Mailpit author reports:
+++ +A Server-Side Request Forgery (SSRF) vulnerability + exists in Mailpit's /proxy endpoint that allows attackers + to make requests to internal network resources.
+The /proxy endpoint allows requests to internal network + resources. While it validates http:// and https:// schemes, + it does not block internal IP addresses, allowing attackers + to access internal services and APIs.
+
net-snmp development team reports:
A specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash.
The GStreamer Security Center reports:
Multiple out-of-bounds reads in the MIDI parser that can cause crashes for certain input files.