Search CVE reports


Toggle filters

1 – 10 of 57 results


CVE-2026-90467

Medium priority
Needs evaluation

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing...

1 affected package

aiosmtplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aiosmtplib Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2026-77358

Medium priority
Needs evaluation

cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In...

1 affected package

cpp-httplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-77341

Medium priority
Needs evaluation

cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a...

1 affected package

cpp-httplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-55558

Medium priority
Needs evaluation

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without...

1 affected package

aiosmtplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aiosmtplib Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2026-53533

Medium priority
Needs evaluation

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line...

1 affected package

aiosmtplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aiosmtplib Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2026-54919

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built...

1 affected package

cpp-httplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59939

Medium priority

Some fixes available 3 of 8

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent...

1 affected package

python-httplib2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-httplib2 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-46527

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request...

1 affected package

cpp-httplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45372

Medium priority
Fixed

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and...

1 affected package

cpp-httplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Fixed Fixed Fixed
Show less packages

CVE-2026-45352

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash....

1 affected package

cpp-httplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Needs evaluation Needs evaluation Needs evaluation
Show less packages