{"cves":[{"id":"CVE-2026-74250","published":"2026-08-14T23:16:00","updated_at":"2026-08-19T12:42:51.814354+00:00","description":"\nIn OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail\nto run cleaning immediately after enrollment with, or changing to, the\nautodetect deploy interface.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-74250","https://bugs.launchpad.net/ossa/+bug/2163017"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144458"],"patches":{"ironic":[]},"tags":{},"packages":[{"name":"ironic","source":"https://ubuntu.com/security/cve?package=ironic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ironic","debian":"https://tracker.debian.org/pkg/ironic","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63650","published":"2026-08-14T23:16:00","updated_at":"2026-08-19T14:35:26.530693+00:00","description":"\nOpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated\nusers to be misidentified by ignoring the configured X.509 username\nidentity lookup field","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"The mbedTLS backend is not built on Ubuntu"}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63650","https://community.openvpn.net/Security%20Announcements/CVE-2026-63650","https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026"],"bugs":[""],"patches":{"openvpn":[]},"tags":{},"packages":[{"name":"openvpn","source":"https://ubuntu.com/security/cve?package=openvpn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openvpn","debian":"https://tracker.debian.org/pkg/openvpn","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63649","published":"2026-08-14T23:16:00","updated_at":"2026-08-19T14:36:17.990067+00:00","description":"\nThe Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and\n2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the\ntrusted configuration directory constraint and load arbitrary configuration\nfiles via crafted options that bypass whitelist checks","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"windows-specific issue"}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63649","https://community.openvpn.net/Security%20Announcements/CVE-2026-63649","https://community.openvpn.net/ReleaseHistory#openvpn-2622-released-5-august-2026","https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026"],"bugs":[""],"patches":{"openvpn":[]},"tags":{},"packages":[{"name":"openvpn","source":"https://ubuntu.com/security/cve?package=openvpn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openvpn","debian":"https://tracker.debian.org/pkg/openvpn","statuses":[{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects OpenVPN on Windows","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-74248","published":"2026-08-14T21:17:00","updated_at":"2026-08-19T12:44:44.737190+00:00","description":"\nOpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy\nauthorization. By associating another project's QoS policy with an amphora,\nan authenticated user may prevent deletion of that policy. All Octavia\ndeployments are affected.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-74248","https://www.openwall.com/lists/oss-security/2026/08/13/12","https://bugs.launchpad.net/octavia/+bug/2161500"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144459"],"patches":{"octavia":[]},"tags":{},"packages":[{"name":"octavia","source":"https://ubuntu.com/security/cve?package=octavia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=octavia","debian":"https://tracker.debian.org/pkg/octavia","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45699","published":"2026-08-14T19:17:00","updated_at":"2026-08-19T12:16:31.390112+00:00","description":"\nNetatalk is a Free and Open Source file server suite for Unix-like\noperating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer\noverflow exists in the copydir() function of Netatalk's afpd daemon due to\nan integer underflow in the calculation of the remaining buffer size used\nfor path construction. copydir() is a utility function called when a file\noperation crosses a device boundary inside an AFP shared volume, which the\nstandard library's renameat() cannot handle. The function attempts to track\navailable buffer space using srem and drem for source and destination\npaths. Incorrect arithmetic causes both srem and drem to underflow to\nSIZE_MAX. Consequently, boundary checks against strlen(de->d_name) always\npass, allowing strcpy() to append filenames into nearly full stack buffers.\nVersion 4.4.3 patches the issue. As a workaround, configure each AFP shared\nvolume to be structured as a single file system, in other words no\nsubdirectory of a shared volume should be a mount point for a different\nfile system.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45699","https://netatalk.io/security/CVE-2026-45699"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137125"],"patches":{"netatalk":[]},"tags":{},"packages":[{"name":"netatalk","source":"https://ubuntu.com/security/cve?package=netatalk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netatalk","debian":"https://tracker.debian.org/pkg/netatalk","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.3~ds-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49282","published":"2026-08-14T18:17:00","updated_at":"2026-08-19T12:16:54.382175+00:00","description":"\nCapstone is a disassembly framework. Prior to version 6.0.0-Alpha9,\nCapstone's public `cs_insn_name()` API forwards caller-supplied instruction\nIDs directly to the selected architecture backend. Most backends validate\nthe ID before indexing instruction-name tables, but the M68K and RISCV\nbackends have missing or incomplete bounds checks. On a Capstone handle\nopened for M68K or RISCV, a caller-controlled invalid instruction ID can\ntrigger an out-of-bounds read and crash the process. The demonstrated\nimpact is availability loss in applications or bindings that expose\ninstruction-name lookup to untrusted IDs. No code execution or data\ndisclosure was demonstrated. Version 6.0.0-Alpha9 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49282","https://github.com/capstone-engine/capstone/security/advisories/GHSA-jrw4-wj52-2vw8","https://github.com/capstone-engine/capstone/blob/251c5bb4bc9bb92973e738ae3c5f4ef86f103356/ChangeLog#L102"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144518"],"patches":{"capstone":[]},"tags":{},"packages":[{"name":"capstone","source":"https://ubuntu.com/security/cve?package=capstone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=capstone","debian":"https://tracker.debian.org/pkg/capstone","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49263","published":"2026-08-14T18:17:00","updated_at":"2026-08-19T12:15:26.257354+00:00","description":"\nCapstone is a disassembly framework. Prior to version 6.0.0-Alpha9,\nCapstone's WebAssembly backend accepts attacker-controlled raw WASM\ninstruction bytes through the public `cs_disasm()` and `cs_disasm_iter()`\nAPIs. For a large but well-formed `br_table` instruction, the WASM decoder\naccumulates the immediate length in a wider local variable but returns it\nthrough a `uint16_t` instruction-size path. When the encoded instruction\nlength is exactly 65,536 bytes, the size wraps to zero and `cs_disasm()`\ncan repeatedly decode the same instruction without advancing. For larger\nlengths, `cs_disasm_iter()` advances into the middle of the `br_table`\npayload and decodes target bytes as subsequent instructions. This is an\navailability and parser-integrity issue. Version 6.0.0-Alpha9 patches the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49263","https://github.com/capstone-engine/capstone/security/advisories/GHSA-5m9f-vqcm-g5pr","https://github.com/capstone-engine/capstone/blob/251c5bb4bc9bb92973e738ae3c5f4ef86f103356/ChangeLog#L102"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144519"],"patches":{"capstone":[]},"tags":{},"packages":[{"name":"capstone","source":"https://ubuntu.com/security/cve?package=capstone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=capstone","debian":"https://tracker.debian.org/pkg/capstone","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47766","published":"2026-08-14T17:18:00","updated_at":"2026-08-19T12:15:02.271537+00:00","description":"\ncrun is an open source OCI Container Runtime fully written in C. Prior to\nversion 1.28, crun's default device setup opens the container rootfs `/dev`\ndirectory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a\nsymlink and the bundle configuration does not mount `/dev`, crun follows\nthat symlink and creates the default device nodes and stdio symlinks at the\nsymlink target outside the container rootfs. In a local rootful crun\nreplay, this created fixed device nodes and symlinks outside the rootfs\nbefore crun returned failure. A pre-existing file named `ptmx` in the\ntarget directory was also replaced by crun's forced `ptmx -> pts/ptmx`\nsymlink. Version 1.28 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47766","https://github.com/containers/crun/security/advisories/GHSA-7vwr-4279-7gq5","https://github.com/containers/crun/commit/c6f338ac2e26e216ab7820b91863a0b84e608097 (1.28)"],"bugs":[""],"patches":{"crun":[]},"tags":{},"packages":[{"name":"crun","source":"https://ubuntu.com/security/cve?package=crun","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=crun","debian":"https://tracker.debian.org/pkg/crun","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.28-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47192","published":"2026-08-14T17:18:00","updated_at":"2026-08-19T12:16:31.390112+00:00","description":"\nkas is a setup tool for bitbake based projects. Starting in version 4.8 and\nprior to version 5.3, kas checks out and processes repositories regarding\nconfiguration includes prior to validating signatures of those\nrepositories. This may allow to replace on original repository with one\nunder the control of an attacker under very specific conditions. First of\nall, the attacker must have gained control of a repository that a kas file\nof the victim is referencing. Furthermore, the following conditions must be\nfulfilled: the victim's kas configuration must include a configuration file\nfrom the attacked repository; the repository state is referenced by tag,\nand no commit ID is specified (this is triggering a warning, though); the\nkey used for validating the tag or commit signature is stored as file in a\nrepository; no fingerprint for the key is specified; and the `_source_dir`\nkey must not be set by the victim when calling kas (e.g. by avoiding a\nlocal `.config.yaml`). Given these conditions, the attacker could modify\nthe included kas configuration in way that the key used to validate the tag\nsignature of the attacker's repository could be replaced by an\nattacker-chosen key. No other exploit possibilities have been identified so\nfar, but this does not rule out that those may exist. All patches have been\nreleased along with kas version 5.3. As a workaround, pin the expected\nsignature key via its fingerprint, also when storing it as file in a\nrepository.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47192","https://github.com/siemens/kas/security/advisories/GHSA-4vqc-wpwg-vh7j","https://github.com/siemens/kas/commit/5b2114becfc154b16ef496d24f8c2191a2297f57 (5.3)"],"bugs":[""],"patches":{"kas":[]},"tags":{},"packages":[{"name":"kas","source":"https://ubuntu.com/security/cve?package=kas","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kas","debian":"https://tracker.debian.org/pkg/kas","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47191","published":"2026-08-14T17:18:00","updated_at":"2026-08-19T12:13:52.080216+00:00","description":"\nkas is a setup tool for bitbake based projects. Prior to version 5.3, when\nrelying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a\ncheckout of a repository is equivalent to the state validated while adding\nits commit ID to a kas configuration, users may be tricked to check out a\nbranch of the same name from this repository. This implies that the\nreferenced repository has been taken over by an attacker and modified to\ncarry such a branch. SHA-1 commits may also be replaced by creating hash\ncollisions, so the primary impact of this issue is on SHA-256 commit IDs.\nVersion 5.3 fixes the issue. As a workaround, avoid relying solely on the\ncommit ID for integrity validation of a repository that might become under\ncontrol of a malicious 3rd party. If available, additional validate\ncryptographically signed commits or tags. Alternatively, mirror the\nrepository to a save place, validate its integrity, and use this instead of\nthe original one.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47191","https://github.com/siemens/kas/security/advisories/GHSA-qjwp-hrq6-r26r","https://github.com/siemens/kas/commit/4cb4a3d01122ffaec9feaae768a5814092f6f9b5 (5.3)"],"bugs":[""],"patches":{"kas":[]},"tags":{},"packages":[{"name":"kas","source":"https://ubuntu.com/security/cve?package=kas","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kas","debian":"https://tracker.debian.org/pkg/kas","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46603","published":"2026-08-14T17:18:00","updated_at":"2026-08-19T12:16:54.382175+00:00","description":"\nVP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount\nof memory when processing a crafted VP8L image containing many unused\nHuffman tree groups. This allows a remote attacker to cause a denial of\nservice via memory exhaustion.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46603","https://github.com/golang/go/issues/80069","https://go.dev/cl/793460","https://go.dev/issue/80069","https://pkg.go.dev/vuln/GO-2026-6222"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144496"],"patches":{"golang-golang-x-image":[]},"tags":{},"packages":[{"name":"golang-golang-x-image","source":"https://ubuntu.com/security/cve?package=golang-golang-x-image","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-golang-x-image","debian":"https://tracker.debian.org/pkg/golang-golang-x-image","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-13002","published":"2026-08-14T16:16:00","updated_at":"2026-09-18T18:33:50.346117+00:00","description":"\nA flow has been identified into dnssec.c library, causing an infinite loop\nto dnsmasq service. An attacker who controls any DNSSEC-signed zone can\nhang the dnsmasq process with a single crafted response, killing all DNS\nresolution for its clients.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"as of 2026-09-18, the only information about this issue is the\nRed Hat bug, there are no details on a fix"}],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-13002","https://access.redhat.com/security/cve/CVE-2026-13002"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=2486360"],"patches":{"dnsmasq":[]},"tags":{},"packages":[{"name":"dnsmasq","source":"https://ubuntu.com/security/cve?package=dnsmasq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dnsmasq","debian":"https://tracker.debian.org/pkg/dnsmasq","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-09-18","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-09-18","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2026-09-18","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2026-09-18","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2026-09-18","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2026-09-18","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2026-09-18","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-19880","published":"2026-08-14T15:17:00","updated_at":"2026-09-16T10:39:57.993148+00:00","description":"\nPath-traversal vulnerability in QOS.CH Sarl Logback-classic on Java\n(logback-classic module) allows path-traversal vulnerability. More\nspecifically, an\nMDC-based discriminator value flows unsanitized into a nested\nFileAppender path, letting an attacker who influences that MDC value\n(e.g. via an HTTP header)\n create and append log files outside the intended directory.\nThis issue affects Logback-classic: from 0.9.14 through 1.6.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-19880","https://logback.qos.ch/news.html#1.6.3"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146719"],"patches":{"logback":[]},"tags":{},"packages":[{"name":"logback","source":"https://ubuntu.com/security/cve?package=logback","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=logback","debian":"https://tracker.debian.org/pkg/logback","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.6.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-19879","published":"2026-08-14T15:17:00","updated_at":"2026-08-19T12:14:13.550609+00:00","description":"\nA flaw was found in Undertow, an HTTP server, within its HTTP response\nheader writing path. The `writeString()` method performs a silent narrowing\ncast from 16-bit Unicode characters to 8-bit bytes when writing HTTP\nresponse header values. A remote attacker can exploit this by supplying\nspecific Unicode characters in user-controlled input that an application\nplaces into response headers. This can lead to the truncation of these\ncharacters into ASCII control characters or special symbols, potentially\nresulting in limited integrity impact or information disclosure if the\napplication does not properly sanitize user input.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-19879","https://bugzilla.redhat.com/show_bug.cgi?id=2516038","https://access.redhat.com/security/cve/CVE-2026-19879"],"bugs":[""],"patches":{"undertow":[]},"tags":{},"packages":[{"name":"undertow","source":"https://ubuntu.com/security/cve?package=undertow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=undertow","debian":"https://tracker.debian.org/pkg/undertow","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-73633","published":"2026-08-14T14:16:00","updated_at":"2026-08-19T14:35:54.830237+00:00","description":"\nUncontrolled resource consumption vulnerability in the JSON plugin of\nApache Struts. When an application is configured to populate actions from a\nJSON request body, the plugin reads that body into memory without bounding\nhow much it will accept, so a single request can exhaust the heap and deny\nservice to other users. The plugin's configurable JSON input length limit\ndoes not bound this read. The JSON plugin is an optional component;\napplications that do not use it, or use it without enabling JSON\nrequest-body handling, are not affected.\nThis issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0\nthrough 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.\nUsers are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes\nthe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-73633","https://cwiki.apache.org/confluence/display/WW/S2-072"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-73051","published":"2026-08-14T12:16:00","updated_at":"2026-08-19T12:42:42.172052+00:00","description":"\nactix-http versions before 3.12.1 contain an HTTP request smuggling\nvulnerability in the HTTP/1.1 parser that accepts requests with both\nContent-Length and Transfer-Encoding: chunked headers. Unauthenticated\nremote attackers can exploit this through a front-end intermediary to\ndesynchronize backend requests and smuggle malicious HTTP requests to the\nActix service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-73051","https://github.com/actix/actix-web/security/advisories/GHSA-xhj4-vrgc-hr34","https://www.vulncheck.com/advisories/actix-http-before-http-request-smuggling-via-cl-te"],"bugs":[""],"patches":{"rust-actix-http":[]},"tags":{},"packages":[{"name":"rust-actix-http","source":"https://ubuntu.com/security/cve?package=rust-actix-http","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-actix-http","debian":"https://tracker.debian.org/pkg/rust-actix-http","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-72817","published":"2026-08-14T12:16:00","updated_at":"2026-08-19T12:47:01.750995+00:00","description":"\ngo-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing\nvulnerability in the RealIP middleware, which resolves the request source\nIP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header\nwithout validating trusted proxies. A malicious client can prepend a forged\nIP as the first value of the X-Forwarded-For header to spoof the request\nsource IP, potentially bypassing access controls or falsifying request\nlogs.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-72817","https://github.com/go-chi/chi/security/advisories/GHSA-9g5q-2w5x-hmxf","https://www.vulncheck.com/advisories/go-chi-chi-before-ip-spoofing-via-x-forwarded-for"],"bugs":[""],"patches":{"golang-github-go-chi-chi":[]},"tags":{},"packages":[{"name":"golang-github-go-chi-chi","source":"https://ubuntu.com/security/cve?package=golang-github-go-chi-chi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-chi-chi","debian":"https://tracker.debian.org/pkg/golang-github-go-chi-chi","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-72816","published":"2026-08-14T12:16:00","updated_at":"2026-08-19T12:43:01.718136+00:00","description":"\ngo-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the\nRealIP middleware (middleware/realip.go). The realIP() function reads\nclient-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For)\nand overwrites r.RemoteAddr without verifying that the request originated\nfrom a trusted proxy. Attackers can supply arbitrary IP addresses in these\nheaders to bypass IP-based access controls, evade rate limiting and geo-IP\nrestrictions, and pollute audit logs. Fixed in 5.3.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-72816","https://github.com/go-chi/chi/security/advisories/GHSA-rjr7-jggh-pgcp","https://www.vulncheck.com/advisories/go-chi-chi-before-ip-spoofing-via-realip-middleware"],"bugs":[""],"patches":{"golang-github-go-chi-chi":[]},"tags":{},"packages":[{"name":"golang-github-go-chi-chi","source":"https://ubuntu.com/security/cve?package=golang-github-go-chi-chi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-chi-chi","debian":"https://tracker.debian.org/pkg/golang-github-go-chi-chi","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-72815","published":"2026-08-14T12:16:00","updated_at":"2026-08-19T12:43:01.718136+00:00","description":"\ngo-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing\nvulnerability in the RealIP middleware, which blindly trusts the first\n(leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can\nbypass IP-based access control lists and rate-limiting mechanisms, and\nforge log entries, by supplying a spoofed IP address in the X-Forwarded-For\nheader. The issue is fixed in version 5.3.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-72815","https://github.com/go-chi/chi/security/advisories/GHSA-3fxj-6jh8-hvhx","https://www.vulncheck.com/advisories/go-chi-chi-ip-spoofing-via-x-forwarded-for-header"],"bugs":[""],"patches":{"golang-github-go-chi-chi":[]},"tags":{},"packages":[{"name":"golang-github-go-chi-chi","source":"https://ubuntu.com/security/cve?package=golang-github-go-chi-chi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-chi-chi","debian":"https://tracker.debian.org/pkg/golang-github-go-chi-chi","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-72814","published":"2026-08-14T12:16:00","updated_at":"2026-08-19T12:47:10.491997+00:00","description":"\nThe actix-files crate (actix_files) before version 0.6.10 contains an\ninformation exposure vulnerability. When a non-existing folder is passed as\nthe serve_from argument to Files::new(), the mount path defaults to an\nempty path; the service then joins the request path with this empty path\nand canonicalizes it, causing Rust to resolve it as a relative path. As a\nresult, an attacker can request paths that resolve relative to the\napplication's working directory and access unintended files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-72814","https://github.com/actix/actix-web/security/advisories/GHSA-8v2v-wjwg-vx6r","https://www.vulncheck.com/advisories/actix-web-before-information-disclosure-via-files"],"bugs":[""],"patches":{"rust-actix-files":[]},"tags":{},"packages":[{"name":"rust-actix-files","source":"https://ubuntu.com/security/cve?package=rust-actix-files","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-actix-files","debian":"https://tracker.debian.org/pkg/rust-actix-files","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Fixed with initial upload to Debian","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":4580,"limit":20,"total_results":79316}