| CVE-2026-39821 |
critical |
9.6 |
9.6 |
|
|
|
7d ago |
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com… |
| CVE-2026-25680 |
medium |
6.5 |
6.5 |
|
|
|
7d ago |
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. |
| CVE-2026-42506 |
medium |
6.1 |
6.1 |
|
|
|
7d ago |
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo… |
| CVE-2026-42502 |
medium |
6.1 |
6.1 |
|
|
|
7d ago |
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo… |
| CVE-2026-27136 |
medium |
6.1 |
6.1 |
|
|
|
7d ago |
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo… |
| CVE-2026-25681 |
medium |
6.1 |
6.1 |
|
|
|
7d ago |
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo… |
| CVE-2023-3978 |
medium |
— |
5.5 |
|
|
|
3y ago |
Moderate: podman security, bug fix, and enhancement update |
| CVE-2022-41723 |
medium |
— |
5.5 |
|
|
|
3y ago |
Moderate: toolbox security and bug fix update |
| CVE-2022-27664 |
medium |
— |
5.5 |
|
|
|
3y ago |
Moderate: git-lfs security and bug fix update |
| CVE-2022-41717 |
medium |
— |
5.5 |
|
|
|
3y ago |
Moderate: git-lfs security and bug fix update |
| CVE-2021-31525 |
medium |
— |
5.5 |
|
|
|
4y ago |
RHSA-2021:3076: go-toolset:rhel8 security, bug fix, and enhancement update (Moderate) |