Количество 116
Количество 116
RLSA-2026:35828
Important: grafana security update
RLSA-2026:35827
Important: grafana security update
SUSE-SU-2026:2285-1
Security update for yq
RLSA-2026:34359
Important: opentelemetry-collector security update
RLSA-2026:34357
Important: opentelemetry-collector security update
openSUSE-SU-2026:20892-1
Security update for yq
CVE-2026-25681
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVE-2026-25681
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVE-2026-25681
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVE-2026-25681
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVE-2026-25681
Parsing arbitrary HTML which is then rendered using Render can result ...
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...
openSUSE-SU-2026:21120-1
Security update for mcphost
openSUSE-SU-2026:20956-1
Security update for trivy
SUSE-SU-2026:3203-1
Security update for kubevirt
SUSE-SU-2026:2733-1
Security update for buildah
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:35828 Important: grafana security update | 24 дня назад | |||
RLSA-2026:35827 Important: grafana security update | 24 дня назад | |||
SUSE-SU-2026:2285-1 Security update for yq | около 2 месяцев назад | |||
RLSA-2026:34359 Important: opentelemetry-collector security update | 26 дней назад | |||
RLSA-2026:34357 Important: opentelemetry-collector security update | 24 дня назад | |||
openSUSE-SU-2026:20892-1 Security update for yq | около 2 месяцев назад | |||
CVE-2026-25681 Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-25681 Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | CVSS3: 8.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-25681 Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-25681 Parsing arbitrary HTML which is then rendered using Render can result ... | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 9.6 | 1% Низкий | 2 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 8.2 | 1% Низкий | 2 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 9.6 | 1% Низкий | 2 месяца назад | |
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CVSS3: 10 | 1% Низкий | 2 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ... | CVSS3: 9.6 | 1% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21120-1 Security update for mcphost | около 1 месяца назад | |||
openSUSE-SU-2026:20956-1 Security update for trivy | около 2 месяцев назад | |||
SUSE-SU-2026:3203-1 Security update for kubevirt | 8 дней назад | |||
SUSE-SU-2026:2733-1 Security update for buildah | 28 дней назад |
Уязвимостей на страницу