2026 CVE Vulnerabilities

45,891 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41727MEDIUM6.5Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on t...
CVE-2026-41726MEDIUM6.5When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r...
CVE-2026-41721MEDIUM5.9Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup...
CVE-2026-41719MEDIUM6.4A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a rep...
CVE-2026-41714MEDIUM4Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also c...
CVE-2026-41711MEDIUM5.9Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowE...
CVE-2026-41706MEDIUM6.1Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser ...
CVE-2026-41701MEDIUM4.4Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to int...
CVE-2026-41697MEDIUM4.8Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (...
CVE-2026-41696MEDIUM5.9Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient...
CVE-2026-41694MEDIUM5.3Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou...
CVE-2026-41008MEDIUM6.1Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame...
CVE-2026-41003MEDIUM5.4An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat...
CVE-2026-40991MEDIUM5.9When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an ...
CVE-2026-9751MEDIUM6.8The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon...
CVE-2026-9742MEDIUM5.9When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th...
CVE-2026-9735MEDIUM6.8MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W...
CVE-2026-46433MEDIUM6.5lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips ...
CVE-2026-47905MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47904MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47903MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v...
CVE-2026-47902MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-34657MEDIUM5.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pa...
CVE-2026-34417MEDIUM6.1OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2026-25860MEDIUM6.1OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now