freenode

← digests

Tor, Jackrabbit, McEliece, and OpenStack advisories

Security & Cryptography2026-10-08

Security and cryptography activity on 2026-10-08 focused on vulnerability releases for Tor, Apache, and OpenStack components, plus a heated post-quantum debate and a new isogeny NIKE. Multiple pre-auth and authorization flaws were disclosed alongside claims against Classic McEliece.

Tor 0.4.9.14 security release

The Tor Project issued version 0.4.9.14 as a security release. It fixes high-severity conflux and MiddleOnly bugs that affect all components. Operators running any Tor software should treat the update as required to reduce attack surface.

Apache Jackrabbit pre-auth session hijack

CVE-2026-92414 was disclosed for Apache Jackrabbit. The issue allows pre-authentication hijack of cached sessions via derivable WebDAV lock tokens. Deployments that expose WebDAV face a critical risk until patched.

Claimed quasipolynomial attack on Classic McEliece

A new eprint asserts a quasipolynomial distinguisher and heuristic decryption against Classic McEliece. The pqc-forum thread ran to 110 messages from 16 participants and included a disclosure dispute involving Apon. The claims matter for anyone tracking NIST post-quantum candidates.

MIKE isogeny-based post-quantum NIKE

Researchers announced the first release of MIKE, a Module Isogeny Key Exchange positioned as a fast and compact post-quantum non-interactive key exchange. The work supplies small keys together with constant-time C and Rust code. It expands the set of practical isogeny NIKE options under discussion.

OpenStack Zaqar cross-project queue access

OpenStack published OSSA-2026-043 for Zaqar. A WebSocket project substitution flaw enables cross-project queue access and is tracked under the associated CVE. Cloud operators using Zaqar messaging should apply the advisory promptly.

OpenStack Gnocchi metric association bypass

OSSN-0109 reports a missing policy check on resource_id in Gnocchi. The gap permits cross-project metric creation and injection. Deployments that rely on Gnocchi for metrics need to review and correct the authorization path.

Apache DolphinScheduler task definition bypass

CVE-2026-66084 covers a project authorization bypass in the Task Definition with-upstream endpoint of Apache DolphinScheduler before 3.4.3. The moderate flaw lets unauthorized actors manipulate task definitions. Upgrading past the affected releases closes the issue.

Apache DolphinScheduler Kubernetes credential exposure

CVE-2026-71895 discloses missing authorization checks in Apache DolphinScheduler. Non-admin users can retrieve Kubernetes credentials through the affected paths. The moderate severity finding requires immediate review in any cluster that stores such credentials.