Bouncy Castle, X.Org, Django patches and GNOME process shifts
A large Bouncy Castle release and patches for X.Org libXfont2 and Django led the day, alongside GNOME security process changes. NIST advanced FIPS 207 key format discussion while Apache disclosed several Qpid denial-of-service flaws.
Bouncy Castle 1.85 fixes 32 CVEs
Bouncy Castle released version 1.85 addressing 32 CVEs. An oss-security thread asked how the issues were discovered but received no further details. Cryptography library users should treat the update as high priority given the volume of fixes.
X.Org libXfont2 out-of-bounds flaws
X.Org issued a security advisory for multiple issues in libXfont2, resolved in 2.0.9. The problems include out-of-bounds read and write in the font server client that can enable privilege escalation. Deployments relying on X font handling need the update to block local escalation paths.
Django issues four CVEs with RCE risk
Django published CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920, patched in 5.2.17 and 6.0.8. The set includes spatial lookup flaws that permit file writes and remote code execution. Application maintainers using Django must apply the releases to close the reported vectors.
GNOME shortens embargo and alters reporting
GNOME reduced its security embargo period to 30 days, stopped forwarding reports to projects that ban AI contributions, and lost its security coordinator. The announcement produced a 29-message thread involving 17 participants on oss-security. The governance changes will alter vulnerability handling for GNOME components.
NIST seed-only keys for FIPS 207 HQC-KEM
NIST signaled a seed-only key format for the upcoming FIPS 207 HQC-KEM standard, diverging from FIPS 203. A 27-message pqc-forum thread examined security and implementation consequences. Post-quantum developers should track the difference as the specification nears finalization.
Apache Qpid ProtonJ2 unbounded caching DoS
Apache disclosed CVE-2026-67588 affecting Qpid ProtonJ2 1.1.0: unbounded symbol value caching enables pre-authentication resource exhaustion, fixed in 1.2.0. Messaging stacks using the library face denial-of-service exposure until upgraded.
Apache Qpid Proton-J flow control bypass
CVE-2026-66275 covers a denial-of-service in Apache Qpid Proton-J through 0.34.1 where the incoming session flow control window can be exceeded, corrected in 0.35.0. The bypass allows pre-authentication resource abuse. Proton-J users should move to the fixed release.
Apache Qpid ProtonJ2 type nesting stack overflow
Apache reported CVE-2026-67590 in ProtonJ2 1.1.0, where unbounded type nesting produces a pre-authentication stack overflow, fixed in 1.2.0. The issue supplies another remote denial-of-service path. The two ProtonJ2 advisories together make the 1.2.0 upgrade essential.