{"cves":[{"id":"CVE-2026-54465","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T17:32:20.563431+00:00","description":"\nwebsocket-driver is a WebSocket protocol handler with pluggable I/O. Prior\nto 0.8.1, when websocket-driver is used to implement a WebSocket server on\ntop of a TCP server using WebSocket::Driver.server() or to complement a\nWebSocket client, a peer can make a single connection consume an unbounded\namount of memory by sending an HTTP request or response with a never-ending\nlist of headers. This can lead to the receiving process running out of\nmemory. This issue is fixed in version 0.8.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54465","https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-8j3g-f24p-4mpw"],"bugs":[""],"patches":{"ruby-websocket-driver":[]},"tags":{},"packages":[{"name":"ruby-websocket-driver","source":"https://ubuntu.com/security/cve?package=ruby-websocket-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-websocket-driver","debian":"https://tracker.debian.org/pkg/ruby-websocket-driver","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54464","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:38:31.895693+00:00","description":"\n### Impact\nIf this library is used in tandem with the `permessage-deflate` extension,\na\nWebSocket server or client can be made to accept messages that are larger\nthan\nthe configured maximum message size. This is because this limit is checked\nagainst the message frames' length headers, which give the size of the\ncompressed data, not the size after decompression. This can lead to\napplications\naccepting larger messages than expected and exceeding their intended\nresource\nusage.\n### Patches\nThe issue has been patched in version 0.8.1, by checking the length of\nmessages\nafter they are processed by incoming extensions. All users should upgrade\nto\nthis version.\n### Workarounds\nNo known workarounds exist.\n### Acknowledgements\nThis issue was discovered and reported by Pranjali Thakur, DepthFirst\nSecurity\nResearch Team.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54464","https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-33ph-fccm-39pj"],"bugs":[""],"patches":{"ruby-websocket-driver":[]},"tags":{},"packages":[{"name":"ruby-websocket-driver","source":"https://ubuntu.com/security/cve?package=ruby-websocket-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-websocket-driver","debian":"https://tracker.debian.org/pkg/ruby-websocket-driver","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54463","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T17:31:14.236728+00:00","description":"\nwebsocket-driver is a WebSocket protocol handler with pluggable I/O. Prior\nto 0.8.1, draft versions of the WebSocket protocol in websocket-driver\ninclude a length header that allows an arbitrarily large integer to be\nencoded as bytes with the high bit set, and a server or client can send an\nindefinite sequence of 0x80 or higher bytes that the peer parses into an\never-growing Ruby integer. This can make a WebSocket connection consume an\nunbounded amount of memory and lead to the host process running out of\nmemory. This issue is fixed in version 0.8.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54463","https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p"],"bugs":[""],"patches":{"ruby-websocket-driver":[]},"tags":{},"packages":[{"name":"ruby-websocket-driver","source":"https://ubuntu.com/security/cve?package=ruby-websocket-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-websocket-driver","debian":"https://tracker.debian.org/pkg/ruby-websocket-driver","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54171","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:38:31.895693+00:00","description":"\nExcon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's\nRedirectFollower middleware failed to strip additional sensitive headers\nwhen following redirects and did not provide a custom list of headers to\nstrip. This could cause inadvertent leakage of sensitive data when the\ninitial request includes header information that is not intended for the\nnew target. This issue is fixed in version 1.5.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54171","https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r","https://github.com/excon/excon/pull/901"],"bugs":[""],"patches":{"ruby-excon":[]},"tags":{},"packages":[{"name":"ruby-excon","source":"https://ubuntu.com/security/cve?package=ruby-excon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-excon","debian":"https://tracker.debian.org/pkg/ruby-excon","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50289","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:37:15.905271+00:00","description":"\nsysteminformation is a System and OS information library for node.js. Prior\nto 5.31.7, networkInterfaces() on Linux is vulnerable to OS command\ninjection through the Debian/Ubuntu interfaces(5) source directive because\nlib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces,\nextracts a source token from file content, and interpolates it\nunquoted into cat ${file} 2> /dev/null | grep 'iface\\|source' executed by\nexecSync(cmd, util.execOptsLinux), allowing a path containing shell\nmetacharacters to execute commands in any process that calls\nnetworkInterfaces(), including via getStaticData() and getAllData(). This\nissue is fixed in version 5.31.7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50289","https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-5xpp-75jx-m839"],"bugs":[""],"patches":{"node-systeminformation":[]},"tags":{},"packages":[{"name":"node-systeminformation","source":"https://ubuntu.com/security/cve?package=node-systeminformation","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-systeminformation","debian":"https://tracker.debian.org/pkg/node-systeminformation","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.31.7-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50163","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:36:50.902693+00:00","description":"\noras-go is a Go library for managing OCI artifacts. Prior to 2.6.2,\nensureLinkPath in content/file/utils.go:262-275 validates a hardlink target\nrelative to the extract base but returns the unresolved target, causing\nos.Link(\"victim.secret\", \"/payload.tar.gz/evil_cwd_link\") to\nresolve header.Linkname against the process current working directory for a\nTypeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and\nLinkname=\"victim.secret\" with io.deis.oras.content.unpack: \"true\", which\ncan expose or tamper with files such as .env, .git/config,\n.aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50163","https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp","https://github.com/oras-project/oras-go/pull/1232"],"bugs":[""],"patches":{"golang-oras-oras-go":[]},"tags":{},"packages":[{"name":"golang-oras-oras-go","source":"https://ubuntu.com/security/cve?package=golang-oras-oras-go","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-oras-oras-go","debian":"https://tracker.debian.org/pkg/golang-oras-oras-go","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50162","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:36:50.902693+00:00","description":"\noras-go is a Go library for managing OCI artifacts. Prior to 2.6.1,\nresolveWritePath() in content/file/file.go uses a lexical filepath.Rel\ncheck for workingDir and does not account for symlink traversal, so when\nAllowPathTraversalOnWrite=false an attacker-controlled blob title through\nocispec.AnnotationTitle such as out/pwn.txt can follow a workingDir symlink\nout -> /some/outside/dir and cause pushFile() to create\n/some/outside/dir/pwn.txt outside workingDir. This issue is fixed in\nversion 2.6.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50162","https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv"],"bugs":[""],"patches":{"golang-oras-oras-go":[]},"tags":{},"packages":[{"name":"golang-oras-oras-go","source":"https://ubuntu.com/security/cve?package=golang-oras-oras-go","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-oras-oras-go","debian":"https://tracker.debian.org/pkg/golang-oras-oras-go","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50151","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:36:50.902693+00:00","description":"\noras-go is a Go library for managing OCI artifacts. Prior to 2.6.1,\nregistry/remote/repository.go in blobStore.completePushAfterInitialPost\nfollows a registry-controlled Location header during monolithic blob upload\nand reuses the Authorization header from the initial POST request for the\nsubsequent PUT request, allowing a malicious registry to return a\ncross-host Location and receive the caller's credentials at an\nattacker-controlled endpoint. This issue is fixed in version 2.6.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50151","https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7","https://github.com/oras-project/oras-go/pull/1152"],"bugs":[""],"patches":{"golang-oras-oras-go":[]},"tags":{},"packages":[{"name":"golang-oras-oras-go","source":"https://ubuntu.com/security/cve?package=golang-oras-oras-go","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-oras-oras-go","debian":"https://tracker.debian.org/pkg/golang-oras-oras-go","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49852","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:36:45.658132+00:00","description":"\njoserfc is a Python library that provides an implementation of several JSON\nObject Signing and Encryption (JOSE) standards. Prior to 1.6.8,\njoserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the\ncaller-supplied verification key is the empty string or None, because\nHMACAlgorithm.sign and HMACAlgorithm.verify in\nsrc/joserfc/_rfc7518/jws_algs.py pass the output of OctKey.get_op_key(...)\nto hmac.new(...) and OctKey.import_key in src/joserfc/_rfc7518/oct_key.py\nonly emits a SecurityWarning for keys shorter than 14 bytes without\nrejecting zero-length input. This issue is fixed in version 1.6.8.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49852","https://github.com/authlib/joserfc/security/advisories/GHSA-gg9x-qcx2-xmrh"],"bugs":[""],"patches":{"joserfc":[]},"tags":{},"packages":[{"name":"joserfc","source":"https://ubuntu.com/security/cve?package=joserfc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=joserfc","debian":"https://tracker.debian.org/pkg/joserfc","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.8-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49834","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:37:15.905271+00:00","description":"\nsigstore-go is a Go library for Sigstore signing and verification. Prior to\n1.2.0, a verifier configured with WithTransparencyLog(N>1) or\nWithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or\nper validation path rather than per log authority, allowing a single\ncompromised transparency log or CT log to satisfy multi-log threshold\nrequirements and defeat the multi-log policy. This issue is fixed in\nversion 1.2.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49834","https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6","https://github.com/sigstore/sigstore-go/pull/633"],"bugs":[""],"patches":{"sigstore-go":[]},"tags":{},"packages":[{"name":"sigstore-go","source":"https://ubuntu.com/security/cve?package=sigstore-go","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sigstore-go","debian":"https://tracker.debian.org/pkg/sigstore-go","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49284","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:36:45.658132+00:00","description":"\nSimpleSAMLphp versions before 1.18.6 contain an information disclosure\nvulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path\ndoes not enforce the IdP selected for an SP-initiated login when unsigned\nResponse/InResponseTo is combined with a signed assertion lacking\nSubjectConfirmationData/InResponseTo, allowing a response issued by one\ntrusted IdP to be bound to SP state created for another IdP and bypass\nflows that route users to a specific IdP, including deployments that set\nenable_unsolicited to false. This issue is fixed in versions 2.4.7 and\n2.5.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49284","https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm"],"bugs":[""],"patches":{"simplesamlphp":[]},"tags":{},"packages":[{"name":"simplesamlphp","source":"https://ubuntu.com/security/cve?package=simplesamlphp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=simplesamlphp","debian":"https://tracker.debian.org/pkg/simplesamlphp","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48978","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:37:00.017200+00:00","description":"\noras-go is a Go library for managing OCI artifacts. Prior to 2.6.1,\nauth.Client follows the realm URL from a registry's WWW-Authenticate:\nBearer challenge without validating the scheme or host, allowing a\nmalicious or compromised registry to cause SSRF to internal networks such\nas http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to\ndowngrade a registry contacted over https:// to an http:// token endpoint\nin registry/remote/auth/client.go through Client.Do(),\nClient.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token.\nThis issue is fixed in version 2.6.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48978","https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w"],"bugs":[""],"patches":{"golang-oras-oras-go":[]},"tags":{},"packages":[{"name":"golang-oras-oras-go","source":"https://ubuntu.com/security/cve?package=golang-oras-oras-go","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-oras-oras-go","debian":"https://tracker.debian.org/pkg/golang-oras-oras-go","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45799","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T05:36:31.054154+00:00","description":"\nWire provides gRPC and protocol buffers for Android, Kotlin, Swift, and\nJava. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup()\nand ProtoReader.skipGroup() in wire-runtime do not validate that a\nLENGTH_DELIMITED field length is non-negative before skip(), allowing a\ncrafted protobuf varint encoding -128 as a signed Int to make skip(-128)\nmove the internal position negative and make the next readByte() throw\nArrayIndexOutOfBoundsException instead of the documented IOException or\nProtocolException, which can crash services using\nProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in\nversions 6.3.0 and 7.0.0-alpha03.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45799"],"bugs":[""],"patches":{"grpc":[]},"tags":{},"packages":[{"name":"grpc","source":"https://ubuntu.com/security/cve?package=grpc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grpc","debian":"https://tracker.debian.org/pkg/grpc","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16118","published":"2026-07-17T20:17:00","updated_at":"2026-08-07T02:00:04.205433+00:00","description":"\nA flaw was found in xdgmime. A heap-based buffer overflow can be triggered\nin _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on\nlittle-endian systems when an attacker-controlled MIME magic file in a\nuser-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic\npath) is parsed by an application performing MIME type detection (e.g., via\ng_content_type_guess()). When performing byte-swap, incorrect pointer\narithmetic on the write side causes an out-of-bounds write of 2 bytes,\nresulting in an application crash or memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16118","https://gitlab.gnome.org/GNOME/glib/-/work_items/3992","https://bugzilla.redhat.com/show_bug.cgi?id=2501732","https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"],"bugs":[""],"patches":{"glib2.0":[]},"tags":{},"packages":[{"name":"glib2.0","source":"https://ubuntu.com/security/cve?package=glib2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glib2.0","debian":"https://tracker.debian.org/pkg/glib2.0","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.88.3-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50185","published":"2026-07-17T19:17:00","updated_at":"2026-08-25T08:57:04.869126+00:00","description":"\nRustCrypto CMOV provides conditional move CPU intrinsics which are\nguaranteed on major platforms to execute in constant-time and not be\nrewritten as branches by the compiler. From 0.1.1 until 0.5.4, the aarch64\nimplementations of Cmov and CmovEq in cmov/src/backends/aarch64.rs assume\nhigh bits are zero-extended when loading values smaller than a register, so\nset high bits such as [8..] in a Cmov selector or [16..] of self or other\nin the u16 and i16 CmovEq implementations can cause left.cmovz(&right,\ncondition) to produce incorrect output. This issue is fixed in version\n0.5.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50185","https://github.com/RustCrypto/utils/security/advisories/GHSA-3rjw-m598-pq24"],"bugs":[""],"patches":{"rust-cmov":[]},"tags":{},"packages":[{"name":"rust-cmov","source":"https://ubuntu.com/security/cve?package=rust-cmov","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-cmov","debian":"https://tracker.debian.org/pkg/rust-cmov","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.5.4-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49835","published":"2026-07-17T19:17:00","updated_at":"2026-08-07T05:37:15.905271+00:00","description":"\nSigstore Timestamp Authority is a service for issuing RFC 3161 timestamps.\nPrior to 2.1.0, the global wrapMetrics middleware records raw HTTP request\npath r.URL.Path and raw HTTP request method r.Method as Prometheus labels\nfor latency and request count metric vectors before routing, allowing an\nunauthenticated remote attacker to issue requests with random paths such as\n/api/v1/timestamp/ or random HTTP methods and create unbounded\npermanent time-series entries that exhaust memory. This issue is fixed in\nversion 2.1.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49835","https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-9c54-x2g4-v92j"],"bugs":[""],"patches":{"golang-github-sigstore-timestamp-authority":[]},"tags":{},"packages":[{"name":"golang-github-sigstore-timestamp-authority","source":"https://ubuntu.com/security/cve?package=golang-github-sigstore-timestamp-authority","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-sigstore-timestamp-authority","debian":"https://tracker.debian.org/pkg/golang-github-sigstore-timestamp-authority","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48487","published":"2026-07-17T19:17:00","updated_at":"2026-08-19T12:18:59.021825+00:00","description":"\nZeroconf is a pure Python implementation of multicast DNS service\ndiscovery. Prior to 0.149.16, _read_character_string and _read_string in\nsrc/zeroconf/_protocol/incoming.py advanced self.offset by\nattacker-declared RDLENGTH without checking it against self._data_len,\nallowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251\n/ ff02::fb) to send a TXT, HINFO, or A/AAAA record with rdlength=65535 and\nseed DNSCache and ServiceInfo.properties with truncated, attacker-shaped\nkey/value or address records. This issue is fixed in version 0.149.16.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48487","https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-qc2x-6f54-m6h9","https://github.com/python-zeroconf/python-zeroconf/issues/1752","https://github.com/python-zeroconf/python-zeroconf/pull/1756"],"bugs":[""],"patches":{"python-zeroconf":[]},"tags":{},"packages":[{"name":"python-zeroconf","source":"https://ubuntu.com/security/cve?package=python-zeroconf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-zeroconf","debian":"https://tracker.debian.org/pkg/python-zeroconf","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.149.16-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48045","published":"2026-07-17T19:17:00","updated_at":"2026-08-07T05:36:50.902693+00:00","description":"\nZeroconf is a pure Python implementation of multicast DNS service\ndiscovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained\nevery truncated TC-bit incoming query, each up to _MAX_MSG_ABSOLUTE = 8966\nbytes, in self._deferred[addr] and armed a per-address timer in\nself._timers[addr] without capping the per-address list or distinct addr\nkeys, allowing unauthenticated hosts on the local link over UDP/5353\n(224.0.0.251 / ff02::fb) to spoof sources, grow _deferred and _timers, and\ncause memory exhaustion and quadratic CPU burn. This issue is fixed in\nversion 0.149.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48045","https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-9663-mqmp-p9mm","https://github.com/python-zeroconf/python-zeroconf/pull/1751"],"bugs":[""],"patches":{"python-zeroconf":[]},"tags":{},"packages":[{"name":"python-zeroconf","source":"https://ubuntu.com/security/cve?package=python-zeroconf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-zeroconf","debian":"https://tracker.debian.org/pkg/python-zeroconf","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.149.16-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47184","published":"2026-07-17T19:17:00","updated_at":"2026-08-07T05:36:45.658132+00:00","description":"\nZeroconf is a pure Python implementation of multicast DNS service\ndiscovery. Prior to 0.149.7, DNSCache._async_add inserted every response\nrecord into cache, _expirations, _expire_heap, and service_cache without a\ncap, allowing unauthenticated hosts on the local link over UDP/5353\n(224.0.0.251 / ff02::fb) to multicast valid mDNS responses with unique\nnames and cause memory exhaustion, slower cache lookups, slower\nasync_expire passes, and broken discovery, registration, and ServiceBrowser\ncallbacks. This issue is fixed in version 0.149.7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47184","https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-rfg2-pjw2-56x2","https://github.com/python-zeroconf/python-zeroconf/issues/1715","https://github.com/python-zeroconf/python-zeroconf/pull/1718"],"bugs":[""],"patches":{"python-zeroconf":[]},"tags":{},"packages":[{"name":"python-zeroconf","source":"https://ubuntu.com/security/cve?package=python-zeroconf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-zeroconf","debian":"https://tracker.debian.org/pkg/python-zeroconf","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.149.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47183","published":"2026-07-17T19:17:00","updated_at":"2026-08-07T05:37:09.592117+00:00","description":"\nZeroconf is a pure Python implementation of multicast DNS service\ndiscovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four\nQuietLogger exception-dedup methods stored an unbounded _seen_logs\ndictionary keyed by attacker-influenced IncomingDecodeError messages,\nretaining sys.exc_info() tracebacks whose frame locals kept raw packet\nself.data buffers and allowing unauthenticated hosts on the local link over\nUDP/5353 (224.0.0.251 / ff02::fb) to drive memory growth until\nmDNS-dependent features degrade or the process is OOM-killed. This issue is\nfixed in version 0.149.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47183","https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-phvx-9mgw-67r5","https://github.com/python-zeroconf/python-zeroconf/issues/1714","https://github.com/python-zeroconf/python-zeroconf/pull/1717"],"bugs":[""],"patches":{"python-zeroconf":[]},"tags":{},"packages":[{"name":"python-zeroconf","source":"https://ubuntu.com/security/cve?package=python-zeroconf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-zeroconf","debian":"https://tracker.debian.org/pkg/python-zeroconf","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.149.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7520,"limit":20,"total_results":79316}