Month: April 2026
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo
CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo
CVE-2026-35611 Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
Chromium: CVE-2026-5919 Insufficient validation of untrusted input in WebSockets
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Continue reading Chromium: CVE-2026-5919 Insufficient validation of untrusted input in WebSockets
Chromium: CVE-2026-5918 Inappropriate implementation in Navigation
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Continue reading Chromium: CVE-2026-5918 Inappropriate implementation in Navigation
