oss-security mailing list
Recent messages:
- 2026/09/14 #32:
Re: Retrospective by 'gpg.fail' authors (Clemens Lang <cllang@...hat.com>)
- 2026/09/14 #31:
The GNU C Library security advisories update for 2026-09-14 (Adhemerval Zanella Netto <adhemerval.zanella@...aro.org>)
- 2026/09/14 #30:
Re: rosbridge_library Protocol.incoming() quadratic
CPU cost in JSON fallback ("David A. Wheeler" <dwheeler@...eeler.com>)
- 2026/09/14 #29:
Re: rosbridge_library Protocol.incoming() quadratic
CPU cost in JSON fallback (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/09/14 #28:
rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback (Evgenios Gkritsis <evgeniosgkritsis@...il.com>)
- 2026/09/14 #27:
Cpython: [CVE-2026-82049] tarfile extraction filters
allow file modification and content disclosure via hard link to sy… (Alan Coopersmith <alan.coopersmith@...c…)
- 2026/09/14 #26:
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule (Evgenios Gkritsis <evgeniosgkritsis@...il.com>)
- 2026/09/14 #25:
CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature
verification bypass (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #24:
CVE-2026-87785: Apache Syncope: JWT subject spoofing (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #23:
CVE-2026-87779: Apache Syncope: AES Secret Key disclosure via log
output (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #22:
CVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search
on Neo4j Persistence (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #21:
CVE-2026-82232: Apache Syncope: SQL injection via sort parameter
in Task search (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #20:
CVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses
client secrets to any authenticated user (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #19:
CVE-2026-78330: Apache Syncope: Privilege escalation for admin
user via JWT authentication (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #18:
CVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in
Console and Enduser (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #17:
CVE-2026-77883: Apache Syncope: Information disclosure via one-hop
JEXL navigation past the JexlContextBuilder name den… (Francesco Chicchiriccò <ilgrosso@...ch…)
- 2026/09/14 #16:
CVE-2026-77181: Apache Syncope: ClientApp update entitlement not
effective (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #15:
CVE-2026-77147: Apache Syncope: Groovy Sandbox escape for empty
CommandArgs (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #14:
CVE-2026-77051: Apache Syncope: SQL injection via unsanitized
entityKey and opEvent in Audit Events search (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #13:
CVE-2026-75030: Apache Syncope: Incomplete authorization checks
for Group members deprovisioning (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #12:
CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into
audit records readable (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #11:
CVE-2026-73668: Apache Syncope: Cross-realm disclosure of
confidential ConnId bundles configuration values (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #10:
CVE-2026-73579: Apache Syncope: Non-recursive Any search could
skip Realms restrictions (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #9:
CVE-2026-73470: Apache Syncope: Delegating users can grant unowned
Roles (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #8:
CVE-2026-73370: Apache Syncope: Cross-Realm boundaries
reconciliation bypass (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #7:
CVE-2026-73236: Apache Syncope: Cross-Realm authorization bypass
in delegated administration (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #6:
CVE-2026-73195: Apache Syncope: CSV export spreadsheet formula
injection (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #5:
CVE-2026-73191: Apache Syncope: CAS service URL injection via
Forwarded HTTP headers (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #4:
CVE-2026-73178: Apache Syncope: JWT Access Token takeover (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2026/09/14 #3:
CVE-2026-72524: Apache Doris: Authorization bypass allowing a
low-privilege user to read/write/drop arbitrary tables (Calvin Kirs <kirs@...che.org>)
- 2026/09/14 #2:
CVE-2026-68570: Apache Doris: Authorization bypass leading to
unauthorized data access (Calvin Kirs <kirs@...che.org>)
- 2026/09/14 #1:
Emacs arbitrary code execution: incomplete fix for CVE-2024-53920 (Sean Whitton <spwhitton@...hitton.name>)
- 2026/09/13 #23:
Re: CVE-2026-82434: Apache Storm Nimbus, Apache Storm
Client: Disclosure of the Topology ZooKeeper Credential to Read-Only… (Gabriel Ravier <gabravier@...il.com>)
- 2026/09/13 #22:
Re: AI slops from Eve (Solar Designer <solar@...nwall.com>)
- 2026/09/13 #21:
Re: AI slops from Eve (Jeroen Roovers <jer@...all.nl>)
- 2026/09/13 #20:
CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure
of Unredacted Merged Daemon Configuration via the Topology P… (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #19:
CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion
and Cluster Denial of Service via Unvalidated Topology Depend… (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #18:
CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded
Memory Growth in DRPC (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #17:
CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses
Exposed to Arbitrary Web Origins (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #16:
CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not
Enforced by Logviewer (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #15:
CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory
Exhaustion in the Worker Messaging Decoder (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #14:
CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client:
Disclosure of the Topology ZooKeeper Credential to Read-Only Users … (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #13:
CVE-2026-82433: Apache Storm Nimbus, Apache Storm UI: Disclosure
of Unredacted Daemon Configuration via Nimbus and the UI (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #12:
CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization
Bypass via Rebalance Configuration Overrides (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #11:
CVE-2026-82431: Apache Storm Client: Authorization Bypass When
nimbus.groups Is Configured Without nimbus.users (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #10:
CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege
Escalation to Root via Container Command Files Chowned to the T… (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #9:
CVE-2026-82429: Apache Storm Worker Launcher: Local Privilege
Escalation to Root via a Time-of-Check Race in the Worker Launc… (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #8:
CVE-2026-82428: Apache Storm Client: Cross-Tenant Dependency Jar
Substitution via Predictable Blob Keys (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #7:
CVE-2026-82427: Apache Storm Nimbus: Path Traversal as the
Supervisor User via Unsanitised Blobstore Map Local Name (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #6:
CVE-2026-82426: Apache Storm Nimbus: Arbitrary File Read on Nimbus
via Unvalidated Uploaded Jar Location (Richard Zowalla <rzo1@...che.org>)
- 2026/09/13 #5:
GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efi (Luppa <essidleith@...il.com>)
- 2026/09/13 #4:
Re: Retrospective by 'gpg.fail' authors (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2026/09/13 #3:
Retrospective by 'gpg.fail' authors (Sam James <sam@...too.org>)
- 2026/09/13 #2:
Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues
for existing installations (Sam James <sam@...too.org>)
- 2026/09/13 #1:
Fwd: UnrealIRCd 6.2.7 released & hot-patch to fix security issues
for existing installations (Sam James <sam@...too.org>)
- 2026/09/12 #4:
Re: AI slops from Eve (Collin Funk <collin.funk1@...il.com>)
- 2026/09/12 #3:
Re: AI slops from Eve ("David A. Wheeler" <dwheeler@...eeler.com>)
- 2026/09/12 #2:
[vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090 (Christian Brabandt <cb@...bit.org>)
- 2026/09/12 #1:
Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey (12345678 <a1489632@...ton.me>)
- 2026/09/11 #11:
Re: pcre2 version 10.48 released with security fixes (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/09/11 #10:
CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in
RegexNameFinderFactory built-in EMAIL and URL patterns (Richard Zowalla <rzo1@...che.org>)
- 2026/09/11 #9:
CVE-2026-67211: Apache OpenNLP: OOM DoS via Unbounded Array
Allocation in SymSpellModelSerializer (Richard Zowalla <rzo1@...che.org>)
- 2026/09/11 #8:
CPython: [CVE-2026-87910] tarfile hardlink fallback
ignores custom extraction filter rejection via None (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/09/11 #7:
Re: AI slops from Eve (Solar Designer <solar@...nwall.com>)
- 2026/09/11 #6:
Re: AI slops from Eve (Joe Krause <r29jk10@...il.com>)
- 2026/09/11 #5:
Re: AI slops from Eve (Solar Designer <solar@...nwall.com>)
- 2026/09/11 #4:
Re: AI slops from Eve (Martin Hecht <martin.hecht@...s.de>)
- 2026/09/11 #3:
CVE-2026-82583, CVE-2026-78224, CVE-2026-82578: NextGen Mirth Connect
SQL injection and XXE (Abhinav Agarwal <abhinavagarwal1996@...il.com>)
- 2026/09/11 #2:
The GNU C Library security advisory update for 2026-09-10 (Siddhesh Poyarekar <siddhesh.poyarekar@...il.com>)
- 2026/09/11 #1:
Re: AI slops from Eve (Ellenor Bjornsdottir <ellenor/securesoftware@...rellix.net>)
- 2026/09/10 #19:
Re: AI slops from Eve (Jeffrey Walton <noloader@...il.com>)
- 2026/09/10 #18:
Re: AI slops from Eve (Eli Schwartz <eschwartz@...too.org>)
- 2026/09/10 #17:
CVE-2026-87464: RCE outside sandbox in Chromium prior to
153.0.8010.36 (Valtteri Vuorikoski <vuori@...com.org>)
- 2026/09/10 #16:
CVE-2026-80354: Apache Camel K: Camel K Builder trait
mavenProfiles ValueSources resolve tenant-named secrets in operat… (Pasquale Congiusti <pcongiusti@...che.o…)
- 2026/09/10 #15:
CVE-2026-80352: Apache Camel K: Camel K Master trait
serviceAccountName YAML injection lets CR author apply arbitrary o… (Pasquale Congiusti <pcongiusti@...che.o…)
- 2026/09/10 #14:
CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach
Maven execution inside operator pod (Pasquale Congiusti <pcongiusti@...che.org>)
- 2026/09/10 #13:
GDCM <= 3.2.7: six memory-safety and denial-of-service
vulnerabilities, no CVE (Abhinav Agarwal <abhinavagarwal1996@...il.com>)
- 2026/09/10 #12:
AI slops from Eve (Solar Designer <solar@...nwall.com>)
- 2026/09/10 #11:
iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level) (Eve <ckr927414@...k.li>)
- 2026/09/10 #10:
Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design) (Eve <ckr927414@...k.li>)
- 2026/09/10 #9:
Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT (Eve <ckr927414@...k.li>)
- 2026/09/10 #8:
Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releases (Solar Designer <solar@...nwall.com>)
- 2026/09/10 #7:
CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message
selector wildcard handling could lead to denial of ser… (Clebert Suconic <clebertsuconic@...che.…)
- 2026/09/10 #6:
CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis:
Pre-authentication Openwire protocol handling can result in qu… (Clebert Suconic <clebertsuconic@...che.…)
- 2026/09/10 #5:
CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing
authentication on CORE protocol session reattachment (Clebert Suconic <clebertsuconic@...che.…)
- 2026/09/10 #4:
CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis:
Message-based management parameter deserialization may lead to… (Clebert Suconic <clebertsuconic@...che.…)
- 2026/09/10 #3:
CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis:
Pre-Authentication Cluster Credential Exposure to Discovered P… (Clebert Suconic <clebertsuconic@...che.…)
- 2026/09/10 #2:
CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis:
Pre-Authentication Information Disclosure in CORE Protocol Top… (Clebert Suconic <clebertsuconic@...che.…)
- 2026/09/10 #1:
CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing
Authentication in CORE Protocol Handler Allows Unautho… (Clebert Suconic <clebertsuconic@...che.…)
- 2026/09/09 #5:
Fwd: XZ Utils 5.8.4 and a security fix (Sam James <sam@...too.org>)
- 2026/09/09 #4:
CVE-2026-37171: SuperTokens Core cross-tenant session isolation
bypass (6.0.0-11.4.0) ("Mr. Gatto" <drew.morana@...il.com>)
- 2026/09/09 #3:
Re: bubblewrap 0.12.0 fixes writes outside sandbox (Simon McVittie <smcv@...ian.org>)
- 2026/09/09 #2:
libpcap 1.10.7 fixes 7 vulnerabilities (Denis Ovsienko <denis@...ienko.info>)
- 2026/09/09 #1:
Security fixes in libfuse-3.18.3 (Sam James <sam@...too.org>)
- 2026/09/08 #24:
CVE-2026-65181: Apache Impala: RCE via External Data Source Class
Loading (Michael Smith <michaelsmith@...che.org>)
- 2026/09/08 #23:
CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF (Michael Smith <michaelsmith@...che.org>)
- 2026/09/08 #22:
CVE-2026-56207: Apache Impala: SAML authentication bypass via
forged bearer token (Michael Smith <michaelsmith@...che.org>)
- 2026/09/08 #21:
CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request
Forgery (Michael Smith <michaelsmith@...che.org>)
- 2026/09/08 #20:
Fwd: Tor Project Forum: Security Release 0.4.9.12 (Sam James <sam@...ct.info>)
- 2026/09/08 #19:
Re: Linux kernel LPEs: ZcopyReaper (CVE-2026-43502)
and 20 more (Dominique Martinet <asmadeus@...ewreck.org>)
34229 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.