Messages by Thread
-
[oss-security] CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
Robert Rothenberg
-
[oss-security] CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
Robert Rothenberg
-
[oss-security] rsync 3.5.0 released with fixes for 33 CVEs
Andrew Tridgell
-
[oss-security] CVE-2026-73238: Apache Allura: XSS in code display
Dave Brondsema
-
[oss-security] Linux kernel: Guest-to-Host DoS via TAP
Dongli Zhang
-
[oss-security] CVE-2026-73240: Apache Allura: Git command injection
Dave Brondsema
-
[oss-security] CVE-2026-73239: Apache Allura: Missing permission checks IDOR
Dave Brondsema
-
[oss-security] CVE-2026-73237: Apache Allura: XSS in markdown pipeline
Dave Brondsema
-
[oss-security] CVE-2026-68971: Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints
Rahul Vats
-
[oss-security] CVE-2026-68970: Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI
Rahul Vats
-
[oss-security] CVE-2026-68969: Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext
Rahul Vats
-
[oss-security] CVE-2026-68968: Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id
Rahul Vats
-
[oss-security] CVE-2026-68076: Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection
Rahul Vats
-
[oss-security] CVE-2026-67587: Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget
Rahul Vats
-
[oss-security] CVE-2026-67260: Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization
Rahul Vats
-
[oss-security] CVE-2026-65017: Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)
Rahul Vats
-
[oss-security] CVE-2026-59244: Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
Rahul Vats
-
[oss-security] CVE-2026-59242: Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint
Rahul Vats
-
[oss-security] CVE-2026-58076: Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server
Rahul Vats
-
[oss-security] CVE-2026-54183: Apache Airflow: Airflow Variables were not masked in the UI for authenticated users
Rahul Vats
-
[oss-security] CVE-2026-68868: Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables
Jarek Potiuk
-
[oss-security] CVE-2026-19566: Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths
Robert Rothenberg
-
[oss-security] xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast message filtering bypass
Simon McVittie
-
[oss-security] Flatpak 1.18.1 fixes multiple vulnerabilities
Simon McVittie
-
[oss-security] [OSSN-0106] Ironic API ramdisk endpoints require network-level access controls
Jay Faulkner
-
[oss-security] [OSSN-0105] OpenStack Glance legacy Tasks import bypasses image import URI filtering
Goutham Pacha Ravi
-
[oss-security] [OSSA-2026-034] OpenStack Designate: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194)
Goutham Pacha Ravi
-
[oss-security] libexpat 2.8.3 fixes CVE-2026-72522 (denial of service)
Sebastian Pipping
-
[oss-security] CVE-2026-69223: Apache Allura: Server-side request forgery
Dave Brondsema
-
[oss-security] Announce: OpenSSH 10.5 released
Damien Miller
-
[oss-security] actix-multipart: field parser hangs indefinitely after EOF on a truncated boundary prefix, leaking the connection slot
Sergei G
-
[oss-security] CVE-2026-68872: Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
[oss-security] CVE-2026-68871: Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
[oss-security] CVE-2026-68870: Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
[oss-security] Roundcube webmail: Many security fixes in 1.6.18 / 1.7.3
Hanno Böck
-
[oss-security] CVE-2026-59774: Arbitrary file read via the Org-mode #+INCLUDE directive in Gitea and Forgejo
Tianyu Chen
-
[oss-security] CVE-2026-44630: Apache IoTDB: RPC service denial of service via unchecked Thrift string length
Haonan Hou
-
[oss-security] CVE-2026-15534: Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Stig Palmquist
-
[oss-security] CVE-2026-65948: Apache Ranger: UnixAuth lacks brute-force protection
Velmurugan Periasamy
-
[oss-security] CVE-2026-65945: Apache Ranger: Logs contain replayable JWT bearer tokens
Velmurugan Periasamy
-
[oss-security] CVE-2026-65942: Apache Ranger: Clients accept TLS certificates issued for other hostnames
Velmurugan Periasamy
-
[oss-security] CVE-2026-55814: Apache Ranger: Download APIs expose plugin data without authentication
Velmurugan Periasamy
-
[oss-security] CVE-2026-55799: Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator
Velmurugan Periasamy
-
[oss-security] CVE-2026-44416: Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
Velmurugan Periasamy
-
[oss-security] CVE-2026-42537: Apache Ranger: Remote Code Execution via JDBC URL Injection
Velmurugan Periasamy
-
[oss-security] CVE-2026-40920: Apache Ranger: Privilege Escalation via URL Parameter
Velmurugan Periasamy
-
[oss-security] CVE-2026-32227: Apache Ranger: SQL Injection vulnerability in lookup functionality
Velmurugan Periasamy
-
[oss-security] CVE-2026-28672: Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
Velmurugan Periasamy
-
[oss-security] CVE-2026-17510: Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute
Timothy Legge
-
[oss-security] CVE-2026-61899: Apache Tapestry: Possible classpath file download through URL manipulation
Thiago Henrique De Paula Figueiredo
-
[oss-security] CVE-2026-17435: File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
Robert Rothenberg
-
[oss-security] CVE-2026-19082: Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
Stig Palmquist
-
[oss-security] CVE-2026-71560: Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Chaokun Yang
-
[oss-security] CVE-2026-71559: Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata
Chaokun Yang
-
[oss-security] CVE-2026-71558: Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
Chaokun Yang
-
[oss-security] CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
Colm O hEigeartaigh
-
[oss-security] CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing
Colm O hEigeartaigh
-
[oss-security] CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
Colm O hEigeartaigh
-
[oss-security] CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
Colm O hEigeartaigh
-
[oss-security] CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped
Colm O hEigeartaigh
-
[oss-security] CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
Colm O hEigeartaigh
-
[oss-security] CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
Colm O hEigeartaigh
-
[oss-security] CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
Colm O hEigeartaigh
-
[oss-security] CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
Colm O hEigeartaigh
-
[oss-security] CVE-2026-64958: Apache CXF: Denial of service via message header attachments
Colm O hEigeartaigh
-
[oss-security] CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message
Colm O hEigeartaigh
-
[oss-security] CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
Colm O hEigeartaigh
-
[oss-security] CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
Alexandre Dutra
-
[oss-security] CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Eric Covener
-
[oss-security] CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Eric Covener
-
[oss-security] CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Eric Covener
-
[oss-security] CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash
Eric Covener
-
[oss-security] CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Eric Covener
-
[oss-security] rust-in-peace: results from agent-assisted Rust OSS vulnerability research
Sergei G
-
[oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Fourie Zhang
-
[oss-security] PowerDNS Security Advisory 2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption
Otto Moerbeek
-
[oss-security] [OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201)
Jay Faulkner
-
[oss-security] ejabberd 26.07 released with several security fixes
Eddie Chapman
-
[oss-security] CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Enxin Xie
-
[oss-security] CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content
Enxin Xie
-
[oss-security] CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Enxin Xie
-
[oss-security] CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Enxin Xie
-
[oss-security] CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Enxin Xie
-
[oss-security] CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Enxin Xie
-
[oss-security] CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP Response Checking
Norbert Pócs
-
[oss-security] CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Piotr Karwasz
-
[oss-security] CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Piotr Karwasz
-
[oss-security] CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Piotr Karwasz
-
[oss-security] CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
Piotr Karwasz
-
[oss-security] CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
Robert Rothenberg
-
[oss-security] CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
Robert Rothenberg
-
[oss-security] CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
-
[oss-security] CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Timothy A. Bish
-
[oss-security] CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
-
[oss-security] CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
-
[oss-security] CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
-
[oss-security] CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
-
[oss-security] CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
Timothy A. Bish
-
[oss-security] CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Timothy A. Bish
-
[oss-security] CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
-
[oss-security] CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
-
[oss-security] CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
-
[oss-security] CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Daniil Kirilyuk
-
[oss-security] CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Daniil Kirilyuk
-
[oss-security] CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Daniil Kirilyuk
-
[oss-security] CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Daniil Kirilyuk
-
[oss-security] CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Daniil Kirilyuk
-
[oss-security] CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Daniil Kirilyuk
-
[oss-security] CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Daniil Kirilyuk
-
[oss-security] CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Robbie Gemmell
-
[oss-security] CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Robbie Gemmell
-
[oss-security] CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded
Robbie Gemmell
-
[oss-security] CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
Robbie Gemmell
-
[oss-security] CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
Robbie Gemmell
-
[oss-security] CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Robbie Gemmell
-
[oss-security] Django CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920
Natalia Bidart
-
[oss-security] Bouncy Castle 1.85 release fixes 32 CVEs
Alan Coopersmith
-
[oss-security] OSSN-0104: Ironic-Python-Agent may fallback to mDNS unexpectedly
Jay Faulkner
-
[oss-security] CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
David Handermann
-
[oss-security] CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
David Handermann
-
[oss-security] CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests
David Handermann
-
[oss-security] CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
David Handermann
-
[oss-security] CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions
Andy Seaborne
-
[oss-security] mpg123 release 1.33.7 with lots of security-relevant fixes
Dr. Thomas Orgis
-
[oss-security] [CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream)
Abhinav Agarwal
-
[oss-security] Lean 4 kernel soundness bug: forging proofs via nested inductive projections (0 = 1 demonstrated)
Jonathan Brossard
-
[oss-security] CVE-2026-18536: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
Robert Rothenberg
-
[oss-security] Rejected CVE reports against SQLite, libraw, ESP32-audioI2S
Alan Coopersmith
-
[oss-security] CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
Akira Ajisaka
-
[oss-security] PHP 30 July 2026 security releases
Alan Coopersmith
-
[oss-security] Some Changes to GNOME Security Tracking
Alan Coopersmith
-
[oss-security] o6 Automation open62541: multiple CISA-coordinated OPC UA vulnerabilities
Abhinav Agarwal
-
[oss-security] CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Tim Allison
-
[oss-security] CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser
Tim Allison
-
[oss-security] 33 Vulnerabilities in cJSON
Alan Coopersmith
-
[oss-security] CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time
Robert Rothenberg
-
[oss-security] CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check
Robert Rothenberg
-
[oss-security] CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28814: Apache JSPWiki: Arbitrary Wiki Markup rendering due to lack of authentication
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28813: Apache JSPWiki: JSON hijacking
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28812: Apache JSPWiki: UserManager does not sanity-check user database at startup
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28811: Apache JSPWiki: Error Handling Reveals Error Details
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-22068+more: multiple vulnerabilities in Apache Traffic Server prior to 9.2.15/10.1.4
Valtteri Vuorikoski
-
[oss-security] [SBA-ADV-20260128-04] CVE-2026-16970: DFIR-IRIS 2.4.26 and possibly others Insufficient Logout Implementation
SBA Research Security Advisory
-
[oss-security] [SBA-ADV-20260128-02] CVE-2026-16971 CVE-2026-18362: DFIR-IRIS 2.4.26 and possibly others Missing Brute Force Protection
SBA Research Security Advisory
-
[oss-security] [SBA-ADV-20260126-01] CVE-2026-16969 CVE-2026-18360 CVE-2026-18361: DFIR-IRIS 2.4.26 and possibly others Stored XSS
SBA Research Security Advisory
-
[oss-security] CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
Daniel Gaspar
-
[oss-security] CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
Daniel Gaspar
-
[oss-security] CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
Akira Ajisaka
-
[oss-security] CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Jongyoul Lee
-
[oss-security] CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Jongyoul Lee
-
[oss-security] CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition
Jongyoul Lee
-
[oss-security] CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Jongyoul Lee
-
[oss-security] Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
Alan Coopersmith
-
[oss-security] Backports available - cBPF JIT spray hardening
Pawan Gupta