{"cves":[{"id":"CVE-2026-33347","published":"2026-03-24T20:16:00","updated_at":"2026-07-10T20:06:40.941137+00:00","description":"\nleague/commonmark is a PHP Markdown parser. From version 2.3.0 to before\nversion 2.8.2, the DomainFilteringAdapter in the Embed extension is\nvulnerable to an allowlist bypass due to a missing hostname boundary\nassertion in the domain-matching regex. An attacker-controlled domain like\nyoutube.com.evil passes the allowlist check when youtube.com is an allowed\ndomain. This issue has been patched in version 2.8.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33347","https://github.com/thephpleague/commonmark/security/advisories/GHSA-hh8v-hgvp-g3f5","https://github.com/thephpleague/commonmark/commit/59fb075d2101740c337c7216e3f32b36c204218b","https://github.com/thephpleague/commonmark/releases/tag/2.8.2","https://ubuntu.com/security/notices/USN-8194-1"],"bugs":[""],"patches":{"php-league-commonmark":["upstream: https://github.com/thephpleague/commonmark/commit/59fb075d2101740c337c7216e3f32b36c204218b"]},"tags":{},"packages":[{"name":"php-league-commonmark","source":"https://ubuntu.com/security/cve?package=php-league-commonmark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-league-commonmark","debian":"https://tracker.debian.org/pkg/php-league-commonmark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.3.1-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.6.7-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.4.2-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"2.8.2-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8194-1"],"notices":[{"id":"USN-8194-1","title":"league/commonmark vulnerabilities","summary":"Several security issues were fixed in league/commonmark.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-21T17:25:51.191310","description":"It was discovered that league/commonmark did not properly restrict\nunsafe attributes when the Attributes extension was enabled. An attacker\ncould possibly use this issue to cause cross-site scripting by injecting\nmalicious code into rendered HTML. This issue only affected Ubuntu 22.04\nLTS and Ubuntu 24.04 LTS. (CVE-2025-46734)\n\nIt was discovered that league/commonmark did not properly block certain\ndisallowed HTML tags in some cases. An attacker could possibly use this\nissue to cause cross-site scripting by inserting malicious HTML that\nbypassed filtering. (CVE-2026-30838)\n\nIt was discovered that league/commonmark did not properly enforce domain\nallowlist checks in the Embed extension. An attacker could possibly use\nthis issue to bypass domain restrictions and cause untrusted content to\nbe treated as allowed. This issue only affected Ubuntu 24.04 LTS.\n(CVE-2026-33347)","is_hidden":false,"release_packages":{"focal":[{"name":"php-league-commonmark","version":"1.3.1-1ubuntu2+esm1","description":"Highly-extensible PHP Markdown parser which fully supports the CommonMark and GFM specs","is_source":true},{"name":"php-league-commonmark","version":"1.3.1-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php-league-commonmark","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"php-league-commonmark","version":"1.6.7-1ubuntu0.1~esm1","description":"Highly-extensible PHP Markdown parser which fully supports the CommonMark and GFM specs","is_source":true},{"name":"php-league-commonmark","version":"1.6.7-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php-league-commonmark","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"php-league-commonmark","version":"2.4.2-2ubuntu0.1~esm1","description":"Highly-extensible PHP Markdown parser which fully supports the CommonMark and GFM specs","is_source":true},{"name":"php-league-commonmark","version":"2.4.2-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php-league-commonmark","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-33347","CVE-2025-46734","CVE-2026-30838"]}]},{"id":"CVE-2026-23924","published":"2026-03-24T19:16:00","updated_at":"2026-07-10T19:47:35.135064+00:00","description":"\nZabbix Agent 2 Docker plugin does not properly sanitize the\n'docker.container_info' parameters when forwarding them to the Docker\ndaemon. An attacker capable of invoking Agent 2 can read arbitrary files\nfrom running Docker containers by injecting them via the Docker archive\nAPI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23924","https://support.zabbix.com/browse/ZBX-27642"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132226"],"patches":{"zabbix":[]},"tags":{},"packages":[{"name":"zabbix","source":"https://ubuntu.com/security/cve?package=zabbix","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zabbix","debian":"https://tracker.debian.org/pkg/zabbix","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-23921","published":"2026-03-24T19:16:00","updated_at":"2026-09-14T08:39:12.049807+00:00","description":"\nA low privilege Zabbix user with API access can exploit a blind SQL\ninjection vulnerability in include/classes/api/CApiService.php to execute\narbitrary SQL selects via the sortfield parameter. Although query results\nare not returned directly, an attacker can exfiltrate arbitrary database\ndata through time-based techniques, potentially leading to session\nidentifier disclosure and administrator account compromise.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23921","https://support.zabbix.com/browse/ZBX-27640"],"bugs":[""],"patches":{"zabbix":[]},"tags":{},"packages":[{"name":"zabbix","source":"https://ubuntu.com/security/cve?package=zabbix","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zabbix","debian":"https://tracker.debian.org/pkg/zabbix","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:7.0.22+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:7.0.22+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-23920","published":"2026-03-24T19:16:00","updated_at":"2026-09-14T08:33:04.275898+00:00","description":"\nHost and event action script input is validated with a regex (set by the\nadministrator), but the validation runs in multiline mode. If ^ and $\nanchors are used in user input validation, an injected newline lets\nauthenticated users bypass the check and inject shell commands.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23920","https://support.zabbix.com/browse/ZBX-27639"],"bugs":[""],"patches":{"zabbix":[]},"tags":{},"packages":[{"name":"zabbix","source":"https://ubuntu.com/security/cve?package=zabbix","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zabbix","debian":"https://tracker.debian.org/pkg/zabbix","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:7.0.22+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:7.0.22+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-23919","published":"2026-03-24T19:16:00","updated_at":"2026-07-10T19:45:54.306832+00:00","description":"\nFor performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape)\ncontexts (used in script items, JavaScript reprocessing, Webhooks). This\ncan lead to confidentiality loss where a regular (non-super) Zabbix\nadministrator leaks data for hosts they do not have access to. A fix has\nbeen released that makes the built in Zabbix JavaScript objects read-only,\nbut please be advised that usage of global JavaScript variables is not\nrecommended because their content could be leaked. More information in\nZabbix documentation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23919","https://support.zabbix.com/browse/ZBX-27638"],"bugs":[""],"patches":{"zabbix":[]},"tags":{},"packages":[{"name":"zabbix","source":"https://ubuntu.com/security/cve?package=zabbix","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zabbix","debian":"https://tracker.debian.org/pkg/zabbix","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:7.0.22+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:7.0.22+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-32854","published":"2026-03-24T18:16:00","updated_at":"2026-06-26T06:34:56.287437+00:00","description":"\nLibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain\nnull pointer dereference vulnerabilities in the HTTP proxy handlers within\nhttpProcessInput() in httpd.c that allow remote attackers to cause a denial\nof service by sending specially crafted HTTP requests. Attackers can\nexploit missing validation of strchr() return values in the CONNECT and GET\nproxy handling paths to trigger null pointer dereferences and crash the\nserver when httpd and proxy features are enabled.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-32854","https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x","https://www.vulncheck.com/advisories/libvncserver-httpd-proxy-null-pointer-dereference","https://ubuntu.com/security/notices/USN-8463-1"],"bugs":[""],"patches":{"libvncserver":["upstream: https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314"],"vino":[],"x11vnc":[],"veyon":[],"italc":[],"tightvnc":[]},"tags":{},"packages":[{"name":"libvncserver","source":"https://ubuntu.com/security/cve?package=libvncserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvncserver","debian":"https://tracker.debian.org/pkg/libvncserver","statuses":[{"release_codename":"resolute","status":"not-affected","description":"0.9.15+dfsg-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.15+dfsg-3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.9.13+dfsg-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.9.14+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.9.15+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"vino","source":"https://ubuntu.com/security/cve?package=vino","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vino","debian":"https://tracker.debian.org/pkg/vino","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"x11vnc","source":"https://ubuntu.com/security/cve?package=x11vnc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=x11vnc","debian":"https://tracker.debian.org/pkg/x11vnc","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"veyon","source":"https://ubuntu.com/security/cve?package=veyon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=veyon","debian":"https://tracker.debian.org/pkg/veyon","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"italc","source":"https://ubuntu.com/security/cve?package=italc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=italc","debian":"https://tracker.debian.org/pkg/italc","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tightvnc","source":"https://ubuntu.com/security/cve?package=tightvnc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tightvnc","debian":"https://tracker.debian.org/pkg/tightvnc","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8463-1"],"notices":[{"id":"USN-8463-1","title":"LibVNCServer vulnerabilities","summary":"Several security issues were fixed in LibVNCServer.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-23T14:46:54.375752","description":"It was discovered that LibVNCServer had a memory leak in the client cleanup\nfunction. An attacker could possibly use this issue to cause LibVNCServer\nto consume memory, leading to a denial of service. This issue only affected\nUbuntu 22.04 LTS. (CVE-2020-29260)\n\nIt was discovered that LibVNCServer did not properly validate bounds when\nhandling UltraZip encoding subrectangles. A remote attacker could possibly\nuse this issue to obtain sensitive information or cause a denial of\nservice. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 25.04. (CVE-2026-32853)\n\nIt was discovered that LibVNCServer did not properly validate return values\nin the HTTP proxy handlers. A remote attacker could possibly use this issue\nto cause LibVNCServer to crash, resulting in a denial of service. This\nissue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.\n(CVE-2026-32854)\n\nIt was discovered that LibVNCServer did not properly handle Tight encoding\ngradient filter rectangles. A remote attacker could use this issue to cause\nLibVNCServer to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-44988)","is_hidden":false,"release_packages":{"jammy":[{"name":"libvncserver","version":"0.9.13+dfsg-3ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"}],"noble":[{"name":"libvncserver","version":"0.9.14+dfsg-1ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"}],"questing":[{"name":"libvncserver","version":"0.9.15+dfsg-1ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"}],"resolute":[{"name":"libvncserver","version":"0.9.15+dfsg-3ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-29260","CVE-2026-32853","CVE-2026-44988","CVE-2026-32854"]}]},{"id":"CVE-2026-32853","published":"2026-03-24T18:16:00","updated_at":"2026-06-26T06:34:56.287437+00:00","description":"\nLibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a\nheap out-of-bounds read vulnerability in the UltraZip encoding handler that\nallows a malicious VNC server to cause information disclosure or\napplication crash. Attackers can exploit improper bounds checking in the\nHandleUltraZipBPP() function by manipulating subrectangle header counts to\nread beyond the allocated heap buffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-32853","https://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj","https://www.vulncheck.com/advisories/libvncserver-ultrazip-encoding-heap-out-of-bounds-read","https://ubuntu.com/security/notices/USN-8463-1"],"bugs":[""],"patches":{"libvncserver":["upstream: https://github.com/LibVNC/libvncserver/commit/009008e2f4d5a54dd71f422070df3af7b3dbc931"],"vino":[],"x11vnc":[],"veyon":[],"italc":[],"tightvnc":[]},"tags":{},"packages":[{"name":"libvncserver","source":"https://ubuntu.com/security/cve?package=libvncserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvncserver","debian":"https://tracker.debian.org/pkg/libvncserver","statuses":[{"release_codename":"resolute","status":"not-affected","description":"0.9.15+dfsg-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.15+dfsg-3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.9.13+dfsg-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.9.14+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.9.15+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"vino","source":"https://ubuntu.com/security/cve?package=vino","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vino","debian":"https://tracker.debian.org/pkg/vino","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"x11vnc","source":"https://ubuntu.com/security/cve?package=x11vnc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=x11vnc","debian":"https://tracker.debian.org/pkg/x11vnc","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"veyon","source":"https://ubuntu.com/security/cve?package=veyon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=veyon","debian":"https://tracker.debian.org/pkg/veyon","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"italc","source":"https://ubuntu.com/security/cve?package=italc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=italc","debian":"https://tracker.debian.org/pkg/italc","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tightvnc","source":"https://ubuntu.com/security/cve?package=tightvnc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tightvnc","debian":"https://tracker.debian.org/pkg/tightvnc","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8463-1"],"notices":[{"id":"USN-8463-1","title":"LibVNCServer vulnerabilities","summary":"Several security issues were fixed in LibVNCServer.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-23T14:46:54.375752","description":"It was discovered that LibVNCServer had a memory leak in the client cleanup\nfunction. An attacker could possibly use this issue to cause LibVNCServer\nto consume memory, leading to a denial of service. This issue only affected\nUbuntu 22.04 LTS. (CVE-2020-29260)\n\nIt was discovered that LibVNCServer did not properly validate bounds when\nhandling UltraZip encoding subrectangles. A remote attacker could possibly\nuse this issue to obtain sensitive information or cause a denial of\nservice. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 25.04. (CVE-2026-32853)\n\nIt was discovered that LibVNCServer did not properly validate return values\nin the HTTP proxy handlers. A remote attacker could possibly use this issue\nto cause LibVNCServer to crash, resulting in a denial of service. This\nissue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.\n(CVE-2026-32854)\n\nIt was discovered that LibVNCServer did not properly handle Tight encoding\ngradient filter rectangles. A remote attacker could use this issue to cause\nLibVNCServer to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-44988)","is_hidden":false,"release_packages":{"jammy":[{"name":"libvncserver","version":"0.9.13+dfsg-3ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"}],"noble":[{"name":"libvncserver","version":"0.9.14+dfsg-1ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"}],"questing":[{"name":"libvncserver","version":"0.9.15+dfsg-1ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"}],"resolute":[{"name":"libvncserver","version":"0.9.15+dfsg-3ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-29260","CVE-2026-32853","CVE-2026-44988","CVE-2026-32854"]}]},{"id":"CVE-2026-4775","published":"2026-03-24T15:16:00","updated_at":"2026-09-11T13:25:37.525159+00:00","description":"\nA flaw was found in the libtiff library. A remote attacker could exploit a\nsigned integer overflow vulnerability in the putcontig8bitYCbCr44tile\nfunction by providing a specially crafted TIFF file. This flaw can lead to\nan out-of-bounds heap write due to incorrect memory pointer calculations,\npotentially causing a denial of service (application crash) or arbitrary\ncode execution.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"texmaker added an embedded copy of libtiff in bionic"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4775","https://access.redhat.com/security/cve/CVE-2026-4775"],"bugs":["https://gitlab.com/libtiff/libtiff/-/work_items/807","https://gitlab.com/libtiff/libtiff/-/work_items/787","https://bugzilla.redhat.com/show_bug.cgi?id=2450768"],"patches":{"tiff":["upstream: https://gitlab.com/libtiff/libtiff/-/commit/782a11d6b5b61c6dc21e714950a4af5bf89f023c"],"qtwebengine-opensource-src":[],"texmaker":[],"gdal":[],"neuron":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qtwebengine-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebengine-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebengine-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebengine-opensource-src","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"texmaker","source":"https://ubuntu.com/security/cve?package=texmaker","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texmaker","debian":"https://tracker.debian.org/pkg/texmaker","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system tiff","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gdal","source":"https://ubuntu.com/security/cve?package=gdal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdal","debian":"https://tracker.debian.org/pkg/gdal","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system tiff","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"uses system tiff","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system tiff","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system tiff","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system tiff","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system tiff","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"neuron","source":"https://ubuntu.com/security/cve?package=neuron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neuron","debian":"https://tracker.debian.org/pkg/neuron","statuses":[{"release_codename":"resolute","status":"not-affected","description":"dropped embedded libtiff","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"dropped embedded libtiff","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"dropped embedded libtiff","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33554","published":"2026-03-24T15:16:00","updated_at":"2026-08-07T07:43:45.063305+00:00","description":"\nipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on\nresponse messages. The Intelligent Platform Management Interface (IPMI)\nspecification defines a set of interfaces for platform management. It is\nimplemented by a large number of hardware manufacturers to support system\nmanagement. It is most commonly used for sensor reading (e.g., CPU\ntemperatures through the ipmi-sensors command within FreeIPMI) and remote\npower control (the ipmipower command). The ipmi-oem client command\nimplements a set of a IPMI OEM commands for specific hardware vendors. If a\nuser has supported hardware, they may wish to use the ipmi-oem command to\nsend a request to a server to retrieve specific information. Three\nsubcommands were found to have exploitable buffer overflows on response\nmessages. They are: \"ipmi-oem dell get-last-post-code - get the last POST\ncode and string describing the error on some Dell servers,\" \"ipmi-oem\nsupermicro extra-firmware-info - get extra firmware info on Supermicro\nservers,\" and \"ipmi-oem wistron read-proprietary-string - read a\nproprietary string on Wistron servers.\"","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nDenial of service in a command line tool"},{"author":"mdeslaur","note":"Because of compiler hardening in Ubuntu, this stack overflow is\nlimited to a denial of service only. This is a denial of service\nin a command-line tool when connecting to a malicious IPMI\ndevice. Marking this as low priority."}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33554","https://ubuntu.com/security/notices/USN-8613-1"],"bugs":["https://savannah.gnu.org/bugs/?68140","https://savannah.gnu.org/bugs/?68141","https://savannah.gnu.org/bugs/?68142","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132018"],"patches":{"freeipmi":["upstream: https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?id=b03ca4d1bff4626c11db8684564b88cd26a2425d"]},"tags":{"freeipmi":["stack-protector"]},"packages":[{"name":"freeipmi","source":"https://ubuntu.com/security/cve?package=freeipmi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freeipmi","debian":"https://tracker.debian.org/pkg/freeipmi","statuses":[{"release_codename":"noble","status":"released","description":"1.6.13-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.4.11-1.1ubuntu4.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.6.4-3ubuntu1.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1.6.9-2ubuntu0.22.04.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.6.16-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.1.5-3ubuntu3.3+esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.17-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8613-1"],"notices":[{"id":"USN-8613-1","title":"FreeIPMI vulnerabilities","summary":"Several security issues were fixed in FreeIPMI.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-27T14:28:55.289377","description":"Zhihan Zheng discovered that FreeIPMI had several buffer overflow\nvulnerabilities in ipmi-oem response message handling. A local attacker\nwith control a malicious IPMI device or simulator could possibly cause\nFreeIPMI to crash, resulting in a denial of service. (CVE-2026-33554,\nCVE-2026-50031)","is_hidden":false,"release_packages":{"bionic":[{"name":"freeipmi","version":"1.4.11-1.1ubuntu4.1+esm1","description":"in-band and out-of-band Intelligent Platform Management Interface","is_source":true},{"name":"freeipmi","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-bmc-watchdog","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-common","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-ipmidetect","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-ipmiseld","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-tools","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libfreeipmi-dev","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libfreeipmi16","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmiconsole-dev","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmiconsole2","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmidetect-dev","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmidetect0","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmimonitoring-dev","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmimonitoring5a","version":"1.4.11-1.1ubuntu4.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"freeipmi","version":"1.6.4-3ubuntu1.1+esm1","description":"in-band and out-of-band Intelligent Platform Management Interface","is_source":true},{"name":"freeipmi","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-bmc-watchdog","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-common","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-ipmidetect","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-ipmiseld","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"freeipmi-tools","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libfreeipmi-dev","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libfreeipmi17","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmiconsole-dev","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmiconsole2","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmidetect-dev","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmidetect0","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmimonitoring-dev","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"},{"name":"libipmimonitoring6","version":"1.6.4-3ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"freeipmi","version":"1.6.9-2ubuntu0.22.04.3","description":"in-band and out-of-band Intelligent Platform Management Interface","is_source":true},{"name":"freeipmi","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"freeipmi-bmc-watchdog","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"freeipmi-common","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"freeipmi-ipmidetect","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"freeipmi-ipmiseld","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"freeipmi-tools","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libfreeipmi-dev","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libfreeipmi17","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libipmiconsole-dev","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libipmiconsole2","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libipmidetect-dev","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libipmidetect0","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libipmimonitoring-dev","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"},{"name":"libipmimonitoring6","version":"1.6.9-2ubuntu0.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3","pocket":"security"}],"noble":[{"name":"freeipmi","version":"1.6.13-3ubuntu0.1","description":"in-band and out-of-band Intelligent Platform Management Interface","is_source":true},{"name":"freeipmi","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"freeipmi-bmc-watchdog","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"freeipmi-common","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"freeipmi-ipmidetect","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"freeipmi-ipmiseld","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"freeipmi-tools","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libfreeipmi-dev","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libfreeipmi17","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libipmiconsole-dev","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libipmiconsole2","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libipmidetect-dev","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libipmidetect0","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libipmimonitoring-dev","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"},{"name":"libipmimonitoring6","version":"1.6.13-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1","pocket":"security"}],"resolute":[{"name":"freeipmi","version":"1.6.16-1ubuntu0.1","description":"in-band and out-of-band Intelligent Platform Management Interface","is_source":true},{"name":"freeipmi","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"freeipmi-bmc-watchdog","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"freeipmi-common","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"freeipmi-ipmidetect","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"freeipmi-ipmiseld","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"freeipmi-tools","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libfreeipmi-dev","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libfreeipmi17","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libipmiconsole-dev","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libipmiconsole2","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libipmidetect-dev","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libipmidetect0","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libipmimonitoring-dev","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"},{"name":"libipmimonitoring6","version":"1.6.16-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":"https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1","pocket":"security"}],"trusty":[{"name":"freeipmi","version":"1.1.5-3ubuntu3.3+esm1","description":"in-band and out-of-band Intelligent Platform Management Interface","is_source":true},{"name":"freeipmi","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-bmc-watchdog","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-common","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-ipmidetect","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-tools","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libfreeipmi-dev","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libfreeipmi12","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmiconsole-dev","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmiconsole2","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmidetect-dev","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmidetect0","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmimonitoring-dev","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmimonitoring5","version":"1.1.5-3ubuntu3.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"freeipmi","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","description":"in-band and out-of-band Intelligent Platform Management Interface","is_source":true},{"name":"freeipmi","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-bmc-watchdog","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-common","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-ipmidetect","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-ipmiseld","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"freeipmi-tools","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libfreeipmi-dev","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libfreeipmi16","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmiconsole-dev","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmiconsole2","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmidetect-dev","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmidetect0","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmimonitoring-dev","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libipmimonitoring5a","version":"1.4.11-1.1ubuntu4.1~0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeipmi","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-33554","CVE-2026-50031"]}]},{"id":"CVE-2026-32647","published":"2026-03-24T15:16:00","updated_at":"2026-06-06T05:23:26.248104+00:00","description":"\nNGINX Open Source and NGINX Plus have a vulnerability in the\nngx_http_mp4_module module, which might allow an attacker to trigger a\nbuffer over-read or over-write to the NGINX worker memory resulting in its\ntermination or possibly code execution, using a specially crafted MP4 file.\nThis issue affects NGINX Open Source and NGINX Plus if it is built with the\nngx_http_mp4_module module and the mp4 directive is used in the\nconfiguration file. Additionally, the attack is possible only if an\nattacker can trigger the processing of a specially crafted MP4 file with\nthe ngx_http_mp4_module module.\nNote: Software versions which have reached End of Technical Support (EoTS)\nare not evaluated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-32647","https://my.f5.com/manage/s/article/K000160366","https://ubuntu.com/security/notices/USN-8210-1","https://ubuntu.com/security/notices/USN-8375-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/a172c880cb51f882a5dc999437e8b3a4f87630cc"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"upstream","status":"released","description":"1.28.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.7","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.28.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.28.0-6ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.14.0-0ubuntu1.11+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.18.0-0ubuntu1.7+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.9+esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.10.3-0ubuntu0.16.04.5+esm7","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8375-1"],"notices":[{"id":"USN-8375-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T07:11:56.067229","description":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","is_hidden":false,"release_packages":{"bionic":[{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-1642","CVE-2026-27654","CVE-2026-9256","CVE-2026-27651","CVE-2026-32647","CVE-2025-53859","CVE-2026-27784","CVE-2026-42934","CVE-2026-42946","CVE-2026-42945","CVE-2026-28753","CVE-2026-40701"]}]},{"id":"CVE-2026-28755","published":"2026-03-24T15:16:00","updated_at":"2026-04-27T15:24:38.168124+00:00","description":"\nNGINX Plus and NGINX Open Source have a vulnerability in the\nngx_stream_ssl_module module due to the improper handling of revoked\ncertificates when configured with the ssl_verify_client on and ssl_ocsp on\ndirectives, allowing the TLS handshake to succeed even after an OCSP check\nidentifies the certificate as revoked.\nNote: Software versions which have reached End of Technical Support (EoTS)\nare not evaluated.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Support for client certificate validation with OCSP was\nintroduced in 1.19.0 with the following commit:\nhttps://github.com/nginx/nginx/commit/60438ae395d83b0f8b21bf667a1e260d60c3f46a"}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-28755","https://my.f5.com/manage/s/article/K000160368","https://ubuntu.com/security/notices/USN-8210-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/78f581487706f2e43eea5a060c516fc4d98090e8"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"upstream","status":"released","description":"1.28.3-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.28.0-6ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.28.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-28753","published":"2026-03-24T15:16:00","updated_at":"2026-06-06T05:23:26.248104+00:00","description":"\nNGINX Plus and NGINX Open Source have a vulnerability in the\nngx_mail_smtp_module module due to the improper handling of CRLF sequences\nin DNS responses. This allows an attacker-controlled DNS server to inject\narbitrary headers into SMTP upstream requests, leading to potential request\nmanipulation. Note: Software versions which have reached End of Technical\nSupport (EoTS) are not evaluated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-28753","https://my.f5.com/manage/s/article/K000160367","https://ubuntu.com/security/notices/USN-8210-1","https://ubuntu.com/security/notices/USN-8375-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/6a8513761fb327f67fcc6cfcf1ad216887e2589f"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"upstream","status":"released","description":"1.28.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.28.0-6ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.28.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.14.0-0ubuntu1.11+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.18.0-0ubuntu1.7+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.9+esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.10.3-0ubuntu0.16.04.5+esm7","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8375-1"],"notices":[{"id":"USN-8375-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T07:11:56.067229","description":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","is_hidden":false,"release_packages":{"bionic":[{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-1642","CVE-2026-27654","CVE-2026-9256","CVE-2026-27651","CVE-2026-32647","CVE-2025-53859","CVE-2026-27784","CVE-2026-42934","CVE-2026-42946","CVE-2026-42945","CVE-2026-28753","CVE-2026-40701"]}]},{"id":"CVE-2026-27784","published":"2026-03-24T15:16:00","updated_at":"2026-06-06T13:09:36.691266+00:00","description":"\nThe 32-bit implementation of NGINX Open Source has a vulnerability in the\nngx_http_mp4_module module, which might allow an attacker to over-read or\nover-write NGINX worker memory resulting in its termination, using a\nspecially crafted MP4 file. The issue only affects 32-bit NGINX Open Source\nif it is built with the ngx_http_mp4_module module and the mp4 directive is\nused in the configuration file. Additionally, the attack is possible only\nif an attacker can trigger the processing of a specially crafted MP4 file\nwith the ngx_http_mp4_module module.\nNote: Software versions which have reached End of Technical Support (EoTS)\nare not evaluated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-27784","https://my.f5.com/manage/s/article/K000160364","https://ubuntu.com/security/notices/USN-8210-1","https://ubuntu.com/security/notices/USN-8375-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/b23ac73b00313d159a99636c21ef71b828781018"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"resolute","status":"not-affected","description":"1.28.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.28.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.28.0-6ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.14.0-0ubuntu1.11+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.18.0-0ubuntu1.7+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.9+esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.10.3-0ubuntu0.16.04.5+esm7","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8375-1"],"notices":[{"id":"USN-8375-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T07:11:56.067229","description":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","is_hidden":false,"release_packages":{"bionic":[{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-1642","CVE-2026-27654","CVE-2026-9256","CVE-2026-27651","CVE-2026-32647","CVE-2025-53859","CVE-2026-27784","CVE-2026-42934","CVE-2026-42946","CVE-2026-42945","CVE-2026-28753","CVE-2026-40701"]}]},{"id":"CVE-2026-27654","published":"2026-03-24T15:16:00","updated_at":"2026-06-06T05:23:26.248104+00:00","description":"\nNGINX Open Source and NGINX Plus have a vulnerability in the\nngx_http_dav_module module that might allow an attacker to trigger a buffer\noverflow to the NGINX worker process; this vulnerability may result in\ntermination of the NGINX worker process or modification of source or\ndestination file names outside the document root. This issue affects NGINX\nOpen Source and NGINX Plus when the configuration file uses DAV module MOVE\nor COPY methods, prefix location (nonregular expression location\nconfiguration), and alias directives. The integrity impact is constrained\nbecause the NGINX worker process user has low privileges and does not have\naccess to the entire system. Note: Software versions which have reached End\nof Technical Support (EoTS) are not evaluated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-27654","https://my.f5.com/manage/s/article/K000160382","https://ubuntu.com/security/notices/USN-8210-1","https://ubuntu.com/security/notices/USN-8375-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/a1d18284e0a173c4ef2b28425535d0f640ae0a82"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"resolute","status":"not-affected","description":"1.28.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.28.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.28.0-6ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.14.0-0ubuntu1.11+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.18.0-0ubuntu1.7+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.9+esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.10.3-0ubuntu0.16.04.5+esm7","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8375-1"],"notices":[{"id":"USN-8375-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T07:11:56.067229","description":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","is_hidden":false,"release_packages":{"bionic":[{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-1642","CVE-2026-27654","CVE-2026-9256","CVE-2026-27651","CVE-2026-32647","CVE-2025-53859","CVE-2026-27784","CVE-2026-42934","CVE-2026-42946","CVE-2026-42945","CVE-2026-28753","CVE-2026-40701"]}]},{"id":"CVE-2026-27651","published":"2026-03-24T15:16:00","updated_at":"2026-06-06T05:23:26.248104+00:00","description":"\nWhen the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX\nOpen Source, undisclosed requests can cause worker processes to terminate.\nThis issue may occur when (1) CRAM-MD5 or APOP authentication is enabled,\nand (2) the authentication server permits retry by returning the Auth-Wait\nresponse header. Note: Software versions which have reached End of\nTechnical Support (EoTS) are not evaluated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-27651","https://my.f5.com/manage/s/article/K000160383","https://ubuntu.com/security/notices/USN-8210-1","https://ubuntu.com/security/notices/USN-8375-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/0f71dd8ea94ab8c123413b2e465be12a35392e9c"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"resolute","status":"not-affected","description":"1.28.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.28.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.28.0-6ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.14.0-0ubuntu1.11+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.18.0-0ubuntu1.7+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.9+esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.10.3-0ubuntu0.16.04.5+esm7","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8375-1"],"notices":[{"id":"USN-8375-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T07:11:56.067229","description":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","is_hidden":false,"release_packages":{"bionic":[{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-1642","CVE-2026-27654","CVE-2026-9256","CVE-2026-27651","CVE-2026-32647","CVE-2025-53859","CVE-2026-27784","CVE-2026-42934","CVE-2026-42946","CVE-2026-42945","CVE-2026-28753","CVE-2026-40701"]}]},{"id":"CVE-2026-4729","published":"2026-03-24T13:16:00","updated_at":"2026-04-16T02:35:31.934197+00:00","description":"\nMemory safety bugs present in Firefox 148 and Thunderbird 148. Some of\nthese bugs showed evidence of memory corruption and we presume that with\nenough effort some of these could have been exploited to run arbitrary\ncode. This vulnerability was fixed in Firefox 149 and Thunderbird 149.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4729","https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/#CVE-2026-4729","https://bugzilla.mozilla.org/buglist.cgi?bug_id=1944033%2C1997282%2C2009213%2C2011412%2C2021925%2C2022034","https://www.mozilla.org/security/advisories/mfsa2026-20/","https://www.mozilla.org/security/advisories/mfsa2026-23/"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4728","published":"2026-03-24T13:16:00","updated_at":"2026-04-16T03:33:17.104225+00:00","description":"\nSpoofing issue in the Privacy: Anti-Tracking component. This vulnerability\nwas fixed in Firefox 149 and Thunderbird 149.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4728","https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/#CVE-2026-4728","https://bugzilla.mozilla.org/show_bug.cgi?id=2013179","https://www.mozilla.org/security/advisories/mfsa2026-20/","https://www.mozilla.org/security/advisories/mfsa2026-23/"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4727","published":"2026-03-24T13:16:00","updated_at":"2026-04-16T03:32:31.235599+00:00","description":"\nDenial-of-service in the Libraries component in NSS. This vulnerability was\nfixed in Firefox 149 and Thunderbird 149.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4727","https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/#CVE-2026-4727","https://bugzilla.mozilla.org/show_bug.cgi?id=2008112","https://www.mozilla.org/security/advisories/mfsa2026-20/","https://www.mozilla.org/security/advisories/mfsa2026-23/"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4726","published":"2026-03-24T13:16:00","updated_at":"2026-04-16T03:59:35.004865+00:00","description":"\nDenial-of-service in the XML component. This vulnerability was fixed in\nFirefox 149 and Thunderbird 149.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4726","https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/#CVE-2026-4726","https://bugzilla.mozilla.org/show_bug.cgi?id=1955311","https://www.mozilla.org/security/advisories/mfsa2026-20/","https://www.mozilla.org/security/advisories/mfsa2026-23/"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4725","published":"2026-03-24T13:16:00","updated_at":"2026-04-16T03:39:57.283269+00:00","description":"\nSandbox escape due to use-after-free in the Graphics: Canvas2D component.\nThis vulnerability was fixed in Firefox 149 and Thunderbird 149.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4725","https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/#CVE-2026-4725","https://bugzilla.mozilla.org/show_bug.cgi?id=2017108","https://www.mozilla.org/security/advisories/mfsa2026-20/","https://www.mozilla.org/security/advisories/mfsa2026-23/"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":14480,"limit":20,"total_results":79316}