Search CVE reports


Toggle filters

1 – 10 of 488 results


CVE-2026-22772

Medium priority
Needs evaluation

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer...

1 affected package

golang-github-sigstore-fulcio

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-fulcio Not in release Not in release
Show less packages

CVE-2025-67726

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in...

1 affected package

python-tornado

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-67725

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add...

1 affected package

python-tornado

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-67724

Medium priority

Some fixes available 5 of 7

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the...

1 affected package

python-tornado

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Fixed Fixed Fixed Ignored
Show less packages

CVE-2025-66564

Medium priority
Needs evaluation

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data)...

1 affected package

golang-github-sigstore-timestamp-authority

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-timestamp-authority Not in release Not in release
Show less packages

CVE-2025-66506

Medium priority
Needs evaluation

Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to strings.Split) its argument (which...

1 affected package

golang-github-sigstore-fulcio

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-fulcio Not in release Not in release
Show less packages

CVE-2025-63396

Medium priority
Needs evaluation

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation
Show less packages

CVE-2025-61261

Medium priority
Needs evaluation

A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-56200

Medium priority
Needs evaluation

A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows...

1 affected package

validator.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
validator.js Not in release Not in release Needs evaluation
Show less packages

CVE-2025-55560

Medium priority
Needs evaluation

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation
Show less packages