VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
73925 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2026-69896 | microsoft_vex | Windows Error Reporting Elevation of Privilege Vulnerability | fixed: 8 known affected: 8 | 2026-10-13T07:00:00+00:00 | Vulnerability · Source |
| CVE-2026-33814 | redhat_vex | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame | fixed: 2322 known affected: 383 known not affected: 27853 under investigation: 496 | 2026-10-02T05:25:56+00:00 | Vulnerability · Source |
| CVE-2026-93748 | redhat_vex | http-cache-semantics: http-cache-semantics: Information Disclosure via max-stale directive | known affected: 204 known not affected: 10 | 2026-10-02T05:20:56+00:00 | Vulnerability · Source |
| CVE-2026-46597 | redhat_vex | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs | fixed: 497 known affected: 141 known not affected: 16993 | 2026-10-02T05:16:52+00:00 | Vulnerability · Source |
| CVE-2026-39829 | redhat_vex | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters | fixed: 1225 known affected: 101 known not affected: 10494 | 2026-10-02T05:16:52+00:00 | Vulnerability · Source |
| CVE-2026-63209 | redhat_vex | github.com/klauspost/compress: klauspost/compress: Denial of Service via integer overflow in dictionary processing | fixed: 96 known affected: 10 known not affected: 2 under investigation: 94 | 2026-10-02T05:13:34+00:00 | Vulnerability · Source |
| CVE-2026-73270 | redhat_vex | erlang: inets: Erlang/OTP inets httpd: Information disclosure via case-insensitive path bypass | fixed: 79 known affected: 84 | 2026-10-02T05:13:18+00:00 | Vulnerability · Source |
| CVE-2026-75538 | redhat_vex | erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver | fixed: 79 known affected: 84 | 2026-10-02T05:13:15+00:00 | Vulnerability · Source |
| CVE-2026-34582 | redhat_vex | botan: Botan: Client authentication bypass in TLS 1.3 implementation | known not affected: 2 | 2026-10-02T05:07:40+00:00 | Vulnerability · Source |
| CVE-2024-45341 | redhat_vex | golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints | fixed: 88 known affected: 797 | 2026-10-02T04:51:45+00:00 | Vulnerability · Source |
| CVE-2026-10051 | redhat_vex | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections | fixed: 48 known affected: 14 known not affected: 393 | 2026-10-02T04:51:16+00:00 | Vulnerability · Source |
| CVE-2026-80775 | redhat_vex | kernel: futex: Fix race on the initial mm->futex.phash.ref allocation | fixed: 303 known affected: 99 known not affected: 91 | 2026-10-02T04:51:10+00:00 | Vulnerability · Source |
| CVE-2026-63794 | redhat_vex | kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path | fixed: 303 known affected: 146 known not affected: 42 | 2026-10-02T04:51:07+00:00 | Vulnerability · Source |
| CVE-2026-45856 | redhat_vex | kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send | fixed: 303 known affected: 188 | 2026-10-02T04:51:06+00:00 | Vulnerability · Source |
| CVE-2026-25680 | redhat_vex | golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing | fixed: 152 known affected: 493 known not affected: 360 | 2026-10-02T04:47:38+00:00 | Vulnerability · Source |
| CVE-2025-61728 | redhat_vex | golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip | fixed: 7014 known affected: 113 known not affected: 4133 | 2026-10-02T04:47:28+00:00 | Vulnerability · Source |
| CVE-2025-58183 | redhat_vex | golang: archive/tar: Unbounded allocation when parsing GNU sparse map | fixed: 8922 known affected: 133 known not affected: 8346 | 2026-10-02T04:47:23+00:00 | Vulnerability · Source |
| CVE-2025-22870 | redhat_vex | golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | fixed: 329 known affected: 607 known not affected: 105 | 2026-10-02T04:47:22+00:00 | Vulnerability · Source |
| CVE-2024-7246 | redhat_vex | grpc: client communicating with a HTTP/2 proxy can poison the HPACK table between the proxy and the backend | fixed: 46 known affected: 1 known not affected: 4663 | 2026-10-02T04:47:22+00:00 | Vulnerability · Source |
| CVE-2024-24786 | redhat_vex | golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON | fixed: 2152 known affected: 112 known not affected: 11937 under investigation: 57 | 2026-10-02T04:43:19+00:00 | Vulnerability · Source |
| CVE-2024-4068 | redhat_vex | braces: fails to limit the number of characters it can handle | fixed: 191 known affected: 67 known not affected: 792 under investigation: 10 | 2026-10-02T04:43:13+00:00 | Vulnerability · Source |
| CVE-2023-45142 | redhat_vex | opentelemetry: DoS vulnerability in otelhttp | fixed: 1109 known affected: 138 known not affected: 8200 | 2026-10-02T04:43:09+00:00 | Vulnerability · Source |
| CVE-2022-41724 | redhat_vex | golang: crypto/tls: large handshake records may cause panics | fixed: 1726 known affected: 85 known not affected: 2714 | 2026-10-02T04:43:03+00:00 | Vulnerability · Source |
| CVE-2022-41723 | redhat_vex | golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding | fixed: 1556 known affected: 287 known not affected: 11951 | 2026-10-02T04:42:58+00:00 | Vulnerability · Source |
| CVE-2022-30631 | redhat_vex | golang: compress/gzip: stack exhaustion in Reader.Read | fixed: 4253 known affected: 91 known not affected: 2159 | 2026-10-02T04:42:56+00:00 | Vulnerability · Source |
| CVE-2026-42506 | redhat_vex | golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing | fixed: 152 known affected: 615 known not affected: 293 | 2026-10-02T04:42:15+00:00 | Vulnerability · Source |
| CVE-2026-33671 | redhat_vex | picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns | fixed: 189 known affected: 186 known not affected: 114 | 2026-10-02T04:42:11+00:00 | Vulnerability · Source |
| CVE-2026-4867 | redhat_vex | path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters | fixed: 12 known affected: 102 known not affected: 85 | 2026-10-02T04:42:08+00:00 | Vulnerability · Source |
| CVE-2025-68121 | redhat_vex | crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption | fixed: 8230 known affected: 186 known not affected: 9015 under investigation: 42 | 2026-10-02T04:41:09+00:00 | Vulnerability · Source |
| CVE-2026-42502 | redhat_vex | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering | fixed: 788 known affected: 239 known not affected: 5661 | 2026-10-02T04:41:03+00:00 | Vulnerability · Source |
| CVE-2026-32282 | redhat_vex | golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root | fixed: 1753 known affected: 175 known not affected: 2277 | 2026-10-02T04:38:42+00:00 | Vulnerability · Source |
| CVE-2026-32281 | redhat_vex | crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation | fixed: 2312 known affected: 168 known not affected: 2210 | 2026-10-02T04:34:28+00:00 | Vulnerability · Source |
| CVE-2021-20329 | redhat_vex | mongo-go-driver: specific cstrings input may not be properly validated | fixed: 252 known affected: 69 known not affected: 3782 | 2026-10-02T04:32:56+00:00 | Vulnerability · Source |
| CVE-2026-84292 | redhat_vex | fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization | fixed: 112 known affected: 81 known not affected: 1191 | 2026-10-02T04:32:33+00:00 | Vulnerability · Source |
| CVE-2026-47888 | redhat_vex | Spring Framework: Spring Framework: Memory leak via malformed RSocket SETUP frame | known affected: 12 known not affected: 117 | 2026-10-02T04:32:29+00:00 | Vulnerability · Source |
| CVE-2026-17615 | redhat_vex | resteasy-core: RESTeasy SourceProvider remote unauthenticated file read | fixed: 15 known affected: 8 known not affected: 7 | 2026-10-02T04:32:20+00:00 | Vulnerability · Source |
| CVE-2026-12816 | redhat_vex | org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Message Authentication Code (MAC) forgery due to a length-dependent Key Derivation Function (KDF) split | known affected: 22 known not affected: 10 under investigation: 19 | 2026-10-02T04:32:16+00:00 | Vulnerability · Source |
| CVE-2026-42035 | redhat_vex | axios: Axios: Arbitrary HTTP header injection via prototype pollution | fixed: 171 known affected: 39 known not affected: 2577 | 2026-10-02T04:32:08+00:00 | Vulnerability · Source |
| CVE-2026-56862 | redhat_vex | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages | fixed: 7271 known affected: 269 known not affected: 3401 | 2026-10-02T04:29:10+00:00 | Vulnerability · Source |
| CVE-2026-56860 | redhat_vex | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution | fixed: 7332 known affected: 276 known not affected: 3544 | 2026-10-02T04:28:41+00:00 | Vulnerability · Source |
| CVE-2026-56858 | redhat_vex | html/template: golang: Go html/template: Cross-Site Scripting via pathological input | fixed: 6772 known affected: 215 known not affected: 3263 | 2026-10-02T04:28:34+00:00 | Vulnerability · Source |
| CVE-2026-33818 | redhat_vex | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal | fixed: 7254 known affected: 200 known not affected: 2931 | 2026-10-02T04:28:32+00:00 | Vulnerability · Source |
| CVE-2026-63622 | redhat_vex | libvirt: swtpm privilege escalation via symlink following | fixed: 4136 known affected: 65 known not affected: 6 | 2026-10-02T04:28:23+00:00 | Vulnerability · Source |
| CVE-2026-18917 | redhat_vex | libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow | fixed: 4136 known affected: 65 known not affected: 6 | 2026-10-02T04:28:14+00:00 | Vulnerability · Source |
| CVE-2026-55193 | redhat_vex | FreeRDP: FreeRDP: Remote code execution or client crash via malicious TS Gateway | fixed: 594 known affected: 5 | 2026-10-02T04:28:10+00:00 | Vulnerability · Source |
| CVE-2026-0799 | redhat_vex | libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access | fixed: 56 known affected: 9 | 2026-10-02T04:28:04+00:00 | Vulnerability · Source |
| CVE-2026-34986 | redhat_vex | github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object | fixed: 2999 known affected: 144 known not affected: 16904 | 2026-10-02T04:27:25+00:00 | Vulnerability · Source |
| CVE-2026-56859 | redhat_vex | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue | fixed: 6850 known affected: 248 known not affected: 3466 | 2026-10-02T04:27:25+00:00 | Vulnerability · Source |
| CVE-2026-39821 | redhat_vex | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing | fixed: 2037 known affected: 153 known not affected: 4815 | 2026-10-02T04:27:15+00:00 | Vulnerability · Source |
| CVE-2026-33810 | redhat_vex | crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application | fixed: 1017 known affected: 174 known not affected: 1442 | 2026-10-02T04:26:54+00:00 | Vulnerability · Source |