Messages by Date
-
2026/08/05
[oss-security] CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Enxin Xie
-
2026/08/05
[oss-security] CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP Response Checking
Norbert Pócs
-
2026/08/05
[oss-security] CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Piotr Karwasz
-
2026/08/05
[oss-security] CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Piotr Karwasz
-
2026/08/05
[oss-security] CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Piotr Karwasz
-
2026/08/05
[oss-security] CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
Piotr Karwasz
-
2026/08/05
[oss-security] Multiple vulnerabilities in Jenkins and Jenkins plugins
Daniel Beck
-
2026/08/05
Re: [oss-security] Bouncy Castle 1.85 release fixes 32 CVEs
TvT
-
2026/08/04
[oss-security] FW: X.Org Security Advisory: multiple security issues in libXfont2
Peter Hutterer
-
2026/08/04
[oss-security] CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
Robert Rothenberg
-
2026/08/04
[oss-security] CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
Robert Rothenberg
-
2026/08/04
Re: [oss-security] Some Changes to GNOME Security Tracking
Francis Perron
-
2026/08/04
Re: [oss-security] Some Changes to GNOME Security Tracking
Alan Coopersmith
-
2026/08/04
[oss-security] CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
-
2026/08/04
[oss-security] CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Daniil Kirilyuk
-
2026/08/04
[oss-security] CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Daniil Kirilyuk
-
2026/08/04
[oss-security] CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Daniil Kirilyuk
-
2026/08/04
[oss-security] CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Daniil Kirilyuk
-
2026/08/04
[oss-security] CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Daniil Kirilyuk
-
2026/08/04
[oss-security] CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Daniil Kirilyuk
-
2026/08/04
[oss-security] CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Daniil Kirilyuk
-
2026/08/04
[oss-security] CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Robbie Gemmell
-
2026/08/04
[oss-security] CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Robbie Gemmell
-
2026/08/04
[oss-security] CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded
Robbie Gemmell
-
2026/08/04
[oss-security] CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
Robbie Gemmell
-
2026/08/04
[oss-security] CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
Robbie Gemmell
-
2026/08/04
[oss-security] CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Robbie Gemmell
-
2026/08/04
Re: [oss-security] Bouncy Castle 1.85 release fixes 32 CVEs
Alan Coopersmith
-
2026/08/04
[oss-security] Django CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920
Natalia Bidart
-
2026/08/04
Re: [oss-security] Some Changes to GNOME Security Tracking
Albert Veli
-
2026/08/03
Re: [oss-security] Some Changes to GNOME Security Tracking
Greg KH
-
2026/08/03
Re: [oss-security] Bouncy Castle 1.85 release fixes 32 CVEs
Peter Gutmann
-
2026/08/03
[oss-security] Bouncy Castle 1.85 release fixes 32 CVEs
Alan Coopersmith
-
2026/08/03
Re: [oss-security] Some Changes to GNOME Security Tracking
Aaron Rainbolt
-
2026/08/03
[oss-security] OSSN-0104: Ironic-Python-Agent may fallback to mDNS unexpectedly
Jay Faulkner
-
2026/08/03
[oss-security] CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
David Handermann
-
2026/08/03
[oss-security] CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
David Handermann
-
2026/08/03
[oss-security] CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests
David Handermann
-
2026/08/03
[oss-security] CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
David Handermann
-
2026/08/03
Re: [oss-security] Some Changes to GNOME Security Tracking
Sebastian Pipping
-
2026/08/03
Re: [oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Darrick J. Wong
-
2026/08/03
Re: [oss-security] Some Changes to GNOME Security Tracking
Emily Shepherd
-
2026/08/03
Re: [oss-security] Some Changes to GNOME Security Tracking
David A. Wheeler
-
2026/08/03
[oss-security] CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions
Andy Seaborne
-
2026/08/03
Re: [oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Marco Benatto
-
2026/08/03
Re: [oss-security] Some Changes to GNOME Security Tracking
Yves-Alexis Perez
-
2026/08/03
[oss-security] mpg123 release 1.33.7 with lots of security-relevant fixes
Dr. Thomas Orgis
-
2026/08/02
Re: [oss-security] Some Changes to GNOME Security Tracking
Jacob Bachmeyer
-
2026/08/02
Re: [oss-security] Some Changes to GNOME Security Tracking
Demi Marie Obenour
-
2026/08/02
Re: [oss-security] Some Changes to GNOME Security Tracking
Solar Designer
-
2026/08/02
Re: [oss-security] Some Changes to GNOME Security Tracking
Russ Allbery
-
2026/08/02
Re: [oss-security] Some Changes to GNOME Security Tracking
Peter Gutmann
-
2026/08/02
[oss-security] [CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream)
Abhinav Agarwal
-
2026/08/01
[oss-security] Lean 4 kernel soundness bug: forging proofs via nested inductive projections (0 = 1 demonstrated)
Jonathan Brossard
-
2026/08/01
Re: [oss-security] 33 Vulnerabilities in cJSON
Collin Funk
-
2026/08/01
[oss-security] CVE-2026-18536: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
Robert Rothenberg
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Peter Gutmann
-
2026/07/31
Re: [oss-security] Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
Alan Coopersmith
-
2026/07/31
Re: [oss-security] 33 Vulnerabilities in cJSON
Peter Gutmann
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Demi Marie Obenour
-
2026/07/31
Re: [oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
Thomas Ward
-
2026/07/31
[oss-security] Rejected CVE reports against SQLite, libraw, ESP32-audioI2S
Alan Coopersmith
-
2026/07/31
RE: [oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
Thomas Ward
-
2026/07/31
Re: [oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
Kevin Riggle
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Jeremy Stanley
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Russ Allbery
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Jeremy Stanley
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Alan Coopersmith
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Collin Funk
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Eli Schwartz
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Sebastian Pipping
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
David A. Wheeler
-
2026/07/31
Re: [oss-security] 33 Vulnerabilities in cJSON
Jeroen Roovers
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Aaron Rainbolt
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Sebastian Pipping
-
2026/07/31
Re: [oss-security] Some Changes to GNOME Security Tracking
Aaron Rainbolt
-
2026/07/31
Re: [oss-security] 33 Vulnerabilities in cJSON
Simon McVittie
-
2026/07/31
Re: [oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Dr. Thomas Orgis
-
2026/07/31
[oss-security] CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
Akira Ajisaka
-
2026/07/30
Re: [oss-security] Some Changes to GNOME Security Tracking
Peter Gutmann
-
2026/07/30
[oss-security] PHP 30 July 2026 security releases
Alan Coopersmith
-
2026/07/30
Re: [oss-security] Backports available - cBPF JIT spray hardening
Jose R Rodriguez
-
2026/07/30
[oss-security] Some Changes to GNOME Security Tracking
Alan Coopersmith
-
2026/07/30
Re: [oss-security] 33 Vulnerabilities in cJSON
Collin Funk
-
2026/07/30
[oss-security] o6 Automation open62541: multiple CISA-coordinated OPC UA vulnerabilities
Abhinav Agarwal
-
2026/07/30
[oss-security] CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Tim Allison
-
2026/07/30
[oss-security] CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser
Tim Allison
-
2026/07/30
[oss-security] 33 Vulnerabilities in cJSON
Alan Coopersmith
-
2026/07/30
Re: [oss-security] Backports available - cBPF JIT spray hardening
Greg KH
-
2026/07/30
[oss-security] CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time
Robert Rothenberg
-
2026/07/30
[oss-security] CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check
Robert Rothenberg
-
2026/07/30
[oss-security] CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
Juan Pablo Santos Rodríguez
-
2026/07/30
[oss-security] CVE-2026-28814: Apache JSPWiki: Arbitrary Wiki Markup rendering due to lack of authentication
Juan Pablo Santos Rodríguez
-
2026/07/30
[oss-security] CVE-2026-28813: Apache JSPWiki: JSON hijacking
Juan Pablo Santos Rodríguez
-
2026/07/30
[oss-security] CVE-2026-28812: Apache JSPWiki: UserManager does not sanity-check user database at startup
Juan Pablo Santos Rodríguez
-
2026/07/30
[oss-security] CVE-2026-28811: Apache JSPWiki: Error Handling Reveals Error Details
Juan Pablo Santos Rodríguez
-
2026/07/30
[oss-security] CVE-2026-22068+more: multiple vulnerabilities in Apache Traffic Server prior to 9.2.15/10.1.4
Valtteri Vuorikoski
-
2026/07/30
[oss-security] [SBA-ADV-20260128-04] CVE-2026-16970: DFIR-IRIS 2.4.26 and possibly others Insufficient Logout Implementation
SBA Research Security Advisory
-
2026/07/30
[oss-security] [SBA-ADV-20260128-02] CVE-2026-16971 CVE-2026-18362: DFIR-IRIS 2.4.26 and possibly others Missing Brute Force Protection
SBA Research Security Advisory
-
2026/07/30
[oss-security] [SBA-ADV-20260126-01] CVE-2026-16969 CVE-2026-18360 CVE-2026-18361: DFIR-IRIS 2.4.26 and possibly others Stored XSS
SBA Research Security Advisory
-
2026/07/30
Re: [oss-security] Backports available - cBPF JIT spray hardening
Pawan Gupta
-
2026/07/30
Re: [oss-security] Backports available - cBPF JIT spray hardening
Jose R Rodriguez
-
2026/07/30
[oss-security] CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
Daniel Gaspar
-
2026/07/30
[oss-security] CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
Daniel Gaspar
-
2026/07/30
[oss-security] CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
Akira Ajisaka
-
2026/07/30
[oss-security] CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Jongyoul Lee
-
2026/07/30
[oss-security] CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Jongyoul Lee
-
2026/07/30
[oss-security] CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition
Jongyoul Lee
-
2026/07/30
[oss-security] CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Jongyoul Lee
-
2026/07/29
Re: [oss-security] Fwd: Node.js security updates for all active release lines, June 2026
Alan Coopersmith
-
2026/07/29
[oss-security] Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
Alan Coopersmith
-
2026/07/29
[oss-security] Backports available - cBPF JIT spray hardening
Pawan Gupta
-
2026/07/29
[oss-security] Fwd: [CVE-2026-13346] pip absolute path traversal during download from malicious package indexes
Alan Coopersmith
-
2026/07/29
[oss-security] Fwd: Node.js security updates for all active release lines, June 2026
Rafael Gonzaga
-
2026/07/29
[oss-security] [OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707)
Goutham Pacha Ravi
-
2026/07/29
[oss-security] [NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service
advisories
-
2026/07/29
[oss-security] CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
Akira Ajisaka
-
2026/07/28
Re: [oss-security] Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28
Douglas Bagnall
-
2026/07/28
[oss-security] CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints
Radhika Kundam
-
2026/07/28
[oss-security] [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/07/28
[oss-security] [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/07/28
[oss-security] CVE-2026-66299: Apache Tomcat: DoS via WebSocket chat example
Mark Thomas
-
2026/07/28
[oss-security] Xen Security Advisory 508 v2 - pygrub is only supported in de-privileged mode
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 507 v2 (CVE-2026-62434) - PoD: Don't try to reclaim special pages
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 506 v2 (CVE-2026-62433) - correct buffer checks for DM_OP hypercalls
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 505 v2 (CVE-2026-62432) - evtchn: Race between FIFO expand and reset
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 504 v2 (CVE-2026-62431) - Viridian STIMER division by zero
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 503 v2 (CVE-2026-62430) - x86: Out-of-bounds read in vRTC emulation
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 502 v3 (CVE-2026-62429) - vNUMA domain cleanup may race other operations
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 501 v4 (CVE-2026-62435,CVE-2026-62436) - grant-table: version change racing with other operations
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 500 v2 (CVE-2026-62428) - grant-table: type confusion in grant-copy
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 497 v2 (CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425) - buffer overruns in libfsimage iso9660 handling
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 496 v2 (CVE-2026-42492) - vIRQ event channel binding may break Xenstore
Xen . org security team
-
2026/07/28
[oss-security] Xen Security Advisory 495 v2 (CVE-2026-42493) - x86 shadow paging is deprecated
Xen . org security team
-
2026/07/28
[oss-security] [CVE pending] Eclipse Milo <= 1.1.4: password-recovery oracle, pre-auth DoS, and four server flaws
Abhinav Agarwal
-
2026/07/28
[oss-security] CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
Shahar Epstein
-
2026/07/28
Re: [oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Sam James
-
2026/07/28
[oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
manizada
-
2026/07/28
[oss-security] [NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Write
advisories
-
2026/07/28
Re: [oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Greg KH
-
2026/07/28
Re: [oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Reid Sutherland
-
2026/07/27
[oss-security] [NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
advisories
-
2026/07/27
[oss-security] CVE-2026-17552: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call
Robert Rothenberg
-
2026/07/27
[oss-security] CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Robert Lazarski
-
2026/07/27
Re: [oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Sam James
-
2026/07/27
[oss-security] CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Christopher L. Shannon
-
2026/07/27
[oss-security] CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Christopher L. Shannon
-
2026/07/27
Re: [oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Reid Sutherland
-
2026/07/27
[oss-security] CVE-2026-66391: Apache Wicket: leaked and missing CSP headers
Pedro Henrique Oliveira dos Santos
-
2026/07/27
[oss-security] CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
-
2026/07/27
Re: [oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Solar Designer
-
2026/07/27
[oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Reid Sutherland
-
2026/07/27
Re: [oss-security] 432 Linux kernel CVEs
Loganaden Velvindron
-
2026/07/26
[oss-security] [security] critical vulnerabilities patched in svxlink (RCE)
Mark Rose
-
2026/07/25
Re: [oss-security] 432 Linux kernel CVEs
Demi Marie Obenour
-
2026/07/25
[oss-security] CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
Robert Rothenberg
-
2026/07/25
[oss-security] GNU Inetutils talkd buffer overflow with long DNS names.
Collin Funk
-
2026/07/25
[oss-security] CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports
Collin Funk
-
2026/07/25
[oss-security] Fwd: The GNU C Library version 2.44 is now available, fixes 3 CVEs
Alan Coopersmith
-
2026/07/24
[oss-security] CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-55970: Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-45112: Apache Thrift: Unbounded Read Leading to Denial of Service
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit
Jens Geyer
-
2026/07/24
[oss-security] CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
Jens Geyer
-
2026/07/24
[oss-security] [vim-security] Arbitrary Command Execution via the Vimball Record File in Vim < 9.2.0847
Christian Brabandt
-
2026/07/24
[oss-security] [vim-security] Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846
Christian Brabandt
-
2026/07/24
[oss-security] [vim-security] Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845
Christian Brabandt
-
2026/07/24
[oss-security] [vim-security] Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844
Christian Brabandt
-
2026/07/24
[oss-security] Re: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)
Goutham Pacha Ravi
-
2026/07/24
[oss-security] Re: [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138)
Goutham Pacha Ravi
-
2026/07/24
Re: [oss-security] 432 Linux kernel CVEs
Steffen Nurpmeso
-
2026/07/24
[oss-security] [vim-security] Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843
Christian Brabandt
-
2026/07/24
[oss-security] CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp
Robert Rothenberg
-
2026/07/24
[oss-security] CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service
Duo Zhang
-
2026/07/24
Re: [oss-security] 432 Linux kernel CVEs
Alan Coopersmith