Search CVE reports


Toggle filters

71 – 80 of 49222 results

Status is adjusted based on your filters.


CVE-2026-82253

Medium priority

Not in release

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via...

2 affected packages

rust-gix, rust-gix-validate

Package 22.04 LTS
rust-gix Not in release
rust-gix-validate Not in release
Show less packages

CVE-2026-82252

Medium priority

Not in release

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked...

1 affected package

rust-gix

Package 22.04 LTS
rust-gix Not in release
Show less packages

CVE-2026-82251

Medium priority

Not in release

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to...

1 affected package

rust-gix

Package 22.04 LTS
rust-gix Not in release
Show less packages

CVE-2026-82250

Medium priority

Not in release

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band...

1 affected package

rust-gix-packetline

Package 22.04 LTS
rust-gix-packetline Not in release
Show less packages

CVE-2026-82249

Medium priority

Not in release

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and...

1 affected package

rust-gix-credentials

Package 22.04 LTS
rust-gix-credentials Not in release
Show less packages

CVE-2026-82248

Medium priority

Not in release

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization...

4 affected packages

rust-gix, rust-gix-features, rust-gix-worktree, rust-gix-worktree-state

Package 22.04 LTS
rust-gix Not in release
rust-gix-features Not in release
rust-gix-worktree Not in release
rust-gix-worktree-state Not in release
Show less packages

CVE-2026-82247

Medium priority

Not in release

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect...

2 affected packages

rust-gix-transport, rust-gix-url

Package 22.04 LTS
rust-gix-transport Not in release
rust-gix-url Not in release
Show less packages

CVE-2026-82072

Medium priority
Not affected

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-81934

Medium priority
Needs evaluation

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute...

1 affected package

redis

Package 22.04 LTS
redis Needs evaluation
Show less packages

CVE-2026-81893

Medium priority
Needs evaluation

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent...

1 affected package

gdk-pixbuf

Package 22.04 LTS
gdk-pixbuf Needs evaluation
Show less packages