CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal
Information published.
Categories: Microsoft
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData
Information published.
Categories: Microsoft
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
Information published.
Categories: Microsoft
CVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer
Information published.
Categories: Microsoft
CVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison length
Information published.
Categories: Microsoft
CVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
Information published.
Categories: Microsoft
CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
Information published.
Categories: Microsoft
CVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse
Information published.
Categories: Microsoft
CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
Information published.
Categories: Microsoft
CVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)
Information published.
Categories: Microsoft
CVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation
Information published.
Categories: Microsoft
CVE-2026-6450 CRL critical extension bypass in ParseCRL_Extensions
Information published.
Categories: Microsoft
CVE-2026-7532 iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
Information published.
Categories: Microsoft
CVE-2026-6291 Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption
Information published.
Categories: Microsoft
CVE-2026-57918 libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid...
Information published.
Categories: Microsoft
CVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the container
Information published.
Categories: Microsoft
CVE-2026-13325 Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces
Information published.
Categories: Microsoft
CVE-2026-13218 Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher
Information published.
Categories: Microsoft
CVE-2026-13208 Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body
Information published.
Categories: Microsoft
CVE-2026-13318 Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip
Information published.
Categories: Microsoft


