[<prev day] [next day>] [month] [year] [list]
oss-security mailing list - 2026/09/10
- CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing
Authentication in CORE Protocol Handler Allows Unautho… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis:
Pre-Authentication Information Disclosure in CORE Protocol Top… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis:
Pre-Authentication Cluster Credential Exposure to Discovered P… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis:
Message-based management parameter deserialization may lead to… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing
authentication on CORE protocol session reattachment (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis:
Pre-authentication Openwire protocol handling can result in qu… (Clebert Suconic <clebertsuconic@...che.…)
- CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message
selector wildcard handling could lead to denial of ser… (Clebert Suconic <clebertsuconic@...che.…)
- Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releases (Solar Designer <solar@...nwall.com>)
- Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT (Eve <ckr927414@...k.li>)
- Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design) (Eve <ckr927414@...k.li>)
- iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level) (Eve <ckr927414@...k.li>)
- AI slops from Eve (Solar Designer <solar@...nwall.com>)
- GDCM <= 3.2.7: six memory-safety and denial-of-service
vulnerabilities, no CVE (Abhinav Agarwal <abhinavagarwal1996@...il.com>)
- CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach
Maven execution inside operator pod (Pasquale Congiusti <pcongiusti@...che.org>)
- CVE-2026-80352: Apache Camel K: Camel K Master trait
serviceAccountName YAML injection lets CR author apply arbitrary o… (Pasquale Congiusti <pcongiusti@...che.o…)
- CVE-2026-80354: Apache Camel K: Camel K Builder trait
mavenProfiles ValueSources resolve tenant-named secrets in operat… (Pasquale Congiusti <pcongiusti@...che.o…)
- CVE-2026-87464: RCE outside sandbox in Chromium prior to
153.0.8010.36 (Valtteri Vuorikoski <vuori@...com.org>)
- Re: AI slops from Eve (Eli Schwartz <eschwartz@...too.org>)
- Re: AI slops from Eve (Jeffrey Walton <noloader@...il.com>)
19 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.