OpenSSL DTLS flaw, McEliece attack debate, Spectre-v2 and auth CVEs
Security activity centered on an OpenSSL DTLS advisory and a contested attack paper against Classic McEliece. Additional disclosures covered a new Spectre-v2 variant in JIT engines plus authentication and file-handling flaws in Apache and CPython components.
OpenSSL high-severity DTLS out-of-bounds read
OpenSSL published a security advisory dated 29 September 2026 for CVE-2026-84782, a high-severity out-of-bounds read in DTLS. The flaw can leak heap data or cause denial of service. DTLS users should treat the update as priority to limit information disclosure and crash risk.
Contested quasipolynomial attack on Classic McEliece
A new eprint paper claims a quasipolynomial distinguisher and decryption attack on Classic McEliece. The pqc-forum saw a 67-message thread with 12 participants, including a lengthy debate among Bernstein and others on the attack's validity, costs, and parameter impact. Post-quantum implementers and standards reviewers need to weigh whether the claimed costs alter the scheme's practical security margins.
Branch Target Reuse Spectre-v2 in JIT engines
Researchers described Branch Target Reuse, a practical Spectre-v2 variant that exploits stale branch prediction entries. Proof-of-concept attacks were shown against Linux kernel cBPF and against JIT engines in Firefox and GraalVM. Systems that rely on JIT compilation or cBPF should evaluate isolation of branch predictor state.
Apache Polaris FileIO endpoint redirection
Apache Polaris disclosed CVE-2026-97395, allowing authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints via operation-scoped storage credentials. The issue arises from untrusted table metadata in versions before 1.8.0. Operators running Polaris should upgrade to remove the redirection path.
CPython TemporaryDirectory cleanup race
CPython issued medium-severity CVE-2026-12345 for a race condition in tempfile.TemporaryDirectory cleanup. A symlink swap during cleanup can delete or alter files outside the temporary directory tree. Code that uses TemporaryDirectory under concurrent or multi-user conditions should apply the fix.
Apache MINA SSHD LDAP password authentication bypass
Critical CVE-2026-94052 was disclosed against Apache MINA SSHD: the optional LdapPasswordAuthenticator component renders LDAP password authentication ineffective. Configurations that enable this authenticator face an authentication bypass. Deployments using the LDAP path need the patched release.
Apache MINA SSHD asynchronous authentication bypass
Critical CVE-2026-77185 affects Apache MINA SSHD asynchronous authentication and can bypass signature verification. The feature is characterized as rarely used. Sites that enable async authentication should update promptly.
NIST revises FN-DSA plan for fixed-point signing
NIST updated the FN-DSA plan in FIPS 206 to require fixed-point arithmetic for signing and to enable exact KAT validation. The change was discussed in a 12-message pqc-forum thread with five participants. Implementers of the forthcoming standard must align signing arithmetic and test-vector handling with the revised requirements.