Search

Found 30,492 results in 4063ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-8556 low 3.1 3.1 FIX debian debianwindows windows google 22d ago Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HT…
CVE-2026-8554 low 3.1 3.1 FIX debian debianwindows windows google 22d ago Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted H…
CVE-2026-8553 low 3.1 3.1 FIX debian debianwindows windows google 22d ago Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Ch…
CVE-2026-8552 medium 4.3 4.3 FIX debian debianwindows windows google 22d ago Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity…
CVE-2026-8550 medium 6.5 6.5 FIX debian debianmacos macos linux-kernel google 22d ago Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memo…
CVE-2026-8546 medium 5.3 5.3 FIX debian debianmacos macoswindows windows google 22d ago Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information fr…
CVE-2026-8545 low 3.1 3.1 FIX debian debianmacos macos linux-kernel google 22d ago Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromi…
CVE-2026-8543 medium 5.3 5.3 FIX debian debianmacos macoswindows windows google 22d ago Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive infor…
CVE-2026-8541 medium 5.3 5.3 FIX debian debianmacos macos linux-kernel google 22d ago Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory vi…
CVE-2026-8539 medium 5.4 5.4 FIX debian debianwindows windows google 22d ago Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security s…
CVE-2026-8538 medium 5.3 5.3 FIX debian debianwindows windows google 22d ago Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform a denial of service via a craf…
CVE-2026-8537 medium 4.3 4.3 FIX debian debianwindows windows google 22d ago Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: H…
CVE-2026-8536 low 3.1 3.1 FIX debian debianmacos macoswindows windows google 22d ago Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass site Isolation v…
CVE-2026-8535 medium 5.3 5.3 FIX debian debian linux-kernelwindows windows google 22d ago Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informati…
CVE-2026-8528 medium 4.3 4.3 FIX debian debianmacos macos linux-kernel google 22d ago Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a …
CVE-2026-8516 medium 5.3 5.3 FIX debian debianmacos macos linux-kernel google 22d ago Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentia…
CVE-2026-8511 critical 9.6 9.6 FIX debian debianmacos macos linux-kernel google 22d ago Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-44638 low 2.5 2.5 FIX debian debian sles saitoha 22d ago libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointe…
CVE-2026-43996 medium 5.5 5.5 debian debian openimageio 22d ago OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, the bounds check in TGAInput::decode_…
CVE-2026-46470 critical 9.1 9.1 FIX debian debian sles freedesktop 22d ago An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…
CVE-2026-46469 medium 5.5 5.5 FIX debian debian sles freedesktop 22d ago An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before per…
CVE-2026-44544 medium 5.5 debian debian 22d ago gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted …
CVE-2026-44283 medium 4.3 4.3 FIX debian debian sleswindows windows etcd 22d ago etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
CVE-2026-41888 medium 6.5 6.5 debian debian sles distribution 22d ago Distribution's tag deletion bypasses `storage.delete.enabled` configuration
CVE-2026-44348 low 2.5 2.5 FIX debian debian sles 22d ago PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFin…
CVE-2026-44898 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 22d ago Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used a…
CVE-2026-45076 low 2.7 2.7 FIX debian debian element 22d ago Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full h…
CVE-2026-45078 medium 5.5 5.5 FIX debian debian element 22d ago Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing o…
CVE-2026-6575 medium 4.3 4.3 FIX slesdebian debian postgresql 22d ago Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintain…
CVE-2026-6478 medium 6.5 6.5 FIX slesdebian debianwindows windows postgresql 22d ago Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 …
CVE-2026-6474 medium 4.3 4.3 FIX slesdebian debianwindows windows postgresql 22d ago Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 1…
CVE-2026-6472 medium 5.4 5.4 FIX slesdebian debianwindows windows postgresql 22d ago Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, t…
CVE-2026-45205 medium 5.3 5.3 FIX debian debian sles apache 22d ago Apache Commons Configuration: StackOverflowError for YAML input with cycles
CVE-2026-44919 medium 4.3 4.3 FIX debian debian 22d ago OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
CVE-2026-8328 unknown slesdebian debianwindows windows 23d ago The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpee…
CVE-2026-8496 medium 6.1 6.1 FIX debian debian 23d ago A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated S…
CVE-2026-42584 critical 9.1 9.1 slesdebian debian netty 23d ago Netty has HttpClientCodec response desynchronization
CVE-2026-42581 critical 9.8 9.8 slesdebian debian netty 23d ago Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CVE-2026-42580 medium 6.5 6.5 slesdebian debian netty 23d ago Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
CVE-2026-42579 critical 9.1 9.1 slesdebian debian netty 23d ago Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
CVE-2026-8367 medium 4.8 4.8 debian debian 23d ago aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be ab…
CVE-2026-44431 medium 5.3 5.3 slesdebian debianwindows windows pythongoogle 23d ago urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fa…
CVE-2026-43489 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: liveupdate: luo_file: remember retrieve() status LUO keeps track of successful retrieve attempts on a LUO file. It does so to av…
CVE-2026-43488 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Prevent interrupt storm on host controller error (HCE) The xHCI controller reports a Host Controller Error (HCE) in UA…
CVE-2026-43487 unknown FIX slesdebian debian google 23d ago In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Disable LPM on ST1000DM010-2EP102 According to a user report, the ST1000DM010-2EP102 has problems with LPM, cau…
CVE-2026-43486 unknown FIX slesdebian debian google 23d ago In the Linux kernel, the following vulnerability has been resolved: arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults contpte_ptep_set_access_flags() compared the gathered ptep…
CVE-2026-43485 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: nouveau/gsp: drop WARN_ON in ACPI probes These WARN_ONs seem to trigger a lot, and we don't seem to have a plan to fix them, so j…
CVE-2026-43484 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid bitfield RMW for claim/retune flags Move claimed and retune control flags out of the bitfield word to avoid unre…
CVE-2026-43483 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated Explicitly set/clear CR8 write interception when AVIC is (d…
CVE-2026-43482 unknown FIX slesdebian debian google 23d ago In the Linux kernel, the following vulnerability has been resolved: sched_ext: Disable preemption between scx_claim_exit() and kicking helper work scx_claim_exit() atomically sets exit_kind, which …
CVE-2026-43480 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the r…
CVE-2026-43479 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect Remove redundant netif_napi_del() call from disconnect path.…
CVE-2026-43478 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: rt1011: Use component to get the dapm context in spk_mode_put The correct helper to use in rt1011_recv_spk_mode_put…
CVE-2026-43477 unknown FIX slesdebian debian 23d ago In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: Configure VRR timings after enabling TRANS_DDI_FUNC_CTL Apparently ICL may hang with an MCE if we write TRANS_VRR_V…
CVE-2026-42946 medium 6.5 6.5 FIX slesdebian debianwindows windows 23d ago A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured…
CVE-2026-42934 medium 4.8 4.8 FIX slesdebian debianwindows windows 23d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives ar…
CVE-2026-42926 medium 5.8 5.8 FIX slesdebian debian 23d ago When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the…
CVE-2026-42557 critical 9.6 9.6 debian debian jupyter 23d ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlink…
CVE-2026-40701 medium 4.8 4.8 FIX slesdebian debianwindows windows 23d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or…
CVE-2026-40460 medium 6.5 6.5 FIX slesdebian debianwindows windows 23d ago When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limi…
CVE-2026-44740 medium 6.5 6.5 debian debian sles 23d ago Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loo…
CVE-2026-8463 medium 5.3 5.3 FIX debian debian leont 23d ago Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the…
CVE-2026-7168 medium 5.3 5.3 FIX debian debian sleswindows windows haxxgoogle 23d ago Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reu…
CVE-2026-7009 medium 5.3 5.3 FIX debian debian sles haxxgoogle 23d ago When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and inste…
CVE-2026-6429 medium 5.3 5.3 FIX debian debian sleswindows windows haxxgoogle 23d ago When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
CVE-2026-6253 medium 5.9 5.9 FIX debian debian sleswindows windows haxxgoogle 23d ago curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for differ…
CVE-2026-5545 medium 6.5 6.5 FIX debian debian sleswindows windows haxxgoogle 23d ago libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a …
CVE-2026-4873 medium 5.9 5.9 FIX debian debian sleswindows windows haxxgoogle 23d ago A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SM…
CVE-2026-41051 medium 5.0 5.0 FIX debian debian sles 23d ago csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
CVE-2026-33985 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-31885 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-31884 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-31883 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-29775 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-27951 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-26986 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-25952 medium 5.5 FIX rheldebian debian sles 23d ago Moderate: freerdp security update
CVE-2026-45185 critical 9.8 9.8 FIX debian debian sles exim 24d ago Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a C…
CVE-2026-42338 medium 6.1 6.1 debian debian beaugunderson 24d ago ip-address has XSS in Address6 HTML-emitting methods
CVE-2026-42177 medium 5.3 5.3 FIX debian debian 24d ago linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter i…
CVE-2026-31236 critical 9.8 9.8 debian debian 24d ago llm CLI tool contains a code injection vulnerability via `--functions` command-line argument
CVE-2026-43515 critical 9.1 9.1 FIX slesdebian debian apache 24d ago Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21,…
CVE-2026-43514 low 3.7 3.7 FIX slesdebian debian apache 24d ago Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M…
CVE-2026-43512 critical 9.8 9.8 FIX slesdebian debian apache 24d ago DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, fr…
CVE-2026-41293 critical 9.8 9.8 FIX slesdebian debian apache 24d ago Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0…
CVE-2026-8368 medium 6.5 6.5 FIX debian debian sleswindows windows 24d ago LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before …
CVE-2026-42006 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 24d ago An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left op…
CVE-2026-40020 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 24d ago Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is lim…
CVE-2026-40016 medium 6.5 6.5 FIX debian debian sles dovecotopen-xchange 24d ago Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to deg…
CVE-2026-33603 medium 5.3 5.3 FIX debian debian sles dovecotopen-xchange 24d ago Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the c…
CVE-2026-27851 critical 9.1 9.1 FIX debian debian sles dovecotopen-xchange 24d ago When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP …
CVE-2026-7010 medium 6.5 6.5 FIX debian debian 25d ago HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host t…
CVE-2026-42050 medium 5.5 5.5 FIX debian debian sles imagemagick 25d ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in…
CVE-2026-41159 medium 5.3 5.3 debian debian mermaid_project 25d ago Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies…
CVE-2026-41150 medium 5.3 5.3 debian debian mermaid_project 25d ago Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, i…
CVE-2026-43969 low 3.2 3.2 FIX debian debianwindows windows ninenines 25d ago cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-43968 medium 4.0 4.0 FIX debian debianwindows windows ninenines 25d ago ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values
CVE-2026-7210 critical 9.8 9.8 slesdebian debianwindows windows libexpat_projectpython 25d ago `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this…
CVE-2026-44777 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 25d ago jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.
CVE-2026-43896 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 25d ago jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachab…