Search CVE reports


Toggle filters

11 – 19 of 19 results


CVE-2025-22872

Medium priority

Some fixes available 8 of 14

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing,...

7 affected packages

golang-golang-x-net, containerd, adsys, golang-golang-x-net-dev, google-guest-agent...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Not affected Fixed Fixed Not in release Not in release
containerd Not affected Not affected Not affected Not affected Not affected
adsys Not affected Not affected Not affected Not affected —
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
google-guest-agent Not affected Not affected Not affected Not affected Not affected
juju-core — — — — —
lxd — — — Not affected Fixed
Show all 7 packages Show less packages

CVE-2023-0092

Medium priority
Not affected

An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.

2 affected packages

juju, juju-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
juju — — — — —
juju-core — Not in release Not in release Not in release —
Show less packages

CVE-2024-45338

Medium priority

Some fixes available 13 of 17

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

7 affected packages

golang-golang-x-net, adsys, containerd, golang-golang-x-net-dev, google-guest-agent...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Vulnerable Fixed Fixed Not in release —
adsys Fixed Fixed Fixed Fixed —
containerd Not affected Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
google-guest-agent Not affected Not affected Not affected Not affected Not affected
juju-core Not in release Not in release Not in release Not in release —
lxd Not in release Not in release Not in release Not affected Not affected
Show all 7 packages Show less packages

CVE-2023-3978

Medium priority

Some fixes available 8 of 12

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

7 affected packages

golang-golang-x-net, containerd, golang-golang-x-net-dev, adsys, google-guest-agent...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Not affected Not affected Fixed Not in release Not in release
containerd Not affected Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
adsys Not affected Not affected Not affected Fixed —
google-guest-agent Not affected Not affected Not affected Not affected Not affected
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Not affected Fixed
Show all 7 packages Show less packages

CVE-2022-41723

Medium priority

Some fixes available 23 of 39

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

20 affected packages

golang-golang-x-net, containerd, golang-1.13, adsys, golang...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Not affected Not affected Fixed Not in release Not in release
containerd Not affected Not affected Not affected Not affected Not affected
golang-1.13 Not in release Not in release Vulnerable Vulnerable Vulnerable
adsys Not affected Not affected Not affected Fixed —
golang Not in release Not in release Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Not in release Vulnerable
golang-1.14 Not in release Not in release Not in release Vulnerable Not in release
golang-1.16 Not in release Not in release Not in release Vulnerable Vulnerable
golang-1.17 Not in release Not in release Fixed Not in release Not in release
golang-1.18 Not in release Not in release Fixed Fixed Fixed
golang-1.19 Not in release Not in release Not in release Not in release Not in release
golang-1.20 Not in release Not in release Not affected Not affected Not in release
golang-1.21 Not in release Not affected Not affected Not affected Not in release
golang-1.6 Not in release Not in release Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Not in release Vulnerable
golang-1.9 Not in release Not in release Not in release Not in release Vulnerable
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
google-guest-agent Fixed Fixed Fixed Fixed Fixed
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Not affected Fixed
Show all 20 packages Show less packages

CVE-2022-27664

Medium priority

Some fixes available 26 of 39

In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

17 affected packages

golang-1.13, golang-1.14, golang-1.16, golang-1.17, golang-1.18...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-1.13 Not in release Not in release Fixed Fixed Fixed
golang-1.14 — — Not in release Vulnerable Not in release
golang-1.16 — — Not in release Fixed Fixed
golang-1.17 — — Vulnerable Not in release Not in release
golang-1.18 Not in release Not in release Fixed Fixed Fixed
golang-1.8 — — Not in release Not in release Vulnerable
golang-1.9 — — Not in release Not in release Vulnerable
golang-golang-x-net Not affected Not affected Fixed Not in release Not in release
google-guest-agent Fixed Fixed Fixed Fixed Needs evaluation
containerd Not affected Not affected Not affected Not affected Not affected
adsys Not affected Not affected Not affected Fixed —
golang — — Not in release Not in release Not in release
golang-1.10 — — Not in release Not in release Vulnerable
golang-1.6 — — Not in release Not in release Not in release
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Not affected Fixed
Show all 17 packages Show less packages

CVE-2020-26160

Medium priority
Needs evaluation

jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type assertion fails, "" is the value of aud....

4 affected packages

golang-github-dgrijalva-jwt-go, golang-github-coreos-discovery-etcd-io, juju-core, telegraf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-dgrijalva-jwt-go Not in release Not in release Not affected Needs evaluation Needs evaluation
golang-github-coreos-discovery-etcd-io Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
juju-core Not in release Not in release Not in release Not in release Not in release
telegraf Not in release Not in release Not affected Not in release Not in release
Show less packages

CVE-2015-1316

Medium priority
Ignored

Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.

1 affected package

juju-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
juju-core — — — — —
Show less packages

CVE-2017-9232

High priority
Fixed

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

2 affected packages

juju-core, juju-core-1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
juju-core — — — — —
juju-core-1 — — — — —
Show less packages