8.7

CVSS4.0

CVE-2026-35458 - Gotenberg has a ReDoS via extraHttpHeaders scope feature

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.

πŸ“… Published: April 7, 2026, 2:24 p.m. πŸ”„ Last Modified: April 7, 2026, 3:17 p.m.

7.5

CVSS3.1

CVE-2026-33034 - Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request b…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 7, 2026, 9:17 p.m.

6.5

CVSS3.1

CVE-2026-33033 - Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such a…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 7, 2026, 4:16 p.m.

2.7

CVSS3.1

CVE-2026-4292 - Privilege abuse in ModelAdmin.list_editable

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evalu…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 7, 2026, 4:16 p.m.

5.4

CVSS3.1

CVE-2026-4277 - Privilege abuse in GenericInlineModelAdmin

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evalua…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 7, 2026, 3:17 p.m.

8.2

CVSS3.1

CVE-2026-35457 - libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in …

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 7, 2026, 5:53 p.m.

7.5

CVSS3.1

CVE-2026-3902 - ASGI header spoofing via underscore/hyphen conflation

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Djan…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 7, 2026, 5:16 p.m.

7.5

CVSS3.1

CVE-2026-35405 - libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer can register. A malicious peer can just keep registering unique namespaces in a loop and the server happily accepts e…

πŸ“… Published: April 7, 2026, 2:21 p.m. πŸ”„ Last Modified: April 7, 2026, 3:17 p.m.

5.8

CVSS3.1

CVE-2026-5384 - runZero Platform incorrect credential scope

An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This i…

πŸ“… Published: April 7, 2026, 2:12 p.m. πŸ”„ Last Modified: April 7, 2026, 7:59 p.m.

4.4

CVSS3.1

CVE-2026-5383 - runZero Explorer missing authorization check

An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This issue was fixed in ver…

πŸ“… Published: April 7, 2026, 2:12 p.m. πŸ”„ Last Modified: April 7, 2026, 8 p.m.
Total resulsts: 343168
Page 46 of 34,317
Β« previous page Β» next page
Filters