Messages by Thread
-
[oss-security] libpng-apng: Chunk-smuggling vulnerability in push-mode APNG parser: CVE-2026-40930
Cosmin Truta
-
[oss-security] CVE-2026-35194: Apache Flink: Remote code execution via SQL injection in code generation
Martijn Visser
-
[oss-security] Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers
135266653
-
[oss-security] CVE-2026-46474: Trog::TOTP versions before 1.006 for Perl generate secrets using rand
Robert Rothenberg
-
[oss-security] CVE-2026-8669: Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files
Timothy Legge
-
[oss-security] CVE-2026-8503: Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids
Robert Rothenberg
-
[oss-security] CVE-2026-8454: Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files
Timothy Legge
-
[oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Qualys Security Advisory
-
[oss-security] CVE-2026-8612: WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution
Stig Palmquist
-
[oss-security] [vim-security] Vimscript Code Injection in netrw NetrwMarkFile() via crafted filename affects Vim < 9.2.480
Christian Brabandt
-
[oss-security] [vim-security] Command Injection in tar.vim affects Vim < 9.2.479
Christian Brabandt
-
[oss-security] CVE-2026-45205: Apache Commons Configuration: StackOverflowError for YAML input with cycles
Gary D. Gregory
-
[oss-security][CVE-2026-8328] CPython: FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
Alan Coopersmith
-
[oss-security] CVE-2026-8500: Web::Passwd versions through 0.03 for Perl is vulnerable to RCE
Robert Rothenberg
-
[oss-security] NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945
Alan Coopersmith
-
[oss-security] CVE-2026-8463: Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input
Stig Palmquist
-
[oss-security] Linux kernel LPE ("fragnesia", copyfail 3.0)
Sam James
-
[oss-security] CVE-2026-41326: Kata Containers: CopyFile Policy Subversion via Symlinks
Solar Designer
-
[oss-security] CVE-2026-5958: GNU sed: TOCTOU race in sed -i --follow-symlinks
Solar Designer
-
[oss-security] Fwd: [siren] [Security Advisory] Severity: CRITICAL - Malicious Compromise of OpenSearch Pre-Release npm Packages
Alan Coopersmith
-
[oss-security] CVE-2026-5089: YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
Robert Rothenberg
-
[oss-security] Xen Security Advisory 490 v1 (CVE-2025-54518) - x86: CPU Opcode Cache corruption
Xen . org security team
-
[oss-security] CVE-2026-42498: Apache Tomcat: WebSocket authentication header exposure
Mark Thomas
-
[oss-security] CVE-2026-41293: Apache Tomcat: HTTP/2 request headers not validated
Mark Thomas
-
[oss-security] CVE-2026-41284: Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Mark Thomas
-
[oss-security] CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied
Mark Thomas
-
[oss-security] CVE-2026-43514: Apache Tomcat: AJP secret compared in non-constant time
Mark Thomas
-
[oss-security] CVE-2026-43513: Apache Tomcat: LockOutRealm treats user names as case-sensitive
Mark Thomas
-
[oss-security] CVE-2026-43512: Apache Tomcat: Digest authenticator will authenticate any unknown user
Mark Thomas
-
[oss-security] CVE-2026-8368: LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects
Stig Palmquist
-
[oss-security] Dovecot Security Advisory OXDC-2026-0002
Aki Tuomi
-
[oss-security] [EXIM-Security-2026-05-01.1] Security Release 4.99.3
Heiko Schlittermann
-
[oss-security] Public security analysis and LLM-assisted variant discovery
Tim Shephard
-
[oss-security] CVE-2026-7010: HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values
Stig Palmquist
-
[oss-security] libexpat 2.8.1 fixes CVE-2026-45186 (denial of service)
Sebastian Pipping
-
[oss-security] CVE-2026-6146: Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys
Robert Rothenberg
-
[oss-security] CVE-2022-4988: Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries
Robert Rothenberg
-
[oss-security] OpenSSL ARM64 SM2 scalar multiplication timing side-channel (no CVE)
Abhinav Agarwal
-
[oss-security] dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
Alan Coopersmith
-
[oss-security] CVE Request: Fail-open authentication in hathor-wallet-headless <= 0.38.0 (vendor declined to fix)
Emiliano Solazzi G.
-
[oss-security][CVE-2026-7210] Cpython: The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
Alan Coopersmith
-
[oss-security] [OSSA-2026-012] Ironic: Remote Code Execution when Anaconda driver enabled (CVE-2026-44916)
Jay Faulkner
-
[oss-security] CVE-2026-5084: WebDyne::Session versions through 2.075 for Perl generates the session id insecurely
Stig Palmquist
-
[oss-security] malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API (CVE-2026-44931)
Matthias Gerstner
-
[oss-security] CVE-2026-45191: Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
Stig Palmquist
-
[oss-security] CVE-2026-8177: XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
Stig Palmquist
-
[oss-security] CVE-2026-45190: Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass
Stig Palmquist
-
[oss-security] CVE-2026-45180: Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids
Robert Rothenberg
-
[oss-security] CVE-2026-45179: Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses
Robert Rothenberg
-
[oss-security] CVE-2026-41018: Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
Shahar Epstein
-
[oss-security] CVE-2026-43826: Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL
Shahar Epstein
-
[oss-security] uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Sebastian Pipping
-
[oss-security] CVE-2026-25199: Apache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access
Piotr P. Karwasz
-
[oss-security] CVE-2026-25077: Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates
Piotr P. Karwasz
-
[oss-security] CVE-2025-69233: Apache CloudStack: Domain/account resources limits not honored
Piotr P. Karwasz
-
[oss-security] CVE-2025-66467: Apache CloudStack: MinIO policy remains intact on bucket deletion
Piotr P. Karwasz
-
[oss-security] CVE-2025-66172: Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
Piotr P. Karwasz
-
[oss-security] CVE-2025-66171: Apache CloudStack: Any user can create a new VM from backups they should not have access to
Piotr P. Karwasz
-
[oss-security] CVE-2025-66170: Apache CloudStack: Any user can list backups that they should not have access to
Piotr P. Karwasz
-
[oss-security] Go 1.26.3 and Go 1.25.10 are released with 11 security fixes
Alan Coopersmith
-
[oss-security] CVE-2026-6659: Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts
Robert Rothenberg
-
[oss-security] BioPython 1.87 fixes CVE-2025-68463 (XXE, SSRF)
Sebastian Pipping
-
[oss-security] CVE-2013-10075: Apache::Session versions through 1.94 for Perl re-creates deleted sessions
Robert Rothenberg
-
[oss-security] Re: Dirty Frag: Universal Linux LPE
Daniel Tang
-
[oss-security] Copy Fail 2 / Dirty Frag — n-day from public commit, not embargo break
SiCk
-
[oss-security] [vim-security] Heap Buffer Overflow in spell file loading affects Vim < 9.2.0450
Christian Brabandt
-
[oss-security] Dirty Frag: Universal Linux LPE
Hyunwoo Kim
-
[oss-security] [OSSA-2026-011] OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management (CVE-2026-40213, CVE-2026-40214)
Goutham Pacha Ravi
-
[oss-security] XSS in Postorius (Mailman 3) 1.3.13 and earlier
Alyssa Ross
-
[oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption
Solar Designer
-
[oss-security] Vulnerability fixes in Tor 0.4.9.7
Sam James
-
[oss-security] CVE-2026-40562: Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence
Robert Rothenberg
-
[oss-security] CVE-2026-5081: Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure
Robert Rothenberg
-
[oss-security] CVE-2026-43975: Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager
Pedro Henrique Oliveira dos Santos
-
[oss-security] CVE-2026-43646: Apache Wicket: crafted URLs can bypass PackageResourceGuard
Pedro Henrique Oliveira dos Santos
-
[oss-security] CVE-2026-42509: Apache Wicket: crafted strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
-
[oss-security] CVE-2026-40010: Apache Wicket: possible session fixation using AuthenticatedWebSession
Pedro Henrique Oliveira dos Santos
-
[oss-security] Security audit of Paramiko completed, fixes coming in 5.0 release
Alan Coopersmith
-
[oss-security] vm2: sandbox escape in NodeVM with nesting:true (CVE-2026-44007)
Akshat Sinha
-
[oss-security] [OSSA-2026-010] Ironic: Credential Forwarding to Arbitrary Endpoints via iDrac Configuration Molds Feature (CVE-2026-42997)
Jay Faulkner
-
[oss-security] CVE-2026-28780: Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
Eric Covener
-
[oss-security] Django CVE-2026-5766, CVE-2026-35192, and CVE-2026-6907
Sarah Boyce
-
[oss-security] [OSSA-2026-009] Horizon: Unauthenticated session flood via login redirect storage (CVE-2026-43002)
Goutham Pacha Ravi
-
[oss-security] CVE-2026-29168: Apache HTTP Server: mod_md unrestricted OCSP response
Eric Covener
-
[oss-security] CVE-2026-43870: Apache Thrift: Node.js web_server.js multi-vulnerability
Jens Geyer
-
[oss-security] CVE-2026-43869: Apache Thrift: TSSLTransportFactory.java hostname verification
Jens Geyer
-
[oss-security] CVE-2026-43868: Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
Jens Geyer
-
[oss-security] Nix/Lix: local privilege escalation in daemon process
Martin Weinelt
-
[oss-security] Local privilege escalation in Lix and Nix
Thomas GERBET
-
[oss-security] Fwd: [pfx] Postfix stable release 3.11.2 and legacy releases 3.10.9, 3.9.10, 3.8.16
Sam James
-
[oss-security] CVE-2026-33523: Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
Eric Covener
-
[oss-security] CVE-2026-33007: Apache HTTP Server: mod_authn_socache crash
Eric Covener
-
[oss-security] CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing attack
Eric Covener
-
[oss-security] CVE-2026-29169: Apache HTTP Server: mod_dav_lock indirect lock crash
Eric Covener
-
[oss-security] CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset
Eric Covener
-
[oss-security] CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
Eric Covener
-
[oss-security] CVE-2026-34059: Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
Eric Covener
-
[oss-security] CVE-2026-34032: Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
Eric Covener
-
[oss-security] CVE-2026-33857: Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
Eric Covener
-
[oss-security] Fwd: mutt 2.3.2 released
Sam James
-
[oss-security] [vim-security] OS Command Injection via 'path' completion affects Vim < 9.2.0435
Christian Brabandt
-
[oss-security] CVE-2026-40563: Apache Atlas: Script injection allows access to unintended data
Pinal Shah
-
[oss-security] CVE request: io_uring zcrx freelist OOB write
Mohamed salem Eddah
-
[oss-security] syzkaller "Reporting Linux kernel bugs" out of date
Solar Designer
-
[oss-security] CVE-2026-40561: Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence
Timothy Legge
-
[oss-security] Re: uutils coreutils CVEs
Collin Funk
-
[oss-security] CVE-2026-42812: Apache Polaris: No protection on `write.metadata.path`
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-42811: Apache Polaris: In plain terms, Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead.
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-42810: Apache Polaris: Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions.
Jean-Baptiste Onofré
-
[oss-security] CVE-2026-42809: Apache Polaris: An authenticated low-privileged user can abuse Polaris staged table creation to mint broad temporary storage credentials for an attacker-chosen location before Polaris validates that location
Jean-Baptiste Onofré
-
[oss-security] Ubuntu back up, In Saturday after DDoS attacks
cyber security
-
[oss-security] uutils coreutils CVEs
Collin Funk
-
[oss-security] Security audit of rust-coreutils
Alan Coopersmith
-
[oss-security] CVE-2026-42440: Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
Richard Zowalla
-
[oss-security] CVE-2026-42027: Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
Richard Zowalla
-
[oss-security] CVE-2026-40682: Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
Richard Zowalla
-
[oss-security] CVE-2026-42404: Apache Neethi: Unrestricted HTTP Redirect Following in Policy References
Colm O hEigeartaigh
-
[oss-security] CVE-2026-42403: Apache Neethi: Circular Policy Reference Infinite Loop
Colm O hEigeartaigh
-
[oss-security] CVE-2026-42402: Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
Colm O hEigeartaigh
-
[oss-security] Prosody XMPP server security advisory 2026-04-31 (multiple vulnerabilities)
Matthew Wild
-
[oss-security] CVE-2026-42167: SQL injection in ProFTPd prior to 1.3.9a
Valtteri Vuorikoski
-
[oss-security] Exim 4.99.2 fixes 4 CVEs
Solar Designer
-
[oss-security] CVE-2026-5080: Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely
Robert Rothenberg
-
[oss-security] [CVE-2026-37555] libsndfile IMA-ADPCM integer overflow (incomplete fix for CVE-2022-33065)
Feng Ning
-
[oss-security] inetutils-2.8 released with 2 CVE fixes
Alan Coopersmith
-
[oss-security] gnutls 3.8.13 released with 12 CVE fixes and more
Alan Coopersmith
-
[oss-security] CVE-2026-7381: Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting
Robert Rothenberg
-
[oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation
Jan Schaumann