Messages by Thread
-
[oss-security] Exim Security Release 4.100.1
Solar Designer
-
[oss-security] Suricata 8.0.7 released with 67 vulnerabilities fixed
Alan Coopersmith
-
[oss-security] Vulnerabilities in libheif and libde265
Alan Coopersmith
-
[oss-security] CVE-2026-93019: Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read
Stig Palmquist
-
[oss-security] CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely
Colm O hEigeartaigh
-
[oss-security] CVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service
Colm O hEigeartaigh
-
[oss-security] CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service
Colm O hEigeartaigh
-
[oss-security] CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service
Colm O hEigeartaigh
-
[oss-security] CVE-2026-93018: Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p
Stig Palmquist
-
[oss-security] CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion
Colm O hEigeartaigh
-
[oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
manizada
-
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Hanno Böck
-
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Kevin Riggle
-
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Eli Schwartz
-
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
SOFIA ETCHEPARE DARONCO
-
Re: [oss-security] A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Valtteri Vuorikoski
-
[oss-security] CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)
Rahul Vats
-
[oss-security] CVE-2026-73639: Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8
Stig Palmquist
-
[oss-security] CVE-2026-73638: Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd
Stig Palmquist
-
[oss-security] CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching
Jean-Baptiste Onofré
-
[oss-security] The GNU C Library security advisories update for 2026-09-17
Adhemerval Zanella Netto
-
[oss-security] CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2
Haitam Lazaar
-
[oss-security] CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
David Handermann
-
[oss-security] CVE-2026-89775: Guest-to-Host Escape in KVM/arm64
Hyunwoo Kim
-
[oss-security] CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing
Volodymyr Siedlecki
-
[oss-security] CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
Volodymyr Siedlecki
-
[oss-security] Unbound: 1.26.1 addresses multiple CVE items
Yorgos Thessalonikefs
-
[oss-security] CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles
David Handermann
-
[oss-security] CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration
David Handermann
-
[oss-security] CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
David Handermann
-
[oss-security] CVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests
David Handermann
-
[oss-security] ISC has disclosed fourteen vulnerabilities in BIND 9 (CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736)
Nicki Křížek
-
[oss-security] CVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
Vincent Beck
-
[oss-security] CVE-2026-86792: Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration
Vincent Beck
-
[oss-security] CVE-2026-86465: Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key
Vincent Beck
-
[oss-security] CVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
Vincent Beck
-
[oss-security] CVE-2026-82311: Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false
Vincent Beck
-
[oss-security] CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
Vincent Beck
-
[oss-security] CVE-2026-76187: Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT
Vincent Beck
-
[oss-security] CVE-2026-76186: Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
Vincent Beck
-
[oss-security] CVE-2026-84501: Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider
Andor Molnar
-
[oss-security] CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
Andor Molnar
-
[oss-security] CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
Andor Molnar
-
[oss-security] CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
Andor Molnar
-
[oss-security] CVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
Andor Molnar
-
[oss-security] CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution
manizada
-
[oss-security] The GNU C Library security advisories update for 2026-09-14
Adhemerval Zanella Netto
-
[oss-security] rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback
Evgenios Gkritsis
-
[oss-security] CVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search
Francesco Chicchiriccò
-
[oss-security] Cpython: [CVE-2026-82049] tarfile extraction filters allow file modification and content disclosure via hard link to symlink
Alan Coopersmith
-
[oss-security] graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule
Evgenios Gkritsis
-
[oss-security] CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Francesco Chicchiriccò
-
[oss-security] CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass
Francesco Chicchiriccò
-
[oss-security] CVE-2026-87785: Apache Syncope: JWT subject spoofing
Francesco Chicchiriccò
-
[oss-security] CVE-2026-87779: Apache Syncope: AES Secret Key disclosure via log output
Francesco Chicchiriccò
-
[oss-security] CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable
Francesco Chicchiriccò
-
[oss-security] CVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
Francesco Chicchiriccò
-
[oss-security] CVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task search
Francesco Chicchiriccò
-
[oss-security] CVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user
Francesco Chicchiriccò
-
[oss-security] CVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authentication
Francesco Chicchiriccò
-
[oss-security] CVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduser
Francesco Chicchiriccò
-
[oss-security] CVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist
Francesco Chicchiriccò
-
[oss-security] CVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective
Francesco Chicchiriccò
-
[oss-security] CVE-2026-77147: Apache Syncope: Groovy Sandbox escape for empty CommandArgs
Francesco Chicchiriccò
-
[oss-security] CVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Francesco Chicchiriccò
-
[oss-security] CVE-2026-73579: Apache Syncope: Non-recursive Any search could skip Realms restrictions
Francesco Chicchiriccò
-
[oss-security] CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles
Francesco Chicchiriccò
-
[oss-security] CVE-2026-73370: Apache Syncope: Cross-Realm boundaries reconciliation bypass
Francesco Chicchiriccò
-
[oss-security] CVE-2026-73236: Apache Syncope: Cross-Realm authorization bypass in delegated administration
Francesco Chicchiriccò
-
[oss-security] CVE-2026-73195: Apache Syncope: CSV export spreadsheet formula injection
Francesco Chicchiriccò
-
[oss-security] CVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers
Francesco Chicchiriccò
-
[oss-security] CVE-2026-73178: Apache Syncope: JWT Access Token takeover
Francesco Chicchiriccò
-
[oss-security] CVE-2026-72524: Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables
Calvin Kirs
-
[oss-security] CVE-2026-68570: Apache Doris: Authorization bypass leading to unauthorized data access
Calvin Kirs
-
[oss-security] Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Sean Whitton
-
[oss-security] CVE-2026-82433: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI
Richard Zowalla
-
[oss-security] CVE-2026-82429: Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher
Richard Zowalla
-
[oss-security] CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
Richard Zowalla
-
[oss-security] CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant
Richard Zowalla
-
[oss-security] CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys
Richard Zowalla
-
[oss-security] CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer
Richard Zowalla
-
[oss-security] CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins
Richard Zowalla
-
[oss-security] CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page
Richard Zowalla
-
[oss-security] CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC
Richard Zowalla
-
[oss-security] CVE-2026-82431: Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users
Richard Zowalla
-
[oss-security] CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder
Richard Zowalla
-
[oss-security] CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides
Richard Zowalla
-
[oss-security] CVE-2026-82428: Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys
Richard Zowalla
-
[oss-security] CVE-2026-82427: Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name
Richard Zowalla
-
[oss-security] CVE-2026-82426: Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location
Richard Zowalla
-
[oss-security] GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efi
Luppa
-
[oss-security] Retrospective by 'gpg.fail' authors
Sam James
-
[oss-security] Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations
Sam James
-
[oss-security] Fwd: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations
Sam James
-
[oss-security] [vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090
Christian Brabandt
-
[oss-security] Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey
12345678
-
[oss-security] CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns
Richard Zowalla
-
[oss-security] CPython: [CVE-2026-87910] tarfile hardlink fallback ignores custom extraction filter rejection via None
Alan Coopersmith
-
[oss-security] CVE-2026-67211: Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer
Richard Zowalla
-
[oss-security] CVE-2026-82583, CVE-2026-78224, CVE-2026-82578: NextGen Mirth Connect SQL injection and XXE
Abhinav Agarwal
-
[oss-security] The GNU C Library security advisory update for 2026-09-10
Siddhesh Poyarekar
-
[oss-security] CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects
Pasquale Congiusti
-
[oss-security] CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36
Valtteri Vuorikoski
-
[oss-security] CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
Pasquale Congiusti
-
[oss-security] CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
Pasquale Congiusti
-
[oss-security] GDCM <= 3.2.7: six memory-safety and denial-of-service vulnerabilities, no CVE
Abhinav Agarwal
-
[oss-security] AI slops from Eve
Solar Designer
-
[oss-security] iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level)
Eve
-
[oss-security] Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design)
Eve
-
[oss-security] Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT
Eve
-
[oss-security] Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releases
Solar Designer
-
[oss-security] CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
Clebert Suconic
-
[oss-security] CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
Clebert Suconic
-
[oss-security] CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment
Clebert Suconic
-
[oss-security] CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service
Clebert Suconic
-
[oss-security] CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
Clebert Suconic
-
[oss-security] CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription
Clebert Suconic
-
[oss-security] CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation
Clebert Suconic
-
[oss-security] Fwd: XZ Utils 5.8.4 and a security fix
Sam James
-
[oss-security] CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)
Mr. Gatto
-
[oss-security] Security fixes in libfuse-3.18.3
Sam James
-
[oss-security] libpcap 1.10.7 fixes 7 vulnerabilities
Denis Ovsienko
-
[oss-security] CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading
Michael Smith
-
[oss-security] CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF
Michael Smith
-
[oss-security] CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token
Michael Smith
-
[oss-security] CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery
Michael Smith
-
[oss-security] Fwd: Tor Project Forum: Security Release 0.4.9.12
Sam James
-
[oss-security] CVE-2026-85630: HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method
Robert Rothenberg
-
[oss-security] CVE-2026-85485: HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping
Robert Rothenberg
-
[oss-security] CVE-2026-85484: HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
Robert Rothenberg
-
[oss-security] CVE-2026-19872: HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message
Robert Rothenberg
-
[oss-security] CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
Niko Oliveira
-
[oss-security] Xen Security Advisory 510 v3 (CVE-2026-79602) - x86: improper handling of HVM emulation return codes
Xen . org security team
-
[oss-security] Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdisk
Xen . org security team
-
[oss-security] CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
Dániel Dékány
-
[oss-security] CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Matt Pavlovich
-
[oss-security] CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation
Gidon Gershinsky
-
[oss-security] Xen Security Advisory 512 v3 (CVE-2026-79604) - oxenstored: Unbounded accumulation of watches
Xen . org security team
-
[oss-security] Xen Security Advisory 511 v3 (CVE-2026-79603) - Unconditionally do TLB flushing ahead of page scrubbing
Xen . org security team
-
[oss-security] CVE-2026-41870: Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
Sebastian Nagel
-
[oss-security] Xen Security Advisory 509 v3 (CVE-2026-62437) - x86: DMs may cause mem leak by IRQ binding
Xen . org security team
-
[oss-security] CVE-2026-41871: Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
Sebastian Nagel
-
[oss-security] CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)
Sebastian Nagel
-
[oss-security] Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more
Yuan Tan
-
[oss-security] CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
Robert Rothenberg
-
[oss-security] CVE-2026-86287: Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
Robert Rothenberg
-
[oss-security] CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
Timothy Legge
-
[oss-security] Fwd: [mapserver-announce] security release available: MapServer 8.6.6
Sam James
-
[oss-security] CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write
Stefan Bodewig
-
[oss-security] CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
Timothy Legge
-
[oss-security] Fwd: Security vulnerabilities fixed in WeeChat 4.10.1
Sam James
-
[oss-security] pcre2 version 10.48 released with security fixes
Alan Coopersmith
-
[oss-security] Vulnerability fixes in util-linux-2.42.3
Sam James
-
[oss-security] Vulnerabilities fixed in libxml2-2.15.4
Sam James
-
[oss-security] CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module
Arnout Engelen
-
[oss-security] CVE-2026-82309: Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries
Robert Rothenberg
-
[oss-security] CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Sheng Wu
-
[oss-security] CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
Kai Wan
-
[oss-security] [OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)
Goutham Pacha Ravi
-
[oss-security] CVE-2026-80530: Linux XFS EXCHANGE_RANGE reflink flag clearing leading to local privilege escalation
Lin Jiapeng
-
[oss-security] CVE-2026-80180: Apache Allura: Stored XSS via markdown HTML processing
Dave Brondsema
-
[oss-security] CVE-2026-81270: Apache Allura: Information exposure via search
Dave Brondsema
-
[oss-security] CVE-2026-80190: Apache Allura: Stored XSS via code repositories
Dave Brondsema
-
[oss-security] CVE-2026-80181: Apache Allura: Server-side request forgery
Dave Brondsema
-
[oss-security] Fwd: Vulnerabilities in golang.org/x/crypto
Alan Coopersmith
-
[oss-security] [SECURITY ADVISORIES] curl 8.22.0
Daniel Stenberg
-
[oss-security] CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record
Timothy Legge
-
[oss-security] CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4
Holden Karau
-
[oss-security] CVE-2026-80205 : ReDoS in NLTK Text.findall() (CVSS 8.7 High)
Aditi Bhatnagar