7.5

CVSS3.1

CVE-2026-33662 - OP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode()

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10, in the function emsa_pkcs1_v1_5_encode() in core/drivers/crypto/crypto_api/acipher/rsassa.c, the amount of padding ne…

πŸ“… Published: April 24, 2026, 6:13 p.m. πŸ”„ Last Modified: April 24, 2026, 6:13 p.m.

8.1

CVSS4.0

CVE-2026-41907 - uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

πŸ“… Published: April 24, 2026, 6:09 p.m. πŸ”„ Last Modified: April 24, 2026, 6:09 p.m.

5.4

CVSS3.1

CVE-2026-42042 - Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Co…

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy no…

πŸ“… Published: April 24, 2026, 6:03 p.m. πŸ”„ Last Modified: April 24, 2026, 6:03 p.m.

6.9

CVSS4.0

CVE-2026-42039 - Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.3…

πŸ“… Published: April 24, 2026, 6:01 p.m. πŸ”„ Last Modified: April 24, 2026, 6:01 p.m.

5.3

CVSS3.1

CVE-2026-42036 - Axios: HTTP adapter streamed responses bypass maxContentLength

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vu…

πŸ“… Published: April 24, 2026, 6 p.m. πŸ”„ Last Modified: April 24, 2026, 6 p.m.

5.3

CVSS3.1

CVE-2026-42034 - Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits…

πŸ“… Published: April 24, 2026, 5:59 p.m. πŸ”„ Last Modified: April 24, 2026, 5:59 p.m.

5.3

CVSS3.1

CVE-2026-42037 - Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\r\n) sequences. An attacker w…

πŸ“… Published: April 24, 2026, 5:58 p.m. πŸ”„ Last Modified: April 24, 2026, 5:58 p.m.

6.8

CVSS3.1

CVE-2026-42038 - Axios: no_proxy bypass via IP alias allows SSRF

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy…

πŸ“… Published: April 24, 2026, 5:57 p.m. πŸ”„ Last Modified: April 24, 2026, 5:57 p.m.

4.8

CVSS3.1

CVE-2026-42041 - Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be t…

πŸ“… Published: April 24, 2026, 5:55 p.m. πŸ”„ Last Modified: April 24, 2026, 5:55 p.m.

7.2

CVSS3.1

CVE-2026-42043 - Axios: Incomplete Fix for CVE-2025-62718 β€” NO_PROXY Protection Bypassed via RFC 1122 Loopback Subn…

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due …

πŸ“… Published: April 24, 2026, 5:54 p.m. πŸ”„ Last Modified: April 24, 2026, 5:54 p.m.
Total resulsts: 347815
Page 133 of 34,782
Β« previous page Β» next page
Filters