oss-security mailing list
Recent messages:
- 2026/02/07 #1:
On patch vs commit messages (Sam James <sam@...too.org>)
- 2026/02/05 #2:
[vim-security] buffer overflow in helpfile option handling affects
Vim <9.1.2132 (Christian Brabandt <cb_home@....de>)
- 2026/02/05 #1:
NGINX < 1.29.5, 1.28.2 MitM injection CVE-2026-1642 (Jan Schaumann <jschauma@...meister.org>)
- 2026/02/04 #1:
CVE-2026-24735: Apache Answer: Revision API Improper Access
Control leads to Information Disclosure (Enxin Xie <linkinstar@...che.org>)
- 2026/02/03 #2:
Re: Systemd vsock sshd (Bastian Blank <bblank@...nkmo.de>)
- 2026/02/03 #1:
Django CVE-2025-13473, CVE-2025-14550, CVE-2026-1207, CVE-2026-1285,
CVE-2026-1287, and CVE-2026-1312 (Jacob Walls <jwalls@...ngoproject.com>)
- 2026/02/02 #3:
[kubernetes] Multiple issues in ingress-nginx (Tabitha Sable <tabitha.c.sable@...il.com>)
- 2026/02/02 #2:
CVE-2026-23795: Apache Syncope: Console XXE on Keymaster
parameters (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/02/02 #1:
CVE-2026-23794: Apache Syncope: Reflected XSS on Enduser Login (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/01/31 #2:
Security incident on plone GitHub org with force pushes (Maurits van Rees <maurits@...rees.org>)
- 2026/01/31 #1:
libexpat 2.7.4 fixes CVE-2026-24515 and CVE-2026-25210 (Sebastian Pipping <sebastian@...ping.org>)
- 2026/01/30 #1:
Re: CVE-2025-56005 Undocumented RCE in PLY via
`picklefile` Parameter (Jakub Wilk <jwilk@...lk.net>)
- 2026/01/29 #2:
Re: CVE-2025-56005 Undocumented RCE in PLY via
`picklefile` Parameter (Sebastian Pipping <sebastian@...ping.org>)
- 2026/01/29 #1:
Re: CVE-2025-56005 Undocumented RCE in PLY via
`picklefile` Parameter (Jakub Wilk <jwilk@...lk.net>)
- 2026/01/28 #5:
Re: CVE-2025-56005 Undocumented RCE in PLY via
`picklefile` Parameter (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/01/28 #4:
Re: GNU InetUtils Security Advisory: remote authentication by-pass in
telnetd (Paul Ducklin <pducklin@...look.com>)
- 2026/01/28 #3:
Re: OpenSSL Security Advisory (corrected - added
CVE-2026-22795 and CVE-2026-22796) (Tomas Mraz <tomas@...nssl.org>)
- 2026/01/28 #2:
Re: OpenSSL Security Advisory (corrected - added
CVE-2026-22795 and CVE-2026-22796) (Demi Marie Obenour <demiobenour@...il.com>)
- 2026/01/28 #1:
Re: Clarification: rbash escape via history built-ins (cyber security <cs7778503@...il.com>)
- 2026/01/27 #11:
Re: GnuPG security release (Salvatore Bonaccorso <carnil@...ian.org>)
- 2026/01/27 #10:
Re: GnuPG security release (Jan Schaumann <jschauma@...meister.org>)
- 2026/01/27 #9:
Re: GnuPG security release (Pedro Sampaio <psampaio@...hat.com>)
- 2026/01/27 #8:
GnuPG security release (Sam James <sam@...too.org>)
- 2026/01/27 #7:
OpenSSL Security Advisory (corrected - added CVE-2026-22795 and
CVE-2026-22796) (Tomas Mraz <tomas@...nssl.org>)
- 2026/01/27 #6:
Clarification: rbash escape via history built-ins (cyber security <cs7778503@...il.com>)
- 2026/01/27 #5:
OpenSSL Security Advisory (Tomas Mraz <tomas@...nssl.org>)
- 2026/01/27 #4:
Agno's PythonTools: Path traversal leads to sensitive information disclosure and potential RCE (Ali Raza <aliraza@...erock.io>)
- 2026/01/27 #3:
Xen Security Advisory 479 v2 (CVE-2026-23553) - x86: incomplete
IBPB for vCPU isolation (Xen.org security team <security@....org>)
- 2026/01/27 #2:
Xen Security Advisory 478 v2 (CVE-2025-58151) - varstored: TOCTOU
issues with mapped guest memory (Xen.org security team <security@....org>)
- 2026/01/27 #1:
Xen Security Advisory 477 v2 (CVE-2025-58150) - x86: buffer
overrun with shadow paging + tracing (Xen.org security team <security@....org>)
- 2026/01/26 #1:
CVE-2016-15057: Apache Continuum: Command injection leading to RCE
(Arnout Engelen <engelen@...che.org>)
- 2026/01/25 #3:
Re: Vulnerability management and Open Source: FOSDEM
BoF ("Olle E. Johansson" <oej@...ina.net>)
- 2026/01/25 #2:
Re: Vulnerability management and Open Source: FOSDEM
BoF (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2026/01/25 #1:
Re: Vulnerability management and Open Source: FOSDEM BoF (Solar Designer <solar@...nwall.com>)
- 2026/01/24 #1:
CVE-2026-24656: Apache Karaf: Decanter log-socket collector has deserialization vulnerability (Jean-Baptiste Onofré <jbonofre@...che.org>)
- 2026/01/23 #8:
8 CVEs in Cpython announced this week (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/01/23 #7:
CVE-2025-27821: HDFS native client: Out of bounds write in URI
parser of native HDFS client (Chris Nauroth <cnauroth@...che.org>)
- 2026/01/23 #6:
Re: Vulnerability management and Open Source: FOSDEM
BoF (Brian Behlendorf <brian@...lendorf.com>)
- 2026/01/23 #5:
Re: CVE-2025-56005 Undocumented RCE in PLY via
`picklefile` Parameter (Stuart Henderson <stu@...cehopper.org>)
- 2026/01/23 #4:
CVE-2025-56005 Undocumented RCE in PLY via
`picklefile` Parameter (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/01/23 #3:
Re: Vulnerability management and Open Source: FOSDEM
BoF ("Olle E. Johansson" <oej@...ina.net>)
- 2026/01/23 #2:
Re: Vulnerability management and Open Source: FOSDEM
BoF (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2026/01/23 #1:
Vulnerability management and Open Source: FOSDEM BoF ("Olle E. Johansson" <oej@...ina.net>)
- 2026/01/22 #2:
Re: GNU InetUtils Security Advisory: remote
authentication by-pass in telnetd (Demi Marie Obenour <demiobenour@...il.com>)
- 2026/01/22 #1:
Re: GNU InetUtils Security Advisory: remote
authentication by-pass in telnetd (Christian Fischer <christian.fischer@...enbone.net>)
- 2026/01/21 #6:
CVE-2024-31884 Ceph: Incorrect usage of certificate checking via Pybind ("Sage [They / Them] McTaggart" <amctagga@...hat.com>)
- 2026/01/21 #5:
Vulnerable tmpdir handling in pytest (Michael Orlitzky <michael@...itzky.com>)
- 2026/01/21 #4:
Re: WordPress Plugin "Under Construction & Maintenance
Mode": Exposed debug functionality (Soatok Dreamseeker <soatok.dhole@...il.com>)
- 2026/01/21 #3:
ISC has disclosed one vulnerability in BIND 9 (CVE-2025-13878) (Michał Kępień <michal@....org>)
- 2026/01/21 #2:
Re: GNU InetUtils Security Advisory: remote
authentication by-pass in telnetd (Jakub Wilk <jwilk@...lk.net>)
- 2026/01/21 #1:
Re: WordPress Plugin "Under Construction &
Maintenance Mode": Exposed debug functionality (Hanno Böck <hanno@...eck.de>)
- 2026/01/20 #8:
Re: GNU InetUtils Security Advisory: remote
authentication by-pass in telnetd (Alexander Bochmann <ab@...ts.gxis.de>)
- 2026/01/20 #7:
Re: WordPress Plugin "Under Construction & Maintenance
Mode": Exposed debug functionality (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/01/20 #6:
Re: WordPress Plugin "Under Construction &
Maintenance Mode": Exposed debug functionality (Moritz Mühlenhoff <jmm@...til.org>)
- 2026/01/20 #5:
CVE-2026-22444: Apache Solr: Insufficient file-access checking in
standalone core-creation requests (Jason Gerlowski <gerlowskija@...che.org>)
- 2026/01/20 #4:
CVE-2026-22022: Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationP… (Jason Gerlowski <gerlowskija@...che.org…)
- 2026/01/20 #3:
The GNU C Library security advisories update for 2026-01-20 (Carlos O'Donell <carlos@...hat.com>)
- 2026/01/20 #2:
GNU InetUtils Security Advisory: remote authentication by-pass in
telnetd (Simon Josefsson <simon@...efsson.org>)
- 2026/01/20 #1:
WordPress Plugin "Under Construction & Maintenance Mode": Exposed debug functionality (mohammed gaming 222 <craftmohammed460@...il.com>)
- 2026/01/18 #2:
Re: CVE-2025-8110 in Gogs self-hosted git service (Michael Orlitzky <michael@...itzky.com>)
- 2026/01/18 #1:
Re: CVE-2025-8110 in Gogs self-hosted git service (Collin Funk <collin.funk1@...il.com>)
- 2026/01/17 #4:
Re: CVE-2025-8110 in Gogs self-hosted git service (Chad Dougherty <crd477@...oud.com>)
- 2026/01/17 #3:
Re: CVE-2025-68121: Regression and Incomplete Fix for Go TLS Session Resumption (Coia Prant <coiaprant@...il.com>)
- 2026/01/17 #2:
CVE-2025-68121: Regression and Incomplete Fix for Go TLS Session Resumption (Coia Prant <coiaprant@...il.com>)
- 2026/01/17 #1:
Re: Re: Best practices for signature verifcation (Jacob Bachmeyer <jcb62281@...il.com>)
- 2026/01/16 #9:
[OSSA-2026-001] OpenStack keystonemiddleware: Privilege Escalation
via Identity Headers in External OAuth2 Tokens (CVE-2026-… (Jeremy Stanley <fungi@...goth.org>)
- 2026/01/16 #8:
Re: NodeJS Security Releases (CVE-2025-55131,
CVE-2025-55130, CVE-2025-59465, and others) (Jan Schaumann <jschauma@...meister.org>)
- 2026/01/16 #7:
Re: NodeJS Security Releases (CVE-2025-55131,
CVE-2025-55130, CVE-2025-59465, and others) (Michel Lind <michel@...hel-slm.name>)
- 2026/01/16 #6:
The GNU C Library security advisories update for 2026-01-16 (part 2) (Carlos O'Donell <carlos@...hat.com>)
- 2026/01/16 #5:
The GNU C Library security advisories update for 2026-01-16 (Siddhesh Poyarekar <siddhesh.poyarekar@...il.com>)
- 2026/01/16 #4:
CVE-2025-60021: Apache bRPC: Remote command injection
vulnerability in heap builtin service (Guangming Chen <guangmingchen@...che.org>)
- 2026/01/16 #3:
Re: [CVE-2026-22797] OpenStack keystonemiddleware:
Privilege Escalation via Identity Headers in External OAuth2 Tokens
(CVE… (Jeremy Stanley <fungi@...goth.org>)
- 2026/01/16 #2:
Re: [CVE-2026-22797] OpenStack keystonemiddleware:
Privilege Escalation via Identity Headers in External OAuth2 Tokens
… (Salvatore Bonaccorso <carnil@...ian.org…)
- 2026/01/16 #1:
Re: Re: Best practices for signature verifcation (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2026/01/15 #7:
Re: Fwd: [FD] zlib v1.3.1.2 Global Buffer Overflow in
TGZfname() of zlib untgz Utility via Unbounded strcpy() on User-S… (Alan Coopersmith <alan.coopersmith@...c…)
- 2026/01/15 #6:
CVE-2025-68675: Apache Airflow: proxy credentials for various
providers might leak in task logs (Ephraim Anierobi <ephraimanierobi@...che.org>)
- 2026/01/15 #5:
CVE-2025-68438: Apache Airflow: Secrets in rendered templates
could contain parts of sensitive values when truncated (Ephraim Anierobi <ephraimanierobi@...che…)
- 2026/01/15 #4:
Re: Go 1.25.6 and Go 1.24.12 are released
with 6 CVE fixes (Steffen Nurpmeso <steffen@...oden.eu>)
- 2026/01/15 #3:
Go 1.25.6 and Go 1.24.12 are released with 6 CVE fixes (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/01/15 #2:
Re: The Curious Case of Stack Pivot Detection (Adam Zabrocki <pi3@....com.pl>)
- 2026/01/15 #1:
[CVE-2026-22797] OpenStack keystonemiddleware: Privilege Escalation
via Identity Headers in External OAuth2 Tokens (CVE-2026… (Jeremy Stanley <fungi@...goth.org>)
- 2026/01/14 #3:
Re: Null Pointer Dereference in HarfBuzz (Jacob Bachmeyer <jcb62281@...il.com>)
- 2026/01/14 #2:
Re: NodeJS Security Releases (CVE-2025-55131,
CVE-2025-55130, CVE-2025-59465, and others) (Jan Schaumann <jschauma@...meister.org>)
- 2026/01/14 #1:
Re: NodeJS Security Releases (CVE-2025-55131,
CVE-2025-55130, CVE-2025-59465, and others) (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/01/13 #5:
CVE-2025-66169: Apache Camel: Cypher injection vulnerability in
Camel-Neo4j component (Andrea Cosentino <acosentino@...che.org>)
- 2026/01/13 #4:
Re: Null Pointer Dereference in HarfBuzz (Vincent Lefevre <vincent@...c17.net>)
- 2026/01/13 #3:
Re: Null Pointer Dereference in HarfBuzz (Jacob Bachmeyer <jcb62281@...il.com>)
- 2026/01/13 #2:
NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130,
CVE-2025-59465, and others) (Jan Schaumann <jschauma@...meister.org>)
- 2026/01/13 #1:
Re: Null Pointer Dereference in HarfBuzz (Jacob Bachmeyer <jcb62281@...il.com>)
- 2026/01/12 #7:
libpng 1.6.54: two heap buffer over-read vulnerabilities fixed:
CVE-2026-22695, CVE-2026-22801 (Cosmin Truta <ctruta@...il.com>)
- 2026/01/12 #6:
Re: CVE-2025-68493: Apache Struts: XXE vulnerability
in outdated XWork component (Loganaden Velvindron <loganaden@...il.com>)
- 2026/01/12 #5:
Re: Null Pointer Dereference in HarfBuzz (Vincent Lefevre <vincent@...c17.net>)
- 2026/01/12 #4:
Re: Null Pointer Dereference in HarfBuzz (Greg KH <greg@...ah.com>)
- 2026/01/12 #3:
Re: Null Pointer Dereference in HarfBuzz (Jan Engelhardt <ej@...i.de>)
- 2026/01/12 #2:
Re: CVE-2025-68493: Apache Struts: XXE vulnerability
in outdated XWork component (Hanno Böck <hanno@...eck.de>)
- 2026/01/12 #1:
Re: Null Pointer Dereference in HarfBuzz (Jacob Bachmeyer <jcb62281@...il.com>)
- 2026/01/11 #2:
CVE-2025-68493: Apache Struts: XXE vulnerability in outdated XWork component (Lukasz Lenart <lukaszlenart@...che.org>)
- 2026/01/11 #1:
Null Pointer Dereference in HarfBuzz (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/01/10 #1:
The Curious Case of Stack Pivot Detection (Ali Polatel <alip@...sys.org>)
- 2026/01/09 #2:
Net-SNMP snmptrapd vulnerability [CVE-2025-68615] (Alan Coopersmith <alan.coopersmith@...cle.com>)
32017 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.