Open Source Security Mailing List

Discussion of security flaws, concepts, and practices in the Open Source community

List Archives

Latest Posts

CVE-2026-63044: Apache InLong: Authenticated SSRF via POST /api/node/testConnection Charles Zhang (Aug 20)
Severity: important

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can
cause the InLong Manager server to make outbound HTTP requests or TCP connections to
arbitrary internal hosts and ports.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache...

CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path Charles Zhang (Aug 20)
Severity: important

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]  https://github.com/apache/inlong/pull/12146 .

Credit:

dyingman1 (finder)

References:...

CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to
the manager can create, modify and delete Data Node definitions.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1] ...

CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDelete Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no
authorization check, any authenticated user can logically delete ALL stream sources.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1] ...

CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong.
This allows an attacker to inject the string value into
the SQL statement, enabling SQL injection.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or...

CVE-2026-63038: Apache InLong: SQL Injection via String Concatenation Vulnerability Report Charles Zhang (Aug 20)
Severity: important

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong.
This allows an attacker to inject arbitrary SQL code through the
dbName, tableName, schemaName, and username parameters. 

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache...

CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. 
This appears to allow SQL injection in the ORDER BY clause against the
Manager backend database.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or...

CVE-2026-63016: Apache InLong: Ordinary users can create new packages Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow
upload of non-official packages.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]

https://github.com/apache/inlong/pull/12095...

CVE-2026-63015: Apache InLong: Non-template responsible persons can view template information Charles Zhang (Aug 20)
Severity: moderate

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template
information.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]

https://github.com/apache/inlong/pull/12093...

rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv) Rainer Gerhards (Aug 20)
Hello,

rsyslog has published GHSA-xmp9-244p-5ggv covering hardening of
dynamic filename handling in the omfile output module:

https://github.com/rsyslog/rsyslog/security/advisories/GHSA-xmp9-244p-5ggv

The affected area is omfile configurations that use dynaFile. Dynamic
filenames are intentionally flexible: some established deployments
need that flexibility, including paths that cannot be restricted to
one static base directory. Consequently,...

Re: GNU Emacs vulnerability upon opening arbitrary file Demi Marie Obenour (Aug 20)
Disabling file-local variables seems to be an alternative mitigation,
and the one I recommend. I would not be surprised if LLMs start
popping out lots of 0day exploits in Emacs.

Re: libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requested Sam James (Aug 19)
Sumit Chakraborty <sumit.ch2004 () gmail com> writes:

Thanks for sharing and bringing it to the list.

I'm not sure if I follow the purpose of the email. If you'd like to
handle disclosure to distros, you can use the linux-distros@ or distros@
mailing list as appropriate, provided you're able & willing to follow
the rules at...

Fwd: [pfx] Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27 Sam James (Aug 19)
The first round Wietse fixed was a few months ago in
https://www.openwall.com/lists/oss-security/2026/05/04/25.

See his summary below for details, but they're all at most DoS.

-------------------- Start of forwarded message --------------------
To: Postfix announce <postfix-announce () postfix org>
Date: Mon, 10 Aug 2026 11:50:35 -0400 (EDT)
CC: Postfix users <postfix-users () postfix org>
Subject: [pfx] Postfix stable release...

Multiple vulnerabilities fixed in libgit2-1.9.5, 1.9.7 Sam James (Aug 19)
Hi,

libgit2-1.9.5 fixes several vulnerabilities [0]:
"""
Fix for blame error handling on hunk creation failures

Fix for potential PCRE memory access: 1-byte heap-buffer-overflow WRITE in bundled PCRE 8.45 reachable via revspec

🔒 This is a security release with multiple changes.

This vulnerability was identified by @DavidKorczynski.

hunk_from_entry can return NULL on error; handle that and
return an...

GNU Emacs vulnerability upon opening arbitrary file Sam James (Aug 19)
Eshel Yaron has shared an arbitrary code execution bug in GNU Emacs
exploitable upon opening an file. It affects >= Emacs 28.1.

The reporter has a writeup at
https://eshelyaron.com/posts/2026-08-06-emacs-arbitrary-code-execution-returns.html.
It's from the same reporter as CVE-2024-53920 [0].

Thread on emacs-devel:
* https://lists.gnu.org/archive/html/emacs-devel/2026-07/msg00453.html
*...

More Lists

Dozens of other network security lists are archived at SecLists.Org.