Messages by Thread
-
[oss-security] 10+ CVEs in GStreamer
Solar Designer
-
[oss-security] Foswiki 2.1.11 is released, fixes CVE-2026-2861
Michael Daum
-
Re: [oss-security] OpenSSH GSSAPI keyex patch issue
Solar Designer
-
[oss-security] CVE-2025-54920: Apache Spark: Spark History Server Code Execution Vulnerability
Holden Karau
-
[oss-security] Some telnet clients leak environment variables
Justin Swartz
-
[oss-security] Multiple vulnerabilities in AppArmor
Qualys Security Advisory
-
[oss-security] Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)
Justin Swartz
-
[oss-security] CVE-2025-60012: Apache Livy: Restrict file access
György Gál
-
[oss-security] CVE-2025-66249: Apache Livy: Unauthorized directory access
György Gál
-
[oss-security] [vim-security] NFA regex engine NULL pointer dereference affects Vim < 9.2.0137
Christian Brabandt
-
[oss-security] The GNU C Library security advisory update for 2026-03-11
Siddhesh Poyarekar
-
[oss-security] [ADVISORY] curl: CVE-2026-3805: use after free in SMB connection reuse
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-3784: wrong proxy connection reuse with credentials
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-3783: token leak with redirect and netrc
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-1965: bad reuse of HTTP Negotiate connection
Daniel Stenberg
-
[oss-security] CVE-2026-23907: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
Tilman Hausherr
-
[oss-security] [kubernetes] CVE-2026-3288: ingress-nginx rewrite-target nginx configuration injection
Tabitha Sable
-
[oss-security] CVE-2026-28431+more: Misskey/Sharkey "extremely severe" vulnerabilities
Valtteri Vuorikoski
-
[oss-security] CVE-2026-25604: Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
Jarek Potiuk
-
[oss-security] CVE-2026-24015: Apache IoTDB: Insecure Default Configuration Vulnerability
Haonan Hou
-
[oss-security] CVE-2026-24713: Apache IoTDB: JEXL Expression Injection Vulnerability
Haonan Hou
-
[oss-security] CVE-2025-64152: Apache IoTDB: Path Traversal Vulnerability
Haonan Hou
-
[oss-security] CVE-2025-55017: Apache IoTDB: Path Traversal Vulnerability
Haonan Hou
-
[oss-security] CVE-2025-69219: Apache Airflow Providers Http: Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperator
Jarek Potiuk
-
[oss-security] AWStats awdownloadcsv.pl command injection and path traversal vulnerabilities
christopher.downs
-
[oss-security] CVE-2026-30910: Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows
Timothy Legge
-
[oss-security] CVE-2026-30909: Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows
Timothy Legge
-
[oss-security] CVE-2026-24308: Apache ZooKeeper: Sensitive information disclosure in client configuration handling
Andor Molnar
-
[oss-security] CVE-2026-24281: Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Andor Molnar
-
[oss-security] CVE-2025-69534 in Python-Markdown
Alan Coopersmith
-
[oss-security] Go 1.26.1 and Go 1.25.8 are released with 5 CVE fixes
Alan Coopersmith
-
[oss-security] CVE-2025-13350 for Ubuntu Linux kernel
Seth Arnold
-
[oss-security] Fwd: [CVE-2026-2297] SourcelessFileLoader does not use io.open_code()
Alan Coopersmith
-
[oss-security] CVE-2026-3381: Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib
Robert Rothenberg
-
[oss-security] CVE-2026-3257: UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library
Robert Rothenberg
-
[oss-security] CVE-2025-40931: Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id
Robert Rothenberg
-
[oss-security] CVE-2025-40926: Plack::Middleware::Session::Simple versions through 0.04 for Perl generates session ids insecurely
Robert Rothenberg
-
[oss-security] CVE-2024-57854: Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator
Robert Rothenberg
-
[oss-security] Announcing FreeType 2.14.2, fixes CVE-2026-23865
Alan Coopersmith
-
[oss-security] Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)
Jan Schaumann
-
[oss-security] [OSSA-2026-003] OpenStack Vitrage: Remote code execution through Vitrage query parser (CVE-2026-28370)
Jeremy Stanley
-
[oss-security] CVE-2025-66168: Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated
Christopher L. Shannon
-
[oss-security] CVE-2026-27446: Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
Justin Bertram
-
[oss-security] Django CVE-2026-25673 and CVE-2026-25674
Natalia Bidart
-
[oss-security] Fwd: [siren] [Security Advisory] Active Exploitation of Weak GitHub Actions Configurations
Solar Designer
-
[oss-security] CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator
Velmurugan Periasamy
-
[oss-security] CVE-2025-59060: Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient
Velmurugan Periasamy
-
[oss-security] Exiv2 version 0.28.8 released with fixes for 3 low-severity CVEs
Kevin Backhouse
-
[oss-security] Fwd: CVE-2018-25160: HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend
Robert Rothenberg
-
[oss-security] CVE-2026-3255: HTTP::Session2 versions before 1.12 for Perl may generate weak session ids using the rand() function
Robert Rothenberg
-
[oss-security] [vim-security] Stack-buffer-overflow in build_stl_str_hl() affects Vim < 9.2.0078
Christian Brabandt
-
[oss-security] [vim-security] Multiple Vulnerabilities in Swap File Recovery affect Vim < 9.2.0077
Christian Brabandt
-
[oss-security] [vim-security] Heap-based Buffer Overflow and OOB Read in :terminal affects Vim < 9.2.0076
Christian Brabandt
-
[oss-security] [vim-security] Heap-based Buffer Underflow in Emacs tags parsing affects Vim < 9.2.0075
Christian Brabandt
-
[oss-security] [vim-security] Heap-based Buffer Overflow in Emacs tags parsing affects Vim < 9.2.0074
Christian Brabandt
-
[oss-security] [vim-security] OS Command Injection in netrw affects Vim < 9.2.0073
Christian Brabandt
-
[oss-security] OSEC-2026-01 in the OCaml runtime: Buffer Over-Read in OCaml Marshal Deserialization
Alan Coopersmith
-
[oss-security] CVE-2026-27900 - Sensitive Information Exposure in Debug Logs of Terraform Provider for Linode
Liang, Zhiwei
-
[oss-security] Unsound Workshop at ECOOP 2026
Jan Bessai
-
[oss-security] CVE-2026-23984: Apache Superset: SQLLab Read-Only Bypass on PostgreSQL
Daniel Gaspar
-
[oss-security] CVE-2026-23983: Apache Superset: Sensitive Data Exposure via REST API (disabled by default)
Daniel Gaspar
-
[oss-security] CVE-2026-23982: Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass
Daniel Gaspar
-
[oss-security] CVE-2026-23980: Apache Superset: Improper Neutralization of Special Elements used in a SQL Command
Daniel Gaspar
-
[oss-security] CVE-2026-23969: Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering
Daniel Gaspar
-
[oss-security] Re: Telnetd Vulnerability Report
Justin Swartz
-
[oss-security] CVE-2024-56373: Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information
Jarek Potiuk
-
[oss-security] CVE-2025-27555: Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli
Jarek Potiuk
-
[oss-security] CVE-2026-26079/CVE-2026-25916: Roundcube vulns prior to 1.5.13/1.6.13
Valtteri Vuorikoski
-
[oss-security] OpenSC, ghostscript, cgif issues from the recent Anthropic disclosure
Joe Malcolm
-
[oss-security] Default IV & other issues in aes-js & pyaes modules, & strongMan VPN manager
Alan Coopersmith
-
[oss-security] MIT/Heimdal Kerberos credentials cache type FILE risks
Solar Designer
-
[oss-security] CVE-2026-23552: Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy
Andrea Cosentino
-
[oss-security] CVE-2026-25747: Apache Camel: Deserialization of Untrusted Data in Camel LevelDB
Andrea Cosentino
-
[oss-security] zlib security audit by 7asecurity
Sam James
-
[oss-security] CVE-2026-25087: Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
Antoine Pitrou
-
[oss-security] [OSSA-2026-002] OpenStack Nova: calls qemu-img without format restrictions for resize (CVE-2026-24708)
Jeremy Stanley
-
[oss-security] CVE-2026-25903: Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates
David Handermann
-
[oss-security] [vim-security] NetBeans specialKeys Stack Buffer Overflow with Vim <9.1.2148
Christian Brabandt
-
[oss-security] CVE-2025-40905: WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic functions
Alan Coopersmith
-
[oss-security] CVE-2025-33042: Apache Avro Java SDK: Code injection on Java generated code
Ryan Skraba
-
[oss-security] Pillow 12.1.1 released with fix for CVE-2026-25990
Alan Coopersmith
-
[oss-security] PyCA cryptography 46.0.5 released with fix for CVE-2026-26007
Alan Coopersmith
-
[oss-security] CVE-2026-25506: MUNGE 0.5-0.5.17 buffer overflow allowing key leakage
Chris Dunlap
-
[oss-security] PowerDNS Security Advisory 2026-01: Crafted zones can lead to increased resource usage in Recursor
Otto Moerbeek
-
[oss-security] FreeRDP fixes 12 CVEs in 3.22.0 release
Alan Coopersmith
-
[oss-security] libpng 1.6.55: Heap buffer overflow vulnerability fixed: CVE-2026-25646
Cosmin Truta
-
[oss-security] gnutls 3.8.12 fixes CVE-2026-1584 & CVE-2025-14831
Alan Coopersmith
-
[oss-security] CVE-2026-23906: Apache Druid: Authentication Bypass via LDAP Anonymous Bind
Karan Kumar
-
[oss-security] CVE-2026-24343: Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
Qingran Zhao
-
[oss-security] CVE-2026-24098: Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors
Ephraim Anierobi
-
[oss-security] CVE-2026-22922: Apache Airflow: Airflow externalLogUrl Permission Bypass
Ephraim Anierobi
-
[oss-security] CVE-2026-23901: Apache Shiro: Brute force attack possible to determine valid user names
Lenny Primak
-
[oss-security] CVE-2026-23903: Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
Lenny Primak
-
[oss-security] Go 1.25.7 and Go 1.24.13 are released with 2 CVE fixes
Alan Coopersmith
-
[oss-security] On patch vs commit messages
Sam James
-
[oss-security] [vim-security] buffer overflow in helpfile option handling affects Vim <9.1.2132
Christian Brabandt
-
[oss-security] NGINX < 1.29.5, 1.28.2 MitM injection CVE-2026-1642
Jan Schaumann
-
[oss-security] CVE-2026-24735: Apache Answer: Revision API Improper Access Control leads to Information Disclosure
Enxin Xie
-
[oss-security] Django CVE-2025-13473, CVE-2025-14550, CVE-2026-1207, CVE-2026-1285, CVE-2026-1287, and CVE-2026-1312
Jacob Walls
-
[oss-security] [kubernetes] Multiple issues in ingress-nginx
Tabitha Sable
-
[oss-security] CVE-2026-23795: Apache Syncope: Console XXE on Keymaster parameters
Francesco Chicchiriccò
-
[oss-security] CVE-2026-23794: Apache Syncope: Reflected XSS on Enduser Login
Francesco Chicchiriccò
-
[oss-security] Security incident on plone GitHub org with force pushes
Maurits van Rees
-
[oss-security] libexpat 2.7.4 fixes CVE-2026-24515 and CVE-2026-25210
Sebastian Pipping
-
[oss-security] Re: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
Paul Ducklin
-
[oss-security] GnuPG security release
Sam James