Tor, Jackrabbit, McEliece, and OpenStack advisories
Security and cryptography activity on 2026-10-08 focused on vulnerability releases for Tor, Apache, and OpenStack components, plus a heated post-quantum debate and a new isogeny NIKE. Multiple pre-auth and authorization flaws were disclosed alongside claims against Classic McEliece.
Tor 0.4.9.14 security release
The Tor Project issued version 0.4.9.14 as a security release. It fixes high-severity conflux and MiddleOnly bugs that affect all components. Operators running any Tor software should treat the update as required to reduce attack surface.
Apache Jackrabbit pre-auth session hijack
CVE-2026-92414 was disclosed for Apache Jackrabbit. The issue allows pre-authentication hijack of cached sessions via derivable WebDAV lock tokens. Deployments that expose WebDAV face a critical risk until patched.
Claimed quasipolynomial attack on Classic McEliece
A new eprint asserts a quasipolynomial distinguisher and heuristic decryption against Classic McEliece. The pqc-forum thread ran to 110 messages from 16 participants and included a disclosure dispute involving Apon. The claims matter for anyone tracking NIST post-quantum candidates.
MIKE isogeny-based post-quantum NIKE
Researchers announced the first release of MIKE, a Module Isogeny Key Exchange positioned as a fast and compact post-quantum non-interactive key exchange. The work supplies small keys together with constant-time C and Rust code. It expands the set of practical isogeny NIKE options under discussion.
OpenStack Zaqar cross-project queue access
OpenStack published OSSA-2026-043 for Zaqar. A WebSocket project substitution flaw enables cross-project queue access and is tracked under the associated CVE. Cloud operators using Zaqar messaging should apply the advisory promptly.
OpenStack Gnocchi metric association bypass
OSSN-0109 reports a missing policy check on resource_id in Gnocchi. The gap permits cross-project metric creation and injection. Deployments that rely on Gnocchi for metrics need to review and correct the authorization path.
Apache DolphinScheduler task definition bypass
CVE-2026-66084 covers a project authorization bypass in the Task Definition with-upstream endpoint of Apache DolphinScheduler before 3.4.3. The moderate flaw lets unauthorized actors manipulate task definitions. Upgrading past the affected releases closes the issue.
Apache DolphinScheduler Kubernetes credential exposure
CVE-2026-71895 discloses missing authorization checks in Apache DolphinScheduler. Non-admin users can retrieve Kubernetes credentials through the affected paths. The moderate severity finding requires immediate review in any cluster that stores such credentials.