2026 CVE Vulnerabilities

60,210 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56109HIGH7The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()...
CVE-2026-55602HIGH8.6http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middlewar...
CVE-2026-55388HIGH8.1piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() ...
CVE-2026-54290HIGH7.1Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials...
CVE-2026-54289MEDIUM4.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Ed...
CVE-2026-54287MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t...
CVE-2026-54286MEDIUM5.9Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts...
CVE-2026-54285MEDIUM5.3opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetr...
CVE-2026-54283HIGH7.5Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_par...
CVE-2026-54282MEDIUM5.3Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being u...
CVE-2026-54280HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are n...
CVE-2026-54279HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that ...
CVE-2026-54278HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is po...
CVE-2026-54277HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypas...
CVE-2026-54276MEDIUM6.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca...
CVE-2026-54275HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS...
CVE-2026-54274HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends la...
CVE-2026-54273HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on...
CVE-2026-54271HIGH8.2protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name hand...
CVE-2026-54270MEDIUM5.3protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unkno...
CVE-2026-54269MEDIUM5.3protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted c...
CVE-2026-53632MEDIUM5.5launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP...
CVE-2026-53571HIGH7.5Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are s...
CVE-2026-53540LOW3.7Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-...
CVE-2026-53539HIGH7.5Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlenc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now