Known Vulnerabilities for Validation Authority by Tumbleweed
Listed below are 10 of the newest known vulnerabilities associated with "Validation Authority" by "Tumbleweed".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54781 json | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreW... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-50202 json | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. ... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-49834 json | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparenc... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-48998 json | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header ... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-44502 json | Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypasse... | Not Provided | 2026-05-26 | 2026-05-26 |
| CVE-2026-43972 json | Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unvalidate... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-42959 json | NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can ... | Not Provided | 2026-05-20 | 2026-07-15 |
| CVE-2026-42769 json | Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Managemen... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-28898 json | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them i... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-16221 json | Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not t... | Not Provided | 2026-07-19 | 2026-07-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tumbleweed | Validation Authority | 4.9 | |||
| Application | Tumbleweed | Validation Authority | 4.11.0 | |||
| Application | Tumbleweed | Validation Authority | 4.10.6 | |||
| Application | Tumbleweed | Validation Authority | 1.0.0 | |||
| Application | Tumbleweed | Validation Authority | 1.0 |