Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 8 April 2026
RSS713 vulnerabilities published on 8 April 2026
Severity:
CVE Removed by Mistake: No Security Issue Exists
CVE-2026-4402
This entry was mistakenly created and has been removed. No security issue actually exists. No action is needed.
AWS C Event Stream Out-of-Bounds Write Vulnerability
openSUSE-SU-2026:20477-1
AWS C Event Stream has a security issue that could allow hackers to execute unintended code by sending a specially crafted message. This update fixes the problem, so it's recommended to install the la...
rootio-glibc: Potential Data Exposure on Root Devices
ROOT-OS-DEBIAN-13-CVE-2026-4046
A vulnerability in the rootio-glibc package on Root devices could allow unauthorized access to sensitive data. This issue has been fixed in updated versions of the software, so it's essential to apply...
rootio-glibc: Unauthorized Access to System Files
ROOT-OS-DEBIAN-13-CVE-2026-4438
An update has been released for rootio-glibc, which fixes a security issue that could allow unauthorized access to system files on a Root Debian 13 system. This could potentially lead to data loss or ...
Rootio-glibc on Debian 13: Remote Code Execution Risk
ROOT-OS-DEBIAN-13-CVE-2026-4437
A patch has been released for a vulnerability in the rootio-glibc package on Debian 13. If left unpatched, an attacker could potentially take control of the system. Update to a fixed version of rootio...
CGA-mx34-279q-wgwf
CGA-mx34-279q-wgwf
Netty HTTP2 library contains a security risk, patched
ROOT-APP-MAVEN-CVE-2026-33871
The Netty HTTP2 library has a security vulnerability that could allow an attacker to execute malicious code. This affects users who rely on the Netty library for HTTP2 functionality. To fix the issue,...
Netty HTTP Library Allows Arbitrary Code Execution
ROOT-APP-MAVEN-CVE-2026-33870
A security patch has been released for the Netty HTTP library, which allows attackers to execute arbitrary code on your system. This affects users who use the library in their applications. To stay se...
Netty HTTP Codec Vulnerability: Data Exposure with Mismatched HTTP Headers
ROOT-APP-MAVEN-CVE-2025-67735
A security patch has been released for io.root.io.netty:netty-codec-http. If not updated, an attacker could potentially access sensitive data by exploiting a mismatch between HTTP headers. Update to a...
Netty HTTP2 Server Vulnerability: Authentication Bypass
ROOT-APP-MAVEN-CVE-2025-55163
A security issue in the Netty HTTP2 server can allow attackers to bypass authentication. This affects users who use the Netty library in their applications. It's recommended to update to a patched ver...
Netty SMTP Library Allows Unauthorized Access to Email Systems
ROOT-APP-MAVEN-CVE-2025-59419
A security patch has fixed a vulnerability in the Netty SMTP library that could allow an attacker to access email systems. This affects organizations that use the Netty SMTP library, so update to the ...
Netty Codec Allows Remote Code Execution via Deserialization
ROOT-APP-MAVEN-CVE-2025-58057
A security patch has been released for Netty Codec, a popular Java library used for network communication. If exploited, this vulnerability could allow attackers to run malicious code on your server, ...
Rootio-glibc: Unauthenticated Command Execution on Debian 12
ROOT-OS-DEBIAN-12-CVE-2019-9192
A security patch has been released for the rootio-glibc package on Debian 12. If left unpatched, an attacker could potentially execute arbitrary commands on your system without a password. Update your...
Rootio-glibc: Unauthorized data access through malicious input
ROOT-OS-DEBIAN-12-CVE-2019-1010023
The rootio-glibc package, used in Root:Debian:12, had a security issue that could allow an attacker to access unauthorized data if they sent the system malicious input. This could potentially lead to ...
rootio-glibc: Unauthenticated Privilege Escalation on Debian 12
ROOT-OS-DEBIAN-12-CVE-2026-4437
A security patch has been released for the rootio-glibc package on Debian 12. This patch fixes a vulnerability that could allow an attacker to gain elevated privileges without being authenticated. Upd...
Rootio-glibc: Remote code execution via malicious network share
ROOT-OS-DEBIAN-12-CVE-2026-0915
A vulnerability in the rootio-glibc package for Root:Debian:12 allows an attacker to execute malicious code on a system by accessing a shared network resource. This could potentially lead to unauthori...
rootio-glibc: Data Exposure in rootio-glibc Package
ROOT-OS-DEBIAN-12-CVE-2018-20796
The rootio-glibc package contains a security issue that could allow sensitive information to be accessed. This affects users of Root:Debian:12 and multiple fixed versions are available. We recommend u...
Rootio-glibc Allows Malicious File Overwrite on Debian 12
ROOT-OS-DEBIAN-12-CVE-2019-1010022
A security update has been made available for the rootio-glibc package on Debian 12. This update fixes a vulnerability that could allow an attacker to overwrite arbitrary files on the system. We recom...
Critical Data Exposure in Debian 12's rootio-glibc
ROOT-OS-DEBIAN-12-CVE-2026-0861
A critical vulnerability has been fixed in the rootio-glibc package used by Debian 12. This issue could allow an attacker to access sensitive data, putting your system's security at risk. Make sure to...
rootio-glibc: Unauthorized Access to System Files on Root Devices
ROOT-OS-DEBIAN-12-CVE-2025-15281
A security patch has been released for the rootio-glibc package on Root:Debian:12 devices. If left unpatched, an attacker could potentially access and modify sensitive system files. Root recommends up...
Fast XML Parser Allows Unrestricted Code Execution
ROOT-APP-NPM-CVE-2026-27942
The Fast XML Parser library may allow an attacker to inject malicious code, which could potentially execute arbitrary commands. This affects users who rely on the library to parse XML data. Update to ...
Fast-XML-Parser for Root:npm: Uncontrolled XML Input Can Cause Crash
ROOT-APP-NPM-CVE-2026-33036
A security issue in the Fast-XML-Parser library used by Root:npm can cause the application to crash if it processes malformed XML input. This could potentially lead to a denial of service. Update to a...
Fast-XML-Parser for Root: XML Parsing Error Allows Unauthorized Access
ROOT-APP-NPM-CVE-2026-25896
A security issue in the Fast-XML-Parser library used by Root could allow an attacker to bypass security checks and access sensitive data. Affected users should update to a patched version to prevent u...
Fast-XML-Parser: Untrusted XML Data Injection
ROOT-APP-NPM-CVE-2026-26278
A security update has been released for the Fast-XML-Parser library used by some Root projects. This update fixes a bug that could allow an attacker to inject malicious data into the affected system. ...
AnyTrack Affiliate Link Manager: Unauthorized Access to Configuration
CVE-2026-39715
AnyTrack Affiliate Link Manager versions up to 1.5.5 have a security flaw that allows unauthorized access to configuration settings. This means that an attacker could potentially make changes to the s...