From Our Security Partners
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Information published.
CVE-2026-43249 9p/xen: protect xen_9pfs_front_free against concurrent calls
Information published.
CVE-2026-31767 drm/i915/dsi: Don’t do DSC horizontal timing adjustments in command mode
Information published.
CVE-2026-41256 jq: Embedded NUL truncates top-level jq programs loaded with -f
Information published.
CVE-2026-40612 jq: Stack overflow via unbounded recursion in jv_contains
Information published.
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
Information published.
CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro
Information published.
CVE-2026-41257 jq: Signed-int overflow in `stack_reallocate` (jq VM stack)
Information published.