{"cves":[{"id":"CVE-2026-18724","published":"2026-08-18T00:00:00","updated_at":"2026-08-18T12:50:01.845167+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-18724","https://bugzilla.redhat.com/show_bug.cgi?id=2461994"],"bugs":[""],"patches":{"open-iscsi":[]},"tags":{},"packages":[{"name":"open-iscsi","source":"https://ubuntu.com/security/cve?package=open-iscsi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=open-iscsi","debian":"https://tracker.debian.org/pkg/open-iscsi","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11817","published":"2026-08-17T22:16:00","updated_at":"2026-08-19T12:14:22.716590+00:00","description":"\nThis vulnerability only affects Grafana stacks configured with multiple\norganizations; single-organization deployments are not impacted. In a\nmulti-organization stack, a user who is an Org Admin of a single\norganization can call GET\n/api/access-control/users/permissions/search?actionPrefix=dashboards: and\nreceive permission data belonging to other organizations. The disclosed\ndata is limited to dashboard and folder identifiers (UIDs) and per-user\npermission/scope mappings (which user holds which access on which\ndashboard). Dashboard contents, panels, query results, datasource\ncredentials, secrets, and personal data are not exposed. This is a limited\ncross-organization information disclosure affecting multi-org deployments\nonly.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11817","https://grafana.com/security/security-advisories/cve-2026-11817"],"bugs":[""],"patches":{"grafana":[]},"tags":{},"packages":[{"name":"grafana","source":"https://ubuntu.com/security/cve?package=grafana","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=grafana","debian":"https://tracker.debian.org/pkg/grafana","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-68765","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:26:50.467694+00:00","description":"\nhashcat master branch builds after v7.1.2 contain a heap buffer overflow\nvulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that\nallows attackers to corrupt adjacent heap memory by supplying an oversized\nninth hash field token. The module accepts up to 600 hex characters for the\nninth token field but decodes it into a fixed 256-byte buffer with no\nlength check, allowing a maximal input to write up to 44 bytes past the\nbuffer boundary into adjacent esalt fields and heap chunk metadata,\npotentially enabling heap corruption or memory access violations.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-68765","https://github.com/hashcat/hashcat","https://github.com/hashcat/hashcat/commit/6f374c4ff7d5dc951530fbbbcf6b45e3c169b100","https://github.com/hashcat/hashcat/pull/4755","https://www.vulncheck.com/advisories/hashcat-keepass-kdbx-v4-module-heap-buffer-overflow-via-token-field"],"bugs":[""],"patches":{"hashcat":[]},"tags":{},"packages":[{"name":"hashcat","source":"https://ubuntu.com/security/cve?package=hashcat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hashcat","debian":"https://tracker.debian.org/pkg/hashcat","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-65976","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:23:28.798604+00:00","description":"\nDeskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous\nbuild 1.26.0.300, a connected peer can send repeated DCLP DataChunk\nmessages to ClipboardChunk::assemble() in\nsrc/lib/deskflow/ClipboardChunk.cpp, causing the server path in\nsrc/lib/server/ClientProxy1_6.cpp or client path in\nsrc/lib/client/ServerProxy.cpp to append data beyond the DataStart declared\nsize and configured clipboard limit before DataEnd validation, exhausting\nreceiver memory. This issue is fixed in continuous build 1.26.0.300.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-65976","https://github.com/deskflow/deskflow/commit/8a535fd5dd48315eaaf6b93d5c7534d0592addef","https://github.com/deskflow/deskflow/commit/bcd3a658fc3b2ad735146fdc9efefa9462d195b7","https://github.com/deskflow/deskflow/security/advisories/GHSA-jf7g-qghg-p54x"],"bugs":[""],"patches":{"deskflow":[]},"tags":{},"packages":[{"name":"deskflow","source":"https://ubuntu.com/security/cve?package=deskflow","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=deskflow","debian":"https://tracker.debian.org/pkg/deskflow","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-65832","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:23:13.885731+00:00","description":"\nDeskflow is a keyboard and mouse sharing app. Prior to continuous build\n1.26.0.299, a remote unauthenticated Deskflow server can send\nkMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in\nsrc/lib/client/ServerProxy.cpp so that the value following a modifier\noption poisons m_modifierTranslationTable, after which\nServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes\nthe seven-row s_translationTable or s_masks arrays out of bounds,\ndisclosing four bytes at an attacker-selected relative offset or crashing\nthe connected client; an odd option count also causes an out-of-bounds\nOptionsList read. This issue is fixed in continuous build 1.26.0.299.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-65832","https://github.com/deskflow/deskflow/commit/205a3c803e5298d56683660736ec1a41b671b56e","https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","https://github.com/deskflow/deskflow/security/advisories/GHSA-8rcq-7w87-h64j"],"bugs":[""],"patches":{"deskflow":[]},"tags":{},"packages":[{"name":"deskflow","source":"https://ubuntu.com/security/cve?package=deskflow","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=deskflow","debian":"https://tracker.debian.org/pkg/deskflow","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-65640","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:25:40.311978+00:00","description":"\nWordPress is vulnerable to a remote code execution vulnerability via\nmalicious Postscript file upload by an Author level user or higher.\nPrerequisites:\n* Imagick and Ghostscript in use on the server\n* A malicious user with the `upload_files` capability\nThis issue affects all versions of WordPress. Version 7.0.4 has been\nreleased, containing a fix for the vulnerability, and as a courtesy to\nusers on older branches the fix has been backported to all branches back to\n4.7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-65640","https://wordpress.org/news/2026/08/wordpress-7-0-4-release/"],"bugs":[""],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63409","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:21:01.091962+00:00","description":"\nDeskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous\nbuild 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP\nvector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp,\ncausing the missing value after the final option key to be read beyond the\nvector during the PacketStreamFilter::filterEvent to\nServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call\nchain and crash the connected client. This issue is fixed in continuous\nbuild 1.26.0.296.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63409","https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","https://github.com/deskflow/deskflow/security/advisories/GHSA-gmvh-3c73-m5gg"],"bugs":[""],"patches":{"deskflow":[]},"tags":{},"packages":[{"name":"deskflow","source":"https://ubuntu.com/security/cve?package=deskflow","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=deskflow","debian":"https://tracker.debian.org/pkg/deskflow","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-34789","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:19:18.143737+00:00","description":"\nFreeCAD is a free and open-source multiplatform 3D parametric modeler.\nPrior to 1.1.2, src/App/PropertyPythonObject.cpp in\nPropertyPythonObject::Restore() passes the attacker-controlled module\nattribute from serialized PropertyPythonObject XML directly to\nPyImport_ImportModule() while restoring a crafted FCStd document, which\nexecutes module-level Python code, and the legacy pickle branch also\nimports an attacker-controlled module and invokes its class constructor\nthrough PyObject_CallObject(). This issue is fixed in version 1.1.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34789","https://github.com/FreeCAD/FreeCAD/commit/81b73925ce22610542367301d8eff4259eb9596e","https://github.com/FreeCAD/FreeCAD/commit/983037f3003dc31f48db36705b86fb3fbe026295","https://github.com/FreeCAD/FreeCAD/commit/e2dc6c8172673642c6856b8b3a5a6accefb18279","https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.2","https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-493w-pp4h-h77v"],"bugs":[""],"patches":{"freecad":[]},"tags":{},"packages":[{"name":"freecad","source":"https://ubuntu.com/security/cve?package=freecad","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freecad","debian":"https://tracker.debian.org/pkg/freecad","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-34399","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:17:08.860058+00:00","description":"\nFreeCAD is a free and open-source multiplatform 3D parametric modeler. From\n0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on\nuntrusted data from SVG template files. When a user creates a TechDraw page\nfrom a malicious SVG template, arbitrary Python code executes. The\nvulnerable code is in src/Mod/BIM/bimcommands/BimTDPage.py (line 87). This\nissue is fixed in version 1.1.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34399","https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.1","https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-chv4-vm6r-wjqj"],"bugs":[""],"patches":{"freecad":[]},"tags":{},"packages":[{"name":"freecad","source":"https://ubuntu.com/security/cve?package=freecad","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freecad","debian":"https://tracker.debian.org/pkg/freecad","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-34398","published":"2026-08-17T21:16:00","updated_at":"2026-08-19T12:18:37.685364+00:00","description":"\nFreeCAD is a free and open-source multiplatform 3D parametric modeler. From\n0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM\nProject Manager Load Template flow passes attacker-controlled FCStd Meta\nproperty values for wpposition, wpu, wpv, and wpaxis directly to eval(),\nallowing arbitrary Python code execution when a user loads a malicious BIM\nproject template. This issue is fixed in version 1.1.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34398","https://github.com/FreeCAD/FreeCAD/commit/871ee19b76224910332bbfbd39eebbede967998b","https://github.com/FreeCAD/FreeCAD/commit/9ed351cc4700db0a94c46f020c34c58bbf1bdaba","https://github.com/FreeCAD/FreeCAD/pull/28610","https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.1","https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-8rfj-7956-6gwf"],"bugs":[""],"patches":{"freecad":[]},"tags":{},"packages":[{"name":"freecad","source":"https://ubuntu.com/security/cve?package=freecad","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freecad","debian":"https://tracker.debian.org/pkg/freecad","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45698","published":"2026-08-17T19:16:00","updated_at":"2026-08-19T12:15:49.773132+00:00","description":"\nNetatalk is a Free and Open Source file server suite for Unix-like\noperating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer\noverflow exists in the deletedir() function of Netatalk's afpd daemon due\nto an integer underflow in the calculation of the remaining buffer size\nused for path construction. deletedir() is a utility function called when a\nfile operation crosses a device boundary inside an AFP shared volume, which\nthe standard library's renameat() cannot handle. The function attempts to\nprevent buffer overflows by tracking available space in a size_t remain\nvariable. However, the arithmetic used to compute remain results in an\nunsigned integer underflow, causing the variable to become SIZE_MAX.\nBecause of this, the subsequent boundary check always evaluates as safe,\nallowing an unbounded strcpy() operation to copy attacker-controlled\nfilenames into a nearly full stack buffer. Version 4.4.3 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45698","https://netatalk.io/security/CVE-2026-45698"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137126"],"patches":{"netatalk":[]},"tags":{},"packages":[{"name":"netatalk","source":"https://ubuntu.com/security/cve?package=netatalk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=netatalk","debian":"https://tracker.debian.org/pkg/netatalk","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.3~ds-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-71491","published":"2026-08-17T18:18:00","updated_at":"2026-08-19T12:24:30.131141+00:00","description":"\nsqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0,\ngroup_comments in sqlparse/engine/grouping.py repeatedly rescans\ncomment-only statements before the MAX_GROUPING_TOKENS guard, causing\nquadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql,\nstrip_comments=True). This issue is fixed in version 0.6.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-71491","https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p"],"bugs":[""],"patches":{"sqlparse":[]},"tags":{},"packages":[{"name":"sqlparse","source":"https://ubuntu.com/security/cve?package=sqlparse","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sqlparse","debian":"https://tracker.debian.org/pkg/sqlparse","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-68520","published":"2026-08-17T18:18:00","updated_at":"2026-08-19T12:26:39.015114+00:00","description":"\nGlances is an open-source system cross-platform monitoring tool. Prior to\n4.5.6, as_dict_secure() in glances/config.py checks only option names and\nexposes public_username and credentials embedded in public_api values\nthrough unauthenticated GET /api/4/config and GET /api/4/config/ip\nrequests. This issue is fixed in 4.5.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-68520","https://github.com/nicolargo/glances/security/advisories/GHSA-4h34-v6r8-mmjc"],"bugs":[""],"patches":{"glances":[]},"tags":{},"packages":[{"name":"glances","source":"https://ubuntu.com/security/cve?package=glances","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glances","debian":"https://tracker.debian.org/pkg/glances","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.5.6+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-68519","published":"2026-08-17T18:18:00","updated_at":"2026-08-19T12:24:30.131141+00:00","description":"\nGlances is an open-source system cross-platform monitoring tool. Prior to\n4.5.6, GlancesActions.run() in glances/actions.py ignores\n--disable-config-exec for on-alert action commands and invokes\nsecure_popen() with shell operators enabled, allowing configured\nredirection, command chaining, or pipes to execute when an alert triggers.\nThis issue is fixed in 4.5.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-68519","https://github.com/nicolargo/glances/security/advisories/GHSA-59fj-m2j6-hcxh"],"bugs":[""],"patches":{"glances":[]},"tags":{},"packages":[{"name":"glances","source":"https://ubuntu.com/security/cve?package=glances","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glances","debian":"https://tracker.debian.org/pkg/glances","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.5.6+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-62982","published":"2026-08-17T18:17:00","updated_at":"2026-08-19T12:22:46.145354+00:00","description":"\nGlances is an open-source system cross-platform monitoring tool. From 4.5.2\nuntil 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested\nlist and dictionary strings such as process cmdline values, allowing pipe\ncharacters to survive chevron.render() and be executed by secure_popen()\nthrough administrator-configured action templates. This issue is fixed in\n4.5.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-62982","https://github.com/nicolargo/glances/security/advisories/GHSA-73wf-9vmv-5pv9"],"bugs":[""],"patches":{"glances":[]},"tags":{},"packages":[{"name":"glances","source":"https://ubuntu.com/security/cve?package=glances","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glances","debian":"https://tracker.debian.org/pkg/glances","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.5.6+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59903","published":"2026-08-17T18:17:00","updated_at":"2026-08-19T12:23:50.380646+00:00","description":"\nNetty is an asynchronous, event-driven network application framework. Prior\nto 4.1.137.Final and 4.2.17.Final,\nio.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces\napplication Vary headers such as Authorization or Cookie with Origin,\nallowing a caching proxy or CDN to reuse authenticated responses across\nusers and disclose sensitive information. This issue is fixed in versions\n4.1.137.Final and 4.2.17.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59903"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59902","published":"2026-08-17T18:17:00","updated_at":"2026-08-19T12:22:32.718071+00:00","description":"\nNetty is an asynchronous, event-driven network application framework. Prior\nto 4.1.137.Final and 4.2.17.Final,\nio.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete\nmessages and fragment counts but not maxBufferedBytes, allowing\nunauthenticated peers to exhaust memory with large SCTP fragments. This\nissue is fixed in versions 4.1.137.Final and 4.2.17.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59902"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59894","published":"2026-08-17T18:17:00","updated_at":"2026-08-19T12:22:14.517489+00:00","description":"\nsqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0,\nsqlparse/filters/output.py fails to escape existing backslashes before\nquotes in sqlparse.format output_format='python' and output_format='php'\nand the corresponding sqlformat -l modes, allowing crafted SQL to terminate\nthe generated string and inject Python or PHP code when a downstream\nconsumer executes or imports the generated source. This issue is fixed in\nversion 0.6.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},"baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59894","https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x"],"bugs":[""],"patches":{"sqlparse":[]},"tags":{},"packages":[{"name":"sqlparse","source":"https://ubuntu.com/security/cve?package=sqlparse","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sqlparse","debian":"https://tracker.debian.org/pkg/sqlparse","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59893","published":"2026-08-17T18:17:00","updated_at":"2026-08-19T12:23:50.380646+00:00","description":"\nsqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0,\nSQL_REGEX in sqlparse/keywords.py and the per-position loop in\nsqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and\nmultiline-comment delimiters, causing quadratic CPU consumption through\nsqlparse.parse(), sqlparse.format(), and sqlparse.split(). This issue is\nfixed in version 0.6.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59893","https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr"],"bugs":[""],"patches":{"sqlparse":[]},"tags":{},"packages":[{"name":"sqlparse","source":"https://ubuntu.com/security/cve?package=sqlparse","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sqlparse","debian":"https://tracker.debian.org/pkg/sqlparse","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54284","published":"2026-08-17T18:17:00","updated_at":"2026-08-19T12:23:28.798604+00:00","description":"\nsqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0,\nTokenList construction and string conversion in sqlparse/sql.py repeatedly\nflatten nested token subtrees constructed by group_parenthesis and\ngroup_case, causing quadratic CPU consumption through sqlparse.parse(),\nsqlparse.format(), and sqlparse.split() before depth and token limits\nterminate processing. This issue is fixed in version 0.6.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54284","https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f"],"bugs":[""],"patches":{"sqlparse":[]},"tags":{},"packages":[{"name":"sqlparse","source":"https://ubuntu.com/security/cve?package=sqlparse","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sqlparse","debian":"https://tracker.debian.org/pkg/sqlparse","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":3680,"limit":20,"total_results":79316}