Messages by Date
-
2026/07/24
[oss-security] Re: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)
Goutham Pacha Ravi
-
2026/07/24
[oss-security] Re: [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138)
Goutham Pacha Ravi
-
2026/07/24
Re: [oss-security] 432 Linux kernel CVEs
Steffen Nurpmeso
-
2026/07/24
[oss-security] [vim-security] Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843
Christian Brabandt
-
2026/07/24
[oss-security] CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp
Robert Rothenberg
-
2026/07/24
[oss-security] CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service
Duo Zhang
-
2026/07/24
Re: [oss-security] 432 Linux kernel CVEs
Alan Coopersmith
-
2026/07/24
[oss-security] CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request
Szymon Janc
-
2026/07/24
[oss-security] CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation
Szymon Janc
-
2026/07/24
[oss-security] [vim-security] Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840
Christian Brabandt
-
2026/07/24
[oss-security] [vim-security] Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842
Christian Brabandt
-
2026/07/24
[oss-security] [vim-security] Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841
Christian Brabandt
-
2026/07/24
[oss-security] [vim-security] Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839
Christian Brabandt
-
2026/07/24
[oss-security] CVE-2026-46452: Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure
Szymon Janc
-
2026/07/24
[oss-security] CVE-2026-45811: Apache NimBLE: Buffer overflow in socket HCI transport
Szymon Janc
-
2026/07/24
[oss-security] CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
Szymon Janc
-
2026/07/24
[oss-security] CVE-2026-45812: Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
Szymon Janc
-
2026/07/24
[oss-security] CVE-2026-66144: Apache Neethi: Remote PolicyReference fetch lacks resource bounds
Colm O hEigeartaigh
-
2026/07/24
[oss-security] CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths
Colm O hEigeartaigh
-
2026/07/24
[oss-security] CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing
Colm O hEigeartaigh
-
2026/07/24
[oss-security] CVE-2026-63317: Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML
Richard Zowalla
-
2026/07/24
Re: [oss-security] Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE)
Przemyslaw Frasunek
-
2026/07/24
Re: [oss-security] 432 Linux kernel CVEs
John Haxby
-
2026/07/24
[oss-security] CVE-2026-16634: TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
Robert Rothenberg
-
2026/07/24
[oss-security] libIEC61850: four MMS/GOOSE memory-safety vulnerabilities, including lab RCE
Abhinav Agarwal
-
2026/07/24
[oss-security] Re: 432 Linux kernel CVEs
Sultan Alsawaf
-
2026/07/24
[oss-security] Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28
Douglas Bagnall
-
2026/07/23
[oss-security] CVE-2026-16277 & CVE-2026-16461: buffer overflows in rpcinfo
Alan Coopersmith
-
2026/07/23
[oss-security] [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/07/23
[oss-security] Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE)
Przemyslaw Frasunek
-
2026/07/23
[oss-security] [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/07/23
[oss-security] [OSSA-2026-028] OpenStack Ironic Python Agent: Credential extraction via malicious container (CVE-2026-54422)
Goutham Pacha Ravi
-
2026/07/23
Re: [oss-security] PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues
Otto Moerbeek
-
2026/07/23
Re: [oss-security] 432 Linux kernel CVEs
Peter Gutmann
-
2026/07/23
[oss-security] Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...)
Hanno Böck
-
2026/07/22
Re: [oss-security] 432 Linux kernel CVEs
Steffen Nurpmeso
-
2026/07/22
Re: [oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Marco Benatto
-
2026/07/22
[oss-security] Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Qualys Security Advisory
-
2026/07/22
[oss-security] CVE-2026-13089: OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify
Robert Rothenberg
-
2026/07/22
Re: [oss-security] 432 Linux kernel CVEs
David A. Wheeler
-
2026/07/22
Re: [oss-security] CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel
Solar Designer
-
2026/07/22
[oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Qualys Security Advisory
-
2026/07/22
Re: [oss-security] 432 Linux kernel CVEs
Marcus Meissner
-
2026/07/22
Re: [oss-security] 432 Linux kernel CVEs
Stephan Verbücheln
-
2026/07/22
Re: [oss-security] 432 Linux kernel CVEs
John Haxby
-
2026/07/22
Re: [oss-security] 432 Linux kernel CVEs
Greg KH
-
2026/07/22
[oss-security] security release for Exim
Jeremy Harris
-
2026/07/22
[oss-security] ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)
Michał Kępień
-
2026/07/22
[oss-security] Unbound: 1.25.2 addresses multiple CVE items
Yorgos Thessalonikefs
-
2026/07/22
[oss-security] PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues
Otto Moerbeek
-
2026/07/22
[oss-security] rsyslog v8.36.0 through v8.2606.0: imptcp regex-framing remote denial of service
Rainer Gerhards
-
2026/07/22
[oss-security] PortProtonQt: Custom Polkit Rule Allows Escalation of NetworkManager and UDisks2 Privileges (CVE-2026-59678)
Matthias Gerstner
-
2026/07/22
[oss-security] CVE-2026-54432+more: Roundcube XSS/SSRF/etc prior to 1.6.17/1.7.2
Valtteri Vuorikoski
-
2026/07/21
Re: [oss-security] 432 Linux kernel CVEs
Peter Gutmann
-
2026/07/21
Re: [oss-security] 432 Linux kernel CVEs
Jan Schaumann
-
2026/07/21
Re: [oss-security] 432 Linux kernel CVEs
Steffen Nurpmeso
-
2026/07/21
[oss-security] Multiple vulnerabilities fixed in various Data::*::Shared modules for Perl
Robert Rothenberg
-
2026/07/21
[oss-security] 432 Linux kernel CVEs
Jan Schaumann
-
2026/07/21
[oss-security] libssh 0.12.1 and 0.11.5 security releases
Alan Coopersmith
-
2026/07/21
[oss-security] CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
Chaokun Yang
-
2026/07/21
[oss-security] CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths
Chaokun Yang
-
2026/07/21
[oss-security] CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface
Chaokun Yang
-
2026/07/21
[oss-security] CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free
Chaokun Yang
-
2026/07/21
[oss-security] Re: LPE in snapd and other vulnerabilities
Qualys Security Advisory
-
2026/07/21
[oss-security] LPE in snapd and other vulnerabilities
Eduardo Barretto
-
2026/07/20
[oss-security] CVE-2026-58624: Apache MINA SSHD: Remote execution of JGit commands can write files on the server
Thomas Wolf
-
2026/07/20
[oss-security] CVE-2026-56624: Apache MINA SSHD: SSH certificate options lack validations
Thomas Wolf
-
2026/07/20
[oss-security] CVE-2026-56623: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows
Thomas Wolf
-
2026/07/20
[oss-security] CVE-2026-56452: Apache MINA SSHD: Path traversal in SCP file reception
Thomas Wolf
-
2026/07/20
Re: [oss-security] dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
Alan Coopersmith
-
2026/07/20
[oss-security] CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains
Robert Rothenberg
-
2026/07/20
[oss-security] CVE-2026-64193: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR
Robert Rothenberg
-
2026/07/20
[oss-security] CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass
Francesco Chicchiriccò
-
2026/07/20
[oss-security] CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check
Francesco Chicchiriccò
-
2026/07/20
[oss-security] CVE-2026-62183: Apache Syncope: User self-service privilege escalation
Francesco Chicchiriccò
-
2026/07/20
[oss-security] CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search
Francesco Chicchiriccò
-
2026/07/20
[oss-security] CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector
Francesco Chicchiriccò
-
2026/07/20
[oss-security] CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
Francesco Chicchiriccò
-
2026/07/20
[oss-security] CVE-2026-13577: Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable
Robert Rothenberg
-
2026/07/20
[oss-security] CVE-2026-6656: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
Robert Rothenberg
-
2026/07/20
[oss-security] CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts
Robert Rothenberg
-
2026/07/20
[oss-security] CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel
Wongi Lee
-
2026/07/20
[oss-security] CVE-2026-61548: rsyslog mmpstrucdata stack overflow
Rainer Gerhards
-
2026/07/18
[oss-security] User prompt injection (CSRF) of the llama-server's Web UI (llama.cpp)
Gabriel Corona
-
2026/07/18
[oss-security] OpenSSL "HollowByte" DoS via attacker-controlled memory allocation size in glibc
Jan Schaumann
-
2026/07/17
[oss-security] Cyrus IMAP 3.12.3 fixed 9 CVEs
Alan Coopersmith
-
2026/07/17
[oss-security] 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
Alan Coopersmith
-
2026/07/17
[oss-security] CVE-2026-9537: Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison
Robert Rothenberg
-
2026/07/17
[oss-security] CVE-2026-14741: HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
Robert Rothenberg
-
2026/07/17
[oss-security] CVE-2026-13082: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
Robert Rothenberg
-
2026/07/17
[oss-security] CVE-2026-13410: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
Robert Rothenberg
-
2026/07/17
Re: [oss-security] SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10
Matthias Gerstner
-
2026/07/16
[oss-security] CVE-2026-62764: Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
Christopher Tubbs
-
2026/07/16
[oss-security] CVE-2026-59173: Apache Traffic Server is vulnerable to stalled HTTP/2 flow-control
Masakazu Kitajo
-
2026/07/16
[oss-security] CVE-2026-57077: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len
Paul Johnson
-
2026/07/16
[oss-security] CVE-2026-57076: YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor
Paul Johnson
-
2026/07/16
[oss-security] CVE-2026-57075: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec
Paul Johnson
-
2026/07/16
[oss-security] CVE-2026-13713: YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack
Paul Johnson
-
2026/07/16
[oss-security] CERT VU#885548 - Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
Alan Coopersmith
-
2026/07/16
[oss-security] CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
-
2026/07/16
[oss-security] CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead
Robert Rothenberg
-
2026/07/16
[oss-security] CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
-
2026/07/16
[oss-security] CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead
Robert Rothenberg
-
2026/07/15
[oss-security] Multiple vulnerabilities in ntfs-3g
Rostislav
-
2026/07/15
[oss-security] CVE-2026-26032: Apache Ivy: PackagerResolver path traversal vulnerability
Stefan Bodewig
-
2026/07/15
[oss-security] SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10
Matthias Gerstner
-
2026/07/14
[oss-security] CVE-2026-57821: Apache Fineract: Office list: SQL Injection via Subquery in orderBy
Terence Monteiro
-
2026/07/14
[oss-security] CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
Terence Monteiro
-
2026/07/14
[oss-security] CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint
Terence Monteiro
-
2026/07/14
[oss-security] CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
Stig Palmquist
-
2026/07/14
[oss-security] CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Robert Rothenberg
-
2026/07/14
[oss-security] CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index
Robert Rothenberg
-
2026/07/14
[oss-security] CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Robert Rothenberg
-
2026/07/14
[oss-security] Xen Security Advisory 498 v2 (CVE-2026-42491) - XAPI: Missing TLS verification in some SDKs
Xen . org security team
-
2026/07/14
Re: [oss-security] new af_alg exploit in the wild?
Simon McVittie
-
2026/07/14
[oss-security] CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read
Maxim Solodovnik
-
2026/07/14
[oss-security] CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
Robert Rothenberg
-
2026/07/14
[oss-security] CVE-2026-59084: Apache Tomcat: EncryptInterceptor requirements not clearly documented
Mark Thomas
-
2026/07/14
[oss-security] CVE-2026-59083: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Mark Thomas
-
2026/07/13
[oss-security] CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval
Li Yang
-
2026/07/13
[oss-security] CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API
Li Yang
-
2026/07/13
[oss-security] CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API
Li Yang
-
2026/07/13
[oss-security] CVE-2026-58319: Apache Doris: Improper Authentication in Frontend HTTP API
Mingyu Chen
-
2026/07/13
Re: [oss-security] new af_alg exploit in the wild?
Solar Designer
-
2026/07/13
Re: [oss-security] new af_alg exploit in the wild?
Vincent Lefevre
-
2026/07/13
[oss-security] new af_alg exploit in the wild?
Bernd Zeimetz
-
2026/07/13
[oss-security] 2 CVEs Crypt::OpenSSL::X509 versions before 2.1.3
Timothy Legge
-
2026/07/13
[oss-security] CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Stig Palmquist
-
2026/07/13
[oss-security] CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Stig Palmquist
-
2026/07/13
[oss-security] CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
Stig Palmquist
-
2026/07/13
[oss-security] CVE-2026-59245: Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)
Vincent Beck
-
2026/07/13
[oss-security] CVE-2026-58065: Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
Vincent Beck
-
2026/07/12
[oss-security] CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs
Yu Qi
-
2026/07/12
[oss-security] CVE-2026-41041: Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
Jerry Shao
-
2026/07/12
Re: [oss-security] Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS
Solar Designer
-
2026/07/12
[oss-security] Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS
gregdurys . security
-
2026/07/10
[oss-security] CVE-2026-49844: Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Piotr Karwasz
-
2026/07/10
[oss-security] CVE-2026-40454: Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data
Haonan Hou
-
2026/07/10
[oss-security] CVE-2026-40452: Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users
Haonan Hou
-
2026/07/10
[oss-security] CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor
Haonan Hou
-
2026/07/10
[oss-security] CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
Haonan Hou
-
2026/07/10
[oss-security] CVE-2026-40007: Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
Haonan Hou
-
2026/07/10
[oss-security] CVE-2026-40006: Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
Haonan Hou
-
2026/07/10
[oss-security] CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
Haonan Hou
-
2026/07/10
[oss-security] CVE-2026-28564: Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
Haonan Hou
-
2026/07/09
[oss-security][CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
Alan Coopersmith
-
2026/07/09
[oss-security] HTSlib <= 1.23.1 Multiple vulnerabilities in file reading code
Robert Davies
-
2026/07/09
Re: [oss-security] Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1
Vega Agent
-
2026/07/08
Re: [oss-security] Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1
Solar Designer
-
2026/07/08
Re: [oss-security] CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android
Jan Engelhardt
-
2026/07/08
[oss-security] CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android
Jan Schaumann
-
2026/07/08
[oss-security] Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1
Dr. Thomas Orgis
-
2026/07/08
[oss-security] CVE-2026-57111: Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin
Junkai Xue
-
2026/07/08
[oss-security] Go 1.26.5 and Go 1.25.12 fix CVE-2026-39822 & CVE-2026-42505
Alan Coopersmith
-
2026/07/08
[oss-security] CVE-2026-49147: App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
Stig Palmquist
-
2026/07/08
[oss-security] CVE-2026-49146: App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc
Stig Palmquist
-
2026/07/08
[oss-security] CVE-2026-49145: App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc
Stig Palmquist
-
2026/07/08
[oss-security] CVE-2026-14454: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
Robert Rothenberg
-
2026/07/08
[oss-security] CVE-2026-41042: Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
Jerry Shao
-
2026/07/08
[oss-security] [OSSA-2026-026] Ironic: Insufficient Access Controls regarding parent/child nodes
Jay Faulkner
-
2026/07/08
[oss-security] [OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423)
Jay Faulkner
-
2026/07/07
[oss-security] FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland
Peter Hutterer
-
2026/07/07
[oss-security] FW: X.Org Security Advisory: multiple security issues in libXfont2
Peter Hutterer
-
2026/07/07
[oss-security] CVE-2026-14895: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
Robert Rothenberg
-
2026/07/07
[oss-security] CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Robert Rothenberg
-
2026/07/07
[oss-security] CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Robert Rothenberg
-
2026/07/07
Re: [oss-security] [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
Solar Designer
-
2026/07/07
Re: [oss-security] [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
Joe Stringer
-
2026/07/07
[oss-security] CVE-2026-7017: HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
Robert Rothenberg
-
2026/07/07
Re: [oss-security] [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
Solar Designer
-
2026/07/07
[oss-security] Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
Feroz Salam
-
2026/07/07
[oss-security] Django CVE-2026-48588, CVE-2026-53877, and CVE-2026-53878
Jacob Walls
-
2026/07/07
Re: [oss-security] Wasm OCI Image Fetcher Bearer Realm SSRF Bypass
Solar Designer
-
2026/07/07
Re: [oss-security] Wasm OCI Image Fetcher Bearer Realm SSRF Bypass
yan xu
-
2026/07/07
[oss-security] Foreman: multiple vulnerabilities fixed in 3.18.2 and 3.19.1 (CVE-2026-5135, CVE-2026-5136, CVE-2026-5138, CVE-2026-5142)
Ondrej Gajdusek
-
2026/07/07
[oss-security] CVE-2026-49487: Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
Rahul Vats
-
2026/07/07
[oss-security] CVE-2026-49296: Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}
Rahul Vats
-
2026/07/07
[oss-security] CVE-2026-48892: Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options
Rahul Vats
-
2026/07/07
[oss-security] CVE-2026-48891: Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target
Rahul Vats
-
2026/07/07
[oss-security] CVE-2026-48828: Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key
Rahul Vats
-
2026/07/07
[oss-security] CVE-2026-33264: Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
Rahul Vats
-
2026/07/06
[oss-security] CVE-2026-43867: Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
Andrea Cosentino
-
2026/07/06
[oss-security] CVE-2026-49042: Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
Federico Mariani
-
2026/07/06
[oss-security] CVE-2026-46588: Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Federico Mariani
-
2026/07/06
[oss-security] CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Federico Mariani
-
2026/07/06
[oss-security] CVE-2026-43866: Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder
Andrea Cosentino
-
2026/07/06
[oss-security] CVE-2026-24014: Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
Haonan Hou
-
2026/07/06
[oss-security] CVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
Haonan Hou
-
2026/07/06
[oss-security] CVE-2026-24012: Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
Haonan Hou
-
2026/07/06
[oss-security] CVE-2026-43825: Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
Richard Zowalla
-
2026/07/06
[oss-security] c-ares 1.34.7 release: CVE-2026-33630, GHSA-pjmc-gx33-gc76, GHSA-jv8r-gqr9-68wj
Brad House
-
2026/07/06
[oss-security] Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359)
Hyunwoo Kim
-
2026/07/06
[oss-security] Security Considerations for Statsd Clients
Robert Rothenberg
-
2026/07/06
[oss-security] Announce: OpenSSH 10.4 released
Damien Miller
-
2026/07/06
[oss-security] CVE-2026-13708: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol
Stig Palmquist
-
2026/07/06
[oss-security] CVE-2026-13705: Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
Stig Palmquist
-
2026/07/05
[oss-security] CVE-2026-14803: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder
Stig Palmquist
-
2026/07/05
Re: [oss-security] Wasm OCI Image Fetcher Bearer Realm SSRF Bypass
Eli Schwartz
-
2026/07/05
[oss-security] CVE-2026-56140: Apache Camel: Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components; because camel-aws2-sns is producer-only (no consumer) there is no reachable inbound header-injection path, so this is a defense-in-
Andrea Cosentino
-
2026/07/05
[oss-security] CVE-2026-56139: Apache Camel: Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients - and the option was not honoured
Andrea Cosentino