Month: April 2026
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
CVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
CVE-2026-35201 Discount has an Out-of-bounds Read in rdiscount
Information published. Continue reading CVE-2026-35201 Discount has an Out-of-bounds Read in rdiscount
CVE-2026-1502 HTTP client proxy tunnel headers not validated for CR/LF
Information published. Continue reading CVE-2026-1502 HTTP client proxy tunnel headers not validated for CR/LF
CVE-2026-5446 wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse
Information published. Continue reading CVE-2026-5446 wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse
CVE-2026-5392 wolfSSL heap OOB read in PKCS7 SignedData streaming
Information published. Continue reading CVE-2026-5392 wolfSSL heap OOB read in PKCS7 SignedData streaming
CVE-2026-5263 URI nameConstraints not enforced in ConfirmNameConstraints()
Information published. Continue reading CVE-2026-5263 URI nameConstraints not enforced in ConfirmNameConstraints()
