Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.8 CVE-2026-13322

Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service_CVE-2026-13322

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buff...

Red Hat Red Hat OpenShift Virtualization 4 CVE
LOW 1 CVE-2026-6681

PKCS#7 decode ignores caller output buffer size, writing past buffer bounds_CVE-2026-6681

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the pro...

wolfSSL wolfSSL 3.10.0 CVE
LOW 1 CVE-2026-6678

Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info_CVE-2026-6678

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

wolfSSL wolfSSL 3.15.5 CVE
LOW 1 CVE-2026-6450

CRL critical extension bypass in ParseCRL_Extensions_CVE-2026-6450

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an u...

wolfSSL wolfSSL 4.3.0 CVE
LOW 2.3 CVE-2026-6412

Continued acceptance of SHA-1/MD5 digests in certificate processing_CVE-2026-6412

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

wolfSSL wolfSSL 3.9.10 CVE
LOW 2.1 CVE-2026-6331

HMAC zero-length tag forgery in EVP_DigestVerifyFinal_CVE-2026-6331

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-...

wolfSSL wolfSSL 3.15.5 CVE
LOW 2 CVE-2026-6325

Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list_CVE-2026-6325

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destina...

wolfSSL wolfSSL 4.8.0 CVE
LOW 2.1 CVE-2026-6092

Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured_CVE-2026-6092

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

wolfSSL wolfSSL 5.2.0 CVE
LOW 3.4 CVE-2026-48940

Joomla Extension – getk2.com – Stored-XSS in K2 extension for Joomla < 2.26_CVE-2026-48940

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `` tag; K2 s...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
LOW 2.3 CVE-2026-57522

Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates_CVE-2026-57522

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-co...

bitwarden server CVE