{"cves":[{"id":"CVE-2026-45764","published":"2026-09-10T22:16:00","updated_at":"2026-09-16T10:39:57.993148+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Prior to versions 7.0.16 and\n8.0.5, a protocol change while processing HTTP/2 traffic could lead to type\nconfusion in Suricata. Crafted traffic may cause Suricata to crash,\nresulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As\na workaround, disable HTTP/2 parsing if it is not required.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45764","https://github.com/OISF/suricata/security/advisories/GHSA-5rvq-72r5-rqhr","https://redmine.openinfosecfoundation.org/issues/8494 (suricata-7.0.16)","https://redmine.openinfosecfoundation.org/issues/8493 (suricata-8.0.5)","https://github.com/OISF/suricata/commit/61c4df2821441226a2e0d3a5723f44ba95764cdd (suricata-7.0.16)","https://github.com/OISF/suricata/commit/75a4641af6ee87a605e10557e6e2417330227a6a (suricata-8.0.5)","https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315","https://redmine.openinfosecfoundation.org/issues/8492"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:8.0.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45762","published":"2026-09-10T22:16:00","updated_at":"2026-09-16T10:42:08.033800+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Prior to versions 7.0.16 and\n8.0.5, Suricata's IP defragmentation tracker lookup did not verify that an\nexisting tracker used the same IP address family as the packet being\nprocessed. Under crafted fragmented IPv4/IPv6 traffic, an IPv6 fragment\ncould be associated with an IPv4 defragmentation tracker. This can lead to\na remote packet-triggered crash and denial of service when Suricata\nperforms the relevant defragmentation. Versions 7.0.16 and 8.0.5 contain a\nfix. As a workaround, if using Suricata as an IDS with AF_PACKET, enabling\nAF_PACKET's `defrag` option may prevent Suricata from seeing such\nfragmented packets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45762","https://github.com/OISF/suricata/security/advisories/GHSA-gv2j-f6jv-3878","https://redmine.openinfosecfoundation.org/issues/8512 (suricata-7.0.16)","https://redmine.openinfosecfoundation.org/issues/8511 (suricata-8.0.5)","https://github.com/OISF/suricata/commit/b8ae15e2a049fac8714a6f37be3171a7376a4255 (suricata-7.0.16)","https://github.com/OISF/suricata/commit/97d6fa9e1467f6e6957f32b034199c51980e2ffd (suricata-8.0.5)","https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315","https://redmine.openinfosecfoundation.org/issues/8510"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:8.0.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-79592","published":"2026-09-10T21:17:00","updated_at":"2026-09-16T10:42:46.630673+00:00","description":"\nAn out-of-bounds read vulnerability exists in the xls_dumpSummary()\nfunction of libxls 1.6.3 due to insufficient validation of file-controlled\nOLE summary offsets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-79592","https://github.com/libxls/libxls/issues/162","https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147420"],"patches":{"r-cran-readxl":[]},"tags":{},"packages":[{"name":"r-cran-readxl","source":"https://ubuntu.com/security/cve?package=r-cran-readxl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=r-cran-readxl","debian":"https://tracker.debian.org/pkg/r-cran-readxl","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-79591","published":"2026-09-10T21:17:00","updated_at":"2026-09-17T07:38:15.414219+00:00","description":"\nA heap-buffer-overflow and use-after-free vulnerability exists in the\nxls_getCSS() function of libxls 1.6.3 due to insufficient validation of a\nfile-controlled font index.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-79591","https://github.com/libxls/libxls/issues/161","https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147420"],"patches":{"r-cran-readxl":[]},"tags":{},"packages":[{"name":"r-cran-readxl","source":"https://ubuntu.com/security/cve?package=r-cran-readxl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=r-cran-readxl","debian":"https://tracker.debian.org/pkg/r-cran-readxl","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45761","published":"2026-09-10T21:17:00","updated_at":"2026-09-16T10:34:44.243337+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Prior to versions 7.0.16 and\n8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap\nbuffer overflow while Suricata is loading signatures. The issue is reached\nduring rule parsing/loading rather than by network traffic alone. Versions\n7.0.16 and 8.0.5 contain a fix. As a workaround, preprocess rules to check\nthat frames are all lowercase and/or only load trusted rulesets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45761","https://github.com/OISF/suricata/security/advisories/GHSA-r74x-74x5-r9vm","https://redmine.openinfosecfoundation.org/issues/8528 (suricata-7.0.16)","https://redmine.openinfosecfoundation.org/issues/8527 (suricata-8.0.5)","https://github.com/OISF/suricata/commit/df3336bf4f8e8034570b1608f87065391d79c022 (suricata-7.0.16)","https://github.com/OISF/suricata/commit/31d3977720990bb0efd20be08a6c2362287ea460 (suricata-8.0.5)","https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315","https://redmine.openinfosecfoundation.org/issues/8526"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:8.0.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45759","published":"2026-09-10T21:17:00","updated_at":"2026-09-16T10:41:58.099503+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Prior to versions 7.0.16 and\n8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP\n`Content-Disposition` headers during HTTP response body processing. Crafted\nHTTP traffic could cause excessive CPU usage and denial of service.\nVersions 7.0.16 and 8.0.5 contain a fix. As a workaround, use a rule like\n`alert http1 any any -> any any (sid: 1; http.request_header; content:\n\"Content-Disposition:\"; startswith; bsize: > 8192; bypass;)`.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45759","https://github.com/OISF/suricata/security/advisories/GHSA-cfq5-g2v5-6652","https://redmine.openinfosecfoundation.org/issues/8531 (suricata-7.0.16)","https://redmine.openinfosecfoundation.org/issues/8530 (suricata-8.0.5)","https://github.com/OISF/suricata/commit/a41b135c5c054c806346f8d6e02d67b8f5594be0 (suricata-7.0.16)","https://github.com/OISF/suricata/commit/8abe0f2a8de0d910d4d4461474f5bfb519877053 (suricata-8.0.5)","https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315","https://redmine.openinfosecfoundation.org/issues/8529"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:8.0.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45752","published":"2026-09-10T21:17:00","updated_at":"2026-09-16T10:37:54.058068+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Starting in version 8.0.0\nand prior to version 8.0.5, when certain detection transforms are chained,\nthe decompress transform pipeline could read from an inspection buffer\nafter it had been reallocated and freed. The issue is reached during\nnetwork traffic processing, but requires a malicious rule as Suricata will\ncrash whatever the traffic. Version 8.0.5 contains a fix. As a workaround,\navoid rules that chain `gunzip` or `zlib_deflate` with `max-size` bigger\nthan 4096 after another transform.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45752","https://github.com/OISF/suricata/security/advisories/GHSA-qmc9-vqq2-8mv3","https://redmine.openinfosecfoundation.org/issues/8541 (suricata-8.0.5)","https://github.com/OISF/suricata/commit/11d1fe1ca866d82e8bb3dd4493016188d890aebd (suricata-8.0.5)","https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315","https://redmine.openinfosecfoundation.org/issues/8536"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:8.0.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45751","published":"2026-09-10T21:17:00","updated_at":"2026-09-16T10:38:42.747675+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Prior to versions 7.0.16 and\n8.0.5, Suricata's inspection-buffer helper could leave an inspection\npointer referencing freed memory after a chained transform caused the\nbacking buffer to be reallocated. The issue is reached during a specific\nnetwork traffic processing, and requires a specific but not malicious rule.\nVersions 7.0.16 and 8.0.5 contain a fix. As a workaround, avoid rules that\nchain `dotprefix` transform after another one.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45751","https://github.com/OISF/suricata/security/advisories/GHSA-59q6-j4w8-8pjx","https://redmine.openinfosecfoundation.org/issues/8542 (suricata-7.0.16)","https://redmine.openinfosecfoundation.org/issues/8540 (suricata-8.0.5)","https://github.com/OISF/suricata/commit/89cde65f8d4314b007c723843b79dfa9e5e26e88 (suricata-7.0.16)","https://github.com/OISF/suricata/commit/3d371fff99d7d0af0912543174c6ea2abb0ff6a3 (suricata-8.0.5)","https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315","https://redmine.openinfosecfoundation.org/issues/8537"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:8.0.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-89087","published":"2026-09-10T20:17:00","updated_at":"2026-09-16T18:46:28.788385+00:00","description":"\nThe cstruct package before 6.3.0 for OCaml mishandles indexes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-89087","https://osv.dev/vulnerability/OSEC-2026-20","https://github.com/mirage/ocaml-cstruct/pull/324 (v6.3.0)"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147522"],"patches":{"ocaml-cstruct":[]},"tags":{},"packages":[{"name":"ocaml-cstruct","source":"https://ubuntu.com/security/cve?package=ocaml-cstruct","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ocaml-cstruct","debian":"https://tracker.debian.org/pkg/ocaml-cstruct","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88060","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T19:34:32.377184+00:00","description":"\nAngular is a development platform for building mobile and desktop web\napplications using TypeScript/JavaScript and other languages. Prior to\n20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in\n@angular/platform-server serializes untrusted input inside template content\nnested in fallback raw-content elements such as noscript, iframe, noembed,\nand noframes. The Domino serializer's fallbackRawContentTags traversal\nstopped at the DocumentFragment used by template.content, so matching\nclosing tags in xmp, style, script, comments, or text nodes were not\nescaped. Standard interpolation with comments or text nodes is reachable\nwithout relaxed schemas; literal xmp or style requires\nCUSTOM_ELEMENTS_SCHEMA or NO_ERRORS_SCHEMA, while Renderer2 imperative DOM\nconstruction is unconditionally affected. When HTML5 RAWTEXT browser\nparsing encounters the unescaped closing tag, it exits the fallback\ncontainer and interprets trailing markup as active DOM elements, enabling\narbitrary JavaScript execution. This issue is fixed in versions 20.3.30,\n21.2.22, and 22.1.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88060","https://github.com/angular/angular/security/advisories/GHSA-v3p8-whq6-r5jg"],"bugs":[""],"patches":{"angular.js":[]},"tags":{},"packages":[{"name":"angular.js","source":"https://ubuntu.com/security/cve?package=angular.js","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=angular.js","debian":"https://tracker.debian.org/pkg/angular.js","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88059","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T17:46:14.219976+00:00","description":"\nAngular is a development platform for building mobile and desktop web\napplications using TypeScript/JavaScript and other languages. Prior to\n20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache\ncan cache an authenticated response when Server-Side Rendering (SSR) and\nhydration use a hierarchical HttpClient configured with\nwithRequestsMadeViaParent. The child TransferCache evaluates an initially\nanonymous request before delegation, then a parent withInterceptors chain\nadds an Authorization header, cookie, or API token; although the parent\ncache skips the authenticated request, the child still stores the private\nresponse in TransferState serialized as JSON in the ng-state script.\nExploitation requires provideClientHydration, child provideHttpClient\ndelegation through withRequestsMadeViaParent, parent-level credential\ninjection, and an SSR HTML response shared across users by a CDN, reverse\nproxy, or application cache. A later unauthenticated or unauthorized\nvisitor can receive the cached HTML containing the earlier authenticated\nuser's sensitive response data. Applications can mitigate by attaching\ncredentials at the child, filtering sensitive endpoints with\nwithHttpTransferCacheOptions, disabling transfer caching for sensitive\nroutes, or marking personalized HTML private or no-store. This issue is\nfixed in versions 20.3.28, 21.2.20, and 22.1.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88059","https://github.com/angular/angular/security/advisories/GHSA-p297-fm68-3q8c"],"bugs":[""],"patches":{"angular.js":[]},"tags":{},"packages":[{"name":"angular.js","source":"https://ubuntu.com/security/cve?package=angular.js","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=angular.js","debian":"https://tracker.debian.org/pkg/angular.js","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88058","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T17:08:41.763825+00:00","description":"\nAngular is a development platform for building mobile and desktop web\napplications using TypeScript/JavaScript and other languages. Prior to\n20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in\n@angular/platform-server serializes ProcessingInstruction DOM nodes inside\nfallback raw-content elements without escaping matching ancestor closing\ntags. ProcessingInstruction data escaped greater-than characters but left\nless-than characters untouched and did not inspect fallback ancestors, so\ndata such as a matching closing tag prematurely terminates noscript,\niframe, noembed, or noframes containers. The vulnerable nodes cannot be\nauthored through standard Angular templates; reachability requires\napplication or library code using\ninject(DOCUMENT).createProcessingInstruction with attacker-controlled data\nor Renderer2 DOM insertion inside a fallback container. In HTML5 RAWTEXT\nparsing, the premature close causes subsequent sibling elements to be\ninterpreted as live HTML and enables arbitrary JavaScript execution in a\nvictim's browser. This issue is fixed in versions 20.3.30, 21.2.22, and\n22.1.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88058","https://github.com/angular/angular/security/advisories/GHSA-j3r3-mxqp-r2p4"],"bugs":[""],"patches":{"angular.js":[]},"tags":{},"packages":[{"name":"angular.js","source":"https://ubuntu.com/security/cve?package=angular.js","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=angular.js","debian":"https://tracker.debian.org/pkg/angular.js","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88057","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T18:52:32.574299+00:00","description":"\nAngular is a development platform for building mobile and desktop web\napplications using TypeScript/JavaScript and other languages. Prior to\n20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in\n@angular/core and @angular/compiler could omit or select an incorrect\nsanitizer for security-sensitive directive host bindings because\nSecurityContext was derived from the declaring directive or component\nselector rather than the concrete host element. The mismatch is reachable\nthrough hostDirectives composition, inherited HostBinding declarations,\ncreateComponent with a custom hostElement or dynamic directives, SVG/MathML\nnamespace elements, and tag-neutral selectors such as :not(...).\nAttacker-controlled href, src, action, xlink:href, or data values can\ntherefore reach DOM attributes without Angular's built-in sanitizer and\nexecute arbitrary JavaScript in the user's browser context. Applications\nunable to upgrade can use DomSanitizer.sanitize with SecurityContext.URL\nbefore assignment or restrict inputs to validated HTTP and HTTPS URL\nschemes. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88057","https://github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg"],"bugs":[""],"patches":{"angular.js":[]},"tags":{},"packages":[{"name":"angular.js","source":"https://ubuntu.com/security/cve?package=angular.js","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=angular.js","debian":"https://tracker.debian.org/pkg/angular.js","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88056","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T23:01:25.677013+00:00","description":"\nAngular is a development platform for building mobile and desktop web\napplications using TypeScript/JavaScript and other languages. Prior to\n20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in\n@angular/platform-server processes user-controlled resource or request URLs\nthrough HttpClient after application code validates them with WHATWG URL\nparsing. The resolveUrl and parseUrl utilities called\nString.prototype.trim(), which removed leading Unicode whitespace such as\nU+00A0 or U+FEFF after the input passed a same-origin check, converting a\nrelative path into a protocol-relative attacker-controlled URL. In affected\napplications that attach sensitive server-side credentials such as\nAuthorization headers to approved requests,\nrelativeUrlsTransformerInterceptorFn then dispatched the request to the\nattacker-controlled origin, causing SSRF and credential disclosure. This\nissue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88056","https://github.com/angular/angular/security/advisories/GHSA-f6mr-pjwc-34m4"],"bugs":[""],"patches":{"angular.js":[]},"tags":{},"packages":[{"name":"angular.js","source":"https://ubuntu.com/security/cve?package=angular.js","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=angular.js","debian":"https://tracker.debian.org/pkg/angular.js","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88036","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T17:55:27.309499+00:00","description":"\nImproper neutralization of special elements in data query logic in the\nGridFS component of the MongoDB C Driver can cause a caller-supplied\nstructured file identifier to be interpreted as a query condition rather\nthan as a literal identifier. An authenticated user who can influence the\nidentifier passed by an affected application may obtain stored file content\nbeyond the intended target or cause all GridFS file chunks in the affected\nbucket to be removed, rendering stored file content unreadable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88036","https://jira.mongodb.org/browse/CDRIVER-6427"],"bugs":[""],"patches":{"mongo-c-driver":[]},"tags":{},"packages":[{"name":"mongo-c-driver","source":"https://ubuntu.com/security/cve?package=mongo-c-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mongo-c-driver","debian":"https://tracker.debian.org/pkg/mongo-c-driver","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88035","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T19:34:32.377184+00:00","description":"\nA size check in the client-side authentication path of the MongoDB C Driver\ncan wrap around, so an unusually large user-name value is accepted and\ncopied past the end of a small buffer. A party able to set the driver's\nconnection settings may cause the application that embeds the driver to\nterminate unexpectedly. Reaching this code requires a build in which the\noptional external SASL authentication backend is present and a connection\nconfigured to use it.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.7,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88035"],"bugs":[""],"patches":{"mongodb":[]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88034","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T22:42:09.585975+00:00","description":"\nImproper neutralization of special elements in data query logic in the\nGridFS component of the MongoDB C++ Driver can cause a caller-supplied\nstructured file identifier to be interpreted as a query condition rather\nthan as a literal identifier. An authenticated user who can influence the\nidentifier passed by an affected application may obtain stored file content\nbeyond the intended target or cause all GridFS file chunks in the affected\nbucket to be removed, rendering stored file content unreadable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88034","https://jira.mongodb.org/browse/CXX-3556"],"bugs":[""],"patches":{"mongo-cxx-driver":[]},"tags":{},"packages":[{"name":"mongo-cxx-driver","source":"https://ubuntu.com/security/cve?package=mongo-cxx-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mongo-cxx-driver","debian":"https://tracker.debian.org/pkg/mongo-cxx-driver","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.5.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88033","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T22:52:31.048127+00:00","description":"\nImproper neutralization of special elements in data query logic in the\nGridFS component of the MongoDB Java Driver can cause a caller-supplied\nstructured file identifier to be interpreted as a query condition rather\nthan as a literal identifier. An authenticated user who can influence the\nidentifier passed by an affected application may obtain stored file content\nbeyond the intended target or cause all GridFS file chunks in the affected\nbucket to be removed, rendering stored file content unreadable. The\naffected rename operation may also rename a stored file other than the\nintended target.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88033","https://jira.mongodb.org/browse/JAVA-6283"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147406"],"patches":{"mongo-java-driver":[]},"tags":{},"packages":[{"name":"mongo-java-driver","source":"https://ubuntu.com/security/cve?package=mongo-java-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mongo-java-driver","debian":"https://tracker.debian.org/pkg/mongo-java-driver","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88032","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T22:22:15.260209+00:00","description":"\nA use-after-free in the reactive client-side encryption component of the\nMongoDB Java Driver can cause native resources to be freed while an\naffected encrypted operation is still using them when the operation is\ncancelled. A party able to cause such an operation to be cancelled may\ncause the hosting application process to terminate. Reaching the issue\nrequires an affected reactive encryption configuration that retrieves KMS\ncredentials on demand.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88032","https://jira.mongodb.org/browse/JAVA-6276"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147406"],"patches":{"mongo-java-driver":[]},"tags":{},"packages":[{"name":"mongo-java-driver","source":"https://ubuntu.com/security/cve?package=mongo-java-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mongo-java-driver","debian":"https://tracker.debian.org/pkg/mongo-java-driver","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88021","published":"2026-09-10T19:17:00","updated_at":"2026-09-16T17:41:33.429655+00:00","description":"\nConsul and Consul Enterprise are vulnerable to an authorization bypass in\nthe Connect service mesh that may allow a service to reach a destination it\nis not authorized to access. When building Envoy RBAC rules to enforce\nConnect intentions, Consul did not correctly escape certain characters in\nservice names, namespaces, and partitions, causing the generated\nauthorization rules to match more broadly than intended. This vulnerability\n(CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18,\n1.22.12 and 2.0.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88021"],"bugs":[""],"patches":{"consul":[]},"tags":{},"packages":[{"name":"consul","source":"https://ubuntu.com/security/cve?package=consul","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=consul","debian":"https://tracker.debian.org/pkg/consul","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":1340,"limit":20,"total_results":79316}