2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42501HIGH7.5A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa...
CVE-2026-42499HIGH7.5Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-42259MEDIUM5.1Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-...
CVE-2026-42241MEDIUM5.3ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0....
CVE-2026-42239HIGH8.1Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess...
CVE-2026-42225MEDIUM5.9PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, ...
CVE-2026-39836HIGH7.5The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
CVE-2026-39826MEDIUM6.1If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit...
CVE-2026-39825MEDIUM5.3ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi...
CVE-2026-39823MEDIUM6.1CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu...
CVE-2026-39820HIGH7.5Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion...
CVE-2026-39819MEDIUM5.3The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp")....
CVE-2026-39817MEDIUM5.9The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa...
CVE-2026-33814HIGH7.5When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei...
CVE-2026-33811HIGH7.5When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a...
CVE-2026-8086HIGH7.8A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file f...
CVE-2026-8084MEDIUM5.5A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the f...
CVE-2026-8083HIGH7.3A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the...
CVE-2026-44742MEDIUM6.1Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as e...
CVE-2026-44244HIGH7.8GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value...
CVE-2026-44243HIGH7.1GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPyt...
CVE-2026-42284CRITICAL9.8GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_...
CVE-2026-42215HIGH8.8GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP...
CVE-2026-42214HIGH7.8Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFrom...
CVE-2026-41906HIGH7.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now