{"cves":[{"id":"CVE-2026-23704","published":"2026-02-04T07:16:00","updated_at":"2026-02-11T03:36:50.061710+00:00","description":"\nA non-administrative user can upload malicious files. When an administrator\nor the product accesses that file, an arbitrary script may be executed on\nthe administrator's browser. Note that Movable Type 7 series and 8.4\nseries, which are End-of-Life (EOL), are affected by the vulnerability as\nwell.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23704","https://jvn.jp/en/jp/JVN45405689/","https://movabletype.org/news/2026/02/mt-906-released.html","https://www.sixapart.jp/movabletype/news/2026/02/04-1100.html"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-22875","published":"2026-02-04T07:16:00","updated_at":"2026-02-11T03:36:06.988117+00:00","description":"\nMovable Type contains a stored cross-site scripting vulnerability in Export\nSites. If crafted input is stored by an attacker, arbitrary script may be\nexecuted on a logged-in user's web browser. Note that Movable Type 7 series\nand 8.4 series, which are End-of-Life (EOL), are affected by the\nvulnerability as well.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-22875","https://jvn.jp/en/jp/JVN45405689/","https://movabletype.org/news/2026/02/mt-906-released.html","https://www.sixapart.jp/movabletype/news/2026/02/04-1100.html"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-21393","published":"2026-02-04T07:16:00","updated_at":"2026-02-11T03:39:23.416451+00:00","description":"\nMovable Type contains a stored cross-site scripting vulnerability in Edit\nComment. If crafted input is stored by an attacker, arbitrary script may be\nexecuted on a logged-in user's web browser. Note that Movable Type 7 series\nand 8.4 series, which are End-of-Life (EOL), are affected by the\nvulnerability as well.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-21393","https://jvn.jp/en/jp/JVN45405689/","https://movabletype.org/news/2026/02/mt-906-released.html","https://www.sixapart.jp/movabletype/news/2026/02/04-1100.html"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25541","published":"2026-02-04T00:00:00","updated_at":"2026-07-10T19:46:52.882283+00:00","description":"\nBytes is a utility library for working with bytes. From version 1.2.1 to\nbefore 1.11.1, Bytes is vulnerable to integer overflow in\nBytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the\ncondition \"v_capacity >= new_cap + offset\" uses an unchecked addition. When\nnew_cap + offset overflows usize in release builds, this condition may\nincorrectly pass, causing self.cap to be set to a value that exceeds the\nactual allocated capacity. Subsequent APIs such as spare_capacity_mut()\nthen trust this corrupted cap value and may create out-of-bounds slices,\nleading to UB. This behavior is observable in release builds (integer\noverflow wraps), whereas debug builds panic due to overflow checks. This\nissue has been patched in version 1.11.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25541","https://rustsec.org/advisories/RUSTSEC-2026-0007.html","https://github.com/advisories/GHSA-434x-w66g-qw3r"],"bugs":[""],"patches":{"rust-bytes":[]},"tags":{},"packages":[{"name":"rust-bytes","source":"https://ubuntu.com/security/cve?package=rust-bytes","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-bytes","debian":"https://tracker.debian.org/pkg/rust-bytes","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.11.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1862","published":"2026-02-03T21:16:00","updated_at":"2026-02-04T13:17:56.739618+00:00","description":"\nType Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1862","https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/479726070"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1861","published":"2026-02-03T21:16:00","updated_at":"2026-02-04T13:19:16.646748+00:00","description":"\nHeap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132\nallowed a remote attacker to potentially exploit heap corruption via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1861","https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/478942410"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1801","published":"2026-02-03T21:16:00","updated_at":"2026-09-18T16:19:34.260363+00:00","description":"\nA flaw was found in libsoup, an HTTP client/server library. This HTTP\nRequest Smuggling vulnerability arises from non-RFC-compliant parsing in\nthe soup_filter_input_stream_read_line() logic, where libsoup accepts\nmalformed chunk headers, such as lone line feed (LF) characters instead of\nthe required carriage return and line feed (CRLF). A remote attacker can\nexploit this without authentication or user interaction by sending\nspecially crafted chunked requests. This allows libsoup to parse and\nprocess multiple HTTP requests from a single network message, potentially\nleading to information disclosure.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1801","https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/506","https://access.redhat.com/security/cve/CVE-2026-1801","https://ubuntu.com/security/notices/USN-8780-1"],"bugs":["https://gitlab.gnome.org/GNOME/libsoup/-/issues/481","https://bugzilla.redhat.com/show_bug.cgi?id=2436315"],"patches":{"libsoup2.4":["upstream: https://gitlab.gnome.org/GNOME/libsoup/-/commit/b9a1c0663ff8ab6e79715db4b35b54f560416ddd"],"libsoup3":["upstream: https://gitlab.gnome.org/GNOME/libsoup/-/commit/b9a1c0663ff8ab6e79715db4b35b54f560416ddd"]},"tags":{},"packages":[{"name":"libsoup2.4","source":"https://ubuntu.com/security/cve?package=libsoup2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup2.4","debian":"https://tracker.debian.org/pkg/libsoup2.4","statuses":[{"release_codename":"bionic","status":"released","description":"2.62.1-1ubuntu0.4+esm8","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.70.0-1ubuntu0.5+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"2.74.2-3ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.52.2-1ubuntu0.3+esm7","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.7.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.74.3-6ubuntu1.8","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.74.3-10.1ubuntu5+esm2","component":null,"pocket":"esm-apps"}]},{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.7-0ubuntu1+esm8","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"3.4.4-5ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.5-8","component":null,"pocket":"security"}]}],"notices_ids":["USN-8780-1"],"notices":[{"id":"USN-8780-1","title":"libsoup vulnerabilities","summary":"Several security issues were fixed in libsoup.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-17T16:27:25.706521","description":"It was discovered that libsoup incorrectly handled certain URLs when\nusing an HTTP proxy. A remote attacker could possibly use this issue to\ninject arbitrary HTTP headers. (CVE-2026-1467)\n\nIt was discovered that libsoup did not remove proxy authentication\ncredentials when following HTTP redirects. A remote attacker could\npossibly use this issue to obtain sensitive information.\n(CVE-2026-1539)\n\nAhmed Lekssays discovered that libsoup incorrectly parsed certain HTTP\nrequests. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-1801)","is_hidden":false,"release_packages":{"bionic":[{"name":"libsoup2.4","version":"2.62.1-1ubuntu0.4+esm8","description":"HTTP client/server library for GNOME","is_source":true},{"name":"gir1.2-soup-2.4","version":"2.62.1-1ubuntu0.4+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup-gnome2.4-1","version":"2.62.1-1ubuntu0.4+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup-gnome2.4-dev","version":"2.62.1-1ubuntu0.4+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup2.4-1","version":"2.62.1-1ubuntu0.4+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup2.4-dev","version":"2.62.1-1ubuntu0.4+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup2.4-doc","version":"2.62.1-1ubuntu0.4+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"libsoup2.4","version":"2.70.0-1ubuntu0.5+esm3","description":"HTTP client/server library for GNOME","is_source":true},{"name":"gir1.2-soup-2.4","version":"2.70.0-1ubuntu0.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup-gnome2.4-1","version":"2.70.0-1ubuntu0.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup-gnome2.4-dev","version":"2.70.0-1ubuntu0.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup2.4-1","version":"2.70.0-1ubuntu0.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup2.4-dev","version":"2.70.0-1ubuntu0.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup2.4-doc","version":"2.70.0-1ubuntu0.5+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"},{"name":"libsoup2.4-tests","version":"2.70.0-1ubuntu0.5+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libsoup2.4","version":"2.74.2-3ubuntu0.8","description":"HTTP client/server library for GNOME","is_source":true},{"name":"libsoup3","version":"3.0.7-0ubuntu1+esm8","description":"HTTP client/server library for GNOME","is_source":true},{"name":"gir1.2-soup-2.4","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"},{"name":"gir1.2-soup-3.0","version":"3.0.7-0ubuntu1+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-3.0-0","version":"3.0.7-0ubuntu1+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-3.0-common","version":"3.0.7-0ubuntu1+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-3.0-dev","version":"3.0.7-0ubuntu1+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-3.0-doc","version":"3.0.7-0ubuntu1+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-3.0-tests","version":"3.0.7-0ubuntu1+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-gnome2.4-1","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"},{"name":"libsoup-gnome2.4-dev","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"},{"name":"libsoup2.4-1","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"},{"name":"libsoup2.4-common","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"},{"name":"libsoup2.4-dev","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"},{"name":"libsoup2.4-doc","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"},{"name":"libsoup2.4-tests","version":"2.74.2-3ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.2-3ubuntu0.8","pocket":"security"}],"noble":[{"name":"libsoup2.4","version":"2.74.3-6ubuntu1.8","description":"HTTP client/server library for GNOME","is_source":true},{"name":"libsoup3","version":"3.4.4-5ubuntu0.8","description":"HTTP client/server library for GNOME","is_source":true},{"name":"gir1.2-soup-2.4","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"},{"name":"gir1.2-soup-3.0","version":"3.4.4-5ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":"https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.8","pocket":"security"},{"name":"libsoup-2.4-1","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"},{"name":"libsoup-3.0-0","version":"3.4.4-5ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":"https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.8","pocket":"security"},{"name":"libsoup-3.0-common","version":"3.4.4-5ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":"https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.8","pocket":"security"},{"name":"libsoup-3.0-dev","version":"3.4.4-5ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":"https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.8","pocket":"security"},{"name":"libsoup-3.0-doc","version":"3.4.4-5ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":"https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.8","pocket":"security"},{"name":"libsoup-3.0-tests","version":"3.4.4-5ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup3","version_link":"https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.8","pocket":"security"},{"name":"libsoup-gnome-2.4-1","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"},{"name":"libsoup-gnome2.4-dev","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"},{"name":"libsoup2.4-common","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"},{"name":"libsoup2.4-dev","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"},{"name":"libsoup2.4-doc","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"},{"name":"libsoup2.4-tests","version":"2.74.3-6ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":"https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.8","pocket":"security"}],"resolute":[{"name":"libsoup2.4","version":"2.74.3-10.1ubuntu5+esm2","description":"HTTP client/server library for GNOME","is_source":true},{"name":"gir1.2-soup-2.4","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-2.4-1","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-gnome-2.4-1","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"},{"name":"libsoup-gnome2.4-dev","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"},{"name":"libsoup2.4-common","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"},{"name":"libsoup2.4-dev","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"},{"name":"libsoup2.4-doc","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"},{"name":"libsoup2.4-tests","version":"2.74.3-10.1ubuntu5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"libsoup2.4","version":"2.52.2-1ubuntu0.3+esm7","description":"HTTP client/server library for GNOME","is_source":true},{"name":"gir1.2-soup-2.4","version":"2.52.2-1ubuntu0.3+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libsoup-gnome2.4-1","version":"2.52.2-1ubuntu0.3+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libsoup-gnome2.4-dev","version":"2.52.2-1ubuntu0.3+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libsoup2.4-1","version":"2.52.2-1ubuntu0.3+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libsoup2.4-dev","version":"2.52.2-1ubuntu0.3+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libsoup2.4-doc","version":"2.52.2-1ubuntu0.3+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsoup2.4","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-1801","CVE-2026-1539","CVE-2026-1467"]}]},{"id":"CVE-2025-64438","published":"2026-02-03T20:15:00","updated_at":"2026-07-10T19:14:18.574777+00:00","description":"\nFast DDS is a C++ implementation of the DDS (Data Distribution Service)\nstandard of the OMG (Object Management Group\n). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely triggerable\nOut-of-Memory (OOM) denial-of-service exists in Fast\n-DDS when processing RTPS GAP submessages under RELIABLE QoS. By sending a\ntiny GAP packet with a huge gap range (`gapList\n.base - gapStart`), an attacker drives `StatefulReader::processGapMsg()`\ninto an unbounded loop that inserts millions of s\nequence numbers into `WriterProxy::changes_received_` (`std::set`), causing\nmulti-GB heap growth and process termination.\nNo authentication is required beyond network reachability to the reader on\nthe DDS domain. In environments without an RSS\nlimit (non-ASan / unlimited), memory consumption was observed to rise to\n~64 GB. Versions 3.4.1, 3.3.1, and 2.6.11 patch t\nhe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-64438","https://github.com/eProsima/Fast-DDS/commit/0b0cb308eaeeb2175694aa0a0a723106824ce9a7"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-64098","published":"2026-02-03T20:15:00","updated_at":"2026-07-10T19:13:50.335658+00:00","description":"\nFast DDS is a C++ implementation of the DDS (Data Distribution Service)\nstandard of the OMG (Object Management Group\n). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is\nenabled, modifying the DATA Submessage within an\nSPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition,\nresulting in remote termination of Fast-DDS. If t\nhe fields of `PID_IDENTITY_TOKEN` or `PID_PERMISSIONS_TOKEN` in the DATA\nSubmessage are tampered with — specifically by ta\nmpering with the the `vecsize` value read by `readOctetVector` — a 32-bit\ninteger overflow can occur, causing `std::vector\n::resize` to request an attacker-controlled size and quickly trigger OOM\nand remote process termination. Versions 3.4.1, 3\n.3.1, and 2.6.11 patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-64098","https://github.com/eProsima/Fast-DDS/commit/354218514d32beac963ff5c306f1cf159ee37c5f"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-62799","published":"2026-02-03T20:15:00","updated_at":"2026-07-10T19:14:41.203713+00:00","description":"\nFast DDS is a C++ implementation of the DDS (Data Distribution Service)\nstandard of the OMG (Object Management Group\n). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a heap buffer overflow\nexists in the Fast-DDS DATA_FRAG receive path. An un\nauthenticated sender can transmit a single malformed RTPS DATA_FRAG packet\nwhere `fragmentSize` and `sampleSize` are craft\ned to violate internal assumptions. Due to a 4-byte alignment step during\nfragment metadata initialization, the code write\ns past the end of the allocated payload buffer, causing immediate crash\n(DoS) and potentially enabling memory corruption (\nRCE risk). Versions 3.4.1, 3.3.1, and 2.6.11 patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-62799","https://github.com/eProsima/Fast-DDS/commit/d6dd58f4ecd28cd1c3bc4ef0467be9110fa94659"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-62603","published":"2026-02-03T20:15:00","updated_at":"2026-07-10T19:14:18.574777+00:00","description":"\nFast DDS is a C++ implementation of the DDS (Data Distribution Service)\nstandard of the OMG (Object Management Group\n). ParticipantGenericMessage is the DDS Security control-message container\nthat carries not only the handshake but also on\ngoing security-control traffic after the handshake, such as crypto-token\nexchange, rekeying, re-authentication, and token\ndelivery for newly appearing endpoints. On receive, the CDR parser is\ninvoked first and deserializes the `message_data` (i\n.e., the `DataHolderSeq`) via the `readParticipantGenericMessage →\nreadDataHolderSeq` path. The `DataHolderSeq` is parsed\nsequentially: a sequence count (`uint32`), and for each DataHolder the\n`class_id` string (e.g. `DDS:Auth:PKI-DH:1.0+Req`),\n string properties (a sequence of key/value pairs), and binary properties\n(a name plus an octet-vector). The parser operat\nes at a stateless level and does not know higher-layer state (for example,\nwhether the handshake has already completed), s\no it fully unfolds the structure before distinguishing legitimate from\nmalformed traffic. Because RTPS permits duplicates,\n delays, and retransmissions, a receiver must perform at least minimal\nstructural parsing to check identity and sequence n\numbers before discarding or processing a message; the current\nimplementation, however, does not \"peek\" only at a minimal\n header and instead parses the entire `DataHolderSeq`. As a result, prior\nto versions 3.4.1, 3.3.1, and 2.6.11, this parsi\nng behavior can trigger an out-of-memory condition and remotely terminate\nthe process. Versions 3.4.1, 3.3.1, and 2.6.11 p\natch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-62603","https://github.com/eProsima/Fast-DDS/commit/354218514d32beac963ff5c306f1cf159ee37c5f"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-62602","published":"2026-02-03T20:15:00","updated_at":"2026-07-10T19:16:02.727689+00:00","description":"\nFast DDS is a C++ implementation of the DDS (Data Distribution Service)\nstandard of the OMG (Object Management Group\n). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is\nenabled, modifying the DATA Submessage within an\nSPDP packet sent by a publisher causes a heap buffer overflow, resulting in\nremote termination of Fast-DDS. If the fields\nof `PID_IDENTITY_TOKEN` or `PID_PERMISSIONS_TOKEN` in the DATA Submessage\nare tampered with — specially `readOctetVector`\n reads an unchecked `vecsize` that is propagated unchanged into `readData`\nas the `length` parameter — the attacker-contro\nlled `vecsize` can trigger a 32-bit integer overflow during the `length`\ncalculation. That overflow can cause large alloca\ntion attempt that quickly leads to OOM, enabling a remotely-triggerable\ndenial-of-service and remote process termination.\nVersions 3.4.1, 3.3.1, and 2.6.11 patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-62602","https://github.com/eProsima/Fast-DDS/commit/354218514d32beac963ff5c306f1cf159ee37c5f"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-62601","published":"2026-02-03T20:15:00","updated_at":"2026-07-10T19:16:02.727689+00:00","description":"\nFast DDS is a C++ implementation of the DDS (Data Distribution Service)\nstandard of the OMG (Object Management Group\n). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is\nenabled, modifying the DATA Submessage within an\nSPDP packet sent by a publisher causes a heap buffer overflow, resulting in\nremote termination of Fast-DDS. If the fields\nof `PID_IDENTITY_TOKEN` or `PID_PERMISSIONS_TOKEN` in the DATA Submessage —\nspecifically by tampering with the `str_size`\nvalue read by `readString` (called from `readBinaryProperty`) — are\nmodified, a 32-bit integer overflow can occur, causing\n `std::vector::resize` to use an attacker-controlled size and quickly\ntrigger heap buffer overflow and remote process term\nination. Versions 3.4.1, 3.3.1, and 2.6.11 patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-62601","https://github.com/eProsima/Fast-DDS/commit/354218514d32beac963ff5c306f1cf159ee37c5f"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-62600","published":"2026-02-03T19:16:00","updated_at":"2026-09-16T10:27:53.450663+00:00","description":"\neprosima Fast DDS is a C++ implementation of the DDS (Data Distribution\nService) standard of the OMG (Object Management Group). Prior to 2.6.11,\n2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled,\nmodifying the DATA Submessage within an SPDP packet sent by a publisher\ncauses an Out-Of-Memory (OOM) condition, resulting in remote termination of\nFast-DDS.\nIf the fields of PID_IDENTITY_TOKEN or PID_PERMISSION_TOKEN in the DATA\nSubmessage — specifically by tampering with the length field in\nreadBinaryPropertySeq— are modified, an integer overflow occurs, leading to\nan OOM during the resize operation. This vulnerability is fixed in 2.6.11,\n2.14.6, 3.2.4, 3.3.1, and 3.4.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-62600","https://github.com/eProsima/Fast-DDS/commit/354218514d32beac963ff5c306f1cf159ee37c5f"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-70559","published":"2026-02-03T18:16:00","updated_at":"2026-02-13T08:21:26.915172+00:00","description":"\npdfminer.six before 20251230 contains an insecure deserialization\nvulnerability in the CMap loading mechanism. The library uses Python pickle\nto deserialize CMap cache files without validation. An attacker with the\nability to place a malicious pickle file in a location accessible to the\napplication can trigger arbitrary code execution or privilege escalation\nwhen the file is loaded by a trusted process. This is caused by an\nincomplete patch to CVE-2025-64512.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-70559","https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-f83h-ghpp-7wcc","https://github.com/pdfminer/pdfminer.six/pull/1172","https://github.com/advisories/GHSA-f83h-ghpp-7wcc"],"bugs":[""],"patches":{"pdfminer":[]},"tags":{},"packages":[{"name":"pdfminer","source":"https://ubuntu.com/security/cve?package=pdfminer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdfminer","debian":"https://tracker.debian.org/pkg/pdfminer","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"20260107+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20260107+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-62599","published":"2026-02-03T18:16:00","updated_at":"2026-09-16T10:28:34.586258+00:00","description":"\neprosima Fast DDS is a C++ implementation of the DDS (Data Distribution\nService) standard of the OMG (Object Management Group). Prior to 2.6.11,\n2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled,\nmodifying the DATA Submessage within an SPDP packet sent by a publisher\ncauses an Out-Of-Memory (OOM) condition, resulting in remote termination of\nFast-DDS.\nIf the fields of PID_IDENTITY_TOKEN or PID_PERMISSION_TOKEN in the DATA\nSubmessage — specifically by tampering with the length field in\nreadPropertySeq — are modified, an integer overflow occurs, leading to an\nOOM during the resize operation. This vulnerability is fixed in 2.6.11,\n2.14.6, 3.2.4, 3.3.1, and 3.4.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-62599","https://github.com/eProsima/Fast-DDS/commit/354218514d32beac963ff5c306f1cf159ee37c5f"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1312","published":"2026-02-03T14:00:00","updated_at":"2026-02-04T13:18:23.682062+00:00","description":"\nAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2\nbefore 4.2.28.\n`.QuerySet.order_by()` is subject to SQL injection in column aliases\ncontaining periods when the same alias is, using a suitably crafted\ndictionary, with dictionary expansion, used in `FilteredRelation`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were\nnot evaluated and may also be affected.\nDjango would like to thank Solomon Kebede for reporting this issue.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"python-django 3.2.x in jammy and earlier versions support\npassing raw column aliases to order_by(), so fixing this issue\nwould change behaviour and possibly introduce a regression in\nexisting applications. Marking as ignored for jammy and earlier."}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1312","https://www.djangoproject.com/weblog/2026/feb/03/security-releases/","https://ubuntu.com/security/notices/USN-8009-1"],"bugs":[""],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"trusty","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.2,5.2.11,4.2.28","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3:4.2.11-1ubuntu1.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3:5.2.4-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [see notes]","component":null,"pocket":"security"}]}],"notices_ids":["USN-8009-1"],"notices":[{"id":"USN-8009-1","title":"Django vulnerabilities","summary":"Several security issues were fixed in Django.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-03T16:06:09.409412","description":"It was discovered that Django exposed timing information when checking\npasswords. An attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2025-13473)\n\nJiyong Yang discovered that Django incorrectly handled malformed requests\nwith duplicate headers. An attacker could possibly use this issue to cause\na denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu\n24.04 LTS, and Ubuntu 25.10. (CVE-2025-14550)\n\nTarek Nakkouch discovered that Django incorrectly parsed raster lookups. An\nattacker could possibly use this issue to perform SQL injection attacks.\nThis issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1207)\n\nSeokchan Yoon discovered that Django incorrectly handled malformed HTML\ninputs containing a large amount of unmatched HTML end tags. An attacker\ncould possibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1285)\n\nSolomon Kebede discovered that Django incorrectly handled control\ncharacters in the dictionary expansion of certain QuerySet methods. An\nattacker could possibly use this issue to perform SQL injection attacks.\n(CVE-2026-1287)\n\nSolomon Kebede discovered that Django incorrectly handled column alias\nparsing with dictionary expansion. An attacker could possibly use this\nissue to perform SQL injection attacks. This issue only affected Ubuntu\n24.04 LTS and Ubuntu 25.10. (CVE-2026-1312)","is_hidden":false,"release_packages":{"bionic":[{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"python-django","version":"2:2.2.12-1ubuntu0.29+esm7","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"python-django","version":"2:3.2.12-2ubuntu1.25","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"},{"name":"python3-django","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"}],"noble":[{"name":"python-django","version":"3:4.2.11-1ubuntu1.14","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"},{"name":"python3-django","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"}],"questing":[{"name":"python-django","version":"3:5.2.4-1ubuntu2.3","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"},{"name":"python3-django","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"}],"trusty":[{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"},{"name":"python-django-doc","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-1312","CVE-2026-1287","CVE-2026-1207","CVE-2025-13473","CVE-2025-14550","CVE-2026-1285"]}]},{"id":"CVE-2026-1287","published":"2026-02-03T14:00:00","updated_at":"2026-02-04T13:21:36.029729+00:00","description":"\nAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2\nbefore 4.2.28.\n`FilteredRelation` is subject to SQL injection in column aliases via\ncontrol characters, using a suitably crafted dictionary, with dictionary\nexpansion, as the `**kwargs` passed to `QuerySet` methods `annotate()`,\n`aggregate()`, `extra()`, `values()`, `values_list()`, and `alias()`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were\nnot evaluated and may also be affected.\nDjango would like to thank Solomon Kebede for reporting this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1287","https://www.djangoproject.com/weblog/2026/feb/03/security-releases/","https://ubuntu.com/security/notices/USN-8009-1"],"bugs":[""],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"resolute","status":"released","description":"3:5.2.9-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.2,5.2.11,4.2.28","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.11.11-1ubuntu1.21+esm14","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2:2.2.12-1ubuntu0.29+esm7","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"2:3.2.12-2ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3:4.2.11-1ubuntu1.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3:5.2.4-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.11-0ubuntu1.3+esm10","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.8.7-1ubuntu5.15+esm11","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8009-1"],"notices":[{"id":"USN-8009-1","title":"Django vulnerabilities","summary":"Several security issues were fixed in Django.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-03T16:06:09.409412","description":"It was discovered that Django exposed timing information when checking\npasswords. An attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2025-13473)\n\nJiyong Yang discovered that Django incorrectly handled malformed requests\nwith duplicate headers. An attacker could possibly use this issue to cause\na denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu\n24.04 LTS, and Ubuntu 25.10. (CVE-2025-14550)\n\nTarek Nakkouch discovered that Django incorrectly parsed raster lookups. An\nattacker could possibly use this issue to perform SQL injection attacks.\nThis issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1207)\n\nSeokchan Yoon discovered that Django incorrectly handled malformed HTML\ninputs containing a large amount of unmatched HTML end tags. An attacker\ncould possibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1285)\n\nSolomon Kebede discovered that Django incorrectly handled control\ncharacters in the dictionary expansion of certain QuerySet methods. An\nattacker could possibly use this issue to perform SQL injection attacks.\n(CVE-2026-1287)\n\nSolomon Kebede discovered that Django incorrectly handled column alias\nparsing with dictionary expansion. An attacker could possibly use this\nissue to perform SQL injection attacks. This issue only affected Ubuntu\n24.04 LTS and Ubuntu 25.10. (CVE-2026-1312)","is_hidden":false,"release_packages":{"bionic":[{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"python-django","version":"2:2.2.12-1ubuntu0.29+esm7","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"python-django","version":"2:3.2.12-2ubuntu1.25","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"},{"name":"python3-django","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"}],"noble":[{"name":"python-django","version":"3:4.2.11-1ubuntu1.14","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"},{"name":"python3-django","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"}],"questing":[{"name":"python-django","version":"3:5.2.4-1ubuntu2.3","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"},{"name":"python3-django","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"}],"trusty":[{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"},{"name":"python-django-doc","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-1312","CVE-2026-1287","CVE-2026-1207","CVE-2025-13473","CVE-2025-14550","CVE-2026-1285"]}]},{"id":"CVE-2026-1285","published":"2026-02-03T14:00:00","updated_at":"2026-02-04T13:23:28.186187+00:00","description":"\nAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2\nbefore 4.2.28.\n`django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with\n`html=True`) and the `truncatechars_html` and `truncatewords_html` template\nfilters allow a remote attacker to cause a potential denial-of-service via\ncrafted inputs containing a large number of unmatched HTML end tags.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were\nnot evaluated and may also be affected.\nDjango would like to thank Seokchan Yoon for reporting this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1285","https://www.djangoproject.com/weblog/2026/feb/03/security-releases/","https://ubuntu.com/security/notices/USN-8009-1"],"bugs":[""],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"resolute","status":"released","description":"3:5.2.9-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.2,5.2.11,4.2.28","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.11.11-1ubuntu1.21+esm14","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2:2.2.12-1ubuntu0.29+esm7","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"2:3.2.12-2ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3:4.2.11-1ubuntu1.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3:5.2.4-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.8.7-1ubuntu5.15+esm11","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8009-1"],"notices":[{"id":"USN-8009-1","title":"Django vulnerabilities","summary":"Several security issues were fixed in Django.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-03T16:06:09.409412","description":"It was discovered that Django exposed timing information when checking\npasswords. An attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2025-13473)\n\nJiyong Yang discovered that Django incorrectly handled malformed requests\nwith duplicate headers. An attacker could possibly use this issue to cause\na denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu\n24.04 LTS, and Ubuntu 25.10. (CVE-2025-14550)\n\nTarek Nakkouch discovered that Django incorrectly parsed raster lookups. An\nattacker could possibly use this issue to perform SQL injection attacks.\nThis issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1207)\n\nSeokchan Yoon discovered that Django incorrectly handled malformed HTML\ninputs containing a large amount of unmatched HTML end tags. An attacker\ncould possibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1285)\n\nSolomon Kebede discovered that Django incorrectly handled control\ncharacters in the dictionary expansion of certain QuerySet methods. An\nattacker could possibly use this issue to perform SQL injection attacks.\n(CVE-2026-1287)\n\nSolomon Kebede discovered that Django incorrectly handled column alias\nparsing with dictionary expansion. An attacker could possibly use this\nissue to perform SQL injection attacks. This issue only affected Ubuntu\n24.04 LTS and Ubuntu 25.10. (CVE-2026-1312)","is_hidden":false,"release_packages":{"bionic":[{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"python-django","version":"2:2.2.12-1ubuntu0.29+esm7","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"python-django","version":"2:3.2.12-2ubuntu1.25","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"},{"name":"python3-django","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"}],"noble":[{"name":"python-django","version":"3:4.2.11-1ubuntu1.14","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"},{"name":"python3-django","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"}],"questing":[{"name":"python-django","version":"3:5.2.4-1ubuntu2.3","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"},{"name":"python3-django","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"}],"trusty":[{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"},{"name":"python-django-doc","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-1312","CVE-2026-1287","CVE-2026-1207","CVE-2025-13473","CVE-2025-14550","CVE-2026-1285"]}]},{"id":"CVE-2026-1207","published":"2026-02-03T14:00:00","updated_at":"2026-02-04T13:22:51.336300+00:00","description":"\nAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2\nbefore 4.2.28.\nRaster lookups on ``RasterField`` (only implemented on PostGIS) allows\nremote attackers to inject SQL via the band index parameter.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were\nnot evaluated and may also be affected.\nDjango would like to thank Tarek Nakkouch for reporting this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1207","https://www.djangoproject.com/weblog/2026/feb/03/security-releases/","https://ubuntu.com/security/notices/USN-8009-1"],"bugs":[""],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.2,5.2.11,4.2.28","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.11.11-1ubuntu1.21+esm14","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2:2.2.12-1ubuntu0.29+esm7","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"2:3.2.12-2ubuntu1.25","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3:4.2.11-1ubuntu1.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3:5.2.4-1ubuntu2.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-8009-1"],"notices":[{"id":"USN-8009-1","title":"Django vulnerabilities","summary":"Several security issues were fixed in Django.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-03T16:06:09.409412","description":"It was discovered that Django exposed timing information when checking\npasswords. An attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2025-13473)\n\nJiyong Yang discovered that Django incorrectly handled malformed requests\nwith duplicate headers. An attacker could possibly use this issue to cause\na denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu\n24.04 LTS, and Ubuntu 25.10. (CVE-2025-14550)\n\nTarek Nakkouch discovered that Django incorrectly parsed raster lookups. An\nattacker could possibly use this issue to perform SQL injection attacks.\nThis issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1207)\n\nSeokchan Yoon discovered that Django incorrectly handled malformed HTML\ninputs containing a large amount of unmatched HTML end tags. An attacker\ncould possibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-1285)\n\nSolomon Kebede discovered that Django incorrectly handled control\ncharacters in the dictionary expansion of certain QuerySet methods. An\nattacker could possibly use this issue to perform SQL injection attacks.\n(CVE-2026-1287)\n\nSolomon Kebede discovered that Django incorrectly handled column alias\nparsing with dictionary expansion. An attacker could possibly use this\nissue to perform SQL injection attacks. This issue only affected Ubuntu\n24.04 LTS and Ubuntu 25.10. (CVE-2026-1312)","is_hidden":false,"release_packages":{"bionic":[{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1:1.11.11-1ubuntu1.21+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"python-django","version":"2:2.2.12-1ubuntu0.29+esm7","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"2:2.2.12-1ubuntu0.29+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"python-django","version":"2:3.2.12-2ubuntu1.25","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"},{"name":"python3-django","version":"2:3.2.12-2ubuntu1.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.25","pocket":"security"}],"noble":[{"name":"python-django","version":"3:4.2.11-1ubuntu1.14","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"},{"name":"python3-django","version":"3:4.2.11-1ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.14","pocket":"security"}],"questing":[{"name":"python-django","version":"3:5.2.4-1ubuntu2.3","description":"High-level Python web development framework","is_source":true},{"name":"python-django-doc","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"},{"name":"python3-django","version":"3:5.2.4-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.3","pocket":"security"}],"trusty":[{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"},{"name":"python-django-doc","version":"1.6.11-0ubuntu1.3+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-common","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python-django-doc","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"},{"name":"python3-django","version":"1.8.7-1ubuntu5.15+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-1312","CVE-2026-1287","CVE-2026-1207","CVE-2025-13473","CVE-2025-14550","CVE-2026-1285"]}]}],"offset":15680,"limit":20,"total_results":79316}