CVE-2026-12957 is a high-severity vulnerability in Language Servers for AWS before version 1.65.0. The issue involves improper trust boundary enforcement, which may allow for arbitrary code execution if a local user opens a maliciously crafted workspace. This requires the user to trust the workspace when prompted. The vulnerability has a CVSS score of 8.5 and is considered HIGH severity. To remediate this [truncated]
CVE-2026-10740 is a medium-severity vulnerability in s2n-quic, a QUIC implementation. The vulnerability is caused by unbounded memory allocation in the CRYPTO frame reassembler, which may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets.