Messages by Date
-
2026/10/02
[ANNOUNCE] Grails Publish Gradle Plugin 1.0.0-RC2
Mattias Reichel
-
2026/10/02
CVE-2026-59265: Apache OpenOffice: Opening a malicious document can lead to system takeover
Dave Fisher
-
2026/10/02
[ANN] Apache Struts 6.12.0
Lukasz Lenart
-
2026/10/02
CVE-2026-103885: Apache Directory LDAP API: Denial of service via crafted telephone number values
Emmanuel Lécharny
-
2026/10/02
[ANNOUNCE] Apache Gravitino 1.3.1 released
Bharath Krishna
-
2026/10/02
[ANN] Apache Struts 7.4.0
Lukasz Lenart
-
2026/10/02
CVE-2026-102731: Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode
Emmanuel Lécharny
-
2026/10/02
CVE-2026-103877: Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements
Emmanuel Lécharny
-
2026/10/02
CVE-2026-103880: Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords
Emmanuel Lécharny
-
2026/10/02
CVE-2026-103878: Apache Directory LDAP API: Injection of plaintext responses during StartTLS
Emmanuel Lécharny
-
2026/10/02
CVE-2026-103552: Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder
Emmanuel Lécharny
-
2026/10/01
CVE-2026-96292: Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line with a backtracking pattern (quadratic)
Jens Geyer
-
2026/10/01
CVE-2026-61373: Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation
Jens Geyer
-
2026/10/01
CVE-2026-61374: Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit
Jens Geyer
-
2026/10/01
CVE-2026-66837: Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length
Jens Geyer
-
2026/10/01
CVE-2026-66081: Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages
Jens Geyer
-
2026/10/01
CVE-2026-66331: Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize
Jens Geyer
-
2026/10/01
CVE-2026-63772: Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count
Jens Geyer
-
2026/10/01
CVE-2026-66055: Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)
Jens Geyer
-
2026/10/01
CVE-2026-66858: Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)
Jens Geyer
-
2026/10/01
CVE-2026-83663: Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)
Jens Geyer
-
2026/10/01
CVE-2026-83632: Apache Thrift: C++ THttpTransport grows its line buffer without bound
Jens Geyer
-
2026/10/01
CVE-2026-94651: Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse error
Jens Geyer
-
2026/10/01
CVE-2026-82459: Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process
Jens Geyer
-
2026/10/01
CVE-2026-66859: Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route
Jens Geyer
-
2026/10/01
CVE-2026-85086: Apache Thrift: Perl TLS client disables certificate verification by default
Jens Geyer
-
2026/10/01
CVE-2026-66054: Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize
Jens Geyer
-
2026/10/01
CVE-2026-85088: Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match
Jens Geyer
-
2026/10/01
CVE-2026-85087: Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op
Jens Geyer
-
2026/10/01
CVE-2026-83745: Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)
Jens Geyer
-
2026/10/01
CVE-2026-85483: Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end
Jens Geyer
-
2026/10/01
CVE-2026-85476: Apache Thrift: c_glib `read_all` spins when the underlying read returns 0
Jens Geyer
-
2026/10/01
CVE-2026-82458: Apache Thrift: Container element count not bounded by the bytes available
Jens Geyer
-
2026/10/01
CVE-2026-85494: Apache Thrift: Framed transport and binary protocol size a read buffer from a peer-declared length with no effective maximum (multi-language)
Jens Geyer
-
2026/10/01
CVE-2026-85493: Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME)
Jens Geyer
-
2026/10/01
CVE-2026-86535: Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely
Jens Geyer
-
2026/10/01
CVE-2026-86536: Apache Thrift: A map key from the wire can replace a decoded object's prototype in generated JavaScript
Jens Geyer
-
2026/10/01
CVE-2026-94655: Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic
Jens Geyer
-
2026/10/01
CVE-2026-94636: Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used up
Jens Geyer
-
2026/10/01
CVE-2026-96990: Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound
Jens Geyer
-
2026/10/01
CVE-2026-94650: Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion)
Jens Geyer
-
2026/10/01
CVE-2026-94648: Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound
Jens Geyer
-
2026/10/01
CVE-2026-90440: Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service
Jens Geyer
-
2026/10/01
CVE-2026-86537: Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service
Jens Geyer
-
2026/10/01
CVE-2026-93925: Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative protocol id
Jens Geyer
-
2026/10/01
CVE-2026-94633: Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length
Jens Geyer
-
2026/10/01
CVE-2026-94634: Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default
Jens Geyer
-
2026/10/01
CVE-2026-87117: Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element spec
Jens Geyer
-
2026/10/01
CVE-2026-91137: Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements
Jens Geyer
-
2026/10/01
CVE-2026-94652: Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back
Jens Geyer
-
2026/10/01
CVE-2026-94646: Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)
Jens Geyer
-
2026/10/01
CVE-2026-94653: Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)
Jens Geyer
-
2026/10/01
CVE-2026-91135: Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction)
Jens Geyer
-
2026/10/01
CVE-2026-94657: Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound
Jens Geyer
-
2026/10/01
CVE-2026-92834: Apache Thrift: C++ WebSocket server transport does not read a full request length
Jens Geyer
-
2026/10/01
CVE-2026-93926: Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error path
Jens Geyer
-
2026/10/01
CVE-2026-96286: Apache Thrift: Perl servers end `serve()` when serving one connection fails
Jens Geyer
-
2026/10/01
CVE-2026-94638: Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize`
Jens Geyer
-
2026/10/01
CVE-2026-94654: Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame
Jens Geyer
-
2026/10/01
CVE-2026-94656: Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound
Jens Geyer
-
2026/10/01
CVE-2026-94639: Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)
Jens Geyer
-
2026/10/01
CVE-2026-96289: Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard
Jens Geyer
-
2026/10/01
CVE-2026-96277: Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception
Jens Geyer
-
2026/10/01
CVE-2026-96288: Apache Thrift: Erlang generated struct reads have no recursion-depth guard (unbounded memory)
Jens Geyer
-
2026/10/01
CVE-2026-96287: Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)
Jens Geyer
-
2026/10/01
CVE-2026-94645: Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound
Jens Geyer
-
2026/10/01
CVE-2026-94635: Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name
Jens Geyer
-
2026/10/01
CVE-2026-94658: Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic)
Jens Geyer
-
2026/10/01
CVE-2026-94637: Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame
Jens Geyer
-
2026/10/01
CVE-2026-96294: Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection
Jens Geyer
-
2026/10/01
CVE-2026-94644: Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound
Jens Geyer
-
2026/10/01
CVE-2026-94642: Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception
Jens Geyer
-
2026/10/01
[ANNOUNCE] Apache log4net 3.5.0 released
Jan Friedrich
-
2026/10/01
CVE-2026-42356: Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories
Eric Covener
-
2026/10/01
CVE-2026-42528: Apache HTTP Server: mod_dav shared lock overflow
Eric Covener
-
2026/10/01
CVE-2026-46729: Apache HTTP Server: mod_heartmonitor denial of service
Eric Covener
-
2026/10/01
CVE-2026-47360: Apache HTTP Server: mod_session: Session cookie not removed during internal redirect
Eric Covener
-
2026/10/01
CVE-2026-56449: Apache HTTP Server: mod_proxy_html: crash in dump_content
Eric Covener
-
2026/10/01
CVE-2026-57941: Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy
Eric Covener
-
2026/10/01
CVE-2026-48005: Apache HTTP Server: mod_auth_digest reauthentication attack
Eric Covener
-
2026/10/01
CVE-2026-56153: Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char
Eric Covener
-
2026/10/01
CVE-2026-63045: Apache HTTP Server: mod_proxy_ftp PASV address handling
Eric Covener
-
2026/10/01
CVE-2026-59797: Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
Eric Covener
-
2026/10/01
CVE-2026-56154: Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}
Eric Covener
-
2026/10/01
CVE-2026-63718: Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
Eric Covener
-
2026/10/01
CVE-2026-58415: Apache HTTP Server: mod_dav_fs property database read access
Eric Covener
-
2026/10/01
CVE-2026-79768: Apache HTTP Server: mod_userdir information disclosure
Eric Covener
-
2026/10/01
CVE-2026-73636: Apache HTTP Server: mod_auth_digest one-time-nonce replay attack
Eric Covener
-
2026/10/01
CVE-2026-93546: Apache HTTP Server: mod_dav_fs namespace overflow
Eric Covener
-
2026/10/01
CVE-2026-63292: Apache HTTP Server: mod_vhost_alias stack overflow
Eric Covener
-
2026/10/01
CVE-2026-63686: Apache HTTP Server: mod_xml2enc crash on charset conversion failure
Eric Covener
-
2026/10/01
CVE-2026-73637: Apache HTTP Server: mod_auth_digest DoS attack
Eric Covener
-
2026/10/01
CVE-2026-59685: Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM
Eric Covener
-
2026/10/01
[ANNOUNCEMENT] Apache HTTP Server 2.4.69 Released
covener
-
2026/10/01
CVE-2026-94250: Apache APISIX: Batch response aggregation can exhaust worker memory
Abhishek Choudhary
-
2026/10/01
CVE-2026-88789: Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening
James Netherton
-
2026/10/01
[ANNOUNCE] Maven 3.10.0 released
Tamás Cservenák
-
2026/10/01
CVE-2026-82806: Apache APISIX: cross-request permission pollution via static permission list mutation
Abhishek Choudhary
-
2026/10/01
CVE-2026-94220: Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin
Abhishek Choudhary
-
2026/10/01
CVE-2026-94276: Apache APISIX: Openid-connect introspection validation issue
Abhishek Choudhary
-
2026/10/01
CVE-2026-94269: Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch
Abhishek Choudhary
-
2026/10/01
CVE-2026-78242: Apache APISIX: data-mask may fail to redact request headers in logger output
Abhishek Choudhary
-
2026/10/01
CVE-2026-94212: Apache APISIX: unauthenticated impersonation issue in saml-auth
Abhishek Choudhary
-
2026/10/01
[ANN] Maven Resolver 2.0.24 Released
Tamás Cservenák
-
2026/10/01
[ANNOUNCE] Apache APISIX 3.19.0 has been released
Abhishek Choudhary
-
2026/09/30
CVE-2026-87830: Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
Colm O hEigeartaigh
-
2026/09/30
CVE-2026-88920: Apache WSS4J: SAML Sender-Vouches Authentication Bypass
Colm O hEigeartaigh
-
2026/09/30
CVE-2026-92899: Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
Colm O hEigeartaigh
-
2026/09/30
CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
Colm O hEigeartaigh
-
2026/09/30
CVE-2026-89238: Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection
Colm O hEigeartaigh
-
2026/09/30
CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
Colm O hEigeartaigh
-
2026/09/30
CVE-2026-85532: Apache WSS4J: Insufficient Validation of Derived-Key Parameters
Colm O hEigeartaigh
-
2026/09/30
CVE-2026-102508: Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
Christofer Dutz
-
2026/09/30
CVE-2026-102510: Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
Christofer Dutz
-
2026/09/30
CVE-2026-102509: Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Christofer Dutz
-
2026/09/30
CVE-2026-102511: Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them
Christofer Dutz
-
2026/09/29
[ANNOUNCE] Apache Fory 1.7.6 released
Shawn Yang
-
2026/09/29
[ANNOUNCE] Asyncband (Incubating) 0.7.3 released
orthur
-
2026/09/29
CVE-2026-77185: Apache MINA SSHD: Asynchronous authentication can bypass signature verification
Thomas Wolf
-
2026/09/29
[ANNOUNCE] Apache Tika 4.1.0 released
Tim Allison
-
2026/09/29
[ANNOUNCE] Apache Airflow Providers prepared on 2026-09-22 are released
Shahar Epstein
-
2026/09/29
[ANNOUCE] Apache Commons Lang 3.21.0
Gary Gregory
-
2026/09/29
CVE-2026-86843: Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
Shahar Epstein
-
2026/09/29
CVE-2026-93996: Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
Thomas Wolf
-
2026/09/29
CVE-2026-94052: Apache MINA SSHD: LDAP password authentication ineffective
Thomas Wolf
-
2026/09/29
CVE-2026-93995: Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the server
Thomas Wolf
-
2026/09/29
CVE-2026-93994: Apache MINA SSHD: Repeated-publickey policy bypass on server
Thomas Wolf
-
2026/09/29
CVE-2026-94002: Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
Thomas Wolf
-
2026/09/29
CVE-2026-94053: Apache MINA SSHD: LDAP injection in sshd-ldap
Thomas Wolf
-
2026/09/29
CVE-2026-94029: Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension
Thomas Wolf
-
2026/09/29
CVE-2026-102495: Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes
Colm O hEigeartaigh
-
2026/09/29
CVE-2026-102496: Apache XMLSchema: Denial of service through deeply nested schema structures
Colm O hEigeartaigh
-
2026/09/29
CVE-2026-97395: Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials
Jean-Baptiste Onofré
-
2026/09/29
CVE-2026-66083: Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
Wenjun Ruan
-
2026/09/29
[ANNOUNCE] Apache LDAP API 2.1.9 released
Emmanuel Lecharny
-
2026/09/29
CVE-2026-78214: Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
Wenjun Ruan
-
2026/09/29
CVE-2026-102497: Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker
Colm O hEigeartaigh
-
2026/09/29
CVE-2026-71897: Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
Wenjun Ruan
-
2026/09/29
CVE-2026-71899: Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure
Wenjun Ruan
-
2026/09/29
CVE-2026-71898: Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions
Wenjun Ruan
-
2026/09/29
CVE-2026-82804: Apache DolphinScheduler: Command Injection in the Alert Script Plugin
Wenjun Ruan
-
2026/09/29
CVE-2026-81569: Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution
Wenjun Ruan
-
2026/09/29
CVE-2026-81914: Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
Shahar Epstein
-
2026/09/29
CVE-2026-81862: Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs
Shahar Epstein
-
2026/09/29
CVE-2026-81930: Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
Shahar Epstein
-
2026/09/28
[ANNOUNCE] Apache Accumulo 4.0.0-alpha-1
Dave Marion
-
2026/09/28
[ANNOUNCE] Apache MINA SSHD 2.20.0 released
Thomas Wolf
-
2026/09/28
[ANNOUNCE] Apache MINA SSHD 3.0.0-M6 released
Thomas Wolf
-
2026/09/28
https://karaf.apache.org/security/cve-2026-92142.txt: CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
Jean-Baptiste Onofré
-
2026/09/28
https://karaf.apache.org/security/cve-2026-91085.txt: CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
Jean-Baptiste Onofré
-
2026/09/28
CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
Jean-Baptiste Onofré
-
2026/09/28
CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
Jean-Baptiste Onofré
-
2026/09/28
https://karaf.apache.org/security/cve-2026-90979.txt: CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules
Jean-Baptiste Onofré
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas
-
2026/09/28
Re: [ANNOUNCE] Apache Polaris 1.8.0
Alex Dutra
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
Mark Thomas
-
2026/09/28
[ANNOUNCE] Apache Polaris 1.8.0
Jean-Baptiste Onofré
-
2026/09/28
CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy
Hongtao Gao
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas
-
2026/09/28
https://karaf.apache.org/security/cve-2026-91006.txt: CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
Jean-Baptiste Onofré
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas
-
2026/09/28
[UPDATE][SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
Mark Thomas
-
2026/09/27
[ANNOUNCE] Apache Karaf 4.4.12 has been released!
Jean-Baptiste Onofré
-
2026/09/25
[ANNOUNCE] Apache ActiveMQ 6.2.10 has been released!
Jean-Baptiste Onofré
-
2026/09/25
CVE-2026-82379: Apache Roller: WSSE digest authentication headers can be replayed
David M. Johnson
-
2026/09/25
CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation
David M. Johnson
-
2026/09/25
CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
David M. Johnson
-
2026/09/25
CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
David M. Johnson
-
2026/09/25
CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI
David M. Johnson
-
2026/09/25
CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
David M. Johnson
-
2026/09/25
CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
David M. Johnson
-
2026/09/25
CVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity
David M. Johnson
-
2026/09/25
CVE-2026-82376: Apache Roller: XML external entity processing in trackback response parser
David M. Johnson
-
2026/09/25
CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
David M. Johnson
-
2026/09/25
CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
David M. Johnson
-
2026/09/25
CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
David M. Johnson
-
2026/09/25
CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL
David M. Johnson
-
2026/09/25
CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
David M. Johnson
-
2026/09/25
CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links
David M. Johnson
-
2026/09/25
CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type
David M. Johnson
-
2026/09/25
CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator
David M. Johnson
-
2026/09/25
CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments
David M. Johnson
-
2026/09/25
[ANN] Apache CycloneDX Antlib 0.2 Released
Stefan Bodewig
-
2026/09/25
[ANNOUNCE] Apache Grails 7.2.4
Mattias Reichel
-
2026/09/24
[ANNOUNCE] Apache Grails 7.1.7
Mattias Reichel
-
2026/09/24
[ANNOUNCE] Apache Groovy 6.0.0 Released
Paul King
-
2026/09/24
[ANN] Apache Maven 4.0.0-rc-7 Release
Guillaume Nodet
-
2026/09/24
CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder
Daniil Kirilyuk
-
2026/09/24
CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder
Daniil Kirilyuk
-
2026/09/24
CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing
Daniil Kirilyuk
-
2026/09/24
CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering
Daniil Kirilyuk
-
2026/09/24
CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Daniil Kirilyuk
-
2026/09/24
CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
Daniil Kirilyuk