Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 16 April 2026
RSS927 vulnerabilities published on 16 April 2026
Severity:
Terraform Providers: Security Update to Prevent Data Corruption and Authorization Bypass
SUSE-SU-2026:1411-1
This update fixes two security issues in Terraform's providers for local storage, randomness, and TLS. If not patched, these issues could allow attackers to consume corrupted files or bypass authoriza...
Tiff Updates Fix Crashes and Data Corruption
SUSE-SU-2026:1408-1
This update fixes two critical bugs in the tiff software that could cause the program to crash or produce incorrect results, potentially leading to data corruption. These issues were found in the way ...
Tiff Update Fixes Critical Data Corruption and Crash Risks
SUSE-SU-2026:1407-1
This update for Tiff fixes two critical issues that could cause data corruption or crashes in the application. If left unpatched, these vulnerabilities could allow malicious users to manipulate or des...
Ubuntu Linux: Improper Hostname Handling in Login Program
SUSE-SU-2026:1406-1
An update for Ubuntu Linux fixes a security issue that could allow an attacker to bypass access controls using the login program. Additionally, the update addresses issues with partition management an...
rootio-tar: Data Exposure Risk in Debian 13
ROOT-OS-DEBIAN-13-CVE-2005-2541
A patch has been released for rootio-tar in Debian 13 to prevent unauthorized access to sensitive data. This vulnerability allows attackers to access sensitive information. Update your system to the l...
rootio-glibc: Unpatched Code Allows Remote Code Execution
ROOT-OS-DEBIAN-13-CVE-2019-1010022
The rootio-glibc software had a vulnerability that allowed attackers to potentially execute malicious code on a system remotely. This issue has been fixed by the developers, and updates are available....
Rootio-glibc Linux Software Allows Local File Access
ROOT-OS-DEBIAN-13-CVE-2019-9192
A patch has been released for a vulnerability in the rootio-glibc package on Root:Debian:13. This issue could allow an attacker with local access to read or write sensitive files. It's recommended to ...
rootio-glibc: Potential Data Exposure on Root Devices
ROOT-OS-DEBIAN-13-CVE-2026-4046
A vulnerability in the rootio-glibc package on Root devices could allow unauthorized access to sensitive data. This issue has been fixed in updated versions of the software, so it's essential to apply...
rootio-glibc: Unpatched Code Allows Unauthorized Access
ROOT-OS-DEBIAN-13-CVE-2019-1010023
The rootio-glibc package in Root:Debian:13 has a security issue that could allow an attacker to gain unauthorized access. This issue has been fixed, so it's essential to update the package to the late...
Rootio-glibc on Root:Debian:13 allows arbitrary code execution
ROOT-OS-DEBIAN-13-CVE-2018-20796
A patch has been released to fix a critical security issue in the rootio-glibc package on Root:Debian:13. This issue could allow an attacker to execute arbitrary code on the system. We recommend updat...
Rootio-glibc on Debian 13: Remote Code Execution Risk
ROOT-OS-DEBIAN-13-CVE-2026-4437
A patch has been released for a vulnerability in the rootio-glibc package on Debian 13. If left unpatched, an attacker could potentially take control of the system. Update to a fixed version of rootio...
rootio-glibc: Unauthorized Access to System Files
ROOT-OS-DEBIAN-13-CVE-2026-4438
An update has been released for rootio-glibc, which fixes a security issue that could allow unauthorized access to system files on a Root Debian 13 system. This could potentially lead to data loss or ...
CGA-4wjj-gwr8-wp83
CGA-4wjj-gwr8-wp83
CGA-fqj9-mx8g-5v3q
CGA-fqj9-mx8g-5v3q
Python PyJWT: Unrestricted Header Extension Allows Arbitrary Data Injection
SUSE-SU-2026:1400-1
An update for the Python PyJWT library is available to fix a vulnerability that could allow an attacker to inject arbitrary data into certain types of JSON Web Tokens (JWTs). This is a security risk b...
CUPS Security Update: Local Printer Admin Token Exposure
SUSE-SU-2026:1399-1
A security update for CUPS fixes a vulnerability that could allow an attacker with local access to print a document and then access administrative functions for all printers. This could be used to gai...
Microsoft Windows Remote Desktop Server Can Be Hacked
SUSE-SU-2026:1398-1
FreeRDP, a tool for remote desktop connections, has security updates to prevent hackers from taking control of your server or executing malicious code. This update is important if you use remote deskt...
Plexus-utils update fixes directory traversal weakness
SUSE-SU-2026:1396-1
This update for plexus-utils fixes a security weakness that could allow an attacker to access and manipulate files on a system. This is a potential security risk, so it's recommended to update to the ...
Plexus-Utils: Directory Traversal Risk in Windows
Plexus-Utils, a library used by some software, has a security issue that could allow an attacker to access files they shouldn't be able to. This update fixes the problem and we recommend updating to v...
Go's spdystream Library Fails to Validate Memory Allocation
DEBIAN-CVE-2026-35469
A vulnerability in the spdystream library for Go can cause a service to consume all available memory and crash. This can happen if a malicious peer sends a specially crafted message to the service. Th...
Azure Storage AzCopy: Unauthorized Access via HTTP/2 Path Header
SUSE-SU-2026:1395-1
A security update is available for Azure Storage AzCopy to prevent unauthorized access to sensitive data. This update fixes a bug that could allow an attacker to access restricted areas of the system....
Corosync: Denial of Service and Data Exposure
A security update is available for Corosync, a tool used in high-availability clusters. This update fixes two security issues that could allow an attacker to crash the system or access sensitive infor...
Corosync Update: Denial of Service and Data Exposure Risk
SUSE-SU-2026:1394-1
Corosync, a software used for clustering and high availability, has released an update to fix a pair of issues that could allow an attacker to crash the system or access sensitive information. If left...
Python-PyJWT Update Fixes Uncontrolled Header Extension
SUSE-SU-2026:1389-1
A security update for python-PyJWT addresses an issue where unknown header extensions could be accepted, potentially leading to security risks. This could allow an attacker to manipulate the token's p...
Python PyJWT Security Update Fixes Header Extension Bypass
An update for the Python PyJWT library fixes a security issue that could allow attackers to bypass security checks by using unknown header extensions. This affects Python users who rely on PyJWT for s...