Messages by Thread
-
[oss-security] [NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
advisories
-
[oss-security] CVE-2026-17552: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call
Robert Rothenberg
-
[oss-security] CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Robert Lazarski
-
[oss-security] CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Christopher L. Shannon
-
[oss-security] CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Christopher L. Shannon
-
[oss-security] CVE-2026-66391: Apache Wicket: leaked and missing CSP headers
Pedro Henrique Oliveira dos Santos
-
[oss-security] CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
-
[oss-security] Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Reid Sutherland
-
[oss-security] [security] critical vulnerabilities patched in svxlink (RCE)
Mark Rose
-
[oss-security] CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
Robert Rothenberg
-
[oss-security] GNU Inetutils talkd buffer overflow with long DNS names.
Collin Funk
-
[oss-security] CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports
Collin Funk
-
[oss-security] Fwd: The GNU C Library version 2.44 is now available, fixes 3 CVEs
Alan Coopersmith
-
[oss-security] CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import
Jens Geyer
-
[oss-security] CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
Jens Geyer
-
[oss-security] CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit
Jens Geyer
-
[oss-security] CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Jens Geyer
-
[oss-security] CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
Jens Geyer
-
[oss-security] CVE-2026-55970: Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
Jens Geyer
-
[oss-security] CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Jens Geyer
-
[oss-security] CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports
Jens Geyer
-
[oss-security] CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
Jens Geyer
-
[oss-security] CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit
Jens Geyer
-
[oss-security] CVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
Jens Geyer
-
[oss-security] CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification
Jens Geyer
-
[oss-security] CVE-2026-45112: Apache Thrift: Unbounded Read Leading to Denial of Service
Jens Geyer
-
[oss-security] CVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit
Jens Geyer
-
[oss-security] CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
Jens Geyer
-
[oss-security] [vim-security] Arbitrary Command Execution via the Vimball Record File in Vim < 9.2.0847
Christian Brabandt
-
[oss-security] [vim-security] Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846
Christian Brabandt
-
[oss-security] [vim-security] Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845
Christian Brabandt
-
[oss-security] [vim-security] Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844
Christian Brabandt
-
[oss-security] [vim-security] Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843
Christian Brabandt
-
[oss-security] CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp
Robert Rothenberg
-
[oss-security] CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service
Duo Zhang
-
[oss-security] CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request
Szymon Janc
-
[oss-security] CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation
Szymon Janc
-
[oss-security] [vim-security] Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840
Christian Brabandt
-
[oss-security] [vim-security] Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842
Christian Brabandt
-
[oss-security] [vim-security] Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841
Christian Brabandt
-
[oss-security] [vim-security] Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839
Christian Brabandt
-
[oss-security] CVE-2026-46452: Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure
Szymon Janc
-
[oss-security] CVE-2026-45811: Apache NimBLE: Buffer overflow in socket HCI transport
Szymon Janc
-
[oss-security] CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
Szymon Janc
-
[oss-security] CVE-2026-45812: Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
Szymon Janc
-
[oss-security] CVE-2026-66144: Apache Neethi: Remote PolicyReference fetch lacks resource bounds
Colm O hEigeartaigh
-
[oss-security] CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths
Colm O hEigeartaigh
-
[oss-security] CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing
Colm O hEigeartaigh
-
[oss-security] CVE-2026-63317: Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML
Richard Zowalla
-
[oss-security] CVE-2026-16634: TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
Robert Rothenberg
-
[oss-security] libIEC61850: four MMS/GOOSE memory-safety vulnerabilities, including lab RCE
Abhinav Agarwal
-
[oss-security] Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28
Douglas Bagnall
-
[oss-security] CVE-2026-16277 & CVE-2026-16461: buffer overflows in rpcinfo
Alan Coopersmith
-
[oss-security] [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE)
Przemyslaw Frasunek
-
[oss-security] [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending)
Goutham Pacha Ravi
-
[oss-security] [OSSA-2026-028] OpenStack Ironic Python Agent: Credential extraction via malicious container (CVE-2026-54422)
Goutham Pacha Ravi
-
[oss-security] Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...)
Hanno Böck
-
[oss-security] CVE-2026-13089: OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify
Robert Rothenberg
-
[oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Qualys Security Advisory
-
[oss-security] security release for Exim
Jeremy Harris
-
[oss-security] ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)
Michał Kępień
-
[oss-security] Unbound: 1.25.2 addresses multiple CVE items
Yorgos Thessalonikefs
-
[oss-security] PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues
Otto Moerbeek
-
[oss-security] rsyslog v8.36.0 through v8.2606.0: imptcp regex-framing remote denial of service
Rainer Gerhards
-
[oss-security] PortProtonQt: Custom Polkit Rule Allows Escalation of NetworkManager and UDisks2 Privileges (CVE-2026-59678)
Matthias Gerstner
-
[oss-security] CVE-2026-54432+more: Roundcube XSS/SSRF/etc prior to 1.6.17/1.7.2
Valtteri Vuorikoski
-
[oss-security] Multiple vulnerabilities fixed in various Data::*::Shared modules for Perl
Robert Rothenberg
-
[oss-security] 432 Linux kernel CVEs
Jan Schaumann
-
[oss-security] libssh 0.12.1 and 0.11.5 security releases
Alan Coopersmith
-
[oss-security] CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
Chaokun Yang
-
[oss-security] CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths
Chaokun Yang
-
[oss-security] CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface
Chaokun Yang
-
[oss-security] CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free
Chaokun Yang
-
[oss-security] LPE in snapd and other vulnerabilities
Eduardo Barretto
-
[oss-security] CVE-2026-58624: Apache MINA SSHD: Remote execution of JGit commands can write files on the server
Thomas Wolf
-
[oss-security] CVE-2026-56624: Apache MINA SSHD: SSH certificate options lack validations
Thomas Wolf
-
[oss-security] CVE-2026-56623: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows
Thomas Wolf
-
[oss-security] CVE-2026-56452: Apache MINA SSHD: Path traversal in SCP file reception
Thomas Wolf
-
[oss-security] CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains
Robert Rothenberg
-
[oss-security] CVE-2026-64193: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR
Robert Rothenberg
-
[oss-security] CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass
Francesco Chicchiriccò
-
[oss-security] CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check
Francesco Chicchiriccò
-
[oss-security] CVE-2026-62183: Apache Syncope: User self-service privilege escalation
Francesco Chicchiriccò
-
[oss-security] CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search
Francesco Chicchiriccò
-
[oss-security] CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector
Francesco Chicchiriccò
-
[oss-security] CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
Francesco Chicchiriccò
-
[oss-security] CVE-2026-13577: Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable
Robert Rothenberg
-
[oss-security] CVE-2026-6656: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
Robert Rothenberg
-
[oss-security] CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts
Robert Rothenberg
-
[oss-security] CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel
Wongi Lee
-
[oss-security] CVE-2026-61548: rsyslog mmpstrucdata stack overflow
Rainer Gerhards
-
[oss-security] User prompt injection (CSRF) of the llama-server's Web UI (llama.cpp)
Gabriel Corona
-
[oss-security] OpenSSL "HollowByte" DoS via attacker-controlled memory allocation size in glibc
Jan Schaumann
-
[oss-security] Cyrus IMAP 3.12.3 fixed 9 CVEs
Alan Coopersmith
-
[oss-security] 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
Alan Coopersmith
-
[oss-security] CVE-2026-9537: Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison
Robert Rothenberg
-
[oss-security] CVE-2026-14741: HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
Robert Rothenberg
-
[oss-security] CVE-2026-13082: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
Robert Rothenberg
-
[oss-security] CVE-2026-13410: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
Robert Rothenberg
-
[oss-security] CVE-2026-62764: Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
Christopher Tubbs
-
[oss-security] CVE-2026-59173: Apache Traffic Server is vulnerable to stalled HTTP/2 flow-control
Masakazu Kitajo
-
[oss-security] CVE-2026-57077: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len
Paul Johnson
-
[oss-security] CVE-2026-57076: YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor
Paul Johnson
-
[oss-security] CVE-2026-57075: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec
Paul Johnson
-
[oss-security] CVE-2026-13713: YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack
Paul Johnson
-
[oss-security] CERT VU#885548 - Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
Alan Coopersmith
-
[oss-security] CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
-
[oss-security] CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead
Robert Rothenberg
-
[oss-security] CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes
Robert Rothenberg
-
[oss-security] CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead
Robert Rothenberg
-
[oss-security] Multiple vulnerabilities in ntfs-3g
Rostislav
-
[oss-security] CVE-2026-26032: Apache Ivy: PackagerResolver path traversal vulnerability
Stefan Bodewig
-
[oss-security] SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10
Matthias Gerstner
-
[oss-security] CVE-2026-57821: Apache Fineract: Office list: SQL Injection via Subquery in orderBy
Terence Monteiro
-
[oss-security] CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
Terence Monteiro
-
[oss-security] CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint
Terence Monteiro
-
[oss-security] CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
Stig Palmquist
-
[oss-security] CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Robert Rothenberg
-
[oss-security] CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index
Robert Rothenberg
-
[oss-security] CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Robert Rothenberg
-
[oss-security] Xen Security Advisory 498 v2 (CVE-2026-42491) - XAPI: Missing TLS verification in some SDKs
Xen . org security team
-
[oss-security] CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read
Maxim Solodovnik
-
[oss-security] CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
Robert Rothenberg
-
[oss-security] CVE-2026-59084: Apache Tomcat: EncryptInterceptor requirements not clearly documented
Mark Thomas
-
[oss-security] CVE-2026-59083: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Mark Thomas
-
[oss-security] CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval
Li Yang
-
[oss-security] CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API
Li Yang
-
[oss-security] CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API
Li Yang
-
[oss-security] CVE-2026-58319: Apache Doris: Improper Authentication in Frontend HTTP API
Mingyu Chen
-
[oss-security] new af_alg exploit in the wild?
Bernd Zeimetz
-
[oss-security] 2 CVEs Crypt::OpenSSL::X509 versions before 2.1.3
Timothy Legge
-
[oss-security] CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Stig Palmquist
-
[oss-security] CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Stig Palmquist
-
[oss-security] CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
Stig Palmquist
-
[oss-security] CVE-2026-59245: Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)
Vincent Beck
-
[oss-security] CVE-2026-58065: Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
Vincent Beck
-
[oss-security] CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs
Yu Qi
-
[oss-security] CVE-2026-41041: Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
Jerry Shao
-
[oss-security] Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS
gregdurys . security
-
[oss-security] CVE-2026-49844: Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Piotr Karwasz
-
[oss-security] CVE-2026-40454: Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data
Haonan Hou
-
[oss-security] CVE-2026-40452: Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users
Haonan Hou
-
[oss-security] CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor
Haonan Hou
-
[oss-security] CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
Haonan Hou
-
[oss-security] CVE-2026-40007: Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
Haonan Hou
-
[oss-security] CVE-2026-40006: Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
Haonan Hou
-
[oss-security] CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
Haonan Hou
-
[oss-security] CVE-2026-28564: Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
Haonan Hou
-
[oss-security][CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
Alan Coopersmith
-
[oss-security] HTSlib <= 1.23.1 Multiple vulnerabilities in file reading code
Robert Davies
-
[oss-security] CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android
Jan Schaumann
-
[oss-security] Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1
Dr. Thomas Orgis
-
[oss-security] CVE-2026-57111: Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin
Junkai Xue