oss-security mailing list
Recent messages:
- 2026/08/27 #5:
Re: Re: Reporter attribution is absent from GitHub's
machine-readable vulnerability records, and from the NVD entirely (Greg KH <greg@...ah.com>)
- 2026/08/27 #4:
Re: Re: Reporter attribution is absent from GitHub's
machine-readable vulnerability records, and from the NVD entirely (Syed <anasmohiddinsyed@...il.com>)
- 2026/08/27 #3:
Re: Reporter attribution is absent from GitHub's
machine-readable vulnerability records, and from the NVD entirely (Greg KH <greg@...ah.com>)
- 2026/08/27 #2:
Re: CVE-2026-41992 gzip 1.14 out-of-bounds memory
buffer access (Jim Meyering <jim@...ering.net>)
- 2026/08/27 #1:
Reporter attribution is absent from GitHub's machine-readable
vulnerability records, and from the NVD entirely (Syed <anasmohiddinsyed@...il.com>)
- 2026/08/26 #18:
[vim-security] Integer Overflow in Undo File Entry Size Check in Vim
< v9.2.1014 && Vim >= v8.1.0688 (Christian Brabandt <cb@...bit.org>)
- 2026/08/26 #17:
[vim-security] Out-of-bounds Access in libvterm Resize Handling in
Vim < 9.2.1013 (Christian Brabandt <cb@...bit.org>)
- 2026/08/26 #16:
graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via
per-error full-document rescan (GetLocation) (First name Last name <0x6675636b736f6369617479@...i…)
- 2026/08/26 #15:
Re: Emacs zero-click local command execution via TRAMP (Sean Whitton <spwhitton@...hitton.name>)
- 2026/08/26 #14:
CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree
identity impersonation (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #13:
CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #12:
CVE-2026-74848: Apache APISIX: Cross-user response poisoning in
serverless plugins (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #11:
CVE-2026-63041: Apache APISIX: attach-consumer-label does not
strip client-supplied consumer-label headers (Abhishek Choudhary <shreemaanabhishek@...che.org>)
- 2026/08/26 #10:
CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session
survives end of HTTP session (Mark Thomas <markt@...che.org>)
- 2026/08/26 #9:
CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2
backlog tracking when a stream is reset (Mark Thomas <markt@...che.org>)
- 2026/08/26 #8:
CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some
cases (Mark Thomas <markt@...che.org>)
- 2026/08/26 #7:
CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass
method specific constraints (Mark Thomas <markt@...che.org>)
- 2026/08/26 #6:
CVE-2026-66422: Apache Tomcat: Servlet role references can bypass
declarative role constraints (Mark Thomas <markt@...che.org>)
- 2026/08/26 #5:
CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the
second rule and may bypass access control (Mark Thomas <markt@...che.org>)
- 2026/08/26 #4:
CVE-2026-65905: Apache Tomcat: Limited replay attack possible with
DIGEST authentication (Mark Thomas <markt@...che.org>)
- 2026/08/26 #3:
CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict
SNI validation - CVE-2026-32990 fix incomplete (Mark Thomas <markt@...che.org>)
- 2026/08/26 #2:
CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific
permissions for Unix Domain Sockets (Mark Thomas <markt@...che.org>)
- 2026/08/26 #1:
CVE-2026-65182: Apache Tomcat: Bypass longest prefix security
constraint (Mark Thomas <markt@...che.org>)
- 2026/08/25 #10:
[CVE-2026-19672] CPython: tarfile extraction filter
bypass allows creation of directories outside the destination (Alan Coopersmith <alan.coopersmith@...cle.co…)
- 2026/08/25 #9:
Re: [OSSA-2026-037] OpenStack Keystone: Inconsistent scope
enforcement for delegated tokens (CVE-2026-80182, CVE-2026-8… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/08/25 #8:
[vim-security] Arbitrary Ex Command Execution via File Names in C
Omni-Completion in Vim < 9.2.1011 (Christian Brabandt <cb@...bit.org>)
- 2026/08/25 #7:
CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl
allow the second-factor attempt limit to be reset by repl… (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/25 #6:
CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl
accept another account's recovery code at the two-factor … (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/25 #5:
[OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement
for delegated tokens (CVE-2026-pending) (Goutham Pacha Ravi <gouthampravi@...il.com>)
- 2026/08/25 #4:
OpenRGB: Remote System Compromise via Custom Network Protocol
(CVE-2026-59682, CVE-2026-59683, CVE-2026-18794) (Matthias Gerstner <mgerstner@...e.de>)
- 2026/08/25 #3:
OpenSSL Security Advisory [25th August 2026] (Tomas Mraz <tomas@...nssl.foundation>)
- 2026/08/25 #2:
graphql-go/graphql <= 0.8.1: improper scalar input-type validation ->
type confusion and unrecoverable stack-overflow D… (First name Last name <0x6675636b736f636…)
- 2026/08/25 #1:
Re: CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access (Solar Designer <solar@...nwall.com>)
- 2026/08/24 #14:
CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint
discarded the undertow-specific header filter strategy in fa… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #13:
CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket:
WebSocket dispatch header injection (Andrea Cosentino <acosentino@...che.org>)
- 2026/08/24 #12:
CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT
authentication was configured with a keystore but no i… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #11:
CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer
appended the remote object name to the configured down… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #10:
CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the
downloadBlobToFile operation built the local download targe… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #9:
CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension
fields received in structured content mode were mappe… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #8:
CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the
downloadToFile operation built the local download targe… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #7:
CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data
format copied MIME headers onto the Camel message with… (Andrea Cosentino <acosentino@...che.org…)
- 2026/08/24 #6:
CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure (Dave Brondsema <dave@...ndsema.net>)
- 2026/08/24 #5:
CVE-2026-78331 / CVE-2026-78332: Multiple Vulnerabilities in NethServer ("Intilangelo, Andrea" <andrea@...ilangelo.it>)
- 2026/08/24 #4:
Re: Linux kernel: Guest-to-Host DoS via TAP (Greg KH <greg@...ah.com>)
- 2026/08/24 #3:
Re: Re: Emacs zero-click local command execution via
TRAMP (Sam James <sam@...too.org>)
- 2026/08/24 #2:
BusyBox dpkg applet: OS command injection (Solar Designer <solar@...nwall.com>)
- 2026/08/24 #1:
Re: Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540) (Solar Designer <solar@...nwall.com>)
- 2026/08/23 #5:
CVE-2026-78183: DBD::Pg version 3.21.0 for Perl has a heap
out-of-bounds write in quote_float (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/23 #4:
CVE-2026-19565: Apache::AppSamurai::Util versions through 1.01 for
Perl generate predictable session authentication keys f… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/23 #3:
Vulnerability in Kata Containers runtimes (both rust and go)
(CVE-2026-50540) (Fabiano Fidencio <ffidencio@...dia.com>)
- 2026/08/23 #2:
CVE-2026-75922: Reverse::Proxy versions before 0.04 for Perl allow
HTTP request smuggling via a percent-decoded PATH_INFO … (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/23 #1:
CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access (Paul Eggert <eggert@...ucla.edu>)
- 2026/08/22 #6:
CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl
issue access tokens outside a client's registered scop… (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/22 #5:
CVE-2026-75870: Punk versions before 0.18 for Perl allow session
cookie forgery via an empty default HMAC key when a sessi… (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/22 #4:
[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows
Arbitrary Code Execution via Crafted Radio File (advisories@...cve.org)
- 2026/08/22 #3:
Re: Emacs zero-click local command execution via TRAMP (nightmare.yeah27@...ecat.org)
- 2026/08/22 #2:
CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will
throw an exception on unparseable lookup keys (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/22 #1:
Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local
root vulnerability (Kevin Riggle <kevinr@...plexsystems.group>)
- 2026/08/21 #1:
Emacs zero-click local command execution via TRAMP (Sean Whitton <spwhitton@...hitton.name>)
- 2026/08/20 #21:
[OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm
enumeration and Watcher webhook authorization bypa… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/08/20 #20:
[OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting
OpenStack (Goutham Pacha Ravi <gouthampravi@...il.com>)
- 2026/08/20 #19:
CVE-2026-77176: Kata-containers: insufficient validation of
createcontainer mount and storage rules in genpolicy (Manuel Huber <manuelh@...dia.com>)
- 2026/08/20 #18:
CVE-2026-15743: Catalyst::Plugin::Static::Simple versions through
0.38 for Perl mark responses as publicly cacheable (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/20 #17:
CVE-2026-63044: Apache InLong: Authenticated SSRF via POST
/api/node/testConnection (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #16:
CVE-2026-63043: Apache InLong: Agent path traversal via
unvalidated file source path (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #15:
CVE-2026-63042: Apache InLong: Missing authorization on DataNode
management endpoints (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #14:
CVE-2026-63040: Apache InLong: Missing authorization in
StreamSource forceDelete (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #13:
CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated
MyBatis Dollar-Sign Interpolation in AuditAlertRuleService (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #12:
CVE-2026-63038: Apache InLong: SQL Injection via String
Concatenation Vulnerability Report (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #11:
CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in
Manager OpenAPI audit alert rule list endpoint (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #10:
CVE-2026-63016: Apache InLong: Ordinary users can create new
packages (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #9:
CVE-2026-63015: Apache InLong: Non-template responsible persons
can view template information (Charles Zhang <dockerzhang@...che.org>)
- 2026/08/20 #8:
rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv) (Rainer Gerhards <rgerhards@...adiscon.com>)
- 2026/08/20 #7:
Re: GNU Emacs vulnerability upon opening arbitrary
file (Demi Marie Obenour <demiobenour@...il.com>)
- 2026/08/20 #6:
Re: libmspack: heap buffer overflow in
make_decode_table() (Huffman decode table construction) -- CVE requested (Sam James <sam@...too.org>)
- 2026/08/20 #5:
Fwd: [pfx] Postfix stable release 3.11.6 and legacy releases
3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27 (Sam James <sam@...too.org>)
- 2026/08/20 #4:
Multiple vulnerabilities fixed in libgit2-1.9.5, 1.9.7 (Sam James <sam@...too.org>)
- 2026/08/20 #3:
GNU Emacs vulnerability upon opening arbitrary file (Sam James <sam@...too.org>)
- 2026/08/20 #2:
uutils coreutils 'stdbuf' uses LD_PRELOAD on a world-writable
temporary file (Collin Funk <collin.funk1@...il.com>)
- 2026/08/20 #1:
CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an
attacker-chosen off-site redirect after login because … (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/19 #7:
WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005 (Adrian Perez de Castro <aperez@...lia.com>)
- 2026/08/19 #6:
[OSSA-2026-008] ERRATA 2: Ironic Command Injection in IPMI Console
Implementations (Jay Faulkner <jay@....cc>)
- 2026/08/19 #5:
[OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm
enumeration and Watcher webhook authorization bypa… (Goutham Pacha Ravi <gouthampravi@...il.…)
- 2026/08/19 #4:
Ceph 20.2.4 and Ceph 19.2.6 are released with 4 security fixes. (Sage McTaggart <sagemct@....com>)
- 2026/08/19 #3:
CVE-2026-75589: Net::OAuth versions before 0.33 for Perl check
HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/19 #2:
CVE-2026-72889: Net::OAuth versions before 0.33 for Perl allow the
sender to choose the signature algorithm in verify (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/19 #1:
Re: GNU Inetutils talkd buffer overflow with long DNS names. (Tristan <TristanInSec@...il.com>)
- 2026/08/18 #3:
CPython [CVE-2026-15806]
urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over
another scheme (Alan Coopersmith <alan.coopersmith@...cle.com…)
- 2026/08/18 #2:
CPython [CVE-2026-17084] StringPrep algorithm
considered Unicode codepoint attributes outside Unicode 3.2.0 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2026/08/18 #1:
AI slop "Combined chain advisory — fallback.efi/SBAT/memdisk bypass" (Solar Designer <solar@...nwall.com>)
- 2026/08/17 #2:
Re: [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy
deletion lock (CVE-2026-74248) errata 1 (Jeremy Stanley <fungi@...goth.org>)
- 2026/08/17 #1:
LyX security advisory (Pavel Sanda <sanda@....org>)
- 2026/08/16 #6:
Re: Fwd: OpenZFS Linux open zpool manipulation and
escapes via unprivileged userns (Aaron Rainbolt <arraybolt3@...il.com>)
- 2026/08/16 #5:
Fwd: OpenZFS Linux open zpool manipulation and escapes via
unprivileged userns (Erica Windisch <erica@...disch.us>)
- 2026/08/16 #4:
CVE-2026-72888: Net::OAuth versions before 0.32 for Perl allow memory
exhaustion via unbounded caching of failed module lo… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/16 #3:
CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl
allow the service provider to silently downgrade OAuth 1.… (Robert Rothenberg <rrwo@...nsec.org>)
- 2026/08/16 #2:
CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before
2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.2… (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/16 #1:
libmspack: heap buffer overflow in make_decode_table() (Huffman
decode table construction) -- CVE requested (Sumit Chakraborty <sumit.ch2004@...il.com>)
- 2026/08/15 #4:
CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through
0.713 for Perl allow password reset link poisoning via … (Timothy Legge <timlegge@...nsec.org>)
- 2026/08/15 #3:
CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap
out-of-bounds write via an unvalidated numeric placeholder… (Robert Rothenberg <rrwo@...nsec.org>)
34048 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.