Search CVE reports


Toggle filters

1 – 10 of 913 results


CVE-2026-71488

Medium priority
Needs evaluation

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several...

2 affected packages

commonmark, markdown

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
commonmark Needs evaluation Needs evaluation Needs evaluation
markdown Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71478

Medium priority
Needs evaluation

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab,...

2 affected packages

commonmark, markdown

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
commonmark Needs evaluation Needs evaluation Needs evaluation
markdown Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-67422

Medium priority
Needs evaluation

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups...

12 affected packages

markdown, python2.7, python3.4, python3.5, python3.6...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
markdown Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python2.7 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Needs evaluation
python3.7 Not in release Not in release Not in release Needs evaluation
python3.8 Not in release Not in release Not in release Needs evaluation Needs evaluation
python3.9 Not in release Not in release Not in release Needs evaluation
python3.10 Not in release Not in release Needs evaluation
python3.11 Not in release Not in release Needs evaluation
python3.12 Not in release Needs evaluation Not in release
python3.14 Needs evaluation Not in release Not in release
Show all 12 packages Show less packages

CVE-2026-61632

Medium priority
Needs evaluation

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...

2 affected packages

markdown, python-markdown

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
markdown Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-markdown Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-51235

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

8 affected packages

libraw, ufraw, darktable, exactimage, dcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not affected
darktable Not affected Not affected Not affected Not affected Not affected
exactimage Not affected Not affected Not affected Not affected Not affected
dcraw Not affected Not affected Not affected Not affected Not affected
rawtherapee Not affected Not affected Not affected Not affected Not affected
kodi Not affected Not affected Not affected Not affected Not affected
digikam Not affected Not affected Not affected Not affected Not affected
Show all 8 packages Show less packages

CVE-2026-48801

Medium priority
Needs evaluation

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails...

1 affected package

node-markdown-it

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-markdown-it Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-15168

Medium priority
Needs evaluation

BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-15174

Medium priority
Needs evaluation

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-15173

Medium priority
Needs evaluation

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-15172

Medium priority
Needs evaluation

FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages