Messages by Date
-
2026/06/22
[oss-security] CVE-2026-6653: libxml2: use after free in xmlParseInternalSubset (>=2.9.11, <2.11.0)
Sudhakar Verma
-
2026/06/22
Re: [oss-security] Squid CVE-2026-47729 and CVE-2026-50012
Salvatore Bonaccorso
-
2026/06/21
[oss-security] CVE-2025-66336: Apache Doris MCP Server: SQL injection leading the authentication bypass
Calvin Kirs
-
2026/06/21
[oss-security] [vim-security] Arbitrary Code Execution via Python Omni-Completion Docstrings in Vim < 9.2.0699
Christian Brabandt
-
2026/06/21
[oss-security] [vim-security] Out-of-bounds Write in SOFO Soundfolding in Vim < 9.2.0698
Christian Brabandt
-
2026/06/20
[oss-security] CVE-2026-54665: Apache NiFi: Missing Validation for Proxy Host Headers
David Handermann
-
2026/06/20
[oss-security] CVE-2026-44914: Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents
David Handermann
-
2026/06/20
[oss-security] CVE-2026-44913: Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
David Handermann
-
2026/06/20
[oss-security] CVE-2026-44911: Apache NiFi: Incorrect Authorization for Configuration Verification Requests
David Handermann
-
2026/06/20
[oss-security] [vim-security] Out-of-bounds Read with Text Properties in Vim >= 9.2.0320 && Vim < 9.2.0679
Christian Brabandt
-
2026/06/20
[oss-security] [vim-security] PowerShell Command Injection in zip.vim via Crafted Archive Entry Names in Vim > 9.1.1783 && Vim < 9.2.0678
Christian Brabandt
-
2026/06/20
[oss-security] CVE-2025-62198: Apache Atlas: Stored XSS in Create Entity page
Madhan Neethiraj
-
2026/06/19
Re: [oss-security] Fwd: Node.js security updates for all active release lines, June 2026
Solar Designer
-
2026/06/19
[oss-security] CVE-2026-49872: Apache APISIX: Improper authentication in cas-auth plugin
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-49871: Apache APISIX: cas-auth login CSRF / session injection issue
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-49231: Apache APISIX: Identity spoofing issue in APISIX opa plugin
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-49230: Apache APISIX: Authentication bypass in jwe-decrypt
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-48895: Apache APISIX: Cas-auth Host header influence on CAS service URL
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-47341: Apache APISIX: Session replay issue in hmac-auth
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-47339: Apache APISIX: authz-casdoor incorrect session sharing
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-44915: Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-44087: Apache APISIX: Openid-connect plugin Identity Header Spoofing
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-44046: Apache APISIX: wolf-rbac plugin Identity Spoofing
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication bypass
Abhishek Choudhary
-
2026/06/19
[oss-security] CVE-2026-39998: Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
Abhishek Choudhary
-
2026/06/19
[oss-security] OpenBSD mpls_do_error: Remote Kernel Stack Disclosure via MPLS Label Stack Over-read
shj
-
2026/06/18
[oss-security] [containerd] Patch releases addressing CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262
Samuel Karp
-
2026/06/18
Re: [oss-security] Squid CVE-2026-47729 and CVE-2026-50012
Alan Coopersmith
-
2026/06/18
[oss-security] [vim-security] Out-of-bounds Read with libsodium-encrypted Files in Vim < 9.2.0671
Christian Brabandt
-
2026/06/18
[oss-security] CVE-2026-9692: Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely
Robert Rothenberg
-
2026/06/18
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Jeremy Stanley
-
2026/06/18
[oss-security] Fwd: Node.js security updates for all active release lines, June 2026
Rafael Gonzaga
-
2026/06/18
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Sylvain Beucler
-
2026/06/18
Re: [oss-security] How to request CVE numbers?
Marta Rybczynska
-
2026/06/18
[oss-security] [CVE-2026-43495] Linux kernel: slab out-of-bounds read in MediaTek t7xx WWAN driver
Pavitra Jha
-
2026/06/17
[oss-security] [vim-security] Out-of-bounds Read in Text Property Count in Vim < 9.2.0670
Christian Brabandt
-
2026/06/17
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
David A. Wheeler
-
2026/06/17
[oss-security] CVE-2026-49268: Apache Shiro: LDAP DN Injection in DefaultLdapRealm
Lenny Primak
-
2026/06/16
[oss-security] CVE-2026-41280: Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
Wenjun Ruan
-
2026/06/16
[oss-security] CVE-2026-49050: Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens
Wenjun Ruan
-
2026/06/16
[oss-security] CVE-2026-47340: Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Wenjun Ruan
-
2026/06/16
[oss-security] CVE-2026-42357: Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Wenjun Ruan
-
2026/06/16
[oss-security] CVE-2026-32967: Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Wenjun Ruan
-
2026/06/16
[oss-security] CVE-2026-32966: Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Wenjun Ruan
-
2026/06/16
[oss-security] [CVE-2026-36849] libtiff: Denial of Service via large SamplesPerPixel tag
Ryo utomo
-
2026/06/16
[oss-security] [vim-security] Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename affects Vim < 9.2.0663
Christian Brabandt
-
2026/06/16
[oss-security] [vim-security] Out-of-bounds Write in Spell File Prefix Dump in Vim < 9.2.0662
Christian Brabandt
-
2026/06/16
[oss-security] [OSSN-0100] Ironic: Command Injection in IPA (CVE-2026-43003)
Jay Faulkner
-
2026/06/16
[oss-security] [OSSA-2026-023] Ironic: Sensitive properties returned unredacted in POST and PATCH HTTP responses (CVE-2026-54421)
Jay Faulkner
-
2026/06/16
[oss-security] OpenBSD sppp_pap_input: PAP authentication bypass
shj
-
2026/06/16
[oss-security][CVE-2026-12003] CPython In-tree (development) search paths can be enabled without modifying install directory
Alan Coopersmith
-
2026/06/16
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
3v
-
2026/06/16
[oss-security] Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649)
Marco Benatto
-
2026/06/16
[oss-security] [OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints (CVE-2026-46448)
Goutham Pacha Ravi
-
2026/06/16
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Prentice Bisbal
-
2026/06/16
[oss-security] CVE-2026-50203: Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry names
Jarek Potiuk
-
2026/06/16
[oss-security] 'rcp' and friends meet escape characters and quoting
Collin Funk
-
2026/06/15
[oss-security] Fwd: gsasl-2.2.4 released - fixes heap disclosure
Alan Coopersmith
-
2026/06/15
[oss-security] CVE-2026-11832: Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce
Robert Rothenberg
-
2026/06/15
[oss-security] CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read
Robert Rothenberg
-
2026/06/15
[oss-security] [OSSA-2026-017] Errata 1: Ironic: Script injection during node boot via linux command line override (CVE-2026-46447)
Jay Faulkner
-
2026/06/15
[oss-security] [vim-security] Out-of-bounds Write in Spell File Word Count in Vim < 9.2.0653
Christian Brabandt
-
2026/06/15
[oss-security] tmux 3.6b fixes CVE-2026-11623
Alan Coopersmith
-
2026/06/15
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Alan Coopersmith
-
2026/06/15
Re: [oss-security] How to request CVE numbers?
Salvatore Bonaccorso
-
2026/06/15
[oss-security] CVE-2026-12205: Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery
Timothy Legge
-
2026/06/15
Re: [oss-security] Squid CVE-2026-47729 and CVE-2026-50012
Amos Jeffries
-
2026/06/15
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Stuart Henderson
-
2026/06/14
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
David A. Wheeler
-
2026/06/14
[oss-security] CVE-2026-11527: Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle
Paul Johnson
-
2026/06/14
[oss-security] CVE-2026-11526: GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
Paul Johnson
-
2026/06/14
Re: [oss-security] CVE-2026-9641: Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
Harry Sintonen
-
2026/06/14
Re: [oss-security] CVE-2026-9641: Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
Peter Gutmann
-
2026/06/14
Re: [oss-security] CVE-2026-9641: Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
Jacob Bachmeyer
-
2026/06/13
Re: [oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Solar Designer
-
2026/06/13
[oss-security] CVE-2025-52292: Stack-based Buffer Overflow in GPAC/MP4Box via filein_process on crafted MP4 file during DASH segmentation
shvedov
-
2026/06/13
[oss-security] CVE-2025-55662: Divide by Zero in GPAC/MP4Box via gf_opus_parse_packet_header on crafted MP4 file with malformed Opus header
shvedov
-
2026/06/13
[oss-security] CVE-2025-52293: Out-of-bounds Read in GPAC/MP4Box via gf_hevc_read_sps_bs_internal on crafted HEVC SPS in MP4 file
shvedov
-
2026/06/13
[oss-security] CVE-2025-55651: NULL Pointer Dereference in GPAC/MP4Box via gf_isom_get_user_data_count on truncated MP4 input
shvedov
-
2026/06/13
[oss-security] CVE-2025-55659: NULL Pointer Dereference in GPAC/MP4Box via ctts_box_write on crafted MP4 file with negative timestamps
shvedov
-
2026/06/13
[oss-security] CVE-2025-55657: NULL Pointer Dereference in GPAC/MP4Box via gf_odf_vvc_cfg_write_bs on crafted MP4 file with unsupported vvc16 box
shvedov
-
2026/06/13
[oss-security] CVE-2025-55660: Stack-based Buffer Overflow in GPAC/MP4Box via gf_opus_read_length on crafted MP4 file with malformed Opus packet
shvedov
-
2026/06/13
[oss-security] CVE-2025-55663: NULL Pointer Dereference in GPAC/MP4Box via Track_SetStreamDescriptor on crafted MP4 with unknown svcC box in av01
shvedov
-
2026/06/13
[oss-security] CVE-2025-55661: Heap-based Buffer Overflow in GPAC/MP4Box via gf_opus_parse_packet_header on crafted MP4 file with malformed Opus packet
shvedov
-
2026/06/13
[oss-security] CVE-2025-55650: Use-After-Free in GPAC/MP4Box via gf_svg_node_del on crafted MP4 file processed with -svg
shvedov
-
2026/06/13
[oss-security] CVE-2025-55649: NULL Pointer Dereference in GPAC/MP4Box via gf_media_map_esd on crafted MP4 with corrupted ESD data
shvedov
-
2026/06/13
[oss-security] CVE-2025-55648: Heap-based Buffer Overflow in GPAC/MP4Box via gf_opus_parse_packet_header on crafted MP4 with corrupted stsz data
shvedov
-
2026/06/13
[oss-security] CVE-2025-55641: NULL Pointer Dereference in GPAC/MP4Box via gf_isom_copy_sample_info on crafted MP4 file with corrupted SAI metadata
shvedov
-
2026/06/13
[oss-security] CVE-2025-55642: Divide by Zero in GPAC/MP4Box via avidmx_process on crafted AVI input with zero declared frames
shvedov
-
2026/06/13
[oss-security] CVE-2025-55647: Integer Overflow in GPAC/MP4Box via mp4_mux_cenc_insert_pssh on crafted MP4 with oversized PSSH metadata
shvedov
-
2026/06/13
[oss-security] CVE-2025-55645: Heap-based Buffer Overflow in GPAC/MP4Box via gf_cenc_set_pssh on crafted MP4 with oversized PSSH payload
shvedov
-
2026/06/13
[oss-security] CVE-2025-55643: NULL Pointer Dereference in GPAC/MP4Box via TrackWriter handling on crafted MP4 with malformed mvcC/stsz metadata during DASH segmentation
shvedov
-
2026/06/13
[oss-security] CVE-2025-55652: Heap-based Buffer Overflow in GPAC/MP4Box via gf_isom_vp_config_new on crafted MP4 with malformed VP codec configuration
shvedov
-
2026/06/13
[oss-security] CVE-2025-55644: Use-After-Free in GPAC/MP4Box via gf_node_get_tag on crafted MP4 file with invalid BIFS GlobalQuantizer command
shvedov
-
2026/06/13
[oss-security] CVE-2026-41579: runc allows a malicious image with a /dev symlink to trigger limited host filesystem integrity violations
Aleksa Sarai
-
2026/06/12
Re: [oss-security] CVE-2026-9641: Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
Peter Gutmann
-
2026/06/12
[oss-security] CVE-2026-9641: Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
Robert Rothenberg
-
2026/06/12
[oss-security] CVE-2026-9638: Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts
Robert Rothenberg
-
2026/06/12
[oss-security] CVE-2017-20240: Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks
Robert Rothenberg
-
2026/06/12
[oss-security] CVE-2026-33590: Insecure default settings of Portainer < 2.38.0 allow host takeover
Dimitris Glynos
-
2026/06/12
[oss-security] Squid CVE-2026-47729 and CVE-2026-50012
Amos Jeffries
-
2026/06/11
[oss-security] CVE-2026-50645: Apache CXF: No restriction on attachment headers per message
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50634: Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50633: Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50632: Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50631: Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50630: Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50629: Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50628: Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50627: Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-50623: Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService
Colm O hEigeartaigh
-
2026/06/11
[oss-security] CVE-2026-49875: Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils
Colm O hEigeartaigh
-
2026/06/11
Re: [oss-security] How to request CVE numbers?
Securin Disclose
-
2026/06/10
Re: [oss-security] How to request CVE numbers?
Hauke Mehrtens
-
2026/06/10
Re: [oss-security] CVE-2026-45257: FreeBSD kTLS-RX in-place AES-GCM decrypt over sendfile(2) EXTPG mbufs to page-cache write / local root
Lucas Holt
-
2026/06/10
[oss-security] CVE-2026-45257: FreeBSD kTLS-RX in-place AES-GCM decrypt over sendfile(2) EXTPG mbufs to page-cache write / local root
bumsrakete
-
2026/06/10
[oss-security] CVE-2026-50639: Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections
Robert Rothenberg
-
2026/06/10
[oss-security] CVE-2026-50638: Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections
Robert Rothenberg
-
2026/06/10
[oss-security] CVE-2026-50637: Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections
Robert Rothenberg
-
2026/06/10
[oss-security] ITScape: Guest-to-Host Escape in KVM/arm64 (CVE-2026-46316)
Hyunwoo Kim
-
2026/06/10
[oss-security] Re: Local privilege escalation in Lix and Nix
Thomas GERBET
-
2026/06/10
Re: [oss-security] Fwd: Node.js security updates for all active release lines, June 2026
h
-
2026/06/10
[oss-security] CVE-2026-50223: Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution
Jacopo Cappellato
-
2026/06/10
[oss-security] CVE-2026-47342: Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
Jacopo Cappellato
-
2026/06/10
[oss-security] Fwd: Node.js security updates for all active release lines, June 2026
Rafael Gonzaga
-
2026/06/10
[oss-security] CVE-2026-25700: Apache Answer: AdminToken not invalidated after admin deactivation
Enxin Xie
-
2026/06/10
Re: [oss-security] How to request CVE numbers?
Sam Bull
-
2026/06/10
Re: [oss-security] How to request CVE numbers?
Michael Freeman
-
2026/06/10
Re: [oss-security] How to request CVE numbers?
Lucas Holt
-
2026/06/10
[oss-security] Multiple vulnerabilities in Jenkins
Daniel Beck
-
2026/06/10
Re: [oss-security] How to request CVE numbers?
Christian Brabandt
-
2026/06/10
Re: [oss-security] How to request CVE numbers?
Marcus Meissner
-
2026/06/10
Re: [oss-security] How to request CVE numbers?
swing sze
-
2026/06/10
[oss-security] ldns insufficiently verifies that responses belong to a query
Willem Toorop
-
2026/06/10
[oss-security] How to request CVE numbers?
Hauke Mehrtens
-
2026/06/09
[oss-security] OpenSSL Security Advisory
Tomas Mraz
-
2026/06/09
[oss-security] Xen Security Advisory 494 v3 (CVE-2026-42488) - x86: mismatched mapcache metadata
Xen . org security team
-
2026/06/09
[oss-security] Xen Security Advisory 491 v2 (CVE-2026-42487) - x86 HVM I/O port list traversal
Xen . org security team
-
2026/06/09
[oss-security] CVE-2009-10007: Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks
Robert Rothenberg
-
2026/06/09
[oss-security] CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
Robert Rothenberg
-
2026/06/09
[oss-security] CVE-2026-49818: Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object names
Jarek Potiuk
-
2026/06/09
[oss-security] CVE-2026-25688: Apache Answer: XSS in AI Answer Rendering
Enxin Xie
-
2026/06/09
[oss-security] CVE-2026-25699: Apache Answer: Authorization Bypass in Timeline API
Enxin Xie
-
2026/06/09
[oss-security] CVE-2026-33582: Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error
Enxin Xie
-
2026/06/09
[oss-security] CVE-2026-34031: Apache Answer: The custom avatar was not properly validated
Enxin Xie
-
2026/06/09
[oss-security] CVE-2026-34033: Apache Answer: HTML Content Injection in Email
Enxin Xie
-
2026/06/09
[oss-security] CVE-2026-34905: Apache Answer: Unlisted Questions Accessible via Direct API Access
Enxin Xie
-
2026/06/09
[oss-security] Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
David A. Wheeler
-
2026/06/08
[oss-security][CVE-2026-9669] CPython: bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
Alan Coopersmith
-
2026/06/08
[oss-security] CVE-2026-49975: Apache HTTP Server: mod_http2 denial of service
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhausted
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-44631: Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-44186: Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-44185: Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-44119: Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-43951: Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-42536: Apache HTTP Server: mod_xml2enc heap overflow
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-42535: Apache HTTP Server: mod_dav_fs protected directory access
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-34356: Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-34355: Apache HTTP Server: mod_proxy_html buffer overflow
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-29170: Apache HTTP Server: mod_proxy_ftp XSS
Eric Covener
-
2026/06/08
[oss-security] CVE-2026-29167: Apache HTTP Server: mod_ldap per-dir use-after-free
Eric Covener
-
2026/06/08
[oss-security] offlineimap 8.0.3 fixes CVE-2020-37248 (STARTTLS stripping)
Sebastian Pipping
-
2026/06/08
Re: [oss-security] libinput: libinput-device-group unescaped phys output can inject udev properties
Salvatore Bonaccorso
-
2026/06/07
[oss-security] rsync 3.4.4 released, regression fixes
Andrew Tridgell
-
2026/06/07
[oss-security] CVE-2026-47430: Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews
Niklas Merz
-
2026/06/06
[oss-security] CVE-2026-10725: Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb
Robert Rothenberg
-
2026/06/05
[oss-security] CVE-2026-11362: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
Robert Rothenberg
-
2026/06/05
[oss-security] CVE-2026-9270: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
Robert Rothenberg
-
2026/06/05
[oss-security] CVE-2026-10879: DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
Robert Rothenberg
-
2026/06/05
Re: [oss-security] libinput: libinput-device-group unescaped phys output can inject udev properties
Salvatore Bonaccorso
-
2026/06/05
[oss-security] [OSSN-0099] Denial of Service in OpenStack Ironic under reduced process stack size (CVE-2026-50589)
Jay Faulkner
-
2026/06/05
[oss-security] Project Zero discloses 4 bugs in FreeType
Alan Coopersmith
-
2026/06/04
[oss-security] Re: FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland
Peter Hutterer
-
2026/06/04
Re: [oss-security] libinput: libinput-device-group unescaped phys output can inject udev properties
Peter Hutterer
-
2026/06/04
Re: [oss-security] HTTP/2 Bomb affects Apache httpd, nginx, envoy, & pingora
Alan Coopersmith
-
2026/06/04
[oss-security] [vim-security] Arbitrary Code Execution via Python Omni-Completion in Vim < 9.2.597
Christian Brabandt
-
2026/06/04
[oss-security] Re: [OSSA-2026-021] OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/06/04
[oss-security] CVE-2026-49942: Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
Robert Rothenberg
-
2026/06/04
[oss-security] CVE-2026-49941: Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
Robert Rothenberg
-
2026/06/04
[oss-security] CVE-2026-49940: Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
Robert Rothenberg
-
2026/06/04
[oss-security][CVE-2026-7774] Cpython: tarfile.data_filter path traversal bypass allows writing outside the extraction directory
Alan Coopersmith
-
2026/06/04
[oss-security] CVE-2026-46741: Etsy::StatsD versions through 1.002002 for Perl allow metric injections
Robert Rothenberg
-
2026/06/04
[oss-security] CVE-2026-46739: Net::Statsd versions before 0.13 for Perl allow metric injections
Robert Rothenberg
-
2026/06/04
[oss-security] [OSSA-2026-021] OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/06/04
[oss-security] libinput: libinput-device-group unescaped phys output can inject udev properties
Peter Hutterer
-
2026/06/04
[oss-security] CVE-2026-50076: Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
Chaokun Yang
-
2026/06/03
Re: [oss-security] Linux kernel TLS ULP use-after-free in tls_sk_proto_close()
Jacob Bachmeyer
-
2026/06/03
[oss-security] CVE-2026-8829: HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities
Paul Johnson
-
2026/06/03
[oss-security] CVE-2026-8722: Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections
Robert Rothenberg
-
2026/06/03
[oss-security] 5 CVEs in Redis
Alan Coopersmith
-
2026/06/03
[oss-security] CVE-2026-48842+more: Roundcube numerous vulnerabilities prior to 1.6.16/1.7.1
Valtteri Vuorikoski
-
2026/06/03
Re: [oss-security] Linux kernel TLS ULP use-after-free in tls_sk_proto_close()
Emily Shepherd
-
2026/06/03
[oss-security][CVE-2026-3276] Potential DoS via quadratic complexity in unicodedata.normalize()
Alan Coopersmith
-
2026/06/03
[oss-security] [OSSA-2026-020] OpenStack Mistral: Mistral policy enforcement bypass allows unauthorized public resource creation and arbitrary code execution (CVE-2026-41283)
Goutham Pacha Ravi
-
2026/06/03
[oss-security] [OSSA-2026-019] Ironic: File Extraction from conductor via pxe_template (CVE-2026-44917)
Jay Faulkner
-
2026/06/03
[oss-security] [OSSA-2026-018] Ironic: File overwrite on Ironic conductor via path traversal in ISO handling (CVE-2026-48681)
Jay Faulkner
-
2026/06/03
[oss-security] [OSSA-2026-017] Ironic: Script injection during node boot via linux command line override (CVE-2026-46447)
Jay Faulkner
-
2026/06/03
[oss-security] Django CVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193, and CVE-2026-48587
Natalia Bidart
-
2026/06/03
Re: [oss-security] Linux kernel TLS ULP use-after-free in tls_sk_proto_close()
Oleg Sevostyanov