{"cves":[{"id":"CVE-2026-69247","published":"2026-08-03T22:16:00","updated_at":"2026-09-17T14:31:22.578429+00:00","description":"\ncryptography is a package designed to expose cryptographic primitives and\nrecipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der,\npkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of\ndecrypting a RecipientInfo's encryptedKey in several distinguishable ways,\none of which disclosed the exact length recovered from the RSA operation.\nThe same distinction was also observable by timing. An application that\ndecrypts attacker-supplied EnvelopedData and reflects the outcome gives the\nattacker a Bleichenbacher oracle against the content-encryption key.\nDecryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES\ncipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA\npadding, a valid padding with a bad key length, a correct length with a\nwrong key, and the real key each failed or succeeded differently. Case 1 is\nreachable only where the linked library lacks implicit rejection: OpenSSL\n3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that\nauto-decrypts untrusted EnvelopedData matching the victim certificate and\nanswers adaptively at high volume, such as an S/MIME gateway or mail\nfilter. This issue is fixed in 50.0.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69247","https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f","https://ubuntu.com/security/notices/USN-8776-1"],"bugs":[""],"patches":{"python-cryptography":["upstream: https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"]},"tags":{},"packages":[{"name":"python-cryptography","source":"https://ubuntu.com/security/cve?package=python-cryptography","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-cryptography","debian":"https://tracker.debian.org/pkg/python-cryptography","statuses":[{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50.0.0","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"46.0.5-1ubuntu2.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8776-1"],"notices":[{"id":"USN-8776-1","title":"python-cryptography vulnerabilities","summary":"Several security issues were fixed in python-cryptography.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-16T20:12:52.538784","description":"It was discovered that python-cryptography incorrectly accepted objects\nwith immutable buffers when performing certain cipher operations. This\nwould result in corrupted output, contrary to expectations. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2023-23931)\n\nIt was discovered that python-cryptography reported the outcome of\ndecrypting PKCS#7 enveloped data in distinguishable ways, and with\nobservable timing differences. A remote attacker could possibly use this\nissue to recover the key used to encrypt the message contents, and obtain\nsensitive information. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-69247)\n\nJack Lloyd discovered that python-cryptography incorrectly handled wildcard\nDNS names when enforcing the name constraints of a certificate authority. A\nremote attacker could possibly use this issue to have an invalid\ncertificate chain accepted, and use names outside of the permitted ones.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248)\n\nSamuel Judson discovered that python-cryptography incorrectly handled\ncertificate chains that contained duplicate certificates. A remote attacker\ncould possibly use this issue to cause python-cryptography to use excessive\nresources, leading to a denial of service. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-69249)","is_hidden":false,"release_packages":{"bionic":[{"name":"python-cryptography","version":"2.1.4-1ubuntu1.4+esm6","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography","version":"2.1.4-1ubuntu1.4+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python-cryptography-doc","version":"2.1.4-1ubuntu1.4+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python3-cryptography","version":"2.1.4-1ubuntu1.4+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"}],"resolute":[{"name":"python-cryptography","version":"46.0.5-1ubuntu2.2","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography-doc","version":"46.0.5-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/46.0.5-1ubuntu2.2","pocket":"security"},{"name":"python3-cryptography","version":"46.0.5-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/46.0.5-1ubuntu2.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-69249","CVE-2026-69247","CVE-2026-69248","CVE-2023-23931"]}]},{"id":"CVE-2026-69246","published":"2026-08-03T21:16:00","updated_at":"2026-08-07T17:49:12.521280+00:00","description":"\nGuzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle\ngives a transport the request URI as text and supplies the Host header\nseparately. The cURL handlers set CURLOPT_URL to the URI exactly as written\nand push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same\nthrough fopen(). libcurl then parses the authority itself, percent-decoding\nit and, on an IDN-capable build, applying IDNA mapping, and uses the result\nto resolve, connect, name the TLS peer and address a proxy CONNECT, while\nthe supplied Host suppresses the aligned one libcurl would have generated.\nFor a URI host written as 127.0.0.%31, filter_var() rejects the host as an\nIP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with\nno DNS lookup while the server receives Host: 127.0.0.%31. An attacker who\ninfluences a fetched URI can therefore reach a host the application's\nchecks excluded and read whatever the host exposes of the response. The\nsame divergence moves Guzzle's own decisions onto a spelling the transport\ndoes not use: no_proxy selects proxy routing from the literal host, and\nRedirectMiddleware decides from it whether to strip Authorization and\nCookie. Exploitation requires the application to build a request URI from\nuntrusted input and to make a host decision before handing it to Guzzle.\nThis issue is fixed in versions 7.15.2 and 8.0.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69246","https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"bugs":[""],"patches":{"guzzle":[]},"tags":{},"packages":[{"name":"guzzle","source":"https://ubuntu.com/security/cve?package=guzzle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=guzzle","debian":"https://tracker.debian.org/pkg/guzzle","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69245","published":"2026-08-03T21:16:00","updated_at":"2026-08-07T17:49:56.954107+00:00","description":"\nGuzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1,\nSetCookie::matchesDomain() gives every subdomain of a cookie Domain that\ncookie unless SetCookie::matchesDomain() recognizes the Domain as an IP\nliteral or a numeric host, and the decision comes from the domain's own\ntext, so two spellings a transport reads as an address keep subdomain\nscope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1\ngo unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A\npercent-escaped Domain keeps that scope on both branches because\npercent-decoding sits above numeric parsing, so 192.168.0.%31 and\n127.0.0.1%2e are registered names in the URI grammar rather than address\nliterals, and no numeric rule in any base classifies them, while libcurl\ndecodes the host before resolving and reads them as 192.168.0.1 and\n127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie\nheader of a request to evil.0x7f000001, disclosing a session identifier or\ntoken to a host that is not that address, and a response from\nevil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and\nreplayed to the address, so a server answering for the look-alike name can\nfix a session or set application state. Exploitation requires the\napplication to enable cookie support, address an origin by one of these\nspellings, and contact a host whose name ends in that spelling. This issue\nis fixed in versions 7.15.2 and 8.0.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69245","https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"bugs":[""],"patches":{"guzzle":[]},"tags":{},"packages":[{"name":"guzzle","source":"https://ubuntu.com/security/cve?package=guzzle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=guzzle","debian":"https://tracker.debian.org/pkg/guzzle","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69244","published":"2026-08-03T21:16:00","updated_at":"2026-08-07T17:49:52.915123+00:00","description":"\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and\nPython. Prior to 3.14.3, an out-of-bounds heap read could occur in the C\nresponse parser while building an error message for a malformed response.\nAn attacker controlled server, or possibly an accidental response, could\ntrigger a DoS in the client. The vulnerable path was error message\nconstruction in aiohttp/_http_parser.pyx, where an llhttp error-position\npointer was used to build a snippet for malformed chunked responses and\nmalformed request or response bytes at the buffer end. This issue is fixed\nin version 3.14.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69244","https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273","https://github.com/aio-libs/aiohttp/pull/13223","https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d","https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3"],"bugs":[""],"patches":{"python-aiohttp":[]},"tags":{},"packages":[{"name":"python-aiohttp","source":"https://ubuntu.com/security/cve?package=python-aiohttp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-aiohttp","debian":"https://tracker.debian.org/pkg/python-aiohttp","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69243","published":"2026-08-03T21:16:00","updated_at":"2026-08-07T17:50:37.092604+00:00","description":"\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and\nPython. Prior to 3.14.2, the HTTP parsers were vulnerable to a request\nsmuggling attack relating to WebSocket upgrades. If using the server-side\ncomponent, an attacker may be able to execute a request smuggling\nvulnerability using an edge case in the WebSocket upgrade procedure. A\nWebSocket upgrade request with a body could cause the parser to switch\nprotocols before the complete request body was received, leaving trailing\nbytes to be handled as upgraded-protocol or pipelined data rather than\nnormal HTTP body data. This issue is fixed in version 3.14.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69243","https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v","https://github.com/aio-libs/aiohttp/pull/13017","https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98","https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2"],"bugs":[""],"patches":{"python-aiohttp":[]},"tags":{},"packages":[{"name":"python-aiohttp","source":"https://ubuntu.com/security/cve?package=python-aiohttp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-aiohttp","debian":"https://tracker.debian.org/pkg/python-aiohttp","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69198","published":"2026-08-03T20:17:00","updated_at":"2026-08-07T17:50:16.836037+00:00","description":"\nip-address is a library for parsing and manipulating IPv4 and IPv6\naddresses in JavaScript. From 10.1.1 until 10.2.2, every special-use\nclassification method is built on isInSubnet, which short-circuits to false\nwhenever the address's own subnet mask is shorter than the reference\nrange's mask. That mask comes verbatim from the CIDR suffix on the parsed\ninput, so appending a suffix such as /0 suppresses classification entirely:\nisLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(),\nisUnspecified(), isBroadcast(), isULA(), and getType() all report an\ninternal address as unremarkable, while correctForm() and address still\nreturn the real internal target. An application that builds a network\ntrust-boundary decision on these checks, for example a filter intended to\nblock Server-Side Request Forgery, or SSRF, may therefore treat an internal\ntarget as external and allow the request. The underlying bit comparison is\ncorrect, and mask(n) already returns the first n bits of the full parsed\naddress independently of subnetMask; the defect is solely that the\ncontainment guard sits in the classification path. This issue is fixed in\nversion 10.2.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69198","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh","https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d","https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2"],"bugs":[""],"patches":{"node-ip-address":[]},"tags":{},"packages":[{"name":"node-ip-address","source":"https://ubuntu.com/security/cve?package=node-ip-address","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-ip-address","debian":"https://tracker.debian.org/pkg/node-ip-address","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.3.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69192","published":"2026-08-03T20:17:00","updated_at":"2026-08-07T17:49:56.954107+00:00","description":"\nip-address is a library for parsing and manipulating IPv4 and IPv6\naddresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written\nwith a leading zero and decodes it as decimal, while the WHATWG URL host\nparser, inet_aton, and getaddrinfo all decode a leading zero as octal. The\nlibrary and the network stack therefore disagree about which host a string\nnames. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and\nisPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1.\nAn application that builds a network trust-boundary decision on these\nchecks, for example a filter intended to block Server-Side Request Forgery,\nor SSRF, will classify an internal target as external and allow the\nrequest. The defect is in the parse gate rather than in any one classifier,\nso every consumer of Address4 inherits it: isPrivate(), isLoopback(),\nisLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm()\nare all computed from the mis-decoded octets. This issue is fixed in\nversion 10.3.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69192","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr","https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e","https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1"],"bugs":[""],"patches":{"node-ip-address":[]},"tags":{},"packages":[{"name":"node-ip-address","source":"https://ubuntu.com/security/cve?package=node-ip-address","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-ip-address","debian":"https://tracker.debian.org/pkg/node-ip-address","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.3.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69185","published":"2026-08-03T20:17:00","updated_at":"2026-08-07T17:49:52.915123+00:00","description":"\nSocket.IO enables bidirectional and low-latency communication for every\nplatform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO\npacket can make the server wait for a large number of binary attachments\nand buffer them, which can be exploited to make the server run out of\nmemory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69185","https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr","https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4","https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240","https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291"],"bugs":[""],"patches":{"node-socket.io-parser":[]},"tags":{},"packages":[{"name":"node-socket.io-parser","source":"https://ubuntu.com/security/cve?package=node-socket.io-parser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-socket.io-parser","debian":"https://tracker.debian.org/pkg/node-socket.io-parser","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69153","published":"2026-08-03T17:16:00","updated_at":"2026-08-07T17:50:41.615790+00:00","description":"\nPostCSS takes a CSS file and provides an API to analyze and modify its\nrules by transforming the rules into an Abstract Syntax Tree. Prior to\n8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to\nread an unintended source-map file by supplying an absolute or\ndirectory-traversal sourceMappingURL. The resulting map’s sources and\nsourcesContent may then be exposed to the application. This issue is fixed\nin version 8.5.19.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69153","https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp","https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8","https://github.com/postcss/postcss/releases/tag/8.5.19"],"bugs":[""],"patches":{"node-postcss":[]},"tags":{},"packages":[{"name":"node-postcss","source":"https://ubuntu.com/security/cve?package=node-postcss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-postcss","debian":"https://tracker.debian.org/pkg/node-postcss","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.5.23+~cs10.2.23-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69152","published":"2026-08-03T17:16:00","updated_at":"2026-08-07T17:50:01.760095+00:00","description":"\nThe brace-expansion library generates arbitrary strings containing a common\nprefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does\nnot apply maxLength while constructing comma-alternative intermediate\narrays or padded sequences, allowing attacker-controlled input to exhaust\nmemory or block the event loop. The fix for CVE-2026-14257 is bypassed by\nthe vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6,\nand 5.0.9.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69152","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf (v5.0.9)","https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d (v3.0.3)","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac (v2.1.4)","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031 (v1.1.17)","https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"],"bugs":[""],"patches":{"node-brace-expansion":[]},"tags":{},"packages":[{"name":"node-brace-expansion","source":"https://ubuntu.com/security/cve?package=node-brace-expansion","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-brace-expansion","debian":"https://tracker.debian.org/pkg/node-brace-expansion","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Incomplete fix for CVE-2026-14257 not applied","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69151","published":"2026-08-03T17:16:00","updated_at":"2026-08-14T18:45:15.675832+00:00","description":"\nAngular is a development platform for building mobile and desktop web\napplications using TypeScript/JavaScript and other languages. Prior to\n20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits\ni18n-onerror and other i18n-on event-handler attributes, allowing a\nlower-trust translation file to replace a static handler with executable\nJavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-69151","https://github.com/angular/angular/commit/417a4071a776464d549509ed3aec121dbd2fda5e","https://github.com/angular/angular/commit/6c41f5ca01c0ae045fc7d929b72853a11eb55865","https://github.com/angular/angular/pull/68821","https://github.com/angular/angular/pull/69306","https://github.com/angular/angular/security/advisories/GHSA-jj27-h5hq-8x99"],"bugs":[""],"patches":{"angular.js":[]},"tags":{},"packages":[{"name":"angular.js","source":"https://ubuntu.com/security/cve?package=angular.js","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=angular.js","debian":"https://tracker.debian.org/pkg/angular.js","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-69149","published":"2026-08-03T17:16:00","updated_at":"2026-08-14T18:45:04.177437+00:00","description":"\nAngular is a development platform for building mobile and desktop web\napplications using TypeScript/JavaScript and other languages. Prior to\n20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability\nexists in @angular/platform-server's DOM emulation dependency (domino) when\nserializing the content of fallback raw-content elements (