Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 8 April 2026

RSS

716 vulnerabilities published on 8 April 2026

Severity:
rootio-linux: Unauthorized Access to Root Account
ROOT-OS-DEBIAN-12-CVE-2026-23401
The rootio-linux package on Debian 12 has a security issue that could allow someone to access the root account without proper permission. This means that a malicious user could gain control of the ent...
rootio-linux: Unrestricted File Access in rootio-linux
ROOT-OS-DEBIAN-12-CVE-2026-23450
A security patch has been released for the rootio-linux package to prevent unauthorized access to files on a Debian 12 system. This update addresses a previously known issue and is recommended for ins...
rootio-linux: Untrusted root access in rootio-linux
ROOT-OS-DEBIAN-12-CVE-2026-31408
A security patch has been released for rootio-linux, a component of the Root platform, which could allow unauthorized users to access sensitive data. This vulnerability affects Root users and requires...
Pygments: CPU Consumption Issue in Certain Lexers
MGASA-2026-0090
A weakness in Pygments' AdlLexer can lead to high CPU usage, potentially causing slow performance or system crashes. This issue affects older versions of Pygments. Upgrade to the latest version to res...
MINI-c7gm-2c6w-r3pq
MINI-c7gm-2c6w-r3pq
Adobe Reader for Android Unsecured Data Storage
MINI-ch3x-mx4m-2rq9
Adobe Reader for Android stores sensitive data in an unsecured location, allowing unauthorized access to documents and user information. This could lead to sensitive data theft or unauthorized access ...
MINI-72v7-qxqr-42c3
MINI-72v7-qxqr-42c3
MINI-c5r7-9v8w-wrv9
MINI-c5r7-9v8w-wrv9
MINI-553w-gfv3-cj7g
MINI-553w-gfv3-cj7g
MINI-f45w-8rgj-q862
MINI-f45w-8rgj-q862
Adobe Flash Player on Windows May Allow Remote Code Execution
MINI-324r-626v-pv33
Adobe Flash Player on Windows computers may allow an attacker to run malicious code on the system without permission. This could happen if a user visits a website that contains a malicious Flash file....
Wildcard Certificates Can Bypass Validation in Some Cases
GO-2026-4866 CVE-2026-33810
A bug in certificate validation can allow a malicious certificate to be accepted as trusted, even if it shouldn't be. This happens when a certificate has a wildcard domain name that doesn't match the ...
Wildcard DNS Certificates Not Verified Correctly with Excluded DNS Constraints
DEBIAN-CVE-2026-33810
A security issue affects how certain certificate chains are verified. Specifically, it overlooks wildcard DNS certificates if their domain name doesn't match the case of the excluded DNS constraint. T...
Incorrect escaping in JavaScript template literals
DEBIAN-CVE-2026-32289
Using JavaScript template literals in specific cases could lead to incorrect content escaping, potentially allowing malicious code to be injected. This affects users of JavaScript template literals, p...
Mistakes in HTML Template Code Can Lead to Website Hacking
GO-2026-4865 CVE-2026-32289
A bug in some HTML templates can allow hackers to inject malicious code into a website, potentially taking control of it. This issue affects websites that use a specific type of template engine. To st...
GNU tar can run out of memory when reading corrupt archives
GO-2026-4869 CVE-2026-32288
A malicious archive can cause GNU tar to consume excessive memory, potentially crashing or freezing the system. This issue affects systems that use GNU tar to extract archives. To mitigate this risk, ...
Libarchive tar reader can run out of memory with malicious archive
DEBIAN-CVE-2026-32288
Libarchive's tar reader can be exploited to consume an excessive amount of memory by processing a specially crafted archive. This can cause the program to crash or become unresponsive. To protect agai...
TLS 1.3 Key Update Records Can Cause Persistent Connections
GO-2026-4870 CVE-2026-32283
A vulnerability in TLS 1.3 can cause connections to become stuck, wasting server resources. This happens when a server or client sends multiple key update messages in one go, freezing the connection. ...
TLS 1.3 Connections Can Be Bricked by Malicious Key Updates
DEBIAN-CVE-2026-32283
If you're using TLS 1.3, an attacker can potentially crash your server or connection by sending multiple key updates at once. This could lead to a denial of service, where your server becomes unrespon...
Linux Chmod Can Access Sensitive Files Through Symlink
GO-2026-4864 CVE-2026-32282
Linux systems using the Chmod function may allow unauthorized access to sensitive files if an attacker replaces the target with a symbolic link. This could potentially lead to unauthorized changes or ...
Linux Chmod can operate on unintended external files through symlink attack
DEBIAN-CVE-2026-32282
This issue affects Linux systems and can occur when a symbolic link to a file outside the root directory is created during a chmod operation. This may allow unauthorized changes to files outside the i...
Large certificate chains can cause Apache HTTP Server denial of service
DEBIAN-CVE-2026-32281
Apache HTTP Server may become unresponsive when validating certain large certificate chains. This affects trusted certificate chains, but does not compromise security. Update your Apache HTTP Server t...
Large Certificate Chains Cause Slow Certificate Validation in Some Software
GO-2026-4946 CVE-2026-32281
Certain software that checks digital certificates for trust may take a long time to validate certificates that have many policy mappings. This can cause the software to become unresponsive or slow. If...
OpenSSL: Excessive Certificate Verification Can Cause Slowdowns
DEBIAN-CVE-2026-32280
A bug in OpenSSL's certificate verification process can cause it to take a long time to verify certificates when dealing with many intermediate certificates. This can cause slowdowns and potentially i...
Crypto/X509: Excessive Work in Certificate Chain Verification
GO-2026-4947 CVE-2026-32280
When verifying a chain of digital certificates, a large number of intermediate certificates can cause the system to become unresponsive or even crash. This issue affects users of the crypto/x509 and c...