Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-44248
Netty MQTT: Resource exhaustion in MqttDecoder
CVE-2026-44503
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
CVE-2026-42587
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
CVE-2026-42586
Netty Redis Codec Encoder has a CRLF Injection Issue
CVE-2026-42585
Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding
CVE-2026-42584
Netty has HttpClientCodec response desynchronization
CVE-2026-42583
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
CVE-2026-42582
Netty HTTP/3 QPACK literal unbounded allocation
CVE-2026-42581
Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CVE-2026-42580
Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
CVE-2026-42579
Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
CVE-2026-42578
Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)
OpenSearch has ineffective TLS certificate hostname verification
OpenSearch Security plugin: DLS not applied on documents linked by has_child or has_parent relation
OpenSearch vulnerable to improper authorization for Rollover Requests
OpenSearch has a bypass of REST Layer Authorization Using Malformed Paths
CVE-2026-44308
Spring Cloud AWS missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notifications
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
CVE-2026-42577
Netty epoll transport denial of service via RST on half-closed TCP connection
CVE-2026-42555
Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
Showing 1 - 20 of 1,000+ results