oss-sec: by date
501 messages
starting Jul 01 26 and
ending Aug 14 26
Date index |
Thread index |
Author index
Wednesday, 01 July
OFFIS DCMTK: 5 CISA-coordinated DICOM vulnerabilities Abhinav Agarwal
Re: hostapd: OOB write in Wi-Fi 7 MLD association parsing (pre-auth DoS) Abhinav Agarwal
CVE-2026-54428: Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK Oleg Kalnichevski
CVE-2026-54399: Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration Oleg Kalnichevski
check_icmp (Monitoring Plugins): host-count overflow leads to heap buffer overflow in setuid-root binary Holger Weiß
CVE-2026-56016: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources Robert Rothenberg
CVE-2025-15646: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion Robert Rothenberg
Fwd: libevent 2.1.13-stable contains several security fixes Alan Coopersmith
Vinyl Cache / Varnish Cache HTTP/2 parsing deficiency [CVE-2026-50052] Alan Coopersmith
CVE-2026-54161: NUT upsmon: remote OS command injection via ups.alarm in NOTIFYCMD - fixed in PR #3499 (affects 2.8.3–2.8.5) pro Err0r
Re: check_icmp (Monitoring Plugins): host-count overflow leads to heap buffer overflow in setuid-root binary Michael Orlitzky
Thursday, 02 July
CVE-2026-43503: Analysis of the "DirtyClone" Linux LPE (Dirty Frag family variant) Or Peles
Re: Fwd: Node.js security updates for all active release lines, June 2026 Alan Coopersmith
CVE-2026-47896: Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server Paul Irwin
CVE-2026-47897: Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client Paul Irwin
CVE-2026-47898: Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser Paul Irwin
Friday, 03 July
CVE-2026-56015: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length Robert Rothenberg
pandemic of incomplete error handling in the OpenSSL ecosystem Julian Andres Klode
[CVE request] Apache Kafka OAUTHBEARER authentication bypass via signed JWT clock skew (vulnerable 4.0.0 - 4.0.x, no maintainer response in 7 days) xylove21
[CVE request] Apache APISIX 3.16.0 JWT-Auth Algorithm Confusion (Authentication Bypass, CVSS 9.8 CRITICAL) — no maintainer response in 9 days via GHSA Triage xylove21
[CONFIDENTIAL] cert-manager v1.15-v1.17+main — Reflected SSRF via Issuer.spec.vault.server (CVSS 7.2 HIGH) xylove21
Wasm OCI Image Fetcher Bearer Realm SSRF Bypass xylove21
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass h
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer
Saturday, 04 July
CVE-2026-49297: Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator) Shahar Epstein
CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg
CVE-2026-12740: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg
CVE-2026-14570: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery Timothy Legge
Sunday, 05 July
CVE-2026-40047: Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer Andrea Cosentino
CVE-2026-40859: Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled Andrea Cosentino
CVE-2026-42527: Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure Andrea Cosentino
CVE-2026-43865: Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution Andrea Cosentino
CVE-2026-46453: Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation Andrea Cosentino
CVE-2026-46454: Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers Andrea Cosentino
CVE-2026-46455: Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted Andrea Cosentino
CVE-2026-46456: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers Andrea Cosentino
CVE-2026-46457: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers Andrea Cosentino
CVE-2026-46584: Apache Camel: Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties, allowing an attacker to weaken the SMTP transport security and, on releases before 4.19.0, redirect the connection and steal Andrea Cosentino
CVE-2026-46585: Apache Camel: Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query Andrea Cosentino
CVE-2026-46590: Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048) Andrea Cosentino
CVE-2026-46591: Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169) Andrea Cosentino
CVE-2026-46592: Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation Andrea Cosentino
CVE-2026-46726: Apache Camel: Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of Andrea Cosentino
CVE-2026-48203: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields Andrea Cosentino
CVE-2026-48204: Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration Andrea Cosentino
CVE-2026-48205: Apache Camel: Camel-DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect DNS queries to an attacker-controlled server (server-side request forgery) and enumerate internal Andrea Cosentino
CVE-2026-48206: Apache Camel: Camel-JIRA: A set of non-Camel-prefixed Exchange header constants (IssueKey, ProjectKey, IssueTransitionId, ...) bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials Andrea Cosentino
CVE-2026-49086: Apache Camel: Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to redirect the re-published message to an arbitrary Dapr Pub/Su Andrea Cosentino
CVE-2026-49097: Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users Andrea Cosentino
CVE-2026-49098: Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic Andrea Cosentino
CVE-2026-49099: Apache Camel: Camel-Salesforce: Non-Camel-prefixed Exchange header constants (sObjectQuery, sObjectSearch, apexUrl, ...) bypass the HTTP header filter, allowing an HTTP client to inject SOQL/SOSL queries, override the target SObject, and redirect Apex REST calls using t Andrea Cosentino
CVE-2026-49365: Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients Andrea Cosentino
CVE-2026-53913: Apache Camel: Camel-Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration (no required roles or permissions) the token is never verified and any non-null bearer value is accepted - a Andrea Cosentino
CVE-2026-55993: Apache Camel: Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of secr Andrea Cosentino
CVE-2026-55994: Apache Camel: Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of secrets when bridged Andrea Cosentino
CVE-2026-56139: Apache Camel: Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients - and the option was not honoured Andrea Cosentino
CVE-2026-56140: Apache Camel: Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components; because camel-aws2-sns is producer-only (no consumer) there is no reachable inbound header-injection path, so this is a defense-in- Andrea Cosentino
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Eli Schwartz
CVE-2026-14803: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder Stig Palmquist
Monday, 06 July
CVE-2026-13705: Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle Stig Palmquist
CVE-2026-13708: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol Stig Palmquist
Announce: OpenSSH 10.4 released Damien Miller
Security Considerations for Statsd Clients Robert Rothenberg
Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359) Hyunwoo Kim
c-ares 1.34.7 release: CVE-2026-33630, GHSA-pjmc-gx33-gc76, GHSA-jv8r-gqr9-68wj Brad House
CVE-2026-43825: Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel Richard Zowalla
CVE-2026-24012: Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query Haonan Hou
CVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC Haonan Hou
CVE-2026-24014: Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write Haonan Hou
CVE-2026-43866: Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder Andrea Cosentino
CVE-2026-43867: Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter Andrea Cosentino
CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Federico Mariani
CVE-2026-46588: Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Federico Mariani
CVE-2026-49042: Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters Federico Mariani
Tuesday, 07 July
CVE-2026-33264: Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() Rahul Vats
CVE-2026-48828: Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key Rahul Vats
CVE-2026-48891: Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target Rahul Vats
CVE-2026-48892: Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options Rahul Vats
CVE-2026-49296: Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} Rahul Vats
CVE-2026-49487: Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs Rahul Vats
Foreman: multiple vulnerabilities fixed in 3.18.2 and 3.19.1 (CVE-2026-5135, CVE-2026-5136, CVE-2026-5138, CVE-2026-5142) Ondrej Gajdusek
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass yan xu
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer
Django CVE-2026-48588, CVE-2026-53877, and CVE-2026-53878 Jacob Walls
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Feroz Salam
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Solar Designer
CVE-2026-7017: HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets Robert Rothenberg
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Joe Stringer
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Solar Designer
CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Robert Rothenberg
CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Robert Rothenberg
CVE-2026-14895: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service Robert Rothenberg
FW: X.Org Security Advisory: multiple security issues in libXfont2 Peter Hutterer
FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland Peter Hutterer
Wednesday, 08 July
[OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423) Jay Faulkner
[OSSA-2026-026] Ironic: Insufficient Access Controls regarding parent/child nodes Jay Faulkner
CVE-2026-41042: Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter Jerry Shao
CVE-2026-14454: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed Robert Rothenberg
CVE-2026-49145: App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc Stig Palmquist
CVE-2026-49146: App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc Stig Palmquist
CVE-2026-49147: App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes Stig Palmquist
Go 1.26.5 and Go 1.25.12 fix CVE-2026-39822 & CVE-2026-42505 Alan Coopersmith
CVE-2026-57111: Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin Junkai Xue
Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Dr. Thomas Orgis
CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android Jan Schaumann
Re: CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android Jan Engelhardt
Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Solar Designer
Thursday, 09 July
Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Vega Agent
HTSlib <= 1.23.1 Multiple vulnerabilities in file reading code Robert Davies
[oss-security][CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations Alan Coopersmith
Friday, 10 July
CVE-2026-28564: Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials Haonan Hou
CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver Haonan Hou
CVE-2026-40006: Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver Haonan Hou
CVE-2026-40007: Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError Haonan Hou
CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC Haonan Hou
CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor Haonan Hou
CVE-2026-40452: Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users Haonan Hou
CVE-2026-40454: Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data Haonan Hou
CVE-2026-49844: Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson() Piotr Karwasz
Sunday, 12 July
Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS gregdurys . security
Re: Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS Solar Designer
CVE-2026-41041: Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints. Jerry Shao
CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs Yu Qi
Monday, 13 July
CVE-2026-58065: Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification Vincent Beck
CVE-2026-59245: Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision) Vincent Beck
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk Stig Palmquist
CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack Stig Palmquist
CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record Stig Palmquist
2 CVEs Crypt::OpenSSL::X509 versions before 2.1.3 Timothy Legge
new af_alg exploit in the wild? Bernd Zeimetz
Re: new af_alg exploit in the wild? Vincent Lefevre
Re: new af_alg exploit in the wild? Solar Designer
CVE-2026-58319: Apache Doris: Improper Authentication in Frontend HTTP API Mingyu Chen
CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API Li Yang
CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API Li Yang
CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval Li Yang
Tuesday, 14 July
CVE-2026-59083: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass Mark Thomas
CVE-2026-59084: Apache Tomcat: EncryptInterceptor requirements not clearly documented Mark Thomas
CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text Robert Rothenberg
CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read Maxim Solodovnik
Re: new af_alg exploit in the wild? Simon McVittie
Xen Security Advisory 498 v2 (CVE-2026-42491) - XAPI: Missing TLS verification in some SDKs Xen . org security team
CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row Robert Rothenberg
CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index Robert Rothenberg
CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location Robert Rothenberg
CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle Stig Palmquist
CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint Terence Monteiro
CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure Terence Monteiro
CVE-2026-57821: Apache Fineract: Office list: SQL Injection via Subquery in orderBy Terence Monteiro
Wednesday, 15 July
SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10 Matthias Gerstner
CVE-2026-26032: Apache Ivy: PackagerResolver path traversal vulnerability Stefan Bodewig
Multiple vulnerabilities in ntfs-3g Rostislav
Thursday, 16 July
CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead Robert Rothenberg
CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg
CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead Robert Rothenberg
CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg
CERT VU#885548 - Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions Alan Coopersmith
CVE-2026-13713: YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack Paul Johnson
CVE-2026-57075: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec Paul Johnson
CVE-2026-57076: YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor Paul Johnson
CVE-2026-57077: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len Paul Johnson
CVE-2026-59173: Apache Traffic Server is vulnerable to stalled HTTP/2 flow-control Masakazu Kitajo
CVE-2026-62764: Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions Christopher Tubbs
Friday, 17 July
Re: SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10 Matthias Gerstner
CVE-2026-13410: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled Robert Rothenberg
CVE-2026-13082: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets Robert Rothenberg
CVE-2026-14741: HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date Robert Rothenberg
CVE-2026-9537: Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison Robert Rothenberg
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability Alan Coopersmith
Cyrus IMAP 3.12.3 fixed 9 CVEs Alan Coopersmith
Saturday, 18 July
OpenSSL "HollowByte" DoS via attacker-controlled memory allocation size in glibc Jan Schaumann
User prompt injection (CSRF) of the llama-server's Web UI (llama.cpp) Gabriel Corona
Monday, 20 July
CVE-2026-61548: rsyslog mmpstrucdata stack overflow Rainer Gerhards
CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel Wongi Lee
CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts Robert Rothenberg
CVE-2026-6656: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks Robert Rothenberg
CVE-2026-13577: Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable Robert Rothenberg
CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask Francesco Chicchiriccò
CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector Francesco Chicchiriccò
CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search Francesco Chicchiriccò
CVE-2026-62183: Apache Syncope: User self-service privilege escalation Francesco Chicchiriccò
CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check Francesco Chicchiriccò
CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass Francesco Chicchiriccò
CVE-2026-64193: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR Robert Rothenberg
CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains Robert Rothenberg
Re: dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation Alan Coopersmith
CVE-2026-56452: Apache MINA SSHD: Path traversal in SCP file reception Thomas Wolf
CVE-2026-56623: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows Thomas Wolf
CVE-2026-56624: Apache MINA SSHD: SSH certificate options lack validations Thomas Wolf
CVE-2026-58624: Apache MINA SSHD: Remote execution of JGit commands can write files on the server Thomas Wolf
Tuesday, 21 July
LPE in snapd and other vulnerabilities Eduardo Barretto
Re: LPE in snapd and other vulnerabilities Qualys Security Advisory
CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free Chaokun Yang
CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface Chaokun Yang
CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths Chaokun Yang
CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization Chaokun Yang
libssh 0.12.1 and 0.11.5 security releases Alan Coopersmith
432 Linux kernel CVEs Jan Schaumann
Multiple vulnerabilities fixed in various Data::*::Shared modules for Perl Robert Rothenberg
Re: 432 Linux kernel CVEs Steffen Nurpmeso
Re: 432 Linux kernel CVEs Jan Schaumann
Re: 432 Linux kernel CVEs Peter Gutmann
Wednesday, 22 July
CVE-2026-54432+more: Roundcube XSS/SSRF/etc prior to 1.6.17/1.7.2 Valtteri Vuorikoski
PortProtonQt: Custom Polkit Rule Allows Escalation of NetworkManager and UDisks2 Privileges (CVE-2026-59678) Matthias Gerstner
rsyslog v8.36.0 through v8.2606.0: imptcp regex-framing remote denial of service Rainer Gerhards
PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues Otto Moerbeek
Unbound: 1.25.2 addresses multiple CVE items Yorgos Thessalonikefs
ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321) Michał Kępień
security release for Exim Jeremy Harris
Re: 432 Linux kernel CVEs Greg KH
Re: 432 Linux kernel CVEs John Haxby
Re: 432 Linux kernel CVEs Stephan Verbücheln
Re: 432 Linux kernel CVEs Marcus Meissner
RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Qualys Security Advisory
Re: CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel Solar Designer
Re: 432 Linux kernel CVEs David A. Wheeler
CVE-2026-13089: OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify Robert Rothenberg
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Qualys Security Advisory
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Marco Benatto
Re: 432 Linux kernel CVEs Steffen Nurpmeso
Thursday, 23 July
Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...) Hanno Böck
Re: 432 Linux kernel CVEs Peter Gutmann
Re: PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues Otto Moerbeek
[OSSA-2026-028] OpenStack Ironic Python Agent: Credential extraction via malicious container (CVE-2026-54422) Goutham Pacha Ravi
[OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending) Goutham Pacha Ravi
Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE) Przemyslaw Frasunek
[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending) Goutham Pacha Ravi
CVE-2026-16277 & CVE-2026-16461: buffer overflows in rpcinfo Alan Coopersmith
Friday, 24 July
Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28 Douglas Bagnall
Re: 432 Linux kernel CVEs Sultan Alsawaf
libIEC61850: four MMS/GOOSE memory-safety vulnerabilities, including lab RCE Abhinav Agarwal
CVE-2026-16634: TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99 Robert Rothenberg
Re: 432 Linux kernel CVEs John Haxby
Re: Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE) Przemyslaw Frasunek
CVE-2026-63317: Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML Richard Zowalla
CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing Colm O hEigeartaigh
CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths Colm O hEigeartaigh
CVE-2026-66144: Apache Neethi: Remote PolicyReference fetch lacks resource bounds Colm O hEigeartaigh
CVE-2026-45811: Apache NimBLE: Buffer overflow in socket HCI transport Szymon Janc
CVE-2026-45812: Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler Szymon Janc
CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation Szymon Janc
CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler Szymon Janc
CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request Szymon Janc
CVE-2026-46452: Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure Szymon Janc
[vim-security] Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839 Christian Brabandt
[vim-security] Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840 Christian Brabandt
[vim-security] Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841 Christian Brabandt
[vim-security] Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842 Christian Brabandt
[vim-security] Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843 Christian Brabandt
Re: 432 Linux kernel CVEs Alan Coopersmith
CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service Duo Zhang
CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp Robert Rothenberg
Re: 432 Linux kernel CVEs Steffen Nurpmeso
Re: [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138) Goutham Pacha Ravi
Re: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139) Goutham Pacha Ravi
[vim-security] Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844 Christian Brabandt
[vim-security] Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845 Christian Brabandt
[vim-security] Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846 Christian Brabandt
[vim-security] Arbitrary Command Execution via the Vimball Record File in Vim < 9.2.0847 Christian Brabandt
CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport Jens Geyer
CVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit Jens Geyer
CVE-2026-45112: Apache Thrift: Unbounded Read Leading to Denial of Service Jens Geyer
CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification Jens Geyer
CVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass Jens Geyer
CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit Jens Geyer
CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb Jens Geyer
CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports Jens Geyer
CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() Jens Geyer
CVE-2026-55970: Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() Jens Geyer
CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path Jens Geyer
CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() Jens Geyer
CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit Jens Geyer
CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass Jens Geyer
CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import Jens Geyer
Saturday, 25 July
Fwd: The GNU C Library version 2.44 is now available, fixes 3 CVEs Alan Coopersmith
CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports Collin Funk
GNU Inetutils talkd buffer overflow with long DNS names. Collin Funk
CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options Robert Rothenberg
Re: 432 Linux kernel CVEs Demi Marie Obenour
Sunday, 26 July
[security] critical vulnerabilities patched in svxlink (RCE) Mark Rose
Monday, 27 July
Re: 432 Linux kernel CVEs Loganaden Velvindron
Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Reid Sutherland
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Solar Designer
CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence Pedro Henrique Oliveira dos Santos
CVE-2026-66391: Apache Wicket: leaked and missing CSP headers Pedro Henrique Oliveira dos Santos
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Reid Sutherland
CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS Christopher L. Shannon
CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations Christopher L. Shannon
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Sam James
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data Robert Lazarski
CVE-2026-17552: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call Robert Rothenberg
[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM advisories
Tuesday, 28 July
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Reid Sutherland
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Greg KH
[NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Write advisories
OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability manizada
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Sam James
CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`) Shahar Epstein
[CVE pending] Eclipse Milo <= 1.1.4: password-recovery oracle, pre-auth DoS, and four server flaws Abhinav Agarwal
Xen Security Advisory 495 v2 (CVE-2026-42493) - x86 shadow paging is deprecated Xen . org security team
Xen Security Advisory 496 v2 (CVE-2026-42492) - vIRQ event channel binding may break Xenstore Xen . org security team
Xen Security Advisory 497 v2 (CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425) - buffer overruns in libfsimage iso9660 handling Xen . org security team
Xen Security Advisory 499 v2 (CVE-2026-62426,CVE-2026-62427) - sysctl and platform-op locks open to abuse Xen . org security team
Xen Security Advisory 500 v2 (CVE-2026-62428) - grant-table: type confusion in grant-copy Xen . org security team
Xen Security Advisory 501 v4 (CVE-2026-62435,CVE-2026-62436) - grant-table: version change racing with other operations Xen . org security team
Xen Security Advisory 502 v3 (CVE-2026-62429) - vNUMA domain cleanup may race other operations Xen . org security team
Xen Security Advisory 503 v2 (CVE-2026-62430) - x86: Out-of-bounds read in vRTC emulation Xen . org security team
Xen Security Advisory 504 v2 (CVE-2026-62431) - Viridian STIMER division by zero Xen . org security team
Xen Security Advisory 505 v2 (CVE-2026-62432) - evtchn: Race between FIFO expand and reset Xen . org security team
Xen Security Advisory 506 v2 (CVE-2026-62433) - correct buffer checks for DM_OP hypercalls Xen . org security team
Xen Security Advisory 507 v2 (CVE-2026-62434) - PoD: Don't try to reclaim special pages Xen . org security team
Xen Security Advisory 508 v2 - pygrub is only supported in de-privileged mode Xen . org security team
CVE-2026-66299: Apache Tomcat: DoS via WebSocket chat example Mark Thomas
[OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending) Goutham Pacha Ravi
[OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending) Goutham Pacha Ravi
CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints Radhika Kundam
Wednesday, 29 July
Re: Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28 Douglas Bagnall
CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy Akira Ajisaka
[NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service advisories
[OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707) Goutham Pacha Ravi
Fwd: Node.js security updates for all active release lines, June 2026 Rafael Gonzaga
Fwd: [CVE-2026-13346] pip absolute path traversal during download from malicious package indexes Alan Coopersmith
Backports available - cBPF JIT spray hardening Pawan Gupta
Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing Alan Coopersmith
Re: Fwd: Node.js security updates for all active release lines, June 2026 Alan Coopersmith
Thursday, 30 July
CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling Jongyoul Lee
CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition Jongyoul Lee
CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction Jongyoul Lee
CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 Jongyoul Lee
CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write Akira Ajisaka
CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification Daniel Gaspar
CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser Daniel Gaspar
Re: Backports available - cBPF JIT spray hardening Jose R Rodriguez
Re: Backports available - cBPF JIT spray hardening Pawan Gupta
[SBA-ADV-20260126-01] CVE-2026-16969 CVE-2026-18360 CVE-2026-18361: DFIR-IRIS 2.4.26 and possibly others Stored XSS SBA Research Security Advisory
[SBA-ADV-20260128-02] CVE-2026-16971 CVE-2026-18362: DFIR-IRIS 2.4.26 and possibly others Missing Brute Force Protection SBA Research Security Advisory
[SBA-ADV-20260128-04] CVE-2026-16970: DFIR-IRIS 2.4.26 and possibly others Insufficient Logout Implementation SBA Research Security Advisory
CVE-2026-22068+more: multiple vulnerabilities in Apache Traffic Server prior to 9.2.15/10.1.4 Valtteri Vuorikoski
CVE-2026-28811: Apache JSPWiki: Error Handling Reveals Error Details Juan Pablo Santos Rodríguez
CVE-2026-28812: Apache JSPWiki: UserManager does not sanity-check user database at startup Juan Pablo Santos Rodríguez
CVE-2026-28813: Apache JSPWiki: JSON hijacking Juan Pablo Santos Rodríguez
CVE-2026-28814: Apache JSPWiki: Arbitrary Wiki Markup rendering due to lack of authentication Juan Pablo Santos Rodríguez
CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing Juan Pablo Santos Rodríguez
CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check Robert Rothenberg
CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time Robert Rothenberg
Re: Backports available - cBPF JIT spray hardening Greg KH
33 Vulnerabilities in cJSON Alan Coopersmith
CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser Tim Allison
CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false Tim Allison
o6 Automation open62541: multiple CISA-coordinated OPC UA vulnerabilities Abhinav Agarwal
Re: 33 Vulnerabilities in cJSON Collin Funk
Some Changes to GNOME Security Tracking Alan Coopersmith
Re: Backports available - cBPF JIT spray hardening Jose R Rodriguez
PHP 30 July 2026 security releases Alan Coopersmith
Re: Some Changes to GNOME Security Tracking Peter Gutmann
Friday, 31 July
CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases Akira Ajisaka
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Dr. Thomas Orgis
Re: 33 Vulnerabilities in cJSON Simon McVittie
Re: Some Changes to GNOME Security Tracking Aaron Rainbolt
Re: Some Changes to GNOME Security Tracking Sebastian Pipping
Re: Some Changes to GNOME Security Tracking Aaron Rainbolt
Re: 33 Vulnerabilities in cJSON Jeroen Roovers
Re: Some Changes to GNOME Security Tracking David A. Wheeler
Re: Some Changes to GNOME Security Tracking Sebastian Pipping
Re: Some Changes to GNOME Security Tracking Eli Schwartz
Re: Some Changes to GNOME Security Tracking Collin Funk
Re: Some Changes to GNOME Security Tracking Alan Coopersmith
Re: Some Changes to GNOME Security Tracking Jeremy Stanley
Re: Some Changes to GNOME Security Tracking Russ Allbery
Re: Some Changes to GNOME Security Tracking Jeremy Stanley
Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability Kevin Riggle
RE: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability Thomas Ward
Rejected CVE reports against SQLite, libraw, ESP32-audioI2S Alan Coopersmith
Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability Thomas Ward
Re: Some Changes to GNOME Security Tracking Demi Marie Obenour
Re: 33 Vulnerabilities in cJSON Peter Gutmann
Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing Alan Coopersmith
Re: Some Changes to GNOME Security Tracking Peter Gutmann
Saturday, 01 August
CVE-2026-18536: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP Robert Rothenberg
Re: 33 Vulnerabilities in cJSON Collin Funk
Lean 4 kernel soundness bug: forging proofs via nested inductive projections (0 = 1 demonstrated) Jonathan Brossard
Sunday, 02 August
[CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream) Abhinav Agarwal
Re: Some Changes to GNOME Security Tracking Peter Gutmann
Re: Some Changes to GNOME Security Tracking Russ Allbery
Re: Some Changes to GNOME Security Tracking Solar Designer
Re: Some Changes to GNOME Security Tracking Demi Marie Obenour
Re: Some Changes to GNOME Security Tracking Jacob Bachmeyer
Monday, 03 August
mpg123 release 1.33.7 with lots of security-relevant fixes Dr. Thomas Orgis
Re: Some Changes to GNOME Security Tracking Yves-Alexis Perez
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Marco Benatto
CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions Andy Seaborne
Re: Some Changes to GNOME Security Tracking David A. Wheeler
Re: Some Changes to GNOME Security Tracking Emily Shepherd
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Darrick J. Wong
Re: Some Changes to GNOME Security Tracking Sebastian Pipping
CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates David Handermann
CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests David Handermann
CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion David Handermann
CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests David Handermann
OSSN-0104: Ironic-Python-Agent may fallback to mDNS unexpectedly Jay Faulkner
Re: Some Changes to GNOME Security Tracking Aaron Rainbolt
Bouncy Castle 1.85 release fixes 32 CVEs Alan Coopersmith
Re: Bouncy Castle 1.85 release fixes 32 CVEs Peter Gutmann
Re: Some Changes to GNOME Security Tracking Greg KH
Tuesday, 04 August
Re: Some Changes to GNOME Security Tracking Albert Veli
Django CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920 Natalia Bidart
Re: Bouncy Castle 1.85 release fixes 32 CVEs Alan Coopersmith
CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Robbie Gemmell
CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication Robbie Gemmell
CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow Robbie Gemmell
CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded Robbie Gemmell
CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service Robbie Gemmell
CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery Robbie Gemmell
CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication Daniil Kirilyuk
CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow Daniil Kirilyuk
CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Daniil Kirilyuk
CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded Daniil Kirilyuk
CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service Daniil Kirilyuk
CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery Daniil Kirilyuk
CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service Daniil Kirilyuk
CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Timothy A. Bish
CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication Timothy A. Bish
CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow Timothy A. Bish
CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded Timothy A. Bish
CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service Timothy A. Bish
CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery Timothy A. Bish
CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Timothy A. Bish
CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication Timothy A. Bish
CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow Timothy A. Bish
CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded Timothy A. Bish
CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery Timothy A. Bish
Re: Some Changes to GNOME Security Tracking Alan Coopersmith
Re: Some Changes to GNOME Security Tracking Francis Perron
CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON Robert Rothenberg
CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call Robert Rothenberg
FW: X.Org Security Advisory: multiple security issues in libXfont2 Peter Hutterer
Wednesday, 05 August
Re: Bouncy Castle 1.85 release fixes 32 CVEs TvT
Multiple vulnerabilities in Jenkins and Jenkins plugins Daniel Beck
CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS Piotr Karwasz
CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS Piotr Karwasz
CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index Piotr Karwasz
CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input Piotr Karwasz
CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP Response Checking Norbert Pócs
CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing Enxin Xie
CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow Enxin Xie
CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL Enxin Xie
CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions Enxin Xie
CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content Enxin Xie
CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation Enxin Xie
ejabberd 26.07 released with several security fixes Eddie Chapman
[OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201) Jay Faulkner
Re: [OSSA-2026-007] OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean (CVE-2026-40683) Goutham Pacha Ravi
Re: [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-71191, CVE-2026-71192) Goutham Pacha Ravi
Re: [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-71190) Goutham Pacha Ravi
Thursday, 06 August
rust-in-peace: results from agent-assisted Rust OSS vulnerability research Sergei G
PowerDNS Security Advisory 2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption Otto Moerbeek
CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Fourie Zhang
Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Emily Shepherd
Re: Some Changes to GNOME Security Tracking Jan Schaumann
Zapscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-64561) Hyunwoo Kim
CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation Alexandre Dutra
CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack Eric Covener
CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash Eric Covener
CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Eric Covener
CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client Eric Covener
CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client Eric Covener
Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Solar Designer
CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments Colm O hEigeartaigh
CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message Colm O hEigeartaigh
CVE-2026-64958: Apache CXF: Denial of service via message header attachments Colm O hEigeartaigh
CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing Colm O hEigeartaigh
CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage Colm O hEigeartaigh
CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow Colm O hEigeartaigh
CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider Colm O hEigeartaigh
CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation Colm O hEigeartaigh
CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters Colm O hEigeartaigh
CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped Colm O hEigeartaigh
CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay Colm O hEigeartaigh
CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider Colm O hEigeartaigh
Thursday, 13 August
CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass Stig Palmquist
CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM) Oleg Kalnichevski
CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template Robert Rothenberg
CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API) Arnout Engelen
CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename Robert Rothenberg
CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template Robert Rothenberg
[OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE pending) Jeremy Stanley
Go 1.26.6 and Go 1.25.13 are released with 10 security fixes Alan Coopersmith
[OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented Jay Faulkner
OpenSSL Security Advisory Tomas Mraz
CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Oleg Kalnichevski
rsync 3.5.0 released with fixes for 33 CVEs Andrew Tridgell
CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document Robert Rothenberg
CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for Robert Rothenberg
Friday, 14 August
Info-ZIP test option (-T) command injection Harry Sintonen
IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser) Bakabaka_9
croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3) Souiri Anas
croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3) Souiri Anas
CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125) Elman Shahbazov
Re: CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125) Alan Coopersmith
Re: GNU Inetutils talkd buffer overflow with long DNS names. Collin Funk
