2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100662HIGH7.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled reso...
CVE-2026-100661HIGH7.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service ...
CVE-2026-100660HIGH7.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPA...
CVE-2026-100659MEDIUM6.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC ...
CVE-2026-100658——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-100657——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-100656——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-100655——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-100654MEDIUM6.5vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/cha...
CVE-2026-100653MEDIUM6.5vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-...
CVE-2026-100652MEDIUM5.9vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC fron...
CVE-2026-100651MEDIUM6.5vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1...
CVE-2026-100650MEDIUM6.5vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls...
CVE-2026-100649LOW3.7vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler sub...
CVE-2026-100648MEDIUM5.3vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing un...
CVE-2026-100647MEDIUM5.3vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-com...
CVE-2026-100646HIGH8.1SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authen...
CVE-2026-100645HIGH8SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database re...
CVE-2026-100644HIGH7.5SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath para...
CVE-2026-100643HIGH8SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing a...
CVE-2026-100642HIGH7.6SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-scree...
CVE-2026-100641HIGH8SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager l...
CVE-2026-100640MEDIUM4.7SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderer...
CVE-2026-100639HIGH8.8SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutt...
CVE-2026-100638HIGH7.6SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authent...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now