CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Information published.


CVE-2026-5160

Information published.


CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks

Information published.


CVE-2026-33055 tar-rs incorrectly ignores PAX size headers if header size is nonzero

Information published.


Chromium: CVE-2026-6307 Type Confusion in Turbofan

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.


CVE-2026-40164 jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed

Information published.


CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers

Information published.


CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input

Information published.


CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()

Information published.


CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow

Information published.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge