Skip to content
Noroxi

Codean Labs

13 credited records · 13 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

    MediumCVSS 6.5No exploitEPSS 0%

    redhat · enterprise linuxJun 29, 2026

  • CVE-2026-2604
    22Monitor

    Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling

    MediumCVSS 5.6No exploitEPSS 0%

    gnome · evolution data serverJun 17, 2026

  • CVE-2026-3634
    26Monitor

    Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header

    MediumCVSS 6.5No exploitEPSS 0%

    gnome · libsoupMar 17, 2026

  • CVE-2026-3633
    26Monitor

    Libsoup: libsoup: header and http request injection via crlf injection

    MediumCVSS 6.5No exploitEPSS 0%

    gnome · libsoupMar 17, 2026

  • CVE-2026-3632
    22Monitor

    Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames

    MediumCVSS 5.5No exploitEPSS 0%

    gnome · libsoupMar 17, 2026

  • Gvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file paths

    MediumCVSS 4.3No exploitEPSS 0%

    red hat · red hat enterprise linux 10Feb 26, 2026

  • Gvfs: gvfs ftp backend: information disclosure via untrusted pasv responses

    MediumCVSS 4.3No exploitEPSS 0%

    red hat · red hat enterprise linux 10Feb 26, 2026

  • CVE-2026-2443
    21Monitor

    Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure

    MediumCVSS 5.3No exploitEPSS 0%

    gnome · libsoupFeb 13, 2026

  • CVE-2026-1539
    23Monitor

    Libsoup: libsoup: credential leakage via http redirects

    MediumCVSS 5.8No exploitEPSS 0%

    gnome · libsoupJan 28, 2026

  • CVE-2026-1536
    21Monitor

    Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header

    MediumCVSS 5.3No exploitEPSS 0%

    gnome · libsoupJan 28, 2026

  • CVE-2026-1467
    21Monitor

    Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured

    MediumCVSS 5.3No exploitEPSS 0%

    gnome · libsoupJan 27, 2026

  • CVE-2026-0988
    14Monitor

    Glib: glib: denial of service via integer overflow in g_buffered_input_stream_peek()

    LowCVSS 3.7No exploitEPSS 0%

    red hat · red hat hardened imagesJan 21, 2026

  • Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow

    MediumCVSS 6.5No exploitEPSS 1%

    gnome · glibDec 11, 2025