oss-security mailing list
Recent messages:
- 2026/09/23 #36:
[kubernetes] CVE-2026-76654: Subpath symlinking on Windows nodes
permits NTLM coercion (Nathan Herz <nathan.herz97@...il.com>)
- 2026/09/23 #35:
[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write
permissions allow cross-namespace pod creation (Nathan Herz <nathan.herz97@...il.com>)
- 2026/09/23 #34:
Re: Flatpak 1.18.1 fixes multiple vulnerabilities (Simon McVittie <smcv@...ian.org>)
- 2026/09/23 #33:
CVE-2026-86247: Apache Tomcat Native: Client certificate requirements
can be down-graded (Mark Thomas <markt@...che.org>)
- 2026/09/23 #32:
CVE-2026-86246: Apache Tomcat Native: Insecure OpenSSL options
enabled (Mark Thomas <markt@...che.org>)
- 2026/09/23 #31:
CVE-2026-86243: Apache Tomcat Native: DoS via TLS handshake (Mark Thomas <markt@...che.org>)
- 2026/09/23 #30:
CVE-2026-87022: Apache Tomcat: WebSocket message smuggling with
per-message-deflate (Mark Thomas <markt@...che.org>)
- 2026/09/23 #29:
CVE-2026-86350: Apache Tomcat: Regression in fix for CVE-2026-41293
can trigger request header mix-up (Mark Thomas <markt@...che.org>)
- 2026/09/23 #28:
CVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete.
OCSP checks sometimes soft-fail with FFM even when soft-fa… (Mark Thomas <markt@...che.org>)
- 2026/09/23 #27:
CVE-2026-79677: Apache Tomcat: WebSocket DoS due to lost asynchronous
write timeout (Mark Thomas <markt@...che.org>)
- 2026/09/23 #26:
CVE-2026-78437: Apache Tomcat: HTTP/2 DoS via malformed request (Mark Thomas <markt@...che.org>)
- 2026/09/23 #25:
CVE-2026-78383: Apache Tomcat: AJP DoS via missing request body (Mark Thomas <markt@...che.org>)
- 2026/09/23 #24:
CVE-2026-77791: Apache Tomcat: DoS via busy wait during WebSocket
close (Mark Thomas <markt@...che.org>)
- 2026/09/23 #23:
CVE-2026-77762: Apache Tomcat: Stale HPACK emitter injects trailers
into recycled pooled Request (Mark Thomas <markt@...che.org>)
- 2026/09/23 #22:
CVE-2026-77756: Apache Tomcat: Transfer-Encoding honored for HTTP/1.0
requests (Mark Thomas <markt@...che.org>)
- 2026/09/23 #21:
CVE-2026-76183: Apache Tomcat: Bypass of security constraints for
WebSocket endpoints (Mark Thomas <markt@...che.org>)
- 2026/09/23 #20:
CVE-2026-75973: Apache Tomcat: Cross-context authentication mix-up
with Jakarta Authentication configured (Mark Thomas <markt@...che.org>)
- 2026/09/23 #19:
CVE-2026-73581: Apache Tomcat: OpenSSL and OpenSSL-FFM TLS
implementations ignore CRLs when certificate uses a keystore (Mark Thomas <markt@...che.org>)
- 2026/09/23 #18:
CVE-2026-73192: Apache Sling XSS: XSS possible through
XSSAPI.getValidHref() (Joerg Hoh <joerghoh@...che.org>)
- 2026/09/23 #17:
CVE-2026-94251: Apache Sling Security Bundle:
ContentDispositionFilter mediates only one address/API shape of a resource
(Joerg Hoh <joerghoh@...che.org>)
- 2026/09/23 #16:
CVE-2026-94243: Apache Sling Security Bundle: RefererFilter
accepts weaker-than-origin evidence (Joerg Hoh <joerghoh@...che.org>)
- 2026/09/23 #15:
CVE-2026-92001: Apache Sling XSS: Missing parser resource limits (Joerg Hoh <joerghoh@...che.org>)
- 2026/09/23 #14:
CVE-2026-91999: Apache Sling XSS: Improper escaping in the XSS
Webconsole plugin (Joerg Hoh <joerghoh@...che.org>)
- 2026/09/23 #13:
CVE-2026-91928: Apache Sling XSS: Sanitizer bypass, uncontrolled
resource consumption and failure pf protection mechanisms (Joerg Hoh <joerghoh@...che.org>)
- 2026/09/23 #12:
CVE-2026-91852: Apache Sling XSS: CWE-79 multiple raw-string
break-outs and ReDOS in XSSImpl (Joerg Hoh <joerghoh@...che.org>)
- 2026/09/23 #11:
CVE-2026-96443: Apache Doris: JDBC driver URL validation bypass
leads to remote code execution (Calvin Kirs <kirs@...che.org>)
- 2026/09/23 #10:
CVE-2026-31377: Apache Doris: Improper Authentication Allows
Unauthorized Access to FE Meta Service (Calvin Kirs <kirs@...che.org>)
- 2026/09/23 #9:
CVE-2026-82331: Apache BuildStream: tar source extraction escape (Jürg Billeter <juergbi@...che.org>)
- 2026/09/23 #8:
npm registry keeps removed-version timestamps but drops the reason
(Sept 2025 campaign as evidence) (ezraax@...nds.app)
- 2026/09/23 #7:
Re: GNU Emacs vulnerability upon opening arbitrary
file (Tomas Hoger <thoger@...hat.com>)
- 2026/09/23 #6:
Re: Emacs arbitrary code execution:
incomplete fix for CVE-2024-53920 (Tomas Hoger <thoger@...hat.com>)
- 2026/09/23 #5:
xdg-dbus-proxy 0.1.9 fixes sandbox escape
CVE-2026-94422 (Simon McVittie <smcv@...ian.org>)
- 2026/09/23 #4:
Vulnerabilities in ntfs-3g (Rostislav <rostislav@...era.com>)
- 2026/09/23 #3:
Re: CVE-2026-95831: Crypt::SelfCertificate versions
from 1.01 through 1.05 for Perl contains malware which executes Python… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/09/23 #2:
Re: CVE-2026-95831: Crypt::SelfCertificate versions
from 1.01 through 1.05 for Perl contains malware which executes Python
code fro… (Sam James <sam@...too.org>)
- 2026/09/23 #1:
CVE-2026-94184: some builds of fetchmail 6.6.6 and older vulnerable
to remote code execution in NTLM authentication cli… (Matthias Andree <matthias.andree@....de…)
- 2026/09/22 #24:
Re: xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast
message filtering bypass (Simon McVittie <smcv@...ian.org>)
- 2026/09/22 #23:
Re: bubblewrap 0.12.0 fixes writes outside sandbox (Simon McVittie <smcv@...ian.org>)
- 2026/09/22 #22:
Re: Flatpak 1.18.1 fixes multiple vulnerabilities (Simon McVittie <smcv@...ian.org>)
- 2026/09/22 #21:
CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through
1.05 for Perl contains malware which executes Python cod… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/09/22 #20:
The GNU C Library security advisories update for 2026-09-22 (Carlos O'Donell <carlos@...hat.com>)
- 2026/09/22 #19:
rsyslog imdtls permitted-peer authorization bypass (Rainer Gerhards <rgerhards@...adiscon.com>)
- 2026/09/22 #18:
[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection
leading to remote code execution in Octavia (CVE-202… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/09/22 #17:
CVE-2026-87082: Net::IDN::Punycode versions before 2.590 for Perl
hang, crash or return a wrong label via unvalidated malformed UT… (Paul Johnson <paul@...j.net>)
- 2026/09/22 #16:
CVE-2026-87081: Net::IDN::UTS46 versions before 2.590 for Perl allow
CPU exhaustion via quadratic punycode encoding of an overlong… (Paul Johnson <paul@...j.net>)
- 2026/09/22 #15:
CVE-2026-87080: Net::IDN::Punycode::PP versions before 2.590 for
Perl decode a truncated label to a name containing a character it… (Paul Johnson <paul@...j.net>)
- 2026/09/22 #14:
CVE-2026-87079: Net::IDN::Punycode versions before 2.590 for Perl
allow CPU exhaustion via quadratic insertion cost when decoding … (Paul Johnson <paul@...j.net>)
- 2026/09/22 #13:
CVE-2026-87078: Net::IDN::Punycode versions from 2.302 before 2.590
for Perl leak the output buffer on every rejected label in dec… (Paul Johnson <paul@...j.net>)
- 2026/09/22 #12:
CVE-2026-74766: Net::IDN::Punycode versions from 2.301 before 2.590
for Perl allow a heap use-after-free via a decoded code point … (Paul Johnson <paul@...j.net>)
- 2026/09/22 #11:
CVE-2026-74765: Net::IDN::Punycode versions before 2.590 for Perl
allow an out-of-bounds read via integer overflow of the delta ac… (Paul Johnson <paul@...j.net>)
- 2026/09/22 #10:
CVE-2016-15059: Net::IDN::Punycode versions before 2.301 for Perl
allow a heap buffer overflow via unchecked writes past the outpu… (Paul Johnson <paul@...j.net>)
- 2026/09/22 #9:
Re: Emacs arbitrary code execution:
incomplete fix for CVE-2024-53920 (Bas Alberts <anticomputer@...hub.com>)
- 2026/09/22 #8:
libexpat 2.8.5 fixes CVE-2026-93990 (malformed UTF-16 smuggling) (Sebastian Pipping <sebastian@...ping.org>)
- 2026/09/22 #7:
New OpenSSL Releases (Norbert Pócs <norbertp@...nssl.org>)
- 2026/09/22 #6:
Re: Vulnerabilities in libheif and libde265 (Hanno Böck <hanno@...eck.de>)
- 2026/09/22 #5:
Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Eli Schwartz <eschwartz@...too.org>)
- 2026/09/22 #4:
CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl
serve files from outside public_dir via relative path segments … (Stig Palmquist <stig@...g.io>)
- 2026/09/22 #3:
CVE-2026-93711: Dancer2 versions before 2.2.0 for Perl do not strip
CR and LF from response header names in headers_to_array (Stig Palmquist <stig@...g.io>)
- 2026/09/22 #2:
CVE-2026-93710: Dancer2 versions from 2.0.0 before 2.2.0 for Perl
dispatch a route that a dying hook refused when the exception h… (Stig Palmquist <stig@...g.io>)
- 2026/09/22 #1:
CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout
as a page when an equivalent spelling of its path misses th… (Stig Palmquist <stig@...g.io>)
- 2026/09/21 #9:
Re: Emacs arbitrary code execution: incomplete fix
for CVE-2024-53920 (Tomas Hoger <thoger@...hat.com>)
- 2026/09/21 #8:
CVE-2026-93012: Email::Sender::Transport::Sendmail versions before
2.602 for Perl allow arbitrary command execution on Windows se… (Stig Palmquist <stig@...g.io>)
- 2026/09/21 #7:
[OSSA-2026-040] OpenStack Blazar: Multiple authorization
vulnerabilities in the Blazar V2 lease API (CVE-2026-93852, CV… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/09/21 #6:
[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection
leading to remote code execution in Octavia (CVE-202… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/09/21 #5:
CVE-2026-86473: Apache Airflow: Logout ignores a presented
Authorization bearer token, leaving it revocable only by expiry (Rahul Vats <rahulvats@...che.org>)
- 2026/09/21 #4:
CVE-2026-82355: Apache Airflow: Session cookie silently overrides
explicit Authorization bearer header, enabling session fixa… (Rahul Vats <rahulvats@...che.org>)
- 2026/09/21 #3:
CVE-2026-75158: Apache Airflow: Assets events API returns asset
events for every Dag with no per-Dag authorization filter (Rahul Vats <rahulvats@...che.org>)
- 2026/09/21 #2:
CVE-2026-94301: Apache MINA: CVE-2026-47065 resolveProxyClass fix
missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.1… (Emmanuel Lécharny <elecharny@...che.or…)
- 2026/09/21 #1:
CVE-2026-47321: Apache MINA: Unbounded Decompression Amplification
DoS in Zlib.inflate (Emmanuel Lécharny <elecharny@...che.org>)
- 2026/09/20 #3:
Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill (Roman Fiedler <roman.fiedler@...aralleled.eu>)
- 2026/09/20 #2:
rsyslog: mmpstrucdata denial of service fixed in 8.2606.0 (Rainer Gerhards <rgerhards@...adiscon.com>)
- 2026/09/20 #1:
Re: Suricata 8.0.7 released with 67 vulnerabilities
fixed (Sam James <sam@...too.org>)
- 2026/09/19 #7:
Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Greg Dahlman <dahlman@...il.com>)
- 2026/09/19 #6:
CVE-2026-82560: Pod::Text versions before 6.1.1 for Perl allow CPU
and memory exhaustion formatting a POD document whose =over ne… (Stig Palmquist <stig@...g.io>)
- 2026/09/19 #5:
Re: Vulnerabilities in libheif and libde265 (Hanno Böck <hanno@...eck.de>)
- 2026/09/19 #4:
CVE-2026-78030: DBI versions before 1.653 for Perl load arbitrary
modules via unvalidated dbm_type and dbm_mldbm attribute… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/09/19 #3:
Re: Suricata 8.0.7 released with 67 vulnerabilities
fixed (Victor Julien <lists@...iniac.net>)
- 2026/09/19 #2:
Exim Security Release 4.100.1 (Solar Designer <solar@...nwall.com>)
- 2026/09/19 #1:
Suricata 8.0.7 released with 67 vulnerabilities fixed (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/09/18 #17:
Vulnerabilities in libheif and libde265 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/09/18 #16:
Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (SOFIA ETCHEPARE DARONCO <sofia.etchepare@...d.ufsm.br>)
- 2026/09/18 #15:
Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Eli Schwartz <eschwartz@...too.org>)
- 2026/09/18 #14:
CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total
timeout, allowing a slow server to hang the request in… (Colm O hEigeartaigh <coheigea@...che.or…)
- 2026/09/18 #13:
CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded
work during intersection leading to denial of service (Colm O hEigeartaigh <coheigea@...che.or…)
- 2026/09/18 #12:
CVE-2026-91865: Apache Neethi: Crafted policy references cause
exponential expansion during normalization leading to de… (Colm O hEigeartaigh <coheigea@...che.or…)
- 2026/09/18 #11:
CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass
element/attribute limits causing memory exhaustion (Colm O hEigeartaigh <coheigea@...che.org…)
- 2026/09/18 #10:
CVE-2026-91863: Apache Neethi: Uncontrolled recursion while
parsing crafted WS-Policy documents allows denial of servic… (Colm O hEigeartaigh <coheigea@...che.or…)
- 2026/09/18 #9:
CVE-2026-93019: Imager versions before 1.036 for Perl exit the
process reading a TGA with a colour map length of 32768 or more in… (Stig Palmquist <stig@...g.io>)
- 2026/09/18 #8:
CVE-2026-93018: Imager versions before 1.036 for Perl disclose
uninitialised heap memory reading a paletted image with pixel inde… (Stig Palmquist <stig@...g.io>)
- 2026/09/18 #7:
Re: Removing dead code (was: Retrospective by
'gpg.fail' authors) (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2026/09/18 #6:
Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Kevin Riggle <kevinr@...plexsystems.group>)
- 2026/09/18 #5:
Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Valtteri Vuorikoski <vuori@...com.org>)
- 2026/09/18 #4:
Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Hanno Böck <hanno@...eck.de>)
- 2026/09/18 #3:
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill (manizada <manizada@...me>)
- 2026/09/18 #2:
Re: Removing dead code (was: Retrospective by
'gpg.fail' authors) (Jacob Bachmeyer <jcb62281@...il.com>)
- 2026/09/18 #1:
CVE-2026-75157: Apache Airflow: Asset queued-events DELETE
endpoints gated on Dag READ instead of Dag EDIT (asset-triggered
… (Rahul Vats <rahulvats@...che.org>)
- 2026/09/17 #6:
CVE-2026-73639: Imager::File::PNG versions from 1.003 before 1.004
for Perl write past the end of the row buffer reading a PNG wi… (Stig Palmquist <stig@...g.io>)
- 2026/09/17 #5:
CVE-2026-73638: Imager versions from 0.45_02 before 1.035 for Perl
read outside the EXIF block via unchecked start offsets in tif… (Stig Palmquist <stig@...g.io>)
- 2026/09/17 #4:
The GNU C Library security advisories update for 2026-09-17 (Adhemerval Zanella Netto <adhemerval.zanella@...aro.org>)
- 2026/09/17 #3:
CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references
via static ThreadLocal caching (Jean-Baptiste Onofré <jbonofre@...che.org>)
34362 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.