freenode

← digests

Unfixed flaws and fresh CVEs across imaging, auth, and middleware

Security & Cryptography2026-10-10

Several long-unmaintained projects drew attention for lingering memory and authentication flaws, while Apache components and Xen posted new advisories. Operators relying on OpenJPEG, Cyrus SASL, CXF, Camel Karavan, or Linux xen-netfront should review exposure and available patches.

OpenJPEG heap overflow remains in all releases

A heap-buffer-overflow write that was corrected on the OpenJPEG master branch in February 2026 is still present in every published release, including 2.5.3 and 2.5.4. The project is now marked unmaintained, leaving downstream users of the JPEG 2000 codec without an official fixed tarball. Readers who process untrusted images should treat the library as vulnerable until a release or fork appears.

Unfixed CVEs linger in Cyrus SASL

An oss-security report lists multiple unresolved vulnerabilities in Cyrus SASL, with no maintainer activity recorded since 2022. The authentication library remains widely embedded in mail and directory stacks. Sites that still ship it need to assess whether the open issues are reachable in their configurations and plan mitigations or replacements.

Apache CXF Netty client skips TLS hostname checks

CVE-2026-107938 covers the Netty HTTP client transport in Apache CXF, which failed to perform TLS hostname verification. An attacker able to present a certificate chain that validates against the trust store could therefore conduct a man-in-the-middle attack. Deployments that use the Netty transport for outbound HTTPS should upgrade or disable the affected path.

Apache CXF STS token cache permits authentication bypass

CVE-2026-97468 describes an authentication bypass caused by weak 32-bit hash keys in the cache of validated STS tokens. Collisions could allow one principal to reuse another’s cached token. CXF users who rely on the Security Token Service integration need the fixed release to close the bypass.

Camel Karavan path traversal on Git commit

CVE-2026-103412 is a high-severity path-traversal flaw in Apache Camel Karavan that lets an authenticated user write files outside the project directory when committing to Git. The issue is fixed in version 4.22.1. Installations that expose the Karavan UI should apply the update promptly.

Xen netfront crash via malformed RX packets

Xen Security Advisory 522 (CVE-2026-98375) documents a denial-of-service condition in the Linux xen-netfront driver. A malicious or compromised backend can crash the guest by sending malformed receive packets. Guests running the affected driver should obtain the corresponding kernel fix.

Camel Karavan applies unvalidated Kubernetes resources

CVE-2026-103413 allows any authenticated Karavan user to apply arbitrary Kubernetes resources from a project’s kubernetes.yaml, including privileged pods. The high-severity issue gives an attacker a direct path to cluster compromise. Operators should restrict access and move to a fixed Karavan release.

Mutt 2.4.3 closes out-of-bounds heap write

Mutt 2.4.3 fixes CVE-2026-107570, an out-of-bounds heap write triggered by a crafted Content-Header during resend-message. The defect could be reached by processing a malicious message. Users of the mail client should upgrade to the new release.