| CVE-2026-31789 | CRITICAL | libcrypto3 | 3.5.6-r0 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing | 1 |
| CVE-2025-59419 | HIGH | io.netty:netty-codec-smtp | 4.2.7.Final, | 4.1.128.Final io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection | 1 |
| CVE-2025-67721 | HIGH | io.airlift:aircompressor | 2.0.3 | aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer | 1 |
| CVE-2026-22184 | HIGH | zlib | 1.3.2-r0 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility | 1 |
| CVE-2026-27135 | HIGH | nghttp2-libs | 1.68.1 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination | 1 |
| CVE-2026-28387 | HIGH | libcrypto3 | 3.5.6-r0 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication | 1 |
| CVE-2026-28388 | HIGH | libcrypto3 | 3.5.6-r0 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing | 1 |
| CVE-2026-28389 | HIGH | libcrypto3 | 3.5.6-r0 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing | 1 |
| CVE-2026-28390 | HIGH | libcrypto3 | 3.5.6-r0 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing | 1 |
| CVE-2026-29062 | HIGH | tools.jackson.core:jackson-core | 3.1.0 | jackson-core: jackson-core: Denial of Service via excessive JSON nesting | 1 |
| CVE-2026-33814 | HIGH | ingress-nginx-controller-1.15 | 1.15.5-r1 | When processing HTTP/2 SETTINGS frames, transport will enter an infini ... | 3 |
| CVE-2026-33870 | HIGH | reposilite | 3.5.28-r2 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extensio... | 2 |
| CVE-2026-33871 | HIGH | reposilite | 3.5.28-r2 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood | 2 |
| CVE-2026-39852 | HIGH | keycloak-26.6 | 26.6.1-r5 | io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests | 2 |
| CVE-2026-40200 | HIGH | musl | 1.2.5-r12 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort | 1 |
| CVE-2026-42198 | HIGH | org.postgresql:postgresql | 42.7.11 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication | 5 |
| CVE-2026-42579 | HIGH | io.netty:netty-codec-dns | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 4 |
| CVE-2026-42583 | HIGH | io.netty:netty-codec | 4.1.133.Final | Netty is an asynchronous, event-driven network application framework. ... | 5 |
| CVE-2026-42584 | HIGH | io.netty:netty-codec-http | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 4 |
| CVE-2026-42587 | HIGH | io.netty:netty-codec-http | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 4 |
| CVE-2026-5588 | HIGH | keycloak-26.6 | 26.6.1-r4 | bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid | 1 |
| CVE-2026-5598 | HIGH | keycloak-26.6 | 26.6.1-r4 | bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons | 1 |
| CVE-2023-1419 | MEDIUM | io.debezium:debezium-connector-mysql | 2.3.0.Alpha1 | debezium: script injection via connector parameter | 1 |
| CVE-2024-25710 | MEDIUM | org.apache.commons:commons-compress | 1.26.0 | commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file | 1 |
| CVE-2024-26308 | MEDIUM | org.apache.commons:commons-compress | 1.26.0 | commons-compress: OutOfMemoryError unpacking broken Pack200 file | 1 |
| CVE-2024-45993 | MEDIUM | giflib | 6.1.2-r0 | giflib: heap buffer overflow via gif2rgb | 1 |
| CVE-2025-31672 | MEDIUM | org.apache.poi:poi-ooxml | 5.4.0 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data... | 1 |
| CVE-2025-48924 | MEDIUM | org.apache.commons:commons-lang3 | 3.18.0 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang | 3 |
| CVE-2025-67735 | MEDIUM | io.netty:netty-codec-http | 4.2.8.Final, | 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection | 1 |
| CVE-2025-68161 | MEDIUM | org.apache.logging.log4j:log4j-core | 2.25.3 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification | 1 |
| CVE-2025-7962 | MEDIUM | com.sun.mail:jakarta.mail | 1.6.8, | 2.0.2 com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability | 1 |
| CVE-2026-0636 | MEDIUM | keycloak-26.6 | 26.6.1-r4 | bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java | 1 |
| CVE-2026-1002 | MEDIUM | io.vertx:vertx-core | 4.5.24, | 5.0.7 io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files | 2 |
| CVE-2026-2673 | MEDIUM | libcrypto3 | 3.6.1-r3 | openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group | 4 |
| CVE-2026-27171 | MEDIUM | zlib | 1.3.2-r0 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions | 1 |
| CVE-2026-31790 | MEDIUM | libcrypto3 | 3.5.6-r0 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key | 1 |
| CVE-2026-33813 | MEDIUM | gitea | 1.26.1-r1 | golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing | 1 |
| CVE-2026-34477 | MEDIUM | org.apache.logging.log4j:log4j-core | 2.25.4 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification | 1 |
| CVE-2026-34478 | MEDIUM | org.apache.logging.log4j:log4j-core | 2.25.4 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute ... | 1 |
| CVE-2026-34480 | MEDIUM | org.apache.logging.log4j:log4j-core | 2.25.4 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging | 1 |
| CVE-2026-34481 | MEDIUM | org.apache.logging.log4j:log4j-layout-template-json | 2.25.4 | org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output | 1 |
| CVE-2026-4046 | MEDIUM | glibc | 2.43-r6 | glibc: glibc: Denial of Service via iconv() function with specific character sets | 4 |
| CVE-2026-41417 | MEDIUM | io.netty:netty-codec-http | 4.1.133.Final, | 4.2.13.Final netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection | 4 |
| CVE-2026-42580 | MEDIUM | io.netty:netty-codec-http | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 4 |
| CVE-2026-42581 | MEDIUM | io.netty:netty-codec-http | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 4 |
| CVE-2026-42585 | MEDIUM | io.netty:netty-codec-http | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 4 |
| CVE-2026-42586 | MEDIUM | io.netty:netty-codec-redis | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 1 |
| CVE-2026-44248 | MEDIUM | io.netty:netty-codec-mqtt | 4.2.13.Final, | 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ... | 1 |
| CVE-2026-4437 | MEDIUM | glibc | 2.43-r4 | glibc: glibc: Incorrect DNS response parsing via crafted DNS server response | 4 |
| CVE-2026-4438 | MEDIUM | glibc | 2.43-r4 | glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions | 4 |
| CVE-2026-45292 | MEDIUM | io.opentelemetry:opentelemetry-api | 1.62.0 | OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation | 1 |
| CVE-2026-5450 | MEDIUM | glibc | 2.43-r7 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width | 5 |
| CVE-2026-5928 | MEDIUM | glibc | 2.43-r7 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings | 5 |
| CVE-2026-6042 | MEDIUM | musl | 1.2.5-r11 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv | 1 |
| CVE-2026-6860 | MEDIUM | keycloak-26.6 | 26.6.1-r5 | Vert.x has a DoS via unbounded server-side SNI SslContext cache growth | 3 |
| CVE-2026-42578 | LOW | io.netty:netty-handler-proxy | 4.1.133.Final, | 4.2.13.Final Netty is an asynchronous, event-driven network application framework. ... | 4 |