VEX records

Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.

Reset

73927 VEX records

API response
Vulnerability Source Title Product status Imported Links
CVE-2026-39919 redhat_vex ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter fixed: 9 known affected: 22 known not affected: 125 2026-10-02T07:26:07+00:00 Vulnerability · Source
CVE-2026-69097 redhat_vex gitpython: GitPython: Remote Code Execution via Config Injection in Submodule Names known affected: 42 known not affected: 36 2026-10-02T07:20:54+00:00 Vulnerability · Source
CVE-2026-45292 redhat_vex opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage fixed: 29 known affected: 26 known not affected: 439 under investigation: 4 2026-10-02T06:58:39+00:00 Vulnerability · Source
CVE-2026-52945 redhat_vex kernel: Revert "wireguard: device: enable threaded NAPI" known affected: 184 known not affected: 90 2026-10-02T06:48:40+00:00 Vulnerability · Source
CVE-2026-93748 redhat_vex http-cache-semantics: http-cache-semantics: Information Disclosure via max-stale directive known affected: 204 known not affected: 10 2026-10-02T05:20:56+00:00 Vulnerability · Source
CVE-2026-46597 redhat_vex golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs fixed: 497 known affected: 141 known not affected: 16993 2026-10-02T05:16:52+00:00 Vulnerability · Source
CVE-2026-63209 redhat_vex github.com/klauspost/compress: klauspost/compress: Denial of Service via integer overflow in dictionary processing fixed: 96 known affected: 10 known not affected: 2 under investigation: 94 2026-10-02T05:13:34+00:00 Vulnerability · Source
CVE-2026-73270 redhat_vex erlang: inets: Erlang/OTP inets httpd: Information disclosure via case-insensitive path bypass fixed: 79 known affected: 84 2026-10-02T05:13:18+00:00 Vulnerability · Source
CVE-2026-75538 redhat_vex erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver fixed: 79 known affected: 84 2026-10-02T05:13:15+00:00 Vulnerability · Source
CVE-2026-34582 redhat_vex botan: Botan: Client authentication bypass in TLS 1.3 implementation known not affected: 2 2026-10-02T05:07:40+00:00 Vulnerability · Source
CVE-2024-45341 redhat_vex golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints fixed: 88 known affected: 797 2026-10-02T04:51:45+00:00 Vulnerability · Source
CVE-2026-10051 redhat_vex jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections fixed: 48 known affected: 14 known not affected: 393 2026-10-02T04:51:16+00:00 Vulnerability · Source
CVE-2026-80775 redhat_vex kernel: futex: Fix race on the initial mm->futex.phash.ref allocation fixed: 303 known affected: 99 known not affected: 91 2026-10-02T04:51:10+00:00 Vulnerability · Source
CVE-2026-63794 redhat_vex kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path fixed: 303 known affected: 146 known not affected: 42 2026-10-02T04:51:07+00:00 Vulnerability · Source
CVE-2026-45856 redhat_vex kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send fixed: 303 known affected: 188 2026-10-02T04:51:06+00:00 Vulnerability · Source
CVE-2026-25680 redhat_vex golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing fixed: 152 known affected: 493 known not affected: 360 2026-10-02T04:47:38+00:00 Vulnerability · Source
CVE-2025-61728 redhat_vex golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip fixed: 7014 known affected: 113 known not affected: 4133 2026-10-02T04:47:28+00:00 Vulnerability · Source
CVE-2025-22870 redhat_vex golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net fixed: 329 known affected: 607 known not affected: 105 2026-10-02T04:47:22+00:00 Vulnerability · Source
CVE-2024-7246 redhat_vex grpc: client communicating with a HTTP/2 proxy can poison the HPACK table between the proxy and the backend fixed: 46 known affected: 1 known not affected: 4663 2026-10-02T04:47:22+00:00 Vulnerability · Source
CVE-2024-4068 redhat_vex braces: fails to limit the number of characters it can handle fixed: 191 known affected: 67 known not affected: 792 under investigation: 10 2026-10-02T04:43:13+00:00 Vulnerability · Source
CVE-2023-45142 redhat_vex opentelemetry: DoS vulnerability in otelhttp fixed: 1109 known affected: 138 known not affected: 8200 2026-10-02T04:43:09+00:00 Vulnerability · Source
CVE-2022-41724 redhat_vex golang: crypto/tls: large handshake records may cause panics fixed: 1726 known affected: 85 known not affected: 2714 2026-10-02T04:43:03+00:00 Vulnerability · Source
CVE-2022-41723 redhat_vex golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding fixed: 1556 known affected: 287 known not affected: 11951 2026-10-02T04:42:58+00:00 Vulnerability · Source
CVE-2026-42506 redhat_vex golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing fixed: 152 known affected: 615 known not affected: 293 2026-10-02T04:42:15+00:00 Vulnerability · Source
CVE-2026-33671 redhat_vex picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns fixed: 189 known affected: 186 known not affected: 114 2026-10-02T04:42:11+00:00 Vulnerability · Source
CVE-2026-4867 redhat_vex path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters fixed: 12 known affected: 102 known not affected: 85 2026-10-02T04:42:08+00:00 Vulnerability · Source
CVE-2025-68121 redhat_vex crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption fixed: 8230 known affected: 186 known not affected: 9015 under investigation: 42 2026-10-02T04:41:09+00:00 Vulnerability · Source
CVE-2026-32282 redhat_vex golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root fixed: 1753 known affected: 175 known not affected: 2277 2026-10-02T04:38:42+00:00 Vulnerability · Source
CVE-2026-32281 redhat_vex crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation fixed: 2312 known affected: 168 known not affected: 2210 2026-10-02T04:34:28+00:00 Vulnerability · Source
CVE-2026-84292 redhat_vex fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization fixed: 112 known affected: 81 known not affected: 1191 2026-10-02T04:32:33+00:00 Vulnerability · Source
CVE-2026-47888 redhat_vex Spring Framework: Spring Framework: Memory leak via malformed RSocket SETUP frame known affected: 12 known not affected: 117 2026-10-02T04:32:29+00:00 Vulnerability · Source
CVE-2026-17615 redhat_vex resteasy-core: RESTeasy SourceProvider remote unauthenticated file read fixed: 15 known affected: 8 known not affected: 7 2026-10-02T04:32:20+00:00 Vulnerability · Source
CVE-2026-12816 redhat_vex org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Message Authentication Code (MAC) forgery due to a length-dependent Key Derivation Function (KDF) split known affected: 22 known not affected: 10 under investigation: 19 2026-10-02T04:32:16+00:00 Vulnerability · Source
CVE-2026-42035 redhat_vex axios: Axios: Arbitrary HTTP header injection via prototype pollution fixed: 171 known affected: 39 known not affected: 2577 2026-10-02T04:32:08+00:00 Vulnerability · Source
CVE-2026-56862 redhat_vex crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages fixed: 7271 known affected: 269 known not affected: 3401 2026-10-02T04:29:10+00:00 Vulnerability · Source
CVE-2026-63622 redhat_vex libvirt: swtpm privilege escalation via symlink following fixed: 4136 known affected: 65 known not affected: 6 2026-10-02T04:28:23+00:00 Vulnerability · Source
CVE-2026-18917 redhat_vex libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow fixed: 4136 known affected: 65 known not affected: 6 2026-10-02T04:28:14+00:00 Vulnerability · Source
CVE-2026-55193 redhat_vex FreeRDP: FreeRDP: Remote code execution or client crash via malicious TS Gateway fixed: 594 known affected: 5 2026-10-02T04:28:10+00:00 Vulnerability · Source
CVE-2026-0799 redhat_vex libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access fixed: 56 known affected: 9 2026-10-02T04:28:04+00:00 Vulnerability · Source
CVE-2026-39821 redhat_vex golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing fixed: 2037 known affected: 153 known not affected: 4815 2026-10-02T04:27:15+00:00 Vulnerability · Source
CVE-2026-32280 redhat_vex crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building fixed: 4575 known affected: 133 known not affected: 7225 2026-10-02T04:26:35+00:00 Vulnerability · Source
CVE-2026-42504 redhat_vex mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header fixed: 4730 known affected: 106 known not affected: 6283 2026-10-02T04:26:10+00:00 Vulnerability · Source
CVE-2026-32141 redhat_vex flatted: flatted: Unbounded recursion DoS in parse() revive phase fixed: 31 known affected: 21 known not affected: 283 2026-10-02T04:22:02+00:00 Vulnerability · Source
CVE-2026-29063 redhat_vex immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fixed: 498 known affected: 34 known not affected: 12737 2026-10-02T04:21:47+00:00 Vulnerability · Source
CVE-2026-13676 redhat_vex fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fixed: 386 known affected: 38 known not affected: 5293 2026-10-02T04:21:03+00:00 Vulnerability · Source
CVE-2026-12143 redhat_vex form-data: form-data: Form field override via CRLF injection fixed: 495 known affected: 39 known not affected: 8567 2026-10-02T04:20:58+00:00 Vulnerability · Source
CVE-2025-66506 redhat_vex github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fixed: 329 known affected: 42 known not affected: 1297 2026-10-02T04:20:35+00:00 Vulnerability · Source
CVE-2025-66471 redhat_vex urllib3: urllib3 Streaming API improperly handles highly compressed data fixed: 1965 known affected: 126 known not affected: 3875 2026-10-02T04:20:20+00:00 Vulnerability · Source
CVE-2025-66418 redhat_vex urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion fixed: 1992 known affected: 379 known not affected: 2959 2026-10-02T04:20:13+00:00 Vulnerability · Source
CVE-2025-64756 redhat_vex glob: glob: Command Injection Vulnerability via Malicious Filenames fixed: 171 known affected: 115 known not affected: 1099 2026-10-02T04:19:58+00:00 Vulnerability · Source