Search CVE reports


Toggle filters

1 – 10 of 532 results


CVE-2026-14456

Medium priority
Vulnerable

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-73283

Medium priority
Needs evaluation

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-73282

Medium priority
Needs evaluation

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-73281

Medium priority
Needs evaluation

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and...

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-17510

Medium priority
Needs evaluation

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its...

1 affected package

libcrypt-openssl-pkcs12-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-openssl-pkcs12-perl Needs evaluation Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-54876

Medium priority
Vulnerable

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45784

Medium priority
Needs evaluation

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-58102

Medium priority
Needs evaluation

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via extensions(), extensions_by_long_name(),...

1 affected package

libcrypt-openssl-x509-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-openssl-x509-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-58101

Medium priority
Needs evaluation

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. basicC, ia5string, and auth_att dereference...

1 affected package

libcrypt-openssl-x509-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-openssl-x509-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-60002

Medium priority

Some fixes available 3 of 14

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages