Search CVE reports


Toggle filters

31 – 40 of 48904 results

Status is adjusted based on your filters.


CVE-2026-102273

Medium priority
Needs evaluation

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses...

1 affected package

pyjwt

Package 24.04 LTS
pyjwt Needs evaluation
Show less packages

CVE-2026-102272

Medium priority
Needs evaluation

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks...

1 affected package

pyjwt

Package 24.04 LTS
pyjwt Needs evaluation
Show less packages

CVE-2026-102270

Medium priority
Needs evaluation

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated...

1 affected package

pyjwt

Package 24.04 LTS
pyjwt Needs evaluation
Show less packages

CVE-2026-102267

Medium priority
Needs evaluation

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted...

1 affected package

pyjwt

Package 24.04 LTS
pyjwt Needs evaluation
Show less packages

CVE-2026-101912

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both...

1 affected package

node-ip-address

Package 24.04 LTS
node-ip-address Needs evaluation
Show less packages

CVE-2026-101911

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid...

1 affected package

node-ip-address

Package 24.04 LTS
node-ip-address Needs evaluation
Show less packages

CVE-2026-101910

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48....

1 affected package

node-ip-address

Package 24.04 LTS
node-ip-address Needs evaluation
Show less packages

CVE-2026-101905

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-101904

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-101902

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages