CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
Information published.
Categories: Microsoft
CVE-2026-40930 LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body
Information published.
Categories: Microsoft
CVE-2026-50265 Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
Information published.
Categories: Microsoft
CVE-2026-49975 Apache HTTP Server: mod_http2 denial of service
Information published.
Categories: Microsoft
CVE-2026-11463 USCiLab Cereal Shared Pointer type confusion
Information published.
Categories: Microsoft
CVE-2026-35429 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft
CVE-2026-33118 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory
Information published.
Categories: Microsoft
CVE-2026-3276 Potential DoS via quadratic complexity in unicodedata.normalize()
Information published.
Categories: Microsoft
CVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directory
Information published.
Categories: Microsoft
CVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities
Information published.
Categories: Microsoft
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service
Information published.
Categories: Microsoft
CVE-2026-5419 Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal
Information published.
Categories: Microsoft
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509
Information published.
Categories: Microsoft
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto
Information published.
Categories: Microsoft
CVE-2026-42504 Quadratic complexity in WordDecoder.DecodeHeader in mime
Information published.
Categories: Microsoft
CVE-2026-37460 Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Information published.
Categories: Microsoft
CVE-2026-10722 cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
Information published.
Categories: Microsoft
CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
Information published.
Categories: Microsoft
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
Information published.
Categories: Microsoft


