Messages by Thread
-
-
[oss-security] [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE PENDING)
Jeremy Stanley
-
[oss-security] [SECURITY ADVISORY] wcurl path traversal with percent-encoded slashes
Daniel Stenberg
-
[oss-security] OpenSMTPD: Trivial Local Denial-of-Service via UNIX Domain Socket (CVE-2025-62875)
Matthias Gerstner
-
Re: [oss-security] Xen Security Notice 2 (CVE-2024-35347) AMD CPU Microcode Signature Verification Vulnerability
Eddie Chapman
-
[oss-security] CVE-2025-62232: Apache APISIX: APISIX basic-auth logs plaintext credentials at info level
Ashish Tiwari
-
[oss-security] CVE-2025-62503: Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)
Kaxil Naik
-
[oss-security] CVE-2025-62402: Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API
Kaxil Naik
-
[oss-security] CVE-2025-54941: Apache Airflow: Command injection in "example_dag_decorator"
Kaxil Naik
-
[oss-security] ISC has disclosed one vulnerability in Kea (CVE-2025-11232)
Wlodek Wencel
-
[oss-security] CVE-2025-30189: Dovecot IMAP Server: Using auth caching causes the first lookup to be cached for all lookups
Camelia Lavender
-
[oss-security] Multiple vulnerabilities in Jenkins plugins
Daniel Beck
-
[oss-security] Fwd: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland
Olivier Fourdan
-
[oss-security] CVE-2025-61795: Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS
Mark Thomas
-
[oss-security] CVE-2025-55754: Apache Tomcat: console manipulation via escape sequences in log messages
Mark Thomas
-
[oss-security] CVE-2025-55752: Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
Mark Thomas
-
[oss-security] Questionable CVE's reported against dnsmasq
Alan Coopersmith
-
[oss-security] OOB read / segfault and endless loop in courier mail server 1.5.0
Hanno Böck
-
[oss-security] Xen Security Advisory 476 v1 (CVE-2025-58149) - Incorrect removal of permissions on PCI device unplug
Xen . org security team
-
[oss-security] PowerDNS Security Advisory 2025-06: Crafted delegations or IP fragments can poison cached delegations in Recursor
Otto Moerbeek
-
[oss-security] ISC has disclosed three vulnerabilities in BIND 9 (CVE-2025-8677, CVE-2025-40778, CVE-2025-40780)
Michał Kępień
-
[oss-security] Xen Security Advisory 475 v2 (CVE-2025-58147,CVE-2025-58148) - x86: Incorrect input sanitisation in Viridian hypercalls
Xen . org security team
-
[oss-security] CVE-2025-57738: Apache Syncope: Remote Code Execution by delegated administrators
Francesco Chicchiriccò
-
[oss-security] CVE-2025-61581: Apache Traffic Control: ReDoS issue in Traffic Router configuration
Arnout Engelen
-
[oss-security] CVE-2025-61733: Apache Kylin: Authentication bypass
Li Yang
-
Re: [oss-security] CVE-2025-22247 - Insecure file handling vulnerability in open-vm-tools
Solar Designer
-
[oss-security] CVE-2025-55039: Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks
Holden Karau
-
[oss-security] Resource consumption weakness in Postgres-using applications & frameworks
Peter Bex
-
[oss-security] OpenSSL Security Advisory
Tomas Mraz
-
[oss-security] Announce: OpenSSH 10.2 released
Damien Miller
-
[oss-security] Announce: OpenSSH 10.1 released
Damien Miller
-
[oss-security] CVE-2025-48459: Apache IoTDB: Deserialization of untrusted Data
Haonan Hou
-
Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
Peter Gutmann
-
[oss-security] CVE-2025-54539: Apache ActiveMQ NMS AMQP Client: Deserialization of Untrusted Data
Krzysztof Porębski
-
[oss-security] BoringSSL private key loading is not constant time
Billy Brumley
-
[oss-security] redis: CVE-2025-49844: Lua Use-After-Free may lead to remote code execution
Jan Schaumann
-
Re: [oss-security] Linux kernel: eBPF vulnerabilities
Willy Tarreau
-
[oss-security] Go 1.25.2 and Go 1.24.8 fix 10 vulnerabilities
Alan Coopersmith
-
[oss-security] [Security Advisory] open-vm-tools: Local privilege escalation (CVE-2025-41244)
VMware PSIRT
-
[oss-security] several vulnerabilities fixed in Go 1.25.2 and Go 1.24.8
Jan Schaumann
-
Re: [oss-security] process exit statuses (was: CVE-2023-51767)
Simon McVittie
-
[oss-security] CVE-2024-44088: Apache Geode: Reflected XSS
William Hodges
-
[oss-security] FreeIPA - CVE-2025-7493 - Privilege Escalation from host to domain admin
Marco Benatto
-
[oss-security] libexpat 2.7.3 improves fixes to CVE-2024-8176 and CVE-2025-59375
Sebastian Pipping
-
[oss-security] rplay (Mark R. Boyns) potential security issues (unsanitized data, unchecked malloc...)
Vincent Lefevre
-
[oss-security] CVE-2025-61735: Apache Kylin: Server-Side Request Forgery
Li Yang
-
Re: [oss-security] Linux kernel: KASAN: out-of-bounds Read in proc_pid_stack on RISC-V
Solar Designer
-
[oss-security] CVE-2025-61734: Apache Kylin: improper restriction of file read
Li Yang
-
[oss-security] Fwd: Heads-up: Upcoming Samba security releases
Douglas Bagnall
-
[oss-security] CVE-2025-47410: Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
William Hodges
-
Re: [oss-security] Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
Jacob Bachmeyer
-
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2025-0007
Adrian Perez de Castro
-
[oss-security] GHSL-2025-042: Use After Free (UAF) in Poppler - CVE-2025-52885
Alan Coopersmith
-
Re: [oss-security] CVE-2025-55188: 7-Zip: Arbitrary file write on extraction, may lead to code execution
lunbun
-
[oss-security] CVE-2025-62228: Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC: SQL injection via maliciously crafted identifiers
Leonard Xu
-
[oss-security] fetchmail-SA-2025-01: SMTP AUTH denial of service
Alan Coopersmith
-
Re: [oss-security] How to do secure coding and create secure software
Eli Schwartz
-
Re: [oss-security] Re: Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
Attila Szasz
-
Re: [oss-security] Re: Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
Greg KH
-
Re: [oss-security] Re: Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
Attila Szasz
-
Re: [oss-security] Re: Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
Greg KH
-
Re: [oss-security] Re: Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
Attila Szasz
-
Re: [oss-security] Re: Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
Greg KH
-
[oss-security] Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
nightmare . yeah27
-
Re: [oss-security] Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
Greg KH
-
[oss-security] Re: Linux kernel: HFS+ filesystem implementation, issues, exposure in distros
nightmare . yeah27
-
[oss-security] Django CVE-2025-59681 and CVE-2025-59682
Jacob Walls
-
[oss-security] CVE-2025-61622: Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory
Chaokun Yang
-
[oss-security] malware in SoopSocks package on PyPi
Alan Coopersmith