
Full Disclosure Mailing List
A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.
List Archives
- Jan
- Feb
- Mar
- Apr
- May
- Jun
- Jul
- Aug
- Sep
- Oct
- Nov
- Dec
- 2026
- 31
- 32
- 26
- 5
- –
- –
- –
- –
- –
- –
- –
- –
- 2025
- 24
- 20
- 9
- 32
- 24
- 28
- 40
- 19
- 80
- 33
- 22
- 37
- 2024
- 75
- 25
- 44
- 29
- 37
- 13
- 24
- 41
- 60
- 21
- 20
- 22
- 2023
- 29
- 17
- 27
- 14
- 28
- 10
- 52
- 33
- 21
- 32
- 15
- 30
- 2022
- 91
- 57
- 63
- 54
- 48
- 57
- 27
- 17
- 30
- 52
- 26
- 32
- 2021
- 84
- 93
- 81
- 77
- 81
- 60
- 72
- 39
- 59
- 79
- 56
- 50
- 2020
- 52
- 36
- 57
- 63
- 60
- 35
- 37
- 24
- 55
- 34
- 45
- 60
- 2019
- 71
- 54
- 64
- 41
- 52
- 49
- 40
- 37
- 45
- 59
- 34
- 37
- 2018
- 102
- 84
- 79
- 61
- 73
- 46
- 95
- 53
- 57
- 54
- 69
- 56
- 2017
- 99
- 103
- 91
- 113
- 108
- 52
- 95
- 58
- 98
- 71
- 51
- 89
- 2016
- 100
- 128
- 97
- 93
- 75
- 79
- 89
- 139
- 85
- 103
- 162
- 88
- 2015
- 134
- 101
- 165
- 115
- 133
- 112
- 126
- 86
- 121
- 115
- 111
- 129
- 2014
- 194
- 273
- 434
- 325
- 213
- 173
- 167
- 89
- 115
- 135
- 103
- 138
- 2013
- 282
- 162
- 290
- 263
- 227
- 259
- 277
- 303
- 187
- 294
- 222
- 224
- 2012
- 611
- 477
- 390
- 382
- 323
- 428
- 394
- 393
- 210
- 277
- 236
- 280
- 2011
- 580
- 687
- 439
- 561
- 572
- 565
- 367
- 393
- 370
- 995
- 466
- 511
- 2010
- 637
- 502
- 564
- 452
- 408
- 631
- 417
- 445
- 414
- 523
- 342
- 696
- 2009
- 979
- 380
- 465
- 318
- 282
- 291
- 550
- 455
- 421
- 339
- 386
- 502
- 2008
- 615
- 496
- 600
- 821
- 681
- 403
- 591
- 557
- 639
- 531
- 739
- 634
- 2007
- 593
- 629
- 573
- 744
- 555
- 661
- 662
- 530
- 709
- 935
- 582
- 641
- 2006
- 992
- 740
- 1865
- 865
- 789
- 1058
- 770
- 771
- 578
- 678
- 545
- 493
- 2005
- 927
- 676
- 950
- 654
- 678
- 437
- 766
- 1078
- 890
- 677
- 1065
- 1531
- 2004
- 1358
- 1534
- 1499
- 1153
- 1451
- 1031
- 1370
- 1314
- 1091
- 1174
- 1424
- 731
- 2003
- 505
- 405
- 296
- 500
- 421
- 890
- 1251
- 1942
- 1763
- 1806
- 1123
- 782
- 2002
- –
- –
- –
- –
- –
- –
- 314
- 835
- 684
- 381
- 454
- 313
Latest Posts
SEC Consult SA-20260401-0 :: Broken Access Control in Open WebUI
SEC Consult Vulnerability Lab via Fulldisclosure (Apr 02)
SEC Consult Vulnerability Lab Security Advisory < 20260401-0 >
=======================================================================
title: Broken Access Control
product: Open WebUI
vulnerable version: <v0.8.11
fixed version: v0.8.11
CVE number: CVE-2026-34222
impact: high
homepage:https://openwebui.com
found: 2026-02-06...
SEC Consult SA-20260326-0 :: Local Privilege Escalation in Vienna Assistant (MacOS) - Vienna Symphonic Library
SEC Consult Vulnerability Lab via Fulldisclosure (Apr 02)
SEC Consult Vulnerability Lab Security Advisory < 20260326-0 >
=======================================================================
title: Local Privilege Escalation
product: Vienna Assistant (MacOS) - Vienna Symphonic Library
vulnerable version: 1.2.542
fixed version: -
CVE number: CVE-2026-24068
impact: high
homepage:https://www.vsl.co.at/
...
Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries, Zero User Visibility
Joseph Goydish II via Fulldisclosure (Apr 02)
SUMMARY
Apple's Oblivious HTTP relay for Live Caller ID Lookup (iOS 18+) routes
traffic through 14 third-party endpoints across six countries. These include
an anonymous Delaware LLC sharing data with OpenAI, a Russian endpoint
(Yandex), and a Swiss GmbH whose privacy policy names "The Legal Entity to
be Confirmed" as its data controller. None of this is disclosed to users.
This is shared infrastructure. All devices using Live...
[KIS-2026-06] MetInfo CMS <= 8.1 (weixinreply.class.php) PHP Code Injection Vulnerability
Egidio Romano (Apr 02)
---------------------------------------------------------------------------
MetInfo CMS <= 8.1 (weixinreply.class.php) PHP Code Injection Vulnerability
---------------------------------------------------------------------------
[-] Software Link:
https://www.metinfo.cn
[-] Affected Versions:
Versions 7.9, 8.0, and 8.1.
[-] Vulnerability Description:
The vulnerable code is located into the...
[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability
cyber security (Apr 02)
A vulnerability was identified in OWASP CRS where whitespace padding
in filenames can bypass file upload extension checks, allowing uploads
of dangerous files such as .php, .phar, .jsp, and .jspx. This issue
has been assigned CVE‑2026‑33691.
Impact: Attackers may evade CRS protections and upload web shells
disguised with whitespace‑padded extensions. Exploitation is most
practical on Windows backends that normalize whitespace in filenames...
APPLE-SA-03-24-2026-10 Xcode 26.4
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-10 Xcode 26.4
Xcode 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126801.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
otool
Available for: macOS Tahoe 26.2 and later
Impact: An app may be able to cause unexpected system termination
Description: An...
APPLE-SA-03-24-2026-9 Safari 26.4
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-9 Safari 26.4
Safari 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126800.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Processing maliciously crafted web content may prevent Content
Security...
APPLE-SA-03-24-2026-8 visionOS 26.4
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-8 visionOS 26.4
visionOS 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126799.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: Apple Vision Pro (all models)
Impact: An attacker in a privileged network position may be able to
intercept...
APPLE-SA-03-24-2026-7 watchOS 26.4
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-7 watchOS 26.4
watchOS 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126798.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: Apple Watch Series 6 and later
Impact: An attacker in a privileged network position may be able to
intercept...
APPLE-SA-03-24-2026-6 tvOS 26.4
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-6 tvOS 26.4
tvOS 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126797.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: Apple TV HD and Apple TV 4K (all models)
Impact: An attacker in a privileged network position may be able to
intercept...
APPLE-SA-03-24-2026-5 macOS Sonoma 14.8.5
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-5 macOS Sonoma 14.8.5
macOS Sonoma 14.8.5 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126796.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: macOS Sonoma
Impact: An attacker in a privileged network position may be able to
intercept network...
APPLE-SA-03-24-2026-4 macOS Sequoia 15.7.5
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-4 macOS Sequoia 15.7.5
macOS Sequoia 15.7.5 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126795.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: macOS Sequoia
Impact: An attacker in a privileged network position may be able to
intercept...
APPLE-SA-03-24-2026-3 macOS Tahoe 26.4
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-3 macOS Tahoe 26.4
macOS Tahoe 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126794.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: macOS Tahoe
Impact: An attacker in a privileged network position may be able to
intercept network...
APPLE-SA-03-24-2026-2 iOS 18.7.7 and iPadOS 18.7.7
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-2 iOS 18.7.7 and iPadOS 18.7.7
iOS 18.7.7 and iPadOS 18.7.7 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126793.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker in...
APPLE-SA-03-24-2026-1 iOS 26.4 and iPadOS 26.4
Apple Product Security via Fulldisclosure (Mar 28)
APPLE-SA-03-24-2026-1 iOS 26.4 and iPadOS 26.4
iOS 26.4 and iPadOS 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126792.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
802.1X
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation
and later, iPad Pro 11-inch 1st...
More Lists
Dozens of other network security lists are archived at SecLists.Org.
