Messages by Date
-
2026/08/25
[oss-security] CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets
Mark Thomas
-
2026/08/25
[oss-security] CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint
Mark Thomas
-
2026/08/25
[oss-security] [CVE-2026-19672] CPython: tarfile extraction filter bypass allows creation of directories outside the destination
Alan Coopersmith
-
2026/08/25
[oss-security] Re: [OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-80182, CVE-2026-80184)
Goutham Pacha Ravi
-
2026/08/25
[oss-security] [vim-security] Arbitrary Ex Command Execution via File Names in C Omni-Completion in Vim < 9.2.1011
Christian Brabandt
-
2026/08/25
[oss-security] CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
Timothy Legge
-
2026/08/25
[oss-security] CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
Timothy Legge
-
2026/08/25
[oss-security] [OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/08/25
[oss-security] OpenRGB: Remote System Compromise via Custom Network Protocol (CVE-2026-59682, CVE-2026-59683, CVE-2026-18794)
Matthias Gerstner
-
2026/08/25
[oss-security] OpenSSL Security Advisory [25th August 2026]
Tomas Mraz
-
2026/08/25
[oss-security] graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS
First name Last name
-
2026/08/24
Re: [oss-security] CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access
Solar Designer
-
2026/08/24
[oss-security] CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Andrea Cosentino
-
2026/08/24
[oss-security] CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure
Dave Brondsema
-
2026/08/24
[oss-security] CVE-2026-78331 / CVE-2026-78332: Multiple Vulnerabilities in NethServer
Intilangelo, Andrea
-
2026/08/24
Re: [oss-security] Linux kernel: Guest-to-Host DoS via TAP
Greg KH
-
2026/08/23
Re: [oss-security] Re: Emacs zero-click local command execution via TRAMP
Sam James
-
2026/08/23
[oss-security] BusyBox dpkg applet: OS command injection
Solar Designer
-
2026/08/23
Re: [oss-security] Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540)
Solar Designer
-
2026/08/23
[oss-security] CVE-2026-78183: DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float
Robert Rothenberg
-
2026/08/23
[oss-security] CVE-2026-19565: Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
Robert Rothenberg
-
2026/08/23
[oss-security] Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540)
Fabiano Fidencio
-
2026/08/23
[oss-security] CVE-2026-75922: Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line
Timothy Legge
-
2026/08/23
[oss-security] CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access
Paul Eggert
-
2026/08/22
[oss-security] CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them
Timothy Legge
-
2026/08/22
[oss-security] CVE-2026-75870: Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret
Timothy Legge
-
2026/08/22
[oss-security] [NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File
advisories
-
2026/08/21
[oss-security] Re: Emacs zero-click local command execution via TRAMP
nightmare . yeah27
-
2026/08/21
[oss-security] CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Robert Rothenberg
-
2026/08/21
Re: [oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
Kevin Riggle
-
2026/08/21
[oss-security] Emacs zero-click local command execution via TRAMP
Sean Whitton
-
2026/08/20
[oss-security] [OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-76878) errata 1
Goutham Pacha Ravi
-
2026/08/20
[oss-security] [OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStack
Goutham Pacha Ravi
-
2026/08/20
[oss-security] CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Manuel Huber
-
2026/08/20
[oss-security] CVE-2026-63044: Apache InLong: Authenticated SSRF via POST /api/node/testConnection
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-15743: Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable
Robert Rothenberg
-
2026/08/20
Re: [oss-security] GNU Emacs vulnerability upon opening arbitrary file
Demi Marie Obenour
-
2026/08/20
[oss-security] CVE-2026-63038: Apache InLong: SQL Injection via String Concatenation Vulnerability Report
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-63016: Apache InLong: Ordinary users can create new packages
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDelete
Charles Zhang
-
2026/08/20
[oss-security] CVE-2026-63015: Apache InLong: Non-template responsible persons can view template information
Charles Zhang
-
2026/08/20
[oss-security] rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv)
Rainer Gerhards
-
2026/08/19
Re: [oss-security] libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requested
Sam James
-
2026/08/19
[oss-security] Fwd: [pfx] Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27
Sam James
-
2026/08/19
[oss-security] Multiple vulnerabilities fixed in libgit2-1.9.5, 1.9.7
Sam James
-
2026/08/19
[oss-security] GNU Emacs vulnerability upon opening arbitrary file
Sam James
-
2026/08/19
[oss-security] uutils coreutils 'stdbuf' uses LD_PRELOAD on a world-writable temporary file
Collin Funk
-
2026/08/19
[oss-security] CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter
Timothy Legge
-
2026/08/19
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005
Adrian Perez de Castro
-
2026/08/19
[oss-security] [OSSA-2026-008] ERRATA 2: Ironic Command Injection in IPMI Console Implementations
Jay Faulkner
-
2026/08/19
[oss-security] Ceph 20.2.4 and Ceph 19.2.6 are released with 4 security fixes.
Sage McTaggart
-
2026/08/19
[oss-security] [OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/08/19
[oss-security] CVE-2026-72889: Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
Robert Rothenberg
-
2026/08/19
[oss-security] CVE-2026-75589: Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify
Robert Rothenberg
-
2026/08/18
[oss-security] Re: GNU Inetutils talkd buffer overflow with long DNS names.
Tristan
-
2026/08/18
[oss-security] CPython [CVE-2026-15806] urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme
Alan Coopersmith
-
2026/08/18
[oss-security] CPython [CVE-2026-17084] StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0
Alan Coopersmith
-
2026/08/17
[oss-security] AI slop "Combined chain advisory — fallback.efi/SBAT/memdisk bypass"
Solar Designer
-
2026/08/17
[oss-security] Re: [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE-2026-74248) errata 1
Jeremy Stanley
-
2026/08/17
[oss-security] LyX security advisory
Pavel Sanda
-
2026/08/16
Re: [oss-security] Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged userns
Aaron Rainbolt
-
2026/08/16
[oss-security] Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged userns
Erica Windisch
-
2026/08/16
[oss-security] CVE-2026-72888: Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require
Robert Rothenberg
-
2026/08/16
[oss-security] CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
Robert Rothenberg
-
2026/08/16
[oss-security] CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
Timothy Legge
-
2026/08/16
[oss-security] libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requested
Sumit Chakraborty
-
2026/08/15
[oss-security] CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
Timothy Legge
-
2026/08/15
[oss-security] CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse
Robert Rothenberg
-
2026/08/15
[oss-security] CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse
Robert Rothenberg
-
2026/08/14
[oss-security] Re: GNU Inetutils talkd buffer overflow with long DNS names.
Collin Funk
-
2026/08/14
Re: [oss-security] CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)
Alan Coopersmith
-
2026/08/14
[oss-security] CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)
Elman Shahbazov
-
2026/08/14
[oss-security] croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)
Souiri Anas
-
2026/08/14
[oss-security] croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)
Souiri Anas
-
2026/08/14
[oss-security] IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)
Bakabaka_9
-
2026/08/14
[oss-security] Info-ZIP test option (-T) command injection
Harry Sintonen
-
2026/08/13
[oss-security] [OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented
Jay Faulkner
-
2026/08/13
[oss-security] Go 1.26.6 and Go 1.25.13 are released with 10 security fixes
Alan Coopersmith
-
2026/08/13
[oss-security] [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE pending)
Jeremy Stanley
-
2026/08/13
[oss-security] CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template
Robert Rothenberg
-
2026/08/13
[oss-security] CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
Robert Rothenberg
-
2026/08/13
[oss-security] CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template
Robert Rothenberg
-
2026/08/13
[oss-security] CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
Stig Palmquist
-
2026/08/13
[oss-security] CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
Arnout Engelen
-
2026/08/13
[oss-security] CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Oleg Kalnichevski
-
2026/08/13
[oss-security] CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Oleg Kalnichevski
-
2026/08/13
[oss-security] OpenSSL Security Advisory
Tomas Mraz
-
2026/08/12
[oss-security] CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
Robert Rothenberg
-
2026/08/12
[oss-security] CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
Robert Rothenberg
-
2026/08/12
[oss-security] rsync 3.5.0 released with fixes for 33 CVEs
Andrew Tridgell
-
2026/08/12
[oss-security] CVE-2026-73238: Apache Allura: XSS in code display
Dave Brondsema
-
2026/08/12
[oss-security] Linux kernel: Guest-to-Host DoS via TAP
Dongli Zhang
-
2026/08/12
[oss-security] CVE-2026-73240: Apache Allura: Git command injection
Dave Brondsema
-
2026/08/12
[oss-security] CVE-2026-73239: Apache Allura: Missing permission checks IDOR
Dave Brondsema
-
2026/08/12
[oss-security] CVE-2026-73237: Apache Allura: XSS in markdown pipeline
Dave Brondsema
-
2026/08/12
[oss-security] CVE-2026-68971: Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-68970: Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-68969: Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-68968: Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-68076: Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-67587: Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-67260: Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-65017: Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-59244: Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-59242: Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-58076: Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-54183: Apache Airflow: Airflow Variables were not masked in the UI for authenticated users
Rahul Vats
-
2026/08/12
[oss-security] CVE-2026-68868: Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables
Jarek Potiuk
-
2026/08/12
[oss-security] CVE-2026-19566: Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths
Robert Rothenberg
-
2026/08/11
Re: [oss-security] Announce: OpenSSH 10.5 released
Alan Coopersmith
-
2026/08/11
[oss-security] xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast message filtering bypass
Simon McVittie
-
2026/08/11
[oss-security] Flatpak 1.18.1 fixes multiple vulnerabilities
Simon McVittie
-
2026/08/11
[oss-security] [OSSN-0106] Ironic API ramdisk endpoints require network-level access controls
Jay Faulkner
-
2026/08/11
[oss-security] [OSSN-0105] OpenStack Glance legacy Tasks import bypasses image import URI filtering
Goutham Pacha Ravi
-
2026/08/11
[oss-security] [OSSA-2026-034] OpenStack Designate: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194)
Goutham Pacha Ravi
-
2026/08/11
[oss-security] libexpat 2.8.3 fixes CVE-2026-72522 (denial of service)
Sebastian Pipping
-
2026/08/11
[oss-security] CVE-2026-69223: Apache Allura: Server-side request forgery
Dave Brondsema
-
2026/08/11
[oss-security] The GNU C Library security advisories update for 2026-04-28
Adhemerval Zanella Netto
-
2026/08/11
[oss-security] PSIRTSUPT-20460 [security] critical vulnerabilities patched in svxlink (RCE)
Thibault Guittet
-
2026/08/10
[oss-security] Announce: OpenSSH 10.5 released
Damien Miller
-
2026/08/10
[oss-security] actix-multipart: field parser hangs indefinitely after EOF on a truncated boundary prefix, leaking the connection slot
Sergei G
-
2026/08/10
[oss-security] CVE-2026-68872: Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
2026/08/10
[oss-security] CVE-2026-68871: Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
2026/08/10
[oss-security] CVE-2026-68870: Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
2026/08/10
[oss-security] Roundcube webmail: Many security fixes in 1.6.18 / 1.7.3
Hanno Böck
-
2026/08/10
[oss-security] CVE-2026-59774: Arbitrary file read via the Org-mode #+INCLUDE directive in Gitea and Forgejo
Tianyu Chen
-
2026/08/10
[oss-security] CVE-2026-44630: Apache IoTDB: RPC service denial of service via unchecked Thrift string length
Haonan Hou
-
2026/08/09
Re: [oss-security] CVE-2026-15534: Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Sevan Janiyan
-
2026/08/09
[oss-security] CVE-2026-15534: Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Stig Palmquist
-
2026/08/08
[oss-security] CVE-2026-65948: Apache Ranger: UnixAuth lacks brute-force protection
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-65945: Apache Ranger: Logs contain replayable JWT bearer tokens
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-65942: Apache Ranger: Clients accept TLS certificates issued for other hostnames
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-55814: Apache Ranger: Download APIs expose plugin data without authentication
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-55799: Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-44416: Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-42537: Apache Ranger: Remote Code Execution via JDBC URL Injection
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-40920: Apache Ranger: Privilege Escalation via URL Parameter
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-32227: Apache Ranger: SQL Injection vulnerability in lookup functionality
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-28672: Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
Velmurugan Periasamy
-
2026/08/08
[oss-security] CVE-2026-17510: Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute
Timothy Legge
-
2026/08/08
[oss-security] CVE-2026-61899: Apache Tapestry: Possible classpath file download through URL manipulation
Thiago Henrique De Paula Figueiredo
-
2026/08/07
Re: [oss-security] CVE-2026-16277 & CVE-2026-16461: buffer overflows in rpcinfo
Alan Coopersmith
-
2026/08/07
Re: [oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
fourie
-
2026/08/07
[oss-security] CVE-2026-17435: File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
Robert Rothenberg
-
2026/08/07
[oss-security] CVE-2026-19082: Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
Stig Palmquist
-
2026/08/07
[oss-security] CVE-2026-71560: Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Chaokun Yang
-
2026/08/07
[oss-security] CVE-2026-71559: Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata
Chaokun Yang
-
2026/08/07
[oss-security] CVE-2026-71558: Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
Chaokun Yang
-
2026/08/07
Re: [oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Dr. Thomas Orgis
-
2026/08/06
Re: [oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
fourie
-
2026/08/06
[oss-security] CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-64958: Apache CXF: Denial of service via message header attachments
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message
Colm O hEigeartaigh
-
2026/08/06
[oss-security] CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
Colm O hEigeartaigh
-
2026/08/06
Re: [oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Solar Designer
-
2026/08/06
[oss-security] CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
Alexandre Dutra
-
2026/08/06
[oss-security] CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Eric Covener
-
2026/08/06
[oss-security] CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Eric Covener
-
2026/08/06
[oss-security] CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Eric Covener
-
2026/08/06
[oss-security] CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash
Eric Covener
-
2026/08/06
[oss-security] CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Eric Covener
-
2026/08/06
Re: [oss-security] Some Changes to GNOME Security Tracking
Jan Schaumann
-
2026/08/06
Re: [oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Emily Shepherd
-
2026/08/06
[oss-security] rust-in-peace: results from agent-assisted Rust OSS vulnerability research
Sergei G
-
2026/08/06
[oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Fourie Zhang
-
2026/08/06
[oss-security] PowerDNS Security Advisory 2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption
Otto Moerbeek
-
2026/08/05
[oss-security] Re: [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-71190)
Goutham Pacha Ravi
-
2026/08/05
[oss-security] Re: [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-71191, CVE-2026-71192)
Goutham Pacha Ravi
-
2026/08/05
[oss-security] Re: [OSSA-2026-007] OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean (CVE-2026-40683)
Goutham Pacha Ravi
-
2026/08/05
[oss-security] [OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201)
Jay Faulkner
-
2026/08/05
[oss-security] ejabberd 26.07 released with several security fixes
Eddie Chapman
-
2026/08/05
[oss-security] CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP Response Checking
Norbert Pócs
-
2026/08/05
[oss-security] CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Piotr Karwasz
-
2026/08/05
[oss-security] CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Piotr Karwasz