Search CVE reports


Toggle filters

1 – 10 of 175 results


CVE-2026-75803

Low priority

Some fixes available 3 of 7

AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2026-63076

Medium priority

Some fixes available 3 of 7

Invalid Pointer Dereference in CMP Server via Crafted protectionAlg

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2026-63075

Low priority

Some fixes available 1 of 4

QUIC ACK-only Packet Retention Can Cause Memory Exhaustion

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-63074

Low priority

Some fixes available 3 of 7

CMP Indefinite Cache Growth of ExtraCerts

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2026-63073

Low priority

Some fixes available 1 of 4

Untrusted Sender DN Used as Format String in CMP Response Validation

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-63072

Medium priority

Some fixes available 8 of 17

Heap Buffer Overflow in CMS Key Unwrapping

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54874

Low priority

Some fixes available 8 of 17

Excessive Memory Use Buffering DTLS Records for a Future Epoch

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18798

Medium priority
Vulnerable

QUIC Server May Trigger Double Free When Processing INITIAL Packet

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Vulnerable Not affected Not affected Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-14457

Low priority

Some fixes available 1 of 4

RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-14456

Medium priority

Some fixes available 1 of 4

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
Show less packages