McEliece parameter warning and Apache Roller flaws
Cryptography discussions centered on quasipolynomial attacks against Classic McEliece. Multiple high-severity issues were also disclosed in Apache Roller and several other open source projects.
Quasipolynomial attack on Classic McEliece
New eprint papers claim quasipolynomial attacks on Classic McEliece, sparking a 32-message thread with eight participants on the pqc-forum. Experts now recommend against its proposed parameters. Post-quantum cryptography implementers should reassess reliance on those parameters.
Unauthenticated deserialization in Apache Roller
CVE-2026-82384 discloses critical unauthenticated deserialization in the XML-RPC endpoint of Apache Roller 6.1.5 that permits remote code execution. The report appeared as a single message on oss-security. Operators of the blogging platform face immediate risk of compromise if unpatched.
CSRF protection bypass in Apache Roller
CVE-2026-82380 reports a high-severity CSRF protection bypass via self-generated salt validation in Apache Roller 6.1.5, rated CVSS 8.1 and fixed in 6.1.6. The single-post disclosure on oss-security details the flaw. Installations should upgrade to restore CSRF defenses.
Uninitialized sigaction in GNU Inetutils
CVE-2026-95510 covers use of an uninitialized struct sigaction in GNU Inetutils, affecting rlogin and telnetd. The initial disclosure came via oss-security. Legacy remote login services may encounter security or stability problems from the bug.
XSS vulnerability in ansi2html
An XSS flaw in ansi2html before 1.9.4 was detailed on oss-security, enabling account takeover through sr.ht CI logs. The two-message thread references a blog write-up of the issue. Projects rendering ANSI logs with the tool should update to block injection.
Path traversal in Input Leap drag-and-drop
NotCVE-2026-0014 reports a path traversal in Input Leap 3.0.3 drag-and-drop file transfer on Windows and macOS that allows arbitrary file writes outside the drop directory. The project is archived with no fix. Users remain exposed without available patches.
Missing weblog authorization in Apache Roller
CVE-2026-82377 discloses a critical authorization bypass in the legacy XML-RPC Blogger and MetaWeblog handlers of Apache Roller 6.1.5, limited to non-default installs. Missing weblog authorization is the root cause. Affected setups should restrict or disable the handlers.
Privilege escalation in GNU libextractor
CVE-2026-100310 describes privilege escalation via an untrusted LIBEXTRACTOR_PREFIX search path in GNU libextractor before 1.16, enabling local privilege escalation in setuid binaries. The single-message oss-security post outlines the issue. Maintainers of setuid tools linking the library need to upgrade.