{"cves":[{"id":"CVE-2026-11770","published":"2026-07-31T10:16:00","updated_at":"2026-08-07T16:53:03.991522+00:00","description":"\nA flaw was found in 389 Directory Server. An unauthenticated remote\nattacker can inject LDAP search filters into the CleanAllRUV replication\nstatus-check extended operation. Because the handler performs the search\nagainst cn=config with elevated replication plugin privileges and returns a\nboolean match result, the attacker can extract sensitive server\nconfiguration metadata, including replication bind DNs and password storage\nscheme information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11770","https://bugzilla.redhat.com/show_bug.cgi?id=2484802","https://access.redhat.com/security/cve/CVE-2026-11770","https://github.com/389ds/389-ds-base/blob/main/ldap/servers/plugins/replication/repl_extop.c"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143455"],"patches":{"389-ds-base":[]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63223","published":"2026-07-31T06:16:00","updated_at":"2026-08-07T17:33:54.384488+00:00","description":"\nCodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image\nand mime_in upload validation rules do not independently enforce a safe\nclient filename extension, allowing a remote attacker to upload executable\ncontent when an application preserves the client filename and stores\nuploads in a web-accessible script-enabled directory. Applications are\nimpacted when they validate uploads using is_image or mime_in without an\nindependent safe extension check (such as ext_in on patched versions), save\nuploaded files using the client-supplied filename, and place uploads in a\nweb-accessible directory where PHP files can execute. This issue is fixed\nin version 4.7.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63223"],"bugs":[""],"patches":{"php-codeigniter-framework":[]},"tags":{},"packages":[{"name":"php-codeigniter-framework","source":"https://ubuntu.com/security/cve?package=php-codeigniter-framework","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-codeigniter-framework","debian":"https://tracker.debian.org/pkg/php-codeigniter-framework","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63222","published":"2026-07-31T06:16:00","updated_at":"2026-08-07T17:33:09.764777+00:00","description":"\nCodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling\nUploadedFile::move() without a second argument uses the client-provided\nfilename without sanitization, allowing a remote attacker to use path\ntraversal sequences to write uploaded content outside the intended\ndirectory when the application exposes an upload path. This issue is fixed\nin version 4.7.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63222"],"bugs":[""],"patches":{"php-codeigniter-framework":[]},"tags":{},"packages":[{"name":"php-codeigniter-framework","source":"https://ubuntu.com/security/cve?package=php-codeigniter-framework","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-codeigniter-framework","debian":"https://tracker.debian.org/pkg/php-codeigniter-framework","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63221","published":"2026-07-31T06:16:00","updated_at":"2026-08-07T17:34:08.819974+00:00","description":"\nCodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3,\nQuery Builder deleteBatch() substitutes bound values from where()\nconditions into generated SQL while ignoring their escape flags, allowing\nuser-controlled condition values to be interpreted as SQL. This affects\nonly the deleteBatch() code path. Regular delete() operations escape\nwhere() binds correctly. This issue is fixed in version 4.7.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63221"],"bugs":[""],"patches":{"php-codeigniter-framework":[]},"tags":{},"packages":[{"name":"php-codeigniter-framework","source":"https://ubuntu.com/security/cve?package=php-codeigniter-framework","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-codeigniter-framework","debian":"https://tracker.debian.org/pkg/php-codeigniter-framework","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63220","published":"2026-07-31T04:17:00","updated_at":"2026-08-07T17:34:29.346054+00:00","description":"\nCodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4,\nIncomingRequest::isSecure() trusted the X-Forwarded-Proto and\nFront-End-Https headers from any incoming request, allowing an attacker\ncould spoof these headers and cause the application to incorrectly treat an\nHTTP request as secure. This may have impacted applications that rely on\nisSecure(), force_https(), forceGlobalSecureRequests, or similar logic to\nenforce HTTPS-only access or make security-sensitive decisions.\nExploitability depends on deployment configuration. Applications are most\nexposed if the backend is reachable directly over HTTP, or if a reverse\nproxy/load balancer forwards client-supplied forwarding headers without\nstripping or overwriting them. This issue has been fixed in version 4.7.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63220"],"bugs":[""],"patches":{"php-codeigniter-framework":[]},"tags":{},"packages":[{"name":"php-codeigniter-framework","source":"https://ubuntu.com/security/cve?package=php-codeigniter-framework","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-codeigniter-framework","debian":"https://tracker.debian.org/pkg/php-codeigniter-framework","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58039","published":"2026-07-31T01:16:00","updated_at":"2026-08-07T17:33:49.737554+00:00","description":"\nA flaw in Node.js Permission Model enforcement allows process.report writes\n(and overwrites) files outside --allow-fs-write paths.\nThis can lead to confidentiality impact or bypass of the intended security\nboundary under affected configurations.\nThis vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58039","https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-process-reports-to-write-outside-the-allowlist-cve-2026-58039---low"],"bugs":[""],"patches":{"nodejs":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9672","published":"2026-07-31T00:00:00","updated_at":"2026-08-07T17:50:01.760095+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"php uses the system libgd2"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9672"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143152"],"patches":{"libgd2":[],"php5":[],"php7.0":[],"php7.2":[]},"tags":{},"packages":[{"name":"libgd2","source":"https://ubuntu.com/security/cve?package=libgd2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgd2","debian":"https://tracker.debian.org/pkg/libgd2","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"uses system libgd2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system libgd2","component":null,"pocket":"security"}]},{"name":"php7.2","source":"https://ubuntu.com/security/cve?package=php7.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php7.2","debian":"https://tracker.debian.org/pkg/php7.2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-62268","published":"2026-07-31T00:00:00","updated_at":"2026-08-07T17:33:25.273529+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-62268"],"bugs":[""],"patches":{"borgbackup":[],"borgbackup2":[]},"tags":{},"packages":[{"name":"borgbackup","source":"https://ubuntu.com/security/cve?package=borgbackup","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=borgbackup","debian":"https://tracker.debian.org/pkg/borgbackup","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.5-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"borgbackup2","source":"https://ubuntu.com/security/cve?package=borgbackup2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=borgbackup2","debian":"https://tracker.debian.org/pkg/borgbackup2","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0b22-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53587","published":"2026-07-31T00:00:00","updated_at":"2026-09-02T21:05:28.156375+00:00","description":"\nlibgit2 is a portable C implementation of the Git core methods provided as\na linkable library with a solid API, allowing to build Git functionality\ninto your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a\nfixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c\nwithout first verifying that the smart-protocol pkt-line capability buffer\ncontains 14 bytes. A malicious Git server can make bytes after the pkt-line\ncomplete object-format=, causing format_str to advance beyond the pkt-line\nand the following memchr length calculation to underflow. The resulting\nheap out-of-bounds walk can crash a client during the first\nrefs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This\nissue is fixed in versions 1.8.6 and 1.9.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53587","https://github.com/libgit2/libgit2/security/advisories/GHSA-pm24-4jhq-3xvm","https://ubuntu.com/security/notices/USN-8628-1"],"bugs":[""],"patches":{"libgit2":["upstream: https://github.com/libgit2/libgit2/commit/d7a9fb87f504434e9f45228678953c4fa56e7640"]},"tags":{},"packages":[{"name":"libgit2","source":"https://ubuntu.com/security/cve?package=libgit2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgit2","debian":"https://tracker.debian.org/pkg/libgit2","statuses":[{"release_codename":"upstream","status":"released","description":"1.9.6+ds-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.7.2+ds-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.9.1+ds-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8628-1"],"notices":[{"id":"USN-8628-1","title":"libgit2 vulnerabilities","summary":"Several security issues were fixed in libgit2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-12T19:13:07.070731","description":"It was discovered that libgit2 incorrectly handled the Git Smart Protocol.\nA remote attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2016-10128)\n\nIt was discovered that libgit2 incorrectly handled empty packet lines in\nthe Git Smart Protocol. A remote attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2016-10129)\n\nIt was discovered that libgit2 incorrectly handled error reporting in the\nHTTP transport. A remote attacker could possibly use this issue to spoof\nservers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)\n\nIt was discovered that libgit2 incorrectly handled certain crafted \"ng\"\npackets. A remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nand Ubuntu 18.04 LTS. (CVE-2018-15501)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2018-8098)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled submodule paths. A remote attacker could possibly use\nthis issue to write files outside the working tree. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 26.04 LTS. (CVE-2026-53584)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled delta object result-size headers. A remote attacker\ncould possibly use this issue to cause libgit2 to consume excessive memory,\nleading to a denial of service. (CVE-2026-53585)\n\nThai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.\nA remote attacker could possibly use this issue to leak credentials to an\noffsite redirect target. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-53586)\n\nIt was discovered that libgit2 incorrectly handled certain capability\nbuffers in the smart protocol. A remote attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 24.04\nLTS and Ubuntu 26.04 LTS. (CVE-2026-53587)","is_hidden":false,"release_packages":{"bionic":[{"name":"libgit2","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-26","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libgit2","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-28","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libgit2","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.1","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-fixtures","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libgit2","version":"1.7.2+ds-1ubuntu3.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.7","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-dev","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"}],"resolute":[{"name":"libgit2","version":"1.9.1+ds-1ubuntu1.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.9","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-dev","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"libgit2","version":"0.19.0-2ubuntu0.4+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-0","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgit2-dev","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libgit2","version":"0.24.1-2ubuntu0.2+esm3","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-24","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libgit2-dev","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53587","CVE-2016-10129","CVE-2016-10128","CVE-2018-8099","CVE-2018-15501","CVE-2016-10130","CVE-2018-8098","CVE-2026-53584","CVE-2026-53586","CVE-2026-53585"]}]},{"id":"CVE-2026-53586","published":"2026-07-31T00:00:00","updated_at":"2026-09-02T21:05:34.820383+00:00","description":"\nlibgit2 is a portable C implementation of the Git core methods provided as\na linkable library with a solid API, allowing to build Git functionality\ninto your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP\ntransport in src/libgit2/transports/http.c follows an offsite initial\nredirect, and handle_remote_auth and handle_auth pass transport->owner->url\ninstead of transport->server.url to the credential callback when the\nredirected host returns 401 Unauthorized. A callback that scopes\ncredentials to the original trusted URL can therefore return\nGIT_CREDENTIAL_USERPASS_PLAINTEXT credentials that libgit2 stores in\ntransport->server.cred and sends as an Authorization header to the\nredirected host. An attacker who controls a trusted Git host or an open\nredirect on that host can disclose HTTP Basic credentials, personal access\ntokens, or equivalent credentials. This issue is fixed in versions 1.8.6\nand 1.9.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53586","https://github.com/libgit2/libgit2/security/advisories/GHSA-2889-x8f6-mc4x","https://ubuntu.com/security/notices/USN-8628-1"],"bugs":[""],"patches":{"libgit2":["upstream: https://github.com/libgit2/libgit2/commit/07de6a7e438f95ac9a6efd3222a82117e871ed27"]},"tags":{},"packages":[{"name":"libgit2","source":"https://ubuntu.com/security/cve?package=libgit2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgit2","debian":"https://tracker.debian.org/pkg/libgit2","statuses":[{"release_codename":"upstream","status":"released","description":"1.9.6+ds-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.28.4+dfsg.1-2ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1.7.2+ds-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.9.1+ds-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8628-1"],"notices":[{"id":"USN-8628-1","title":"libgit2 vulnerabilities","summary":"Several security issues were fixed in libgit2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-12T19:13:07.070731","description":"It was discovered that libgit2 incorrectly handled the Git Smart Protocol.\nA remote attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2016-10128)\n\nIt was discovered that libgit2 incorrectly handled empty packet lines in\nthe Git Smart Protocol. A remote attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2016-10129)\n\nIt was discovered that libgit2 incorrectly handled error reporting in the\nHTTP transport. A remote attacker could possibly use this issue to spoof\nservers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)\n\nIt was discovered that libgit2 incorrectly handled certain crafted \"ng\"\npackets. A remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nand Ubuntu 18.04 LTS. (CVE-2018-15501)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2018-8098)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled submodule paths. A remote attacker could possibly use\nthis issue to write files outside the working tree. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 26.04 LTS. (CVE-2026-53584)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled delta object result-size headers. A remote attacker\ncould possibly use this issue to cause libgit2 to consume excessive memory,\nleading to a denial of service. (CVE-2026-53585)\n\nThai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.\nA remote attacker could possibly use this issue to leak credentials to an\noffsite redirect target. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-53586)\n\nIt was discovered that libgit2 incorrectly handled certain capability\nbuffers in the smart protocol. A remote attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 24.04\nLTS and Ubuntu 26.04 LTS. (CVE-2026-53587)","is_hidden":false,"release_packages":{"bionic":[{"name":"libgit2","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-26","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libgit2","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-28","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libgit2","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.1","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-fixtures","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libgit2","version":"1.7.2+ds-1ubuntu3.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.7","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-dev","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"}],"resolute":[{"name":"libgit2","version":"1.9.1+ds-1ubuntu1.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.9","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-dev","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"libgit2","version":"0.19.0-2ubuntu0.4+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-0","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgit2-dev","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libgit2","version":"0.24.1-2ubuntu0.2+esm3","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-24","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libgit2-dev","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53587","CVE-2016-10129","CVE-2016-10128","CVE-2018-8099","CVE-2018-15501","CVE-2016-10130","CVE-2018-8098","CVE-2026-53584","CVE-2026-53586","CVE-2026-53585"]}]},{"id":"CVE-2026-53585","published":"2026-07-31T00:00:00","updated_at":"2026-09-02T21:06:00.000023+00:00","description":"\nlibgit2 is a portable C implementation of the Git core methods provided as\na linkable library with a solid API, allowing to build Git functionality\ninto your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in\nsrc/libgit2/delta.c trusts the attacker-controlled res_sz value parsed by\nhdr_sz from a delta object header and passes that amount to git__malloc\nbefore validating delta instructions. Malicious pack data supplied through\ngit_clone, git_fetch, git_remote_fetch, git_indexer_append, or a local\nattacker-supplied repository can use a very small multi-level OFS_DELTA\nchain to retain extremely large allocations and exhaust memory. This issue\nis fixed in versions 1.8.6 and 1.9.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53585","https://github.com/libgit2/libgit2/security/advisories/GHSA-27m5-gxxh-x79j","https://ubuntu.com/security/notices/USN-8628-1"],"bugs":[""],"patches":{"libgit2":["upstream: https://github.com/libgit2/libgit2/commit/0cdfdd5fa8f8514c82413025e1e0808866cf7c30"]},"tags":{},"packages":[{"name":"libgit2","source":"https://ubuntu.com/security/cve?package=libgit2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgit2","debian":"https://tracker.debian.org/pkg/libgit2","statuses":[{"release_codename":"upstream","status":"released","description":"1.9.6+ds-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.28.4+dfsg.1-2ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1.7.2+ds-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.9.1+ds-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.19.0-2ubuntu0.4+esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"0.24.1-2ubuntu0.2+esm3","component":null,"pocket":"esm-apps-legacy"}]}],"notices_ids":["USN-8628-1"],"notices":[{"id":"USN-8628-1","title":"libgit2 vulnerabilities","summary":"Several security issues were fixed in libgit2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-12T19:13:07.070731","description":"It was discovered that libgit2 incorrectly handled the Git Smart Protocol.\nA remote attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2016-10128)\n\nIt was discovered that libgit2 incorrectly handled empty packet lines in\nthe Git Smart Protocol. A remote attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2016-10129)\n\nIt was discovered that libgit2 incorrectly handled error reporting in the\nHTTP transport. A remote attacker could possibly use this issue to spoof\nservers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)\n\nIt was discovered that libgit2 incorrectly handled certain crafted \"ng\"\npackets. A remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nand Ubuntu 18.04 LTS. (CVE-2018-15501)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2018-8098)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled submodule paths. A remote attacker could possibly use\nthis issue to write files outside the working tree. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 26.04 LTS. (CVE-2026-53584)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled delta object result-size headers. A remote attacker\ncould possibly use this issue to cause libgit2 to consume excessive memory,\nleading to a denial of service. (CVE-2026-53585)\n\nThai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.\nA remote attacker could possibly use this issue to leak credentials to an\noffsite redirect target. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-53586)\n\nIt was discovered that libgit2 incorrectly handled certain capability\nbuffers in the smart protocol. A remote attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 24.04\nLTS and Ubuntu 26.04 LTS. (CVE-2026-53587)","is_hidden":false,"release_packages":{"bionic":[{"name":"libgit2","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-26","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libgit2","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-28","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libgit2","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.1","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-fixtures","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libgit2","version":"1.7.2+ds-1ubuntu3.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.7","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-dev","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"}],"resolute":[{"name":"libgit2","version":"1.9.1+ds-1ubuntu1.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.9","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-dev","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"libgit2","version":"0.19.0-2ubuntu0.4+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-0","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgit2-dev","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libgit2","version":"0.24.1-2ubuntu0.2+esm3","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-24","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libgit2-dev","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53587","CVE-2016-10129","CVE-2016-10128","CVE-2018-8099","CVE-2018-15501","CVE-2016-10130","CVE-2018-8098","CVE-2026-53584","CVE-2026-53586","CVE-2026-53585"]}]},{"id":"CVE-2026-53584","published":"2026-07-31T00:00:00","updated_at":"2026-09-02T21:04:39.102492+00:00","description":"\nlibgit2 is a portable C implementation of the Git core methods provided as\na linkable library with a solid API, allowing to build Git functionality\ninto your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject\ntraversal components in a submodule path loaded from .gitmodules. The\naffected src/libgit2/submodule.c paths include git_submodule_lookup and\ngit_submodule_add_setup. A crafted repository can specify a path such as\n../escape-target, and applications that initialize the submodule can create\ndirectories outside the repository working tree. This issue is fixed in\nversions 1.8.6 and 1.9.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53584","https://github.com/libgit2/libgit2/security/advisories/GHSA-cw77-j82w-mchm","https://ubuntu.com/security/notices/USN-8628-1"],"bugs":[""],"patches":{"libgit2":["upstream: https://github.com/libgit2/libgit2/commit/ec7371da9f359cd8293e9108e7a0b1c1b61b67c4"]},"tags":{},"packages":[{"name":"libgit2","source":"https://ubuntu.com/security/cve?package=libgit2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgit2","debian":"https://tracker.debian.org/pkg/libgit2","statuses":[{"release_codename":"upstream","status":"released","description":"1.9.6+ds-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.28.4+dfsg.1-2ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1.7.2+ds-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.9.1+ds-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"}]}],"notices_ids":["USN-8628-1"],"notices":[{"id":"USN-8628-1","title":"libgit2 vulnerabilities","summary":"Several security issues were fixed in libgit2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-12T19:13:07.070731","description":"It was discovered that libgit2 incorrectly handled the Git Smart Protocol.\nA remote attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2016-10128)\n\nIt was discovered that libgit2 incorrectly handled empty packet lines in\nthe Git Smart Protocol. A remote attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2016-10129)\n\nIt was discovered that libgit2 incorrectly handled error reporting in the\nHTTP transport. A remote attacker could possibly use this issue to spoof\nservers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)\n\nIt was discovered that libgit2 incorrectly handled certain crafted \"ng\"\npackets. A remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nand Ubuntu 18.04 LTS. (CVE-2018-15501)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2018-8098)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled submodule paths. A remote attacker could possibly use\nthis issue to write files outside the working tree. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 26.04 LTS. (CVE-2026-53584)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled delta object result-size headers. A remote attacker\ncould possibly use this issue to cause libgit2 to consume excessive memory,\nleading to a denial of service. (CVE-2026-53585)\n\nThai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.\nA remote attacker could possibly use this issue to leak credentials to an\noffsite redirect target. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-53586)\n\nIt was discovered that libgit2 incorrectly handled certain capability\nbuffers in the smart protocol. A remote attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 24.04\nLTS and Ubuntu 26.04 LTS. (CVE-2026-53587)","is_hidden":false,"release_packages":{"bionic":[{"name":"libgit2","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-26","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libgit2","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-28","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libgit2","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.1","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-fixtures","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libgit2","version":"1.7.2+ds-1ubuntu3.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.7","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-dev","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"}],"resolute":[{"name":"libgit2","version":"1.9.1+ds-1ubuntu1.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.9","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-dev","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"libgit2","version":"0.19.0-2ubuntu0.4+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-0","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgit2-dev","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libgit2","version":"0.24.1-2ubuntu0.2+esm3","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-24","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libgit2-dev","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53587","CVE-2016-10129","CVE-2016-10128","CVE-2018-8099","CVE-2018-15501","CVE-2016-10130","CVE-2018-8098","CVE-2026-53584","CVE-2026-53586","CVE-2026-53585"]}]},{"id":"CVE-2026-65423","published":"2026-07-30T23:16:00","updated_at":"2026-08-07T17:47:44.438158+00:00","description":"\nAn integer overflow in the UA_Variant arrayDimensions product\ncomputation in open62541 may allow a remote attacker to trigger an\nout-of-bounds write.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-65423"],"bugs":[""],"patches":{"open62541":[]},"tags":{},"packages":[{"name":"open62541","source":"https://ubuntu.com/security/cve?package=open62541","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=open62541","debian":"https://tracker.debian.org/pkg/open62541","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63362","published":"2026-07-30T23:16:00","updated_at":"2026-08-07T17:33:09.764777+00:00","description":"\nAn unsigned integer underflow in the PubSub signature verification path\nin open62541 may allow a remote attacker to cause a denial of service\nvia a crafted UDP packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63362"],"bugs":[""],"patches":{"open62541":[]},"tags":{},"packages":[{"name":"open62541","source":"https://ubuntu.com/security/cve?package=open62541","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=open62541","debian":"https://tracker.debian.org/pkg/open62541","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63035","published":"2026-07-30T23:16:00","updated_at":"2026-08-07T17:33:39.919062+00:00","description":"\nA heap use-after-free vulnerability in the TransferSubscriptions service\n in open62541 may allow an authenticated attacker to cause a denial of\nservice or potentially execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63035"],"bugs":[""],"patches":{"open62541":[]},"tags":{},"packages":[{"name":"open62541","source":"https://ubuntu.com/security/cve?package=open62541","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=open62541","debian":"https://tracker.debian.org/pkg/open62541","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63033","published":"2026-07-30T23:16:00","updated_at":"2026-08-07T17:34:29.346054+00:00","description":"\nA crafted IEC 60870-5-104 I-frame with a declared object count exceeding\n what fits in the ASDU body causes InformationObject_ParseObjectAddress\nto read one byte past the end of the heap-allocated message buffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63033"],"bugs":[""],"patches":{"lib60870":[]},"tags":{},"packages":[{"name":"lib60870","source":"https://ubuntu.com/security/cve?package=lib60870","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lib60870","debian":"https://tracker.debian.org/pkg/lib60870","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-61893","published":"2026-07-30T23:16:00","updated_at":"2026-08-07T17:34:35.751420+00:00","description":"\nA crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an\ninflated object count causes TestCommand_getFromBuffer to read one byte\npast the end of the heap-allocated message buffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-61893"],"bugs":[""],"patches":{"lib60870":[]},"tags":{},"packages":[{"name":"lib60870","source":"https://ubuntu.com/security/cve?package=lib60870","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lib60870","debian":"https://tracker.debian.org/pkg/lib60870","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63559","published":"2026-07-30T22:16:00","updated_at":"2026-08-07T17:34:08.819974+00:00","description":"\nAn integer overflow in the UA_Variant arrayDimensions product\ncomputation in open62541 may allow a remote attacker to read\nout-of-bounds heap memory, potentially disclosing sensitive information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63559"],"bugs":[""],"patches":{"open62541":[]},"tags":{},"packages":[{"name":"open62541","source":"https://ubuntu.com/security/cve?package=open62541","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=open62541","debian":"https://tracker.debian.org/pkg/open62541","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-68499","published":"2026-07-30T21:18:00","updated_at":"2026-08-07T17:49:34.774749+00:00","description":"\nre2 provides Node.js bindings for Google's RE2 regular expression engine.\nPrior to 1.25.2, re2's String.prototype.match implementation with a global\nRE2 pattern that can match the empty string fails to advance its native\nmatching cursor in lib/match.cc, causing an infinite loop and unbounded\nnative memory growth that blocks the event loop and can exhaust host\nmemory. This issue is fixed in 1.25.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-68499","https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836"],"bugs":[""],"patches":{"node-re2":[]},"tags":{},"packages":[{"name":"node-re2","source":"https://ubuntu.com/security/cve?package=node-re2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-re2","debian":"https://tracker.debian.org/pkg/node-re2","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55777","published":"2026-07-30T21:17:00","updated_at":"2026-08-07T17:31:02.357939+00:00","description":"\nGoAccess is a real-time web log analyzer and interactive viewer that runs\nin a terminal in *nix systems or through the browser. Prior to 1.11, the\nparse_ios() function uses an attacker-controlled keyword-to-OS offset as\nboth the source offset and copy length for memmove, allowing a crafted\nUser-Agent in a processed access log to read up to approximately 4 KB\nbeyond the heap allocation and conditionally crash GoAccess. This issue is\nfixed in version 1.11.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55777"],"bugs":[""],"patches":{"goaccess":[]},"tags":{},"packages":[{"name":"goaccess","source":"https://ubuntu.com/security/cve?package=goaccess","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=goaccess","debian":"https://tracker.debian.org/pkg/goaccess","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":5700,"limit":20,"total_results":79316}