2026 CVE Vulnerabilities

57,064 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50812MEDIUM5.5A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807...
CVE-2026-14362MEDIUM4.9HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling tha...
CVE-2026-60102HIGH8.8Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb dri...
CVE-2026-59930MEDIUM4.3Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents direc...
CVE-2026-59929MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/rende...
CVE-2026-59928HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repe...
CVE-2026-59927MEDIUM5.3Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/dir...
CVE-2026-59926MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/direc...
CVE-2026-59925HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-ast...
CVE-2026-59924MEDIUM5.9Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes use...
CVE-2026-59923MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block p...
CVE-2026-59922HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or c...
CVE-2026-59897MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS...
CVE-2026-59896MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/j...
CVE-2026-59895MEDIUM6.1Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in...
CVE-2026-59892HIGH7.5OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode...
CVE-2026-59890MEDIUM6.1setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to ...
CVE-2026-59887HIGH7.5linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used b...
CVE-2026-59883MEDIUM6.1Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar...
CVE-2026-59882MEDIUM6.5guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not ...
CVE-2026-59879HIGH7.5Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#...
CVE-2026-59731HIGH8.2Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco...
CVE-2026-59261MEDIUM6.5OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide...
CVE-2026-42505MEDIUM5.3Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of...
CVE-2026-39822HIGH7.8On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now