Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-44503
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
CVE-2026-44375
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
CVE-2026-44302
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
CVE-2026-42348
OpAMP client reads unbounded HTTP response bodies
CVE-2026-43939
YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
CVE-2026-43937
YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
CVE-2026-43938
YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
CVE-2026-42191
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
CVE-2026-41484
OneCollector exporter reads unbounded HTTP response bodies
CVE-2026-41483
OpenTelemetry.Resources.Azure has an unbounded HTTP response body read
CVE-2026-41310
OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure
CVE-2026-42241
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
CVE-2026-41173
OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads
CVE-2026-40894
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVE-2026-40891
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVE-2026-40182
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVE-2026-40372
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
CVE-2026-41511
OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
CVE-2026-41319
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
CVE-2026-41078
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
Showing 1 - 20 of 1,000+ results