VEX records

Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.

Reset

73960 VEX records

API response
Vulnerability Source Title Product status Imported Links
CVE-2026-29063 redhat_vex immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fixed: 498 known affected: 34 known not affected: 12737 2026-10-02T04:21:47+00:00 Vulnerability · Source
CVE-2026-13676 redhat_vex fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fixed: 386 known affected: 38 known not affected: 5293 2026-10-02T04:21:03+00:00 Vulnerability · Source
CVE-2025-62718 redhat_vex axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization fixed: 162 known affected: 62 known not affected: 1807 2026-10-02T04:19:52+00:00 Vulnerability · Source
CVE-2024-52011 redhat_vex launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization fixed: 8 known not affected: 145 2026-10-02T04:17:36+00:00 Vulnerability · Source
CVE-2026-27145 redhat_vex crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries fixed: 1083 known affected: 74 known not affected: 5346 2026-10-02T04:16:30+00:00 Vulnerability · Source
CVE-2026-40895 redhat_vex follow-redirects: follow-redirects: Information disclosure via cross-domain redirects fixed: 218 known affected: 39 known not affected: 6475 2026-10-02T04:06:49+00:00 Vulnerability · Source
CVE-2026-39831 redhat_vex golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check fixed: 402 known affected: 136 known not affected: 5964 2026-10-02T04:06:38+00:00 Vulnerability · Source
CVE-2026-33896 redhat_vex node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance fixed: 8 known affected: 19 known not affected: 344 2026-10-02T04:05:43+00:00 Vulnerability · Source
CVE-2026-33895 redhat_vex node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures fixed: 8 known affected: 13 known not affected: 350 2026-10-02T04:05:38+00:00 Vulnerability · Source
CVE-2026-33894 redhat_vex node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification fixed: 33 known affected: 16 known not affected: 496 2026-10-02T04:05:31+00:00 Vulnerability · Source
CVE-2026-33891 redhat_vex node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() fixed: 10 known affected: 14 known not affected: 595 2026-10-02T04:05:09+00:00 Vulnerability · Source
CVE-2026-33811 redhat_vex net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME fixed: 1835 known affected: 138 known not affected: 8314 2026-10-02T04:04:28+00:00 Vulnerability · Source
CVE-2026-33228 redhat_vex flatted: Flatted: Prototype pollution vulnerability allows arbitrary code execution via crafted JSON. fixed: 14 known affected: 11 known not affected: 181 2026-10-02T04:04:07+00:00 Vulnerability · Source
CVE-2026-6322 redhat_vex fast-uri: fast-uri: URI authority bypass due to improper delimiter handling fixed: 628 known affected: 29 known not affected: 6954 2026-10-02T04:03:01+00:00 Vulnerability · Source
CVE-2026-4800 redhat_vex lodash: lodash: Arbitrary code execution via untrusted input in template imports fixed: 1010 known affected: 113 known not affected: 10848 2026-10-02T04:02:47+00:00 Vulnerability · Source
CVE-2026-55677 redhat_vex github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy fixed: 234 known affected: 1 known not affected: 721 2026-10-02T04:02:33+00:00 Vulnerability · Source
CVE-2026-27137 redhat_vex crypto/x509: Incorrect enforcement of email constraints in crypto/x509 fixed: 540 known affected: 170 known not affected: 1317 2026-10-02T03:59:50+00:00 Vulnerability · Source
CVE-2026-48779 redhat_vex ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments fixed: 613 known affected: 39 known not affected: 1178 2026-10-02T03:57:28+00:00 Vulnerability · Source
CVE-2026-12151 redhat_vex undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames fixed: 660 known affected: 13 known not affected: 2342 2026-10-02T03:56:19+00:00 Vulnerability · Source
CVE-2026-9697 redhat_vex undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy fixed: 437 known affected: 13 known not affected: 2327 2026-10-02T03:55:39+00:00 Vulnerability · Source
CVE-2026-6734 redhat_vex undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing fixed: 429 known affected: 12 known not affected: 1027 2026-10-02T03:55:06+00:00 Vulnerability · Source
CVE-2026-46595 redhat_vex golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation fixed: 307 known affected: 58 known not affected: 2269 2026-10-02T03:54:12+00:00 Vulnerability · Source
CVE-2026-42508 redhat_vex golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey fixed: 1077 known affected: 50 known not affected: 2434 2026-10-02T03:53:48+00:00 Vulnerability · Source
CVE-2026-39832 redhat_vex golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions fixed: 1022 known affected: 65 known not affected: 2524 2026-10-02T03:53:10+00:00 Vulnerability · Source
CVE-2026-35469 redhat_vex Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code fixed: 588 known affected: 53 known not affected: 24282 2026-10-02T03:50:50+00:00 Vulnerability · Source
CVE-2026-6321 redhat_vex fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fixed: 672 known affected: 11 known not affected: 1216 2026-10-02T03:38:14+00:00 Vulnerability · Source
CVE-2026-9277 redhat_vex shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators fixed: 167 known affected: 19 known not affected: 7976 2026-10-02T03:26:51+00:00 Vulnerability · Source
CVE-2026-73643 redhat_vex js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections fixed: 58 known affected: 39 known not affected: 1796 2026-10-02T03:26:51+00:00 Vulnerability · Source
CVE-2023-42794 redhat_vex tomcat: FileUpload: DoS due to accumulation of temporary files on Windows fixed: 20 known affected: 10 known not affected: 25 2026-10-02T03:02:15+00:00 Vulnerability · Source
CVE-2023-41900 redhat_vex jetty: OpenId Revoked authentication allows one request fixed: 1 known affected: 37 known not affected: 8 2026-10-02T03:02:15+00:00 Vulnerability · Source
CVE-2023-46604 redhat_vex activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack fixed: 6 known affected: 1 2026-10-02T03:02:15+00:00 Vulnerability · Source
CVE-2024-21733 redhat_vex tomcat: Leaking of unrelated request bodies in default error page fixed: 2 known not affected: 66 2026-10-02T03:00:57+00:00 Vulnerability · Source
CVE-2024-22257 redhat_vex spring-security: Broken Access Control With Direct Use of AuthenticatedVoter fixed: 3 known affected: 9 known not affected: 7 2026-10-02T03:00:56+00:00 Vulnerability · Source
CVE-2023-34055 redhat_vex spring-boot: org.springframework.boot: spring-boot-actuator class vulnerable to denial of service fixed: 1 known affected: 10 known not affected: 17 2026-10-02T03:00:56+00:00 Vulnerability · Source
CVE-2023-5072 redhat_vex JSON-java: parser confusion leads to OOM fixed: 8 known affected: 7 known not affected: 9 2026-10-02T03:00:54+00:00 Vulnerability · Source
CVE-2023-6481 redhat_vex logback: A serialization vulnerability in logback receiver fixed: 122 known affected: 14 known not affected: 10 2026-10-02T03:00:54+00:00 Vulnerability · Source
CVE-2023-39410 redhat_vex apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK fixed: 96 known affected: 10 known not affected: 3486 2026-10-02T03:00:53+00:00 Vulnerability · Source
CVE-2023-6378 redhat_vex logback: serialization vulnerability in logback receiver fixed: 6 known affected: 16 known not affected: 43 2026-10-02T03:00:53+00:00 Vulnerability · Source
CVE-2023-40167 redhat_vex jetty: Improper validation of HTTP/1 content-length fixed: 16 known affected: 48 known not affected: 1950 2026-10-02T03:00:52+00:00 Vulnerability · Source
CVE-2023-50290 redhat_vex Solr: Host environment variables are published via the Metrics API fixed: 1 known not affected: 6 2026-10-02T03:00:51+00:00 Vulnerability · Source
CVE-2022-41678 redhat_vex ActiveMQ: Deserialization vulnerability on Jolokia that allows authenticated users to perform RCE fixed: 11 known affected: 4 known not affected: 12 2026-10-02T03:00:50+00:00 Vulnerability · Source
CVE-2024-22243 redhat_vex springframework: URL Parsing with Host Validation fixed: 1 known affected: 2 known not affected: 2 2026-10-02T03:00:49+00:00 Vulnerability · Source
CVE-2023-46749 redhat_vex shiro: path traversal attack may lead to authentication bypass fixed: 1 known affected: 1 known not affected: 6 2026-10-02T03:00:48+00:00 Vulnerability · Source
CVE-2024-1635 redhat_vex undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol fixed: 109 known affected: 4 known not affected: 2455 2026-10-02T03:00:47+00:00 Vulnerability · Source
CVE-2023-46589 redhat_vex tomcat: HTTP request smuggling via malformed trailer headers fixed: 105 known affected: 13 known not affected: 30 2026-10-02T03:00:46+00:00 Vulnerability · Source
CVE-2023-36479 redhat_vex jetty: Improper addition of quotation marks to user inputs in CgiServlet fixed: 25 known affected: 43 known not affected: 1952 under investigation: 1 2026-10-02T03:00:44+00:00 Vulnerability · Source
CVE-2023-36478 redhat_vex jetty: hpack header values cause denial of service in http/2 fixed: 2 known affected: 11 known not affected: 44 2026-10-02T03:00:43+00:00 Vulnerability · Source
CVE-2023-3223 redhat_vex undertow: OutOfMemoryError due to @MultipartConfig handling fixed: 109 known affected: 7 known not affected: 2378 2026-10-02T03:00:42+00:00 Vulnerability · Source
CVE-2026-35388 redhat_vex OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions fixed: 965 known affected: 19 known not affected: 160 2026-10-02T02:27:45+00:00 Vulnerability · Source
CVE-2026-35387 redhat_vex OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage fixed: 968 known affected: 19 known not affected: 157 2026-10-02T02:27:42+00:00 Vulnerability · Source