{"cves":[{"id":"CVE-2025-64998","published":"2026-03-24T12:16:00","updated_at":"2026-08-17T19:11:10.965952+00:00","description":"\nExposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and\n2.2.0 allows an administrator of a remote site with config sync enabled to\nhijack sessions on the central site by forging session cookies.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-64998","https://checkmk.com/werk/18954"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4649","published":"2026-03-24T09:16:00","updated_at":"2026-07-10T20:55:03.285915+00:00","description":"\nApache Artemis before version 2.52.0 is affected by an authentication\nbypass flaw which allows reading all messages exchanged via the broker and\ninjection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ).\nSince KNIME Business Hub uses Apache Artemis it is also affected by the\nissue. However, since Apache Artemis is not exposed to the outside it\nrequires at least normal user privileges and the ability to execute\nworkflows in an executor. Such a user can install and register a federated\nmirror without authentication to the original Apache Artemis instance and\nthereby read all internal messages and inject new messages.\nThe issue affects all versions of KNIME Business Hub. A fixed version of\nApache Artemis is shipped with versions 1.18.0, 1.17.4, and 1.16.3.\nWe recommend updating to a fixed version as soon as possible since no\nworkaround is known.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4649","https://www.knime.com/security/advisories#CVE-2026-4649"],"bugs":[""],"patches":{"artemis":[]},"tags":{},"packages":[{"name":"artemis","source":"https://ubuntu.com/security/cve?package=artemis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=artemis","debian":"https://tracker.debian.org/pkg/artemis","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-32642","published":"2026-03-24T08:16:00","updated_at":"2026-07-10T20:06:12.885994+00:00","description":"\nIncorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache\nActiveMQ Artemis exists when an application using the OpenWire protocol\nattempts to create a non-durable JMS topic subscription on an address that\ndoesn't exist with an authenticated user which has the \"createDurableQueue\"\npermission but does not have the \"createAddress\" permission and address\nauto-creation is disabled. In this circumstance, a temporary address will\nbe created whereas the attempt to create the non-durable subscription\nshould instead fail since the user is not authorized to create the\ncorresponding address. When the OpenWire connection is closed the address\nis removed.\nThis issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache\nActiveMQ Artemis: from 2.0.0 through 2.44.0.\nUsers are recommended to upgrade to version 2.53.0, which fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-32642","https://lists.apache.org/thread/4wlrp31ngq2yb54sf4kjb3bl41t4xgtp","http://www.openwall.com/lists/oss-security/2026/03/20/2"],"bugs":[""],"patches":{"artemis":[]},"tags":{},"packages":[{"name":"artemis","source":"https://ubuntu.com/security/cve?package=artemis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=artemis","debian":"https://tracker.debian.org/pkg/artemis","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4751","published":"2026-03-24T06:16:00","updated_at":"2026-04-01T04:13:55.762225+00:00","description":"\nNULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects\ntmate: before 2.4.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4751","https://github.com/tmate-io/tmate/pull/328"],"bugs":[""],"patches":{"tmate":[]},"tags":{},"packages":[{"name":"tmate","source":"https://ubuntu.com/security/cve?package=tmate","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tmate","debian":"https://tracker.debian.org/pkg/tmate","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4750","published":"2026-03-24T06:16:00","updated_at":"2026-03-25T03:22:53.411607+00:00","description":"\nOut-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects\nwoof: before woof_15.3.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4750","https://github.com/fabiangreffrath/woof/pull/2521"],"bugs":[""],"patches":{"woof":[],"woof-doom":[]},"tags":{},"packages":[{"name":"woof","source":"https://ubuntu.com/security/cve?package=woof","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=woof","debian":"https://tracker.debian.org/pkg/woof","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"woof-doom","source":"https://ubuntu.com/security/cve?package=woof-doom","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=woof-doom","debian":"https://tracker.debian.org/pkg/woof-doom","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-3260","published":"2026-03-24T05:16:00","updated_at":"2026-07-09T14:48:02.721280+00:00","description":"\nRejected reason: The Undertow web server enforces a default maximum HTTP\nrequest entity size limit. Any request (including GET or HEAD) containing a\nbody that exceeds this configurable limit is safely dropped by the server,\npreventing single-request Resource Exhaustion (Out of Memory) Denial of\nService attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-3260","https://access.redhat.com/security/cve/CVE-2026-3260","https://bugzilla.redhat.com/show_bug.cgi?id=2443010"],"bugs":[""],"patches":{"undertow":[]},"tags":{},"packages":[{"name":"undertow","source":"https://ubuntu.com/security/cve?package=undertow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=undertow","debian":"https://tracker.debian.org/pkg/undertow","statuses":[{"release_codename":"bionic","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"rejected CVE","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4739","published":"2026-03-24T04:17:00","updated_at":"2026-09-04T17:48:46.090610+00:00","description":"\nInteger Overflow or Wraparound vulnerability in InsightSoftwareConsortium\nITK (‎Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK:\nbefore 2.7.1.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"paraview uses system expat\nxotcl uses system expat\npoco uses system expat\ngdcm uses system expat\naudacity uses system expat\nsimgear uses system expat\ncoin3 uses system expat as of 4.0.0~CMake~6f54f1602475+ds1-1\nsitecopy uses system expat since 1:0.16.0-1 (dapper!)\ninsighttoolkit uses system expat as of 4.12.1-dfsg1"},{"author":"mdeslaur","note":"apache2 uses system expat\napr-util uses system expat\ncmake uses system expat\nghostscript uses system expat\nfirefox uses system expat\nthunderbird uses system expat\nmatanza embeds an expat fork to parse its own config file, there\nis no attack vector there, we will not be fixing matanza."},{"author":"igcontreras","note":"this is not an expat vulnerability"}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/S:P/AU:Y/R:U/V:C/RE:M/U:Amber","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},"baseScore":9.4,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4739","https://github.com/InsightSoftwareConsortium/ITK/pull/5351"],"bugs":[""],"patches":{"expat":[],"apache2":[],"apr-util":[],"cmake":[],"ghostscript":[],"texlive-bin":[],"xmlrpc-c":[],"vnc4":[],"wbxml2":[],"swish-e":[],"insighttoolkit4":["upstream: https://github.com/InsightSoftwareConsortium/ITK/commit/38cca3709eaa24eeabbc634373221c8e787b5263"],"cadaver":[],"gdcm":[],"ayttm":[],"cableswig":[],"coin3":[],"matanza":[],"tdom":[],"vtk":[],"smart":[],"firefox":[],"thunderbird":[],"libxmltok":[]},"tags":{},"packages":[{"name":"expat","source":"https://ubuntu.com/security/cve?package=expat","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=expat","debian":"https://tracker.debian.org/pkg/expat","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"}]},{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"}]},{"name":"apr-util","source":"https://ubuntu.com/security/cve?package=apr-util","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apr-util","debian":"https://tracker.debian.org/pkg/apr-util","statuses":[{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"}]},{"name":"cmake","source":"https://ubuntu.com/security/cve?package=cmake","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cmake","debian":"https://tracker.debian.org/pkg/cmake","statuses":[{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"}]},{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"}]},{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code-not-compiled","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code-not-compiled","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code-not-compiled","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-compiled","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code-not-compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code-not-compiled","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code-not-compiled","component":null,"pocket":"security"}]},{"name":"xmlrpc-c","source":"https://ubuntu.com/security/cve?package=xmlrpc-c","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xmlrpc-c","debian":"https://tracker.debian.org/pkg/xmlrpc-c","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"}]},{"name":"vnc4","source":"https://ubuntu.com/security/cve?package=vnc4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vnc4","debian":"https://tracker.debian.org/pkg/vnc4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"wbxml2","source":"https://ubuntu.com/security/cve?package=wbxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wbxml2","debian":"https://tracker.debian.org/pkg/wbxml2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"}]},{"name":"swish-e","source":"https://ubuntu.com/security/cve?package=swish-e","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swish-e","debian":"https://tracker.debian.org/pkg/swish-e","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"}]},{"name":"insighttoolkit4","source":"https://ubuntu.com/security/cve?package=insighttoolkit4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=insighttoolkit4","debian":"https://tracker.debian.org/pkg/insighttoolkit4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0b01","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"cadaver","source":"https://ubuntu.com/security/cve?package=cadaver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cadaver","debian":"https://tracker.debian.org/pkg/cadaver","statuses":[{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"}]},{"name":"gdcm","source":"https://ubuntu.com/security/cve?package=gdcm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdcm","debian":"https://tracker.debian.org/pkg/gdcm","statuses":[{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"}]},{"name":"ayttm","source":"https://ubuntu.com/security/cve?package=ayttm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ayttm","debian":"https://tracker.debian.org/pkg/ayttm","statuses":[{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"cableswig","source":"https://ubuntu.com/security/cve?package=cableswig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cableswig","debian":"https://tracker.debian.org/pkg/cableswig","statuses":[{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"coin3","source":"https://ubuntu.com/security/cve?package=coin3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=coin3","debian":"https://tracker.debian.org/pkg/coin3","statuses":[{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"}]},{"name":"matanza","source":"https://ubuntu.com/security/cve?package=matanza","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=matanza","debian":"https://tracker.debian.org/pkg/matanza","statuses":[{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"tdom","source":"https://ubuntu.com/security/cve?package=tdom","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tdom","debian":"https://tracker.debian.org/pkg/tdom","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"}]},{"name":"vtk","source":"https://ubuntu.com/security/cve?package=vtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vtk","debian":"https://tracker.debian.org/pkg/vtk","statuses":[{"release_codename":"trusty","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"smart","source":"https://ubuntu.com/security/cve?package=smart","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=smart","debian":"https://tracker.debian.org/pkg/smart","statuses":[{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system expat","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"libxmltok","source":"https://ubuntu.com/security/cve?package=libxmltok","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxmltok","debian":"https://tracker.debian.org/pkg/libxmltok","statuses":[{"release_codename":"bionic","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not an expat vulnerability","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4738","published":"2026-03-24T04:17:00","updated_at":"2026-07-10T20:59:40.752804+00:00","description":"\nImproper Restriction of Operations within the Bounds of a Memory Buffer\nvulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This\nvulnerability is associated with program files inftree9.C‎.\nThis issue affects gdal: before 3.11.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/S:P/AU:Y/R:U/V:C/RE:L/U:Amber","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},"baseScore":9.4,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4738","https://github.com/OSGeo/gdal/pull/12244"],"bugs":[""],"patches":{"gdal":[]},"tags":{},"packages":[{"name":"gdal","source":"https://ubuntu.com/security/cve?package=gdal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdal","debian":"https://tracker.debian.org/pkg/gdal","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.11.0","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33308","published":"2026-03-24T03:16:00","updated_at":"2026-04-01T04:13:55.762225+00:00","description":"\nMod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to\nversion 0.13.0, code for client certificate verification did not check the\nkey purpose as set in the Extended Key Usage extension. An attacker with\naccess to the private key for a valid certificate issued by a CA trusted\nfor TLS client authentication but designated for a different purpose could\nhave used that certificate to improperly access resources requiring TLS\nclient authentication. Server configurations that do not use client\ncertificates (`GnuTLSClientVerify ignore`, the default) are not affected.\nThe problem has been fixed in version 0.13.0 by rewriting certificate\nverification to use `gnutls_certificate_verify_peers()`, and requiring key\npurpose id-kp-clientAuth (also known as `tls_www_client` in GnuTLS) by\ndefault if the Extended Key Usage extension is present. The new\n`GnuTLSClientKeyPurpose` option allows overriding the expected key purpose\nif needed (please see the manual for details). Behavior for certificates\nwithout an Extended Key Usage extension is unchanged. If dedicated\n(sub-)CAs are used for issuing TLS client certificates only (not for any\nother purposes) the issue has no practical impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33308","https://github.com/airtower-luna/mod_gnutls/security/advisories/GHSA-hm2g-m958-8qgh"],"bugs":[""],"patches":{"mod-gnutls":[]},"tags":{},"packages":[{"name":"mod-gnutls","source":"https://ubuntu.com/security/cve?package=mod-gnutls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mod-gnutls","debian":"https://tracker.debian.org/pkg/mod-gnutls","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33307","published":"2026-03-24T02:16:00","updated_at":"2026-04-01T04:13:04.017260+00:00","description":"\nMod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions\nprior to 0.12.3 and 0.13.0, code for client certificate verification\nimported the certificate chain sent by the client into a fixed size\n`gnutls_x509_crt_t x509[]` array without checking the number of\ncertificates is less than or equal to the array size. `gnutls_x509_crt_t`\nis a `typedef` for a pointer to an opaque GnuTLS structure created using\nwith `gnutls_x509_crt_init()` before importing certificate data into it, so\nno attacker-controlled data was written into the stack buffer, but writing\na pointer after the last array element generally triggered a segfault, and\ncould theoretically cause stack corruption otherwise (not observed in\npractice). Server configurations that do not use client certificates\n(`GnuTLSClientVerify ignore`, the default) are not affected. The problem\nhas been fixed in version 0.12.3 by checking the length of the provided\ncertificate chain and rejecting it if it exceeds the buffer length, and in\nversion 0.13.0 by rewriting certificate verification to use\n`gnutls_certificate_verify_peers()`, removing the need for the buffer\nentirely. There is no workaround. Version 0.12.3 provides the minimal fix\nfor users of 0.12.x who do not wish to upgrade to 0.13.0 yet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33307","https://github.com/airtower-luna/mod_gnutls/security/advisories/GHSA-gjpm-55p4-c76r","https://github.com/airtower-luna/mod_gnutls/commit/bf4f08c49acae528e97885082cdee460f4534dc1"],"bugs":[""],"patches":{"mod-gnutls":[]},"tags":{},"packages":[{"name":"mod-gnutls","source":"https://ubuntu.com/security/cve?package=mod-gnutls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mod-gnutls","debian":"https://tracker.debian.org/pkg/mod-gnutls","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33320","published":"2026-03-24T01:17:00","updated_at":"2026-04-01T04:14:45.783991+00:00","description":"\nDasel is a command-line tool and library for querying, modifying, and\ntransforming data structures. Starting in version 3.0.0 and prior to\nversion 3.3.1, Dasel's YAML reader allows an attacker who can supply YAML\nfor processing to trigger extreme CPU and memory consumption. The issue is\nin the library's own `UnmarshalYAML` implementation, which manually\nresolves alias nodes by recursively following `yaml.Node.Alias` pointers\nwithout any expansion budget, bypassing go-yaml v4's built-in alias\nexpansion limit. Version 3.3.2 contains a patch for the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33320","https://github.com/TomWright/dasel/security/advisories/GHSA-4fcp-jxh7-23x8","https://github.com/TomWright/dasel/pull/531"],"bugs":[""],"patches":{"dasel":[]},"tags":{},"packages":[{"name":"dasel","source":"https://ubuntu.com/security/cve?package=dasel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dasel","debian":"https://tracker.debian.org/pkg/dasel","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33306","published":"2026-03-24T01:17:00","updated_at":"2026-08-17T19:16:26.871637+00:00","description":"\nbcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing\nalgorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt\nimplementation for JRuby can cause zero iterations in the strengthening\nloop. Impacted applications must be setting the cost to 31 to see this\nhappen. The JRuby implementation of bcrypt-ruby (`BCrypt.java`) computes\nthe key-strengthening round count as a signed 32-bit integer. When\n`cost=31` (the maximum allowed by the gem), signed integer overflow causes\nthe round count to become negative, and the strengthening loop executes\n**zero iterations**. This collapses bcrypt from 2^31 rounds of exponential\nkey-strengthening to effectively constant-time computation — only the\ninitial EksBlowfish key setup and final 64x encryption phase remain. The\nresulting hash looks valid (`$2a$31$...`) and verifies correctly via\n`checkpw`, making the weakness invisible to the application. This issue is\ntriggered only when cost=31 is used or when verifying a `$2a$31$` hash.\nThis problem has been fixed in version 3.1.22. As a workaround, set the\ncost to something less than 31.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33306","https://github.com/bcrypt-ruby/bcrypt-ruby/commit/831ce64cb0a9502130fa93a28bfd9527a5fa45c4","https://github.com/bcrypt-ruby/bcrypt-ruby/releases/tag/v3.1.22","https://github.com/bcrypt-ruby/bcrypt-ruby/security/advisories/GHSA-f27w-vcwj-c954"],"bugs":[""],"patches":{"bcrypt":[]},"tags":{},"packages":[{"name":"bcrypt","source":"https://ubuntu.com/security/cve?package=bcrypt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bcrypt","debian":"https://tracker.debian.org/pkg/bcrypt","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33298","published":"2026-03-24T01:17:00","updated_at":"2026-03-25T03:22:53.411607+00:00","description":"\nllama.cpp is an inference of several LLM models in C/C++. Prior to b7824,\nan integer overflow vulnerability in the `ggml_nbytes` function allows an\nattacker to bypass memory validation by crafting a GGUF file with specific\ntensor dimensions. This causes `ggml_nbytes` to return a significantly\nsmaller size than required (e.g., 4MB instead of Exabytes), leading to a\nheap-based buffer overflow when the application subsequently processes the\ntensor. This vulnerability allows potential Remote Code Execution (RCE) via\nmemory corruption. b7824 contains a fix.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33298","https://github.com/ggml-org/llama.cpp/releases/tag/b7824","https://github.com/ggml-org/llama.cpp/security/advisories/GHSA-96jg-mvhq-q7q7"],"bugs":[""],"patches":{"llama.cpp":[]},"tags":{},"packages":[{"name":"llama.cpp","source":"https://ubuntu.com/security/cve?package=llama.cpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=llama.cpp","debian":"https://tracker.debian.org/pkg/llama.cpp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33250","published":"2026-03-24T00:16:00","updated_at":"2026-09-14T17:41:40.207480+00:00","description":"\nFreeciv21 is a free open source, turn-based, empire-building strategy game.\nVersions prior to 3.1.1 crash with a stack overflow when receiving\nspecially-crafted packets. A remote attacker can use this to take down any\npublic server. A malicious server can use this to crash the game on the\nplayer's machine. Authentication is not needed and, by default, logs do not\ncontain any useful information. All users should upgrade to Freeciv21\nversion 3.1.1. Running the server behind a firewall can help mitigate the\nissue for non-public servers. For local games, Freeciv21 restricts\nconnections to the current user and is therefore not affected.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33250","https://redmine.freeciv.org/issues/1955","https://github.com/longturn/freeciv21/commit/ad8e18ca22595529599782b2984bf44df8d69ed6","https://github.com/longturn/freeciv21/releases/tag/v3.1.1","https://github.com/longturn/freeciv21/security/advisories/GHSA-f76g-6w3f-f6r3","https://ubuntu.com/security/notices/USN-8754-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1131524"],"patches":{"freeciv":[]},"tags":{},"packages":[{"name":"freeciv","source":"https://ubuntu.com/security/cve?package=freeciv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freeciv","debian":"https://tracker.debian.org/pkg/freeciv","statuses":[{"release_codename":"resolute","status":"not-affected","description":"3.2.4+ds-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.5.10-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.6.2-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.6.6-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"3.1.0+ds-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"2.5.3-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"upstream","status":"released","description":"3.2.4+ds-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8754-1"],"notices":[{"id":"USN-8754-1","title":"Freeciv vulnerability","summary":"Freeciv could be made to crash if it received specially crafted network\ntraffic.","instructions":"After a standard system update you need to restart Freeciv to make all the\nnecessary changes.","references":[],"published":"2026-09-14T12:40:26.142259","description":"It was discovered that Freeciv incorrectly handled certain network packets,\nresulting in a stack overflow. A remote attacker could possibly use this\nissue to cause Freeciv clients or servers to crash, resulting in a denial\nof service.","is_hidden":false,"release_packages":{"bionic":[{"name":"freeciv","version":"2.5.10-1ubuntu0.1~esm1","description":"Civilization turn based strategy game","is_source":true},{"name":"freeciv","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-extras","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-gtk","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-gtk3","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-qt","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-sdl","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-data","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-server","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-sound-standard","version":"2.5.10-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"freeciv","version":"2.6.2-1ubuntu0.1~esm1","description":"Civilization turn based strategy game","is_source":true},{"name":"freeciv","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-extras","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-gtk","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-gtk3","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-qt","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-sdl","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-data","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-server","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-sound-standard","version":"2.6.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"freeciv","version":"2.6.6-1ubuntu0.1~esm1","description":"Civilization turn based strategy game","is_source":true},{"name":"freeciv","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-extras","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-gtk","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-gtk3","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-qt","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-sdl","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-data","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-server","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-sound-standard","version":"2.6.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"freeciv","version":"3.1.0+ds-1ubuntu0.1~esm1","description":"Civilization turn based strategy game","is_source":true},{"name":"freeciv","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-extras","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-gtk3","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-qt","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-client-sdl","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-data","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-ruleset-tools","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"},{"name":"freeciv-server","version":"3.1.0+ds-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"freeciv","version":"2.5.3-1ubuntu0.1~esm1","description":"Civilization turn based strategy game","is_source":true},{"name":"freeciv","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"},{"name":"freeciv-client-extras","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"},{"name":"freeciv-client-gtk","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"},{"name":"freeciv-client-qt","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"},{"name":"freeciv-client-sdl","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"},{"name":"freeciv-data","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"},{"name":"freeciv-server","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"},{"name":"freeciv-sound-standard","version":"2.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeciv","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-33250"]}]},{"id":"CVE-2026-33202","published":"2026-03-24T00:16:00","updated_at":"2026-07-10T20:05:42.323828+00:00","description":"\nActive Storage allows users to attach cloud and local files in Rails\napplications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active\nStorage's `DiskService#delete_prefixed` passes blob keys directly to\n`Dir.glob` without escaping glob metacharacters. If a blob key contains\nattacker-controlled input or custom-generated keys with glob\nmetacharacters, it may be possible to delete unintended files from the\nstorage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33202","https://github.com/rails/rails/commit/8c9676b803820110548cdb7523800db43bc6874c","https://github.com/rails/rails/commit/955284d26e469a9c026a4eee5b21f0414ab0bccf","https://github.com/rails/rails/commit/fa19073546360856e9f4dab221fc2c5d73a45e82","https://github.com/rails/rails/releases/tag/v7.2.3.1","https://github.com/rails/rails/releases/tag/v8.0.4.1","https://github.com/rails/rails/releases/tag/v8.1.2.1","https://github.com/rails/rails/security/advisories/GHSA-73f9-jhhh-hr5m"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33195","published":"2026-03-24T00:16:00","updated_at":"2026-06-30T18:42:13.825903+00:00","description":"\nActive Storage allows users to attach cloud and local files in Rails\napplications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active\nStorage's `DiskService#path_for` does not validate that the resolved\nfilesystem path remains within the storage root directory. If a blob key\ncontaining path traversal sequences (e.g. `../`) is used, it could allow\nreading, writing, or deleting arbitrary files on the server. Blob keys are\nexpected to be trusted strings, but some applications could be passing user\ninput as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1\ncontain a patch.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33195","https://github.com/rails/rails/commit/4933c1e3b8c1bb04925d60347be9f69270392f2c","https://github.com/rails/rails/commit/9b06fbc0f504b8afe333f33d19548f3b85fbe655","https://github.com/rails/rails/commit/a290c8a1ec189d793aa6d7f2570b6a763f675348","https://github.com/rails/rails/releases/tag/v7.2.3.1","https://github.com/rails/rails/releases/tag/v8.0.4.1","https://github.com/rails/rails/releases/tag/v8.1.2.1","https://github.com/rails/rails/security/advisories/GHSA-9xrj-h377-fr87"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33176","published":"2026-03-24T00:16:00","updated_at":"2026-07-10T20:07:07.563005+00:00","description":"\nActive Support is a toolkit of support libraries and Ruby core extensions\nextracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and\n7.2.3.1, Active Support number helpers accept strings containing scientific\nnotation (e.g. `1e10000`), which `BigDecimal` expands into extremely large\ndecimal representations. This can cause excessive memory allocation and CPU\nconsumption when the expanded number is formatted, possibly resulting in a\nDoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33176","https://github.com/rails/rails/commit/19dbab51ca086a657bb86458042bc44314916bcb","https://github.com/rails/rails/commit/ebd6be18120d1136511eb516338e27af25ac0a1a","https://github.com/rails/rails/commit/ee2c59e730e5b8faed502cd2c573109df093f856","https://github.com/rails/rails/releases/tag/v7.2.3.1","https://github.com/rails/rails/releases/tag/v8.0.4.1","https://github.com/rails/rails/releases/tag/v8.1.2.1","https://github.com/rails/rails/security/advisories/GHSA-2j26-frm8-cmj9"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33174","published":"2026-03-24T00:16:00","updated_at":"2026-07-10T20:06:40.941137+00:00","description":"\nActive Storage allows users to attach cloud and local files in Rails\napplications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving\nfiles through Active Storage's proxy delivery mode, the proxy controller\nloads the entire requested byte range into memory before sending it. A\nrequest with a large or unbounded Range header (e.g. `bytes=0-`) could\ncause the server to allocate memory proportional to the file size, possibly\nresulting in a DoS vulnerability through memory exhaustion. Versions\n8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33174","https://github.com/rails/rails/commit/2cd933c366b777f873d4d590127da2f4a25e4ba5","https://github.com/rails/rails/commit/42012eaaa88dfc7d0030161b2bc8074a7bbce92a","https://github.com/rails/rails/commit/8159a9c3de3f27a2bcf2866b8bf9ceb9075e229b","https://github.com/rails/rails/releases/tag/v7.2.3.1","https://github.com/rails/rails/releases/tag/v8.0.4.1","https://github.com/rails/rails/releases/tag/v8.1.2.1","https://github.com/rails/rails/security/advisories/GHSA-r46p-8f7g-vvvg"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33173","published":"2026-03-24T00:16:00","updated_at":"2026-07-10T20:05:42.323828+00:00","description":"\nActive Storage allows users to attach cloud and local files in Rails\napplications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1,\n`DirectUploadsController` accepts arbitrary metadata from the client and\npersists it on the blob. Because internal flags like `identified` and\n`analyzed` are stored in the same metadata hash, a direct-upload client can\nset these flags to skip MIME detection and analysis. This allows an\nattacker to upload arbitrary content while claiming a safe `content_type`,\nbypassing any validations that rely on Active Storage's automatic content\ntype identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a\npatch.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33173","https://github.com/rails/rails/commit/707c0f1f41f067fdf96d54e99d43b28dfaae7e53","https://github.com/rails/rails/commit/8fcb934caadc79c8cc4ce53287046d0f67005b3e","https://github.com/rails/rails/commit/d9502f5214e2198245a4c1defe9cd02a7c8057d0","https://github.com/rails/rails/releases/tag/v7.2.3.1","https://github.com/rails/rails/releases/tag/v8.0.4.1","https://github.com/rails/rails/releases/tag/v8.1.2.1","https://github.com/rails/rails/security/advisories/GHSA-qcfx-2mfw-w4cg"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33170","published":"2026-03-24T00:16:00","updated_at":"2026-07-10T20:06:12.885994+00:00","description":"\nActive Support is a toolkit of support libraries and Ruby core extensions\nextracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and\n7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to the\nnewly created buffer. If a `SafeBuffer` is mutated in place (e.g. via\n`gsub!`) and then formatted with `%` using untrusted arguments, the result\nincorrectly reports `html_safe? == true`, bypassing ERB auto-escaping and\npossibly leading to XSS. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a\npatch.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33170","https://github.com/rails/rails/commit/50d732af3b7c8aaf63cbcca0becbc00279b215b7","https://github.com/rails/rails/commit/6e8a81108001d58043de9e54a06fca58962fc2db","https://github.com/rails/rails/commit/c1ad0e8e1972032f3395853a5e99cea035035beb","https://github.com/rails/rails/releases/tag/v7.2.3.1","https://github.com/rails/rails/releases/tag/v8.0.4.1","https://github.com/rails/rails/releases/tag/v8.1.2.1","https://github.com/rails/rails/security/advisories/GHSA-89vf-4333-qx8v"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":14540,"limit":20,"total_results":79316}