Open Source Vulnerabilities
tomcat
Apache Tomcat: Servlet role references can bypass declarative role constraints
tomcat
Apache Tomcat: Servlet role references can bypass declarative role constraints
tomcat
Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
tomcat
Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
tomcat
Apache Tomcat: Limited replay attack possible with DIGEST authentication
tomcat
Apache Tomcat: Limited replay attack possible with DIGEST authentication
tomcat
Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets
tomcat
Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets
tomcat
Apache Tomcat: Bypass longest prefix security constraint
tomcat
Apache Tomcat: Bypass longest prefix security constraint
tomcat
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
tomcat
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
tomcat
Apache Tomcat: Security constraints for default servlet ignored method
tomcat
Apache Tomcat: Security constraints for default servlet ignored method
tomcat
Apache Tomcat: EncryptInterceptor not protected against replay attacks
tomcat
Apache Tomcat: EncryptInterceptor not protected against replay attacks
tomcat
Apache Tomcat: Logged effective web.xml is incomplete
tomcat
Apache Tomcat: Logged effective web.xml is incomplete
tomcat
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
tomcat
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
tomcat
Apache Tomcat: Bad ornext processing in RewriteValve
tomcat
Apache Tomcat: Bad ornext processing in RewriteValve
tomcat
Apache Tomcat: XSS in number guess example
tomcat
Apache Tomcat: Security constraints not correctly applied
tomcat
Apache Tomcat: Security constraints not correctly applied
tomcat
Apache Tomcat: AJP secret compared in non-constant time
tomcat
Apache Tomcat: AJP secret compared in non-constant time
tomcat
Apache Tomcat: LockOutRealm treats user names as case-sensitive
tomcat
Apache Tomcat: LockOutRealm treats user names as case-sensitive
tomcat
Apache Tomcat: Digest authenticator will authenticate any unknown user
tomcat
Apache Tomcat: Digest authenticator will authenticate any unknown user
tomcat
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
tomcat
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
tomcat
Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
tomcat
Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
tomcat
Apache Tomcat: Incomplete escaping of JSON access logs
tomcat
Apache Tomcat: Incomplete escaping of JSON access logs
tomcat
Apache Tomcat: Occasionally open redirect
tomcat
Apache Tomcat: Request smuggling via invalid chunk extension
tomcat
Apache Tomcat: Request smuggling via invalid chunk extension
tomcat
Apache Tomcat: Security constraint bypass with HTTP/0.9
tomcat
Apache Tomcat: Security constraint bypass with HTTP/0.9
tomcat
Apache Tomcat: Client certificate verification bypass due to virtual host mapping
tomcat
Apache Tomcat: Client certificate verification bypass due to virtual host mapping
python
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
python
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
python-min
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
python-min
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
python
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
python
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
python-min
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
python-min
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
python
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
python
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
python-min
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
python-min
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
org.postgresql:postgresql, io.root.org.postgresql:postgresql
CVE-2025-49146 in org.postgresql:postgresql - Patched by Root
org.postgresql:postgresql/ io.root.org.postgresql:postgresql
CVE-2025-49146 in org.postgresql:postgresql - Patched by Root
libpython
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
libpython
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
libpython
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
libpython
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
libpython
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
libpython
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
live-boot, live-boot, live-boot
libhttp-date-perl, rootio-libhttp-date-perl
CVE-2026-14741 in libhttp-date-perl - Patched by Root
libhttp-date-perl/ rootio-libhttp-date-perl
CVE-2026-14741 in libhttp-date-perl - Patched by Root
libhttp-date-perl, rootio-libhttp-date-perl
CVE-2026-14741 in libhttp-date-perl - Patched by Root
libhttp-date-perl/ rootio-libhttp-date-perl
CVE-2026-14741 in libhttp-date-perl - Patched by Root
pcre2, rootio-pcre2
CVE-2026-86145 in pcre2 - Patched by Root
pcre2/ rootio-pcre2
CVE-2026-86145 in pcre2 - Patched by Root
pcre2
CVE-2026-89160 affecting package pcre2 10.42-3
pcre2
CVE-2026-89161 affecting package pcre2 10.42-3
pcre2
CVE-2026-89156 affecting package pcre2 10.42-3
pcre2
CVE-2026-89158 affecting package pcre2 10.42-3
pcre2
CVE-2026-89157 affecting package pcre2 10.42-3
