oss-sec: by author

253 messages starting Jul 01 26 and ending Jul 12 26
Date index | Thread index | Author index


Abhinav Agarwal

OFFIS DCMTK: 5 CISA-coordinated DICOM vulnerabilities Abhinav Agarwal (Jul 01)
Re: hostapd: OOB write in Wi-Fi 7 MLD association parsing (pre-auth DoS) Abhinav Agarwal (Jul 01)
libIEC61850: four MMS/GOOSE memory-safety vulnerabilities, including lab RCE Abhinav Agarwal (Jul 24)

Alan Coopersmith

CERT VU#885548 - Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions Alan Coopersmith (Jul 16)
[oss-security][CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations Alan Coopersmith (Jul 09)
Go 1.26.5 and Go 1.25.12 fix CVE-2026-39822 & CVE-2026-42505 Alan Coopersmith (Jul 08)
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability Alan Coopersmith (Jul 17)
libssh 0.12.1 and 0.11.5 security releases Alan Coopersmith (Jul 21)
Fwd: libevent 2.1.13-stable contains several security fixes Alan Coopersmith (Jul 01)
Re: Fwd: Node.js security updates for all active release lines, June 2026 Alan Coopersmith (Jul 02)
Cyrus IMAP 3.12.3 fixed 9 CVEs Alan Coopersmith (Jul 17)
Vinyl Cache / Varnish Cache HTTP/2 parsing deficiency [CVE-2026-50052] Alan Coopersmith (Jul 01)
Re: dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation Alan Coopersmith (Jul 20)
Re: 432 Linux kernel CVEs Alan Coopersmith (Jul 24)
CVE-2026-16277 & CVE-2026-16461: buffer overflows in rpcinfo Alan Coopersmith (Jul 23)

Andrea Cosentino

CVE-2026-46584: Apache Camel: Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties, allowing an attacker to weaken the SMTP transport security and, on releases before 4.19.0, redirect the connection and steal Andrea Cosentino (Jul 05)
CVE-2026-42527: Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure Andrea Cosentino (Jul 05)
CVE-2026-46590: Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048) Andrea Cosentino (Jul 05)
CVE-2026-48206: Apache Camel: Camel-JIRA: A set of non-Camel-prefixed Exchange header constants (IssueKey, ProjectKey, IssueTransitionId, ...) bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials Andrea Cosentino (Jul 05)
CVE-2026-40047: Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer Andrea Cosentino (Jul 05)
CVE-2026-55994: Apache Camel: Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of secrets when bridged Andrea Cosentino (Jul 05)
CVE-2026-46592: Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation Andrea Cosentino (Jul 05)
CVE-2026-49097: Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users Andrea Cosentino (Jul 05)
CVE-2026-46454: Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers Andrea Cosentino (Jul 05)
CVE-2026-43865: Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution Andrea Cosentino (Jul 05)
CVE-2026-43866: Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder Andrea Cosentino (Jul 06)
CVE-2026-46457: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers Andrea Cosentino (Jul 05)
CVE-2026-46585: Apache Camel: Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query Andrea Cosentino (Jul 05)
CVE-2026-56140: Apache Camel: Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components; because camel-aws2-sns is producer-only (no consumer) there is no reachable inbound header-injection path, so this is a defense-in- Andrea Cosentino (Jul 05)
CVE-2026-46726: Apache Camel: Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of Andrea Cosentino (Jul 05)
CVE-2026-48205: Apache Camel: Camel-DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect DNS queries to an attacker-controlled server (server-side request forgery) and enumerate internal Andrea Cosentino (Jul 05)
CVE-2026-43867: Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter Andrea Cosentino (Jul 06)
CVE-2026-48203: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields Andrea Cosentino (Jul 05)
CVE-2026-49365: Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients Andrea Cosentino (Jul 05)
CVE-2026-40859: Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled Andrea Cosentino (Jul 05)
CVE-2026-56139: Apache Camel: Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients - and the option was not honoured Andrea Cosentino (Jul 05)
CVE-2026-55993: Apache Camel: Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of secr Andrea Cosentino (Jul 05)
CVE-2026-53913: Apache Camel: Camel-Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration (no required roles or permissions) the token is never verified and any non-null bearer value is accepted - a Andrea Cosentino (Jul 05)
CVE-2026-46455: Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted Andrea Cosentino (Jul 05)
CVE-2026-46591: Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169) Andrea Cosentino (Jul 05)
CVE-2026-46453: Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation Andrea Cosentino (Jul 05)
CVE-2026-49098: Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic Andrea Cosentino (Jul 05)
CVE-2026-49099: Apache Camel: Camel-Salesforce: Non-Camel-prefixed Exchange header constants (sObjectQuery, sObjectSearch, apexUrl, ...) bypass the HTTP header filter, allowing an HTTP client to inject SOQL/SOSL queries, override the target SObject, and redirect Apex REST calls using t Andrea Cosentino (Jul 05)
CVE-2026-46456: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers Andrea Cosentino (Jul 05)
CVE-2026-48204: Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration Andrea Cosentino (Jul 05)
CVE-2026-49086: Apache Camel: Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to redirect the re-published message to an arbitrary Dapr Pub/Su Andrea Cosentino (Jul 05)

Bernd Zeimetz

new af_alg exploit in the wild? Bernd Zeimetz (Jul 13)

Brad House

c-ares 1.34.7 release: CVE-2026-33630, GHSA-pjmc-gx33-gc76, GHSA-jv8r-gqr9-68wj Brad House (Jul 06)

Chaokun Yang

CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths Chaokun Yang (Jul 21)
CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free Chaokun Yang (Jul 21)
CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface Chaokun Yang (Jul 21)
CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization Chaokun Yang (Jul 21)

Christian Brabandt

[vim-security] Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841 Christian Brabandt (Jul 24)
[vim-security] Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840 Christian Brabandt (Jul 24)
[vim-security] Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842 Christian Brabandt (Jul 24)
[vim-security] Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839 Christian Brabandt (Jul 24)
[vim-security] Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843 Christian Brabandt (Jul 24)

Christopher Tubbs

CVE-2026-62764: Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions Christopher Tubbs (Jul 16)

Colm O hEigeartaigh

CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing Colm O hEigeartaigh (Jul 24)
CVE-2026-66144: Apache Neethi: Remote PolicyReference fetch lacks resource bounds Colm O hEigeartaigh (Jul 24)
CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths Colm O hEigeartaigh (Jul 24)

Damien Miller

Announce: OpenSSH 10.4 released Damien Miller (Jul 06)

David A. Wheeler

Re: 432 Linux kernel CVEs David A. Wheeler (Jul 22)

Douglas Bagnall

Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28 Douglas Bagnall (Jul 24)

Dr. Thomas Orgis

Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Dr. Thomas Orgis (Jul 08)

Duo Zhang

CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service Duo Zhang (Jul 24)

Eduardo Barretto

LPE in snapd and other vulnerabilities Eduardo Barretto (Jul 21)

Eli Schwartz

Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Eli Schwartz (Jul 05)

Federico Mariani

CVE-2026-49042: Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters Federico Mariani (Jul 06)
CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Federico Mariani (Jul 06)
CVE-2026-46588: Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Federico Mariani (Jul 06)

Feroz Salam

Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Feroz Salam (Jul 07)

Francesco Chicchiriccò

CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector Francesco Chicchiriccò (Jul 20)
CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask Francesco Chicchiriccò (Jul 20)
CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search Francesco Chicchiriccò (Jul 20)
CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check Francesco Chicchiriccò (Jul 20)
CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass Francesco Chicchiriccò (Jul 20)
CVE-2026-62183: Apache Syncope: User self-service privilege escalation Francesco Chicchiriccò (Jul 20)

Gabriel Corona

User prompt injection (CSRF) of the llama-server's Web UI (llama.cpp) Gabriel Corona (Jul 18)

Goutham Pacha Ravi

[OSSA-2026-028] OpenStack Ironic Python Agent: Credential extraction via malicious container (CVE-2026-54422) Goutham Pacha Ravi (Jul 23)
[OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending) Goutham Pacha Ravi (Jul 23)
[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending) Goutham Pacha Ravi (Jul 23)

gregdurys . security

Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS gregdurys . security (Jul 12)

Greg KH

Re: 432 Linux kernel CVEs Greg KH (Jul 22)

h

Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass h (Jul 03)

Hanno Böck

Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...) Hanno Böck (Jul 23)

Haonan Hou

CVE-2026-40454: Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data Haonan Hou (Jul 10)
CVE-2026-40452: Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users Haonan Hou (Jul 10)
CVE-2026-24012: Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query Haonan Hou (Jul 06)
CVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC Haonan Hou (Jul 06)
CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC Haonan Hou (Jul 10)
CVE-2026-28564: Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials Haonan Hou (Jul 10)
CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor Haonan Hou (Jul 10)
CVE-2026-24014: Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write Haonan Hou (Jul 06)
CVE-2026-40006: Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver Haonan Hou (Jul 10)
CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver Haonan Hou (Jul 10)
CVE-2026-40007: Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError Haonan Hou (Jul 10)

Holger Weiß

check_icmp (Monitoring Plugins): host-count overflow leads to heap buffer overflow in setuid-root binary Holger Weiß (Jul 01)

Hyunwoo Kim

Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359) Hyunwoo Kim (Jul 06)

Jacob Walls

Django CVE-2026-48588, CVE-2026-53877, and CVE-2026-53878 Jacob Walls (Jul 07)

Jan Engelhardt

Re: CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android Jan Engelhardt (Jul 08)

Jan Schaumann

432 Linux kernel CVEs Jan Schaumann (Jul 21)
OpenSSL "HollowByte" DoS via attacker-controlled memory allocation size in glibc Jan Schaumann (Jul 18)
CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android Jan Schaumann (Jul 08)
Re: 432 Linux kernel CVEs Jan Schaumann (Jul 21)

Jay Faulkner

[OSSA-2026-026] Ironic: Insufficient Access Controls regarding parent/child nodes Jay Faulkner (Jul 08)
[OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423) Jay Faulkner (Jul 08)

Jeremy Harris

security release for Exim Jeremy Harris (Jul 22)

Jerry Shao

CVE-2026-41042: Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter Jerry Shao (Jul 08)
CVE-2026-41041: Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints. Jerry Shao (Jul 12)

Joe Stringer

Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Joe Stringer (Jul 07)

John Haxby

Re: 432 Linux kernel CVEs John Haxby (Jul 24)
Re: 432 Linux kernel CVEs John Haxby (Jul 22)

Julian Andres Klode

pandemic of incomplete error handling in the OpenSSL ecosystem Julian Andres Klode (Jul 03)

Junkai Xue

CVE-2026-57111: Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin Junkai Xue (Jul 08)

Li Yang

CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API Li Yang (Jul 13)
CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval Li Yang (Jul 13)
CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API Li Yang (Jul 13)

Marco Benatto

Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Marco Benatto (Jul 22)

Marcus Meissner

Re: 432 Linux kernel CVEs Marcus Meissner (Jul 22)

Mark Thomas

CVE-2026-59084: Apache Tomcat: EncryptInterceptor requirements not clearly documented Mark Thomas (Jul 14)
CVE-2026-59083: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass Mark Thomas (Jul 14)

Masakazu Kitajo

CVE-2026-59173: Apache Traffic Server is vulnerable to stalled HTTP/2 flow-control Masakazu Kitajo (Jul 16)

Matthias Gerstner

Re: SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10 Matthias Gerstner (Jul 17)
PortProtonQt: Custom Polkit Rule Allows Escalation of NetworkManager and UDisks2 Privileges (CVE-2026-59678) Matthias Gerstner (Jul 22)
SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10 Matthias Gerstner (Jul 15)

Maxim Solodovnik

CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read Maxim Solodovnik (Jul 14)

Michael Orlitzky

Re: check_icmp (Monitoring Plugins): host-count overflow leads to heap buffer overflow in setuid-root binary Michael Orlitzky (Jul 01)

Michał Kępień

ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321) Michał Kępień (Jul 22)

Mingyu Chen

CVE-2026-58319: Apache Doris: Improper Authentication in Frontend HTTP API Mingyu Chen (Jul 13)

Oleg Kalnichevski

CVE-2026-54428: Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK Oleg Kalnichevski (Jul 01)
CVE-2026-54399: Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration Oleg Kalnichevski (Jul 01)

Ondrej Gajdusek

Foreman: multiple vulnerabilities fixed in 3.18.2 and 3.19.1 (CVE-2026-5135, CVE-2026-5136, CVE-2026-5138, CVE-2026-5142) Ondrej Gajdusek (Jul 07)

Or Peles

CVE-2026-43503: Analysis of the "DirtyClone" Linux LPE (Dirty Frag family variant) Or Peles (Jul 02)

Otto Moerbeek

PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues Otto Moerbeek (Jul 22)
Re: PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues Otto Moerbeek (Jul 23)

Paul Irwin

CVE-2026-47896: Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server Paul Irwin (Jul 02)
CVE-2026-47898: Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser Paul Irwin (Jul 02)
CVE-2026-47897: Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client Paul Irwin (Jul 02)

Paul Johnson

CVE-2026-57075: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec Paul Johnson (Jul 16)
CVE-2026-13713: YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack Paul Johnson (Jul 16)
CVE-2026-57077: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len Paul Johnson (Jul 16)
CVE-2026-57076: YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor Paul Johnson (Jul 16)

Peter Gutmann

Re: 432 Linux kernel CVEs Peter Gutmann (Jul 21)
Re: 432 Linux kernel CVEs Peter Gutmann (Jul 23)

Peter Hutterer

FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland Peter Hutterer (Jul 07)
FW: X.Org Security Advisory: multiple security issues in libXfont2 Peter Hutterer (Jul 07)

Piotr Karwasz

CVE-2026-49844: Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson() Piotr Karwasz (Jul 10)

pro Err0r

CVE-2026-54161: NUT upsmon: remote OS command injection via ups.alarm in NOTIFYCMD - fixed in PR #3499 (affects 2.8.3–2.8.5) pro Err0r (Jul 01)

Przemyslaw Frasunek

Re: Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE) Przemyslaw Frasunek (Jul 24)
Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE) Przemyslaw Frasunek (Jul 23)

Qualys Security Advisory

RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Qualys Security Advisory (Jul 22)
Re: LPE in snapd and other vulnerabilities Qualys Security Advisory (Jul 21)
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Qualys Security Advisory (Jul 22)

Rahul Vats

CVE-2026-49487: Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs Rahul Vats (Jul 07)
CVE-2026-33264: Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() Rahul Vats (Jul 07)
CVE-2026-48892: Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options Rahul Vats (Jul 07)
CVE-2026-49296: Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} Rahul Vats (Jul 07)
CVE-2026-48828: Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key Rahul Vats (Jul 07)
CVE-2026-48891: Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target Rahul Vats (Jul 07)

Rainer Gerhards

rsyslog v8.36.0 through v8.2606.0: imptcp regex-framing remote denial of service Rainer Gerhards (Jul 22)
CVE-2026-61548: rsyslog mmpstrucdata stack overflow Rainer Gerhards (Jul 20)

Richard Zowalla

CVE-2026-63317: Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML Richard Zowalla (Jul 24)
CVE-2026-43825: Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel Richard Zowalla (Jul 06)

Robert Davies

HTSlib <= 1.23.1 Multiple vulnerabilities in file reading code Robert Davies (Jul 09)

Robert Rothenberg

CVE-2025-15646: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion Robert Rothenberg (Jul 01)
CVE-2026-14895: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service Robert Rothenberg (Jul 07)
CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts Robert Rothenberg (Jul 20)
CVE-2026-56015: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length Robert Rothenberg (Jul 03)
CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg (Jul 16)
CVE-2026-6656: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks Robert Rothenberg (Jul 20)
CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead Robert Rothenberg (Jul 16)
CVE-2026-13089: OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify Robert Rothenberg (Jul 22)
CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead Robert Rothenberg (Jul 16)
CVE-2026-13410: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled Robert Rothenberg (Jul 17)
CVE-2026-9537: Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison Robert Rothenberg (Jul 17)
CVE-2026-14454: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed Robert Rothenberg (Jul 08)
CVE-2026-12740: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg (Jul 04)
CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Robert Rothenberg (Jul 07)
Security Considerations for Statsd Clients Robert Rothenberg (Jul 06)
CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg (Jul 04)
CVE-2026-56016: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources Robert Rothenberg (Jul 01)
CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains Robert Rothenberg (Jul 20)
CVE-2026-14741: HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date Robert Rothenberg (Jul 17)
CVE-2026-16634: TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99 Robert Rothenberg (Jul 24)
CVE-2026-7017: HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets Robert Rothenberg (Jul 07)
CVE-2026-13577: Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable Robert Rothenberg (Jul 20)
CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text Robert Rothenberg (Jul 14)
CVE-2026-64193: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR Robert Rothenberg (Jul 20)
CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row Robert Rothenberg (Jul 14)
Multiple vulnerabilities fixed in various Data::*::Shared modules for Perl Robert Rothenberg (Jul 21)
CVE-2026-13082: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets Robert Rothenberg (Jul 17)
CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Robert Rothenberg (Jul 07)
CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg (Jul 16)
CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index Robert Rothenberg (Jul 14)
CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp Robert Rothenberg (Jul 24)
CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location Robert Rothenberg (Jul 14)

Rostislav

Multiple vulnerabilities in ntfs-3g Rostislav (Jul 15)

Shahar Epstein

CVE-2026-49297: Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator) Shahar Epstein (Jul 04)

Simon McVittie

Re: new af_alg exploit in the wild? Simon McVittie (Jul 14)

Solar Designer

Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Solar Designer (Jul 07)
Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Solar Designer (Jul 08)
Re: CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel Solar Designer (Jul 22)
Re: Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS Solar Designer (Jul 12)
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer (Jul 03)
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer (Jul 03)
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Solar Designer (Jul 07)
Re: new af_alg exploit in the wild? Solar Designer (Jul 13)
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer (Jul 07)

Stefan Bodewig

CVE-2026-26032: Apache Ivy: PackagerResolver path traversal vulnerability Stefan Bodewig (Jul 15)

Steffen Nurpmeso

Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 22)
Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 21)

Stephan Verbücheln

Re: 432 Linux kernel CVEs Stephan Verbücheln (Jul 22)

Stig Palmquist

CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk Stig Palmquist (Jul 13)
CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record Stig Palmquist (Jul 13)
CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle Stig Palmquist (Jul 14)
CVE-2026-13708: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol Stig Palmquist (Jul 06)
CVE-2026-49146: App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc Stig Palmquist (Jul 08)
CVE-2026-49145: App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc Stig Palmquist (Jul 08)
CVE-2026-49147: App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes Stig Palmquist (Jul 08)
CVE-2026-13705: Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle Stig Palmquist (Jul 06)
CVE-2026-14803: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder Stig Palmquist (Jul 05)
CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack Stig Palmquist (Jul 13)

Sultan Alsawaf

Re: 432 Linux kernel CVEs Sultan Alsawaf (Jul 24)

Szymon Janc

CVE-2026-45811: Apache NimBLE: Buffer overflow in socket HCI transport Szymon Janc (Jul 24)
CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request Szymon Janc (Jul 24)
CVE-2026-46452: Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure Szymon Janc (Jul 24)
CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation Szymon Janc (Jul 24)
CVE-2026-45812: Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler Szymon Janc (Jul 24)
CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler Szymon Janc (Jul 24)

Terence Monteiro

CVE-2026-57821: Apache Fineract: Office list: SQL Injection via Subquery in orderBy Terence Monteiro (Jul 14)
CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint Terence Monteiro (Jul 14)
CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure Terence Monteiro (Jul 14)

Thomas Wolf

CVE-2026-56624: Apache MINA SSHD: SSH certificate options lack validations Thomas Wolf (Jul 20)
CVE-2026-56452: Apache MINA SSHD: Path traversal in SCP file reception Thomas Wolf (Jul 20)
CVE-2026-56623: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows Thomas Wolf (Jul 20)
CVE-2026-58624: Apache MINA SSHD: Remote execution of JGit commands can write files on the server Thomas Wolf (Jul 20)

Timothy Legge

2 CVEs Crypt::OpenSSL::X509 versions before 2.1.3 Timothy Legge (Jul 13)
CVE-2026-14570: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery Timothy Legge (Jul 04)

Valtteri Vuorikoski

CVE-2026-54432+more: Roundcube XSS/SSRF/etc prior to 1.6.17/1.7.2 Valtteri Vuorikoski (Jul 22)

Vega Agent

Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Vega Agent (Jul 09)

Vincent Beck

CVE-2026-58065: Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification Vincent Beck (Jul 13)
CVE-2026-59245: Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision) Vincent Beck (Jul 13)

Vincent Lefevre

Re: new af_alg exploit in the wild? Vincent Lefevre (Jul 13)

Wongi Lee

CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel Wongi Lee (Jul 20)

Xen . org security team

Xen Security Advisory 498 v2 (CVE-2026-42491) - XAPI: Missing TLS verification in some SDKs Xen . org security team (Jul 14)

xylove21

[CONFIDENTIAL] cert-manager v1.15-v1.17+main — Reflected SSRF via Issuer.spec.vault.server (CVSS 7.2 HIGH) xylove21 (Jul 03)
[CVE request] Apache Kafka OAUTHBEARER authentication bypass via signed JWT clock skew (vulnerable 4.0.0 - 4.0.x, no maintainer response in 7 days) xylove21 (Jul 03)
[CVE request] Apache APISIX 3.16.0 JWT-Auth Algorithm Confusion (Authentication Bypass, CVSS 9.8 CRITICAL) — no maintainer response in 9 days via GHSA Triage xylove21 (Jul 03)
Wasm OCI Image Fetcher Bearer Realm SSRF Bypass xylove21 (Jul 03)

yan xu

Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass yan xu (Jul 07)

Yorgos Thessalonikefs

Unbound: 1.25.2 addresses multiple CVE items Yorgos Thessalonikefs (Jul 22)

Yu Qi

CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs Yu Qi (Jul 12)