{"cves":[{"id":"CVE-2026-12610","published":"2026-06-30T00:00:00","updated_at":"2026-09-02T01:13:58.401561+00:00","description":"\nA flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM\nresponder can crash due to a use-after-free vulnerability, where a memory\npointer is incorrectly handled. A local attacker could exploit this flaw by\nmanipulating smartcard or YubiKey contents, leading to a denial of service\nthat disrupts authentication. This vulnerability also presents a potential\nfor privilege escalation, although it is difficult to exploit.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-12610","https://access.redhat.com/security/cve/CVE-2026-12610","https://ubuntu.com/security/notices/USN-8672-1"],"bugs":["https://github.com/SSSD/sssd/issues/8796","https://bugzilla.redhat.com/show_bug.cgi?id=2490288"],"patches":{"sssd":["upstream: https://github.com/SSSD/sssd/commit/fa7a55949a30fed064a28ea6f0c801fc5e8c5ba7"]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.6.3-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.9.4-1.1ubuntu6.7","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.12.0-1ubuntu5.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-8672-1"],"notices":[{"id":"USN-8672-1","title":"SSSD vulnerability","summary":"SSSD could be made to crash if it interacted with a smartcard or Yubikey","instructions":"After a standard system update you need to restart sssd to make\nall the necessary changes.","references":[],"published":"2026-08-25T02:30:55.763880","description":"It was discovered that the SSSD PAM responder may crash if a physically\nproximate attacker manipulates a smartcard or Yubikey. Non-malicious\nphysically proximate users may not be able to log in depending upon the\ndetails of their legitimate smartcard or Yubikey.","is_hidden":false,"release_packages":{"jammy":[{"name":"sssd","version":"2.6.3-1ubuntu3.8","description":"System Security Services Daemon","is_source":true},{"name":"libipa-hbac-dev","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libipa-hbac0","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libnss-sss","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libpam-sss","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-certmap-dev","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-certmap0","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-idmap-dev","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-idmap0","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-nss-idmap-dev","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-nss-idmap0","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-simpleifp-dev","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-simpleifp0","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"libsss-sudo","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"python3-libipa-hbac","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"python3-libsss-nss-idmap","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"python3-sss","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-ad","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-ad-common","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-common","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-dbus","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-ipa","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-kcm","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-krb5","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-krb5-common","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-ldap","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-proxy","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"},{"name":"sssd-tools","version":"2.6.3-1ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.6.3-1ubuntu3.8","pocket":"security"}],"noble":[{"name":"sssd","version":"2.9.4-1.1ubuntu6.7","description":"System Security Services Daemon","is_source":true},{"name":"libipa-hbac-dev","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libipa-hbac0t64","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libnss-sss","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libpam-sss","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libsss-certmap-dev","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libsss-certmap0","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libsss-idmap-dev","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libsss-idmap0","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libsss-nss-idmap-dev","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libsss-nss-idmap0","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"libsss-sudo","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"python3-libipa-hbac","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"python3-libsss-nss-idmap","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"python3-sss","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-ad","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-ad-common","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-common","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-dbus","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-idp","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-ipa","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-kcm","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-krb5","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-krb5-common","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-ldap","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-passkey","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-proxy","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"},{"name":"sssd-tools","version":"2.9.4-1.1ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.9.4-1.1ubuntu6.7","pocket":"security"}],"resolute":[{"name":"sssd","version":"2.12.0-1ubuntu5.3","description":"System Security Services Daemon","is_source":true},{"name":"libipa-hbac-dev","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libipa-hbac0t64","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libnss-sss","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libpam-sss","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libsss-certmap-dev","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libsss-certmap0","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libsss-idmap-dev","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libsss-idmap0","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libsss-nss-idmap-dev","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libsss-nss-idmap0","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"libsss-sudo","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"python3-libipa-hbac","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"python3-libsss-nss-idmap","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"python3-sss","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-ad","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-ad-common","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-common","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-dbus","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-idp","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-ipa","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-kcm","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-krb5","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-krb5-common","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-ldap","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-passkey","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-proxy","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"},{"name":"sssd-tools","version":"2.12.0-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.12.0-1ubuntu5.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-12610"]}]},{"id":"CVE-2026-12243","published":"2026-06-30T00:00:00","updated_at":"2026-09-02T21:16:19.337123+00:00","description":"\nRejected reason: This CVE ID has been rejected or withdrawn by its CVE\nNumbering Authority.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-12243","https://huntr.com/bounties/39aa9354-54ca-4e77-96da-580eb1fe6ed1"],"bugs":[""],"patches":{"nltk":[]},"tags":{},"packages":[{"name":"nltk","source":"https://ubuntu.com/security/cve?package=nltk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nltk","debian":"https://tracker.debian.org/pkg/nltk","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55957","published":"2026-06-29T21:16:00","updated_at":"2026-07-01T23:25:57.277699+00:00","description":"\nMissing Critical Step in Authentication vulnerability in Apache Tomcat when\nthe JNDIRealm was configured to authenticate binds using GSSAPI allowed\nattackers to authenticate without provided the correct password.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from\n10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0\nthrough 8.5.100, from 7.0.0 through 7.0.109.\nUsers are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101,\nwhich fixes the issue.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xenial tomcat6 only builds libservlet2.5-java, not the Tomcat\nserver binaries\nbionic tomcat7 only builds libservlet3.0-java, not the Tomcat\nserver binaries"}],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55957","https://github.com/apache/tomcat/commit/fd96ab415631eea44636c94f911dd38427070ef9 (11.0.5)","https://github.com/apache/tomcat/commit/0cd21c0393b8811af22daddbba7b4e7328e2d79e (10.1.37)","https://github.com/apache/tomcat/commit/c32bbd37ea9ee0aaab848af4ee1c9a76e84240ea (9.0.101)","https://lists.apache.org/thread/7fk339o5jvd4mcgsf0chbrn4o525ccjh","http://www.openwall.com/lists/oss-security/2026/06/29/26"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[],"tomcat11":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat11","source":"https://ubuntu.com/security/cve?package=tomcat11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat11","debian":"https://tracker.debian.org/pkg/tomcat11","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55956","published":"2026-06-29T21:16:00","updated_at":"2026-07-01T23:25:57.277699+00:00","description":"\nImproper Authorization vulnerability in Apache Tomcat leads to security\nconstraints specified for the default servlet ignoring any method or method\nomission configured as part of the constraint.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from\n10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0\nthrough 8.5.100, from 7.0.0 through 7.0.109. Other versions that have\nreached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119,\nwhich fix the issue.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xenial tomcat6 only builds libservlet2.5-java, not the Tomcat\nserver binaries\nbionic tomcat7 only builds libservlet3.0-java, not the Tomcat\nserver binaries"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55956","https://github.com/apache/tomcat/commit/3f6bd2ba5e53d1f340bbe5ad2d42a28b29440b7a (11.0.23)","https://github.com/apache/tomcat/commit/9c3b1efb74fd04f77639720af1d48a8f664ad9bb (10.1.56)","https://github.com/apache/tomcat/commit/a0374c450970760efafbd8806a1db278830ba7bd (9.0.119)","https://lists.apache.org/thread/dcjdcnnnww9hhdm016hr0l7hpw1bzjfp","http://www.openwall.com/lists/oss-security/2026/06/29/25"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[],"tomcat11":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat11","source":"https://ubuntu.com/security/cve?package=tomcat11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat11","debian":"https://tracker.debian.org/pkg/tomcat11","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55955","published":"2026-06-29T21:16:00","updated_at":"2026-07-01T23:25:57.277699+00:00","description":"\nImproper Authentication vulnerability in Apache Tomcat allowed a replay\nattack against the EncryptionInterceptor in the cluster component.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from\n10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through\n8.5.100, from 7.0.100 through 7.0.109.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119,\nwhich fixes the issue.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xenial tomcat6 only builds libservlet2.5-java, not the Tomcat\nserver binaries\nbionic tomcat7 only builds libservlet3.0-java, not the Tomcat\nserver binaries"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55955","https://github.com/apache/tomcat/commit/5e594400c7f6ac0eaf2526bd64442a70f5ccaace (11.0.23)","https://github.com/apache/tomcat/commit/3a9ff01d2dfaca651edacbda3260e37b98b540d3 (10.1.56)","https://github.com/apache/tomcat/commit/6a7a432cd7fb4ef358dc12e8da99cf3ab320f3fe (9.0.119)","https://lists.apache.org/thread/g4p5sf45p3f9r011pwqs9r54yd64s106","http://www.openwall.com/lists/oss-security/2026/06/29/24"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[],"tomcat11":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat11","source":"https://ubuntu.com/security/cve?package=tomcat11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat11","debian":"https://tracker.debian.org/pkg/tomcat11","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55276","published":"2026-06-29T21:16:00","updated_at":"2026-07-16T08:07:45.078925+00:00","description":"\nAlways-Incorrect Control Flow Implementation vulnerability in Apache Tomcat\nmeant that special roles and empty authorisation constraints were not\nincluded when the effective web.xml was logged.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from\n10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0\nthrough 8.5.100. Other versions that have reached end of support may also\nbe affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119\nwhich fixes the issue.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xenial tomcat6 only builds libservlet2.5-java, not the Tomcat\nserver binaries\nbionic tomcat7 only builds libservlet3.0-java, not the Tomcat\nserver binaries"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55276","https://github.com/apache/tomcat/commit/f844614c6d92eeb11e81e179606bf4c390f642dd (11.0.23)","https://github.com/apache/tomcat/commit/e391c6b201eae2ad9707a1335aff68ab8b3e0f84 (11.0.23)","https://github.com/apache/tomcat/commit/25677f90fd721c26ef0f613d34ef8275b1aafc31 (10.1.56)","https://github.com/apache/tomcat/commit/17daf80a738d66a8e6cad05c5e32c2db81500ce1 (10.1.56)","https://github.com/apache/tomcat/commit/3ca8cae5fd3796b1bd9759e11b0e238161e7a39c (9.0.119)","https://lists.apache.org/thread/jy09xjlzn6r2qwvqoph8vcmf959yq68v","http://www.openwall.com/lists/oss-security/2026/06/29/23","https://ubuntu.com/security/notices/USN-8551-1"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[],"tomcat11":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8.5.39-1ubuntu1~18.04.3+esm6","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"8.0.32-1ubuntu1.13+esm2","component":null,"pocket":"esm-infra-legacy"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat11","source":"https://ubuntu.com/security/cve?package=tomcat11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat11","debian":"https://tracker.debian.org/pkg/tomcat11","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8551-1"],"notices":[{"id":"USN-8551-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T14:15:28.556145","description":"It was discovered that Tomcat incorrectly handled authorization when\nmultiple method constraints defined the same HTTP method. A remote\nattacker could possibly use this issue to bypass authorization\nrestrictions. (CVE-2026-43515)\n\nIt was discovered that the Tomcat number guess example application did\nnot properly sanitize user-supplied input. An attacker could possibly\nuse this issue to inject malicious scripts, resulting in cross-site\nscripting. (CVE-2026-50229)\n\nIt was discovered that Tomcat incorrectly evaluated rewrite valve\nconditions in certain configurations. An attacker could possibly use\nthis issue to bypass rewrite rules, resulting in unauthorized access.\n(CVE-2026-53404)\n\nIt was discovered that Tomcat incorrectly omitted certain authorization\ninformation when logging the effective web.xml configuration. An\nattacker could possibly use this issue to hide authorization\nconstraints, resulting in reduced auditability. (CVE-2026-55276)","is_hidden":false,"release_packages":{"bionic":[{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm6","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat8-embed-java","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"libtomcat8-java","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-admin","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-common","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-docs","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-examples","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-user","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"tomcat8","version":"8.0.32-1ubuntu1.13+esm2","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.1-java","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libservlet3.1-java-doc","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libtomcat8-java","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-admin","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-common","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-docs","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-examples","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-user","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-50229","CVE-2026-53404","CVE-2026-55276","CVE-2026-43515"]}]},{"id":"CVE-2026-53434","published":"2026-06-29T21:16:00","updated_at":"2026-07-16T08:07:45.078925+00:00","description":"\nDetection of Error Condition Without Action vulnerability in Apache Tomcat\nwhen configuring CRLs for a FFM based connector.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from\n10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119,\nwhich fixes the issue.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xenial tomcat6 only builds libservlet2.5-java, not the Tomcat\nserver binaries\nbionic tomcat7 only builds libservlet3.0-java, not the Tomcat\nserver binaries"},{"author":"mrmajumder","note":"tomcat8 not-affected, FFM/Panama OpenSSL connector absent in\n8.0.x and 8.5.x"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53434","https://github.com/apache/tomcat/commit/7f8ecdbd930d8c5a7fae73aa0eec9124d919e2f5 (11.0.23)","https://github.com/apache/tomcat/commit/feec60d6099727db6f911534f6a0f6926ebab070 (10.1.56)","https://github.com/apache/tomcat/commit/c48ac39c27f4494f8c96b9d56a487253e362d276 (9.0.119)","https://lists.apache.org/thread/x510lbq0sfrd1qyo7q3r1mpllgpdcosk","http://www.openwall.com/lists/oss-security/2026/06/29/22"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[],"tomcat11":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat11","source":"https://ubuntu.com/security/cve?package=tomcat11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat11","debian":"https://tracker.debian.org/pkg/tomcat11","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53404","published":"2026-06-29T21:16:00","updated_at":"2026-07-16T08:07:45.078925+00:00","description":"\nAlways-Incorrect Control Flow Implementation vulnerability in Apache\nTomcat's rewrite valve meant that if the first condition in an OR chain\nmatched, subsequent non-OR conditions were skipped.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from\n10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0\nthrough 8.5.100. Other versions that have reached end of support may also\nbe affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119,\nwhich fix the issue.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xenial tomcat6 only builds libservlet2.5-java, not the Tomcat\nserver binaries\nbionic tomcat7 only builds libservlet3.0-java, not the Tomcat\nserver binaries"}],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53404","https://github.com/apache/tomcat/commit/b647cb584cea8bf95e64f5d2526c59ab8fca3225 (11.0.23)","https://github.com/apache/tomcat/commit/bbb6219fa5ac185060bef7842cee5fb90230ca00 (10.1.56)","https://github.com/apache/tomcat/commit/fe06ae8a71997061596f54189dae1b1b5da75430 (9.0.119)","https://lists.apache.org/thread/rdhpghgfskrdmw9hqzjgjrtw538smpmz","http://www.openwall.com/lists/oss-security/2026/06/29/21","https://ubuntu.com/security/notices/USN-8551-1"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[],"tomcat11":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8.5.39-1ubuntu1~18.04.3+esm6","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"8.0.32-1ubuntu1.13+esm2","component":null,"pocket":"esm-infra-legacy"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat11","source":"https://ubuntu.com/security/cve?package=tomcat11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat11","debian":"https://tracker.debian.org/pkg/tomcat11","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8551-1"],"notices":[{"id":"USN-8551-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T14:15:28.556145","description":"It was discovered that Tomcat incorrectly handled authorization when\nmultiple method constraints defined the same HTTP method. A remote\nattacker could possibly use this issue to bypass authorization\nrestrictions. (CVE-2026-43515)\n\nIt was discovered that the Tomcat number guess example application did\nnot properly sanitize user-supplied input. An attacker could possibly\nuse this issue to inject malicious scripts, resulting in cross-site\nscripting. (CVE-2026-50229)\n\nIt was discovered that Tomcat incorrectly evaluated rewrite valve\nconditions in certain configurations. An attacker could possibly use\nthis issue to bypass rewrite rules, resulting in unauthorized access.\n(CVE-2026-53404)\n\nIt was discovered that Tomcat incorrectly omitted certain authorization\ninformation when logging the effective web.xml configuration. An\nattacker could possibly use this issue to hide authorization\nconstraints, resulting in reduced auditability. (CVE-2026-55276)","is_hidden":false,"release_packages":{"bionic":[{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm6","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat8-embed-java","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"libtomcat8-java","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-admin","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-common","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-docs","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-examples","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-user","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"tomcat8","version":"8.0.32-1ubuntu1.13+esm2","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.1-java","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libservlet3.1-java-doc","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libtomcat8-java","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-admin","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-common","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-docs","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-examples","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-user","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-50229","CVE-2026-53404","CVE-2026-55276","CVE-2026-43515"]}]},{"id":"CVE-2026-50229","published":"2026-06-29T21:16:00","updated_at":"2026-07-16T08:07:45.078925+00:00","description":"\nImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic\nXSS) vulnerability in the number guess example for Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from\n10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0\nthrough 8.5.100, from 7.0.0 through 7.0.109. Other versions that have\nreached end of support may also be affected.\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119,\nwhich fix the issue.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xenial tomcat6 only builds libservlet2.5-java, not the Tomcat\nserver binaries\nbionic tomcat7 only builds libservlet3.0-java, not the Tomcat\nserver binaries"}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50229","https://github.com/apache/tomcat/commit/1fe95d841e9d461a16069974142d12c3ef68819a (11.0.23)","https://github.com/apache/tomcat/commit/0d5bdd5b0dd964e9f73e530b7d753462b9bfd1d0 (10.1.56)","https://github.com/apache/tomcat/commit/de5a950415fc67713f17fab63d0c7809e0fca80b (9.0.119)","https://lists.apache.org/thread/wlt2no8bw45zl1w8byop4zfqphldf5j0","http://www.openwall.com/lists/oss-security/2026/06/29/20","https://ubuntu.com/security/notices/USN-8551-1"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[],"tomcat11":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8.5.39-1ubuntu1~18.04.3+esm6","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"8.0.32-1ubuntu1.13+esm2","component":null,"pocket":"esm-infra-legacy"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"tomcat11","source":"https://ubuntu.com/security/cve?package=tomcat11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat11","debian":"https://tracker.debian.org/pkg/tomcat11","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8551-1"],"notices":[{"id":"USN-8551-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T14:15:28.556145","description":"It was discovered that Tomcat incorrectly handled authorization when\nmultiple method constraints defined the same HTTP method. A remote\nattacker could possibly use this issue to bypass authorization\nrestrictions. (CVE-2026-43515)\n\nIt was discovered that the Tomcat number guess example application did\nnot properly sanitize user-supplied input. An attacker could possibly\nuse this issue to inject malicious scripts, resulting in cross-site\nscripting. (CVE-2026-50229)\n\nIt was discovered that Tomcat incorrectly evaluated rewrite valve\nconditions in certain configurations. An attacker could possibly use\nthis issue to bypass rewrite rules, resulting in unauthorized access.\n(CVE-2026-53404)\n\nIt was discovered that Tomcat incorrectly omitted certain authorization\ninformation when logging the effective web.xml configuration. An\nattacker could possibly use this issue to hide authorization\nconstraints, resulting in reduced auditability. (CVE-2026-55276)","is_hidden":false,"release_packages":{"bionic":[{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm6","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat8-embed-java","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"libtomcat8-java","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-admin","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-common","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-docs","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-examples","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-user","version":"8.5.39-1ubuntu1~18.04.3+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"tomcat8","version":"8.0.32-1ubuntu1.13+esm2","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.1-java","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libservlet3.1-java-doc","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libtomcat8-java","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-admin","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-common","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-docs","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-examples","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"tomcat8-user","version":"8.0.32-1ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-50229","CVE-2026-53404","CVE-2026-55276","CVE-2026-43515"]}]},{"id":"CVE-2026-13758","published":"2026-06-29T21:16:00","updated_at":"2026-07-01T23:24:34.983707+00:00","description":"\nCryptX versions before 0.088_001 for Perl compare AEAD authentication tags\nin non-constant time in the streaming decrypt_done path.\nThe decrypt_done($tag) form compares it against the computed tag with memNE\n(memcmp() != 0), which short-circuits on the first differing byte, so its\nrun time depends on the number of matching leading bytes. This affects all\nfive AEAD modes: GCM, CCM, ChaCha20Poly1305, EAX and OCB. The one-shot\n*_decrypt_verify helpers are unaffected; they verify the tag inside\nlibtomcrypt with a constant-time comparison.\nThe timing difference is a tag-verification oracle. An attacker who can\nsubmit many candidate tags for the same nonce, ciphertext and associated\ndata while measuring the timing precisely enough may recover the expected\ntag byte by byte and forge a message that verifies.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-13758","https://lists.security.metacpan.org/cve-announce/msg/41398101/","https://github.com/DCIT/perl-CryptX/commit/7e56347d420aaf43b2ee1586f4a230492ccf1642.patch","https://metacpan.org/release/MIK/CryptX-0.088_001/changes","http://www.openwall.com/lists/oss-security/2026/06/29/19"],"bugs":[""],"patches":{"libcryptx-perl":[]},"tags":{},"packages":[{"name":"libcryptx-perl","source":"https://ubuntu.com/security/cve?package=libcryptx-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcryptx-perl","debian":"https://tracker.debian.org/pkg/libcryptx-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.089-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-56018","published":"2026-06-29T20:17:00","updated_at":"2026-07-01T23:25:57.277699+00:00","description":"\nJavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every\ncall to minify(), allowing unbounded memory growth.\nIn JsMinify (XS.xs) the cleanup frees only the NodeSet structures and never\nthe per-token contents buffers allocated in JsSetNodeContents;\nJsDiscardNode unlinks nodes without freeing their contents. Each token's\ncontents buffer is therefore leaked on every call, and the two early\nreturns taken when the node list is empty leak the whole NodeSet.\nA long-lived process that minifies repeatedly, such as an asset pipeline or\na server-side minifier endpoint, grows in memory without bound until it\nexhausts available memory and is killed, causing denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56018","https://lists.security.metacpan.org/cve-announce/msg/41396069/","https://github.com/bleargh45/JavaScript-Minifier-XS/issues/10","https://metacpan.org/release/GTERMARS/JavaScript-Minifier-XS-0.16/changes","http://www.openwall.com/lists/oss-security/2026/06/29/17"],"bugs":[""],"patches":{"libjavascript-minifier-xs-perl":[]},"tags":{},"packages":[{"name":"libjavascript-minifier-xs-perl","source":"https://ubuntu.com/security/cve?package=libjavascript-minifier-xs-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjavascript-minifier-xs-perl","debian":"https://tracker.debian.org/pkg/libjavascript-minifier-xs-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-56017","published":"2026-06-29T20:17:00","updated_at":"2026-07-01T23:25:57.277699+00:00","description":"\nJavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL\npointer dereference when the first meaningful token of the input is a\nslash.\nThe regexp versus division disambiguator in JsTokenizeString (XS.xs)\ninspects the previous token's last byte to choose between a regexp literal\nand a division operator. When a slash is the first meaningful token, with\nthe start of input or only whitespace and comments before it, there is no\nvalid preceding token: the walk back over whitespace and comment nodes runs\noff the head of the node list to NULL, and the byte lookup reads through a\nNULL contents pointer at an underflowed length index. The following\nidentifier check dereferences the same NULL pointer.\nThe crash is reachable through the public minify() API, so input as small\nas a single slash byte crashes the calling process. A service that minifies\nuntrusted or third-party JavaScript can be crashed by a remote request,\ncausing denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56017","https://lists.security.metacpan.org/cve-announce/msg/41396063/","https://metacpan.org/release/GTERMARS/JavaScript-Minifier-XS-0.16/changes","http://www.openwall.com/lists/oss-security/2026/06/29/16"],"bugs":[""],"patches":{"libjavascript-minifier-xs-perl":[]},"tags":{},"packages":[{"name":"libjavascript-minifier-xs-perl","source":"https://ubuntu.com/security/cve?package=libjavascript-minifier-xs-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjavascript-minifier-xs-perl","debian":"https://tracker.debian.org/pkg/libjavascript-minifier-xs-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.16-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-43712","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:11:55.478503+00:00","description":"\nThe issue was addressed with improved memory handling. This issue is fixed\nin Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS\n26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web\ncontent may lead to an unexpected process crash.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43712","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]},{"id":"CVE-2026-43707","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:14:36.962541+00:00","description":"\nA memory corruption issue was addressed with improved memory handling. This\nissue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe\n26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously\ncrafted web content may lead to an unexpected process crash.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43707","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]},{"id":"CVE-2026-43705","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:11:55.478503+00:00","description":"\nA type confusion issue was addressed with improved checks. This issue is\nfixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and\niPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6.\nProcessing maliciously crafted web content may lead to memory corruption.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43705","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]},{"id":"CVE-2026-43701","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:12:51.858578+00:00","description":"\nThe issue was addressed with improved checks. This issue is fixed in Safari\n26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS\nTahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website\nmay be able to process restricted web content outside the sandbox.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43701","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]},{"id":"CVE-2026-43699","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:12:29.736982+00:00","description":"\nA use-after-free issue was addressed with improved memory management. This\nissue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2\nand iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS\n26.6. Processing maliciously crafted web content may lead to an unexpected\nprocess crash.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43699","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]},{"id":"CVE-2026-43676","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:15:05.038381+00:00","description":"\nAn out-of-bounds access issue was addressed with improved bounds checking.\nThis issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS\n26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6.\nProcessing maliciously crafted web content may lead to an unexpected Safari\ncrash.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43676","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]},{"id":"CVE-2026-43663","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:11:19.125837+00:00","description":"\nThe issue was addressed with improved memory handling. This issue is fixed\nin Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS\n26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6.\nProcessing maliciously crafted web content may lead to an unexpected\nprocess crash.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43663","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]},{"id":"CVE-2026-39872","published":"2026-06-29T20:17:00","updated_at":"2026-08-31T18:12:14.234248+00:00","description":"\nThe issue was addressed with improved memory handling. This issue is fixed\nin Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS\n26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6.\nProcessing maliciously crafted web content may lead to an unexpected\nprocess crash.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\njammy and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored.\nthis does not appear to affect webkit2gtk"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39872","https://webkitgtk.org/security/WSA-2026-0004.html","https://ubuntu.com/security/notices/USN-8703-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.52.6-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.52.6-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.52.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8703-1"],"notices":[{"id":"USN-8703-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.","references":[],"published":"2026-08-31T12:46:51.507087","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.","is_hidden":false,"release_packages":{"noble":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.24.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.52.6-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"webkit2gtk","version":"2.52.6-0ubuntu0.26.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-bin","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libwebkitgtk-doc","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"webkitgtk-webdriver","version":"2.52.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.52.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43742","CVE-2026-43713","CVE-2026-43707","CVE-2026-28955","CVE-2026-64719","CVE-2026-43701","CVE-2026-39872","CVE-2026-43732","CVE-2026-43745","CVE-2026-64783","CVE-2026-28947","CVE-2026-43663","CVE-2026-43804","CVE-2026-43715","CVE-2026-43712","CVE-2026-28984","CVE-2026-43727","CVE-2026-28905","CVE-2026-28907","CVE-2026-43731","CVE-2026-43658","CVE-2026-28946","CVE-2026-43716","CVE-2026-28958","CVE-2026-28901","CVE-2026-43699","CVE-2026-64713","CVE-2026-28903","CVE-2026-64787","CVE-2026-28904","CVE-2026-28902","CVE-2026-43705","CVE-2026-43660","CVE-2026-28847","CVE-2026-43740","CVE-2026-64730","CVE-2026-28942","CVE-2026-43676","CVE-2026-28953","CVE-2026-43734","CVE-2026-64728","CVE-2026-43725","CVE-2026-43721","CVE-2026-43720","CVE-2026-64757","CVE-2026-28883","CVE-2026-43726"]}]}],"offset":8660,"limit":20,"total_results":79316}