Search CVE reports


Toggle filters

341 – 350 of 49652 results

Status is adjusted based on your filters.


CVE-2026-66075

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, is_authorized/2 for the /federation-links/.../restart route uses is_authorized_monitor (accepts the monitoring tag), while...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-66074

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, match_value/3 passes the user-supplied ?name= regular expression to re:run with no match_limit option, and executes it once...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-66072

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> property from post-auth subscribe...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-66070

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-66069

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-66068

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("shutting down Shovel '~ts', ... Shovel state: ~tp", [Name, State]) formats the entire state map. The 'uris'...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-66067

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only check_vhost_access; it omits the node/vhost/user connection-limit checks that rabbit_reader performs for AMQP. A...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-61814

Medium priority
Needs evaluation

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start....

1 affected package

jawn

Package 20.04 LTS
jawn Needs evaluation
Show less packages

CVE-2026-6103

Medium priority
Needs evaluation

[Unknown description]

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 20.04 LTS
php5 —
php7.0 —
php7.2 —
php7.4 Needs evaluation
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2026-59990

Medium priority
Needs evaluation

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts...

1 affected package

jawn

Package 20.04 LTS
jawn Needs evaluation
Show less packages