Messages by Thread
-
[oss-security] CVE-2026-97791: Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares validation state between requests
Colm O hEigeartaigh
-
[oss-security] CVE-2026-103412: Apache Camel Karavan: project file name path traversal when committing a project to Git
Andrea Cosentino
-
[oss-security] CVE-2026-103413: Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes.yaml
Andrea Cosentino
-
[oss-security] CVE-2026-107938: Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.
Colm O hEigeartaigh
-
[oss-security] CVE-2026-107937: Apache CXF: The attachment header size and count limits can be bypassed, which allows denial of service through memory exhaustion.
Colm O hEigeartaigh
-
[oss-security] CVE-2026-100227: Apache CXF: XML Signature wrapping in JAX-RS XML Security
Colm O hEigeartaigh
-
[oss-security] CVE-2026-79650: Apache CXF: OIDC RP Open Redirect
Colm O hEigeartaigh
-
[oss-security] [OSSN-0110] Ironic can leak basic auth credentials to image server
Jay Faulkner
-
[oss-security] [OSSA-2026-044] OpenStack Mistral: Four authorization and privilege vulnerabilities in Mistral (CVE-2026-93858, CVE-2026-93860, CVE-2026-93861, CVE-2026-97147))
Jeremy Stanley
-
[oss-security] Fwd: Vulnerabilities in golang.org/x/net
Alan Coopersmith
-
[oss-security] Fwd: Go 1.27.2 and Go 1.26.9 are released
Alan Coopersmith
-
[oss-security] OpenJPEG: heap-buffer-overflow write fixed on master since Feb 2026, still present in every release (2.5.3, 2.5.4)
TheSecguy
-
[oss-security] CVE-2026-71895: Apache DolphinScheduler: Missing Authorization Checks Allow Non-Admin Users to Retrieve Kubernetes Credentials
Wenjun Ruan
-
[oss-security] CVE-2026-71896: Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of User Account Information
Wenjun Ruan
-
[oss-security] CVE-2026-71183: Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Information and Passwords
Wenjun Ruan
-
[oss-security] CVE-2026-66087: Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint Endpoint
Wenjun Ruan
-
[oss-security] CVE-2026-66084: Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream Endpoint
Wenjun Ruan
-
[oss-security] CVE-2026-66082: Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (schedule / workflow)
Wenjun Ruan
-
[oss-security] tor-0.4.9.14 released
Sam James
-
[oss-security] [OSSN-0109] Cross-project metric association bypass in Gnocchi
Goutham Pacha Ravi
-
[oss-security] CVE-2026-103371: Apache Geode: Management REST API: Insertion of Sensitive Information into Log File
Jinwoo Hwang
-
[oss-security] [OSSA-2026-043] OpenStack Zaqar: Zaqar WebSocket project substitution allows cross-project queue access (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] CVE-2026-92415: Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-controlled error bodies
Julian Reschke
-
[oss-security] CVE-2026-92414: Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
Julian Reschke
-
[oss-security] CVE-2026-97146: Apache YuniKorn: Admission control bypass via system label forgery
Wilfred Spiegelenburg
-
[oss-security] CVE-2026-92393: Apache YuniKorn: Admission control bypass via workload UPDATE operation
Wilfred Spiegelenburg
-
[oss-security] CVE-2026-78243: Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
Wilfred Spiegelenburg
-
[oss-security] CVE-2026-105243: Apache log4net: Oversize EventLogAppender record silently discarded
Jan Friedrich
-
[oss-security] FW: X.Org Security Advisory: multiple security issues in X.Org X server
Peter Hutterer
-
[oss-security] CVE-2026-97720: Apache Impala: Impala Executor Webserver Auth Bypass
Michael Smith
-
[oss-security] CVE-2026-93684: Apache Impala: Stored XSS in Impala query plans
Michael Smith
-
[oss-security] CVE-2026-90466: Apache Impala: Path traversal executes JARs outside trusted paths
Michael Smith
-
[oss-security] CVE-2026-105244: Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
Jan Friedrich
-
[oss-security] CVE-2026-105240: Apache log4net: NUL character truncates OutputDebugStringAppender records
Jan Friedrich
-
[oss-security] CVE-2026-105242: Apache log4net: Request validation failure drops the event in the aspnet-request converter
Jan Friedrich
-
[oss-security] CVE-2026-105241: Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
Jan Friedrich
-
[oss-security] CVE-2026-105239: Apache log4net: NUL character truncates EventLogAppender records
Jan Friedrich
-
[oss-security] CVE-2026-105111: Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS
Gary D. Gregory
-
[oss-security] CVE-2026-12540: Foreman: command injection in foreman-rake errors:fetch_log (fixed in 3.19.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-94114: Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
Gary D. Gregory
-
[oss-security] CVE-2026-12405: Foreman Remote Execution: command injection via effective_user (fixed in 16.6.6, 17.2.2, 18.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-12423: Foreman: provisioning token validation flaw (fixed in 3.19.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-12541: Foreman: command injection in foreman-rake database tasks (fixed in 3.19.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-12542: Foreman: command injection in foreman-tail (fixed in 3.19.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-12544: Foreman: SSTI and unsafe deserialization in configuration (fixed in 3.19.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-12545: Hammer CLI: editor command injection (fixed in 3.19.1, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-56097: Katello: SQL injection in Registry Proxy labels (fixed in 4.21.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-56098: Katello: Registry Proxy authorization bypass (fixed in 4.21.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-96658: Foreman: Safemode bypass leading to RCE (fixed in 3.19.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] CVE-2026-96659: Foreman: excessive Viewer permissions on preview (fixed in 3.19.2, 5.0.1)
Ondrej Gajdusek
-
[oss-security] Django CVE-2026-77050, CVE-2026-84429, CVE-2026-87890, and CVE-2026-87975
Sarah Boyce
-
[oss-security] Announce: OpenSSH 10.6 released
Damien Miller
-
[oss-security] CVE-2026-104380: Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one
Timothy Legge
-
[oss-security] Fwd: [Freeipmi-announce] FreeIPMI 1.6.20 Released
Chad Dougherty
-
[oss-security] libexpat 2.9.0 fixes two vulnerabilities
Sebastian Pipping
-
[oss-security] CVE-2026-104714: Apache Struts: Shared message formatter exposes date and time values across concurrent requests
Lukasz Lenart
-
[oss-security] CVE-2026-104713: Apache Struts: Unbounded request body read in the REST plugin
Lukasz Lenart
-
[oss-security] CVE-2026-104712: Apache Struts: Disproportionate response size when rendering BigDecimal request parameters
Lukasz Lenart
-
[oss-security] CVE-2026-104711: Apache Struts: OGNL injection in the legacy RESTful action mapper
Lukasz Lenart
-
[oss-security] CVE-2019-25777: YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution
Stig Palmquist
-
[oss-security] CVE-2026-19954: Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names
Robert Rothenberg
-
[oss-security] CVE-2017-20285: YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes
Stig Palmquist
-
[oss-security] [cups] Multiple security fixes in incoming new version 2.4.20
Zdenek Dohnal
-
[oss-security] openjpeg 2.4.0 through 2.5.4 and git master: heap buffer overflow in opj_dwt_encode_and_deinterleave_v() (reversible 5/3 forward DWT, encoder)
Security @ Red Eagle Tech
-
[oss-security] cloud computing provider disclosures
Jan Schaumann
-
[oss-security] Apache Thrift 0.25.0: 61 CVEs fixed (combined announcement)
Jens Geyer
-
[oss-security] CVE-2026-103885: Apache Directory LDAP API: Denial of service via crafted telephone number values
Emmanuel Lécharny
-
[oss-security] CVE-2026-103880: Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords
Emmanuel Lécharny
-
[oss-security] CVE-2026-103878: Apache Directory LDAP API: Injection of plaintext responses during StartTLS
Emmanuel Lécharny
-
[oss-security] CVE-2026-103877: Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements
Emmanuel Lécharny
-
[oss-security] CVE-2026-103552: Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder
Emmanuel Lécharny
-
[oss-security] CVE-2026-102731: Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode
Emmanuel Lécharny
-
[oss-security] CVE-2026-59265: Apache OpenOffice: Opening a malicious document can lead to system takeover
Dave Fisher
-
[oss-security] CVE-2026-102795: Apache Traffic Server: SNI to Host header matching policy is not properly enforced (supersedes CVE-2026-41920)
Masakazu Kitajo
-
[oss-security] CVE-2026-59685: Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM
Eric Covener
-
[oss-security] CVE-2026-56449: Apache HTTP Server: mod_proxy_html: crash in dump_content
Eric Covener
-
[oss-security] CVE-2026-42356: Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories
Eric Covener
-
[oss-security] CVE-2026-93546: Apache HTTP Server: mod_dav_fs namespace overflow
Eric Covener
-
[oss-security] CVE-2026-79768: Apache HTTP Server: mod_userdir information disclosure
Eric Covener
-
[oss-security] CVE-2026-73637: Apache HTTP Server: mod_auth_digest DoS attack
Eric Covener
-
[oss-security] CVE-2026-73636: Apache HTTP Server: mod_auth_digest one-time-nonce replay attack
Eric Covener
-
[oss-security] CVE-2026-63718: Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
Eric Covener
-
[oss-security] CVE-2026-63686: Apache HTTP Server: mod_xml2enc crash on charset conversion failure
Eric Covener
-
[oss-security] CVE-2026-63292: Apache HTTP Server: mod_vhost_alias stack overflow
Eric Covener
-
[oss-security] CVE-2026-63045: Apache HTTP Server: mod_proxy_ftp PASV address handling
Eric Covener
-
[oss-security] CVE-2026-59797: Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
Eric Covener
-
[oss-security] CVE-2026-58415: Apache HTTP Server: mod_dav_fs property database read access
Eric Covener
-
[oss-security] CVE-2026-57941: Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy
Eric Covener
-
[oss-security] CVE-2026-56154: Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}
Eric Covener
-
[oss-security] CVE-2026-56153: Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char
Eric Covener
-
[oss-security] CVE-2026-48005: Apache HTTP Server: mod_auth_digest reauthentication attack
Eric Covener
-
[oss-security] CVE-2026-47360: Apache HTTP Server: mod_session: Session cookie not removed during internal redirect
Eric Covener
-
[oss-security] CVE-2026-46729: Apache HTTP Server: mod_heartmonitor denial of service
Eric Covener
-
[oss-security] CVE-2026-42528: Apache HTTP Server: mod_dav shared lock overflow
Eric Covener
-
[oss-security] CVE-2026-94220: Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin
Abhishek Choudhary
-
[oss-security] CVE-2026-94269: Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch
Abhishek Choudhary
-
[oss-security] CVE-2026-94276: Apache APISIX: Openid-connect introspection validation issue
Abhishek Choudhary
-
[oss-security] CVE-2026-102504: Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol
Stig Palmquist
-
[oss-security] CVE-2026-102505: Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp
Stig Palmquist
-
[oss-security] CVE-2026-94250: Apache APISIX: Batch response aggregation can exhaust worker memory
Abhishek Choudhary
-
[oss-security] CVE-2026-94212: Apache APISIX: unauthenticated impersonation issue in saml-auth
Abhishek Choudhary
-
[oss-security] CVE-2026-82806: Apache APISIX: cross-request permission pollution via static permission list mutation
Abhishek Choudhary
-
[oss-security] CVE-2026-78242: Apache APISIX: data-mask may fail to redact request headers in logger output
Abhishek Choudhary
-
[oss-security] CVE-2026-88789: Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening
James Netherton
-
[oss-security] CPython [CVE-2026-19445] Use-after-free of a server-side SSLContext when sni_callback switches contexts
Alan Coopersmith
-
[oss-security] CPython [CVE-2026-19553] SSLContext.wrap_bio() missing validation of server_hostname parameter
Alan Coopersmith
-
[oss-security] CVE-2026-102510: Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
Christofer Dutz
-
[oss-security] CVE-2026-85532: Apache WSS4J: Insufficient Validation of Derived-Key Parameters
Colm O hEigeartaigh
-
[oss-security] CVE-2026-80490: Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified
Robert Rothenberg
-
[oss-security] CVE-2026-92899: Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
Colm O hEigeartaigh
-
[oss-security] CVE-2026-102508: Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
Christofer Dutz
-
[oss-security] CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
Colm O hEigeartaigh
-
[oss-security] CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
Colm O hEigeartaigh
-
[oss-security] CVE-2026-89238: Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection
Colm O hEigeartaigh
-
[oss-security] CVE-2026-88920: Apache WSS4J: SAML Sender-Vouches Authentication Bypass
Colm O hEigeartaigh
-
[oss-security] CVE-2026-87830: Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
Colm O hEigeartaigh
-
[oss-security] CVE-2026-102511: Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them
Christofer Dutz
-
[oss-security] CVE-2026-102509: Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Christofer Dutz
-
[oss-security] Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries
Alan Coopersmith
-
[oss-security] Linux KVM/x86 (tested on 6.1.74): guest-triggered host panic via SMM shadow MMU
Jinu Kim
-
[oss-security] CPython [CVE-2026-12345] Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
Alan Coopersmith
-
[oss-security] CVE-2026-94053: Apache MINA SSHD: LDAP injection in sshd-ldap
Thomas Wolf
-
[oss-security] CVE-2026-93995: Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the server
Thomas Wolf
-
[oss-security] CVE-2026-94052: Apache MINA SSHD: LDAP password authentication ineffective
Thomas Wolf
-
[oss-security] CVE-2026-94029: Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension
Thomas Wolf
-
[oss-security] CVE-2026-94002: Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
Thomas Wolf
-
[oss-security] CVE-2026-93996: Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
Thomas Wolf
-
[oss-security] CVE-2026-93994: Apache MINA SSHD: Repeated-publickey policy bypass on server
Thomas Wolf
-
[oss-security] CVE-2026-77185: Apache MINA SSHD: Asynchronous authentication can bypass signature verification
Thomas Wolf
-
[oss-security] Fwd: groff 1.24.2 released
Alan Coopersmith
-
[oss-security] CVE-2026-71897: Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
Wenjun Ruan
-
[oss-security] CVE-2026-81569: Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution
Wenjun Ruan
-
[oss-security] CVE-2026-81930: Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
Shahar Epstein
-
[oss-security] CVE-2026-66083: Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource
Wenjun Ruan
-
[oss-security] OpenSSL Security Advisory [29th September 2026]
Tomas Mraz
-
[oss-security] [NotCVE-2026-0018] game-music-emu (libgme) through 0.6.5 Unbounded GYM Command Loop Allows Heap Out-of-Bounds Read
advisories
-
[oss-security] [NotCVE-2026-0016] game-music-emu VGM Command Interpreter Unvalidated 0xE0 PCM Seek Offset Allows Out-of-Bounds Read and Denial of Service
advisories
-
[oss-security] [NotCVE-2026-0019] game-music-emu through 0.6.5 VGM Command Interpreter Missing Operand Length Check Allows Heap Out-of-Bounds Read
advisories
-
[oss-security] CVE-2026-97395: Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-82804: Apache DolphinScheduler: Command Injection in the Alert Script Plugin
Wenjun Ruan
-
[oss-security] CVE-2026-78214: Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
Wenjun Ruan
-
[oss-security] CVE-2026-71899: Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure
Wenjun Ruan
-
[oss-security] "several" CVEs in latest Debian linux security advisory DSA 6528-1
Jan Schaumann
-
[oss-security] CVE-2026-71898: Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions
Wenjun Ruan
-
[oss-security] CVE-2026-81862: Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs
Shahar Epstein
-
[oss-security] CVE-2026-102497: Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker
Colm O hEigeartaigh
-
[oss-security] CVE-2026-102496: Apache XMLSchema: Denial of service through deeply nested schema structures
Colm O hEigeartaigh
-
[oss-security] CVE-2026-102495: Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes
Colm O hEigeartaigh
-
[oss-security] CVE-2026-86843: Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
Shahar Epstein
-
[oss-security] CVE-2026-81914: Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
Shahar Epstein
-
[oss-security] [NotCVE-2026-0017] game-music-emu (libgme) 0.6.5 and Earlier AY Loader NULL Pointer Dereference Allows Denial of Service
advisories
-
[oss-security] JIT buffer overflow fixed in libpcre2-10.49
Sam James
-
[oss-security] libpng 1.6.59: Use-after-free vulnerability fixed: CVE-2026-46675
Cosmin Truta
-
[oss-security] Moodle LMS 3.9.2: authenticated file-upload validation bypass (CWE-434) leading to RCE under misconfiguration
Muhammad Arslan Official
-
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006
Adrian Perez de Castro
-
[oss-security] CVE-2026-88815: DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv
Robert Rothenberg
-
[oss-security] CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-85644: XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference
Robert Rothenberg
-
[oss-security] CVE-2026-88816: DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName
Robert Rothenberg
-
[oss-security] CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
Jean-Baptiste Onofré
-
[oss-security] The GNU C Library security advisory update for 2026-09-28
Siddhesh Poyarekar
-
[oss-security] Flatpak 1.18.4 fixes multiple security vulnerabilities
Simon McVittie
-
[oss-security] CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy
Hongtao Gao
-
[oss-security] crontab(1) silently truncates file path arguments >=100 chars
Vincent Lefevre
-
[oss-security] CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules
Jean-Baptiste Onofré
-
[oss-security] [kubernetes] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes
Vyom Yadav
-
[oss-security] CVE-2026-95510: GNU Inetutils: use of uninitialized struct sigaction
Collin Funk
-
[oss-security] CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
Haitam Lazaar
-
[oss-security] CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
David M. Johnson
-
[oss-security] CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator
David M. Johnson
-
[oss-security] CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments
David M. Johnson
-
[oss-security] CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL
David M. Johnson
-
[oss-security] CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links
David M. Johnson
-
[oss-security] CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type
David M. Johnson
-
[oss-security] CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
David M. Johnson
-
[oss-security] CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
David M. Johnson
-
[oss-security] CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
David M. Johnson
-
[oss-security] CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
David M. Johnson
-
[oss-security] CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI
David M. Johnson
-
[oss-security] CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation
David M. Johnson