{"cves":[{"id":"CVE-2026-44982","published":"2026-07-16T20:16:00","updated_at":"2026-08-07T14:02:26.727317+00:00","description":"\nCrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0\nuntil 1.7.8, pkg/appsec/request.go NewParsedRequestFromRequest allocated a\nrequest body buffer from max(r.ContentLength, 0), so HTTP/1.1 requests\nusing Transfer-Encoding: chunked and HTTP/2 requests without a\ncontent-length header produced an empty body and caused WAF rules targeting\nREQUEST_BODY, BODY_ARGS, ARGS_POST, JSON, or XML to be skipped. This issue\nis fixed in version 1.7.8.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44982","https://github.com/crowdsecurity/crowdsec/commit/3d5c4d9b127091e9063b9b5eb785372a599a4435","https://github.com/crowdsecurity/crowdsec/commit/57a793548671e6bbd2cde5562fe87b856ec9c642","https://github.com/crowdsecurity/crowdsec/pull/4355","https://github.com/crowdsecurity/crowdsec/releases/tag/v1.7.8","https://github.com/crowdsecurity/crowdsec/security/advisories/GHSA-rw47-hm26-6wr7"],"bugs":[""],"patches":{"crowdsec":[]},"tags":{},"packages":[{"name":"crowdsec","source":"https://ubuntu.com/security/cve?package=crowdsec","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=crowdsec","debian":"https://tracker.debian.org/pkg/crowdsec","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44981","published":"2026-07-16T20:16:00","updated_at":"2026-08-07T14:02:44.062410+00:00","description":"\nCrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0\nuntil 1.7.8, the LAPI router used gin-contrib/gzip with\nDefaultDecompressHandle globally in\npkg/apiserver/controllers/controller.go, causing /v1/watchers and\n/v1/watchers/login to decompress unauthenticated gzip-compressed JSON\nrequest bodies without enforcing a maximum decompressed size and allowing\nexcessive heap allocation that can make LAPI unreachable. This issue is\nfixed in version 1.7.8.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44981","https://github.com/crowdsecurity/crowdsec/commit/54a0dfe6c16b7687b0da6634e0b19ef0f5d9bb30","https://github.com/crowdsecurity/crowdsec/commit/56d0d6915f7f25941dc5b4f484028646f6601a37","https://github.com/crowdsecurity/crowdsec/security/advisories/GHSA-273h-gvwr-c3qj"],"bugs":[""],"patches":{"crowdsec":[]},"tags":{},"packages":[{"name":"crowdsec","source":"https://ubuntu.com/security/cve?package=crowdsec","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=crowdsec","debian":"https://tracker.debian.org/pkg/crowdsec","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47089","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:41.355044+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.\nLISTRIGHTS os not limited to users with admin access. An authenticated user\ncould call IMAP LISTRIGHTS against any mailbox they could name and learn\nwhat principals had what access to it. (This action should have been\nrestricted to users with admin access on the target mailbox.)","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47089","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47088","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:34.415965+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There\nis heap exposure in nested MIME comment parsing. An authenticated IMAP user\ncould craft an email message containing an RFC 822 comment ending with a\nbackslash. When parsing the message, the server would read past the\nmessage's end in memory, and read into the heap, returning the read content\nto the user.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47088","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47087","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:34.415965+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.\nURLAUTH does not honor revoked authorizer access. A URLAUTH URL minted\nwhile the authorizer had access continued to work after that access was\nrevoked.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47087","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47086","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:21.927600+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.\nGENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint\na URLAUTH token (via the GENURLAUTH command) for any mailbox they could\nname, even without read access on it. This would allow reading mail from\nmailboxes despite having no granted permissions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47086","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47085","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:13.247098+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.\nURLAUTH token forgery can occur via a missing mboxkey. If an attacker knew\na folder name on the victim's account for which the victim had never issued\nan auth URL, they could forge a working URLAUTH token by computing an\nHMAC-SHA1 value with a predictable key, giving them read access to the\nmailbox. (URLAUTH is an obscure feature, meaning that the odds of any user\nactually being susceptible to this attack are very low. Perhaps no public\nclients use URLAUTH.)","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47085","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47084","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:21.927600+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The\nLOCALDELETE command bypassed ACL checks. An authenticated but non-admin\nuser could invoke the admin-only LOCALDELETE IMAP command and delete\nmailboxes for which they had no permissions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47084","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47083","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:13.247098+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There\nis an ESEARCH cross-user content oracle. By using the ESEARCH command, an\nauthenticated IMAP user could enumerate folder names under any account they\ncould name. Search would return UIDs of messages matching the search,\ncreating a content oracle (without allowing arbitrary reads of the target's\ncontent).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47083","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47082","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:13.247098+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The\nvacation \"fcc\" feature skips the destination-mailbox ACL. A user whose\nvacation Sieve script used :fcc (to save a copy of the sent message) could\ndeliver vacation auto-reply copies into any mailbox the script could name,\nregardless of whether the script owner had insert permissions on the\ndestination mailbox.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47082","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47081","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:03:13.247098+00:00","description":"\nAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There\nis an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An\nauthenticated IMAP user could probe for the existence of arbitrary\nmailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and\nthen create Apple Push Notification Service notifications for new mail in\nthose mailboxes to their own APNS device. This did not leak any data about\nthe content of mailboxes. Instead, a \"mailbox has changed\" notice would be\npushed when the mailbox modseq changed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47081","https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html","https://www.cyrusimap.org/imap/download/release-notes/index.html"],"bugs":[""],"patches":{"cyrus-imapd":[]},"tags":{},"packages":[{"name":"cyrus-imapd","source":"https://ubuntu.com/security/cve?package=cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd","debian":"https://tracker.debian.org/pkg/cyrus-imapd","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46378","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:02:35.678800+00:00","description":"\nDasel is a command-line tool and library for querying, modifying, and\ntransforming data structures. From 3.0.0 until 3.10.1, the selector lexer\nmatchRegexPattern closure in (*Tokenizer).parseCurRune in\nselector/lexer/tokenize.go loops while tokenizing an unterminated regex\nliteral such as r/ because peekRuneEqual returns false after the end of\ninput, allowing attacker-controlled selector strings to consume CPU\nindefinitely. This issue is fixed in version 3.10.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46378","https://github.com/TomWright/dasel/commit/95f8dd3af12958bf6ca2a737b3ec0267280f86ed","https://github.com/TomWright/dasel/security/advisories/GHSA-m6xr-fvfg-5g64"],"bugs":[""],"patches":{"dasel":[]},"tags":{},"packages":[{"name":"dasel","source":"https://ubuntu.com/security/cve?package=dasel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dasel","debian":"https://tracker.debian.org/pkg/dasel","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46377","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:02:51.072682+00:00","description":"\nDasel is a command-line tool and library for querying, modifying, and\ntransforming data structures. From 3.0.0 until 3.10.1, the escape sequence\nhandler in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go\nincrements past a trailing backslash in a quoted string such as \"\\ or '\\\nand then reads p.src[pos] without a bounds check, allowing\nattacker-controlled selector strings to trigger a Go index-out-of-range\npanic. This issue is fixed in version 3.10.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46377","https://github.com/TomWright/dasel/commit/5fc1172287df89860caf139b146007d7ed12178c","https://github.com/TomWright/dasel/releases/tag/v3.10.1","https://github.com/TomWright/dasel/security/advisories/GHSA-m5j3-4634-c2vq"],"bugs":[""],"patches":{"dasel":[]},"tags":{},"packages":[{"name":"dasel","source":"https://ubuntu.com/security/cve?package=dasel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dasel","debian":"https://tracker.debian.org/pkg/dasel","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46338","published":"2026-07-16T19:16:00","updated_at":"2026-08-07T14:02:35.678800+00:00","description":"\nPyMdown Extensions is a set of extensions for the Python-Markdown markdown\nproject. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix\ncontainment check in SnippetPreprocessor.get_snippet_path() in\npymdownx/snippets.py when `restrict_base_path: True`, allowing markdown\nsnippet directives to read files from sibling paths that share the same\nbase_path prefix, such as docs and docs_internal. This is a regression of\nCVE-2023-32309. This issue is fixed in version 10.21.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46338","https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c","https://github.com/facelessuser/pymdown-extensions/releases/tag/10.21.3","https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h"],"bugs":[""],"patches":{"pymdown-extensions":[]},"tags":{},"packages":[{"name":"pymdown-extensions","source":"https://ubuntu.com/security/cve?package=pymdown-extensions","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pymdown-extensions","debian":"https://tracker.debian.org/pkg/pymdown-extensions","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57074","published":"2026-07-16T17:16:00","updated_at":"2026-08-07T05:39:20.386461+00:00","description":"\nXML::Bare versions through 0.53 for Perl have an unbounded character\nlookahead.\nThe parserc_parse function attempts to check for multicharacter strings\nsuch as \"<![CDATA\" or element terminators such as \">\" without checking that\nthe offsets are within the buffer.\nTruncated strings such as \"<a/\" can trigger an out-of-bounds read.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57074","https://lists.security.metacpan.org/cve-announce/msg/41876806/","https://github.com/nanoscopic/perl-XML-Bare/pull/1","https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-57074-r1.patch","http://www.openwall.com/lists/oss-security/2026/07/16/1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142227"],"patches":{"libxml-bare-perl":[]},"tags":{},"packages":[{"name":"libxml-bare-perl","source":"https://ubuntu.com/security/cve?package=libxml-bare-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxml-bare-perl","debian":"https://tracker.debian.org/pkg/libxml-bare-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.53-5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-13401","published":"2026-07-16T17:16:00","updated_at":"2026-08-07T05:33:24.338319+00:00","description":"\nXML::Bare versions through 0.53 for Perl will hang in an infinite loop when\nparsing malformed attributes.\nThe parserc_parse function never advances the attribute-parse state cursor\non certain malformed attribute forms, looping forever.\nNameless attributes such as \"<a ='c'>\" or unbalanced quotes \"<a\nb='''''''c'>\" can trigger this condition.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-13401","https://lists.security.metacpan.org/cve-announce/msg/41876829/","https://github.com/nanoscopic/perl-XML-Bare/pull/2","https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-13401-r1.patch","http://www.openwall.com/lists/oss-security/2026/07/16/2"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142227"],"patches":{"libxml-bare-perl":[]},"tags":{},"packages":[{"name":"libxml-bare-perl","source":"https://ubuntu.com/security/cve?package=libxml-bare-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxml-bare-perl","debian":"https://tracker.debian.org/pkg/libxml-bare-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.53-5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5674","published":"2026-07-16T14:16:00","updated_at":"2026-08-07T14:05:36.357876+00:00","description":"\nA flaw was found in PipeWire, a multimedia server. This vulnerability\nallows an attacker to escape sandboxed applications, such as Flatpak, by\nexploiting PipeWire's PulseAudio compatibility layer. An attacker with\nminimal permissions within a sandboxed environment can load a malicious\nlibrary, leading to arbitrary code execution outside the sandbox and\npotential compromise of the user's system.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5674","https://access.redhat.com/security/cve/CVE-2026-5674","https://bugzilla.redhat.com/show_bug.cgi?id=2455341"],"bugs":[""],"patches":{"pipewire":[]},"tags":{},"packages":[{"name":"pipewire","source":"https://ubuntu.com/security/cve?package=pipewire","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pipewire","debian":"https://tracker.debian.org/pkg/pipewire","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48863","published":"2026-07-16T01:16:00","updated_at":"2026-08-06T19:58:36.603631+00:00","description":"\nA flaw was found in libsolv. A stack-based buffer overflow vulnerability\nexists in the PGP verification component due to incorrect length handling\nwhen copying EdDSA 's' MPI into a stack buffer. A remote attacker could\ncraft a malicious Ed25519 PGP signature with mismatched MPI lengths.\nProcessing this crafted signature could lead to a denial of service in\nautomated package or repository processing workflows.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48863","https://bugzilla.redhat.com/show_bug.cgi?id=2460975"],"bugs":[""],"patches":{"libsolv":[]},"tags":{},"packages":[{"name":"libsolv","source":"https://ubuntu.com/security/cve?package=libsolv","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libsolv","debian":"https://tracker.debian.org/pkg/libsolv","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.7.38-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-60005","published":"2026-07-16T00:00:00","updated_at":"2026-08-06T19:58:47.909294+00:00","description":"\nNGINX Plus and NGINX Open Source have a vulnerability in the\nngx_http_slice_module module. When the slice directive and unnamed regex\ncaptures are configured or when a background cache update happens,\nunauthenticated attackers can send requests that may cause uninitialized\nmemory access in the NGINX worker process, leading to limited disclosure of\nmemory or a restart.\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have\nlimited control to disclose memory contents or restart the NGINX worker\nprocess. There is no control plane exposure; this is a data plane issue\nonly.\nNote: The ngx_http_slice_module module is not enabled by default; it's\nenabled with the --with-http_slice_module configuration parameter.\nNote: Software versions which have reached End of Technical Support (EoTS)\nare not evaluated.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects nginx built with --with-http_slice_module, but\nUbuntu builds do enable this"}],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60005","https://my.f5.com/manage/s/article/K000162100","https://ubuntu.com/security/notices/USN-8563-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/b99f804ad38a60ceb07bc429598d5b2c4e70e336"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.31.3,1.30.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.17","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.14","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.28.3-2ubuntu1.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-8563-1"],"notices":[{"id":"USN-8563-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T12:17:44.688569","description":"It was discovered that nginx incorrectly handled certain map directives\nusing regex matching and capture variables. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42533)\n\nIt was discovered that nginx had a use-after-free vulnerability in the\nngx_http_ssi_module module when configured with Server-Side Includes,\nproxy_pass, and proxy buffering disabled directives. An attacker able to\nintercept traffic and control responses from an upstream server could\npossibly use this issue to cause nginx to crash, resulting in a denial of\nservice. (CVE-2026-56434)\n\nIt was discovered that nginx incorrectly handled certain requests in the\nngx_http_slice_module module. A remote attacker could possibly use this\nissue to obtain sensitive information or cause nginx to crash, resulting\nin a denial of service. (CVE-2026-60005)","is_hidden":false,"release_packages":{"jammy":[{"name":"nginx","version":"1.18.0-6ubuntu14.17","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-echo","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-nchan","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-rtmp","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-stream-geoip2","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-common","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-core","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-doc","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-extras","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-full","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-light","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"}],"noble":[{"name":"nginx","version":"1.24.0-2ubuntu7.14","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-geoip","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-common","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-core","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-dev","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-doc","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-extras","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-full","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-light","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"}],"resolute":[{"name":"nginx","version":"1.28.3-2ubuntu1.7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-geoip","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-common","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-core","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-dev","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-doc","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-extras","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-full","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-light","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-56434","CVE-2026-42533","CVE-2026-60005"]}]},{"id":"CVE-2026-56434","published":"2026-07-16T00:00:00","updated_at":"2026-08-06T19:58:27.856653+00:00","description":"\nNGINX Plus and NGINX Open Source have a vulnerability in the\nngx_http_ssi_module module. This vulnerability may exist when the\nServer-Side Includes (SSI), proxy_pass, and proxy_buffering off directives\nare configured. With this configuration, an unauthenticated attacker with\nman-in-the-middle (MITM) ability to control responses from an upstream\nserver may be able to cause a use-after-free in the NGINX worker process.\nThis issue may lead to limited modification of memory or a restart of the\nNGINX worker process.\nImpact:\nThis vulnerability may allow remote attackers to have limited control to\nmodify memory contents or restart the NGINX worker process. There is no\ncontrol plane exposure; this is a data plane issue only.\nNote: Software versions which have reached End of Technical Support (EoTS)\nare not evaluated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56434","https://my.f5.com/manage/s/article/K000162098","https://ubuntu.com/security/notices/USN-8563-1"],"bugs":[""],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/ddde692db11ab8238e9ca661007f64c9f6d764d2"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.17","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.31.3,1.30.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.28.3-2ubuntu1.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-8563-1"],"notices":[{"id":"USN-8563-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T12:17:44.688569","description":"It was discovered that nginx incorrectly handled certain map directives\nusing regex matching and capture variables. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42533)\n\nIt was discovered that nginx had a use-after-free vulnerability in the\nngx_http_ssi_module module when configured with Server-Side Includes,\nproxy_pass, and proxy buffering disabled directives. An attacker able to\nintercept traffic and control responses from an upstream server could\npossibly use this issue to cause nginx to crash, resulting in a denial of\nservice. (CVE-2026-56434)\n\nIt was discovered that nginx incorrectly handled certain requests in the\nngx_http_slice_module module. A remote attacker could possibly use this\nissue to obtain sensitive information or cause nginx to crash, resulting\nin a denial of service. (CVE-2026-60005)","is_hidden":false,"release_packages":{"jammy":[{"name":"nginx","version":"1.18.0-6ubuntu14.17","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-echo","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-nchan","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-rtmp","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"libnginx-mod-stream-geoip2","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-common","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-core","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-doc","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-extras","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-full","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"},{"name":"nginx-light","version":"1.18.0-6ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17","pocket":"security"}],"noble":[{"name":"nginx","version":"1.24.0-2ubuntu7.14","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-geoip","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-common","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-core","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-dev","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-doc","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-extras","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-full","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"},{"name":"nginx-light","version":"1.24.0-2ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14","pocket":"security"}],"resolute":[{"name":"nginx","version":"1.28.3-2ubuntu1.7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-geoip","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-common","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-core","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-dev","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-doc","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-extras","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-full","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"},{"name":"nginx-light","version":"1.28.3-2ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-56434","CVE-2026-42533","CVE-2026-60005"]}]}],"offset":7560,"limit":20,"total_results":79316}