{"cves":[{"id":"CVE-2026-45072","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the\ndevelopment profiler file_excerpt Twig filter escapes PHP files through\nhighlight_string() but interpolates lines from non-PHP files directly into\n elements, allowing stored XSS against a developer who opens an\nattacker-written file such as var/log/dev.log in the profiler. This issue\nis fixed in versions 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":2.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45072","https://symfony.com/blog/cve-2026-45072-stored-xss-in-webprofiler-codeextension-fileexcerpt-unescaped-non-php-file-rendering"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45070","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nSymfony\\Component\\Mime\\Header\\ParameterizedHeader validates and encodes\nparameter values but emits parameter names verbatim, allowing a caller that\nderives a parameter name from untrusted input to include CRLF or other\nnon-token bytes and inject additional headers into rendered structured mail\nheaders such as Content-Type or Content-Disposition. This issue is reported\nas fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45070","https://symfony.com/blog/cve-2026-45070-email-header-injection-via-non-token-characters-in-mime-parameter-names"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45069","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12,\nOidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss),\nand expiry (exp) checkers but did not pass the mandatory claims list to\nClaimCheckerManager::check(), so a validly signed JWT that omitted those\nclaims could pass verification. This issue is fixed in versions 6.4.40,\n7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45069","https://symfony.com/blog/cve-2026-45069-oidctokenhandler-accepts-jwts-missing-aud-iss-exp-claims"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45064","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12,\nUrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting\ncharacters through into sanitized href and src attributes, allowing\nsanitized content to display a link destination that visually differs from\nthe actual destination and enabling phishing-style visual spoofing. This\nissue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45064","https://symfony.com/blog/cve-2026-45064-htmlsanitizer-url-attributes-pass-through-bidi-override-characters-visual-href-spoofing"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45063","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nX509Authenticator extracts the user identifier from\n$_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches\nemailAddress= anywhere in the distinguished name, allowing an attacker with\na trusted certificate containing emailAddress=victim inside another RDN\nvalue such as CN to authenticate as the victim. This issue is fixed in\nversions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45063","https://symfony.com/blog/cve-2026-45063-identity-spoofing-via-unanchored-dn-regex-in-x509authenticator"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15712","published":"2026-07-14T19:16:00","updated_at":"2026-07-16T10:53:55.672417+00:00","description":"\nA heap buffer over-read vulnerability was discovered in libsoup's\n(versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When\nthe library processes an HTTP/2 GOAWAY frame, it improperly handles the\n\"Additional Debug Data\" payload by assuming the data stream is a safely\nNUL-terminated C-string. Because the parser lacks strict length-boundary\nverification before reading this data, a remote, unauthenticated attacker\ncan intentionally send a malformed GOAWAY frame missing the appropriate\nnull delimiter. This causes the library to read past the end of the\nallocated buffer, triggering an application crash that results in a denial\nof service (DoS), or potentially exposing fragments of memory contents.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15712","https://access.redhat.com/security/cve/CVE-2026-15712","https://bugzilla.redhat.com/show_bug.cgi?id=2499939","https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540"],"bugs":[""],"patches":{"libsoup3":[]},"tags":{},"packages":[{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57108","published":"2026-07-14T18:18:00","updated_at":"2026-07-17T19:28:44.187250+00:00","description":"\nAccess of resource using incompatible type ('type confusion') in .NET Core\nallows an unauthorized attacker to deny service over a network.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."},{"author":"mdeslaur","note":"Marking .NET 6 as deferred until information is available to\ndetermine if it is impacted."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57108","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57108","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-july-2026-servicing-updates","https://github.com/dotnet/announcements/issues/408","https://ubuntu.com/security/notices/USN-8553-1"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"8.0.129-8.0.29-0ubuntu1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.129-8.0.29-0ubuntu1~24.04.1","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"10.0.110-10.0.10-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"10.0.110-10.0.10-0ubuntu1~26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8553-1"],"notices":[{"id":"USN-8553-1","title":".NET vulnerabilities","summary":"Several security issues were fixed in .NET.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T17:13:59.965059","description":"Artur Stetsko discovered that the .NET did not properly validate\nauthentication data. An attacker could possibly use this issue to elevate\nprivileges. (CVE-2026-47300)\n\nLevi Broderick discovered that .NET did not properly handle XML encryption\nduring parsing. An attacker could possibly use this issue to consume\nexcessive resources, resulting in a denial of service. (CVE-2026-47302)\n\nPham Quang Minh discovered that .NET did not properly parse\nauthentication data. An attacker could possibly use this issue to bypass\nauthentication and elevate privileges. (CVE-2026-47303)\n\nLevi Broderick discovered that .NET did not properly verify cryptographic\nsignatures during XML encryption. An attacker could possibly use this issue\nto bypass security features over a network and access encrypted data.\n(CVE-2026-47304)\n\nIt was discovered that .NET did not properly validate input during TLS\nhandshakes. An attacker could possibly use this issue to cause .NET to\ncrash, resulting in a denial of service. (CVE-2026-50524)\n\nLevi Broderick discovered that .NET did not properly handle resource\nallocation during XML encryption. An attacker could possibly use this issue\nto consume excessive resources, resulting in a denial of service.\n(CVE-2026-50525)\n\nSiwei Li discovered that .NET did not properly handle link resolution\nbefore file access during the container image build process. A local\nattacker could possibly use this issue to inject resources that could be\nincorporated into container images built by other users on the same\nmachine. (CVE-2026-50526)\n\nLevi Broderick discovered that .NET did not properly handle memory while\nperforming XML encryption. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-50527)\n\nHenrique Pereira discovered that .NET did not properly handle\nauthorization checks during TLS/SSL connections. An attacker could\npossibly use this issue to bypass authorization checks during secure\ncommunications. (CVE-2026-50528)\n\nIt was discovered that .NET did not properly handle resource allocation\nduring XML encryption. An attacker could possibly use this issue to\nconsume excessive resources, resulting in a denial of service.\n(CVE-2026-50648)\n\nMiha Zupan discovered that .NET did not properly limit resource\nallocation when handling HTTP/2 requests. An attacker could possibly use\nthis issue to consume excessive resources, resulting in a denial of\nservice. (CVE-2026-50651)\n\nIt was discovered that the .NET SMTP client did not properly handle the\nencoding or escaping of output. An attacker could possibly use this issue\nto spoof messages during message routing. (CVE-2026-50659)\n\nIt was discovered that .NET did not properly validate resource types when\nparsing X.509 certificates. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-57108)","is_hidden":false,"release_packages":{"jammy":[{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"}],"noble":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"}],"resolute":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-57108","CVE-2026-50659","CVE-2026-47304","CVE-2026-50527","CVE-2026-50648","CVE-2026-50651","CVE-2026-47300","CVE-2026-47303","CVE-2026-50525","CVE-2026-50526","CVE-2026-50528","CVE-2026-50524","CVE-2026-47302"]}]},{"id":"CVE-2026-45756","published":"2026-07-14T18:17:00","updated_at":"2026-07-17T19:24:22.972425+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the\nJsonPath component compiles attacker-controlled match() and search() filter\npatterns directly into preg_match() without a length cap, i-regexp\nrestriction, or bounded backtracking, allowing catastrophic-backtracking\nexpressions to pin worker CPU and cause denial of service. This issue is\nfixed in versions 7.4.12 and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45756","https://symfony.com/blog/cve-2026-45756-jsonpath-evaluates-attacker-controlled-regular-expressions-in-match-search-without-limits-redos"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45077","published":"2026-07-14T18:17:00","updated_at":"2026-07-17T19:24:22.972425+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the\nserver:log listener (Symfony\\Bridge\\Monolog\\Command\\ServerLogCommand) binds\nto 0.0.0.0:9911 by default and processes each received frame with\nunserialize(base64_decode($message)) without authentication, integrity\nchecks, or an allowed_classes allowlist, allowing any reachable host to\nsubmit attacker-chosen serialized PHP payloads that can crash the listener\nand may trigger object-injection gadget effects. This issue is fixed in\nversions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45077","https://symfony.com/blog/cve-2026-45077-unauthenticated-php-object-deserialization-in-monologbridge-server-log-listener"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45074","published":"2026-07-14T18:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler\nbuilds the CAS service parameter from Request::getSchemeAndHttpHost(),\nwhich reflects an attacker-controlled Host header when\nframework.trusted_hosts is not configured; an attacker controlling another\napplication registered with the same CAS server can replay a victim ticket\nagainst the Symfony application and authenticate as the victim. This issue\nis fixed in versions 7.4.12 and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45074","https://symfony.com/blog/cve-2026-45074-cas2handler-derives-cas-service-url-from-client-host-header-cross-service-ticket-replay"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45067","published":"2026-07-14T18:17:00","updated_at":"2026-07-16T10:54:18.822095+00:00","description":"\n### Description\n`Symfony\\Component\\Mime\\Address` is the value-object every Symfony Mailer\naddress (to/cc/bcc/from/reply-to) flows through; its constructor is\ndocumented as validating the address and throwing on invalid input, so\ndevelopers treat it as a security boundary.\nThe constructor accepts email addresses whose local-part (the part before\n`@`) is an RFC-5322 *quoted string* containing raw `\\r\\n` bytes — e.g.\n`\"x\\r\\nBcc: attacker@evil\"@example.com`. The stored address is later\nemitted verbatim into (1) the rendered message headers and (2)\n`SmtpTransport`'s `MAIL FROM:<...>` / `RCPT TO:<...>` protocol lines,\nturning the embedded CRLF into a new mail header and/or a new SMTP command.\n### Resolution\nThe `Address` constructor now rejects addresses containing line breaks.\nThe patch for this issue is available\n[here](https://github.com/symfony/symfony/commit/dc2dbd29211eb4ddc451373fa1374fb926e94604)\nfor branch 5.4.\n### Credits\nWe would like to thank Claude Mythos Preview (via Project Glasswing) for\nreporting the issue and providing the fix.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45067","https://symfony.com/blog/cve-2026-45067-email-header-smtp-command-injection-via-crlf-in-symfony-component-mime-address"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45066","published":"2026-07-14T18:17:00","updated_at":"2026-07-17T19:24:22.972425+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12,\nHtmlSanitizer URL sanitization can allow off-allowlist URLs through\nallowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows\nRFC 3986 while browsers follow WHATWG URL parsing, and because \nis checked against the media policy rather than the link policy. This issue\nis fixed in versions 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45066","https://symfony.com/blog/cve-2026-45066-htmlsanitizer-allowlinkhosts-allowmediahosts-bypass-via-url-parser-differentials-and-area-misclassification"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45065","published":"2026-07-14T18:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nUrlGenerator validates route parameters against a pattern built as ^ plus\nthe raw requirement plus $; with ungrouped alternations, middle\nalternatives match as unanchored substrings, allowing a value such as\n//evil.com to satisfy a common locale requirement and generate a\nprotocol-relative off-site URL. This issue is fixed in versions 5.4.52,\n6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45065","https://symfony.com/blog/cve-2026-45065-urlgenerator-route-requirement-bypass-via-unanchored-regex-alternation-off-site-host-url-injection"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15747","published":"2026-07-14T18:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nMojolicious versions from 4.59 before 9.48 for Perl expose a stable\nrepresentation of the session CSRF token to a BREACH compression oracle.\n_csrf_token generates and caches one token per session and returns the same\nvalue on every call, and _csrf_field places that value in a hidden\n`csrf_token` input. When a response carrying the token also echoes\nattacker-controlled input and is gzip-compressed, the chosen values and the\nresulting compressed lengths form a BREACH oracle.\nAn attacker able to query it can recover the token and pass csrf_protect\nvalidation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15747","https://lists.security.metacpan.org/cve-announce/msg/41816171/","https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27.patch","https://metacpan.org/release/SRI/Mojolicious-9.48/changes","http://www.openwall.com/lists/oss-security/2026/07/14/16"],"bugs":[""],"patches":{"libmojolicious-perl":[]},"tags":{},"packages":[{"name":"libmojolicious-perl","source":"https://ubuntu.com/security/cve?package=libmojolicious-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libmojolicious-perl","debian":"https://tracker.debian.org/pkg/libmojolicious-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59888","published":"2026-07-14T17:17:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\njackson-databind contains the general-purpose data-binding functionality\nand tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8,\n2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass\n@JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals()\nrecords an ignored component under its original implicit name before\n_renameUsing() applies the naming strategy, allowing the renamed JSON key\nto be assigned to the Record constructor parameter. This issue is fixed in\nversions 2.18.8, 2.21.4, and 3.1.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59888","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code introduced later","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59886","published":"2026-07-14T17:17:00","updated_at":"2026-09-01T17:39:47.325028+00:00","description":"\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real\ntype converted its mantissa, base, and exponent value to a Python float\nusing exact big-integer exponentiation. A BER, CER, or DER encoded REAL\nvalue only a few bytes long can carry a very large exponent, causing float\nconversion through prettyPrint(), str(), comparison, arithmetic, int(), or\nan explicit float() call to consume excessive CPU and memory and hang\napplications that decode untrusted ASN.1 data and then print, log, or\ncompare decoded objects. This issue is fixed in version 0.6.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59886","https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r","https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4","https://ubuntu.com/security/notices/USN-8712-1"],"bugs":[""],"patches":{"pyasn1":["upstream: https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886"]},"tags":{},"packages":[{"name":"pyasn1","source":"https://ubuntu.com/security/cve?package=pyasn1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pyasn1","debian":"https://tracker.debian.org/pkg/pyasn1","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.4-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.4.8-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.4.8-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.6.3-1ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8712-1"],"notices":[{"id":"USN-8712-1","title":"pyasn1 vulnerabilities","summary":"Several security issues were fixed in pyasn1.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-01T16:20:26.834191","description":"It was discovered that pyasn1 did not properly bound the size of long-form\ntag identifiers when parsing BER, CER, or DER encoded data. An attacker\ncould possibly use this issue to cause applications decoding untrusted\nASN.1 data to consume excessive CPU resources, resulting in a denial of\nservice. (CVE-2026-59884)\n\nIt was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID\nvalues in quadratic time relative to the number of arcs. An attacker could\npossibly use this issue to cause applications decoding untrusted ASN.1 data\nto consume excessive CPU resources, resulting in a denial of service.\n(CVE-2026-59885)\n\nIt was discovered that pyasn1 incorrectly handled conversion of decoded\nREAL values to Python float types. An attacker could possibly use this\nissue to cause applications decoding untrusted ASN.1 data to consume\nexcessive CPU and memory resources, resulting in a denial of service.\n(CVE-2026-59886)","is_hidden":false,"release_packages":{"jammy":[{"name":"pyasn1","version":"0.4.8-1ubuntu0.3","description":"ASN.1 library for Python","is_source":true},{"name":"pypy-pyasn1","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"},{"name":"python-pyasn1-doc","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"},{"name":"python3-pyasn1","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"}],"noble":[{"name":"pyasn1","version":"0.4.8-4ubuntu0.3","description":"ASN.1 library for Python","is_source":true},{"name":"python-pyasn1-doc","version":"0.4.8-4ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.3","pocket":"security"},{"name":"python3-pyasn1","version":"0.4.8-4ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.3","pocket":"security"}],"resolute":[{"name":"pyasn1","version":"0.6.3-1ubuntu0.1","description":"ASN.1 library for Python","is_source":true},{"name":"python-pyasn1-doc","version":"0.6.3-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.6.3-1ubuntu0.1","pocket":"security"},{"name":"python3-pyasn1","version":"0.6.3-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.6.3-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-59885","CVE-2026-59886","CVE-2026-59884"]}]},{"id":"CVE-2026-59885","published":"2026-07-14T17:17:00","updated_at":"2026-09-01T17:39:47.325028+00:00","description":"\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER,\nand DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in\nquadratic time relative to the number of arcs, so a small crafted payload\ncontaining an OID with many arcs consumes excessive CPU per decode() call\nand can deny service to applications that decode untrusted ASN.1 data. The\ncorresponding encoders have the same quadratic behavior when an application\nre-encodes previously decoded attacker-supplied values. This issue is fixed\nin version 0.6.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59885","https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj","https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4","https://ubuntu.com/security/notices/USN-8712-1"],"bugs":[""],"patches":{"pyasn1":["upstream: https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9"]},"tags":{},"packages":[{"name":"pyasn1","source":"https://ubuntu.com/security/cve?package=pyasn1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pyasn1","debian":"https://tracker.debian.org/pkg/pyasn1","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.4-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.4.8-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.4.8-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.6.3-1ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8712-1"],"notices":[{"id":"USN-8712-1","title":"pyasn1 vulnerabilities","summary":"Several security issues were fixed in pyasn1.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-01T16:20:26.834191","description":"It was discovered that pyasn1 did not properly bound the size of long-form\ntag identifiers when parsing BER, CER, or DER encoded data. An attacker\ncould possibly use this issue to cause applications decoding untrusted\nASN.1 data to consume excessive CPU resources, resulting in a denial of\nservice. (CVE-2026-59884)\n\nIt was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID\nvalues in quadratic time relative to the number of arcs. An attacker could\npossibly use this issue to cause applications decoding untrusted ASN.1 data\nto consume excessive CPU resources, resulting in a denial of service.\n(CVE-2026-59885)\n\nIt was discovered that pyasn1 incorrectly handled conversion of decoded\nREAL values to Python float types. An attacker could possibly use this\nissue to cause applications decoding untrusted ASN.1 data to consume\nexcessive CPU and memory resources, resulting in a denial of service.\n(CVE-2026-59886)","is_hidden":false,"release_packages":{"jammy":[{"name":"pyasn1","version":"0.4.8-1ubuntu0.3","description":"ASN.1 library for Python","is_source":true},{"name":"pypy-pyasn1","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"},{"name":"python-pyasn1-doc","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"},{"name":"python3-pyasn1","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"}],"noble":[{"name":"pyasn1","version":"0.4.8-4ubuntu0.3","description":"ASN.1 library for Python","is_source":true},{"name":"python-pyasn1-doc","version":"0.4.8-4ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.3","pocket":"security"},{"name":"python3-pyasn1","version":"0.4.8-4ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.3","pocket":"security"}],"resolute":[{"name":"pyasn1","version":"0.6.3-1ubuntu0.1","description":"ASN.1 library for Python","is_source":true},{"name":"python-pyasn1-doc","version":"0.6.3-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.6.3-1ubuntu0.1","pocket":"security"},{"name":"python3-pyasn1","version":"0.6.3-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.6.3-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-59885","CVE-2026-59886","CVE-2026-59884"]}]},{"id":"CVE-2026-59884","published":"2026-07-14T17:17:00","updated_at":"2026-09-01T17:39:47.325028+00:00","description":"\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER\ndecoder shared by the CER and DER codecs parses long-form tags by\naccumulating continuation octets without an upper bound on the tag ID size,\nallowing a crafted input to force construction of an arbitrarily large\ninteger with CPU cost growing quadratically and to trigger unhandled\nValueError exceptions in Python 3.11+ error formatting paths. Any\napplication decoding untrusted BER, CER, or DER input is affected. This\nissue is fixed in version 0.6.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59884","https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j","https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4","https://ubuntu.com/security/notices/USN-8712-1"],"bugs":[""],"patches":{"pyasn1":["upstream: https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5"]},"tags":{},"packages":[{"name":"pyasn1","source":"https://ubuntu.com/security/cve?package=pyasn1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pyasn1","debian":"https://tracker.debian.org/pkg/pyasn1","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.4.8-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.4-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.4.8-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.6.3-1ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8712-1"],"notices":[{"id":"USN-8712-1","title":"pyasn1 vulnerabilities","summary":"Several security issues were fixed in pyasn1.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-01T16:20:26.834191","description":"It was discovered that pyasn1 did not properly bound the size of long-form\ntag identifiers when parsing BER, CER, or DER encoded data. An attacker\ncould possibly use this issue to cause applications decoding untrusted\nASN.1 data to consume excessive CPU resources, resulting in a denial of\nservice. (CVE-2026-59884)\n\nIt was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID\nvalues in quadratic time relative to the number of arcs. An attacker could\npossibly use this issue to cause applications decoding untrusted ASN.1 data\nto consume excessive CPU resources, resulting in a denial of service.\n(CVE-2026-59885)\n\nIt was discovered that pyasn1 incorrectly handled conversion of decoded\nREAL values to Python float types. An attacker could possibly use this\nissue to cause applications decoding untrusted ASN.1 data to consume\nexcessive CPU and memory resources, resulting in a denial of service.\n(CVE-2026-59886)","is_hidden":false,"release_packages":{"jammy":[{"name":"pyasn1","version":"0.4.8-1ubuntu0.3","description":"ASN.1 library for Python","is_source":true},{"name":"pypy-pyasn1","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"},{"name":"python-pyasn1-doc","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"},{"name":"python3-pyasn1","version":"0.4.8-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.3","pocket":"security"}],"noble":[{"name":"pyasn1","version":"0.4.8-4ubuntu0.3","description":"ASN.1 library for Python","is_source":true},{"name":"python-pyasn1-doc","version":"0.4.8-4ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.3","pocket":"security"},{"name":"python3-pyasn1","version":"0.4.8-4ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.3","pocket":"security"}],"resolute":[{"name":"pyasn1","version":"0.6.3-1ubuntu0.1","description":"ASN.1 library for Python","is_source":true},{"name":"python-pyasn1-doc","version":"0.6.3-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.6.3-1ubuntu0.1","pocket":"security"},{"name":"python3-pyasn1","version":"0.6.3-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyasn1","version_link":"https://launchpad.net/ubuntu/+source/pyasn1/0.6.3-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-59885","CVE-2026-59886","CVE-2026-59884"]}]},{"id":"CVE-2026-59200","published":"2026-07-14T17:17:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nPillow is a Python imaging library. From 5.1.0 until 12.3.0,\nPdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress()\nwith bufsize set to the PDF stream Length field without bounding the\ndecompressed output size, allowing a crafted FlateDecode PDF stream to\nexhaust memory from a small file. This issue is fixed in version 12.3.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59200","https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565","https://github.com/python-pillow/Pillow/pull/9718","https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09","https://github.com/python-pillow/Pillow/releases/tag/12.3.0"],"bugs":[""],"patches":{"pillow":[],"pillow-python2":[]},"tags":{},"packages":[{"name":"pillow","source":"https://ubuntu.com/security/cve?package=pillow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pillow","debian":"https://tracker.debian.org/pkg/pillow","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"pillow-python2","source":"https://ubuntu.com/security/cve?package=pillow-python2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pillow-python2","debian":"https://tracker.debian.org/pkg/pillow-python2","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59197","published":"2026-07-14T17:17:00","updated_at":"2026-07-16T10:55:34.092887+00:00","description":"\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public\nrank-filter API can trigger a native heap out-of-bounds write when given a\nvery large odd filter size because ImageFilter.RankFilter.filter() calls\nimage.expand(size // 2, size // 2) before rank-filter size validation and\nImagingExpand() computes output dimensions with unchecked signed int\narithmetic. This issue is fixed in version 12.3.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59197","https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr","https://github.com/python-pillow/Pillow/pull/9695","https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1","https://github.com/python-pillow/Pillow/releases/tag/12.3.0"],"bugs":[""],"patches":{"pillow":[],"pillow-python2":[]},"tags":{},"packages":[{"name":"pillow","source":"https://ubuntu.com/security/cve?package=pillow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pillow","debian":"https://tracker.debian.org/pkg/pillow","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"pillow-python2","source":"https://ubuntu.com/security/cve?package=pillow-python2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pillow-python2","debian":"https://tracker.debian.org/pkg/pillow-python2","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7700,"limit":20,"total_results":79316}