2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-97025LOW3.2Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cac...
CVE-2026-91096——In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destr...
CVE-2026-91095——In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::...
CVE-2026-84895——In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calli...
CVE-2026-18416LOW3.7The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource pa...
CVE-2026-18415MEDIUM6.3ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte trans...
CVE-2026-18414HIGH7.8The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi...
CVE-2026-18413HIGH7.8The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi...
CVE-2026-16513HIGH7.8The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c...
CVE-2026-102279LOW3.1Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true ...
CVE-2026-102278HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3...
CVE-2026-102277MEDIUM5.3The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3...
CVE-2026-102276HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3...
CVE-2026-102275MEDIUM6.5PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in j...
CVE-2026-102274MEDIUM5.9PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain...
CVE-2026-102273HIGH7.4PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key ...
CVE-2026-102272HIGH7.4PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt...
CVE-2026-102271HIGH7.4PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key i...
CVE-2026-102270MEDIUM4.4PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because l...
CVE-2026-102269MEDIUM4.8PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected becau...
CVE-2026-102268CRITICAL9.1PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
CVE-2026-102267HIGH7.4PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because red...
CVE-2026-102266HIGH7.4PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affect...
CVE-2026-102265MEDIUM5.3PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is...
CVE-2026-102006MEDIUM5.5In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem fa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now