Search CVE reports


Toggle filters

611 – 620 of 34287 results

Status is adjusted based on your filters.


CVE-2026-29145

Medium priority
Needs evaluation

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 24.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Needs evaluation
tomcat11 Not in release
Show less packages

CVE-2026-29129

Medium priority
Needs evaluation

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 24.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Needs evaluation
tomcat11 Not in release
Show less packages

CVE-2026-25854

Medium priority
Needs evaluation

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 24.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Needs evaluation
tomcat11 Not in release
Show less packages

CVE-2026-24880

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 24.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Needs evaluation
tomcat11 Not in release
Show less packages

CVE-2026-35195

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's realloc is...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-35186

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result to be incorrectly typed. For...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34988

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of its pooling allocator contains a bug where in certain configurations the contents of linear memory can be leaked...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34987

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34983

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not controllable by guest Wasm programs. It can only be triggered by a specific sequence of...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34971

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages