Search CVE reports


Toggle filters

121 – 130 of 37368 results

Status is adjusted based on your filters.


CVE-2026-33940

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause...

1 affected package

node-handlebars

Package 22.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33939

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the...

1 affected package

node-handlebars

Package 22.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33938

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within...

1 affected package

node-handlebars

Package 22.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33937

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a...

1 affected package

node-handlebars

Package 22.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33916

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials`...

1 affected package

node-handlebars

Package 22.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33896

Medium priority
Needs evaluation

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an...

1 affected package

node-node-forge

Package 22.04 LTS
node-node-forge Needs evaluation
Show less packages

CVE-2026-33895

Medium priority
Needs evaluation

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not...

1 affected package

node-node-forge

Package 22.04 LTS
node-node-forge Needs evaluation
Show less packages

CVE-2026-33894

Medium priority
Needs evaluation

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3)....

1 affected package

node-node-forge

Package 22.04 LTS
node-node-forge Needs evaluation
Show less packages

CVE-2026-33891

Medium priority
Needs evaluation

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the...

1 affected package

node-node-forge

Package 22.04 LTS
node-node-forge Needs evaluation
Show less packages

CVE-2026-34475

Medium priority
Needs evaluation

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

1 affected package

varnish

Package 22.04 LTS
varnish Needs evaluation
Show less packages