6.4

CVSS3.1

CVE-2026-41591 - Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping

Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dynamic text is interpolated into a <script> or <style> tag the Marko runtime failed to prevent tag breakout when the closing tag used non-lowercase casin…

πŸ“… Published: May 8, 2026, 3:22 p.m. πŸ”„ Last Modified: May 8, 2026, 3:22 p.m.

10

CVSS3.1

CVE-2026-41070 - openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin…

πŸ“… Published: May 8, 2026, 3:14 p.m. πŸ”„ Last Modified: May 8, 2026, 3:14 p.m.

8.7

CVSS4.0

CVE-2026-44499 - ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent wea…

πŸ“… Published: May 8, 2026, 3:11 p.m. πŸ”„ Last Modified: May 8, 2026, 3:11 p.m.

5.3

CVSS3.1

CVE-2026-44500 - ZEBRA: Allocation Amplification in Inbound Network Deserializers

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter pro…

πŸ“… Published: May 8, 2026, 3:10 p.m. πŸ”„ Last Modified: May 8, 2026, 3:10 p.m.

9.2

CVSS4.0

CVE-2026-44498 - ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigops

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who produces such a bloc…

πŸ“… Published: May 8, 2026, 3:09 p.m. πŸ”„ Last Modified: May 8, 2026, 3:09 p.m.

9.3

CVSS4.0

CVE-2026-44497 - ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computation. Instead of retu…

πŸ“… Published: May 8, 2026, 3:08 p.m. πŸ”„ Last Modified: May 8, 2026, 3:08 p.m.

6.9

CVSS4.0

CVE-2026-41585 - ZEBRA: Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients

ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnecting before the req…

πŸ“… Published: May 8, 2026, 3:06 p.m. πŸ”„ Last Modified: May 8, 2026, 3:06 p.m.

9.2

CVSS4.0

CVE-2026-41584 - ZEBRA: rk Identity Point Panic in Transaction Verification

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" …

πŸ“… Published: May 8, 2026, 3:05 p.m. πŸ”„ Last Modified: May 8, 2026, 3:05 p.m.

9.3

CVSS4.0

CVE-2026-41583 - ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network u…

πŸ“… Published: May 8, 2026, 2:55 p.m. πŸ”„ Last Modified: May 8, 2026, 2:55 p.m.

9

CVSS3.1

CVE-2026-41588 - RELATE: Timing Attack Vulnerability in course/auth.py β€” check_sign_in_key()

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py β€” check_sign_in_key(). This issue has been patched via commit 2f68e16.

πŸ“… Published: May 8, 2026, 2:51 p.m. πŸ”„ Last Modified: May 8, 2026, 2:51 p.m.
Total resulsts: 349182
Page 2 of 34,919
Β« previous page Β» next page
Filters