
Open Source Security Mailing List
Discussion of security flaws, concepts, and practices in the Open Source community
List Archives
- Jan–Mar
- Apr–Jun
- Jul–Sep
- Oct–Dec
- 2026
- 431
- 1080
- 550
- –
- 2025
- 262
- 289
- 251
- 361
- 2024
- 358
- 314
- 293
- 183
- 2023
- 220
- 284
- 269
- 356
- 2022
- 212
- 220
- 239
- 273
- 2021
- 281
- 236
- 193
- 182
- 2020
- 131
- 219
- 211
- 241
- 2019
- 199
- 237
- 257
- 176
- 2018
- 287
- 256
- 284
- 279
- 2017
- 701
- 658
- 596
- 437
- 2016
- 738
- 637
- 689
- 788
- 2015
- 1068
- 839
- 658
- 618
- 2014
- 714
- 711
- 886
- 1185
- 2013
- 777
- 648
- 688
- 583
- 2012
- 815
- 578
- 591
- 549
- 2011
- 640
- 738
- 550
- 591
- 2010
- 291
- 376
- 465
- 383
- 2009
- 250
- 264
- 272
- 304
- 2008
- 206
- 390
- 402
- 358
Latest Posts
CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them
Timothy Legge (Aug 22)
========================================================================
CVE-2026-75866 CPAN Security Group
========================================================================
CVE ID: CVE-2026-75866
Distribution: Punk-OAuth2
Versions: through 0.03
MetaCPAN: https://metacpan.org/dist/Punk-OAuth2
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens...
CVE-2026-75870: Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret
Timothy Legge (Aug 22)
========================================================================
CVE-2026-75870 CPAN Security Group
========================================================================
CVE ID: CVE-2026-75870
Distribution: Punk
Versions: before 0.18
MetaCPAN: https://metacpan.org/dist/Punk
Punk versions before 0.18 for Perl allow session cookie forgery via an
empty default HMAC key...
[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File
advisories (Aug 22)
----------------------------------------------------------------------------
NotCVE Advisory — NotCVE-2026-0013
----------------------------------------------------------------------------
[-] Summary:
Eval injection in the Kenwood ITM file format driver of CHIRP, an
open-source application for programming amateur radios, allows an attacker
who can persuade a user to open a crafted radio file to execute arbitrary
Python code with the...
Re: Emacs zero-click local command execution via TRAMP
nightmare . yeah27 (Aug 21)
Emacs has no security releases; do we have any idea if this will
be fixed in Emacs 31?
CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
Robert Rothenberg (Aug 21)
========================================================================
CVE-2026-77781 CPAN Security Group
========================================================================
CVE ID: CVE-2026-77781
Distribution: Tie-Hash-Regex
Versions: before 2.0.0
MetaCPAN: https://metacpan.org/dist/Tie-Hash-Regex
VCS Repo: ...
Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
Kevin Riggle (Aug 21)
Hey Thomas,
Sorry for my delayed response. I see that these patches are now in the
process of landing. Thank you so much for digging in on this and
providing this context!
Best,
- Kevin
Emacs zero-click local command execution via TRAMP
Sean Whitton (Aug 21)
Bas Alberts of the GitHub Security Lab discovered a local command
execution vulnerability in GNU Emacs 30.2 onwards, and possibly earlier.
I am attaching a fix prepared by Michael Albinus, the TRAMP maintainer.
Here is Bas's description of the problem (edited down a bit).
--8<---------------cut here---------------start------------->8---
1. Tramp: local shell command injection through the user field
(tramp-sh.el, CRITICAL)...
[OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-76878) errata 1
Goutham Pacha Ravi (Aug 20)
============================================================================================
OSSA-2026-036: Aodh cross-project alarm enumeration and Watcher webhook
authorization bypass
============================================================================================
:Date: August 19, 2026
:CVE: CVE-2026-76878
Affects
~~~~~~~
- Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0
- Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2,...
[OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStack
Goutham Pacha Ravi (Aug 20)
OSSN-0108: Multiple authentication vulnerabilities in Ceph
---
### Summary ###
The latest Ceph releases of Ceph 20.2.4 and Ceph 19.2.6 patch four CVEs
across several components (CVE-2025-30156, CVE-2026-39944, CVE-2026-50152
and CVE-2026-54330). All OpenStack services using CephX keyrings are
affected.
Ceph servers should be upgraded and their CephX keyrings should be rotated.
The CephX keyrings used by OpenStack should be rotated only after...
CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Manuel Huber (Aug 20)
This vulnerability has been fixed in Kata Containers. The fix will be
included
in the upcoming 4.1.0 release, which is expected to be available shortly:
genpolicy: don't match image pull storages to mounts
<https://github.com/kata-containers/kata-containers/commit/fe8eeefcd0bec13c0
37ceb8f0889e48b75db17ab> . kata-containers/kata-containers@fe8eeef
Description:
A flaw was found in Kata Containers. In configurations utilizing...
CVE-2026-15743: Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable
Robert Rothenberg (Aug 20)
========================================================================
CVE-2026-15743 CPAN Security Group
========================================================================
CVE ID: CVE-2026-15743
Distribution: Catalyst-Plugin-Static-Simple
Versions: through 0.38
MetaCPAN: https://metacpan.org/dist/Catalyst-Plugin-Static-Simple
...
CVE-2026-63044: Apache InLong: Authenticated SSRF via POST /api/node/testConnection
Charles Zhang (Aug 20)
Severity: important
Affected versions:
- Apache InLong 2.0.0 before 2.4.0
Description:
Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can
cause the InLong Manager server to make outbound HTTP requests or TCP connections to
arbitrary internal hosts and ports.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache...
CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Charles Zhang (Aug 20)
Severity: important
Affected versions:
- Apache InLong 2.0.0 before 2.4.0
Description:
Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/12146 .
Credit:
dyingman1 (finder)
References:...
CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints
Charles Zhang (Aug 20)
Severity: moderate
Affected versions:
- Apache InLong 2.0.0 before 2.4.0
Description:
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to
the manager can create, modify and delete Data Node definitions.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] ...
CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDelete
Charles Zhang (Aug 20)
Severity: moderate
Affected versions:
- Apache InLong 2.0.0 before 2.4.0
Description:
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no
authorization check, any authenticated user can logically delete ALL stream sources.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] ...
More Lists
Dozens of other network security lists are archived at SecLists.Org.
