Search CVE reports


Toggle filters

631 – 640 of 45011 results

Status is adjusted based on your filters.


CVE-2026-19113

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-19017

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-19016

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-19015

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-19014

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-19012

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-15972

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-15970

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-71851

Medium priority
Needs evaluation

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator,...

1 affected package

cryptojs

Package 20.04 LTS
cryptojs Needs evaluation
Show less packages

CVE-2026-71847

Medium priority
Needs evaluation

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into...

1 affected package

ruby-json

Package 20.04 LTS
ruby-json Needs evaluation
Show less packages