Search CVE reports


Toggle filters

1 – 10 of 361 results


CVE-2026-54873

Low priority
Vulnerable

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Vulnerable Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-42772

Low priority
Vulnerable

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Vulnerable Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-84784

Low priority

Some fixes available 1 of 4

QUIC: Unbounded RETIRE_CONNECTION_ID Backlog

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-84783

Medium priority
Vulnerable

Use-After-Free in X.509 Extension Cache Under Concurrent Use

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Not affected Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Not affected Not affected Not affected Not affected Not affected
edk2-hwe Not affected Not in release Not in release — —
Show less packages

CVE-2026-84782

High priority

Some fixes available 8 of 18

DTLS Retransmits Handshake Messages From a Stale Buffer Offset

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-77696

Low priority

Some fixes available 8 of 18

Timing Side-Channel in SM2 Signature Generation

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-75806

Low priority

Some fixes available 3 of 18

Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Needs evaluation Needs evaluation
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-75805

Low priority

Some fixes available 3 of 7

NULL Pointer Dereference in CMP Client Revocation Response Handling

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-75804

Low priority

Some fixes available 1 of 4

QUIC Connection-Level Flow Control is Not Enforced for Streams

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-72897

Low priority

Some fixes available 1 of 4

Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages