2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7532HIGH7.5iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced ...
CVE-2026-7511HIGH7.5PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bo...
CVE-2026-6331HIGH7.5HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC ve...
CVE-2026-6330MEDIUM6.5The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i...
CVE-2026-6329MEDIUM6.5PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all...
CVE-2026-6325HIGH7.5Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write pas...
CVE-2026-6092MEDIUM5.3When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing E...
CVE-2026-55962MEDIUM6.5TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl...
CVE-2026-54479HIGH7.3The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-50176HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-44622MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-40702CRITICAL9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res...
CVE-2026-22879HIGH8.1vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability
CVE-2026-13283HIGH7.5Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a...
CVE-2026-13282MEDIUM6.8Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e...
CVE-2026-13281HIGH8.3Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the rend...
CVE-2026-12992HIGH7.4A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.ws...
CVE-2026-12975HIGH8.5A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena...
CVE-2026-11800HIGH8.1A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an a...
CVE-2026-11703HIGH7.5Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for t...
CVE-2026-10098MEDIUM5.3OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se...
CVE-2026-6731HIGH7.5X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN...
CVE-2026-6681MEDIUM5.3The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written...
CVE-2026-6679HIGH7.5A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T...
CVE-2026-6678MEDIUM5.3Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now