{"cves":[{"id":"CVE-2026-59997","published":"2026-07-08T01:16:00","updated_at":"2026-07-13T14:06:29.239996+00:00","description":"\ninternal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9\ncommand-line arguments, which can be important if a later command-line\nargument would have helped to ensure the intended security properties of an\nSFTP connection.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."}],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59997","https://www.openssh.org/releasenotes.html#10.4p1","https://ubuntu.com/security/notices/USN-8533-1"],"bugs":[""],"patches":{"openssh":["upstream: https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014"],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.16","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.18","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:10.2p1-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:10.4p1-1","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8533-1"],"notices":[{"id":"USN-8533-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-13T13:07:08.062444","description":"It was discovered that OpenSSH sftp did not properly constrain the location\nof downloaded files when connecting to an attacker-controlled server. An\nattacker could possibly use this issue to write files to unintended\nlocations on the file system. (CVE-2026-59995)\n\nIt was discovered that OpenSSH scp could place files in the parent\ndirectory of the intended destination when copying between two remote\nhosts. An attacker could possibly use this issue to write files to\nunintended locations. (CVE-2026-59996)\n\nIt was discovered that OpenSSH internal-sftp only recognized the first nine\ncommand-line arguments, This could result in certain security-sensitive\narguments being ignored, contrary to expectations. (CVE-2026-59997)\n\nIt was discovered that OpenSSH had undocumented behaviour regarding the\nGSSAPIStrictAcceptorCheck option in environments using Windows Active\nDirectory. The documentation has been updated to clarify use of the option.\n(CVE-2026-59998)\n\nIt was discovered that OpenSSH did not properly enforce precedence of\nDisableForwarding=yes over PermitTunnel=yes in server configurations. This\ncould possibly result in intended network forwarding restrictions being\nbypassed, contrary to expectations. (CVE-2026-59999)\n\nIt was discovered that OpenSSH mishandled the MaxAuthTries limit for GSSAPI\nauthentication. A remote attacker could use this issue to perform excessive\nauthentication attempts. (CVE-2026-60000)\n\nIt was discovered that OpenSSH did not always honour the minimum\nauthentication delay. An attacker could possibly use this issue to perform\nbrute-force attacks more efficiently. (CVE-2026-60001)\n\nIt was discovered that the OpenSSH client had a use-after-free\nvulnerability when a server changed its host key during a key re-exchange.\nAn attacker able to intercept communications could possibly use this issue\nto execute arbitrary code or obtain sensitive information. (CVE-2026-60002)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.16","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.18","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"}],"resolute":[{"name":"openssh","version":"1:10.2p1-2ubuntu3.4","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-server","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-tests","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"ssh","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60001","CVE-2026-60002","CVE-2026-59998","CVE-2026-59997","CVE-2026-59999","CVE-2026-59995","CVE-2026-59996","CVE-2026-60000"]}]},{"id":"CVE-2026-59996","published":"2026-07-08T01:16:00","updated_at":"2026-07-13T14:06:29.239996+00:00","description":"\nscp in OpenSSH before 10.4 may place a file in the parent directory of an\nintended directory when the copy occurs between two remote destinations.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."}],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59996","https://www.openssh.org/releasenotes.html#10.4p1","https://ubuntu.com/security/notices/USN-8533-1"],"bugs":[""],"patches":{"openssh":["upstream: https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78"],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.16","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.18","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:10.2p1-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:10.4p1-1","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8533-1"],"notices":[{"id":"USN-8533-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-13T13:07:08.062444","description":"It was discovered that OpenSSH sftp did not properly constrain the location\nof downloaded files when connecting to an attacker-controlled server. An\nattacker could possibly use this issue to write files to unintended\nlocations on the file system. (CVE-2026-59995)\n\nIt was discovered that OpenSSH scp could place files in the parent\ndirectory of the intended destination when copying between two remote\nhosts. An attacker could possibly use this issue to write files to\nunintended locations. (CVE-2026-59996)\n\nIt was discovered that OpenSSH internal-sftp only recognized the first nine\ncommand-line arguments, This could result in certain security-sensitive\narguments being ignored, contrary to expectations. (CVE-2026-59997)\n\nIt was discovered that OpenSSH had undocumented behaviour regarding the\nGSSAPIStrictAcceptorCheck option in environments using Windows Active\nDirectory. The documentation has been updated to clarify use of the option.\n(CVE-2026-59998)\n\nIt was discovered that OpenSSH did not properly enforce precedence of\nDisableForwarding=yes over PermitTunnel=yes in server configurations. This\ncould possibly result in intended network forwarding restrictions being\nbypassed, contrary to expectations. (CVE-2026-59999)\n\nIt was discovered that OpenSSH mishandled the MaxAuthTries limit for GSSAPI\nauthentication. A remote attacker could use this issue to perform excessive\nauthentication attempts. (CVE-2026-60000)\n\nIt was discovered that OpenSSH did not always honour the minimum\nauthentication delay. An attacker could possibly use this issue to perform\nbrute-force attacks more efficiently. (CVE-2026-60001)\n\nIt was discovered that the OpenSSH client had a use-after-free\nvulnerability when a server changed its host key during a key re-exchange.\nAn attacker able to intercept communications could possibly use this issue\nto execute arbitrary code or obtain sensitive information. (CVE-2026-60002)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.16","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.18","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"}],"resolute":[{"name":"openssh","version":"1:10.2p1-2ubuntu3.4","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-server","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-tests","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"ssh","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60001","CVE-2026-60002","CVE-2026-59998","CVE-2026-59997","CVE-2026-59999","CVE-2026-59995","CVE-2026-59996","CVE-2026-60000"]}]},{"id":"CVE-2026-59995","published":"2026-07-08T01:16:00","updated_at":"2026-07-13T14:06:29.239996+00:00","description":"\nsftp in OpenSSH before 10.4 does not properly constrain the location of\ndownloaded files when \"sftp server:/path .\" is used with an\nattacker-controlled server.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."}],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59995","https://www.openssh.org/releasenotes.html#10.4p1","https://ubuntu.com/security/notices/USN-8533-1"],"bugs":[""],"patches":{"openssh":["upstream: https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b"],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.16","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.18","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:10.2p1-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:10.4p1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8533-1"],"notices":[{"id":"USN-8533-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-13T13:07:08.062444","description":"It was discovered that OpenSSH sftp did not properly constrain the location\nof downloaded files when connecting to an attacker-controlled server. An\nattacker could possibly use this issue to write files to unintended\nlocations on the file system. (CVE-2026-59995)\n\nIt was discovered that OpenSSH scp could place files in the parent\ndirectory of the intended destination when copying between two remote\nhosts. An attacker could possibly use this issue to write files to\nunintended locations. (CVE-2026-59996)\n\nIt was discovered that OpenSSH internal-sftp only recognized the first nine\ncommand-line arguments, This could result in certain security-sensitive\narguments being ignored, contrary to expectations. (CVE-2026-59997)\n\nIt was discovered that OpenSSH had undocumented behaviour regarding the\nGSSAPIStrictAcceptorCheck option in environments using Windows Active\nDirectory. The documentation has been updated to clarify use of the option.\n(CVE-2026-59998)\n\nIt was discovered that OpenSSH did not properly enforce precedence of\nDisableForwarding=yes over PermitTunnel=yes in server configurations. This\ncould possibly result in intended network forwarding restrictions being\nbypassed, contrary to expectations. (CVE-2026-59999)\n\nIt was discovered that OpenSSH mishandled the MaxAuthTries limit for GSSAPI\nauthentication. A remote attacker could use this issue to perform excessive\nauthentication attempts. (CVE-2026-60000)\n\nIt was discovered that OpenSSH did not always honour the minimum\nauthentication delay. An attacker could possibly use this issue to perform\nbrute-force attacks more efficiently. (CVE-2026-60001)\n\nIt was discovered that the OpenSSH client had a use-after-free\nvulnerability when a server changed its host key during a key re-exchange.\nAn attacker able to intercept communications could possibly use this issue\nto execute arbitrary code or obtain sensitive information. (CVE-2026-60002)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.16","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.18","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18","pocket":"security"}],"resolute":[{"name":"openssh","version":"1:10.2p1-2ubuntu3.4","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-server","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"openssh-tests","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"ssh","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.2p1-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60001","CVE-2026-60002","CVE-2026-59998","CVE-2026-59997","CVE-2026-59999","CVE-2026-59995","CVE-2026-59996","CVE-2026-60000"]}]},{"id":"CVE-2026-50811","published":"2026-07-07T23:16:00","updated_at":"2026-07-20T18:03:47.709846+00:00","description":"\nAn out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions\nbefore commit 5a280ecde6f324de0d226261036e736e0cb49a71 in\nsrc/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by\nFT_Get_Var_Design_Coordinates","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"per Debian, this issue was introduced in 2.14.0 by this:\nhttps://gitlab.freedesktop.org/freetype/freetype/-/commit/f64c7db2fee3f5304df1cd722df72699736118f3"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50811","https://gitlab.freedesktop.org/freetype/freetype/-/merge_requests/432","https://ubuntu.com/security/notices/USN-8562-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141704","https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436"],"patches":{"freetype":["upstream: https://gitlab.freedesktop.org/freetype/freetype/-/commit/5a280ecde6f324de0d226261036e736e0cb49a71","upstream: https://gitlab.freedesktop.org/freetype/freetype/-/commit/8fa928f1617aba65f45b00f0dcb109f077b7741e"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.14.2+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]}],"notices_ids":["USN-8562-1"],"notices":[{"id":"USN-8562-1","title":"FreeType vulnerability","summary":"FreeType could be made to crash if it opened a specially crafted file.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T11:59:08.525730","description":"It was discovered that FreeType incorrectly handled certain variable font\nfiles. An attacker could possibly use this issue to cause FreeType to\ncrash, resulting in a denial of service, or obtain sensitive information.","is_hidden":false,"release_packages":{"resolute":[{"name":"freetype","version":"2.14.2+dfsg-1ubuntu0.1","description":"FreeType 2 is a font engine library","is_source":true},{"name":"freetype2-demos","version":"2.14.2+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.14.2+dfsg-1ubuntu0.1","pocket":"security"},{"name":"freetype2-doc","version":"2.14.2+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.14.2+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libfreetype-dev","version":"2.14.2+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.14.2+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libfreetype6","version":"2.14.2+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.14.2+dfsg-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-50811"]}]},{"id":"CVE-2026-50810","published":"2026-07-07T23:16:00","updated_at":"2026-07-16T10:53:55.672417+00:00","description":"\nA NULL pointer dereference in smooth_parse_stream_index() in\nsrc/media_tools/mpd.c in GPAC master HEAD before commit\nb35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial\nof service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50810","https://gist.github.com/junius-sec/0c67bf67a268ff8861100bfc132e801c","https://github.com/gpac/gpac/commit/b35c61f104b85fbb16520ac2838d5d2ef70845b5","https://github.com/gpac/gpac/issues/3507"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14895","published":"2026-07-07T23:16:00","updated_at":"2026-07-09T15:14:49.465585+00:00","description":"\nString::Util versions before 1.36 for Perl are susceptible to a regular\nexpression denial of service.\nThe trim and rtrim functions stripped trailing whitespace with s/\\s*$//u.\nBecause \\s* matches greedily and the $ anchor fails whenever a\nnon-whitespace character follows the whitespace, the regex engine retries\nthe match at each offset of a long whitespace run, producing quadratic\nbacktracking. The fix replaces \\s*$ with \\s+$.\nAny caller that passes untrusted input to trim or rtrim can trigger CPU\nexhaustion with a string containing a long run of whitespace.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14895","https://lists.security.metacpan.org/cve-announce/msg/41625636/"],"bugs":[""],"patches":{"libstring-util-perl":[]},"tags":{},"packages":[{"name":"libstring-util-perl","source":"https://ubuntu.com/security/cve?package=libstring-util-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstring-util-perl","debian":"https://tracker.debian.org/pkg/libstring-util-perl","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.36-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14740","published":"2026-07-07T23:16:00","updated_at":"2026-07-09T15:15:31.546634+00:00","description":"\nDBI versions before 1.650 for Perl read one byte out-of-bounds in preparse\nwhen deleting an initial SQL comment.\nThe preparse method normalises SQL and removes comments. When the SQL\nstarts with a comment line, the deletion of that line during normalisation\nled to an out-of-bounds read by one byte. The result is a fault on\nmemory-hardened builds and nondeterministic newline retention on normal\nbuilds.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14740","https://lists.security.metacpan.org/cve-announce/msg/41625532/","https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141667"],"patches":{"libdbi-perl":[]},"tags":{},"packages":[{"name":"libdbi-perl","source":"https://ubuntu.com/security/cve?package=libdbi-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libdbi-perl","debian":"https://tracker.debian.org/pkg/libdbi-perl","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.650-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14739","published":"2026-07-07T23:16:00","updated_at":"2026-07-09T15:15:31.546634+00:00","description":"\nDBI versions before 1.650 for Perl have a heap overflow when preparsing SQL\nstatements with an extreme number of placeholders.\nThe fix for CVE-2026-10879 did not allocate enough memory to handle\napproximately 1.2-million placeholders.\nDBI version 1.650 sets a hard limit of 99,999 placeholders.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14739","https://lists.security.metacpan.org/cve-announce/msg/41625530/"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141667"],"patches":{"libdbi-perl":[]},"tags":{},"packages":[{"name":"libdbi-perl","source":"https://ubuntu.com/security/cve?package=libdbi-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libdbi-perl","debian":"https://tracker.debian.org/pkg/libdbi-perl","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.650-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14380","published":"2026-07-07T23:16:00","updated_at":"2026-07-10T19:29:10.444716+00:00","description":"\nDBI versions before 1.650 for Perl are vulnerable to code injection via\ncaller-influenced Profile.\nWhen a string is assigned to a DBI handle's Profile attribute, DBI splits\nit into path, package and arguments, and interpolates the package part in a\nstring eval with no validation of the package name.\nAny caller-influenced value that reaches the Profile attribute is therefore\narbitrary Perl code execution, including calls to run system commands.\nThe Profile attribute can be set from three different sources that can\ncarry untrusted data: the DBI_PROFILE environment variable, a direct\nattribute assignment, and a DSN driver-attribute clause\ndbi:Driver(Profile=>SPEC):db.\nAn attacker controlling any of those inputs runs arbitrary Perl in the host\nprocess. The strongest remote position is a network-exposed DBI::Gofer /\nDBI::ProxyServer whose per-request DSN reaches the Profile attribute,\nletting a client execute code on the broker host.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14380","https://lists.security.metacpan.org/cve-announce/msg/41625527/","https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141667"],"patches":{"libdbi-perl":[]},"tags":{},"packages":[{"name":"libdbi-perl","source":"https://ubuntu.com/security/cve?package=libdbi-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libdbi-perl","debian":"https://tracker.debian.org/pkg/libdbi-perl","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.650-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59153","published":"2026-07-07T22:16:00","updated_at":"2026-07-09T14:47:31.710291+00:00","description":"\nAnki is a program for creating and reviewing flashcards. Prior to 25.09.3,\nAnki launches a local HTTP server to serve media files and web pages for\nparts of its interface, but requests from other origins were not\nsufficiently blocked. A malicious website could potentially trigger\nside-effecting requests to the local server, with severity varying by\nbrowser depending on Private Network Access protections. This issue is\nfixed in version 25.09.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59153","https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g"],"bugs":[""],"patches":{"anki":[]},"tags":{},"packages":[{"name":"anki","source":"https://ubuntu.com/security/cve?package=anki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=anki","debian":"https://tracker.debian.org/pkg/anki","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58266","published":"2026-07-07T22:16:00","updated_at":"2026-07-09T14:46:28.887269+00:00","description":"\nAnki is a program for creating and reviewing flashcards. Prior to 25.09.4,\nAnki's webview-based pages communicate with the Rust backend using an\ninternal localhost API, and user scripts included via iframes in the editor\ncan access this API despite protections intended to block reviewer and\neditor scripts. A malicious imported card package with an embedded iframe\ncan use exposed API methods such as getImageForOcclusion to read arbitrary\nfiles accessible to the Anki process and exfiltrate them over the network.\nThis issue is fixed in version 25.09.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58266","https://github.com/ankitects/anki/security/advisories/GHSA-cw6h-ffmh-x6vh"],"bugs":[""],"patches":{"anki":[]},"tags":{},"packages":[{"name":"anki","source":"https://ubuntu.com/security/cve?package=anki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=anki","debian":"https://tracker.debian.org/pkg/anki","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58472","published":"2026-07-07T21:17:00","updated_at":"2026-07-16T10:24:44.342395+00:00","description":"\nGNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer\noverflow vulnerability in the html_quote_string() function in src/convert.c\nthat allows a remote attacker to trigger memory corruption by supplying a\ncrafted HTML attribute with a large number of characters requiring entity\nencoding. A server-supplied HTML attribute causes a signed integer counter\nto overflow during output size accumulation, resulting in an undersized\nheap allocation and subsequent heap buffer overflow during the copy phase.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58472","https://ubuntu.com/security/notices/USN-8543-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141689"],"patches":{"wget":["upstream: https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.19.4-1ubuntu2.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.20.3-1ubuntu2.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1.21.2-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.21.4-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.25.0-2ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.15-1ubuntu1.14.04.5+esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.17.1-1ubuntu1.5+esm3","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8543-1"],"notices":[{"id":"USN-8543-1","title":"Wget vulnerabilities","summary":"Several security issues were fixed in Wget.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T19:06:42.710588","description":"It was discovered that Wget mishandled semicolons in the userinfo\nsubcomponent of a URL. A remote attacker could possibly use this issue\nto trick a user into connecting to a different host than intended. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)\n\nIt was discovered that Wget incorrectly handled Metalink documents\ncontaining a whitespace-only URL. A remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n26.04 LTS. (CVE-2026-58469)\n\nIt was discovered that Wget incorrectly handled Content-Range header\nvalues, leading to an integer overflow. A remote attacker could\npossibly use this issue to cause download desynchronization.\n(CVE-2026-58470)\n\nIt was discovered that Wget incorrectly handled character set\nconversion of server-supplied filenames. A remote attacker could possibly\nuse this issue to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471)\n\nIt was discovered that Wget incorrectly handled HTML attributes\nrequiring entity encoding. A remote attacker could possibly use this issue\nto cause a denial of service or possibly execute arbitrary code.\n(CVE-2026-58472)","is_hidden":false,"release_packages":{"bionic":[{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"wget","version":"1.21.2-2ubuntu1.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.2-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.3","pocket":"security"}],"noble":[{"name":"wget","version":"1.21.4-1ubuntu4.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.4-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.3","pocket":"security"}],"resolute":[{"name":"wget","version":"1.25.0-2ubuntu4.2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.25.0-2ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.2","pocket":"security"}],"trusty":[{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-58470","CVE-2024-38428","CVE-2026-58472","CVE-2026-58469","CVE-2026-58471"]}]},{"id":"CVE-2026-58471","published":"2026-07-07T21:17:00","updated_at":"2026-07-16T10:24:44.342395+00:00","description":"\nGNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer\noverflow vulnerability in the convert_fname() function within src/url.c\nthat allows remote attackers to trigger memory corruption through a\nserver-supplied filename requiring character set conversion. When the\noutput buffer is too small during iconv E2BIG reallocation, the\nreallocation logic miscalculates the remaining space, leading to a heap\nbuffer overflow that can be exploited via a maliciously crafted server\nresponse.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58471","https://ubuntu.com/security/notices/USN-8543-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141689"],"patches":{"wget":["upstream: https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.19.4-1ubuntu2.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.20.3-1ubuntu2.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.21.2-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.21.4-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.25.0-2ubuntu4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8543-1"],"notices":[{"id":"USN-8543-1","title":"Wget vulnerabilities","summary":"Several security issues were fixed in Wget.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T19:06:42.710588","description":"It was discovered that Wget mishandled semicolons in the userinfo\nsubcomponent of a URL. A remote attacker could possibly use this issue\nto trick a user into connecting to a different host than intended. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)\n\nIt was discovered that Wget incorrectly handled Metalink documents\ncontaining a whitespace-only URL. A remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n26.04 LTS. (CVE-2026-58469)\n\nIt was discovered that Wget incorrectly handled Content-Range header\nvalues, leading to an integer overflow. A remote attacker could\npossibly use this issue to cause download desynchronization.\n(CVE-2026-58470)\n\nIt was discovered that Wget incorrectly handled character set\nconversion of server-supplied filenames. A remote attacker could possibly\nuse this issue to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471)\n\nIt was discovered that Wget incorrectly handled HTML attributes\nrequiring entity encoding. A remote attacker could possibly use this issue\nto cause a denial of service or possibly execute arbitrary code.\n(CVE-2026-58472)","is_hidden":false,"release_packages":{"bionic":[{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"wget","version":"1.21.2-2ubuntu1.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.2-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.3","pocket":"security"}],"noble":[{"name":"wget","version":"1.21.4-1ubuntu4.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.4-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.3","pocket":"security"}],"resolute":[{"name":"wget","version":"1.25.0-2ubuntu4.2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.25.0-2ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.2","pocket":"security"}],"trusty":[{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-58470","CVE-2024-38428","CVE-2026-58472","CVE-2026-58469","CVE-2026-58471"]}]},{"id":"CVE-2026-58470","published":"2026-07-07T21:17:00","updated_at":"2026-07-16T10:24:44.342395+00:00","description":"\nGNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer\noverflow vulnerability in the parse_content_range() function within\nsrc/http.c that allows server-controlled values to cause signed integer\narithmetic to overflow. Attackers can supply malicious Content-Range header\nvalues to trigger undefined behavior and download desynchronization in the\naffected client.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58470","https://ubuntu.com/security/notices/USN-8543-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141689"],"patches":{"wget":["upstream: https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.19.4-1ubuntu2.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.20.3-1ubuntu2.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1.21.2-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.21.4-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.25.0-2ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.15-1ubuntu1.14.04.5+esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.17.1-1ubuntu1.5+esm3","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8543-1"],"notices":[{"id":"USN-8543-1","title":"Wget vulnerabilities","summary":"Several security issues were fixed in Wget.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T19:06:42.710588","description":"It was discovered that Wget mishandled semicolons in the userinfo\nsubcomponent of a URL. A remote attacker could possibly use this issue\nto trick a user into connecting to a different host than intended. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)\n\nIt was discovered that Wget incorrectly handled Metalink documents\ncontaining a whitespace-only URL. A remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n26.04 LTS. (CVE-2026-58469)\n\nIt was discovered that Wget incorrectly handled Content-Range header\nvalues, leading to an integer overflow. A remote attacker could\npossibly use this issue to cause download desynchronization.\n(CVE-2026-58470)\n\nIt was discovered that Wget incorrectly handled character set\nconversion of server-supplied filenames. A remote attacker could possibly\nuse this issue to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471)\n\nIt was discovered that Wget incorrectly handled HTML attributes\nrequiring entity encoding. A remote attacker could possibly use this issue\nto cause a denial of service or possibly execute arbitrary code.\n(CVE-2026-58472)","is_hidden":false,"release_packages":{"bionic":[{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"wget","version":"1.21.2-2ubuntu1.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.2-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.3","pocket":"security"}],"noble":[{"name":"wget","version":"1.21.4-1ubuntu4.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.4-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.3","pocket":"security"}],"resolute":[{"name":"wget","version":"1.25.0-2ubuntu4.2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.25.0-2ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.2","pocket":"security"}],"trusty":[{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-58470","CVE-2024-38428","CVE-2026-58472","CVE-2026-58469","CVE-2026-58471"]}]},{"id":"CVE-2026-58469","published":"2026-07-07T21:17:00","updated_at":"2026-07-16T10:24:44.342395+00:00","description":"\nGNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer\nunderread vulnerability in the clean_metalink_string() function within\nsrc/metalink.c that allows a malicious server to trigger memory corruption\nby serving a Metalink document containing a whitespace-only URL. Attackers\ncan cause the function to decrement a pointer past the start of the buffer\nwhen processing an all-whitespace Metalink URL, potentially leading to\nabnormal program behavior.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58469","https://ubuntu.com/security/notices/USN-8543-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141689"],"patches":{"wget":["upstream: https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.19.4-1ubuntu2.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.20.3-1ubuntu2.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.21.2-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.21.4-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.25.0-2ubuntu4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8543-1"],"notices":[{"id":"USN-8543-1","title":"Wget vulnerabilities","summary":"Several security issues were fixed in Wget.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T19:06:42.710588","description":"It was discovered that Wget mishandled semicolons in the userinfo\nsubcomponent of a URL. A remote attacker could possibly use this issue\nto trick a user into connecting to a different host than intended. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)\n\nIt was discovered that Wget incorrectly handled Metalink documents\ncontaining a whitespace-only URL. A remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n26.04 LTS. (CVE-2026-58469)\n\nIt was discovered that Wget incorrectly handled Content-Range header\nvalues, leading to an integer overflow. A remote attacker could\npossibly use this issue to cause download desynchronization.\n(CVE-2026-58470)\n\nIt was discovered that Wget incorrectly handled character set\nconversion of server-supplied filenames. A remote attacker could possibly\nuse this issue to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471)\n\nIt was discovered that Wget incorrectly handled HTML attributes\nrequiring entity encoding. A remote attacker could possibly use this issue\nto cause a denial of service or possibly execute arbitrary code.\n(CVE-2026-58472)","is_hidden":false,"release_packages":{"bionic":[{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.19.4-1ubuntu2.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.20.3-1ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"wget","version":"1.21.2-2ubuntu1.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.2-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.3","pocket":"security"}],"noble":[{"name":"wget","version":"1.21.4-1ubuntu4.3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.21.4-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.3","pocket":"security"}],"resolute":[{"name":"wget","version":"1.25.0-2ubuntu4.2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.25.0-2ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.2","pocket":"security"}],"trusty":[{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.15-1ubuntu1.14.04.5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.17.1-1ubuntu1.5+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-58470","CVE-2024-38428","CVE-2026-58472","CVE-2026-58469","CVE-2026-58471"]}]},{"id":"CVE-2026-53511","published":"2026-07-07T21:17:00","updated_at":"2026-07-09T14:47:31.710291+00:00","description":"\ncalibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or\nPDF file can execute arbitrary Python code when its metadata is read by\ncalibre, including through Add books or Edit books, by embedding a custom\ncolumn definition with a python: template in calibre:user_metadata that is\npassed unsanitized to exec() in the template formatter. This issue is fixed\nin version 9.10.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53511","https://github.com/kovidgoyal/calibre/security/advisories/GHSA-2j4m-2q7x-2c47"],"bugs":[""],"patches":{"calibre":[]},"tags":{},"packages":[{"name":"calibre","source":"https://ubuntu.com/security/cve?package=calibre","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=calibre","debian":"https://tracker.debian.org/pkg/calibre","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.10.0+ds+~0.10.6-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7017","published":"2026-07-07T19:16:00","updated_at":"2026-08-27T21:36:37.366602+00:00","description":"\nHTTP::Tiny versions before 0.095 for Perl forward credential headers to\ncross-origin redirect targets.\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the\n`Location:` header and `_prepare_headers_and_cb` re-merges the caller's\n`headers` argument into the new request, without checking whether the\nredirect target shares an origin with the original URL. Caller-supplied\n`Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore\nre-sent to whatever host the redirect names, across scheme, host or port\nboundaries, and including `https` to `http` downgrades that expose them in\nplaintext on the wire.\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in\na redirected request\" applied only to the URL-userinfo Basic-auth path, not\nto headers passed explicitly by the caller.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7017","https://lists.security.metacpan.org/cve-announce/msg/41618211/","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://ubuntu.com/security/notices/USN-8684-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141638","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141639"],"patches":{"libhttp-tiny-perl":[],"perl":[]},"tags":{},"packages":[{"name":"libhttp-tiny-perl","source":"https://ubuntu.com/security/cve?package=libhttp-tiny-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libhttp-tiny-perl","debian":"https://tracker.debian.org/pkg/libhttp-tiny-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.096-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"5.38.2-3.2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8684-1"],"notices":[{"id":"USN-8684-1","title":"Perl vulnerabilities","summary":"Perl could be made to crash or run programs as your login if it\nopened a specially crafted file.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-27T11:10:17.278158","description":"It was discovered that Perl incorrectly handled certain arguments to\nSocket and pack/unpack functions. An attacker could possibly use this\nissue to read sensitive information from memory.\n(CVE-2026-12087, CVE-2026-57432)\n\nIt was discovered that Perl incorrectly handled regular expressions\nwith a large number of alternation branches. An attacker could\npossibly use this issue to cause incorrect matching results.\n(CVE-2026-13221)\n\nIt was discovered that Perl incorrectly handled certain files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-57433, CVE-2025-15649, CVE-2026-48959, CVE-2026-9538)\n\nIt was discovered that Perl incorrectly handled certain inputs. An\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-48962)\n\nIt was discovered that Perl incorrectly handled credential headers\nduring cross-origin redirects in HTTP::Tiny. An attacker could\npossibly use this issue to expose sensitive information.\n(CVE-2026-7017)","is_hidden":false,"release_packages":{"noble":[{"name":"perl","version":"5.38.2-3.2ubuntu0.4","description":"Practical Extraction and Report Language","is_source":true},{"name":"libperl-dev","version":"5.38.2-3.2ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.4","pocket":"security"},{"name":"libperl5.38t64","version":"5.38.2-3.2ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.4","pocket":"security"},{"name":"perl","version":"5.38.2-3.2ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.4","pocket":"security"},{"name":"perl-base","version":"5.38.2-3.2ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.4","pocket":"security"},{"name":"perl-debug","version":"5.38.2-3.2ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.4","pocket":"security"},{"name":"perl-doc","version":"5.38.2-3.2ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.4","pocket":"security"},{"name":"perl-modules-5.38","version":"5.38.2-3.2ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-13221","CVE-2026-57432","CVE-2026-48962","CVE-2025-15649","CVE-2026-57433","CVE-2026-9538","CVE-2026-48959","CVE-2026-12087","CVE-2026-7017"]}]},{"id":"CVE-2026-14969","published":"2026-07-07T16:16:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\nA flaw was found in 389-ds-base where the LDBM backend attribute encryption\nuses a hardcoded static initialization vector for AES-CBC and 3DES-CBC\noperations, allowing an attacker with privileged filesystem access to\ndetect plaintext equality across encrypted entries by comparing ciphertext\nblocks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14969","https://bugzilla.redhat.com/show_bug.cgi?id=2497735"],"bugs":[""],"patches":{"389-ds-base":[]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14935","published":"2026-07-07T16:16:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nA logic vulnerability was found in GStreamer's webrtcbin component. The\n_check_sdp_crypto() function contains an inverted boolean condition that\ncauses it to accept remote SDP offers or answers that lack the required\na=fingerprint attribute, while incorrectly rejecting those that include it.\nAn attacker with the ability to intercept and modify WebRTC signaling\nmessages could exploit this to bypass the SDP-level DTLS certificate\nfingerprint binding, weakening defenses against man-in-the-middle attacks\non media streams.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14935","https://bugzilla.redhat.com/show_bug.cgi?id=2497679","https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5171 (private)"],"bugs":[""],"patches":{"gst-plugins-bad1.0":[]},"tags":{},"packages":[{"name":"gst-plugins-bad1.0","source":"https://ubuntu.com/security/cve?package=gst-plugins-bad1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gst-plugins-bad1.0","debian":"https://tracker.debian.org/pkg/gst-plugins-bad1.0","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53878","published":"2026-07-07T15:16:00","updated_at":"2026-07-09T14:46:28.887269+00:00","description":"\nAn issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`DomainNameValidator` does not prohibit newlines in domain names (unless\nused via a form field, since `CharField` strips newlines). If an\napplication uses values with newlines in an HTTP response, header injection\ncan occur. Django itself is unaffected because `HttpResponse` prohibits\nnewlines in HTTP headers.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were\nnot evaluated and may also be affected.\nDjango would like to thank Bence Nagy for reporting this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53878","https://www.djangoproject.com/weblog/2026/jul/07/security-releases/"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141629"],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3:5.2.16-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7960,"limit":20,"total_results":79316}