diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 739c7611690f..5655c1d50c03 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,18251 +1,18255 @@
gstreamer1 -- multiple vulnerabilities
gstreamer1-libav
gstreamer1-plugins-bad
gstreamer1-plugins-good
gstreamer1-plugins-ugly
1.28.6
The GStreamer project reports:
Multiple security issues were identified and fixed in the GStreamer framework.
- GStreamer-SA-2026-0067: Heap buffer overflow and memory leak in JPEG 2000 decoder
- GStreamer-SA-2026-0068: Heap buffer overflow in QCELP RTP depayloader
- GStreamer-SA-2026-0069: Heap buffer overflow in FFmpeg demuxer wrapper
- GStreamer-SA-2026-0070: Out-of bounds write in H.265/HEVC parser short-term RPS parsing
- GStreamer-SA-2026-0071: Heap buffer overflow in DVD subpicture decoder
- GStreamer-SA-2026-0072: Multiple out-of-bounds reads, out-of-bounds writes, and integer overflow vulnerabilities in the AVI demuxer
- GStreamer-SA-2026-0073: Out-of-bounds read in Matroska demuxer FLAC header parser
- GStreamer-SA-2026-0075: Integer overflow and underflow in ASF demuxer bounds checks
- GStreamer-SA-2026-0076: Unbounded memory growth in H.264/H.265 RTP depayloaders during fragmented NAL unit reassembly
- GStreamer-SA-2026-0077: Heap out-of-bounds write in IMA ADPCM audio decoder
CVE-2026-18649
https://gstreamer.freedesktop.org/security/sa-2026-0067.html
https://gstreamer.freedesktop.org/security/sa-2026-0068.html
https://gstreamer.freedesktop.org/security/sa-2026-0069.html
https://gstreamer.freedesktop.org/security/sa-2026-0070.html
https://gstreamer.freedesktop.org/security/sa-2026-0071.html
https://gstreamer.freedesktop.org/security/sa-2026-0072.html
https://gstreamer.freedesktop.org/security/sa-2026-0073.html
https://gstreamer.freedesktop.org/security/sa-2026-0075.html
https://gstreamer.freedesktop.org/security/sa-2026-0076.html
https://gstreamer.freedesktop.org/security/sa-2026-0077.html
2026-08-05
2026-08-08
libXfont2 -- multiple vulnerabilities
libXfont2
2.0.9
Zhixi "Jace" Sun, independent security researcher reports:
- CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer Overflow
- CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write
CVE-2026-44950
CVE-2026-59679
https://lists.x.org/archives/xorg-announce/2026-August/003734.html
2026-08-05
2026-08-07
DNSDist, PowerDNS, PowerDNS Recursor -- vulnerability
dnsdist
2.1.1
powerdns
5.1.4
powerdns-recursor
5.4.5
CVE-2026-52682: A crafted DNS packet can cause increased memory and CPU consumption.
CVE-2026-52682
https://blog.powerdns.com/2026/08/06/powerdns-security-advisory-2026-11-for-powerdns-authoritative-server-recursor-and-dnsdist
2026-07-28
2026-08-07
py-djangorestframework -- two vulnerabilities
py310-djangorestframework
py311-djangorestframework
py312-djangorestframework
py313-djangorestframework
py313t-djangorestframework
py314-djangorestframework
py314t-djangorestframework
py315-djangorestframework
3.17.2,1
py312-dj60-djangorestframework
py313-dj60-djangorestframework
py313t-dj60-djangorestframework
py314-dj60-djangorestframework
py314t-dj60-djangorestframework
py315-dj60-djangorestframework
3.17.2
Bruno Alla reports:
- Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
- AdminRenderer may disclose GET-protected data when rendering invalid write requests
https://github.com/encode/django-rest-framework/security/advisories/GHSA-2m8g-3cmr-wg3w
https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
2026-08-05
2026-08-07
Keycloak -- multiple vulnerabilities
keycloak
26.7.1
The Keycloak Team reports:
- CVE-2026-9793: JWE request object bypasses requestObjectSignatureAlg enforcement
- CVE-2026-4629: Privilege escalation via hardcoded role mapper injection in manage-clients
- CVE-2026-14209: Keycloak Admin UI Extension `brute-force-user` User Disclosure via `search=id:` under FGAP v2
- CVE-2026-14614: Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment
- CVE-2026-14615: FGAP v2 parent group children endpoint bypasses per-child view permission filter
CVE-2026-9793
CVE-2026-4629
CVE-2026-14209
CVE-2026-14614
CVE-2026-14615
https://www.keycloak.org/2026/08/keycloak-2671-released
2026-08-05
2026-08-06
erlang -- SSH plaintext recovery attack against CBC ciphers
erlang
28.5.0.5,4
erlang-runtime27
27.3.4.16
erlang-runtime28
28.5.0.5
erlang-runtime29
29.0.5
The Erlang/OTP team reports:
The SSH client and server now reject incoming packets not
aligned to the cipher block size as required by RFC 4253
section 6. For CBC ciphers, a timing-safe "packet discard"
mechanism (CVE-2008-5161 mitigation) ensures structural errors
are indistinguishable from MAC failures before disconnecting.
AEAD and encrypt-then-MAC modes disconnect immediately.
CVE-2008-5161
https://nvd.nist.gov/vuln/detail/CVE-2008-5161
https://github.com/erlang/otp/pull/11110
2026-07-30
2026-08-04
jenkins -- multiple vulnerabilities
jenkins
2.576
jenkins-lts
2.568.2
Jenkins Security Advisory 2026-08-05:
- SECURITY-3911 / CVE-2026-70426: Agent-to-controller
deserialization filter bypass (Critical)
- SECURITY-3930 / CVE-2026-70427: Link following vulnerability
allows arbitrary file creation (High)
- SECURITY-3927 / CVE-2026-70428: Path traversal vulnerability in
file parameters (High)
- SECURITY-3924 / CVE-2026-70429: Improper handling of case
sensitivity allows privilege escalation (High)
- SECURITY-3916 / CVE-2026-70430: Users with Overall/Manage
permission can instantiate any types related to configuration
(Low)
CVE-2026-70426
CVE-2026-70427
CVE-2026-70428
CVE-2026-70429
CVE-2026-70430
https://www.jenkins.io/security/advisory/2026-08-05/
2026-08-05
2026-08-06
MySQL 8.4 -- Multiple vulnerabilities
mysql84-client
8.4.11
mysql84-server
8.4.11
The Oracle Critical Patch Update of July 2026 addresses 54 issues
in Oracle MySQL, 31 of which apply to the MySQL 8.4 series and to
the MySQL Router shipped with these ports.
The affected server components are Optimizer, Replication,
Group Replication (plugin and GCS), X Plugin, Clone Plugin,
InnoDB, JSON, DDL, Performance Schema and Pluggable
Authentication.
Most of the issues require an authenticated account, in many
cases one with high privileges, and let an attacker hang or
repeatedly crash the server, resulting in a denial of service.
Three issues need no credentials at all: CVE-2026-60315 (CVSS
8.2) is reachable over the X protocol and affects availability,
while CVE-2026-60314 and CVE-2026-60725 affect MySQL Router over
HTTP, the latter allowing unauthorized read and write access.
The highest rated issue for this branch is CVE-2026-60163 (CVSS
8.4) in the Group Replication plugin, exploitable locally with
full impact on confidentiality, integrity and availability.
Please refer to the referenced CVE entries for the details of
each individual issue.
CVE-2026-46936
CVE-2026-47012
CVE-2026-47023
CVE-2026-47052
CVE-2026-47064
CVE-2026-60145
CVE-2026-60163
CVE-2026-60177
CVE-2026-60178
CVE-2026-60182
CVE-2026-60183
CVE-2026-60184
CVE-2026-60185
CVE-2026-60186
CVE-2026-60187
CVE-2026-60188
CVE-2026-60189
CVE-2026-60190
CVE-2026-60191
CVE-2026-60314
CVE-2026-60315
CVE-2026-60316
CVE-2026-60331
CVE-2026-60332
CVE-2026-60585
CVE-2026-60725
CVE-2026-60747
CVE-2026-61081
CVE-2026-61094
CVE-2026-61096
CVE-2026-61109
https://www.oracle.com/security-alerts/cpujul2026.html
https://dev.mysql.com/community/security/advisories/2026-07-21/
2026-07-21
2026-08-05
MySQL 9.7 -- Multiple vulnerabilities
mysql97-client
9.7.2
mysql97-server
9.7.2
The Oracle Critical Patch Update of July 2026 addresses 54 issues
in Oracle MySQL, 43 of which apply to the MySQL 9.7 series and to
the MySQL Router shipped with these ports. The 9.7 branch is
affected by every server issue of the 8.4 branch plus twelve
additional ones in code paths that only exist in 9.x.
The affected server components are Optimizer, Replication,
Group Replication (plugin and GCS), X Plugin, Clone Plugin,
InnoDB, JSON, JSON Duality, GIS, DDL, Configurator, Performance
Schema and Pluggable Authentication.
Most of the issues require an authenticated account, in many
cases one with high privileges, and let an attacker hang or
repeatedly crash the server, resulting in a denial of service.
Three issues need no credentials at all: CVE-2026-60315 (CVSS
8.2) is reachable over the X protocol and affects availability,
while CVE-2026-60314 and CVE-2026-60725 affect MySQL Router over
HTTP, the latter allowing unauthorized read and write access.
The highest rated issue for this branch is CVE-2026-60163 (CVSS
8.4) in the Group Replication plugin, exploitable locally with
full impact on confidentiality, integrity and availability.
CVE-2026-60181 in the Configurator component requires user
interaction and is specific to the 9.7 branch.
Please refer to the referenced CVE entries for the details of
each individual issue.
CVE-2026-46936
CVE-2026-47008
CVE-2026-47012
CVE-2026-47023
CVE-2026-47052
CVE-2026-47064
CVE-2026-60145
CVE-2026-60163
CVE-2026-60174
CVE-2026-60177
CVE-2026-60178
CVE-2026-60181
CVE-2026-60182
CVE-2026-60183
CVE-2026-60184
CVE-2026-60185
CVE-2026-60186
CVE-2026-60187
CVE-2026-60188
CVE-2026-60189
CVE-2026-60190
CVE-2026-60191
CVE-2026-60194
CVE-2026-60195
CVE-2026-60311
CVE-2026-60314
CVE-2026-60315
CVE-2026-60316
CVE-2026-60324
CVE-2026-60331
CVE-2026-60332
CVE-2026-60585
CVE-2026-60718
CVE-2026-60725
CVE-2026-60747
CVE-2026-61081
CVE-2026-61093
CVE-2026-61094
CVE-2026-61096
CVE-2026-61108
CVE-2026-61109
CVE-2026-61128
CVE-2026-61144
https://www.oracle.com/security-alerts/cpujul2026.html
https://dev.mysql.com/community/security/advisories/2026-07-21/
2026-07-21
2026-08-05
PowerDNS Recursor -- multiple vulnerabilities
powerdns-recursor
5.4.4
PowerDNS Team reports:
- CVE-2026-52688: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
- CVE-2026-52686: Wildcard CNAME proof validation bypass¶
CVE-2026-52868
https://nvd.nist.gov/vuln/detail/CVE-2026-52688
CVE-2026-52686
https://nvd.nist.gov/vuln/detail/CVE-2026-52686
2026-07-22
2026-08-05
Angie -- multiple vulnerabilities
angie
1.12.1
The Angie Software Team reports:
When evaluating a string expression in which unnamed capture variables ($1, $2, etc.) preceded a map directive variable whose value is determined by a regular expression, or when using a non-cacheable (volatile) map directive variable whose key contained a capture variable also used in the value of the same directive, worker process memory corruption or a worker process crash could occur (CVE-2026-42533); the fix was ported from nginx 1.31.3.
When using the slice directive or background cache update, if unnamed capture variables ($1, $2, etc.) were used together with a non-cacheable (volatile) map directive variable with a regular expression, the value of an unnamed capture variable could contain arbitrary bytes from worker process memory, or a worker process crash could occur (CVE-2026-60005); the fix was ported from nginx 1.31.3.
When using the SSI module with unbuffered proxying, worker process memory corruption or a worker process crash could occur (CVE-2026-56434); the fix was ported from nginx 1.31.3.
CVE-2026-42533
https://nvd.nist.gov/vuln/detail/CVE-2026-42533
CVE-2026-60005
https://nvd.nist.gov/vuln/detail/CVE-2026-60005
CVE-2026-56434
https://nvd.nist.gov/vuln/detail/CVE-2026-56434
2026-07-17
2026-08-03
Weechat -- Multiple vulnerabilities
weechat
4.10.0
The Weechat project reports:
- core: fix buffer overflow in display of time in chat area with a custom time format
- core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}"
- core: fix possible buffer overflow in command /color alias
- core: fix possible buffer overflow in list of commands displayed by /help
- irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
- irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
- irc: limit size of data received from the server to prevent memory exhaustion
- irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message
- logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators
- relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
- relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)
- relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3, CVE-2026-53524)
- relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
- relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
- relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
- relay: fix out-of-bounds read in dump of data
- relay/api: fix memory leak in resources "handshake", "input" and "completion" (GHSA-wmpc-m6g9-fwj8)
- relay: fix read of uncompressed websocket frame
- api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
- xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory
- xfer: fix out-of-bounds read when receiving empty line in DCC chat
- xfer: fix out-of-bounds write in xfer file transfer resume
CVE-2026-53524
CVE-2026-53525
https://github.com/weechat/weechat/releases/tag/v4.10.0
2026-08-02
2026-08-02
ejabberd -- Multiple security vulnerabilities
ejabberd
26.07
ejabberd team reports:
- It's possible to craft PLAIN auth request and
authenticate as one user, but then open session for
different one.
- mod_caps persistent cache can be poisoned by using
legacy version requests.This cache was only used to
determine list of nodes that should trigger notifications
in PubSub presence-based delivery.
- SQL injection in mod_pubsub handling of paging
requests.
- Possible atom exhaustion that can be triggered by
issuing REST requests to mod_http_api.
- It was possible to make ejabberd send redirect
response for OAuth requests to unvetted url. This required
enabling ejabberd to act as OAuth provider (by adding
request handler for ejabberd_oauth in http listener). As
part of this fix we changed oauth_client_id_check default
value to db.
- using ejabberd as OAuth provider will be only allowed
by clients
- that were previously registered with
oauth_add_client_password or oauth_add_client_implicit
commands.
- Tokens generated by mod_bosh, captcha, mod_auth_fast,
mod_http_upload and mod_invites used not cryptographically
strong random number generators.
- Files server by mod_http_upload didn't have XSS
prevention headers.
- Issues in authentication of SIP requests.
- Request to web_admin were lacking CSRF
protection.
- It was possible to skip captcha verification in
mod_register_web.
- mod_conversejs allowed putting unescaped value from
url in page content.
https://www.process-one.net/blog/ejabberd-26-07/#security
2026-07-30
2026-08-01
py-mkdocs-material -- DOM XSS vulnerability
py310-mkdocs-material
py311-mkdocs-material
py312-mkdocs-material
py313-mkdocs-material
py313t-mkdocs-material
py314-mkdocs-material
py314t-mkdocs-material
py315-mkdocs-material
9.7.7
Martin Donath reports:
Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. A crafted q URL parameter could execute JavaScript in the documentation site's origin after user interaction.
https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
2026-07-17
2026-07-31
2026-08-07
Weechat -- Multiple vulnerabilities
weechat
4.9.5
The Weechat project reports:
Use-after-free and double free when a remote relay sends an event with an array as body.
Use-after-free in the irc plugin when a batched message disconnects the server.
Stack buffer overflow when building a JOIN command with channel keys.
https://weechat.org/doc/weechat/security/
2026-07-26
2026-07-30
NetBird -- Local Privilege Escalation via Unauthenticated IPC Socket
netbird
0.5.00.76.0
The NetBird Team reports:
The NetBird client daemon exposes its gRPC control interface to any local process with no authentication, in all versions from 0.5.0 (March 2022) to 0.75.1. On Linux, macOS and FreeBSD the interface is a Unix domain socket (/var/run/netbird.sock) with world-readable/writable permissions (0666). On Windows it is a loopback TCP listener (127.0.0.1:41731), where the transport carries no caller identity at all. Any unprivileged local user can connect and invoke all daemon RPCs without credentials.
https://github.com/netbirdio/netbird/security/advisories/GHSA-qcpp-8vwj-hhwr
2026-07-29
2026-07-30
chromium -- security fixes
chromium
151.0.7922.71
ungoogled-chromium
151.0.7922.71
Chrome Releases reports:
This update includes 370 security fixes:
- [514442821] Critical CVE-2026-17650: Use after free in Compositing.
- [517307966] Critical CVE-2026-17651: Insufficient validation of untrusted input in Dawn.
- [519262990] Critical CVE-2026-17652: Use after free in Views.
- [520514458] Critical CVE-2026-17653: Use after free in Skia.
- [522314940] Critical CVE-2026-17654: Race in Updater.
- [522556145] Critical CVE-2026-17655: Insufficient validation of untrusted input in ANGLE.
- [523725277] Critical CVE-2026-17656: Use after free in Ozone.
- [502293787] High CVE-2026-17657: Use after free in Navigation.
- [523030583] High CVE-2026-17658: Use after free in V8.
- [495463654] High CVE-2026-17659: Inappropriate implementation in SiteIsolation.
- [497428001] High CVE-2026-17660: Insufficient validation of untrusted input in Network.
- [497451790] High CVE-2026-17661: Use after free in Loader.
- [497491557] High CVE-2026-17662: Insufficient policy enforcement in Prefetch.
- [500225310] High CVE-2026-17663: Insufficient validation of untrusted input in GPU.
- [500554346] High CVE-2026-17664: Insufficient validation of untrusted input in Loader.
- [511277457] High CVE-2026-17665: Use after free in V8.
- [511761758] High CVE-2026-17666: Cryptographic Flaw in Enterprise.
- [513043537] High CVE-2026-17667: Uninitialized Use in ANGLE.
- [513134019] High CVE-2026-17668: Uninitialized Use in ANGLE.
- [513142464] High CVE-2026-17669: Inappropriate implementation in Chrome for iOS.
- [513228974] High CVE-2026-17670: Use after free in Views.
- [513257423] High CVE-2026-17671: Insufficient validation of untrusted input in ANGLE.
- [513375270] High CVE-2026-17672: Insufficient validation of untrusted input in Chromecast.
- [513735177] High CVE-2026-17673: Integer overflow in QUIC.
- [513791232] High CVE-2026-17674: Inappropriate implementation in HTML.
- [513920258] High CVE-2026-17675: Out of bounds write in ANGLE.
- [513920298] High CVE-2026-17676: Inappropriate implementation in ANGLE.
- [513921488] High CVE-2026-17677: Inappropriate implementation in ANGLE.
- [515452019] High CVE-2026-17678: Out of bounds read in ANGLE.
- [516430649] High CVE-2026-17679: Insufficient validation of untrusted input in Print Preview.
- [516486611] High CVE-2026-17680: Heap buffer overflow in Color.
- [516813184] High CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication.
- [516837126] High CVE-2026-17682: Integer overflow in ANGLE.
- [516887576] High CVE-2026-17683: Inappropriate implementation in ANGLE.
- [516894682] High CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS.
- [516910278] High CVE-2026-17685: Use after free in Autofill.
- [516917065] High CVE-2026-17686: Insufficient validation of untrusted input in Passwords.
- [516985726] High CVE-2026-17687: Type Confusion in ANGLE.
- [517016413] High CVE-2026-17688: Use after free in Input.
- [517045160] High CVE-2026-17689: Uninitialized Use in ANGLE.
- [517129282] High CVE-2026-17690: Insufficient validation of untrusted input in PDF.
- [517321292] High CVE-2026-17691: Out of bounds write in ANGLE.
- [517350808] High CVE-2026-17692: Use after free in DataTransfer.
- [517448723] High CVE-2026-17693: Inappropriate implementation in FileSystem.
- [517511796] High CVE-2026-17694: Use after free in DOM.
- [517543052] High CVE-2026-17695: Inappropriate implementation in ANGLE.
- [517550034] High CVE-2026-17696: Side-channel information leakage in Media.
- [517575864] High CVE-2026-17697: Type Confusion in ANGLE.
- [517670731] High CVE-2026-17698: Insufficient validation of untrusted input in UI.
- [517785292] High CVE-2026-17699: Use after free in Views.
- [517789833] High CVE-2026-17700: Insufficient validation of untrusted input in Actor.
- [517972648] High CVE-2026-17701: Out of bounds read in ANGLE.
- [517973093] High CVE-2026-17702: Inappropriate implementation in Skia.
- [518051499] High CVE-2026-17703: Policy bypass in Chrome for iOS.
- [519259107] High CVE-2026-17704: Use after free in ANGLE.
- [519665978] High CVE-2026-17705: Integer overflow in libxml.
- [519693032] High CVE-2026-17706: Insufficient validation of untrusted input in Media.
- [519701233] High CVE-2026-17707: Uninitialized Use in Media.
- [519738647] High CVE-2026-17708: Use after free in Audio.
- [519981494] High CVE-2026-17709: Race in Downloads.
- [519991712] High CVE-2026-17710: Inappropriate implementation in MHTML.
- [519996040] High CVE-2026-17711: Race in Downloads.
- [520535595] High CVE-2026-17712: Race in Skia.
- [520572766] High CVE-2026-17713: Insufficient validation of untrusted input in Accessibility.
- [521293438] High CVE-2026-17714: Uninitialized Use in ANGLE.
- [521491778] High CVE-2026-17715: Inappropriate implementation in Passwords.
- [521866061] High CVE-2026-17716: Use after free in Updater.
- [522063116] High CVE-2026-17717: Integer overflow in ANGLE.
- [522079372] High CVE-2026-17718: Use after free in ANGLE.
- [522304853] High CVE-2026-17719: Use after free in Input.
- [522545249] High CVE-2026-17720: Insufficient policy enforcement in Passwords.
- [523495723] High CVE-2026-17721: Out of bounds write in ANGLE.
- [523592755] High CVE-2026-17722: Object lifecycle issue in WebView.
- [523718303] High CVE-2026-17723: Use after free in Media.
- [523720739] High CVE-2026-17724: Race in Chrome for iOS.
- [528501127] High CVE-2026-17725: Type Confusion in V8.
- [529867799] High CVE-2026-17726: Integer overflow in WebGL.
- [529932631] High CVE-2026-17727: Out of bounds write in WebGL.
- [461167648] Medium CVE-2026-17728: Inappropriate implementation in Extensions.
- [503801946] Medium CVE-2026-17758: Heap buffer overflow in Dawn.
- [476646486] Medium CVE-2026-17732: Inappropriate implementation in SVG.
- [520656237] Medium CVE-2026-17729: Use after free in V8.
- [40057032] Medium CVE-2026-17730: Side-channel information leakage in Autofill.
- [463551850] Medium CVE-2026-17731: Inappropriate implementation in Autofill.
- [495793059] Medium CVE-2026-17733: Inappropriate implementation in QUIC.
- [496304083] Medium CVE-2026-17734: Inappropriate implementation in Autofill.
- [496569497] Medium CVE-2026-17735: Insufficient validation of untrusted input in BFCache.
- [496715442] Medium CVE-2026-17736: Insufficient validation of untrusted input in WebView.
- [498000415] Medium CVE-2026-17737: Use after free in Bluetooth.
- [498079379] Medium CVE-2026-17738: Insufficient validation of untrusted input in Payments.
- [498353463] Medium CVE-2026-17739: Insufficient policy enforcement in Extensions.
- [498827800] Medium CVE-2026-17740: Uninitialized Use in ANGLE.
- [498877660] Medium CVE-2026-17741: Insufficient validation of untrusted input in WebView.
- [499003233] Medium CVE-2026-17742: Insufficient policy enforcement in Payments.
- [499204022] Medium CVE-2026-17743: Insufficient policy enforcement in ControlledFrame.
- [500137309] Medium CVE-2026-17744: Inappropriate implementation in File Input.
- [500172224] Medium CVE-2026-17745: Out of bounds read in Skia.
- [500390256] Medium CVE-2026-17746: Use after free in GPU.
- [500472958] Medium CVE-2026-17747: Insufficient validation of untrusted input in Payments.
- [500494349] Medium CVE-2026-17748: Inappropriate implementation in Extensions.
- [500526602] Medium CVE-2026-17749: Insufficient validation of untrusted input in Extensions.
- [500560234] Medium CVE-2026-17750: Use after free in ANGLE.
- [501591293] Medium CVE-2026-17751: Inappropriate implementation in AdFilter.
- [501619207] Medium CVE-2026-17752: Use after free in Views.
- [501628355] Medium CVE-2026-17753: Inappropriate implementation in Autofill.
- [501675996] Medium CVE-2026-17754: Inappropriate implementation in Blink.
- [501854535] Medium CVE-2026-17755: Incorrect security UI in Extensions.
- [501980797] Medium CVE-2026-17756: Insufficient policy enforcement in Presentation.
- [502351526] Medium CVE-2026-17757: Uninitialized Use in Skia.
- [504650654] Medium CVE-2026-17759: Uninitialized Use in Codecs.
- [506473189] Medium CVE-2026-17760: Side-channel information leakage in NoStatePrefetch.
- [508249524] Medium CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS.
- [508251844] Medium CVE-2026-17762: Inappropriate implementation in Chrome for iOS.
- [511738693] Medium CVE-2026-17763: Inappropriate implementation in GPU.
- [511754400] Medium CVE-2026-17764: Inappropriate implementation in FedCM.
- [511765328] Medium CVE-2026-17765: Inappropriate implementation in WebProtect.
- [511799537] Medium CVE-2026-17766: Insufficient validation of untrusted input in Clipboard.
- [511822402] Medium CVE-2026-17767: Insufficient validation of untrusted input in WebView.
- [512999037] Medium CVE-2026-17768: Insufficient validation of untrusted input in WebSockets.
- [513022076] Medium CVE-2026-17769: Insufficient validation of untrusted input in Cast.
- [513103345] Medium CVE-2026-17770: Out of bounds read in Media.
- [513160525] Medium CVE-2026-17771: Uninitialized Use in Skia.
- [513197846] Medium CVE-2026-17772: Out of bounds read in WebGL.
- [513232523] Medium CVE-2026-17773: Insufficient validation of untrusted input in Cast.
- [513323066] Medium CVE-2026-17774: Insufficient validation of untrusted input in Variations.
- [513363822] Medium CVE-2026-17775: Inappropriate implementation in PresentationAPI.
- [513404032] Medium CVE-2026-17776: Policy bypass in Receiver.
- [513462236] Medium CVE-2026-17777: Inappropriate implementation in Autofill.
- [513467993] Medium CVE-2026-17778: Use after free in Extensions.
- [513478933] Medium CVE-2026-17779: Inappropriate implementation in Site Isolation.
- [513485951] Medium CVE-2026-17780: Inappropriate implementation in Isolated Web Apps.
- [513502990] Medium CVE-2026-17781: Inappropriate implementation in Extensions.
- [513507830] Medium CVE-2026-17782: Incorrect security UI in Chrome for iOS.
- [513532735] Medium CVE-2026-17783: Inappropriate implementation in Loader.
- [513694032] Medium CVE-2026-17784: Use after free in Audio.
- [513769898] Medium CVE-2026-17785: Uninitialized Use in ANGLE.
- [513770449] Medium CVE-2026-17786: Insufficient validation of untrusted input in DevTools.
- [513783632] Medium CVE-2026-17787: Inappropriate implementation in DevTools.
- [513824957] Medium CVE-2026-17788: Inappropriate implementation in Blink.
- [513855922] Medium CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS.
- [513919931] Medium CVE-2026-17790: Uninitialized Use in ANGLE.
- [514006959] Medium CVE-2026-17791: Insufficient validation of untrusted input in Payments.
- [514019823] Medium CVE-2026-17792: Inappropriate implementation in Credential Management.
- [514063859] Medium CVE-2026-17793: Inappropriate implementation in Messages.
- [514067070] Medium CVE-2026-17794: Insufficient validation of untrusted input in Mobile.
- [514242889] Medium CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia.
- [514427844] Medium CVE-2026-17796: Side-channel information leakage in WebXR.
- [514441966] Medium CVE-2026-17797: Inappropriate implementation in CSS.
- [514460133] Medium CVE-2026-17798: Inappropriate implementation in Cast.
- [514461031] Medium CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing.
- [514480948] Medium CVE-2026-17800: Side-channel information leakage in MediaRecording.
- [514482938] Medium CVE-2026-17801: Out of bounds memory access in ANGLE.
- [514512198] Medium CVE-2026-17802: Side-channel information leakage in GPU.
- [515438919] Medium CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive.
- [515448947] Medium CVE-2026-17804: Use after free in Media.
- [516420806] Medium CVE-2026-17805: Insufficient policy enforcement in Glic.
- [516433058] Medium CVE-2026-17806: Insufficient validation of untrusted input in Extensions.
- [516763884] Medium CVE-2026-17807: Use after free in V8.
- [516778390] Medium CVE-2026-17808: Uninitialized Use in WebGL.
- [516813317] Medium CVE-2026-17809: Insufficient validation of untrusted input in Extensions.
- [516882109] Medium CVE-2026-17810: Uninitialized Use in Dawn.
- [516954622] Medium CVE-2026-17811: Use after free in ANGLE.
- [517101596] Medium CVE-2026-17812: Inappropriate implementation in DigitalCredentials.
- [517184957] Medium CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS.
- [517312048] Medium CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS.
- [517427352] Medium CVE-2026-17815: Insufficient policy enforcement in GuestView.
- [517429672] Medium CVE-2026-17816: Inappropriate implementation in Speech.
- [517461759] Medium CVE-2026-17817: Inappropriate implementation in ReportingAndNEL.
- [517466133] Medium CVE-2026-17818: Inappropriate implementation in Network.
- [517487028] Medium CVE-2026-17819: Inappropriate implementation in WebAppInstalls.
- [517493101] Medium CVE-2026-17820: Insufficient policy enforcement in Autofill.
- [517597914] Medium CVE-2026-17821: Insufficient policy enforcement in Extensions.
- [517621178] Medium CVE-2026-17822: Inappropriate implementation in Chrome for iOS.
- [517628043] Medium CVE-2026-17823: Insufficient policy enforcement in WebXR.
- [517655543] Medium CVE-2026-17824: Insufficient policy enforcement in ServiceWorker.
- [517675979] Medium CVE-2026-17825: Insufficient policy enforcement in Passwords.
- [517690521] Medium CVE-2026-17826: Inappropriate implementation in Chrome for iOS.
- [517693726] Medium CVE-2026-17827: Inappropriate implementation in CSS.
- [517702279] Medium CVE-2026-17828: Inappropriate implementation in Chrome for iOS.
- [517705103] Medium CVE-2026-17829: Insufficient policy enforcement in Passwords.
- [517710397] Medium CVE-2026-17830: Inappropriate implementation in Chrome for iOS.
- [517714728] Medium CVE-2026-17831: Insufficient validation of untrusted input in Passwords.
- [517723319] Medium CVE-2026-17832: Use after free in ANGLE.
- [517779123] Medium CVE-2026-17833: Inappropriate implementation in Passwords.
- [517793801] Medium CVE-2026-17834: Inappropriate implementation in Passwords.
- [517801739] Medium CVE-2026-17835: Inappropriate implementation in Chrome for iOS.
- [517972812] Medium CVE-2026-17836: Use after free in V8.
- [517978932] Medium CVE-2026-17837: Insufficient validation of untrusted input in DevTools.
- [518075952] Medium CVE-2026-17838: Incorrect security UI in Chrome for iOS.
- [518080978] Medium CVE-2026-17839: Inappropriate implementation in Chrome for iOS.
- [518082162] Medium CVE-2026-17840: Incorrect security UI in Passwords.
- [518088219] Medium CVE-2026-17841: Race in Chrome for iOS.
- [518089997] Medium CVE-2026-17842: Inappropriate implementation in Chrome for iOS.
- [518103887] Medium CVE-2026-17843: Inappropriate implementation in CSS.
- [518111542] Medium CVE-2026-17844: Insufficient validation of untrusted input in Cast.
- [518112775] Medium CVE-2026-17845: Inappropriate implementation in CSS.
- [518121320] Medium CVE-2026-17846: Inappropriate implementation in Media.
- [518243653] Medium CVE-2026-17847: Insufficient validation of untrusted input in ANGLE.
- [518284253] Medium CVE-2026-17848: Insufficient validation of untrusted input in Codecs.
- [518812672] Medium CVE-2026-17849: Inappropriate implementation in Chrome for iOS.
- [519078527] Medium CVE-2026-17850: Inappropriate implementation in Permissions.
- [519243927] Medium CVE-2026-17851: Side-channel information leakage in Autofill.
- [519348818] Medium CVE-2026-17852: Inappropriate implementation in Media Router.
- [519472272] Medium CVE-2026-17853: Inappropriate implementation in DevTools.
- [519500882] Medium CVE-2026-17854: Insufficient policy enforcement in WebMCP.
- [519982572] Medium CVE-2026-17855: Race in DevTools.
- [519991751] Medium CVE-2026-17856: Inappropriate implementation in Network.
- [520186620] Medium CVE-2026-17857: Inappropriate implementation in Network.
- [520191468] Medium CVE-2026-17858: Uninitialized Use in WebNN.
- [520196753] Medium CVE-2026-17859: Side-channel information leakage in Favicons.
- [520407381] Medium CVE-2026-17860: Insufficient validation of untrusted input in Mobile.
- [520417861] Medium CVE-2026-17861: Insufficient validation of untrusted input in Updater.
- [520426287] Medium CVE-2026-17862: Use after free in Tracing.
- [520468718] Medium CVE-2026-17863: Inappropriate implementation in Browser.
- [520494861] Medium CVE-2026-17864: Inappropriate implementation in Updater.
- [520516655] Medium CVE-2026-17865: Inappropriate implementation in Crypto.
- [520525732] Medium CVE-2026-17866: Type Confusion in Tab.
- [520527496] Medium CVE-2026-17867: Insufficient validation of untrusted input in Dawn.
- [520743499] Medium CVE-2026-17868: Insufficient policy enforcement in USB.
- [521759269] Medium CVE-2026-17869: Out of bounds read in WebXR.
- [521784856] Medium CVE-2026-17870: Insufficient validation of untrusted input in Cast.
- [521938924] Medium CVE-2026-17871: Inappropriate implementation in Passwords.
- [521963740] Medium CVE-2026-17872: Cryptographic Flaw in WebAppInstalls.
- [522074033] Medium CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS.
- [522074154] Medium CVE-2026-17874: Inappropriate implementation in Chrome for iOS.
- [522299155] Medium CVE-2026-17875: Use after free in PDFium.
- [522425471] Medium CVE-2026-17876: Inappropriate implementation in Payments.
- [522426086] Medium CVE-2026-17877: Inappropriate implementation in Chromoting.
- [522781838] Medium CVE-2026-17878: Inappropriate implementation in CSS.
- [522878450] Medium CVE-2026-17879: Inappropriate implementation in Autofill.
- [523229759] Medium CVE-2026-17880: Inappropriate implementation in Autofill.
- [523477987] Medium CVE-2026-17881: Use after free in WebXR.
- [523637452] Medium CVE-2026-17882: Policy bypass in Extensions.
- [523639090] Medium CVE-2026-17883: Inappropriate implementation in Headless.
- [523692228] Medium CVE-2026-17884: Object lifecycle issue in WebRTC.
- [523698038] Medium CVE-2026-17885: Inappropriate implementation in Paint.
- [523715964] Medium CVE-2026-17886: Use after free in Enterprise.
- [523717010] Medium CVE-2026-17887: Use after free in TabStrip.
- [523720529] Medium CVE-2026-17888: Insufficient validation of untrusted input in WebUI.
- [523735357] Medium CVE-2026-17889: Uninitialized Use in WebXR.
- [524029061] Medium CVE-2026-17890: Insufficient validation of untrusted input in DevTools.
- [524639223] Medium CVE-2026-17891: Use after free in ANGLE.
- [524822998] Medium CVE-2026-17892: Inappropriate implementation in WebXR.
- [524824730] Medium CVE-2026-17893: Insufficient validation of untrusted input in Updater.
- [524825209] Medium CVE-2026-17894: Use after free in Views.
- [524931675] Medium CVE-2026-17895: Inappropriate implementation in DataTransfer.
- [525331547] Medium CVE-2026-17896: Use after free in DevTools.
- [527665262] Medium CVE-2026-17897: Inappropriate implementation in ORB.
- [506193577] Low CVE-2026-17898: Use after free in DevTools.
- [375959766] Low CVE-2026-17899: Insufficient policy enforcement in DevTools.
- [496195854] Low CVE-2026-17900: Inappropriate implementation in Enterprise.
- [496271098] Low CVE-2026-17901: Inappropriate implementation in Sharing.
- [497251066] Low CVE-2026-17902: Inappropriate implementation in Editing.
- [497277880] Low CVE-2026-17903: Insufficient policy enforcement in Chromecast.
- [497337759] Low CVE-2026-17904: Insufficient policy enforcement in NFC.
- [497366217] Low CVE-2026-17905: Inappropriate implementation in SurfaceCapture.
- [497654761] Low CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth.
- [497837927] Low CVE-2026-17907: Side-channel information leakage in Network.
- [499062890] Low CVE-2026-17908: Insufficient validation of untrusted input in Printing.
- [501693236] Low CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps.
- [501749600] Low CVE-2026-17910: Insufficient policy enforcement in NFC.
- [502505715] Low CVE-2026-17911: Insufficient policy enforcement in SVG.
- [504202939] Low CVE-2026-17912: Inappropriate implementation in Chrome for iOS.
- [504209246] Low CVE-2026-17913: Inappropriate implementation in Chrome for iOS.
- [506377118] Low CVE-2026-17914: Side-channel information leakage in Skia.
- [506390325] Low CVE-2026-17915: Inappropriate implementation in WebView.
- [510808598] Low CVE-2026-17916: Insufficient policy enforcement in Settings.
- [511816897] Low CVE-2026-17917: Policy bypass in Chrome for iOS.
- [513127137] Low CVE-2026-17918: Use after free in Sync.
- [513291747] Low CVE-2026-17919: Insufficient policy enforcement in Enterprise.
- [513413942] Low CVE-2026-17920: Use after free in V8.
- [513503197] Low CVE-2026-17921: Insufficient validation of untrusted input in Navigation.
- [513611659] Low CVE-2026-17922: Inappropriate implementation in Enterprise.
- [513612928] Low CVE-2026-17923: Policy bypass in Enterprise.
- [513714124] Low CVE-2026-17924: Use after free in DNS.
- [513719671] Low CVE-2026-17925: Inappropriate implementation in Cast.
- [513735900] Low CVE-2026-17926: Insufficient validation of untrusted input in DevTools.
- [513754837] Low CVE-2026-17927: Insufficient policy enforcement in DevTools.
- [513762372] Low CVE-2026-17928: Inappropriate implementation in DataTransfer.
- [513768645] Low CVE-2026-17929: Insufficient validation of untrusted input in DevTools.
- [513769158] Low CVE-2026-17930: Insufficient validation of untrusted input in Extensions.
- [513781245] Low CVE-2026-17931: Inappropriate implementation in DevTools.
- [513819157] Low CVE-2026-17932: Use after free in DataTransfer.
- [513822044] Low CVE-2026-17933: Inappropriate implementation in DOMStorage.
- [513838421] Low CVE-2026-17934: Insufficient validation of untrusted input in DevTools.
- [513863267] Low CVE-2026-17935: Heap buffer overflow in Codecs.
- [513864014] Low CVE-2026-17936: Inappropriate implementation in DevTools.
- [513866380] Low CVE-2026-17937: Inappropriate implementation in DevTools.
- [513989304] Low CVE-2026-17938: Inappropriate implementation in FullScreen.
- [514060089] Low CVE-2026-17939: Inappropriate implementation in Passwords.
- [514069440] Low CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture.
- [514147906] Low CVE-2026-17941: Inappropriate implementation in Chrome for iOS.
- [514406198] Low CVE-2026-17942: Side-channel information leakage in SVG.
- [514424283] Low CVE-2026-17943: Inappropriate implementation in Parser.
- [514510853] Low CVE-2026-17944: Inappropriate implementation in Chrome for iOS.
- [514519203] Low CVE-2026-17945: Inappropriate implementation in Navigation.
- [515437522] Low CVE-2026-17946: Uninitialized Use in Dawn.
- [515438256] Low CVE-2026-17947: Use after free in WebSockets.
- [516849257] Low CVE-2026-17948: Type Confusion in V8.
- [517000034] Low CVE-2026-17949: Uninitialized Use in GPU.
- [517063658] Low CVE-2026-17950: Policy bypass in Safebrowsing.
- [517180511] Low CVE-2026-17951: Heap buffer overflow in WebRTC.
- [517316174] Low CVE-2026-17952: Inappropriate implementation in V8.
- [517335150] Low CVE-2026-17953: Insufficient policy enforcement in WebView.
- [517383492] Low CVE-2026-17954: Policy bypass in MHTML.
- [517385072] Low CVE-2026-17955: Insufficient validation of untrusted input in Payments.
- [517436171] Low CVE-2026-17956: Inappropriate implementation in Scheduling.
- [517476342] Low CVE-2026-17957: Inappropriate implementation in CORS.
- [517538206] Low CVE-2026-17958: Inappropriate implementation in Views.
- [517607890] Low CVE-2026-17959: Inappropriate implementation in Network.
- [517631680] Low CVE-2026-17960: Inappropriate implementation in Chrome for iOS.
- [517700791] Low CVE-2026-17961: Inappropriate implementation in Session.
- [517757268] Low CVE-2026-17962: Inappropriate implementation in Blink.
- [517759257] Low CVE-2026-17963: Inappropriate implementation in SVG.
- [518025103] Low CVE-2026-17964: Incorrect security UI in UI.
- [518049812] Low CVE-2026-17965: Incorrect security UI in Chrome for iOS.
- [518058990] Low CVE-2026-17966: Inappropriate implementation in Views.
- [518243858] Low CVE-2026-17967: Use after free in Chrome for iOS.
- [518337516] Low CVE-2026-17968: Uninitialized Use in WebXR.
- [518812295] Low CVE-2026-17969: Inappropriate implementation in Passwords.
- [518814464] Low CVE-2026-17970: Insufficient validation of untrusted input in Passwords.
- [518815075] Low CVE-2026-17971: Inappropriate implementation in Frame.
- [519202895] Low CVE-2026-17972: Inappropriate implementation in Chrome for iOS.
- [519230894] Low CVE-2026-17973: Inappropriate implementation in Views.
- [519232592] Low CVE-2026-17974: Insufficient policy enforcement in DevTools.
- [519233776] Low CVE-2026-17975: Inappropriate implementation in IME.
- [519455164] Low CVE-2026-17976: Policy bypass in Extensions.
- [519603552] Low CVE-2026-17977: Policy bypass in CSS.
- [519610845] Low CVE-2026-17978: Side-channel information leakage in WebCodecs.
- [519664497] Low CVE-2026-17979: Race in V8.
- [519710361] Low CVE-2026-17980: Inappropriate implementation in UI.
- [519719512] Low CVE-2026-17981: Inappropriate implementation in Blink.
- [519735808] Low CVE-2026-17982: Insufficient validation of untrusted input in Cast.
- [519744561] Low CVE-2026-17983: Incorrect security UI in Global Media Controls.
- [519978460] Low CVE-2026-17984: Inappropriate implementation in Browser.
- [519981430] Low CVE-2026-17985: Insufficient policy enforcement in Speech.
- [519981896] Low CVE-2026-17986: Insufficient policy enforcement in Bluetooth.
- [519988071] Low CVE-2026-17987: Insufficient validation of untrusted input in Notifications.
- [520005624] Low CVE-2026-17988: Insufficient validation of untrusted input in Navigation.
- [520017306] Low CVE-2026-17989: Type Confusion in V8.
- [520018012] Low CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn.
- [520110535] Low CVE-2026-17991: Insufficient validation of untrusted input in AI.
- [520506316] Low CVE-2026-17992: Uninitialized Use in Skia.
- [520532191] Low CVE-2026-17993: Race in Updater.
- [520663771] Low CVE-2026-17994: Inappropriate implementation in Media.
- [520972775] Low CVE-2026-17995: Out of bounds read in Dawn.
- [521473427] Low CVE-2026-17996: Inappropriate implementation in Browser.
- [521476960] Low CVE-2026-17997: Inappropriate implementation in Passwords.
- [521601450] Low CVE-2026-17998: Incorrect security UI in Extensions.
- [521615681] Low CVE-2026-17999: Incorrect security UI in PictureInPicture.
- [521623907] Low CVE-2026-18000: Insufficient policy enforcement in USB.
- [521757779] Low CVE-2026-18001: Inappropriate implementation in WebGL.
- [521864362] Low CVE-2026-18002: Insufficient validation of untrusted input in Google Lens.
- [521934304] Low CVE-2026-18003: Inappropriate implementation in Chrome for iOS.
- [522280805] Low CVE-2026-18004: Insufficient policy enforcement in Speech.
- [522300211] Low CVE-2026-18005: Inappropriate implementation in WebXR.
- [522396262] Low CVE-2026-18006: Inappropriate implementation in Google Lens.
- [522404101] Low CVE-2026-18007: Inappropriate implementation in Input.
- [522412676] Low CVE-2026-18008: Inappropriate implementation in Settings.
- [522419718] Low CVE-2026-18009: Insufficient validation of untrusted input in Passwords.
- [522419819] Low CVE-2026-18010: Inappropriate implementation in Passwords.
- [522479633] Low CVE-2026-18011: Inappropriate implementation in Chrome for iOS.
- [522938824] Low CVE-2026-18012: Use after free in PDFium.
- [523245998] Low CVE-2026-18013: Inappropriate implementation in Chrome for iOS.
- [523248021] Low CVE-2026-18014: Insufficient validation of untrusted input in DevTools.
- [523698428] Low CVE-2026-18015: Inappropriate implementation in Tint.
- [523708527] Low CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS.
- [523731236] Low CVE-2026-18017: Use after free in Dawn.
- [524467747] Low CVE-2026-18018: Inappropriate implementation in Updater.
- [525691898] Low CVE-2026-18019: Side-channel information leakage in Media.
CVE-2026-17650
CVE-2026-17651
CVE-2026-17652
CVE-2026-17653
CVE-2026-17654
CVE-2026-17655
CVE-2026-17656
CVE-2026-17657
CVE-2026-17658
CVE-2026-17659
CVE-2026-17660
CVE-2026-17661
CVE-2026-17662
CVE-2026-17663
CVE-2026-17664
CVE-2026-17665
CVE-2026-17666
CVE-2026-17667
CVE-2026-17668
CVE-2026-17669
CVE-2026-17670
CVE-2026-17671
CVE-2026-17672
CVE-2026-17673
CVE-2026-17674
CVE-2026-17675
CVE-2026-17676
CVE-2026-17677
CVE-2026-17678
CVE-2026-17679
CVE-2026-17680
CVE-2026-17681
CVE-2026-17682
CVE-2026-17683
CVE-2026-17684
CVE-2026-17685
CVE-2026-17686
CVE-2026-17687
CVE-2026-17688
CVE-2026-17689
CVE-2026-17690
CVE-2026-17691
CVE-2026-17692
CVE-2026-17693
CVE-2026-17694
CVE-2026-17695
CVE-2026-17696
CVE-2026-17697
CVE-2026-17698
CVE-2026-17699
CVE-2026-17700
CVE-2026-17701
CVE-2026-17702
CVE-2026-17703
CVE-2026-17704
CVE-2026-17705
CVE-2026-17706
CVE-2026-17707
CVE-2026-17708
CVE-2026-17709
CVE-2026-17710
CVE-2026-17711
CVE-2026-17712
CVE-2026-17713
CVE-2026-17714
CVE-2026-17715
CVE-2026-17716
CVE-2026-17717
CVE-2026-17718
CVE-2026-17719
CVE-2026-17720
CVE-2026-17721
CVE-2026-17722
CVE-2026-17723
CVE-2026-17724
CVE-2026-17725
CVE-2026-17726
CVE-2026-17727
CVE-2026-17728
CVE-2026-17758
CVE-2026-17732
CVE-2026-17729
CVE-2026-17730
CVE-2026-17731
CVE-2026-17733
CVE-2026-17734
CVE-2026-17735
CVE-2026-17736
CVE-2026-17737
CVE-2026-17738
CVE-2026-17739
CVE-2026-17740
CVE-2026-17741
CVE-2026-17742
CVE-2026-17743
CVE-2026-17744
CVE-2026-17745
CVE-2026-17746
CVE-2026-17747
CVE-2026-17748
CVE-2026-17749
CVE-2026-17750
CVE-2026-17751
CVE-2026-17752
CVE-2026-17753
CVE-2026-17754
CVE-2026-17755
CVE-2026-17756
CVE-2026-17757
CVE-2026-17759
CVE-2026-17760
CVE-2026-17761
CVE-2026-17762
CVE-2026-17763
CVE-2026-17764
CVE-2026-17765
CVE-2026-17766
CVE-2026-17767
CVE-2026-17768
CVE-2026-17769
CVE-2026-17770
CVE-2026-17771
CVE-2026-17772
CVE-2026-17773
CVE-2026-17774
CVE-2026-17775
CVE-2026-17776
CVE-2026-17777
CVE-2026-17778
CVE-2026-17779
CVE-2026-17780
CVE-2026-17781
CVE-2026-17782
CVE-2026-17783
CVE-2026-17784
CVE-2026-17785
CVE-2026-17786
CVE-2026-17787
CVE-2026-17788
CVE-2026-17789
CVE-2026-17790
CVE-2026-17791
CVE-2026-17792
CVE-2026-17793
CVE-2026-17794
CVE-2026-17795
CVE-2026-17796
CVE-2026-17797
CVE-2026-17798
CVE-2026-17799
CVE-2026-17800
CVE-2026-17801
CVE-2026-17802
CVE-2026-17803
CVE-2026-17804
CVE-2026-17805
CVE-2026-17806
CVE-2026-17807
CVE-2026-17808
CVE-2026-17809
CVE-2026-17810
CVE-2026-17811
CVE-2026-17812
CVE-2026-17813
CVE-2026-17814
CVE-2026-17815
CVE-2026-17816
CVE-2026-17817
CVE-2026-17818
CVE-2026-17819
CVE-2026-17820
CVE-2026-17821
CVE-2026-17822
CVE-2026-17823
CVE-2026-17824
CVE-2026-17825
CVE-2026-17826
CVE-2026-17827
CVE-2026-17828
CVE-2026-17829
CVE-2026-17830
CVE-2026-17831
CVE-2026-17832
CVE-2026-17833
CVE-2026-17834
CVE-2026-17835
CVE-2026-17836
CVE-2026-17837
CVE-2026-17838
CVE-2026-17839
CVE-2026-17840
CVE-2026-17841
CVE-2026-17842
CVE-2026-17843
CVE-2026-17844
CVE-2026-17845
CVE-2026-17846
CVE-2026-17847
CVE-2026-17848
CVE-2026-17849
CVE-2026-17850
CVE-2026-17851
CVE-2026-17852
CVE-2026-17853
CVE-2026-17854
CVE-2026-17855
CVE-2026-17856
CVE-2026-17857
CVE-2026-17858
CVE-2026-17859
CVE-2026-17860
CVE-2026-17861
CVE-2026-17862
CVE-2026-17863
CVE-2026-17864
CVE-2026-17865
CVE-2026-17866
CVE-2026-17867
CVE-2026-17868
CVE-2026-17869
CVE-2026-17870
CVE-2026-17871
CVE-2026-17872
CVE-2026-17873
CVE-2026-17874
CVE-2026-17875
CVE-2026-17876
CVE-2026-17877
CVE-2026-17878
CVE-2026-17879
CVE-2026-17880
CVE-2026-17881
CVE-2026-17882
CVE-2026-17883
CVE-2026-17884
CVE-2026-17885
CVE-2026-17886
CVE-2026-17887
CVE-2026-17888
CVE-2026-17889
CVE-2026-17890
CVE-2026-17891
CVE-2026-17892
CVE-2026-17893
CVE-2026-17894
CVE-2026-17895
CVE-2026-17896
CVE-2026-17897
CVE-2026-17898
CVE-2026-17899
CVE-2026-17900
CVE-2026-17901
CVE-2026-17902
CVE-2026-17903
CVE-2026-17904
CVE-2026-17905
CVE-2026-17906
CVE-2026-17907
CVE-2026-17908
CVE-2026-17909
CVE-2026-17910
CVE-2026-17911
CVE-2026-17912
CVE-2026-17913
CVE-2026-17914
CVE-2026-17915
CVE-2026-17916
CVE-2026-17917
CVE-2026-17918
CVE-2026-17919
CVE-2026-17920
CVE-2026-17921
CVE-2026-17922
CVE-2026-17923
CVE-2026-17924
CVE-2026-17925
CVE-2026-17926
CVE-2026-17927
CVE-2026-17928
CVE-2026-17929
CVE-2026-17930
CVE-2026-17931
CVE-2026-17932
CVE-2026-17933
CVE-2026-17934
CVE-2026-17935
CVE-2026-17936
CVE-2026-17937
CVE-2026-17938
CVE-2026-17939
CVE-2026-17940
CVE-2026-17941
CVE-2026-17942
CVE-2026-17943
CVE-2026-17944
CVE-2026-17945
CVE-2026-17946
CVE-2026-17947
CVE-2026-17948
CVE-2026-17949
CVE-2026-17950
CVE-2026-17951
CVE-2026-17952
CVE-2026-17953
CVE-2026-17954
CVE-2026-17955
CVE-2026-17956
CVE-2026-17957
CVE-2026-17958
CVE-2026-17959
CVE-2026-17960
CVE-2026-17961
CVE-2026-17962
CVE-2026-17963
CVE-2026-17964
CVE-2026-17965
CVE-2026-17966
CVE-2026-17967
CVE-2026-17968
CVE-2026-17969
CVE-2026-17970
CVE-2026-17971
CVE-2026-17972
CVE-2026-17973
CVE-2026-17974
CVE-2026-17975
CVE-2026-17976
CVE-2026-17977
CVE-2026-17978
CVE-2026-17979
CVE-2026-17980
CVE-2026-17981
CVE-2026-17982
CVE-2026-17983
CVE-2026-17984
CVE-2026-17985
CVE-2026-17986
CVE-2026-17987
CVE-2026-17988
CVE-2026-17989
CVE-2026-17990
CVE-2026-17991
CVE-2026-17992
CVE-2026-17993
CVE-2026-17994
CVE-2026-17995
CVE-2026-17996
CVE-2026-17997
CVE-2026-17998
CVE-2026-17999
CVE-2026-18000
CVE-2026-18001
CVE-2026-18002
CVE-2026-18003
CVE-2026-18004
CVE-2026-18005
CVE-2026-18006
CVE-2026-18007
CVE-2026-18008
CVE-2026-18009
CVE-2026-18010
CVE-2026-18011
CVE-2026-18012
CVE-2026-18013
CVE-2026-18014
CVE-2026-18015
CVE-2026-18016
CVE-2026-18017
CVE-2026-18018
CVE-2026-18019
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
2026-07-29
2026-07-30
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
19.2.019.2.1
19.1.019.1.3
8.8.019.0.5
Gitlab reports:
Sensitive Information Exposure issue in Workhorse impacts GitLab CE/EE
Mass Assignment issue in Pipeline Schedule API impacts GitLab CE/EE
Denial of Service issue in Merge Request Discussions impacts GitLab CE/EE
Race Condition issue in merge request approval rules impacts GitLab EE
Insufficiently Protected Credentials issue in Virtual Registries impacts GitLab EE
Improper Access Control issue in project import status impacts GitLab CE/EE
Improper Authorization issue in project import functionality impacts GitLab CE/EE
Cross-site Scripting issue in paginated views impacts GitLab CE/EE
Prompt Injection issue in Duo Code Review impacts GitLab EE
Incorrect Security Token Generation issue in Duo Workflows impacts GitLab EE
Exposure of Sensitive Information issue in merge request title generation impacts GitLab CE/EE
Improper Access Control issue in Pipeline Test Report API impacts GitLab CE/EE
Incorrect Authorization issue in merge request collaboration settings impacts GitLab CE/EE
CVE-2026-6267
CVE-2026-12436
CVE-2026-15975
CVE-2026-13113
CVE-2026-16553
CVE-2026-6336
CVE-2026-14341
CVE-2026-3093
CVE-2026-15077
CVE-2026-15831
CVE-2026-14351
CVE-2026-4672
CVE-2025-14562
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/?nav=19.2.1
2026-07-29
2026-07-30
FreeBSD -- Race condition in ELF core dump segment counting
FreeBSD-kernel
15.115.1_2
15.015.0_12
14.414.4_8
Problem Description:
The ELF core dump code counted the number of dumpable VM map
entries, allocated a buffer for the corresponding program headers,
then iterated over the map a second time to populate them. A process
sharing the address space via rfork(2) can mutate the map between
the two passes, causing the second pass to write program headers
past the end of the buffer.
Impact:
An unprivileged local user sharing an address space with a
process that dumps core can trigger an out-of-bounds write on the
kernel heap, potentially leading to privilege escalation.
CVE-2026-58088
SA-26:55.elf
2026-07-29
2026-07-30
FreeBSD -- Heap out-of-bounds access in semctl(2)
FreeBSD-kernel
15.115.1_2
15.015.0_12
14.414.4_8
Problem Description:
The GETALL and SETALL commands in semctl(2) recorded the number
of semaphores in the target set, dropped the lock protecting the
set, allocated a buffer sized for that count, and reacquired the
lock. A sequence-number check was used to verify that the set had
not been replaced in the interim, but the sequence number wraps
after 0x8000 create/destroy cycles. By rapidly destroying and
recreating semaphore sets at the same index, another process can
cause the sequence number to wrap, allowing a set with a different
number of semaphores to pass validation. The subsequent copy then
reads or writes past the end of the allocated buffer.
Impact:
An unprivileged local user can trigger out-of-bounds reads and
writes on kernel heap memory, potentially leading to privilege
escalation.
CVE-2026-58087
SA-26:54.sysvsem
2026-07-29
2026-07-30
FreeBSD -- ktrace(2) privilege incorrectly validated in jails
FreeBSD-kernel
15.115.1_2
15.015.0_12
Problem Description:
As an inadvertent side effect of an unrelated code change,
PRIV_KTRACE was always denied to a jailed root user. Tracing
configured by a jailed root user was therefore not flagged as
privileged.
Impact:
An unprivileged user in a jail that has permission to debug the
target process can modify the jailed root user's ktrace(2) flags,
or disable tracing outright. A jailed root user therefore cannot
reliably trace unprivileged processes.
CVE-2026-58086
SA-26:53.ktrace
2026-07-29
2026-07-30
FreeBSD -- Missing MAC validation in wg(4) packet decryption
FreeBSD-kernel
15.115.1_2
15.015.0_12
14.414.4_8
Problem Description:
After dispatching a decrypt operation to OCF and receiving the
result, the wg(4) driver failed to check whether the MAC verification
step succeeded. The driver thus silently accepted packets with an
invalid Poly1305 authentication tag.
Impact:
A remote attacker who can send UDP packets to a WireGuard
endpoint, and who can guess the bounds of the receiver's replay
window, can inject forged or modified transport data packets into
the tunnel.
A remote attacker who can intercept WireGuard packets bound for a
FreeBSD host can modify the ciphertext and authenticated data without
detection by the receiver.
CVE-2026-58085
SA-26:52.if_wg
2026-07-29
2026-07-30
FreeBSD -- Kernel stack disclosure via timer_settime(2)
FreeBSD-kernel
15.115.1_2
15.015.0_12
Problem Description:
To retrieve the previous timer value, the kernel calls
realtimer_gettime(), which obtains the current time for the timer's
clock. For a timer using CLOCK_TAI this can fail when no TAI offset
has been configured, but the error return was not checked, so the
uninitialized output buffer was copied to userspace.
Impact:
An unprivileged local user can obtain uninitialized kernel stack
memory by creating a POSIX timer with CLOCK_TAI and calling
timer_settime(2), potentially disclosing sensitive kernel data.
CVE-2026-58084
SA-26:51.ktimer
2026-07-29
2026-07-30
FreeBSD -- Use-after-free in kqueue copy-on-fork
FreeBSD-kernel
15.115.1_2
Problem Description:
While the kernel was copying knotes during fork, a knote with
a timer-based filter could fire and be enqueued on the kqueue's
active list before the copy was complete. The copy routine did not
account for this and could enqueue the new knote a second time,
corrupting the active list. In addition, the copy routine did not
hold the appropriate locks while reading knote state, allowing
further races.
Impact:
An unprivileged local user can trigger a use-after-free in the
kernel, potentially leading to privilege escalation.
CVE-2026-58083
SA-26:50.kqueue
2026-07-29
2026-07-30
chromium -- security fixes
chromium
150.0.7871.186
ungoogled-chromium
150.0.7871.186
Chrome Releases reports:
This update includes 4 security fixes:
- [518237034] High CVE-2026-16807: Out of bounds write in Codecs.
- [522064153] High CVE-2026-16806: Use after free in WebMCP.
- [523292588] High CVE-2026-16805: Use after free in Blink.
- [524721670] High CVE-2026-16804: Use after free in Input.
CVE-2026-16807
CVE-2026-16806
CVE-2026-16805
CVE-2026-16804
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html
2026-07-23
2026-07-29
chromium -- security fixes
chromium
150.0.7871.181
ungoogled-chromium
150.0.7871.181
Chrome Releases reports:
This update includes 12 security fixes:
- [527930356] High CVE-2026-16420: Type Confusion in WebAudio.
- [528276487] High CVE-2026-16421: Inappropriate implementation in WebAudio.
- [517359779] High CVE-2026-16413: Out of bounds write in ANGLE.
- [517651910] High CVE-2026-16414: Insufficient validation of untrusted input in Chromecast.
- [519244446] High CVE-2026-16415: Insufficient validation of untrusted input in Extensions.
- [520172356] High CVE-2026-16416: Integer overflow in Chromecast.
- [521491024] High CVE-2026-16417: Uninitialized Use in Skia.
- [522125255] High CVE-2026-16418: Stack buffer overflow in V8.
- [523435970] High CVE-2026-16419: Out of bounds read and write in ANGLE.
- [533515002] High CVE-2026-16422: Insufficient validation of untrusted input in Certificate.
- [534582496] High CVE-2026-16423: Use after free in UI.
- [534858939] High CVE-2026-16424: Use after free in GPU.
CVE-2026-16420
CVE-2026-16421
CVE-2026-16413
CVE-2026-16414
CVE-2026-16415
CVE-2026-16416
CVE-2026-16417
CVE-2026-16418
CVE-2026-16419
CVE-2026-16422
CVE-2026-16423
CVE-2026-16424
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
2026-07-21
2026-07-29
chromium -- security fixes
chromium
150.0.7871.128
ungoogled-chromium
150.0.7871.128
Chrome Releases reports:
This update includes 7 security fixes:
- [516987782] Critical CVE-2026-15899: Use after free in CameraCapture.
- [523750584] Critical CVE-2026-15900: Use after free in GPU.
- [533446300] Critical CVE-2026-15901: Use after free in Network.
- [522436154] High CVE-2026-15902: Use after free in Cast.
- [531503216] High CVE-2026-15903: Out of bounds read and write in V8.
- [532925350] High CVE-2026-15904: Use after free in Ozone.
- [532970574] High CVE-2026-15905: Use after free in Aura.
CVE-2026-15899
CVE-2026-15900
CVE-2026-15901
CVE-2026-15902
CVE-2026-15903
CVE-2026-15904
CVE-2026-15905
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html
2026-07-16
2026-07-29
chromium -- security fixes
chromium
150.0.7871.124
ungoogled-chromium
150.0.7871.124
Chrome Releases reports:
This update includes 15 security fixes:
- [517100492] Critical CVE-2026-15764: Use after free in Ozone.
- [518007484] Critical CVE-2026-15765: Use after free in Ozone.
- [514010477] High CVE-2026-15766: Uninitialized Use in Skia.
- [514748734] High CVE-2026-15767: Heap buffer overflow in libyuv.
- [517931625] High CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas.
- [519731111] High CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming.
- [524792614] High CVE-2026-15770: Uninitialized Use in V8.
- [525177160] High CVE-2026-15771: Insufficient validation of untrusted input in Media.
- [525317502] High CVE-2026-15772: Use after free in GPU.
- [527676561] High CVE-2026-15773: Use after free in Core.
- [530646115] High CVE-2026-15774: Use after free in Skia.
- [531319201] High CVE-2026-15775: Insufficient policy enforcement in V8.
- [532595489] High CVE-2026-15776: Type Confusion in V8.
- [532929679] High CVE-2026-15777: Use after free in UI.
- [513795122] Medium CVE-2026-15778: Insufficient validation of untrusted input in Navigation.
CVE-2026-15764
CVE-2026-15765
CVE-2026-15766
CVE-2026-15767
CVE-2026-15768
CVE-2026-15769
CVE-2026-15770
CVE-2026-15771
CVE-2026-15772
CVE-2026-15773
CVE-2026-15774
CVE-2026-15775
CVE-2026-15776
CVE-2026-15777
CVE-2026-15778
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html
2026-07-14
2026-07-29
GoLand -- Multiple vulnerabilities
jetbrains-goland
2026.2
https://www.jetbrains.com/privacy-security/issues-fixed/ reports:
-
In JetBrains GoLand before 2026.2 arbitrary code execution
was possible before granting project trust in the Go
Modules integration
-
In JetBrains GoLand before 2026.2 sensitive configuration
values written to log files by default
CVE-2026-64802
https://cveawg.mitre.org/api/cve/CVE-2026-64802
2026-07-23
2026-07-28
Mozilla -- Memory safety bugs
firefox
152.0.0,2
firefox-esr
140.12,2
thunderbird
140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360 reports:
Memory safety bugs present in Firefox ESR 115.37,
Firefox ESR 140.12 and Firefox 152. Some of these bugs
showed evidence of memory corruption and we presume that
with enough effort some of these could have been
exploited to run arbitrary code.
CVE-2026-16360
https://cveawg.mitre.org/api/cve/CVE-2026-16360
2026-07-21
2026-07-28
Mozilla -- Memory safety bugs
firefox
153.0.0,2
firefox-esr
140.13,2
thunderbird
153.0.0
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412 reports:
Memory safety bugs present in Firefox ESR 140.12 and
Firefox 152. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort
some of these could have been exploited to run arbitrary
code.
CVE-2026-16412
https://cveawg.mitre.org/api/cve/CVE-2026-16412
2026-07-21
2026-07-28
Mozilla -- Memory safety bugs
firefox
153.0.0,2
thunderbird
153.0.0
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411 reports
Memory safety bugs present in Firefox 152. Some of
these bugs showed evidence of memory corruption and we
presume that with enough effort some of these could have
been exploited to run arbitrary code.
CVE-2026-16411
https://cveawg.mitre.org/api/cve/CVE-2026-16411
2026-07-21
2026-07-28
mailpit -- WebSocket origin check bypass via percent-encoded path
mailpit
1.30.6
Mailpit author reports:
The cross-site WebSocket hijacking fix was reimplemented
as an origin check gated on a raw-URI prefix test, but
Go's ServeMux routes on the percent-decoded path, so
requesting /%61pi/events reaches the WebSocket handler
while skipping the only origin control, and the upgrader
itself accepts every origin.
https://github.com/axllent/mailpit/security/advisories/GHSA-8r62-w5wh-fc5m
2026-07-28
2026-07-28
Erlang/OTP -- (D)TLS-1.2 server certificate verification bypass
erlang
28.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882 reports:
The OTP TLS/DTLS client (pre TLS-1.3) does not verify that
the cipher suite selected by the server in ServerHello is one
of those offered in ClientHello. A man-in-the-middle attacker
can select an anonymous cipher suite such as ECDH_anon that
was never offered by the client. Since anonymous suites do not
require a server certificate, this completely bypasses the
client's verify_peer setting, giving the attacker a fully
established connection without possessing any trusted
certificate, and thus complete read and modify access to the
transmitted data. TLS-1.3 is not affected.
CVE-2026-55953
https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882
2026-07-27
2026-07-27
Erlang/OTP -- TLS denial of service using invalid certificate chains
erlang
23.2,428.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw reports:
A TLS/DTLS peer can crash the remote node by sending a
certificate chain containing two mutually cross-signed
certificates in unordered form. When the receiving side
attempts to build a valid chain path, it enters unbounded
recursion between the two certificates (A issues B, B issues
A) with no cycle detection or depth limit. The call stack and
chain accumulator grow without bound until the process
exhausts available memory and the BEAM node crashes.
CVE-2026-58227
https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw
2026-07-27
2026-07-27
Erlang/OTP -- denial of service via exponential certificate policy tree growth
erlang
26.2,428.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
https://github.com/erlang/otp/security/advisories/GHSA-622p-qfh6-c352 reports:
A remote attacker can trigger a denial of service through
TLS certificate handling. By sending a specially crafted
certificate chain with multiple certificate policies at each
level, the policy tree expands exponentially during validation,
growing as M^K nodes (where M is the number of policies per
certificate and K is the chain depth). This pins schedulers
and exhausts memory without any authentication. Any
application using SSL/TLS that validates certificate paths is
affected, as are direct calls to
public_key:pkix_path_validation/3.
CVE-2026-59251
https://github.com/erlang/otp/security/advisories/GHSA-622p-qfh6-c352
2026-07-27
2026-07-27
Erlang/OTP -- megaco flex scanner buffer overflow
erlang
28.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7 reports:
A remote unauthenticated attacker can crash Erlang nodes
running the megaco text codec with the flex scanner option by
sending an H.248/Megaco message with a property parm name
exceeding 452 bytes. The overflow occurs in a C linked-in
driver, causing the entire BEAM VM process to terminate. It is
reachable pre-authentication, as the flex scanner processes
raw TCP payloads before protocol validation.
CVE-2026-59250
https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7
2026-07-27
2026-07-27
Erlang/OTP -- binary_to_term crash on crafted BIT_BINARY_EXT input
erlang
27.0,428.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
https://github.com/erlang/otp/security/advisories/GHSA-54pw-5645-jh86 reports:
A specially crafted External Term Format (ETF) payload of
merely 7 bytes triggers a crash in the BEAM virtual machine
when processed by binary_to_term/1,2. The BIT_BINARY_EXT tag
with specific parameters causes an unsigned integer underflow
during bitstring size calculation, resulting in an enormous
memory allocation attempt that immediately terminates the VM.
This is a full system crash, not a recoverable process
exception: Erlang supervision mechanisms, the [safe] option
and standard error handling cannot prevent it.
CVE-2026-54890
https://github.com/erlang/otp/security/advisories/GHSA-54pw-5645-jh86
2026-07-27
2026-07-27
Erlang/OTP -- heap corruption decoding invalidly encoded large tuples
erlang
28.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
The Erlang/OTP team reports:
Fixed heap corruption when an invalidly encoded tuple with
an arity of 2^31 or larger is decoded from Erlang's External
Term Format (binary_to_term).
CVE-2026-55737
https://github.com/erlang/otp/releases/tag/OTP-29.0.4
2026-07-27
2026-07-27
Erlang/OTP -- relative path traversal in the zip module
erlang
28.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
The Erlang/OTP team reports:
Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were
vulnerable to a relative path traversal attack. A crafted zip
archive containing entry names such as ../x/y could have
caused files to be written outside the intended extraction
directory.
CVE-2026-47078
https://github.com/erlang/otp/releases/tag/OTP-29.0.4
2026-07-27
2026-07-27
Erlang/OTP -- denial of service in epmd
erlang
28.5.0.4,4
erlang-runtime27
27.3.4.15
erlang-runtime28
28.5.0.4
erlang-runtime29
29.0.4
The Erlang/OTP team reports:
Mitigated a denial of service attack in epmd.
CVE-2026-42792
https://github.com/erlang/otp/releases/tag/OTP-29.0.4
2026-07-27
2026-07-27
Vaultwarden -- multiple vulnerabilities
vaultwarden
1.37.0
The Vaultwarden project reports:
- SSRF via the icon endpoint [GHSA-hw4g-2v3f-74x5] [GHSA-vh5m-fc9v-m84g] (Medium, 5.8 / 6.3)
- Cross-Organization Cipher Access [GHSA-xwf8-pjh7-h589] (Medium, 5.9)
- Organization Policy Bypass on Directory Import [GHSA-88qc-6ch9-mc3j] (Medium, 5.5)
- Send Access-Count Bypass [GHSA-rxhg-2pw9-vf25] (Medium, 5.3)
- Unauthenticated WebSocket Flooding DDOS [GHSA-96f7-78q5-j345] (Medium, 5.3)
- Cross-Organization Secret Sharing [GHSA-455c-vgg9-jxw8] (Medium, 4.3)
- Organization Import Authorization [GHSA-f3qw-qg77-hmm4][GHSA-jq2g-h4xr-4mcr] (Medium, 4.3)
- Organization Data Enumeration via the Manager role [GHSA-rqf8-2568-r7mc] (Medium, 4.3)
https://github.com/dani-garcia/vaultwarden/releases/tag/1.37.0
2026-07-24
2026-07-25
unbound -- multiple vulnerabilities
unbound
1.25.2
NLnet Labs reports:
This release consolidates security fixes for issues reported
over a period of time. There are fixes for:
- CVE-2026-14586: Assertion in libngtcp2 when under pressure
in high concurrency DNS-over-QUIC environments.
- CVE-2026-32665: Remote DNS-over-QUIC denial of service due to
quic-size budget bypass.
- CVE-2026-40691: Packet of death for DNSCrypt over TCP.
- CVE-2026-41637: Degradation of resolution service from
improperly accounted client-terminated DNS-over-QUIC
queries.
- CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the
TTL of A/AAAA records disallowing a one-time 'ghost domain'
delegation renewal via glue records.
- CVE-2026-44621: Libunbound applications configured with
'unwanted-reply-threshold' could eventually be abruptly
terminated.
- CVE-2026-44687: Off-by-one error in 'harden-below-nxdomain'
logic can shadow a stub/forward zone by a legitimate parent's
NXDOMAIN.
- CVE-2026-44690: Cross-zone wildcard cache poisoning via
RRSIG.labels manipulation.
- CVE-2026-46582: A wildcard replay, as another piece of data,
triggers poisoning in the serve expired reply path.
- CVE-2026-50045: 'max-global-quota' reset by DNSSEC validation
restarts.
- CVE-2026-50046: Possible heap use-after-free in an error path
when a DoT forwarded query is jostled out.
- CVE-2026-50243: 'response-ip'/'rpz' can rewrite BOGUS answers
instead of returning SERVFAIL.
- CVE-2026-50248: BOGUS configured primary hostname accepted for
XFR in auth/rpz zones.
- CVE-2026-50251: Attacker supplied 0.0.0.0/:: glue triggers
defensive full-cache flush.
- CVE-2026-50252: Possible cache poisoning attack by mapping
source port population per thread.
- CVE-2026-52863: Memory corruption could lead to crash and
denial of service.
- CVE-2026-54478: DNS Cookie bypass when combined with
proxy-protocol use.
- CVE-2026-55708: Privacy/configuration issue when adding local
data in views through 'unbound-control'.
- CVE-2026-55717: 'serve-expired-client-timeout' and 'response-ip'
CNAME redirect could lead to a crash.
- CVE-2026-55973: 'dns-error-reporting: yes' leads to stack
buffer overflow.
- CVE-2026-55990: Packet of death for a DNSCrypt misconfigured
Unbound.
- CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control
assertion failure in libngtcp2.
- CVE-2026-56416: Possible heap buffer overflow when validator
canonicalizes RDATA that contains domain name.
- CVE-2026-56444: Degradation of resolution service when
'discard-timeout' and 'serve-expired-client-timeout' are
combined in unusual configuration.
CVE-2026-14586
CVE-2026-32665
CVE-2026-40691
CVE-2026-41637
CVE-2026-42955
CVE-2026-44621
CVE-2026-44687
CVE-2026-44690
CVE-2026-46582
CVE-2026-50045
CVE-2026-50046
CVE-2026-50243
CVE-2026-50248
CVE-2026-50251
CVE-2026-50252
CVE-2026-52863
CVE-2026-54478
CVE-2026-55708
CVE-2026-55717
CVE-2026-55973
CVE-2026-55990
CVE-2026-55991
CVE-2026-56416
CVE-2026-56444
https://github.com/NLnetLabs/unbound/releases/tag/release-1.25.2
https://www.nlnetlabs.nl/projects/unbound/security-advisories/
2026-07-22
2026-07-25
gstreamer1 -- multiple vulnerabilities
gstreamer1-plugins
gstreamer1-plugins-bad
gstreamer1-plugins-good
gstreamer1-plugins-ugly
1.28.5
The GStreamer project reports:
Multiple security issues were identified and fixed in the GStreamer framework.
- GStreamer-SA-2026-0044: Out-of-bounds read in RTP CELT audio depayloader
- GStreamer-SA-2026-0049: Heap buffer overflow in MPEG-4 Video parser
- GStreamer-SA-2026-0050: Heap buffer overflow in MOV/MP4 moov recovery tool
- GStreamer-SA-2026-0051: Out-of-bounds read in RTP SBC depayloader
- GStreamer-SA-2026-0052: Heap buffer overflow in GdkPixbuf image decoder due to dimension changes
- GStreamer-SA-2026-0053: Stack and heap buffer overflow in Opus audio decoder
- GStreamer-SA-2026-0054: Heap buffer overflow in encoding-target loader on malformed UTF-8 input
- GStreamer-SA-2026-0055: Out-of-bounds read in H.266/VVC parser PPS tile slice loop
- GStreamer-SA-2026-0056: Heap-based buffer overflow in H.266 video parser slice header processing
- GStreamer-SA-2026-0057: Out-of-bounds read in RTP JPEG depayloader
- GStreamer-SA-2026-0058: Out-of-bounds read in ASF demuxer packet payload parsing
- GStreamer-SA-2026-0059: Out-of-bounds read in VP9 parser superframe index parsing
- GStreamer-SA-2026-0060: Stack-based out-of-bounds write in closed caption converter
- GStreamer-SA-2026-0061: Possible authentication bypass in WebRTC SDP fingerprint validation
- GStreamer-SA-2026-0062: Stack buffer overflow in DTLS certificate verification
- GStreamer-SA-2026-0063: Heap out-of-bounds write in RFB source when decoding framebuffer updates
- GStreamer-SA-2026-0064: NULL pointer dereference in WAV parser during adtl chunk parsing in streaming mode
- GStreamer-SA-2026-0065: Integer overflow in Matroska LZO1X decompressor
CVE-2026-2920
CVE-2026-14935
CVE-2026-59691
CVE-2026-59692
https://gstreamer.freedesktop.org/security/sa-2026-0044.html
https://gstreamer.freedesktop.org/security/sa-2026-0049.html
https://gstreamer.freedesktop.org/security/sa-2026-0050.html
https://gstreamer.freedesktop.org/security/sa-2026-0051.html
https://gstreamer.freedesktop.org/security/sa-2026-0052.html
https://gstreamer.freedesktop.org/security/sa-2026-0053.html
https://gstreamer.freedesktop.org/security/sa-2026-0054.html
https://gstreamer.freedesktop.org/security/sa-2026-0055.html
https://gstreamer.freedesktop.org/security/sa-2026-0056.html
https://gstreamer.freedesktop.org/security/sa-2026-0057.html
https://gstreamer.freedesktop.org/security/sa-2026-0058.html
https://gstreamer.freedesktop.org/security/sa-2026-0059.html
https://gstreamer.freedesktop.org/security/sa-2026-0060.html
https://gstreamer.freedesktop.org/security/sa-2026-0061.html
https://gstreamer.freedesktop.org/security/sa-2026-0062.html
https://gstreamer.freedesktop.org/security/sa-2026-0063.html
https://gstreamer.freedesktop.org/security/sa-2026-0064.html
https://gstreamer.freedesktop.org/security/sa-2026-0065.html
2026-07-08
2026-07-24
giflib -- Buffer Overflow vulnerability
giflib
6.1.3
https://github.com/zakkanijia/POC/blob/main/giflib/giftool/giflib_giftool_gce_len_heap_oobwrite_disclosure.md reports:
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote
attacker to cause a denial of service via the EGifGCBToExtension
overwriting an existing Graphic Control Extension block without
validating its allocated size.
CVE-2026-26740
https://cveawg.mitre.org/api/cve/CVE-2026-26740
2026-03-18
2026-07-21
srt -- Multiple vulnerabilities
srt
1.5.6
The SRT project reports:
- CVE-2026-55869: Heap-Based Buffer Overflow in KMREQ Handling.
A remote attacker may be able to trigger a heap-based buffer
overflow during key material request processing, leading to a
denial of service or potentially arbitrary code execution.
- CVE-2026-55868: Encryption State Machine Downgrade.
A flaw in the encryption state machine may allow an attacker to
downgrade the negotiated encryption, weakening confidentiality
protections for the SRT stream.
CVE-2026-55869
CVE-2026-55868
https://github.com/Haivision/srt/releases/tag/v1.5.6
2026-07-20
2026-07-21
Weechat -- Multiple vulnerabilities
weechat
4.9.4
The Weechat project reports:
Write of logger file outside of configured path.
Authentication bypass in Relay plugin, protocols "api" and "weechat".
https://github.com/weechat/weechat/releases/tag/v4.9.4
2026-07-19
2026-07-20
Mailpit -- SMTP DATA line reader buffers over-limit input before size enforcement
mailpit
1.30.5
Mailpit author reports:
Mailpit's SMTP DATA reader enforces the configured
MaxMessageSize only after bufio.Reader.ReadBytes('\n')
has already buffered a complete DATA line. A remote
unauthenticated SMTP client can send one line larger than
the configured message-size cap and force memory allocation
before Mailpit returns the expected 552 5.3.4 rejection,
leaving patched versions still exposed to a single-line
incomplete-fix variant of the earlier SMTP DATA body-size
issue.
https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97
2026-07-20
2026-07-20
tailscale -- Multiple vulnerabilities
tailscale
1.98.10
Tailscale team reports:
Tailscale SSH Unix socket forwarding respects symlink
permissions. This fix addresses a security vulnerability
described in TS-2026-004.
Tailscale Serve Unix socket proxy targets are restricted
to the root user. This fix addresses a security
vulnerability described in TS-2026-005.
Tailscale SSH does not allow the use of UIDs or
numeric-only usernames. This fix addresses a security
vulnerability described in TS-2026-006.
Nodes advertising Tailscale Services filter and reject
packets from service IPs on ports they do not
advertise. This fix addresses a security vulnerability
described in TS-2026-007.
Tailscale Serve and Tailscale Funnel terminate path walks
for non-absolute paths, preventing CPU core pinning. This
fix addresses a security vulnerability described in
TS-2026-008.
Tailscale SSH does not allow the use of usernames with
leading dashes. This fix addresses a security vulnerability
described in TS-2026-009.
https://tailscale.com/changelog#2026-07-14
2026-06-03
2026-07-19
traefik -- Multiple vulnerabilities
traefik
3.7.8
The traefik project releases a new version addressing multiple vulnerabilities:
- GHSA-cxjq-mrr5-89rv (Authentication Bypass via Path Traversal in ReplacePathRegex Middleware)
- GHSA-42cj-m3vj-89wv (CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass)
- GHSA-qq9q-x9w4-chhj (Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion)
- GHSA-8rxv-jg7p-wvg3 (Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass)
https://github.com/traefik/traefik/releases/tag/v3.7.7
https://github.com/traefik/traefik/releases/tag/v3.7.8
2026-07-08
2026-07-18
phpmyfaq -- multiple vulnerabilities
phpmyfaq-php83
phpmyfaq-php84
phpmyfaq-php85
4.1.6
phpMyFAQ team reports:
An authenticated administrator can supply an untrusted
update-package path to the configuration API, causing phpMyFAQ
to write an arbitrary PHP file to the server and thereby
execute attacker-controlled code.
An attacker can exploit a path traversal in the category image
deletion routine to remove arbitrary files outside the intended
directory, which can leave the installation in a state that
allows a setup takeover.
The two-factor authentication login flow can be completed
without verifying the password factor, so an attacker who
possesses only the second factor is able to authenticate as the
victim.
A delegated administrator with only the GROUP_EDIT permission
can assign group memberships without restriction through
GroupController::updateMembers, inheriting rights they do not
hold and escalating their privileges.
An authenticated user can inject SQL through an unescaped stop
word inserted via StopWords::add(), allowing manipulation of the
underlying database query.
https://www.phpmyfaq.de/security/advisory-2026-07-13/
2026-07-13
2026-07-18
nginx -- multiple vulnerabilities
nginx
1.30.4,3
nginx-devel
1.31.3
The nginx development team reports:
Buffer overflow when using map and regex
(CVE-2026-42533). Severity: major.
Memory disclosure when using ngx_http_slice_module
(CVE-2026-60005). Severity: medium.
Use-after-free when using ngx_http_ssi_module
(CVE-2026-56434). Severity: medium.
CVE-2026-42533
CVE-2026-56434
CVE-2026-60005
https://nginx.org/en/security_advisories.html
2026-07-15
2026-07-18
liboqs -- Multiple vulnerabilities
liboqs
0.16.0
The OpenQuantumSafe project reports:
- uninitialized encaps_derand pointer dereference
- out-of-bounds read in XMSS/XMSS^MT signature verification
- Integer underflow in CROSS crypto_sign_open()
- incorrect array size when calling secure_clean
- Implemented optimization barrier OQS_MEM_BLACK_BOX and applied to ct_select in FrodoKEM
https://github.com/open-quantum-safe/liboqs/releases/tag/0.16.0
2026-07-09
2026-07-16
Poppler: integer overflow in tilingPatternFill
poppler
poppler-glib
poppler-qt5
poppler-qt6
poppler-utils
26.04.0_1
https://access.redhat.com/errata/RHSA-2026:24984 reports:
A flaw was found in Poppler's Splash backend. A remote attacker
could exploit this vulnerability by crafting a malicious PDF file
that, when rendered, triggers an integer overflow in the
`tilingPatternFill` function. This overflow leads to an undersized
heap memory allocation, allowing a subsequent out-of-bounds write.
Successful exploitation could result in arbitrary code execution,
information disclosure, or denial of service within the context of
the application processing the PDF.
CVE-2026-10118
https://cveawg.mitre.org/api/cve/CVE-2026-10118
2026-06-01
2026-07-14
ocaml-opam -- opam install sandbox escape using symlinks
ocaml-opam
2.5.2
The OCaml Team reports:
Installing files through .install files do not check symlinks resolution of the target path, and so can bypass sandboxing.
Credits:
Reporter: "Kate Deplaix"
Remediation Developer: "Nathan Rebours"
Remediation Reviewer: "Raja Boujbel"
Coordinator: "Hannes Mehnert"
CVE-2026-57825
https://github.com/ocaml/security-advisories/blob/main/advisories/2026/OSEC-2026-10.md
https://nvd.nist.gov/vuln/detail/CVE-2026-57825
2026-07-12
2026-07-14
Apache HttpClient -- misinterpret malformed authority component
apache-commons-httpclient
jakarta-commons-httpclient
3.1
httpclient
4.5.13
5.0.05.0.3
Apache Software Foundation reports:
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
CVE-2020-13956
https://nvd.nist.gov/vuln/detail/CVE-2020-13956
2020-02-12
2026-07-10
httpclient -- Improper Certificate Validation
apache-commons-httpclient
jakarta-commons-httpclient
3.1
MITRE reports:
Apache Commons HttpClient 3.x, as used in ..., does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVE-2012-5783
https://nvd.nist.gov/vuln/detail/CVE-2012-5783
2012-04-11
2026-07-10
mailpit -- multiple vulnerabilities
mailpit
1.30.4
Mailpit author reports:
Mailpit's SMTP server reads each command line with an
unbounded bufio.Reader.ReadString('\n') before parsing
the command or enforcing any protocol length limit. A
remote SMTP client can send an oversized single command
line and force Mailpit to allocate attacker-controlled
memory before the server returns a syntax error or times
out, even though RFC 5321 limits SMTP command lines to
512 octets including CRLF.
Mailpit's thumbnail endpoint decodes attacker-supplied
image attachments into a full raster before checking any
decoded-pixel, dimension, or memory budget. A remote
client that can store an email and reach the default web
API can supply a compact high-dimension image, then request
/api/v1/message/{id}/part/{partID}/thumb to
force server-side memory and CPU work far larger than the
encoded attachment size before Mailpit returns a 180x120
thumbnail.
https://github.com/axllent/mailpit/security/advisories/GHSA-w878-pj84-3j5v
https://github.com/axllent/mailpit/security/advisories/GHSA-75mr-qw9x-3r39
2026-07-09
2026-07-09
Gitlab -- Vulnerabilities
gitlab-ce
gitlab-ee
19.1.019.1.2
19.0.019.0.4
9.1.018.11.7
Gitlab reports:
Cross-site Scripting issue in vulnerability evidence table renderer impacts GitLab EE
HTML Injection in wiki markup rendering impacts GitLab CE/EE
Insufficiently Protected Credentials issue in repository mirroring impacts GitLab EE
Improper Access Control issue in work items impacts GitLab EE
Missing Authorization issue in commit discussion display impacts GitLab CE/EE
Ambiguity Reference issue in a tag or branch impacts GitLab CE/EE
Incorrect Authorization issue in group-level settings impacts GitLab EE
Incorrect Authorization issue in compliance violation management impacts GitLab EE
CVE-2026-6896
CVE-2026-13320
CVE-2026-11827
CVE-2026-8472
CVE-2026-7492
CVE-2025-12506
CVE-2026-13151
CVE-2026-6352
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/
2026-07-08
2026-07-09
libXfont2 -- Multiple vulnerabilities
libXfont2
2.0.8
X.Org project reports:
Multiple issues have been found in the libXfont2 library published
by X.Org for which we are releasing security fixes in libXfont2-2.0.8.
CVE-2026-56001
CVE-2026-56002
CVE-2026-56003
https://lists.x.org/archives/xorg-announce/2026-July/003714.html
2026-07-08
2026-07-08
xwayland -- Multiple vulnerabilities
xwayland
24.1.13,1
X.Org project reports:
Multiple issues have been found in the X server and Xwayland
implementations published by X.Org for which we are releasing
security fixes for in xorg-server-21.1.24 and xwayland-24.1.13.
CVE-2026-55999
CVE-2026-56000
https://lists.x.org/archives/xorg-announce/2026-July/003716.html
2026-07-07
2026-07-08
xorg-server -- Multiple vulnerabilities
xorg-server
21.1.24,1
X.Org project reports:
Multiple issues have been found in the X server and Xwayland
implementations published by X.Org for which we are releasing
security fixes for in xorg-server-21.1.24 and xwayland-24.1.13.
CVE-2026-55999
CVE-2026-56000
https://lists.x.org/archives/xorg-announce/2026-July/003716.html
2026-07-07
2026-07-08
cacti -- multiple vulnerabilities
cacti
1.2.31
Cacti project reports:
This release includes fixes for a number of vulnerabilities that were responsibly disclosed by external researchers
- CVE-2026-39894 RRDtool metric shift via LC_NUMERIC locale comma decimal formatting
- CVE-2026-40082 Session Fixation via missing session_regenerate_id() after login
- CVE-2026-40941 Package Import Signature Validation Bypass allows self-signed packages
- CVE-2026-39897 Reflected XSS in html_auth_footer error message output
- CVE-2026-39900 Reflected XSS via tab parameter in auth_profile.php JavaScript context
- CVE-2026-46531 SQL Injection in automation_tree_rules.php
- CVE-2026-44481 Pre-auth Open Redirect via link.php Referer header
- CVE-2026-39952 Stored XSS in Report Tree expansion titles
- CVE-2026-39893 Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php
- CVE-2026-22802 Authentication Bypass leads to information disclosure
- CVE-2026-40080 Open Redirect via HTTP_REFERER substring check in auth_login_redirect
- CVE-2026-40078 Backend ORDER BY SQL Injection
- CVE-2026-39949 Authenticated Remote Code Execution via Host Variable Injection
- CVE-2026-40081 Reports IDOR allows any authenticated user to modify other users' reports (CWE-639)
- CVE-2026-39948 SQL Injection via rfilter parameter in RLIKE clauses
- CVE-2026-39902 Authenticated RCE on Data Input
- CVE-2026-39898 Reflected XSS via rfilter parameter in aggregate_graphs.php input value
- CVE-2026-41884 Arbitrary File Read via Reports format_file path traversal
- CVE-2026-39955 Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
- CVE-2026-39896 TOCTOU race in auth_process_lockout allows brute-force lockout bypass
- CVE-2026-39950 Arbitrary PHP file write via Plugin Archive extraction leading to RCE
- CVE-2026-40083 SQL Injection in managers.php via uncast array values in IN clauses
- CVE-2026-40084 Arbitrary File Read via path traversal in Report format_file parameter
- CVE-2026-39951 Stored SQL Injection via graph_name_regexp in Reports feature
- CVE-2026-39899 Path traversal via filename parameter in package_import.php
- CVE-2026-39938 Unauthenticated LFI via graph_theme and rrdtool IPC serialization hardening
- CVE-2026-39939 Path traversal in Package Import file write allows arbitrary file creation in webroot
- CVE-2026-39947 RRDtool IPC pipe poisoning via is_numeric newline bypass in rrdtool_function_update
- CVE-2026-39895 Second-order RCE via unescaped log path in exec_background shell redirection
- CVE-2026-40079 Command Injection via escape_command() no-op in RRDtool execution
- CVE-2026-40194, CVE-2026-32935 in phpseclib - This is breaking change for RRDProxy
- CVE-2026-1513 billboard.js before 3.18.0 Improper Input Sanitization Allows Remote JavaScript Execution
CVE-2026-39894
CVE-2026-40082
CVE-2026-40941
CVE-2026-39897
CVE-2026-39900
CVE-2026-46531
CVE-2026-44481
CVE-2026-39952
CVE-2026-39893
CVE-2026-22802
CVE-2026-40080
CVE-2026-40078
CVE-2026-39949
CVE-2026-40081
CVE-2026-39948
CVE-2026-39902
CVE-2026-39898
CVE-2026-41884
CVE-2026-39955
CVE-2026-39896
CVE-2026-39950
CVE-2026-40083
CVE-2026-40084
CVE-2026-39951
CVE-2026-39899
CVE-2026-39938
CVE-2026-39939
CVE-2026-39947
CVE-2026-39895
CVE-2026-40079
CVE-2026-40194
CVE-2026-32935
CVE-2026-1513
https://github.com/Cacti/cacti/releases/tag/release%2F1.2.31
2026-06-16
2026-07-07
xrdp -- multiple vulnerabilities
xrdp
0.10.6.1.r.1,1
xrdp-devel
0.10.80.b20260706,1
xrdp projects reports:
xrdp v0.10.6.1 fixes 10 vulnerabilities and 1 regression introduced
by a vulnerability fix in the previous release.
CVE-2026-41252
CVE-2026-41521
CVE-2026-44178
CVE-2026-42218
CVE-2026-44978
CVE-2026-54538
CVE-2026-55238
CVE-2026-55626
CVE-2026-55639
CVE-2026-55645
https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1
2026-07-06
2026-07-06
zeek -- potential DoS vulnerabilities
zeek
8.0.9
Tim Wojtulewicz of Corelight reports:
The NVT, Rlogin, and RSH analyzers have received fixes
to avoid unbounded state growth. Due to the fact that
these packets can be received from remote hosts, these
are considered DoS risks.
A specially crafted WebSocket payload can cause the
Spicy WebSocket analyzer to use excessive memory when
processing close, ping, and pong frames. Due to the fact
that these packets can be received from remote hosts,
these are considered a DoS risk.
A specially crafted series of Finger packets can cause
the Spicy Finger analyzer to use excessive amounts of
memory and potentially crash Zeek. Due to the fact that
these packets can be received from remote hosts, this is
considered a DoS risk.
A specially crafted Kerberos packet can cause the
Kerberos analyzer to enter an invalid state and potentially
crash Zeek. Due to the fact that these packets can be
received from remote hosts, this is considered a DoS risk.
A specially crafted series of RDP packets can cause
the RDP analyzer to use excessive amounts of memory and
potentially crash Zeek. Due to the fact that these packets
can be received from remote hosts, this is considered a
DoS risk.
A specially crafted IP packet can cause the IP analyzer
to read past the end of the contents of the packet when
emitting the packet_contents event and possibly crash.
Due to the fact that these packets can be received from
remote hosts, this is considered a DoS risk.
A specially crafted IP packet can cause the packet
discarding code to read off the end of the packet when
looking for follow-on header data. This may potentially
lead to a crash of Zeek. Due to the fact that these packets
can be received from remote hosts, this is considered a
DoS risk.
A specially crafted series of Gnutella packets may
cause Zeek to continue accumulating memory and eventually
crash. Due to the fact that these packets can be received
from remote hosts, this is considered a DoS risk.
A specially crafted ICMPv6 packet can cause the ICMP
analyzer to skip part of the packet and not report
corresponding events and logs. Due to the fact that these
packets can be received from remote hosts, this is
considered an evasion risk.
A specially crafted SSH packet can cause the SSH
analyzer to throw BinPAC exceptions for extremely large
packets and skip logging them otherwise. Due to the fact
that these packets can be received from remote hosts,
this is considered an evasion risk.
A number of issues with the HTTP analyzer were found
involving unusual Content-Length, Transfer-Encoding and
Expect header usage. Due to the fact that these packets
can be received from remote hosts, this is considered an
evasion risk.
A series of fixes were applied to the serialization
code in Zeek to avoid buffer overreads with both Broker
and ZeroMQ traffic. On debug builds, these hit various
abort() conditions and cause Zeek to exit. Due to the
fact that all of these states require direct access to
the Broker/ZeroMQ ports (meaning access to the local
network to some degree), this isn’t considered a DoS risk.
https://github.com/zeek/zeek/releases/tag/v8.0.9
2026-07-06
2026-07-06
Emacs -- Heap out-of-bounds write when rendering SVG images
emacs
emacs-canna
emacs-nox
emacs-wayland
28.1,330.2_4,3
emacs-devel
emacs-devel-nox
31.0.50.20250201,3
Problem Description
When GNU Emacs renders an SVG image whose image spec includes a
:css property, an off-by-one error in svg_load_image() writes a NUL
byte one position past the end of a heap allocation. The copied
string is also left without NUL termination within its allocation,
causing a subsequent out-of-bounds read.
Impact
A single NUL byte heap overflow is a well-understood exploitation
primitive ("poison NUL byte") that can corrupt heap metadata and
potentially be escalated to arbitrary code execution. The overflow
can be triggered by Lisp code that displays an SVG image with a
crafted :css property.
CVE-2026-6861
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80851
https://nvd.nist.gov/vuln/detail/CVE-2026-6861
2026-04-17
2026-07-06
Weechat -- Memory leak in relay-API
weechat
4.9.3
The Weechat project reports:
Pre-auth memory leak in relay-api POST /api/handshake (unfreed JSON body) → unauthenticated remote memory-exhaustion DoS.
https://github.com/weechat/weechat/security/advisories/GHSA-wmpc-m6g9-fwj8
2026-07-05
2026-07-05
Roundcube -- Multiple vulnerabilities
roundcube-php82
roundcube-php83
roundcube-php84
roundcube-php85
1.7.2,1
The Rouncube project reports:
See links for more detail
CVE-2026-54432
CVE-2026-54433
https://github.com/roundcube/roundcubemail/releases/tag/1.7.2
2026-07-05
2026-07-05
traefik -- Multiple vulnerabilities
traefik
3.7.6
The traefik project releases a new version addressing multiple CVEs:
- CVE-2026-54763 (underscore-variant identity spoofing)
- CVE-2026-54764 (ForwardAuth middleware leaks X-Forwarded-Port spoofing)
- CVE-2026-54765 (Gateway HTTPRoute backendRef filters can leak backend context)
CVE-2026-54763
CVE-2026-54764
CVE-2026-54765
https://github.com/traefik/traefik/releases/tag/v3.7.6
2026-06-30
2026-07-04
p5-CGI-Session -- secuity fixes
p5-CGI-Session
4.49
CGI-Session project reports:
SECURITY: Strengthen cryptographic randomness of MD5 driver.
CVE-2026-56016
https://nvd.nist.gov/vuln/detail/CVE-2026-56016
2026-06-30
2026-07-04
chromium -- security fixes
chromium
150.0.7871.46
ungoogled-chromium
150.0.7871.46
Chrome Releases reports:
This update includes 382 security fixes:
- [506558270] Critical CVE-2026-13774: Use after free in Extensions.
- [511766407] Critical CVE-2026-13775: Use after free in GPU.
- [513012139] Critical CVE-2026-13776: Type Confusion in Dawn.
- [513128566] Critical CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb.
- [513167952] Critical CVE-2026-13778: Use after free in WebUSB.
- [513222854] Critical CVE-2026-13779: Use after free in Chromoting.
- [514769383] Critical CVE-2026-13780: Insufficient validation of untrusted input in ANGLE.
- [516457532] Critical CVE-2026-13781: Insufficient validation of untrusted input in Skia.
- [516683433] Critical CVE-2026-13782: Use after free in Browser.
- [516962178] Critical CVE-2026-13783: Use after free in Views.
- [516962715] Critical CVE-2026-13784: Use after free in Views.
- [517021684] Critical CVE-2026-13785: Use after free in Bluetooth.
- [518007821] Critical CVE-2026-13786: Use after free in Ozone.
- [522919313] Critical CVE-2026-13787: Use after free in Chromoting.
- [523119897] Critical CVE-2026-13788: Use after free in Fullscreen.
- [493847920] High CVE-2026-13789: Use after free in GPU.
- [457771782] High CVE-2026-13790: Side-channel information leakage in Scroll.
- [503850012] High CVE-2026-13791: Insufficient validation of untrusted input in Downloads.
- [496012368] High CVE-2026-13792: Use after free in Touchbar.
- [510829679] High CVE-2026-13793: Insufficient policy enforcement in SVG.
- [513893425] High CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls.
- [476591032] High CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS.
- [491894115] High CVE-2026-13796: Integer overflow in Chromecast.
- [499025645] High CVE-2026-13797: Insufficient validation of untrusted input in Chromecast.
- [499048914] High CVE-2026-13798: Heap buffer overflow in Chromecast.
- [499252371] High CVE-2026-13799: Use after free in QUIC.
- [500108770] High CVE-2026-13800: Inappropriate implementation in Updater.
- [500587568] High CVE-2026-13801: Integer overflow in Chromecast.
- [501623322] High CVE-2026-13802: Use after free in Views.
- [501669642] High CVE-2026-13803: Type Confusion in Chrome Tabs.
- [501873032] High CVE-2026-13804: Use after free in Chromecast.
- [502282040] High CVE-2026-13805: Use after free in GFX.
- [503333798] High CVE-2026-13806: Insufficient validation of untrusted input in Accessibility.
- [504194494] High CVE-2026-13807: Use after free in Import.
- [504221510] High CVE-2026-13808: Insufficient data validation in Chrome for iOS.
- [504222227] High CVE-2026-13809: Side-channel information leakage in Safe Browsing. eported by Google on 2026-04-19
- [504600482] High CVE-2026-13810: Inappropriate implementation in Input.
- [506149253] High CVE-2026-13811: Use after free in IME.
- [508293203] High CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS.
- [508462149] High CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS.
- [511712766] High CVE-2026-13814: Use after free in Views.
- [511722207] High CVE-2026-13815: Use after free in Blink.
- [511735715] High CVE-2026-13816: Insufficient validation of untrusted input in File Input.
- [511739631] High CVE-2026-13817: Insufficient validation of untrusted input in Glic.
- [511823182] High CVE-2026-13818: Inappropriate implementation in Passwords.
- [512962749] High CVE-2026-13819: Out of bounds read in ANGLE.
- [512986879] High CVE-2026-13820: Out of bounds read in Skia.
- [513142445] High CVE-2026-13821: Use after free in Canvas.
- [513148038] High CVE-2026-13822: Inappropriate implementation in Extensions.
- [513163011] High CVE-2026-13823: Use after free in Glic.
- [513177497] High CVE-2026-13824: Insufficient validation of untrusted input in Extensions.
- [513209610] High CVE-2026-13825: Uninitialized Use in Dawn.
- [513237800] High CVE-2026-13826: Inappropriate implementation in Autofill.
- [513371963] High CVE-2026-13827: Use after free in Updater.
- [513399832] High CVE-2026-13828: Inappropriate implementation in Enterprise.
- [513490996] High CVE-2026-13829: Insufficient validation of untrusted input in Settings.
- [513727494] High CVE-2026-13830: Use after free in Chromoting.
- [513781328] High CVE-2026-13831: Use after free in GPU.
- [513822378] High CVE-2026-13832: Use after free in Headless.
- [513920082] High CVE-2026-13833: Uninitialized Use in ANGLE.
- [513925114] High CVE-2026-13834: Insufficient validation of untrusted input in ANGLE.
- [514338102] High CVE-2026-13835: Inappropriate implementation in XML.
- [514420555] High CVE-2026-13836: Inappropriate implementation in CSS.
- [514429130] High CVE-2026-13837: Inappropriate implementation in CSS.
- [514445398] High CVE-2026-13838: Inappropriate implementation in CSS.
- [514449396] High CVE-2026-13839: Inappropriate implementation in CSS.
- [514609778] High CVE-2026-13840: Insufficient policy enforcement in Canvas.
- [515467789] High CVE-2026-13841: Integer overflow in Skia.
- [516836297] High CVE-2026-13842: Incorrect security UI in Chrome for iOS.
- [516869032] High CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS.
- [516926115] High CVE-2026-13844: Use after free in Updater.
- [516936863] High CVE-2026-13845: Use after free in DOM.
- [516999424] High CVE-2026-13846: Use after free in USB.
- [517073397] High CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS.
- [517345069] High CVE-2026-13848: Use after free in Forms.
- [517351411] High CVE-2026-13849: Insufficient validation of untrusted input in Chromoting.
- [517610676] High CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS.
- [519692255] High CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls.
- [522560124] High CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls.
- [523224019] High CVE-2026-13853: Use after free in Journeys.
- [523690961] High CVE-2026-13854: Use after free in Ozone.
- [524395469] High CVE-2026-13855: Use after free in Ozone.
- [508092634] Medium CVE-2026-13856: Insufficient validation of untrusted input in Speech.
- [479203484] Medium CVE-2026-13857: Inappropriate implementation in Geometry.
- [507090179] Medium CVE-2026-13858: Out of bounds read in FFmpeg.
- [484756087] Medium CVE-2026-13859: Inappropriate implementation in ANGLE.
- [417052041] Medium CVE-2026-13860: Incorrect security UI in Autofill.
- [495456765] Medium CVE-2026-13861: Use after free in Core.
- [495897416] Medium CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys).
- [496012495] Medium CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs.
- [496399913] Medium CVE-2026-13864: Insufficient policy enforcement in WebHID.
- [497090912] Medium CVE-2026-13865: Insufficient validation of untrusted input in Enterprise.
- [497207698] Medium CVE-2026-13866: Insufficient validation of untrusted input in Input.
- [497345177] Medium CVE-2026-13867: Inappropriate implementation in Geolocation.
- [497453475] Medium CVE-2026-13868: Inappropriate implementation in Network.
- [497610642] Medium CVE-2026-13869: Use after free in Device.
- [497634837] Medium CVE-2026-13870: Use after free in WebView.
- [497961376] Medium CVE-2026-13871: Insufficient data validation in GuestView.
- [497977983] Medium CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls.
- [498085466] Medium CVE-2026-13873: Out of bounds memory access in Layout.
- [498411773] Medium CVE-2026-13874: Inappropriate implementation in DataTransfer.
- [498721671] Medium CVE-2026-13875: Insufficient validation of untrusted input in GPU.
- [498722200] Medium CVE-2026-13876: Inappropriate implementation in Network.
- [498820206] Medium CVE-2026-13877: Insufficient validation of untrusted input in ANGLE.
- [499007266] Medium CVE-2026-13878: Use after free in Bluetooth.
- [499022239] Medium CVE-2026-13879: Use after free in Bluetooth.
- [499025880] Medium CVE-2026-13880: Use after free in USB.
- [499100491] Medium CVE-2026-13881: Insufficient data validation in WebAppInstalls.
- [499162550] Medium CVE-2026-13882: Inappropriate implementation in USB.
- [500030250] Medium CVE-2026-13883: Type Confusion in ANGLE.
- [500077014] Medium CVE-2026-13884: Heap buffer overflow in Chromecast.
- [500474409] Medium CVE-2026-13885: Use after free in Skia.
- [500475136] Medium CVE-2026-13886: Policy bypass in Isolated Web Apps.
- [500508524] Medium CVE-2026-13887: Insufficient policy enforcement in NFC.
- [500566906] Medium CVE-2026-13888: Use after free in Extensions.
- [500588580] Medium CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication.
- [500601345] Medium CVE-2026-13890: Out of bounds read in Chromecast.
- [501631475] Medium CVE-2026-13891: Insufficient validation of untrusted input in Extensions.
- [501674841] Medium CVE-2026-13892: Inappropriate implementation in Chrome for iOS.
- [501729582] Medium CVE-2026-13893: Insufficient validation of untrusted input in WebUI.
- [501741117] Medium CVE-2026-13894: Insufficient policy enforcement in Network.
- [501770542] Medium CVE-2026-13895: Inappropriate implementation in Autofill.
- [501820076] Medium CVE-2026-13896: Insufficient policy enforcement in Glic.
- [501877896] Medium CVE-2026-13897: Insufficient policy enforcement in Chromecast.
- [501925480] Medium CVE-2026-13898: Use after free in Cast Receiver.
- [502109002] Medium CVE-2026-13899: Use after free in HTML.
- [502374993] Medium CVE-2026-13900: Insufficient validation of untrusted input in Chromecast.
- [503585173] Medium CVE-2026-13901: Insufficient validation of untrusted input in Serial.
- [503725717] Medium CVE-2026-13902: Inappropriate implementation in Chrome for iOS.
- [503912196] Medium CVE-2026-13903: Insufficient policy enforcement in Bluetooth.
- [504185807] Medium CVE-2026-13904: Incorrect security UI in Safe Browsing.
- [504192688] Medium CVE-2026-13905: Incorrect security UI in Chrome for iOS.
- [504613867] Medium CVE-2026-13906: Out of bounds read in Codecs.
- [505156685] Medium CVE-2026-13907: Inappropriate implementation in iOSWeb.
- [505242189] Medium CVE-2026-13908: Insufficient validation of untrusted input in Omnibox.
- [505933538] Medium CVE-2026-13909: Insufficient policy enforcement in DevTools.
- [507231605] Medium CVE-2026-13910: Insufficient policy enforcement in WebXR.
- [507239830] Medium CVE-2026-13911: Insufficient data validation in Spellcheck.
- [508259433] Medium CVE-2026-13912: Incorrect security UI in Safe Browsing.
- [508260619] Medium CVE-2026-13913: Insufficient policy enforcement in Autofill.
- [508273690] Medium CVE-2026-13914: Inappropriate implementation in Passwords.
- [508275293] Medium CVE-2026-13915: Use after free in Chrome for iOS.
- [508283108] Medium CVE-2026-13916: Inappropriate implementation in Chrome for iOS.
- [508286935] Medium CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS.
- [509712284] Medium CVE-2026-13918: Use after free in Chrome for iOS.
- [511249430] Medium CVE-2026-13919: Insufficient data validation in Extensions.
- [511722559] Medium CVE-2026-13920: Insufficient validation of untrusted input in Media.
- [511738175] Medium CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials.
- [511748106] Medium CVE-2026-13922: Side-channel information leakage in Paint.
- [511772034] Medium CVE-2026-13923: Uninitialized Use in GPU.
- [511784747] Medium CVE-2026-13924: Insufficient validation of untrusted input in WebView.
- [511802911] Medium CVE-2026-13925: Inappropriate implementation in Downloads.
- [511814550] Medium CVE-2026-13926: Insufficient validation of untrusted input in Network.
- [511826446] Medium CVE-2026-13927: Insufficient validation of untrusted input in UI.
- [512162479] Medium CVE-2026-13928: Insufficient validation of untrusted input in Enterprise.
- [512249559] Medium CVE-2026-13929: Insufficient validation of untrusted input in DevTools.
- [512937764] Medium CVE-2026-13930: Insufficient policy enforcement in Actor.
- [512997441] Medium CVE-2026-13931: Inappropriate implementation in Media.
- [513001690] Medium CVE-2026-13932: Inappropriate implementation in Sharing.
- [513002625] Medium CVE-2026-13933: Insufficient policy enforcement in Passwords.
- [513006636] Medium CVE-2026-13934: Insufficient validation of untrusted input in Dawn.
- [513009005] Medium CVE-2026-13935: Side-channel information leakage in ComputePressure.
- [513044658] Medium CVE-2026-13936: Inappropriate implementation in Passwords.
- [513046494] Medium CVE-2026-13937: Insufficient policy enforcement in Passwords.
- [513143921] Medium CVE-2026-13938: Integer overflow in Fonts.
- [513149760] Medium CVE-2026-13939: Insufficient validation of untrusted input in WebShare.
- [513158425] Medium CVE-2026-13940: Uninitialized Use in Cast.
- [513183855] Medium CVE-2026-13941: Inappropriate implementation in SiteSettings.
- [513186670] Medium CVE-2026-13942: Insufficient validation of untrusted input in Video Capture.
- [513204116] Medium CVE-2026-13943: Uninitialized Use in CSS.
- [513224212] Medium CVE-2026-13944: Inappropriate implementation in DataTransfer.
- [513226551] Medium CVE-2026-13945: Insufficient policy enforcement in Extensions.
- [513274039] Medium CVE-2026-13946: Inappropriate implementation in ScriptInjections.
- [513280648] Medium CVE-2026-13947: Uninitialized Use in XR.
- [513286820] Medium CVE-2026-13948: Insufficient policy enforcement in Extensions.
- [513311569] Medium CVE-2026-13949: Insufficient policy enforcement in Payments.
- [513360781] Medium CVE-2026-13950: Uninitialized Use in GPU.
- [513394321] Medium CVE-2026-13951: Policy bypass in USB.
- [513401808] Medium CVE-2026-13952: Inappropriate implementation in PerformanceAPIs.
- [513459192] Medium CVE-2026-13953: Inappropriate implementation in SplitView.
- [513504934] Medium CVE-2026-13954: Insufficient policy enforcement in XML.
- [513508305] Medium CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs.
- [513515168] Medium CVE-2026-13956: Incorrect security UI in PageInfo.
- [513553557] Medium CVE-2026-13957: Incorrect security UI in Extensions.
- [513567306] Medium CVE-2026-13958: Uninitialized Use in Codecs.
- [513609249] Medium CVE-2026-13959: Insufficient validation of untrusted input in Blink.
- [513714023] Medium CVE-2026-13960: Inappropriate implementation in Passwords.
- [513719481] Medium CVE-2026-13961: Insufficient validation of untrusted input in DevTools.
- [513721370] Medium CVE-2026-13962: Insufficient data validation in PDF.
- [513727626] Medium CVE-2026-13963: Inappropriate implementation in DevTools.
- [513735096] Medium CVE-2026-13964: Insufficient policy enforcement in WebView.
- [513737952] Medium CVE-2026-13965: Use after free in Oilpan.
- [513741393] Medium CVE-2026-13966: Inappropriate implementation in History.
- [513751951] Medium CVE-2026-13967: Type Confusion in V8.
- [513762145] Medium CVE-2026-13968: Insufficient validation of untrusted input in DevTools.
- [513762962] Medium CVE-2026-13969: Uninitialized Use in UI.
- [513779283] Medium CVE-2026-13970: Uninitialized Use in Media.
- [513780208] Medium CVE-2026-13971: Uninitialized Use in Skia.
- [513792140] Medium CVE-2026-13972: Inappropriate implementation in Paint.
- [513832989] Medium CVE-2026-13973: Inappropriate implementation in UI.
- [513850475] Medium CVE-2026-13974: Integer overflow in Safe Browsing.
- [513857658] Medium CVE-2026-13975: Out of bounds read in ANGLE.
- [513858286] Medium CVE-2026-13976: Heap buffer overflow in Storage.
- [513859894] Medium CVE-2026-13977: Inappropriate implementation in HTMLParser.
- [513866949] Medium CVE-2026-13978: Insufficient policy enforcement in PageInfo.
- [513988889] Medium CVE-2026-13979: Inappropriate implementation in Paint.
- [513989973] Medium CVE-2026-13980: Incorrect security UI in Chrome for iOS.
- [513990408] Medium CVE-2026-13981: Inappropriate implementation in Chrome for iOS.
- [514006829] Medium CVE-2026-13982: Incorrect security UI in Passwords.
- [514009910] Medium CVE-2026-13983: Incorrect security UI in Chrome for iOS.
- [514010404] Medium CVE-2026-13984: Incorrect security UI in TabStrip.
- [514013849] Medium CVE-2026-13985: Inappropriate implementation in MediaCapture.
- [514020959] Medium CVE-2026-13986: Inappropriate implementation in Media UI.
- [514039122] Medium CVE-2026-13987: Incorrect security UI in Mobile.
- [514040614] Medium CVE-2026-13988: Inappropriate implementation in Paint.
- [514056221] Medium CVE-2026-13989: Insufficient policy enforcement in PageInfo.
- [514058439] Medium CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer.
- [514061117] Medium CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS.
- [514063409] Medium CVE-2026-13992: Inappropriate implementation in UI.
- [514064139] Medium CVE-2026-13993: Incorrect security UI in WebAppInstalls.
- [514067416] Medium CVE-2026-13994: Inappropriate implementation in Credential Management.
- [514067524] Medium CVE-2026-13995: Insufficient validation of untrusted input in Autofill.
- [514068972] Medium CVE-2026-13996: Incorrect security UI in Permissions.
- [514069689] Medium CVE-2026-13997: Incorrect security UI in Extensions.
- [514070501] Medium CVE-2026-13998: Incorrect security UI in File Input.
- [514071697] Medium CVE-2026-13999: Inappropriate implementation in Extensions.
- [514461552] Medium CVE-2026-14000: Inappropriate implementation in XML.
- [514481943] Medium CVE-2026-14001: Inappropriate implementation in Network.
- [514489361] Medium CVE-2026-14002: Inappropriate implementation in Geolocation.
- [514503077] Medium CVE-2026-14003: Insufficient policy enforcement in Extensions.
- [514538751] Medium CVE-2026-14004: Inappropriate implementation in CSS.
- [514740273] Medium CVE-2026-14005: Use after free in Omnibox.
- [515423596] Medium CVE-2026-14006: Use after free in Navigation.
- [516425999] Medium CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy.
- [516781007] Medium CVE-2026-14008: Uninitialized Use in WebXR.
- [516819850] Medium CVE-2026-14009: Insufficient data validation in Passwords.
- [516924151] Medium CVE-2026-14010: Uninitialized Use in Codecs.
- [516944556] Medium CVE-2026-14011: Out of bounds read in SurfaceCapture.
- [517110749] Medium CVE-2026-14012: Side-channel information leakage in CSS.
- [517114175] Medium CVE-2026-14013: Inappropriate implementation in SVG.
- [517155893] Medium CVE-2026-14014: Inappropriate implementation in Paint.
- [517207235] Medium CVE-2026-14015: Inappropriate implementation in WebRTC.
- [517234388] Medium CVE-2026-14016: Insufficient policy enforcement in SVG.
- [517241992] Medium CVE-2026-14017: Inappropriate implementation in Navigation.
- [517350251] Medium CVE-2026-14018: Use after free in Updater.
- [517455455] Medium CVE-2026-14019: Inappropriate implementation in Passwords.
- [517598518] Medium CVE-2026-14020: Insufficient validation of untrusted input in WebXR.
- [517731924] Medium CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI.
- [517791835] Medium CVE-2026-14022: Insufficient validation of untrusted input in Network.
- [518063436] Medium CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI.
- [518245882] Medium CVE-2026-14024: Use after free in Ozone.
- [506482786] Low CVE-2026-14025: Use after free in Views.
- [507263861] Low CVE-2026-14026: Incorrect security UI in SplitView.
- [361375787] Low CVE-2026-14027: Use after free in SignIn.
- [401816601] Low CVE-2026-14028: Incorrect security UI in Chrome for iOS.
- [488762971] Low CVE-2026-14030: Incorrect security UI in SplitView.
- [495459838] Low CVE-2026-14031: Incorrect security UI in File Input.
- [495783474] Low CVE-2026-14032: Use after free in Bluetooth.
- [495848160] Low CVE-2026-14033: Insufficient policy enforcement in Media.
- [496368832] Low CVE-2026-14034: Inappropriate implementation in WebXR.
- [496371586] Low CVE-2026-14035: Insufficient policy enforcement in Bluetooth.
- [496411061] Low CVE-2026-14036: Insufficient policy enforcement in Bluetooth.
- [496522611] Low CVE-2026-14037: Insufficient policy enforcement in GPU.
- [497241148] Low CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page.
- [497358012] Low CVE-2026-14039: Insufficient policy enforcement in GetUserMedia.
- [497488593] Low CVE-2026-14040: Use after free in BrowserTag.
- [497544822] Low CVE-2026-14041: Insufficient policy enforcement in Serial.
- [497558336] Low CVE-2026-14042: Inappropriate implementation in Isolated Web Apps.
- [497632232] Low CVE-2026-14043: Use after free in GetUserMedia.
- [497670996] Low CVE-2026-14044: Use after free in ANGLE.
- [497723649] Low CVE-2026-14045: Insufficient validation of untrusted input in Network.
- [497959724] Low CVE-2026-14046: Inappropriate implementation in CustomTabs.
- [498864176] Low CVE-2026-14047: Insufficient policy enforcement in Extensions.
- [499189601] Low CVE-2026-14048: Use after free in Chromecast.
- [501659888] Low CVE-2026-14049: Inappropriate implementation in GPU.
- [501708647] Low CVE-2026-14050: Insufficient policy enforcement in Passwords.
- [501747804] Low CVE-2026-14051: Uninitialized Use in GamepadAPI.
- [501810874] Low CVE-2026-14052: Insufficient policy enforcement in FileSystem.
- [501836539] Low CVE-2026-14053: Insufficient policy enforcement in Extensions.
- [501851312] Low CVE-2026-14054: Insufficient policy enforcement in Network.
- [501857663] Low CVE-2026-14055: Insufficient validation of untrusted input in Device Trust.
- [501888426] Low CVE-2026-14056: Insufficient validation of untrusted input in Media.
- [502212647] Low CVE-2026-14057: Insufficient policy enforcement in FedCM.
- [502354038] Low CVE-2026-14058: Policy bypass in Parser.
- [502363986] Low CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets.
- [502372527] Low CVE-2026-14060: Insufficient validation of untrusted input in Chromoting.
- [502434484] Low CVE-2026-14061: Inappropriate implementation in Dawn.
- [502448128] Low CVE-2026-14062: Inappropriate implementation in Views.
- [502473563] Low CVE-2026-14063: Out of bounds memory access in Chromecast.
- [502714977] Low CVE-2026-14064: Use after free in PageInfo.
- [503617508] Low CVE-2026-14065: Insufficient validation of untrusted input in PageInfo.
- [503779807] Low CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS.
- [504069465] Low CVE-2026-14067: Use after free in Chrome for iOS.
- [504210171] Low CVE-2026-14068: Inappropriate implementation in Omnibox.
- [505136542] Low CVE-2026-14069: Integer overflow in WebNN.
- [505137978] Low CVE-2026-14070: Uninitialized Use in WebNN.
- [506143724] Low CVE-2026-14071: Side-channel information leakage in WebAudio.
- [507099867] Low CVE-2026-14072: Incorrect security UI in SplitView.
- [507237563] Low CVE-2026-14073: Insufficient policy enforcement in WebXR.
- [511743480] Low CVE-2026-14074: Side-channel information leakage in WebAuthentication.
- [511808800] Low CVE-2026-14075: Policy bypass in Chrome for iOS.
- [511815165] Low CVE-2026-14076: Policy bypass in Network.
- [511869411] Low CVE-2026-14077: Incorrect security UI in Select.
- [512953564] Low CVE-2026-14078: Policy bypass in WebRTC.
- [512971938] Low CVE-2026-14079: Policy bypass in Network.
- [512997517] Low CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher.
- [513030698] Low CVE-2026-14081: Insufficient policy enforcement in DevTools.
- [513049578] Low CVE-2026-14082: Race in Storage.
- [513128322] Low CVE-2026-14083: Insufficient validation of untrusted input in HTML.
- [513138148] Low CVE-2026-14084: Insufficient validation of untrusted input in Chromoting.
- [513155863] Low CVE-2026-14085: Side-channel information leakage in CSS.
- [513169718] Low CVE-2026-14086: Insufficient policy enforcement in HID.
- [513177237] Low CVE-2026-14087: Insufficient validation of untrusted input in WebNN.
- [513178869] Low CVE-2026-14088: Uninitialized Use in Canvas.
- [513188254] Low CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker.
- [513194241] Low CVE-2026-14090: Out of bounds read in CameraCapture.
- [513208773] Low CVE-2026-14091: Use after free in DevTools.
- [513212892] Low CVE-2026-14092: Insufficient policy enforcement in Privacy.
- [513240099] Low CVE-2026-14093: Use after free in Cast.
- [513264273] Low CVE-2026-14094: Use after free in Installer.
- [513271007] Low CVE-2026-14095: Insufficient validation of untrusted input in Browser.
- [513310821] Low CVE-2026-14096: Object lifecycle issue in Input.
- [513333529] Low CVE-2026-14097: Inappropriate implementation in WebAppInstalls.
- [513375767] Low CVE-2026-14098: Inappropriate implementation in CSS.
- [513382161] Low CVE-2026-14099: Use after free in Chrome for iOS.
- [513383891] Low CVE-2026-14100: Insufficient data validation in NetworkCache.
- [513454805] Low CVE-2026-14101: Insufficient policy enforcement in Sandbox.
- [513455047] Low CVE-2026-14102: Use after free in Passwords.
- [513465245] Low CVE-2026-14103: Use after free in SSL.
- [513484193] Low CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls.
- [513528117] Low CVE-2026-14105: Insufficient policy enforcement in Speech.
- [513532778] Low CVE-2026-14106: Insufficient validation of untrusted input in Text.
- [513544566] Low CVE-2026-14107: Use after free in Scheduling.
- [513689974] Low CVE-2026-14108: Use after free in PDFium.
- [513694957] Low CVE-2026-14109: Insufficient policy enforcement in Mojo.
- [513698452] Low CVE-2026-14110: Inappropriate implementation in DarkMode.
- [513710926] Low CVE-2026-14111: Use after free in WebProtect.
- [513713946] Low CVE-2026-14112: Inappropriate implementation in Enterprise.
- [513737335] Low CVE-2026-14113: Use after free in Updater.
- [513743129] Low CVE-2026-14114: Inappropriate implementation in WebAppInstalls.
- [513745699] Low CVE-2026-14115: Insufficient validation of untrusted input in Cast.
- [513747800] Low CVE-2026-14116: Insufficient validation of untrusted input in DevTools.
- [513751020] Low CVE-2026-14117: Insufficient validation of untrusted input in DevTools.
- [513772764] Low CVE-2026-14118: Insufficient data validation in DevTools.
- [513775483] Low CVE-2026-14119: Type Confusion in Bluetooth.
- [513777411] Low CVE-2026-14120: Inappropriate implementation in DevTools.
- [513789382] Low CVE-2026-14121: Use after free in Chromoting.
- [513824891] Low CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls.
- [513856644] Low CVE-2026-14123: Incorrect security UI in Chrome for iOS.
- [513867710] Low CVE-2026-14124: Inappropriate implementation in CredentialProvider.
- [513918431] Low CVE-2026-14125: Uninitialized Use in ANGLE.
- [513992796] Low CVE-2026-14126: Incorrect security UI in UI.
- [514009654] Low CVE-2026-14127: Inappropriate implementation in Printing.
- [514015836] Low CVE-2026-14128: Insufficient data validation in Chrome for iOS.
- [514018024] Low CVE-2026-14129: Incorrect security UI in PreviewTab.
- [514019522] Low CVE-2026-14130: Incorrect security UI in Omnibox.
- [514020982] Low CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls.
- [514039492] Low CVE-2026-14132: Inappropriate implementation in WebXR.
- [514039947] Low CVE-2026-14133: Race in History Embeddings.
- [514055973] Low CVE-2026-14134: Inappropriate implementation in Autofill.
- [514058566] Low CVE-2026-14135: Insufficient validation of untrusted input in Network.
- [514068611] Low CVE-2026-14136: Incorrect security UI in Chrome for iOS.
- [514070067] Low CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS.
- [514071775] Low CVE-2026-14138: Inappropriate implementation in WebAppInstalls.
- [514072495] Low CVE-2026-14139: Inappropriate implementation in TabStrip.
- [514072607] Low CVE-2026-14140: Insufficient validation of untrusted input in Input.
- [514072867] Low CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture.
- [514073460] Low CVE-2026-14142: Inappropriate implementation in Extensions.
- [514075028] Low CVE-2026-14143: Incorrect security UI in Passwords.
- [514079793] Low CVE-2026-14144: Incorrect security UI in Views.
- [514485825] Low CVE-2026-14145: Inappropriate implementation in CSS.
- [514550047] Low CVE-2026-14146: Inappropriate implementation in CSS.
- [514632767] Low CVE-2026-14147: Inappropriate implementation in CSS.
- [515426873] Low CVE-2026-14148: Type Confusion in CSS.
- [515427046] Low CVE-2026-14149: Use after free in Audio.
- [517376041] Low CVE-2026-14150: Insufficient validation of untrusted input in Speech.
- [517381770] Low CVE-2026-14151: Inappropriate implementation in AI.
- [517534944] Low CVE-2026-14152: Out of bounds write in ANGLE.
- [517684077] Low CVE-2026-14153: Inappropriate implementation in Glic.
- [517741170] Low CVE-2026-14154: Inappropriate implementation in DevTools.
- [518246925] Low CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI.
- [518247789] Low CVE-2026-14156: Policy bypass in StorageAccessAPI.
CVE-2026-13774
CVE-2026-13775
CVE-2026-13776
CVE-2026-13777
CVE-2026-13778
CVE-2026-13779
CVE-2026-13780
CVE-2026-13781
CVE-2026-13782
CVE-2026-13783
CVE-2026-13784
CVE-2026-13785
CVE-2026-13786
CVE-2026-13787
CVE-2026-13788
CVE-2026-13789
CVE-2026-13790
CVE-2026-13791
CVE-2026-13792
CVE-2026-13793
CVE-2026-13794
CVE-2026-13795
CVE-2026-13796
CVE-2026-13797
CVE-2026-13798
CVE-2026-13799
CVE-2026-13800
CVE-2026-13801
CVE-2026-13802
CVE-2026-13803
CVE-2026-13804
CVE-2026-13805
CVE-2026-13806
CVE-2026-13807
CVE-2026-13808
CVE-2026-13809
CVE-2026-13810
CVE-2026-13811
CVE-2026-13812
CVE-2026-13813
CVE-2026-13814
CVE-2026-13815
CVE-2026-13816
CVE-2026-13817
CVE-2026-13818
CVE-2026-13819
CVE-2026-13820
CVE-2026-13821
CVE-2026-13822
CVE-2026-13823
CVE-2026-13824
CVE-2026-13825
CVE-2026-13826
CVE-2026-13827
CVE-2026-13828
CVE-2026-13829
CVE-2026-13830
CVE-2026-13831
CVE-2026-13832
CVE-2026-13833
CVE-2026-13834
CVE-2026-13835
CVE-2026-13836
CVE-2026-13837
CVE-2026-13838
CVE-2026-13839
CVE-2026-13840
CVE-2026-13841
CVE-2026-13842
CVE-2026-13843
CVE-2026-13844
CVE-2026-13845
CVE-2026-13846
CVE-2026-13847
CVE-2026-13848
CVE-2026-13849
CVE-2026-13850
CVE-2026-13851
CVE-2026-13852
CVE-2026-13853
CVE-2026-13854
CVE-2026-13855
CVE-2026-13856
CVE-2026-13857
CVE-2026-13858
CVE-2026-13859
CVE-2026-13860
CVE-2026-13861
CVE-2026-13862
CVE-2026-13863
CVE-2026-13864
CVE-2026-13865
CVE-2026-13866
CVE-2026-13867
CVE-2026-13868
CVE-2026-13869
CVE-2026-13870
CVE-2026-13871
CVE-2026-13872
CVE-2026-13873
CVE-2026-13874
CVE-2026-13875
CVE-2026-13876
CVE-2026-13877
CVE-2026-13878
CVE-2026-13879
CVE-2026-13880
CVE-2026-13881
CVE-2026-13882
CVE-2026-13883
CVE-2026-13884
CVE-2026-13885
CVE-2026-13886
CVE-2026-13887
CVE-2026-13888
CVE-2026-13889
CVE-2026-13890
CVE-2026-13891
CVE-2026-13892
CVE-2026-13893
CVE-2026-13894
CVE-2026-13895
CVE-2026-13896
CVE-2026-13897
CVE-2026-13898
CVE-2026-13899
CVE-2026-13900
CVE-2026-13901
CVE-2026-13902
CVE-2026-13903
CVE-2026-13904
CVE-2026-13905
CVE-2026-13906
CVE-2026-13907
CVE-2026-13908
CVE-2026-13909
CVE-2026-13910
CVE-2026-13911
CVE-2026-13912
CVE-2026-13913
CVE-2026-13914
CVE-2026-13915
CVE-2026-13916
CVE-2026-13917
CVE-2026-13918
CVE-2026-13919
CVE-2026-13920
CVE-2026-13921
CVE-2026-13922
CVE-2026-13923
CVE-2026-13924
CVE-2026-13925
CVE-2026-13926
CVE-2026-13927
CVE-2026-13928
CVE-2026-13929
CVE-2026-13930
CVE-2026-13931
CVE-2026-13932
CVE-2026-13933
CVE-2026-13934
CVE-2026-13935
CVE-2026-13936
CVE-2026-13937
CVE-2026-13938
CVE-2026-13939
CVE-2026-13940
CVE-2026-13941
CVE-2026-13942
CVE-2026-13943
CVE-2026-13944
CVE-2026-13945
CVE-2026-13946
CVE-2026-13947
CVE-2026-13948
CVE-2026-13949
CVE-2026-13950
CVE-2026-13951
CVE-2026-13952
CVE-2026-13953
CVE-2026-13954
CVE-2026-13955
CVE-2026-13956
CVE-2026-13957
CVE-2026-13958
CVE-2026-13959
CVE-2026-13960
CVE-2026-13961
CVE-2026-13962
CVE-2026-13963
CVE-2026-13964
CVE-2026-13965
CVE-2026-13966
CVE-2026-13967
CVE-2026-13968
CVE-2026-13969
CVE-2026-13970
CVE-2026-13971
CVE-2026-13972
CVE-2026-13973
CVE-2026-13974
CVE-2026-13975
CVE-2026-13976
CVE-2026-13977
CVE-2026-13978
CVE-2026-13979
CVE-2026-13980
CVE-2026-13981
CVE-2026-13982
CVE-2026-13983
CVE-2026-13984
CVE-2026-13985
CVE-2026-13986
CVE-2026-13987
CVE-2026-13988
CVE-2026-13989
CVE-2026-13990
CVE-2026-13991
CVE-2026-13992
CVE-2026-13993
CVE-2026-13994
CVE-2026-13995
CVE-2026-13996
CVE-2026-13997
CVE-2026-13998
CVE-2026-13999
CVE-2026-14000
CVE-2026-14001
CVE-2026-14002
CVE-2026-14003
CVE-2026-14004
CVE-2026-14005
CVE-2026-14006
CVE-2026-14007
CVE-2026-14008
CVE-2026-14009
CVE-2026-14010
CVE-2026-14011
CVE-2026-14012
CVE-2026-14013
CVE-2026-14014
CVE-2026-14015
CVE-2026-14016
CVE-2026-14017
CVE-2026-14018
CVE-2026-14019
CVE-2026-14020
CVE-2026-14021
CVE-2026-14022
CVE-2026-14023
CVE-2026-14024
CVE-2026-14025
CVE-2026-14026
CVE-2026-14027
CVE-2026-14028
CVE-2026-14030
CVE-2026-14031
CVE-2026-14032
CVE-2026-14033
CVE-2026-14034
CVE-2026-14035
CVE-2026-14036
CVE-2026-14037
CVE-2026-14038
CVE-2026-14039
CVE-2026-14040
CVE-2026-14041
CVE-2026-14042
CVE-2026-14043
CVE-2026-14044
CVE-2026-14045
CVE-2026-14046
CVE-2026-14047
CVE-2026-14048
CVE-2026-14049
CVE-2026-14050
CVE-2026-14051
CVE-2026-14052
CVE-2026-14053
CVE-2026-14054
CVE-2026-14055
CVE-2026-14056
CVE-2026-14057
CVE-2026-14058
CVE-2026-14059
CVE-2026-14060
CVE-2026-14061
CVE-2026-14062
CVE-2026-14063
CVE-2026-14064
CVE-2026-14065
CVE-2026-14066
CVE-2026-14067
CVE-2026-14068
CVE-2026-14069
CVE-2026-14070
CVE-2026-14071
CVE-2026-14072
CVE-2026-14073
CVE-2026-14074
CVE-2026-14075
CVE-2026-14076
CVE-2026-14077
CVE-2026-14078
CVE-2026-14079
CVE-2026-14080
CVE-2026-14081
CVE-2026-14082
CVE-2026-14083
CVE-2026-14084
CVE-2026-14085
CVE-2026-14086
CVE-2026-14087
CVE-2026-14088
CVE-2026-14089
CVE-2026-14090
CVE-2026-14091
CVE-2026-14092
CVE-2026-14093
CVE-2026-14094
CVE-2026-14095
CVE-2026-14096
CVE-2026-14097
CVE-2026-14098
CVE-2026-14099
CVE-2026-14100
CVE-2026-14101
CVE-2026-14102
CVE-2026-14103
CVE-2026-14104
CVE-2026-14105
CVE-2026-14106
CVE-2026-14107
CVE-2026-14108
CVE-2026-14109
CVE-2026-14110
CVE-2026-14111
CVE-2026-14112
CVE-2026-14113
CVE-2026-14114
CVE-2026-14115
CVE-2026-14116
CVE-2026-14117
CVE-2026-14118
CVE-2026-14119
CVE-2026-14120
CVE-2026-14121
CVE-2026-14122
CVE-2026-14123
CVE-2026-14124
CVE-2026-14125
CVE-2026-14126
CVE-2026-14127
CVE-2026-14128
CVE-2026-14129
CVE-2026-14130
CVE-2026-14131
CVE-2026-14132
CVE-2026-14133
CVE-2026-14134
CVE-2026-14135
CVE-2026-14136
CVE-2026-14137
CVE-2026-14138
CVE-2026-14139
CVE-2026-14140
CVE-2026-14141
CVE-2026-14142
CVE-2026-14143
CVE-2026-14144
CVE-2026-14145
CVE-2026-14146
CVE-2026-14147
CVE-2026-14148
CVE-2026-14149
CVE-2026-14150
CVE-2026-14151
CVE-2026-14152
CVE-2026-14153
CVE-2026-14154
CVE-2026-14155
CVE-2026-14156
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html
2026-06-30
2026-07-02
openvpn -- multiple vulnerabilities
openvpn 2.7.5
openvpn-devel g20260701,2
The OpenVPN community project team reports:
[...] OpenVPN 2.7.5 [...] is a bugfix release fixing several security issues:
- Fix use-after-free bug in ack_write_buf(), triggerable by a well-timed sequence of control channel + authentication packets (CVE-2026-12996)
- Fix use-after-free bug in tls_wrap_reneg(), triggerable by suitable sequence of dynamic tls-crypt control-channel packets (CVE-2026-13117)
- Fix server crash on reception of suitably malformed auth-token, if --auth-gen-token external-auth is active (CVE-2026-13122)
- Fix memory-leak in tls-crypt-v2 client key handling that could lead to out-of-memory situations and subsequent server crashes (CVE-2026-12932)
- Fix possible 1-byte buffer overrun on NTLMv2 proxy responses. (CVE-2026-11771)
- Fix another memory leak on reception of suitable tls-crypt-v2 packets that could lead to an out of memory situation and server crash (CVE-2026-13698)
https://github.com/OpenVPN/openvpn/blob/v2.7.5/Changes.rst#overview-of-changes-in-275
CVE-2026-11771
CVE-2026-12932
CVE-2026-12996
CVE-2026-13117
CVE-2026-13122
CVE-2026-13698
https://community.openvpn.net/Downloads#openvpn-275-released-1-july-2026
2026-07-01
2026-07-01
FreeBSD -- Multiple vulnerabilities in iconv(3)
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
Several encoding modules, including HZ, UTF-7, VIQR, and ZW,
did not properly check the size of the caller-supplied output buffer
before writing converted characters. [CVE-2026-58081]
The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX
(6 bytes) for intermediate character output. Some ISO-2022 variants
can require up to 10 bytes per character, in which case conversions
can trigger a stack buffer overflow of up to four bytes.
[CVE-2026-58082]
Impact:
An application that uses iconv(3) to convert untrusted input
to or from one of the affected encodings may be vulnerable to buffer
overflows if it uses one of the affected encoding modules.
CVE-2026-58081
CVE-2026-58082
SA-26:49.iconv
2026-06-30
2026-07-01
FreeBSD-kernel -- Kernel stack disclosure in 32-bit compatibility support
FreeBSD-kernel
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
The compat32 kevent() handler translates a 64-bit kevent struct
into a stack- declared 32-bit struct. It did not first zero the
stack struct.
Impact:
An unprivileged user may observe a small amount of uninitialized
kernel stack data, which may contain sensitive information.
CVE-2026-49425
SA-26:48.compat32
2026-06-30
2026-07-01
FreeBSD -- Kernel stack disclosure in Linux compatibility layer
FreeBSD-kernel
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
The Linux waitid() implementation translates a FreeBSD siginfo_t
struct into a stack-declared Linux siginfo_t. It did not first
zero the stack struct.
Impact:
An unprivileged user may observe 104 bytes of uninitialized
kernel stack data, which may contain sensitive information.
CVE-2026-49424
SA-26:47.linux
2026-06-30
2026-07-01
FreeBSD -- Remote DOS via uninitialized memory access in KTLS receive
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
When building the iovec array for a received TLS 1.2 CBC record,
ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every
mbuf in the chain, including mbufs that were skipped because they
contained only TLS header bytes. This left uninitialized entries
in the iovec array. The iovec array was allocated without zeroing.
Impact:
A remote TLS peer can cause the kernel to read from uninitialized
iovec entries during HMAC computation, resulting in a kernel panic.
The peer must be able to control TCP segmentation such that the
first mbuf of a CBC record contains only the 5-byte TLS record
header.
CVE-2026-49423
SA-26:46.ktls
2026-06-30
2026-07-01
FreeBSD -- Incorrect audit records for ptrace(2) syscall requests
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
When auditing a system call executed via ptrace(PT_SC_REMOTE),
the kernel passed the return value of an internal setup function
to AUDIT_SYSCALL_EXIT() rather than the actual result of the executed
system call. As a result, committed audit records for system calls
which returned an error do not reflect the true outcome of the
operation. That is, they indicate that the operation succeeded
when it in fact failed.
Impact:
Audit records for system calls executed via ptrace(PT_SC_REMOTE)
may show an incorrect error status. An attacker with the ability
to debug a process could use this to produce misleading audit trails,
potentially undermining audit-based Intrusion Detection Systems
(IDS).
CVE-2026-49426
SA-26:45.audit
2026-06-30
2026-07-01
FreeBSD -- Multiple vulnerabilities in POSIX largepage objects
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
Pages belonging to largepage shared memory objects were not
explicitly wired. When sendfile(2) transmitted such an object with
the SF_NOCACHE flag, it freed the underlying pages after transmission
even though existing mappings still referred to them. [CVE-2026-49427]
Separately, certain system calls, such open(2) with the O_TRUNC
flag set, and fspacectl(2), could incorrectly free memory in largepage
objects. These operations are not permitted on largepage objects,
but the implementation did not verify this. [CVE-2026-49428]
Impact:
An unprivileged local user can abuse the bug to access freed
kernel memory. This can be exploited to escalate privileges.
CVE-2026-49427
CVE-2026-49428
SA-26:44.posixshm
2026-06-30
2026-07-01
FreeBSD -- Use-after-free in TCP RACK stack option handler
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
The RACK setsockopt(2) handler drops the connection lock in
order to copy option data from userspace, then reacquires the lock.
After reacquiring, it verifies that the TCP stack had not been
switched away, but did not reload its pointer to the stack's
per-connection control block. If userspace switches stacks twice
during this window, the check will succeed but the saved pointer
will refer to freed memory.
Impact:
The bug may be exploitable by an unprivileged local user to
escalate privileges.
CVE-2026-49422
SA-26:43.tcp
2026-06-30
2026-07-01
FreeBSD -- unlinkat(2) ignores AT_RESOLVE_BENEATH flag
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
The kernel function that implements unlinkat(2) and funlinkat(2)
validated the AT_RESOLVE_BENEATH flag but failed to pass it through
to the underlying path lookup. The flag was silently dropped, so
path resolution was not actually restricted.
Impact:
A process that uses AT_RESOLVE_BENEATH with unlinkat(2) or
funlinkat(2) to confine path resolution can in fact resolve paths
above the starting directory. A caller relying on this flag for
path containment may delete files outside the intended directory
tree.
CVE-2026-49421
SA-26:42.unlinkat
2026-06-30
2026-07-01
FreeBSD -- Buffer overflow in libalias RTSP handler
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
The RTSP handler in libalias rewrote outgoing packets into a
fixed-length stack buffer without checking whether the rewritten
data fit in the buffer, or whether the result fit back in the
original packet.
Impact:
A host sending crafted RTSP traffic from inside a NAT gateway
using libalias can overflow a stack buffer, potentially achieving
remote code execution in the kernel (when using ipfw(4) NAT) or in
the natd(8) process (which generally runs as the root user).
CVE-2026-49420
SA-26:41.libalias
2026-06-30
2026-07-01
FreeBSD -- Multiple vulnerabilities in OpenZFS
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8),
truncated a 64-bit output buffer size to a 32-bit integer for the
kernel allocation, but used the original 64-bit size as the buffer
limit when writing records.
The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly
truncated a 64-bit payload size to a 32-bit integer for allocation,
then used the original 64-bit size as the length for a byteswap
operation.
The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated
the calling user such that an unprivileged user is able to set
metadata on a dataset indicating that the dataset has received
properties from a zfs-recv(8) stream.
Impact:
A local user with the "userused" delegated ZFS permission can
trigger a kernel heap overflow via the ZFS_IOC_USERSPACE_MANY ioctl,
potentially escalating privileges. [CVE-2026-49429]
A local user with the "receive" delegated ZFS permission can trigger
kernel memory corruption via ZFS_IOC_RECV_NEW by sending a crafted
receive stream in heal mode. [CVE-2026-49430]
Any local user can set the internal ZFS metadata flag "$hasrecvd"
on datasets via ZFS_IOC_SET_PROP. [CVE-2026-49431]
CVE-2026-49429
CVE-2026-49430
CVE-2026-49431
SA-26:40.zfs
2026-06-30
2026-07-01
FreeBSD -- Local privilege escalation via execve(2) TOCTOU race
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
During execve(2) of a SUID binary, the new virtual address space
is installed before the process credentials are updated. During
this window, a process running as the same user can access the
target process's memory via procfs or linprocfs, because the kernel's
debugging permission check still saw the original credentials.
Impact:
An unprivileged local user can exploit this race to modify the
address space of a SUID binary before its credentials are elevated,
potentially gaining full control of the affected system.
CVE-2026-49415
SA-26:39.execve
2026-06-30
2026-07-01
FreeBSD -- Jail reference count underflow
FreeBSD-kernel
15.115.1_1
15.015.0_11
Problem Description:
When the JAIL_AT_DESC flag is specified, kern_jail_set() and
kern_jail_get() released the reference to the caller's current
prison before looking up the jail descriptor. If the descriptor
lookup failed, error-handling paths released the same reference a
second time.
Impact:
An unprivileged local user can trigger a prison reference count
underflow, which may cause the prison structure to be freed while
still in use. When this is done on the jail host, the bug will
generally result in an immediate panic. However, if the user is
running in a jail, then it may be possible to exploit the bug to
elevate privileges.
CVE-2026-49419
SA-26:38.jail
2026-06-30
2026-07-01
FreeBSD -- Use-after-free in device pager page list
FreeBSD-kernel
15.115.1_1
15.015.0_11
14.414.4_7
14.314.3_16
Problem Description:
When msync(MS_INVALIDATE) is called on a mapping of an unmanaged
device object, the physical pages in the mapping range are marked
invalid but remain in the pager's page list. A subsequent page
fault will cause the fault handler to re-insert the page into the
object's list. This corrupts the list, and on object destruction
the page is freed twice.
Impact:
An unprivileged local user with access to a device that provides
memory-mapped I/O can trigger a use-after-free in the kernel, though
this is limited to a pool of objects ("fictitious pages") that are
never recycled for a different purpose. It may be possible to
exploit this to escalate privileges.
CVE-2026-49418
SA-26:37.vm
2026-06-30
2026-07-01
icinga2 -- Improper access control for JSON-RPC update certificate messages
icinga2
2.16.2
The Icinga team reports:
The code handling certificate update JSON-RPC messages was
flawed and did not properly validate the sender of the message,
allowing an unauthenticated attacker that can connect to Icinga
2 to update both the own certificate as well as the trusted CA
certificate. Updating the trusted CA allows an attacker to
impersonate a trusted node, allowing them to take control over
the node.
Any Icinga 2 instance that is accessible to an attacker over
the network is affected.
https://github.com/Icinga/icinga2/security/advisories/GHSA-vj39-ww8j-vvx5
2026-06-29
2026-06-30
PostgresSQL JDBC -- Silent channel-binding authentication downgrade via unsupported certificate algorithms
postgresql-jdbc
47.7.12
47.7.4
PostgreSQL project reports:
channelBinding=require connections can be silently
downgraded from SCRAM-SHA-256-PLUS (with channel
binding) to plain SCRAM-SHA-256 (without it), losing the
man-in-the-middle protection the setting is meant to
guarantee. An attacker who can intercept the TLS
connection triggers the downgrade with a certificate
whose signature algorithm has no tls-server-end-point
channel-binding hash. Examples are Ed25519, Ed448, and
post-quantum algorithms.
CVE-2026-54291
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-j92g-9f8w-j867
2026-06-30
2026-06-30
chromium -- security fixes
chromium
149.0.7827.200
ungoogled-chromium
149.0.7827.200
Chrome Releases reports:
This update includes 3 security fixes:
- [513138301] High CVE-2026-13281: Integer overflow in Mojo. Reported by Google on 2026-05-14
- [517522620] High CVE-2026-13282: Use after free in Payments. Reported by Google on 2026-05-28
- [522561151] High CVE-2026-13283: Use after free in AdFilter. Reported by Google on 2026-06-11
CVE-2026-13281
CVE-2026-13282
CVE-2026-13283
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html
2026-06-25
2026-06-30
NSD -- vulnerabilities
nsd
4.14.3
NLnet Labs reports:
CVE-2026-12244: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes
Even though the data is from a configured primary inside NSD's trust boundary, we do consider the risk significant enough for multi-tenant secondary DNS deployments, given the potential severity of the attack.
CVE-2026-12245: An attacker can keep all children in a crash-restart loop denying DoT service.
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
Any client with access to the DoT port (853) can trigger this. Even though a new server process will be immediately reforked to replace the crashed one, an attacker can keep all children in a crash-restart loop denying DoT service.
CVE-2026-12246: The RR type APL rdata address, if too large, causes out of bounds write on the
stack, when the zonefile is written out.
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
Even though the data is from a configured primary inside NSD's trust boundary, we do consider the risk significant enough for multi-tenant secondary DNS deployments, where a primary could introduce the rogue APL with the secondary not noticing or only after the fact.
CVE-2026-12490: Secondaries authenticated by a client certificate to transfer a zone over TLS,
can bypass verification by transferring over TCP.
When a "provide-xfr" is given with a "tls-auth-name", a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular "tls-port" (and not the "tls-auth-port") or over over TCP over the regular port, when the other conditions of the "provide-xfr" rule match.
The transfer security restrictions for client certificates can be bypassed completely if the attacker can match the other access control conditions, and the "tls-auth-xfr-only" option is not explicitly set to "yes" (which it by default is not)
Thanks to people below for reporting and disclosing these vulnerabilities:
- Qifan Zhang from Palo Alto Networks
- Haruki Oyama from Waseda University
- zhangph
CVE-2026-12244
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12244.txt
CVE-2026-12245
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12245.txt
CVE-2026-12246
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12246.txt
CVE-2026-12490
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt
2026-06-25
2026-06-29
rclone -- Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation
rclone
1.46.01.74.3
https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv reports:
Rclone is a command-line program to sync files and directories to
and from different cloud storage providers.
From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD
requests to paths of the form: /[remote:path]/object.
The remote
value is parsed from the URL and passed to normal backend initialization.
Inline remote configuration can set backend options that execute
local commands during initialization.
As a result, a single
unauthenticated GET or HEAD request can execute a command as the
rclone process user.
Thanks to Nick Craig-Wood for reporting this vulnerability.
CVE-2026-49980
https://cveawg.mitre.org/api/cve/CVE-2026-49980
https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv
2026-06-24
2026-06-29
PowerDNS -- vulnerabilities
powerdns
5.1.2
PowerDNS Team reports:
- CVE-2026-33257: Insufficient input validation of internal webserver
- CVE-2026-33260: Insufficient input validation of internal webserver
- CVE-2026-33608: Incomplete domain name sanitization during Bind autosecondary zone transfer
- CVE-2026-33609: LDAP DN injection
- CVE-2026-33610: Possible file descriptor exhaustion in forward-dnsupdate
- CVE-2026-33611: Insufficient validation of HTTPS and SVCB records
Thanks to people below for reporting these vulnerabilities:
- Vitaly Simonovich
- Cavid
- Tibs
- ylwango613
- CVE-2026-42005: Insufficient input validation of internal web server
Thanks to ilya rozentsvaig for reporting this vulnerability.
CVE-2026-33257
CVE-2026-33260
CVE-2026-33608
CVE-2026-33609
CVE-2026-33610
CVE-2026-33611
CVE-2026-42005
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html
2026-02-16
2026-06-29
powerdns-recursor -- vulnerabilities
powerdns-recursor
5.4.3
PowerDNS Team reports:
- CVE-2026-3361: ZoneToCache can poison the cache
- CVE-2026-40012: Information about ECS zero scoped answers might leak to clients that use a specific ECS
- CVE-2026-42005: Unbounded resource consumption in internal webserver
- CVE-2026-42387: Insufficient input validation in ZoneToCache
- CVE-2026-42388: Missing input validation for catalog zones
- CVE-2026-42389: Reject more queries with invalid header values
- CVE-2026-42390: ZONEMD validation can be bypassed
- CVE-2026-52690: Spoofed answers can mark an authoritative non-EDNS capable
Thanks to people below for reporting these vulnerabilities.
- Danial Mahadzir
- ilya rozentsvaig
- Vitaly Simonovich
- ylwango613
- nurmukhammyed
- Mehtab Zafar
CVE-2026-3361
CVE-2026-40012
CVE-2026-42005
CVE-2026-42387
CVE-2026-42388
CVE-2026-42389
CVE-2026-42390
CVE-2026-52690
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-08.html
2026-04-04
2026-06-29
DNSdist -- vulnerabilities
dnsdist
2.0.7
The DNSdist team reports:
- CVE-2026-40011: Prometheus denial of service via crafted DNS queries
- CVE-2026-42004: EDNS options smuggling
- CVE-2026-42005: Insufficient input validation of internal web server
- CVE-2026-40208: Denial of service via DoH3 queries
- CVE-2026-40209: Denial of service via IXFR queries
- CVE-2026-40210: Out-of-bounds read in SetMacAddrAction
- CVE-2026-40211: Denial of service via crafted DoH3 queries
Thanks to people below for reporting these vulnerabilities.
- Haruki Oyama (Waseda University)
- Vitaly Simonovich
- ilya rozentsvaig
- ylwango613
- Qifan Zhang (Palo Alto Networks)
- Mehtab Zafar
CVE-2026-40011
CVE-2026-42004
CVE-2026-42005
CVE-2026-40208
CVE-2026-40209
CVE-2026-40210
CVE-2026-40211
https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-09.html
2026-06-25
2026-06-29
gstreamer1 -- multiple vulnerabilities
gstreamer1-libav
gstreamer1-plugins
gstreamer1-plugins-bad
gstreamer1-plugins-good
gstreamer1-plugins-ugly
1.28.4
The GStreamer project reports:
Multiple security issues were identified and fixed in the GStreamer framework.
- GStreamer-SA-2026-0030: Missing bounds checks in RTCP SDES packet parsing
- GStreamer-SA-2026-0031: Integer overflow and truncation in MXF demuxer
- GStreamer-SA-2026-0032: Out-of-bounds read and write in XMP tag parser
- GStreamer-SA-2026-0033: Out-of-bounds read and modification of const data in ID3v2 parser
- GStreamer-SA-2026-0034: Division by zero in mDVDsub subtitle parser
- GStreamer-SA-2026-0035: Integer overflow in WavPack decoder
- GStreamer-SA-2026-0036: Out-of-bounds read in SBC audio parser header parsing
- GStreamer-SA-2026-0037: Heap corruption in gst-libav AV protocol pipe
- GStreamer-SA-2026-0038: Memory leak and NULL pointer dereference in gst-libav demuxer
- GStreamer-SA-2026-0039: Assertion in AV1 parser tile data parsing
- GStreamer-SA-2026-0040: Out-of-bounds read in VA JPEG decoder segment parsing
- GStreamer-SA-2026-0042: Out-of-bounds reads and integer overflows in RealMedia demuxer
- GStreamer-SA-2026-0043: Out-of-bounds read and write in RFB source
- GStreamer-SA-2026-0045: Out-of-bounds reads in PCAP parser due to missing bounds checks
- GStreamer-SA-2026-0046: Integer overflow in VMNC decoder cursor payload size calculation
- GStreamer-SA-2026-0047: One-byte out-of-bounds read in H.264 NAL unit parser
- GStreamer-SA-2026-0048: Out-of-bounds read in H.266 parser VUI aspect ratio parsing
CVE-2026-12891
CVE-2026-12892
CVE-2026-12893
CVE-2026-52717
CVE-2026-52718
CVE-2026-52719
CVE-2026-52720
CVE-2026-52721
CVE-2026-52722
CVE-2026-53703
CVE-2026-53704
CVE-2026-53705
https://gstreamer.freedesktop.org/security/sa-2026-0030.html
https://gstreamer.freedesktop.org/security/sa-2026-0031.html
https://gstreamer.freedesktop.org/security/sa-2026-0032.html
https://gstreamer.freedesktop.org/security/sa-2026-0033.html
https://gstreamer.freedesktop.org/security/sa-2026-0034.html
https://gstreamer.freedesktop.org/security/sa-2026-0035.html
https://gstreamer.freedesktop.org/security/sa-2026-0036.html
https://gstreamer.freedesktop.org/security/sa-2026-0037.html
https://gstreamer.freedesktop.org/security/sa-2026-0038.html
https://gstreamer.freedesktop.org/security/sa-2026-0039.html
https://gstreamer.freedesktop.org/security/sa-2026-0040.html
https://gstreamer.freedesktop.org/security/sa-2026-0042.html
https://gstreamer.freedesktop.org/security/sa-2026-0043.html
https://gstreamer.freedesktop.org/security/sa-2026-0045.html
https://gstreamer.freedesktop.org/security/sa-2026-0046.html
https://gstreamer.freedesktop.org/security/sa-2026-0047.html
https://gstreamer.freedesktop.org/security/sa-2026-0048.html
2026-06-12
2026-06-29
Multiple vulnerability found in Expat
expat
linux-c7-expat
linux-rl9-expat
2.8.2
Expat 2.8.2 was released yesterday. The key motivation for cutting a release and doing so now was
getting security and non-security bugsfixes out to users. On the security side,
13 vulnerabilities have been fixed:
- CVE-2026-50219: missing control flow integrity checks
- CVE-2026-56131: missing control flow integrity checks
- CVE-2026-56132: out-of-bounds write
- CVE-2026-56403: integer overflow
- CVE-2026-56404: integer overflow
- CVE-2026-56405: integer overflow
- CVE-2026-56406: integer overflow
- CVE-2026-56407: integer overflow
- CVE-2026-56408: integer overflow
- CVE-2026-56409: integer overflow
- CVE-2026-56410: integer overflow
- CVE-2026-56411: integer overflow
- CVE-2026-56412: missing control flow integrity checks
CVE-2026-50219
CVE-2026-56131
CVE-2026-56132
CVE-2026-56403
CVE-2026-56404
CVE-2026-56405
CVE-2026-56406
CVE-2026-56407
CVE-2026-56408
CVE-2026-56409
CVE-2026-56410
CVE-2026-56411
CVE-2026-56412
https://nvd.nist.gov/vuln/detail/CVE-2026-50219
https://nvd.nist.gov/vuln/detail/CVE-2026-56131
https://nvd.nist.gov/vuln/detail/CVE-2026-56132
https://nvd.nist.gov/vuln/detail/CVE-2026-56403
https://nvd.nist.gov/vuln/detail/CVE-2026-56404
https://nvd.nist.gov/vuln/detail/CVE-2026-56405
https://nvd.nist.gov/vuln/detail/CVE-2026-56406
https://nvd.nist.gov/vuln/detail/CVE-2026-56407
https://nvd.nist.gov/vuln/detail/CVE-2026-56408
https://nvd.nist.gov/vuln/detail/CVE-2026-56409
https://nvd.nist.gov/vuln/detail/CVE-2026-56410
https://nvd.nist.gov/vuln/detail/CVE-2026-56411
https://nvd.nist.gov/vuln/detail/CVE-2026-56412
2026-06-25
2026-06-28
gitea -- multiple vulnerabilities
gitea
1.26.4
The Gitea team reports:
- CVE-2026-27783: incorrect read permission check
- CVE-2026-25714: public-only token filtering bypass
- CVE-2026-20706: missing token scope checking
- CVE-2026-27771: unauthenticated access to private container images
- CVE-2026-28744: git smart HTTP request scope bug
- CVE-2026-28699: basic auth bug
- CVE-2026-26231: maintainer edit permission escalation
- CVE-2026-20896: reverse proxy trusted proxies misconfiguration allowing user impersonation
- CVE-2026-22874: incomplete SSRF protection in webhooks and migrations
- CVE-2026-27775: branch write permission cache escalation
- CVE-2026-27761: RSS/Atom feed token scope not enforced
- CVE-2026-25038: private organization labels leaked to non-members
- CVE-2026-24451: fork sync allowed after base repo access revoked
- CVE-2026-20779: TOTP passcode reuse across login surfaces (TOCTOU race)
- CVE-2026-28740: cross-repository LFS object reuse without Code-unit access
- OAuth2 callback could auto-reactivate disabled users
CVE-2026-27783
CVE-2026-25714
CVE-2026-20706
CVE-2026-27771
CVE-2026-28744
CVE-2026-28699
CVE-2026-26231
CVE-2026-20896
CVE-2026-22874
CVE-2026-27775
CVE-2026-27761
CVE-2026-25038
CVE-2026-24451
CVE-2026-20779
CVE-2026-28740
https://blog.gitea.com/release-of-1.26.2/
https://blog.gitea.com/release-of-1.26.3-and-1.26.4/
2026-05-20
2026-06-28
ffmpeg -- Out-of-bounds write
ffmpeg
8.1.2,1
ffmpeg4
4.4.7
ffmpeg6
6.1.6
https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159 reports:
An out-of-bounds write vulnerability in FFmpeg's libavcodec library,
specifically in the MagicYUV decoder, allows denial-of-service and,
in some cases, can be exploited for remote code execution. This
vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
CVE-2026-8461
https://nvd.nist.gov/vuln/detail/CVE-2026-8461
https://github.com/advisories/GHSA-qff7-4q6c-m8h6
2026-06-18
2026-06-25
Gitlab -- Vulnerabilities
gitlab-ce
gitlab-ee
19.1.019.1.1
19.0.019.0.3
8.3.018.11.6
Gitlab reports:
Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE
Cross-site Scripting issue in Web IDE workbench asset handler impacts GitLab CE/EE
Information Disclosure issue in Duo Workflows impacts GitLab EE
Authorization Bypass issue in Virtual Registry Cleanup Policy API impacts GitLab EE
Improper Authorization issue in Rapid Diffs impacts GitLab CE/EE
Incorrect Authorization issue in DAST scanner and site profile management impacts GitLab EE
Insufficient Filtering issue in CI/CD API impacts GitLab CE/EE
Improper Input Validation issue in Snippets impacts GitLab CE/EE
Incorrect Authorization issue in Maven Package Registry impacts GitLab CE/EE
Improper Access Control issue in group packages API impacts GitLab CE/EE
Improper Access Control issue in Protected Environments API impacts GitLab EE
Missing Authorization issue in Security Dashboard impacts GitLab EE
Server-Side Request Forgery issue in Repository Mirroring impacts GitLab CE/EE
CVE-2026-10086
CVE-2026-10712
CVE-2026-12053
CVE-2026-5309
CVE-2026-2238
CVE-2026-11379
CVE-2026-8330
CVE-2026-1606
CVE-2026-5952
CVE-2026-5796
CVE-2026-0934
CVE-2026-3176
CVE-2026-12635
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/
2026-06-24
2026-06-26
go-git -- DoS vulnerability
go-git
5.11.0
The go-git project reports:
See link for details.
https://github.com/go-git/go-git/security/advisories/GHSA-mw99-9chc-xw7r
2023-12-24
2026-06-24
ldns -- CWE-346 Origin Validation Error
ldns
1.2.01.9.1
https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt reports:
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used
in applications as (stub) resolver over UDP, lacks matching the
query destination address and port with the response source address
and port. Furthermore not the query ID, neither the question of
the query is matched with that of the response. This makes
applications, that use ldns for (stub) resolver functionality over
UDP, vulnerable for off-path poisoning attacks. The drill tool,
which is shipped with ldns, suffers from this vulnerability.
We would like to thank Pablo Ruiz from codecome.ai for finding and reporting
this vulnerability.
CVE-2026-10846
https://cveawg.mitre.org/api/cve/CVE-2026-10846
2026-06-10
2026-06-23
podman -- files outside build context may be included via malicious Git repo or tar archive
podman
5.8.3
The Podman developers report:
Building a Dockerfile using an ADD or COPY instruction accessing
a malicious Git repository or tar archive could cause files outside
the build context directory to be included in the build context or
copied into the build.
CVE-2026-44517
https://github.com/podman-container-tools/podman/releases/tag/v5.8.3
https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
2026-06-22
2026-06-22
nginx -- multiple vulnerabilities
nginx
1.30.3,3
The nginx developers report:
A heap memory buffer overflow vulnerability when using the
"ignore_invalid_headers off;" and "large_client_header_buffers"
directives with large configured values while proxying a specially
crafted request to an HTTP/2 or gRPC backend may allow memory
corruption or a segmentation fault in a worker process
(CVE-2026-42055).
A heap memory buffer overread vulnerability while handling a
specially crafted response with decoding from UTF-8 via the
"charset_map" directive may allow limited disclosure of worker
process memory or a segmentation fault in a worker process
(CVE-2026-48142).
CVE-2026-42055
CVE-2026-48142
https://nginx.org/en/CHANGES
2026-06-17
2026-06-17
nginx -- multiple vulnerabilities
nginx-devel
1.31.2
The nginx developers report:
A use-after-free vulnerability when using HTTP/3 and processing a
specially crafted QUIC session may allow memory corruption or a
segmentation fault in a worker process (CVE-2026-42530).
A heap memory buffer overflow vulnerability when using the
"ignore_invalid_headers off;" and "large_client_header_buffers"
directives with large configured values while proxying a specially
crafted request to an HTTP/2 or gRPC backend may allow memory
corruption or a segmentation fault in a worker process
(CVE-2026-42055).
A heap memory buffer overread vulnerability while handling a
specially crafted response with decoding from UTF-8 via the
"charset_map" directive may allow limited disclosure of worker
process memory or a segmentation fault in a worker process
(CVE-2026-48142).
CVE-2026-42530
CVE-2026-42055
CVE-2026-48142
https://nginx.org/en/CHANGES
2026-06-17
2026-06-17
jenkins -- multiple vulnerabilities
jenkins
2.568
jenkins-lts
2.555.3
Jenkins Security Advisory 2026-06-10:
- SECURITY-3707 / CVE-2026-53435: Deserialization vulnerability
(High)
- SECURITY-3711+3755 / CVE-2026-53436, CVE-2026-53437: Open
redirect vulnerability (Medium)
- SECURITY-3712 / CVE-2026-53438: Missing permission check allows
canceling queue items (Medium)
- SECURITY-3713 / CVE-2026-53439: Missing permission checks allow
obtaining limited user profile information (Medium)
- SECURITY-3721 / CVE-2026-53440: Open redirect vulnerability in
"Delegate to servlet container" security realm (Medium)
- SECURITY-3731 / CVE-2026-53441: Stored XSS vulnerability in
node offline cause description (High)
- SECURITY-3744 / CVE-2026-53442: Plaintext secrets persisted and
served by config.xml endpoints (Medium)
CVE-2026-53435
CVE-2026-53436
CVE-2026-53437
CVE-2026-53438
CVE-2026-53439
CVE-2026-53440
CVE-2026-53441
CVE-2026-53442
https://www.jenkins.io/security/advisory/2026-06-10/
2026-06-10
2026-06-17
Routinator -- CWE-755 Improper Handling of Exceptional Conditions
routinator
0.15.2
https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49235.txt reports:
When Routinator encounters a file via RRDP using a specifically
crafted Document Type Definition, Routinator crashes.
Thanks to X41 D-Sec GmbH for reporting the vulnerability.
CVE-2026-49235
https://cveawg.mitre.org/api/cve/CVE-2026-49235
2026-06-08
2026-06-17
Routinator -- CWE-20 Improper Input Validation
routinator
0.15.2
https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49234.txt reports:
When sending a specifically crafted non-UTF-8 string as select-asn
query parameter to the /api/v1/origins endpoint, Routinator crashes.
This only affects users who allow API access from untrusted networks.
Thanks to X41 D-Sec GmbH for reporting the vulnerability.
CVE-2026-49234
https://cveawg.mitre.org/api/cve/CVE-2026-49234
2026-06-08
2026-06-17
Routinator -- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
routinator
0.15.2
https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt reports:
Routinator does not properly check the module component of rsync
URIs, which are used to create the file system paths for the
Routinator cache. This allows for path traversal by having a module
name containing .., potentially providing an attacker access to the
entire Routinator rsync cache.
Thanks to X41 D-Sec GmbH for reporting the vulnerability.
CVE-2026-49233
https://cveawg.mitre.org/api/cve/CVE-2026-49233
2026-06-08
2026-06-17
Routinator -- CWE-755 Improper Handling of Exceptional Conditions
routinator
0.15.2
https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49232.txt reports:
Routinator exits on any error when accepting incoming HTTP or RTR
connections, including ones it can recover from such as running out
of file descriptors. This condition can be triggered maliciously
by an attacker by opening a large number of connections to the HTTP
or RTR server.
This only affects users that make their HTTP or RTR server available
to untrusted networks.
Thanks to X41 D-Sec GmbH for reporting the vulnerability.
CVE-2026-49232
https://cveawg.mitre.org/api/cve/CVE-2026-49232
2026-06-08
2026-06-17
chromium -- security fixes
chromium
149.0.7827.155
ungoogled-chromium
149.0.7827.155
Chrome Releases reports:
This update includes 33 security fixes:
- [516496659] Critical CVE-2026-12437: Use after free in WebShare.
- [516947912] Critical CVE-2026-12438: Inappropriate implementation in WebView.
- [519728275] Critical CVE-2026-12439: Use after free in Digital Credentials.
- [519731619] Critical CVE-2026-12440: Use after free in DigitalCredentials.
- [520157118] Critical CVE-2026-12441: Use after free in File Input.
- [521950423] Critical CVE-2026-12442: Use after free in Passwords.
- [522566295] Critical CVE-2026-12443: Use after free in Web Authentication.
- [513160088] High CVE-2026-12444: Out of bounds read in Chromoting.
- [513199795] High CVE-2026-12445: Use after free in Extensions.
- [513313107] High CVE-2026-12446: Insufficient data validation in Passwords.
- [513405023] High CVE-2026-12447: Heap buffer overflow in WebRTC.
- [513458233] High CVE-2026-12448: Inappropriate implementation in WebView.
- [513480539] High CVE-2026-12449: Use after free in Chromoting.
- [514531776] High CVE-2026-12450: Inappropriate implementation in Media.
- [514741076] High CVE-2026-12451: Use after free in DigitalCredentials.
- [515462244] High CVE-2026-12452: Use after free in Downloads.
- [516448843] High CVE-2026-12453: Insufficient validation of untrusted input in Input.
- [516926968] High CVE-2026-12454: Race in Safe Browsing.
- [517069848] High CVE-2026-12455: Use after free in Tab Strip.
- [517124587] High CVE-2026-12456: Insufficient validation of untrusted input in Extensions.
- [517153117] High CVE-2026-12457: Insufficient data validation in Extensions.
- [517258337] High CVE-2026-12458: Incorrect security UI in Passwords.
- [517406035] High CVE-2026-12459: Inappropriate implementation in Serial.
- [517484284] High CVE-2026-12460: Insufficient policy enforcement in File System Access.
- [517727318] High CVE-2026-12461: Out of bounds read in WebRTC.
- [517916024] High CVE-2026-12462: Use after free in Media.
- [518042749] High CVE-2026-12463: Inappropriate implementation in Views.
- [519358344] High CVE-2026-12464: Use after free in Browser.
- [520189702] High CVE-2026-12465: Insufficient validation of untrusted input in Metrics.
- [520199394] High CVE-2026-12466: Heap buffer overflow in WebRTC.
- [520202726] High CVE-2026-12467: Use after free in Extensions.
- [521485244] High CVE-2026-12468: Inappropriate implementation in Updater.
- [521618871] High CVE-2026-12469: Uninitialized Use in GPU.
CVE-2026-12437
CVE-2026-12438
CVE-2026-12439
CVE-2026-12440
CVE-2026-12441
CVE-2026-12442
CVE-2026-12443
CVE-2026-12444
CVE-2026-12445
CVE-2026-12446
CVE-2026-12447
CVE-2026-12448
CVE-2026-12449
CVE-2026-12450
CVE-2026-12451
CVE-2026-12452
CVE-2026-12453
CVE-2026-12454
CVE-2026-12455
CVE-2026-12456
CVE-2026-12457
CVE-2026-12458
CVE-2026-12459
CVE-2026-12460
CVE-2026-12461
CVE-2026-12462
CVE-2026-12463
CVE-2026-12464
CVE-2026-12465
CVE-2026-12466
CVE-2026-12467
CVE-2026-12468
CVE-2026-12469
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html
2026-06-11
2026-06-15
mail/mailpit -- Incomplete SSRF protection in Link Check API via uncovered IPv6 forms
mailpit
1.30.2
Mailpit authorreports:
The tools.IsInternalIP deny-list relies on Go's stdlib
classification helpers (IsLoopback, IsPrivate,
IsLinkLocalUnicast, IsLinkLocalMulticast, IsUnspecified,
IsMulticast) plus an inline CGNAT range, but those helpers
do not match two classes of IPv6 address that should be
blocked for SSRF purposes
CVE-2026-55187
https://github.com/axllent/mailpit/security/advisories/GHSA-w4mc-hhc6-xp28
2026-06-17
2026-06-17
chromium -- security fixes
chromium
149.0.7827.114
ungoogled-chromium
149.0.7827.114
Chrome Releases reports:
This update includes 28 security fixes:
- [516731749] Critical CVE-2026-12007: Use after free Core. Reported by Google on 2026-05-26
- [516942828] Critical CVE-2026-12008: Use after free DigitalCredentials. Reported by Google on 2026-05-27
- [517332006] Critical CVE-2026-12009: Insufficient validation of untrusted input ccessibility. Reported by Google on 2026-05-28
- [517531647] Critical CVE-2026-12010: Heap buffer overflow GPU. Reported by Google on 2026-05-28
- [518108291] Critical CVE-2026-12011: Use after free WebMIDI. Reported by Google on 2026-05-30
- [499182801] High CVE-2026-12012: Use after free etwork. Reported by Google on 2026-04-03
- [514229805] High CVE-2026-12013: Use after free Media. Reported by Henock Habte, Independent Security Researcher on 2026-05-18
- [514742747] High CVE-2026-12014: Use after free Cast. Reported by Google on 2026-05-19
- [515463295] High CVE-2026-12015: Use after free utofill. Reported by Google on 2026-05-21
- [516482138] High CVE-2026-12016: Insufficient validation of untrusted input DevTools. Reported by Google on 2026-05-25
- [516797143] High CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google on 2026-05-26
- [516808201] High CVE-2026-12018: Inappropriate implementation Mojo. Reported by Google on 2026-05-26
- [516872067] High CVE-2026-12019: Out of bounds write Codecs. Reported by Google on 2026-05-26
- [516907083] High CVE-2026-12020: Use after free utofill. Reported by Google on 2026-05-27
- [516929496] High CVE-2026-12022: Race Safe Browsing. Reported by Google on 2026-05-27
- [517018374] High CVE-2026-12023: Use after free GPU. Reported by Google on 2026-05-27
- [517086161] High CVE-2026-12024: Insufficient policy enforcement DevTools. Reported by Google on 2026-05-27
- [517153191] High CVE-2026-12025: Insufficient validation of untrusted input etwork. Reported by Google on 2026-05-27
- [517347084] High CVE-2026-12026: Out of bounds read Video. Reported by Google on 2026-05-28
- [517517155] High CVE-2026-12027: Insufficient policy enforcement Headless. Reported by Google on 2026-05-28
- [517555461] High CVE-2026-12028: Use after free GPU. Reported by Google on 2026-05-28
- [518002958] High CVE-2026-12029: Use after free Video. Reported by Google on 2026-05-29
- [518007423] High CVE-2026-12030: Heap buffer overflow GPU. Reported by Google on 2026-05-29
- [518045638] High CVE-2026-12031: Inappropriate implementation Views. Reported by Google on 2026-05-30
- [518128953] High CVE-2026-12032: Inappropriate implementation Passwords. Reported by Google on 2026-05-30
- [519248779] High CVE-2026-12033: Out of bounds read VideoCapture. Reported by Google on 2026-06-02
- [519258799] High CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming. Reported by Google on 2026-06-02
- [520210566] High CVE-2026-12035: Use after free Views. Reported by Google on 2026-06-05
CVE-2026-12007
CVE-2026-12008
CVE-2026-12009
CVE-2026-12010
CVE-2026-12011
CVE-2026-12012
CVE-2026-12013
CVE-2026-12014
CVE-2026-12015
CVE-2026-12016
CVE-2026-12017
CVE-2026-12018
CVE-2026-12019
CVE-2026-12020
CVE-2026-12022
CVE-2026-12023
CVE-2026-12024
CVE-2026-12025
CVE-2026-12026
CVE-2026-12027
CVE-2026-12028
CVE-2026-12029
CVE-2026-12030
CVE-2026-12031
CVE-2026-12032
CVE-2026-12033
CVE-2026-12034
CVE-2026-12035
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html
2026-06-11
2026-06-15
libsmi -- Buffer overflow in the smiGetNode function in lib/smi
libsmi
0.4.80.4.8_3
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html reports:
Buffer overflow in the smiGetNode function in lib/smi.c in libsmi
0.4.8 allows context-dependent attackers to execute arbitrary code
via an Object Identifier (aka OID) represented as a numerical string
containing many components separated by . (dot) characters.
CVE-2010-2891
https://cveawg.mitre.org/api/cve/CVE-2010-2891
2010-10-27
2026-06-14
traefik -- Multiple vulnerabilities
traefik
3.7.3
The traefik project releases a new version addressing multiple CVEs:
- CVE-2026-48020 (StripPrefix Route-Level Auth Bypass)
- CVE-2026-48491 (SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass)
- HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
CVE-2026-48020
CVE-2026-48491
https://github.com/traefik/traefik/releases/tag/v3.7.3
2026-06-04
2026-06-14
caddy -- multiple vulnerabilities
caddy
2.11.4
Caddy project reports:
Caddy 2.11.4 contains multiple security fixes.
GitHub Security Advisory GHSA-qrp7-cvwr-j2c6 reports:
Windows-encoded backslashes in request paths could bypass
path-scoped authorization rules before files are served by
file_server.
GitHub Security Advisory GHSA-f59h-q822-g45g reports:
forward_auth copy_headers could fail to remove
underscore aliases of copied identity headers before FastCGI header
normalization, allowing identity or group header spoofing.
GitHub Security Advisory GHSA-vcc4-2c75-vc9v reports:
The stripHTML template function could fail to remove
malformed HTML, potentially allowing client-side cross-site
scripting if untrusted output is later rendered as HTML.
CVE-2026-52844
CVE-2026-52845
CVE-2026-52846
https://github.com/caddyserver/caddy/releases/tag/v2.11.4
https://github.com/caddyserver/caddy/security/advisories/GHSA-qrp7-cvwr-j2c6
https://github.com/caddyserver/caddy/security/advisories/GHSA-f59h-q822-g45g
https://github.com/caddyserver/caddy/security/advisories/GHSA-vcc4-2c75-vc9v
2026-06-08
2026-06-13
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
19.0.019.0.2
18.11.018.11.5
12.0.018.10.8
Gitlab reports:
Improper Access Control issue in Group SAML Identity API impacts GitLab EE
Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE
Denial of Service issue in Grape API JSON parsing middleware impacts GitLab CE/EE
HTML injection issue in certain group setting fields impacts GitLab EE
Denial of Service issue in Group Placeholder Reassignments API impacts GitLab CE/EE
Improper Access Control issue in Merge Requests API impacts GitLab CE/EE
Server-Side Request Forgery issue in Gitaly repository import impacts GitLab CE/EE
HTML injection issue in CI/CD Catalog impacts GitLab CE/EE
Improper Access Control issue in Security Inventory impacts GitLab EE
Authorization Bypass issue in Merge Request diff impacts GitLab CE/EE
Improper Access Control issue in Todos API impacts GitLab CE/EE
Improper Neutralization issue in Service Desk email template impacts GitLab CE/EE
CVE-2026-6552
CVE-2026-10087
CVE-2026-7250
CVE-2026-8589
CVE-2026-1500
CVE-2026-6269
CVE-2026-9204
CVE-2026-10733
CVE-2026-6277
CVE-2026-6976
CVE-2026-3553
CVE-2026-9694
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-2-released/
2026-06-11
2026-06-12
h2o -- stack overflow serving static files on musl libc
h2o
20260609
h2o project reports:
When serving static files, h2o can allocate a file path on
the stack using alloca. On systems using musl libc, a large
allocation can exceed the default pthread stack size and crash
the server, causing a denial of service.
CVE-2026-44453
https://github.com/h2o/h2o/security/advisories/GHSA-rf9v-m59p-mq84
2026-05-29
2026-06-11
h2o -- heap overrun parsing zero-length SNI
h2o
20260609
h2o project reports:
When h2o receives a TLS or QUIC ClientHello containing a
zero-length SNI extension, it can overrun the zero-length
hostname while copying it. This can trigger a segmentation
fault and cause a denial of service.
CVE-2026-44452
https://github.com/h2o/h2o/security/advisories/GHSA-w68q-rqwx-7wvq
2026-05-29
2026-06-11
h2o -- HTTP/2 state amplification denial of service
h2o
20260609
h2o project reports:
An HTTP/2 attack can combine HPACK decompression state
amplification with stalled streams. Depending on server
configuration, decoded header state can be retained by stalled
streams, causing excessive memory use and denial of service.
https://github.com/h2o/h2o/security/advisories/GHSA-qcrr-wrhc-pgq9
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
2026-06-04
2026-06-11
Erlang/OTP -- buffer overflow parsing SCTP ERROR/ABORT chunks
erlang-runtime27
27.3.4.13
erlang-runtime28
28.5.0.2
erlang-runtime29
29.0.2
https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97 reports:
A buffer overflow error when parsing SCTP ERROR or ABORT
chunks has been fixed. This could lead to stack corruption and
VM crash, but ultimately with hard work by an attacker be
refined into maybe even remote code execution.
CVE-2026-49759
https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97
2026-06-10
2026-06-10
Erlang/OTP -- stack overflow in ei_s_print_term for very large integer terms
erlang-runtime27
27.3.4.13
erlang-runtime28
28.5.0.2
erlang-runtime29
29.0.2
https://github.com/erlang/otp/security/advisories/GHSA-xcxj-5pg2-v72j reports:
Fixed a stack overflow in ei_s_print_term in erl_interface
for very large integer terms (more than 2000 hexadecimal digits
long).
CVE-2026-49760
https://github.com/erlang/otp/security/advisories/GHSA-xcxj-5pg2-v72j
2026-06-10
2026-06-10
Erlang/OTP -- FTP passive-mode client does not validate server response IP
erlang-runtime27
27.3.4.13
erlang-runtime28
28.5.0.2
erlang-runtime29
29.0.2
https://github.com/erlang/otp/security/advisories/GHSA-24cv-hwgr-37fq reports:
The FTP client in passive mode did not validate the IP
address returned in the server's response, allowing a
compromised or malicious server to redirect the data connection
to an arbitrary host. This enables server-side request forgery
(SSRF) and FTP bounce attacks.
CVE-2026-48858
https://github.com/erlang/otp/security/advisories/GHSA-24cv-hwgr-37fq
2026-06-10
2026-06-10
Erlang/OTP -- httpc leaks authentication headers on cross-host redirect
erlang-runtime27
27.3.4.13
erlang-runtime28
28.5.0.2
erlang-runtime29
29.0.2
https://github.com/erlang/otp/security/advisories/GHSA-m75x-4vwg-ggjh reports:
The HTTP client (httpc) in inets now removes Authorization,
Proxy-Authorization, Cookie, Referer, and Origin headers when
following a redirect to a different host or port, following the
requirements of RFC 9110 section 15.4. Previously these headers
were forwarded verbatim, potentially leaking credentials to
unintended targets.
CVE-2026-48856
https://github.com/erlang/otp/security/advisories/GHSA-m75x-4vwg-ggjh
2026-06-10
2026-06-10
Erlang/OTP -- SFTP READLINK discloses server filesystem paths
erlang-runtime27
27.3.4.13
erlang-runtime28
28.5.0.2
erlang-runtime29
29.0.2
https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh reports:
The SSH SFTP daemon's handling of SSH_FXP_READLINK returned
symbolic link targets containing the server's absolute
filesystem path, disclosing the backend root prefix to clients.
The handler now strips the backend root prefix from symlink
targets before returning them.
CVE-2026-48855
https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh
2026-06-10
2026-06-10
Erlang/OTP -- TLS distribution check_ip flag does not enforce same-LAN constraint
erlang-runtime27
27.3.4.13
erlang-runtime28
28.5.0.2
erlang-runtime29
29.0.2
https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv reports:
Erlang distribution over TLS run with the kernel check_ip
flag now properly enforces connecting nodes to be on the same
LAN. Previously the constraint was not enforced.
CVE-2026-48860
https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv
2026-06-10
2026-06-10
Erlang/OTP -- timing-based username enumeration in SSH password authentication
erlang-runtime29
29.0.2
https://github.com/erlang/otp/security/advisories/GHSA-3w6p-vwhf-wvp4 reports:
A timing-based username enumeration vulnerability during
password authentication with the user_passwords option has been
fixed by performing a dummy PBKDF2 computation for invalid
usernames, so authentication timing no longer reveals whether a
username exists.
CVE-2026-48859
https://github.com/erlang/otp/security/advisories/GHSA-3w6p-vwhf-wvp4
2026-06-10
2026-06-10
p5-ack -- Multiple issues
p5-ack
3.10.0
Ack project reports:
CVE-2026-49147: filename ANSI escape sequences
CVE-2026-49146: project .ackrc -A -B -C memory exhaustion
CVE-2026-49145: project .ackrc --follow / --files-from file exfiltration
CVE-2026-49147
https://www.suse.com/security/cve/CVE-2026-49147.html
CVE-2026-49146
https://www.suse.com/security/cve/CVE-2026-49146.html
CVE-2026-49145
https://www.suse.com/security/cve/CVE-2026-49145.html
2026-06-07
2026-06-10
tree-sitter-cli -- Always-Incorrect Control Flow Implementation in wasmtime crate
tree-sitter-cli
0.26.9
https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-q49f-xg75-m9xw reports:
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7,
42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability
where the compilation of the table.fill instruction can result in
a host panic. This means that a valid guest can be compiled with
Winch, on any architecture, and cause the host to panic. This
represents a denial-of-service vulnerability in Wasmtime due to
guests being able to trigger a panic. The specific issue is that
a historical refactoring changed how compiled code referenced tables
within the table.* instructions. This refactoring forgot to update
the Winch code paths associated as well, meaning that Winch was
using the wrong indexing scheme. Due to the feature support of
Winch the only problem that can result is tables being mixed up or
nonexistent tables being used, meaning that the guest is limited
to panicking the host (using a nonexistent table), or executing
spec-incorrect behavior and modifying the wrong table. This
vulnerability is fixed in crate versions: 36.0.7, 42.0.2, and 43.0.1.
https://rustsec.org/advisories/RUSTSEC-2026-0089
CVE-2026-34946
https://cveawg.mitre.org/api/cve/CVE-2026-34946
https://github.com/advisories/GHSA-q49f-xg75-m9xw
2026-04-09
2026-06-08
OpenSSL -- Multiple vulnerabilities
openssl
3.0.21,1
openssl34
3.4.6
openssl35
3.5.7
openssl36
3.6.3
openssl40
4.0.1
openssl111
1.1.1zh
The OpenSSL project reports:
Eighteen vulnerabilities in OpenSSL library.
Highest classification High.
CVE-2026-45447
CVE-2026-34182
CVE-2026-34183
CVE-2026-35188
CVE-2026-42764
CVE-2026-45445
CVE-2026-7383
CVE-2026-9076
CVE-2026-34180
CVE-2026-34181
CVE-2026-42765
CVE-2026-42766
CVE-2026-42767
CVE-2026-42768
CVE-2026-42769
CVE-2026-42770
CVE-2026-42771
CVE-2026-45446
https://openssl-library.org/news/secadv/20260609.txt
2026-06-09
2026-06-10
chromium -- security fixes
chromium
149.0.7827.102
ungoogled-chromium
149.0.7827.102
Chrome Releases reports:
This update includes 74 security fixes:
- [516501794] Critical CVE-2026-11628: Use after free in Ozone.
- [516674532] Critical CVE-2026-11629: Use after free in Ozone.
- [516677924] Critical CVE-2026-11630: Use after free in File Input.
- [516691130] Critical CVE-2026-11631: Use after free in Aura.
- [516707881] Critical CVE-2026-11632: Use after free in TabStrip.
- [516963272] Critical CVE-2026-11633: Use after free in Bluetooth.
- [516975148] Critical CVE-2026-11634: Use after free in Gamepad.
- [516987814] Critical CVE-2026-11635: Use after free in Bluetooth.
- [517023053] Critical CVE-2026-11636: Use after free in Autofill.
- [517040438] Critical CVE-2026-11637: Use after free in Views.
- [517047197] Critical CVE-2026-11638: Use after free in Printing.
- [517227707] Critical CVE-2026-11639: Use after free in Compositing.
- [517339758] Critical CVE-2026-11640: Integer overflow in libyuv.
- [517418936] Critical CVE-2026-11641: Use after free in Bluetooth.
- [517678820] Critical CVE-2026-11642: Use after free in Web Apps.
- [518006379] Critical CVE-2026-11643: Use after free in Proxy.
- [518043597] Critical CVE-2026-11644: Use after free in Views.
- [506689381] High CVE-2026-11645: Out of bounds memory access in V8.
- [517168239] High CVE-2026-11646: Use after free in ViewTransitions.
- [502156940] High CVE-2026-11647: Use after free in Printing.
- [506684534] High CVE-2026-11648: Use after free in FullScreen.
- [511270083] High CVE-2026-11649: Use after free in V8.
- [511279942] High CVE-2026-11650: Use after free in V8.
- [511736002] High CVE-2026-11651: Use after free in Network.
- [513156160] High CVE-2026-11652: Use after free in Extensions.
- [513321171] High CVE-2026-11653: Insufficient validation of untrusted input in Extensions.
- [513362710] High CVE-2026-11654: Use after free in CameraCapture.
- [513396305] High CVE-2026-11655: Integer overflow in Media.
- [513424000] High CVE-2026-11656: Use after free in ServiceWorker.
- [513465272] High CVE-2026-11657: Use after free in Payments.
- [513564337] High CVE-2026-11658: Insufficient validation of untrusted input in Extensions.
- [513702971] High CVE-2026-11659: Insufficient validation of untrusted input in UI.
- [513731890] High CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page.
- [513748868] High CVE-2026-11661: Use after free in Views.
- [513773313] High CVE-2026-11662: Type Confusion in Bindings.
- [513820666] High CVE-2026-11663: Use after free in Skia.
- [513830374] High CVE-2026-11664: Use after free in Payments.
- [513948465] High CVE-2026-11665: Out of bounds read in Dawn.
- [514009323] High CVE-2026-11666: Insufficient validation of untrusted input in Input.
- [514671098] High CVE-2026-11667: Out of bounds read in WebRTC.
- [515419790] High CVE-2026-11668: Uninitialized Use in Codecs.
- [515429352] High CVE-2026-11669: Integer overflow in Media.
- [515469283] High CVE-2026-11670: Use after free in PDF.
- [516608438] High CVE-2026-11671: Use after free in Navigation.
- [516794471] High CVE-2026-11672: Out of bounds write in GPU.
- [516902973] High CVE-2026-11673: Use after free in InterestGroups.
- [516910450] High CVE-2026-11674: Use after free in Guest View.
- [516915337] High CVE-2026-11675: Insufficient validation of untrusted input in Skia.
- [516949298] High CVE-2026-11676: Insufficient validation of untrusted input in Dawn.
- [516979551] High CVE-2026-11677: Race in Network.
- [516986556] High CVE-2026-11678: Integer overflow in libyuv.
- [516997135] High CVE-2026-11679: Use after free in Codecs.
- [517004487] High CVE-2026-11680: Use after free in Media.
- [517050585] High CVE-2026-11681: Use after free in Ozone.
- [517103584] High CVE-2026-11682: Insufficient validation of untrusted input in Views.
- [517129549] High CVE-2026-11683: Use after free in WebCodecs.
- [517130229] High CVE-2026-11684: Insufficient policy enforcement in Network.
- [517183713] High CVE-2026-11685: Insufficient data validation in MediaCapture.
- [517247333] High CVE-2026-11686: Insufficient validation of untrusted input in Dawn.
- [517303276] High CVE-2026-11687: Use after free in Dawn.
- [517309206] High CVE-2026-11688: Object lifecycle issue in SVG.
- [517486004] High CVE-2026-11689: Insufficient validation of untrusted input in Passwords.
- [517533654] High CVE-2026-11690: Out of bounds read and write in Media.
- [517585486] High CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page.
- [517607902] High CVE-2026-11692: Use after free in Read Anything.
- [517644287] High CVE-2026-11693: Inappropriate implementation in Plugins.
- [517705966] High CVE-2026-11694: Use after free in ServiceWorker.
- [517762104] High CVE-2026-11695: Inappropriate implementation in Passwords.
- [517993381] High CVE-2026-11696: Uninitialized Use in Video.
- [518105731] High CVE-2026-11697: Insufficient validation of untrusted input in UI.
- [518235412] High CVE-2026-11698: Use after free in Bluetooth.
- [518237527] High CVE-2026-11699: Use after free in Bluetooth.
- [511732085] Medium CVE-2026-11700: Use after free in Tracing.
- [516413817] Medium CVE-2026-11701: Insufficient validation of untrusted input in Guest View.
CVE-2026-11628
CVE-2026-11629
CVE-2026-11630
CVE-2026-11631
CVE-2026-11632
CVE-2026-11633
CVE-2026-11634
CVE-2026-11635
CVE-2026-11636
CVE-2026-11637
CVE-2026-11638
CVE-2026-11639
CVE-2026-11640
CVE-2026-11641
CVE-2026-11642
CVE-2026-11643
CVE-2026-11644
CVE-2026-11645
CVE-2026-11646
CVE-2026-11647
CVE-2026-11648
CVE-2026-11649
CVE-2026-11650
CVE-2026-11651
CVE-2026-11652
CVE-2026-11653
CVE-2026-11654
CVE-2026-11655
CVE-2026-11656
CVE-2026-11657
CVE-2026-11658
CVE-2026-11659
CVE-2026-11660
CVE-2026-11661
CVE-2026-11662
CVE-2026-11663
CVE-2026-11664
CVE-2026-11665
CVE-2026-11666
CVE-2026-11667
CVE-2026-11668
CVE-2026-11669
CVE-2026-11670
CVE-2026-11671
CVE-2026-11672
CVE-2026-11673
CVE-2026-11674
CVE-2026-11675
CVE-2026-11676
CVE-2026-11677
CVE-2026-11678
CVE-2026-11679
CVE-2026-11680
CVE-2026-11681
CVE-2026-11682
CVE-2026-11683
CVE-2026-11684
CVE-2026-11685
CVE-2026-11686
CVE-2026-11687
CVE-2026-11688
CVE-2026-11689
CVE-2026-11690
CVE-2026-11691
CVE-2026-11692
CVE-2026-11693
CVE-2026-11694
CVE-2026-11695
CVE-2026-11696
CVE-2026-11697
CVE-2026-11698
CVE-2026-11699
CVE-2026-11700
CVE-2026-11701
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
2026-06-08
2026-06-10
FreeBSD -- Insufficient response validation in the ldns stub resolver
FreeBSD
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
When used as a stub resolver over UDP, ldns failed to verify
that a received response belonged to the outstanding query. It did
not check that the response source address and port matched the
query destination, that the transaction ID matched, or that the
question section of the response matched that of the query.
Impact:
Without these checks, an off-path attacker who cannot observe
the query can forge UDP responses that ldns will accept as genuine.
By injecting spoofed replies, the attacker can return arbitrary DNS
data to any program that uses ldns for stub resolving, including
drill(1).
CVE-2026-10846
SA-26:36.ldns
2026-06-09
2026-06-10
FreeBSD -- Multiple vulnerabilities in OpenSSL
FreeBSD
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
Multiple issues have been reported as part of this advisory
with different issues affecting different OpenSSL versions and
therefore different FreeBSD versions. Instead of exhaustively
listing detailed writeups for each issue, please see the referenced
advisory from OpenSSL.
Issues affecting FreeBSD 15.x (OpenSSL 3.5):
- CVE-2026-7383: Possible heap buffer overflow in ASN.1 string conversion
- CVE-2026-9076: Out-of-bounds read in CMS password-based decryption
- CVE-2026-34180: Heap buffer over-read in ASN.1 content parsing
- CVE-2026-34181: PKCS#12 files with PBMAC1 accepted with short HMAC keys
- CVE-2026-34182: CMS AuthEnvelopedData may accept forged messages
- CVE-2026-34183: Unbounded memory growth in the QUIC PATH_CHALLENGE handler
- CVE-2026-42764: NULL dereference in QUIC server initial packet handling
- CVE-2026-42766: Possible NULL dereference in password-based CMS decryption
- CVE-2026-42767: NULL dereference in CRMF EncryptedValue decryption
- CVE-2026-42768: Bleichenbacher oracle in CMS_decrypt() and PKCS7_decrypt()
- CVE-2026-42769: Trust-anchor substitution in CMP rootCaKeyUpdate handling
- CVE-2026-42770: FFC-DH peer validation uses attacker-supplied q
- CVE-2026-45445: AES-OCB IV ignored on the EVP_Cipher() one-shot path
- CVE-2026-45446: Empty-message tag bypass in AES-GCM-SIV and AES-SIV modes
- CVE-2026-45447: Heap use-after-free in PKCS7_verify()
Issues affecting FreeBSD 14.x (OpenSSL 3.0):
- CVE-2026-7383: Possible heap buffer overflow in ASN.1 string conversion
- CVE-2026-9076: Out-of-bounds read in CMS password-based decryption
- CVE-2026-34180: Heap buffer over-read in ASN.1 content parsing
- CVE-2026-34182: CMS AuthEnvelopedData may accept forged messages
- CVE-2026-42766: Possible NULL dereference in password-based CMS decryption
- CVE-2026-42770: FFC-DH peer validation uses attacker-supplied q
- CVE-2026-45445: AES-OCB IV ignored on the EVP_Cipher() one-shot path
- CVE-2026-45446: Empty-message tag bypass in AES-GCM-SIV and AES-SIV modes
- CVE-2026-45447: Heap use-after-free in PKCS7_verify()
Impact:
The issues include heap buffer overflows and over-reads, NULL
pointer dereferences, a use-after-free, unbounded memory allocation,
and several cryptographic flaws permitting message forgery, integrity
bypass, or recovery of a private key.
Security impact ranges from a Denial of Service to a potential
remote code execution. See the OpenSSL advisory for specific
details.
CVE-2026-7383
CVE-2026-9076
CVE-2026-34180
CVE-2026-34181
CVE-2026-34182
CVE-2026-34183
CVE-2026-42764
CVE-2026-42766
CVE-2026-42767
CVE-2026-42768
CVE-2026-42769
CVE-2026-42770
CVE-2026-45445
CVE-2026-45446
CVE-2026-45447
SA-26:35.openssl
2026-06-09
2026-06-10
FreeBSD -- Integer overflow in vt(4) CONS_HISTORY ioctl
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
The CONS_HISTORY ioctl handler did not adequately validate the
requested history size. A large value caused an integer overflow
in the buffer size calculation, resulting in a heap allocation
smaller than expected. Subsequent initialization of the buffer
wrote beyond the end of the allocation.
Impact:
An unprivileged local user with access to a vt(4) device can
trigger an out-of-bounds write in the kernel, potentially escalating
privileges.
CVE-2026-49416
SA-26:34.vt
2026-06-09
2026-06-10
FreeBSD -- Multiple vulnerabilities in unbound
FreeBSD
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
Multiple vulnerabilities have been reported in Unbound. Instead
of listing detailed writeups for each issue, please see the upstream
advisories referenced below.
- CVE-2026-32792: Packet of death with DNSCrypt
- CVE-2026-33278: Possible remote code execution during DNSSEC validation
- CVE-2026-40622: "Ghost domain name" variant
- CVE-2026-41292: Parsing a long list of incoming EDNS options degrades performance
- CVE-2026-42534: Jostle logic bypass degrades resolution performance
- CVE-2026-42923: Degradation of service with unbounded NSEC3 hash calculations
- CVE-2026-42944: Heap overflow and crash with multiple nsid, cookie, padding EDNS options
- CVE-2026-42959: Crash during DNSSEC validation of malicious content
- CVE-2026-42960: Possible cache poisoning while following delegation
- CVE-2026-44390: Unbounded name compression causes degradation of service
- CVE-2026-44608: Use-after-free and crash in RPZ code
Impact:
The issues range from Denial of Service (DoS) through resource
exhaustion or crashes to possible remote code execution during
DNSSEC validation. See the upstream Unbound advisories for specific
details.
CVE-2026-32792
CVE-2026-33278
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-42923
CVE-2026-42944
CVE-2026-42959
CVE-2026-42960
CVE-2026-44390
CVE-2026-44608
SA-26:33.unbound
2026-06-09
2026-06-10
FreeBSD-kernel -- ASLR bypass for setuid executables via procctl(2)
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
The ELF image activator cleared per-process ASLR preference
flags for setuid binaries after the code that computes the PIE base
address, rather than before. As a result, a user-requested ASLR
disable was still in effect at the point where the base address was
chosen.
Impact:
An unprivileged local user can disable ASLR for a setuid PIE
binary by calling procctl(2) before execve(2). This makes exploitation
of any separate memory corruption vulnerability in that binary
significantly easier.
CVE-2026-49414
SA-26:32.elf
2026-06-09
2026-06-10
FreeBSD -- Arm CPU errata may bypass page table permission changes
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
Some Arm CPUs have errata where the ordering of stores and the
TLBI+DSB sequence may be incorrect. If one CPU stores to a virtual
address while another CPU invalidates the translation for that
address, the second CPU's TLBI+DSB may complete before the first
CPU's store has been globally observed.
Impact:
This erratum may allow software to write to a previously writable
location after the page table is modified to forbid writes to that
location. Consequently this may allow software to write to memory
owned by a higher exception level, possibly allowing software to
escalate privilege to that higher exception level.
CVE-2025-10263
SA-26:31.arm64
2026-06-09
2026-06-10
FreeBSD -- Flaw in Linuxulator execution of setugid binaries
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
The Linuxulator determined whether a binary was set-user-ID or
set-group-ID by checking the P_SUGID process flag. During execve(2),
this flag is not yet set at the point where the auxiliary vector
is constructed, so AT_SECURE was incorrectly set to zero for
set-user-ID and set-group-ID executables.
Impact:
An unprivileged local user can inject a shared library via
LD_PRELOAD into a set-user-ID or set-group-ID Linux binary, gaining
the privileges of that binary.
CVE-2026-49413
SA-26:30.linux
2026-06-09
2026-06-10
FreeBSD -- Use-after-free bug in the IPV6_MSFILTER socket option handler
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
The kernel handler for IPV6_MSFILTER dropped a serializing lock
in order to copy the source-filter list from userspace, then
reacquired the lock. During this window another thread could free
the multicast filter structure, leaving the handler with a stale
pointer to freed memory.
Impact:
An unprivileged local user can exploit this use-after-free to
escalate privileges.
CVE-2026-49412
SA-26:28.ip6_multicast
2026-06-09
2026-06-10
FreeBSD -- sigqueue(2) missing capability mode restriction
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
sigqueue(2) was marked as permitted in capability mode with the
introduction of Capsicum in 2011, but the implementation of
kern_sigqueue did not include a capability mode check restricting
signal delivery to the calling process's own PID.
Impact:
A process in capability mode can use sigqueue(2) to send signals
to any process it could signal following standard Unix permissions,
bypassing the Capsicum sandbox restriction. A compromised sandboxed
process could interfere with other processes, for example by sending
SIGKILL or SIGSTOP. This could be any process running as the same
user, or any process, for a superuser sandboxed process.
CVE-2026-45259
SA-26:28.capsicum
2026-06-09
2026-06-10
FreeBSD -- Multiple vulnerabilities in the sound(4) mmap path
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
The sound(4) driver contained two memory-safety errors in its
mmap(2) support.
First, dsp_mmap_single() validated the requested mapping by checking
the sum of the user-supplied offset and length against the buffer
size. This addition could overflow, so that a large offset and
length wrapped around and passed the check. The offset was then
narrowed from 64 to 32 bits when converted to a buffer address,
yielding a mapping that extended past the audio buffer into unrelated
kernel memory. (CVE-2026-45258)
Second, the audio buffer backing a mapping could be freed when the
device was closed even though the mapping remained valid. The freed
memory could then be reused elsewhere while still accessible through
the stale mapping. (CVE-2026-49417)
Impact:
The /dev/dsp device nodes are world-accessible by default. On
a system with an audio device, either issue allows an unprivileged
local user to read and write kernel memory, which can be used to
escalate privileges, potentially gaining full control of the affected
system. At a minimum, an attacker can crash the kernel, resulting
in a Denial of Service (DoS).
CVE-2026-45258
CVE-2026-49417
SA-26:27.sound
2026-06-09
2026-06-10
FreeBSD -- Arbitrary file overwrite via the KTLS receive path
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
The KTLS receive path decrypted each record in place, assuming
that the mbufs holding received data were anonymous and safe to
modify. This assumption does not hold for data placed on a socket
by sendfile(2), which can reference file-backed memory directly
through non-anonymous M_EXTPG pages or EXT_SFBUF mbufs. When the
sender transmits such data over a loopback connection without
enabling KTLS on the transmit side, the file-backed mbufs reach the
receiver's decryption path unchanged. Decrypting a record in place
then overwrites the backing file's page cache instead of a private
copy of the data.
Impact:
An unprivileged local user who can read a file can overwrite
its contents with data of their choosing by sending the file over
a loopback connection on which they have enabled KTLS receive. The
write modifies the page cache directly, so it bypasses file flags
such as schg and is written back to disk. By overwriting a setuid
binary or other trusted file, a local user can escalate privileges,
potentially gaining full control of the affected system.
CVE-2026-45257
SA-26:26.ktls
2026-06-09
2026-06-10
FreeBSD -- Missing permission check in thr_kill2(2)
FreeBSD-kernel
15.015.0_10
14.414.4_6
14.314.3_15
Problem Description:
When used to deliver a signal to a specific thread, thr_kill2(2)
called p_cansignal() to determine whether the operation was permitted
but did not check the result before delivering the signal. The
signal was sent even when the permission check failed. The system
call returned the resulting error to the caller, but by then the
signal had already been delivered.
Impact:
The missing check allows an unprivileged local user who knows
or can guess a target's process and thread IDs to send any signal
to a process they would not normally be permitted to signal, including
processes owned by other users or by root. The same check enforces
jail boundaries, so a jailed process can signal processes on the
host or in other jails. Thread IDs are allocated globally and
sequentially, and so can be discovered by brute force with no
visibility into the target.
An attacker can stop or terminate arbitrary processes, including
critical system daemons, resulting in a Denial of Service (DoS).
CVE-2026-45256
SA-26:25.thr
2026-06-09
2026-06-10
Elixir -- Denial of service via unbounded integer parsing in Version
elixir
1.5.01.19.5
PJUllrich reports:
The Version module parses numeric version components without
length limits. Untrusted input can trigger creation of
arbitrary-precision integers, causing CPU and memory exhaustion.
CVE-2026-49762
https://github.com/elixir-lang/elixir/security/advisories/GHSA-w2h8-8x3g-278p
2026-06-09
2026-06-09
Elixir -- Denial of service via unbounded integer parsing in Version
elixir-devel
1.5.01.20.1
PJUllrich reports:
The Version module parses numeric version components without
length limits. Untrusted input can trigger creation of
arbitrary-precision integers, causing CPU and memory exhaustion.
CVE-2026-49762
https://github.com/elixir-lang/elixir/security/advisories/GHSA-w2h8-8x3g-278p
2026-06-09
2026-06-09
Apache httpd -- Multiple vulnerabilities
apache24
2.4.68
The Apache httpd project reports:
See links for details.
CVE-2026-48913
CVE-2026-44631
CVE-2026-44186
CVE-2026-44185
CVE-2026-44119
CVE-2026-43951
CVE-2026-42536
CVE-2026-42535
CVE-2026-34356
CVE-2026-34355
CVE-2026-29170
CVE-2026-29167
https://downloads.apache.org/httpd/CHANGES_2.4.68
2026-06-08
2026-06-08
Unbound -- Multiple vulnerabilities
unbound
1.25.1
NLnet Labs reports:
This release consolidates security fixes for issues reported
over a period of time. There are fixes for:
- CVE-2026-33278: Possible remote code execution during
DNSSEC validation.
- CVE-2026-42944: Heap overflow and crash with multiple
nsid, cookie, padding EDNS options.
- CVE-2026-42959: Crash during DNSSEC validation of
malicious content.
- CVE-2026-32792: Packet of death with DNSCrypt.
- CVE-2026-40622: "Ghost domain name" variant.
- CVE-2026-41292: Parsing a long list of incoming EDNS
options degrades performance.
- CVE-2026-42534: Jostle logic bypass degrades resolution
performance.
- CVE-2026-42923: Degradation of service with unbounded
NSEC3 hash calculations.
- CVE-2026-42960: Possible cache poisoning attack while
following delegation.
- CVE-2026-44390: Unbounded name compression in certain
cases causes degradation of service.
- CVE-2026-44608: Use after free and crash in RPZ code.
CVE-2026-32792
CVE-2026-33278
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-42923
CVE-2026-42944
CVE-2026-42959
CVE-2026-42960
CVE-2026-44390
CVE-2026-44608
https://www.nlnetlabs.nl/projects/unbound/security-advisories/
2026-05-20
2026-06-08
strongSwan -- Double-free when destroying certain cloned identities that can lead to remote code execution
strongswan
4.3.36.0.7
R. Elliott Childre reports:
The clone() method of the identification_t class doesn't correctly handle identities that have an empty but
non-NULL encoding. Both objects will point to the same location, resulting in a double-free once the second object
is destroyed. This can lead to a crash and could potentially be exploitable for remote code execution. Affected are
all strongSwan versions since 4.3.3.
CVE-2026-47895
https://www.cve.org/CVERecord?id=CVE-2026-47895
2026-06-08
2026-06-08
Weechat -- Multiple vulnerabilities
weechat
4.9.1
The Weechat project reports:
See links for detail.
https://weechat.org/download/weechat/4.9.1/
https://weechat.org/doc/weechat/security/#WSA-2026-1
https://weechat.org/doc/weechat/security/#WSA-2026-2
2026-05-31
2026-06-07
Weechat -- Multiple vulnerabilities
weechat
4.9.2
The Weechat project reports:
See links for detail.
https://weechat.org/download/weechat/4.9.2/
https://weechat.org/doc/weechat/security/#WSA-2026-3
https://weechat.org/doc/weechat/security/#WSA-2026-4
https://weechat.org/doc/weechat/security/#WSA-2026-5
https://weechat.org/doc/weechat/security/#WSA-2026-6
https://weechat.org/doc/weechat/security/#WSA-2026-7
https://weechat.org/doc/weechat/security/#WSA-2026-8
2026-06-07
2026-06-07
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
19.0.019.0.1
18.11.018.11.4
12.7.018.10.7
Gitlab reports:
Improper Access Control issue in Duo AI workflow runners impacts GitLab EE
Denial of Service issue in Wiki impacts GitLab CE/EE
Incorrect Authorization issue in GraphQL WorkItem API impacts GitLab CE/EE
Improper Authorization issue in Duo Workflows API impacts GitLab EE
Missing Authorization issue in Operations impacts GitLab EE
Incorrect Name Resolution issue in Pipelines impacts GitLab CE/EE
Incorrect Authorization issue in certain authentication endpoints impacts GitLab CE/EE
CVE-2026-4868
CVE-2026-1402
CVE-2026-6713
CVE-2026-5296
CVE-2026-2601
CVE-2026-8716
CVE-2026-2710
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/
2026-05-27
2026-06-06
PowerDNS -- Multiple vulnerabilities
powerdns
5.0.5
PowerDNS Team reports:
2025-07: Internal logic flaw in cache management can lead to
a denial of service in Recursor
When using views, queries sent using TCP Proxy Protocol will select
the view according to the address of the proxy, rather than the address
of the initial query. This can lead to wrong data being returned.
Missing escaping of special characters (such as $ or @) in DNS names
received during an AXFR operation can lead to an incorrect
(non-parseable) Bind backend configuration to be written, causing this
backend to fail until manual operation is performed to fix the
configuration.
Missing sanity checks of the answer to the initial SOA query, when
running in auto-secondary mode and receiving a notification for an
not-yet-known domain may cause the server to crash.
Multiple concurrency and locking defects in the GSS-TSIG code can
lead to memory corruption due to accidental data structure sharing,
which can in turn lead to a program crash.
Missing proper escaping of double-quote characters when computing
labels will cause AXFR of a catalog zone with a member whose producer
group option contains such a character to fail.
CVE-2026-41999
CVE-2026-42000
CVE-2026-42001
CVE-2026-42002
CVE-2026-42396
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html
2026-05-20
2026-06-04
Apache httpd -- DoS exploit in HTTP/2
apache24
2.4.67_2
Calif security reports:
Remote DoS in mod_http2
CVE-2026-49975
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
2026-06-02
2026-06-04
xwayland -- Multiple vulnerabilities
xwayland
24.1.12,1
X.Org project reports:
Multiple issues have been found in the X server and Xwayland
implementations published by X.Org for which we are releasing
security fixes for in xorg-server-21.1.23 and xwayland-24.1.12.
CVE-2026-50256
CVE-2026-50257
CVE-2026-50258
CVE-2026-50259
CVE-2026-50260
CVE-2026-50261
CVE-2026-50262
CVE-2026-50263
CVE-2026-50264
https://lists.x.org/archives/xorg-announce/2026-June/003702.html
https://lists.x.org/archives/xorg-announce/2026-June/003705.html
2026-06-01
2026-06-01
xorg-server -- Multiple vulnerabilities
xorg-server
21.1.23,1
X.Org project reports:
Multiple issues have been found in the X server and Xwayland
implementations published by X.Org for which we are releasing
security fixes for in xorg-server-21.1.23 and xwayland-24.1.12.
CVE-2026-50256
CVE-2026-50257
CVE-2026-50258
CVE-2026-50259
CVE-2026-50260
CVE-2026-50261
CVE-2026-50262
CVE-2026-50263
CVE-2026-50264
https://lists.x.org/archives/xorg-announce/2026-June/003702.html
https://lists.x.org/archives/xorg-announce/2026-June/003705.html
2026-06-01
2026-06-01
chromium -- security fixes
chromium
148.0.7778.215
ungoogled-chromium
148.0.7778.215
Chrome Releases reports:
This update includes 151 security fixes:
- [505077859] Critical CVE-2026-9872: Out of bounds write in GPU.
- [507365348] Critical CVE-2026-9873: Use after free in Network.
- [500609038] Critical CVE-2026-9874: Use after free in Dawn.
- [507508103] Critical CVE-2026-9875: Out of bounds read in WebGL.
- [493747593] Critical CVE-2026-9876: Use after free in WebGL.
- [496445460] Critical CVE-2026-9877: Use after free in ANGLE.
- [499054245] Critical CVE-2026-9878: Use after free in ANGLE.
- [499129768] Critical CVE-2026-9879: Out of bounds write in ANGLE.
- [503615025] Critical CVE-2026-9880: Insufficient validation of untrusted input in WebGL.
- [505140741] Critical CVE-2026-9881: Use after free in Bluetooth.
- [506375217] Critical CVE-2026-9882: Integer overflow in ANGLE.
- [506477192] Critical CVE-2026-9883: Use after free in Base.
- [508289938] Critical CVE-2026-9884: Use after free in Browser.
- [508452241] Critical CVE-2026-9885: Insufficient validation of untrusted input in UI.
- [508456788] Critical CVE-2026-9886: Use after free in Base.
- [511249104] Critical CVE-2026-9887: Use after free in Proxy.
- [511715166] Critical CVE-2026-9888: Use after free in WebView.
- [511727159] Critical CVE-2026-9889: Out of bounds read and write in Dawn.
- [513135985] Critical CVE-2026-9890: Use after free in XR.
- [513508128] Critical CVE-2026-9891: Use after free in Extensions.
- [513948178] Critical CVE-2026-9892: Inappropriate implementation in Skia.
- [513972075] Critical CVE-2026-9893: Use after free in Skia.
- [507707838] High CVE-2026-9894: Use after free in GPU.
- [491685406] High CVE-2026-9895: Out of bounds read in GPU.
- [508811474] High CVE-2026-9896: Out of bounds write in V8.
- [496271580] High CVE-2026-9897: Use after free in DOM.
- [496282591] High CVE-2026-9898: Insufficient validation of untrusted input in GPU.
- [497533569] High CVE-2026-9899: Use after free in ANGLE.
- [497637277] High CVE-2026-9900: Out of bounds write in ANGLE.
- [497737770] High CVE-2026-9901: Use after free in ANGLE.
- [498205735] High CVE-2026-9902: Use after free in Accessibility.
- [498783665] High CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation.
- [498804020] High CVE-2026-9904: Use after free in ANGLE.
- [498883610] High CVE-2026-9905: Use after free in Accessibility.
- [499005260] High CVE-2026-9906: Out of bounds write in GPU.
- [499091269] High CVE-2026-9907: Out of bounds read in Dawn.
- [499091328] High CVE-2026-9908: Out of bounds read in ANGLE.
- [499152771] High CVE-2026-9909: Integer overflow in Skia.
- [499176133] High CVE-2026-9910: Out of bounds memory access in ANGLE.
- [499205491] High CVE-2026-9911: Integer overflow in ANGLE.
- [499873765] High CVE-2026-9912: Inappropriate implementation in GPU.
- [500046096] High CVE-2026-9913: Inappropriate implementation in ANGLE.
- [500047428] High CVE-2026-9914: Insufficient validation of untrusted input in ANGLE.
- [500063836] High CVE-2026-9915: Heap buffer overflow in ANGLE.
- [500080303] High CVE-2026-9916: Out of bounds write in ANGLE.
- [500095304] High CVE-2026-9917: Uninitialized Use in WebGL.
- [500099471] High CVE-2026-9918: Inappropriate implementation in Tint.
- [500114058] High CVE-2026-9919: Out of bounds read in WebGL.
- [500138014] High CVE-2026-9920: Uninitialized Use in GPU.
- [500150338] High CVE-2026-9921: Uninitialized Use in WebGL.
- [500187083] High CVE-2026-9922: Use after free in GPU.
- [500393328] High CVE-2026-9923: Use after free in Skia.
- [500398345] High CVE-2026-9924: Heap buffer overflow in ANGLE.
- [500536458] High CVE-2026-9925: Use after free in ANGLE.
- [500540748] High CVE-2026-9926: Heap buffer overflow in ANGLE.
- [500540958] High CVE-2026-9927: Use after free in ANGLE.
- [501125002] High CVE-2026-9928: Out of bounds read in ANGLE.
- [501367791] High CVE-2026-9929: Inappropriate implementation in WebGL.
- [501499832] High CVE-2026-9930: Out of bounds write in Dawn.
- [501524262] High CVE-2026-9931: Use after free in GPU.
- [501563323] High CVE-2026-9932: Use after free in ANGLE.
- [501575979] High CVE-2026-9933: Use after free in Input.
- [501576946] High CVE-2026-9934: Use after free in Aura.
- [501584689] High CVE-2026-9935: Uninitialized Use in ANGLE.
- [502104354] High CVE-2026-9936: Use after free in GFX.
- [502112506] High CVE-2026-9937: Use after free in UI.
- [502300817] High CVE-2026-9938: Inappropriate implementation in V8.
- [502735235] High CVE-2026-9939: Heap buffer overflow in WebCodecs.
- [502738003] High CVE-2026-9940: Heap buffer overflow in ANGLE.
- [502812366] High CVE-2026-9941: Use after free in ANGLE.
- [503438092] High CVE-2026-9942: Uninitialized Use in ANGLE.
- [503464551] High CVE-2026-9943: Out of bounds read in WebGL.
- [503471286] High CVE-2026-9944: Uninitialized Use in ANGLE.
- [503565293] High CVE-2026-9945: Use after free in Media.
- [503596863] High CVE-2026-9946: Use after free in ANGLE.
- [503627446] High CVE-2026-9947: Use after free in XML.
- [503790201] High CVE-2026-9948: Use after free in Views.
- [503793153] High CVE-2026-9949: Use after free in Core.
- [503862359] High CVE-2026-9950: Insufficient validation of untrusted input in iOS.
- [503873388] High CVE-2026-9951: Use after free in UI.
- [503929476] High CVE-2026-9952: Use after free in WebAudio.
- [503985322] High CVE-2026-9953: Out of bounds read in ANGLE.
- [504175497] High CVE-2026-9954: Use after free in TabStrip.
- [504184408] High CVE-2026-9955: Inappropriate implementation in iOS.
- [504195132] High CVE-2026-9956: Use after free in iOS.
- [504516117] High CVE-2026-9957: Use after free in PDF.
- [504555886] High CVE-2026-9958: Use after free in PDFium.
- [504557432] High CVE-2026-9959: Race in WebRTC.
- [504573260] High CVE-2026-9960: Integer overflow in PDFium.
- [504710769] High CVE-2026-9961: Use after free in SurfaceCapture.
- [504716948] High CVE-2026-9962: Use after free in WebRTC.
- [505143241] High CVE-2026-9963: Uninitialized Use in iOS.
- [505190999] High CVE-2026-9964: Use after free in Bluetooth.
- [506377574] High CVE-2026-9965: Out of bounds write in ANGLE.
- [506388321] High CVE-2026-9966: Integer overflow in XML.
- [506414791] High CVE-2026-9967: Out of bounds write in GPU.
- [506499280] High CVE-2026-9968: Integer overflow in V8.
- [506550494] High CVE-2026-9969: Insufficient validation of untrusted input in ANGLE.
- [506653647] High CVE-2026-9970: Use after free in WebGL.
- [508448586] High CVE-2026-9971: Inappropriate implementation in iOS.
- [508463705] High CVE-2026-9972: Uninitialized Use in Gamepad.
- [509268941] High CVE-2026-9973: Out of bounds write in V8.
- [511710468] High CVE-2026-9974: Out of bounds write in GPU.
- [511719039] High CVE-2026-9975: Out of bounds read and write in ANGLE.
- [511732828] High CVE-2026-9976: Inappropriate implementation in USB.
- [511741173] High CVE-2026-9977: Insufficient validation of untrusted input in WebShare.
- [511741396] High CVE-2026-9978: Use after free in Glic.
- [511742228] High CVE-2026-9979: Insufficient validation of untrusted input in Input.
- [511776372] High CVE-2026-9980: Insufficient validation of untrusted input in Printing.
- [512995705] High CVE-2026-9981: Inappropriate implementation in Skia.
- [513001247] High CVE-2026-9982: Insufficient validation of untrusted input in ANGLE.
- [513001309] High CVE-2026-9983: Type Confusion in Skia.
- [513002543] High CVE-2026-9984: Use after free in UI.
- [513019760] High CVE-2026-9985: Insufficient validation of untrusted input in Media.
- [513028160] High CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide.
- [513046475] High CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls.
- [513049286] High CVE-2026-9988: Use after free in WebRTC.
- [513054053] High CVE-2026-9989: Inappropriate implementation in Media.
- [513128608] High CVE-2026-9990: Use after free in WebAppInstalls.
- [513173565] High CVE-2026-9991: Inappropriate implementation in Media.
- [513177826] High CVE-2026-9992: Use after free in Network.
- [513208588] High CVE-2026-9993: Use after free in Views.
- [513235131] High CVE-2026-9994: Use after free in Core.
- [513256572] High CVE-2026-9995: Use after free in WebXR.
- [513268100] High CVE-2026-9996: Out of bounds read in WebRTC.
- [513324041] High CVE-2026-9997: Use after free in Input.
- [513337118] High CVE-2026-9998: Integer overflow in Skia.
- [513364480] High CVE-2026-9999: Inappropriate implementation in ANGLE.
- [513505608] High CVE-2026-10000: Use after free in Passwords.
- [513505927] High CVE-2026-10001: Use after free in PerformanceManager.
- [513536416] High CVE-2026-10002: Use after free in PDFium.
- [513609324] High CVE-2026-10003: Use after free in Views.
- [513730012] High CVE-2026-10004: Insufficient validation of untrusted input in Passwords.
- [513750089] High CVE-2026-10005: Use after free in WebAppInstalls.
- [513750691] High CVE-2026-10006: Race in WebAudio.
- [513754619] High CVE-2026-10007: Use after free in SVG.
- [513768979] High CVE-2026-10008: Uninitialized Use in GPU.
- [513973560] High CVE-2026-10009: Integer overflow in Skia.
- [513995565] High CVE-2026-10010: Inappropriate implementation in Input.
- [514017326] High CVE-2026-10011: Inappropriate implementation in Skia.
- [514063977] High CVE-2026-10012: Use after free in Skia.
- [514715455] High CVE-2026-10013: Use after free in WebCodecs.
- [514742327] High CVE-2026-10014: Use after free in WebMIDI.
- [514746176] High CVE-2026-10015: Integer overflow in WTF.
- [515155946] High CVE-2026-10016: Use after free in DOM.
- [504156069] Medium CVE-2026-10017: Out of bounds read in Headless.
- [504175501] Medium CVE-2026-10018: Integer overflow in ANGLE.
- [505056913] Medium CVE-2026-10019: Integer overflow in ANGLE.
- [496565479] Medium CVE-2026-10020: Insufficient validation of untrusted input in Skia.
- [497327715] Medium CVE-2026-10021: Insufficient validation of untrusted input in USB.
- [513289241] Medium CVE-2026-10022: Type Confusion in V8.
CVE-2026-9872
CVE-2026-9873
CVE-2026-9874
CVE-2026-9875
CVE-2026-9876
CVE-2026-9877
CVE-2026-9878
CVE-2026-9879
CVE-2026-9880
CVE-2026-9881
CVE-2026-9882
CVE-2026-9883
CVE-2026-9884
CVE-2026-9885
CVE-2026-9886
CVE-2026-9887
CVE-2026-9888
CVE-2026-9889
CVE-2026-9890
CVE-2026-9891
CVE-2026-9892
CVE-2026-9893
CVE-2026-9894
CVE-2026-9895
CVE-2026-9896
CVE-2026-9897
CVE-2026-9898
CVE-2026-9899
CVE-2026-9900
CVE-2026-9901
CVE-2026-9902
CVE-2026-9903
CVE-2026-9904
CVE-2026-9905
CVE-2026-9906
CVE-2026-9907
CVE-2026-9908
CVE-2026-9909
CVE-2026-9910
CVE-2026-9911
CVE-2026-9912
CVE-2026-9913
CVE-2026-9914
CVE-2026-9915
CVE-2026-9916
CVE-2026-9917
CVE-2026-9918
CVE-2026-9919
CVE-2026-9920
CVE-2026-9921
CVE-2026-9922
CVE-2026-9923
CVE-2026-9924
CVE-2026-9925
CVE-2026-9926
CVE-2026-9927
CVE-2026-9928
CVE-2026-9929
CVE-2026-9930
CVE-2026-9931
CVE-2026-9932
CVE-2026-9933
CVE-2026-9934
CVE-2026-9935
CVE-2026-9936
CVE-2026-9937
CVE-2026-9938
CVE-2026-9939
CVE-2026-9940
CVE-2026-9941
CVE-2026-9942
CVE-2026-9943
CVE-2026-9944
CVE-2026-9945
CVE-2026-9946
CVE-2026-9947
CVE-2026-9948
CVE-2026-9949
CVE-2026-9950
CVE-2026-9951
CVE-2026-9952
CVE-2026-9953
CVE-2026-9954
CVE-2026-9955
CVE-2026-9956
CVE-2026-9957
CVE-2026-9958
CVE-2026-9959
CVE-2026-9960
CVE-2026-9961
CVE-2026-9962
CVE-2026-9963
CVE-2026-9964
CVE-2026-9965
CVE-2026-9966
CVE-2026-9967
CVE-2026-9968
CVE-2026-9969
CVE-2026-9970
CVE-2026-9971
CVE-2026-9972
CVE-2026-9973
CVE-2026-9974
CVE-2026-9975
CVE-2026-9976
CVE-2026-9977
CVE-2026-9978
CVE-2026-9979
CVE-2026-9980
CVE-2026-9981
CVE-2026-9982
CVE-2026-9983
CVE-2026-9984
CVE-2026-9985
CVE-2026-9986
CVE-2026-9987
CVE-2026-9988
CVE-2026-9989
CVE-2026-9990
CVE-2026-9991
CVE-2026-9992
CVE-2026-9993
CVE-2026-9994
CVE-2026-9995
CVE-2026-9996
CVE-2026-9997
CVE-2026-9998
CVE-2026-9999
CVE-2026-10000
CVE-2026-10001
CVE-2026-10002
CVE-2026-10003
CVE-2026-10004
CVE-2026-10005
CVE-2026-10006
CVE-2026-10007
CVE-2026-10008
CVE-2026-10009
CVE-2026-10010
CVE-2026-10011
CVE-2026-10012
CVE-2026-10013
CVE-2026-10014
CVE-2026-10015
CVE-2026-10016
CVE-2026-10017
CVE-2026-10018
CVE-2026-10019
CVE-2026-10020
CVE-2026-10021
CVE-2026-10022
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
2026-05-27
2026-05-30
www/gohugo -- CWE-79: XSS vulnerabilities
gohugo
0.162.0,1
https://go.dev/issue/78913 reports:
CVE-2026-27142 fixed a vulnerability in which URLs were
not correctly escaped inside of a <meta> tag's
<content> attribute. If the URL content were to
insert ASCII whitespaces around the '=' rune inside of the
<content> attribute, the escaper would fail to
similarly escape it, leading to XSS.
If a trusted template author were to write a <script>
tag containing an empty 'type' attribute or a 'type'
attribute with an ASCII whitespace, the execution of the
template would incorrectly escape any data passed into the
<script> block.
CVE-2026-39823
https://cveawg.mitre.org/api/cve/CVE-2026-39823
CVE-2026-39826
https://cveawg.mitre.org/api/cve/CVE-2026-39826
2026-05-07
2026-05-29
MariaDB -- Multiple vulnerabilities
mariadb118-server
11.8.8
mariadb114-server
11.4.12
mariadb1011-server
10.11.18
mariadb106-server
10.6.27
The MariaDB project reports:
Multiple vulnerabilities in MariaDB Cluster (Galera)
CVE-2026-48165
CVE-2026-48163
CVE-2026-49261
https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8
https://mariadb.com/docs/release-notes/community-server/11.4/11.4.12
https://mariadb.com/docs/release-notes/community-server/10.11/10.11.8
https://mariadb.com/docs/release-notes/community-server/10.6/10.6.27
2026-05-28
2026-05-29
2026-05-30
mail/mailpit -- memory-exhaustion DoS via unbounded JSON body
mailpit
1.30.1
Mailpit author reports:
Sibling-endpoint memory-exhaustion DoS via unbounded
JSON body on /api/v1/messages, /api/v1/tags, and
/api/v1/message/{id}/release
CVE-2026-48824
https://github.com/axllent/mailpit/security/advisories/GHSA-28pq-6qxg-wg5r
2026-05-28
2026-05-28
OpenEXR -- 3.4.12 fixes multiple vulnerabilities
openexr
3.4.12
Cary Phillips reports:
[The OpenEXR 3.4.12] release addresses the following security vulnerabilities:
- CVE-2026-45696 OpenEXR ht_undo_impl heap-buffer-overflow READ via codestream/channel width mismatch in HTJ2K decode
- CVE-2026-44663 Integer overflow in HTJ2K decoder ( ht_undo_impl ) leading to heap-buffer-overflow
- OSS-Fuzz 512895184 Null-dereference WRITE in Imf_4_0::TileProcess::run_decode
- OSS-fuzz 512314697 Direct-leak in internal_exr_add_part
- OSS-fuzz 508362159 Heap-buffer-overflow in DwaCompressor_uncompress
- OSS-fuzz 507413960 Heap-buffer-overflow in generic_unpack
CVE-2026-45696
CVE-2026-44663
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.12
2026-05-25
2026-05-25
Erlang/OTP -- TLS hostname verification bypass via Subject CommonName fallback and name constraints
erlang
19.3,326.2.5.21,4
erlang-runtime27
27.3.4.12
erlang-runtime28
28.5.0.1
erlang-runtime29
29.0.1
https://github.com/erlang/otp/security/advisories/GHSA-22cw-4ph4-6447 reports:
Erlang/OTP's TLS hostname verification implements a legacy
RFC 6125 fallback that checks the Subject CommonName when the
Subject Alternative Name (SAN) extension is absent, rather
than following RFC 9525 which requires validation to fail
without SAN. Combined with weak handling of X.509 Name
Constraints, this enables man-in-the-middle attacks when an
attacker controls a DNS-constrained sub-CA and can intercept
network traffic, allowing forgery of certificates for
unauthorized domains.
CVE-2026-42790
https://github.com/erlang/otp/security/advisories/GHSA-22cw-4ph4-6447
2026-05-27
2026-05-28
Erlang/OTP -- public_key accepts non-CA certificate as intermediate issuer
erlang
17.0,326.2.5.21,4
erlang-runtime27
27.3.4.12
erlang-runtime28
28.5.0.1
erlang-runtime29
29.0.1
https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq reports:
Erlang/OTP's public_key application contains a
path-validation flaw where non-CA certificates lacking
keyUsage extensions can be accepted as intermediate issuers.
An attacker with an end-entity certificate issued by a
trusted CA can exploit this to forge arbitrary leaf
certificates, allowing public_key:pkix_path_validation/3 to
validate fraudulent certificate chains and potentially
compromise systems relying on SSL/TLS validation.
CVE-2026-42789
https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq
2026-05-27
2026-05-28
Erlang/OTP -- OCSP responder certificate accepted after expiry in public_key
erlang-runtime27
27.3.4.12
erlang-runtime28
28.5.0.1
erlang-runtime29
29.0.1
https://github.com/erlang/otp/security/advisories/GHSA-cjxj-wj6x-3fff reports:
Erlang/OTP's public_key application fails to validate the
validity period of OCSP responder certificates during
response verification. An attacker possessing an expired
OCSP responder's private key can forge responses that the
system accepts as valid, potentially allowing acceptance of
revoked TLS certificates in OCSP stapling scenarios or
authentication bypass in applications using the
public_key:pkix_ocsp_validate/5 API directly.
CVE-2026-42791
https://github.com/erlang/otp/security/advisories/GHSA-cjxj-wj6x-3fff
2026-05-27
2026-05-28
Grafana -- Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
grafana
11.6.011.6.14
12.1.012.1.10
12.2.012.2.8
12.3.012.3.6
12.4.012.4.2
https://grafana.com/security/security-advisories/cve-2026-33375 reports:
The Grafana MSSQL data source plugin contains a logic flaw that
allows a low-privileged user (Viewer) to bypass API restrictions
and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion,
crashing the host container.
CVE-2026-33375
https://cveawg.mitre.org/api/cve/CVE-2026-33375
2026-03-26
2026-05-26
Grafana -- Grafana Testdata datasource can issue unbounded memory allocations
grafana
8.1.011.6.14
12.0.012.1.10
12.2.012.2.8
12.3.012.3.6
12.4.012.4.2
https://grafana.com/security/security-advisories/cve-2026-28375 reports:
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-28375
https://cveawg.mitre.org/api/cve/CVE-2026-28375
2026-03-27
2026-05-26
Grafana -- OpenFeature evaluation API reads input data with no bounds
grafana
12.1.012.1.10
12.2.012.2.8
12.3.012.3.6
12.4.012.4.2
https://grafana.com/security/security-advisories/cve-2026-27880 reports:
The OpenFeature feature toggle evaluation endpoint reads unbounded
values into memory, which can cause out-of-memory crashes.
CVE-2026-27880
https://cveawg.mitre.org/api/cve/CVE-2026-27880
2026-03-27
2026-05-26
Grafana -- Query resampling can cause unbounded memory allocations
grafana
8.0.011.6.14
12.0.012.1.10
12.2.012.2.8
12.3.012.3.6
12.4.012.4.2
https://grafana.com/security/security-advisories/cve-2026-27879 reports:
A resample query can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-27879
https://cveawg.mitre.org/api/cve/CVE-2026-27879
2026-03-27
2026-05-26
Grafana -- Public dashboards discloses all direct mode datasources
grafana
9.3.011.6.14
12.0.012.1.10
12.2.012.2.8
12.3.012.3.6
12.4.012.4.2
https://grafana.com/security/security-advisories/cve-2026-27877 reports:
When using public dashboards and direct data-sources, all direct
data-sources' passwords are exposed despite not being used in dashboards.
No passwords of proxied data-sources are exposed. We encourage all
direct data-sources to be converted to proxied data-sources as far
as possible to improve your deployments' security.
CVE-2026-27877
https://cveawg.mitre.org/api/cve/CVE-2026-27877
2026-03-27
2026-05-26
Grafana -- RCE on Grafana via sqlExpressions
grafana
11.6.011.6.14
12.0.012.1.10
12.2.012.2.8
12.3.012.3.6
12.4.012.4.2
https://grafana.com/security/security-advisories/cve-2026-27876 reports:
A chained attack via SQL Expressions and a Grafana Enterprise plugin
can lead to a remote arbitrary code execution impact (RCE). This
is enabled by a feature in Grafana (OSS), so all users are always
recommended to update to avoid future attack vectors going this
path.
Only instances with the sqlExpressions feature toggle enabled are
vulnerable.
CVE-2026-27876
https://cveawg.mitre.org/api/cve/CVE-2026-27876
2026-03-27
2026-05-26
Grafana -- Public Dashboards time range restriction on annotations can be bypassed
grafana
9.3.011.6.10
12.0.012.1.6
12.2.012.2.4
12.3.012.3.2
https://grafana.com/security/security-advisories/cve-2026-21722 reports:
Public dashboards with annotations enabled did not limit their
annotation timerange to the locked timerange of the public dashboard.
This means one could read the entire history of annotations visible
on the specific dashboard, even those outside the locked timerange.
This did not leak any annotations that would not otherwise be visible
on the public dashboard.
CVE-2026-21722
https://cveawg.mitre.org/api/cve/CVE-2026-21722
2026-02-12
2026-05-26
Grafana -- XSS in Grafana Explore stack trace
grafana
12.2.012.2.4
12.3.012.3.2
https://grafana.com/security/security-advisories/cve-2025-41117 reports:
Stack traces in Grafana's Explore Traces view can be rendered as
raw HTML, and thus inject malicious JavaScript in the browser. This
would require malicious JavaScript to be entered into the stack
trace field.
Only datasources with the Jaeger HTTP API appear to be affected;
Jaeger gRPC and Tempo do not appear affected whatsoever.
CVE-2025-41117
https://cveawg.mitre.org/api/cve/CVE-2025-41117
2026-02-12
2026-05-26
jellyfin -- multiple vulnerabilities
jellyfin
10.11.10
The Jellyfin project reports:
Jellyfin Server 10.11.10 fixes three security vulnerabilities:
- GHSA-f47c-m7gr-q92j: (details pending disclosure)
- GHSA-jg92-mrxq-vv75: (details pending disclosure)
- GHSA-wwwm-px48-fpvq: (details pending disclosure)
https://github.com/jellyfin/jellyfin/security/advisories/GHSA-f47c-m7gr-q92j
https://github.com/jellyfin/jellyfin/security/advisories/GHSA-jg92-mrxq-vv75
https://github.com/jellyfin/jellyfin/security/advisories/GHSA-wwwm-px48-fpvq
https://github.com/jellyfin/jellyfin/releases/tag/v10.11.10
2026-05-24
2026-05-25
Roundcube Webmail -- Multiple vulnerabilities
roundcube-php82
roundcube-php83
roundcube-php84
roundcube-php85
1.6.16,1
1.7.0,11.7.1,1
The Roundcube Webmail project reports:
See link for details. No CVE numbers available at the moment.
https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
2026-05-24
2026-05-24
traefik -- Unauthorized exposure of the REST provider
traefik
3.7.1
The traefik project releases a new version addressing a CVE:
- CVE-2026-44774 (Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider)
CVE-2026-44774
https://github.com/traefik/traefik/releases/tag/v3.7.1
2026-05-15
2026-05-24
nginx -- heap buffer overflow in ngx_http_rewrite_module
nginx
0.1.17,31.30.2_2,3
1.31.0,31.31.1,3
The nginx developers report:
A heap memory buffer overflow might occur in a worker process
when using a configuration with overlapping captures in
ngx_http_rewrite_module, potentially resulting in arbitrary
code execution (CVE-2026-9256).
CVE-2026-9256
https://nginx.org/en/CHANGES
2026-05-22
2026-05-22
putty -- multiple security vulnerabilities
putty 0.84
putty-nogtk 0.84
Simon Tatham reports:
These features are new in PuTTY 0.84:
- Security issue: fixed a remotely triggerable double-free in RSA key exchange. (We don't know of any way it is exploitable to execute code.)
- Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. (An assertion failure – definitely not exploitable to execute code.)
- Minor security issue: fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt).
https://lists.tartarus.org/pipermail/putty-announce/2026/000042.html
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
2026-05-22
2026-05-22
gstreamer1 -- multiple vulnerabilities
gstreamer1
1.28.3
gstreamer1-plugins
1.28.3
gstreamer1-plugins-base
1.28.3
gstreamer1-plugins-good
1.28.3
gstreamer1-plugins-bad
1.28.3
gstreamer1-plugins-ugly
1.28.3
The GStreamer project reports multiple security vulnerabilities fixed in the 1.28.3 release:
Six security vulnerabilities were addressed, including:
- Bounds check errors in MXF VANC packet handling.
- Use-after-free in GStreamer core buffer value deserialization.
- Out-of-bounds read in MXF demuxer temporal offset check.
- Out-of-bounds write in H.266/VVC parser when parsing PPS tile slices.
- Insufficient validation in MOV/MP4 demuxer uncompressed video handling.
- Out-of-bounds reads in MPEG PS PES header parsing.
These could lead to application crashes, memory corruption, or potentially arbitrary code execution.
https://gstreamer.freedesktop.org/security/sa-2026-0024.html
https://gstreamer.freedesktop.org/security/sa-2026-0025.html
https://gstreamer.freedesktop.org/security/sa-2026-0026.html
https://gstreamer.freedesktop.org/security/sa-2026-0027.html
https://gstreamer.freedesktop.org/security/sa-2026-0028.html
https://gstreamer.freedesktop.org/security/sa-2026-0029.html
2026-05-11
2026-05-22
gstreamer1 -- multiple vulnerabilities
gstreamer1
1.28.2
gstreamer1-plugins
1.28.2
gstreamer1-plugins-base
1.28.2
gstreamer1-plugins-good
1.28.2
gstreamer1-plugins-bad
1.28.2
gstreamer1-plugins-ugly
1.28.2
The GStreamer project reports multiple security vulnerabilities fixed in the 1.28.2 release:
Several security vulnerabilities were addressed, including:
- H.264 video parser NULL pointer dereference when freeing SPS/MVC data.
- Integer overflows in the AV1 LEB128 parser, H.266/VVC video parser, and WAV parser cue handling.
- Heap buffer overflow in the Matroska demuxer.
- Assertion failures in the FLV demuxer on corrupted streams.
- NULL-pointer dereferences in the mDVDsub subtitle parser.
- Multiple out-of-bounds reads and writes in the MOV/MP4 demuxer audio channel layout parsing.
- Denial of service in SRT/WebVTT parser
These could lead to application crashes, memory exhaustion, or potentially arbitrary code execution.
CVE-2026-5056
CVE-2026-39043
CVE-2026-39044
CVE-2026-46469
CVE-2026-46470
CVE-2026-46472
https://gstreamer.freedesktop.org/security/sa-2026-0013.html
https://gstreamer.freedesktop.org/security/sa-2026-0014.html
https://gstreamer.freedesktop.org/security/sa-2026-0015.html
https://gstreamer.freedesktop.org/security/sa-2026-0017.html
https://gstreamer.freedesktop.org/security/sa-2026-0018.html
https://gstreamer.freedesktop.org/security/sa-2026-0019.html
https://gstreamer.freedesktop.org/security/sa-2026-0020.html
https://gstreamer.freedesktop.org/security/sa-2026-0021.html
https://gstreamer.freedesktop.org/security/sa-2026-0022.html
https://gstreamer.freedesktop.org/security/sa-2026-0023.html
2026-04-07
2026-05-22
qt6-webengine -- multiple vulnerabilities
qt6-pdf
qt6-webengine
6.11.1
Qt qtwebengine-chromium repo reports:
Backports for 262 security bugs in Chromium:
- CVE-2025-13223: Type Confusion in V8
- CVE-2025-13224: Type Confusion in V8
- CVE-2025-13630: Type Confusion in V8
- CVE-2025-13632: Inappropriate implementation in DevTools
- CVE-2025-13634: Inappropriate implementation in Downloads
- CVE-2025-13721: Race in v8
- CVE-2025-14766: Out of bounds read and write in V8
- CVE-2026-0628: Insufficient policy enforcement in WebView tag
- CVE-2026-0899: Out of bounds memory access in V8
- CVE-2026-0902: Inappropriate implementation in V8
- CVE-2026-0905: Insufficient policy enforcement in Network
- CVE-2026-1220: Description pending NVD publication
- CVE-2026-1861: Heap buffer overflow in libvpx
- CVE-2026-2314: Heap buffer overflow in Codecs
- CVE-2026-2315: Inappropriate implementation in WebGPU
- CVE-2026-2316: Insufficient policy enforcement in Frames
- CVE-2026-2317: Inappropriate implementation in Animation
- CVE-2026-2319: Race in DevTools
- CVE-2026-2320: Inappropriate implementation in File input
- CVE-2026-2441: Use after free in CSS
- CVE-2026-2648: Heap buffer overflow in PDFium
- CVE-2026-2649: Integer overflow in V8
- CVE-2026-2650: Heap buffer overflow in Media
- CVE-2026-3061: Out of bounds read in Media
- CVE-2026-3062: Out of bounds read and write in Tint
- CVE-2026-3063: Inappropriate implementation in DevTools
- CVE-2026-3536: Integer overflow in ANGLE
- CVE-2026-3537: Object lifecycle issue in PowerVR
- CVE-2026-3538: Integer overflow in Skia
- CVE-2026-3539: Object lifecycle issue in DevTools
- CVE-2026-3540: Inappropriate implementation in WebAudio
- CVE-2026-3541: Inappropriate implementation in CSS
- CVE-2026-3542: Inappropriate implementation in WebAssembly
- CVE-2026-3543: Inappropriate implementation in V8
- CVE-2026-3544: Heap buffer overflow in WebCodecs
- CVE-2026-3545: Insufficient data validation in Navigation
- CVE-2026-3909: Out of bounds write in Skia
- CVE-2026-3910: Inappropriate implementation in V8
- CVE-2026-3919: Use after free in Extensions
- CVE-2026-3921: Use after free in TextEncoding
- CVE-2026-3922: Use after free in MediaStream
- CVE-2026-3923: Use after free in WebMIDI
- CVE-2026-3924: use after free in WindowDialog
- CVE-2026-3926: Out of bounds read in V8
- CVE-2026-3929: Side-channel information leakage in ResourceTiming
- CVE-2026-3931: Heap buffer overflow in Skia
- CVE-2026-3934: Insufficient policy enforcement in ChromeDriver
- CVE-2026-3938: Insufficient policy enforcement in Clipboard
- CVE-2026-3940: Insufficient policy enforcement in DevTools
- CVE-2026-3941: Insufficient policy enforcement in DevTools
- CVE-2026-3942: Incorrect security UI in PictureInPicture
- CVE-2026-4440: Out of bounds read and write in WebGL
- CVE-2026-4441: Use after free in Base
- CVE-2026-4442: Heap buffer overflow in CSS
- CVE-2026-4443: Heap buffer overflow in WebAudio
- CVE-2026-4444: Stack buffer overflow in WebRTC
- CVE-2026-4445: Use after free in WebRTC
- CVE-2026-4446: Use after free in WebRTC
- CVE-2026-4448: Heap buffer overflow in ANGLE
- CVE-2026-4449: Use after free in Blink
- CVE-2026-4450: Out of bounds write in V8
- CVE-2026-4451: Insufficient validation of untrusted input in Navigation
- CVE-2026-4452: Integer overflow in ANGLE
- CVE-2026-4453: Integer overflow in Dawn
- CVE-2026-4454: Use after free in Network
- CVE-2026-4455: Heap buffer overflow in PDFium
- CVE-2026-4457: Type Confusion in V8
- CVE-2026-4458: Use after free in Extensions
- CVE-2026-4459: Out of bounds read and write in WebAudio
- CVE-2026-4460: Out of bounds read in Skia
- CVE-2026-4462: Out of bounds read in Blink
- CVE-2026-4463: Heap buffer overflow in WebRTC
- CVE-2026-4464: Integer overflow in ANGLE
- CVE-2026-4674: Out of bounds read in CSS
- CVE-2026-4675: Heap buffer overflow in WebGL
- CVE-2026-4677: Out of bounds read in WebAudio
- CVE-2026-4679: Integer overflow in Fonts
- CVE-2026-5272: Heap buffer overflow in GPU
- CVE-2026-5273: Use after free in CSS
- CVE-2026-5274: Integer overflow in Codecs
- CVE-2026-5275: Heap buffer overflow in ANGLE
- CVE-2026-5276: Insufficient policy enforcement in WebUSB
- CVE-2026-5277: Integer overflow in ANGLE
- CVE-2026-5279: Object corruption in V8
- CVE-2026-5280: Use after free in WebCodecs
- CVE-2026-5281: Use after free in Dawn
- CVE-2026-5282: Out of bounds read in WebCodecs
- CVE-2026-5283: Inappropriate implementation in ANGLE
- CVE-2026-5284: Use after free in Dawn
- CVE-2026-5285: Use after free in WebGL
- CVE-2026-5287: Use after free in PDF
- CVE-2026-5289: Use after free in Navigation
- CVE-2026-5290: Use after free in Compositing
- CVE-2026-5291: Inappropriate implementation in WebGL
- CVE-2026-5292: Out of bounds read in WebCodecs
- CVE-2026-5860: Use after free in WebRTC
- CVE-2026-5861: Use after free in V8
- CVE-2026-5862: Inappropriate implementation in V8
- CVE-2026-5863: Inappropriate implementation in V8
- CVE-2026-5865: Type Confusion in V8
- CVE-2026-5866: Use after free in Media
- CVE-2026-5868: Heap buffer overflow in ANGLE
- CVE-2026-5870: Integer overflow in Skia
- CVE-2026-5871: Type Confusion in V8
- CVE-2026-5872: Use after free in Blink
- CVE-2026-5873: Out of bounds read and write in V8
- CVE-2026-5875: Policy bypass in Blink
- CVE-2026-5876: Side-channel information leakage in Navigation
- CVE-2026-5877: Use after free in Navigation
- CVE-2026-5878: Incorrect security UI in Blink
- CVE-2026-5879: Insufficient validation of untrusted input in ANGLE
- CVE-2026-5880: Incorrect security UI in browser UI
- CVE-2026-5882: Incorrect security UI in Fullscreen
- CVE-2026-5883: Use after free in Media
- CVE-2026-5884: Insufficient validation of untrusted input in Media
- CVE-2026-5885: Insufficient validation of untrusted input in WebML
- CVE-2026-5886: Out of bounds read in WebAudio
- CVE-2026-5888: Uninitialized Use in WebCodecs
- CVE-2026-5889: Cryptographic Flaw in PDFium
- CVE-2026-5890: Race in WebCodecs
- CVE-2026-5891: Insufficient policy enforcement in browser UI
- CVE-2026-5893: Race in V8
- CVE-2026-5894: Inappropriate implementation in PDF
- CVE-2026-5896: Policy bypass in Audio
- CVE-2026-5899: Incorrect security UI in History Navigation
- CVE-2026-5900: Policy bypass in Downloads
- CVE-2026-5901: Policy bypass in DevTools
- CVE-2026-5903: Policy bypass in IFrameSandbox
- CVE-2026-5904: Use after free in V8
- CVE-2026-5907: Insufficient data validation in Media
- CVE-2026-5908: Integer overflow in Media
- CVE-2026-5909: Integer overflow in Media
- CVE-2026-5910: Integer overflow in Media
- CVE-2026-5911: Policy bypass in ServiceWorkers
- CVE-2026-5912: Integer overflow in WebRTC
- CVE-2026-5913: Out of bounds read in Blink
- CVE-2026-5914: Type Confusion in CSS
- CVE-2026-5915: Insufficient validation of untrusted input in WebML
- CVE-2026-5918: Inappropriate implementation in Navigation
- CVE-2026-5919: Insufficient validation of untrusted input in WebSockets
- CVE-2026-6296: Heap buffer overflow in ANGLE
- CVE-2026-6297: Use after free in Proxy
- CVE-2026-6298: Heap buffer overflow in Skia
- CVE-2026-6299: Use after free in Prerender
- CVE-2026-6300: Use after free in CSS
- CVE-2026-6301: Type Confusion in Turbofan
- CVE-2026-6302: Use after free in Video
- CVE-2026-6303: Use after free in Codecs
- CVE-2026-6304: Use after free in Graphite
- CVE-2026-6305: Heap buffer overflow in PDFium
- CVE-2026-6306: Heap buffer overflow in PDFium
- CVE-2026-6307: Type Confusion in Turbofan
- CVE-2026-6308: Out of bounds read in Media
- CVE-2026-6309: Use after free in Viz
- CVE-2026-6311: Uninitialized Use in Accessibility
- CVE-2026-6312: Insufficient policy enforcement in Passwords
- CVE-2026-6313: Insufficient policy enforcement in CORS
- CVE-2026-6314: Out of bounds write in GPU
- CVE-2026-6316: Use after free in Forms
- CVE-2026-6359: Use after free in Video
- CVE-2026-6360: Use after free in FileSystem
- CVE-2026-6361: Heap buffer overflow in PDFium
- CVE-2026-6362: Use after free in Codecs
- CVE-2026-6363: Type Confusion in V8
- CVE-2026-6364: Out of bounds read in Skia
- CVE-2026-6919: Use after free in DevTools
- CVE-2026-6920: Out of bounds read in GPU
- CVE-2026-7333: Use after free in GPU
- CVE-2026-7335: Use after free in media
- CVE-2026-7336: Use after free in WebRTC
- CVE-2026-7339: Heap buffer overflow in WebRTC
- CVE-2026-7340: Integer overflow in ANGLE
- CVE-2026-7341: Use after free in WebRTC
- CVE-2026-7342: Use after free in WebView
- CVE-2026-7343: Use after free in Views
- CVE-2026-7344: Use after free in Accessibility
- CVE-2026-7345: Insufficient validation of untrusted input in Feedback
- CVE-2026-7346: Inappropriate implementation in Tint
- CVE-2026-7348: Use after free in Codecs
- CVE-2026-7349: Use after free in Cast
- CVE-2026-7350: Use after free in WebMIDI
- CVE-2026-7351: Race in MHTML
- CVE-2026-7353: Heap buffer overflow in Skia
- CVE-2026-7354: Out of bounds read and write in Angle
- CVE-2026-7355: Use after free in Media
- CVE-2026-7356: Use after free in Navigation
- CVE-2026-7357: Use after free in GPU
- CVE-2026-7359: Use after free in ANGLE
- CVE-2026-7360: Insufficient validation of untrusted input in Compositing
- CVE-2026-7363: Use after free in Canvas
- CVE-2026-7899: Out of bounds read and write in V8
- CVE-2026-7900: Heap buffer overflow in ANGLE
- CVE-2026-7901: Use after free in ANGLE
- CVE-2026-7902: Out of bounds memory access in V8
- CVE-2026-7903: Integer overflow in ANGLE
- CVE-2026-7904: Out of bounds read in Fonts
- CVE-2026-7906: Use after free in SVG
- CVE-2026-7907: Use after free in DOM
- CVE-2026-7908: Use after free in Fullscreen
- CVE-2026-7910: Use after free in Views
- CVE-2026-7912: Integer overflow in GPU
- CVE-2026-7914: Type Confusion in Accessibility
- CVE-2026-7916: Insufficient data validation in InterestGroups
- CVE-2026-7917: Use after free in Fullscreen
- CVE-2026-7918: Use after free in GPU
- CVE-2026-7919: Use after free in Aura
- CVE-2026-7920: Use after free in Skia
- CVE-2026-7921: Use after free in Passwords
- CVE-2026-7922: Use after free in ServiceWorker
- CVE-2026-7923: Out of bounds write in Skia
- CVE-2026-7924: Uninitialized Use in Dawn
- CVE-2026-7926: Use after free in PresentationAPI
- CVE-2026-7927: Type Confusion in Runtime
- CVE-2026-7929: Use after free in MediaRecording
- CVE-2026-7933: Out of bounds read in WebCodecs
- CVE-2026-7935: Inappropriate implementation in Speech
- CVE-2026-7937: Insufficient policy enforcement in DevTools
- CVE-2026-7938: Use after free in CSS
- CVE-2026-7940: Use after free in V8
- CVE-2026-7942: Integer overflow in ANGLE
- CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache
- CVE-2026-7945: Insufficient validation of untrusted input in COOP
- CVE-2026-7946: Insufficient policy enforcement in WebUI
- CVE-2026-7947: Insufficient validation of untrusted input in Network
- CVE-2026-7949: Out of bounds read in Skia
- CVE-2026-7950: Out of bounds read and write in GFX
- CVE-2026-7951: Out of bounds write in WebRTC
- CVE-2026-7954: Race in Shared Storage
- CVE-2026-7955: Uninitialized Use in GPU
- CVE-2026-7956: Use after free in Navigation
- CVE-2026-7957: Out of bounds write in Media
- CVE-2026-7959: Inappropriate implementation in Navigation
- CVE-2026-7963: Inappropriate implementation in ServiceWorker
- CVE-2026-7964: Insufficient validation of untrusted input in FileSystem
- CVE-2026-7965: Insufficient validation of untrusted input in DevTools
- CVE-2026-7967: Insufficient validation of untrusted input in Navigation
- CVE-2026-7968: Insufficient validation of untrusted input in CORS
- CVE-2026-7969: Integer overflow in Network
- CVE-2026-7971: Inappropriate implementation in ORB
- CVE-2026-7972: Uninitialized Use in GPU
- CVE-2026-7973: Integer overflow in Dawn
- CVE-2026-7974: Use after free in Blink
- CVE-2026-7975: Use after free in DevTools
- CVE-2026-7976: Use after free in Views
- CVE-2026-7977: Inappropriate implementation in Canvas
- CVE-2026-7980: Use after free in WebAudio
- CVE-2026-7982: Uninitialized Use in WebCodecs
- CVE-2026-7983: Out of bounds read in Dawn
- CVE-2026-7985: Use after free in GPU
- CVE-2026-7986: Insufficient policy enforcement in Autofill
- CVE-2026-7987: Use after free in WebRTC
- CVE-2026-7988: Type Confusion in WebRTC
- CVE-2026-7989: Insufficient data validation in DataTransfer
- CVE-2026-7991: Use after free in UI
- CVE-2026-7993: Insufficient validation of untrusted input in Payments
- CVE-2026-7996: Insufficient validation of untrusted input in SSL
- CVE-2026-7998: Insufficient validation of untrusted input in Dialog
- CVE-2026-7999: Inappropriate implementation in V8
- CVE-2026-8002: Use after free in Audio
- CVE-2026-8003: Insufficient validation of untrusted input in TabGroups
- CVE-2026-8004: Insufficient policy enforcement in DevTools
- CVE-2026-8007: Insufficient validation of untrusted input in Cast
CVE-2025-13223
CVE-2025-13224
CVE-2025-13630
CVE-2025-13632
CVE-2025-13634
CVE-2025-13721
CVE-2025-14766
CVE-2026-0628
CVE-2026-0899
CVE-2026-0902
CVE-2026-0905
CVE-2026-1220
CVE-2026-1861
CVE-2026-2314
CVE-2026-2315
CVE-2026-2316
CVE-2026-2317
CVE-2026-2319
CVE-2026-2320
CVE-2026-2441
CVE-2026-2648
CVE-2026-2649
CVE-2026-2650
CVE-2026-3061
CVE-2026-3062
CVE-2026-3063
CVE-2026-3536
CVE-2026-3537
CVE-2026-3538
CVE-2026-3539
CVE-2026-3540
CVE-2026-3541
CVE-2026-3542
CVE-2026-3543
CVE-2026-3544
CVE-2026-3545
CVE-2026-3909
CVE-2026-3910
CVE-2026-3919
CVE-2026-3921
CVE-2026-3922
CVE-2026-3923
CVE-2026-3924
CVE-2026-3926
CVE-2026-3929
CVE-2026-3931
CVE-2026-3934
CVE-2026-3938
CVE-2026-3940
CVE-2026-3941
CVE-2026-3942
CVE-2026-4440
CVE-2026-4441
CVE-2026-4442
CVE-2026-4443
CVE-2026-4444
CVE-2026-4445
CVE-2026-4446
CVE-2026-4448
CVE-2026-4449
CVE-2026-4450
CVE-2026-4451
CVE-2026-4452
CVE-2026-4453
CVE-2026-4454
CVE-2026-4455
CVE-2026-4457
CVE-2026-4458
CVE-2026-4459
CVE-2026-4460
CVE-2026-4462
CVE-2026-4463
CVE-2026-4464
CVE-2026-4674
CVE-2026-4675
CVE-2026-4677
CVE-2026-4679
CVE-2026-5272
CVE-2026-5273
CVE-2026-5274
CVE-2026-5275
CVE-2026-5276
CVE-2026-5277
CVE-2026-5279
CVE-2026-5280
CVE-2026-5281
CVE-2026-5282
CVE-2026-5283
CVE-2026-5284
CVE-2026-5285
CVE-2026-5287
CVE-2026-5289
CVE-2026-5290
CVE-2026-5291
CVE-2026-5292
CVE-2026-5860
CVE-2026-5861
CVE-2026-5862
CVE-2026-5863
CVE-2026-5865
CVE-2026-5866
CVE-2026-5868
CVE-2026-5870
CVE-2026-5871
CVE-2026-5872
CVE-2026-5873
CVE-2026-5875
CVE-2026-5876
CVE-2026-5877
CVE-2026-5878
CVE-2026-5879
CVE-2026-5880
CVE-2026-5882
CVE-2026-5883
CVE-2026-5884
CVE-2026-5885
CVE-2026-5886
CVE-2026-5888
CVE-2026-5889
CVE-2026-5890
CVE-2026-5891
CVE-2026-5893
CVE-2026-5894
CVE-2026-5896
CVE-2026-5899
CVE-2026-5900
CVE-2026-5901
CVE-2026-5903
CVE-2026-5904
CVE-2026-5907
CVE-2026-5908
CVE-2026-5909
CVE-2026-5910
CVE-2026-5911
CVE-2026-5912
CVE-2026-5913
CVE-2026-5914
CVE-2026-5915
CVE-2026-5918
CVE-2026-5919
CVE-2026-6296
CVE-2026-6297
CVE-2026-6298
CVE-2026-6299
CVE-2026-6300
CVE-2026-6301
CVE-2026-6302
CVE-2026-6303
CVE-2026-6304
CVE-2026-6305
CVE-2026-6306
CVE-2026-6307
CVE-2026-6308
CVE-2026-6309
CVE-2026-6311
CVE-2026-6312
CVE-2026-6313
CVE-2026-6314
CVE-2026-6316
CVE-2026-6359
CVE-2026-6360
CVE-2026-6361
CVE-2026-6362
CVE-2026-6363
CVE-2026-6364
CVE-2026-6919
CVE-2026-6920
CVE-2026-7333
CVE-2026-7335
CVE-2026-7336
CVE-2026-7339
CVE-2026-7340
CVE-2026-7341
CVE-2026-7342
CVE-2026-7343
CVE-2026-7344
CVE-2026-7345
CVE-2026-7346
CVE-2026-7348
CVE-2026-7349
CVE-2026-7350
CVE-2026-7351
CVE-2026-7353
CVE-2026-7354
CVE-2026-7355
CVE-2026-7356
CVE-2026-7357
CVE-2026-7359
CVE-2026-7360
CVE-2026-7363
CVE-2026-7899
CVE-2026-7900
CVE-2026-7901
CVE-2026-7902
CVE-2026-7903
CVE-2026-7904
CVE-2026-7906
CVE-2026-7907
CVE-2026-7908
CVE-2026-7910
CVE-2026-7912
CVE-2026-7914
CVE-2026-7916
CVE-2026-7917
CVE-2026-7918
CVE-2026-7919
CVE-2026-7920
CVE-2026-7921
CVE-2026-7922
CVE-2026-7923
CVE-2026-7924
CVE-2026-7926
CVE-2026-7927
CVE-2026-7929
CVE-2026-7933
CVE-2026-7935
CVE-2026-7937
CVE-2026-7938
CVE-2026-7940
CVE-2026-7942
CVE-2026-7944
CVE-2026-7945
CVE-2026-7946
CVE-2026-7947
CVE-2026-7949
CVE-2026-7950
CVE-2026-7951
CVE-2026-7954
CVE-2026-7955
CVE-2026-7956
CVE-2026-7957
CVE-2026-7959
CVE-2026-7963
CVE-2026-7964
CVE-2026-7965
CVE-2026-7967
CVE-2026-7968
CVE-2026-7969
CVE-2026-7971
CVE-2026-7972
CVE-2026-7973
CVE-2026-7974
CVE-2026-7975
CVE-2026-7976
CVE-2026-7977
CVE-2026-7980
CVE-2026-7982
CVE-2026-7983
CVE-2026-7985
CVE-2026-7986
CVE-2026-7987
CVE-2026-7988
CVE-2026-7989
CVE-2026-7991
CVE-2026-7993
CVE-2026-7996
CVE-2026-7998
CVE-2026-7999
CVE-2026-8002
CVE-2026-8003
CVE-2026-8004
CVE-2026-8007
https://code.qt.io/cgit/qt/qtwebengine-chromium.git/log/?h=140-based
2026-01-29
2026-05-21
net/rsync -- multiple vulnerabilities
rsync
3.4.3
The rsync project reports:
Six CVEs are fixed in this release. All six are assigned by VulnCheck as CNA.
Affected versions are 3.4.2 and earlier in every case.
In addition to the six CVE fixes, this release adds defence-in-depth
hardening on several adjacent paths: bounded wire-supplied counts and
lengths in flist/io/acls/xattrs, a guard against length underflow in
cumulative snprintf() callers, a parent block-index bounds check on the
receiver, a NULL check in read_delay_line(), a lower ceiling on
MAX_WIRE_DEL_STAT to avoid signed-int overflow in the read_del_stats()
accumulator, rejection of hyphen-prefixed remote-shell hostnames
(defence-in-depth against argv-injection in tooling that forwards untrusted
input into the hostspec position; reported by Aisle Research via Michal
Ruprich), and a NULL-check on localtime_r() in timestring() to keep a
malicious server from crashing the client by advertising a file with an
out-of-range modtime.
CVE-2026-29518
CVE-2026-43617
CVE-2026-43618
CVE-2026-43619
CVE-2026-43620
CVE-2026-45232
https://download.samba.org/pub/rsync/NEWS#3.4.3
2026-05-20
2026-05-21
FreeBSD -- Incorrect libcap_net limitation list manipulation
FreeBSD
15.015.0_9
14.414.4_5
14.314.3_14
Problem Description:
In the case of the cap_net service, when a key present in the
old limit was omitted from the new limit, the missing key was treated
as "allow any" instead of being rejected.
Impact:
In certain scenarios, an application that had previously
restricted a subset of network operations could ask for a new limit
that extended the permissions of the process.
CVE-2026-45254
SA-26:24.cap_net
2026-05-20
2026-05-21
FreeBSD -- Remote code execution via installer Wi-Fi access point scans
FreeBSD
15.015.0_9
14.414.4_5
14.314.3_14
Problem Description:
When bsdinstall or bsdconfig are prompted to scan for nearby
Wi-Fi networks, they build up a list of network names and use
bsddialog(1) to prompt the user to select a network. This is
implemented using a shell script, and the code which handled network
names was not careful to prevent expansion by the shell. As a
result, a suitably crafted network name can be used to execute
commands via a subshell.
Impact:
The problem can be exploited to execute code as root on the
system running bsdinstall or bsdconfig. The attacker would need
to create an access point with a specially crafted name and be
within range of a Wi-Fi scan. Note that bsdinstall and bsdconfig
are vulnerable as soon as the user prompts them to scan for nearby
networks; they do not need to actually select the malicious
network.
CVE-2026-45255
SA-26:23.bsdinstall
2026-05-20
2026-05-21
FreeBSD -- select(2) file descriptor set overflow causes stack overflow
FreeBSD
15.015.0_9
14.414.4_5
14.314.3_14
Problem Description:
libcasper(3) communicates with helper processes via UNIX domain
sockets, and uses the select(2) system call to wait for data to
become available. However, it does not verify that its socket
descriptor fits within select(2)'s descriptor set size limit of
FD_SETSIZE (1024).
Impact:
An attacker able to cause an application using libcasper(3) to
allocate large file descriptors, e.g., by opening many descriptors
and executing a program which is not careful to close them upon
startup, may trigger stack corruption. If the target application
runs with setuid root privileges, this could be used to escalate
local privileges.
CVE-2026-39461
SA-26:22.libcasper
2026-05-20
2026-05-21
FreeBSD -- Missing validation in ptrace(PT_SC_REMOTE)
FreeBSD-kernel
15.015.0_9
14.414.4_5
14.314.3_14
Problem Description:
ptrace(PT_SC_REMOTE) failed to properly validate parameters for
the syscall(2) and __syscall(2) meta-system calls. As a result, a
user with the ability to debug a process may trigger arbitrary code
execution in the kernel, even if the target process has no special
privileges.
Impact:
The missing validation allows an unprivileged local user to
escalate privileges, potentially gaining full control of the affected
system.
CVE-2026-45253
SA-26:21.ptrace
2026-05-20
2026-05-21
FreeBSD -- Heap overflow in FUSE_LISTXATTR
FreeBSD-kernel
15.015.0_9
14.414.4_5
14.314.3_14
Problem Description:
When a fusefs file system implements extended attributes, the
kernel may send a FUSE_LISTXATTR message to the userspace daemon
to retrieve the list of extended attributes for a given file. The
FUSE protocol requires the daemon to return a packed list of
NUL-terminated strings. The fusefs kernel module calls strlen()
on this daemon-supplied buffer without first verifying that the
entire list is NUL-terminated.
Impact:
If a malicious daemon sends a non-NUL-terminated list, the
fusefs kernel module may read beyond the end of one heap-allocated
buffer and potentially write beyond the end of a second buffer. A
malicious daemon could disclose up to 253 bytes of kernel heap
memory, or it could inject up to 250 attacker-controlled bytes into
unallocated kernel heap space.
CVE-2026-45252
SA-26:20.fusefs
2026-05-20
2026-05-21
FreeBSD -- Kernel use-after-free via file descriptor syscalls
FreeBSD-kernel
15.015.0_9
14.414.4_5
14.314.3_14
Problem Description:
A file descriptor can be closed while a thread is blocked in a
poll(2) or select(2) call waiting for that descriptor. Because the
blocked thread does not hold a reference to the underlying object,
this closure may result in the object being freed while the thread
remains blocked. In this situation, the kernel must remove the
blocked thread from the per-object wait queue prior to freeing the
object.
In the case of some file descriptor types, the kernel failed to
unlink blocked threads from the object before freeing it. When the
blocked thread is subsequently woken, it accesses memory that has
already been freed resulting in a use-after-free vulnerability.
Impact:
The use-after-free vulnerability may be triggered by an
unprivileged local user and can be exploited to obtain superuser
privileges.
CVE-2026-45251
SA-26:19.file
2026-05-20
2026-05-21
FreeBSD -- Stack buffer overflow via setcred(2)
FreeBSD-kernel
15.015.0_9
14.414.4_5
14.314.3_14
Problem Description:
The setcred(2) system call is only available to privileged
users. However, before the privilege level of the caller is checked,
the user-supplied list of supplementary groups is copied into a
fixed-size kernel stack buffer without first validating its length.
If the supplied list exceeds the capacity of that buffer, a stack
buffer overflow occurs.
Impact:
Because the bounds check on the supplementary groups list occurs
after the kernel stack buffer has already been written, an unprivileged
local user may trigger the overflow without holding any special
privilege. Successful exploitation may allow an attacker to execute
arbitrary code in the context of the kernel, allowing an unprivileged
local user to gain elevated privileges on the affected system.
CVE-2026-45250
SA-26:18.setcred
2026-05-20
2026-05-21
nginx-devel -- multiple vulnerabilities
nginx-devel
1.31.0
The nginx project reports:
nginx 1.31.0 fixes multiple security issues affecting HTTP/2
proxying, rewrite handling, SCGI/uWSGI response handling, charset
conversion, HTTP/3 connection migration, and OCSP resolver response
processing.
CVE-2026-42926
CVE-2026-42945
CVE-2026-42946
CVE-2026-42934
CVE-2026-40460
CVE-2026-40701
https://nginx.org/en/CHANGES
https://nginx.org/en/security_advisories.html
2026-05-13
2026-05-19
MySQL -- Multiple vulnerabilities
mysql80-client
8.0.46
mysql84-client
8.4.9
mysql96-client
9.6.1
mysql80-server
8.0.46
mysql84-server
8.4.9
mysql96-server
9.6.1
Oracle reports:
See linked CVE's for details.
CVE-2025-15467
CVE-2026-34270
CVE-2026-34271
CVE-2026-34276
CVE-2026-34308
CVE-2026-22009
CVE-2026-22017
CVE-2026-34272
CVE-2026-34303
CVE-2025-14017
CVE-2026-34318
CVE-2026-34317
CVE-2026-34319
CVE-2026-22004
CVE-2026-34304
CVE-2026-35236
CVE-2026-35237
CVE-2026-35238
CVE-2026-34293
CVE-2026-35239
CVE-2026-35235
CVE-2026-21998
CVE-2026-22005
CVE-2026-22002
CVE-2026-34267
CVE-2026-34278
CVE-2026-35240
CVE-2026-35234
CVE-2026-22015
CVE-2026-22001
https://www.oracle.com/security-alerts/cpuapr2026.html
2026-04-21
2026-05-19
MariaDB -- Multiple vulnerabilities
mariadb118-client
11.8.7
mariadb114-client
11.4.11
mariadb1011-client
10.11.17
mariadb106-client
10.6.26
mariadb118-server
11.8.7
mariadb114-server
11.4.11
mariadb1011-server
10.11.17
mariadb106-server
10.6.26
The MariaDB project reports:
See linked CVE's for details.
CVE-2026-44173
CVE-2026-44172
CVE-2026-44171
CVE-2026-44170
CVE-2026-44169
CVE-2026-44168
https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7
https://mariadb.com/docs/release-notes/community-server/11.4/11.4.11
https://mariadb.com/docs/release-notes/community-server/10.11/11.11.17
https://mariadb.com/docs/release-notes/community-server/10.6/10.6.26
2026-05-18
2026-05-19
Vinyl/Varnish -- HTTP/2 parsing deficiency
vinyl09
9.0.1
varnish7
7.7.3_1
Vinyl Development Team reports:
A deficiency in HTTP/2 request parsing can be exploited to launch a backend request
desync attack (request smuggling), which in turn can be used for cache poisoning,
authentication bypass or possibly even information disclosure and manipulation.
https://vinyl-cache.org/security/VSV00019.html
2026-05-18
2026-05-18
PostgreSQL -- Multiple vulnerabilities
postgresql14-server
14.23
postgresql15-server
15.18
postgresql16-server
16.14
postgresql17-server
17.10
postgresql18-server
18.4
postgresql14-client
14.23
postgresql15-client
15.18
postgresql16-client
16.14
postgresql17-client
17.10
postgresql18-client
18.4
The PostgreSQL project reports:
Missing authorization in PostgreSQL CREATE TYPE
allows an object creator to hijack other queries that use
search_path to find user-defined types, including
extension-defined types. That is to say, the victim will execute
arbitrary SQL functions of the attacker's choice.
Integer wraparound in multiple PostgreSQL server
features allows an application input provider to cause the
server to undersize an allocation and write out-of-bounds. This
results in a segmentation fault.
Externally-controlled format string in PostgreSQL timeofday()
function allows an attacker to retrieve portions of server
memory, via crafted timezone zones.
Symlink following in
PostgreSQL pg_basebackup plain format and in pg_rewind allows an
origin superuser to overwrite local files, e.g.
/var/lib/postgres/.bashrc, that hijack the operating system
account. It will remain the case that starting the server after
these commands implicitly trusts the origin superuser, due to
features like shared_preload_libraries. Hence, the attack has
practical implications only if one takes relevant action between
these commands and server start, like moving the files to a
different VM or snapshotting the VM.
SQL injection in PostgreSQL
pg_createsubscriber allows an attacker with
pg_create_subscription rights to execute arbitrary SQL as a
superuser. The attack takes effect when pg_createsubscriber next
runs. Versions before PostgreSQL 17 are unaffected.
PostgreSQL libpq lo_* functions let server superuser overwrite
client stack memory. Use of inherently dangerous function
PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(),
lo_read(), lo_lseek64(), and lo_tell64() functions allows the
server superuser to overwrite a client stack buffer with an
arbitrarily-large response. Like gets(), PQfn(...,
result_is_int=0, ...) stores arbitrary-length, server-determined
data into a buffer of unspecified size. Because both the
\lo_export command in psql and pg_dump call lo_read(), the
server superuser can overwrite pg_dump or psql stack memory.
PostgreSQL discloses MD5-hashed passwords via covert timing
channel. Covert timing channel in comparison of MD5-hashed
password in PostgreSQL authentication allows an attacker to
recover user credentials sufficient to authenticate. This does
not affect scram-sha-256 passwords, the default in all supported
releases. However, current databases may have MD5-hashed
passwords originating in upgrades from PostgreSQL 13 or earlier.
PostgreSQL SSL/GSS init causes denial of service, via
uncontrolled recursion. Uncontrolled recursion in PostgreSQL SSL
and GSS negotiation allows an attacker able to connect to a
PostgreSQL AF_UNIX socket to achieve sustained denial of
service. If SSL and GSS are both disabled, an attacker can do
the same via access to a PostgreSQL TCP socket.
PostgreSQL pg_restore_attribute_stats accepts values that cause
query planning to read past end of stats array. Buffer over-read
in PostgreSQL function pg_restore_attribute_stats() accepts
array values of unmatched length, which causes query planning to
read past end of one array. This allows a table maintainer to
infer memory values past that array end. Versions before
PostgreSQL 18 are unaffected.
PostgreSQL refint allows stack buffer overflow and SQL
injection. Stack buffer overflow in PostgreSQL module refint
allows an unprivileged database user to execute arbitrary code
as the operating system user running the database. A distinct
attack is possible if the application declares a user-controlled
column as a refint cascade primary key and facilitates
user-controlled updates to that column. In that case, a SQL
injection allows a primary key update value provider to execute
arbitrary SQL as the database user performing the primary key
update.
PostgreSQL REFRESH PUBLICATION allows SQL injection via table
name. SQL injection in PostgreSQL logical replication ALTER
SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table
creator to execute arbitrary SQL with the subscription's
publication-side credentials. The attack takes effect at the
next REFRESH PUBLICATION. Versions before PostgreSQL 16 are
unaffected.
CVE-2026-6472
https://www.postgresql.org/support/security/CVE-2026-6472/
CVE-2026-6473
https://www.postgresql.org/support/security/CVE-2026-6473/
CVE-2026-6474
https://www.postgresql.org/support/security/CVE-2026-6474/
CVE-2026-6475
https://www.postgresql.org/support/security/CVE-2026-6475/
CVE-2026-6476
https://www.postgresql.org/support/security/CVE-2026-6476/
CVE-2026-6477
https://www.postgresql.org/support/security/CVE-2026-6477/
CVE-2026-6478
https://www.postgresql.org/support/security/CVE-2026-6478/
CVE-2026-6479
https://www.postgresql.org/support/security/CVE-2026-6479/
CVE-2026-6575
https://www.postgresql.org/support/security/CVE-2026-6575/
CVE-2026-6637
https://www.postgresql.org/support/security/CVE-2026-6637/
CVE-2026-6538
https://www.postgresql.org/support/security/CVE-2026-6538/
2026-05-14
2026-05-14
www/nginx -- Remote Code Execution/DoS
nginx
1.30.1,3
nginx development team reports:
When using the "proxy_set_body" directive, an attacker
might inject data in the proxied request to an HTTP/2 backend
A heap memory buffer overflow might occur in a worker
process while handling a specially crafted request by
ngx_http_rewrite_module, potentially resulting in arbitrary code
execution
A heap memory buffer overread might occur in a worker
process while handling a specially crafted response by
ngx_http_scgi_module or ngx_http_uwsgi_module, allowing an attacker
to cause a disclosure of worker process memory or segmentation fault
in a worker process
A heap memory buffer overread might occur in a worker
process while handling a specially sent response with decoding from
UTF-8 via the "charset_map" directive, allowing an attacker to cause
a limited disclosure of worker proccess memory or segmentation fault
in a worker process
When using HTTP/3, processing of connection migration might
cause new QUIC streams to receive a new client address before
validation, allowing an attacker to cause address spoofing
use-after-free might occur during DNS server response
processing if the "ssl_ocsp" directive was used, allowing an attacker
to cause worker process memory corruption or segmentation fault in a
worker process
CVE-2026-42926
CVE-2026-42945
CVE-2026-42946
CVE-2026-42934
CVE-2026-40460
CVE-2026-40701
2026-05-14
2026-05-14
2026-05-17
mail/mailpit -- multiple vulnerabilities
mailpit
1.30.0
Mailpit author reports:
Set a default 50MB per message limit to prevent DoS via
unlimited SMTP DATA and /api/v1/send body sizes
(GHSA-fpxj-m5q8-fphw)
Include CGNAT (Carrier-Grade NAT) in internal IP checks
(GHSA-j3fj-qppj-fmmc)
Block internal IP access by default in HTML check
(GHSA-j3fj-qppj-fmmc)
Fix for path traversal & arbitrary file write in
mailpit dump --http <instance> via attacker-controlled
message IDs (GHSA-qx5x-85p8-vg4j)
Fix concurrent map read & write in proxy CSS rewriter
(GHSA-w4vj-r5pg-3722)
CVE-2026-45713
https://github.com/axllent/mailpit/security/advisories/GHSA-fpxj-m5q8-fphw
CVE-2026-45709
https://github.com/axllent/mailpit/security/advisories/GHSA-j3fj-qppj-fmmc
CVE-2026-45711
https://github.com/axllent/mailpit/security/advisories/GHSA-qx5x-85p8-vg4j
CVE-2026-45712
https://github.com/axllent/mailpit/security/advisories/GHSA-w4vj-r5pg-3722
2026-05-14
2026-05-14
py-setuptools -- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
py27-setuptools44
py310-setuptools58
py311-setuptools58
py312-setuptools58
py313-setuptools58
py313t-setuptools58
py314-setuptools58
py310-setuptools
py311-setuptools
py312-setuptools
py313-setuptools
py313t-setuptools
py314-setuptools
78.1.1
https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf reports:
setuptools is a package that allows users to download, build,
install, upgrade, and uninstall Python packages. A path traversal
vulnerability in `PackageIndex` is present in setuptools prior to
version 78.1.1. An attacker would be allowed to write files to
arbitrary locations on the filesystem with the permissions of the
process running the Python code, which could escalate to remote
code execution depending on the context.
CVE-2025-47273
https://cveawg.mitre.org/api/cve/CVE-2025-47273
2025-05-17
2026-05-14
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.11.018.11.3
18.10.018.10.6
8.3.018.9.7
Gitlab reports:
Cross-site Scripting issue in Analytics dashboard chart rendering impacts GitLab EE
Cross-site Scripting issue in global search impacts GitLab CE/EE
Cross-site Scripting issue in Duo Agent output rendering impacts GitLab EE
Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE
Denial of Service issue in CI/CD job update API impacts GitLab CE/EE
Denial of Service issue in Duo Workflows API impacts GitLab CE/EE
Denial of Service issue in internal API endpoints impacts GitLab CE/EE
Improper Authorization issue in GraphQL token scope enforcement impacts GitLab CE/EE
Denial of Service issue in Insights Configuration impacts GitLab EE
Access Control issue in Issues API impacts GitLab CE/EE
Denial of Service issue in direct transfer CSV parser impacts GitLab CE/EE
CSRF issue in JiraConnect subscriptions impacts GitLab CE/EE
Confused Deputy issue in Jira integration impacts GitLab CE/EE
Cross-site Scripting issue in Banzai markdown sanitizer impacts GitLab CE/EE
Cross-site Scripting issue in achievement email notifications impacts GitLab CE/EE
Access Control issue in Helm package upload impacts GitLab CE/EE
Improper Access Control issue in NuGet Symbol Server impacts GitLab CE/EE
Improper Access Control issue in Container Registry protected tags impacts GitLab CE/EE
Missing Authorization issue in group user search impacts GitLab CE/EE
Improper Access Control issue in code owner approval rules impacts GitLab EE
Access Control issue in PyPI Package Protection Rules impacts GitLab CE/EE
Improper Access Control issue in issue links API impacts GitLab CE/EE
Server-Side Request Forgery issue in virtual registry redirect handler impacts GitLab EE
Access Control issue in GraphQL approval rule mutations impacts GitLab EE
Missing Authorization issue in Security Policy Project Reassignment impacts GitLab EE
CVE-2026-7481
CVE-2026-5297
CVE-2026-6073
CVE-2026-7377
CVE-2026-1659
CVE-2025-14870
CVE-2025-14869
CVE-2026-1322
CVE-2026-1184
CVE-2026-4524
CVE-2026-8280
CVE-2026-4527
CVE-2026-3160
CVE-2026-6335
CVE-2025-12669
CVE-2026-3607
CVE-2026-3074
CVE-2026-1338
CVE-2026-8144
CVE-2026-6063
CVE-2026-3073
CVE-2025-13874
CVE-2026-7471
CVE-2026-2900
CVE-2026-6883
https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-3-released/
2026-05-13
2026-05-14
zeek -- potential DoS vulnerability
zeek
8.0.8
Wojtulewicz of Corelight reports:
A specially-crafted series of MIME headers sent via
SMTP or HTTP could cause Zeek to use large amounts of
memory and potentially crash.
https://github.com/zeek/zeek/releases/tag/v8.0.8
2026-05-12
2026-05-12
dnsmasq -- multiple vulnerabilities
dnsmasq
2.92rel2,1
dnsmasq-devel
2.93.r1,8
Simon Kelley reports:
Today, 11th May 2026 CERT is releasing a set of six CVEs for serious
security vulnerabilities in dnsmasq. These are all long-standing
bugs
which apply to pretty much all non-ancient versions.
Christopher Cullen and Molly Jaconski write, in Vulnerability Note
VU#471747:
- CVE-2026-2291
-
dnsmasq's
extract_name() function can be abused to
cause a heap buffer overflow, enabling an attacker to inject false
DNS cache entries. This could cause DNS queries to be redirected
to attacker-controlled IP addresses or result in a Denial of
Service (DoS).
- CVE-2026-4890
-
An infinite-loop flaw in the DNSSEC validation of dnsmasq allows
remote attackers to cause Denial of Service (DoS) conditions via a
crafted DNS packet.
- CVE-2026-4891
-
A heap-based out-of-bounds read vulnerability in the DNSSEC
validation of dnsmasq allows remote attackers to leak memory
information via a crafted DNS packet.
- CVE-2026-4892
-
A heap-based out-of-bounds write vulnerability in the DHCPv6
implementation of dnsmasq allows local attackers to execute
arbitrary code with root privileges via a crafted DHCPv6 packet.
- CVE-2026-4893
-
An information disclosure vulnerability in dnsmasq allows remote
attackers to bypass source checks via a crafted DNS packet
containing RFC 7871 client-subnet information.
- CVE-2026-5172
-
A buffer overflow vulnerability in dnsmasq’s
extract_addresses() function
allows attackers to trigger a heap out-of-bounds read and crash
dnsmasq by exploiting a malformed DNS response.
https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html
https://www.kb.cert.org/vuls/id/471747
CVE-2026-2291
CVE-2026-4890
CVE-2026-4891
CVE-2026-4892
CVE-2026-4893
CVE-2026-5172
2026-03-25
2026-05-11
postorius -- XSS
py310-postorius
py311-postorius
py312-postorius
py313-postorius
py314-postorius
py315-postorius
1.3.13_2
NIST reports:
Postorius through 1.3.13 does not escape HTML in the
message subject when rendering it in the Held messages
pop-up, as exploited in the wild in May 2026.
CVE-2026-44742
https://nvd.nist.gov/vuln/detail/CVE-2026-44742
2025-01-29
2026-05-12
Vulnerability found in Expat
expat
linux-c7-expat
linux-rl9-expat
2.8.1
Expat 2.8.1 was released yesterday. The key motivation for cutting a release and doing so now was:
Fixing vulnerability CVE-2026-45186 that allows easy denial of service.
See also https://github.com/libexpat/libexpat/pull/1216
CVE-2026-45186
https://nvd.nist.gov/vuln/detail/CVE-2026-45186
2025-10-01
2026-05-11
dash -- arith: INTMAX_MIN / -1 overflow
dash
0.5.13.3
https://git.kernel.org/pub/scm/utils/dash/dash.git/commit/?id=0034bfe185d3d875cebace8cb3ca5c9dabf9e0f3 reports:
Division and remainder currently guard against division by zero, but not
against the signed overflow case INTMAX_MIN / -1. On affected systems
this can trigger SIGFPE during arithmetic expansion.
CVE-2026-31323
https://git.kernel.org/pub/scm/utils/dash/dash.git/commit/?id=0034bfe185d3d875cebace8cb3ca5c9dabf9e0f3
2026-04-13
2026-05-11
firefox ESR -- Other issue in the WebRTC component
firefox-esr
140.10.2,2
https://bugzilla.mozilla.org/show_bug.cgi?id=2035939 reports:
Other issue in the WebRTC component.
CVE-2026-8094
https://cveawg.mitre.org/api/cve/CVE-2026-8094
2026-05-07
2026-05-08
firefox -- Memory safety bugs present in Firefox 150
firefox
150.0.2,2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-40/ reports:
Memory safety bugs present in Firefox 150.0.1. Some of
these bugs showed evidence of memory corruption and we
presume that with enough effort some of these could have
been exploited to run arbitrary code.
CVE-2026-8093
https://cveawg.mitre.org/api/cve/CVE-2026-8093
2026-05-07
2026-05-08
firefox -- Memory safety bugs present in Firefox ESR 115
firefox
150.0.2,2
firefox-esr
140.10.2,2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-40/ reports:
Memory safety bugs. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort
some of these could have been exploited to run arbitrary
code.
CVE-2026-8092
https://cveawg.mitre.org/api/cve/CVE-2026-8092
2026-05-07
2026-05-08
Mozilla -- Incorrect boundary conditions
firefox
150.0.0,2
firefox-esr
140.10.1,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2029301 reports:
Incorrect boundary conditions in the Audio/Video: Playback
component.
CVE-2026-8091
https://cveawg.mitre.org/api/cve/CVE-2026-8091
2026-05-07
2026-05-08
firefox -- Use-after-free
firefox
150.0.2,2
firefox-esr
140.10.2,2
https://bugzilla.mozilla.org/show_bug.cgi?id=2034352 reports:
Use-after-free in the DOM: Networking component.
CVE-2026-8090
https://cveawg.mitre.org/api/cve/CVE-2026-8090
2026-05-07
2026-05-08
chromium -- security fixes
chromium
148.0.7778.96
ungoogled-chromium
148.0.7778.96
Chrome Releases reports:
This update includes 127 security fixes:
Critical:
- [493747582] CVE-2026-7896: Integer overflow in Blink.
- [504069514] CVE-2026-7897: Use after free in Mobile.
- [504587882] CVE-2026-7898: Use after free in Chromoting.
High:
- [505481948] CVE-2026-7899: Out of bounds read and write in V8.
- [496503799] CVE-2026-7900: Heap buffer overflow in ANGLE.
- [497724490] CVE-2026-7901: Use after free in ANGLE.
- [502030575] CVE-2026-7902: Out of bounds memory access in V8.
- [491760376] CVE-2026-7903: Integer overflow in ANGLE.
- [492350406] CVE-2026-7904: Out of bounds read in Fonts.
- [495259842] CVE-2026-7905: Insufficient validation of untrusted input in Media.
- [496284584] CVE-2026-7906: Use after free in SVG.
- [496292089] CVE-2026-7907: Use after free in DOM.
- [497436531] CVE-2026-7908: Use after free in Fullscreen.
- [497437113] CVE-2026-7909: Inappropriate implementation in ServiceWorker.
- [497543810] CVE-2026-7910: Use after free in Views.
- [497548912] CVE-2026-7911: Use after free in Aura.
- [497639714] CVE-2026-7912: Integer overflow in GPU.
- [497936728] CVE-2026-7913: Insufficient policy enforcement in DevTools.
- [498401609] CVE-2026-7914: Type Confusion in Accessibility.
- [498454478] CVE-2026-7915: Insufficient data validation in DevTools.
- [498720754] CVE-2026-7916: Insufficient data validation in InterestGroups.
- [498752242] CVE-2026-7917: Use after free in Fullscreen.
- [498780188] CVE-2026-7918: Use after free in GPU.
- [498832921] CVE-2026-7919: Use after free in Aura.
- [498989348] CVE-2026-7920: Use after free in Skia.
- [499062376] CVE-2026-7921: Use after free in Passwords.
- [499449324] CVE-2026-7922: Use after free in ServiceWorker.
- [500080194] CVE-2026-7923: Out of bounds write in Skia.
- [500087204] CVE-2026-7924: Uninitialized Use in Dawn.
- [501833981] CVE-2026-7925: Use after free in Chromoting.
- [502249087] CVE-2026-7926: Use after free in PresentationAPI.
- [502830119] CVE-2026-7927: Type Confusion in Runtime.
- [504612429] CVE-2026-7928: Use after free in WebRTC.
- [504660052] CVE-2026-7929: Use after free in MediaRecording.
Medium:
- [434825208] CVE-2026-7930: Insufficient validation of untrusted input in Cookies.
- [474338157] CVE-2026-7931: Insufficient validation of untrusted input in iOS.
- [481634116] CVE-2026-7932: Insufficient policy enforcement in Downloads.
- [488585490] CVE-2026-7933: Out of bounds read in WebCodecs.
- [489023922] CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker.
- [489624550] CVE-2026-7935: Inappropriate implementation in Speech.
- [490485402] CVE-2026-7936: Object lifecycle issue in V8.
- [491766258] CVE-2026-7937: Insufficient policy enforcement in DevTools.
- [492735384] CVE-2026-7938: Use after free in CSS.
- [492963096] CVE-2026-7939: Inappropriate implementation in SanitizerAPI.
- [493631402] CVE-2026-7940: Use after free in V8.
- [493955234] CVE-2026-7941: Insufficient validation of untrusted input in Mobile.
- [495363705] CVE-2026-7942: Integer overflow in ANGLE.
- [495373657] CVE-2026-7943: Insufficient validation of untrusted input in ANGLE.
- [495783187] CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache.
- [495802788] CVE-2026-7945: Insufficient validation of untrusted input in COOP.
- [496016840] CVE-2026-7946: Insufficient policy enforcement in WebUI.
- [496169594] CVE-2026-7947: Insufficient validation of untrusted input in Network.
- [496193452] CVE-2026-7948: Race in Chromoting.
- [496206134] CVE-2026-7949: Out of bounds read in Skia.
- [496259890] CVE-2026-7950: Out of bounds read and write in GFX.
- [496266456] CVE-2026-7951: Out of bounds write in WebRTC.
- [496279876] CVE-2026-7952: Insufficient policy enforcement in Extensions.
- [496379792] CVE-2026-7953: Insufficient validation of untrusted input in Omnibox.
- [496380960] CVE-2026-7954: Race in Shared Storage.
- [496441232] CVE-2026-7955: Uninitialized Use in GPU.
- [496463315] CVE-2026-7956: Use after free in Navigation.
- [496607380] CVE-2026-7957: Out of bounds write in Media.
- [496632973] CVE-2026-7958: Inappropriate implementation in ServiceWorker.
- [496645205] CVE-2026-7959: Inappropriate implementation in Navigation.
- [497007825] CVE-2026-7960: Race in Speech.
- [497008295] CVE-2026-7961: Insufficient validation of untrusted input in Permissions.
- [497081987] CVE-2026-7962: Insufficient policy enforcement in DirectSockets.
- [497250399] CVE-2026-7963: Inappropriate implementation in ServiceWorker.
- [497254383] CVE-2026-7964: Insufficient validation of untrusted input in FileSystem.
- [497255035] CVE-2026-7965: Insufficient validation of untrusted input in DevTools.
- [497341787] CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation.
- [497365545] CVE-2026-7967: Insufficient validation of untrusted input in Navigation.
- [497432281] CVE-2026-7968: Insufficient validation of untrusted input in CORS.
- [497450574] CVE-2026-7969: Integer overflow in Network.
- [497487462] CVE-2026-7970: Use after free in TopChrome.
- [497529290] CVE-2026-7971: Inappropriate implementation in ORB.
- [497546281] CVE-2026-7972: Uninitialized Use in GPU.
- [497565944] CVE-2026-7973: Integer overflow in Dawn.
- [497649372] CVE-2026-7974: Use after free in Blink.
- [497735587] CVE-2026-7975: Use after free in DevTools.
- [497736679] CVE-2026-7976: Use after free in Views.
- [497821223] CVE-2026-7977: Inappropriate implementation in Canvas.
- [497828892] CVE-2026-7978: Inappropriate implementation in Companion.
- [497849876] CVE-2026-7979: Inappropriate implementation in Media.
- [497859275] CVE-2026-7980: Use after free in WebAudio.
- [497926602] CVE-2026-7981: Out of bounds read in Codecs.
- [497952533] CVE-2026-7982: Uninitialized Use in WebCodecs.
- [497975608] CVE-2026-7983: Out of bounds read in Dawn.
- [498277368] CVE-2026-7984: Use after free in ReadingMode.
- [498352423] CVE-2026-7985: Use after free in GPU.
- [498396238] CVE-2026-7986: Insufficient policy enforcement in Autofill.
- [498696266] CVE-2026-7987: Use after free in WebRTC.
- [498753456] CVE-2026-7988: Type Confusion in WebRTC.
- [498765082] CVE-2026-7989: Insufficient data validation in DataTransfer.
- [498892267] CVE-2026-7990: Insufficient validation of untrusted input in Updater.
- [499065126] CVE-2026-7991: Use after free in UI.
- [499067529] CVE-2026-7992: Insufficient validation of untrusted input in UI.
- [499099003] CVE-2026-7993: Insufficient validation of untrusted input in Payments.
- [499116954] CVE-2026-7994: Inappropriate implementation in Chromoting.
- [501745798] CVE-2026-7995: Out of bounds read in AdFilter.
Low:
- [484547631] CVE-2026-7996: Insufficient validation of untrusted input in SSL.
- [487960705] CVE-2026-7997: Insufficient validation of untrusted input in Updater.
- [491676472] CVE-2026-7998: Insufficient validation of untrusted input in Dialog.
- [493099941] CVE-2026-7999: Inappropriate implementation in V8.
- [494464734] CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver.
- [494764371] CVE-2026-8001: Use after free in Printing.
- [495779613] CVE-2026-8002: Use after free in Audio.
- [495985532] CVE-2026-8003: Insufficient validation of untrusted input in TabGroups.
- [496189510] CVE-2026-8004: Insufficient policy enforcement in DevTools.
- [496298665] CVE-2026-8005: Insufficient validation of untrusted input in Cast.
- [496373088] CVE-2026-8006: Insufficient policy enforcement in DevTools.
- [496399759] CVE-2026-8007: Insufficient validation of untrusted input in Cast.
- [496426191] CVE-2026-8008: Inappropriate implementation in DevTools.
- [496555077] CVE-2026-8009: Inappropriate implementation in Cast.
- [496624084] CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation.
- [496626029] CVE-2026-8011: Insufficient policy enforcement in Search.
- [496628298] CVE-2026-8012: Inappropriate implementation in MHTML.
- [497427430] CVE-2026-8013: Insufficient validation of untrusted input in FedCM.
- [497490364] CVE-2026-8014: Inappropriate implementation in Preload.
- [497548558] CVE-2026-8015: Inappropriate implementation in Media.
- [497695401] CVE-2026-8016: Use after free in WebRTC.
- [497722578] CVE-2026-8017: Side-channel information leakage in Media.
- [498292657] CVE-2026-8018: Insufficient policy enforcement in DevTools.
- [498353173] CVE-2026-8019: Insufficient policy enforcement in WebApp.
- [498382925] CVE-2026-8020: Uninitialized Use in GPU.
- [498417031] CVE-2026-8021: Script injection in UI.
- [499194407] CVE-2026-8022: Inappropriate implementation in MHTML.
CVE-2026-7896
CVE-2026-7897
CVE-2026-7898
CVE-2026-7899
CVE-2026-7900
CVE-2026-7901
CVE-2026-7902
CVE-2026-7903
CVE-2026-7904
CVE-2026-7905
CVE-2026-7906
CVE-2026-7907
CVE-2026-7908
CVE-2026-7909
CVE-2026-7910
CVE-2026-7911
CVE-2026-7912
CVE-2026-7913
CVE-2026-7914
CVE-2026-7915
CVE-2026-7916
CVE-2026-7917
CVE-2026-7918
CVE-2026-7919
CVE-2026-7920
CVE-2026-7921
CVE-2026-7922
CVE-2026-7923
CVE-2026-7924
CVE-2026-7925
CVE-2026-7926
CVE-2026-7927
CVE-2026-7928
CVE-2026-7929
CVE-2026-7930
CVE-2026-7931
CVE-2026-7932
CVE-2026-7933
CVE-2026-7934
CVE-2026-7935
CVE-2026-7936
CVE-2026-7937
CVE-2026-7938
CVE-2026-7939
CVE-2026-7940
CVE-2026-7941
CVE-2026-7942
CVE-2026-7943
CVE-2026-7944
CVE-2026-7945
CVE-2026-7946
CVE-2026-7947
CVE-2026-7948
CVE-2026-7949
CVE-2026-7950
CVE-2026-7951
CVE-2026-7952
CVE-2026-7953
CVE-2026-7954
CVE-2026-7955
CVE-2026-7956
CVE-2026-7957
CVE-2026-7958
CVE-2026-7959
CVE-2026-7960
CVE-2026-7961
CVE-2026-7962
CVE-2026-7963
CVE-2026-7964
CVE-2026-7965
CVE-2026-7966
CVE-2026-7967
CVE-2026-7968
CVE-2026-7969
CVE-2026-7970
CVE-2026-7971
CVE-2026-7972
CVE-2026-7973
CVE-2026-7974
CVE-2026-7975
CVE-2026-7976
CVE-2026-7977
CVE-2026-7978
CVE-2026-7979
CVE-2026-7980
CVE-2026-7981
CVE-2026-7982
CVE-2026-7983
CVE-2026-7984
CVE-2026-7985
CVE-2026-7986
CVE-2026-7987
CVE-2026-7988
CVE-2026-7989
CVE-2026-7990
CVE-2026-7991
CVE-2026-7992
CVE-2026-7993
CVE-2026-7994
CVE-2026-7995
CVE-2026-7996
CVE-2026-7997
CVE-2026-7998
CVE-2026-7999
CVE-2026-8000
CVE-2026-8001
CVE-2026-8002
CVE-2026-8003
CVE-2026-8004
CVE-2026-8005
CVE-2026-8006
CVE-2026-8007
CVE-2026-8008
CVE-2026-8009
CVE-2026-8010
CVE-2026-8011
CVE-2026-8012
CVE-2026-8013
CVE-2026-8014
CVE-2026-8015
CVE-2026-8016
CVE-2026-8017
CVE-2026-8018
CVE-2026-8019
CVE-2026-8020
CVE-2026-8021
CVE-2026-8022
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html
2026-05-05
2026-05-08
MongoDB Server -- Multiple vulnerabilities
mongodb80
8.0.21
https://jira.mongodb.org/browse/SERVER-119981 reports:
-
Computing the MD5 checksum of a malformed BSON object
under specific conditions may cause loss of availability
in MongoDB server.
-
An authorization flaw in the user management command
could allow an authenticated user to make limited
changes to authentication-related data associated with
another user account. This could affect how
authentication is performed for the impacted account.
CVE-2026-6914
https://cveawg.mitre.org/api/cve/CVE-2026-6914
CVE-2026-6915
https://cveawg.mitre.org/api/cve/CVE-2026-6915
2026-04-29
2026-05-07
devel/ocaml-opam -- CWE-24 Path Traversal: '../filedir'
ocaml-opam
2.5.1
https://github.com/ocaml/opam/releases/tag/2.5.1 reports:
In OCaml opam before 2.5.1, a .install field containing a destination
filepath can use ../ to reach a parent directory.
Reported by Andrew Nesbitt <andrewnez@gmail.com>.
CVE-2026-41082
https://cveawg.mitre.org/api/cve/CVE-2026-41082
2026-04-16
2026-05-05
www/apache24 -- Multiple vulnerabilities
apache24
2.4.67
The Apache httpd project reports:
mod_proxy_ajp: CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-28780
multiple modules: CVE-2026-33523
mod_authn_socache: CVE-2026-33007
mod_auth_digest: CVE-2026-33006
mod_dav_lock: mod_dav_lock
mod_md: CVE-2026-29168
mod_rewrite: CVE-2026-24072
mod_http2: CVE-2026-23918
CVE-2026-34059
CVE-2026-34032
CVE-2026-33857
CVE-2026-33523
CVE-2026-33007
CVE-2026-33006
CVE-2026-29169
CVE-2026-29168
CVE-2026-28780
CVE-2026-24072
CVE-2026-23918
https://dlcdn.apache.org/httpd/CHANGES_2.4.67
2026-05-04
2026-05-05
modsecurity3 -- multiple vulnerabilities
modsecurity3
3.0.15
ModSecurity is an open source web application firewall engine.
According to the upstream changelog, multiple vulnerabilities have been fixed.
- CVE-2026-42268: unsigned integer underflow in verify operators
- CVE-2026-30923: buffer overflow in hex_decode
CVE-2026-42268
CVE-2026-30923
https://github.com/owasp-modsecurity/ModSecurity/blob/v3.0.15/CHANGES
2026-04-28
2026-05-04
Mozilla -- Memory safety bugs
firefox
150.0.1,2
firefox-esr
140.10.1,2
thunderbird
150.0.1
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2028537%2C2029911%2C2031121%2C2033602 reports:
Memory safety bugs. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort
some of these could have been exploited to run arbitrary
code.
CVE-2026-7323
https://cveawg.mitre.org/api/cve/CVE-2026-7323
2026-04-28
2026-05-03
Prosody XMPP server advisory 2026-04-29
prosody
13.0.5
The Prosody team reports:
Traffic patterns were discovered which can cause Prosody to consume excessive
amounts of memory with much smaller amounts of incoming traffic. This traffic
can be sent by unauthenticated connections. It was discovered that
mod_proxy65’s access control was broken and incomplete due to two bugs.
The issue with unpausing connections was discovered and disclosed by Max Hearnden.
CVE-2026-43504
CVE-2026-43505
CVE-2026-43506
CVE-2026-43507
https://prosody.im/security/advisory_735dd9d3/
2026-04-29
2026-04-30
2026-05-08
Text::CSV_XS -- CWE-825 Expired Pointer Dereference
p5-Text-CSV_XS
1.62
H.Merijn Brand - Tux <linux@tux.freedom.nl> reports:
Text::CSV_XS versions before 1.62 for Perl have a use-after-free
when registered callbacks extend the Perl argument stack, which may
enable type confusion or memory corruption.
The Parse, print, getline, and getline_all methods invoke registered
callbacks (for example after_parse, before_print, or on_error) and
cache the Perl argument stack pointer across the call. If a callback
extends the argument stack enough to trigger a reallocation, the
return value is written through the stale pointer into the freed
buffer, and the caller reads the original $self argument as the
return value instead.
Calling code that expects parsed data from getline_all receives the
Text::CSV_XS object in its place, leading to logic errors or crashes.
Text::CSV_XS objects used without any registered callbacks are not
affected.
CVE-2026-7111
https://cveawg.mitre.org/api/cve/CVE-2026-7111
2026-04-29
2026-04-30
FreeBSD -- Heap overflow in libnv
FreeBSD-kernel
15.015.0_7
14.414.4_3
14.314.3_12
13.513.5_13
Problem Description:
When processing the header of an incoming message, libnv failed
to properly validate the message size.
Impact:
The lack of validation allows a malicious program to write
outside the bounds of a heap allocation. This can trigger a crash
or system panic, and it may be possible for an unprivileged user
to exploit the bug to elevate their privileges.
CVE-2026-35547
SA-26:17.libnv
2026-04-29
2026-04-30
FreeBSD -- Stack overflow via select() file descriptor set overflow
FreeBSD
15.015.0_7
14.414.4_3
14.314.3_12
13.513.5_13
Problem Description:
When exchanging data over a socket, libnv uses select(2) to
wait for data to arrive. However, it does not verify whether the
provided socket descriptor fits in select(2)'s file descriptor set
size limit of FD_SETSIZE (1024).
Impact:
An attacker who is able to force a libnv application to allocate
large file descriptors, e.g., by opening many descriptors and
executing a program which is not careful to close them upon startup,
can trigger stack corruption. If the target application is
setuid-root, then this could be used to elevate local privileges.
CVE-2026-39457
SA-26:16.libnv
2026-04-29
2026-04-30
FreeBSD -- Remotely triggerable out-of-bounds heap write in dhclient
FreeBSD
15.015.0_7
14.414.4_3
14.314.3_12
13.513.5_13
Problem Description:
As dhclient is building an environment to pass to dhclient-script,
it may need to resize the array of string pointers. The code which
expands the array incorrectly calculates its new size when requesting
memory, resulting in a heap buffer overrun.
Impact:
A specially crafted packet can cause dhclient to overrun its
buffer of environment entries. This can result in a crash, but it
may be possible to leverage this bug to achieve remote code
execution.
CVE-2026-42512
SA-26:15.dhclient
2026-04-29
2026-04-30
FreeBSD -- pf can overflow the stack parsing crafted SCTP packets
FreeBSD-kernel
15.015.0_7
14.414.4_3
14.314.3_12
13.513.5_13
Problem Description:
Incorrect packet validation allowed unbounded recursion parsing
SCTP chunk parameters. This can eventually result in a stack
overflow and panic.
Impact:
Remote attackers can craft packets which cause affected systems
to panic. This affects any system where pf is configured to process
traffic, independent of the configured ruleset.
CVE-2026-7164
SA-26:14.pf
2026-04-29
2026-04-30
FreeBSD -- Local privilege escalation via execve()
FreeBSD-kernel
15.015.0_7
14.414.4_3
14.314.3_12
13.513.5_13
Problem Description:
An operator precedence bug in the kernel results in a scenario
where a buffer overflow causes attacker-controlled data to overwrite
adjacent execve(2) argument buffers.
Impact:
The bug may be exploitable by an unprivileged user to obtain
superuser privileges.
CVE-2026-7270
SA-26:13.exec
2026-04-29
2026-04-30
FreeBSD -- Remote code execution via malicious DHCP options
FreeBSD
15.015.0_7
14.414.4_3
14.314.3_12
13.513.5_13
Problem Description:
The BOOTP file field is written to the lease file without
escaping embedded double-quotes, allowing injection of arbitrary
dhclient.conf directives. When the lease file is subsequently
re-parsed by dhclient, e.g., after a system restart, an attacker-controlled
field from the lease is passed to dhclient-script(8), which evaluates
it.
Impact:
A rogue DHCP server may be able to execute arbirary code as
root on a system running dhclient.
CVE-2026-42511
SA-26:12.dhclient
2026-04-29
2026-04-30
openexr -- multiple vulnerabilities
openexr
3.4.11
Cary Phillips reports:
[OpenEXR v3.4.11 is a p]atch release that addresses the following security vulnerabilities:
- CVE-2026-42217 Shift exponent overflow in readVariableLengthInteger() (ImfIDManifest.cpp)
- CVE-2026-42216 Out-of-bounds read in IDManifest::init() during prefix expansion
- CVE-2026-41142 Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API
- OSS-fuzz 504280155 Heap-buffer-overflow in DwaCompressor_uncompress
- OSS-fuzz 505062709 Null-dereference READ in Imf_3_3::prefixFromLayerName
CVE-2026-42217
CVE-2026-42216
CVE-2026-41142
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.11
2026-04-29
2026-04-29
Mozilla -- Sandbox escape
firefox
150.0.0,2
firefox-esr
140.10.1,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2029461 reports:
Sandbox escape due to incorrect boundary conditions in the
WebRTC: Networking component.
CVE-2026-7321
https://cveawg.mitre.org/api/cve/CVE-2026-7321
2026-04-28
2026-04-29
firefox -- Memory safety bugs
firefox
150.0.1,2
firefox-esr
140.10.0,2
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2021904%2C2022731%2C2027158%2C2027733%2C2027973%2C2027976%2C2028231%2C2028731%2C2028886%2C2029067%2C2029700%2C2029724%2C2029806%2C2029814%2C2030108%2C2030111%2C2031524%2C2031921%2C2032040 reports:
Memory safety bugs. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort
some of these could have been exploited to run arbitrary
code.
CVE-2026-7322
https://cveawg.mitre.org/api/cve/CVE-2026-7322
2026-04-28
2026-04-29
firefox -- Information disclosure
firefox
150.0.1,2
firefox-esr
140.10.1,2
https://bugzilla.mozilla.org/show_bug.cgi?id=2027433 reports:
Information disclosure due to incorrect boundary
conditions in the Audio/Video component.
CVE-2026-7320
https://cveawg.mitre.org/api/cve/CVE-2026-7320
2026-04-28
2026-04-29
firefox -- Memory safety bugs
firefox
150.0.1,2
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029419%2C2029717%2C2029769%2C2029886 reports:
Memory safety bugs. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort
some of these could have been exploited to run arbitrary
code.
CVE-2026-7324
https://cveawg.mitre.org/api/cve/CVE-2026-7324
2026-04-28
2026-04-29
firefox -- Information disclosure
firefox
150.0.1,2
firefox-esr
140.10.1,2
https://bugzilla.mozilla.org/show_bug.cgi?id=2027433 reports:
Information disclosure due to incorrect boundary
conditions in the Audio/Video component.
CVE-2026-7320
https://cveawg.mitre.org/api/cve/CVE-2026-7320
2026-04-28
2026-04-29
Mozilla -- Memory safety bugs
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2010727%2C2019004%2C2019224%2C2019547%2C2020378%2C2022381%2C2022608%2C2022785%2C2023120%2C2023128%2C2023140%2C2023279%2C2023836%2C2023882%2C2023925%2C2023950%2C2023959%2C2023965%2C2024243%2C2024245%2C2024247%2C2024253%2C2024346%2C2024357%2C2024416%2C2024420%2C2024429%2C2024432%2C2024455%2C2024466%2C2024468%2C2024476%2C2024664%2C2024666%2C2024669%2C2024670%2C2024671%2C2024761%2C2024918%2C2025292%2C2025332%2C2025348%2C2025384%2C2025395%2C2025458%2C2025461%2C2025463%2C2025481%2C2025483%2C2025485%2C2025494%2C2025506%2C2025511%2C2025513%2C2025520%2C2026277%2C2026282%2C2026288%2C2026289%2C2026311%2C2026312%2C2026869%2C2027152%2C2027161%2C2027238%2C2027261%2C2027269%2C2027274%2C2027280%2C2027281%2C2027300%2C2027302%2C2027331%2C2027339%2C2027340%2C2027738%2C2027975%2C2028000%2C2028011%2C2028289%2C2028525%2C2028728%2C2028887%2C2028888%2C2028896%2C2029063%2C2029064%2C2029290%2C2029291%2C2029294%2C2029300%2C2029304%2C2029316%2C2029317%2C2029401%2C2029415%2C2029430%2C2029457%2C2029727%2C2029735%2C2029743%2C2029752%2C2029754%2C2029776%2C2029809%2C2030324%2C2030370 reports:
Memory safety bugs present. Some of these bugs showed
evidence of memory corruption and we presume that with
enough effort some of these could have been exploited to
run arbitrary code.
CVE-2026-6786
https://cveawg.mitre.org/api/cve/CVE-2026-6786
2026-04-21
2026-04-28
Mozilla -- Memory safety bugs
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1935995%2C1999158%2C2015952%2C2021909%2C2022026%2C2022041%2C2022088%2C2022276%2C2022335%2C2022338%2C2022373%2C2022597%2C2022874%2C2023276%2C2023544%2C2023551%2C2023599%2C2023608%2C2023814%2C2024233%2C2024239%2C2024241%2C2024242%2C2024250%2C2024251%2C2024343%2C2024422%2C2024425%2C2024440%2C2024442%2C2024446%2C2024458%2C2024463%2C2024478%2C2024650%2C2024653%2C2024654%2C2024655%2C2024656%2C2024661%2C2024662%2C2024668%2C2024919%2C2025278%2C2025349%2C2025350%2C2025354%2C2025360%2C2025363%2C2025370%2C2025379%2C2025381%2C2025399%2C2025400%2C2025403%2C2025407%2C2025415%2C2025420%2C2025427%2C2025429%2C2025430%2C2025479%2C2025489%2C2025493%2C2025497%2C2025502%2C2025515%2C2025517%2C2025526%2C2025609%2C2025948%2C2025949%2C2025951%2C2025953%2C2025955%2C2025962%2C2025969%2C2025970%2C2025971%2C2025973%2C2025976%2C2025977%2C2026280%2C2026285%2C2026293%2C2026296%2C2026310%2C2027237%2C2027260%2C2027268%2C2027277%2C2027284%2C2027291%2C2027293%2C2027298%2C2027330%2C2027342%2C2027345%2C2027359%2C2027365%2C2027378%2C2027754%2C2027959%2C2027962%2C2027964%2C2027971%2C2027974%2C2027979%2C2027982%2C2027995%2C2028001%2C2028267%2C2028268%2C2028275%2C2028288%2C2028290%2C2028291%2C2028528%2C2028551%2C2028627%2C2028879%2C2028889%2C2029061%2C2029071%2C2029283%2C2029296%2C2029314%2C2029323%2C2029411%2C2029423%2C2029424%2C2029425%2C2029427%2C2029436%2C2029440%2C2029449%2C2029450%2C2029458%2C2029462%2C2029468%2C2029472%2C2029690%2C2029707%2C2029708%2C2029728%2C2029802%2C2029896%2C2029906%2C2030106%2C2030118%2C2030123%2C2030135%2C2030230%2C2030320 reports:
Memory safety bugs. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort
some of these could have been exploited to run arbitrary
code.
CVE-2026-6785
https://cveawg.mitre.org/api/cve/CVE-2026-6785
2026-04-21
2026-04-28
Mozilla -- Memory safety bugs
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1536243%2C1745382%2C1851073%2C1893400%2C1963301%2C2001319%2C2002899%2C2012436%2C2014435%2C2016901%2C2019916%2C2020486%2C2020612%2C2020817%2C2021788%2C2022051%2C2022367%2C2022431%2C2023302%2C2023670%2C2024225%2C2024238%2C2024240%2C2024265%2C2024367%2C2024369%2C2024424%2C2024760%2C2025281%2C2025361%2C2025387%2C2025466%2C2025954%2C2025958%2C2026278%2C2026292%2C2026297%2C2026378%2C2027148%2C2027287%2C2027341%2C2027384%2C2027427%2C2027694%2C2027993%2C2028009%2C2028270%2C2028416%2C2028524%2C2029295%2C2029301%2C2029461%2C2029699%2C2029800%2C2029801 reports:
Memory safety bugs. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort
some of these could have been exploited to run arbitrary
code.
CVE-2026-6784
https://cveawg.mitre.org/api/cve/CVE-2026-6784
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2027564 reports:
Incorrect boundary conditions, integer overflow in the
Audio/Video: Playback component.
CVE-2026-6783
https://cveawg.mitre.org/api/cve/CVE-2026-6783
2026-04-21
2026-04-28
Mozilla -- Information disclosure in the IP Protection component
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2026571 reports:
Information disclosure in the IP Protection component.
CVE-2026-6782
https://cveawg.mitre.org/api/cve/CVE-2026-6782
2026-04-21
2026-04-28
Mozilla -- Denial-of-service
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2025583 reports:
Denial-of-service in the Audio/Video: Playback component.
CVE-2026-6781
https://cveawg.mitre.org/api/cve/CVE-2026-6781
CVE-2026-6780
https://cveawg.mitre.org/api/cve/CVE-2026-6780
2026-04-21
2026-04-28
Mozilla -- Other issue in the JavaScript Engine component
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2023343 reports:
Other issue in the JavaScript Engine component.
CVE-2026-6779
https://cveawg.mitre.org/api/cve/CVE-2026-6779
2026-04-21
2026-04-28
Mozilla -- Invalid pointer
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2022746 reports:
Invalid pointer in the Audio/Video: Playback component.
CVE-2026-6778
https://cveawg.mitre.org/api/cve/CVE-2026-6778
2026-04-21
2026-04-28
Mozilla -- Other issue in the Networking: DNS component
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2022726 reports:
Other issue in the Networking: DNS component.
CVE-2026-6777
https://cveawg.mitre.org/api/cve/CVE-2026-6777
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary conditions
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2021770 reports:
Incorrect boundary conditions in the WebRTC: Networking
component.
CVE-2026-6776
https://cveawg.mitre.org/api/cve/CVE-2026-6776
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary conditions in the WebRTC component
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2021768 reports:
Incorrect boundary conditions in the WebRTC component.
CVE-2026-6775
https://cveawg.mitre.org/api/cve/CVE-2026-6775
2026-04-21
2026-04-28
Mozilla -- Mitigation bypass
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2016915 reports:
Mitigation bypass in the DOM: Security component.
CVE-2026-6774
https://cveawg.mitre.org/api/cve/CVE-2026-6774
2026-04-21
2026-04-28
Mozilla -- Denial-of-service
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2015959 reports:
Denial-of-service due to integer overflow in the Graphics:
WebGPU component.
CVE-2026-6773
https://cveawg.mitre.org/api/cve/CVE-2026-6773
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary conditions
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2026089 reports:
Incorrect boundary conditions in the Libraries component
in NSS.
CVE-2026-6772
https://cveawg.mitre.org/api/cve/CVE-2026-6772
2026-04-21
2026-04-28
Mozilla -- Mitigation bypass
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2025067 reports:
Mitigation bypass in the DOM: Security component.
CVE-2026-6771
https://cveawg.mitre.org/api/cve/CVE-2026-6771
2026-04-21
2026-04-28
Mozilla -- Other issue in the Storage: IndexedDB component
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2024220 reports:
Other issue in the Storage: IndexedDB component.
CVE-2026-6770
https://cveawg.mitre.org/api/cve/CVE-2026-6770
2026-04-21
2026-04-28
Mozilla -- Privilege escalation in the Debugger component
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2023753 reports:
Privilege escalation in the Debugger component.
CVE-2026-6769
https://cveawg.mitre.org/api/cve/CVE-2026-6769
2026-04-21
2026-04-28
Mozilla -- Mitigation bypass
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2023615 reports:
Mitigation bypass in the Networking: Cookies component.
CVE-2026-6768
https://cveawg.mitre.org/api/cve/CVE-2026-6768
2026-04-21
2026-04-28
Mozilla -- Other issue in the Libraries component in NSS
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2023209 reports:
Other issue in the Libraries component in NSS.
CVE-2026-6767
https://cveawg.mitre.org/api/cve/CVE-2026-6767
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary conditions
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2023207 reports:
Incorrect boundary conditions in the Libraries component
in NSS.
CVE-2026-6766
https://cveawg.mitre.org/api/cve/CVE-2026-6766
2026-04-21
2026-04-28
Mozilla -- Information disclosure
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2022419 reports:
Information disclosure in the Form Autofill component.
CVE-2026-6765
https://cveawg.mitre.org/api/cve/CVE-2026-6765
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary conditions
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2022162 reports:
Incorrect boundary conditions in the DOM: Device Interfaces
component.
CVE-2026-6764
https://cveawg.mitre.org/api/cve/CVE-2026-6764
2026-04-21
2026-04-28
Mozilla -- Mitigation bypass
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2021666 reports:
Mitigation bypass in the File Handling component.
CVE-2026-6763
https://cveawg.mitre.org/api/cve/CVE-2026-6763
2026-04-21
2026-04-28
Mozilla -- Spoofing issue
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2021080 reports:
Spoofing issue in the DOM: Core & HTML component.
CVE-2026-6762
https://cveawg.mitre.org/api/cve/CVE-2026-6762
2026-04-21
2026-04-28
Mozilla -- Privilege escalation
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2017857 reports:
Privilege escalation in the Networking component.
CVE-2026-6761
https://cveawg.mitre.org/api/cve/CVE-2026-6761
2026-04-21
2026-04-28
Mozilla -- Mitigation bypass
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2016923 reports:
Mitigation bypass in the Networking: Cookies component.
CVE-2026-6760
https://cveawg.mitre.org/api/cve/CVE-2026-6760
2026-04-21
2026-04-28
Mozilla -- Use-after-free
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2016164 reports:
Use-after-free in the Widget: Cocoa component.
CVE-2026-6759
https://cveawg.mitre.org/api/cve/CVE-2026-6759
2026-04-21
2026-04-28
Mozilla -- Use-after-free
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2013619 reports:
Use-after-free in the JavaScript: WebAssembly component.
CVE-2026-6758
https://cveawg.mitre.org/api/cve/CVE-2026-6758
2026-04-21
2026-04-28
Mozilla -- Invalid pointer
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2013588 reports:
Invalid pointer in the JavaScript: WebAssembly component.
CVE-2026-6757
https://cveawg.mitre.org/api/cve/CVE-2026-6757
2026-04-21
2026-04-28
Mozilla -- Mitigation bypass
firefox
150.0.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=1880429 reports:
Mitigation bypass in the DOM: postMessage component.
CVE-2026-6755
https://cveawg.mitre.org/api/cve/CVE-2026-6755
2026-04-21
2026-04-28
Mozilla -- Use-after-free
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2027541 reports:
Use-after-free in the JavaScript Engine component.
CVE-2026-6754
https://cveawg.mitre.org/api/cve/CVE-2026-6754
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2027501 reports:
Incorrect boundary conditions in the WebRTC component.
CVE-2026-6753
https://cveawg.mitre.org/api/cve/CVE-2026-6753
2026-04-21
2026-04-28
Mozilla -- Incorrect boundary conditions
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2027499 reports:
Incorrect boundary conditions in the WebRTC component.
CVE-2026-6752
https://cveawg.mitre.org/api/cve/CVE-2026-6752
2026-04-21
2026-04-28
Mozilla -- Uninitialized memory
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2025883 reports:
Uninitialized memory in the Audio/Video: Web Codecs component.
CVE-2026-6751
https://cveawg.mitre.org/api/cve/CVE-2026-6751
2026-04-21
2026-04-28
Mozilla -- Privilege escalation
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2023407 reports:
Privilege escalation in the Graphics: WebRender component.
CVE-2026-6750
https://cveawg.mitre.org/api/cve/CVE-2026-6750
2026-04-21
2026-04-28
Mozilla -- Information disclosure
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2022610 reports:
Information disclosure due to uninitialized memory in the
Graphics: Canvas2D component.
CVE-2026-6749
https://cveawg.mitre.org/api/cve/CVE-2026-6749
2026-04-21
2026-04-28
Mozilla -- Uninitialized memory
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2022604 reports:
Uninitialized memory in the Audio/Video: Web Codecs
component.
CVE-2026-6748
https://cveawg.mitre.org/api/cve/CVE-2026-6748
2026-04-21
2026-04-28
Mozilla -- Use-after-free
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2021769 reports:
Use-after-free in the WebRTC component.
CVE-2026-6747
https://cveawg.mitre.org/api/cve/CVE-2026-6747
2026-04-21
2026-04-28
firefox -- Use-after-free
firefox
150.0.0,2
firefox-esr
140.10.0,2
thunderbird
150.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2014596 reports:
Use-after-free in the DOM: Core & HTML component.
CVE-2026-6746
https://cveawg.mitre.org/api/cve/CVE-2026-6746
2026-04-21
2026-04-28
libXpm -- Out-of-bounds read in xpmNextWord()
libXpm
3.5.19
The X.Org project reports:
libXpm uses a number of internal helper functions to parse the XPM
file format.
One of these internal functions, xpmNextString(), checks for the
NULL terminator when looking for the end of the current string but
not when looking for the beginning of the next string.
A small XPM file with a malformed color table definition may cause
the function xpmNextWord(), called from xpmParseColors() following
a call to xpmNextString(), to start past the actual end of the file,
causing an out-of-bound read.
CVE-2026-4367
https://lists.x.org/archives/xorg-announce/2026-April/003690.html
2026-04-21
2026-04-27
(lib)expat -- Insufficient entropy
expat
2.8.0
https://github.com/libexpat/libexpat/pull/1183 reports:
libexpat before 2.8.0 uses insufficient entropy, and thus hash
flooding can occur via a crafted XML document.
CVE-2026-41080
https://cveawg.mitre.org/api/cve/CVE-2026-41080
2026-04-16
2026-04-26
lcms2 -- Integer overflow
lcms2
2.19
https://github.com/mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0 reports:
Little CMS (lcms2) through 2.18 has an integer overflow in
CubeSize in cmslut.c because the overflow check is performed after
the multiplication.
CVE-2026-41254
https://cveawg.mitre.org/api/cve/CVE-2026-41254
2026-04-18
2026-04-26
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.11.018.11.1
18.10.018.10.4
9.2.018.9.6
Gitlab reports:
Cross-Site Request Forgery issue in GraphQL API impacts GitLab CE/EE GitLab
Improper Resolution of Path Equivalence issue in Web IDE asset impacts GitLab CE/EE
Cross-site Scripting issue in Storybook impacts GitLab CE/EE
Denial of Service issue in discussions endpoint impacts GitLab CE/EE
Denial of Service issue in Jira import impacts GitLab CE/EE
Denial of Service issue in notes endpoint impacts GitLab CE/EE
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Insufficient Session Expiration issue in virtual registry credentials validation impacts GitLab CE/E
Improper Access Control issue in issue description renderer impacts GitLab CE/EE
Improper Restriction of Rendered UI Layers or Frames issue in Mermaid sandbox impacts GitLab CE/EE
Improper Access Control issue in project fork relationship API impacts GitLab CE/EE
CVE-2026-4922
CVE-2026-5816
CVE-2026-5262
CVE-2025-0186
CVE-2026-1660
CVE-2025-6016
CVE-2025-3922
CVE-2026-6515
CVE-2026-5377
CVE-2026-3254
CVE-2025-9957
https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-1-released/
2026-04-22
2026-04-23
OpenVPN -- server DOS and data leak in TLS handshake vulnerabilities
openvpn
2.7.02.7.2
2.6.20
Gert Doering reports:
[Security fixes in 2.7.2]
- fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances (CVE-2026-40215)
- fix server [termination] on receiving a suitably malformed packet with a valid tls-crypt-v2 key (CVE-2026-35058)
CVE-2026-35058
CVE-2026-40215
https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst
2026-04-19
2026-04-22
2026-05-02
FreeBSD -- Missing large page handling in pmap_pkru_update_range()
FreeBSD-kernel
15.015.0_6
14.414.4_2
14.314.3_11
13.513.5_12
Problem Description:
In order to apply a particular protection key to an address
range, the kernel must update the corresponding page table entries.
The subroutine which handled this failed to take into account the
presence of 1GB largepage mappings created using the
shm_create_largepage(3) interface. In particular, it would always
treat a page directory page entry as pointing to another page table
page.
Impact:
The bug can be abused by an unprivileged user to cause
pmap_pkru_update_range() to treat userspace memory as a page table
page, and thus overwrite memory to which the application would
otherwise not have access.
CVE-2026-6386
SA-26:11.amd64
2026-04-21
2026-04-22
FreeBSD -- Kernel use-after-free bug in the TIOCNOTTY handler
FreeBSD-kernel
15.015.0_6
14.414.4_2
14.314.3_11
13.513.5_12
Problem Description:
The implementation of TIOCNOTTY failed to clear a back-pointer
from the structure representing the controlling terminal to the
calling process' session. If the invoking process then exits, the
terminal structure may end up containing a pointer to freed memory.
Impact:
A malicious process can abuse the dangling pointer to grant
itself root privileges.
CVE-2026-5398
SA-26:10.tty
2026-04-21
2026-04-22
Mozilla -- Integer overflow
firefox
148.0.0,2
firefox-esr
140.8.0,2
thunderbird
148.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2009552 reports:
Integer overflow in the Libraries component in NSS.
CVE-2026-2781
https://cveawg.mitre.org/api/cve/CVE-2026-2781
2026-02-24
2026-04-21
ejabberd -- Potential DDoS in XML Parser
ejabberd
26.04
ejabberd team reports:
This release adds new options that limit max memory used
by XML parser used to process XMPP payloads, to prevent
potential Denial of Service attack. The default values for
pre-auth provide sufficient protection for ejabberd against
non-authenticated users on c2s and s2s, so there is no need
to change your configuration.
https://www.process-one.net/blog/ejabberd-26-04/
2026-04-20
2026-04-21
zeek -- potential DoS vulnerabilities
zeek
8.0.7
Tim Wojtulewicz of Corelight reports:
A series of DNS messages containing long DNS compression
chains can cause Zeek to spend a long time processing
packets and potentially crash. Due to the fact that these
packets can be received from remote hosts, this is a DoS
risk.
A specially-crafted LDAP search request can cause Zeek
to spend a long time processing the packet, resulting in
Zeek silently dropping the LDAP analyzer for the connection.
Due to the fact that these packets can be received from
remote hosts, this is an evasion risk.
A specially-crafted series of ASN.1 messages in LDAP
packets can cause Zeek to spend a long time processing
the packets, resulting in Zeek silently dropping the LDAP
analyzer for the connection. Due to the fact that these
packets can be received from remote hosts, this is an
evasion risk.
https://github.com/zeek/zeek/releases/tag/v8.0.7
2026-04-20
2026-04-20
OpenEXR -- several integer overflow vulnerabilities
openexr
3.4.10
Cary Phillips reports:
OpenEXR 3.4.10 is a patch release that addresses the following security vulnerabilities:
- CVE-2026-39886 HTJ2K Signed Integer Overflow in ht_undo_impl()
- CVE-2026-40244 Integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)
- CVE-2026-40250 Integer overflow in DWA decoder outBufferEnd pointer arithmetic (missed variant of CVE-2026-34589)
CVE-2026-39886
CVE-2026-40244
CVE-2026-40250
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.10
2026-04-17
2026-04-19
xrdp -- Multiple vulnerabilities
xrdp
0.10.6,1
xrdp project reports:
This release includes 8 security fixes:
- CVE-2026-32105
- CVE-2026-32107
- CVE-2026-32623
- CVE-2026-32624
- CVE-2026-33145
- CVE-2026-32516
- CVE-2026-32689
- CVE-2026-35512
CVE-2026-32105
CVE-2026-32107
CVE-2026-32623
CVE-2026-32624
CVE-2026-33145
CVE-2026-32516
CVE-2026-32689
CVE-2026-35512
2026-03-03
2026-04-18
py-strawberry-graphql -- Multiple vulnerabilities
py310-strawberry-graphql
py311-strawberry-graphql
py312-strawberry-graphql
py313-strawberry-graphql
py313t-strawberry-graphql
py314-strawberry-graphql
0.312.3
py310-dj52-strawberry-graphql
py311-dj52-strawberry-graphql
py312-dj52-strawberry-graphql
py313-dj52-strawberry-graphql
py313t-dj52-strawberry-graphql
py314-dj52-strawberry-graphql
0.312.3
The Strawberry GraphQL project reports:
Strawberry up until version 0.312.3 is vulnerable to an authentication bypass
on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler
does not verify that a 'connection_init' handshake has been completed before
processing start (subscription) messages. This allows a remote attacker to skip
the 'on_ws_connect' authentication hook entirely by connecting with the
graphql-ws subprotocol and sending a start message directly, without ever
sending 'connection_init'.
The graphql-transport-ws subprotocol handler is not affected, as it correctly
gates subscription operations on a connection_acknowledged flag. However, both
subprotocols are enabled by default in all framework integrations that support
websockets, and the subprotocol is selected by the client via the
Sec-WebSocket-Protocol header.
Any application relying on 'on_ws_connect' for authentication or authorization
is affected.
Strawberry GraphQL's WebSocket subscription handlers for both the
'graphql-transport-ws' and legacy 'graphql-ws' protocols allocate an
asyncio.Task and associated Operation object for every incoming subscribe
message without enforcing any limit on the number of active subscriptions per
connection.
An unauthenticated attacker can open a single WebSocket connection, send
connection_init, and then flood subscribe messages with unique IDs. Each
message unconditionally spawns a new 'asyncio.Task' and async generator,
causing linear memory growth and event loop saturation. This leads to server
degradation or an OOM crash.
CVE-2026-35523
https://www.cve.org/CVERecord?id=CVE-2026-35523
CVE-2026-35526
https://www.cve.org/CVERecord?id=CVE-2026-35526
2026-04-04
2026-04-17
Mozilla -- Memory safety bugs
firefox
149.0.2,2
firefox-esr
140.9.1,2
thunderbird
149.0.2
thunderbird-esr
140.9.1
Mozilla reports:
Memory safety bugs present in Firefox ESR, Firefox ESR ,
Thunderbird ESR, and Thunderbird. Some of these bugs
showed evidence of memory corruption and we presume that
with enough effort some of these could have been exploited
to run arbitrary code.
CVE-2026-5731
https://cveawg.mitre.org/api/cve/CVE-2026-5731
2026-04-07
2026-04-17
go-ethereum -- vulnerabilities
go-ethereum
1.17.0
https://github.com/ethereum/go-ethereum/security/advisories reports:
- DoS via malicious p2p message (CVE-2026-26313)
- DoS via malicious p2p message (CVE-2026-26314)
- Improper ECIES Public Key Validation in RLPx Handshake (CVE-2026-26315)
CVE-2026-26313
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-689v-6xwf-5jf3
CVE-2026-26314
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-2gjw-fg97-vg3r
CVE-2026-26315
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-m6j8-rg6r-7mv8
2026-02-17
2026-04-12
chromium -- security fixes
chromium
147.0.7727.101
ungoogled-chromium
147.0.7727.101
Chrome Releases reports:
This update includes 31 security fixes:
- [490170083] Critical CVE-2026-6296: Heap buffer overflow in ANGLE. Reported by cinzinga on 2026-03-05
- [493628982] Critical CVE-2026-6297: Use after free in Proxy. Reported by heapracer on 2026-03-17
- [495700484] Critical CVE-2026-6298: Heap buffer overflow in Skia. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-24
- [497053588] Critical CVE-2026-6299: Use after free in Prerender. Reported by Google on 2026-03-28
- [497724498] Critical CVE-2026-6358: Use after free in XR. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-03-30
- [490251701] High CVE-2026-6359: Use after free in Video. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-06
- [491994185] High CVE-2026-6300: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-12
- [495273999] High CVE-2026-6301: Type Confusion in Turbofan. Reported by qymag1c on 2026-03-23
- [495477995] High CVE-2026-6302: Use after free in Video. Reported by Syn4pse on 2026-03-24
- [496282147] High CVE-2026-6303: Use after free in Codecs. Reported by Google on 2026-03-25
- [496393742] High CVE-2026-6304: Use after free in Graphite. Reported by Google on 2026-03-26
- [496618639] High CVE-2026-6305: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-26
- [496907110] High CVE-2026-6306: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-27
- [497404188] High CVE-2026-6307: Type Confusion in Turbofan. Reported by Project WhatForLunch (@pjwhatforlunch) on 2026-03-29
- [497412658] High CVE-2026-6308: Out of bounds read in Media. Reported by Google on 2026-03-29
- [497846428] High CVE-2026-6309: Use after free in Viz. Reported by Google on 2026-03-30
- [497880137] High CVE-2026-6360: Use after free in FileSystem. Reported by asjidkalam on 2026-03-31
- [497969820] High CVE-2026-6310: Use after free in Dawn. Reported by Google on 2026-03-31
- [498201025] High CVE-2026-6311: Uninitialized Use in Accessibility. Reported by Google on 2026-03-31
- [498269651] High CVE-2026-6312: Insufficient policy enforcement in Passwords. Reported by Google on 2026-03-31
- [498765210] High CVE-2026-6313: Insufficient policy enforcement in CORS. Reported by Google on 2026-04-02
- [498782145] High CVE-2026-6314: Out of bounds write in GPU. Reported by Google on 2026-04-02
- [499247910] High CVE-2026-6315: Use after free in Permissions. Reported by Google on 2026-04-03
- [499384399] High CVE-2026-6316: Use after free in Forms. Reported by Google on 2026-04-03
- [500036290] High CVE-2026-6361: Heap buffer overflow in PDFium. Reported by Google on 2026-04-06
- [500066234] High CVE-2026-6362: Use after free in Codecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-07
- [500091052] High CVE-2026-6317: Use after free in Cast. Reported by Google on 2026-04-06
- [495751197] Medium CVE-2026-6363: Type Confusion in V8. Reported by Google on 2026-03-24
- [495996858] Medium CVE-2026-6318: Use after free in Codecs. Reported by Syn4pse on 2026-03-25
- [499018889] Medium CVE-2026-6319: Use after free in Payments. Reported by pwn2addr on 2026-04-02
- [502103414] Medium CVE-2026-6364: Out of bounds read in Skia. Reported by Google Threat Intelligence on 2026-04-13
CVE-2026-6296
CVE-2026-6297
CVE-2026-6298
CVE-2026-6299
CVE-2026-6358
CVE-2026-6359
CVE-2026-6300
CVE-2026-6301
CVE-2026-6302
CVE-2026-6303
CVE-2026-6304
CVE-2026-6305
CVE-2026-6306
CVE-2026-6307
CVE-2026-6308
CVE-2026-6309
CVE-2026-6360
CVE-2026-6310
CVE-2026-6311
CVE-2026-6312
CVE-2026-6313
CVE-2026-6314
CVE-2026-6315
CVE-2026-6316
CVE-2026-6361
CVE-2026-6362
CVE-2026-6317
CVE-2026-6363
CVE-2026-6318
CVE-2026-6319
CVE-2026-6364
https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html
2026-04-15
2026-04-16
PHP Composer -- Multiple vulnerabilities
php82-composer
php83-composer
php84-composer
php85-composer
2.9.6
Composer project reports:
Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
CVE-2026-40261
CVE-2026-40176
https://github.com/composer/composer/releases/tag/2.9.6
2026-04-14
2026-04-14
xwayland -- Multiple vulnerabilities
xwayland
24.1.10,1
X.Org project reports:
Multiple issues have been found in the X server and Xwayland
implementations published by X.Org for which we are releasing
security fixes for in xorg-server-21.1.22 and xwayland-24.1.10.
CVE-2026-33999
CVE-2026-34000
CVE-2026-34001
CVE-2026-34002
CVE-2026-34003
https://lists.x.org/archives/xorg-announce/2026-April/003677.html
2026-04-14
2026-04-14
xorg-server -- Multiple vulnerabilities
xorg-server
21.1.22,1
X.Org project reports:
Multiple issues have been found in the X server and Xwayland
implementations published by X.Org for which we are releasing
security fixes for in xorg-server-21.1.22 and xwayland-24.1.10.
CVE-2026-33999
CVE-2026-34000
CVE-2026-34001
CVE-2026-34002
CVE-2026-34003
https://lists.x.org/archives/xorg-announce/2026-April/003677.html
2026-04-14
2026-04-14
python -- more webbrowser.open() command injection vulnerabilities
python3103.10.20_4
python3113.11.15_4
python3120
python3133.13.14
python313t3.13.14
python3143.14.4_2
Seth Larson reports:
[CVE-2026-4786] Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
There is a HIGH severity vulnerability affecting CPython.
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action"
the mitigation could be bypassed for certain browser types the
"webbrowser.open()" API could have commands injected into the underlying
shell. See CVE-2026-4519 for details.
CVE-2026-4786
https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/
https://www.cve.org/CVERecord?id=CVE-2026-4786
https://github.com/python/cpython/issues/148169
https://github.com/python/cpython/pull/148170
2026-04-06
2026-04-13
2026-06-19
Python -- use-after-free vulnerability in decompressors under memory pressure
python3103.10.20_3
python3113.11.15_4
python3120
python3133.13.14
python313t3.13.14
python3143.14.4_1
Seth Larson reports:
There is a CRITICAL severity vulnerability affecting CPython.
Use-after-free (UAF) was possible in the lzma.LZMADecompressor,
bz2.BZ2Decompressor, and gzip.GzipFile when a memory allocation fails
with a MemoryError and the decompression instance is re-used. This
scenario can be triggered if the process is under memory pressure. The fix
cleans up the dangling pointer in this specific error condition.
The vulnerability is only present if the program re-uses decompressor
instances across multiple decompression calls even after a MemoryError is
raised during decompression. Using the helper functions to one-shot
decompress data such as lzma.decompress(), bz2.decompress(),
gzip.decompress(), and zlib.decompress() are not affected as a new
decompressor instance is created for each call. If the decompressor
instance is not re-used after an error condition, this usage is similarly
not vulnerable.
CVE-2026-6100
https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/
https://github.com/python/cpython/issues/148395
2026-04-11
2026-04-13
2026-06-19
Vaultwarden -- Multiple vulnerabilities
vaultwarden
1.35.5
The Vaultwarden project reports:
GHSA-937x-3j8m-7w7p Unconfirmed Owner Can Purge Entire Organization Vault.
GHSA-569v-845w-g82p Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization
GHSA-6j4w-g4jh-xjfx Refresh tokens not invalidated on security stamp rotation
https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.5
2026-04-12
2026-04-12
Python -- HTTP proxy CONNECT tunnel does not sanitize CR/LF
python3100
python3110
python3123.12.13_3
python3133.13.14
python313t3.13.14
python3143.14.4
Seth Larson reports:
HTTP proxy via "CONNECT" tunneling doesn't sanitize CR/LF (CVE-2026-1502).
CVE-2026-1502
https://github.com/python/cpython/issues/146211
2026-03-20
2026-04-12
2026-06-19
Python -- configparser vulnerable to excessive CPU use
python3100
python3110
python3120
python3133.13.14
python313t3.13.14
python3143.14.4
Stan Ulbrych reports:
configparser.RawConfigParser.{OPTCRE,OPTCRE_NV} regexes [are] vulnerable to quadratic backtracking.
https://github.com/python/cpython/issues/146333
2026-03-23
2026-04-12
2026-06-19
py-ormar -- vulnerabilities
py310-ormar
py311-ormar
py312-ormar
py313-ormar
py313t-ormar
py314-ormar
0.23.1
https://github.com/ormar-orm/ormar/security/advisories reports:
- SQL Injection in aggregate functions min() and max()
- Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor
CVE-2026-26198
https://github.com/ormar-orm/ormar/security/advisories/GHSA-xxh2-68g9-8jqr
CVE-2026-27953
https://github.com/ormar-orm/ormar/security/advisories/GHSA-f964-whrq-44h8
2026-02-22
2026-04-11
(lib)tiff -- Integer Overflow or Wraparound
tiff
4.7.1_1
PrymEvol and Quang Luong reports:
A flaw was found in the libtiff library. A remote attacker could
exploit a signed integer overflow vulnerability in the
putcontig8bitYCbCr44tile function by providing a specially crafted
TIFF file. This flaw can lead to an out-of-bounds heap write due
to incorrect memory pointer calculations, potentially causing a
denial of service (application crash) or arbitrary code execution.
CVE-2026-4775
https://cveawg.mitre.org/api/cve/CVE-2026-4775
2026-03-24
2026-04-11
DNSdist -- vulnerabilities
dnsdist
2.0.3
https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html reports:
- CVE-2026-0396: HTML injection in the web dashboard
- CVE-2026-0397: Information disclosure via CORS misconfiguration
- CVE-2026-24028: Out-of-bounds read when parsing DNS packets via Lua
- CVE-2026-24029: DNS over HTTPS ACL bypass
- CVE-2026-24030: Unbounded memory allocation for DoQ and DoH3
- CVE-2026-27853: Out-of-bounds write when rewriting large DNS packets
- CVE-2026-27854: Use after free when parsing EDNS options in Lua
CVE-2026-0396
CVE-2026-0397
CVE-2026-24028
CVE-2026-24029
CVE-2026-24030
CVE-2026-27853
CVE-2026-27854
https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html
2026-03-31
2026-04-10
Mbed TLS -- vulnerabilities
mbedtls3
3.6.6
mbedtls4
4.1.0
https://mbed-tls.readthedocs.io/en/latest/security-advisories/ reports:
- Client impersonation while resuming a TLS 1.3 session (CVE-2026-34873)
- Entropy on Linux can fall back to /dev/urandom (CVE-2026-34871)
- PSA random generator cloning (CVE-2026-25835)
- Compiler-induced constant-time violations (CVE-2025-66442)
- Null pointer dereference when setting a distinguished name (CVE-2026-34874)
- Buffer overflow in FFDH public key export (CVE-2026-34875)
- FFDH: lack of contributory behaviour due to improper input validation (CVE-2026-34872)
- Signature Algorithm Injection (CVE-2026-25834)
- CCM multipart finish tag-length validation bypass (CVE-2026-34876)
- Risk of insufficient protection of serialized session or context data leading to potential memory safety issues (CVE-2026-34877)
- Buffer underflow in x509_inet_pton_ipv6() (CVE-2026-25833)
CVE-2026-34873
CVE-2026-34871
CVE-2026-25835
CVE-2025-66442
CVE-2026-34874
CVE-2026-34875
CVE-2026-34872
CVE-2026-25834
CVE-2026-34876
CVE-2026-34877
CVE-2026-25833
https://mbed-tls.readthedocs.io/en/latest/security-advisories/
2026-03-31
2026-04-10
chromium -- security fixes
chromium
147.0.7727.55
ungoogled-chromium
147.0.7727.55
Chrome Releases reports:
This update includes multiple security fixes:
Critical:
- CVE-2026-5858: Heap buffer overflow in WebML.
- CVE-2026-5859: Integer overflow in WebML.
High:
- CVE-2026-5860: Use after free in WebRTC.
- CVE-2026-5861: Use after free in V8.
- CVE-2026-5862: Inappropriate implementation in V8.
- CVE-2026-5863: Inappropriate implementation in V8.
- CVE-2026-5864: Heap buffer overflow in WebAudio.
- CVE-2026-5865: Type Confusion in V8.
- CVE-2026-5866: Use after free in Media.
- CVE-2026-5867: Heap buffer overflow in WebML.
- CVE-2026-5868: Heap buffer overflow in ANGLE.
- CVE-2026-5869: Heap buffer overflow in WebML.
- CVE-2026-5870: Integer overflow in Skia.
- CVE-2026-5871: Type Confusion in V8.
- CVE-2026-5872: Use after free in Blink.
- CVE-2026-5873: Out of bounds read and write in V8.
Medium:
- CVE-2026-5874: Use after free in PrivateAI.
- CVE-2026-5875: Policy bypass in Blink.
- CVE-2026-5876: Side-channel information leakage in Navigation.
- CVE-2026-5877: Use after free in Navigation.
- CVE-2026-5878: Incorrect security UI in Blink.
- CVE-2026-5879: Insufficient validation of untrusted input in ANGLE.
- CVE-2026-5880: Incorrect security UI in browser UI.
- CVE-2026-5881: Policy bypass in LocalNetworkAccess.
- CVE-2026-5882: Incorrect security UI in Fullscreen.
- CVE-2026-5883: Use after free in Media.
- CVE-2026-5884: Insufficient validation of untrusted input in Media.
- CVE-2026-5885: Insufficient validation of untrusted input in WebML.
- CVE-2026-5886: Out of bounds read in WebAudio.
- CVE-2026-5887: Insufficient validation of untrusted input in Downloads.
- CVE-2026-5888: Uninitialized Use in WebCodecs.
- CVE-2026-5889: Cryptographic Flaw in PDFium.
- CVE-2026-5890: Race in WebCodecs.
- CVE-2026-5891: Insufficient policy enforcement in browser UI.
- CVE-2026-5892: Insufficient policy enforcement in PWAs.
- CVE-2026-5893: Race in V8.
Low:
- CVE-2026-5894: Inappropriate implementation in PDF.
- CVE-2026-5895: Incorrect security UI in Omnibox.
- CVE-2026-5896: Policy bypass in Audio.
- CVE-2026-5897: Incorrect security UI in Downloads.
- CVE-2026-5898: Incorrect security UI in Omnibox.
- CVE-2026-5899: Incorrect security UI in History Navigation.
- CVE-2026-5900: Policy bypass in Downloads.
- CVE-2026-5901: Policy bypass in DevTools.
- CVE-2026-5902: Race in Media.
- CVE-2026-5903: Policy bypass in IFrameSandbox.
- CVE-2026-5904: Use after free in V8.
- CVE-2026-5905: Incorrect security UI in Permissions.
- CVE-2026-5906: Incorrect security UI in Omnibox.
- CVE-2026-5907: Insufficient data validation in Media.
- CVE-2026-5908: Integer overflow in Media.
- CVE-2026-5909: Integer overflow in Media.
- CVE-2026-5910: Integer overflow in Media.
- CVE-2026-5911: Policy bypass in ServiceWorkers.
- CVE-2026-5912: Integer overflow in WebRTC.
- CVE-2026-5913: Out of bounds read in Blink.
- CVE-2026-5914: Type Confusion in CSS.
- CVE-2026-5915: Insufficient validation of untrusted input in WebML.
- CVE-2026-5918: Inappropriate implementation in Navigation.
- CVE-2026-5919: Insufficient validation of untrusted input in WebSockets.
CVE-2026-5858
CVE-2026-5859
CVE-2026-5860
CVE-2026-5861
CVE-2026-5862
CVE-2026-5863
CVE-2026-5864
CVE-2026-5865
CVE-2026-5866
CVE-2026-5867
CVE-2026-5868
CVE-2026-5869
CVE-2026-5870
CVE-2026-5871
CVE-2026-5872
CVE-2026-5873
CVE-2026-5874
CVE-2026-5875
CVE-2026-5876
CVE-2026-5877
CVE-2026-5878
CVE-2026-5879
CVE-2026-5880
CVE-2026-5881
CVE-2026-5882
CVE-2026-5883
CVE-2026-5884
CVE-2026-5885
CVE-2026-5886
CVE-2026-5887
CVE-2026-5888
CVE-2026-5889
CVE-2026-5890
CVE-2026-5891
CVE-2026-5892
CVE-2026-5893
CVE-2026-5894
CVE-2026-5895
CVE-2026-5896
CVE-2026-5897
CVE-2026-5898
CVE-2026-5899
CVE-2026-5900
CVE-2026-5901
CVE-2026-5902
CVE-2026-5903
CVE-2026-5904
CVE-2026-5905
CVE-2026-5906
CVE-2026-5907
CVE-2026-5908
CVE-2026-5909
CVE-2026-5910
CVE-2026-5911
CVE-2026-5912
CVE-2026-5913
CVE-2026-5914
CVE-2026-5915
CVE-2026-5918
CVE-2026-5919
https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html
2026-04-07
2026-04-10
Mozilla -- Memory safety bugs
firefox
149.0.2,2
thunderbird
149.0.2
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2025475%2C2025477 reports:
Memory safety bugs present in Firefox 149.0.1 and
Thunderbird 149.0.1. Some of these bugs showed evidence
of memory corruption and we presume that with enough
effort some of these could have been exploited to run
arbitrary code.
CVE-2026-5735
https://cveawg.mitre.org/api/cve/CVE-2026-5735
2026-04-07
2026-04-09
Mozilla -- Memory safety bugs
firefox
149.0.2,2
firefox-esr
140.9.1,2
thunderbird
140.9.1
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022369%2C2023026%2C2023545%2C2023555%2C2023958%2C2025422%2C2025468%2C2025492%2C2025505 reports:
Memory safety bugs present in Firefox ESR 140.9.0,
Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird
149.0.1. Some of these bugs showed evidence of memory
corruption and we presume that with enough effort some of
these could have been exploited to run arbitrary code.
CVE-2026-5734
https://cveawg.mitre.org/api/cve/CVE-2026-5734
2026-04-07
2026-04-09
Mozilla -- Incorrect boundary conditions
firefox
149.0.2,2
thunderbird
149.0.2
https://bugzilla.mozilla.org/show_bug.cgi?id=2022554 reports:
Incorrect boundary conditions in the Graphics: WebGPU
component.
CVE-2026-5733
https://cveawg.mitre.org/api/cve/CVE-2026-5733
2026-04-07
2026-04-09
Mozilla -- Incorrect boundary conditions, integer overflow
firefox
149.0.2,2
firefox-esr
140.9.1,2
thunderbird
149.0.2
thunderbird
140.9.1
https://bugzilla.mozilla.org/show_bug.cgi?id=2017867 reports:
Incorrect boundary conditions, integer overflow in the
Graphics: Text component.
CVE-2026-5732
https://cveawg.mitre.org/api/cve/CVE-2026-5732
2026-04-07
2026-04-09
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.10.018.10.3
18.9.018.9.5
11.3.018.8.9
Gitlab reports:
Exposed Method issue in websocket connections impacts GitLab CE/EE
Denial of Service issue in Terraform state lock API impacts GitLab CE/EE
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Denial of Service issue in CSV import impacts GitLab CE/EE
Denial of Service issue in GraphQL SBOM API impacts GitLab EE
Code Injection issue in Code Quality reports impacts GitLab EE
Cross-site Scripting issue in analytics dashboards impacts GitLab EE
Incorrect Authorization issue in vulnerability flags AI detection API impacts GitLab EE
Information Disclosure issue in certain GraphQl query impacts GitLab EE
Improper Access Control issue in Environments API impacts GitLab EE
Information Disclosure issue in CSV export impacts GitLab CE/EE
Missing Authorization issue in custom role permissions impacts GitLab CE/EE
CVE-2026-5173
CVE-2026-1092
CVE-2025-12664
CVE-2026-1403
CVE-2026-1101
CVE-2026-1516
CVE-2026-4332
CVE-2026-2619
CVE-2025-9484
CVE-2026-1752
CVE-2026-2104
CVE-2026-4916
https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/
2026-04-08
2026-04-09
OpenSSL -- Multiple vulnerabilities
openssl
3.0.20,1
openssl34
3.4.5
openssl35
3.5.6
openssl36
3.6.2
openssl111
1.1.1zg
The OpenSSL project reports:
Seven vulnerabilities in OpenSSL library. Highest classification Moderate.
CVE-2026-31790
CVE-2026-2637
CVE-2026-28386
CVE-2026-28387
CVE-2026-28388
CVE-2026-28389
CVE-2026-28390
CVE-2026-31789
https://openssl-library.org/news/secadv/20260407.txt
2026-04-07
2026-04-07
nghttp2 -- CWE-617: Reachable Assertion
libnghttp2
1.68.1
nghttp2
1.68.1
https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 reports:
nghttp2 is an implementation of the Hypertext Transfer
Protocol version 2 in C. Prior to version 1.68.1, the
nghttp2 library stops reading the incoming data when user
facing public API `nghttp2_session_terminate_session` or
`nghttp2_session_terminate_session2` is called by the
application. They might be called internally by the
library when it detects the situation that is subject to
connection error. Due to the missing internal state
validation, the library keeps reading the rest of the data
after one of those APIs is called. Then receiving a
malformed frame that causes FRAME_SIZE_ERROR causes
assertion failure. nghttp2 v1.68.1 adds missing state
validation to avoid assertion failure. No known
workarounds are available.
CVE-2026-27135
https://cveawg.mitre.org/api/cve/CVE-2026-27135
2026-03-18
2026-04-05
MongoDB Server -- CWE-617: Reachable Assertion
mongodb80
8.0.18
mongodb70
7.0.31
https://jira.mongodb.org/browse/SERVER-101758 reports:
A user with access to the cluster with a limited set of
privilege actions can trigger a crash of amongod process
during the limited and unpredictable window when the
cluster is being promoted from a replica set to a sharded
cluster. This may cause a denial of service by taking
down the primary of the replica set.
CVE-2026-5170
https://cveawg.mitre.org/api/cve/CVE-2026-5170
2026-03-30
2026-04-03
openexr -- multiple vulnerabilities
openexr
3.4.9
Cary Phillips reports:
[OpenEXR 3.4.9] addresses the following CVEs:
- CVE-2026-34589 DWA Lossy Decoder Heap Out-of-Bounds Write
- CVE-2026-34588 Signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
- CVE-2026-34380 Signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bounds-check bypass in PXR24 decompression
- CVE-2026-34379 Misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression)
- CVE-2026-34378 Signed integer overflow in generic_unpack() when parsing EXR files with crafted negative dataWindow.min.x
CVE-2026-34589
CVE-2026-34588
CVE-2026-34380
CVE-2026-34379
CVE-2026-34378
https://github.com/AcademySoftwareFoundation/openexr/blob/v3.4.9-rc/CHANGES.md#version-349-april--3-2026
https://lists.aswf.io/g/openexr-dev/message/5436
2026-03-26
2026-04-02
Python -- The webbrowser.open() API allows leading dashes
python310 3.10.20_2
python311 3.11.15_2
python312 3.12.13_2
python313 3.13.12_3
python313t 3.13.12_3
python314 3.14.4
https://github.com/python/cpython/pull/143931 reports:
The webbrowser.open() API would accept leading dashes in the URL
which could be handled as command line options for certain web
browsers. New behavior rejects leading dashes. Users are recommended
to sanitize URLs prior to passing to webbrowser.open().
CVE-2026-4519
https://cveawg.mitre.org/api/cve/CVE-2026-4519
2026-03-20
2026-04-01
2026-04-04
Python -- poplib module, when passed a user-controlled command, can have additional commands injected using newlines
python310 0
python311 0
python312 0
python313 0
python313t 0
python314 0
+ python314t 0
+ python315 0
Python Software Foundation Security Developer reports:
The poplib module, when passed a user-controlled command, can have
additional commands injected using newlines. Mitigation rejects
commands containing control characters.
CVE-2025-15367
https://cveawg.mitre.org/api/cve/CVE-2025-15367
2026-01-20
2026-04-01
- 2026-04-04
+ 2026-08-08
Python -- imaplib module, when passed a user-controlled command, can have additional commands injected using newlines
python310 0
python311 0
python312 0
- python313 0
- python313t 0
- python314 0
+ python313 3.13.15
+ python313t 3.13.15
+ python314 3.14.7
+ python314t 3.14.7
+ python315 3.15.0.b4
Python Software Foundation Security Developer reports:
The imaplib module, when passed a user-controlled command, can have
additional commands injected using newlines. Mitigation rejects
- commands containing control characters.
+ commands containing specific control characters.
CVE-2025-15366
https://cveawg.mitre.org/api/cve/CVE-2025-15366
2026-01-20
2026-04-01
- 2026-04-04
+ 2026-08-08
chromium -- security fixes
chromium
146.0.7680.177
ungoogled-chromium
146.0.7680.177
Chrome Releases reports:
This update includes 21 security fixes:
- [493952652] High CVE-2026-5273: Use after free in CSS. Reported by Anonymous on 2026-03-18
- [491732188] High CVE-2026-5272: Heap buffer overflow in GPU. Reported by inspector-ambitious on 2026-03-11
- [488596746] High CVE-2026-5274: Integer overflow in Codecs. Reported by heapracer (@heapracer) on 2026-03-01
- [489494022] High CVE-2026-5275: Heap buffer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-04
- [489711638] High CVE-2026-5276: Insufficient policy enforcement in WebUSB. Reported by Ariel Simon on 2026-03-04
- [489791424] High CVE-2026-5277: Integer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-05
- [490254128] High CVE-2026-5278: Use after free in Web MIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-06
- [490642836] High CVE-2026-5279: Object corruption in V8. Reported by Hyeonjun Ahn (@_deayzl) on 2026-03-08
- [491515787] High CVE-2026-5280: Use after free in WebCodecs. Reported by heapracer (@heapracer) on 2026-03-11
- [491518608] High CVE-2026-5281: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-10
- [491655161] High CVE-2026-5282: Out of bounds read in WebCodecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-11
- [492131521] High CVE-2026-5283: Inappropriate implementation in ANGLE. Reported by sweetchip on 2026-03-12
- [492139412] High CVE-2026-5284: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-12
- [492228019] High CVE-2026-5285: Use after free in WebGL. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-13
- [493900619] High CVE-2026-5286: Use after free in Dawn. Reported by sweetchip on 2026-03-18
- [494644471] High CVE-2026-5287: Use after free in PDF. Reported by Syn4pse on 2026-03-21
- [495507390] High CVE-2026-5288: Use after free in WebView. Reported by Google on 2026-03-23
- [495931147] High CVE-2026-5289: Use after free in Navigation. Reported by Google on 2026-03-25
- [496205576] High CVE-2026-5290: Use after free in Compositing. Reported by Google on 2026-03-25
- [490118036] Medium CVE-2026-5291: Inappropriate implementation in WebGL. Reported by heapracer (@heapracer) on 2026-03-06
- [492213293] Medium CVE-2026-5292: Out of bounds read in WebCodecs. Reported by Google on 2026-03-12
CVE-2026-5273
CVE-2026-5272
CVE-2026-5274
CVE-2026-5275
CVE-2026-5276
CVE-2026-5277
CVE-2026-5278
CVE-2026-5279
CVE-2026-5280
CVE-2026-5281
CVE-2026-5282
CVE-2026-5283
CVE-2026-5284
CVE-2026-5285
CVE-2026-5286
CVE-2026-5287
CVE-2026-5288
CVE-2026-5289
CVE-2026-5290
CVE-2026-5291
CVE-2026-5292
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html
2026-03-31
2026-04-01
traefik -- Multiple vulnerabilities
traefik
3.6.12
The traefik project releases a new version addressing multiple CVEs:
- CVE-2026-33433 (BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField)
- CVE-2026-33186 (authorization bypass via missing leading slash in :path)
CVE-2026-33433
CVE-2026-33186
https://github.com/traefik/traefik/releases/tag/v3.6.12
2026-03-26
2026-03-29
Roundcube -- SVG Attribute Bypass
roundcube-php82
roundcube-php83
roundcube-php84
roundcube-php85
1.6.15,1
The Roundcube project reports:
.
https://github.com/roundcube/roundcubemail/releases/tag/1.6.15
2026-03-29
2026-03-29
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.10.018.10.1
18.9.018.9.3
7.11.018.8.7
Gitlab reports:
Improper Handling of Parameters issue in Jira Connect installations impacts GitLab CE/EE
Cross-Site Request Forgery issue in GLQL API impacts GitLab CE/EE
HTML Injection in vulnerability report impacts GitLab EE
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Improper Access Control issue in WebAuthn 2FA impacts GitLab CE/EE
Improper Access Control issue in GraphQL query impacts GitLab EE
Denial of Service issue in CI configuration processing impacts GitLab CE/EE
Denial of Service issue in webhook configuration impacts GitLab CE/EE
Cross-site Scripting issue in Mermaid diagram renderer impacts GitLab CE/EE
Improper Access Control issue in Merge Requests impacts GitLab CE/EE
Access Control issue in GraphQL API impacts GitLab EE
Incorrect Authorization issue in authorization caching impacts GitLab EE
CVE-2026-2370
CVE-2026-3857
CVE-2026-2995
CVE-2026-3988
CVE-2026-2745
CVE-2026-1724
CVE-2025-13436
CVE-2025-13078
CVE-2026-2973
CVE-2026-2726
CVE-2025-14595
CVE-2026-4363
https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/
2026-03-25
2026-03-29
jenkins -- multiple vulnerabilities
jenkins
2.555
jenkins-lts
2.541.3
Jenkins Security Advisory 2026-03-18:
- SECURITY-3657 / CVE-2026-33001: Arbitrary file write
vulnerability through specially crafted archives in Jenkins
(High)
- SECURITY-3674 / CVE-2026-33002: DNS rebinding vulnerability
in WebSocket CLI origin validation in Jenkins (High)
CVE-2026-33001
CVE-2026-33002
https://www.jenkins.io/security/advisory/2026-03-18/
2026-03-18
2026-03-27
Mozilla -- Multiple vulnerabilities
firefox
149.0.0,2
thunderbird
149.0.0
CVE-2026-4729: Memory safety bugs
CVE-2026-4728: Spoofing issue in the Privacy: Anti-Tracking
component.
CVE-2026-4727: Denial-of-service in the Libraries component
in NSS.
CVE-2026-4726: Denial-of-service in the XML component.
CVE-2026-4725: Sandbox escape due to use-after-free in the
Graphics: Canvas2D component.
CVE-2026-4724: Undefined behavior in the Audio/Video
component.
CVE-2026-4723: Use-after-free in the JavaScript Engine
component.
CVE-2026-4722: Privilege escalation in the IPC component.
CVE-2026-4729
CVE-2026-4728
CVE-2026-4727
CVE-2026-4726
CVE-2026-4725
CVE-2026-4724
CVE-2026-4723
CVE-2026-4722
2026-03-24
2026-03-26
Mozilla -- Multiple vulnerabilities
firefox
149.0.0,2
firefox-esr
140.9.0,2
thunderbird
149.0.0
CVE-2026-4721: Memory safety bugs. Potential arbitrary code
execution.
CVE-2026-4709: Incorrect boundary conditions in the
Audio/Video: GMP component.
CVE-2026-4707: Incorrect boundary conditions in the Graphics:
Canvas2D component.
CVE-2026-4706: Incorrect boundary conditions in the Graphics:
Canvas2D component.
CVE-2026-4699: Incorrect boundary conditions in the Layout:
Text and Fonts component.
CVE-2026-4698: JIT miscompilation in the JavaScript Engine:
JIT component.
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts
component.
CVE-2026-4694: Incorrect boundary conditions, integer
overflow in the Graphics component.
CVE-2026-4693: Incorrect boundary conditions in the
Audio/Video: Playback component.
CVE-2026-4692: Sandbox escape in the Responsive Design Mode
component.
CVE-2026-4691: Use-after-free in the CSS Parsing and
Computation component.
CVE-2026-4690: Sandbox escape due to integer overflow in the
XPCOM component.
CVE-2026-4689: Sandbox escape due to integer overflow in the
XPCOM component.
CVE-2026-4687: Sandbox escape in the Telemetry component.
CVE-2026-4686: Incorrect boundary conditions in the Graphics:
Canvas2D component.
CVE-2026-4685: Incorrect boundary conditions in the Graphics:
Canvas2D component.
CVE-2026-4684: Race condition, use-after-free in the
Graphics: WebRender component.
CVE-2026-4721
CVE-2026-4709
CVE-2026-4707
CVE-2026-4706
CVE-2026-4699
CVE-2026-4698
CVE-2026-4696
CVE-2026-4694
CVE-2026-4693
CVE-2026-4692
CVE-2026-4691
CVE-2026-4690
CVE-2026-4689
CVE-2026-4687
CVE-2026-4686
CVE-2026-4685
CVE-2026-4684
2026-03-24
2026-03-26
Mozilla -- Multiple vulnerabilities
firefox
149.0.0,2
thunderbird
149.0.0
CVE-2026-4688: Sandbox escape due to use-after-free in
Disability Access APIs.
CVE-2026-4695: Incorrect boundary conditions in the
Audio/Video: Web Codecs component.
CVE-2026-4697: Incorrect boundary conditions in the
Audio/Video: Web Codecs component.
CVE-2026-4700: Mitigation bypass in the Networking: HTTP
component.
CVE-2026-4701: Use-after-free in the JavaScript Engine
component.
CVE-2026-4702: JIT miscompilation in the JavaScript Engine
component.
CVE-2026-4704: Denial-of-service in the WebRTC: Signaling
component.
CVE-2026-4705: Undefined behavior in the WebRTC: Signaling
component.
CVE-2026-4708: Incorrect boundary conditions in the Graphics
component.
CVE-2026-4710: Incorrect boundary conditions in the
Audio/Video component.
CVE-2026-4711: Use-after-free in the Widget: Cocoa
component.
CVE-2026-4712: Information disclosure in the Widget: Cocoa
component.
CVE-2026-4713: Incorrect boundary conditions in the Graphics
component.
CVE-2026-4714: Incorrect boundary conditions in the
Audio/Video component.
CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D
component.
CVE-2026-4716: Incorrect boundary conditions and
uninitialized memory in the JavaScript Engine.
CVE-2026-4717: Privilege escalation in the Netmonitor
component.
CVE-2026-4718: Undefined behavior in the WebRTC: Signaling
component.
CVE-2026-4719: Incorrect boundary conditions in the Graphics:
Text component.
CVE-2026-4720: Memory safety bugs
CVE-2026-4688
CVE-2026-4695
CVE-2026-4697
CVE-2026-4700
CVE-2026-4701
CVE-2026-4702
CVE-2026-4704
CVE-2026-4705
CVE-2026-4708
CVE-2026-4710
CVE-2026-4711
CVE-2026-4712
CVE-2026-4713
CVE-2026-4714
CVE-2026-4715
CVE-2026-4716
CVE-2026-4717
CVE-2026-4718
CVE-2026-4719
CVE-2026-4720
2026-03-24
2026-03-26
FreeBSD -- Remote code execution via RPCSEC_GSS packet validation
FreeBSD-kernel
15.015.0_5
14.414.4_1
14.314.3_10
13.513.5_11
Problem Description:
Each RPCSEC_GSS data packet is validated by a routine which
checks a signature in the packet. This routine copies a portion
of the packet into a stack buffer, but fails to ensure that the
buffer is sufficiently large, and a malicious client can trigger a
stack overflow. Notably, this does not require the client to
authenticate itself first.
Impact:
As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote
code execution in the kernel is possible by an authenticated user
that is able to send packets to the kernel's NFS server while
kgssapi.ko is loaded into the kernel.
In userspace, applications which have librpcgss_sec loaded and run
an RPC server are vulnerable to remote code execution from any
client able to send it packets. We are not aware of any such
applications in the FreeBSD base system.
CVE-2026-4747
SA-26:08.rpcsec_gss
2026-03-25
2026-03-26
FreeBSD -- Remote denial of service via null pointer dereference
FreeBSD-kernel
15.015.0_5
Problem Description:
On a system exposing an NVMe/TCP target, a remote client can
trigger a kernel panic by sending a CONNECT command for an I/O queue
with a bogus or stale CNTLID.
Impact:
An attacker with network access to the NVMe/TCP target can
trigger an unauthenticated Denial of Service condition on the
affected machine.
CVE-2026-4652
SA-26:07.nvmf
2026-03-25
2026-03-26
FreeBSD -- TCP: remotely exploitable DoS vector (mbuf leak)
FreeBSD-kernel
15.015.0_5
14.414.4_1
14.314.3_10
Problem Description:
When a challenge ACK is to be sent tcp_respond() constructs and
sends the challenge ACK and consumes the mbuf that is passed in.
When no challenge ACK should be sent the function returns and leaks
the mbuf.
Impact:
If an attacker is either on path with an established TCP
connection, or can themselves establish a TCP connection, to an
affected FreeBSD machine, they can easily craft and send packets
which meet the challenge ACK criteria and cause the FreeBSD host
to leak an mbuf for each crafted packet in excess of the configured
rate limit settings i.e. with default settings, crafted packets
in excess of the first 5 sent within a 1s period will leak an mbuf.
Technically, off-path attackers can also exploit this problem by
guessing the IP addresses, TCP port numbers and in some cases the
sequence numbers of established connections and spoofing packets
towards a FreeBSD machine, but this is harder to do effectively.
CVE-2026-4247
SA-26:06.tcp
2026-03-25
2026-03-26
chromium -- security fixes
chromium
146.0.7680.164
ungoogled-chromium
146.0.7680.164
Chrome Releases reports:
This update includes 8 security fixes:
- [485397284] High CVE-2026-4673: Heap buffer overflow in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-18
- [488188166] High CVE-2026-4674: Out of bounds read in CSS. Reported by Syn4pse on 2026-02-27
- [488270257] High CVE-2026-4675: Heap buffer overflow in WebGL. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-02-27
- [488613135] High CVE-2026-4676: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-01
- [490533968] High CVE-2026-4677: Out of bounds read in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-07
- [491164019] High CVE-2026-4678: Use after free in WebGPU. Reported by Google on 2026-03-10
- [491516670] High CVE-2026-4679: Integer overflow in Fonts. Reported by GF, Un3xploitable Of DeadSec on 2026-03-11
- [491869946] High CVE-2026-4680: Use after free in FedCM. Reported by Shaheen Fazim on 2026-03-12
CVE-2026-4673
CVE-2026-4674
CVE-2026-4675
CVE-2026-4676
CVE-2026-4677
CVE-2026-4678
CVE-2026-4679
CVE-2026-4680
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_23.html
2026-03-23
2026-03-24
chromium -- security fixes
chromium
146.0.7680.153
ungoogled-chromium
146.0.7680.153
Chrome Releases reports:
This update includes 26 security fixes:
- [475877320] Critical CVE-2026-4439: Out of bounds memory access in WebGL. Reported by Goodluck on 2026-01-15
- [485935305] Critical CVE-2026-4440: Out of bounds read and write in WebGL. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-20
- [489381399] Critical CVE-2026-4441: Use after free in Base. Reported by Google on 2026-03-03
- [484751092] High CVE-2026-4442: Heap buffer overflow in CSS. Reported by Syn4pse on 2026-02-16
- [485292589] High CVE-2026-4443: Heap buffer overflow in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-18
- [486349161] High CVE-2026-4444: Stack buffer overflow in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-21
- [486421953] High CVE-2026-4445: Use after free in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-22
- [486421954] High CVE-2026-4446: Use after free in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-22
- [486657483] High CVE-2026-4447: Inappropriate implementation in V8. Reported by Erge on 2026-02-23
- [486972661] High CVE-2026-4448: Heap buffer overflow in ANGLE. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-02-23
- [487117772] High CVE-2026-4449: Use after free in Blink. Reported by Syn4pse on 2026-02-24
- [487746373] High CVE-2026-4450: Out of bounds write in V8. Reported by qymag1c on 2026-02-26
- [487768779] High CVE-2026-4451: Insufficient validation of untrusted input in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-26
- [487977696] High CVE-2026-4452: Integer overflow in ANGLE. Reported by cinzinga on 2026-02-26
- [488400770] High CVE-2026-4453: Integer overflow in Dawn. Reported by sweetchip on 2026-02-27
- [488585488] High CVE-2026-4454: Use after free in Network. Reported by heapracer (@heapracer) on 2026-03-01
- [488585504] High CVE-2026-4455: Heap buffer overflow in PDFium. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-01
- [488617440] High CVE-2026-4456: Use after free in Digital Credentials API. Reported by sean wong on 2026-02-28
- [488803413] High CVE-2026-4457: Type Confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-03-01
- [489619753] High CVE-2026-4458: Use after free in Extensions. Reported by Shaheen Fazim on 2026-03-04
- [490246422] High CVE-2026-4459: Out of bounds read and write in WebAudio. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-03-06
- [490254124] High CVE-2026-4460: Out of bounds read in Skia. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-06
- [490558172] High CVE-2026-4461: Inappropriate implementation in V8. Reported by Google on 2026-03-07
- [491080830] High CVE-2026-4462: Out of bounds read in Blink. Reported by heapracer (@heapracer) on 2026-03-09
- [491358681] High CVE-2026-4463: Heap buffer overflow in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-10
- [487208468] Medium CVE-2026-4464: Integer overflow in ANGLE. Reported by heesun on 2026-02-24
CVE-2026-4439
CVE-2026-4440
CVE-2026-4441
CVE-2026-4442
CVE-2026-4443
CVE-2026-4444
CVE-2026-4445
CVE-2026-4446
CVE-2026-4447
CVE-2026-4448
CVE-2026-4449
CVE-2026-4450
CVE-2026-4451
CVE-2026-4452
CVE-2026-4453
CVE-2026-4454
CVE-2026-4455
CVE-2026-4456
CVE-2026-4457
CVE-2026-4458
CVE-2026-4459
CVE-2026-4460
CVE-2026-4461
CVE-2026-4462
CVE-2026-4463
CVE-2026-4464
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_18.html
2026-03-18
2026-03-24
traefik -- Multiple vulnerabilities
traefik
3.6.11
The traefik project releases a new version addressing multiple CVEs:
- CVE-2026-32595 (BasicAuth Middleware Timing Attack)
- CVE-2026-32305 (Potential mTLS Bypass via Fragmented TLS ClientHello)
- CVE-2026-32695 (Details not yet available)
CVE-2026-32595
CVE-2026-32305
CVE-2026-32695
https://github.com/traefik/traefik/releases/tag/v3.6.11
2026-03-19
2026-03-22
UniFi Network Application - Multiple vulnerabilities
unifi10
10.1.89
unifi9
9.0.114
https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b reports:
An Authenticated NoSQL Injection vulnerability found in
UniFi Network Application could allow a malicious actor with
authenticated access to the network to escalate
privileges.
A malicious actor with access to the network could
exploit a Path Traversal vulnerability found in the UniFi
Network Application to access files on the underlying system
that could be manipulated to access an underlying
account.
CVE-2026-22558
https://cveawg.mitre.org/api/cve/CVE-2026-22558
CVE-2026-22557
https://cveawg.mitre.org/api/cve/CVE-2026-22557
2026-03-19
2026-03-19
Roundcube -- Multiple vulnerabilities
roundcube-php82
roundcube-php83
roundcube-php84
roundcube-php85
1.6.14,1
The Roundcube project reports:
pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler
password could get changed without providing the old password
IMAP Injection + CSRF bypass in mail search
remote image blocking bypass via various SVG animate attributes
remote image blocking bypass via a crafted body background attribute
fixed position mitigation bypass via use of !important
XSS issue in a HTML attachment preview
SSRF + Information Disclosure via stylesheet links to a local network hosts
https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
2026-03-18
2026-03-19
homebox -- multiple vulnerabilities
homebox
0.24.0
Homebox reports:
- [HIGH] CVE-2026-27981: Auth Rate Limit Bypass via IP Spoofing
- [MODERATE] CVE-2026-27600: Blind SSRF
- [MODERATE] CVE-2026-26272: Stored XSS via HTML/SVG Attachment Upload
CVE-2026-27981
CVE-2026-27600
CVE-2026-26272
2026-03-01
2026-03-17
chromium -- security fix
chromium
146.0.7680.80
ungoogled-chromium
146.0.7680.80
Chrome Releases reports:
This update includes 1 security fix:
- [491421267] High CVE-2026-3909: Out of bounds write in Skia. Reported by Google Threat Analysis Group on 2026-03-10
CVE-2026-3909
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_13.html
2026-03-13
2026-03-15
chromium -- security fixes
chromium
146.0.7680.75
ungoogled-chromium
146.0.7680.75
Chrome Releases reports:
This update includes 2 security fixes:
- [491421267] High CVE-2026-3909: Out of bounds write in Skia. Reported by Google on 2026-03-10
- [491410818] High CVE-2026-3910: Inappropriate implementation in V8. Reported by Google on 2026-03-10
CVE-2026-3909
CVE-2026-3910
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
2026-03-12
2026-03-15
chromium -- security fixes
chromium
146.0.7680.71
ungoogled-chromium
146.0.7680.71
Chrome Releases reports:
This update includes 29 security fixes:
- [483445078] Critical CVE-2026-3913: Heap buffer overflow in WebML. Reported by Tobias Wienand on 2026-02-10
- [481776048] High CVE-2026-3914: Integer overflow in WebML. Reported by cinzinga on 2026-02-04
- [483971526] High CVE-2026-3915: Heap buffer overflow in WebML. Reported by Tobias Wienand on 2026-02-12
- [482828615] High CVE-2026-3916: Out of bounds read in Web Speech. Reported by Grischa Hauser on 2026-02-09
- [483569512] High CVE-2026-3917: Use after free in Agents. Reported by Syn4pse on 2026-02-11
- [483853103] High CVE-2026-3918: Use after free in WebMCP. Reported by Syn4pse on 2026-02-12
- [444176961] High CVE-2026-3919: Use after free in Extensions. Reported by Huinian Yang (@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd. on 2025-09-10
- [482875307] High CVE-2026-3920: Out of bounds memory access in WebML. Reported by Google on 2026-02-09
- [484946544] High CVE-2026-3921: Use after free in TextEncoding. Reported by Pranamya Keshkamat & Cantina.xyz on 2026-02-17
- [485397139] High CVE-2026-3922: Use after free in MediaStream. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-18
- [485935314] High CVE-2026-3923: Use after free in WebMIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-20
- [487338366] High CVE-2026-3924: Use after free in WindowDialog. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-25
- [418214610] Medium CVE-2026-3925: Incorrect security UI in LookalikeChecks. Reported by NDevTK and Alesandro Ortiz on 2025-05-17
- [478659010] Medium CVE-2026-3926: Out of bounds read in V8. Reported by qymag1c on 2026-01-26
- [474948986] Medium CVE-2026-3927: Incorrect security UI in PictureInPicture. Reported by Barath Stalin K on 2026-01-11
- [435980394] Medium CVE-2026-3928: Insufficient policy enforcement in Extensions. Reported by portsniffer443 on 2025-08-03
- [477180001] Medium CVE-2026-3929: Side-channel information leakage in ResourceTiming. Reported by Povcfe of Tencent Security Xuanwu Lab on 2026-01-20
- [476898368] Medium CVE-2026-3930: Unsafe navigation in Navigation. Reported by Povcfe of Tencent Security Xuanwu Lab on 2026-01-19
- [417599694] Medium CVE-2026-3931: Heap buffer overflow in Skia. Reported by Huinian Yang (@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd. on 2025-05-14
- [478296121] Medium CVE-2026-3932: Insufficient policy enforcement in PDF. Reported by Ayato Shitomi on 2026-01-23
- [478783560] Medium CVE-2026-3934: Insufficient policy enforcement in ChromeDriver. Reported by Povcfe of Tencent Security Xuanwu Lab on 2026-01-26
- [479326680] Medium CVE-2026-3935: Incorrect security UI in WebAppInstalls. Reported by Barath Stalin K on 2026-01-28
- [481920229] Medium CVE-2026-3936: Use after free in WebView. Reported by Am4deu$ on 2026-02-05
- [473118648] Low CVE-2026-3937: Incorrect security UI in Downloads. Reported by Abhishek Kumar on 2026-01-03
- [474763968] Low CVE-2026-3938: Insufficient policy enforcement in Clipboard. Reported by vicevirus on 2026-01-10
- [40058077] Low CVE-2026-3939: Insufficient policy enforcement in PDF. Reported by NDevTK on 2021-11-30
- [470574526] Low CVE-2026-3940: Insufficient policy enforcement in DevTools. Reported by Jorian Woltjer, Mian, bug_blitzer on 2025-12-21
- [474670215] Low CVE-2026-3941: Insufficient policy enforcement in DevTools. Reported by Lyra Rebane (rebane2001) on 2026-01-10
- [475238879] Low CVE-2026-3942: Incorrect security UI in PictureInPicture. Reported by Barath Stalin K on 2026-01-12
CVE-2026-3913
CVE-2026-3914
CVE-2026-3915
CVE-2026-3916
CVE-2026-3917
CVE-2026-3918
CVE-2026-3919
CVE-2026-3920
CVE-2026-3921
CVE-2026-3922
CVE-2026-3923
CVE-2026-3924
CVE-2026-3925
CVE-2026-3926
CVE-2026-3927
CVE-2026-3928
CVE-2026-3929
CVE-2026-3930
CVE-2026-3931
CVE-2026-3932
CVE-2026-3934
CVE-2026-3935
CVE-2026-3936
CVE-2026-3937
CVE-2026-3938
CVE-2026-3939
CVE-2026-3940
CVE-2026-3941
CVE-2026-3942
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_10.html
2026-03-10
2026-03-15
OpenSSL -- key agreement vulnerability
openssl35
3.5.5_1
openssl36
3.6.1_1
The OpenSSL project reports:
TLS 1.3 server may choose unexpected key agreement group (Low)
An OpenSSL TLS 1.3 server may fail to negotiate the expected
preferred key exchange group when its key exchange group configuration includes
the default by using the "DEFAULT" keyword.
CVE-2026-2673
https://openssl-library.org/news/secadv/20260313.txt
2026-03-13
2026-03-13
Mozilla -- Undefined behavior in the DOM: Core & HTML component
firefox
148.0.0,2
firefox-esr
140.8.0,2
thunderbird
148.0.0
https://bugzilla.mozilla.org/show_bug.cgi?id=2014593 reports:
Undefined behavior in the DOM: Core & HTML component.
CVE-2026-2771
https://cveawg.mitre.org/api/cve/CVE-2026-2771
2026-02-24
2026-03-12
Firefox -- Same-origin policy bypass
firefox
148.0.2,2
https://bugzilla.mozilla.org/show_bug.cgi?id=2018400 reports:
Same-origin policy bypass in the CSS Parsing and
Computation component.
CVE-2026-3846
https://cveawg.mitre.org/api/cve/CVE-2026-3846
2026-03-10
2026-03-12
firefox -- Memory safety bugs
firefox
148.0.2,2
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2017513%2C2017622%2C2019341 reports:
Memory safety bugs present in Firefox 148.0.2. Some of
these bugs showed evidence of memory corruption and we
presume that with enough effort some of these could have
been exploited to run arbitrary code.
CVE-2026-3847
https://cveawg.mitre.org/api/cve/CVE-2026-3847
2026-03-10
2026-03-12
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.9.018.9.2
18.8.018.8.6
1.0.018.7.6
Gitlab reports:
Cross-site Scripting issue in Markdown placeholder processing impacts GitLab CE/EE
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Denial of Service issue in repository archive endpoint impacts GitLab CE/EE
Denial of Service issue in protected branches API impacts GitLab CE/EE
Denial of Service issue in webhook custom headers impacts GitLab CE/EE
Denial of Service issue in webhook endpoint impacts GitLab CE/EE
Improper Neutralization of CRLF Sequences issue impacts GitLab CE/EE
Improper Access Control issue in runners API impacts GitLab CE/EE
Improper Access Control issue in snippet rendering impacts GitLab CE/EE
Information Disclosure issue in inaccessible issues impacts GitLab CE/EE
Missing Authorization issue in Group Import impacts GitLab CE/EE
Incorrect Reference issue in repository download impacts GitLab CE/EE
Incorrect Authorization issue in Virtual Registry impacts GitLab EE
Improper Escaping of Output issue in Datadog integration impacts GitLab CE/EE
CVE-2026-1090
CVE-2026-1069
CVE-2025-13929
CVE-2025-14513
CVE-2025-13690
CVE-2025-12576
CVE-2026-3848
CVE-2025-12555
CVE-2026-0602
CVE-2026-1732
CVE-2026-1663
CVE-2026-1230
CVE-2025-12704
CVE-2025-12697
https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/
2026-03-11
2026-03-11
curl -- Multiple vulnerabilities
curl
8.18.0
The curl project reports:
Multiple vulnerabilities
CVE-2025-15224
CVE-2025-15079
CVE-2025-14819
CVE-2025-14524
CVE-2025-14017
CVE-2025-13034
https://curl.se/docs/vuln-8.17.0.html
2026-01-06
2026-03-11
curl -- Multiple vulnerabilties
curl
8.19.0
The curl project reports:
- use after free in SMB connection reuse
- wrong proxy connection reuse with credentials
- token leak with redirect and netrc
- bad reuse of HTTP Negotiate connection
CVE-2026-3805
CVE-2026-3784
CVE-2026-3783
CVE-2026-1965
https://curl.se/docs/vuln-8.18.0.html
2026-03-11
2026-03-11
gstreamer1 -- multiple vulnerabilities
gstreamer1
1.28.1
gstreamer1-plugins
1.28.1
gstreamer1-plugins-good
1.28.1
gstreamer1-plugins-bad
1.28.1
gstreamer1-plugins-ugly
1.28.1
The GStreamer project reports multiple security vulnerabilities fixed in the 1.28.1 release:
Twelve security vulnerabilities were addressed, including:
- Out-of-bounds reads and writes in the H.266 video parser, WAV parser,
MP4 and ASF demuxers, and DVB subtitle decoder.
- Integer overflows in the RIFF parser and Huffman table handling in the JPEG parser.
- Stack buffer overflows in the RTP QDM2 depayloader and H.266 parser.
These could lead to application crashes or potentially arbitrary code execution.
CVE-2026-1940
CVE-2026-3082
CVE-2026-2921
CVE-2026-2922
CVE-2026-2920
CVE-2026-2923
CVE-2026-3083
CVE-2026-3085
CVE-2026-3086
CVE-2026-3081
CVE-2026-3084
https://gstreamer.freedesktop.org/security/sa-2026-0001.html
https://gstreamer.freedesktop.org/security/sa-2026-0002.html
https://gstreamer.freedesktop.org/security/sa-2026-0003.html
https://gstreamer.freedesktop.org/security/sa-2026-0004.html
https://gstreamer.freedesktop.org/security/sa-2026-0005.html
https://gstreamer.freedesktop.org/security/sa-2026-0006.html
https://gstreamer.freedesktop.org/security/sa-2026-0007.html
https://gstreamer.freedesktop.org/security/sa-2026-0008.html
https://gstreamer.freedesktop.org/security/sa-2026-0009.html
https://gstreamer.freedesktop.org/security/sa-2026-0010.html
https://gstreamer.freedesktop.org/security/sa-2026-0011.html
https://gstreamer.freedesktop.org/security/sa-2026-0012.html
2026-02-25
2026-03-07
oauth2-proxy -- multiple vulnerabilities
oauth2-proxy
7.14.2
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed.
CVE-2025-68121
2026-02-05
2026-02-27
Mozilla -- Multiple vulnerabilities
firefox
148.0.0,2
firefox-esr
140.8.0,2
thunderbird
148.0.0
CVE-2026-2809: Memory safety bug in the JavaScript: WebAssembly component.
CVE-2026-2808: Integer overflow in the JavaScript: Standard Library component.
CVE-2026-2809
CVE-2026-2808
2026-02-24
2026-02-26
Firefox -- Multiple vulnerabilities
firefox
148.0.0,2
thunderbird
148.0.0
CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147
CVE-2026-2806: Uninitialized memory in the Graphics: Text component.
CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component.
CVE-2026-2804: Use-after-free in the JavaScript: WebAssembly component.
CVE-2026-2803: Information disclosure, mitigation bypass in the Settings
UI component.
CVE-2026-2802: Race condition in the JavaScript: GC component.
CVE-2026-2801: Incorrect boundary conditions in the JavaScript:
WebAssembly component.
CVE-2026-2799: Use-after-free in the DOM: Core & HTML component.
CVE-2026-2798: Use-after-free in the DOM: Core & HTML component.
CVE-2026-2797: Use-after-free in the JavaScript: GC component.
CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-2795: Use-after-free in the JavaScript: GC component.
CVE-2026-2807
CVE-2026-2806
CVE-2026-2805
CVE-2026-2804
CVE-2026-2803
CVE-2026-2802
CVE-2026-2801
CVE-2026-2799
CVE-2026-2798
CVE-2026-2797
CVE-2026-2796
CVE-2026-2795
2026-02-24
2026-02-26
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.9.018.9.1
18.8.018.8.5
9.0.018.7.5
Gitlab reports:
Cross-site Scripting issue in Mermaid sandbox impacts GitLab CE/EE
Denial of Service issue in container registry impacts GitLab CE/EE
Denial of Service issue in Jira events endpoint impacts GitLab CE/EE
Regular Expression Denial of Service issue in GitLab merge requests impacts GitLab CE/EE
Missing rate limit in Bitbucket Server importer impacts GitLab CE/EE
Denial of Service issue in CI trigger API impacts GitLab CE/EE
Denial of Service issue in token decoder impacts GitLab CE/EE
Improper Access Control issue in Conan package registry impacts GitLab EE
Access Control issue in CI job mutation impacts GitLab CE/EE
CVE-2026-0752
CVE-2025-14511
CVE-2026-1662
CVE-2026-1388
CVE-2026-2845
CVE-2025-3525
CVE-2026-1725
CVE-2026-1747
CVE-2025-14103
https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/
2026-02-25
2026-02-26
mail/mailpit -- Server-Side Request Forgery (SSRF) via Link Check API
mailpit
1.29.2
Mailpit author reports:
The Link Check API (/api/v1/message/{ID}/link-check)
is vulnerable to Server-Side Request Forgery (SSRF). The
server performs HTTP HEAD requests to every URL found in
an email without validating target hosts or filtering
private/internal IP addresses. The response returns status
codes and status text per link, making this a non-blind
SSRF. In the default configuration (no authentication on
SMTP or API), this is fully exploitable remotely with
zero user interaction.
CVE-2026-27808
https://github.com/axllent/mailpit/security/advisories/GHSA-mpf7-p9x7-96r3
2026-02-25
2026-02-25
FreeBSD -- Local DoS and possible privilege escalation via routing sockets
FreeBSD-kernel
15.015.0_4
14.314.3_9
13.513.5_10
Problem Description:
The rtsock_msg_buffer() function serializes routing information
into a buffer. As a part of this, it copies sockaddr structures
into a sockaddr_storage structure on the stack. It assumes that
the source sockaddr length field had already been validated, but
this is not necessarily the case, and it's possible for a malicious
userspace program to craft a request which triggers a 127-byte
overflow.
In practice, this overflow immediately overwrites the canary for
the rtsock_msg_buffer() stack frame, resulting in a panic once the
function returns.
Impact:
The bug allows an unprivileged user to crash the kernel by
triggering a stack buffer overflow in rtsock_msg_buffer(). In
particular, the overflow will corrupt a stack canary value that is
verified when the function returns; this mitigates the impact of
the stack overflow by triggering a kernel panic.
Other kernel bugs may exist which allow userspace to find the canary
value and thus defeat the mitigation, at which point local privilege
escalation may be possible.
CVE-2026-3038
SA-26:05.route
2026-02-24
2026-02-25
FreeBSD -- Jail chroot escape via fd exchange with a different jail
FreeBSD-kernel
14.314.3_9
13.513.5_10
Problem Description:
If two sibling jails are restricted to separate filesystem
trees, which is to say that neither of the two jail root directories
is an ancestor of the other, jailed processes may nonetheless be
able to access a shared directory via a nullfs mount, if the
administrator has configured one.
In this case, cooperating processes in the two jails may establish
a connection using a unix domain socket and exchange directory
descriptors with each other.
When performing a filesystem name lookup, at each step of the lookup,
the kernel checks whether the lookup would descend below the jail
root of the current process. If the jail root directory is not
encountered, the lookup continues.
Impact:
In a configuration where processes in two different jails are
able to exchange file descriptors using a unix domain socket, it
is possible for a jailed process to receive a directory for a
descriptor that is below that process' jail root. This enables
full filesystem access for a jailed process, breaking the chroot.
Note that the system administrator is still responsible for ensuring
that an unprivileged user on the jail host is not able to pass
directory descriptors to a jailed process, even in a patched
kernel.
CVE-2025-15576
SA-26:04.jail
2026-02-24
2026-02-25
Vaultwarden -- Multiple vulnerabilities
vaultwarden
1.35.4
The Vaultwarden project reports:
- GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
- GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
- GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.
https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.4
2026-02-23
2026-02-24
openexr -- buffer overflow in istream_nonparallel_read on invalid input data
openexr
3.3.7
3.4.03.4.5
Cary Phillips reports:
[openexr] v3.4.5 [...] fixes an incorrect size check in istream_nonparallel_read that could lead to a buffer overflow on invalid input data.
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.5
https://github.com/AcademySoftwareFoundation/openexr/commit/6bb2ddf1068573d073edf81270a015b38cc05cef
2026-02-16
2026-02-22
jenkins -- multiple vulnerabilities
jenkins
2.551
jenkins-lts
2.541.2
Jenkins Security Advisory:
Description
(High) SECURITY-3669 / CVE-2026-27099
Stored XSS vulnerability in node offline cause description
(Medium) SECURITY-3658 / CVE-2026-27100
Build information disclosure vulnerability through Run Parameter
CVE-2026-27099
CVE-2026-27100
https://www.jenkins.io/security/advisory/2026-02-18/
2026-02-18
2026-02-20
Mozilla -- Heap buffer overflow
firefox
147.0.4,2
firefox-esr
140.7.1,2
thunderbird
147.0.2
https://bugzilla.mozilla.org/show_bug.cgi?id=2014390 reports:
Heap buffer overflow in libvpx.
CVE-2026-2447
https://cveawg.mitre.org/api/cve/CVE-2026-2447
2026-02-16
2026-02-20
chromium -- security fixes
chromium
145.0.7632.109
ungoogled-chromium
145.0.7632.109
Chrome Releases reports:
This update includes 3 security fixes:
- [477033835] High CVE-2026-2648: Heap buffer overflow in PDFium. Reported by soiax on 2026-01-19
- [481074858] High CVE-2026-2649: Integer overflow in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab on 2026-02-03
- [476461867] Medium CVE-2026-2650: Heap buffer overflow in Media. Reported by Google on 2026-01-18
CVE-2026-2648
CVE-2026-2649
CVE-2026-2650
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_18.html
2026-02-18
2026-02-19
powerdns-recursor -- Denial of Service
powerdns-recursor
5.3.5
PowerDNS Team reports:
2025-07: Internal logic flaw in cache management can lead to
a denial of service in Recursor
2025-08: Insufficient validation of incoming notifies over
TCP can lead to a denial of service in Recursor
2026-01: Crafted zones can lead to increased resource usage in Recursor
2026-01: This problem can be triggered by publishing and querying a crafted
zone that causes large memory usage.
CVE-2025-59029
CVE-2025-59030
CVE-2026-24027
CVE-2026-0398
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-07.html
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-08.html
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-01.html
2025-12-08
2026-02-16
png -- CWE-122: Heap-based Buffer Overflow
png
1.6.55
https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3 reports:
LIBPNG is a reference library for use in applications
that read, create, and manipulate PNG (Portable Network
Graphics) raster image files. Prior to 1.6.55, an
out-of-bounds read vulnerability exists in the
png_set_quantize() API function. When the function is
called with no histogram and the number of colors in the
palette is more than twice the maximum supported by the
user's display, certain palettes will cause the function to
enter into an infinite loop that reads past the end of an
internal heap-allocated buffer. The images that trigger
this vulnerability are valid per the PNG specification.
This vulnerability is fixed in 1.6.55.
CVE-2026-25646
https://cveawg.mitre.org/api/cve/CVE-2026-25646
2026-02-10
2026-02-16
traefik -- TCP readTimeout bypass via STARTTLS on Postgres
traefik
3.6.8
The traefik project reports:
There is a potential vulnerability in Traefik managing STARTTLS requests.
An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout
by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling,
causing connections to remain open indefinitely, leading to a denial of service
CVE-2026-25949
https://nvd.nist.gov/vuln/detail/CVE-2026-25949
2026-02-11
2026-02-14
munge -- CWE-787: Out-of-bounds Write
munge
0.5.18
https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh reports:
MUNGE is an authentication service for creating and
validating user credentials. From 0.5 to 0.5.17, local
attacker can exploit a buffer overflow vulnerability in
munged (the MUNGE authentication daemon) to leak
cryptographic key material from process memory. With the
leaked key material, the attacker could forge arbitrary
MUNGE credentials to impersonate any user (including root)
to services that rely on MUNGE for authentication. The
vulnerability allows a buffer overflow by sending a crafted
message with an oversized address length field, corrupting
munged's internal state and enabling extraction of the MAC
subkey used for credential verification. This vulnerability
is fixed in 0.5.18.
CVE-2026-25506
https://cveawg.mitre.org/api/cve/CVE-2026-25506
2026-02-10
2026-02-14
chromium -- security fix
chromium
145.0.7632.75
ungoogled-chromium
145.0.7632.75
Chrome Releases reports:
This update includes 1 security fix:
- [483569511] High CVE-2026-2441: Use after free in CSS. Reported by Shaheen Fazim on 2026-02-11
CVE-2026-2441
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html
2026-02-13
2026-02-14
expat -- multiple vulnerabilities
expat
2.7.4
expat team reports:
Update contains 2 security fixes:
- CVE-2026-24515: NULL dereference in function XML_ExternalEntityParserCreate
- CVE-2026-25210: missing check for integer overflow in function doContent
CVE-2026-24515
CVE-2026-25210
2026-01-31
2026-02-10
PostgreSQL -- Multiple vulnerabilities
postgresql14-server
14.21
postgresql15-server
15.16
postgresql16-server
16.12
postgresql17-server
17.8
postgresql18-server
18.2
postgresql14-server
14.21
The PostgreSQL project reports:
Improper validation of type oidvector in PostgreSQL
allows a database user to disclose a few bytes of server
memory. We have not ruled out viability of attacks that
arrange for presence of confidential information in
disclosed bytes, but they seem unlikely.
Missing validation of type of input in PostgreSQL
intarray extension selectivity estimator function allows
an object creator to execute arbitrary code as the
operating system user running the database.
Heap buffer overflow in PostgreSQL pgcrypto allows a
ciphertext provider to execute arbitrary code as the
operating system user running the database.
Missing validation of multibyte character length in
PostgreSQL text manipulation allows a database user to
issue crafted queries that achieve a buffer overrun.
That suffices to execute arbitrary code as the operating
system user running the database.
Heap buffer overflow in PostgreSQL pg_trgm allows a
database user to achieve unknown impacts via a crafted
input string. The attacker has limited control over the
byte patterns to be written, but we have not ruled out
the viability of attacks that lead to privilege
escalation.
CVE-2026-2003
CVE-2026-2004
CVE-2026-2005
CVE-2026-2006
CVE-2026-2007
https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/
2026-02-12
2026-02-12
MongoDB Server -- CWE-704 Incorrect Type Conversion or Cast
mongodb70
7.0.29
https://jira.mongodb.org/browse/SERVER-113685 reports:
An authorized user may disable the MongoDB server by
issuing a query against a collection that contains an
invalid compound wildcard index.
CVE-2026-25613
https://cveawg.mitre.org/api/cve/CVE-2026-25613
2026-02-10
2026-02-12
MongoDB Server -- CWE-617 Reachable Assertion
mongodb80
8.0.13
https://jira.mongodb.org/browse/SERVER-99119 reports:
An authorized user may trigger a server crash by running
a $geoNear pipeline with certain invalid index hints.
CVE-2026-25610
https://cveawg.mitre.org/api/cve/CVE-2026-25610
2026-02-10
2026-02-12
MongoDB Server -- Multiple vulnerabilities
mongodb80
8.0.18
https://jira.mongodb.org/browse/SERVER-114126 reports:
Complex queries can cause excessive memory usage in
MongoDB Query Planner resulting in an Out-Of-Memory
Crash.
https://jira.mongodb.org/browse/SERVER-102364 reports:
MongoDB Server may experience an out-of-memory failure while
evaluating expressions that produce deeply nested documents. The
issue arises in recursive functions because the server does not
periodically check the depth of the expression.
https://jira.mongodb.org/browse/SERVER-113532 reports:
Inserting certain large documents into a replica set could lead to
replica set secondaries not being able to fetch the oplog from the
primary. This could stall replication inside the replica set leading
to server crash.
CVE-2026-1850
CVE-2026-1849
CVE-2026-1847
https://cveawg.mitre.org/api/cve/CVE-2026-1850
https://cveawg.mitre.org/api/cve/CVE-2026-1849
https://cveawg.mitre.org/api/cve/CVE-2026-1847
2026-02-10
2026-02-12
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.8.018.8.4
18.7.018.7.4
8.0.018.6.6
Gitlab reports:
Incomplete Validation issue in Web IDE impacts GitLab CE/EE
Denial of Service issue in GraphQL introspection impacts GitLab CE/EE
Denial of Service issue in JSON validation middleware impacts GitLab CE/EE
Cross-site Scripting issue in Code Flow impacts GitLab CE/EE
HTML Injection issue in test case titles impacts GitLab CE/EE
Denial of Service issue in Markdown processor impacts GitLab CE/EE
Denial of Service issue in Markdown Preview impacts GitLab CE/EE
Denial of Service issue in dashboard impacts GitLab EE
Server-Side Request Forgery issue in Virtual Registry impacts GitLab EE
Improper Validation issue in diff parser impacts GitLab CE/EE
Server-Side Request Forgery issue in Git repository import impacts GitLab CE/EE
Authorization Bypass issue in iterations API impacts GitLab EE
Missing Authorization issue in GLQL API impacts GitLab CE/EE
Stored HTML Injection issue in project label impacts GitLab CE/EE
Authorization Bypass issue in Pipeline Schedules API impacts GitLab CE/EE
CVE-2025-7659
CVE-2025-8099
CVE-2026-0958
CVE-2025-14560
CVE-2026-0595
CVE-2026-1458
CVE-2026-1456
CVE-2026-1387
CVE-2025-12575
CVE-2026-1094
CVE-2025-12073
CVE-2026-1080
CVE-2025-14592
CVE-2026-1282
CVE-2025-14594
https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/
2026-02-10
2026-02-11
FreeBSD -- blocklistd(8) socket leak
FreeBSD
15.015.0_3
Problem Description:
Due to a programming error, blocklistd leaks a socket descriptor
for each adverse event report it receives.
Once a certain number of leaked sockets is reached, blocklistd
becomes unable to run the helper script: a child process is forked,
but this child dereferences a null pointer and crashes before it
is able to exec the helper. At this point, blocklistd still records
adverse events but is unable to block new addresses or unblock
addresses whose database entries have expired.
Once a second, much higher number of leaked sockets is reached,
blocklistd becomes unable to receive new adverse event reports.
Impact:
An attacker may take advantage of this by triggering a large
number of adverse events from sacrificial IP addresses to effectively
disable blocklistd before launching an attack.
Even in the absence of attacks or probes by would-be attackers,
adverse events will occur regularly in the course of normal operations,
and blocklistd will gradually run out file descriptors and become
ineffective.
The accumulation of open sockets may have knock-on effects on other
parts of the system, resulting in a general slowdown until blocklistd
is restarted.
CVE-2026-2261
SA-26:03.blocklistd
2026-02-10
2026-02-11
chromium -- multiple security fixes
chromium
144.0.7559.132
ungoogled-chromium
144.0.7559.132
Chrome Releases reports:
This update includes 2 security fixes:
- [478942410] High CVE-2026-1861: Heap buffer overflow in libvpx. Reported by Google on 2026-01-26
- [479726070] High CVE-2026-1862: Type Confusion in V8. Reported by Chaoyuan Peng (@ret2happy) on 2026-01-29
CVE-2026-1861
CVE-2026-1862
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html
2026-02-03
2026-02-09
Roundcube -- Multiple vulnerabilities
roundcube-php82
roundcube-php83
roundcube-php84
roundcube-php85
1.6.13,1
The Roundcube project reports:
Unspecified CSS injection vulnerability.
Remote image blocking bypass via SVG content.
https://github.com/roundcube/roundcubemail/releases/tag/1.6.13
2026-02-08
2026-02-08
qt6-webengine -- multiple vulnerabilities
qt6-pdf
qt6-webengine
6.10.2
Qt qtwebengine-chromium repo reports:
Backports for 7 security bugs in Chromium:
- CVE-2025-13638: Prevent media element GC in callbacks in WebMediaPlayerMS
- CVE-2025-13639: Improve validation of SDP direction in remote description
- CVE-2025-13720: Avoid downcasting Hash and Integrity reports
- CVE-2025-14174: Metal: Don't use pixelsDepthPitch to size buffers
- CVE-2025-14765: Polyfill unary negation and abs for amd mesa frontend
- CVE-2026-0908: Use CheckedNumerics in HandleAllocator
- CVE-2026-1504: Block opaque 416 responses to non-range requests
CVE-2025-13638
CVE-2025-13639
CVE-2025-13720
CVE-2025-14174
CVE-2025-14765
CVE-2026-0908
CVE-2026-1504
https://code.qt.io/cgit/qt/qtwebengine-chromium.git/log/?h=134-based
2026-02-02
2026-02-08
navidrome -- multiple vulnerabilities
navidrome
0.60.0
An XSS vulnerability in the frontend allows a malicious attacker to inject code through the comment metadata of a song to exfiltrate user credentials.
Authenticated users can crash the Navidrome server by supplying an excessively large size parameter to /rest/getCoverArt or to a shared-image URL (/share/img/{token}). When processing such requests, the server attempts to create an extremely large resized image, causing uncontrolled memory growth. This triggers the Linux OOM killer, terminates the Navidrome process, and results in a full service outage.
CVE-2026-25578
https://github.com/navidrome/navidrome/security/advisories/GHSA-rh3r-8pxm-hg4w
CVE-2026-25579
https://github.com/navidrome/navidrome/security/advisories/GHSA-hrr4-3wgr-68x3
2026-02-03
2026-02-07
traefik -- ACME TLS-ALPN fast path potential DoS
traefik
3.6.7
The traefik project reports:
There is a potential vulnerability in Traefik ACME TLS certificates' automatic
generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to
tie up goroutines and file descriptors indefinitely when the ACME TLS challenge
is enabled.A malicious client can open many connections, send a minimal ClientHello
with acme-tls/1, then stop responding, leading to denial of service of the entrypoint.
CVE-2026-22045
https://nvd.nist.gov/vuln/detail/CVE-2026-22045
2026-01-15
2026-02-07
python -- several security vulnerabilities
python310 3.10.19_2
python311 3.11.14_2
python312 3.12.12_4
python313 3.13.12
python313t 3.13.12
python314 3.14.3
The Python project announces a new release with several security fixes:
- CVE-2026-1299: gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
- gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
- gh-143925: Reject control characters in data: URL media types.
- gh-143919: Reject control characters in http.cookies.Morsel fields and values.
- CVE-2026-0865: gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
CVE-2026-1299
CVE-2026-0865
https://docs.python.org/release/3.14.3/whatsnew/changelog.html
2026-01-16
2026-02-04
2026-03-03
xrdp -- remote code execution
xrdp
0.10.5,1
Denis Skvortsov, Security Researcher at Kaspersky reports:
xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system.
CVE-2025-68670
https://www.cve.org/CVERecord?id=CVE-2025-68670
2025-12-06
2026-01-27
zeek -- potential DoS vulnerability
zeek
8.0.6
Tim Wojtulewicz of Corelight reports:
Zeek's HTTP analyzer can be tricked into interpreting
Transfer-Encoding or Content-Length headers set in MIME
entities within HTTP bodies and change the analyzer
behavior.
https://github.com/zeek/zeek/releases/tag/v8.0.6
2026-01-29
2026-01-29
chromium -- security fix
chromium
144.0.7559.109
ungoogled-chromium
144.0.7559.109
Chrome Releases reports:
This update includes 1 security fix:
- [474435504] High CVE-2026-1504: Inappropriate implementation in Background Fetch API. Reported by Luan Herrera (@lbherrera_) on 2026-01-09
CVE-2026-1504
https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_27.html
2026-01-27
2026-01-28
Firefox -- Multiple vulnerabilities
firefox
147.0.2,2
https://bugzilla.mozilla.org/show_bug.cgi?id=2007302 reports:
Mitigation bypass in the Privacy: Anti-Tracking component.
Use-after-free in the Layout: Scrolling and Overflow component.
CVE-2026-24868
https://cveawg.mitre.org/api/cve/CVE-2026-24868
CVE-2026-24869
https://cveawg.mitre.org/api/cve/CVE-2026-24869
2026-01-27
2026-01-28
FreeBSD -- Jail escape by a privileged user via nullfs
FreeBSD-kernel
14.314.3_8
13.513.5_9
Problem Description:
By default, jailed processes cannot mount filesystems, including
nullfs(4). However, the allow.mount.nullfs option enables mounting
nullfs filesystems, subject to privilege checks.
If a privileged user within a jail is able to nullfs-mount directories,
a limitation of the kernel's path lookup logic allows that user to
escape the jail's chroot, yielding access to the full filesystem
of the host or parent jail.
Impact:
In a jail configured to allow nullfs(4) mounts from within the
jail, the jailed root user can escape the jail's filesystem root.
CVE-2025-15547
SA-26:02.jail
2026-01-27
2026-01-28
OpenSSL -- Multiple vulnerabilities
FreeBSD
15.015.0_2
14.314.3_8
13.513.5_9
openssl
3.0.19,1
openssl33
3.3.6
openssl34
3.4.4
openssl35
3.5.5
openssl36
3.6.1
The OpenSSL project reports:
- Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (CVE-2025-11187)
- Stack buffer overflow in CMS AuthEnvelopedData parsing (CVE-2025-15467)
- NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (CVE-2025-15468)
- "openssl dgst" one-shot codepath silently truncates inputs >16MB (CVE-2025-15469)
- TLS 1.3 CompressedCertificate excessive memory allocation (CVE-2025-66199)
- Heap out-of-bounds write in BIO_f_linebuffer on short writes (CVE-2025-68160)
- Unauthenticated/unencrypted trailing bytes with low-level OCB function calls (CVE-2025-69418)
- Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion (CVE-2025-69419)
- Missing ASN1_TYPE validation in TS_RESP_verify_response() function (CVE-2025-69420)
- NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function (CVE-2025-69421)
- Missing ASN1_TYPE validation in PKCS#12 parsing (CVE-2026-22795)
- ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function (CVE-2026-22796)
CVE-2025-11187
CVE-2025-15467
CVE-2025-15468
CVE-2025-15469
CVE-2025-66199
CVE-2025-68160
CVE-2025-69418
CVE-2025-69419
CVE-2025-69420
CVE-2025-69421
CVE-2026-22795
CVE-2026-22796
https://openssl-library.org/news/secadv/20260127.txt
SA-26:01.openssl
2026-01-27
2026-01-27
2026-01-28
MySQL -- Multiple vulnerabilities
mysql80-server
8.0.45
mysql84-server
8.4.8
mysql91-server
9.1.3
mysql94-server
9.4.3
Oracle reports:
Oracle reports multiple vulnerabilities in its MySQL server products.
CVE-2026-21949
CVE-2026-21950
CVE-2026-21968
CVE-2026-21929
CVE-2026-21936
CVE-2026-21937
CVE-2026-21941
CVE-2026-21948
CVE-2026-21952
CVE-2026-21964
CVE-2026-21965
https://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL
2026-01-20
2026-01-24
wheel -- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
py310-wheel
py311-wheel
py312-wheel
py313-wheel
py313t-wheel
py314-wheel
0.46.2
https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx reports:
wheel is a command line tool for manipulating Python wheel files,
as defined in PEP 427. In versions 0.46.1 and below, the unpack
function is vulnerable to file permission modification through
mishandling of file permissions after extraction. The logic blindly
trusts the filename from the archive header for the chmod operation,
even though the extraction process itself might have sanitized the
path. Attackers can craft a malicious wheel file that, when unpacked,
changes the permissions of critical system files (e.g., /etc/passwd,
SSH keys, config files), allowing for Privilege Escalation or
arbitrary code execution by modifying now-writable scripts. This
issue has been fixed in version 0.46.2.
CVE-2026-24049
https://cveawg.mitre.org/api/cve/CVE-2026-24049
2026-01-22
2026-01-22
chromium -- multiple security fixes
chromium
144.0.7559.96
ungoogled-chromium
144.0.7559.96
Chrome Releases reports:
This update includes 1 security fix:
- [473851441] High CVE-2026-1220: Race in V8. Reported by @p1nky4745 on 2026-01-07
CVE-2026-1220
https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_20.html
2026-01-20
2026-01-22
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.8.018.8.2
18.7.018.7.2
11.9.018.6.4
Gitlab reports:
Denial of Service issue in Jira Connect integration impacts GitLab CE/EE
Incorrect Authorization issue in Releases API impacts GitLab CE/EE
Unchecked Return Value issue in authentication services impacts GitLab CE/EE
Infinite Loop issue in Wiki redirects impacts GitLab CE/EE
Denial of Service issue in API endpoint impacts GitLab CE/EE
CVE-2025-13927
CVE-2025-13928
CVE-2026-0723
CVE-2025-13335
CVE-2026-1102
https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/
2026-01-21
2026-01-21
mail/mailpit -- multiple vulnerabilities
mailpit
1.28.3
Mailpit author reports:
Ensure SMTP TO & FROM addresses are RFC 5322
compliant and prevent header injection (GHSA-54wq-72mp-cq7c)
Prevent Server-Side Request Forgery (SSRF) via HTML
Check API (GHSA-6jxm-fv7w-rw5j)
CVE-2026-23829
https://github.com/axllent/mailpit/security/advisories/GHSA-54wq-72mp-cq7c
CVE-2026-23845
https://github.com/axllent/mailpit/security/advisories/GHSA-6jxm-fv7w-rw5j
2026-01-18
2026-01-19
oauth2-proxy -- multiple vulnerabilities
oauth2-proxy
7.14.1
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.
A flaw was found in the crypto/x509 package in the Go standard library. This vulnerability allows a certificate validation bypass via an excluded subdomain constraint in a certificated chain as it does not restrict the usage of wildcard SANs in the leaf certificate.
SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVE-2025-61729
CVE-2025-61727
CVE-2025-47914
CVE-2025-58181
2026-01-16
2026-01-18
Mozilla -- multiple vulnerabilities
firefox
147.0.0,2
thunderbird
147.0.0
Memory safety bugs present in Firefox 146 and Thunderbird
146. Some of these bugs showed evidence of memory corruption
and we presume that with enough effort some of these could
have been exploited to run arbitrary code.
Denial-of-service in the DOM: Service Workers component.
Information disclosure in the XML component.
Sandbox escape in the Messaging System component.
CVE-2026-0892
CVE-2026-0889
CVE-2026-0888
CVE-2026-0881
2026-01-13
2026-01-15
Mozilla -- multiple vulnerabilities
firefox
147.0.0,2
firefox-esr
140.7.0,2
thunderbird
147
Memory safety bugs present in firefox-esr 140.6,
Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146.
Spoofing issue in the DOM: Copy & Paste and Drag &
Drop component.
Clickjacking issue and information disclosure in the PDF
Viewer component.
Use-after-free in the JavaScript: GC component.
Use-after-free in the JavaScript Engine component.
Information disclosure in the Networking component.
Sandbox escape due to incorrect boundary conditions in the
Graphics: CanvasWebGL component.
CVE-2026-0891
CVE-2026-0890
CVE-2026-0887
CVE-2026-0885
CVE-2026-0884
CVE-2026-0883
CVE-2026-0878
2026-01-13
2026-01-15
Mozilla -- multiple vulnerabilities
firefox
147.0.0,2
firefox-esr
140.7.0,2
thunderbird
147.0.0
Incorrect boundary conditions in the Graphics
component.
Use-after-free in the IPC component.
Sandbox escape due to integer overflow in the Graphics
component.
Sandbox escape due to incorrect boundary conditions in the
Graphics component.
Mitigation bypass in the DOM: Security component.
CVE-2026-0886
CVE-2026-0882
CVE-2026-0880
CVE-2026-0879
CVE-2026-0877
2026-01-13
2026-01-15
chromium -- multiple security fixes
chromium
144.0.7559.59
ungoogled-chromium
144.0.7559.59
Chrome Releases reports:
This update includes 10 security fixes:
- [458914193] High CVE-2026-0899: Out of bounds memory access in V8. Reported by @p1nky4745 on 2025-11-08
- [465730465] High CVE-2026-0900: Inappropriate implementation in V8. Reported by Google on 2025-12-03
- [40057499] High CVE-2026-0901: Inappropriate implementation in Blink. Reported by Irvan Kurniawan (sourc7) on 2021-10-04
- [469143679] Medium CVE-2026-0902: Inappropriate implementation in V8. Reported by 303f06e3 on 2025-12-16
- [444803530] Medium CVE-2026-0903: Insufficient validation of untrusted input in Downloads. Reported by Azur on 2025-09-13
- [452209495] Medium CVE-2026-0904: Incorrect security UI in Digital Credentials. Reported by Hafiizh on 2025-10-15
- [465466773] Medium CVE-2026-0905: Insufficient policy enforcement in Network. Reported by Google on 2025-12-02
- [467448811] Low CVE-2026-0906: Incorrect security UI. Reported by Khalil Zhani on 2025-12-10
- [444653104] Low CVE-2026-0907: Incorrect security UI in Split View. Reported by Hafiizh on 2025-09-12
- [452209503] Low CVE-2026-0908: Use after free in ANGLE. Reported by Glitchers BoB 14th. on 2025-10-15
CVE-2026-0899
CVE-2026-0900
CVE-2026-0901
CVE-2026-0902
CVE-2026-0903
CVE-2026-0904
CVE-2026-0905
CVE-2026-0906
CVE-2026-0907
CVE-2026-0908
https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_13.html
2026-01-13
2026-01-15
virtualenv -- CWE-59: Improper Link Resolution Before File Access ('Link Following')
py310-virtualenv
py311-virtualenv
py312-virtualenv
py313-virtualenv
py313t-virtualenv
py314-virtualenv
20.36.1
https://github.com/pypa/virtualenv/security/advisories/GHSA-597g-3phw-6986 reports:
virtualenv is a tool for creating isolated virtual python environments.
Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use)
vulnerabilities in virtualenv allow local attackers to perform
symlink-based attacks on directory creation operations. An attacker
with local access can exploit a race condition between directory
existence checks and creation to redirect virtualenv's app_data and
lock file operations to attacker-controlled locations. This issue
has been patched in version 20.36.1.
CVE-2026-22702
https://cveawg.mitre.org/api/cve/CVE-2026-22702
2026-01-10
2026-01-12
libtasn1 -- Stack-based buffer overflow
libtasn1
4.21.0
oss-security@ list reports:
Stack-based buffer overflow in libtasn1 version: v4.20.0.
The function fails to validate the size of input data resulting
in a buffer overflow in asn1_expend_octet_string.
CVE-2025-13151
https://nvd.nist.gov/vuln/detail/CVE-2025-13151
2026-01-07
2026-01-11
Gitlab -- vulnerabilities
gitlab-ce
gitlab-ee
18.7.018.7.1
18.6.018.6.3
8.3.018.5.5
Gitlab reports:
Stored Cross-site Scripting issue in GitLab Flavored Markdown placeholders impacts GitLab CE/EE
Cross-site Scripting issue in Web IDE impacts GitLab CE/EE
Missing Authorization issue in Duo Workflows API impacts GitLab EE
Missing Authorization issue in AI GraphQL mutation impacts GitLab EE
Denial of Service issue in import functionality impacts GitLab CE/EE
Insufficient Access Control Granularity issue in GraphQL runnerUpdate mutation impacts GitLab CE/EE
Information Disclosure issue in Mermaid diagram rendering impacts GitLab CE/EE
CVE-2025-9222
CVE-2025-13761
CVE-2025-13772
CVE-2025-13781
CVE-2025-10569
CVE-2025-11246
CVE-2025-3950
https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/
2026-01-07
2026-01-11
mail/mailpit -- Cross-Site WebSocket Hijacking
mailpit
1.28.2
Mailpit author reports:
The Mailpit WebSocket server is configured to accept
connections from any origin. This lack of Origin header
validation introduces a Cross-Site WebSocket Hijacking
(CSWSH) vulnerability.
An attacker can host a malicious website that, when
visited by a developer running Mailpit locally, establishes
a WebSocket connection to the victim's Mailpit instance
(default ws://localhost:8025). This allows the attacker
to intercept sensitive data such as email contents,
headers, and server statistics in real-time.
CVE-2026-22689
https://github.com/axllent/mailpit/security/advisories/GHSA-524m-q5m7-79mm
2026-01-10
2026-01-10
phpmyfaq -- multiple vulnerabilities
phpmyfaq-php82
phpmyfaq-php83
phpmyfaq-php84
phpmyfaq-php85
4.0.16
phpMyFAQ team reports:
Stored cross-site scripting (XSS) and unauthenticated config backup
download vulnerability
https://www.phpmyfaq.de/security/advisory-2025-12-29/
2025-12-29
2026-01-10
chromium -- multiple security fixes
chromium
143.0.7499.192
ungoogled-chromium
143.0.7499.192
Chrome Releases reports:
This update includes 1 security fix:
- [463155954] High CVE-2026-0628: Insufficient policy enforcement in WebView tag. Reported by Gal Weizman on 2025-11-23
CVE-2026-0628
https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop.html
2026-01-06
2026-01-07
security/libsodium -- crypto_core_ed25519_is_valid_point mishandles checks for whether an elliptic curve point is valid
libsodium
1.0.21
Libsodium maintainer reports:
The function crypto_core_ed25519_is_valid_point(), a low-level function
used to check if a given elliptic curve point is valid, was supposed to
reject points that aren't in the main cryptographic group,
but some points were slipping through.
CVE-2025-69277
https://00f.net/2025/12/30/libsodium-vulnerability/
2025-12-30
2026-01-07
mail/mailpit -- Server-Side Request Forgery
mailpit
1.28.1
Mailpit author reports:
A Server-Side Request Forgery (SSRF) vulnerability
exists in Mailpit's /proxy endpoint that allows attackers
to make requests to internal network resources.
The /proxy endpoint allows requests to internal network
resources. While it validates http:// and https:// schemes,
it does not block internal IP addresses, allowing attackers
to access internal services and APIs.
CVE-2026-21859
https://github.com/axllent/mailpit/security/advisories/GHSA-8v65-47jx-7mfr
2026-01-06
2026-01-06
net-mgmt/net-snmp -- Remote Code Execution (snmptrapd)
net-snmp
5.9.5,1
net-snmp development team reports:
A specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and
the daemon to crash.
CVE-2025-68615
https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq
2025-12-23
2026-01-06
gstreamer1-plugins-bad -- Out-of-bounds reads in MIDI parser
gstreamer1-plugins-bad
1.26.10
The GStreamer Security Center reports:
Multiple out-of-bounds reads in the MIDI parser that can cause
crashes for certain input files.
CVE-2025-67326
CVE-2025-67327
https://gstreamer.freedesktop.org/security/sa-2025-0009.html
2025-12-27
2026-01-04