7.5

CVSS3.1

CVE-2026-33666 - Zserio: Integer Overflow in BitStreamReader on 32-bit platforms

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readString(), the setBitPosition() bounds check receives the overflowed value and is completely bypassed. The code then reads len bytes (512 …

πŸ“… Published: April 24, 2026, 6:21 p.m. πŸ”„ Last Modified: April 24, 2026, 6:21 p.m.

7.5

CVSS3.1

CVE-2026-33524 - Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). This vulnerability is fixed in …

πŸ“… Published: April 24, 2026, 6:18 p.m. πŸ”„ Last Modified: April 24, 2026, 6:18 p.m.

7.5

CVSS3.1

CVE-2026-33662 - OP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode()

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10, in the function emsa_pkcs1_v1_5_encode() in core/drivers/crypto/crypto_api/acipher/rsassa.c, the amount of padding ne…

πŸ“… Published: April 24, 2026, 6:13 p.m. πŸ”„ Last Modified: April 24, 2026, 6:13 p.m.

8.1

CVSS4.0

CVE-2026-41907 - uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

πŸ“… Published: April 24, 2026, 6:09 p.m. πŸ”„ Last Modified: April 24, 2026, 6:09 p.m.

5.4

CVSS3.1

CVE-2026-42042 - Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Co…

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy no…

πŸ“… Published: April 24, 2026, 6:03 p.m. πŸ”„ Last Modified: April 24, 2026, 6:03 p.m.

6.9

CVSS4.0

CVE-2026-42039 - Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.3…

πŸ“… Published: April 24, 2026, 6:01 p.m. πŸ”„ Last Modified: April 24, 2026, 6:01 p.m.

5.3

CVSS3.1

CVE-2026-42036 - Axios: HTTP adapter streamed responses bypass maxContentLength

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vu…

πŸ“… Published: April 24, 2026, 6 p.m. πŸ”„ Last Modified: April 24, 2026, 6 p.m.

5.3

CVSS3.1

CVE-2026-42034 - Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits…

πŸ“… Published: April 24, 2026, 5:59 p.m. πŸ”„ Last Modified: April 24, 2026, 5:59 p.m.

5.3

CVSS3.1

CVE-2026-42037 - Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\r\n) sequences. An attacker w…

πŸ“… Published: April 24, 2026, 5:58 p.m. πŸ”„ Last Modified: April 24, 2026, 5:58 p.m.

6.8

CVSS3.1

CVE-2026-42038 - Axios: no_proxy bypass via IP alias allows SSRF

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy…

πŸ“… Published: April 24, 2026, 5:57 p.m. πŸ”„ Last Modified: April 24, 2026, 5:57 p.m.
Total resulsts: 347919
Page 143 of 34,792
Β« previous page Β» next page
Filters