oss-security mailing list
Recent messages:
- 2026/09/06 #2:
CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write (Stefan Bodewig <bodewig@...che.org>)
- 2026/09/06 #1:
CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100
for Perl accept replayed authentication responses vi… (Timothy Legge <timlegge@...nsec.org>)
- 2026/09/05 #5:
Fwd: Security vulnerabilities fixed in WeeChat 4.10.1 (Sam James <sam@...too.org>)
- 2026/09/05 #4:
Re: Vulnerabilities fixed in libxml2-2.15.4 (Salvatore Bonaccorso <carnil@...ian.org>)
- 2026/09/05 #3:
Re: pcre2 version 10.48 released with security fixes (Salvatore Bonaccorso <carnil@...ian.org>)
- 2026/09/05 #2:
Re: Vulnerability fixes in util-linux-2.42.3 (Salvatore Bonaccorso <carnil@...ian.org>)
- 2026/09/05 #1:
Re: Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released (Salvatore Bonaccorso <carnil@...ian.org>)
- 2026/09/04 #7:
pcre2 version 10.48 released with security fixes (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/09/04 #6:
Vulnerability fixes in util-linux-2.42.3 (Sam James <sam@...too.org>)
- 2026/09/04 #5:
Vulnerabilities fixed in libxml2-2.15.4 (Sam James <sam@...too.org>)
- 2026/09/04 #4:
CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL
Injection Vulnerability in Hive Metastore Module (Arnout Engelen <engelen@...che.org>)
- 2026/09/04 #3:
CVE-2026-82309: Robots::Validate versions from 0.3.2 before 0.3.11
for Perl allow unbounded outbound DNS queries per valid… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/09/04 #2:
CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI
dashboard widgets (incomplete fix of CVE-2025-54057) (Sheng Wu <wusheng@...che.org>)
- 2026/09/04 #1:
CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits
the integration routing key over cleartext HTTP (Kai Wan <wankai@...che.org>)
- 2026/09/03 #6:
CVE-2026-81270: Apache Allura: Information exposure via search (Dave Brondsema <dave@...ndsema.net>)
- 2026/09/03 #5:
CVE-2026-80190: Apache Allura: Stored XSS via code repositories (Dave Brondsema <dave@...ndsema.net>)
- 2026/09/03 #4:
CVE-2026-80181: Apache Allura: Server-side request forgery (Dave Brondsema <dave@...ndsema.net>)
- 2026/09/03 #3:
CVE-2026-80180: Apache Allura: Stored XSS via markdown HTML
processing (Dave Brondsema <dave@...ndsema.net>)
- 2026/09/03 #2:
[OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in
web-download and HTTP image APIs (CVE-2026-71196, CV… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/09/03 #1:
CVE-2026-80530: Linux XFS EXCHANGE_RANGE reflink flag clearing
leading to local privilege escalation (Lin Jiapeng <ljp1205831794@...il.com>)
- 2026/09/02 #5:
Fwd: Vulnerabilities in golang.org/x/crypto (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/09/02 #4:
Multiple vulnerabilities in Jenkins and Jenkins plugins (Kevin Guerroudj <kguerroudj@...udbees.com>)
- 2026/09/02 #3:
Re: Fwd: [Announce] Libgcrypt 1.12.3 released (Sam James <sam@...too.org>)
- 2026/09/02 #2:
[SECURITY ADVISORIES] curl 8.22.0 (Daniel Stenberg <daniel@...x.se>)
- 2026/09/02 #1:
CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory
exhaustion via unbounded recursion in sig_data when re… (Timothy Legge <timlegge@...nsec.org>)
- 2026/09/01 #4:
CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4
(Holden Karau <holden@...che.org>)
- 2026/09/01 #3:
CVE-2026-80205 : ReDoS in NLTK Text.findall() (CVSS 8.7 High) (Aditi Bhatnagar <aditi@...gridsec.com>)
- 2026/09/01 #2:
FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0,
pre-auth RCE demonstrated (Samuel Page <sam@...ar.io>)
- 2026/09/01 #1:
Re: CVE-2026-19873: HTML::FormFu versions through 2.08
for Perl allow resource exhaustion via an unbounded repeat count fr… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/31 #14:
CVE-2026-19953: URI versions before 5.36 for Perl encode non-NFC host
names to non-standard punycode labels via missing no… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/31 #13:
libexpat 2.8.4 fixes 4 vulnerabilities (Sebastian Pipping <sebastian@...ping.org>)
- 2026/08/31 #12:
Plone security advisory 20260831 ("Maurits van Rees (Plone)" <maurits@...ne.org>)
- 2026/08/31 #11:
Re: Fwd: [Announce] Libgcrypt 1.12.3 released (Werner Koch <wk@...pg.org>)
- 2026/08/31 #10:
libksba-1.8.1 fixes a possible CMS parser infinite loop (Sam James <sam@...too.org>)
- 2026/08/31 #9:
LACT: Polkit Authentication Bypass and Temporary File Handling
Issues (CVE-2026-75037, CVE-2026-75038) (Matthias Gerstner <mgerstner@...e.de>)
- 2026/08/31 #8:
Fwd: [Announce] Libgcrypt 1.12.3 released (Sam James <sam@...too.org>)
- 2026/08/31 #7:
CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow
resource exhaustion via an unbounded repeat count from t… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/31 #6:
CVE-2026-76986: Apache Wicket: XSS in AbstractSingleSelectChoice
via getNullValidDisplayValue (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/31 #5:
CVE-2026-76985: Apache Wicket: XSS in Palette via
getAdditionalAttributes (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/31 #4:
CVE-2026-76984: Apache Wicket: XSS in MetaDataHeaderItem via
addTagAttribute (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/31 #3:
CVE-2026-76983: Apache Wicket: XSS in AutoLabelTextResolver via
FormComponent.setLabel (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/31 #2:
CVE-2026-76982: Apache Wicket: XSS in Button via its model object (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/31 #1:
CVE-2026-75802: Apache Wicket: XSS in AjaxEditableLabel and its
subclasses via IChoiceRenderer and defaultNullLabel (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/30 #5:
CVE-2026-71378: Apache Wicket: Cross-Site Request Forgery (CSRF)
protection bypass in ResourceIsolationRequestCycleListe… (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/30 #4:
CVE-2026-71257: Apache Wicket: Configured file upload limits are
not enforced when the multipart request has already bee… (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/30 #3:
CVE-2026-70449: Apache Wicket: Path traversal in resource
style/variation/locale (Emond Papegaaij <papegaaij@...che.org>)
- 2026/08/30 #2:
CVE-2026-58301: Apache Shiro: Server-side POST request may be
steered to an alternate host (Lenny Primak <lprimak@...che.org>)
- 2026/08/30 #1:
Exiv2 0.28.9 released (Kevin Backhouse <kevin.backhouse@...il.com>)
- 2026/08/29 #4:
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via
full-schema "did you mean" suggestion scan (William Carrier <0x6675636b736f6369617479@...il.com>)
- 2026/08/29 #3:
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS from a
single syntax error (William Carrier <0x6675636b736f6369617479@...il.com>)
- 2026/08/29 #2:
Re: graphql-go/graphql <= 0.8.1: improper scalar input-type
validation -> type confusion and unrecoverable stack-overfl… (William Carrier <0x6675636b736f63696174…)
- 2026/08/29 #1:
CVE-2026-78002: rsyslog RainerScript replace() heap buffer overflow (Rainer Gerhards <rgerhards@...adiscon.com>)
- 2026/08/28 #5:
Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released (Chad Dougherty <crd@...rew.cmu.edu>)
- 2026/08/28 #4:
Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293) ("t.preissl" <t.preissl@...me>)
- 2026/08/28 #3:
[CVE-2026-8715] HashiCorp Vault Secrets Operator 1.3.0-1.4.1: tenant-controlled secretIDPath leaks operator ServiceAccount token… (cherez0ff <cherez0ff@...ton.me>)
- 2026/08/28 #2:
NSD 4.15.1 security release (Willem Toorop <willem@...etlabs.nl>)
- 2026/08/28 #1:
Dovecot Security Advisory 3/2026 (Aki Tuomi <aki.tuomi@...ecot.fi>)
- 2026/08/27 #7:
bubblewrap 0.12.0 fixes writes outside sandbox (Simon McVittie <smcv@...ian.org>)
- 2026/08/27 #6:
The GNU C Library security advisory update for 2026-08-27 (Siddhesh Poyarekar <siddhesh.poyarekar@...il.com>)
- 2026/08/27 #5:
Re: Re: Reporter attribution is absent from GitHub's
machine-readable vulnerability records, and from the NVD entirely (Greg KH <greg@...ah.com>)
- 2026/08/27 #4:
Re: Re: Reporter attribution is absent from GitHub's
machine-readable vulnerability records, and from the NVD entirely (Syed <anasmohiddinsyed@...il.com>)
- 2026/08/27 #3:
Re: Reporter attribution is absent from GitHub's
machine-readable vulnerability records, and from the NVD entirely (Greg KH <greg@...ah.com>)
- 2026/08/27 #2:
Re: CVE-2026-41992 gzip 1.14 out-of-bounds memory
buffer access (Jim Meyering <jim@...ering.net>)
- 2026/08/27 #1:
Reporter attribution is absent from GitHub's machine-readable
vulnerability records, and from the NVD entirely (Syed <anasmohiddinsyed@...il.com>)
- 2026/08/26 #18:
[vim-security] Integer Overflow in Undo File Entry Size Check in Vim
< v9.2.1014 && Vim >= v8.1.0688 (Christian Brabandt <cb@...bit.org>)
- 2026/08/26 #17:
[vim-security] Out-of-bounds Access in libvterm Resize Handling in
Vim < 9.2.1013 (Christian Brabandt <cb@...bit.org>)
- 2026/08/26 #16:
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via
per-error full-document rescan (GetLocation) (First name Last name <0x6675636b736f6369617479@...i…)
- 2026/08/26 #15:
Re: Emacs zero-click local command execution via TRAMP (Sean Whitton <spwhitton@...hitton.name>)
- 2026/08/26 #14:
CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree
identity impersonation (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #13:
CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #12:
CVE-2026-74848: Apache APISIX: Cross-user response poisoning in
serverless plugins (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #11:
CVE-2026-63041: Apache APISIX: attach-consumer-label does not
strip client-supplied consumer-label headers (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #10:
CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session
survives end of HTTP session (Mark Thomas <markt@...che.org>)
- 2026/08/26 #9:
CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2
backlog tracking when a stream is reset (Mark Thomas <markt@...che.org>)
- 2026/08/26 #8:
CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some
cases (Mark Thomas <markt@...che.org>)
- 2026/08/26 #7:
CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass
method specific constraints (Mark Thomas <markt@...che.org>)
- 2026/08/26 #6:
CVE-2026-66422: Apache Tomcat: Servlet role references can bypass
declarative role constraints (Mark Thomas <markt@...che.org>)
- 2026/08/26 #5:
CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the
second rule and may bypass access control (Mark Thomas <markt@...che.org>)
- 2026/08/26 #4:
CVE-2026-65905: Apache Tomcat: Limited replay attack possible with
DIGEST authentication (Mark Thomas <markt@...che.org>)
- 2026/08/26 #3:
CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict
SNI validation - CVE-2026-32990 fix incomplete (Mark Thomas <markt@...che.org>)
- 2026/08/26 #2:
CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific
permissions for Unix Domain Sockets (Mark Thomas <markt@...che.org>)
- 2026/08/26 #1:
CVE-2026-65182: Apache Tomcat: Bypass longest prefix security
constraint (Mark Thomas <markt@...che.org>)
- 2026/08/25 #10:
[CVE-2026-19672] CPython: tarfile extraction filter
bypass allows creation of directories outside the destination (Alan Coopersmith <alan.coopersmith@...cle.co…)
- 2026/08/25 #9:
Re: [OSSA-2026-037] OpenStack Keystone: Inconsistent scope
enforcement for delegated tokens (CVE-2026-80182, CVE-2026-8… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/08/25 #8:
[vim-security] Arbitrary Ex Command Execution via File Names in C
Omni-Completion in Vim < 9.2.1011 (Christian Brabandt <cb@...bit.org>)
- 2026/08/25 #7:
CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl
allow the second-factor attempt limit to be reset by repl… (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/25 #6:
CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl
accept another account's recovery code at the two-factor … (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/25 #5:
[OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement
for delegated tokens (CVE-2026-pending) (Goutham Pacha Ravi <gouthampravi@...il.com>)
- 2026/08/25 #4:
OpenRGB: Remote System Compromise via Custom Network Protocol
(CVE-2026-59682, CVE-2026-59683, CVE-2026-18794) (Matthias Gerstner <mgerstner@...e.de>)
- 2026/08/25 #3:
OpenSSL Security Advisory [25th August 2026] (Tomas Mraz <tomas@...nssl.foundation>)
- 2026/08/25 #2:
graphql-go/graphql <= 0.8.1: improper scalar input-type validation ->
type confusion and unrecoverable stack-overflow D… (First name Last name <0x6675636b736f636…)
- 2026/08/25 #1:
Re: CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access (Solar Designer <solar@...nwall.com>)
- 2026/08/24 #14:
CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint
discarded the undertow-specific header filter strategy in fa… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #13:
CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket:
WebSocket dispatch header injection (Andrea Cosentino <acosentino@...che.org>)
- 2026/08/24 #12:
CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT
authentication was configured with a keystore but no i… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #11:
CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer
appended the remote object name to the configured down… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #10:
CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the
downloadBlobToFile operation built the local download targe… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #9:
CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension
fields received in structured content mode were mappe… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #8:
CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the
downloadToFile operation built the local download targe… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #7:
CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data
format copied MIME headers onto the Camel message with… (Andrea Cosentino <acosentino@...che.org…)
34107 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.