Search CVE reports


Toggle filters

11 – 20 of 33063 results

Status is adjusted based on your filters.


CVE-2026-33216

Medium priority
Needs evaluation

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a...

1 affected package

nats-server

Package 24.04 LTS
nats-server Needs evaluation
Show less packages

CVE-2026-30892

Medium priority
Needs evaluation

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have...

1 affected package

crun

Package 24.04 LTS
crun Needs evaluation
Show less packages

CVE-2026-29785

Medium priority
Needs evaluation

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can...

1 affected package

nats-server

Package 24.04 LTS
nats-server Needs evaluation
Show less packages

CVE-2026-27889

Medium priority
Needs evaluation

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a...

1 affected package

nats-server

Package 24.04 LTS
nats-server Needs evaluation
Show less packages

CVE-2026-27860

Medium priority
Not affected

v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and...

1 affected package

dovecot

Package 24.04 LTS
dovecot Not affected
Show less packages

CVE-2026-27859

Medium priority
Vulnerable

v3.0.2+ regression: Message headers MIME parameter parsing can cause excessive CPU usage. A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2026-27858

Medium priority
Vulnerable

managesieve-login out-of-memory DoS. Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2026-27857

Medium priority
Vulnerable

imap-login: Excessive memory usage DoS. Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2026-27856

Medium priority
Vulnerable

doveadm: Credentials verified without timing safety. Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2026-27855

Medium priority
Vulnerable

auth: OTP driver vulnerable to replay attack. Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages