CVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
Information published.
Categories: Microsoft
CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass
Information published.
Categories: Microsoft
CVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz pagination
Information published.
Categories: Microsoft
CVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumption
Information published.
Categories: Microsoft
CVE-2026-59890 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Information published.
Categories: Microsoft
CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Information published.
Categories: Microsoft
CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
Information published.
Categories: Microsoft
CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Information published.
Categories: Microsoft
CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive
Information published.
Categories: Microsoft
CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
Information published.
Categories: Microsoft
CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Information published.
Categories: Microsoft
CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Information published.
Categories: Microsoft
CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
Information published.
Categories: Microsoft
CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
Information published.
Categories: Microsoft
CVE-2026-20244 ClamAV DMG File Processing Denial of Service Vulnerability
Information published.
Categories: Microsoft
CVE-2026-20243 ClamAV ALZ Archive Processing Denial of Service Vulnerability
Information published.
Categories: Microsoft
CVE-2026-20217 ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Information published.
Categories: Microsoft
CVE-2026-20216 ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
Information published.
Categories: Microsoft
CVE-2026-20215 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Information published.
Categories: Microsoft


