Search CVE reports


Toggle filters

291 – 300 of 32959 results

Status is adjusted based on your filters.


CVE-2026-67317

Medium priority
Needs evaluation

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-67316

Medium priority
Needs evaluation

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-67315

Medium priority
Needs evaluation

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-67314

Medium priority
Needs evaluation

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-67313

Medium priority
Needs evaluation

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-67312

Medium priority
Needs evaluation

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type:...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-67306

Medium priority
Needs evaluation

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c. Only...

3 affected packages

freerdp, freerdp2, freerdp3

Package 26.04 LTS
freerdp Not in release
freerdp2 Not in release
freerdp3 Needs evaluation
Show less packages

CVE-2026-67305

Medium priority
Needs evaluation

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the...

3 affected packages

freerdp, freerdp2, freerdp3

Package 26.04 LTS
freerdp Not in release
freerdp2 Not in release
freerdp3 Needs evaluation
Show less packages

CVE-2026-67304

Medium priority
Needs evaluation

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and...

3 affected packages

freerdp, freerdp2, freerdp3

Package 26.04 LTS
freerdp Not in release
freerdp2 Not in release
freerdp3 Needs evaluation
Show less packages

CVE-2026-67303

Medium priority
Needs evaluation

FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_process_irp_device_control() in channels/serial/client/serial_main.c. When serial device redirection is enabled and...

3 affected packages

freerdp, freerdp2, freerdp3

Package 26.04 LTS
freerdp Not in release
freerdp2 Not in release
freerdp3 Needs evaluation
Show less packages