{"cves":[{"id":"CVE-2026-57220","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ\nstream listener does not enforce the configured stream frame-size limit\nwhile assembling frames during authentication and before Tune negotiation,\nallowing an unauthenticated remote client to declare oversized frame\nlengths and consume broker memory in rabbit_stream_core. This issue is\nfixed in version 4.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57220","https://github.com/rabbitmq/rabbitmq-server/commit/595ec28fa1621b1f2c28124e4e0466a8ad963547","https://github.com/rabbitmq/rabbitmq-server/commit/773a49c4921e8be990262a2d609c35916825679e","https://github.com/rabbitmq/rabbitmq-server/pull/16171","https://github.com/rabbitmq/rabbitmq-server/pull/16173","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-f364-87q5-j35q"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57219","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20,\n4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the\nOAuth 2 client secret on RabbitMQ installations configured with\nmanagement.oauth_client_secret, exposing credentials to unauthenticated\ncallers when the management plugin and that OAuth configuration are\nenabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and\n4.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57219","https://github.com/rabbitmq/rabbitmq-server/commit/98b1daf740237c85941e8addcbea6e74f4a2743c","https://github.com/rabbitmq/rabbitmq-server/commit/aa387c4451e7b674df3e3ba89df86a99d697cc7f","https://github.com/rabbitmq/rabbitmq-server/pull/16083","https://github.com/rabbitmq/rabbitmq-server/pull/16086","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9q"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57218","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:55:55.253395+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP\n0-9-1 allows an existing consumer to keep receiving messages after OAuth\ntoken expiry or connection.update_secret refresh to reduced scopes because\nexisting consumers are not canceled or reauthorized at delivery time after\nthe channel user state changes. This issue is fixed in version 4.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57218","https://github.com/rabbitmq/rabbitmq-server/commit/501ad947cd6bbcc9486fe96e0d073992bfe52cc4","https://github.com/rabbitmq/rabbitmq-server/commit/db20d6c0fcf3056030f244b5adab0d45c0db0c9e","https://github.com/rabbitmq/rabbitmq-server/pull/16092","https://github.com/rabbitmq/rabbitmq-server/pull/16097","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57217","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:55:34.092887+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21,\n4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic\nwrites and binds during metadata-store failures because topic-permission\nlookup errors from Khepri can collapse to undefined, which the internal\nbackend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21,\n4.1.11, and 4.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57217","https://github.com/rabbitmq/rabbitmq-server/commit/94f1d33a70fcfa09006649599e79fc92786a2d36","https://github.com/rabbitmq/rabbitmq-server/commit/ce1f682aa6b398820c5e3ce1ff7435184027c82c","https://github.com/rabbitmq/rabbitmq-server/pull/15941","https://github.com/rabbitmq/rabbitmq-server/pull/15943","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gpvw-75h5-3wvx"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57216","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:55:34.092887+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20,\n4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication\ncan allow a loopback-restricted user such as guest to connect remotely when\ntraffic is accepted through a trusted PROXY-protocol path and the backend\nlistener is loopback-bound because the loopback check uses the\nlistener-side socket address instead of the real client source. This issue\nis fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57216","https://github.com/rabbitmq/rabbitmq-server/commit/7273c9eb6920abcde17b892dbe97ccaf906ead47","https://github.com/rabbitmq/rabbitmq-server/commit/9f8c39fcf0acbc43080ee7017a62a02832114112","https://github.com/rabbitmq/rabbitmq-server/pull/15936","https://github.com/rabbitmq/rabbitmq-server/pull/15940","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-36m6-588r-vqcw"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57215","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:55:34.092887+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20,\n4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to\namq.rabbitmq.reply-to destinations because volatile direct-reply-to queues\ncan be accepted at bind and route time but are missing from Khepri-backed\ndeletion checks, leaving persistent route entries after unbind. This issue\nis fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57215","https://github.com/rabbitmq/rabbitmq-server/commit/9055500d10ca7629dd2b051c6dc7a4b0bb8f6734","https://github.com/rabbitmq/rabbitmq-server/commit/c84f3c880e0f22b49c01237cf8f86e176eeadc72","https://github.com/rabbitmq/rabbitmq-server/pull/15935","https://github.com/rabbitmq/rabbitmq-server/pull/15938","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5cq3-v9jx-p3x3"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57214","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ\nmanagement UI renders the x-internal-purpose queue or exchange argument\ninto an HTML title attribute without proper escaping on the Queues and\nExchanges pages, allowing a user with permission to declare a queue or\nexchange to execute JavaScript in another user's browser. This issue is\nfixed in version 4.2.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57214","https://github.com/rabbitmq/rabbitmq-server/commit/b0027b6c1ae5b869d876e211efe6189ffd92b5c2","https://github.com/rabbitmq/rabbitmq-server/commit/b267a290dd89e42c6e0256f46fc273a8adb7f3ec","https://github.com/rabbitmq/rabbitmq-server/pull/15606","https://github.com/rabbitmq/rabbitmq-server/pull/15608","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwp"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57213","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:55:34.092887+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19,\n4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the\nconsumer_tag field on the Federation Status page without HTML escaping,\nallowing a user who can configure a federation upstream or policy to\nexecute JavaScript in the browser of a user viewing that page. This issue\nis fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57213","https://github.com/rabbitmq/rabbitmq-server/commit/33dedfe4fd53ff009cc67ab36358d0624c6b2e53","https://github.com/rabbitmq/rabbitmq-server/commit/c2d0d69edf01efbd6e87dfb250c373a32da957f8","https://github.com/rabbitmq/rabbitmq-server/pull/15708","https://github.com/rabbitmq/rabbitmq-server/pull/15711","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-qxrp-7cmp-p77h"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57212","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19,\n4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid\nJSON bodies on with_decode and direct_request paths because\nread_complete_body checks the accumulated size before the final chunk but\nnot the final combined size. This issue is fixed in versions 3.13.14,\n4.0.19, 4.1.10, and 4.2.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.7,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57212","https://github.com/rabbitmq/rabbitmq-server/commit/3976d148901bdfa82e1cd60b7a4534e073266ba5","https://github.com/rabbitmq/rabbitmq-server/commit/b8fc2ef7c50a2797d15e1ea7cf34f290032303bb","https://github.com/rabbitmq/rabbitmq-server/pull/15712","https://github.com/rabbitmq/rabbitmq-server/pull/15714","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5cmq-vp28-xqrj"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57211","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:55:55.253395+00:00","description":"\nRabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on\nWindows, the RabbitMQ management plugin static file handler\nrabbit_mgmt_wm_static can pass URL-encoded backslashes to\nerl_prim_loader:read_file_info before path validation when multiple\nmanagement extension plugins are enabled, causing outbound DNS and SMB\nrequests to attacker-controlled UNC paths. This issue is fixed in versions\n4.1.11 and 4.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57211","https://github.com/rabbitmq/rabbitmq-server/commit/39c3a8e9c71da0403d8dfc13f700e60c936e3682","https://github.com/rabbitmq/rabbitmq-server/commit/6730797f6a34b4e8308cea60adf1243857e70204","https://github.com/rabbitmq/rabbitmq-server/pull/15803","https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-7v84-m3g5-vxq6"],"bugs":[""],"patches":{"rabbitmq-server":[]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55213","published":"2026-07-10T21:16:00","updated_at":"2026-07-16T10:55:34.092887+00:00","description":"\nh2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior\nto commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a\nQPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might\nallocate an on-stack buffer as large as approximately 800 KB by calling\nalloca, which exceeds the default pthread stack size used by musl libc and\ncauses the h2o server to crash with a segmentation fault while touching the\nguard page. This issue is fixed in commit\nedd7a120bfc4af11ac0cbebce2a43cc1f93f9af1.","ubuntu_description":"","notes":[{"author":"hlibk","note":"Before dnsdist version 1.8.2-2, dnsdist used system h2o. Between\n1.8.2-2 and 1.9.0, dnsdist vendored h2o. After 1.9.0, dnsdist\nswitched\nfrom using h2o to nghttp2 and now uses system nghttp2. Also, before\n1.4.0\ndns-over-https support was not implemented."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55213","https://github.com/h2o/h2o/security/advisories/GHSA-432c-8xmj-frmq","https://github.com/h2o/h2o/commit/edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1"],"bugs":[""],"patches":{"h2o":[],"dnsdist":[]},"tags":{},"packages":[{"name":"h2o","source":"https://ubuntu.com/security/cve?package=h2o","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=h2o","debian":"https://tracker.debian.org/pkg/h2o","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dnsdist","source":"https://ubuntu.com/security/cve?package=dnsdist","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dnsdist","debian":"https://tracker.debian.org/pkg/dnsdist","statuses":[{"release_codename":"bionic","status":"not-affected","description":"dns over https not implemented","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system h2o","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system h2o","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"no longer depends on h2o","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"dns over https not implemented","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-57158","published":"2026-07-10T20:16:00","updated_at":"2026-07-20T18:01:27.398901+00:00","description":"\nFreeRDP is a free implementation of the Remote Desktop Protocol. From\n3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an\nincomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in\nlibfreerdp/codec/planar.c, allowing a malicious RDP server to send a\ntruncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte\npast the input buffer. This issue is fixed in version 3.28.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57158","https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mp3f-59pg-c5pp","https://ubuntu.com/security/notices/USN-8561-1"],"bugs":[""],"patches":{"freerdp":[],"freerdp2":[],"freerdp3":[]},"tags":{},"packages":[{"name":"freerdp","source":"https://ubuntu.com/security/cve?package=freerdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp","debian":"https://tracker.debian.org/pkg/freerdp","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp2","source":"https://ubuntu.com/security/cve?package=freerdp2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp2","debian":"https://tracker.debian.org/pkg/freerdp2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp3","source":"https://ubuntu.com/security/cve?package=freerdp3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp3","debian":"https://tracker.debian.org/pkg/freerdp3","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.28.0","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.30.0+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.30.0+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8561-1"],"notices":[{"id":"USN-8561-1","title":"FreeRDP vulnerabilities","summary":"Several security issues were fixed in FreeRDP.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-20T11:49:26.882744","description":"It was discovered that FreeRDP contained multiple security issues. An\nattacker could possibly use these issues to obtain sensitive information,\ncause FreeRDP to crash, resulting in a denial of service, or execute\narbitrary code.","is_hidden":false,"release_packages":{"noble":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server-proxy3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-33995","CVE-2026-57157","CVE-2026-33952","CVE-2026-55648","CVE-2026-44422","CVE-2026-55194","CVE-2026-29775","CVE-2026-40254","CVE-2026-55192","CVE-2026-33984","CVE-2026-31897","CVE-2026-44420","CVE-2026-31806","CVE-2026-56297","CVE-2026-57158","CVE-2026-27951","CVE-2026-33986","CVE-2026-55191","CVE-2026-31883","CVE-2026-29774","CVE-2026-55193","CVE-2026-57156","CVE-2026-33987","CVE-2026-31884","CVE-2026-55827","CVE-2026-33983","CVE-2026-33985","CVE-2026-44421","CVE-2026-33982","CVE-2026-29776","CVE-2026-33977","CVE-2026-55564","CVE-2026-40033","CVE-2026-31885"]}]},{"id":"CVE-2026-57157","published":"2026-07-10T20:16:00","updated_at":"2026-07-20T18:01:27.398901+00:00","description":"\nFreeRDP is a free implementation of the Remote Desktop Protocol. Prior to\n3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device\nenumerator channel enabled scan attacker-supplied DeviceName and\nVirtualChannelName fields for a NUL terminator in\nchannels/rdpecam/server/camera_device_enumerator_main.c and then\ndereference once past the scan bound, allowing a malicious RDP client to\ntrigger a 1- to 2-byte out-of-bounds heap read. This issue is fixed in\nversion 3.28.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57157","https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-47fr-jw86-c3fj","https://ubuntu.com/security/notices/USN-8561-1"],"bugs":[""],"patches":{"freerdp":[],"freerdp2":[],"freerdp3":[]},"tags":{},"packages":[{"name":"freerdp","source":"https://ubuntu.com/security/cve?package=freerdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp","debian":"https://tracker.debian.org/pkg/freerdp","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp2","source":"https://ubuntu.com/security/cve?package=freerdp2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp2","debian":"https://tracker.debian.org/pkg/freerdp2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp3","source":"https://ubuntu.com/security/cve?package=freerdp3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp3","debian":"https://tracker.debian.org/pkg/freerdp3","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.30.0+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.30.0+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.28.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-8561-1"],"notices":[{"id":"USN-8561-1","title":"FreeRDP vulnerabilities","summary":"Several security issues were fixed in FreeRDP.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-20T11:49:26.882744","description":"It was discovered that FreeRDP contained multiple security issues. An\nattacker could possibly use these issues to obtain sensitive information,\ncause FreeRDP to crash, resulting in a denial of service, or execute\narbitrary code.","is_hidden":false,"release_packages":{"noble":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server-proxy3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-33995","CVE-2026-57157","CVE-2026-33952","CVE-2026-55648","CVE-2026-44422","CVE-2026-55194","CVE-2026-29775","CVE-2026-40254","CVE-2026-55192","CVE-2026-33984","CVE-2026-31897","CVE-2026-44420","CVE-2026-31806","CVE-2026-56297","CVE-2026-57158","CVE-2026-27951","CVE-2026-33986","CVE-2026-55191","CVE-2026-31883","CVE-2026-29774","CVE-2026-55193","CVE-2026-57156","CVE-2026-33987","CVE-2026-31884","CVE-2026-55827","CVE-2026-33983","CVE-2026-33985","CVE-2026-44421","CVE-2026-33982","CVE-2026-29776","CVE-2026-33977","CVE-2026-55564","CVE-2026-40033","CVE-2026-31885"]}]},{"id":"CVE-2026-57156","published":"2026-07-10T20:16:00","updated_at":"2026-07-20T18:01:27.398901+00:00","description":"\nFreeRDP is a free implementation of the Remote Desktop Protocol. Prior to\n3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in\nupdate_read_delta_points in libfreerdp/core/orders.c when multiplying an\nattacker-controlled point count by sizeof(DELTA_POINT), allowing a\nmalicious RDP peer to allocate an undersized heap buffer and then write\nbeyond it during initialization. This issue is fixed in version 3.28.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-57156","https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v5wf-j8j4-77h7","https://ubuntu.com/security/notices/USN-8561-1"],"bugs":[""],"patches":{"freerdp":[],"freerdp2":[],"freerdp3":[]},"tags":{},"packages":[{"name":"freerdp","source":"https://ubuntu.com/security/cve?package=freerdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp","debian":"https://tracker.debian.org/pkg/freerdp","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp2","source":"https://ubuntu.com/security/cve?package=freerdp2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp2","debian":"https://tracker.debian.org/pkg/freerdp2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp3","source":"https://ubuntu.com/security/cve?package=freerdp3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp3","debian":"https://tracker.debian.org/pkg/freerdp3","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.28.0","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.30.0+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.30.0+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8561-1"],"notices":[{"id":"USN-8561-1","title":"FreeRDP vulnerabilities","summary":"Several security issues were fixed in FreeRDP.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-20T11:49:26.882744","description":"It was discovered that FreeRDP contained multiple security issues. An\nattacker could possibly use these issues to obtain sensitive information,\ncause FreeRDP to crash, resulting in a denial of service, or execute\narbitrary code.","is_hidden":false,"release_packages":{"noble":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server-proxy3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-33995","CVE-2026-57157","CVE-2026-33952","CVE-2026-55648","CVE-2026-44422","CVE-2026-55194","CVE-2026-29775","CVE-2026-40254","CVE-2026-55192","CVE-2026-33984","CVE-2026-31897","CVE-2026-44420","CVE-2026-31806","CVE-2026-56297","CVE-2026-57158","CVE-2026-27951","CVE-2026-33986","CVE-2026-55191","CVE-2026-31883","CVE-2026-29774","CVE-2026-55193","CVE-2026-57156","CVE-2026-33987","CVE-2026-31884","CVE-2026-55827","CVE-2026-33983","CVE-2026-33985","CVE-2026-44421","CVE-2026-33982","CVE-2026-29776","CVE-2026-33977","CVE-2026-55564","CVE-2026-40033","CVE-2026-31885"]}]},{"id":"CVE-2026-55827","published":"2026-07-10T20:16:00","updated_at":"2026-07-20T18:01:27.398901+00:00","description":"\nFreeRDP is a free implementation of the Remote Desktop Protocol. Prior to\n3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx\noption pass desktop stride and height to RemoteFX decoding for Cache Bitmap\nV3 data while allocating bitmap->data only for the smaller DstWidth and\nDstHeight in gdi_Bitmap_Decompress, allowing a malicious RDP server to\ntrigger a heap out-of-bounds write with attacker-controlled offset and\ncontent. This issue is fixed in version 3.27.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55827","https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c495-h83v-3prp","https://ubuntu.com/security/notices/USN-8561-1"],"bugs":[""],"patches":{"freerdp":[],"freerdp2":[],"freerdp3":[]},"tags":{},"packages":[{"name":"freerdp","source":"https://ubuntu.com/security/cve?package=freerdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp","debian":"https://tracker.debian.org/pkg/freerdp","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp2","source":"https://ubuntu.com/security/cve?package=freerdp2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp2","debian":"https://tracker.debian.org/pkg/freerdp2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp3","source":"https://ubuntu.com/security/cve?package=freerdp3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp3","debian":"https://tracker.debian.org/pkg/freerdp3","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.27.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.30.0+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.30.0+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8561-1"],"notices":[{"id":"USN-8561-1","title":"FreeRDP vulnerabilities","summary":"Several security issues were fixed in FreeRDP.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-20T11:49:26.882744","description":"It was discovered that FreeRDP contained multiple security issues. An\nattacker could possibly use these issues to obtain sensitive information,\ncause FreeRDP to crash, resulting in a denial of service, or execute\narbitrary code.","is_hidden":false,"release_packages":{"noble":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"freerdp3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","description":"RDP client for Windows Terminal Services","is_source":true},{"name":"freerdp-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-proxy-modules","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-sdl","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-shadow-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-wayland","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"freerdp3-x11","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-client3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server-proxy3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-server3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow-subsystem3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp-shadow3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libfreerdp3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr-tools3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-3","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwinpr3-dev","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"},{"name":"winpr3-utils","version":"3.30.0+dfsg-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freerdp3","version_link":"https://launchpad.net/ubuntu/+source/freerdp3/3.30.0+dfsg-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-33995","CVE-2026-57157","CVE-2026-33952","CVE-2026-55648","CVE-2026-44422","CVE-2026-55194","CVE-2026-29775","CVE-2026-40254","CVE-2026-55192","CVE-2026-33984","CVE-2026-31897","CVE-2026-44420","CVE-2026-31806","CVE-2026-56297","CVE-2026-57158","CVE-2026-27951","CVE-2026-33986","CVE-2026-55191","CVE-2026-31883","CVE-2026-29774","CVE-2026-55193","CVE-2026-57156","CVE-2026-33987","CVE-2026-31884","CVE-2026-55827","CVE-2026-33983","CVE-2026-33985","CVE-2026-44421","CVE-2026-33982","CVE-2026-29776","CVE-2026-33977","CVE-2026-55564","CVE-2026-40033","CVE-2026-31885"]}]},{"id":"CVE-2026-53450","published":"2026-07-10T19:17:00","updated_at":"2026-07-16T10:55:55.253395+00:00","description":"\nCoturn is a free open source implementation of TURN and STUN Server. Prior\nto 4.13.0, coturn rejects loopback peers by default unless\nallow-loopback-peers is enabled, but the default loopback guard can be\nbypassed by using the IPv4-mapped IPv6 peer address ::ffff:127.0.0.1 in a\nTURN XOR-PEER-ADDRESS attribute. ioa_addr_is_loopback checks for the\nliteral IPv6 loopback shape before IPv4-mapped IPv6 handling, so\ngood_peer_addr does not apply the default loopback rejection and an\nauthenticated TURN client can expose services bound only to localhost on\nthe coturn host through TURN relay traffic. This issue is fixed in version\n4.13.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53450","https://github.com/coturn/coturn/security/advisories/GHSA-w4hf-cr3w-6h79","https://github.com/coturn/coturn/commit/b057acbebe721c8f2f202ddad5e16289e295c754"],"bugs":[""],"patches":{"coturn":[]},"tags":{},"packages":[{"name":"coturn","source":"https://ubuntu.com/security/cve?package=coturn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=coturn","debian":"https://tracker.debian.org/pkg/coturn","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53449","published":"2026-07-10T19:17:00","updated_at":"2026-07-16T10:55:55.253395+00:00","description":"\nCoturn is a free open source implementation of TURN and STUN Server. Prior\nto 4.13.0, the psd print sessions dump CLI command in coturn takes a\nfilename argument and directly passes it to fopen with no path validation.\nAn authenticated admin with CLI access can overwrite arbitrary files\nwritable by the coturn process because the command string is used as-is\nafter stripping the psd prefix and leading spaces, allowing truncation and\noverwrite with session dump data. This issue is fixed in version 4.13.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53449","https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r","https://github.com/coturn/coturn/commit/e72930f571beba3bc7a9f97661af2614aae92a55","https://github.com/coturn/coturn/releases/tag/4.13.0"],"bugs":[""],"patches":{"coturn":[]},"tags":{},"packages":[{"name":"coturn","source":"https://ubuntu.com/security/cve?package=coturn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=coturn","debian":"https://tracker.debian.org/pkg/coturn","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53448","published":"2026-07-10T19:17:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nCoturn is a free open source implementation of TURN and STUN Server. Prior\nto 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters\ndirectly into SQL queries via snprintf string interpolation without\nsanitization. The is_secure_string filter that protects the STUN protocol\npath is not applied to the admin panel's delete-user, delete-secret, and\ndelete-IP operations, so an authenticated admin can inject arbitrary SQL\nthrough the du, ds, and dip parameters, gaining full database control and\npotentially OS-level access via PostgreSQL COPY TO PROGRAM. This issue is\nfixed in version 4.12.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53448","https://github.com/coturn/coturn/security/advisories/GHSA-v8hj-2xx7-xmp5","https://github.com/coturn/coturn/pull/1924","https://github.com/coturn/coturn/commit/b84dbab1d1aa6e2bf0211a1cdbb250d6de2a0d09","https://github.com/coturn/coturn/releases/tag/4.12.0"],"bugs":[""],"patches":{"coturn":[]},"tags":{},"packages":[{"name":"coturn","source":"https://ubuntu.com/security/cve?package=coturn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=coturn","debian":"https://tracker.debian.org/pkg/coturn","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15146","published":"2026-07-10T19:17:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nGNU Wget does not validate the IP address provided by an FTP PASV response\nwhile operating in FTP passive mode. A malicious FTP server, or an HTTP\nserver that redirects to an FTP URL, can exploit this behavior to redirect\nWget’s data connection to an arbitrary IP address and port. This allows an\nattacker to forge server-side requests (SSRF) from the machine running\nWget, potentially accessing localhost services or internal network\nresources.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15146","https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b","https://kb.cert.org/vuls/id/564823","https://www.kb.cert.org/vuls/id/564823","https://ubuntu.com/security/notices/USN-8572-1"],"bugs":[""],"patches":{"wget":["upstream: https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"upstream","status":"released","description":"1.25.0-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.19.4-1ubuntu2.2+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.20.3-1ubuntu2.1+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1.21.2-2ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.21.4-1ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.25.0-2ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.15-1ubuntu1.14.04.5+esm3","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.17.1-1ubuntu1.5+esm4","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8572-1"],"notices":[{"id":"USN-8572-1","title":"Wget vulnerability","summary":"Wget could be made to connect to unintended network resources.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:12:11.497645","description":"It was discovered that Wget did not properly validate the IP address\nprovided in an FTP PASV response when operating in FTP passive mode. A\nremote attacker controlling a malicious FTP server, or an HTTP server\nthat redirects to an FTP URL, could possibly use this issue to redirect\nWget's data connection to an arbitrary address and perform server-side\nrequest forgery, potentially accessing localhost services or internal\nnetwork resources.","is_hidden":false,"release_packages":{"bionic":[{"name":"wget","version":"1.19.4-1ubuntu2.2+esm4","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.19.4-1ubuntu2.2+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"wget","version":"1.20.3-1ubuntu2.1+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.20.3-1ubuntu2.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"wget","version":"1.21.2-2ubuntu1.4","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.2-2ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.4","pocket":"security"}],"noble":[{"name":"wget","version":"1.21.4-1ubuntu4.4","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.4-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.4","pocket":"security"}],"resolute":[{"name":"wget","version":"1.25.0-2ubuntu4.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.25.0-2ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.3","pocket":"security"}],"trusty":[{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"wget","version":"1.17.1-1ubuntu1.5+esm4","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.17.1-1ubuntu1.5+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-15146"]}]},{"id":"CVE-2026-59180","published":"2026-07-10T17:17:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nApprise is an open source library which allows you to send a notification\nto almost all of the most popular notification services available. Prior to\n1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and\nconfig loaders in apprise/attachment/http.py and apprise/config/http.py\nfollow HTTP redirects by default and resend user-configured auth headers\nand query parameters on the redirected request, allowing a compromised\ntrusted destination or on-path attacker to receive secrets such as\nAuthorization headers, bearer tokens, custom headers, and service keys.\nThis issue is fixed in version 1.11.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59180","https://github.com/caronc/apprise/security/advisories/GHSA-856c-92hv-3vxx","https://github.com/caronc/apprise/pull/1610","https://github.com/caronc/apprise/commit/68c0aef218055e4586cf4605fd6b56358f5f462d","https://github.com/caronc/apprise/releases/tag/v1.11.0"],"bugs":[""],"patches":{"apprise":[]},"tags":{},"packages":[{"name":"apprise","source":"https://ubuntu.com/security/cve?package=apprise","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apprise","debian":"https://tracker.debian.org/pkg/apprise","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.11.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7780,"limit":20,"total_results":79316}