Codean Labs
13 credited records · 13 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2026-13601No exploit | Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applicationsredhat · enterprise linux · CWE-693 | Medium6.5 | — | 0.2% | Jun 29, 2026 |
22Monitor | CVE-2026-2604No exploit | Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handlinggnome · evolution data server · CWE-73 | Medium5.6 | — | 0.3% | Jun 17, 2026 |
26Monitor | CVE-2026-3634No exploit | Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type headergnome · libsoup · CWE-93 | Medium6.5 | — | 0.3% | Mar 17, 2026 |
26Monitor | CVE-2026-3633No exploit | Libsoup: libsoup: header and http request injection via crlf injectiongnome · libsoup · CWE-93 | Medium6.5 | — | 0.4% | Mar 17, 2026 |
22Monitor | CVE-2026-3632No exploit | Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnamesgnome · libsoup · CWE-1286 | Medium5.5 | — | 0.3% | Mar 17, 2026 |
17Monitor | CVE-2026-28296No exploit | Gvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file pathsred hat · red hat enterprise linux 10 · CWE-93 | Medium4.3 | — | 0.5% | Feb 26, 2026 |
17Monitor | CVE-2026-28295No exploit | Gvfs: gvfs ftp backend: information disclosure via untrusted pasv responsesred hat · red hat enterprise linux 10 · CWE-918 | Medium4.3 | — | 0.3% | Feb 26, 2026 |
21Monitor | CVE-2026-2443No exploit | Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosuregnome · libsoup · CWE-125 | Medium5.3 | — | 0.4% | Feb 13, 2026 |
23Monitor | CVE-2026-1539No exploit | Libsoup: libsoup: credential leakage via http redirectsgnome · libsoup · CWE-201 | Medium5.8 | — | 0.3% | Jan 28, 2026 |
21Monitor | CVE-2026-1536No exploit | Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition headergnome · libsoup · CWE-93 | Medium5.3 | — | 0.3% | Jan 28, 2026 |
21Monitor | CVE-2026-1467No exploit | Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configuredgnome · libsoup · CWE-93 | Medium5.3 | — | 0.4% | Jan 27, 2026 |
14Monitor | CVE-2026-0988No exploit | Glib: glib: denial of service via integer overflow in g_buffered_input_stream_peek()red hat · red hat hardened images · CWE-190 | Low3.7 | — | 0.4% | Jan 21, 2026 |
26Monitor | CVE-2025-14512No exploit | Glib: integer overflow in glib gio attribute escaping causes heap buffer overflowgnome · glib · CWE-190 | Medium6.5 | — | 0.6% | Dec 11, 2025 |
- CVE-2026-1360126Monitor
Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
MediumCVSS 6.5No exploitEPSS 0%redhat · enterprise linuxJun 29, 2026
- CVE-2026-260422Monitor
Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling
MediumCVSS 5.6No exploitEPSS 0%gnome · evolution data serverJun 17, 2026
- CVE-2026-363426Monitor
Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
MediumCVSS 6.5No exploitEPSS 0%gnome · libsoupMar 17, 2026
- CVE-2026-363326Monitor
Libsoup: libsoup: header and http request injection via crlf injection
MediumCVSS 6.5No exploitEPSS 0%gnome · libsoupMar 17, 2026
- CVE-2026-363222Monitor
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
MediumCVSS 5.5No exploitEPSS 0%gnome · libsoupMar 17, 2026
- CVE-2026-2829617Monitor
Gvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file paths
MediumCVSS 4.3No exploitEPSS 0%red hat · red hat enterprise linux 10Feb 26, 2026
- CVE-2026-2829517Monitor
Gvfs: gvfs ftp backend: information disclosure via untrusted pasv responses
MediumCVSS 4.3No exploitEPSS 0%red hat · red hat enterprise linux 10Feb 26, 2026
- CVE-2026-244321Monitor
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
MediumCVSS 5.3No exploitEPSS 0%gnome · libsoupFeb 13, 2026
- CVE-2026-153923Monitor
Libsoup: libsoup: credential leakage via http redirects
MediumCVSS 5.8No exploitEPSS 0%gnome · libsoupJan 28, 2026
- CVE-2026-153621Monitor
Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header
MediumCVSS 5.3No exploitEPSS 0%gnome · libsoupJan 28, 2026
- CVE-2026-146721Monitor
Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured
MediumCVSS 5.3No exploitEPSS 0%gnome · libsoupJan 27, 2026
- CVE-2026-098814Monitor
Glib: glib: denial of service via integer overflow in g_buffered_input_stream_peek()
LowCVSS 3.7No exploitEPSS 0%red hat · red hat hardened imagesJan 21, 2026
- CVE-2025-1451226Monitor
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
MediumCVSS 6.5No exploitEPSS 1%gnome · glibDec 11, 2025