[<prev day] [month] [year] [list]
oss-security mailing list - 2026/10/07
- CVE-2026-96659: Foreman: excessive Viewer permissions on preview
(fixed in 3.19.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-96658: Foreman: Safemode bypass leading to RCE (fixed in
3.19.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-56098: Katello: Registry Proxy authorization bypass (fixed
in 4.21.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-56097: Katello: SQL injection in Registry Proxy labels
(fixed in 4.21.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-12545: Hammer CLI: editor command injection (fixed in
3.19.1, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-12544: Foreman: SSTI and unsafe deserialization in
configuration (fixed in 3.19.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-12542: Foreman: command injection in foreman-tail (fixed in
3.19.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-12541: Foreman: command injection in foreman-rake database
tasks (fixed in 3.19.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-12540: Foreman: command injection in foreman-rake
errors:fetch_log (fixed in 3.19.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-12423: Foreman: provisioning token validation flaw (fixed in
3.19.2, 5.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-12405: Foreman Remote Execution: command injection via
effective_user (fixed in 16.6.6, 17.2.2, 18.0.1) (Ondrej Gajdusek <ogajduse@...hat.com>)
- CVE-2026-94114: Apache Commons BCEL: Nested Code/Record attributes
drive unbounded parse-time recursion in ClassParser ("Gary D. Gregory" <ggregory@...che.org>)
- CVE-2026-105111: Apache Commons BCEL: Class2HTML emits unescaped
class strings, enabling stored XSS ("Gary D. Gregory" <ggregory@...che.org>)
- CVE-2026-105239: Apache log4net: NUL character truncates
EventLogAppender records (Jan Friedrich <freeandnil@...che.org>)
- CVE-2026-105241: Apache log4net: Unencodable content discards a
whole SmtpPickupDirAppender batch (Jan Friedrich <freeandnil@...che.org>)
- CVE-2026-105242: Apache log4net: Request validation failure drops
the event in the aspnet-request converter (Jan Friedrich <freeandnil@...che.org>)
- CVE-2026-105243: Apache log4net: Oversize EventLogAppender record
silently discarded (Jan Friedrich <freeandnil@...che.org>)
- CVE-2026-105240: Apache log4net: NUL character truncates
OutputDebugStringAppender records (Jan Friedrich <freeandnil@...che.org>)
- CVE-2026-105244: Apache log4net: RemoteSyslogAppender silently
deletes non-ASCII content (Jan Friedrich <freeandnil@...che.org>)
- CVE-2026-90466: Apache Impala: Path traversal executes JARs
outside trusted paths (Michael Smith <michaelsmith@...che.org>)
- CVE-2026-93684: Apache Impala: Stored XSS in Impala query plans (Michael Smith <michaelsmith@...che.org>)
- CVE-2026-97720: Apache Impala: Impala Executor Webserver Auth
Bypass (Michael Smith <michaelsmith@...che.org>)
- FW: X.Org Security Advisory: multiple security issues in X.Org X
server (Peter Hutterer <peter.hutterer@...-t.net>)
- CVE-2026-78243: Apache YuniKorn: LDAP Group provider panics on
lowercase attribute name (Wilfred Spiegelenburg <wilfreds@...che.org>)
- CVE-2026-92393: Apache YuniKorn: Admission control bypass via
workload UPDATE operation (Wilfred Spiegelenburg <wilfreds@...che.org>)
- CVE-2026-97146: Apache YuniKorn: Admission control bypass via
system label forgery (Wilfred Spiegelenburg <wilfreds@...che.org>)
26 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.