2026 CVE Vulnerabilities

70,269 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2833CRITICAL9.1An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The i...
CVE-2026-22052MEDIUM4.3ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Success...
CVE-2026-2297MEDIUM5.7The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (...
CVE-2026-29086MEDIUM5.4Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCo...
CVE-2026-29085MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin...
CVE-2026-29045CRITICAL9.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin...
CVE-2026-26002CRITICAL9.8Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4...
CVE-2026-29000CRITICAL9.1pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator w...
CVE-2026-27898MEDIUM5.4Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi...
CVE-2026-27803HIGH8.3Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi...
CVE-2026-27802HIGH8.3Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi...
CVE-2026-27801MEDIUM5.9Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve...
CVE-2026-25750HIGH8.1Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm ver...
CVE-2026-22040MEDIUM5.3NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffi...
CVE-2026-3545CRITICAL9.6Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potenti...
CVE-2026-3544HIGH8.8Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out o...
CVE-2026-3543HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially per...
CVE-2026-3542HIGH8.8Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perfor...
CVE-2026-3541HIGH8.8Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out...
CVE-2026-3540HIGH8.8Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform o...
CVE-2026-3539——Rejected reason: Determined a bug and not a vulnerability
CVE-2026-3538HIGH8.8Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out o...
CVE-2026-3537HIGH8.8Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to poten...
CVE-2026-3536HIGH8.8Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out ...
CVE-2026-28435HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now