oss-sec: by author
960 messages
starting Sep 12 26 and
ending Aug 03 26
Date index |
Thread index |
Author index
12345678
Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey 12345678 (Sep 12)
Aaron Rainbolt
Re: Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged userns Aaron Rainbolt (Aug 16)
Re: Some Changes to GNOME Security Tracking Aaron Rainbolt (Jul 31)
Re: Some Changes to GNOME Security Tracking Aaron Rainbolt (Aug 03)
Re: Some Changes to GNOME Security Tracking Aaron Rainbolt (Jul 31)
Abhinav Agarwal
[CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream) Abhinav Agarwal (Aug 02)
GDCM <= 3.2.7: six memory-safety and denial-of-service vulnerabilities, no CVE Abhinav Agarwal (Sep 09)
o6 Automation open62541: multiple CISA-coordinated OPC UA vulnerabilities Abhinav Agarwal (Jul 30)
[CVE pending] Eclipse Milo <= 1.1.4: password-recovery oracle, pre-auth DoS, and four server flaws Abhinav Agarwal (Jul 28)
CVE-2026-82583, CVE-2026-78224, CVE-2026-82578: NextGen Mirth Connect SQL injection and XXE Abhinav Agarwal (Sep 11)
OFFIS DCMTK: 5 CISA-coordinated DICOM vulnerabilities Abhinav Agarwal (Jul 01)
Re: hostapd: OOB write in Wi-Fi 7 MLD association parsing (pre-auth DoS) Abhinav Agarwal (Jul 01)
libIEC61850: four MMS/GOOSE memory-safety vulnerabilities, including lab RCE Abhinav Agarwal (Jul 24)
Abhishek Choudhary
CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers Abhishek Choudhary (Aug 25)
CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS Abhishek Choudhary (Aug 26)
CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation Abhishek Choudhary (Aug 26)
CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins Abhishek Choudhary (Aug 26)
Adhemerval Zanella Netto
The GNU C Library security advisories update for 2026-09-14 Adhemerval Zanella Netto (Sep 14)
The GNU C Library security advisories update for 2026-09-17 Adhemerval Zanella Netto (Sep 17)
Aditi Bhatnagar
CVE-2026-80205 : ReDoS in NLTK Text.findall() (CVSS 8.7 High) Aditi Bhatnagar (Sep 01)
Adrian Perez de Castro
WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005 Adrian Perez de Castro (Aug 19)
advisories
[NotCVE-2026-0014] Input Leap 3.0.3 Drag-and-Drop File Transfer Path Traversal Allows Arbitrary File Write Outside the Drop Directory advisories (Sep 25)
[NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service advisories (Jul 29)
[NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Write advisories (Jul 28)
[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM advisories (Sep 25)
[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File advisories (Aug 22)
[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM advisories (Jul 27)
Akira Ajisaka
CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases Akira Ajisaka (Jul 31)
CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy Akira Ajisaka (Jul 29)
CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write Akira Ajisaka (Jul 30)
Aki Tuomi
Dovecot Security Advisory 3/2026 Aki Tuomi (Aug 28)
Alan Coopersmith
Vulnerabilities in libheif and libde265 Alan Coopersmith (Sep 18)
Rejected CVE reports against SQLite, libraw, ESP32-audioI2S Alan Coopersmith (Jul 31)
Re: CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125) Alan Coopersmith (Aug 14)
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability Alan Coopersmith (Jul 17)
Bouncy Castle 1.85 release fixes 32 CVEs Alan Coopersmith (Aug 03)
Fwd: [CVE-2026-13346] pip absolute path traversal during download from malicious package indexes Alan Coopersmith (Jul 29)
Re: Fwd: Node.js security updates for all active release lines, June 2026 Alan Coopersmith (Jul 29)
33 Vulnerabilities in cJSON Alan Coopersmith (Jul 30)
Suricata 8.0.7 released with 67 vulnerabilities fixed Alan Coopersmith (Sep 18)
CVE-2026-16277 & CVE-2026-16461: buffer overflows in rpcinfo Alan Coopersmith (Jul 23)
Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing Alan Coopersmith (Jul 31)
Fwd: Vulnerabilities in golang.org/x/crypto Alan Coopersmith (Sep 02)
[CVE-2026-19672] CPython: tarfile extraction filter bypass allows creation of directories outside the destination Alan Coopersmith (Aug 25)
CERT VU#885548 - Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions Alan Coopersmith (Jul 16)
CPython: [CVE-2026-87910] tarfile hardlink fallback ignores custom extraction filter rejection via None Alan Coopersmith (Sep 11)
PHP 30 July 2026 security releases Alan Coopersmith (Jul 30)
Re: Some Changes to GNOME Security Tracking Alan Coopersmith (Jul 31)
Cyrus IMAP 3.12.3 fixed 9 CVEs Alan Coopersmith (Jul 17)
Re: 432 Linux kernel CVEs Alan Coopersmith (Jul 24)
Some Changes to GNOME Security Tracking Alan Coopersmith (Jul 30)
Re: pcre2 version 10.48 released with security fixes Alan Coopersmith (Sep 11)
Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing Alan Coopersmith (Jul 29)
Go 1.26.6 and Go 1.25.13 are released with 10 security fixes Alan Coopersmith (Aug 13)
Re: Bouncy Castle 1.85 release fixes 32 CVEs Alan Coopersmith (Aug 04)
Go 1.26.5 and Go 1.25.12 fix CVE-2026-39822 & CVE-2026-42505 Alan Coopersmith (Jul 08)
libssh 0.12.1 and 0.11.5 security releases Alan Coopersmith (Jul 21)
Fwd: libevent 2.1.13-stable contains several security fixes Alan Coopersmith (Jul 01)
Re: Some Changes to GNOME Security Tracking Alan Coopersmith (Aug 04)
Vinyl Cache / Varnish Cache HTTP/2 parsing deficiency [CVE-2026-50052] Alan Coopersmith (Jul 01)
CPython [CVE-2026-17084] StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 Alan Coopersmith (Aug 18)
Re: dnsmasq vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation Alan Coopersmith (Jul 20)
pcre2 version 10.48 released with security fixes Alan Coopersmith (Sep 04)
Re: rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback Alan Coopersmith (Sep 14)
[oss-security][CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations Alan Coopersmith (Jul 09)
CPython [CVE-2026-15806] urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme Alan Coopersmith (Aug 18)
Cpython: [CVE-2026-82049] tarfile extraction filters allow file modification and content disclosure via hard link to symlink Alan Coopersmith (Sep 14)
Re: Fwd: Node.js security updates for all active release lines, June 2026 Alan Coopersmith (Jul 02)
Fwd: The GNU C Library version 2.44 is now available, fixes 3 CVEs Alan Coopersmith (Jul 25)
Albert Veli
Re: Some Changes to GNOME Security Tracking Albert Veli (Aug 04)
Alexandre Dutra
CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation Alexandre Dutra (Aug 06)
Andor Molnar
CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode Andor Molnar (Sep 15)
CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode Andor Molnar (Sep 15)
CVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay Andor Molnar (Sep 15)
CVE-2026-84501: Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider Andor Molnar (Sep 15)
CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources Andor Molnar (Sep 15)
Andrea Cosentino
CVE-2026-46585: Apache Camel: Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query Andrea Cosentino (Jul 05)
CVE-2026-56140: Apache Camel: Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components; because camel-aws2-sns is producer-only (no consumer) there is no reachable inbound header-injection path, so this is a defense-in- Andrea Cosentino (Jul 05)
CVE-2026-46726: Apache Camel: Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of Andrea Cosentino (Jul 05)
CVE-2026-48205: Apache Camel: Camel-DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect DNS queries to an attacker-controlled server (server-side request forgery) and enumerate internal Andrea Cosentino (Jul 05)
CVE-2026-49365: Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients Andrea Cosentino (Jul 05)
CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes Andrea Cosentino (Aug 24)
CVE-2026-40859: Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled Andrea Cosentino (Jul 05)
CVE-2026-55993: Apache Camel: Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of secr Andrea Cosentino (Jul 05)
CVE-2026-46453: Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation Andrea Cosentino (Jul 05)
CVE-2026-49099: Apache Camel: Camel-Salesforce: Non-Camel-prefixed Exchange header constants (sObjectQuery, sObjectSearch, apexUrl, ...) bypass the HTTP header filter, allowing an HTTP client to inject SOQL/SOSL queries, override the target SObject, and redirect Apex REST calls using t Andrea Cosentino (Jul 05)
CVE-2026-48206: Apache Camel: Camel-JIRA: A set of non-Camel-prefixed Exchange header constants (IssueKey, ProjectKey, IssueTransitionId, ...) bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials Andrea Cosentino (Jul 05)
CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy Andrea Cosentino (Aug 24)
CVE-2026-55994: Apache Camel: Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of secrets when bridged Andrea Cosentino (Jul 05)
CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted Andrea Cosentino (Aug 24)
CVE-2026-46591: Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169) Andrea Cosentino (Jul 05)
CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection Andrea Cosentino (Aug 24)
CVE-2026-42527: Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure Andrea Cosentino (Jul 05)
CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir Andrea Cosentino (Aug 24)
CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result Andrea Cosentino (Aug 24)
CVE-2026-46592: Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation Andrea Cosentino (Jul 05)
CVE-2026-46454: Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers Andrea Cosentino (Jul 05)
CVE-2026-43865: Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution Andrea Cosentino (Jul 05)
CVE-2026-43866: Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder Andrea Cosentino (Jul 06)
CVE-2026-46457: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers Andrea Cosentino (Jul 05)
CVE-2026-43867: Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter Andrea Cosentino (Jul 06)
CVE-2026-48203: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields Andrea Cosentino (Jul 05)
CVE-2026-56139: Apache Camel: Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients - and the option was not honoured Andrea Cosentino (Jul 05)
CVE-2026-46455: Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted Andrea Cosentino (Jul 05)
CVE-2026-53913: Apache Camel: Camel-Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration (no required roles or permissions) the token is never verified and any non-null bearer value is accepted - a Andrea Cosentino (Jul 05)
CVE-2026-48204: Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration Andrea Cosentino (Jul 05)
CVE-2026-46584: Apache Camel: Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties, allowing an attacker to weaken the SMTP transport security and, on releases before 4.19.0, redirect the connection and steal Andrea Cosentino (Jul 05)
CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir Andrea Cosentino (Aug 24)
CVE-2026-46590: Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048) Andrea Cosentino (Jul 05)
CVE-2026-40047: Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer Andrea Cosentino (Jul 05)
CVE-2026-49097: Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users Andrea Cosentino (Jul 05)
CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled Andrea Cosentino (Aug 24)
CVE-2026-49098: Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic Andrea Cosentino (Jul 05)
CVE-2026-46456: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers Andrea Cosentino (Jul 05)
CVE-2026-49086: Apache Camel: Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to redirect the re-published message to an arbitrary Dapr Pub/Su Andrea Cosentino (Jul 05)
Andrew Tridgell
rsync 3.5.0 released with fixes for 33 CVEs Andrew Tridgell (Aug 13)
Andy Seaborne
CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions Andy Seaborne (Aug 03)
Arnout Engelen
CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API) Arnout Engelen (Aug 13)
CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module Arnout Engelen (Sep 04)
Bakabaka_9
IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser) Bakabaka_9 (Aug 14)
Bas Alberts
Re: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920 Bas Alberts (Sep 22)
Bernd Zeimetz
new af_alg exploit in the wild? Bernd Zeimetz (Jul 13)
Brad House
c-ares 1.34.7 release: CVE-2026-33630, GHSA-pjmc-gx33-gc76, GHSA-jv8r-gqr9-68wj Brad House (Jul 06)
Calvin Kirs
CVE-2026-96443: Apache Doris: JDBC driver URL validation bypass leads to remote code execution Calvin Kirs (Sep 23)
CVE-2026-68570: Apache Doris: Authorization bypass leading to unauthorized data access Calvin Kirs (Sep 14)
CVE-2026-31377: Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service Calvin Kirs (Sep 23)
CVE-2026-72524: Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables Calvin Kirs (Sep 14)
Carlos O'Donell
The GNU C Library security advisories update for 2026-09-22 Carlos O'Donell (Sep 22)
Chad Dougherty
Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released Chad Dougherty (Aug 28)
Chaokun Yang
CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths Chaokun Yang (Jul 21)
CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization Chaokun Yang (Jul 21)
CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free Chaokun Yang (Jul 21)
CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface Chaokun Yang (Jul 21)
Charles Zhang
CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDelete Charles Zhang (Aug 20)
CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint Charles Zhang (Aug 20)
CVE-2026-63044: Apache InLong: Authenticated SSRF via POST /api/node/testConnection Charles Zhang (Aug 20)
CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path Charles Zhang (Aug 20)
CVE-2026-63038: Apache InLong: SQL Injection via String Concatenation Vulnerability Report Charles Zhang (Aug 20)
CVE-2026-63016: Apache InLong: Ordinary users can create new packages Charles Zhang (Aug 20)
CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService Charles Zhang (Aug 20)
CVE-2026-63015: Apache InLong: Non-template responsible persons can view template information Charles Zhang (Aug 20)
CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints Charles Zhang (Aug 20)
cherez0ff
[CVE-2026-8715] HashiCorp Vault Secrets Operator 1.3.0-1.4.1: tenant-controlled secretIDPath leaks operator ServiceAccount token (path to cluster-admin) cherez0ff (Aug 28)
Christian Brabandt
[vim-security] Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846 Christian Brabandt (Jul 24)
[vim-security] Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845 Christian Brabandt (Jul 24)
[vim-security] Arbitrary Ex Command Execution via File Names in C Omni-Completion in Vim < 9.2.1011 Christian Brabandt (Aug 25)
[vim-security] Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013 Christian Brabandt (Aug 26)
[vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090 Christian Brabandt (Sep 12)
[vim-security] Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839 Christian Brabandt (Jul 24)
[vim-security] Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843 Christian Brabandt (Jul 24)
[vim-security] Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841 Christian Brabandt (Jul 24)
[vim-security] Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844 Christian Brabandt (Jul 24)
[vim-security] Arbitrary Command Execution via the Vimball Record File in Vim < 9.2.0847 Christian Brabandt (Jul 24)
[vim-security] Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842 Christian Brabandt (Jul 24)
[vim-security] Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840 Christian Brabandt (Jul 24)
[vim-security] Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688 Christian Brabandt (Aug 26)
Christopher L. Shannon
CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations Christopher L. Shannon (Jul 27)
CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS Christopher L. Shannon (Jul 27)
Christopher Tubbs
CVE-2026-62764: Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions Christopher Tubbs (Jul 16)
Clebert Suconic
CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation Clebert Suconic (Sep 09)
CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers Clebert Suconic (Sep 09)
CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription Clebert Suconic (Sep 09)
CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion Clebert Suconic (Sep 09)
CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service Clebert Suconic (Sep 09)
CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service Clebert Suconic (Sep 09)
CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment Clebert Suconic (Sep 09)
Clemens Lang
Re: Retrospective by 'gpg.fail' authors Clemens Lang (Sep 14)
Collin Funk
CVE-2026-95510: GNU Inetutils: use of uninitialized struct sigaction Collin Funk (Sep 25)
CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports Collin Funk (Jul 25)
GNU Inetutils talkd buffer overflow with long DNS names. Collin Funk (Jul 25)
Re: 33 Vulnerabilities in cJSON Collin Funk (Jul 30)
uutils coreutils 'stdbuf' uses LD_PRELOAD on a world-writable temporary file Collin Funk (Aug 19)
Re: Some Changes to GNOME Security Tracking Collin Funk (Jul 31)
Re: AI slops from Eve Collin Funk (Sep 12)
Re: 33 Vulnerabilities in cJSON Collin Funk (Aug 01)
Re: GNU Inetutils talkd buffer overflow with long DNS names. Collin Funk (Aug 14)
Colm O hEigeartaigh
CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow Colm O hEigeartaigh (Aug 06)
CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider Colm O hEigeartaigh (Aug 06)
CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped Colm O hEigeartaigh (Aug 06)
CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service Colm O hEigeartaigh (Sep 18)
CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message Colm O hEigeartaigh (Aug 06)
CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay Colm O hEigeartaigh (Aug 06)
CVE-2026-64958: Apache CXF: Denial of service via message header attachments Colm O hEigeartaigh (Aug 06)
CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing Colm O hEigeartaigh (Aug 06)
CVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service Colm O hEigeartaigh (Sep 18)
CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation Colm O hEigeartaigh (Aug 06)
CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths Colm O hEigeartaigh (Jul 24)
CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters Colm O hEigeartaigh (Aug 06)
CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider Colm O hEigeartaigh (Aug 06)
CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage Colm O hEigeartaigh (Aug 06)
CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion Colm O hEigeartaigh (Sep 18)
CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing Colm O hEigeartaigh (Jul 24)
CVE-2026-66144: Apache Neethi: Remote PolicyReference fetch lacks resource bounds Colm O hEigeartaigh (Jul 24)
CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely Colm O hEigeartaigh (Sep 18)
CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments Colm O hEigeartaigh (Aug 06)
CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service Colm O hEigeartaigh (Sep 18)
Damien Miller
Announce: OpenSSH 10.4 released Damien Miller (Jul 06)
Daniel Beck
Multiple vulnerabilities in Jenkins and Jenkins plugins Daniel Beck (Aug 05)
Dániel Dékány
CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks Dániel Dékány (Sep 08)
Daniel Gaspar
CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification Daniel Gaspar (Jul 30)
CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser Daniel Gaspar (Jul 30)
Daniel Stenberg
[SECURITY ADVISORIES] curl 8.22.0 Daniel Stenberg (Sep 02)
Daniil Kirilyuk
CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 Daniil Kirilyuk (Sep 24)
CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow Daniil Kirilyuk (Aug 04)
CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service Daniil Kirilyuk (Aug 04)
CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder Daniil Kirilyuk (Sep 24)
CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Daniil Kirilyuk (Aug 04)
CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service Daniil Kirilyuk (Aug 04)
CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication Daniil Kirilyuk (Sep 24)
CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering Daniil Kirilyuk (Sep 24)
CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing Daniil Kirilyuk (Sep 24)
CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded Daniil Kirilyuk (Aug 04)
CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication Daniil Kirilyuk (Aug 04)
CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder Daniil Kirilyuk (Sep 24)
CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery Daniil Kirilyuk (Aug 04)
Darrick J. Wong
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Darrick J. Wong (Aug 03)
Dave Brondsema
CVE-2026-81270: Apache Allura: Information exposure via search Dave Brondsema (Sep 03)
CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure Dave Brondsema (Aug 24)
CVE-2026-80190: Apache Allura: Stored XSS via code repositories Dave Brondsema (Sep 03)
CVE-2026-80180: Apache Allura: Stored XSS via markdown HTML processing Dave Brondsema (Sep 03)
CVE-2026-80181: Apache Allura: Server-side request forgery Dave Brondsema (Sep 03)
David A. Wheeler
Re: AI slops from Eve David A. Wheeler (Sep 12)
Re: rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback David A. Wheeler (Sep 14)
Re: 432 Linux kernel CVEs David A. Wheeler (Jul 22)
Re: Some Changes to GNOME Security Tracking David A. Wheeler (Aug 03)
Re: Some Changes to GNOME Security Tracking David A. Wheeler (Jul 31)
David Handermann
CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration David Handermann (Sep 16)
CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests David Handermann (Aug 03)
CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates David Handermann (Aug 03)
CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles David Handermann (Sep 16)
CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion David Handermann (Aug 03)
CVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests David Handermann (Sep 16)
CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods David Handermann (Sep 16)
CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration David Handermann (Sep 16)
CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests David Handermann (Aug 03)
David M. Johnson
CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation David M. Johnson (Sep 25)
CVE-2026-82376: Apache Roller: XML external entity processing in trackback response parser David M. Johnson (Sep 25)
CVE-2026-82379: Apache Roller: WSSE digest authentication headers can be replayed David M. Johnson (Sep 25)
CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL David M. Johnson (Sep 25)
CVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity David M. Johnson (Sep 25)
CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator David M. Johnson (Sep 25)
CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups David M. Johnson (Sep 25)
CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type David M. Johnson (Sep 25)
CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering David M. Johnson (Sep 25)
CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers David M. Johnson (Sep 25)
CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI David M. Johnson (Sep 25)
CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links David M. Johnson (Sep 25)
CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments David M. Johnson (Sep 25)
CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint David M. Johnson (Sep 25)
CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs David M. Johnson (Sep 25)
CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import David M. Johnson (Sep 25)
CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter David M. Johnson (Sep 25)
CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files David M. Johnson (Sep 25)
Demi Marie Obenour
Re: Some Changes to GNOME Security Tracking Demi Marie Obenour (Jul 31)
Re: GNU Emacs vulnerability upon opening arbitrary file Demi Marie Obenour (Aug 20)
Re: Some Changes to GNOME Security Tracking Demi Marie Obenour (Aug 02)
Re: 432 Linux kernel CVEs Demi Marie Obenour (Jul 25)
Denis Ovsienko
libpcap 1.10.7 fixes 7 vulnerabilities Denis Ovsienko (Sep 08)
Dominique Martinet
Re: Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more Dominique Martinet (Sep 08)
Douglas Bagnall
Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28 Douglas Bagnall (Jul 24)
Re: Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28 Douglas Bagnall (Jul 29)
Dr. Thomas Orgis
Re: Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more Dr. Thomas Orgis (Sep 08)
Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Dr. Thomas Orgis (Jul 08)
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Dr. Thomas Orgis (Jul 31)
mpg123 release 1.33.7 with lots of security-relevant fixes Dr. Thomas Orgis (Aug 03)
Duo Zhang
CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service Duo Zhang (Jul 24)
Eddie Chapman
ejabberd 26.07 released with several security fixes Eddie Chapman (Aug 05)
Eduardo Barretto
LPE in snapd and other vulnerabilities Eduardo Barretto (Jul 21)
Eli Schwartz
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Eli Schwartz (Sep 21)
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Eli Schwartz (Jul 05)
Re: AI slops from Eve Eli Schwartz (Sep 10)
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Eli Schwartz (Sep 18)
Re: Some Changes to GNOME Security Tracking Eli Schwartz (Jul 31)
Ellenor Bjornsdottir
Re: AI slops from Eve Ellenor Bjornsdottir (Sep 10)
Elman Shahbazov
CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125) Elman Shahbazov (Aug 14)
Emily Shepherd
Re: Some Changes to GNOME Security Tracking Emily Shepherd (Aug 03)
Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Emily Shepherd (Aug 06)
Emmanuel Lécharny
CVE-2026-94301: Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 Emmanuel Lécharny (Sep 21)
CVE-2026-47321: Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate Emmanuel Lécharny (Sep 21)
Emond Papegaaij
CVE-2026-76982: Apache Wicket: XSS in Button via its model object Emond Papegaaij (Aug 31)
CVE-2026-76983: Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel Emond Papegaaij (Aug 31)
CVE-2026-76985: Apache Wicket: XSS in Palette via getAdditionalAttributes Emond Papegaaij (Aug 31)
CVE-2026-76984: Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute Emond Papegaaij (Aug 31)
CVE-2026-75802: Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel Emond Papegaaij (Aug 31)
CVE-2026-76986: Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue Emond Papegaaij (Aug 31)
CVE-2026-71378: Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener Emond Papegaaij (Aug 30)
CVE-2026-71257: Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed Emond Papegaaij (Aug 30)
CVE-2026-70449: Apache Wicket: Path traversal in resource style/variation/locale Emond Papegaaij (Aug 30)
Enxin Xie
CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content Enxin Xie (Aug 05)
CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation Enxin Xie (Aug 05)
CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing Enxin Xie (Aug 05)
CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions Enxin Xie (Aug 05)
CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow Enxin Xie (Aug 05)
CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL Enxin Xie (Aug 05)
Erica Windisch
Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged userns Erica Windisch (Aug 16)
Eric Covener
CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash Eric Covener (Aug 06)
CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client Eric Covener (Aug 06)
CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client Eric Covener (Aug 06)
CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Eric Covener (Aug 06)
CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack Eric Covener (Aug 06)
Ermenson Junior
CVE-2026-96512: sudo: TZ still affects NOTBEFORE/NOTAFTER Ermenson Junior (Sep 24)
Eve
Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT Eve (Sep 09)
iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level) Eve (Sep 09)
Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design) Eve (Sep 09)
Evgenios Gkritsis
rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback Evgenios Gkritsis (Sep 14)
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule Evgenios Gkritsis (Sep 14)
ezraax
npm registry keeps removed-version timestamps but drops the reason (Sept 2025 campaign as evidence) ezraax (Sep 23)
Fabiano Fidencio
Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540) Fabiano Fidencio (Aug 23)
Federico Mariani
CVE-2026-49042: Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters Federico Mariani (Jul 06)
CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Federico Mariani (Jul 06)
CVE-2026-46588: Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Federico Mariani (Jul 06)
Feroz Salam
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Feroz Salam (Jul 07)
First name Last name
graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS First name Last name (Aug 25)
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via per-error full-document rescan (GetLocation) First name Last name (Aug 26)
Fourie Zhang
CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Fourie Zhang (Aug 06)
Francesco Chicchiriccò
CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask Francesco Chicchiriccò (Jul 20)
CVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence Francesco Chicchiriccò (Sep 14)
CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check Francesco Chicchiriccò (Jul 20)
CVE-2026-73178: Apache Syncope: JWT Access Token takeover Francesco Chicchiriccò (Sep 14)
CVE-2026-87779: Apache Syncope: AES Secret Key disclosure via log output Francesco Chicchiriccò (Sep 14)
CVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task search Francesco Chicchiriccò (Sep 14)
CVE-2026-73579: Apache Syncope: Non-recursive Any search could skip Realms restrictions Francesco Chicchiriccò (Sep 14)
CVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective Francesco Chicchiriccò (Sep 14)
CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable Francesco Chicchiriccò (Sep 14)
CVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authentication Francesco Chicchiriccò (Sep 14)
CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles Francesco Chicchiriccò (Sep 14)
CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search Francesco Chicchiriccò (Jul 20)
CVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user Francesco Chicchiriccò (Sep 14)
CVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search Francesco Chicchiriccò (Sep 14)
CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values Francesco Chicchiriccò (Sep 14)
CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass Francesco Chicchiriccò (Sep 14)
CVE-2026-77147: Apache Syncope: Groovy Sandbox escape for empty CommandArgs Francesco Chicchiriccò (Sep 14)
CVE-2026-73195: Apache Syncope: CSV export spreadsheet formula injection Francesco Chicchiriccò (Sep 14)
CVE-2026-87785: Apache Syncope: JWT subject spoofing Francesco Chicchiriccò (Sep 14)
CVE-2026-73236: Apache Syncope: Cross-Realm authorization bypass in delegated administration Francesco Chicchiriccò (Sep 14)
CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass Francesco Chicchiriccò (Jul 20)
CVE-2026-62183: Apache Syncope: User self-service privilege escalation Francesco Chicchiriccò (Jul 20)
CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector Francesco Chicchiriccò (Jul 20)
CVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers Francesco Chicchiriccò (Sep 14)
CVE-2026-73370: Apache Syncope: Cross-Realm boundaries reconciliation bypass Francesco Chicchiriccò (Sep 14)
CVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist Francesco Chicchiriccò (Sep 14)
CVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning Francesco Chicchiriccò (Sep 14)
CVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduser Francesco Chicchiriccò (Sep 14)
Francis Perron
Re: Some Changes to GNOME Security Tracking Francis Perron (Aug 04)
Gabriel Corona
User prompt injection (CSRF) of the llama-server's Web UI (llama.cpp) Gabriel Corona (Jul 18)
Gabriel Ravier
Re: CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs Gabriel Ravier (Sep 13)
Gidon Gershinsky
CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation Gidon Gershinsky (Sep 08)
Goutham Pacha Ravi
[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-pending) Goutham Pacha Ravi (Sep 21)
Re: [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-71190) Goutham Pacha Ravi (Aug 05)
[OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending) Goutham Pacha Ravi (Jul 28)
[OSSA-2026-042] OpenStack Zaqar: Zaqar empty URL-Signature header bypasses authentication (CVE-2026-97404) Goutham Pacha Ravi (Sep 24)
Re: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139) Goutham Pacha Ravi (Jul 24)
[OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198) Goutham Pacha Ravi (Sep 03)
[OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-pending) Goutham Pacha Ravi (Aug 25)
[OSSA-2026-040] OpenStack Blazar: Multiple authorization vulnerabilities in the Blazar V2 lease API (CVE-2026-93852, CVE-2026-93854) Goutham Pacha Ravi (Sep 21)
[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending) Goutham Pacha Ravi (Jul 23)
[OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-pending) Goutham Pacha Ravi (Aug 19)
Re: [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138) Goutham Pacha Ravi (Jul 24)
[OSSA-2026-041] OpenStack Swift: Cross-container information disclosure via Swift tempurl (CVE-2026-97149) Goutham Pacha Ravi (Sep 24)
Re: [OSSA-2026-007] OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean (CVE-2026-40683) Goutham Pacha Ravi (Aug 05)
[OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707) Goutham Pacha Ravi (Jul 29)
[OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-76878) errata 1 Goutham Pacha Ravi (Aug 20)
[OSSA-2026-028] OpenStack Ironic Python Agent: Credential extraction via malicious container (CVE-2026-54422) Goutham Pacha Ravi (Jul 23)
Re: [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-71191, CVE-2026-71192) Goutham Pacha Ravi (Aug 05)
[OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending) Goutham Pacha Ravi (Jul 28)
[OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStack Goutham Pacha Ravi (Aug 20)
Re: [OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-80182, CVE-2026-80184) Goutham Pacha Ravi (Aug 25)
[OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending) Goutham Pacha Ravi (Jul 23)
[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-94572, CVE-2026-94571) Goutham Pacha Ravi (Sep 22)
Greg Dahlman
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Greg Dahlman (Sep 19)
gregdurys . security
Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS gregdurys . security (Jul 12)
Greg KH
Re: Backports available - cBPF JIT spray hardening Greg KH (Jul 30)
Re: Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely Greg KH (Aug 26)
Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely Greg KH (Aug 26)
Re: 432 Linux kernel CVEs Greg KH (Jul 22)
Re: Linux kernel: Guest-to-Host DoS via TAP Greg KH (Aug 24)
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Greg KH (Jul 28)
Re: Some Changes to GNOME Security Tracking Greg KH (Aug 03)
h
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass h (Jul 03)
Haitam Lazaar
CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX Haitam Lazaar (Sep 25)
CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2 Haitam Lazaar (Sep 16)
Hanno Böck
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Hanno Böck (Sep 18)
Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...) Hanno Böck (Jul 23)
Re: Vulnerabilities in libheif and libde265 Hanno Böck (Sep 19)
Re: Vulnerabilities in libheif and libde265 Hanno Böck (Sep 22)
Haonan Hou
CVE-2026-24012: Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query Haonan Hou (Jul 06)
CVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC Haonan Hou (Jul 06)
CVE-2026-28564: Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials Haonan Hou (Jul 10)
CVE-2026-24014: Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write Haonan Hou (Jul 06)
CVE-2026-40454: Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data Haonan Hou (Jul 10)
CVE-2026-40006: Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver Haonan Hou (Jul 10)
CVE-2026-40452: Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users Haonan Hou (Jul 10)
CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor Haonan Hou (Jul 10)
CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver Haonan Hou (Jul 10)
CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC Haonan Hou (Jul 10)
CVE-2026-40007: Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError Haonan Hou (Jul 10)
Harry Sintonen
Info-ZIP test option (-T) command injection Harry Sintonen (Aug 14)
Holden Karau
CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4 Holden Karau (Sep 01)
Holger Weiß
check_icmp (Monitoring Plugins): host-count overflow leads to heap buffer overflow in setuid-root binary Holger Weiß (Jul 01)
Hyunwoo Kim
CVE-2026-89775: Guest-to-Host Escape in KVM/arm64 Hyunwoo Kim (Sep 16)
Zapscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-64561) Hyunwoo Kim (Aug 06)
Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359) Hyunwoo Kim (Jul 06)
Intilangelo, Andrea
CVE-2026-78331 / CVE-2026-78332: Multiple Vulnerabilities in NethServer Intilangelo, Andrea (Aug 24)
Jacob Bachmeyer
Re: Some Changes to GNOME Security Tracking Jacob Bachmeyer (Aug 02)
Re: Removing dead code (was: Retrospective by 'gpg.fail' authors) Jacob Bachmeyer (Sep 17)
Jacob Walls
Django CVE-2026-48588, CVE-2026-53877, and CVE-2026-53878 Jacob Walls (Jul 07)
Jan Engelhardt
Re: CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android Jan Engelhardt (Jul 08)
Jan Schaumann
OpenSSL "HollowByte" DoS via attacker-controlled memory allocation size in glibc Jan Schaumann (Jul 18)
CVE-2026-46242 ("Bad Epoll") local privilege escalation on Linux, including Android Jan Schaumann (Jul 08)
432 Linux kernel CVEs Jan Schaumann (Jul 21)
Re: Some Changes to GNOME Security Tracking Jan Schaumann (Aug 06)
Re: 432 Linux kernel CVEs Jan Schaumann (Jul 21)
Jarek Potiuk
CVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key Jarek Potiuk (Sep 24)
Jay Faulkner
[OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423) Jay Faulkner (Jul 08)
[OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201) Jay Faulkner (Aug 05)
OSSN-0104: Ironic-Python-Agent may fallback to mDNS unexpectedly Jay Faulkner (Aug 03)
[OSSA-2026-026] Ironic: Insufficient Access Controls regarding parent/child nodes Jay Faulkner (Jul 08)
[OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented Jay Faulkner (Aug 13)
[OSSA-2026-008] ERRATA 2: Ironic Command Injection in IPMI Console Implementations Jay Faulkner (Aug 19)
Jean-Baptiste Onofré
CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching Jean-Baptiste Onofré (Sep 17)
Jeffrey Walton
Re: AI slops from Eve Jeffrey Walton (Sep 10)
Jens Geyer
CVE-2026-55970: Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() Jens Geyer (Jul 24)
CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport Jens Geyer (Jul 24)
CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification Jens Geyer (Jul 24)
CVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass Jens Geyer (Jul 24)
CVE-2026-45112: Apache Thrift: Unbounded Read Leading to Denial of Service Jens Geyer (Jul 24)
CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path Jens Geyer (Jul 24)
CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass Jens Geyer (Jul 24)
CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb Jens Geyer (Jul 24)
CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit Jens Geyer (Jul 24)
CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit Jens Geyer (Jul 24)
CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports Jens Geyer (Jul 24)
CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import Jens Geyer (Jul 24)
CVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit Jens Geyer (Jul 24)
CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() Jens Geyer (Jul 24)
CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() Jens Geyer (Jul 24)
Jeremy Harris
security release for Exim Jeremy Harris (Jul 22)
Jeremy Stanley
Re: Some Changes to GNOME Security Tracking Jeremy Stanley (Jul 31)
[OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE pending) Jeremy Stanley (Aug 13)
Re: [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE-2026-74248) errata 1 Jeremy Stanley (Aug 17)
Re: Some Changes to GNOME Security Tracking Jeremy Stanley (Jul 31)
Jeroen Roovers
Re: 33 Vulnerabilities in cJSON Jeroen Roovers (Jul 31)
Re: AI slops from Eve Jeroen Roovers (Sep 13)
Jerry Shao
CVE-2026-41042: Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter Jerry Shao (Jul 08)
CVE-2026-41041: Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints. Jerry Shao (Jul 12)
Jim Meyering
Re: CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access Jim Meyering (Aug 26)
Joe Krause
Re: AI slops from Eve Joe Krause (Sep 11)
Joerg Hoh
CVE-2026-94243: Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence Joerg Hoh (Sep 23)
CVE-2026-92001: Apache Sling XSS: Missing parser resource limits Joerg Hoh (Sep 23)
CVE-2026-73192: Apache Sling XSS: XSS possible through XSSAPI.getValidHref() Joerg Hoh (Sep 23)
CVE-2026-91999: Apache Sling XSS: Improper escaping in the XSS Webconsole plugin Joerg Hoh (Sep 23)
CVE-2026-91852: Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl Joerg Hoh (Sep 23)
CVE-2026-94251: Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource Joerg Hoh (Sep 23)
CVE-2026-91928: Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms Joerg Hoh (Sep 23)
Joe Stringer
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Joe Stringer (Jul 07)
John Haxby
Re: 432 Linux kernel CVEs John Haxby (Jul 22)
Re: 432 Linux kernel CVEs John Haxby (Jul 24)
Jonathan Brossard
Lean 4 kernel soundness bug: forging proofs via nested inductive projections (0 = 1 demonstrated) Jonathan Brossard (Aug 01)
Jongyoul Lee
CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 Jongyoul Lee (Jul 30)
CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling Jongyoul Lee (Jul 30)
CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction Jongyoul Lee (Jul 30)
CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition Jongyoul Lee (Jul 30)
Jose R Rodriguez
Re: Backports available - cBPF JIT spray hardening Jose R Rodriguez (Jul 30)
Re: Backports available - cBPF JIT spray hardening Jose R Rodriguez (Jul 30)
Juan Pablo Santos Rodríguez
CVE-2026-28814: Apache JSPWiki: Arbitrary Wiki Markup rendering due to lack of authentication Juan Pablo Santos Rodríguez (Jul 30)
CVE-2026-28813: Apache JSPWiki: JSON hijacking Juan Pablo Santos Rodríguez (Jul 30)
CVE-2026-28811: Apache JSPWiki: Error Handling Reveals Error Details Juan Pablo Santos Rodríguez (Jul 30)
CVE-2026-28812: Apache JSPWiki: UserManager does not sanity-check user database at startup Juan Pablo Santos Rodríguez (Jul 30)
CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing Juan Pablo Santos Rodríguez (Jul 30)
Julian Andres Klode
pandemic of incomplete error handling in the OpenSSL ecosystem Julian Andres Klode (Jul 03)
Junkai Xue
CVE-2026-57111: Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin Junkai Xue (Jul 08)
Jürg Billeter
CVE-2026-82331: Apache BuildStream: tar source extraction escape Jürg Billeter (Sep 23)
Kai Wan
CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP Kai Wan (Sep 03)
Kevin Backhouse
Exiv2 0.28.9 released Kevin Backhouse (Aug 30)
Kevin Guerroudj
Multiple vulnerabilities in Jenkins and Jenkins plugins Kevin Guerroudj (Sep 02)
Multiple vulnerabilities in Jenkins plugins Kevin Guerroudj (Sep 16)
Kevin Riggle
Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability Kevin Riggle (Jul 31)
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Kevin Riggle (Sep 18)
Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability Kevin Riggle (Aug 21)
Lenny Primak
CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate host Lenny Primak (Aug 30)
Lexi Groves (49016)
Re: Retrospective by 'gpg.fail' authors Lexi Groves (49016) (Sep 15)
Lin Jiapeng
CVE-2026-80530: Linux XFS EXCHANGE_RANGE reflink flag clearing leading to local privilege escalation Lin Jiapeng (Sep 03)
Li Yang
CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API Li Yang (Jul 13)
CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API Li Yang (Jul 13)
CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval Li Yang (Jul 13)
Loganaden Velvindron
Re: 432 Linux kernel CVEs Loganaden Velvindron (Jul 27)
Luppa
GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efi Luppa (Sep 13)
manizada
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill manizada (Sep 17)
CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution manizada (Sep 14)
OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability manizada (Jul 28)
Manuel Huber
CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy Manuel Huber (Aug 20)
Marco Benatto
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Marco Benatto (Aug 03)
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Marco Benatto (Jul 22)
Marcus Meissner
Re: 432 Linux kernel CVEs Marcus Meissner (Jul 22)
Mark Rose
[security] critical vulnerabilities patched in svxlink (RCE) Mark Rose (Jul 26)
Mark Thomas
CVE-2026-86243: Apache Tomcat Native: DoS via TLS handshake Mark Thomas (Sep 23)
CVE-2026-86247: Apache Tomcat Native: Client certificate requirements can be down-graded Mark Thomas (Sep 23)
CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control Mark Thomas (Aug 25)
CVE-2026-79677: Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout Mark Thomas (Sep 23)
CVE-2026-77762: Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request Mark Thomas (Sep 23)
CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset Mark Thomas (Aug 25)
CVE-2026-86246: Apache Tomcat Native: Insecure OpenSSL options enabled Mark Thomas (Sep 23)
CVE-2026-86350: Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up Mark Thomas (Sep 23)
CVE-2026-87022: Apache Tomcat: WebSocket message smuggling with per-message-deflate Mark Thomas (Sep 23)
CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session Mark Thomas (Aug 25)
CVE-2026-59084: Apache Tomcat: EncryptInterceptor requirements not clearly documented Mark Thomas (Jul 14)
CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint Mark Thomas (Aug 25)
CVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled Mark Thomas (Sep 23)
CVE-2026-75973: Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured Mark Thomas (Sep 23)
CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints Mark Thomas (Aug 25)
CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases Mark Thomas (Aug 25)
CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints Mark Thomas (Aug 25)
CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets Mark Thomas (Aug 25)
CVE-2026-73581: Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore Mark Thomas (Sep 23)
CVE-2026-78437: Apache Tomcat: HTTP/2 DoS via malformed request Mark Thomas (Sep 23)
CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete Mark Thomas (Aug 25)
CVE-2026-66299: Apache Tomcat: DoS via WebSocket chat example Mark Thomas (Jul 28)
CVE-2026-59083: Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass Mark Thomas (Jul 14)
CVE-2026-77791: Apache Tomcat: DoS via busy wait during WebSocket close Mark Thomas (Sep 23)
CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication Mark Thomas (Aug 25)
CVE-2026-78383: Apache Tomcat: AJP DoS via missing request body Mark Thomas (Sep 23)
CVE-2026-77756: Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests Mark Thomas (Sep 23)
CVE-2026-76183: Apache Tomcat: Bypass of security constraints for WebSocket endpoints Mark Thomas (Sep 23)
Martin Hecht
Re: AI slops from Eve Martin Hecht (Sep 11)
Masakazu Kitajo
CVE-2026-59173: Apache Traffic Server is vulnerable to stalled HTTP/2 flow-control Masakazu Kitajo (Jul 16)
Matthias Andree
CVE-2026-94184: some builds of fetchmail 6.6.6 and older vulnerable to remote code execution in NTLM authentication client (revised fetchmail-SA-2026-01) Matthias Andree (Sep 22)
Matthias Gerstner
OpenRGB: Remote System Compromise via Custom Network Protocol (CVE-2026-59682, CVE-2026-59683, CVE-2026-18794) Matthias Gerstner (Aug 25)
Re: SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10 Matthias Gerstner (Jul 17)
LACT: Polkit Authentication Bypass and Temporary File Handling Issues (CVE-2026-75037, CVE-2026-75038) Matthias Gerstner (Aug 31)
PortProtonQt: Custom Polkit Rule Allows Escalation of NetworkManager and UDisks2 Privileges (CVE-2026-59678) Matthias Gerstner (Jul 22)
SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10 Matthias Gerstner (Jul 15)
Matt Pavlovich
CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId Matt Pavlovich (Sep 08)
Maurits van Rees (Plone)
Plone security advisory 20260831 Maurits van Rees (Plone) (Aug 31)
Maxim Solodovnik
CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read Maxim Solodovnik (Jul 14)
Michael Orlitzky
Re: check_icmp (Monitoring Plugins): host-count overflow leads to heap buffer overflow in setuid-root binary Michael Orlitzky (Jul 01)
Michael Smith
CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token Michael Smith (Sep 08)
CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery Michael Smith (Sep 08)
CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF Michael Smith (Sep 08)
CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading Michael Smith (Sep 08)
Michał Kępień
ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321) Michał Kępień (Jul 22)
Mingyu Chen
CVE-2026-58319: Apache Doris: Improper Authentication in Frontend HTTP API Mingyu Chen (Jul 13)
Mr. Gatto
CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0) Mr. Gatto (Sep 09)
Natalia Bidart
Django CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920 Natalia Bidart (Aug 04)
Nathan Herz
[kubernetes] CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion Nathan Herz (Sep 23)
[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation Nathan Herz (Sep 23)
Nicki Křížek
ISC has disclosed fourteen vulnerabilities in BIND 9 (CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736) Nicki Křížek (Sep 16)
nightmare . yeah27
Re: Emacs zero-click local command execution via TRAMP nightmare . yeah27 (Aug 21)
Niko Oliveira
CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass Niko Oliveira (Sep 08)
Norbert Pócs
New OpenSSL Releases Norbert Pócs (Sep 22)
CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP Response Checking Norbert Pócs (Aug 05)
Oleg Kalnichevski
CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Oleg Kalnichevski (Aug 13)
CVE-2026-54399: Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration Oleg Kalnichevski (Jul 01)
CVE-2026-54428: Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK Oleg Kalnichevski (Jul 01)
CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM) Oleg Kalnichevski (Aug 13)
Ondrej Gajdusek
Foreman: multiple vulnerabilities fixed in 3.18.2 and 3.19.1 (CVE-2026-5135, CVE-2026-5136, CVE-2026-5138, CVE-2026-5142) Ondrej Gajdusek (Jul 07)
Or Peles
CVE-2026-43503: Analysis of the "DirtyClone" Linux LPE (Dirty Frag family variant) Or Peles (Jul 02)
Otto Moerbeek
PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues Otto Moerbeek (Jul 22)
PowerDNS Security Advisory 2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption Otto Moerbeek (Aug 06)
Re: PowerDNS Security Advisory 2026-10 for PowerDNS Recursor: Multiple issues Otto Moerbeek (Jul 23)
Pasquale Congiusti
CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace Pasquale Congiusti (Sep 10)
CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod Pasquale Congiusti (Sep 10)
CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects Pasquale Congiusti (Sep 10)
Paul Eggert
CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access Paul Eggert (Aug 23)
Paul Irwin
CVE-2026-47898: Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser Paul Irwin (Jul 02)
CVE-2026-47896: Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server Paul Irwin (Jul 02)
CVE-2026-47897: Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client Paul Irwin (Jul 02)
Paul Johnson
CVE-2026-13713: YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack Paul Johnson (Jul 16)
CVE-2026-87082: Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode Paul Johnson (Sep 22)
CVE-2026-87080: Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode Paul Johnson (Sep 22)
CVE-2026-87078: Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode Paul Johnson (Sep 22)
CVE-2026-74765: Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode Paul Johnson (Sep 22)
CVE-2026-87081: Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii Paul Johnson (Sep 22)
CVE-2026-57076: YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor Paul Johnson (Jul 16)
CVE-2016-15059: Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode Paul Johnson (Sep 22)
CVE-2026-57075: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec Paul Johnson (Jul 16)
CVE-2026-87079: Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode Paul Johnson (Sep 22)
CVE-2026-57077: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len Paul Johnson (Jul 16)
CVE-2026-74766: Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode Paul Johnson (Sep 22)
Pavel Sanda
LyX security advisory Pavel Sanda (Aug 17)
Pawan Gupta
Backports available - cBPF JIT spray hardening Pawan Gupta (Jul 29)
Re: Backports available - cBPF JIT spray hardening Pawan Gupta (Jul 30)
Pedro Henrique Oliveira dos Santos
CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence Pedro Henrique Oliveira dos Santos (Jul 27)
CVE-2026-66391: Apache Wicket: leaked and missing CSP headers Pedro Henrique Oliveira dos Santos (Jul 27)
Peter Gutmann
Re: 432 Linux kernel CVEs Peter Gutmann (Jul 23)
Re: Retrospective by 'gpg.fail' authors Peter Gutmann (Sep 13)
Re: Some Changes to GNOME Security Tracking Peter Gutmann (Aug 02)
Re: Some Changes to GNOME Security Tracking Peter Gutmann (Jul 31)
Re: Removing dead code (was: Retrospective by 'gpg.fail' authors) Peter Gutmann (Sep 18)
Re: Retrospective by 'gpg.fail' authors Peter Gutmann (Sep 16)
Re: Bouncy Castle 1.85 release fixes 32 CVEs Peter Gutmann (Aug 03)
Re: Some Changes to GNOME Security Tracking Peter Gutmann (Jul 30)
Re: 432 Linux kernel CVEs Peter Gutmann (Jul 21)
Re: 33 Vulnerabilities in cJSON Peter Gutmann (Jul 31)
Peter Hutterer
FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland Peter Hutterer (Jul 07)
FW: X.Org Security Advisory: multiple security issues in libXfont2 Peter Hutterer (Jul 07)
FW: X.Org Security Advisory: multiple security issues in libXfont2 Peter Hutterer (Aug 04)
Piotr Karwasz
CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS Piotr Karwasz (Aug 05)
CVE-2026-49844: Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson() Piotr Karwasz (Jul 10)
CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input Piotr Karwasz (Aug 05)
CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index Piotr Karwasz (Aug 05)
CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS Piotr Karwasz (Aug 05)
pro Err0r
CVE-2026-54161: NUT upsmon: remote OS command injection via ups.alarm in NOTIFYCMD - fixed in PR #3499 (affects 2.8.3–2.8.5) pro Err0r (Jul 01)
Przemyslaw Frasunek
Re: Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE) Przemyslaw Frasunek (Jul 24)
Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE) Przemyslaw Frasunek (Jul 23)
Qualys Security Advisory
Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Qualys Security Advisory (Jul 22)
RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) Qualys Security Advisory (Jul 22)
Re: LPE in snapd and other vulnerabilities Qualys Security Advisory (Jul 21)
Radhika Kundam
CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints Radhika Kundam (Jul 28)
Rafael Gonzaga
Fwd: Node.js security updates for all active release lines, June 2026 Rafael Gonzaga (Jul 29)
Rahul Vats
CVE-2026-49487: Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs Rahul Vats (Jul 07)
CVE-2026-48828: Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key Rahul Vats (Jul 07)
CVE-2026-48891: Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target Rahul Vats (Jul 07)
CVE-2026-75158: Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter Rahul Vats (Sep 21)
CVE-2026-33264: Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() Rahul Vats (Jul 07)
CVE-2026-49296: Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} Rahul Vats (Jul 07)
CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression) Rahul Vats (Sep 17)
CVE-2026-86473: Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry Rahul Vats (Sep 21)
CVE-2026-48892: Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options Rahul Vats (Jul 07)
CVE-2026-82355: Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation Rahul Vats (Sep 21)
Rainer Gerhards
rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv) Rainer Gerhards (Aug 20)
CVE-2026-61548: rsyslog mmpstrucdata stack overflow Rainer Gerhards (Jul 20)
rsyslog: mmpstrucdata denial of service fixed in 8.2606.0 Rainer Gerhards (Sep 20)
rsyslog imdtls permitted-peer authorization bypass Rainer Gerhards (Sep 22)
CVE-2026-78002: rsyslog RainerScript replace() heap buffer overflow Rainer Gerhards (Aug 29)
rsyslog v8.36.0 through v8.2606.0: imptcp regex-framing remote denial of service Rainer Gerhards (Jul 22)
Reid Sutherland
Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Reid Sutherland (Jul 27)
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Reid Sutherland (Jul 27)
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Reid Sutherland (Jul 28)
Richard Zowalla
CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns Richard Zowalla (Sep 11)
CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys Richard Zowalla (Sep 13)
CVE-2026-82426: Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location Richard Zowalla (Sep 13)
CVE-2026-82429: Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher Richard Zowalla (Sep 13)
CVE-2026-67211: Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer Richard Zowalla (Sep 11)
CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant Richard Zowalla (Sep 13)
CVE-2026-82427: Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name Richard Zowalla (Sep 13)
CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer Richard Zowalla (Sep 13)
CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC Richard Zowalla (Sep 13)
CVE-2026-63317: Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML Richard Zowalla (Jul 24)
CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs Richard Zowalla (Sep 13)
CVE-2026-43825: Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel Richard Zowalla (Jul 06)
CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins Richard Zowalla (Sep 13)
CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides Richard Zowalla (Sep 13)
CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page Richard Zowalla (Sep 13)
CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder Richard Zowalla (Sep 13)
CVE-2026-82428: Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys Richard Zowalla (Sep 13)
CVE-2026-82433: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI Richard Zowalla (Sep 13)
CVE-2026-82431: Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users Richard Zowalla (Sep 13)
Robbie Gemmell
CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery Robbie Gemmell (Aug 04)
CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication Robbie Gemmell (Aug 04)
CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded Robbie Gemmell (Aug 04)
CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Robbie Gemmell (Aug 04)
CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow Robbie Gemmell (Aug 04)
CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service Robbie Gemmell (Aug 04)
Robert Davies
HTSlib <= 1.23.1 Multiple vulnerabilities in file reading code Robert Davies (Jul 09)
Robert Lazarski
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data Robert Lazarski (Jul 27)
Robert Rothenberg
CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse Robert Rothenberg (Aug 15)
CVE-2026-85485: HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping Robert Rothenberg (Sep 08)
CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts Robert Rothenberg (Jul 20)
CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys Robert Rothenberg (Aug 21)
CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template Robert Rothenberg (Aug 13)
CVE-2026-14454: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed Robert Rothenberg (Jul 08)
CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time Robert Rothenberg (Jul 30)
CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg (Jul 04)
CVE-2026-56016: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources Robert Rothenberg (Jul 01)
CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains Robert Rothenberg (Jul 20)
CVE-2026-15743: Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable Robert Rothenberg (Aug 20)
CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token Robert Rothenberg (Aug 16)
CVE-2026-16634: TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99 Robert Rothenberg (Jul 24)
CVE-2026-19953: URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep Robert Rothenberg (Aug 31)
CVE-2026-85630: HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method Robert Rothenberg (Sep 08)
CVE-2026-18536: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP Robert Rothenberg (Aug 01)
Multiple vulnerabilities fixed in various Data::*::Shared modules for Perl Robert Rothenberg (Jul 21)
CVE-2026-13082: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets Robert Rothenberg (Jul 17)
CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL Robert Rothenberg (Sep 22)
CVE-2026-13401: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg (Jul 16)
CVE-2026-82309: Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries Robert Rothenberg (Sep 04)
Re: CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements Robert Rothenberg (Aug 31)
CVE-2025-15646: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion Robert Rothenberg (Jul 01)
CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse Robert Rothenberg (Aug 15)
CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document Robert Rothenberg (Aug 13)
CVE-2026-14895: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service Robert Rothenberg (Jul 07)
CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options Robert Rothenberg (Jul 25)
CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Robert Rothenberg (Jul 07)
CVE-2026-86287: Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths Robert Rothenberg (Sep 07)
CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for Robert Rothenberg (Aug 13)
CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text Robert Rothenberg (Jul 14)
Re: CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL Robert Rothenberg (Sep 23)
CVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index Robert Rothenberg (Jul 14)
CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON Robert Rothenberg (Aug 04)
CVE-2026-85484: HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping Robert Rothenberg (Sep 08)
CVE-2026-19872: HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message Robert Rothenberg (Sep 08)
CVE-2026-13397: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes Robert Rothenberg (Jul 16)
CVE-2026-6656: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks Robert Rothenberg (Jul 20)
CVE-2026-57073: HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead Robert Rothenberg (Jul 16)
CVE-2026-13089: OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify Robert Rothenberg (Jul 22)
CVE-2026-13410: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled Robert Rothenberg (Jul 17)
CVE-2026-9537: Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison Robert Rothenberg (Jul 17)
CVE-2026-72888: Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require Robert Rothenberg (Aug 16)
CVE-2026-12740: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter Robert Rothenberg (Jul 04)
CVE-2026-72889: Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify Robert Rothenberg (Aug 19)
CVE-2026-13577: Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable Robert Rothenberg (Jul 20)
CVE-2026-64193: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR Robert Rothenberg (Jul 20)
CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Robert Rothenberg (Jul 07)
CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements Robert Rothenberg (Aug 31)
CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone Robert Rothenberg (Sep 24)
Re: CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone Robert Rothenberg (Sep 24)
CVE-2026-56015: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length Robert Rothenberg (Jul 03)
CVE-2026-57074: XML::Bare versions through 0.53 for Perl have an unbounded character lookahead Robert Rothenberg (Jul 16)
CVE-2026-78183: DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float Robert Rothenberg (Aug 23)
CVE-2026-19565: Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey Robert Rothenberg (Aug 23)
Security Considerations for Statsd Clients Robert Rothenberg (Jul 06)
CVE-2026-78030: DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM Robert Rothenberg (Sep 19)
CVE-2026-97230: IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL Robert Rothenberg (Sep 24)
CVE-2026-14741: HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date Robert Rothenberg (Jul 17)
CVE-2026-7017: HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets Robert Rothenberg (Jul 07)
CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row Robert Rothenberg (Jul 14)
CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table Robert Rothenberg (Sep 07)
CVE-2026-75589: Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify Robert Rothenberg (Aug 19)
CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template Robert Rothenberg (Aug 13)
CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check Robert Rothenberg (Jul 30)
CVE-2026-17552: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call Robert Rothenberg (Jul 27)
CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call Robert Rothenberg (Aug 04)
CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp Robert Rothenberg (Jul 24)
CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location Robert Rothenberg (Jul 14)
CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename Robert Rothenberg (Aug 13)
Roman Fiedler
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Roman Fiedler (Sep 20)
Rostislav
Multiple vulnerabilities in ntfs-3g Rostislav (Jul 15)
Vulnerabilities in ntfs-3g Rostislav (Sep 23)
Russ Allbery
Re: Some Changes to GNOME Security Tracking Russ Allbery (Aug 02)
Re: Some Changes to GNOME Security Tracking Russ Allbery (Jul 31)
Sage McTaggart
Ceph 20.2.4 and Ceph 19.2.6 are released with 4 security fixes. Sage McTaggart (Aug 19)
Salvatore Bonaccorso
Re: Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released Salvatore Bonaccorso (Sep 05)
Re: Vulnerabilities fixed in libxml2-2.15.4 Salvatore Bonaccorso (Sep 05)
Re: pcre2 version 10.48 released with security fixes Salvatore Bonaccorso (Sep 05)
Re: Vulnerability fixes in util-linux-2.42.3 Salvatore Bonaccorso (Sep 05)
Sam James
Re: Suricata 8.0.7 released with 67 vulnerabilities fixed Sam James (Sep 19)
Fwd: Security vulnerabilities fixed in WeeChat 4.10.1 Sam James (Sep 05)
Re: Fwd: [Announce] Libgcrypt 1.12.3 released Sam James (Sep 02)
Multiple vulnerabilities fixed in libgit2-1.9.5, 1.9.7 Sam James (Aug 19)
Re: libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requested Sam James (Aug 19)
XSS vulnerability in <ansi2html-1.9.4 Sam James (Sep 24)
Fwd: XZ Utils 5.8.4 and a security fix Sam James (Sep 09)
Fwd: [mapserver-announce] security release available: MapServer 8.6.6 Sam James (Sep 06)
Re: Fwd: Tor Project Forum: Security Release 0.4.9.12 Sam James (Sep 23)
Fwd: [pfx] Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27 Sam James (Aug 19)
Vulnerability fixes in util-linux-2.42.3 Sam James (Sep 04)
Fwd: [Announce] Libgcrypt 1.12.3 released Sam James (Aug 31)
Vulnerabilities fixed in libxml2-2.15.4 Sam James (Sep 04)
Security fixes in libfuse-3.18.3 Sam James (Sep 08)
Fwd: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations Sam James (Sep 12)
Re: Re: Emacs zero-click local command execution via TRAMP Sam James (Aug 23)
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Sam James (Jul 28)
libksba-1.8.1 fixes a possible CMS parser infinite loop Sam James (Aug 31)
Retrospective by 'gpg.fail' authors Sam James (Sep 12)
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Sam James (Jul 27)
GNU Emacs vulnerability upon opening arbitrary file Sam James (Aug 19)
Fwd: Tor Project Forum: Security Release 0.4.9.12 Sam James (Sep 08)
Re: CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL Sam James (Sep 22)
Fwd: Tor Project Forum: Security Release 0.4.9.13 Sam James (Sep 23)
Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations Sam James (Sep 12)
Re: Retrospective by 'gpg.fail' authors Sam James (Sep 15)
Samuel Page
FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstrated Samuel Page (Sep 01)
SBA Research Security Advisory
[SBA-ADV-20260128-04] CVE-2026-16970: DFIR-IRIS 2.4.26 and possibly others Insufficient Logout Implementation SBA Research Security Advisory (Jul 30)
[SBA-ADV-20260128-02] CVE-2026-16971 CVE-2026-18362: DFIR-IRIS 2.4.26 and possibly others Missing Brute Force Protection SBA Research Security Advisory (Jul 30)
[SBA-ADV-20260126-01] CVE-2026-16969 CVE-2026-18360 CVE-2026-18361: DFIR-IRIS 2.4.26 and possibly others Stored XSS SBA Research Security Advisory (Jul 30)
Sean Whitton
Emacs zero-click local command execution via TRAMP Sean Whitton (Aug 21)
Emacs arbitrary code execution: incomplete fix for CVE-2024-53920 Sean Whitton (Sep 14)
Re: Emacs zero-click local command execution via TRAMP Sean Whitton (Aug 26)
Sebastian Nagel
CVE-2026-41871: Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API) Sebastian Nagel (Sep 08)
CVE-2026-41870: Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API) Sebastian Nagel (Sep 08)
CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API) Sebastian Nagel (Sep 08)
Sebastian Pipping
Re: XSS vulnerability in <ansi2html-1.9.4 Sebastian Pipping (Sep 25)
Re: Some Changes to GNOME Security Tracking Sebastian Pipping (Jul 31)
Re: Some Changes to GNOME Security Tracking Sebastian Pipping (Jul 31)
libexpat 2.8.5 fixes CVE-2026-93990 (malformed UTF-16 smuggling) Sebastian Pipping (Sep 22)
libexpat 2.8.4 fixes 4 vulnerabilities Sebastian Pipping (Aug 31)
Re: Some Changes to GNOME Security Tracking Sebastian Pipping (Aug 03)
Sergei G
rust-in-peace: results from agent-assisted Rust OSS vulnerability research Sergei G (Aug 06)
Shahar Epstein
CVE-2026-49297: Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator) Shahar Epstein (Jul 04)
CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`) Shahar Epstein (Jul 28)
Sheng Wu
CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057) Sheng Wu (Sep 03)
Siddhesh Poyarekar
The GNU C Library security advisory update for 2026-09-10 Siddhesh Poyarekar (Sep 10)
The GNU C Library security advisory update for 2026-08-27 Siddhesh Poyarekar (Aug 27)
Simon McVittie
xdg-dbus-proxy 0.1.9 fixes sandbox escape CVE-2026-94422 Simon McVittie (Sep 23)
Re: 33 Vulnerabilities in cJSON Simon McVittie (Jul 31)
bubblewrap 0.12.0 fixes writes outside sandbox Simon McVittie (Aug 27)
Re: Flatpak 1.18.1 fixes multiple vulnerabilities Simon McVittie (Sep 23)
Re: bubblewrap 0.12.0 fixes writes outside sandbox Simon McVittie (Sep 09)
Re: bubblewrap 0.12.0 fixes writes outside sandbox Simon McVittie (Sep 22)
Re: xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast message filtering bypass Simon McVittie (Sep 22)
Re: CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX Simon McVittie (Sep 26)
Re: new af_alg exploit in the wild? Simon McVittie (Jul 14)
Re: Flatpak 1.18.1 fixes multiple vulnerabilities Simon McVittie (Sep 22)
Soatok Dreamseeker
Re: Retrospective by 'gpg.fail' authors Soatok Dreamseeker (Sep 16)
SOFIA ETCHEPARE DARONCO
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill SOFIA ETCHEPARE DARONCO (Sep 18)
Solar Designer
Re: Some Changes to GNOME Security Tracking Solar Designer (Aug 02)
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer (Jul 03)
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer (Jul 07)
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD Solar Designer (Jul 27)
BusyBox dpkg applet: OS command injection Solar Designer (Aug 23)
Re: new af_alg exploit in the wild? Solar Designer (Jul 13)
Re: AI slops from Eve Solar Designer (Sep 13)
Re: AI slops from Eve Solar Designer (Sep 11)
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Solar Designer (Jul 07)
Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Solar Designer (Jul 08)
Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releases Solar Designer (Sep 09)
Re: AI slops from Eve Solar Designer (Sep 11)
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass Solar Designer (Jul 03)
Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Solar Designer (Aug 06)
Re: Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540) Solar Designer (Aug 23)
Re: CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel Solar Designer (Jul 22)
Re: Skillable SCORM launch: userId parameter not validated against session token allows allocation bypass and cross-user DoS Solar Designer (Jul 12)
AI slop "Combined chain advisory — fallback.efi/SBAT/memdisk bypass" Solar Designer (Aug 17)
Exim Security Release 4.100.1 Solar Designer (Sep 18)
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage Solar Designer (Jul 07)
AI slops from Eve Solar Designer (Sep 09)
Re: CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access Solar Designer (Aug 24)
Souiri Anas
croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3) Souiri Anas (Aug 14)
croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3) Souiri Anas (Aug 14)
Stefan Bodewig
CVE-2026-26032: Apache Ivy: PackagerResolver path traversal vulnerability Stefan Bodewig (Jul 15)
CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write Stefan Bodewig (Sep 06)
Steffen Nurpmeso
Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 24)
Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 21)
Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 22)
Stephan Verbücheln
Re: 432 Linux kernel CVEs Stephan Verbücheln (Jul 22)
Stig Palmquist
CVE-2026-73639: Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8 Stig Palmquist (Sep 17)
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk Stig Palmquist (Jul 13)
CVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record Stig Palmquist (Jul 13)
CVE-2026-13708: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol Stig Palmquist (Jul 06)
CVE-2026-49146: App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc Stig Palmquist (Jul 08)
CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass Stig Palmquist (Aug 13)
CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler Stig Palmquist (Sep 21)
CVE-2026-73638: Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd Stig Palmquist (Sep 17)
CVE-2026-93710: Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks Stig Palmquist (Sep 21)
CVE-2026-93012: Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe Stig Palmquist (Sep 21)
CVE-2026-49145: App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc Stig Palmquist (Jul 08)
CVE-2026-15747: Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle Stig Palmquist (Jul 14)
CVE-2026-93711: Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array Stig Palmquist (Sep 21)
CVE-2026-93019: Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read Stig Palmquist (Sep 18)
CVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack Stig Palmquist (Jul 13)
CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler Stig Palmquist (Sep 21)
CVE-2026-82560: Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width Stig Palmquist (Sep 19)
CVE-2026-49147: App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes Stig Palmquist (Jul 08)
CVE-2026-13705: Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle Stig Palmquist (Jul 06)
CVE-2026-14803: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder Stig Palmquist (Jul 05)
CVE-2026-93018: Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p Stig Palmquist (Sep 18)
Sultan Alsawaf
Re: 432 Linux kernel CVEs Sultan Alsawaf (Jul 24)
Sumit Chakraborty
libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requested Sumit Chakraborty (Aug 16)
Syed
Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely Syed (Aug 26)
Re: Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely Syed (Aug 26)
Szymon Janc
CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation Szymon Janc (Jul 24)
CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request Szymon Janc (Jul 24)
CVE-2026-46452: Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure Szymon Janc (Jul 24)
CVE-2026-45811: Apache NimBLE: Buffer overflow in socket HCI transport Szymon Janc (Jul 24)
CVE-2026-45812: Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler Szymon Janc (Jul 24)
CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler Szymon Janc (Jul 24)
Terence Monteiro
CVE-2026-57821: Apache Fineract: Office list: SQL Injection via Subquery in orderBy Terence Monteiro (Jul 14)
CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure Terence Monteiro (Jul 14)
CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint Terence Monteiro (Jul 14)
Thomas Ward
Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability Thomas Ward (Jul 31)
RE: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability Thomas Ward (Jul 31)
Thomas Wolf
CVE-2026-56452: Apache MINA SSHD: Path traversal in SCP file reception Thomas Wolf (Jul 20)
CVE-2026-56624: Apache MINA SSHD: SSH certificate options lack validations Thomas Wolf (Jul 20)
CVE-2026-56623: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows Thomas Wolf (Jul 20)
CVE-2026-58624: Apache MINA SSHD: Remote execution of JGit commands can write files on the server Thomas Wolf (Jul 20)
Tim Allison
CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser Tim Allison (Jul 30)
CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false Tim Allison (Jul 30)
Timothy A. Bish
CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Timothy A. Bish (Aug 04)
CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion Timothy A. Bish (Aug 04)
CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication Timothy A. Bish (Aug 04)
CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow Timothy A. Bish (Aug 04)
CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service Timothy A. Bish (Aug 04)
CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication Timothy A. Bish (Aug 04)
CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded Timothy A. Bish (Aug 04)
CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery Timothy A. Bish (Aug 04)
CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery Timothy A. Bish (Aug 04)
CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow Timothy A. Bish (Aug 04)
CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded Timothy A. Bish (Aug 04)
Timothy Legge
CVE-2026-95811: Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it Timothy Legge (Sep 24)
CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor Timothy Legge (Sep 06)
CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret Timothy Legge (Sep 24)
CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends Timothy Legge (Aug 16)
CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session Timothy Legge (Aug 25)
CVE-2026-14570: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery Timothy Legge (Jul 04)
CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step Timothy Legge (Sep 06)
CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them Timothy Legge (Aug 22)
CVE-2026-75870: Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret Timothy Legge (Aug 22)
2 CVEs Crypt::OpenSSL::X509 versions before 2.1.3 Timothy Legge (Jul 13)
CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record Timothy Legge (Sep 02)
CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send Timothy Legge (Aug 15)
CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter Timothy Legge (Aug 19)
CVE-2026-92288: Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party Timothy Legge (Sep 24)
CVE-2026-75922: Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line Timothy Legge (Aug 23)
CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically Timothy Legge (Aug 25)
Tomas Hoger
Re: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920 Tomas Hoger (Sep 21)
Re: GNU Emacs vulnerability upon opening arbitrary file Tomas Hoger (Sep 23)
Re: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920 Tomas Hoger (Sep 23)
Tomas Mraz
OpenSSL Security Advisory [25th August 2026] Tomas Mraz (Aug 25)
OpenSSL Security Advisory Tomas Mraz (Aug 13)
t.preissl
Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293) t.preissl (Aug 28)
Tristan
Re: GNU Inetutils talkd buffer overflow with long DNS names. Tristan (Aug 18)
TvT
Re: Bouncy Castle 1.85 release fixes 32 CVEs TvT (Aug 05)
Valtteri Vuorikoski
CVE-2026-22068+more: multiple vulnerabilities in Apache Traffic Server prior to 9.2.15/10.1.4 Valtteri Vuorikoski (Jul 30)
CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36 Valtteri Vuorikoski (Sep 10)
CVE-2026-54432+more: Roundcube XSS/SSRF/etc prior to 1.6.17/1.7.2 Valtteri Vuorikoski (Jul 22)
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Valtteri Vuorikoski (Sep 18)
Vega Agent
Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1 Vega Agent (Jul 09)
Victor Julien
Re: Suricata 8.0.7 released with 67 vulnerabilities fixed Victor Julien (Sep 19)
Vincent Beck
CVE-2026-86792: Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration Vincent Beck (Sep 15)
CVE-2026-82311: Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false Vincent Beck (Sep 15)
CVE-2026-58065: Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification Vincent Beck (Jul 13)
CVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated Vincent Beck (Sep 15)
CVE-2026-76187: Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT Vincent Beck (Sep 15)
CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access Vincent Beck (Sep 15)
CVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions Vincent Beck (Sep 15)
CVE-2026-86465: Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key Vincent Beck (Sep 15)
CVE-2026-76186: Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity Vincent Beck (Sep 15)
CVE-2026-59245: Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision) Vincent Beck (Jul 13)
Vincent Lefevre
Re: new af_alg exploit in the wild? Vincent Lefevre (Jul 13)
Volodymyr Siedlecki
CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability Volodymyr Siedlecki (Sep 16)
CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing Volodymyr Siedlecki (Sep 16)
Wenjun Ruan
CVE-2026-57590: Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations Wenjun Ruan (Sep 24)
Werner Koch
Re: Retrospective by 'gpg.fail' authors Werner Koch (Sep 16)
Re: Retrospective by 'gpg.fail' authors Werner Koch (Sep 15)
Re: Retrospective by 'gpg.fail' authors Werner Koch (Sep 17)
Re: Fwd: [Announce] Libgcrypt 1.12.3 released Werner Koch (Aug 31)
Willem Toorop
NSD 4.15.1 security release Willem Toorop (Aug 28)
William Carrier
Re: graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS William Carrier (Aug 29)
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS from a single syntax error William Carrier (Aug 29)
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via full-schema "did you mean" suggestion scan William Carrier (Aug 29)
Wongi Lee
CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel Wongi Lee (Jul 20)
Xen . org security team
Xen Security Advisory 508 v2 - pygrub is only supported in de-privileged mode Xen . org security team (Jul 28)
Xen Security Advisory 506 v2 (CVE-2026-62433) - correct buffer checks for DM_OP hypercalls Xen . org security team (Jul 28)
Xen Security Advisory 505 v2 (CVE-2026-62432) - evtchn: Race between FIFO expand and reset Xen . org security team (Jul 28)
Xen Security Advisory 504 v2 (CVE-2026-62431) - Viridian STIMER division by zero Xen . org security team (Jul 28)
Xen Security Advisory 509 v3 (CVE-2026-62437) - x86: DMs may cause mem leak by IRQ binding Xen . org security team (Sep 08)
Xen Security Advisory 499 v2 (CVE-2026-62426,CVE-2026-62427) - sysctl and platform-op locks open to abuse Xen . org security team (Jul 28)
Xen Security Advisory 503 v2 (CVE-2026-62430) - x86: Out-of-bounds read in vRTC emulation Xen . org security team (Jul 28)
Xen Security Advisory 496 v2 (CVE-2026-42492) - vIRQ event channel binding may break Xenstore Xen . org security team (Jul 28)
Xen Security Advisory 497 v2 (CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425) - buffer overruns in libfsimage iso9660 handling Xen . org security team (Jul 28)
Xen Security Advisory 511 v3 (CVE-2026-79603) - Unconditionally do TLB flushing ahead of page scrubbing Xen . org security team (Sep 08)
Xen Security Advisory 500 v2 (CVE-2026-62428) - grant-table: type confusion in grant-copy Xen . org security team (Jul 28)
Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdisk Xen . org security team (Sep 08)
Xen Security Advisory 510 v3 (CVE-2026-79602) - x86: improper handling of HVM emulation return codes Xen . org security team (Sep 08)
Xen Security Advisory 495 v2 (CVE-2026-42493) - x86 shadow paging is deprecated Xen . org security team (Jul 28)
Xen Security Advisory 498 v2 (CVE-2026-42491) - XAPI: Missing TLS verification in some SDKs Xen . org security team (Jul 14)
Xen Security Advisory 501 v4 (CVE-2026-62435,CVE-2026-62436) - grant-table: version change racing with other operations Xen . org security team (Jul 28)
Xen Security Advisory 512 v3 (CVE-2026-79604) - oxenstored: Unbounded accumulation of watches Xen . org security team (Sep 08)
Xen Security Advisory 507 v2 (CVE-2026-62434) - PoD: Don't try to reclaim special pages Xen . org security team (Jul 28)
Xen Security Advisory 502 v3 (CVE-2026-62429) - vNUMA domain cleanup may race other operations Xen . org security team (Jul 28)
xylove21
[CVE request] Apache Kafka OAUTHBEARER authentication bypass via signed JWT clock skew (vulnerable 4.0.0 - 4.0.x, no maintainer response in 7 days) xylove21 (Jul 03)
Wasm OCI Image Fetcher Bearer Realm SSRF Bypass xylove21 (Jul 03)
[CVE request] Apache APISIX 3.16.0 JWT-Auth Algorithm Confusion (Authentication Bypass, CVSS 9.8 CRITICAL) — no maintainer response in 9 days via GHSA Triage xylove21 (Jul 03)
[CONFIDENTIAL] cert-manager v1.15-v1.17+main — Reflected SSRF via Issuer.spec.vault.server (CVSS 7.2 HIGH) xylove21 (Jul 03)
yan xu
Re: Wasm OCI Image Fetcher Bearer Realm SSRF Bypass yan xu (Jul 07)
Yorgos Thessalonikefs
Unbound: 1.25.2 addresses multiple CVE items Yorgos Thessalonikefs (Jul 22)
Unbound: 1.26.1 addresses multiple CVE items Yorgos Thessalonikefs (Sep 16)
Yuan Tan
Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more Yuan Tan (Sep 07)
Yu Qi
CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs Yu Qi (Jul 12)
Yves-Alexis Perez
Re: Some Changes to GNOME Security Tracking Yves-Alexis Perez (Aug 03)
