Search CVE reports


Toggle filters

11 – 20 of 1641 results


CVE-2026-67323

Medium priority
Needs evaluation

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary...

1 affected package

python-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-git Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-67322

Medium priority
Needs evaluation

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the...

1 affected package

python-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-git Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54909

Medium priority
Needs evaluation

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of...

2 affected packages

golang-github-pion-stun, golang-github-pion-stun-v3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-pion-stun Needs evaluation Needs evaluation Not in release
golang-github-pion-stun-v3 Needs evaluation Not in release Not in release
Show less packages

CVE-2026-53587

Medium priority
Fixed

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-53586

Medium priority
Fixed

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2026-53585

Medium priority
Fixed

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-53584

Medium priority

Some fixes available 4 of 6

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Fixed Fixed Ignored
Show less packages

CVE-2026-53583

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54345

Medium priority
Needs evaluation

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a...

2 affected packages

golang-github-gopacket-gopacket, gopacket

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gopacket-gopacket Needs evaluation Needs evaluation Not in release
gopacket Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54332

Medium priority
Needs evaluation

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes...

2 affected packages

golang-github-gopacket-gopacket, gopacket

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gopacket-gopacket Needs evaluation Needs evaluation Not in release
gopacket Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages