
Open Source Security Mailing List
Discussion of security flaws, concepts, and practices in the Open Source community
List Archives
- Jan–Mar
- Apr–Jun
- Jul–Sep
- Oct–Dec
- 2026
- 431
- 1080
- 922
- –
- 2025
- 262
- 289
- 251
- 361
- 2024
- 358
- 314
- 293
- 183
- 2023
- 220
- 284
- 269
- 356
- 2022
- 212
- 220
- 239
- 273
- 2021
- 281
- 236
- 193
- 182
- 2020
- 131
- 219
- 211
- 241
- 2019
- 199
- 237
- 257
- 176
- 2018
- 287
- 256
- 284
- 279
- 2017
- 701
- 658
- 596
- 437
- 2016
- 738
- 637
- 689
- 788
- 2015
- 1068
- 839
- 658
- 618
- 2014
- 714
- 711
- 886
- 1185
- 2013
- 777
- 648
- 688
- 583
- 2012
- 815
- 578
- 591
- 549
- 2011
- 640
- 738
- 550
- 591
- 2010
- 291
- 376
- 465
- 383
- 2009
- 250
- 264
- 272
- 304
- 2008
- 206
- 390
- 402
- 358
Latest Posts
[OSSA-2026-042] OpenStack Zaqar: Zaqar empty URL-Signature header bypasses authentication (CVE-2026-97404)
Goutham Pacha Ravi (Sep 24)
=======================================================================
OSSA-2026-042: Zaqar empty URL-Signature header bypasses authentication
=======================================================================
:Date: September 24, 2026
:CVE: CVE-2026-97404
Affects
~~~~~~~
- Zaqar: >=1.0.0 <20.1.2, >=21.0.0 <21.0.2, >=22.0.0 <22.0.2
Description
~~~~~~~~~~~
pple, an independent security researcher, reported that...
[OSSA-2026-041] OpenStack Swift: Cross-container information disclosure via Swift tempurl (CVE-2026-97149)
Goutham Pacha Ravi (Sep 24)
=======================================================================
OSSA-2026-041: Cross-container information disclosure via Swift tempurl
=======================================================================
:Date: September 24, 2026
:CVE: CVE-2026-97149
Affects
~~~~~~~
- Swift: >=1.4.6 <2.35.5, >=2.36.0 <2.36.4, >=2.37.0 <2.37.4, >=2.38.0
<2.38.2
Description
~~~~~~~~~~~
Oren Yomtov from ACT Security and...
CVE-2026-96512: sudo: TZ still affects NOTBEFORE/NOTAFTER
Ermenson Junior (Sep 24)
Hi,
CVE-2026-96512 was assigned to a sudo bug where TZ from the calling user
still affects NOTBEFORE/NOTAFTER checks in sudoers.
If the timestamp in the rule has no trailing Z, parse_gentime() uses
mktime(), which reads TZ again. Commit db669167c fixed an earlier report of
this (no CVE, not mine) but only covered localtime_r(), so mktime() was
still reachable.
A local user can set TZ to an extreme offset and move the time window by
almost 25...
CVE-2026-57590: Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations
Wenjun Ruan (Sep 24)
Severity: low
Affected versions:
- Apache DolphinScheduler before 3.4.3
Description:
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do
not properly verify whether the authenticated user has permission to access the project associated with the target Task
Group.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3,...
Fwd: Tor Project Forum: Security Release 0.4.9.13
Sam James (Sep 23)
Here's the relevant release notes at the link in the email below:
"""
+Changes in version 0.4.9.13 - 2026-09-23
+ This security release includes several high severity fixes, once again
+ originating from the LLM report firehose. The fixes affect all Tor
+ components: relays, clients, and onion services. We strongly recommend
+ upgrading as soon as possible.
+
+ o Major bugfixes (security):
+ - Avoid a set of possible...
Re: Fwd: Tor Project Forum: Security Release 0.4.9.12
Sam James (Sep 23)
Sam James <sam () cmpct info> writes:
These bugs are public now. They're accessible at
https://gitlab.torproject.org/tpo/core/tor/-/work_items/XXXX.
From a quick look, this appears to be the most significant one, as a
malicious guard can influence circuit building to relays of its
choosing, without the tampering being detected by tor.
sam
[kubernetes] CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion
Nathan Herz (Sep 23)
Hello Kubernetes Community,
An NTLM coercion vulnerability exists on Windows nodes when the subPath
supplied in a pod's volumeMounts is set to a symbolic link that points to
an attacker-controlled network share. When a kubelet resolves symlinks, it
does not reject a target that resolves to a UNC path. As a result, the
kubelet will transparently attempt to authenticate to the share using NTLM.
This allows an attacker to obtain the NetNTLMv2...
[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation
Nathan Herz (Sep 23)
Hello Kubernetes Community,
A confused deputy attack exists in the StatefulSet controller that allows a
user with namespace-scoped write permissions on StatefulSet and
ControllerRevision objects to create a cross-namespace pod. An attacker
exploiting this vulnerability would have full control over the resulting
pod’s metadata and specification, including namespace selection. Note that
the cross-namespace pod will be immediately deleted by the...
Re: Flatpak 1.18.1 fixes multiple vulnerabilities
Simon McVittie (Sep 23)
CVE-2026-96808 was allocated for GHSA-qrwq-7qwx-q9rp.
CVE-2026-96807 was allocated for GHSA-99wv-m8rp-g58x.
(Thanks to MITRE CNA-LR for these)
CVE-2026-86247: Apache Tomcat Native: Client certificate requirements can be down-graded
Mark Thomas (Sep 23)
Severity: moderate
Affected versions:
- Apache Tomcat Native 2.0.0 through 2.0.15
- Apache Tomcat Native 1.3.0 through 1.3.8
Description:
Race condition within a thread vulnerability in Apache Tomcat Native
allowed client certificate verification requirements to be down-graded
for some configurations.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from
1.3.0 through 1.3.8. Unsupported versions may also be affected....
CVE-2026-86246: Apache Tomcat Native: Insecure OpenSSL options enabled
Mark Thomas (Sep 23)
Severity: moderate
Affected versions:
- Apache Tomcat Native 2.0.0 through 2.0.15
- Apache Tomcat Native 1.3.0 through 1.3.8
Description:
Initialization of a resource with an insecure default vulnerability in
Apache Tomcat Native enabled insecure options by default including
ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET,
IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX.
This issue affects Apache Tomcat Native: from 2.0.0 through...
CVE-2026-86243: Apache Tomcat Native: DoS via TLS handshake
Mark Thomas (Sep 23)
Severity: important
Affected versions:
- Apache Tomcat Native 2.0.0 through 2.0.15
- Apache Tomcat Native 1.3.0 through 1.3.8
Description:
Buffer over-read vulnerability in Apache Tomcat Native during the TLS
handshake permits a malicious user to trigger a DoS via a JVM crash.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from
1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected.
Users are...
CVE-2026-87022: Apache Tomcat: WebSocket message smuggling with per-message-deflate
Mark Thomas (Sep 23)
Severity: low
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.25
- Apache Tomcat 10.1.0-M1 through 10.1.59
- Apache Tomcat 9.0.0.M1 through 9.0.121
- Apache Tomcat 8.5.0 through 8.5.100
- Apache Tomcat 7.0.56 through 7.0.109
Description:
Improper handling of length parameter inconsistency vulnerability in
Apache Tomcat allows WebSocket message smuggling when
per-message-deflate is used.
This issue affects Apache Tomcat: from...
CVE-2026-86350: Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up
Mark Thomas (Sep 23)
Severity: important
Affected versions:
- Apache Tomcat 11.0.22 through 11.0.25
- Apache Tomcat 10.1.55 through 10.1.59
- Apache Tomcat 9.0.118 through 9.0.121
Description:
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response
smuggling') vulnerability in Apache Tomcat caused by a regression in fix
for CVE-2026-41293 can trigger request header mix-up.
This issue affects Apache Tomcat: from 11.0.22 through 11.0.25,...
CVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Mark Thomas (Sep 23)
Severity: moderate
Affected versions:
- Apache Tomcat 11.0.0-M14 through 11.0.25
- Apache Tomcat 10.1.22 through 10.1.59
- Apache Tomcat 9.0.92 through 9.0.121
Description:
CLIENT_CERT authentication does not fail as expected for some scenarios
when soft fail is disabled vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from
10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.
Users are...
More Lists
Dozens of other network security lists are archived at SecLists.Org.
