Messages by Date
-
2026/05/19
[oss-security] CVE-2026-29220: Apache OFBiz: Low-Privilege LFI in Content Component
Jacopo Cappellato
-
2026/05/19
[oss-security] CVE-2026-29207: Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component
Jacopo Cappellato
-
2026/05/19
[oss-security] CVE-2026-47323: Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
Andrea Cosentino
-
2026/05/19
[oss-security] [SBA-ADV-20260128-05] CVE-2026-42547: DFIR-IRIS before 2.4.28 Alerts Can be Falsely Attributed to Customers
SBA Research Security Advisory
-
2026/05/19
[oss-security] [SBA-ADV-20260128-03] CVE-2026-42543: DFIR-IRIS before 2.4.28 Cross-Site Request Forgery (CSRF)
SBA Research Security Advisory
-
2026/05/19
[oss-security] [SBA-ADV-20260128-01] CVE-2026-42540: DFIR-IRIS before 2.4.28 Mass Assignment
SBA Research Security Advisory
-
2026/05/19
[oss-security] [SBA-ADV-20260126-04] CVE-2026-42539: DFIR-IRIS before 2.4.28 Excessive Data Exposure
SBA Research Security Advisory
-
2026/05/19
[oss-security] [SBA-ADV-20260126-03] CVE-2026-42538: DFIR-IRIS before 2.4.28 Insecure File Upload
SBA Research Security Advisory
-
2026/05/19
[oss-security] [SBA-ADV-20260126-02] CVE-2026-42329: DFIR-IRIS before 2.4.28 Open Redirect
SBA Research Security Advisory
-
2026/05/19
[oss-security] PinTheft Linux LPE
Sam James
-
2026/05/19
Re: [oss-security] Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054
Steffen Nurpmeso
-
2026/05/19
Re: [oss-security] Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054
Hanno Böck
-
2026/05/19
[oss-security] Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054
Marcus Meissner
-
2026/05/19
Re: [oss-security] On the issue of MIME handlers that execute arbitrary code (e.g. Wine)
Simon McVittie
-
2026/05/18
[oss-security] On the issue of MIME handlers that execute arbitrary code (e.g. Wine)
Aaron Rainbolt
-
2026/05/18
[oss-security] CVE-2026-31431 Copy Fail Linux LPE - new public exploit
Andrei Berestov
-
2026/05/18
Re: [oss-security] CVE request experience
Fabian Keil
-
2026/05/17
[oss-security] CVE-2026-8788: Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections
Robert Rothenberg
-
2026/05/17
[oss-security] CVE-2026-8721: Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs
Timothy Legge
-
2026/05/17
[oss-security] CVE-2026-8507: Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out of bound (OOB) write flaws
Timothy Legge
-
2026/05/17
[oss-security] [vim-security] Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex affects Vim < 9.2.0496
Christian Brabandt
-
2026/05/17
[oss-security] [vim-security] Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name affects Vim < 9.2.495
Christian Brabandt
-
2026/05/17
[oss-security] CVE-2026-46720: Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections
Robert Rothenberg
-
2026/05/17
Re: [oss-security] Recent Kernel exploits, attack surface reduction, example IPSEC
Donald Buczek
-
2026/05/16
[oss-security] CVE-2026-46719: Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections
Robert Rothenberg
-
2026/05/16
Re: [oss-security] Recent Kernel exploits, attack surface reduction, example IPSEC
Jeffrey Walton
-
2026/05/16
Re: [oss-security] Recent Kernel exploits, attack surface reduction, example IPSEC
Lionel Debroux
-
2026/05/16
Re: [oss-security] Recent Kernel exploits, attack surface reduction, example IPSEC
Bernhard R. Link
-
2026/05/16
Re: [oss-security] Recent Kernel exploits, attack surface reduction, example IPSEC
Agostino Sarubbo
-
2026/05/16
Re: [oss-security] Recent Kernel exploits, attack surface reduction, example IPSEC
Valtteri Vuorikoski
-
2026/05/16
[oss-security] Recent Kernel exploits, attack surface reduction, example IPSEC
Hanno Böck
-
2026/05/16
Re: [oss-security] Coordinated Disclosure in the LLM Age
Greg KH
-
2026/05/15
Sv: [oss-security] Coordinated Disclosure in the LLM Age
ROI AI
-
2026/05/15
[oss-security] CVE-2026-8704: Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified
Timothy Legge
-
2026/05/15
[oss-security] CVE-2026-8700: Crypt::DSA versions before 1.20 for Perl generate seeds using rand
Timothy Legge
-
2026/05/15
Re: [oss-security] Poppy: XPC Observability & Fault Injection
Solar Designer
-
2026/05/15
[oss-security] Poppy: XPC Observability & Fault Injection
Stuart Thomas
-
2026/05/15
[oss-security] PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 Released with security fixes
Alan Coopersmith
-
2026/05/15
[oss-security] netatalk 4.4.3 fixes 20 CVEs, leaves 18 for later
Alan Coopersmith
-
2026/05/15
[oss-security] libpng-apng: Chunk-smuggling vulnerability in push-mode APNG parser: CVE-2026-40930
Cosmin Truta
-
2026/05/15
[oss-security] CVE-2026-35194: Apache Flink: Remote code execution via SQL injection in code generation
Martijn Visser
-
2026/05/15
[oss-security] Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers
135266653
-
2026/05/15
[oss-security] CVE-2026-46474: Trog::TOTP versions before 1.006 for Perl generate secrets using rand
Robert Rothenberg
-
2026/05/15
[oss-security] CVE-2026-8669: Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files
Timothy Legge
-
2026/05/15
[oss-security] CVE-2026-8503: Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids
Robert Rothenberg
-
2026/05/15
[oss-security] CVE-2026-8454: Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files
Timothy Legge
-
2026/05/15
Sv: [oss-security] Coordinated Disclosure in the LLM Age
Markus Klyver
-
2026/05/15
Re: [oss-security] Coordinated Disclosure in the LLM Age
Demi Marie Obenour
-
2026/05/15
Re: [oss-security] Coordinated Disclosure in the LLM Age
Santiago Ruano Rincón
-
2026/05/15
Re: [oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Sam James
-
2026/05/15
Re: [oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
David Gonzalez
-
2026/05/15
[oss-security] Re: Logic bug in the Linux kernel's __ptrace_may_access() function
Qualys Security Advisory
-
2026/05/15
Re: [oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Qualys Security Advisory
-
2026/05/15
Re: [oss-security] Coordinated Disclosure in the LLM Age
Greg KH
-
2026/05/15
Re: [oss-security] Coordinated Disclosure in the LLM Age
Yves-Alexis Perez
-
2026/05/14
Re: [oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Salvatore Bonaccorso
-
2026/05/14
Re: [oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Salvatore Bonaccorso
-
2026/05/14
Re: [oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Sam James
-
2026/05/14
[oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Qualys Security Advisory
-
2026/05/14
[oss-security] CVE-2026-8612: WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution
Stig Palmquist
-
2026/05/14
[oss-security] [vim-security] Vimscript Code Injection in netrw NetrwMarkFile() via crafted filename affects Vim < 9.2.480
Christian Brabandt
-
2026/05/14
[oss-security] [vim-security] Command Injection in tar.vim affects Vim < 9.2.479
Christian Brabandt
-
2026/05/14
[oss-security] CVE-2026-45205: Apache Commons Configuration: StackOverflowError for YAML input with cycles
Gary D. Gregory
-
2026/05/14
Re: [oss-security] Linux kernel LPE ("fragnesia", copyfail 3.0)
Salvatore Bonaccorso
-
2026/05/13
Re: [oss-security] [vim-security] Heap Buffer Overflow in spell file loading affects Vim < 9.2.0450
Tianyu Chen
-
2026/05/13
Re: [oss-security] Linux kernel LPE ("fragnesia", copyfail 3.0)
Jan Schaumann
-
2026/05/13
[oss-security][CVE-2026-8328] CPython: FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
Alan Coopersmith
-
2026/05/13
[oss-security] CVE-2026-8500: Web::Passwd versions through 0.03 for Perl is vulnerable to RCE
Robert Rothenberg
-
2026/05/13
[oss-security] NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945
Alan Coopersmith
-
2026/05/13
Re: [oss-security] Linux kernel LPE ("fragnesia", copyfail 3.0)
Solar Designer
-
2026/05/13
Re: [oss-security] Linux kernel LPE ("fragnesia", copyfail 3.0)
Greg KH
-
2026/05/13
[oss-security] CVE-2026-8463: Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input
Stig Palmquist
-
2026/05/13
[oss-security] Linux kernel LPE ("fragnesia", copyfail 3.0)
Sam James
-
2026/05/12
[oss-security] CVE-2026-41326: Kata Containers: CopyFile Policy Subversion via Symlinks
Solar Designer
-
2026/05/12
[oss-security] CVE-2026-5958: GNU sed: TOCTOU race in sed -i --follow-symlinks
Solar Designer
-
2026/05/12
Re: [oss-security] [EXIM-Security-2026-05-01.1] Security Release 4.99.3
Sam James
-
2026/05/12
Re: [oss-security] dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
Sam James
-
2026/05/12
[oss-security] Fwd: [siren] [Security Advisory] Severity: CRITICAL - Malicious Compromise of OpenSearch Pre-Release npm Packages
Alan Coopersmith
-
2026/05/12
Re: [oss-security] Coordinated Disclosure in the LLM Age
Willy Tarreau
-
2026/05/12
Re: [oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Ilia
-
2026/05/12
Re: [oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Joshua Windle
-
2026/05/12
Re: [oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Sebastian Pipping
-
2026/05/12
Re: [oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Ilia
-
2026/05/12
Re: [oss-security] Coordinated Disclosure in the LLM Age
Demi Marie Obenour
-
2026/05/12
[oss-security] CVE-2026-5089: YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
Robert Rothenberg
-
2026/05/12
[oss-security] Xen Security Advisory 490 v1 (CVE-2025-54518) - x86: CPU Opcode Cache corruption
Xen . org security team
-
2026/05/12
[oss-security] CVE-2026-42498: Apache Tomcat: WebSocket authentication header exposure
Mark Thomas
-
2026/05/12
[oss-security] CVE-2026-41293: Apache Tomcat: HTTP/2 request headers not validated
Mark Thomas
-
2026/05/12
[oss-security] CVE-2026-41284: Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Mark Thomas
-
2026/05/12
[oss-security] CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied
Mark Thomas
-
2026/05/12
[oss-security] CVE-2026-43514: Apache Tomcat: AJP secret compared in non-constant time
Mark Thomas
-
2026/05/12
[oss-security] CVE-2026-43513: Apache Tomcat: LockOutRealm treats user names as case-sensitive
Mark Thomas
-
2026/05/12
[oss-security] CVE-2026-43512: Apache Tomcat: Digest authenticator will authenticate any unknown user
Mark Thomas
-
2026/05/12
[oss-security] CVE-2026-8368: LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects
Stig Palmquist
-
2026/05/12
[oss-security] Dovecot Security Advisory OXDC-2026-0002
Aki Tuomi
-
2026/05/12
[oss-security] Re: [EXIM-Security-2026-05-01.1] Security Release 4.99.3
Heiko Schlittermann
-
2026/05/12
[oss-security] [EXIM-Security-2026-05-01.1] Security Release 4.99.3
Heiko Schlittermann
-
2026/05/12
Re: [oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Sebastian Pipping
-
2026/05/11
[oss-security] Public security analysis and LLM-assisted variant discovery
Tim Shephard
-
2026/05/11
Re: [oss-security] Coordinated Disclosure in the LLM Age
Tim Shephard
-
2026/05/11
[oss-security] CVE-2026-7010: HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values
Stig Palmquist
-
2026/05/11
[oss-security] libexpat 2.8.1 fixes CVE-2026-45186 (denial of service)
Sebastian Pipping
-
2026/05/11
[oss-security] CVE-2026-6146: Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys
Robert Rothenberg
-
2026/05/11
[oss-security] CVE-2022-4988: Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries
Robert Rothenberg
-
2026/05/11
Re: [oss-security][CVE-2026-7210] Cpython: The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
Sebastian Pipping
-
2026/05/11
Re: [oss-security] dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
Alan Coopersmith
-
2026/05/11
[oss-security] OpenSSL ARM64 SM2 scalar multiplication timing side-channel (no CVE)
Abhinav Agarwal
-
2026/05/11
[oss-security] dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
Alan Coopersmith
-
2026/05/11
[oss-security] CVE Request: Fail-open authentication in hathor-wallet-headless <= 0.38.0 (vendor declined to fix)
Emiliano Solazzi G.
-
2026/05/11
[oss-security][CVE-2026-7210] Cpython: The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
Alan Coopersmith
-
2026/05/11
[oss-security] [OSSA-2026-012] Ironic: Remote Code Execution when Anaconda driver enabled (CVE-2026-44916)
Jay Faulkner
-
2026/05/11
Re: [oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption
xw x
-
2026/05/11
Re: [oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption
xw x
-
2026/05/11
Re: [oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption
xw x
-
2026/05/11
[oss-security] CVE-2026-5084: WebDyne::Session versions through 2.075 for Perl generates the session id insecurely
Stig Palmquist
-
2026/05/11
Re: [oss-security] CVE-2026-8177: XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
Stig Palmquist
-
2026/05/11
[oss-security] malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API (CVE-2026-44931)
Matthias Gerstner
-
2026/05/10
[oss-security] CVE-2026-45191: Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
Stig Palmquist
-
2026/05/10
[oss-security] CVE-2026-8177: XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
Stig Palmquist
-
2026/05/10
[oss-security] CVE-2026-45190: Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass
Stig Palmquist
-
2026/05/10
[oss-security] CVE-2026-45180: Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids
Robert Rothenberg
-
2026/05/10
[oss-security] CVE-2026-45179: Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses
Robert Rothenberg
-
2026/05/10
[oss-security] CVE-2026-41018: Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
Shahar Epstein
-
2026/05/10
[oss-security] CVE-2026-43826: Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL
Shahar Epstein
-
2026/05/10
Re: [oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Solar Designer
-
2026/05/09
[oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Sebastian Pipping
-
2026/05/08
[oss-security] CVE-2026-25199: Apache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access
Piotr P. Karwasz
-
2026/05/08
[oss-security] CVE-2026-25077: Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates
Piotr P. Karwasz
-
2026/05/08
[oss-security] CVE-2025-69233: Apache CloudStack: Domain/account resources limits not honored
Piotr P. Karwasz
-
2026/05/08
[oss-security] CVE-2025-66467: Apache CloudStack: MinIO policy remains intact on bucket deletion
Piotr P. Karwasz
-
2026/05/08
[oss-security] CVE-2025-66172: Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
Piotr P. Karwasz
-
2026/05/08
[oss-security] CVE-2025-66171: Apache CloudStack: Any user can create a new VM from backups they should not have access to
Piotr P. Karwasz
-
2026/05/08
[oss-security] CVE-2025-66170: Apache CloudStack: Any user can list backups that they should not have access to
Piotr P. Karwasz
-
2026/05/08
[oss-security] Go 1.26.3 and Go 1.25.10 are released with 11 security fixes
Alan Coopersmith
-
2026/05/08
Re: [oss-security] Re: Dirty Frag: Universal Linux LPE
Emily Shepherd
-
2026/05/08
Re: [oss-security] Re: Dirty Frag: Universal Linux LPE
Greg Dahlman
-
2026/05/08
[oss-security] CVE-2026-6659: Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts
Robert Rothenberg
-
2026/05/08
[oss-security] BioPython 1.87 fixes CVE-2025-68463 (XXE, SSRF)
Sebastian Pipping
-
2026/05/08
Re: [oss-security] Re: Dirty Frag: Universal Linux LPE
Kalin KOZHUHAROV
-
2026/05/08
Re: [oss-security] CVE request: io_uring zcrx freelist OOB write
Jens Axboe
-
2026/05/08
Re: [oss-security] Copy Fail 2 / Dirty Frag — n-day from public commit, not embargo break
Sam James
-
2026/05/08
[oss-security] CVE-2013-10075: Apache::Session versions through 1.94 for Perl re-creates deleted sessions
Robert Rothenberg
-
2026/05/08
Re: [oss-security] Dirty Frag: Universal Linux LPE
Bernhard R. Link
-
2026/05/08
Re: [oss-security] CVE request: io_uring zcrx freelist OOB write
Mohamed salem Eddah
-
2026/05/08
Re: [oss-security] XSS in Postorius (Mailman 3) 1.3.13 and earlier
Sebastian Pipping
-
2026/05/08
Re: [oss-security] Dirty Frag: Universal Linux LPE
Greg KH
-
2026/05/08
Re: [oss-security] Dirty Frag: Universal Linux LPE
Greg KH
-
2026/05/07
[oss-security] Re: Dirty Frag: Universal Linux LPE
Daniel Tang
-
2026/05/07
Re: [oss-security] XSS in Postorius (Mailman 3) 1.3.13 and earlier
Demi Marie Obenour
-
2026/05/07
Re: [oss-security] CVE request: io_uring zcrx freelist OOB write
Solar Designer
-
2026/05/07
[oss-security] Re: CVE request: io_uring zcrx freelist OOB write
Jens Axboe
-
2026/05/07
Re: [oss-security] CVE request: io_uring zcrx freelist OOB write
Pavel Begunkov
-
2026/05/07
[oss-security] Re: CVE request: io_uring zcrx freelist OOB write
Benjamin Hays
-
2026/05/07
[oss-security] Copy Fail 2 / Dirty Frag — n-day from public commit, not embargo break
SiCk
-
2026/05/07
Re: [oss-security] CVE request: io_uring zcrx freelist OOB write
Jens Axboe
-
2026/05/07
Re: [oss-security] Dirty Frag: Universal Linux LPE
Sandipan Roy
-
2026/05/07
[oss-security] [vim-security] Heap Buffer Overflow in spell file loading affects Vim < 9.2.0450
Christian Brabandt
-
2026/05/07
[oss-security] Dirty Frag: Universal Linux LPE
Hyunwoo Kim
-
2026/05/07
Re: [oss-security] CVE request: io_uring zcrx freelist OOB write
Mohamed salem Eddah
-
2026/05/07
[oss-security] [OSSA-2026-011] OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management (CVE-2026-40213, CVE-2026-40214)
Goutham Pacha Ravi
-
2026/05/07
Re: [oss-security] CVE request: io_uring zcrx freelist OOB write
Solar Designer
-
2026/05/07
Re: [oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption
Sam James
-
2026/05/07
[oss-security] XSS in Postorius (Mailman 3) 1.3.13 and earlier
Alyssa Ross
-
2026/05/06
Re: [oss-security] Precise disclosure contents for copyfail (Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation)
Greg KH
-
2026/05/06
[oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption
Solar Designer
-
2026/05/06
[oss-security] Vulnerability fixes in Tor 0.4.9.7
Sam James
-
2026/05/06
[oss-security] CVE-2026-40562: Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence
Robert Rothenberg
-
2026/05/06
[oss-security] CVE-2026-5081: Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure
Robert Rothenberg
-
2026/05/05
Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation
Eric Biggers
-
2026/05/05
[oss-security] CVE-2026-43975: Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager
Pedro Henrique Oliveira dos Santos
-
2026/05/05
[oss-security] CVE-2026-43646: Apache Wicket: crafted URLs can bypass PackageResourceGuard
Pedro Henrique Oliveira dos Santos
-
2026/05/05
[oss-security] CVE-2026-42509: Apache Wicket: crafted strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
-
2026/05/05
[oss-security] CVE-2026-40010: Apache Wicket: possible session fixation using AuthenticatedWebSession
Pedro Henrique Oliveira dos Santos
-
2026/05/05
[oss-security] Security audit of Paramiko completed, fixes coming in 5.0 release
Alan Coopersmith
-
2026/05/05
Re: [oss-security] CVE-2026-29169: Apache HTTP Server: mod_dav_lock indirect lock crash
Solar Designer
-
2026/05/05
[oss-security] vm2: sandbox escape in NodeVM with nesting:true (CVE-2026-44007)
Akshat Sinha
-
2026/05/05
[oss-security] [OSSA-2026-010] Ironic: Credential Forwarding to Arbitrary Endpoints via iDrac Configuration Molds Feature (CVE-2026-42997)
Jay Faulkner
-
2026/05/05
[oss-security] CVE-2026-28780: Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
Eric Covener
-
2026/05/05
[oss-security] Django CVE-2026-5766, CVE-2026-35192, and CVE-2026-6907
Sarah Boyce
-
2026/05/05
[oss-security] [OSSA-2026-009] Horizon: Unauthenticated session flood via login redirect storage (CVE-2026-43002)
Goutham Pacha Ravi
-
2026/05/05
[oss-security] CVE-2026-29168: Apache HTTP Server: mod_md unrestricted OCSP response
Eric Covener
-
2026/05/04
Re: [oss-security] [pfx] Postfix stable release 3.11.2 and legacy releases 3.10.9, 3.9.10, 3.8.16
Solar Designer
-
2026/05/04
[oss-security] CVE-2026-43870: Apache Thrift: Node.js web_server.js multi-vulnerability
Jens Geyer
-
2026/05/04
[oss-security] CVE-2026-43869: Apache Thrift: TSSLTransportFactory.java hostname verification
Jens Geyer
-
2026/05/04
[oss-security] CVE-2026-43868: Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
Jens Geyer
-
2026/05/04
[oss-security] Re: systemd-journald in systemd 259 does not escape characters in emerg messages that are wall'd to other user's terminals
Aaron Rainbolt
-
2026/05/04
[oss-security] Nix/Lix: local privilege escalation in daemon process
Martin Weinelt
-
2026/05/04
[oss-security] Local privilege escalation in Lix and Nix
Thomas GERBET
-
2026/05/04
Re: [oss-security] Precise disclosure contents for copyfail (Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation)
Emily Shepherd
-
2026/05/04
Re: [oss-security] Fwd: [pfx] Postfix stable release 3.11.2 and legacy releases 3.10.9, 3.9.10, 3.8.16
Salvatore Bonaccorso
-
2026/05/04
Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation
Solar Designer
-
2026/05/04
Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation
Demi Marie Obenour
-
2026/05/04
Re: [oss-security] Precise disclosure contents for copyfail (Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation)
Greg KH
-
2026/05/04
[oss-security] Re: [pfx] Postfix stable release 3.11.2 and legacy releases 3.10.9, 3.9.10, 3.8.16
Sam James
-
2026/05/04
[oss-security] Fwd: [pfx] Postfix stable release 3.11.2 and legacy releases 3.10.9, 3.9.10, 3.8.16
Sam James
-
2026/05/04
Re: [oss-security] Precise disclosure contents for copyfail (Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation)
Emily Shepherd
-
2026/05/04
[oss-security] CVE-2026-33523: Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
Eric Covener
-
2026/05/04
[oss-security] CVE-2026-33007: Apache HTTP Server: mod_authn_socache crash
Eric Covener
-
2026/05/04
[oss-security] CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing attack
Eric Covener
-
2026/05/04
[oss-security] CVE-2026-29169: Apache HTTP Server: mod_dav_lock indirect lock crash
Eric Covener