Search CVE reports


Toggle filters

321 – 330 of 38395 results

Status is adjusted based on your filters.


CVE-2026-44727

Medium priority
Needs evaluation

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in...

1 affected package

jupyter-server

Package 24.04 LTS
jupyter-server Needs evaluation
Show less packages

CVE-2026-41479

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses...

1 affected package

python-authlib

Package 24.04 LTS
python-authlib Needs evaluation
Show less packages

CVE-2026-48931

Medium priority
Needs evaluation

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-54293

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-56109

Medium priority
Needs evaluation

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration...

1 affected package

alsa-lib

Package 24.04 LTS
alsa-lib Needs evaluation
Show less packages

CVE-2026-54283

Medium priority
Needs evaluation

Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced...

1 affected package

starlette

Package 24.04 LTS
starlette Needs evaluation
Show less packages

CVE-2026-54282

Medium priority
Needs evaluation

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path}...

1 affected package

starlette

Package 24.04 LTS
starlette Needs evaluation
Show less packages

CVE-2026-54280

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or...

1 affected package

python-aiohttp

Package 24.04 LTS
python-aiohttp Needs evaluation
Show less packages

CVE-2026-54279

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status....

1 affected package

python-aiohttp

Package 24.04 LTS
python-aiohttp Needs evaluation
Show less packages

CVE-2026-54278

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to...

1 affected package

python-aiohttp

Package 24.04 LTS
python-aiohttp Needs evaluation
Show less packages