{"cves":[{"id":"CVE-2026-80211","published":"2026-08-27T17:20:00","updated_at":"2026-09-02T21:14:08.965000+00:00","description":"\nFrontAccounting through 2.4.20 stores and verifies user passwords as\nunsalted MD5 digests. admin/users.php passes md5($_POST['password']) to\nadd_user() and update_user_password(),\nadmin/change_current_user_password.php does the same when a user changes\ntheir own password, the forgotten-password path in\nincludes/current_user.inc hashes the newly generated password the same way,\nand authentication calls get_user_auth($loginname, md5($password)). The\ncodebase applies no per-password salt and contains no call to\npassword_hash(), password_verify() or any other adaptive hash, so identical\npasswords yield identical digests and an attacker who obtains the user\ntable can recover plaintext passwords with precomputed lookup tables or\nhigh-rate GPU cracking.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-80211","https://github.com/FrontAccountingERP/FA","https://github.com/FrontAccountingERP/FA/blob/9464a3ffef03c139d9396e697bce9a0a9f131a72/includes/current_user.inc#L79","https://github.com/geo-chen/oss/blob/main/FA.md#finding-2-unsalted-md5-password-hashing-in-frontaccounting","https://www.vulncheck.com/advisories/frontaccounting-through-2.4.20-use-of-unsalted-md5-for-password-storage"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-80210","published":"2026-08-27T17:20:00","updated_at":"2026-09-02T21:15:19.330134+00:00","description":"\nFrontAccounting through 2.4.20 generates a CSRF token in end_form() in\nincludes/ui/ui_controls.inc and embeds it as the _token hidden field in\nevery form it renders, but only admin/users.php and\nadmin/change_current_user_password.php call check_csrf_token() to validate\nit. No financial transaction handler validates the token, including\ngl/gl_journal.php, gl/gl_bank.php, purchasing/supplier_invoice.php,\nsales/customer_invoice.php, sales/customer_payments.php and\nadmin/company_preferences.php, so those endpoints act on POST data with no\norigin check. An attacker who gets an authenticated user to load a page\nunder attacker control can auto-submit a cross-origin form to any of them\nand have the forged journal entry, invoice, customer payment, bank\ntransaction or company configuration change recorded under the victim's\nsession.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-80210","https://github.com/FrontAccountingERP/FA","https://github.com/FrontAccountingERP/FA/blob/9464a3ffef03c139d9396e697bce9a0a9f131a72/includes/ui/ui_controls.inc#L89","https://github.com/geo-chen/oss/blob/main/FA.md#finding-1-cross-site-request-forgery-on-financial-transaction-forms-in-frontaccounting","https://www.vulncheck.com/advisories/frontaccounting-through-2.4.20-cross-site-request-forgery-on-financial-transaction-forms"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-78002","published":"2026-08-27T17:20:00","updated_at":"2026-09-11T16:17:20.604657+00:00","description":"\nA flaw was found in rsyslog. An unauthenticated remote attacker can trigger\na heap buffer overflow in the RainerScript `replace()` function by sending\nspecially crafted syslog messages. This vulnerability arises from an\nincorrect buffer size calculation during string replacement, causing memory\ncorruption. Successful exploitation can lead to a denial of service (DoS)\nfor the affected system.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-78002","https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3","https://github.com/rsyslog/rsyslog/pull/7525","https://www.openwall.com/lists/oss-security/2026/08/29/1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145980","https://bugzilla.redhat.com/show_bug.cgi?id=2521135"],"patches":{"rsyslog":["upstream: https://github.com/rsyslog/rsyslog/commit/667e3f61aec5ee02c5c2ee6f0f8accf6fe4301a9"]},"tags":{},"packages":[{"name":"rsyslog","source":"https://ubuntu.com/security/cve?package=rsyslog","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rsyslog","debian":"https://tracker.debian.org/pkg/rsyslog","statuses":[{"release_codename":"upstream","status":"released","description":"8.2608.0-4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59280","published":"2026-08-27T17:18:00","updated_at":"2026-09-02T21:04:46.842262+00:00","description":"\nApplications using Spring Framework's FreeMarker integration may be\nvulnerable to a path traversal attack when a controller returns a view name\nderived from untrusted input and FreeMarker is configured to resolve\ntemplates through SpringTemplateLoader.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59280","https://spring.io/security/cve-2026-59280"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5680","published":"2026-08-27T17:18:00","updated_at":"2026-09-02T21:04:23.398185+00:00","description":"\nA flaw was found in Undertow. A remote attacker could exploit this\nvulnerability by sending specially crafted WebSocket messages with\npermessage-deflate negotiated. This could lead to excessive memory\nconsumption due to the PerMessageDeflateFunction.largerBuffer() method\nusing exponential doubling, resulting in a Denial of Service (DoS) for the\naffected application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5680","https://bugzilla.redhat.com/show_bug.cgi?id=2455350","https://access.redhat.com/security/cve/CVE-2026-5680"],"bugs":[""],"patches":{"undertow":[]},"tags":{},"packages":[{"name":"undertow","source":"https://ubuntu.com/security/cve?package=undertow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=undertow","debian":"https://tracker.debian.org/pkg/undertow","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59354","published":"2026-08-27T10:16:00","updated_at":"2026-09-02T21:06:17.590070+00:00","description":"\nIn versions of Spring Security's OAuth2 Authorization Server module 7.0.0\nthrough 7.0.4, when Dynamic Client Registration is explicitly enabled, the\nregistration endpoint performs insufficient validation of certain client\nmetadata fields supplied by the registering client. An attacker who\npossesses a valid Initial Access Token can register a malicious client with\ncrafted metadata, which, depending on server configuration and how the\nmetadata is later rendered or used, may result in Stored Cross-Site\nScripting (XSS), Privilege Escalation, or Server-Side Request Forgery\n(SSRF).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59354","https://spring.io/security/cve-2026-59354","https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N&version=3.1"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47893","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:46:21.284640+00:00","description":"\nA Spring WebFlux application that supports WebSocket connections may expose\nindirectly sensitive user information by including request headers in an\nexception reason.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47893","https://spring.io/security/cve-2026-47893"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47892","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:46:12.972112+00:00","description":"\nA WebFlux application using functional endpoints and deployed with\nDispatcherServlet may be vulnerable to a header predicate bypass in a\npre-flight request.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.5.RELEASE - 5.2.25.RELEASE","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47892","https://spring.io/security/cve-2026-47892"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47891","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:45:39.434274+00:00","description":"\nA Spring WebFlux application that relies on the Aalto XML processor to\nparse XML input does not correctly enforce the maxInMemorySize limit.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47891","https://spring.io/security/cve-2026-47891"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47890","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:44:41.259391+00:00","description":"\nSpring MVC and WebFlux applications are vulnerable to stream corruption\nwhen using Server-Sent Events (SSE) with view fragments.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47890","https://spring.io/security/cve-2026-47890"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47889","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:44:10.924245+00:00","description":"\nA WebFlux application running on the Jetty 12 Core reactive adapter\nserializes response cookies without the sameSite attribute.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47889","https://spring.io/security/cve-2026-47889"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47888","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:46:12.972112+00:00","description":"\nA Spring RSocket application is exposed to a memory leak via a malformed\nSETUP frame.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.0.RELEASE - 5.2.25.RELEASE","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47888","https://spring.io/security/cve-2026-47888"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47887","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:44:10.924245+00:00","description":"\nA Spring MVC application that uses UrlFileNameViewController that is mapped\nwith an end-of-path, and does not have a configured prefix is vulnerable to\nan open redirect.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47887","https://spring.io/security/cve-2026-47887"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47886","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:46:21.284640+00:00","description":"\nApplications that evaluate user-supplied Spring Expression Language (SpEL)\nexpressions may be vulnerable to a Denial of Service (DoS) attack when the\npower operator (^) is used with a BigDecimal or BigInteger operand and a\nlarge exponent value.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47886","https://spring.io/security/cve-2026-47886"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47885","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:44:57.096645+00:00","description":"\nThe PartEventHttpMessageReader in Spring WebFlux does not enforce the\nmaxPartSize limit when maxInMemorySize is set to -1.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47885","https://spring.io/security/cve-2026-47885"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47884","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:44:34.052718+00:00","description":"\nUse of XsltView in a Spring MVC application can result in SSRF and RCE\nattack if the application has an \"/**\" mapping that results in view\nrendering, and where the view name is not explicitly specified.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47884","https://spring.io/security/cve-2026-47884"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47883","published":"2026-08-27T06:17:00","updated_at":"2026-08-31T06:44:28.124863+00:00","description":"\nUrlHandlerFilter can be vulnerable to an open redirect when configured with\nvery broadly matching patterns. The issue applies to the filter variants in\nboth Spring MVC and Spring WebFlux.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47883","https://spring.io/security/cve-2026-47883"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-80183","published":"2026-08-27T01:18:00","updated_at":"2026-08-27T22:05:34.004765+00:00","description":"\nIn OpenStack Keystone before 29.0.3, any authenticated user holding\nrole:reader on any project can list every project-scoped role assignment\nunder any domain by passing a domain ID as scope.project.id with\ninclude_subtree to the GET /v3/role_assignments endpoint. The domain's\nproject record has domain_id=null, causing the policy domain_id check to\npass for any caller. With include_names, the response discloses the names\nand home-domain IDs of every user, group, project, and role involved. The\nliteral \"default\" domain ID works against any deployment created with\nkeystone-manage bootstrap. An attacker can harvest domain IDs from the\nresponse and repeat the query to map role assignments across the entire\ncloud. This is caused by misuse of \"None\" in\nlist_role_assignments_for_tree.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-80183","https://launchpad.net/bugs/2154645"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145816"],"patches":{"keystone":[]},"tags":{},"packages":[{"name":"keystone","source":"https://ubuntu.com/security/cve?package=keystone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=keystone","debian":"https://tracker.debian.org/pkg/keystone","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-79619","published":"2026-08-27T00:00:00","updated_at":"2026-09-02T21:15:44.350072+00:00","description":"\nOn Linux, several OpenZFS ioctl authorization checks accept a capability\nheld only within a user-created, unprivileged namespace as equivalent to\nreal host privilege, allowing an unprivileged local user to perform\noperations that should require root. Affected operations include\npool-administrative operations (eg create, import, destroy), pool event log\naccess (zpool events) and fault injection (zinject). Exploiting the problem\nrequires only that the local user is permitted to open /dev/zfs (governed\nby local device permissions) and that the kernel permits unprivileged user\nnamespace creation. No prior access to the target pool or its underlying\ndevices is needed.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nSee ubuntu cvss score"}],"codename":null,"priority":"high","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-79619","https://github.com/advisories/GHSA-mhf5-q8gw-qg9v","https://www.openwall.com/lists/oss-security/2026/08/16/5","https://github.com/openzfs/zfs/pull/18959","https://ubuntu.com/security/notices/USN-8705-1","https://ubuntu.com/security/notices/USN-8705-2"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/zfs-linux/+bug/2164774","https://github.com/openzfs/zfs/issues/18936"],"patches":{"zfs-linux":[]},"tags":{},"packages":[{"name":"zfs-linux","source":"https://ubuntu.com/security/cve?package=zfs-linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zfs-linux","debian":"https://tracker.debian.org/pkg/zfs-linux","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.4-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.7.5-1ubuntu16.12+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"0.8.3-1ubuntu12.18+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"2.1.5-1ubuntu6~22.04.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.2.2-0ubuntu9.5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.1-1ubuntu5.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8705-1","USN-8705-2"],"notices":[{"id":"USN-8705-1","title":"OpenZFS vulnerability","summary":"OpenZFS could be made to run programs as an administrator.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-31T12:57:46.759302","description":"It was discovered that OpenZFS incorrectly handled authorization checks for\ncertain ioctl operations on Linux. A local attacker could possibly use this\nissue to perform pool-administrative operations or access privileged\ninformation, resulting in an authorization bypass.","is_hidden":false,"release_packages":{"jammy":[{"name":"zfs-linux","version":"2.1.5-1ubuntu6~22.04.7","description":"OpenZFS file system for Linux","is_source":true},{"name":"libnvpair3linux","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"libpam-zfs","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"libuutil3linux","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"libzfs4linux","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"libzfsbootenv1linux","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"libzfslinux-dev","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"libzpool5linux","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"python3-pyzfs","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"pyzfs-doc","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"zfs-dkms","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"zfs-dracut","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"zfs-initramfs","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"zfs-test","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"zfs-zed","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"},{"name":"zfsutils-linux","version":"2.1.5-1ubuntu6~22.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.1.5-1ubuntu6~22.04.7","pocket":"security"}],"noble":[{"name":"zfs-linux","version":"2.2.2-0ubuntu9.5","description":"OpenZFS file system for Linux","is_source":true},{"name":"libnvpair3linux","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"libpam-zfs","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"libuutil3linux","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"libzfs4linux","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"libzfsbootenv1linux","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"libzfslinux-dev","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"libzpool5linux","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"python3-pyzfs","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"pyzfs-doc","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"zfs-dkms","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"zfs-dracut","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"zfs-initramfs","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"zfs-test","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"zfs-zed","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"},{"name":"zfsutils-linux","version":"2.2.2-0ubuntu9.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.2.2-0ubuntu9.5","pocket":"security"}],"resolute":[{"name":"zfs-linux","version":"2.4.1-1ubuntu5.1","description":"OpenZFS file system for Linux","is_source":true},{"name":"libnvpair3linux","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"libpam-zfs","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"libuutil3linux","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"libzfs7linux","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"libzfsbootenv1linux","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"libzfslinux-dev","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"libzpool7linux","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"python3-pyzfs","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"pyzfs-doc","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"zfs-dkms","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"zfs-dracut","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"zfs-initramfs","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"zfs-test","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"zfs-zed","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"},{"name":"zfsutils-linux","version":"2.4.1-1ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":"https://launchpad.net/ubuntu/+source/zfs-linux/2.4.1-1ubuntu5.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-79619"]},{"id":"USN-8705-2","title":"OpenZFS vulnerability","summary":"OpenZFS could be made to run programs as an administrator.","instructions":"After a standard system update you need to reboot your computer to make all the necessary changes.","references":[],"published":"2026-08-31T21:36:58.481395","description":"USN-8705-1 fixed vulnerabilities in OpenZFS. This update provides the\ncorresponding fix for OpenZFS on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n\nOriginal advisory details:\n\nIt was discovered that OpenZFS incorrectly handled authorization checks for\ncertain ioctl operations on Linux. A local attacker could possibly use this\nissue to perform pool-administrative operations or access privileged\ninformation, resulting in an authorization bypass.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"zfs-linux","version":"0.7.5-1ubuntu16.12+esm1","description":"OpenZFS file system for Linux","is_source":true},{"name":"libnvpair1linux","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libuutil1linux","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libzfs2linux","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libzfslinux-dev","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libzpool2linux","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-dkms","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-doc","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-dracut","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-initramfs","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-test","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-zed","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfsutils-linux","version":"0.7.5-1ubuntu16.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"zfs-linux","version":"0.8.3-1ubuntu12.18+esm1","description":"OpenZFS file system for Linux","is_source":true},{"name":"libnvpair1linux","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libuutil1linux","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libzfs2linux","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libzfslinux-dev","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"libzpool2linux","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"python3-pyzfs","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"pyzfs-doc","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"spl","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"spl-dkms","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-dkms","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-dracut","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-initramfs","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-test","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfs-zed","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"},{"name":"zfsutils-linux","version":"0.8.3-1ubuntu12.18+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/zfs-linux","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-79619"]}]},{"id":"CVE-2026-77682","published":"2026-08-27T00:00:00","updated_at":"2026-08-27T22:02:31.144577+00:00","description":"\n[Use a user message to trigger form autofill]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-77682","https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2147"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145177"],"patches":{"epiphany-browser":[]},"tags":{},"packages":[{"name":"epiphany-browser","source":"https://ubuntu.com/security/cve?package=epiphany-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=epiphany-browser","debian":"https://tracker.debian.org/pkg/epiphany-browser","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":2540,"limit":20,"total_results":79316}