Advisories
All published security advisories for packages in the Julia ecosystem.
JLSEC-2026-797Windows IOCP lifetime bugs can corrupt memory during cancellation or shutdownJLSEC-2026-798TLS 1.3 KeyUpdate handling can race concurrent writesJLSEC-2026-799Unauthenticated TLS records can exhaust memory or CPU during a handshakeJLSEC-2026-800Slow DNS lookups can stall garbage collection process-wideJLSEC-2026-801Native TLS accepts undersized or malformed RSA certificate public keysJLSEC-2026-802TLS 1.2 session resumption can renew one master secret indefinitelyJLSEC-2026-803Windows IOCP poller races unsynchronized registration tablesJLSEC-2026-791Low 3.9Writing to SFTP files resulting in sending out-of-bounds data to the serverJLSEC-2026-788Medium 5.1UpstreamBuffer overflow in gawk's `readdir.c` can cause denial of service and possible code execu…JLSEC-2026-787Medium 5.1UpstreamInteger overflow in gawk's `do_sub()` can cause buffer overflow and denial of serviceJLSEC-2026-786Low 2.1UpstreamInteger overflow in gawk's `builtin.c` can cause buffer overflow and denial of serviceJLSEC-2026-785Medium 5.1UpstreamUse after free vulnerability in gawk 5.4.0 and earlierJLSEC-2026-796Medium 5.1UpstreamXSS via unescaped code-fence language in default code block rendererJLSEC-2026-795Medium 6.3UpstreamHugo: security.http.urls allow-list bypass via HTTP redirectsJLSEC-2026-794Medium 5.1UpstreamHugo: XSS via text/html content filesJLSEC-2026-663High 8.3Upstreamlibssh2 through 1.11.1 grows its publickey list with `SSH2_REALLOC` but does not zero-ini…JLSEC-2026-662High 8.3Upstreamlibssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a...JLSEC-2026-758Medium 5.7UpstreamiPAddress name constraints bypass when `WOLFSSL_IP_ALT_NAME` is not definedJLSEC-2026-756Medium 5.9Upstream`PKCS7_verify` signer confusion allows forged signatures, where the signer associated wit…JLSEC-2026-749Low 2.1UpstreamHMAC zero-length tag forgery in `EVP_DigestVerifyFinal`, where a zero-length tag could be…JLSEC-2026-748Medium 6.3UpstreamThe ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the…JLSEC-2026-747Medium 6.0UpstreamPKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the int…JLSEC-2026-746Low 2.0UpstreamOut-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algori…JLSEC-2026-743Low 2.1UpstreamWhen `HAVE_ENCRYPT_THEN_MAC` is configured, the implementation could fall back to MAC-the…JLSEC-2026-737Medium 6.0UpstreamTLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's …JLSEC-2026-633High 8.1Upstreamvtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerabilityJLSEC-2026-698Medium 6.0UpstreamMissing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped th…JLSEC-2026-694Medium 6.3UpstreamOCSP CertID serial-number length-confusion in `wolfSSL_OCSP_resp_find_status` allows a sa…JLSEC-2026-755Medium 6.0UpstreamX.509 name constraint bypass via the Subject Common Name when treated as a DNS-type nameJLSEC-2026-754Low 1.0UpstreamThe PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowin…JLSEC-2026-753High 8.8UpstreamA heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the conn…JLSEC-2026-752Low 1.0UpstreamInteger underflow in `wc_PKCS7_DecryptOri` when handling crafted Other Recipient Info, le…JLSEC-2026-751Low 1.0UpstreamA CRL critical extension bypass exists in `ParseCRL_Extensions` where critical extensions…JLSEC-2026-750Low 2.3UpstreamCertificate policy and RFC 8446 compliance concerns regarding the continued acceptance of…JLSEC-2026-757Low 2.3UpstreamUse-after-free in PQC hybrid key-share handlingJLSEC-2026-738Medium 6.3UpstreamChain intermediate CA:TRUE without keyCertSign accepted as a signing CAJLSEC-2026-735High 8.2UpstreamUn-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypass…JLSEC-2026-734High 8.3UpstreamOut-of-bounds write in the Renesas TSIP TLS 1.3 transcript bufferJLSEC-2026-700Medium 6.3UpstreamOut-of-bounds heap read during SM2/SM3 certificate signature verificationJLSEC-2026-697High 8.7UpstreamX.509 trust-chain bypass in the OpenSSL compatibility certificate verifier...JLSEC-2026-696Medium 6.3UpstreamCertificates with wildcard DNS SANs (e.gJLSEC-2026-695Low 2.3UpstreamThe X25519 `x86_64` assembly implementation fails to clear the most significant bit durin…JLSEC-2026-693High 8.3UpstreamML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks …JLSEC-2026-745Medium 6.0UpstreamBleichenbacher padding oracle in PKCS#7 KTRI decryptionJLSEC-2026-744Medium 6.3UpstreamHeap buffer overread in `wc_PKCS7_DecodeEnvelopedData` when parsing crafted PKCS7 Envelop…JLSEC-2026-742Medium 6.0UpstreamPartial-chain certificate verification may accept chains that terminate at a peer-supplie…JLSEC-2026-739Low 2.0UpstreamAES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 G…JLSEC-2026-736High 8.2Upstream`wolfSSL_PKCS7_verify()` returning success for a degenerate (certs-only) PKCS#7 object th…JLSEC-2026-699High 8.2UpstreamX.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate…JLSEC-2026-667Low 2.5UpstreamGNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToU…JLSEC-2026-658High 7.4UpstreamDeno: Miller-Rabin Primality Test Allows Zero RoundsJLSEC-2026-657Medium 5.5UpstreamDeno: BYONM module resolution allows `package.json` main path traversal to bypass `--allo…JLSEC-2026-656High 8.1UpstreamDeno: Command Injection via spawnSync & spawn on WindowsJLSEC-2026-655High 8.4UpstreamDeno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)JLSEC-2026-654Critical 9.1UpstreamDeno's TLS retry copies stale upgrade hook, risking plaintext trafficJLSEC-2026-611Unbounded HTTP/2 concurrent streams and Rapid Reset denial of service in HTTP.jl serverJLSEC-2026-612Path traversal in the HTTP.jl static file server via separator/absolute path segmentsJLSEC-2026-613Redirect credential leakage across scheme/port in HTTP.jlJLSEC-2026-614WebSocket default Origin check ignores scheme and port in HTTP.jlJLSEC-2026-615Cookie jar accepts `Secure/__Host-/__Secure-` cookies from non-secure origins in HTTP.jlJLSEC-2026-616HTTP/1 client request smuggling via CR/LF in method, target, or host in HTTP.jlJLSEC-2026-617Open redirect in the HTTP.jl static file server canonical redirectsJLSEC-2026-618HTTP/1 request smuggling via bare-LF, lenient chunk size, and TE/CL handling in HTTP.jl s…JLSEC-2026-619CR/LF injection in server-sent events (SSE) fields in HTTP.jlJLSEC-2026-620WebSocket reader data race in auto-PONG/CLOSE-echo handling in HTTP.jlJLSEC-2026-621Thread-safety and out-of-bounds reads in the HTTP.jl content-type snifferJLSEC-2026-622Predictable WebSocket masking key and handshake nonce in HTTP.jl clientJLSEC-2026-623Insufficient HTTP/2 pseudo-header and Host/:authority validation in HTTP.jl serverJLSEC-2026-624HTTP/2 client HPACK desynchronization via header blocks for unknown streams in HTTP.jlJLSEC-2026-790High 7.1UpstreamA malicious h.265 bitstream can cause integer overflow and out of bounds writes in libde2…JLSEC-2026-789High 7.1UpstreamA malicious h.265 bitstream can cause an out-of-bounds write in libde265JLSEC-2026-813High 8.3UpstreamCrafted HTJ2K compressed EXR files can trigger out of bounds reads in OpenEXRJLSEC-2026-812High 7.1UpstreamHeap buffer overflow when decoding a malicious HTJ2K-compressed EXR fileJLSEC-2026-659High 8.3Upstreamlibssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vuln…JLSEC-2026-653High 8.8UpstreamAn out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the …JLSEC-2026-661Critical 9.2Upstreamlibssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerabi…JLSEC-2026-660High 8.2Upstreamlibssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of …JLSEC-2026-666Medium 5.1Upstreamlibusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in...JLSEC-2026-665Medium 6.9Upstreamlibusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allow…JLSEC-2026-766High 7.8UpstreamGDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-ba…JLSEC-2026-574Medium 5.1UpstreamNo summary availableJLSEC-2026-573Medium 6.5UpstreamNo summary availableJLSEC-2026-626High 7.3UpstreamRsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race conditio…JLSEC-2026-632Low 2.1UpstreamNo summary availableJLSEC-2026-631Medium 6.9UpstreamRsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerabil…JLSEC-2026-630High 7.2UpstreamRsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-base…JLSEC-2026-629Medium 6.1UpstreamRsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed…JLSEC-2026-628Medium 6.3UpstreamRsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync …JLSEC-2026-572High 8.8UpstreamNo summary availableJLSEC-2026-571Medium 6.5UpstreamNo summary availableJLSEC-2026-570Medium 6.5UpstreamNo summary availableJLSEC-2026-608High 8.8UpstreamNo summary availableJLSEC-2026-607High 8.8UpstreamNo summary availableJLSEC-2026-606High 7.5UpstreamNo summary availableJLSEC-2026-605Medium 6.5UpstreamNo summary availableJLSEC-2026-604High 8.8UpstreamNo summary availableJLSEC-2026-603High 8.8UpstreamNo summary availableJLSEC-2026-602Medium 4.3UpstreamNo summary availableJLSEC-2026-601High 8.8UpstreamNo summary availableJLSEC-2026-600Medium 5.4UpstreamNo summary availableJLSEC-2026-793Medium 6.2UpstreamHugo's Node tool execution allows file system access outside the project directoryJLSEC-2026-772Low 1.9UpstreamA vulnerability has been found in OSGeo gdal up to 3.13.0dev-4JLSEC-2026-771Low 1.9UpstreamOSGeo gdal has a heap-based buffer overflowJLSEC-2026-770Low 1.9UpstreamOSGeo GDAL vulnerable to out-of-bounds readJLSEC-2026-769Low 1.9UpstreamOSGeo GDAL vulnerable to heap-based buffer overflowJLSEC-2026-768Low 1.9UpstreamA vulnerability was identified in OSGeo gdal up to 3.13.0dev-4JLSEC-2026-767Low 1.9UpstreamA vulnerability was determined in OSGeo gdal up to 3.13.0dev-4JLSEC-2026-811Medium 6.3UpstreamA malicious EXR file can trigger undefined behavior in OpenEXRJLSEC-2026-810High 8.8UpstreamPossible out-of-bounds access in OpenEXR's `IDManifest::init()`JLSEC-2026-809High 8.8UpstreamInteger overflow in OpenEXR's `ImageChannel:resize`JLSEC-2026-492Medium 6.9UpstreamNo summary availableJLSEC-2026-373Low 2.9UpstreamNo summary availableJLSEC-2026-372Medium 5.5UpstreamNo summary availableJLSEC-2026-497Medium 4.0UpstreamLibgcrypt before 1.12.2 mishandles Dilithium signingJLSEC-2026-496Medium 6.7UpstreamLibgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of servi…JLSEC-2026-281Critical 9.2UpstreamRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiatio…JLSEC-2026-280Critical 9.2UpstreamRclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive oper…JLSEC-2026-808High 8.4UpstreamInteger overflow in OpenEXR's `internal_dwa_compressor`JLSEC-2026-807High 8.4UpstreamInteger overflow in OpenEXR's `internal_dwa_compressor`JLSEC-2026-806Medium 5.3UpstreamReading malicious EXR files can cause out-of-bounds writesJLSEC-2026-213Low 2.1UpstreamWhen sed is invoked with both -i (in-place edit) and --follow-symlinks, the function...JLSEC-2026-491High 7.5UpstreamNo summary availableJLSEC-2026-384Low 2.9UpstreamNo summary availableJLSEC-2026-627High 7.8UpstreamIn rsync 3.0.1 through 3.4.1, `receive_xattr` relies on an untrusted length value during …JLSEC-2026-652Critical 9.8UpstreamFFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Com…JLSEC-2026-773Medium 5.3UpstreamNo summary availableJLSEC-2026-651High 7.5UpstreamNo summary availableJLSEC-2026-650High 7.5UpstreamNo summary availableJLSEC-2026-649High 7.5UpstreamNo summary availableJLSEC-2026-152High 7.1UpstreamIn libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus Mak…JLSEC-2026-151High 7.1UpstreamIn libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling…JLSEC-2026-353Medium 5.5UpstreamNo summary availableJLSEC-2026-727High 8.2UpstreamAn integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited…JLSEC-2026-730High 8.6Upstream`wolfSSL_X509_verify_cert` in the OpenSSL compatibility layer accepts a certificate chain…JLSEC-2026-729High 8.7UpstreamwolfSSL's `wc_PKCS7_DecodeAuthEnvelopedData()` does not properly sanitize the AES-GCM aut…JLSEC-2026-728High 7.6UpstreamIn wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in `wolfSSL_EVP_Cipher…JLSEC-2026-726High 7.6UpstreamwolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars f…JLSEC-2026-715Low 2.3UpstreamAn integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (S…JLSEC-2026-725Medium 6.3UpstreamA heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid …JLSEC-2026-724Low 2.3UpstreamX.509 date buffer overflow in `wolfSSL_X509_notAfter` / `wolfSSL_X509_notBefore`JLSEC-2026-721Medium 6.3UpstreamDual-Algorithm CertificateVerify out-of-bounds readJLSEC-2026-720Low 2.3UpstreamHeap out-of-bounds read in PKCS7 parsingJLSEC-2026-733Medium 4.1UpstreamWhen restoring a session from cache, a pointer from the serialized session data is used i…JLSEC-2026-732Medium 6.3UpstreamA padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to…JLSEC-2026-731Medium 6.9UpstreamIn `TLSX_EchChangeSNI`, the ctx->extensions branch set extensions unconditionally even wh…JLSEC-2026-719Medium 5.9UpstreamNo summary availableJLSEC-2026-741Low 2.1UpstreamInteger underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a progra…JLSEC-2026-740Low 2.1UpstreamA 1-byte stack buffer over-read was identified in the MatchDomainName function (`src/inte…JLSEC-2026-718High 8.3UpstreamHeap buffer overflow in DTLS 1.3 ACK message processingJLSEC-2026-717High 7.0UpstreamNo summary availableJLSEC-2026-723Medium 6.3UpstreamHeap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusionJLSEC-2026-722Medium 6.0UpstreamIn wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byt…JLSEC-2026-716Critical 9.3UpstreamMissing hash/digest size and OID checks allow digests smaller than allowed when verifying…JLSEC-2026-714Low 2.3UpstreamNo summary availableJLSEC-2026-354High 7.8UpstreamNo summary availableJLSEC-2026-498Medium 4.4UpstreamNo summary availableJLSEC-2026-277High 7.5UpstreamIssue summary: Applications using RSASVE key encapsulation to establish a secret encrypti…JLSEC-2026-276Critical 9.8UpstreamIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string…JLSEC-2026-275High 7.5UpstreamNo summary availableJLSEC-2026-274High 7.5UpstreamIssue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeReci…JLSEC-2026-273High 7.5UpstreamNo summary availableJLSEC-2026-272High 8.1UpstreamNo summary availableJLSEC-2026-778High 7.0UpstreamNo summary availableJLSEC-2026-792Medium 5.3UpstreamHugo: Certain markdown links are not properly escapedJLSEC-2026-149High 8.4UpstreamNo summary availableJLSEC-2026-148High 8.6UpstreamNo summary availableJLSEC-2026-144Medium 5.9UpstreamNo summary availableJLSEC-2026-143High 7.1UpstreamNo summary availableJLSEC-2026-142Medium 6.5UpstreamNo summary availableJLSEC-2026-212Medium 4.7UpstreamNo summary availableJLSEC-2026-462Low 1.7UpstreamNo summary availableJLSEC-2026-78High 8.1UpstreamNo summary availableJLSEC-2026-77Low 2.5UpstreamNo summary availableJLSEC-2026-76Medium 6.5UpstreamNo summary availableJLSEC-2026-75High 8.1UpstreamNo summary availableJLSEC-2026-74High 8.1UpstreamIn OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an ou…JLSEC-2026-467Critical 9.8UpstreamMbed TLS serialized session data is not cryptographically protectedJLSEC-2026-371Low 2.9UpstreamA vulnerability was determined in Cesanta Mongoose up to 7.20JLSEC-2026-370Low 2.9UpstreamA vulnerability was found in Cesanta Mongoose up to 7.20JLSEC-2026-369Medium 5.5UpstreamA vulnerability has been found in Cesanta Mongoose up to 7.20JLSEC-2026-147High 8.4UpstreamNo summary availableJLSEC-2026-146High 8.4UpstreamNo summary availableJLSEC-2026-145High 8.7UpstreamNo summary availableJLSEC-2026-466Critical 9.1UpstreamMbed TLS peer can force the FFDH shared secret into a small set of valuesJLSEC-2026-463Medium 5.1UpstreamMbed TLS timing side channel in RSA and CBC/ECB decryptionJLSEC-2026-465Medium 6.7UpstreamMbed TLS may use a low entropy PRNG seedJLSEC-2026-464High 7.7UpstreamMbed TLS might use cloned PSA random generator statesJLSEC-2026-783Low 3.1UpstreamNo summary availableJLSEC-2026-782Medium 5.5UpstreamNo summary availableJLSEC-2026-781High 8.2UpstreamNo summary availableJLSEC-2026-780Low 3.3UpstreamNo summary availableJLSEC-2026-779Medium 6.3UpstreamNo summary availableJLSEC-2026-96High 7.6UpstreamNo summary availableJLSEC-2026-95High 7.5UpstreamNo summary availableJLSEC-2026-79High 7.8UpstreamNo summary availableJLSEC-2026-288Critical 9.4UpstreamImproper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in …JLSEC-2026-159Medium 5.0UpstreamNo summary availableJLSEC-2026-158High 8.7UpstreamNo summary availableJLSEC-2026-712Low 1.2UpstreamNo summary availableJLSEC-2026-713Low 1.3UpstreamNo summary availableJLSEC-2026-711Medium 6.9UpstreamStack Buffer Overflow in `wc_HpkeLabeledExtract` via Oversized ECH ConfigJLSEC-2026-708High 8.3UpstreamNo summary availableJLSEC-2026-706High 7.5UpstreamOut-of-bounds read in ALPN parsing due to incomplete validationJLSEC-2026-704Low 1.2UpstreamMissing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake log…JLSEC-2026-703Low 1.2UpstreamNo summary availableJLSEC-2026-710Low 2.1UpstreamNo summary availableJLSEC-2026-709Low 2.1UpstreamNo summary availableJLSEC-2026-705Medium 4.3UpstreamProtection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA…JLSEC-2026-707High 7.2UpstreamTwo buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL nu…JLSEC-2026-702Medium 5.0UpstreamA heap-buffer-overflow vulnerability exists in wolfSSL's `wolfSSL_d2i_SSL_SESSION()` func…JLSEC-2026-701Medium 5.5UpstreamNo summary availableJLSEC-2026-692Low 2.1UpstreamInteger underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer…JLSEC-2026-691Low 2.2UpstreamA stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding funct…JLSEC-2026-5High 7.5Upstreamnghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in CJLSEC-2026-182Low 2.0UpstreamNo summary availableJLSEC-2026-383Medium 5.5UpstreamNo summary availableJLSEC-2026-382Medium 5.5UpstreamNo summary availableJLSEC-2026-381Medium 5.5UpstreamNo summary availableJLSEC-2026-150High 7.8UpstreamNo summary availableJLSEC-2026-271Medium 6.5UpstreamIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key…JLSEC-2026-439High 7.5UpstreamWhen doing a second SMB request to the same host again, curl would wrongly use a data poi…JLSEC-2026-438Medium 6.5Upstreamcurl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, eve…JLSEC-2026-437Medium 5.3UpstreamWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a…JLSEC-2026-436Medium 6.5UpstreamNo summary availableJLSEC-2026-784Medium 6.9UpstreamNo summary availableJLSEC-2026-141High 8.4UpstreamNo summary availableJLSEC-2026-461Medium 5.3UpstreamAn integer overflow in the `tt_var_load_item_variation_store` function of the Freetype li…JLSEC-2026-425Medium 4.6UpstreamURLs containing percent-encoded slashes (`/` or `\ `) can trick wcurl into saving the out…JLSEC-2026-140Medium 6.5UpstreamNo summary availableJLSEC-2026-157Medium 6.2UpstreamNo summary availableJLSEC-2026-486Medium 5.0UpstreamNo summary availableJLSEC-2026-485High 7.3UpstreamNo summary availableJLSEC-2026-484Medium 5.5UpstreamNo summary availableJLSEC-2026-368Low 2.9UpstreamA vulnerability was detected in Cesanta Mongoose up to 7.20JLSEC-2026-367Low 2.9UpstreamA security vulnerability has been detected in Cesanta Mongoose up to 7.20JLSEC-2026-366Low 2.9UpstreamA weakness has been identified in Cesanta Mongoose up to 7.20JLSEC-2026-116Critical 9.8UpstreamDeno has a Command Injection via Incomplete shell metacharacter blocklist in `node:child_…JLSEC-2026-352High 7.8UpstreamNo summary availableJLSEC-2026-642Medium 5.5UpstreamNo summary availableJLSEC-2026-641Medium 5.5UpstreamNo summary availableJLSEC-2026-480Medium 5.5Upstreamzlib before 1.3.2 allows CPU consumption via `crc32_combine64` and `crc32_combine_gen64` …JLSEC-2026-805High 7.0UpstreamApache Arrow: Potential use-after-free when reading IPC file with pre-bufferingJLSEC-2026-56High 8.8UpstreamNo summary availableJLSEC-2026-55High 8.8UpstreamNo summary availableJLSEC-2026-54High 8.8UpstreamNo summary availableJLSEC-2026-53Medium 4.3UpstreamNo summary availableJLSEC-2026-11High 8.3UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2026-380High 7.8UpstreamNo summary availableJLSEC-2026-566Medium 5.5UpstreamIn GnuPG before 2.5.17, a long signature packet length causes `parse_signature` to return…JLSEC-2026-565High 7.8UpstreamIn GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handlin…JLSEC-2026-564Critical 9.8UpstreamIn GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversize…JLSEC-2026-270Medium 5.3UpstreamIssue summary: A type confusion vulnerability exists in the signature verification of sig…JLSEC-2026-269Medium 5.5UpstreamIssue summary: An invalid or NULL pointer dereference can happen in an application proces…JLSEC-2026-265High 7.5UpstreamIssue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference…JLSEC-2026-264High 7.5UpstreamIssue summary: A type confusion vulnerability exists in the TimeStamp Response verificati…JLSEC-2026-263High 7.4UpstreamIssue summary: Calling `PKCS12_get_friendlyname()` function on a maliciously crafted PKCS…JLSEC-2026-262Medium 4.0UpstreamIssue summary: When using the low-level OCB API directly with AES-NI or<br>other...JLSEC-2026-261Medium 4.7UpstreamIssue summary: Writing large, newline-free data into a BIO chain using the line-buffering…JLSEC-2026-260Medium 5.9UpstreamIssue summary: A TLS 1.3 connection using certificate compression can be forced to alloca…JLSEC-2026-10Medium 5.5UpstreamBuffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a …JLSEC-2026-9Medium 5.5UpstreamBuffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a …JLSEC-2026-258Medium 5.5UpstreamIssue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB…JLSEC-2026-257Medium 5.9UpstreamIssue summary: If an application using the `SSL_CIPHER_find()` function in a QUIC protoco…JLSEC-2026-256High 8.8UpstreamIssue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parame…JLSEC-2026-255Medium 6.1UpstreamIssue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigge…JLSEC-2026-379Low 2.5UpstreamNo summary availableJLSEC-2026-189Low 1.9UpstreamNo summary availableJLSEC-2026-531Low 1.9UpstreamNo summary availableJLSEC-2026-530Low 1.9UpstreamNo summary availableJLSEC-2026-115Critical 9.8UpstreamDeno has an incomplete fix for command-injection prevention on Windows — case-insensiti…JLSEC-2026-114Critical 9.2UpstreamDeno node:crypto doesn't finalize cipherJLSEC-2026-8High 7.8UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2026-7High 7.1UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2026-777Medium 5.3UpstreamNo summary availableJLSEC-2026-431Low 3.1UpstreamWhen doing SSH-based transfers using either SCP or SFTP, and asked to do public key authe…JLSEC-2026-430Medium 5.3UpstreamWhen doing SSH-based transfers using either SCP or SFTP, and setting the `known_hosts` fi…JLSEC-2026-429Medium 5.3UpstreamWhen doing TLS related transfers with reused easy or multi handles and altering the...JLSEC-2026-428Medium 5.3UpstreamWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a…JLSEC-2026-427Medium 6.3UpstreamWhen doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS opti…JLSEC-2026-426Medium 5.9UpstreamWhen using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the cur…JLSEC-2026-156High 7.1UpstreamNo summary availableJLSEC-2026-563High 7.0UpstreamIn GnuPG through 2.4.8, `armor_filter` in g10/armor.c has two increments of an index vari…JLSEC-2026-562Medium 4.7UpstreamIn GnuPG through 2.4.8, if a signed message has `\f` at the end of a plaintext line, an a…JLSEC-2026-137High 7.8UpstreamNo summary availableJLSEC-2026-136High 7.8UpstreamNo summary availableJLSEC-2026-135High 7.8UpstreamNo summary availableJLSEC-2026-688Low 1.0UpstreamMultiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed…JLSEC-2026-489Medium 6.5UpstreamA flaw was found in glibJLSEC-2026-488Critical 9.8UpstreamA flaw was found in GLib (Gnome Lib)JLSEC-2026-6High 7.1UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2026-378Medium 5.5UpstreamNo summary availableJLSEC-2026-487High 7.7UpstreamNo summary availableJLSEC-2025-331High 7.1UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2025-330High 7.1UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2025-329Medium 6.1UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2025-328Medium 6.1UpstreamLIBPNG is a reference library for use in applications that read, create, and manipulate P…JLSEC-2026-687Low 2.3UpstreamWith TLS 1.2 connections a client can use any digest, specifically a weaker digest that i…JLSEC-2026-686Low 2.1UpstreamInteger Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 DecryptJLSEC-2026-181Medium 6.9UpstreamNo summary availableJLSEC-2026-625Medium 4.3UpstreamA malicious client acting as the receiver of an rsync file transfer can trigger an out of…JLSEC-2026-775Medium 6.9UpstreamNo summary availableJLSEC-2026-139Medium 5.5UpstreamNo summary availableJLSEC-2026-138Medium 5.5UpstreamNo summary availableJLSEC-2026-424Medium 4.3Upstreamcurl's code for managing SSH connections when SFTP was done using the wolfSSH powered bac…JLSEC-2026-153Medium 5.5UpstreamNo summary availableJLSEC-2025-233Medium 5.3UpstreamPadding oracle through timing of cipher error reportingJLSEC-2025-232Medium 6.2UpstreamSide channel in RSA key generation and operations (SSBleed, M-Step)JLSEC-2026-89Medium 6.1UpstreamNo summary availableJLSEC-2025-40High 8.7Header injection/Response splitting via header construction.JLSEC-2026-113High 8.1UpstreamDeno is Vulnerable to Command Injection on Windows During Batch File ExecutionJLSEC-2026-112Low 3.3UpstreamDeno's --deny-read check does not prevent permission bypassJLSEC-2026-111Low 3.3UpstreamDeno's --deny-write check does not prevent permission bypassJLSEC-2025-8Low 3.6Upstreamssh in OpenSSH before 10.1 allows the '`\0`' character in an `ssh://` URI, potentially le…JLSEC-2025-7Low 3.6Upstreamssh in OpenSSH before 10.1 allows control characters in usernames that originate from cer…JLSEC-2026-647High 8.7UpstreamIt is possible to cause an use-after-free write in SANM decoding with a carefully crafted…JLSEC-2026-646High 8.7UpstreamWhen decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit ass…JLSEC-2026-645High 8.7UpstreamWhen decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit ass…JLSEC-2026-644Medium 6.9UpstreamWhen decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw lengt…JLSEC-2026-268Medium 5.9UpstreamIssue summary: An application using the OpenSSL HTTP client API functions may trigger an.…JLSEC-2026-267Medium 6.5UpstreamIssue summary: A timing side-channel which could potentially allow remote recovery of the…JLSEC-2026-266High 7.5UpstreamNo summary availableJLSEC-2025-173High 7.5Upstreamlibexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocatio…JLSEC-2026-435High 7.5Upstream1JLSEC-2026-423Medium 5.3Upstreamcurl's websocket code did not update the 32 bit mask pattern for each new outgoing frame …JLSEC-2025-91Medium 5.5UpstreamUncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 …JLSEC-2026-648High 7.2UpstreamNo summary availableJLSEC-2026-60Medium 6.9UpstreamNo summary availableJLSEC-2025-323Low 1.1WithdrawnUpstreamA flaw has been found in LibTIFF 4.7.0JLSEC-2025-322Low 1.9UpstreamA weakness has been identified in LibTIFF 4.7.0JLSEC-2025-321Medium 4.8UpstreamA vulnerability was determined in LibTIFF up to 4.5.1JLSEC-2026-551Medium 6.5UpstreamNo summary availableJLSEC-2026-552Medium 6.6UpstreamNo summary availableJLSEC-2025-320Low 1.1UpstreamA vulnerability classified as problematic was found in libtiff 4.6.0JLSEC-2026-88Medium 6.5UpstreamNo summary availableJLSEC-2026-763Medium 5.3UpstreamNo summary availableJLSEC-2026-762Critical 10.0UpstreamNo summary availableJLSEC-2025-319Low 2.0UpstreamA vulnerability was found in LibTIFF up to 4.7.0JLSEC-2025-168High 7.5UpstreamA flaw was found in GLibJLSEC-2025-318Medium 4.8UpstreamA vulnerability was found in LibTIFF up to 4.7.0JLSEC-2025-317Low 1.9UpstreamA vulnerability was found in LibTIFF up to 4.7.0JLSEC-2025-100Medium 6.5UpstreamA flaw was found in the SFTP server message decoding logic of libsshJLSEC-2025-99Medium 4.7UpstreamA flaw was found in libssh, a library that implements the SSH protocolJLSEC-2025-231Critical 9.8UpstreamMbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that …JLSEC-2025-230High 7.5UpstreamMbed TLS before 3.6.4 has a NULL pointer dereference because `mbedtls_asn1_store_named_da…JLSEC-2026-690Critical 9.2UpstreamA certificate verification error in wolfSSL when building with the `WOLFSSL_SYS_CA_CERTS`…JLSEC-2026-689High 7.0UpstreamIn the OpenSSL compatibility layer implementation, the function `RAND_poll()` was not beh…JLSEC-2026-569Medium 6.6UpstreamNo summary availableJLSEC-2025-9High 7.5UpstreamImageMagick is free and open-source software used for editing and manipulating digital im…JLSEC-2025-197Medium 4.1UpstreamGNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archive…JLSEC-2026-527High 8.2UpstreamNo summary availableJLSEC-2025-332High 8.1UpstreamA flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL libraryJLSEC-2026-351Low 1.9UpstreamNo summary availableJLSEC-2026-350Low 1.9UpstreamNo summary availableJLSEC-2026-349Low 1.9UpstreamNo summary availableJLSEC-2025-229Medium 4.8UpstreamMbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in...JLSEC-2025-228High 7.8UpstreamMbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimiz…JLSEC-2025-98Medium 6.5UpstreamA flaw was found in the key export functionality of libsshJLSEC-2025-97High 8.8UpstreamA flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifica…JLSEC-2026-90Medium 5.5UpstreamNo summary availableJLSEC-2026-348Low 1.9UpstreamNo summary availableJLSEC-2026-347Low 1.9UpstreamNo summary availableJLSEC-2026-346Low 1.9UpstreamNo summary availableJLSEC-2026-345Low 1.9UpstreamNo summary availableJLSEC-2026-344Low 1.9UpstreamNo summary availableJLSEC-2026-343Low 1.9UpstreamNo summary availableJLSEC-2026-342Low 1.9UpstreamNo summary availableJLSEC-2025-5Medium 6.6Lack of validation for user-provided fields in GitHub.jlJLSEC-2025-2High 8.1Command injection in `withpasswd()` function in Registrator.jlJLSEC-2025-4High 8.1Argument injection in `gettreesha()` function in Registrator.jlJLSEC-2025-1High 7.7CR/LF injection in URIs.jl (also affects HTTP.jl)JLSEC-2025-3Medium 6.6Lack of validation for user-provided fields in GitForge.jlJLSEC-2025-96High 8.1UpstreamA flaw was found in the libssh library in versions less than 0.11.2JLSEC-2025-39Medium 6.9Possible XSS in HTMLSanitizer when using svg elementsJLSEC-2026-341Low 1.9UpstreamNo summary availableJLSEC-2026-340Low 1.9UpstreamNo summary availableJLSEC-2026-339Low 1.9UpstreamNo summary availableJLSEC-2026-454Medium 4.8UpstreamA vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as proble…JLSEC-2026-197Low 1.9UpstreamNo summary availableJLSEC-2026-196Low 1.9UpstreamNo summary availableJLSEC-2025-167High 7.5UpstreamA flaw was found in how GLib’s GString manages memory when adding data to stringsJLSEC-2025-196High 7.5UpstreamA flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer s…JLSEC-2025-249Medium 6.6UpstreamA vulnerability has been identified in the libarchive libraryJLSEC-2025-247Medium 5.0UpstreamA vulnerability has been identified in the libarchive libraryJLSEC-2025-248Medium 5.6UpstreamA vulnerability has been identified in the libarchive libraryJLSEC-2025-246Medium 6.6UpstreamA vulnerability has been identified in the libarchive libraryJLSEC-2025-245High 7.8UpstreamA vulnerability has been identified in the libarchive library, specifically within the...JLSEC-2026-434High 7.5UpstreamDue to a mistake in libcurl's WebSocket code, a malicious server can send a particularly …JLSEC-2026-110Medium 5.5UpstreamDeno.env.toObject() ignores the variables listed in --deny-env and returns all environmen…JLSEC-2026-109Medium 5.5UpstreamDeno run with --allow-read and --deny-read flags results in allowedJLSEC-2026-108High 7.7UpstreamDeno's AES GCM authentication tags are not verifiedJLSEC-2026-338High 8.8UpstreamNo summary availableJLSEC-2026-337High 8.8UpstreamNo summary availableJLSEC-2026-433Medium 4.8Upstreamlibcurl supports *pinning* of the server certificate public key for HTTPS transfersJLSEC-2026-432Medium 6.5Upstreamlibcurl accidentally skips the certificate verification for QUIC connections when connect…JLSEC-2026-195Medium 4.8UpstreamNo summary availableJLSEC-2026-194Medium 4.8UpstreamNo summary availableJLSEC-2026-193Medium 4.8UpstreamNo summary availableJLSEC-2026-192Medium 4.8UpstreamNo summary availableJLSEC-2026-191Medium 4.8UpstreamNo summary availableJLSEC-2026-259Medium 6.5UpstreamIssue summary: Use of -addreject option with the openssl x509 application adds a trusted …JLSEC-2026-126Medium 6.5UpstreamIn libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multipl…JLSEC-2026-125Critical 9.1UpstreamIn libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffe…JLSEC-2025-152Medium 5.3Upstreamffmpeg 7.1 is vulnerable to Null Pointer Dereference in function `iamf_read_header` in...JLSEC-2026-87Low 3.3UpstreamNSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 sig…JLSEC-2025-90High 7.5UpstreamIn libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschem…JLSEC-2026-190Low 1.9UpstreamNo summary availableJLSEC-2026-73Low 3.8UpstreamIn sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the do…JLSEC-2026-495Critical 9.1UpstreamGraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in `coder…JLSEC-2025-89High 7.5UpstreamIn libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur …JLSEC-2026-86High 7.1UpstreamPoppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the...JLSEC-2026-85Medium 5.5UpstreamA floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can ca…JLSEC-2026-336Low 1.9UpstreamNo summary availableJLSEC-2026-335Low 1.9UpstreamNo summary availableJLSEC-2026-334Low 1.9UpstreamNo summary availableJLSEC-2026-333Low 1.9UpstreamNo summary availableJLSEC-2026-332Low 1.9UpstreamNo summary availableJLSEC-2026-331Low 1.9UpstreamNo summary availableJLSEC-2026-330Low 1.9UpstreamNo summary availableJLSEC-2026-329Low 1.9UpstreamNo summary availableJLSEC-2025-244High 7.5UpstreamNull Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running progr…JLSEC-2026-359Medium 6.2UpstreamNo summary availableJLSEC-2026-358Medium 6.2UpstreamNo summary availableJLSEC-2026-357Medium 6.2UpstreamNo summary availableJLSEC-2026-356Medium 6.2UpstreamNo summary availableJLSEC-2026-355Medium 6.2UpstreamNo summary availableJLSEC-2025-187Medium 4.8UpstreamMbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation o…JLSEC-2025-227Medium 5.4UpstreamMbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that ha…JLSEC-2025-94Medium 4.7UpstreamIn GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted sub…JLSEC-2026-328Medium 4.8UpstreamNo summary availableJLSEC-2026-327Medium 4.8UpstreamNo summary availableJLSEC-2026-326Medium 4.8UpstreamNo summary availableJLSEC-2026-583High 7.8Upstreamnumbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluati…JLSEC-2026-582High 7.8UpstreamxsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exc…JLSEC-2026-460High 8.1UpstreamAn out of bounds write exists in FreeType versions 2.13.0 and below when attempting to pa…JLSEC-2026-325Low 2.3UpstreamNo summary availableJLSEC-2026-494Critical 9.8UpstreamWPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation.JLSEC-2026-493High 7.5UpstreamJXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.JLSEC-2025-243High 7.8Upstream`list_item_verbose` in `tar/util.c` in libarchive through 3.7.7 does not check an strftim…JLSEC-2025-242Medium 4.8UpstreamA vulnerability was found in libarchive up to 3.7.7JLSEC-2025-151Medium 5.3UpstreamA vulnerability, which was classified as critical, was found in FFmpeg up to 7.1JLSEC-2025-88High 7.5Upstreamlibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatM…JLSEC-2025-87High 7.7Upstreamlibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in...JLSEC-2026-643Medium 6.5UpstreamNo summary availableJLSEC-2025-86Critical 9.8Upstreamlibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillN…JLSEC-2026-72Medium 6.8UpstreamNo summary availableJLSEC-2025-150Medium 4.8UpstreamA vulnerability was found in FFmpeg up to 7.1JLSEC-2025-250Medium 4.0Upstreamlibarchive through 3.7.7 has a heap-based buffer over-read in `header_gnu_longlink` in...JLSEC-2026-422High 7.3UpstreamWhen libcurl is asked to perform automatic gzip decompression of content-encoded HTTP res…JLSEC-2026-421High 7.0Upstreamlibcurl would wrongly close the same eventfd file descriptor twice when taking down a con…JLSEC-2026-420Low 3.4UpstreamWhen asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl …JLSEC-2025-85High 7.8UpstreamxmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.JLSEC-2026-248Medium 4.1UpstreamIssue summary: A timing side-channel which could potentially allow recovering the private…JLSEC-2025-149Medium 4.8UpstreamUnchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive …JLSEC-2025-327High 7.5UpstreamA flaw was found in rsyncJLSEC-2025-326High 7.5UpstreamA path traversal vulnerability exists in rsyncJLSEC-2025-325Medium 6.8UpstreamA flaw was found in rsyncJLSEC-2025-324High 7.5UpstreamA flaw was found in rsync which could be triggered when rsync compares file checksumsJLSEC-2025-147High 7.2UpstreamA flaw was found in FFmpeg's DASH playlist supportJLSEC-2025-148Medium 5.3UpstreamA flaw was found in FFmpegJLSEC-2025-146Medium 4.7UpstreamA flaw was found in FFmpeg's HLS demuxerJLSEC-2025-145Medium 6.2UpstreamFFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing …JLSEC-2025-144High 8.8UpstreamFFmpeg version n6.1.1 has a double-free vulnerability in the `fftools/ffmpeg_mux_init.c` …JLSEC-2025-143High 7.5UpstreamA flaw was found in FFmpeg's HLS playlist parsingJLSEC-2025-142Medium 5.3UpstreamA flaw was found in FFmpeg's TTY DemuxerJLSEC-2026-776Critical 9.3UpstreamNo summary availableJLSEC-2026-468Critical 9.1UpstreamNo summary availableJLSEC-2026-83Medium 4.3UpstreamNo summary availableJLSEC-2026-413Low 3.4UpstreamWhen asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl…JLSEC-2025-141Critical 9.1UpstreamFFmpeg n6.1.1 has an Out-of-bounds Read via `libavcodec/ppc/vp8dsp_altivec.c`, static con…JLSEC-2025-140Critical 9.1UpstreamFFmpeg n6.1.1 is Integer OverflowJLSEC-2025-139Medium 6.5UpstreamAn integer overflow in the component `/libavformat/westwood_vqa.c` of FFmpeg n6.1.1 allow…JLSEC-2025-137Medium 6.2UpstreamFFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which all…JLSEC-2025-138Medium 6.2UpstreamFFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.JLSEC-2025-135Medium 5.3UpstreamFFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which a…JLSEC-2025-136Medium 5.5UpstreamIn FFmpeg version n6.1.1, specifically within the `avcodec/speexdec.c` module, a potentia…JLSEC-2026-804Critical 9.8UpstreamDeserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R packag…JLSEC-2026-119Medium 6.5UpstreamApplications that use Wget to access a remote resource using shorthand URLs and pass arbi…JLSEC-2026-279Medium 5.4UpstreamRclone has Improper Permission and Ownership Handling on Symlink Targets with --links and…JLSEC-2026-50High 8.8UpstreamNo summary availableJLSEC-2026-49Medium 4.2UpstreamNo summary availableJLSEC-2026-48Low 3.7UpstreamNo summary availableJLSEC-2026-47Medium 5.4UpstreamNo summary availableJLSEC-2026-251High 7.5UpstreamIssue summary: Calling the OpenSSL API function `SSL_free_buffers` may cause memory to be…JLSEC-2025-166Critical 9.8Upstream`gio/gsocks4aproxy.c` in GNOME GLib before 2.82.1 has an off-by-one error and resultant b…JLSEC-2026-419Medium 6.5UpstreamWhen curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent …JLSEC-2025-65Medium 5.9UpstreamAn issue was discovered in libexpat before 2.6.4JLSEC-2026-254Medium 4.3UpstreamIssue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit v…JLSEC-2025-241High 7.8Upstream`execute_filter_delta` in `archive_read_support_format_rar.c` in libarchive before 3.7.5 …JLSEC-2025-240High 7.8Upstream`execute_filter_audio` in `archive_read_support_format_rar.c` in libarchive before 3.7.5 …JLSEC-2026-303Critical 9.8UpstreamNo summary availableJLSEC-2026-188High 8.4UpstreamNo summary availableJLSEC-2026-418Medium 6.5UpstreamWhen curl is told to use the Certificate Status Request TLS extension, often referred to …JLSEC-2025-226Medium 5.1UpstreamAn issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user…JLSEC-2026-253High 7.5UpstreamIssue summary: Applications performing certificate name checks (e.g., TLS clients checkin…JLSEC-2026-765Medium 4.4UpstreamRemote packet capture support is disabled by default in libpcapJLSEC-2026-764Medium 4.4UpstreamIn affected libpcap versions during the setup of a remote packet capture the internal fun…JLSEC-2025-64Critical 9.8UpstreamAn issue was discovered in libexpat before 2.6.3JLSEC-2025-63Critical 9.8UpstreamAn issue was discovered in libexpat before 2.6.3JLSEC-2025-62High 7.5UpstreamAn issue was discovered in libexpat before 2.6.3JLSEC-2026-681Medium 5.5UpstreamThe side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects…JLSEC-2026-685Critical 10.0UpstreamIn function MatchDomainName(), input param str is treated as a NULL terminated string des…JLSEC-2026-684Medium 5.1UpstreamA malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ci…JLSEC-2026-683Medium 5.9UpstreamAn issue was discovered in wolfSSL before 5.7.0JLSEC-2026-682Medium 4.9UpstreamGenerating the ECDSA nonce k samples a random number r and then truncates this randomness…JLSEC-2025-134Medium 6.9UpstreamA vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5JLSEC-2025-316High 7.5UpstreamA null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`JLSEC-2026-52High 7.5UpstreamNo summary availableJLSEC-2026-180High 7.8UpstreamNo summary availableJLSEC-2025-133Medium 6.9UpstreamA vulnerability was found in FFmpeg up to 7.0.1JLSEC-2025-38Medium 6.5Upstreamlibcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Gene…JLSEC-2026-774High 7.5Upstream`sniff_csv` provides filesystem access even when `enable_external_access` is disabled in …JLSEC-2025-37Medium 4.3Upstreamlibcurl's URL API function [`curl_url_get()`](https://curl.se/libcurl/c/curl_url_get.html…JLSEC-2025-36High 7.5Upstreamlibcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 str…JLSEC-2026-187High 7.8UpstreamNo summary availableJLSEC-2026-550Medium 6.5UpstreamNo summary availableJLSEC-2026-548Medium 4.3UpstreamNo summary availableJLSEC-2026-549Medium 5.5UpstreamNo summary availableJLSEC-2026-71High 8.1UpstreamNo summary availableJLSEC-2026-94Critical 9.1UpstreamNo summary availableJLSEC-2026-93High 7.5UpstreamNo summary availableJLSEC-2026-252Critical 9.1UpstreamIssue summary: Calling the OpenSSL API function `SSL_select_next_proto` with an empty sup…JLSEC-2026-84High 7.5UpstreamNo summary availableJLSEC-2026-120Critical 9.1UpstreamNo summary availableJLSEC-2026-122Critical 10.0UpstreamNo summary availableJLSEC-2026-377Medium 5.9UpstreamNo summary availableJLSEC-2026-376Medium 5.7UpstreamNo summary availableJLSEC-2026-250Medium 5.3UpstreamIssue summary: Checking excessively long DSA keys or parameters may be very slow.JLSEC-2026-51Medium 4.3UpstreamNo summary availableJLSEC-2025-84High 7.5UpstreamAn issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7JLSEC-2026-324High 8.8UpstreamNo summary availableJLSEC-2026-323Medium 5.7UpstreamNo summary availableJLSEC-2026-322Medium 5.7UpstreamNo summary availableJLSEC-2026-321Critical 9.8UpstreamNo summary availableJLSEC-2026-320High 8.8UpstreamNo summary availableJLSEC-2026-319High 7.4UpstreamNo summary availableJLSEC-2026-318High 8.8UpstreamNo summary availableJLSEC-2026-317Critical 9.1UpstreamNo summary availableJLSEC-2026-316Critical 9.8UpstreamNo summary availableJLSEC-2026-315High 7.4UpstreamNo summary availableJLSEC-2026-314High 7.4UpstreamNo summary availableJLSEC-2026-313High 7.4UpstreamNo summary availableJLSEC-2026-312High 8.8UpstreamNo summary availableJLSEC-2026-311High 7.4UpstreamNo summary availableJLSEC-2026-310Critical 9.8UpstreamNo summary availableJLSEC-2026-309High 8.8UpstreamNo summary availableJLSEC-2026-308High 7.4UpstreamNo summary availableJLSEC-2026-307High 7.4UpstreamNo summary availableJLSEC-2026-306Critical 9.8UpstreamNo summary availableJLSEC-2026-305Medium 5.7UpstreamNo summary availableJLSEC-2026-304High 7.5UpstreamNo summary availableJLSEC-2026-302Medium 5.7UpstreamNo summary availableJLSEC-2026-301Medium 5.7UpstreamNo summary availableJLSEC-2026-300High 8.8UpstreamNo summary availableJLSEC-2026-299Medium 5.7UpstreamNo summary availableJLSEC-2026-298High 7.4UpstreamNo summary availableJLSEC-2026-297Critical 9.8UpstreamNo summary availableJLSEC-2026-296High 7.4UpstreamNo summary availableJLSEC-2026-295High 7.4UpstreamNo summary availableJLSEC-2026-294High 8.8UpstreamNo summary availableJLSEC-2026-293High 7.4UpstreamNo summary availableJLSEC-2026-292Critical 9.8UpstreamNo summary availableJLSEC-2026-291High 7.4UpstreamNo summary availableJLSEC-2026-290Critical 9.8UpstreamNo summary availableJLSEC-2026-761Medium 5.9UpstreamNo summary availableJLSEC-2026-107Critical 9.0UpstreamDeno permission escalation vulnerability via open of privileged files with missing `--den…JLSEC-2025-165Medium 5.2UpstreamAn issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1JLSEC-2026-636High 7.8UpstreamNo summary availableJLSEC-2026-246Medium 5.9UpstreamIssue summary: Checking excessively long invalid RSA public keys may take a long time.JLSEC-2026-640High 7.8UpstreamNo summary availableJLSEC-2026-639Medium 6.7UpstreamNo summary availableJLSEC-2026-638Low 3.6UpstreamNo summary availableJLSEC-2026-637High 8.0UpstreamNo summary availableJLSEC-2026-635High 7.8UpstreamNo summary availableJLSEC-2026-634High 7.8UpstreamNo summary availableJLSEC-2025-132High 7.8UpstreamFFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at `ff_gradfun_blur_line_movdqa_sse…JLSEC-2025-131High 8.0UpstreamFFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the `ff_gaussian_blur…JLSEC-2025-130High 7.8UpstreamFFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter,…JLSEC-2025-128Medium 4.0UpstreamFFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative …JLSEC-2025-129High 8.8UpstreamBuffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to e…JLSEC-2026-106High 7.4UpstreamNo summary availableJLSEC-2025-127Medium 5.3UpstreamFFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability i…JLSEC-2025-126High 7.8UpstreamFFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the…JLSEC-2025-125High 7.5UpstreamFFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the `av_hwframe…JLSEC-2025-239High 7.8UpstreamLibarchive Remote Code Execution VulnerabilityJLSEC-2026-134Low 3.3UpstreamNo summary availableJLSEC-2026-249Medium 5.9UpstreamIssue summary: Some non-default TLS server configurations can cause unbounded memory grow…JLSEC-2026-4Medium 5.3Upstreamnghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in CJLSEC-2026-62Critical 10.0UpstreamNo summary availableJLSEC-2025-225High 8.2UpstreamAn issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.…JLSEC-2025-194Low 3.3Upstreamwall in util-linux through 2.40, often installed with setgid tty permissions, allows esca…JLSEC-2026-417Medium 6.5Upstreamlibcurl did not check the server certificate of TLS connections done to a host specified …JLSEC-2026-416High 8.6UpstreamWhen an application tells libcurl it wants to allow HTTP/2 server push, and the amount of…JLSEC-2026-415Medium 6.3Upstreamlibcurl skips the certificate verification for a QUIC connection under certain conditions…JLSEC-2026-414Low 3.5UpstreamWhen a protocol selection parameter option disables all protocols without adding any then…JLSEC-2026-185Medium 6.2UpstreamNo summary availableJLSEC-2026-680Critical 9.1UpstreamRemotely executed SEGV and out of bounds read allows malicious packet sender to crash or …JLSEC-2026-105Medium 6.5UpstreamDeno's `deno_runtime` vulnerable to interactive permission prompt spoofing via improper A…JLSEC-2026-104Medium 4.6UpstreamDeno's improper suffix match testing for `DENO_AUTH_TOKENS`JLSEC-2026-760Medium 5.3UpstreamNo summary availableJLSEC-2025-61High 7.5Upstreamlibexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use o…JLSEC-2026-103Medium 6.5UpstreamInsufficient permission checking in `Deno.makeTemp*` APIsJLSEC-2026-678Critical 9.1UpstreamIn wolfSSL prior to 5.6.6, if callback functions are enabled (via the `WOLFSSL_CALLBACKS`…JLSEC-2026-679Medium 5.3UpstreamwolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key b…JLSEC-2026-677Medium 5.9UpstreamwolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation …JLSEC-2026-46High 8.0UpstreamNo summary availableJLSEC-2025-186Critical 9.8Upstreamlibgit2 is a portable C implementation of the Git core methods provided as a linkable lib…JLSEC-2025-185High 7.5Upstreamlibgit2 is a portable C implementation of the Git core methods provided as a linkable lib…JLSEC-2025-59Medium 5.5Upstreamlibexpat through 2.5.0 allows recursive XML Entity Expansion if `XML_DTD` is undefined at…JLSEC-2025-60High 7.5Upstreamlibexpat through 2.5.0 allows a denial of service (resource consumption) because many ful…JLSEC-2025-83High 7.5UpstreamAn issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5JLSEC-2026-412Medium 5.3Upstreamcurl inadvertently kept the SSL session ID for connections in its cache even when the ver…JLSEC-2026-133Critical 9.1UpstreamNo summary availableJLSEC-2025-224High 7.5UpstreamInteger Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows…JLSEC-2025-223Medium 5.5UpstreamAn issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2JLSEC-2026-247Medium 5.5UpstreamNull pointer dereference in PKCS12 parsingJLSEC-2025-315High 7.5UpstreamAn out-of-memory flaw was found in libtiff that could be triggered by passing a crafted t…JLSEC-2026-599Medium 5.5UpstreamNo summary availableJLSEC-2026-526High 7.5UpstreamNo summary availableJLSEC-2026-525High 7.5UpstreamNo summary availableJLSEC-2026-179High 7.5UpstreamNo summary availableJLSEC-2026-245Medium 6.5UpstreamIssue summary: The POLY1305 MAC (message authentication code) implementation contains a b…JLSEC-2026-70Medium 6.5UpstreamNo summary availableJLSEC-2026-69Medium 5.5UpstreamNo summary availableJLSEC-2025-95Medium 5.9UpstreamNo summary availableJLSEC-2026-45Medium 4.4UpstreamNo summary availableJLSEC-2026-44High 8.8UpstreamNo summary availableJLSEC-2026-43Medium 4.3UpstreamNo summary availableJLSEC-2026-411Medium 6.5UpstreamThis flaw allows a malicious HTTP server to set "super cookies" in curl that are then pas…JLSEC-2026-524Medium 5.9UpstreamNo summary availableJLSEC-2026-244Medium 5.3UpstreamIssue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.…JLSEC-2025-314Medium 5.5UpstreamA heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at...JLSEC-2026-243High 7.5UpstreamIssue summary: A bug has been identified in the processing of key and initialisation vect…JLSEC-2025-35Low 3.7UpstreamThis flaw allows an attacker to insert cookies at will into a running program using libcu…JLSEC-2025-34Critical 9.8UpstreamThis flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.JLSEC-2026-479Critical 9.8UpstreamNo summary availableJLSEC-2026-287Medium 5.5UpstreamNo summary availableJLSEC-2026-3High 7.5UpstreamThe HTTP/2 protocol allows a denial of service (server resource consumption) because requ…JLSEC-2026-286Medium 5.5UpstreamNo summary availableJLSEC-2026-475High 7.8UpstreamNo summary availableJLSEC-2026-474Medium 5.5UpstreamNo summary availableJLSEC-2026-473Medium 5.5UpstreamNo summary availableJLSEC-2025-222High 7.5UpstreamMbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.JLSEC-2025-82Medium 6.5WithdrawnUpstreamlibxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory al…JLSEC-2025-313Medium 6.5UpstreamA vulnerability was found in libtiff due to multiple potential integer overflows in raw2t…JLSEC-2025-312Medium 6.5UpstreamLibTIFF is vulnerable to an integer overflowJLSEC-2025-310Medium 5.5UpstreamA memory leak flaw was found in Libtiff's tiffcrop utilityJLSEC-2026-374High 7.5UpstreamNo summary availableJLSEC-2026-375High 8.8UpstreamNo summary availableJLSEC-2025-164Medium 5.5UpstreamA flaw was found in GLibJLSEC-2025-163High 7.8UpstreamA flaw was found in GLibJLSEC-2025-162High 7.5UpstreamA flaw was found in glib, where the gvariant deserialization code is vulnerable to a deni…JLSEC-2025-161Medium 5.5UpstreamA flaw was found in GLibJLSEC-2025-160High 7.5UpstreamA flaw was found in GLibJLSEC-2026-441High 8.8UpstreamNo summary availableJLSEC-2026-242High 7.8UpstreamIssue summary: The POLY1305 MAC (message authentication code) implementation contains a b…JLSEC-2025-81Medium 6.5UpstreamXmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the...JLSEC-2026-178High 7.5UpstreamNo summary availableJLSEC-2025-176Medium 4.7UpstreamAn issue was discovered in open-mpi hwloc 2.1.0 allows attackers to cause a denial of ser…JLSEC-2026-664High 7.5UpstreamStack overflow vulnerability in `ast_selectors.cpp` in function...JLSEC-2025-311Medium 6.5UpstreamAn issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attacke…JLSEC-2026-202Medium 5.5UpstreamNo summary availableJLSEC-2026-21High 7.8UpstreamBuffer Overflow vulnerability in function `bitwriter_grow_` in flac before 1.4.0 allows r…JLSEC-2025-189High 7.5UpstreamAn issue was discovered in function `_libssh2_packet_add` in libssh2 1.10.0 allows attack…JLSEC-2026-201Medium 5.5UpstreamNo summary availableJLSEC-2026-200Medium 5.5UpstreamNo summary availableJLSEC-2026-450Medium 6.5UpstreamNo summary availableJLSEC-2026-449Medium 6.5UpstreamNo summary availableJLSEC-2026-448Medium 6.5UpstreamNo summary availableJLSEC-2026-447Medium 6.5UpstreamNo summary availableJLSEC-2026-446Medium 6.5UpstreamNo summary availableJLSEC-2026-445Medium 6.5UpstreamNo summary availableJLSEC-2025-309Medium 5.5UpstreamThere exists one heap buffer overflow in `_TIFFmemcpy` in `tif_unix.c` in libtiff 4.0.10,…JLSEC-2025-124High 7.5UpstreamAn issue was discovered in `decode_frame` in `libavcodec/tiff.c` in FFmpeg version 4.3, a…JLSEC-2026-42High 8.8UpstreamNo summary availableJLSEC-2026-92Medium 6.5UpstreamNo summary availableJLSEC-2026-241Medium 5.3UpstreamIssue summary: Checking excessively long DH keys or parameters may be very slow.JLSEC-2026-82Medium 5.5UpstreamNo summary availableJLSEC-2026-500Medium 6.3UpstreamNo summary availableJLSEC-2026-512Medium 5.5UpstreamNo summary availableJLSEC-2026-68Critical 9.8UpstreamNo summary availableJLSEC-2026-59High 7.5UpstreamNo summary availableJLSEC-2026-676High 8.8UpstreamIf a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share ex…JLSEC-2026-759High 7.5UpstreamNo summary availableJLSEC-2026-240Medium 5.3UpstreamIssue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore …JLSEC-2026-2High 7.5UpstreamEnvoy is a cloud-native high-performance edge/middle/service proxyJLSEC-2025-308Medium 6.5UpstreamA flaw was found in libtiffJLSEC-2026-499Medium 5.0UpstreamNo summary availableJLSEC-2025-307Medium 5.5UpstreamA null pointer dereference issue was found in Libtiff's `tif_dir.c` fileJLSEC-2026-472High 7.5UpstreamNo summary availableJLSEC-2026-440High 7.5UpstreamNo summary availableJLSEC-2025-305Medium 6.5UpstreamA NULL pointer dereference in TIFFClose() is caused by a failure to open an output file...JLSEC-2025-306Medium 5.5UpstreamloadImage() in `tools/tiffcrop.c` in LibTIFF through 4.5.0 has a heap-based use after fre…JLSEC-2026-41Medium 5.4UpstreamNo summary availableJLSEC-2026-40High 7.2UpstreamNo summary availableJLSEC-2025-22Medium 6.5UpstreamD-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemonJLSEC-2026-19Medium 6.5UpstreamThere's a memory leak in yajl 2.1.0 with use of `yajl_tree_parse` functionJLSEC-2026-239Medium 6.5UpstreamIssue summary: Processing some specially crafted ASN.1 object identifiers or data contain…JLSEC-2025-238Medium 5.3UpstreamLibarchive through 3.6.2 can cause directories to have world-writable permissionsJLSEC-2026-410Low 3.7UpstreamNo summary availableJLSEC-2026-409Medium 5.9UpstreamNo summary availableJLSEC-2026-408Medium 5.9UpstreamNo summary availableJLSEC-2026-407High 7.5UpstreamNo summary availableJLSEC-2025-304Medium 5.5UpstreamA vulnerability was found in the libtiff libraryJLSEC-2025-302Medium 5.5UpstreamA vulnerability was found in the libtiff libraryJLSEC-2025-303Medium 5.5UpstreamA NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the...JLSEC-2026-568High 7.5UpstreamNo summary availableJLSEC-2026-567High 7.5UpstreamNo summary availableJLSEC-2025-80Medium 6.5UpstreamAn issue was discovered in libxml2 before 2.10.4JLSEC-2025-79Medium 6.5UpstreamIn libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL point…JLSEC-2026-238Medium 5.9UpstreamIssue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform conta…JLSEC-2026-529Medium 6.1UpstreamNo summary availableJLSEC-2026-453High 7.8UpstreamNo summary availableJLSEC-2025-301Medium 6.1UpstreamA flaw was found in tiffcrop, a program distributed by the libtiff packageJLSEC-2026-559High 7.5UpstreamNo summary availableJLSEC-2025-33Medium 5.5UpstreamAn authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses …JLSEC-2025-32Medium 5.9UpstreamA double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separ…JLSEC-2025-30Medium 5.9UpstreamAn authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feat…JLSEC-2025-31Medium 5.9UpstreamAn authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reu…JLSEC-2026-406High 8.8UpstreamNo summary availableJLSEC-2026-405High 8.8UpstreamNo summary availableJLSEC-2026-203High 7.8UpstreamNo summary availableJLSEC-2025-123High 8.1Upstream`libavcodec/pthread_frame.c` in FFmpeg before 5.1.2, as used in VLC and other products, l…JLSEC-2026-237Medium 5.3UpstreamThe function `X509_VERIFY_PARAM_add0_policy()` is documented to implicitly enable the cer…JLSEC-2026-236Medium 5.3UpstreamApplications that use a non-default option when verifying certificates may be vulnerable …JLSEC-2026-102High 8.8UpstreamInteractive `run` permission prompt spoofing via improper ANSI neutralizationJLSEC-2026-235High 7.5UpstreamA security vulnerability has been identified in all supported versionsJLSEC-2026-67Critical 9.8UpstreamNo summary availableJLSEC-2025-300Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in tiffcp in `tools/tiffcp.c:948`, allowing attac…JLSEC-2026-39Low 3.7UpstreamNo summary availableJLSEC-2026-101High 7.5UpstreamNo summary availableJLSEC-2026-404Medium 6.5UpstreamNo summary availableJLSEC-2026-403Medium 6.5UpstreamNo summary availableJLSEC-2026-402Critical 9.1UpstreamNo summary availableJLSEC-2026-20High 7.5UpstreamNo summary availableJLSEC-2025-181High 7.3WithdrawnUpstreamUncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 202…JLSEC-2025-298Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in `tools/tiffcrop.c:3609`, allowing…JLSEC-2025-299Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in `tools/tiffcrop.c:3516`, allowing…JLSEC-2025-297Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in `tools/tiffcrop.c:3724`, allowing…JLSEC-2025-296Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in `libtiff/tif_unix.c:368`, invoked…JLSEC-2025-295Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in `tools/tiffcrop.c:3502`, allowing…JLSEC-2025-294Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in `tools/tiffcrop.c:3701`, allowing …JLSEC-2025-293Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in `tools/tiffcrop.c:3400`, allowing …JLSEC-2025-292Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in `libtiff/tif_unix.c:368`, invoked …JLSEC-2025-291Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in `tools/tiffcrop.c:3592`, allowing …JLSEC-2025-290Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in `tools/tiffcrop.c:3488`, allowing …JLSEC-2026-401Medium 5.9UpstreamNo summary availableJLSEC-2026-234High 7.4UpstreamVulnerable OpenSSL included in cryptography wheelsJLSEC-2026-233High 7.5Upstreamopenssl-src vulnerable to Use-after-free following `BIO_new_NDEF`JLSEC-2026-232High 7.5Upstreamopenssl-src contains Double free after calling `PEM_read_bio_ex`JLSEC-2026-231Medium 5.9Upstreamopenssl-src subject to Timing Oracle in RSA DecryptionJLSEC-2026-285High 8.8UpstreamNo summary availableJLSEC-2026-284High 7.5UpstreamNo summary availableJLSEC-2026-283High 7.5UpstreamNo summary availableJLSEC-2025-175High 7.5Upstreamhb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) gro…JLSEC-2026-66Medium 6.5UpstreamNo summary availableJLSEC-2026-184Medium 5.5UpstreamNo summary availableJLSEC-2025-289Medium 5.5UpstreamprocessCropSelections in `tools/tiffcrop.c` in LibTIFF through 4.5.0 has a heap-based buf…JLSEC-2025-184Medium 5.9Upstreamlibgit2 is a cross-platform, linkable library implementation of GitJLSEC-2026-100High 7.5UpstreamDeno is vulnerable to race condition via interactive permission prompt spoofingJLSEC-2025-221Medium 4.7UpstreamUse of a Broken or Risky Cryptographic Algorithm in the function `mbedtls_mpi_exp_mod()` …JLSEC-2026-365High 7.5UpstreamNo summary availableJLSEC-2025-93Critical 9.8UpstreamA vulnerability was found in the Libksba library due to an integer overflow within the CR…JLSEC-2025-122Medium 5.3UpstreamA null pointer dereference issue was discovered in 'FFmpeg' in `decode_main_header()` fun…JLSEC-2026-204Medium 6.1UpstreamNo summary availableJLSEC-2026-91High 8.8UpstreamNo summary availableJLSEC-2026-400High 7.5UpstreamNo summary availableJLSEC-2026-57Critical 9.8UpstreamNo summary availableJLSEC-2025-121High 7.5UpstreamAn issue was discovered in the FFmpeg package, where `vp3_decode_frame` in `libavcodec/vp…JLSEC-2025-220Critical 9.8UpstreamAn issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0JLSEC-2025-219Medium 5.3UpstreamAn issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0JLSEC-2026-396Critical 9.8UpstreamNo summary availableJLSEC-2025-78High 7.8UpstreamAn issue was discovered in libxml2 before 2.10.3JLSEC-2025-77High 7.5UpstreamAn issue was discovered in libxml2 before 2.10.3JLSEC-2025-237Critical 9.8UpstreamIn libarchive before 3.6.2, the software does not check for an error after calling calloc…JLSEC-2025-288High 8.8UpstreamA vulnerability was found in LibTIFFJLSEC-2025-120High 8.1UpstreamA vulnerability classified as problematic has been found in ffmpegJLSEC-2026-674Critical 9.1UpstreamNo summary availableJLSEC-2026-175High 8.8UpstreamNo summary availableJLSEC-2026-398High 8.1UpstreamNo summary availableJLSEC-2026-399High 7.5UpstreamNo summary availableJLSEC-2025-58High 7.5UpstreamIn libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a…JLSEC-2025-287Medium 6.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in `_TIFFmemcpy` in `libtiff/tif_unix.c:346` whe…JLSEC-2025-286Medium 6.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in `_TIFFmemset` in `libtiff/tif_unix.c:340` whe…JLSEC-2025-285Medium 6.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in `tools/tiffcrop.c:7345`,…JLSEC-2025-284Medium 6.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in...JLSEC-2025-283Medium 6.5UpstreamLibTIFF 4.4.0 has an out-of-bounds write in `_TIFFmemcpy` in `libtiff/tif_unix.c:346` whe…JLSEC-2025-282Medium 5.5UpstreamMultiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 all…JLSEC-2026-675Medium 5.3UpstreamNo summary availableJLSEC-2025-21Medium 6.5UpstreamAn issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.1…JLSEC-2025-20Medium 6.5UpstreamAn issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.1…JLSEC-2025-19Medium 6.5UpstreamAn issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.1…JLSEC-2026-673High 7.5UpstreamNo summary availableJLSEC-2026-97Medium 6.6UpstreamNo summary availableJLSEC-2026-397Low 3.7UpstreamNo summary availableJLSEC-2025-57High 8.1Upstreamlibexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.JLSEC-2026-210Medium 6.5UpstreamNo summary availableJLSEC-2026-289High 7.8UpstreamNo summary availableJLSEC-2026-186Medium 6.5UpstreamNo summary availableJLSEC-2025-172Medium 5.5UpstreamA segmentation fault (SEGV) flaw was found in the Fribidi package and affects the...JLSEC-2025-171Medium 5.5UpstreamA heap-based buffer overflow flaw was found in the Fribidi package and affects the...JLSEC-2025-170High 7.8UpstreamA stack-based buffer overflow flaw was found in the Fribidi packageJLSEC-2026-668Medium 5.9UpstreamNo summary availableJLSEC-2026-672High 7.5UpstreamNo summary availableJLSEC-2026-37High 8.8UpstreamNo summary availableJLSEC-2025-281Medium 6.1UpstreamA stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() functionJLSEC-2025-280Medium 5.5UpstreamA heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped()…JLSEC-2026-61High 8.8UpstreamNo summary availableJLSEC-2026-81High 7.8UpstreamNo summary availableJLSEC-2025-279Medium 5.5UpstreamLibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in `tools/tiffcrop.c:6905`…JLSEC-2026-36Medium 5.9UpstreamNo summary availableJLSEC-2026-522Medium 6.5UpstreamNo summary availableJLSEC-2025-193Medium 5.5UpstreamA logic error was found in the libmount library of util-linux in the function that allows…JLSEC-2025-192Medium 5.5UpstreamA logic error was found in the libmount library of util-linux in the function that allows…JLSEC-2025-159Medium 5.5UpstreamA flaw was found in glib before version 2.63.6JLSEC-2025-236High 7.8UpstreamAn improper link resolution flaw can occur while extracting an archive leading to changin…JLSEC-2025-235High 7.8UpstreamAn improper link resolution flaw while extracting an archive can lead to changing the acc…JLSEC-2026-80High 7.8UpstreamNo summary availableJLSEC-2026-38High 8.0UpstreamNo summary availableJLSEC-2025-278Medium 5.5Upstreamlibtiff's tiffcrop tool has a `uint32_t` underflow which leads to out of bounds read and …JLSEC-2025-277Medium 5.5Upstreamlibtiff's tiffcrop utility has a improper input validation flaw that can lead to out of b…JLSEC-2025-276Medium 5.5Upstreamlibtiff's tiffcrop utility has a `uint32_t` underflow that can lead to out of bounds read…JLSEC-2026-671High 7.5UpstreamNo summary availableJLSEC-2026-478Critical 9.8UpstreamNo summary availableJLSEC-2026-523High 7.5UpstreamNo summary availableJLSEC-2025-275Medium 6.5UpstreamA stack overflow was discovered in the `_TIFFVGetField` function of Tiffsplit v4.4.0JLSEC-2025-76Medium 6.1UpstreamPossible cross-site scripting vulnerability in libxml after commit 960f0e2.JLSEC-2026-598Medium 5.5UpstreamNo summary availableJLSEC-2026-597Medium 5.5UpstreamNo summary availableJLSEC-2026-596Medium 5.5UpstreamNo summary availableJLSEC-2026-595Medium 5.5UpstreamNo summary availableJLSEC-2026-594Medium 5.5UpstreamNo summary availableJLSEC-2026-593Medium 5.5UpstreamNo summary availableJLSEC-2026-592Medium 5.5UpstreamNo summary availableJLSEC-2026-591Medium 5.5UpstreamNo summary availableJLSEC-2026-590Medium 5.5UpstreamNo summary availableJLSEC-2026-589Medium 5.5UpstreamNo summary availableJLSEC-2026-588Medium 5.5UpstreamNo summary availableJLSEC-2026-587Medium 5.5UpstreamNo summary availableJLSEC-2026-586Medium 5.5UpstreamNo summary availableJLSEC-2026-585Medium 5.5UpstreamNo summary availableJLSEC-2026-584Medium 5.5UpstreamNo summary availableJLSEC-2025-218Critical 9.1UpstreamAn issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0JLSEC-2026-395Medium 5.9UpstreamNo summary availableJLSEC-2026-394Critical 9.8UpstreamNo summary availableJLSEC-2026-393Medium 6.5UpstreamNo summary availableJLSEC-2026-392Medium 4.3UpstreamNo summary availableJLSEC-2026-230Medium 5.3UpstreamAES OCB fails to encrypt some bytesJLSEC-2025-92Medium 6.5UpstreamGnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key inf…JLSEC-2026-561High 7.5UpstreamNo summary availableJLSEC-2025-274Medium 6.5UpstreamDivide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-s…JLSEC-2025-273Medium 6.5UpstreamDivide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-s…JLSEC-2025-272Medium 6.5UpstreamDivide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-s…JLSEC-2026-229High 7.3UpstreamIn addition to the `c_rehash` shell command injection identified in CVE-2022-1292, furthe…JLSEC-2025-180Medium 5.5UpstreamThe PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading …JLSEC-2026-99High 8.4UpstreamNo summary availableJLSEC-2026-391High 7.5UpstreamNo summary availableJLSEC-2026-390High 7.5UpstreamNo summary availableJLSEC-2026-389High 7.5UpstreamNo summary availableJLSEC-2026-388Medium 6.5UpstreamNo summary availableJLSEC-2026-387High 7.5UpstreamNo summary availableJLSEC-2026-386Medium 5.7UpstreamNo summary availableJLSEC-2026-385High 8.1UpstreamNo summary availableJLSEC-2025-271Medium 5.5UpstreamLibTIFF master branch has an out-of-bounds read in LZWDecode in `libtiff/tif_lzw.c:624`, …JLSEC-2025-270Medium 5.5UpstreamLibTIFF master branch has an out-of-bounds read in LZWDecode in `libtiff/tif_lzw.c:619`, …JLSEC-2026-174Critical 9.8UpstreamNo summary availableJLSEC-2026-127High 7.8UpstreamNo summary availableJLSEC-2026-228High 7.3UpstreamThe `c_rehash` script does not properly sanitise shell metacharacters to prevent command …JLSEC-2025-75Medium 6.5UpstreamIn libxml2 before 2.9.14, several buffer handling functions in buf.c (`xmlBuf*`) and tree…JLSEC-2025-119Medium 5.5UpstreamAn integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.…JLSEC-2026-459High 7.5UpstreamNo summary availableJLSEC-2026-458High 7.5UpstreamNo summary availableJLSEC-2026-457Critical 9.8UpstreamNo summary availableJLSEC-2026-452High 7.1UpstreamNo summary availableJLSEC-2026-560Critical 9.1UpstreamNo summary availableJLSEC-2025-268Medium 6.5UpstreamA vulnerability classified as problematic was found in LibTIFF 4.3.0JLSEC-2026-364High 8.8UpstreamNo summary availableJLSEC-2026-547Medium 5.5UpstreamNo summary availableJLSEC-2025-269Medium 5.5UpstreamOut-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-…JLSEC-2026-131Medium 6.5UpstreamNo summary availableJLSEC-2026-130Medium 5.5UpstreamNo summary availableJLSEC-2026-477High 7.5UpstreamNo summary availableJLSEC-2025-217High 7.5UpstreamA Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the...JLSEC-2026-227High 7.5Upstreamopenssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificatesJLSEC-2026-558Medium 6.3UpstreamNo summary availableJLSEC-2025-267Medium 5.5UpstreamOut-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of…JLSEC-2025-266Medium 5.5UpstreamDivide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-s…JLSEC-2025-265Medium 5.5UpstreamNull source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag …JLSEC-2025-264Medium 5.5UpstreamUnchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows at…JLSEC-2025-263High 7.1UpstreamA heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library V…JLSEC-2025-262Medium 6.5UpstreamReachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-serv…JLSEC-2026-546High 7.8UpstreamNo summary availableJLSEC-2026-29High 8.1UpstreamNo summary availableJLSEC-2026-35Medium 6.5UpstreamNo summary availableJLSEC-2026-30Medium 5.9UpstreamNo summary availableJLSEC-2025-74High 7.5Upstreamvalid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.JLSEC-2026-670High 7.5UpstreamNo summary availableJLSEC-2026-669Medium 6.5UpstreamNo summary availableJLSEC-2025-191Medium 5.5UpstreamA flaw was found in the util-linux chfn and chsh utilities when compiled with Readline su…JLSEC-2025-56Critical 9.8UpstreamIn Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.JLSEC-2025-55High 7.5UpstreamIn Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.JLSEC-2025-54Medium 6.5UpstreamIn Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in `build_…JLSEC-2025-53Critical 9.8Upstreamxmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-sepa…JLSEC-2025-52Critical 9.8Upstream`xmltok_impl.c` in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding…JLSEC-2025-261Medium 5.5UpstreamNull source pointer passed as an argument to memcpy() function within TIFFReadDirectory()…JLSEC-2025-260Medium 5.5UpstreamNull source pointer passed as an argument to memcpy() function within TIFFFetchStripThing…JLSEC-2026-226Medium 5.9UpstreamThere is a carry propagation bug in the MIPS32 and MIPS64 squaring procedureJLSEC-2025-51High 7.5UpstreamExpat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.JLSEC-2025-50Critical 9.8UpstreamExpat (aka libexpat) before 2.4.4 has a signed integer overflow in `XML_GetBuffer`, for...JLSEC-2026-557Medium 5.5UpstreamNo summary availableJLSEC-2025-259Medium 5.5UpstreamLibTIFF 4.3.0 has an out-of-bounds read in `_TIFFmemcpy` in `tif_unix.c` in certain situa…JLSEC-2025-49High 8.8UpstreamstoreAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-48High 8.8UpstreamnextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overfl…JLSEC-2025-47High 8.8Upstreamlookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-46Critical 9.8UpstreamdefineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflo…JLSEC-2025-45Critical 9.8Upstream`build_model` in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-44Critical 9.8UpstreamaddBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-43High 7.8UpstreamIn doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exist…JLSEC-2025-42High 8.8UpstreamIn Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtt…JLSEC-2026-132Medium 5.5UpstreamNo summary availableJLSEC-2025-216High 7.5UpstreamIn Mbed TLS before 3.1.0, `psa_aead_generate_nonce` allows policy bypass or oracle-based …JLSEC-2025-215High 7.5UpstreamIn Mbed TLS before 2.28.0 and 3.x before 3.1.0, `psa_cipher_generate_iv` and `psa_cipher_…JLSEC-2025-214Critical 9.8UpstreamMbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstra…JLSEC-2025-6Critical 9.1UpstreamAn out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions …JLSEC-2026-556Medium 5.5UpstreamNo summary availableJLSEC-2026-32Medium 6.5UpstreamNo summary availableJLSEC-2026-33Medium 6.5UpstreamNo summary availableJLSEC-2026-65High 7.0UpstreamNo summary availableJLSEC-2025-29Critical 9.1UpstreamWhen sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumsta…JLSEC-2026-451High 8.8UpstreamNo summary availableJLSEC-2026-483Medium 6.5UpstreamNo summary availableJLSEC-2026-482Medium 6.5UpstreamNo summary availableJLSEC-2026-361Medium 6.5UpstreamNo summary availableJLSEC-2026-481High 7.5UpstreamNo summary availableJLSEC-2026-124Medium 5.9UpstreamNo summary availableJLSEC-2026-129Medium 5.5UpstreamNo summary availableJLSEC-2026-199Low 3.3UpstreamNo summary availableJLSEC-2025-195High 7.8UpstreamAn integer overflow was addressed with improved input validationJLSEC-2026-225High 7.4UpstreamRead buffer overruns processing ASN.1 stringsJLSEC-2026-224Critical 9.8UpstreamSM2 Decryption Buffer OverflowJLSEC-2025-213High 7.5UpstreamAn issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.1…JLSEC-2025-212Medium 5.9UpstreamAn issue was discovered in Mbed TLS before 2.24.0JLSEC-2025-211High 7.5UpstreamAn issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.1…JLSEC-2025-210High 7.5UpstreamAn issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.1…JLSEC-2025-118Critical 9.8Upstream`adts_decode_extradata` in `libavformat/adtsenc.c` in FFmpeg 4.4 does not check the `init…JLSEC-2025-117High 7.5UpstreamFFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an as…JLSEC-2026-576High 7.5UpstreamNo summary availableJLSEC-2025-116Medium 5.5UpstreamPrior to ffmpeg version 4.3, the tty demuxer did not have a '`read_probe`' function assig…JLSEC-2025-28Low 3.7Upstreamlibcurl keeps previously used connections in a connection pool for subsequenttransfers to…JLSEC-2026-360Medium 6.5UpstreamNo summary availableJLSEC-2025-115Medium 5.5Upstream`libavcodec/dnxhddec.c` in FFmpeg 4.4 does not check the return value of the `init_vlc` f…JLSEC-2026-581High 8.8UpstreamNo summary availableJLSEC-2025-190Medium 5.5WithdrawnUpstreamAn integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow …JLSEC-2025-234Medium 6.5Upstreamlibarchive 3.4.1 through 3.5.1 has a use-after-free in `copy_string` (called from...JLSEC-2026-282High 7.8UpstreamNo summary availableJLSEC-2025-209High 7.5UpstreamAn issue was discovered in Arm Mbed TLS before 2.24.0JLSEC-2025-208Medium 5.3UpstreamAn issue was discovered in Arm Mbed TLS before 2.24.0JLSEC-2025-207Medium 4.7UpstreamAn issue was discovered in Arm Mbed TLS before 2.24.0JLSEC-2025-206High 7.5UpstreamAn issue was discovered in Arm Mbed TLS before 2.23.0JLSEC-2025-205Medium 5.3UpstreamAn issue was discovered in Arm Mbed TLS before 2.23.0JLSEC-2025-204Medium 5.3UpstreamAn issue was discovered in Arm Mbed TLS before 2.23.0JLSEC-2025-203Medium 4.9UpstreamIn Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file deco…JLSEC-2025-73Medium 6.5UpstreamA flaw was found in libxml2JLSEC-2026-128Medium 5.5UpstreamNo summary availableJLSEC-2026-123High 7.5UpstreamNo summary availableJLSEC-2025-114High 8.8Upstream`dwa_uncompress` in `libavcodec/exr.c` in FFmpeg 4.4 allows an out-of-bounds array access…JLSEC-2026-532Critical 9.8UpstreamNo summary availableJLSEC-2025-179High 8.8UpstreamLibjpeg-turbo all version have a stack-based buffer overflow in the "transform" componentJLSEC-2026-31High 8.8UpstreamNo summary availableJLSEC-2026-98Critical 9.8UpstreamDeno's static imports inside dynamically imported modules do not adhere to permission che…JLSEC-2026-517High 7.5UpstreamNo summary availableJLSEC-2026-516Critical 9.8UpstreamNo summary availableJLSEC-2026-162High 7.5UpstreamNo summary availableJLSEC-2026-471Critical 9.8UpstreamNo summary availableJLSEC-2025-113High 7.5UpstreamBuffer Overflow vulnerability exists in FFmpeg 4.1 via `apng_do_inverse_blend` in...JLSEC-2025-72High 8.6UpstreamThere is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.…JLSEC-2026-476High 7.8UpstreamNo summary availableJLSEC-2025-71High 8.8UpstreamThere's a flaw in libxml2 in versions before 2.9.11JLSEC-2026-161High 7.5UpstreamNo summary availableJLSEC-2025-70Medium 5.9UpstreamA vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagat…JLSEC-2026-536High 7.8UpstreamNo summary availableJLSEC-2026-537Medium 5.5UpstreamNo summary availableJLSEC-2026-118Medium 6.1UpstreamNo summary availableJLSEC-2026-545Medium 5.5UpstreamNo summary availableJLSEC-2025-112High 8.8UpstreamFFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted fil…JLSEC-2026-575High 8.1UpstreamNo summary availableJLSEC-2025-27Low 3.7Upstreamcurl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS …JLSEC-2025-26Medium 5.3Upstreamcurl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Info…JLSEC-2026-34Medium 4.3UpstreamNo summary availableJLSEC-2026-515High 8.1UpstreamNo summary availableJLSEC-2026-514Medium 6.5UpstreamNo summary availableJLSEC-2026-183Low 3.3UpstreamNo summary availableJLSEC-2026-223Medium 5.9Upstreamopenssl-src NULL pointer Dereference in `signature_algorithms` processingJLSEC-2026-154High 8.8UpstreamNo summary availableJLSEC-2025-17High 7.8UpstreamA flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4JLSEC-2026-521Critical 9.8UpstreamNo summary availableJLSEC-2026-520Critical 9.8UpstreamNo summary availableJLSEC-2026-209High 7.5UpstreamNo summary availableJLSEC-2026-208High 7.5UpstreamNo summary availableJLSEC-2026-207High 7.5UpstreamNo summary availableJLSEC-2026-206High 7.5UpstreamNo summary availableJLSEC-2025-158Medium 5.3UpstreamAn issue was discovered in GNOME GLib before 2.66.8JLSEC-2026-205High 7.5UpstreamNo summary availableJLSEC-2025-258High 7.8UpstreamA heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in …JLSEC-2025-257High 7.8UpstreamAn integer overflow flaw was found in libtiff that exists in the `tif_getimage.c` fileJLSEC-2025-256Medium 5.5UpstreamIn LibTIFF, there is a memory malloc failure in `tif_pixarlog.c`JLSEC-2025-255Medium 5.5UpstreamA flaw was found in libtiffJLSEC-2026-64High 7.1UpstreamNo summary availableJLSEC-2026-121Medium 4.7UpstreamBeginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the…JLSEC-2026-222Medium 5.9UpstreamInteger Overflow in openssl-srcJLSEC-2026-221High 7.5UpstreamInteger Overflow in openssl-srcJLSEC-2025-157High 7.5UpstreamAn issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3JLSEC-2025-156High 7.5UpstreamAn issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4JLSEC-2026-173High 7.5UpstreamNo summary availableJLSEC-2026-172High 7.5UpstreamNo summary availableJLSEC-2026-171High 7.5UpstreamNo summary availableJLSEC-2026-170High 7.5UpstreamNo summary availableJLSEC-2026-169High 7.5UpstreamNo summary availableJLSEC-2026-168High 7.5UpstreamNo summary availableJLSEC-2026-167High 7.5UpstreamNo summary availableJLSEC-2026-166High 7.5UpstreamNo summary availableJLSEC-2026-165High 7.5UpstreamNo summary availableJLSEC-2026-164High 7.5UpstreamNo summary availableJLSEC-2026-163High 7.5UpstreamNo summary availableJLSEC-2026-535High 7.8UpstreamNo summary availableJLSEC-2026-363Medium 5.4UpstreamNo summary availableJLSEC-2026-362High 7.8UpstreamNo summary availableJLSEC-2026-542Medium 5.5UpstreamNo summary availableJLSEC-2026-541High 7.8UpstreamNo summary availableJLSEC-2026-540Medium 5.5UpstreamNo summary availableJLSEC-2026-539Medium 5.5UpstreamNo summary availableJLSEC-2026-538Medium 5.5UpstreamNo summary availableJLSEC-2025-111High 7.5Upstream`decode_frame` in `libavcodec/exr.c` in FFmpeg 4.3.1 has an out-of-bounds write because o…JLSEC-2025-110Medium 6.5Upstream`track_header` in `libavformat/vividas.c` in FFmpeg 4.3.1 has an out-of-bounds write beca…JLSEC-2025-155High 7.8UpstreamGNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds wri…JLSEC-2025-25High 7.5Upstreamcurl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation …JLSEC-2025-24High 7.5Upstreamcurl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stac…JLSEC-2025-23High 7.5UpstreamDue to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connect…JLSEC-2026-220Medium 5.9UpstreamThe X.509 GeneralName type is a generic type for representing different types of namesJLSEC-2026-160High 7.5UpstreamNo summary availableJLSEC-2026-28High 7.5UpstreamNo summary availableJLSEC-2026-278High 7.5UpstreamNo summary availableJLSEC-2026-27High 8.8UpstreamNo summary availableJLSEC-2026-26High 8.1UpstreamNo summary availableJLSEC-2026-528High 7.8UpstreamNo summary availableJLSEC-2026-456Critical 9.6UpstreamNo summary availableJLSEC-2026-155High 8.8UpstreamNo summary availableJLSEC-2026-470High 7.8UpstreamAn integer overflow vulnerability leading to a double-free was found in libX11JLSEC-2026-513High 7.5UpstreamNo summary availableJLSEC-2026-519High 7.5UpstreamNo summary availableJLSEC-2025-69Medium 6.5UpstreamGNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in...JLSEC-2025-202Medium 5.5UpstreamA Lucky 13 timing side channel in `mbedtls_ssl_decrypt_buf` in `library/ssl_msg.c` in Tru…JLSEC-2026-25High 7.3UpstreamNo summary availableJLSEC-2026-24High 7.1UpstreamNo summary availableJLSEC-2026-555Medium 5.3UpstreamNo summary availableJLSEC-2026-469Medium 6.7UpstreamAn integer overflow leading to a heap-buffer overflow was found in The X Input Method (XI…JLSEC-2026-554Medium 5.5UpstreamNo summary availableJLSEC-2026-534Medium 6.5UpstreamNo summary availableJLSEC-2026-63Medium 5.9UpstreamNo summary availableJLSEC-2025-109High 8.8UpstreamFFmpeg through 4.3 has a heap-based buffer overflow in `avio_get_str` in `libavformat/avi…JLSEC-2026-177Medium 5.3UpstreamNo summary availableJLSEC-2026-117Medium 5.5UpstreamNo summary availableJLSEC-2026-176High 7.5UpstreamNo summary availableJLSEC-2025-18Medium 5.5UpstreamAn issue was discovered in dbus >= 1.3.0 before 1.12.18JLSEC-2026-518High 7.4UpstreamNo summary availableJLSEC-2026-1High 7.5UpstreamIn nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes d…JLSEC-2026-211High 8.8UpstreamNo summary availableJLSEC-2025-108Critical 9.8Upstream`cbs_jpeg_split_fragment` in `libavcodec/cbs_jpeg.c` in FFmpeg 4.1 and 4.2.2 has a heap-b…JLSEC-2025-183Critical 9.8UpstreamAn issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0JLSEC-2025-182Critical 9.8UpstreamAn issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0JLSEC-2026-219High 7.5UpstreamNull pointer deference in openssl-srcJLSEC-2025-201Medium 4.7UpstreamAn issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15JLSEC-2026-18Medium 5.5UpstreamNo summary availableJLSEC-2025-200Medium 5.9UpstreamArm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA priva…JLSEC-2026-58High 8.8UpstreamNo summary availableJLSEC-2026-511Medium 6.5UpstreamNo summary availableJLSEC-2026-544High 8.8UpstreamNo summary availableJLSEC-2025-199Medium 4.7UpstreamThe ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through…JLSEC-2025-68High 7.5UpstreamxmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certai…JLSEC-2025-67High 7.5UpstreamxmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memor…JLSEC-2026-543High 7.5UpstreamNo summary availableJLSEC-2025-66High 7.5UpstreamxmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak…JLSEC-2026-216Medium 5.3UpstreamThere is an overflow bug in the `x64_64` Montgomery squaring procedure used in exponentia…JLSEC-2025-169High 7.8UpstreamA buffer overflow in the `fribidi_get_par_embedding_levels_ex()` function in `lib/fribidi…JLSEC-2026-507Medium 6.5UpstreamNo summary availableJLSEC-2026-506Medium 6.5UpstreamNo summary availableJLSEC-2026-505Medium 6.5UpstreamNo summary availableJLSEC-2025-188High 8.1UpstreamIn libssh2 v1.9.0 and earlier versions, the `SSH_MSG_DISCONNECT` logic in packet.c has an…JLSEC-2026-580High 7.5UpstreamNo summary availableJLSEC-2026-444Medium 5.4UpstreamNo summary availableJLSEC-2026-443Medium 5.3UpstreamNo summary availableJLSEC-2025-254High 8.8Upstream`tif_getimage.c` in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other produ…JLSEC-2025-107Critical 9.8UpstreamFFmpeg before 4.2 has a heap-based buffer overflow in `vqa_decode_chunk` because of an ou…JLSEC-2025-106Critical 9.8UpstreamIn FFmpeg before 4.2, `avcodec_open2` in `libavcodec/utils.c` allows a NULL pointer deref…JLSEC-2025-198Medium 5.3UpstreamArm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is …JLSEC-2026-218Low 3.7UpstreamIn situations where an attacker receives automated notification of the success or failure…JLSEC-2026-215Medium 5.3UpstreamOpenSSL 1.1.1 introduced a rewritten random number generator (RNG)JLSEC-2026-214Medium 4.7UpstreamNormally in OpenSSL EC groups always have a co-factor present and this is used in side ch…JLSEC-2025-105High 8.8UpstreamFFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue …JLSEC-2025-41High 7.5UpstreamIn libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD …JLSEC-2026-13High 7.8UpstreamNo summary availableJLSEC-2025-253Medium 6.5Upstream`_TIFFCheckMalloc` and `_TIFFCheckRealloc` in `tif_aux.c` in LibTIFF through 4.0.10 misha…JLSEC-2026-217Low 3.3UpstreamOpenSSL has internal defaults for a directory tree where it can find a configuration file…JLSEC-2026-17High 7.8UpstreamNo summary availableJLSEC-2026-455Critical 9.8UpstreamGnome Pango 1.42 and later is affected by: Buffer OverflowJLSEC-2026-16Medium 5.9UpstreamNo summary availableJLSEC-2026-579Medium 5.3UpstreamNo summary availableJLSEC-2026-578Medium 5.3UpstreamNo summary availableJLSEC-2025-154High 7.5UpstreamThe keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directorie…JLSEC-2026-533Medium 5.5UpstreamNo summary availableJLSEC-2025-11Critical 9.8Upstream`BZ2_decompress` in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when t…JLSEC-2025-153Critical 9.8Upstream`file_copy_fallback` in `gio/gfile.c` in GNOME GLib 2.15.0 through 2.61.1 does not proper…JLSEC-2026-504Medium 6.5UpstreamNo summary availableJLSEC-2025-104High 8.8UpstreamThe studio profile decoder in `libavcodec/mpeg4videodec.c` in FFmpeg 4.0 before 4.0.4 and…JLSEC-2026-577Critical 9.8UpstreamNo summary availableJLSEC-2025-103Medium 6.5UpstreamA denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog…JLSEC-2025-102Medium 6.5UpstreamIn FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to ho…JLSEC-2025-252Medium 6.5UpstreamAn Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in…JLSEC-2025-101Medium 6.5UpstreamFFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability i…JLSEC-2026-553High 7.5UpstreamNo summary availableJLSEC-2025-16Medium 6.5UpstreamAn issue was discovered in cairo 1.16.0JLSEC-2025-15Medium 6.5UpstreamAn issue was discovered in cairo 1.16.0JLSEC-2026-510Medium 6.5UpstreamNo summary availableJLSEC-2026-509Medium 6.5UpstreamNo summary availableJLSEC-2026-508Medium 6.5UpstreamNo summary availableJLSEC-2025-251High 8.8UpstreamThe TIFFFdOpen function in `tif_unix.c` in LibTIFF 4.0.10 has a memory leak, as demonstra…JLSEC-2025-178High 8.8UpstreamThe tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant …JLSEC-2026-198Medium 5.5UpstreamNo summary availableJLSEC-2026-503Medium 6.5UpstreamNo summary availableJLSEC-2025-14Medium 6.5Upstreamcairo 1.16.0, in `cairo_ft_apply_variations()` in cairo-ft-font.c, would free memory usin…JLSEC-2026-502High 8.8UpstreamNo summary availableJLSEC-2026-501Medium 6.5UpstreamNo summary availableJLSEC-2025-177Medium 6.5Upstreamlibjpeg-turbo 2.0.1 has a heap-based buffer over-read in the `put_pixel_rows` function in…JLSEC-2026-442Medium 5.5UpstreamNo summary availableJLSEC-2025-174Critical 9.8UpstreamAn issue was discovered in GNU gettext 0.19.8JLSEC-2025-13Medium 6.5Upstreamcairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a craf…JLSEC-2026-490Medium 5.5UpstreamNo summary availableJLSEC-2026-12High 7.8UpstreamNo summary availableJLSEC-2026-15High 7.5UpstreamNo summary availableJLSEC-2026-14High 7.5UpstreamNo summary availableJLSEC-2026-22High 7.5UpstreamNo summary availableJLSEC-2025-12High 7.5Upstreamcairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a de…JLSEC-2026-23Medium 5.5UpstreamNo summary availableJLSEC-2025-10Medium 6.5UpstreamUse-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to ca…