Search CVE reports


Toggle filters

1 – 10 of 56 results


CVE-2026-33750

Medium priority
Needs evaluation

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence...

1 affected package

node-brace-expansion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-brace-expansion Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-32875

Medium priority
Needs evaluation

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the...

3 affected packages

ujson, pandas, collada2gltf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ujson Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pandas Needs evaluation Needs evaluation Needs evaluation Needs evaluation
collada2gltf Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-32874

Medium priority
Needs evaluation

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1])...

3 affected packages

pandas, ujson, collada2gltf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandas Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ujson Needs evaluation Needs evaluation Needs evaluation Needs evaluation
collada2gltf Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-25547

Medium priority
Needs evaluation

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an...

1 affected package

node-brace-expansion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-brace-expansion Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69662

Medium priority
Fixed

SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.

1 affected package

python-geopandas

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-geopandas Fixed Fixed Not affected Not affected
Show less packages

CVE-2025-40929

Medium priority

Some fixes available 4 of 7

Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

1 affected package

libcpanel-json-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcpanel-json-xs-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-51591

Medium priority
Needs evaluation

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve...

1 affected package

pandoc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-5889

Medium priority
Needs evaluation

A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient...

1 affected package

node-brace-expansion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-brace-expansion Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-9880

Medium priority
Ignored

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

1 affected package

pandas

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandas Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-45321

Medium priority
Needs evaluation

The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

1 affected package

cpanminus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpanminus Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages