Search CVE reports


Toggle filters

31 – 40 of 1518 results


CVE-2026-1388

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-0752

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-14511

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-3525

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-14103

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-1229

Medium priority
Needs evaluation

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are...

1 affected package

golang-github-cloudflare-circl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-cloudflare-circl Needs evaluation Needs evaluation
Show less packages

CVE-2026-26963

Medium priority
Needs evaluation

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption...

1 affected package

golang-github-cilium-ebpf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-cilium-ebpf Needs evaluation Needs evaluation
Show less packages

CVE-2025-69725

Medium priority
Needs evaluation

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

1 affected package

golang-github-go-chi-chi

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-chi-chi Needs evaluation Needs evaluation
Show less packages

CVE-2026-25766

Medium priority
Not affected

Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static...

3 affected packages

golang-github-labstack-echo, golang-github-labstack-echo.v2, golang-github-labstack-echo.v3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-labstack-echo Not affected Not affected
golang-github-labstack-echo.v2 Not in release Not affected Not affected
golang-github-labstack-echo.v3 Not in release Not affected Not affected
Show less packages

CVE-2026-26014

Medium priority
Needs evaluation

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for remote attackers to obtain the...

2 affected packages

golang-github-pion-dtls-v3, golang-github-pion-dtls.v2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-pion-dtls-v3 Not in release Not in release
golang-github-pion-dtls.v2 Needs evaluation Not in release
Show less packages