[<prev month] [year] [list]
oss-security mailing list - 2026/09
Messages by day:
September 1 (4 messages)
September 2 (5 messages)
September 3 (6 messages)
September 4 (7 messages)
September 5 (5 messages)
September 6 (4 messages)
September 7 (2 messages)
September 8 (24 messages)
September 9 (5 messages)
September 10 (19 messages)
- CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing
Authentication in CORE Protocol Handler Allows Unautho… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis:
Pre-Authentication Information Disclosure in CORE Protocol Top… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis:
Pre-Authentication Cluster Credential Exposure to Discovered P… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis:
Message-based management parameter deserialization may lead to… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing
authentication on CORE protocol session reattachment (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis:
Pre-authentication Openwire protocol handling can result in qu… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message
selector wildcard handling could lead to denial of ser… (Clebert Suconic <clebertsuconic@...che.…)
- Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releases (Solar Designer <solar@...nwall.com>)
- Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT (Eve <ckr927414@...k.li>)
- Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design) (Eve <ckr927414@...k.li>)
- iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level) (Eve <ckr927414@...k.li>)
- AI slops from Eve (Solar Designer <solar@...nwall.com>)
- GDCM <= 3.2.7: six memory-safety and denial-of-service
vulnerabilities, no CVE (Abhinav Agarwal <abhinavagarwal1996@...il.com>)
- CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach
Maven execution inside operator pod (Pasquale Congiusti <pcongiusti@...che.org>)
- CVE-2026-80352: Apache Camel K: Camel K Master trait
serviceAccountName YAML injection lets CR author apply arbitrary o… (Pasquale Congiusti <pcongiusti@...che.o…)
- CVE-2026-80354: Apache Camel K: Camel K Builder trait
mavenProfiles ValueSources resolve tenant-named secrets in operat… (Pasquale Congiusti <pcongiusti@...che.o…)
- CVE-2026-87464: RCE outside sandbox in Chromium prior to
153.0.8010.36 (Valtteri Vuorikoski <vuori@...com.org>)
- Re: AI slops from Eve (Eli Schwartz <eschwartz@...too.org>)
- Re: AI slops from Eve (Jeffrey Walton <noloader@...il.com>)
September 11 (11 messages)
September 12 (4 messages)
September 13 (23 messages)
September 14 (32 messages)
September 15 (15 messages)
September 16 (16 messages)
September 17 (6 messages)
September 18 (17 messages)
- CVE-2026-75157: Apache Airflow: Asset queued-events DELETE
endpoints gated on Dag READ instead of Dag EDIT (asset-triggered
… (Rahul Vats <rahulvats@...che.org>)
- Re: Removing dead code (was: Retrospective by
'gpg.fail' authors) (Jacob Bachmeyer <jcb62281@...il.com>)
- A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill (manizada <manizada@...me>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Hanno Böck <hanno@...eck.de>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Valtteri Vuorikoski <vuori@...com.org>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Kevin Riggle <kevinr@...plexsystems.group>)
- Re: Removing dead code (was: Retrospective by
'gpg.fail' authors) (Peter Gutmann <pgut001@...auckland.ac.nz>)
- CVE-2026-93018: Imager versions before 1.036 for Perl disclose
uninitialised heap memory reading a paletted image with pixel inde… (Stig Palmquist <stig@...g.io>)
- CVE-2026-93019: Imager versions before 1.036 for Perl exit the
process reading a TGA with a colour map length of 32768 or more in… (Stig Palmquist <stig@...g.io>)
- CVE-2026-91863: Apache Neethi: Uncontrolled recursion while
parsing crafted WS-Policy documents allows denial of servic… (Colm O hEigeartaigh <coheigea@...che.or…)
- CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass
element/attribute limits causing memory exhaustion (Colm O hEigeartaigh <coheigea@...che.org…)
- CVE-2026-91865: Apache Neethi: Crafted policy references cause
exponential expansion during normalization leading to de… (Colm O hEigeartaigh <coheigea@...che.or…)
- CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded
work during intersection leading to denial of service (Colm O hEigeartaigh <coheigea@...che.or…)
- CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total
timeout, allowing a slow server to hang the request in… (Colm O hEigeartaigh <coheigea@...che.or…)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Eli Schwartz <eschwartz@...too.org>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (SOFIA ETCHEPARE DARONCO <sofia.etchepare@...d.ufsm.br>)
- Vulnerabilities in libheif and libde265 (Alan Coopersmith <alan.coopersmith@...cle.com>)
September 19 (7 messages)
September 20 (3 messages)
September 21 (9 messages)
September 22 (5 messages)
229 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.