CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability

Added products to the Security Updates table that document the various packaging methods used to deliver Azure MCP Server Tools.


CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation

Information published.


CVE-2026-3479 pkgutil.get_data() does not enforce documented restrictions

Information published.


CVE-2026-30922 pyasn1 Vulnerable to Denial of Service via Unbounded Recursion

Information published.


CVE-2026-3633 Libsoup: libsoup: header and http request injection via crlf injection

Information published.


CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames

Information published.


CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header

Information published.


CVE-2026-32766 astral-tokio-tar insufficiently validates PAX extensions during extraction

Information published.


CVE-2026-23276 net: add xmit recursion limit to tunnel xmit functions

Information published.


CVE-2026-23246 wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration

Information published.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge