Search CVE reports


Toggle filters

241 – 250 of 42078 results

Status is adjusted based on your filters.


CVE-2026-48043

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-48006

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-47691

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-44967

Medium priority

Not in release

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This...

1 affected package

opentelemetry-cpp

Package 22.04 LTS
opentelemetry-cpp Not in release
Show less packages

CVE-2026-47244

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-46340

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-45674

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-45673

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-45536

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-45416

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages