Messages by Date
-
2026/09/14
Re: [oss-security] rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback
Alan Coopersmith
-
2026/09/14
[oss-security] CVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search
Francesco Chicchiriccò
-
2026/09/14
[oss-security] Cpython: [CVE-2026-82049] tarfile extraction filters allow file modification and content disclosure via hard link to symlink
Alan Coopersmith
-
2026/09/14
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule
Evgenios Gkritsis
-
2026/09/14
[oss-security] CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-87785: Apache Syncope: JWT subject spoofing
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-87779: Apache Syncope: AES Secret Key disclosure via log output
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task search
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authentication
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduser
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-77147: Apache Syncope: Groovy Sandbox escape for empty CommandArgs
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-73579: Apache Syncope: Non-recursive Any search could skip Realms restrictions
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-73370: Apache Syncope: Cross-Realm boundaries reconciliation bypass
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-73236: Apache Syncope: Cross-Realm authorization bypass in delegated administration
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-73195: Apache Syncope: CSV export spreadsheet formula injection
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-73178: Apache Syncope: JWT Access Token takeover
Francesco Chicchiriccò
-
2026/09/14
[oss-security] CVE-2026-72524: Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables
Calvin Kirs
-
2026/09/14
[oss-security] CVE-2026-68570: Apache Doris: Authorization bypass leading to unauthorized data access
Calvin Kirs
-
2026/09/14
[oss-security] Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Sean Whitton
-
2026/09/13
Re: [oss-security] CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
Gabriel Ravier
-
2026/09/13
[oss-security] CVE-2026-82433: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82429: Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
Richard Zowalla
-
2026/09/13
Re: [oss-security] AI slops from Eve
Solar Designer
-
2026/09/13
[oss-security] CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys
Richard Zowalla
-
2026/09/13
Re: [oss-security] AI slops from Eve
Jeroen Roovers
-
2026/09/13
[oss-security] CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82431: Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82428: Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82427: Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name
Richard Zowalla
-
2026/09/13
[oss-security] CVE-2026-82426: Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location
Richard Zowalla
-
2026/09/13
[oss-security] GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efi
Luppa
-
2026/09/13
Re: [oss-security] Retrospective by 'gpg.fail' authors
Peter Gutmann
-
2026/09/12
[oss-security] Retrospective by 'gpg.fail' authors
Sam James
-
2026/09/12
[oss-security] Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations
Sam James
-
2026/09/12
[oss-security] Fwd: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations
Sam James
-
2026/09/12
Re: [oss-security] AI slops from Eve
Collin Funk
-
2026/09/12
Re: [oss-security] AI slops from Eve
David A. Wheeler
-
2026/09/12
[oss-security] [vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090
Christian Brabandt
-
2026/09/12
[oss-security] Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey
12345678
-
2026/09/11
Re: [oss-security] AI slops from Eve
Joe Krause
-
2026/09/11
[oss-security] CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns
Richard Zowalla
-
2026/09/11
Re: [oss-security] pcre2 version 10.48 released with security fixes
Alan Coopersmith
-
2026/09/11
[oss-security] CPython: [CVE-2026-87910] tarfile hardlink fallback ignores custom extraction filter rejection via None
Alan Coopersmith
-
2026/09/11
[oss-security] CVE-2026-67211: Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer
Richard Zowalla
-
2026/09/11
Re: [oss-security] AI slops from Eve
Solar Designer
-
2026/09/11
Re: [oss-security] AI slops from Eve
Solar Designer
-
2026/09/11
Re: [oss-security] AI slops from Eve
Martin Hecht
-
2026/09/11
[oss-security] CVE-2026-82583, CVE-2026-78224, CVE-2026-82578: NextGen Mirth Connect SQL injection and XXE
Abhinav Agarwal
-
2026/09/10
[oss-security] The GNU C Library security advisory update for 2026-09-10
Siddhesh Poyarekar
-
2026/09/10
Re: [oss-security] AI slops from Eve
Ellenor Bjornsdottir
-
2026/09/10
Re: [oss-security] AI slops from Eve
Jeffrey Walton
-
2026/09/10
Re: [oss-security] AI slops from Eve
Eli Schwartz
-
2026/09/10
[oss-security] CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects
Pasquale Congiusti
-
2026/09/10
[oss-security] CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36
Valtteri Vuorikoski
-
2026/09/10
[oss-security] CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
Pasquale Congiusti
-
2026/09/10
[oss-security] CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
Pasquale Congiusti
-
2026/09/09
[oss-security] GDCM <= 3.2.7: six memory-safety and denial-of-service vulnerabilities, no CVE
Abhinav Agarwal
-
2026/09/09
[oss-security] AI slops from Eve
Solar Designer
-
2026/09/09
[oss-security] iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level)
Eve
-
2026/09/09
[oss-security] Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design)
Eve
-
2026/09/09
[oss-security] Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT
Eve
-
2026/09/09
[oss-security] Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releases
Solar Designer
-
2026/09/09
[oss-security] CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
Clebert Suconic
-
2026/09/09
[oss-security] CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
Clebert Suconic
-
2026/09/09
[oss-security] CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment
Clebert Suconic
-
2026/09/09
[oss-security] CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service
Clebert Suconic
-
2026/09/09
[oss-security] CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
Clebert Suconic
-
2026/09/09
[oss-security] CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription
Clebert Suconic
-
2026/09/09
[oss-security] CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation
Clebert Suconic
-
2026/09/09
[oss-security] Fwd: XZ Utils 5.8.4 and a security fix
Sam James
-
2026/09/09
[oss-security] CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)
Mr. Gatto
-
2026/09/09
Re: [oss-security] bubblewrap 0.12.0 fixes writes outside sandbox
Simon McVittie
-
2026/09/09
[oss-security] Security fixes in libfuse-3.18.3
Sam James
-
2026/09/08
[oss-security] libpcap 1.10.7 fixes 7 vulnerabilities
Denis Ovsienko
-
2026/09/08
[oss-security] CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading
Michael Smith
-
2026/09/08
[oss-security] CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF
Michael Smith
-
2026/09/08
[oss-security] CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token
Michael Smith
-
2026/09/08
[oss-security] CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery
Michael Smith
-
2026/09/08
[oss-security] Fwd: Tor Project Forum: Security Release 0.4.9.12
Sam James
-
2026/09/08
Re: [oss-security] Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more
Dominique Martinet
-
2026/09/08
[oss-security] CVE-2026-85630: HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method
Robert Rothenberg
-
2026/09/08
[oss-security] CVE-2026-85485: HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping
Robert Rothenberg
-
2026/09/08
[oss-security] CVE-2026-85484: HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
Robert Rothenberg
-
2026/09/08
[oss-security] CVE-2026-19872: HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message
Robert Rothenberg
-
2026/09/08
Re: [oss-security] Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more
Dr. Thomas Orgis
-
2026/09/08
[oss-security] CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
Niko Oliveira
-
2026/09/08
[oss-security] Xen Security Advisory 510 v3 (CVE-2026-79602) - x86: improper handling of HVM emulation return codes
Xen . org security team
-
2026/09/08
[oss-security] Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdisk
Xen . org security team
-
2026/09/08
[oss-security] CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
Dániel Dékány
-
2026/09/08
[oss-security] CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Matt Pavlovich
-
2026/09/08
[oss-security] CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation
Gidon Gershinsky
-
2026/09/08
[oss-security] Xen Security Advisory 512 v3 (CVE-2026-79604) - oxenstored: Unbounded accumulation of watches
Xen . org security team
-
2026/09/08
[oss-security] Xen Security Advisory 511 v3 (CVE-2026-79603) - Unconditionally do TLB flushing ahead of page scrubbing
Xen . org security team
-
2026/09/08
[oss-security] CVE-2026-41870: Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
Sebastian Nagel
-
2026/09/08
[oss-security] Xen Security Advisory 509 v3 (CVE-2026-62437) - x86: DMs may cause mem leak by IRQ binding
Xen . org security team
-
2026/09/08
[oss-security] CVE-2026-41871: Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
Sebastian Nagel
-
2026/09/08
[oss-security] CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)
Sebastian Nagel
-
2026/09/07
[oss-security] Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more
Yuan Tan
-
2026/09/07
[oss-security] CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
Robert Rothenberg
-
2026/09/07
[oss-security] CVE-2026-86287: Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
Robert Rothenberg
-
2026/09/06
[oss-security] CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
Timothy Legge
-
2026/09/06
[oss-security] Fwd: [mapserver-announce] security release available: MapServer 8.6.6
Sam James
-
2026/09/06
[oss-security] CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write
Stefan Bodewig
-
2026/09/06
[oss-security] CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
Timothy Legge
-
2026/09/05
[oss-security] Fwd: Security vulnerabilities fixed in WeeChat 4.10.1
Sam James
-
2026/09/05
Re: [oss-security] Vulnerabilities fixed in libxml2-2.15.4
Salvatore Bonaccorso
-
2026/09/05
Re: [oss-security] pcre2 version 10.48 released with security fixes
Salvatore Bonaccorso
-
2026/09/05
Re: [oss-security] Vulnerability fixes in util-linux-2.42.3
Salvatore Bonaccorso
-
2026/09/05
Re: [oss-security] Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released
Salvatore Bonaccorso
-
2026/09/04
[oss-security] pcre2 version 10.48 released with security fixes
Alan Coopersmith
-
2026/09/04
[oss-security] Vulnerability fixes in util-linux-2.42.3
Sam James
-
2026/09/04
[oss-security] Vulnerabilities fixed in libxml2-2.15.4
Sam James
-
2026/09/04
[oss-security] CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module
Arnout Engelen
-
2026/09/04
[oss-security] CVE-2026-82309: Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries
Robert Rothenberg
-
2026/09/03
[oss-security] CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Sheng Wu
-
2026/09/03
[oss-security] CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
Kai Wan
-
2026/09/03
[oss-security] [OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)
Goutham Pacha Ravi
-
2026/09/03
[oss-security] CVE-2026-80530: Linux XFS EXCHANGE_RANGE reflink flag clearing leading to local privilege escalation
Lin Jiapeng
-
2026/09/03
[oss-security] CVE-2026-80180: Apache Allura: Stored XSS via markdown HTML processing
Dave Brondsema
-
2026/09/03
[oss-security] CVE-2026-81270: Apache Allura: Information exposure via search
Dave Brondsema
-
2026/09/03
[oss-security] CVE-2026-80190: Apache Allura: Stored XSS via code repositories
Dave Brondsema
-
2026/09/03
[oss-security] CVE-2026-80181: Apache Allura: Server-side request forgery
Dave Brondsema
-
2026/09/02
[oss-security] Fwd: Vulnerabilities in golang.org/x/crypto
Alan Coopersmith
-
2026/09/02
[oss-security] Multiple vulnerabilities in Jenkins and Jenkins plugins
Kevin Guerroudj
-
2026/09/02
[oss-security] [SECURITY ADVISORIES] curl 8.22.0
Daniel Stenberg
-
2026/09/02
Re: [oss-security] Fwd: [Announce] Libgcrypt 1.12.3 released
Sam James
-
2026/09/02
[oss-security] CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record
Timothy Legge
-
2026/09/01
[oss-security] CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4
Holden Karau
-
2026/09/01
[oss-security] CVE-2026-80205 : ReDoS in NLTK Text.findall() (CVSS 8.7 High)
Aditi Bhatnagar
-
2026/09/01
[oss-security] FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstrated
Samuel Page
-
2026/08/31
Re: [oss-security] CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements
Robert Rothenberg
-
2026/08/31
[oss-security] CVE-2026-76986: Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue
Emond Papegaaij
-
2026/08/31
[oss-security] Plone security advisory 20260831
Maurits van Rees (Plone)
-
2026/08/31
[oss-security] CVE-2026-19953: URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
Robert Rothenberg
-
2026/08/31
[oss-security] libexpat 2.8.4 fixes 4 vulnerabilities
Sebastian Pipping
-
2026/08/31
Re: [oss-security] Fwd: [Announce] Libgcrypt 1.12.3 released
Werner Koch
-
2026/08/31
[oss-security] libksba-1.8.1 fixes a possible CMS parser infinite loop
Sam James
-
2026/08/31
[oss-security] LACT: Polkit Authentication Bypass and Temporary File Handling Issues (CVE-2026-75037, CVE-2026-75038)
Matthias Gerstner
-
2026/08/31
[oss-security] Fwd: [Announce] Libgcrypt 1.12.3 released
Sam James
-
2026/08/31
[oss-security] CVE-2026-76983: Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel
Emond Papegaaij
-
2026/08/31
[oss-security] CVE-2026-76984: Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute
Emond Papegaaij
-
2026/08/31
[oss-security] CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements
Robert Rothenberg
-
2026/08/31
[oss-security] CVE-2026-76985: Apache Wicket: XSS in Palette via getAdditionalAttributes
Emond Papegaaij
-
2026/08/31
[oss-security] CVE-2026-76982: Apache Wicket: XSS in Button via its model object
Emond Papegaaij
-
2026/08/31
[oss-security] CVE-2026-75802: Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel
Emond Papegaaij
-
2026/08/30
[oss-security] CVE-2026-71378: Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener
Emond Papegaaij
-
2026/08/30
[oss-security] CVE-2026-71257: Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed
Emond Papegaaij
-
2026/08/30
[oss-security] CVE-2026-70449: Apache Wicket: Path traversal in resource style/variation/locale
Emond Papegaaij
-
2026/08/30
[oss-security] CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate host
Lenny Primak
-
2026/08/30
[oss-security] Exiv2 0.28.9 released
Kevin Backhouse
-
2026/08/29
[oss-security] Re: graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS
William Carrier
-
2026/08/29
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via full-schema "did you mean" suggestion scan
William Carrier
-
2026/08/29
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS from a single syntax error
William Carrier
-
2026/08/29
[oss-security] CVE-2026-78002: rsyslog RainerScript replace() heap buffer overflow
Rainer Gerhards
-
2026/08/28
[oss-security] Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293)
t.preissl
-
2026/08/28
[oss-security] Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released
Chad Dougherty
-
2026/08/28
[oss-security] [CVE-2026-8715] HashiCorp Vault Secrets Operator 1.3.0-1.4.1: tenant-controlled secretIDPath leaks operator ServiceAccount token (path to cluster-admin)
cherez0ff
-
2026/08/28
[oss-security] NSD 4.15.1 security release
Willem Toorop
-
2026/08/28
[oss-security] Dovecot Security Advisory 3/2026
Aki Tuomi
-
2026/08/27
[oss-security] bubblewrap 0.12.0 fixes writes outside sandbox
Simon McVittie
-
2026/08/27
[oss-security] The GNU C Library security advisory update for 2026-08-27
Siddhesh Poyarekar
-
2026/08/26
Re: Re: [oss-security] Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely
Greg KH
-
2026/08/26
Re: Re: [oss-security] Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely
Syed
-
2026/08/26
Re: [oss-security] Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely
Greg KH
-
2026/08/26
Re: [oss-security] CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access
Jim Meyering
-
2026/08/26
[oss-security] Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely
Syed
-
2026/08/26
[oss-security] [vim-security] Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688
Christian Brabandt
-
2026/08/26
[oss-security] [vim-security] Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013
Christian Brabandt
-
2026/08/26
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via per-error full-document rescan (GetLocation)
First name Last name
-
2026/08/26
[oss-security] CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
Abhishek Choudhary
-
2026/08/26
[oss-security] CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS
Abhishek Choudhary
-
2026/08/26
[oss-security] Re: Emacs zero-click local command execution via TRAMP
Sean Whitton
-
2026/08/26
[oss-security] CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins
Abhishek Choudhary
-
2026/08/25
[oss-security] CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
Abhishek Choudhary
-
2026/08/25
[oss-security] CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint
Mark Thomas