{"cves":[{"id":"CVE-2026-53589","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:47:02.086063+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53589"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53588","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:47:31.710291+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53588"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49863","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49863"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49862","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49862"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49861","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49861"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45098","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45098"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45097","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45097"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45096","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45096"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45095","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45095"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45094","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45094"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45093","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45093"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45092","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45092"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-3886","published":"2026-07-09T00:00:00","updated_at":"2026-08-27T21:25:51.506701+00:00","description":"\n[virtio-gpu: fix overflow check when allocating 2d image]","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nVulnerability allows for VM escape"},{"author":"mdeslaur","note":"introduced in 8.1.0 by:\nhttps://gitlab.com/qemu-project/qemu/-/commit/9462ff4695aa0d086fd63f7f2efafe5a05f2a243"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-3886"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/2162697"],"patches":{"qemu":["upstream: https://gitlab.com/qemu-project/qemu/-/commit/c035d5eadf400670593a76778f98f052d7482968"],"qemu-hwe":[]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:6.2+dfsg-2ubuntu6.31","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"qemu-hwe","source":"https://ubuntu.com/security/cve?package=qemu-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-hwe","debian":"https://tracker.debian.org/pkg/qemu-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-12590","published":"2026-07-09T00:00:00","updated_at":"2026-07-09T15:15:31.546634+00:00","description":"\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x\nline), when the parser is configured with an invalid limit option value\nsuch as an unparseable string or NaN, bytes.parse returns null and the\nrequest body size check is silently skipped. Applications that rely on\nlimit as their primary safeguard against oversized request bodies will\naccept arbitrarily large payloads, leading to excessive memory and CPU\nusage and denial of service. Patches: This issue is fixed in body-parser\n1.20.6 and 2.3.0. After the fix, invalid limit values throw a clear error\nat parser construction time instead of silently disabling enforcement,\nwhile null and undefined continue to fall back to the default limit of\n100kb. Workarounds: Validate the limit value before passing it to\nbody-parser. For example, parse the value at startup and reject any\nconfiguration where the result is null or a non-finite number.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-12590","https://cna.openjsf.org/security-advisories.html","https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6"],"bugs":[""],"patches":{"node-body-parser":[]},"tags":{},"packages":[{"name":"node-body-parser","source":"https://ubuntu.com/security/cve?package=node-body-parser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-body-parser","debian":"https://tracker.debian.org/pkg/node-body-parser","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15105","published":"2026-07-08T23:16:00","updated_at":"2026-08-07T16:52:48.382182+00:00","description":"\nA flaw has been found in davenardella snap7 up to 1.4.3. This affects the\nfunction TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp\nof the component ReadVar Request Handler. This manipulation causes\nout-of-bounds write. The attack requires access to the local network. The\nexploit has been published and may be used. The project was informed of the\nproblem early through an issue report but has not responded yet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15105","https://github.com/davenardella/snap7/","https://github.com/davenardella/snap7/issues/16","https://github.com/user-attachments/files/28681740/poc.zip","https://vuldb.com/cve/CVE-2026-15105","https://vuldb.com/submit/851026","https://vuldb.com/vuln/376946","https://vuldb.com/vuln/376946/cti"],"bugs":[""],"patches":{"snap7":[]},"tags":{},"packages":[{"name":"snap7","source":"https://ubuntu.com/security/cve?package=snap7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snap7","debian":"https://tracker.debian.org/pkg/snap7","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-39179","published":"2026-07-08T22:17:00","updated_at":"2026-07-16T10:54:18.822095+00:00","description":"\nA SQL injection vulnerability in SOGo before 5.12.7 allows authenticated\nusers to execute arbitrary SQL statements via the newPassword parameter in\nthe password change functionality.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39179","https://github.com/Alinto/sogo/commit/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21","https://www.sogo.nu/news/2026/sogo-v5127-released.html"],"bugs":[""],"patches":{"sogo":[]},"tags":{},"packages":[{"name":"sogo","source":"https://ubuntu.com/security/cve?package=sogo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sogo","debian":"https://tracker.debian.org/pkg/sogo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-39178","published":"2026-07-08T22:17:00","updated_at":"2026-07-16T10:55:01.493164+00:00","description":"\nA SQL injection vulnerability in SOGo before 5.12.7 allows authenticated\nusers to execute arbitrary SQL statements via the search parameter of the\nallContactSearch endpoint.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39178","https://github.com/Alinto/sogo/commit/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21","https://www.sogo.nu/news/2026/sogo-v5127-released.html"],"bugs":[""],"patches":{"sogo":[]},"tags":{},"packages":[{"name":"sogo","source":"https://ubuntu.com/security/cve?package=sogo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sogo","debian":"https://tracker.debian.org/pkg/sogo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15168","published":"2026-07-08T22:17:00","updated_at":"2026-07-16T10:55:01.493164+00:00","description":"\nBLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows\npossible information disclosure","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15168"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10037","published":"2026-07-08T21:18:56","updated_at":"2026-07-16T10:54:41.070484+00:00","description":"\nA sandbox escape vulnerability exists in the OpenJDK packages provided in\nUbuntu. The .jar MIME handlers installed by these packages execute files\nmarked as executable when the mailcap package is installed. A compromised\nor malicious sandboxed application with access to the OpenURI portal via\nxdg-desktop-portal-gtk can write a malicious .jar file to the host file\nsystem, set its executable bit, and trigger the handler to execute\narbitrary code outside of the sandbox environment.","ubuntu_description":"","notes":[{"author":"federicoquattrin","note":"The mailcap package has been updated to block jar file execution.\nThis make the openjdk packages not vulnerable to this issue."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10037","https://bugs.launchpad.net/ubuntu/+source/openjdk-25/+bug/2153100","https://ubuntu.com/security/notices/USN-8518-1"],"bugs":[""],"patches":{"mailcap":[],"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[],"openjdk-13":[],"openjdk-16":[],"openjdk-17":[],"openjdk-17-crac":[],"openjdk-18":[],"openjdk-21":[],"openjdk-21-crac":[],"openjdk-25":[]},"tags":{},"packages":[{"name":"mailcap","source":"https://ubuntu.com/security/cve?package=mailcap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mailcap","debian":"https://tracker.debian.org/pkg/mailcap","statuses":[{"release_codename":"jammy","status":"released","description":"3.70+nmu1ubuntu1.22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.70+nmu1ubuntu1.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.74ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.75ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"no longer supported by upstream","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-13","source":"https://ubuntu.com/security/cve?package=openjdk-13","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-13","debian":"https://tracker.debian.org/pkg/openjdk-13","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-16","source":"https://ubuntu.com/security/cve?package=openjdk-16","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-16","debian":"https://tracker.debian.org/pkg/openjdk-16","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-17","source":"https://ubuntu.com/security/cve?package=openjdk-17","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-17","debian":"https://tracker.debian.org/pkg/openjdk-17","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-17-crac","source":"https://ubuntu.com/security/cve?package=openjdk-17-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-17-crac","debian":"https://tracker.debian.org/pkg/openjdk-17-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-18","source":"https://ubuntu.com/security/cve?package=openjdk-18","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-18","debian":"https://tracker.debian.org/pkg/openjdk-18","statuses":[{"release_codename":"jammy","status":"ignored","description":"superseded by openjdk-19","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-21","source":"https://ubuntu.com/security/cve?package=openjdk-21","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-21","debian":"https://tracker.debian.org/pkg/openjdk-21","statuses":[{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-21-crac","source":"https://ubuntu.com/security/cve?package=openjdk-21-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-21-crac","debian":"https://tracker.debian.org/pkg/openjdk-21-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjdk-25","source":"https://ubuntu.com/security/cve?package=openjdk-25","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-25","debian":"https://tracker.debian.org/pkg/openjdk-25","statuses":[{"release_codename":"jammy","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"mailcap update prevents it","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8518-1"],"notices":[{"id":"USN-8518-1","title":"mailcap vulnerability","summary":"mailcap could allow applications to escape sandbox restrictions","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T17:15:41.206551","description":"Aaron Rainbolt discovered that the cautious-launcher utility in the\nmailcap package did not properly restrict the execution of certain\nfile types. An attacker could use this issue to escape a sandboxed\napplication and execute arbitrary code on the host operating system.","is_hidden":false,"release_packages":{"jammy":[{"name":"mailcap","version":"3.70+nmu1ubuntu1.22.04.1","description":"Debian's mailcap system, and support programs","is_source":true},{"name":"mailcap","version":"3.70+nmu1ubuntu1.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailcap","version_link":"https://launchpad.net/ubuntu/+source/mailcap/3.70+nmu1ubuntu1.22.04.1","pocket":"security"}],"noble":[{"name":"mailcap","version":"3.70+nmu1ubuntu1.24.04.1","description":"Debian's mailcap system, and support programs","is_source":true},{"name":"mailcap","version":"3.70+nmu1ubuntu1.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailcap","version_link":"https://launchpad.net/ubuntu/+source/mailcap/3.70+nmu1ubuntu1.24.04.1","pocket":"security"}],"questing":[{"name":"mailcap","version":"3.74ubuntu1.1","description":"Debian's mailcap system, and support programs","is_source":true},{"name":"mailcap","version":"3.74ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailcap","version_link":"https://launchpad.net/ubuntu/+source/mailcap/3.74ubuntu1.1","pocket":"security"}],"resolute":[{"name":"mailcap","version":"3.75ubuntu1.1","description":"Debian's mailcap system, and support programs","is_source":true},{"name":"mailcap","version":"3.75ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailcap","version_link":"https://launchpad.net/ubuntu/+source/mailcap/3.75ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-10037"]}]},{"id":"CVE-2026-8472","published":"2026-07-08T21:16:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under\ncertain conditions could have allowed an authenticated user with minimal\naccess permissions to read work item metadata from private projects due to\nmissing authorization checks.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8472"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7840,"limit":20,"total_results":79316}