Messages by Date
-
2026/04/10
[oss-security] CVE-2026-34480: Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
2026/04/10
[oss-security] CVE-2026-40023: Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
2026/04/10
[oss-security] CVE-2026-40021: Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
2026/04/10
[oss-security] CVE-2026-34481: Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Piotr Karwasz
-
2026/04/10
[oss-security] CVE-2026-34479: Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Piotr Karwasz
-
2026/04/10
[oss-security] CVE-2026-34478: Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Piotr Karwasz
-
2026/04/10
[oss-security] CVE-2026-34477: Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Piotr Karwasz
-
2026/04/10
Re: [oss-security] systemd-journald in systemd 259 does not escape characters in emerg messages that are wall'd to other user's terminals
Vincent Lefevre
-
2026/04/10
[oss-security] CVE-2026-4631 [cockpit] Unauthenticated remote code execution due to SSH command-line argument injection
Jelle van der Waa
-
2026/04/09
Re: [oss-security] Go 1.26.2 and Go 1.25.9 are released with 10 security fixes
Solar Designer
-
2026/04/09
Re: [oss-security] X41 Advisory X41-2026-001: Guardrail Sandbox Escape in LiteLLM
Solar Designer
-
2026/04/09
Re: [oss-security] systemd-journald in systemd 259 does not escape characters in emerg messages that are wall'd to other user's terminals
Aaron Rainbolt
-
2026/04/09
[oss-security] [OSSA-2026-006] OpenStack Skyline: DOM-based XSS in Skyline Console via unsanitized instance console log rendering (CVE-2026-pending)
Goutham Pacha Ravi
-
2026/04/09
[oss-security] CVE-2026-34500: Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-34487: Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-34486: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-34483: Apache Tomcat: Incomplete escaping of JSON access logs
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-32990: Apache Tomcat: Fix for CVE-2025-66614 is incomplete
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-29129: Apache Tomcat: TLS cipher order is not preserved
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-29146: Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-29145: Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-25854: Apache Tomcat: Occasionally open redirect
Mark Thomas
-
2026/04/09
[oss-security] CVE-2026-24880: Apache Tomcat: Request smuggling via invalid chunk extension
Mark Thomas
-
2026/04/09
[oss-security] Re: [libc musl] - Algorithmic complexity DoS in iconv GB18030 decoder
Jens Jarl Nestén Hansen-Nord
-
2026/04/09
[oss-security] CVE-2026-40046: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
Christopher L. Shannon
-
2026/04/09
[oss-security] CVE-2026-39304: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
Christopher L. Shannon
-
2026/04/09
[oss-security] CVE-2025-57735: Apache Airflow: Airflow Logout Not Invalidating JWT
Rahul Vats
-
2026/04/09
Re: [oss-security] libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Tianyu Chen
-
2026/04/09
Re: [oss-security] libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Andrew G. Morgan
-
2026/04/09
Re: [oss-security] systemd-journald in systemd 259 does not escape characters in emerg messages that are wall'd to other user's terminals
Salvatore Bonaccorso
-
2026/04/09
[oss-security] CVE-2026-34020: Apache OpenMeetings: Login Credentials Passed via GET Query Parameters
Maxim Solodovnik
-
2026/04/09
[oss-security] CVE-2026-33266: Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt
Maxim Solodovnik
-
2026/04/09
[oss-security] CVE-2026-33005: Apache OpenMeetings: Insufficient checks in FileWebService
Maxim Solodovnik
-
2026/04/09
[oss-security] CVE-2026-34538: Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
Rahul Vats
-
2026/04/09
Re: [oss-security] 4 security fixes in Flatpak, including critical CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context
Simon McVittie
-
2026/04/08
Re: [oss-security] libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Solar Designer
-
2026/04/08
Re: [oss-security] libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Andrew G. Morgan
-
2026/04/08
[oss-security] Re: systemd-journald in systemd 259 does not escape characters in emerg messages that are wall'd to other user's terminals
Aaron Rainbolt
-
2026/04/08
Re: [oss-security] libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Solar Designer
-
2026/04/08
[oss-security] lftp 4.9.3 does not filter non-printable characters in the output to the terminal
Vincent Lefevre
-
2026/04/08
Re: [oss-security] Re: Heads-up: Upcoming Samba security releases (2026-04-09)
Douglas Bagnall
-
2026/04/08
[oss-security] 4 security fixes in Flatpak, including critical CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context
Solar Designer
-
2026/04/08
[oss-security] libpng 1.6.57: Use-after-free vulnerability fixed: CVE-2026-34757
Cosmin Truta
-
2026/04/08
[oss-security] X41 Advisory X41-2026-001: Guardrail Sandbox Escape in LiteLLM
Markus Vervier
-
2026/04/08
[oss-security] Go 1.26.2 and Go 1.25.9 are released with 10 security fixes
Alan Coopersmith
-
2026/04/08
[oss-security] Re: libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Andrew G. Morgan
-
2026/04/08
[oss-security] Re: [EXTERN] Re: [oss-security] Multiple CVEs disclosed in CUPS
Schwedas, Sven
-
2026/04/08
[oss-security] PyCA cryptography 46.0.7 released, fixes CVE-2026-39892
Alan Coopersmith
-
2026/04/08
Re: [oss-security] Fwd: [siren] Severity: High – Potential Malicious Campaign Underway Targeting Open Source Developers via Slack
Stuart D Gathman
-
2026/04/08
[oss-security] CVE-2026-5082: Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id
Robert Rothenberg
-
2026/04/08
[oss-security] CVE-2026-5083: Ado::Sessions versions through 0.935 for Perl generates insecure session ids
Robert Rothenberg
-
2026/04/07
Re: [oss-security] Axios Supply-Chain Attack [v1.14.1] [0.30.4] --> plain-crypto-js [4.2.0][4.2.1]
Solar Designer
-
2026/04/07
[oss-security] Fwd: [siren] Severity: High – Potential Malicious Campaign Underway Targeting Open Source Developers via Slack
Solar Designer
-
2026/04/07
Re: [oss-security] Multiple CVEs disclosed in CUPS
Peter Gutmann
-
2026/04/07
[oss-security] Multiple CVEs disclosed in CUPS
Alan Coopersmith
-
2026/04/07
[oss-security] systemd-journald in systemd 259 does not escape characters in emerg messages that are wall'd to other user's terminals
Aaron Rainbolt
-
2026/04/07
Re: [oss-security] libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Christian Göttsche
-
2026/04/07
[oss-security] CVE-2026-35554: Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Manikumar
-
2026/04/07
[oss-security] [vim-security] Netbeans command injection in Vim < v9.2.0316
Christian Brabandt
-
2026/04/07
[oss-security] CVE-2026-27315: Apache Cassandra: cqlsh history sensitive information leak
Michael Semb Wever
-
2026/04/07
[oss-security] Django CVE-2026-3902, CVE-2026-4277, CVE-2026-4292, CVE-2026-33033, and CVE-2026-33034
Jacob Walls
-
2026/04/07
[oss-security] [OSSA-2026-005] Keystone: Restricted application credentials can create EC2 credentials (CVE-2026-33551)
Jeremy Stanley
-
2026/04/07
[oss-security] OpenSSL Security Advisory
Tomas Mraz
-
2026/04/07
[oss-security] CASSANDRA-21202: CVE-2026-32588: Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
Michael Semb Wever
-
2026/04/07
[oss-security] CVE-2026-27314: Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
Michael Semb Wever
-
2026/04/07
[oss-security] Re: Heads-up: Upcoming Samba security releases (2026-04-09)
Douglas Bagnall
-
2026/04/07
[oss-security] libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Andrew G. Morgan
-
2026/04/07
Re: [oss-security] Announce: OpenSSH 10.3 released
Demi Marie Obenour
-
2026/04/07
Re: [oss-security] Announce: OpenSSH 10.3 released
Damien Miller
-
2026/04/07
Re: [oss-security] Announce: OpenSSH 10.3 released
Demi Marie Obenour
-
2026/04/06
[oss-security] CVE-2026-33227: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ Web: Improper Limitation of a Pathname to a Restricted Directory
Christopher L. Shannon
-
2026/04/06
[oss-security] CVE-2026-34197: Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Christopher L. Shannon
-
2026/04/06
Re: [oss-security] Announce: OpenSSH 10.3 released
Damien Miller
-
2026/04/05
[oss-security] Heads-up: Upcoming Samba security releases (2026-04-09)
Douglas Bagnall
-
2026/04/03
Re: [oss-security] Announce: OpenSSH 10.3 released
Demi Marie Obenour
-
2026/04/03
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Salvatore Bonaccorso
-
2026/04/03
Re: [oss-security] Re: Multiple vulnerabilities in AppArmor
Salvatore Bonaccorso
-
2026/04/03
Re: [oss-security] Announce: OpenSSH 10.3 released
Salvatore Bonaccorso
-
2026/04/03
Re: [oss-security] Announce: OpenSSH 10.3 released
Agostino Sarubbo
-
2026/04/02
Re: [oss-security] [libc musl] - Algorithmic complexity DoS in iconv GB18030 decoder
Rich Felker
-
2026/04/02
Re: [oss-security] [libc musl] - Algorithmic complexity DoS in iconv GB18030 decoder
Rich Felker
-
2026/04/02
[oss-security] [libc musl] - Algorithmic complexity DoS in iconv GB18030 decoder
Jens Jarl Nestén Hansen-Nord
-
2026/04/02
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Solar Designer
-
2026/04/02
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Christian Brabandt
-
2026/04/02
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
David A. Wheeler
-
2026/04/02
[oss-security] [ANNOUNCE] ATS is vulnerable to HTTP requests with body
Masakazu Kitajo
-
2026/04/02
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Tianyu Chen
-
2026/04/02
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Christian Brabandt
-
2026/04/02
[oss-security] Announce: OpenSSH 10.3 released
Damien Miller
-
2026/04/02
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Christian Brabandt
-
2026/04/01
[oss-security] FW: libinput Security Advisory: multiple security issues in libinput
Peter Hutterer
-
2026/04/01
[oss-security][CVE-2026-5271] Python install manager script aliases search path hijack
Alan Coopersmith
-
2026/04/01
[oss-security] [vim-security] Path traversal issue with zip.vim and special crafted zip archives in Vim < v9.2.0280
Christian Brabandt
-
2026/04/01
[oss-security] Re: Multiple vulnerabilities in AppArmor
Greg KH
-
2026/04/01
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Christian Brabandt
-
2026/04/01
Re: [oss-security] [vim-security] Vim modeline bypass via various options affects Vim < 9.2.0276
Salvatore Bonaccorso
-
2026/03/31
[oss-security] [ADVISORY] CVE-2026-34956: Open vSwitch: Invalid memory access in conntrack FTP alg.
Aaron Conole
-
2026/03/31
[oss-security] Fwd: XZ Utils 5.8.3 and a security fix
Sam James
-
2026/03/31
[oss-security] [vim-security] Vim modeline bypass via various options affects Vim < 9.2.0276
Christian Brabandt
-
2026/03/31
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
David A. Wheeler
-
2026/03/31
[oss-security] Re: Multiple vulnerabilities in AppArmor
Greg KH
-
2026/03/31
[oss-security] Fwd: CVE-2026-5087: PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely
Robert Rothenberg
-
2026/03/31
[oss-security] CVE-2024-14030: Sereal::Decoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library
Robert Rothenberg
-
2026/03/31
[oss-security] CVE-2024-14031: Sereal::Encoder versions from 4.000 through 4.009_002 for Perl is vulnerable to a buffer overwrite flaw in the Zstandard library
Robert Rothenberg
-
2026/03/31
[oss-security] CVE-2025-15618: Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key
Robert Rothenberg
-
2026/03/31
[oss-security] Axios Supply-Chain Attack [v1.14.1] [0.30.4] --> plain-crypto-js [4.2.0][4.2.1]
Michael Straßberger
-
2026/03/31
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Tianyu Chen
-
2026/03/31
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Christian Brabandt
-
2026/03/31
[oss-security] PowerDNS Security Advisory 2026-02 for DNSdist: Multiple issues
Remi Gacogne
-
2026/03/31
[oss-security] Re: Multiple vulnerabilities in AppArmor
John Johansen
-
2026/03/30
Re: [oss-security] KVM shadow EPT stale rmap use-after-free
Solar Designer
-
2026/03/30
[oss-security] CVE-2026-32794: Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
Jens Scheffler
-
2026/03/30
[oss-security] pyca/cryptography: CVE-2026-34073: X.509: bypass of name constraints on wildcard SANs with matching peer names
Alan Coopersmith
-
2026/03/30
[oss-security] The GNU C Library security advisory update for 2026-03-30
Siddhesh Poyarekar
-
2026/03/30
Re: [oss-security] KVM shadow EPT stale rmap use-after-free
Demi Marie Obenour
-
2026/03/30
[oss-security] KVM shadow EPT stale rmap use-after-free
Sandipan Roy
-
2026/03/30
Re: [oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Demi Marie Obenour
-
2026/03/30
[oss-security] [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
Christian Brabandt
-
2026/03/29
Re: [oss-security] CVE-2026-4176: Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
Jacob Bachmeyer
-
2026/03/29
[oss-security] CVE-2026-4176: Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
Stig Palmquist
-
2026/03/29
[oss-security] [CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability
cyber security
-
2026/03/29
[oss-security] Re: Multiple vulnerabilities in AppArmor
Greg KH
-
2026/03/28
[oss-security] Re: Multiple vulnerabilities in AppArmor
John Johansen
-
2026/03/28
[oss-security] CVE-2025-15604: Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions
Robert Rothenberg
-
2026/03/28
[oss-security] CVE-2026-3256: HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated session ids
Robert Rothenberg
-
2026/03/28
[oss-security] Re: Multiple vulnerabilities in AppArmor
Greg KH
-
2026/03/27
Re: [oss-security] [ADVISORY] SQUID-2026:1 Denial of Service in ICP Request handling (CVE-2026-33526)
Solar Designer
-
2026/03/27
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2026-0002
Adrian Perez de Castro
-
2026/03/27
Re: [oss-security] Re: Multiple vulnerabilities in AppArmor
kf503bla
-
2026/03/27
[oss-security] Re: Multiple vulnerabilities in AppArmor
Qualys Security Advisory
-
2026/03/27
[oss-security] CVE-2026-1961: Foreman: Remote Code Execution via command injection in WebSocket proxy
Ondrej Gajdusek
-
2026/03/27
[oss-security] Dovecot Security Advisory OXDC-2026-0001
Aki Tuomi
-
2026/03/27
[oss-security] Re: Multiple vulnerabilities in AppArmor
Greg KH
-
2026/03/26
[oss-security] TigerVNC 1.16.2 security release
Alan Coopersmith
-
2026/03/26
[oss-security] CVE-2026-4851: remote-to-local code execution in GRID::Machine
piedcrow
-
2026/03/26
[oss-security] Re: Multiple vulnerabilities in AppArmor
Qualys Security Advisory
-
2026/03/26
Re: [oss-security] Xen Security Advisory 482 v2 - Linux privcmd driver can circumvent kernel lockdown
Juergen Gross
-
2026/03/25
[oss-security] 7 CVEs fixed in nginx
Solar Designer
-
2026/03/25
[oss-security] CVE-2014-125112: Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution
Timothy Legge
-
2026/03/25
[oss-security] libpng 1.6.56: Two high-severity vulnerabilities fixed: CVE-2026-33416, CVE-2026-33636
Cosmin Truta
-
2026/03/25
[oss-security] Re: CVE-2026-33150, CVE-2026-33179: libfuse io_uring memory safety vulnerabilities (use-after-free, NULL deref)
Abhinav Agarwal
-
2026/03/25
[oss-security] ISC has disclosed four vulnerabilities in BIND 9 (CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591)
Nicki Křížek
-
2026/03/25
[oss-security] ISC has disclosed one vulnerability in Kea (CVE-2026-3608)
Peter Davies
-
2026/03/25
[oss-security] backdoor in litellm version 1.82.7
Jan Schaumann
-
2026/03/24
[oss-security] [ADVISORY] SQUID-2026:3 Out of Bounds Read in ICP message handling (CVE-2026-33515)
Amos Jeffries
-
2026/03/24
[oss-security] [ADVISORY] SQUID-2026:2 Denial of Service in ICP Request handling (CVE-2026-32748)
Amos Jeffries
-
2026/03/24
[oss-security] [ADVISORY] SQUID-2026:1 Denial of Service in ICP Request handling (CVE-2026-33526)
Amos Jeffries
-
2026/03/24
[oss-security] NodeJS Security Releases fixes High, 5 Medium, 2 Low severity issues
Jan Schaumann
-
2026/03/24
[oss-security] litellm pypi packages compromised, infostealer added
Alan Coopersmith
-
2026/03/24
Re: [oss-security] Xen Security Advisory 482 v2 - Linux privcmd driver can circumvent kernel lockdown
Andrew Cooper
-
2026/03/24
Re: [oss-security] Xen Security Advisory 482 v2 - Linux privcmd driver can circumvent kernel lockdown
Greg KH
-
2026/03/24
[oss-security] Xen Security Advisory 482 v3 (CVE-2026-31788) - Linux privcmd driver can circumvent kernel lockdown
Xen . org security team
-
2026/03/24
Re: [oss-security] Xen Security Advisory 482 v2 - Linux privcmd driver can circumvent kernel lockdown
Greg KH
-
2026/03/24
[oss-security] Xen Security Advisory 482 v2 - Linux privcmd driver can circumvent kernel lockdown
Xen . org security team
-
2026/03/23
[oss-security] The GNU C Library security advisories update for 2026-03-23
Carlos O'Donell
-
2026/03/23
Re: [oss-security] Trivy github actions repo compromised, infostealer added
Jeremy Utiera
-
2026/03/22
Re: [oss-security] CVE-2006-10002: XML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes
Salvatore Bonaccorso
-
2026/03/21
Re: [oss-security] Buffer overflow in /bin/su from UNIX v4
Peter Gutmann
-
2026/03/21
Re: [oss-security] Buffer overflow in /bin/su from UNIX v4
Steffen Nurpmeso
-
2026/03/21
Re: [oss-security] Buffer overflow in /bin/su from UNIX v4
Alan Coopersmith
-
2026/03/21
[oss-security] Re: Buffer overflow in /bin/su from UNIX v4
Justin Swartz
-
2026/03/21
Re: [oss-security] Buffer overflow in /bin/su from UNIX v4
Solar Designer
-
2026/03/21
Re: [oss-security] Buffer overflow in /bin/su from UNIX v4
kf503bla
-
2026/03/20
Re: [oss-security] pyOpenSSL 26.0.0 released with two CVE fixes
Alex Gaynor
-
2026/03/20
[oss-security] CVE-2026-33150, CVE-2026-33179: libfuse io_uring memory safety vulnerabilities (use-after-free, NULL deref)
Abhinav Agarwal
-
2026/03/20
[oss-security] Trivy github actions repo compromised, infostealer added
Alan Coopersmith
-
2026/03/20
Re: [oss-security] Buffer overflow in /bin/su from UNIX v4
Alan Coopersmith
-
2026/03/20
[oss-security] pyOpenSSL 26.0.0 released with two CVE fixes
Alan Coopersmith
-
2026/03/20
[oss-security] [CVE-2026-30922] Denial of Service in pyasn1 via Unbounded Recursion
Alan Coopersmith
-
2026/03/20
[oss-security] nghttp2 Denial of service: Assertion failure due to the missing state validation
Alan Coopersmith
-
2026/03/20
[oss-security] CVE-2026-32642: Apache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission
Justin Bertram
-
2026/03/20
[oss-security] Fwd: [CPython][CVE-2026-4519] webbrowser.open() API allows leading dashes
Alan Coopersmith
-
2026/03/19
[oss-security] [vim-security]: Command injection via newline in glob() affects Vim < 9.2.0202
Christian Brabandt
-
2026/03/19
[oss-security] [kubernetes] CVE-2026-4342: ingress-nginx comment-based nginx configuration injection
Tabitha Sable
-
2026/03/19
[oss-security] Re: Off-by-one heap buffer overflow in libuv
Ali Raza
-
2026/03/19
Re: [oss-security] Off-by-one heap buffer overflow in libuv
Stuart Henderson
-
2026/03/19
[oss-security] Re: Off-by-one heap buffer overflow in libuv
Ali Raza
-
2026/03/19
[oss-security] Re: Off-by-one heap buffer overflow in libuv
Ali Raza
-
2026/03/19
[oss-security] Off-by-one heap buffer overflow in libuv
Ali Raza
-
2026/03/19
[oss-security] [OSSA-2026-004] Glance: Server-Side Request Forgery (SSRF) vulnerabilities in OpenStack Glance image import functionality (CVE-2026-pending)
Brian Rosmaita
-
2026/03/19
[oss-security] CVE-2006-10003: XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack
Timothy Legge
-
2026/03/19
[oss-security] CVE-2006-10002: XML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes
Timothy Legge
-
2026/03/18
[oss-security] CVE-2026-31973: samtools <= 1.23 NULL pointer dereference in cram-size
Robert Davies
-
2026/03/18
[oss-security] CVE-2026-31972: samtools <= 1.21 Use-after-free in mpileup leading to an invalid read
Robert Davies
-
2026/03/18
[oss-security] HTSlib <= 1.23 Multiple vulnerabilities in the CRAM file reader
Robert Davies
-
2026/03/18
[oss-security] CVE-2026-31970: HTSlib <= 1.23 heap buffer overflow in the BGZF index file reader
Robert Davies
-
2026/03/18
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2026-0001
Adrian Perez de Castro
-
2026/03/18
Re: [oss-security] OpenSSH GSSAPI keyex patch issue
Jeffrey Walton
-
2026/03/18
[oss-security] Multiple vulnerabilities in Jenkins and Jenkins plugins
Daniel Beck
-
2026/03/18
Re: [oss-security] OpenSSH GSSAPI keyex patch issue
Dmitry Belyavskiy
-
2026/03/18
Re: [oss-security] OpenSSH GSSAPI keyex patch issue
Solar Designer
-
2026/03/18
[oss-security] [SBA-ADV-20251205-01] LibreChat 0.8.1-rc2 RAG API Authentication Bypass
SBA Research Security Advisory
-
2026/03/18
Re: [oss-security] OpenSSH GSSAPI keyex patch issue
Dmitry Belyavskiy
-
2026/03/17
Re: [oss-security] snap-confine + systemd-tmpfiles = root (CVE-2026-3888)
Michael Orlitzky
-
2026/03/17
Re: [oss-security] libexpat 2.7.5 fixes three vulnerabilities (2x null deref, 1x infinite loop)
Alan Coopersmith
-
2026/03/17
[oss-security] libexpat 2.7.5 fixes three vulnerabilities (2x null deref, 1x infinite loop)
Sebastian Pipping
-
2026/03/17
Re: [oss-security] snap-confine + systemd-tmpfiles = root (CVE-2026-3888)
Michal Zalewski
-
2026/03/17
[oss-security] snap-confine + systemd-tmpfiles = root (CVE-2026-3888)
Qualys Security Advisory
-
2026/03/17
[oss-security] Xen Security Advisory 481 v2 (CVE-2026-23555) - Xenstored DoS by unprivileged domain
Xen . org security team
-
2026/03/17
[oss-security] Xen Security Advisory 480 v3 (CVE-2026-23554) - Use after free of paging structures in EPT
Xen . org security team