Messages by Thread
-
[oss-security] [ADVISORY] curl: CVE-2026-7168: cross-proxy Digest auth state leak
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-6276: stale custom cookie host causes cookie leak
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-7009: OCSP stapling bypass with Apple SecTrust
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-6253: proxy credentials leak over redirect-to proxy
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-6429: netrc credential leak with reused proxy connection
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-5773: wrong reuse of SMB connection
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-5545: wrong reuse of HTTP Negotiate connection
Daniel Stenberg
-
[oss-security] [ADVISORY] curl: CVE-2026-4873: connection reuse ignores TLS requirement
Daniel Stenberg
-
[oss-security] CVE-2026-40560: Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence
Timothy Legge
-
Re: [oss-security] [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2
Alan Coopersmith
-
[oss-security] Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2
Dmitry Butskoy
-
[oss-security] Xen Security Advisory 489 v1 (CVE-2026-23559,CVE-2026-23560,CVE-2026-23561,CVE-2026-23562,CVE-2026-42486) - Multiple RBAC issues in XAPI
Xen . org security team
-
[oss-security] CVE-2026-41873: Pony Mail: Admin account takeover via request smuggling
Arnout Engelen
-
[oss-security] The GNU C Library security advisories update for 2026-04-28
Carlos O'Donell
-
[oss-security] Coordinated Disclosure in the LLM Age
Jeremy Stanley
-
[oss-security] Xen Security Advisory 487 v2 (CVE-2026-31787) - Linux kernel double free in Xen privcmd driver
Xen . org security team
-
[oss-security] Xen Security Advisory 486 v2 (CVE-2026-23558) - grant table v2 race in status page mapping
Xen . org security team
-
[oss-security] Xen Security Advisory 485 v2 (CVE-2026-31786) - Linux kernel out of bounds read via Xen-related sysfs file
Xen . org security team
-
[oss-security] Xen Security Advisory 484 v2 (CVE-2026-23557) - Xenstored DoS via XS_RESET_WATCHES command
Xen . org security team
-
[oss-security] Xen Security Advisory 483 v2 (CVE-2026-23556) - oxenstored keeps quota related use counts across domain destruction
Xen . org security team
-
[oss-security][CVE-2026-3087] shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
Alan Coopersmith
-
[oss-security] CVE-2026-41602: Apache Thrift: Go TFramedTransport uint32 overflow
Jens Geyer
-
[oss-security] CVE-2025-48431: Apache Thrift glibc language bindings: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
Jens Geyer
-
[oss-security] CVE-2026-41603: Apache Thrift: Java TSSLTransportFactory hostname verification
Jens Geyer
-
[oss-security] CVE-2026-41604: Apache Thrift: Swift Range crash in skip()
Jens Geyer
-
[oss-security] CVE-2026-41605: Apache Thrift: Swift Compact Protocol integer overflow
Jens Geyer
-
[oss-security] CVE-2026-41606: Apache Thrift: c_glib dispatch stack overflow
Jens Geyer
-
[oss-security] CVE-2026-41607: Apache Thrift: C++ JSON OOB read
Jens Geyer
-
[oss-security] CVE-2026-41636: Apache Thrift: Node.js skip() recursion
Jens Geyer
-
[oss-security] CVE-2026-40355, CVE-2026-40356: MIT krb5 1.18+ Unauthenticated Network read overrun and null pointer dereference
Cem Onat Karagun
-
[oss-security][CVE-2026-6357] pip self-update functionality can import newly installed modules after wheel installation
Alan Coopersmith
-
[oss-security] [OSSA-2026-008] Ironic: Command Injection in IPMI Console Implementations (CVE pending)
Jay Faulkner
-
[oss-security] CVE-2026-41409: Apache MINA: CWE-502 Deserialization of Untrusted Data
Emmanuel Lécharny
-
[oss-security] CVE-2026-7040: Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters
Robert Rothenberg
-
[oss-security] ZDRES-059: CVE-2026-41635: Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE
Emmanuel Lécharny
-
[oss-security] uriparser 1.0.1 fixes CVE-2026-42371 (integer overflow)
Sebastian Pipping
-
[oss-security] plasma-login-manager: Weaknesses in plasmaloginauthhelper (CVE-2026-25710)
Matthias Gerstner
-
[oss-security] CVE-2026-40860: Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
Andrea Cosentino
-
[oss-security] CVE-2026-40858: Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
Andrea Cosentino
-
[oss-security] CVE-2026-40473: Apache Camel: Camel-Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
Andrea Cosentino
-
[oss-security] CVE-2026-40453: Apache Camel: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
Andrea Cosentino
-
[oss-security] CVE-2026-40048: Apache Camel: Camel-PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
Andrea Cosentino
-
[oss-security] CVE-2026-40022: Apache Camel: Camel-Platform-HTTP-Main: Authentication Bypass on Non-Root Context Paths in camel main runtime
Andrea Cosentino
-
[oss-security] CVE-2026-33454: Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)
Andrea Cosentino
-
[oss-security] CVE-2026-33453: Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
Andrea Cosentino
-
[oss-security] CVE-2026-27172: Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store
Andrea Cosentino
-
[oss-security] libexpat 2.8.0 fixes CVE-2026-41080 (insufficient entropy)
Sebastian Pipping
-
[oss-security] CVE-2026-41081: Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure
Richard Zowalla
-
[oss-security] CVE-2026-40557: Apache Storm Prometheus Reporter: Disabling TLS verification for Prometheus Reporter also disables it for all other connections
Richard Zowalla
-
[oss-security] bubblewrap CVE-2026-41163: Privilege escalation if setuid root, via ptrace
Simon McVittie
-
[oss-security] rust-openssl-v0.10.78 fixes 5 CVEs
Alan Coopersmith
-
[oss-security] CVE-2026-40690: Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users
Rahul Vats
-
[oss-security] CVE-2026-38743: Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities
Rahul Vats
-
[oss-security] CVE-2025-62233: Apache DolphinScheduler: Deserialization of untrusted data in RPC
Wenjun Ruan
-
[oss-security] CVE-2026-23902: Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution.
Wenjun Ruan
-
[oss-security] CVE-2026-41044: Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
Christopher L. Shannon
-
[oss-security] CVE-2026-41043: Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues
Christopher L. Shannon
-
[oss-security] CVE-2026-40466: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
Christopher L. Shannon
-
[oss-security] PowerDNS Authoritative Server 4.9.14 and 5.0.4 released
Miod Vallat
-
[oss-security] CVE-2026-41564: CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking
Stig Palmquist
-
[oss-security] PowerDNS Security Advisory 2026-03 for PowerDNS Recursor: Multiple issues
Otto Moerbeek
-
[oss-security] [vim-security] OS Command Injection in netrw affects Vim < 9.2.0383
Christian Brabandt
-
[oss-security] CVE-2026-41651: TOCTOU vulnerability in PackageKit <= 1.3.4 leads to local root exploit
Matthias Klumpp
-
[oss-security] [SECURITY] CVE-2026-40542: Apache HttpClient 5.6 SCRAM-SHA-256 mutual authentication bypass
Arturo Bernal
-
[oss-security] CVE-2025-15638: Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt
Robert Rothenberg
-
[oss-security] CVE-2017-20230: Storable versions before 3.05 for Perl has a stack overflow
Robert Rothenberg
-
[oss-security] CVE-2026-40706: ntfs-3g 2022.10.3: Heap buffer overflow
Rostislav
-
[oss-security] Fwd: X.Org Security Advisory: CVE-2026-4367: libXpm Out-of-bounds read in xpmNextWord()
Olivier Fourdan
-
[oss-security] Libgcrypt security releases 1.12.2, 1.11.3, 1.10.x
Valtteri Vuorikoski
-
[oss-security] The GNU C Library security advisories update for 2026-04-20
Carlos O'Donell
-
[oss-security] Fwd: [CVE-2026-3219] pip doesn't reject concatenated ZIP and tar archives
Alan Coopersmith
-
[oss-security] [ADVISORY] CVE-2026-5367: Heap over-read in OVN DHCPv6 Client ID processing
Ales Musil
-
[oss-security] [ADVISORY] CVE-2026-5265: Heap Over-Read in ICMP Error Response Generation
Ales Musil
-
[oss-security] [CVE REQUEST] terminal-controller-mcp: trivially bypassable command blocklist enables unrestricted RCE (CVSS 10.0)
Pico 🧬
-
[oss-security] CVE-2026-41113: RCE in sagredo fork of qmail
Alan Coopersmith
-
[oss-security] lcms2 <= 2.18 CubeSize() integer overflow: stock Ubuntu 24.04 Poppler / evince-thumbnailer / OpenJDK crashers (different triggers), no CVE
Abhinav Agarwal
-
[oss-security] CVE-2026-40948: Apache Airflow Keycloak Provider: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager
Jarek Potiuk
-
[oss-security] Xen Security Advisory 488 v1 - x86: Floating Point Divider State Sampling
Xen . org security team
-
[oss-security] ngtcp2: qlog_parameters_set_transport_params_stack_overflow [CVE-2026-40170]
Alan Coopersmith
-
[oss-security] cups: 8 various moderate vulnerabilities
Zdenek Dohnal
-
[oss-security] CVE-2026-25917: Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)
Rahul Vats
-
[oss-security] CVE-2026-32228: Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
Rahul Vats
-
[oss-security] CVE-2026-30898: Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf
Rahul Vats
-
[oss-security] CVE-2026-32690: Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
Rahul Vats
-
[oss-security] CVE-2026-30912: Apache Airflow: Exposing stack trace in case of constraint error
Rahul Vats
-
[oss-security] CVE-2025-66335: Apache Doris MCP Server: MCP SQL inject
Mingyu Chen
-
[oss-security] CVE-2026-33558: Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output
Luke Chen
-
[oss-security] CVE-2026-33557: Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
Luke Chen
-
[oss-security] CVE-2026-31987: Apache Airflow: JWT token appearing in logs
Rahul Vats
-
[oss-security] Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory
yangjincheng1998
-
[oss-security] CVE-2025-27363: FontForge affected by FreeType heap-buffer-overflow; upstream maintainer declines under Community-guidelines #D1
yangjincheng1998
-
[oss-security] cosmic-greeter: Unsafe File System Operations in User Home Directories (CVE-2026-25704)
Matthias Gerstner
-
[oss-security] UAF in rsync 3.4.1 and below
Przemyslaw Frasunek
-
[oss-security] 7 vulnerabilities disclosed & patched in jq
Alan Coopersmith
-
[oss-security] [vim-security] Command injection via backtick expansion in tag filenames in Vim < v9.2.0357
Christian Brabandt
-
[oss-security][CVE-2026-5713] CPython: Out-of-bounds read/write during remote debugging when connecting to malicious target
Alan Coopersmith
-
[oss-security] CVE-2026-5088: Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts
Robert Rothenberg
-
[oss-security] CVE-2026-25219: Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
Jarek Potiuk
-
[oss-security] CVE-2026-30778: Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
Kai Wan
-
[oss-security] CVE-2025-54550: Apache Airflow: RCE by race condition in example_xcom dag
Jarek Potiuk
-
[oss-security] [OSSA-2026-007] OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean (CVE PENDING)
Goutham Pacha Ravi
-
[oss-security] [disclosure] Multiple unpatched CVEs in libav (unmaintained FFmpeg fork, last update 2019)
yangjincheng1998
-
[oss-security] wolfSSL 5.9.1 CVE and non-CVE fixes
Solar Designer
-
[oss-security] wolfSSL ML-DSA: same-process heap reuse exposes private signing material, enabling signature forgery
Abhinav Agarwal
-
[oss-security] CVE-2026-33929: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
Tilman Hausherr
-
[oss-security] CVE-2026-31908: Apache APISIX: forward auth plugin allows header injection
Abhishek Choudhary
-
[oss-security] CVE-2026-31924: Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP
Abhishek Choudhary
-
[oss-security] CVE-2026-31923: Apache APISIX: Openid-connect `tls_verify` field is disabled by default
Abhishek Choudhary
-
[oss-security] CVE-2026-5086: Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks
Robert Rothenberg
-
[oss-security][CVE-2026-4786] CPython: Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Alan Coopersmith
-
[oss-security][CVE-2026-6100] CPython: Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
Alan Coopersmith
-
[oss-security] CVE-2026-39816: Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService
David Handermann
-
[oss-security] CVE-2026-33858: Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
Rahul Vats
-
[oss-security] CVE-2025-66236: Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
Rahul Vats
-
[oss-security] CVE-2026-34884: Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server
Qiuxia Fan
-
[oss-security] CVE-2026-34476: Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
Qiuxia Fan
-
[oss-security] CVE-2026-5085: Solstice::Session versions through 1440 for Perl generates session ids insecurely
Robert Rothenberg
-
[oss-security] CVE-2026-35565: Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI
Richard Zowalla
-
[oss-security] CVE-2026-35337: Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling
Richard Zowalla
-
[oss-security] Security Audit of Hex, the Erlang package manager
Alan Coopersmith
-
[oss-security] GNU tar: listing/extraction desynchronization allows hidden file injection
Alan Coopersmith
-
[oss-security] Avahi: Reachable assertion in transport_flags_from_domain (CVE-2026-34933)
Alan Coopersmith
-
[oss-security] LibRaw 0.22.1 Release with security fixes
Alan Coopersmith
-
[oss-security] CVE-2026-35537+more: Roundcube arbitrary write + ID/XSS/etc. prior to 1.6.14
Valtteri Vuorikoski
-
[oss-security] CPython [CVE-2026-3446] Base64 decoding stops at first padded quad by default
Alan Coopersmith
-
[oss-security] CPython [CVE-2026-1502] HTTP client proxy tunnel headers not validated for CR/LF
Alan Coopersmith
-
[oss-security] [kubernetes] CVE-2026-3865: CSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server
Vinayak Goyal
-
[oss-security] CVE-2026-40199: Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass
Stig Palmquist
-
[oss-security] CVE-2026-40198: Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass
Stig Palmquist
-
[oss-security] xdg-dbus-proxy CVE-2026-34080: Eavesdrop filter bypass allows message interception
Simon McVittie
-
[oss-security] xdg-desktop-portal GHSA-rqr9-jwwf-wxgj: Trashing of arbitrary host files
Simon McVittie
-
[oss-security] CVE-2026-40200: musl libc: stack corruption in qsort with sufficiently large inputs
Rich Felker
-
[oss-security] CVE-2026-34480: Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
[oss-security] CVE-2026-40023: Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
[oss-security] CVE-2026-40021: Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
[oss-security] CVE-2026-34481: Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Piotr Karwasz
-
[oss-security] CVE-2026-34479: Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
[oss-security] CVE-2026-34478: Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Piotr Karwasz
-
[oss-security] CVE-2026-34477: Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Piotr Karwasz
-
[oss-security] CVE-2026-4631 [cockpit] Unauthenticated remote code execution due to SSH command-line argument injection
Jelle van der Waa
-
[oss-security] [OSSA-2026-006] OpenStack Skyline: DOM-based XSS in Skyline Console via unsanitized instance console log rendering (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] CVE-2026-34500: Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
-
[oss-security] CVE-2026-34487: Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
Mark Thomas
-
[oss-security] CVE-2026-34486: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Mark Thomas
-
[oss-security] CVE-2026-34483: Apache Tomcat: Incomplete escaping of JSON access logs
Mark Thomas
-
[oss-security] CVE-2026-32990: Apache Tomcat: Fix for CVE-2025-66614 is incomplete
Mark Thomas
-
[oss-security] CVE-2026-29129: Apache Tomcat: TLS cipher order is not preserved
Mark Thomas
-
[oss-security] CVE-2026-29146: Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
Mark Thomas
-
[oss-security] CVE-2026-29145: Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Mark Thomas
-
[oss-security] CVE-2026-25854: Apache Tomcat: Occasionally open redirect
Mark Thomas
-
[oss-security] CVE-2026-24880: Apache Tomcat: Request smuggling via invalid chunk extension
Mark Thomas
-
[oss-security] CVE-2026-40046: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
Christopher L. Shannon
-
[oss-security] CVE-2026-39304: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
Christopher L. Shannon
-
[oss-security] CVE-2025-57735: Apache Airflow: Airflow Logout Not Invalidating JWT
Rahul Vats
-
[oss-security] CVE-2026-34020: Apache OpenMeetings: Login Credentials Passed via GET Query Parameters
Maxim Solodovnik
-
[oss-security] CVE-2026-33266: Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt
Maxim Solodovnik
-
[oss-security] CVE-2026-33005: Apache OpenMeetings: Insufficient checks in FileWebService
Maxim Solodovnik
-
[oss-security] CVE-2026-34538: Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
Rahul Vats
-
[oss-security] lftp 4.9.3 does not filter non-printable characters in the output to the terminal
Vincent Lefevre
-
[oss-security] 4 security fixes in Flatpak, including critical CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context
Solar Designer
-
[oss-security] libpng 1.6.57: Use-after-free vulnerability fixed: CVE-2026-34757
Cosmin Truta
-
[oss-security] X41 Advisory X41-2026-001: Guardrail Sandbox Escape in LiteLLM
Markus Vervier
-
[oss-security] Go 1.26.2 and Go 1.25.9 are released with 10 security fixes
Alan Coopersmith