2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100662 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled reso... |
| CVE-2026-100661 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service ... |
| CVE-2026-100660 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPA... |
| CVE-2026-100659 | MEDIUM | 6.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC ... |
| CVE-2026-100658 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2026-100657 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2026-100656 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2026-100655 | — | — | — | Sep 26, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2026-100654 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/cha... |
| CVE-2026-100653 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-... |
| CVE-2026-100652 | MEDIUM | 5.9 | — | Sep 26, 2026 | vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC fron... |
| CVE-2026-100651 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1... |
| CVE-2026-100650 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls... |
| CVE-2026-100649 | LOW | 3.7 | — | Sep 26, 2026 | vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler sub... |
| CVE-2026-100648 | MEDIUM | 5.3 | — | Sep 26, 2026 | vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing un... |
| CVE-2026-100647 | MEDIUM | 5.3 | — | Sep 26, 2026 | vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-com... |
| CVE-2026-100646 | HIGH | 8.1 | — | Sep 26, 2026 | SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authen... |
| CVE-2026-100645 | HIGH | 8 | — | Sep 26, 2026 | SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database re... |
| CVE-2026-100644 | HIGH | 7.5 | — | Sep 26, 2026 | SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath para... |
| CVE-2026-100643 | HIGH | 8 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing a... |
| CVE-2026-100642 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-scree... |
| CVE-2026-100641 | HIGH | 8 | — | Sep 26, 2026 | SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager l... |
| CVE-2026-100640 | MEDIUM | 4.7 | — | Sep 26, 2026 | SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderer... |
| CVE-2026-100639 | HIGH | 8.8 | — | Sep 26, 2026 | SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutt... |
| CVE-2026-100638 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now