Skip to main content

CWE archive

CWE-135 CVEs

Programmatic archive

2 CVEs tagged with CWE-1350 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-34831

Published Apr 2, 2026

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of Str…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0810

Published Jan 26, 2026

A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety…

CVSS 7.1 · High
evidence mentions
5
Buzz score
35.9
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1