CVE-2026-39825
- EPSS 0.39%
- Veröffentlicht 07.05.2026 19:41:18
- Zuletzt bearbeitet 13.05.2026 16:58:56
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters ...
CVE-2026-39836
- EPSS 0.59%
- Veröffentlicht 07.05.2026 19:41:18
- Zuletzt bearbeitet 13.05.2026 15:11:10
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
CVE-2026-42499
- EPSS 0.8%
- Veröffentlicht 07.05.2026 19:41:18
- Zuletzt bearbeitet 18.09.2026 13:18:17
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-33814
- EPSS 0.78%
- Veröffentlicht 07.05.2026 19:41:17
- Zuletzt bearbeitet 18.09.2026 13:17:59
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
CVE-2026-32280
- EPSS 0.62%
- Veröffentlicht 08.04.2026 01:06:58
- Zuletzt bearbeitet 18.09.2026 13:17:45
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypt...
CVE-2026-32281
- EPSS 0.36%
- Veröffentlicht 08.04.2026 01:06:58
- Zuletzt bearbeitet 25.07.2026 10:10:00
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certific...
CVE-2026-27140
- EPSS 0.66%
- Veröffentlicht 08.04.2026 01:06:57
- Zuletzt bearbeitet 10.09.2026 13:17:57
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVE-2026-27143
- EPSS 0.54%
- Veröffentlicht 08.04.2026 01:06:57
- Zuletzt bearbeitet 25.07.2026 11:10:00
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
CVE-2026-32283
- EPSS 0.62%
- Veröffentlicht 08.04.2026 01:06:57
- Zuletzt bearbeitet 18.09.2026 13:17:48
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
CVE-2026-32288
- EPSS 0.29%
- Veröffentlicht 08.04.2026 01:06:57
- Zuletzt bearbeitet 25.07.2026 10:10:00
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.