Bugs addressed in recent updates
| Origin | Bug number | Title | Packages |
|---|---|---|---|
| CVE | CVE-2026-48526 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric | pyjwt pyjwt pyjwt |
| CVE | CVE-2026-48525 | PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64 | pyjwt pyjwt |
| CVE | CVE-2026-48524 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint f | pyjwt pyjwt |
| CVE | CVE-2026-48523 | PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or j | pyjwt |
| CVE | CVE-2026-48522 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which u | pyjwt pyjwt pyjwt |
| CVE | CVE-2026-78161 | A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP | libwebsockets |
| CVE | CVE-2026-10650 | A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ | libwebsockets |
| CVE | CVE-2026-6893 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Hos | dracut dracut dracut dracut |
| CVE | CVE-2026-55951 | The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option de | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-71380 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denia | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-73276 | Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-66357 | httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet uncondition | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-70399 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denia | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-73270 | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_aut | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-66835 | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-74835 | The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 befor | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-69664 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denia | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-23941 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smugglin | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-73812 | httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 ide | erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang erlang |
| CVE | CVE-2026-59251 | Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial | erlang erlang erlang erlang |
About
-
Send Feedback to @ubuntu_updates