Messages by Thread
-
[oss-security] CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Sheng Wu
-
[oss-security] CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
Kai Wan
-
[oss-security] [OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)
Goutham Pacha Ravi
-
[oss-security] CVE-2026-80530: Linux XFS EXCHANGE_RANGE reflink flag clearing leading to local privilege escalation
Lin Jiapeng
-
[oss-security] CVE-2026-80180: Apache Allura: Stored XSS via markdown HTML processing
Dave Brondsema
-
[oss-security] CVE-2026-81270: Apache Allura: Information exposure via search
Dave Brondsema
-
[oss-security] CVE-2026-80190: Apache Allura: Stored XSS via code repositories
Dave Brondsema
-
[oss-security] CVE-2026-80181: Apache Allura: Server-side request forgery
Dave Brondsema
-
[oss-security] Fwd: Vulnerabilities in golang.org/x/crypto
Alan Coopersmith
-
[oss-security] [SECURITY ADVISORIES] curl 8.22.0
Daniel Stenberg
-
[oss-security] CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record
Timothy Legge
-
[oss-security] CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4
Holden Karau
-
[oss-security] CVE-2026-80205 : ReDoS in NLTK Text.findall() (CVSS 8.7 High)
Aditi Bhatnagar
-
[oss-security] FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstrated
Samuel Page
-
[oss-security] CVE-2026-76986: Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue
Emond Papegaaij
-
[oss-security] Plone security advisory 20260831
Maurits van Rees (Plone)
-
[oss-security] CVE-2026-19953: URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
Robert Rothenberg
-
[oss-security] libexpat 2.8.4 fixes 4 vulnerabilities
Sebastian Pipping
-
[oss-security] libksba-1.8.1 fixes a possible CMS parser infinite loop
Sam James
-
[oss-security] LACT: Polkit Authentication Bypass and Temporary File Handling Issues (CVE-2026-75037, CVE-2026-75038)
Matthias Gerstner
-
[oss-security] Fwd: [Announce] Libgcrypt 1.12.3 released
Sam James
-
[oss-security] CVE-2026-76983: Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel
Emond Papegaaij
-
[oss-security] CVE-2026-76984: Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute
Emond Papegaaij
-
[oss-security] CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements
Robert Rothenberg
-
[oss-security] CVE-2026-76985: Apache Wicket: XSS in Palette via getAdditionalAttributes
Emond Papegaaij
-
[oss-security] CVE-2026-76982: Apache Wicket: XSS in Button via its model object
Emond Papegaaij
-
[oss-security] CVE-2026-75802: Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel
Emond Papegaaij
-
[oss-security] CVE-2026-71378: Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener
Emond Papegaaij
-
[oss-security] CVE-2026-71257: Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed
Emond Papegaaij
-
[oss-security] CVE-2026-70449: Apache Wicket: Path traversal in resource style/variation/locale
Emond Papegaaij
-
[oss-security] CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate host
Lenny Primak
-
[oss-security] Exiv2 0.28.9 released
Kevin Backhouse
-
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via full-schema "did you mean" suggestion scan
William Carrier
-
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS from a single syntax error
William Carrier
-
[oss-security] CVE-2026-78002: rsyslog RainerScript replace() heap buffer overflow
Rainer Gerhards
-
[oss-security] Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293)
t.preissl
-
[oss-security] Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released
Chad Dougherty
-
[oss-security] [CVE-2026-8715] HashiCorp Vault Secrets Operator 1.3.0-1.4.1: tenant-controlled secretIDPath leaks operator ServiceAccount token (path to cluster-admin)
cherez0ff
-
[oss-security] NSD 4.15.1 security release
Willem Toorop
-
[oss-security] Dovecot Security Advisory 3/2026
Aki Tuomi
-
[oss-security] bubblewrap 0.12.0 fixes writes outside sandbox
Simon McVittie
-
[oss-security] The GNU C Library security advisory update for 2026-08-27
Siddhesh Poyarekar
-
[oss-security] Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely
Syed
-
[oss-security] [vim-security] Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688
Christian Brabandt
-
[oss-security] [vim-security] Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013
Christian Brabandt
-
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via per-error full-document rescan (GetLocation)
First name Last name
-
[oss-security] CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
Abhishek Choudhary
-
[oss-security] CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS
Abhishek Choudhary
-
[oss-security] CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins
Abhishek Choudhary
-
[oss-security] CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
Abhishek Choudhary
-
[oss-security] CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session
Mark Thomas
-
[oss-security] CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Mark Thomas
-
[oss-security] CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases
Mark Thomas
-
[oss-security] CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints
Mark Thomas
-
[oss-security] CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints
Mark Thomas
-
[oss-security] CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
Mark Thomas
-
[oss-security] CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication
Mark Thomas
-
[oss-security] CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete
Mark Thomas
-
[oss-security] CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets
Mark Thomas
-
[oss-security] CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint
Mark Thomas
-
[oss-security] [CVE-2026-19672] CPython: tarfile extraction filter bypass allows creation of directories outside the destination
Alan Coopersmith
-
[oss-security] [vim-security] Arbitrary Ex Command Execution via File Names in C Omni-Completion in Vim < 9.2.1011
Christian Brabandt
-
[oss-security] CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
Timothy Legge
-
[oss-security] CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
Timothy Legge
-
[oss-security] [OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] OpenRGB: Remote System Compromise via Custom Network Protocol (CVE-2026-59682, CVE-2026-59683, CVE-2026-18794)
Matthias Gerstner
-
[oss-security] OpenSSL Security Advisory [25th August 2026]
Tomas Mraz
-
[oss-security] graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS
First name Last name
-
[oss-security] CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Andrea Cosentino
-
[oss-security] CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Andrea Cosentino
-
[oss-security] CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Andrea Cosentino
-
[oss-security] CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
Andrea Cosentino
-
[oss-security] CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
Andrea Cosentino
-
[oss-security] CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Andrea Cosentino
-
[oss-security] CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Andrea Cosentino
-
[oss-security] CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Andrea Cosentino
-
[oss-security] CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure
Dave Brondsema
-
[oss-security] CVE-2026-78331 / CVE-2026-78332: Multiple Vulnerabilities in NethServer
Intilangelo, Andrea
-
[oss-security] BusyBox dpkg applet: OS command injection
Solar Designer
-
[oss-security] CVE-2026-78183: DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float
Robert Rothenberg
-
[oss-security] CVE-2026-19565: Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
Robert Rothenberg
-
[oss-security] Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540)
Fabiano Fidencio
-
[oss-security] CVE-2026-75922: Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line
Timothy Legge
-
[oss-security] CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access
Paul Eggert
-
[oss-security] CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them
Timothy Legge
-
[oss-security] CVE-2026-75870: Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret
Timothy Legge
-
[oss-security] [NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File
advisories
-
[oss-security] CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Robert Rothenberg
-
[oss-security] Emacs zero-click local command execution via TRAMP
Sean Whitton
-
[oss-security] [OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStack
Goutham Pacha Ravi
-
[oss-security] CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Manuel Huber
-
[oss-security] CVE-2026-63044: Apache InLong: Authenticated SSRF via POST /api/node/testConnection
Charles Zhang
-
[oss-security] CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
Charles Zhang
-
[oss-security] CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint
Charles Zhang
-
[oss-security] CVE-2026-15743: Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable
Robert Rothenberg
-
[oss-security] CVE-2026-63038: Apache InLong: SQL Injection via String Concatenation Vulnerability Report
Charles Zhang
-
[oss-security] CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Charles Zhang
-
[oss-security] CVE-2026-63016: Apache InLong: Ordinary users can create new packages
Charles Zhang
-
[oss-security] CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints
Charles Zhang
-
[oss-security] CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDelete
Charles Zhang
-
[oss-security] CVE-2026-63015: Apache InLong: Non-template responsible persons can view template information
Charles Zhang
-
[oss-security] rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv)
Rainer Gerhards
-
[oss-security] Fwd: [pfx] Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27
Sam James
-
[oss-security] Multiple vulnerabilities fixed in libgit2-1.9.5, 1.9.7
Sam James
-
[oss-security] GNU Emacs vulnerability upon opening arbitrary file
Sam James
-
[oss-security] uutils coreutils 'stdbuf' uses LD_PRELOAD on a world-writable temporary file
Collin Funk
-
[oss-security] CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter
Timothy Legge
-
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005
Adrian Perez de Castro
-
[oss-security] [OSSA-2026-008] ERRATA 2: Ironic Command Injection in IPMI Console Implementations
Jay Faulkner
-
[oss-security] Ceph 20.2.4 and Ceph 19.2.6 are released with 4 security fixes.
Sage McTaggart
-
[oss-security] [OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] CVE-2026-72889: Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
Robert Rothenberg
-
[oss-security] CVE-2026-75589: Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify
Robert Rothenberg
-
[oss-security] CPython [CVE-2026-15806] urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme
Alan Coopersmith
-
[oss-security] CPython [CVE-2026-17084] StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0
Alan Coopersmith
-
[oss-security] AI slop "Combined chain advisory — fallback.efi/SBAT/memdisk bypass"
Solar Designer
-
[oss-security] LyX security advisory
Pavel Sanda
-
[oss-security] Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged userns
Erica Windisch
-
[oss-security] CVE-2026-72888: Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require
Robert Rothenberg
-
[oss-security] CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
Robert Rothenberg
-
[oss-security] CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
Timothy Legge
-
[oss-security] libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requested
Sumit Chakraborty
-
[oss-security] CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
Timothy Legge
-
[oss-security] CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse
Robert Rothenberg
-
[oss-security] CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse
Robert Rothenberg
-
[oss-security] CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)
Elman Shahbazov
-
[oss-security] croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)
Souiri Anas
-
[oss-security] IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)
Bakabaka_9
-
[oss-security] Info-ZIP test option (-T) command injection
Harry Sintonen
-
[oss-security] [OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented
Jay Faulkner
-
[oss-security] Go 1.26.6 and Go 1.25.13 are released with 10 security fixes
Alan Coopersmith
-
[oss-security] [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE pending)
Jeremy Stanley
-
[oss-security] CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template
Robert Rothenberg
-
[oss-security] CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
Robert Rothenberg
-
[oss-security] CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template
Robert Rothenberg
-
[oss-security] CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
Stig Palmquist
-
[oss-security] CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
Arnout Engelen
-
[oss-security] CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Oleg Kalnichevski
-
[oss-security] CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Oleg Kalnichevski
-
[oss-security] CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
Robert Rothenberg
-
[oss-security] CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
Robert Rothenberg
-
[oss-security] rsync 3.5.0 released with fixes for 33 CVEs
Andrew Tridgell
-
[oss-security] CVE-2026-73238: Apache Allura: XSS in code display
Dave Brondsema
-
[oss-security] Linux kernel: Guest-to-Host DoS via TAP
Dongli Zhang
-
[oss-security] CVE-2026-73240: Apache Allura: Git command injection
Dave Brondsema
-
[oss-security] CVE-2026-73239: Apache Allura: Missing permission checks IDOR
Dave Brondsema
-
[oss-security] CVE-2026-73237: Apache Allura: XSS in markdown pipeline
Dave Brondsema
-
[oss-security] CVE-2026-68971: Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints
Rahul Vats
-
[oss-security] CVE-2026-68970: Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI
Rahul Vats
-
[oss-security] CVE-2026-68969: Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext
Rahul Vats
-
[oss-security] CVE-2026-68968: Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id
Rahul Vats
-
[oss-security] CVE-2026-68076: Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection
Rahul Vats
-
[oss-security] CVE-2026-67587: Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget
Rahul Vats
-
[oss-security] CVE-2026-67260: Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization
Rahul Vats
-
[oss-security] CVE-2026-65017: Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)
Rahul Vats
-
[oss-security] CVE-2026-59244: Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
Rahul Vats
-
[oss-security] CVE-2026-59242: Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint
Rahul Vats
-
[oss-security] CVE-2026-58076: Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server
Rahul Vats
-
[oss-security] CVE-2026-54183: Apache Airflow: Airflow Variables were not masked in the UI for authenticated users
Rahul Vats
-
[oss-security] CVE-2026-68868: Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables
Jarek Potiuk
-
[oss-security] CVE-2026-19566: Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths
Robert Rothenberg
-
[oss-security] xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast message filtering bypass
Simon McVittie
-
[oss-security] Flatpak 1.18.1 fixes multiple vulnerabilities
Simon McVittie
-
[oss-security] [OSSN-0106] Ironic API ramdisk endpoints require network-level access controls
Jay Faulkner
-
[oss-security] [OSSN-0105] OpenStack Glance legacy Tasks import bypasses image import URI filtering
Goutham Pacha Ravi
-
[oss-security] [OSSA-2026-034] OpenStack Designate: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194)
Goutham Pacha Ravi
-
[oss-security] libexpat 2.8.3 fixes CVE-2026-72522 (denial of service)
Sebastian Pipping
-
[oss-security] CVE-2026-69223: Apache Allura: Server-side request forgery
Dave Brondsema
-
[oss-security] Announce: OpenSSH 10.5 released
Damien Miller
-
[oss-security] actix-multipart: field parser hangs indefinitely after EOF on a truncated boundary prefix, leaking the connection slot
Sergei G
-
[oss-security] CVE-2026-68872: Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
[oss-security] CVE-2026-68871: Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
[oss-security] CVE-2026-68870: Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
-
[oss-security] Roundcube webmail: Many security fixes in 1.6.18 / 1.7.3
Hanno Böck
-
[oss-security] CVE-2026-59774: Arbitrary file read via the Org-mode #+INCLUDE directive in Gitea and Forgejo
Tianyu Chen
-
[oss-security] CVE-2026-44630: Apache IoTDB: RPC service denial of service via unchecked Thrift string length
Haonan Hou
-
[oss-security] CVE-2026-15534: Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Stig Palmquist