Search CVE reports


Toggle filters

1381 – 1390 of 47438 results

Status is adjusted based on your filters.


CVE-2026-19672

Medium priority
Needs evaluation

The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.14
Show all 11 packages Show less packages

CVE-2026-49289

Medium priority
Needs evaluation

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages....

1 affected package

simplesamlphp

Package 20.04 LTS
simplesamlphp Needs evaluation
Show less packages

CVE-2026-49283

Medium priority
Needs evaluation

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as...

1 affected package

simplesamlphp

Package 20.04 LTS
simplesamlphp Needs evaluation
Show less packages

CVE-2026-48711

Medium priority
Needs evaluation

SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() removes the brackets, leaving a host...

1 affected package

sshfs-fuse

Package 20.04 LTS
sshfs-fuse Needs evaluation
Show less packages

CVE-2026-47187

Medium priority
Needs evaluation

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes...

1 affected package

sshfs-fuse

Package 20.04 LTS
sshfs-fuse Needs evaluation
Show less packages

CVE-2026-76222

Medium priority
Needs evaluation

GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-76221

Medium priority
Needs evaluation

GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-76220

Medium priority
Needs evaluation

GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-76219

Medium priority
Needs evaluation

GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-76218

Medium priority
Needs evaluation

GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages