Messages by Thread
-
-
[oss-security] CVE-2026-65948: Apache Ranger: UnixAuth lacks brute-force protection
Velmurugan Periasamy
-
[oss-security] CVE-2026-65945: Apache Ranger: Logs contain replayable JWT bearer tokens
Velmurugan Periasamy
-
[oss-security] CVE-2026-65942: Apache Ranger: Clients accept TLS certificates issued for other hostnames
Velmurugan Periasamy
-
[oss-security] CVE-2026-55814: Apache Ranger: Download APIs expose plugin data without authentication
Velmurugan Periasamy
-
[oss-security] CVE-2026-55799: Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator
Velmurugan Periasamy
-
[oss-security] CVE-2026-44416: Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
Velmurugan Periasamy
-
[oss-security] CVE-2026-42537: Apache Ranger: Remote Code Execution via JDBC URL Injection
Velmurugan Periasamy
-
[oss-security] CVE-2026-40920: Apache Ranger: Privilege Escalation via URL Parameter
Velmurugan Periasamy
-
[oss-security] CVE-2026-32227: Apache Ranger: SQL Injection vulnerability in lookup functionality
Velmurugan Periasamy
-
[oss-security] CVE-2026-28672: Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
Velmurugan Periasamy
-
[oss-security] CVE-2026-17510: Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute
Timothy Legge
-
[oss-security] CVE-2026-61899: Apache Tapestry: Possible classpath file download through URL manipulation
Thiago Henrique De Paula Figueiredo
-
[oss-security] CVE-2026-17435: File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
Robert Rothenberg
-
[oss-security] CVE-2026-19082: Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
Stig Palmquist
-
[oss-security] CVE-2026-71560: Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Chaokun Yang
-
[oss-security] CVE-2026-71559: Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata
Chaokun Yang
-
[oss-security] CVE-2026-71558: Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
Chaokun Yang
-
[oss-security] CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
Colm O hEigeartaigh
-
[oss-security] CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing
Colm O hEigeartaigh
-
[oss-security] CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
Colm O hEigeartaigh
-
[oss-security] CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
Colm O hEigeartaigh
-
[oss-security] CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped
Colm O hEigeartaigh
-
[oss-security] CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
Colm O hEigeartaigh
-
[oss-security] CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
Colm O hEigeartaigh
-
[oss-security] CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
Colm O hEigeartaigh
-
[oss-security] CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
Colm O hEigeartaigh
-
[oss-security] CVE-2026-64958: Apache CXF: Denial of service via message header attachments
Colm O hEigeartaigh
-
[oss-security] CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message
Colm O hEigeartaigh
-
[oss-security] CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
Colm O hEigeartaigh
-
[oss-security] CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
Alexandre Dutra
-
[oss-security] CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Eric Covener
-
[oss-security] CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Eric Covener
-
[oss-security] CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Eric Covener
-
[oss-security] CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash
Eric Covener
-
[oss-security] CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Eric Covener
-
[oss-security] rust-in-peace: results from agent-assisted Rust OSS vulnerability research
Sergei G
-
[oss-security] CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Fourie Zhang
-
[oss-security] PowerDNS Security Advisory 2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption
Otto Moerbeek
-
[oss-security] [OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201)
Jay Faulkner
-
[oss-security] ejabberd 26.07 released with several security fixes
Eddie Chapman
-
[oss-security] CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Enxin Xie
-
[oss-security] CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content
Enxin Xie
-
[oss-security] CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Enxin Xie
-
[oss-security] CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Enxin Xie
-
[oss-security] CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Enxin Xie
-
[oss-security] CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Enxin Xie
-
[oss-security] CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP Response Checking
Norbert Pócs
-
[oss-security] CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Piotr Karwasz
-
[oss-security] CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Piotr Karwasz
-
[oss-security] CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Piotr Karwasz
-
[oss-security] CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
Piotr Karwasz
-
[oss-security] CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
Robert Rothenberg
-
[oss-security] CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
Robert Rothenberg
-
[oss-security] CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
-
[oss-security] CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Timothy A. Bish
-
[oss-security] CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
-
[oss-security] CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
-
[oss-security] CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
-
[oss-security] CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
-
[oss-security] CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
Timothy A. Bish
-
[oss-security] CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Timothy A. Bish
-
[oss-security] CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
-
[oss-security] CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
-
[oss-security] CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
-
[oss-security] CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Daniil Kirilyuk
-
[oss-security] CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Daniil Kirilyuk
-
[oss-security] CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Daniil Kirilyuk
-
[oss-security] CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Daniil Kirilyuk
-
[oss-security] CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Daniil Kirilyuk
-
[oss-security] CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Daniil Kirilyuk
-
[oss-security] CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Daniil Kirilyuk
-
[oss-security] CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Robbie Gemmell
-
[oss-security] CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Robbie Gemmell
-
[oss-security] CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded
Robbie Gemmell
-
[oss-security] CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
Robbie Gemmell
-
[oss-security] CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
Robbie Gemmell
-
[oss-security] CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Robbie Gemmell
-
[oss-security] Django CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920
Natalia Bidart
-
[oss-security] Bouncy Castle 1.85 release fixes 32 CVEs
Alan Coopersmith
-
[oss-security] OSSN-0104: Ironic-Python-Agent may fallback to mDNS unexpectedly
Jay Faulkner
-
[oss-security] CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
David Handermann
-
[oss-security] CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
David Handermann
-
[oss-security] CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests
David Handermann
-
[oss-security] CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
David Handermann
-
[oss-security] CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions
Andy Seaborne
-
[oss-security] mpg123 release 1.33.7 with lots of security-relevant fixes
Dr. Thomas Orgis
-
[oss-security] [CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream)
Abhinav Agarwal
-
[oss-security] Lean 4 kernel soundness bug: forging proofs via nested inductive projections (0 = 1 demonstrated)
Jonathan Brossard
-
[oss-security] CVE-2026-18536: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
Robert Rothenberg
-
[oss-security] Rejected CVE reports against SQLite, libraw, ESP32-audioI2S
Alan Coopersmith
-
[oss-security] CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
Akira Ajisaka
-
[oss-security] PHP 30 July 2026 security releases
Alan Coopersmith
-
[oss-security] Some Changes to GNOME Security Tracking
Alan Coopersmith
-
[oss-security] o6 Automation open62541: multiple CISA-coordinated OPC UA vulnerabilities
Abhinav Agarwal
-
[oss-security] CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Tim Allison
-
[oss-security] CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser
Tim Allison
-
[oss-security] 33 Vulnerabilities in cJSON
Alan Coopersmith
-
[oss-security] CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time
Robert Rothenberg
-
[oss-security] CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check
Robert Rothenberg
-
[oss-security] CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28814: Apache JSPWiki: Arbitrary Wiki Markup rendering due to lack of authentication
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28813: Apache JSPWiki: JSON hijacking
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28812: Apache JSPWiki: UserManager does not sanity-check user database at startup
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-28811: Apache JSPWiki: Error Handling Reveals Error Details
Juan Pablo Santos Rodríguez
-
[oss-security] CVE-2026-22068+more: multiple vulnerabilities in Apache Traffic Server prior to 9.2.15/10.1.4
Valtteri Vuorikoski
-
[oss-security] [SBA-ADV-20260128-04] CVE-2026-16970: DFIR-IRIS 2.4.26 and possibly others Insufficient Logout Implementation
SBA Research Security Advisory
-
[oss-security] [SBA-ADV-20260128-02] CVE-2026-16971 CVE-2026-18362: DFIR-IRIS 2.4.26 and possibly others Missing Brute Force Protection
SBA Research Security Advisory
-
[oss-security] [SBA-ADV-20260126-01] CVE-2026-16969 CVE-2026-18360 CVE-2026-18361: DFIR-IRIS 2.4.26 and possibly others Stored XSS
SBA Research Security Advisory
-
[oss-security] CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
Daniel Gaspar
-
[oss-security] CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
Daniel Gaspar
-
[oss-security] CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
Akira Ajisaka
-
[oss-security] CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Jongyoul Lee
-
[oss-security] CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Jongyoul Lee
-
[oss-security] CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition
Jongyoul Lee
-
[oss-security] CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Jongyoul Lee
-
[oss-security] Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
Alan Coopersmith
-
[oss-security] Backports available - cBPF JIT spray hardening
Pawan Gupta
-
[oss-security] Fwd: [CVE-2026-13346] pip absolute path traversal during download from malicious package indexes
Alan Coopersmith
-
[oss-security] [OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707)
Goutham Pacha Ravi
-
[oss-security] [NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service
advisories
-
[oss-security] CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
Akira Ajisaka
-
[oss-security] CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints
Radhika Kundam
-
[oss-security] [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] CVE-2026-66299: Apache Tomcat: DoS via WebSocket chat example
Mark Thomas
-
[oss-security] Xen Security Advisory 508 v2 - pygrub is only supported in de-privileged mode
Xen . org security team
-
[oss-security] Xen Security Advisory 507 v2 (CVE-2026-62434) - PoD: Don't try to reclaim special pages
Xen . org security team
-
[oss-security] Xen Security Advisory 506 v2 (CVE-2026-62433) - correct buffer checks for DM_OP hypercalls
Xen . org security team
-
[oss-security] Xen Security Advisory 505 v2 (CVE-2026-62432) - evtchn: Race between FIFO expand and reset
Xen . org security team
-
[oss-security] Xen Security Advisory 504 v2 (CVE-2026-62431) - Viridian STIMER division by zero
Xen . org security team
-
[oss-security] Xen Security Advisory 503 v2 (CVE-2026-62430) - x86: Out-of-bounds read in vRTC emulation
Xen . org security team
-
[oss-security] Xen Security Advisory 502 v3 (CVE-2026-62429) - vNUMA domain cleanup may race other operations
Xen . org security team
-
[oss-security] Xen Security Advisory 501 v4 (CVE-2026-62435,CVE-2026-62436) - grant-table: version change racing with other operations
Xen . org security team
-
[oss-security] Xen Security Advisory 500 v2 (CVE-2026-62428) - grant-table: type confusion in grant-copy
Xen . org security team
-
[oss-security] Xen Security Advisory 497 v2 (CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425) - buffer overruns in libfsimage iso9660 handling
Xen . org security team
-
[oss-security] Xen Security Advisory 496 v2 (CVE-2026-42492) - vIRQ event channel binding may break Xenstore
Xen . org security team
-
[oss-security] Xen Security Advisory 495 v2 (CVE-2026-42493) - x86 shadow paging is deprecated
Xen . org security team
-
[oss-security] [CVE pending] Eclipse Milo <= 1.1.4: password-recovery oracle, pre-auth DoS, and four server flaws
Abhinav Agarwal
-
[oss-security] CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
Shahar Epstein
-
[oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
manizada
-
[oss-security] [NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Write
advisories
-
[oss-security] [NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
advisories
-
[oss-security] CVE-2026-17552: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call
Robert Rothenberg
-
[oss-security] CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Robert Lazarski
-
[oss-security] CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Christopher L. Shannon
-
[oss-security] CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Christopher L. Shannon