4.8

CVSS3.1

CVE-2026-26962 - Rack: Header injection in multipart requests

Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack preserves the embedded CRLF in parsed parameter values such as filename or …

πŸ“… Published: April 2, 2026, 5:10 p.m. πŸ”„ Last Modified: April 3, 2026, 6:13 p.m.

4.8

CVSS3.1

CVE-2026-34835 - Rack: `Rack::Request` accepts invalid Host characters, enabling host allowlist bypass.

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host…

πŸ“… Published: April 2, 2026, 5:09 p.m. πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.

4.2

CVSS3.1

CVE-2026-35414 - OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

πŸ“… Published: April 2, 2026, 5:08 p.m. πŸ”„ Last Modified: April 9, 2026, 8:47 p.m.

7.5

CVSS3.1

CVE-2026-34827 - Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition: form-data; name="..." using repeated String#index searches combined with Strin…

πŸ“… Published: April 2, 2026, 5:07 p.m. πŸ”„ Last Modified: April 3, 2026, 6:13 p.m.

4.8

CVSS3.1

CVE-2026-32762 - Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling quoted-string values. Because quoted values may legally contain semicolons,…

πŸ“… Published: April 2, 2026, 5:06 p.m. πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.

6.7

CVSS3.0

CVE-2026-33271 - Local Privilege Escalation via Insecure Folder Permissions in Acronis True Image (before build 4290…

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902.

πŸ“… Published: April 2, 2026, 5:06 p.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.7

CVSS3.0

CVE-2026-27774 - Local Privilege Escalation via DLL Hijacking in Acronis True Image

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

πŸ“… Published: April 2, 2026, 5:05 p.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.7

CVSS3.0

CVE-2026-28728 -

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

πŸ“… Published: April 2, 2026, 5:04 p.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.3

CVSS4.0

CVE-2026-5360 - Free5GC aper type confusion

A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The expl…

πŸ“… Published: April 2, 2026, 5 p.m. πŸ”„ Last Modified: April 3, 2026, 7:59 p.m.

2.5

CVSS3.1

CVE-2026-35388 - OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

πŸ“… Published: April 2, 2026, 4:57 p.m. πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.
Total resulsts: 343864
Page 198 of 34,387
Β« previous page Β» next page
Filters