Open Source Security Mailing List

Discussion of security flaws, concepts, and practices in the Open Source community

List Archives

Latest Posts

CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. 
This appears to allow SQL injection in the ORDER BY clause against the
Manager backend database.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or...

CVE-2026-63016: Apache InLong: Ordinary users can create new packages Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow
upload of non-official packages.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]

https://github.com/apache/inlong/pull/12095...

CVE-2026-63015: Apache InLong: Non-template responsible persons can view template information Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template
information.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]

https://github.com/apache/inlong/pull/12093...

rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv) Rainer Gerhards (Aug 20)
Hello,

rsyslog has published GHSA-xmp9-244p-5ggv covering hardening of
dynamic filename handling in the omfile output module:

https://github.com/rsyslog/rsyslog/security/advisories/GHSA-xmp9-244p-5ggv

The affected area is omfile configurations that use dynaFile. Dynamic
filenames are intentionally flexible: some established deployments
need that flexibility, including paths that cannot be restricted to
one static base directory. Consequently,...

Re: GNU Emacs vulnerability upon opening arbitrary file Demi Marie Obenour (Aug 20)
Disabling file-local variables seems to be an alternative mitigation,
and the one I recommend. I would not be surprised if LLMs start
popping out lots of 0day exploits in Emacs.

Re: libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requested Sam James (Aug 19)
Sumit Chakraborty <sumit.ch2004 () gmail com> writes:

Thanks for sharing and bringing it to the list.

I'm not sure if I follow the purpose of the email. If you'd like to
handle disclosure to distros, you can use the linux-distros@ or distros@
mailing list as appropriate, provided you're able & willing to follow
the rules at...

Fwd: [pfx] Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27 Sam James (Aug 19)
The first round Wietse fixed was a few months ago in
https://www.openwall.com/lists/oss-security/2026/05/04/25.

See his summary below for details, but they're all at most DoS.

-------------------- Start of forwarded message --------------------
To: Postfix announce <postfix-announce () postfix org>
Date: Mon, 10 Aug 2026 11:50:35 -0400 (EDT)
CC: Postfix users <postfix-users () postfix org>
Subject: [pfx] Postfix stable release...

Multiple vulnerabilities fixed in libgit2-1.9.5, 1.9.7 Sam James (Aug 19)
Hi,

libgit2-1.9.5 fixes several vulnerabilities [0]:
"""
Fix for blame error handling on hunk creation failures

Fix for potential PCRE memory access: 1-byte heap-buffer-overflow WRITE in bundled PCRE 8.45 reachable via revspec

🔒 This is a security release with multiple changes.

This vulnerability was identified by @DavidKorczynski.

hunk_from_entry can return NULL on error; handle that and
return an...

GNU Emacs vulnerability upon opening arbitrary file Sam James (Aug 19)
Eshel Yaron has shared an arbitrary code execution bug in GNU Emacs
exploitable upon opening an file. It affects >= Emacs 28.1.

The reporter has a writeup at
https://eshelyaron.com/posts/2026-08-06-emacs-arbitrary-code-execution-returns.html.
It's from the same reporter as CVE-2024-53920 [0].

Thread on emacs-devel:
* https://lists.gnu.org/archive/html/emacs-devel/2026-07/msg00453.html
*...

uutils coreutils 'stdbuf' uses LD_PRELOAD on a world-writable temporary file Collin Funk (Aug 19)
GNU coreutils distributes a 'stdbuf' program that executes another
program with modified buffering characteristics for its standard
streams. It does this by setting environment variables and then setting
LD_PRELOAD (or the platform-specific equivalent) to a shared library
named "libstdbuf.so". This shared library uses .init and .init_array (or
the platform-specific equivalent) sections that alter the standard
stream...

CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter Timothy Legge (Aug 19)
========================================================================
CVE-2026-75628 CPAN Security Group
========================================================================

CVE ID: CVE-2026-75628
Distribution: Punk-OAuth2
Versions: before 0.03

MetaCPAN: https://metacpan.org/dist/Punk-OAuth2

Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen
off-site...

WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005 Adrian Perez de Castro (Aug 19)
------------------------------------------------------------------------
WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005
------------------------------------------------------------------------

Date reported : August 20, 2026
Advisory ID : WSA-2026-0005
WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0005.html
WPE WebKit Advisory URL :...

[OSSA-2026-008] ERRATA 2: Ironic Command Injection in IPMI Console Implementations Jay Faulkner (Aug 19)
=======================================================================
OSSA-2026-008: Command Injection in Ironic IPMI Console Implementations
=======================================================================

:Date: April 27, 2026
:CVE: CVE-2026-42510

Affects
~~~~~~~
- Ironic: >=4.3.0 <26.1.6, >=27.0.0 <29.0.5, >=30.0.0 <32.0.1, >=33.0.0
<35.0.1

Description
~~~~~~~~~~~
Dmitry Tantsur and Tuomo Tanskanen from the...

[OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-pending) Goutham Pacha Ravi (Aug 19)
============================================================================================
OSSA-2026-036: Aodh cross-project alarm enumeration and Watcher webhook
authorization bypass
============================================================================================

:Date: August 19, 2026
:CVE: CVE-2026-pending

Affects
~~~~~~~
- Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0
- Watcher: >=4.0.0 <14.1.2, >=15.0.0...

Ceph 20.2.4 and Ceph 19.2.6 are released with 4 security fixes. Sage McTaggart (Aug 19)
Today, August 19th 2026, the Ceph project has released Tentacle
20.2.4<https://github.com/ceph/ceph/releases/tag/v20.2.4> and Squid
19.2.6<https://github.com/ceph/ceph/releases/tag/v19.2.6>.

These releases include 4 security fixes.

*CVE-2025-30156 AES-CBC misuse in CephX facilitating authentication bypass

CVE-2025-30156[1][2] stems from a broken cryptographic implementation in CephX, similar to the vulnerability class
described...

More Lists

Dozens of other network security lists are archived at SecLists.Org.