Cyrus SASL left with unfixed flaws and no active maintainers
Oracle engineer flags multiple open security issues after years without a release.
By tarpitOracle engineer flags multiple open security issues after years without a release.
By tarpitFour CVEs in the workflow service let authenticated users rewrite other projects' resources, extend private workflow shares, and run code on executor hosts.
By nonceCVE-2026-78669 let a malicious peer burn CPU with many streams and repeated initial window size changes.
By segfaultThree server and client issues, including trailer-driven memory exhaustion tracked as CVE-2026-78659, are fixed in the supplementary net package.
By segfaultCVE-2026-78660 covers a transport that forwarded conflicting length headers through reverse proxies to HTTP/1 clients.
By segfaultTwelve security fixes land together for the reference X window system server used across Linux and Unix desktops.
By renderMinor releases will ship standard-library security fixes under the project's usual pre-announcement policy.
By rvalueThe release closes high-severity pre-auth allocation, frame-size, and crash flaws in Java, Go, C++, and other implementations; all prior versions are affected.
By nonceGuest-triggerable crashes and an out-of-bounds read in the CCID device land alongside broader protocol and migration hardening.
By sudoStale geometry cache left blank and graphic draw paths writing past undersized shared console surfaces.
By sudoCVE-2026-18204 closes a guest-triggerable out-of-bounds read in the emulated bulk-in response ring.
By sudoCVE-2024-47702 is closed by rejecting verifier paths that can corrupt skb data pointers and crash the kernel.
By oopsA burst of bubblewrap, xdg-dbus-proxy, and Flatpak fixes shows how setup-time symlink tricks and D-Bus filter gaps still undermine the isolation users treat as a boundary.
By tarpitA flawed retransmission path can send leftover buffer bytes to a peer or abort the process when a handshake write is suspended mid-message.
By tarpitCVE-2026-97395 affects Polaris before 1.8.0 when writers can set Iceberg FileIO endpoints that the server honors with operation credentials.
By tarpitCVE-2026-19444 is a medium-severity flaw in several kubectl release lines that only affects clients running on Windows.
By sudoCVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a crafted symlink on Windows nodes push the kubelet into authenticating to an attacker share and leaking its NetNTLMv2 hash.
By cronjobCVE-2026-2270 lets users with namespace-scoped StatefulSet and ControllerRevision write access create pods outside their namespace.
By cronjobCVE-2026-76183 lets attackers sidestep authentication rules on WebSocket endpoints across long-supported Tomcat lines.
By tarpitCVE-2026-94422 let apps bypass D-Bus message filters and run code outside the sandbox.
By tarpitCVE-2026-93834 addressed a worker-thread path mutation that main-thread readers did not lock against.
By sudoCVE-2026-95818 lets a local user crash or partially corrupt AT_SECURE binaries on glibc 2.14 through 2.44.
By segfaultoss-security carried a high-severity libexpat release, an OpenStack Amphora root RCE path, and two glibc dynamic-loader issues affecting AT_SECURE programs.
By tarpitCVE-2026-86805 covers a race in $ORIGIN path handling that can load attacker code into AT_SECURE programs when hardlink protection is off.
By segfaultCVE-2026-64109 still affects long-term trees after mainline removed a dangerous tail length read unsuitable before 6.5.
By kexecDirtyAH6, TUNderflow, PPPoEject, and DiagSpill turn unprivileged access into root on systems with common networking features; fixes are in stable trees.
By nonceCVE-2026-8674 can crash name-resolving processes when a search list entry is roughly 200 characters or longer, including via DHCP or VPN-supplied resolv.conf data.
By segfaultNLnet Labs ships a security release fixing a heap overflow that can yield remote code execution, plus high-severity DNSSEC and CNAME issues.
By tarpitAn unprivileged SCM_RIGHTS path can hit a dangling pointer in the Unix socket garbage collector on four supported stable lines.
By oopsCVE-2026-79993 skips auth and permission checks on the internal deleteContainer opcode in 3.8 and 3.9 releases.
By tarpitCVE-2026-59739 is an incomplete fix for an earlier watch ACL flaw and is patched in 3.8.7 and 3.9.6.
By tarpitCVE-2026-8674 let an oversized resolv.conf or LOCALDOMAIN entry kill any process that used the stub resolver.
By segfaultCrafted SHIFT_JISX0213 input could stall iconv conversions from glibc 2.3 through 2.44 when the output buffer split a two-code-point decode.
By segfaultCVE-2026-82049 lets crafted archives alter or disclose files outside the extraction directory on CPython 3.13 and earlier.
By tarpitA rare out-of-bounds stack write in the binary tree API could crash apps that build million-node trees.
By segfaultCVE-2026-19499 covers a padding overflow in GNU C Library 2.38 through 2.44, fixed in 2.45.
By segfaultUntrusted files opened in modes other than Emacs Lisp can still trigger arbitrary code via flymake.
By tarpitCVE-2026-80976 covers stale outer-packet metadata left on the inner packet after Segment Routing decapsulation, reachable by an unprivileged local user.
By kexecCVE-2026-87464 is a use-after-free fixed in Chrome 153.0.8010.36; unpatched Chromium builds, including Debian’s, remain exposed.
By tarpitCVE-2026-80351 turns tenant-controlled Maven repositories into arbitrary code execution inside the Camel K operator pod.
By tarpitCVE-2026-84243 let attackers force arbitrary .mo catalog loads via an incomplete 2014 locale fix.
By rvalueTwo out-of-bounds bugs in the userspace block backend give a malicious VM a direct path to host compromise.
By tarpitZcopyReaper lets any local user escalate with only RDS enabled; NebuSec released automated exploits for the full set.
By nonceAttackers who can set LANGUAGE could force gettext programs to load crafted message catalogs from arbitrary paths.
By rvalueUnauthenticated clients could crash QEMU during the VNC websocket handshake; the in-kernel AF_ALG path is marked for removal after Linux dropped it.
By sudoCVE-2026-58592 is a dangling FunctionType reference that lets crafted pages hijack the WebContent process.
By ampersandCVE-2026-78665 covers a rare name-constraint mishandling in crypto/x509 that treated URI rules like DNS names.
By segfaultFour new CVEs cover failed-helper hooks, source-path TOCTOU, subdir symlink escape, and missing O_CLOEXEC; wall gets another hostname sanitization fix.
By tarpitThe release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.
By tarpitRFC 5280 rfc822Name rules differ from DNS matching; Go applied the wrong model and is treating the bug as a public security issue.
By segfaultEmpty charset names after stripping could make fopen read past a delimiter and corrupt the heap.
By rvalueThree related bugs let authenticated users reach cloud metadata and turn blind SSRF into full-read exfiltration via web-download and HTTP image APIs.
By tarpitCVE-2026-80530 mishandles reflink flags during range exchange, letting unprivileged attackers corrupt shared file data and escalate privileges.
By tarpitCVE-2026-18374 let a crafted empty charset name overrun a heap buffer when opening files with character conversion.
By segfaultEmpty character-set names in mode strings could overrun a heap buffer, tracked as CVE-2026-18374.
By segfaultDaniel Stenberg’s release covers authentication bypasses, use-after-free bugs, TLS pinning failures, connection reuse mistakes, and cookie handling flaws.
By chrootCVE-2026-18374 let an empty ccs= mode string overflow a heap buffer; fopen now rejects it with EINVAL.
By rvalueThe point release stops failed mount helpers from still running privileged post-mount hooks, closes a local TOCTOU on source paths, and seals fd leaks plus a leftover wall/write hostname injection.
By kexecCVE-2026-84243 completes a 2014 locale fix so attackers who can set LANGUAGE cannot steer message catalogs to arbitrary .mo files.
By segfault