Messages by Date
-
2026/09/28
[oss-security] CVE-2026-88815: DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv
Robert Rothenberg
-
2026/09/28
[oss-security] CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
Jean-Baptiste Onofré
-
2026/09/28
[oss-security] CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
Jean-Baptiste Onofré
-
2026/09/28
[oss-security] CVE-2026-85644: XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference
Robert Rothenberg
-
2026/09/28
[oss-security] CVE-2026-88816: DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName
Robert Rothenberg
-
2026/09/28
[oss-security] CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
Jean-Baptiste Onofré
-
2026/09/28
[oss-security] CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
Jean-Baptiste Onofré
-
2026/09/28
[oss-security] The GNU C Library security advisory update for 2026-09-28
Siddhesh Poyarekar
-
2026/09/28
[oss-security] Flatpak 1.18.4 fixes multiple security vulnerabilities
Simon McVittie
-
2026/09/28
[oss-security] CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy
Hongtao Gao
-
2026/09/28
[oss-security] crontab(1) silently truncates file path arguments >=100 chars
Vincent Lefevre
-
2026/09/28
[oss-security] CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
Jean-Baptiste Onofré
-
2026/09/28
[oss-security] CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules
Jean-Baptiste Onofré
-
2026/09/28
[oss-security] [kubernetes] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes
Vyom Yadav
-
2026/09/26
Re: [oss-security] CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
Simon McVittie
-
2026/09/25
[oss-security] CVE-2026-95510: GNU Inetutils: use of uninitialized struct sigaction
Collin Funk
-
2026/09/25
[oss-security] CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
Haitam Lazaar
-
2026/09/25
[oss-security] CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82379: Apache Roller: WSSE digest authentication headers can be replayed
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82376: Apache Roller: XML external entity processing in trackback response parser
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
David M. Johnson
-
2026/09/25
[oss-security] CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
David M. Johnson
-
2026/09/25
[oss-security] [NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
advisories
-
2026/09/25
Re: [oss-security] XSS vulnerability in <ansi2html-1.9.4
Sebastian Pipping
-
2026/09/25
[oss-security] [NotCVE-2026-0014] Input Leap 3.0.3 Drag-and-Drop File Transfer Path Traversal Allows Arbitrary File Write Outside the Drop Directory
advisories
-
2026/09/24
[oss-security] CVE-2026-95811: Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it
Timothy Legge
-
2026/09/24
[oss-security] CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
Timothy Legge
-
2026/09/24
[oss-security] CVE-2026-92288: Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party
Timothy Legge
-
2026/09/24
[oss-security] CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Daniil Kirilyuk
-
2026/09/24
[oss-security] CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
Daniil Kirilyuk
-
2026/09/24
[oss-security] CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering
Daniil Kirilyuk
-
2026/09/24
[oss-security] CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing
Daniil Kirilyuk
-
2026/09/24
[oss-security] CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder
Daniil Kirilyuk
-
2026/09/24
[oss-security] CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder
Daniil Kirilyuk
-
2026/09/24
[oss-security] XSS vulnerability in <ansi2html-1.9.4
Sam James
-
2026/09/24
[oss-security] CVE-2026-97230: IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL
Robert Rothenberg
-
2026/09/24
Re: [oss-security] CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone
Robert Rothenberg
-
2026/09/24
[oss-security] CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone
Robert Rothenberg
-
2026/09/24
[oss-security] CVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key
Jarek Potiuk
-
2026/09/24
[oss-security] [OSSA-2026-042] OpenStack Zaqar: Zaqar empty URL-Signature header bypasses authentication (CVE-2026-97404)
Goutham Pacha Ravi
-
2026/09/24
[oss-security] [OSSA-2026-041] OpenStack Swift: Cross-container information disclosure via Swift tempurl (CVE-2026-97149)
Goutham Pacha Ravi
-
2026/09/24
[oss-security] CVE-2026-96512: sudo: TZ still affects NOTBEFORE/NOTAFTER
Ermenson Junior
-
2026/09/24
[oss-security] CVE-2026-57590: Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations
Wenjun Ruan
-
2026/09/23
[oss-security] Fwd: Tor Project Forum: Security Release 0.4.9.13
Sam James
-
2026/09/23
Re: [oss-security] Fwd: Tor Project Forum: Security Release 0.4.9.12
Sam James
-
2026/09/23
[oss-security] [kubernetes] CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion
Nathan Herz
-
2026/09/23
[oss-security] [kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation
Nathan Herz
-
2026/09/23
Re: [oss-security] Flatpak 1.18.1 fixes multiple vulnerabilities
Simon McVittie
-
2026/09/23
[oss-security] CVE-2026-86247: Apache Tomcat Native: Client certificate requirements can be down-graded
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-86246: Apache Tomcat Native: Insecure OpenSSL options enabled
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-86243: Apache Tomcat Native: DoS via TLS handshake
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-87022: Apache Tomcat: WebSocket message smuggling with per-message-deflate
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-86350: Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-79677: Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-78437: Apache Tomcat: HTTP/2 DoS via malformed request
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-78383: Apache Tomcat: AJP DoS via missing request body
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-77791: Apache Tomcat: DoS via busy wait during WebSocket close
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-77762: Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-77756: Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-76183: Apache Tomcat: Bypass of security constraints for WebSocket endpoints
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-75973: Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-73581: Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Mark Thomas
-
2026/09/23
[oss-security] CVE-2026-73192: Apache Sling XSS: XSS possible through XSSAPI.getValidHref()
Joerg Hoh
-
2026/09/23
[oss-security] CVE-2026-94251: Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource
Joerg Hoh
-
2026/09/23
[oss-security] CVE-2026-94243: Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
Joerg Hoh
-
2026/09/23
[oss-security] CVE-2026-92001: Apache Sling XSS: Missing parser resource limits
Joerg Hoh
-
2026/09/23
[oss-security] CVE-2026-91999: Apache Sling XSS: Improper escaping in the XSS Webconsole plugin
Joerg Hoh
-
2026/09/23
[oss-security] CVE-2026-91928: Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms
Joerg Hoh
-
2026/09/23
[oss-security] CVE-2026-91852: Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl
Joerg Hoh
-
2026/09/23
[oss-security] CVE-2026-96443: Apache Doris: JDBC driver URL validation bypass leads to remote code execution
Calvin Kirs
-
2026/09/23
[oss-security] CVE-2026-31377: Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
Calvin Kirs
-
2026/09/23
[oss-security] CVE-2026-82331: Apache BuildStream: tar source extraction escape
Jürg Billeter
-
2026/09/23
[oss-security] npm registry keeps removed-version timestamps but drops the reason (Sept 2025 campaign as evidence)
ezraax
-
2026/09/23
Re: [oss-security] GNU Emacs vulnerability upon opening arbitrary file
Tomas Hoger
-
2026/09/23
Re: [oss-security] Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Tomas Hoger
-
2026/09/23
[oss-security] xdg-dbus-proxy 0.1.9 fixes sandbox escape CVE-2026-94422
Simon McVittie
-
2026/09/23
[oss-security] Vulnerabilities in ntfs-3g
Rostislav
-
2026/09/23
Re: [oss-security] CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
Robert Rothenberg
-
2026/09/22
[oss-security] CVE-2026-94184: some builds of fetchmail 6.6.6 and older vulnerable to remote code execution in NTLM authentication client (revised fetchmail-SA-2026-01)
Matthias Andree
-
2026/09/22
Re: [oss-security] CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
Sam James
-
2026/09/22
Re: [oss-security] xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast message filtering bypass
Simon McVittie
-
2026/09/22
Re: [oss-security] bubblewrap 0.12.0 fixes writes outside sandbox
Simon McVittie
-
2026/09/22
Re: [oss-security] Flatpak 1.18.1 fixes multiple vulnerabilities
Simon McVittie
-
2026/09/22
[oss-security] CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
Robert Rothenberg
-
2026/09/22
[oss-security] The GNU C Library security advisories update for 2026-09-22
Carlos O'Donell
-
2026/09/22
[oss-security] rsyslog imdtls permitted-peer authorization bypass
Rainer Gerhards
-
2026/09/22
[oss-security] [OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-94572, CVE-2026-94571)
Goutham Pacha Ravi
-
2026/09/22
[oss-security] CVE-2026-87082: Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode
Paul Johnson
-
2026/09/22
[oss-security] CVE-2026-87081: Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii
Paul Johnson
-
2026/09/22
[oss-security] CVE-2026-87080: Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode
Paul Johnson
-
2026/09/22
[oss-security] CVE-2026-87079: Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode
Paul Johnson
-
2026/09/22
[oss-security] CVE-2026-87078: Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode
Paul Johnson
-
2026/09/22
[oss-security] CVE-2026-74766: Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode
Paul Johnson
-
2026/09/22
[oss-security] CVE-2026-74765: Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode
Paul Johnson
-
2026/09/22
[oss-security] CVE-2016-15059: Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode
Paul Johnson
-
2026/09/22
Re: [oss-security] Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Bas Alberts
-
2026/09/22
[oss-security] libexpat 2.8.5 fixes CVE-2026-93990 (malformed UTF-16 smuggling)
Sebastian Pipping
-
2026/09/22
[oss-security] New OpenSSL Releases
Norbert Pócs
-
2026/09/22
Re: [oss-security] Vulnerabilities in libheif and libde265
Hanno Böck
-
2026/09/22
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Eli Schwartz
-
2026/09/21
[oss-security] CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler
Stig Palmquist
-
2026/09/21
[oss-security] CVE-2026-93711: Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array
Stig Palmquist
-
2026/09/21
[oss-security] CVE-2026-93710: Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks
Stig Palmquist
-
2026/09/21
[oss-security] CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler
Stig Palmquist
-
2026/09/21
Re: [oss-security] Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Tomas Hoger
-
2026/09/21
[oss-security] CVE-2026-93012: Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe
Stig Palmquist
-
2026/09/21
[oss-security] [OSSA-2026-040] OpenStack Blazar: Multiple authorization vulnerabilities in the Blazar V2 lease API (CVE-2026-93852, CVE-2026-93854)
Goutham Pacha Ravi
-
2026/09/21
[oss-security] [OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/09/21
[oss-security] CVE-2026-86473: Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry
Rahul Vats
-
2026/09/21
[oss-security] CVE-2026-82355: Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation
Rahul Vats
-
2026/09/21
[oss-security] CVE-2026-75158: Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter
Rahul Vats
-
2026/09/21
[oss-security] CVE-2026-94301: Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232
Emmanuel Lécharny
-
2026/09/21
[oss-security] CVE-2026-47321: Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate
Emmanuel Lécharny
-
2026/09/20
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Roman Fiedler
-
2026/09/20
[oss-security] rsyslog: mmpstrucdata denial of service fixed in 8.2606.0
Rainer Gerhards
-
2026/09/20
Re: [oss-security] Suricata 8.0.7 released with 67 vulnerabilities fixed
Sam James
-
2026/09/19
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Greg Dahlman
-
2026/09/19
[oss-security] CVE-2026-82560: Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width
Stig Palmquist
-
2026/09/19
Re: [oss-security] Vulnerabilities in libheif and libde265
Hanno Böck
-
2026/09/19
[oss-security] CVE-2026-78030: DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM
Robert Rothenberg
-
2026/09/19
Re: [oss-security] Suricata 8.0.7 released with 67 vulnerabilities fixed
Victor Julien
-
2026/09/18
[oss-security] Exim Security Release 4.100.1
Solar Designer
-
2026/09/18
[oss-security] Suricata 8.0.7 released with 67 vulnerabilities fixed
Alan Coopersmith
-
2026/09/18
[oss-security] Vulnerabilities in libheif and libde265
Alan Coopersmith
-
2026/09/18
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
SOFIA ETCHEPARE DARONCO
-
2026/09/18
[oss-security] CVE-2026-93019: Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read
Stig Palmquist
-
2026/09/18
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Eli Schwartz
-
2026/09/18
[oss-security] CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely
Colm O hEigeartaigh
-
2026/09/18
[oss-security] CVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service
Colm O hEigeartaigh
-
2026/09/18
[oss-security] CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service
Colm O hEigeartaigh
-
2026/09/18
[oss-security] CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service
Colm O hEigeartaigh
-
2026/09/18
[oss-security] CVE-2026-93018: Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p
Stig Palmquist
-
2026/09/18
[oss-security] CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion
Colm O hEigeartaigh
-
2026/09/18
Re: [oss-security] Removing dead code (was: Retrospective by 'gpg.fail' authors)
Peter Gutmann
-
2026/09/18
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Kevin Riggle
-
2026/09/18
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Valtteri Vuorikoski
-
2026/09/18
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Hanno Böck
-
2026/09/17
[oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
manizada
-
2026/09/17
Re: [oss-security] Removing dead code (was: Retrospective by 'gpg.fail' authors)
Jacob Bachmeyer
-
2026/09/17
[oss-security] CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)
Rahul Vats
-
2026/09/17
[oss-security] CVE-2026-73639: Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8
Stig Palmquist
-
2026/09/17
[oss-security] CVE-2026-73638: Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd
Stig Palmquist
-
2026/09/17
[oss-security] CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching
Jean-Baptiste Onofré
-
2026/09/17
[oss-security] The GNU C Library security advisories update for 2026-09-17
Adhemerval Zanella Netto
-
2026/09/17
Re: [oss-security] Retrospective by 'gpg.fail' authors
Werner Koch
-
2026/09/16
Re: [oss-security] Retrospective by 'gpg.fail' authors
Peter Gutmann
-
2026/09/16
[oss-security] CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2
Haitam Lazaar
-
2026/09/16
[oss-security] CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
David Handermann
-
2026/09/16
Re: [oss-security] Retrospective by 'gpg.fail' authors
Soatok Dreamseeker
-
2026/09/16
Re: [oss-security] Retrospective by 'gpg.fail' authors
Werner Koch
-
2026/09/16
[oss-security] CVE-2026-89775: Guest-to-Host Escape in KVM/arm64
Hyunwoo Kim
-
2026/09/16
[oss-security] CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing
Volodymyr Siedlecki
-
2026/09/16
[oss-security] CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
Volodymyr Siedlecki
-
2026/09/16
[oss-security] Unbound: 1.26.1 addresses multiple CVE items
Yorgos Thessalonikefs
-
2026/09/16
[oss-security] CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles
David Handermann
-
2026/09/16
[oss-security] CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration
David Handermann
-
2026/09/16
[oss-security] CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
David Handermann
-
2026/09/16
[oss-security] CVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests
David Handermann
-
2026/09/16
[oss-security] Multiple vulnerabilities in Jenkins plugins
Kevin Guerroudj
-
2026/09/16
[oss-security] ISC has disclosed fourteen vulnerabilities in BIND 9 (CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736)
Nicki Křížek
-
2026/09/15
Re: [oss-security] Retrospective by 'gpg.fail' authors
Sam James
-
2026/09/15
Re: [oss-security] Retrospective by 'gpg.fail' authors
Lexi Groves (49016)
-
2026/09/15
[oss-security] CVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-86792: Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-86465: Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-82311: Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-76187: Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-76186: Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
Vincent Beck
-
2026/09/15
[oss-security] CVE-2026-84501: Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider
Andor Molnar
-
2026/09/15
[oss-security] CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
Andor Molnar
-
2026/09/15
[oss-security] CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
Andor Molnar
-
2026/09/15
[oss-security] CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
Andor Molnar
-
2026/09/15
[oss-security] CVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
Andor Molnar
-
2026/09/15
Re: [oss-security] Retrospective by 'gpg.fail' authors
Werner Koch
-
2026/09/14
[oss-security] CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution
manizada
-
2026/09/14
Re: [oss-security] Retrospective by 'gpg.fail' authors
Clemens Lang
-
2026/09/14
[oss-security] The GNU C Library security advisories update for 2026-09-14
Adhemerval Zanella Netto
-
2026/09/14
Re: [oss-security] rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback
David A. Wheeler
-
2026/09/14
[oss-security] rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback
Evgenios Gkritsis
-
2026/09/14
Re: [oss-security] rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback
Alan Coopersmith
-
2026/09/14
[oss-security] CVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search
Francesco Chicchiriccò
-
2026/09/14
[oss-security] Cpython: [CVE-2026-82049] tarfile extraction filters allow file modification and content disclosure via hard link to symlink
Alan Coopersmith
-
2026/09/14
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule
Evgenios Gkritsis
-
2026/09/14
[oss-security] CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Francesco Chicchiriccò