VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
2537 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2026-69896 | microsoft_vex | Windows Error Reporting Elevation of Privilege Vulnerability | fixed: 8 known affected: 8 | 2026-10-13T07:00:00+00:00 | Vulnerability · Source |
| CVE-2021-47088 | redhat_vex | kernel: mm/damon/dbgfs: protect targets destructions with kdamond_lock | fixed: 286 known affected: 38 known not affected: 42 | 2026-10-03T15:28:07+00:00 | Vulnerability · Source |
| CVE-2021-47090 | redhat_vex | kernel: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() | fixed: 120 known affected: 58 known not affected: 108 | 2026-10-03T15:28:07+00:00 | Vulnerability · Source |
| CVE-2026-56860 | redhat_vex | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution | fixed: 7334 known affected: 274 known not affected: 3610 | 2026-10-03T15:22:53+00:00 | Vulnerability · Source |
| CVE-2026-42502 | redhat_vex | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering | fixed: 788 known affected: 238 known not affected: 5662 | 2026-10-03T14:21:56+00:00 | Vulnerability · Source |
| CVE-2026-73643 | redhat_vex | js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections | fixed: 58 known affected: 38 known not affected: 1797 | 2026-10-03T13:56:23+00:00 | Vulnerability · Source |
| CVE-2025-66471 | redhat_vex | urllib3: urllib3 Streaming API improperly handles highly compressed data | fixed: 1965 known affected: 125 known not affected: 3876 | 2026-10-03T13:04:33+00:00 | Vulnerability · Source |
| CVE-2025-66418 | redhat_vex | urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion | fixed: 1992 known affected: 379 known not affected: 2959 | 2026-10-03T13:04:33+00:00 | Vulnerability · Source |
| CVE-2023-53429 | redhat_vex | kernel: btrfs: don't check PageError in __extent_writepage | known affected: 42 known not affected: 232 | 2026-10-03T11:18:11+00:00 | Vulnerability · Source |
| CVE-2025-61728 | redhat_vex | golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip | fixed: 7014 known affected: 113 known not affected: 4133 | 2026-10-03T10:07:56+00:00 | Vulnerability · Source |
| CVE-2025-58183 | redhat_vex | golang: archive/tar: Unbounded allocation when parsing GNU sparse map | fixed: 9024 known affected: 131 known not affected: 8348 | 2026-10-03T10:07:52+00:00 | Vulnerability · Source |
| CVE-2026-12345 | redhat_vex | python: python: Arbitrary file deletion via race condition during temporary directory cleanup | fixed: 65 known affected: 141 | 2026-10-03T10:07:50+00:00 | Vulnerability · Source |
| CVE-2026-27145 | redhat_vex | crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries | fixed: 1083 known affected: 74 known not affected: 5346 | 2026-10-03T10:06:18+00:00 | Vulnerability · Source |
| CVE-2026-27136 | redhat_vex | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass | fixed: 1345 known affected: 178 known not affected: 13996 | 2026-10-03T10:06:10+00:00 | Vulnerability · Source |
| CVE-2026-25681 | redhat_vex | golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting | fixed: 1332 known affected: 240 known not affected: 8613 | 2026-10-03T10:06:08+00:00 | Vulnerability · Source |
| CVE-2025-66506 | redhat_vex | github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token | fixed: 329 known affected: 42 known not affected: 1297 | 2026-10-03T10:05:44+00:00 | Vulnerability · Source |
| CVE-2025-64756 | redhat_vex | glob: glob: Command Injection Vulnerability via Malicious Filenames | fixed: 171 known affected: 115 known not affected: 1099 | 2026-10-03T10:05:10+00:00 | Vulnerability · Source |
| CVE-2025-61729 | redhat_vex | crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate | fixed: 8116 known affected: 434 known not affected: 5144 | 2026-10-03T10:04:52+00:00 | Vulnerability · Source |
| CVE-2025-61726 | redhat_vex | golang: net/url: Memory exhaustion in query parameter parsing in net/url | fixed: 11002 known affected: 443 known not affected: 17463 | 2026-10-03T10:04:35+00:00 | Vulnerability · Source |
| CVE-2025-52881 | redhat_vex | runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects | fixed: 2419 known affected: 40 known not affected: 4478 | 2026-10-03T10:04:28+00:00 | Vulnerability · Source |
| CVE-2025-30204 | redhat_vex | golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing | fixed: 3866 known affected: 68 known not affected: 13220 | 2026-10-03T10:04:20+00:00 | Vulnerability · Source |
| CVE-2025-22869 | redhat_vex | golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh | fixed: 2839 known affected: 56 known not affected: 6264 under investigation: 1 | 2026-10-03T10:04:16+00:00 | Vulnerability · Source |
| CVE-2025-22868 | redhat_vex | golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws | fixed: 2199 known affected: 93 known not affected: 8426 | 2026-10-03T10:04:12+00:00 | Vulnerability · Source |
| CVE-2025-12816 | redhat_vex | node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications | fixed: 460 known affected: 37 known not affected: 2169 | 2026-10-03T10:04:11+00:00 | Vulnerability · Source |
| CVE-2026-56859 | redhat_vex | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue | fixed: 6850 known affected: 248 known not affected: 3466 | 2026-10-03T09:52:24+00:00 | Vulnerability · Source |
| CVE-2026-56858 | redhat_vex | html/template: golang: Go html/template: Cross-Site Scripting via pathological input | fixed: 6774 known affected: 215 known not affected: 3326 | 2026-10-03T09:52:04+00:00 | Vulnerability · Source |
| CVE-2026-41178 | redhat_vex | github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers | fixed: 1083 known affected: 213 known not affected: 6482 | 2026-10-03T09:51:28+00:00 | Vulnerability · Source |
| CVE-2026-39828 | redhat_vex | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions | fixed: 482 known affected: 83 known not affected: 4987 | 2026-10-03T09:51:14+00:00 | Vulnerability · Source |
| CVE-2026-34986 | redhat_vex | github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object | fixed: 2999 known affected: 144 known not affected: 16904 | 2026-10-03T09:50:58+00:00 | Vulnerability · Source |
| CVE-2026-33818 | redhat_vex | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal | fixed: 7256 known affected: 200 known not affected: 2994 | 2026-10-03T09:50:32+00:00 | Vulnerability · Source |
| CVE-2026-33814 | redhat_vex | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame | fixed: 2322 known affected: 380 known not affected: 27856 under investigation: 496 | 2026-10-03T09:49:12+00:00 | Vulnerability · Source |
| CVE-2026-33186 | redhat_vex | google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation | fixed: 3352 known affected: 364 known not affected: 39263 | 2026-10-03T09:48:43+00:00 | Vulnerability · Source |
| CVE-2024-24786 | redhat_vex | golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON | fixed: 2152 known affected: 112 known not affected: 11937 under investigation: 57 | 2026-10-03T09:48:33+00:00 | Vulnerability · Source |
| CVE-2023-48795 | redhat_vex | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | fixed: 1933 known affected: 153 known not affected: 12358 | 2026-10-03T09:48:05+00:00 | Vulnerability · Source |
| CVE-2023-39325 | redhat_vex | golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) | fixed: 6046 known affected: 223 known not affected: 30360 | 2026-10-03T09:47:28+00:00 | Vulnerability · Source |
| CVE-2022-30631 | redhat_vex | golang: compress/gzip: stack exhaustion in Reader.Read | fixed: 4253 known affected: 91 known not affected: 2159 | 2026-10-03T09:47:26+00:00 | Vulnerability · Source |
| CVE-2021-20329 | redhat_vex | mongo-go-driver: specific cstrings input may not be properly validated | fixed: 252 known affected: 69 known not affected: 3782 | 2026-10-03T09:29:56+00:00 | Vulnerability · Source |
| CVE-2026-95331 | redhat_vex | chromium-browser: angle: Out of bounds write in ANGLE | known affected: 27 known not affected: 18 | 2026-10-03T07:20:56+00:00 | Vulnerability · Source |
| CVE-2026-9915 | redhat_vex | chromium-browser: angle: Heap buffer overflow in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:20:56+00:00 | Vulnerability · Source |
| CVE-2026-9965 | redhat_vex | chromium-browser: angle: Out of bounds write in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:20:56+00:00 | Vulnerability · Source |
| CVE-2026-8567 | redhat_vex | chromium-browser: angle: chromium-browser: Integer overflow in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:15:59+00:00 | Vulnerability · Source |
| CVE-2026-79189 | redhat_vex | chromium-browser: angle: ANGLE: Arbitrary code execution via a crafted HTML page | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:15:59+00:00 | Vulnerability · Source |
| CVE-2026-5277 | redhat_vex | chromium-browser: angle: Integer overflow in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:11:00+00:00 | Vulnerability · Source |
| CVE-2026-7900 | redhat_vex | chromium-browser: angle: Heap buffer overflow in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:11:00+00:00 | Vulnerability · Source |
| CVE-2026-17740 | redhat_vex | chromium-browser: angle: chromium-browser: Uninitialized Use in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:11:00+00:00 | Vulnerability · Source |
| CVE-2026-17677 | redhat_vex | chromium-browser: angle: chromium-browser: Inappropriate implementation in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:05:56+00:00 | Vulnerability · Source |
| CVE-2026-14402 | redhat_vex | chromium-browser: angle: chromium-browser: Uninitialized Use in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:05:56+00:00 | Vulnerability · Source |
| CVE-2026-11005 | redhat_vex | chromium-browser: angle: Out of bounds read in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:01:07+00:00 | Vulnerability · Source |
| CVE-2026-14044 | redhat_vex | chromium-browser: angle: Use after free in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:01:07+00:00 | Vulnerability · Source |
| CVE-2026-11111 | redhat_vex | chromium-browser: angle: Out of bounds read in ANGLE | fixed: 92 known affected: 11 known not affected: 23 | 2026-10-03T07:01:07+00:00 | Vulnerability · Source |