{"cves":[{"id":"CVE-2026-9648","published":"2026-06-11T16:16:00","updated_at":"2026-06-19T08:07:25.237957+00:00","description":"\nThe crypton-x509-validation Haskell library fails to enforce X.509\nNameConstraints, allowing TLS clients to accept certificates whose Subject\nAlternative Names fall outside the issuing CA’s permitted subtrees. This\noversight enables an attacker who compromises a name-constrained sub-CA to\nimpersonate domains beyond its intended scope.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9648","https://www.kb.cert.org/vuls/id/862559","https://github.com/kazu-yamamoto/crypton-certificate/pull/30","https://github.com/haskell/security-advisories/pull/332","https://github.com/kazu-yamamoto/crypton-certificate/pull/30/changes/f4b77edf6ead77f4a886da40e41eab20f0180e39","https://hackage.haskell.org/package/crypton-x509-validation-1.9.1/revisions/"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139732"],"patches":{"haskell-crypton-x509-validation":[]},"tags":{},"packages":[{"name":"haskell-crypton-x509-validation","source":"https://ubuntu.com/security/cve?package=haskell-crypton-x509-validation","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=haskell-crypton-x509-validation","debian":"https://tracker.debian.org/pkg/haskell-crypton-x509-validation","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11816","published":"2026-06-11T14:16:00","updated_at":"2026-06-19T08:05:26.775840+00:00","description":"\nKeras versions prior to 3.14.0 are vulnerable to a path traversal issue in\nthe archive extraction utilities located in\n`keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and\n`filter_safe_zipinfos()` validate archive member paths against the process\ncurrent working directory (CWD) instead of the actual extraction\ndestination. When the process runs with CWD set to `/`, which is common in\nDocker containers, CI/CD runners, and Jupyter environments, the validation\nboundary becomes the filesystem root, allowing traversal paths to bypass\nthe security check. Additionally, the zip filter contains a bug that causes\nan `AttributeError` when a blocked entry is encountered, leading to\nincomplete extraction. Furthermore, Python 3.11 installations lack the\n`filter=\"data\"` safety net, leaving them entirely reliant on the flawed\nCWD-based filter. Exploitation of this vulnerability can result in\narbitrary file writes outside the intended extraction directory, enabling\nattackers to overwrite configuration files, inject malicious code, or\ncorrupt machine learning datasets and pipelines.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11816","https://github.com/keras-team/keras/commit/2465b6657b02c8eed308759b7e800e295ae01888","https://huntr.com/bounties/a07e3983-7158-4419-af2b-38f1dea01a4f"],"bugs":[""],"patches":{"keras":[]},"tags":{},"packages":[{"name":"keras","source":"https://ubuntu.com/security/cve?package=keras","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=keras","debian":"https://tracker.debian.org/pkg/keras","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49214","published":"2026-06-11T13:16:00","updated_at":"2026-06-19T08:06:54.087792+00:00","description":"\nguzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP.\nVersions prior to 2.10.2 did not reject ASCII control characters,\nwhitespace, or DEL in first-party URI host components. A vulnerable flow\nis: First, an application accepts a user-controlled URL. Second, the URL is\nused to construct a PSR-7 `Uri` or `Request`. Third, the host component\ncontains CRLF or another header-unsafe character. Fourth, the host is\ncopied into the PSR-7 `Host` header when no explicit `Host` header is\nprovided. Finally, the request is serialized or sent by an HTTP client that\ndoes not independently reject the malformed host. In that flow, an attacker\ncan cause the serialized request to contain additional attacker-controlled\nheader lines. For example, a host containing `\"\\r\\nX-Injected: yes\"` can\ncause the generated `Host` header to span multiple HTTP header lines.\nApplications are affected when they use user-controlled URLs for outbound\nHTTP requests, URL forwarding, proxying, crawling, webhook delivery, or\nsimilar request-dispatch flows. In deployments involving HTTP/1.1\nconnection reuse, proxies, gateways, or load balancers, this malformed\nrequest may also contribute to request smuggling or cache poisoning,\ndepending on how downstream components parse the request. The issue is\npatched in `2.10.2` and later. `1.x` is end-of-life and will not receive a\npatch. As a workaround, validate and reject all untrusted URI strings\nbefore constructing PSR-7 `Uri` or `Request` instances. Reject input\ncontaining ASCII control characters, whitespace, or DEL, including CRLF,\ntab, space, NUL, or DEL characters. Applications that forward requests\nshould also ensure the final HTTP client or serializer rejects invalid URI\nand header data before writing requests to the network.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49214","https://github.com/guzzle/psr7/security/advisories/GHSA-hq7v-mx3g-29hw"],"bugs":[""],"patches":{"php-guzzlehttp-psr7":[]},"tags":{},"packages":[{"name":"php-guzzlehttp-psr7","source":"https://ubuntu.com/security/cve?package=php-guzzlehttp-psr7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-guzzlehttp-psr7","debian":"https://tracker.debian.org/pkg/php-guzzlehttp-psr7","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48998","published":"2026-06-11T13:16:00","updated_at":"2026-06-19T08:06:54.087792+00:00","description":"\nguzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP.\nVersions prior to 2.10.2 contain improper Host header validation when\nparsing raw HTTP request messages and when deriving a server request URI\nfrom server variables. An attacker can provide a malformed Host header\ncontaining URI authority delimiters, such as\n`trusted.example@evil.example`. When the Host value is used to construct a\nURI, the malformed value can be reinterpreted as URI userinfo and host.\nThis can cause the PSR-7 request URI host to differ from the original Host\nheader value. Applications are affected if they parse attacker-controlled\nraw HTTP requests with `GuzzleHttp\\Psr7\\Message::parseRequest()` or the\nlegacy 1.x `GuzzleHttp\\Psr7\\parse_request()` function, or if they build\nserver requests from attacker-controlled server variables, then rely on the\nresulting URI host for routing, allow-list checks, or forwarding decisions.\nIn affected forwarding or gateway scenarios, this may cause requests or\ncredentials to be sent to an unintended host. The issue is patched in\n`2.10.2`. `1.x` is end-of-life and will not receive a patch. Some\nworkarounds are available. Validate the `Host` header as `uri-host [ \":\"\nport ]` before calling `Message::parseRequest()` or legacy\n`parse_request()` on untrusted HTTP request data, or before deriving\nrouting and forwarding decisions from a parsed request URI. Reject Host\nvalues containing userinfo, path, query, or fragment delimiters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48998","https://github.com/guzzle/psr7/security/advisories/GHSA-34xg-wgjx-8xph"],"bugs":[""],"patches":{"php-guzzlehttp-psr7":[]},"tags":{},"packages":[{"name":"php-guzzlehttp-psr7","source":"https://ubuntu.com/security/cve?package=php-guzzlehttp-psr7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-guzzlehttp-psr7","debian":"https://tracker.debian.org/pkg/php-guzzlehttp-psr7","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9694","published":"2026-06-11T12:16:00","updated_at":"2026-06-19T08:07:25.237957+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that\nunder certain conditions, could have allowed an unauthenticated user to\nimpersonate the GitLab Support Bot and inject arbitrary content via a\nspecially crafted Service Desk email reply due to improper neutralization\nin email template processing.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":2.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":2.6,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9694","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/601330","https://hackerone.com/reports/3685720"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9204","published":"2026-06-11T12:16:00","updated_at":"2026-06-19T08:07:14.564125+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that\nunder certain conditions could have allowed an authenticated user to read\narbitrary files from the Gitaly server and access internal network\nresources during repository import, due to insufficient validation of\nsecondary URLs.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9204","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/592677"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-8589","published":"2026-06-11T12:16:00","updated_at":"2026-06-19T08:07:14.564125+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that\nunder certain conditions could have allowed an authenticated user to add\nunauthorized email addresses to a targeted user's account due to improper\nsanitization of user-supplied input in certain group setting fields.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8589","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/600099","https://hackerone.com/reports/3722842"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7250","published":"2026-06-11T12:16:00","updated_at":"2026-06-19T08:07:14.564125+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that\nunder certain conditions could have allowed an unauthenticated user to\ncause denial of service due to improper input validation in the API request\nparsing middleware.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7250","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/598311","https://hackerone.com/reports/3671995"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6976","published":"2026-06-11T12:16:00","updated_at":"2026-06-19T08:07:14.564125+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that\nunder certain conditions could have allowed an authenticated user with\ndeveloper-role permissions to hide changes from merge request diff views\ndue to improper input handling of file names.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6976","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/598165","https://hackerone.com/reports/3638136"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6552","published":"2026-06-11T12:16:00","updated_at":"2026-08-07T17:59:29.643536+00:00","description":"\nRejected reason: This CVE ID has been rejected. GitLab determined that the\nreported behavior does not constitute a vulnerability: linking a group SAML\nidentity requires the user to explicitly consent to that group controlling\ntheir GitLab account for sign-in, and management of group SAML identities\nby a group Owner is therefore expected behavior rather than an\nauthorization bypass. No GitLab version was affected.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":8.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6552","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/597295","https://hackerone.com/reports/3655189"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6277","published":"2026-06-11T12:16:00","updated_at":"2026-06-19T08:07:14.564125+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that\nunder certain conditions could have allowed an authenticated user with\nSecurity Manager-role permissions to manage project security configuration\neven when the relevant feature was in a disabled state, due to incorrect\nauthorization enforcement.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6277","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/596656","https://hackerone.com/reports/3662615"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6269","published":"2026-06-11T12:16:00","updated_at":"2026-06-19T08:07:14.564125+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that\nunder certain conditions could have allowed an authenticated user with\ndeveloper-role permissions to modify hidden merge requests due to incorrect\nauthorization enforcements.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6269","https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/596625","https://hackerone.com/reports/3661880"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11850","published":"2026-06-11T10:16:00","updated_at":"2026-08-06T23:21:53.208050+00:00","description":"\nAn integer underflow vulnerability was found in MIT krb5 in the\nberval2tl_data() function in\nplugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an\nunsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len\nis 0 or 1, the subtraction wraps to a large value which is then truncated\nto uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent\nmalloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer,\nresulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend\nreturning a krbExtraData attribute with bv_len < 2, triggering the\nunderflow when the KDC or kadmind reads principal data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11850","https://access.redhat.com/security/cve/CVE-2026-11850","https://ubuntu.com/security/notices/USN-8585-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139821","https://krbdev.mit.edu/rt/Ticket/Display.html?id=9206","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"patches":{"krb5":["upstream: https://github.com/krb5/krb5/commit/2a5fd83d4436583f2ddc0e193269a4d800ee45c4"]},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.19.2-2ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.22.1-3","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.20.1-6ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.22.1-2ubuntu4.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8585-1"],"notices":[{"id":"USN-8585-1","title":"Kerberos vulnerabilities","summary":"Several security issues were fixed in Kerberos.","instructions":"After a standard system update you need to restart Kerberos to make\nall the necessary changes.","references":[],"published":"2026-07-22T13:04:35.771321","description":"It was discovered that Kerberos had an integer underflow vulnerability\nin the berval2tl_data() function. An attacker could possibly use this issue\nto cause Kerberos to crash, resulting in a denial of service.\n(CVE-2026-11850)\n\nIt was discovered that Kerberos had vulnerabilities in its NegoEx mechanism\nparsing. A remote attacker could possibly use these issues to cause\nKerberos to crash, resulting in a denial of service. (CVE-2026-40355,\nCVE-2026-40356)","is_hidden":false,"release_packages":{"jammy":[{"name":"krb5","version":"1.19.2-2ubuntu0.8","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-doc","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-gss-samples","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-k5tls","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-kdc","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-kpropd","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-locales","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-multidev","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-otp","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-pkinit","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"krb5-user","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libgssrpc4","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libk5crypto3","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkadm5clnt-mit12","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkadm5srv-mit12","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkdb5-10","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkrad-dev","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkrad0","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkrb5-3","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkrb5-dev","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"},{"name":"libkrb5support0","version":"1.19.2-2ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8","pocket":"security"}],"noble":[{"name":"krb5","version":"1.20.1-6ubuntu2.7","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-doc","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-gss-samples","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-k5tls","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-kdc","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-kpropd","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-locales","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-multidev","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-otp","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-pkinit","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"krb5-user","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libgssrpc4t64","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libk5crypto3","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkadm5clnt-mit12","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkadm5srv-mit12","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkdb5-10t64","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkrad-dev","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkrad0","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkrb5-3","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkrb5-dev","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"},{"name":"libkrb5support0","version":"1.20.1-6ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7","pocket":"security"}],"resolute":[{"name":"krb5","version":"1.22.1-2ubuntu4.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-doc","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-gss-samples","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-k5tls","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-kdc","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-kpropd","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-locales","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-multidev","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-otp","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-pkinit","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"krb5-user","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libgssrpc4t64","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libk5crypto3","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkadm5clnt-mit12","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkadm5srv-mit12","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkdb5-10t64","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkrad-dev","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkrad0","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkrb5-3","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkrb5-dev","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"},{"name":"libkrb5support0","version":"1.22.1-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-40356","CVE-2026-40355","CVE-2026-11850"]}]},{"id":"CVE-2026-40997","published":"2026-06-11T07:16:00","updated_at":"2026-06-19T08:06:03.033034+00:00","description":"\nSeveral Spring WS integration paths with Spring Security could surface\ndetailed account state (for example locked or disabled user semantics) to\nremote SOAP clients through exception messages or callback outcomes,\ninstead of failing with generic authentication errors. That behavior\nassists remote attackers in distinguishing valid accounts from invalid ones\nand inferring lifecycle state.\nAffected versions:\nSpring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through\n4.0.18; 3.1.0 through 3.1.8.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40997","https://spring.io/security/cve-2026-40997"],"bugs":[""],"patches":{"spring":[]},"tags":{},"packages":[{"name":"spring","source":"https://ubuntu.com/security/cve?package=spring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spring","debian":"https://tracker.debian.org/pkg/spring","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40994","published":"2026-06-11T07:16:00","updated_at":"2026-06-19T08:06:03.033034+00:00","description":"\nWss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile)\ncompliance flag so that inbound validation disabled WSS4J BSP enforcement\non RequestData. Services that validate WS-Security on the network could\ntherefore accept messages that violate BSP rules, weakening protocol-level\nchecks.\nAffected versions:\nSpring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through\n4.0.18; 3.1.0 through 3.1.8.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40994","https://spring.io/security/cve-2026-40994"],"bugs":[""],"patches":{"its":[]},"tags":{},"packages":[{"name":"its","source":"https://ubuntu.com/security/cve?package=its","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=its","debian":"https://tracker.debian.org/pkg/its","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53689","published":"2026-06-11T00:00:00","updated_at":"2026-06-25T23:49:44.682377+00:00","description":"\nlibnfs through 6.0.2 before 55c18ea does not validate a string size,\nleading to an integer overflow during a connection to a crafted NFS server.\nThis occurs in libnfs_zdr_string in lib/libnfs-zdr.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53689","https://ubuntu.com/security/notices/USN-8464-1"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139731"],"patches":{"libnfs":["upstream: https://github.com/sahlberg/libnfs/commit/55c18ea33a83d667f79f0ef209c96895795c729f"]},"tags":{},"packages":[{"name":"libnfs","source":"https://ubuntu.com/security/cve?package=libnfs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libnfs","debian":"https://tracker.debian.org/pkg/libnfs","statuses":[{"release_codename":"jammy","status":"released","description":"4.0.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"5.0.2-1ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"5.0.2-1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"5.0.2-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8464-1"],"notices":[{"id":"USN-8464-1","title":"LIBNFS vulnerability","summary":"LIBNFS could be made to crash or run programs if it connected to a\nspecially crafted NFS server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-23T14:57:53.299110","description":"It was discovered that LIBNFS incorrectly handled certain string sizes when\nconnecting to an NFS server. An attacker could use this issue to cause\nLIBNFS to crash, resulting in a denial of service, or possibly execute\narbitrary code.","is_hidden":false,"release_packages":{"jammy":[{"name":"libnfs","version":"4.0.0-1ubuntu0.1","description":"NFS client library","is_source":true},{"name":"libnfs-dev","version":"4.0.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/4.0.0-1ubuntu0.1","pocket":"security"},{"name":"libnfs-utils","version":"4.0.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/4.0.0-1ubuntu0.1","pocket":"security"},{"name":"libnfs13","version":"4.0.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/4.0.0-1ubuntu0.1","pocket":"security"}],"noble":[{"name":"libnfs","version":"5.0.2-1ubuntu0.24.04.1","description":"NFS client library","is_source":true},{"name":"libnfs-dev","version":"5.0.2-1ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu0.24.04.1","pocket":"security"},{"name":"libnfs-utils","version":"5.0.2-1ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu0.24.04.1","pocket":"security"},{"name":"libnfs14","version":"5.0.2-1ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"libnfs","version":"5.0.2-1ubuntu0.25.10.1","description":"NFS client library","is_source":true},{"name":"libnfs-dev","version":"5.0.2-1ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu0.25.10.1","pocket":"security"},{"name":"libnfs-utils","version":"5.0.2-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu0.25.10.1","pocket":"security"},{"name":"libnfs14","version":"5.0.2-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"libnfs","version":"5.0.2-1ubuntu1.1","description":"NFS client library","is_source":true},{"name":"libnfs-dev","version":"5.0.2-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu1.1","pocket":"security"},{"name":"libnfs-utils","version":"5.0.2-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu1.1","pocket":"security"},{"name":"libnfs14","version":"5.0.2-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libnfs","version_link":"https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-53689"]}]},{"id":"CVE-2026-44236","published":"2026-06-11T00:00:00","updated_at":"2026-09-04T00:30:48.054512+00:00","description":"\nHeap buffer overflow in AMQP login handshake via undersized\nconnection.tune.frame_max","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44236","https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jh48-qjf5-fx5v","https://ubuntu.com/security/notices/USN-8437-1","https://ubuntu.com/security/notices/USN-8724-1"],"bugs":[""],"patches":{"librabbitmq":["upstream: https://github.com/alanxz/rabbitmq-c/commit/dff9eb7205fe0769d7bdac76ab882b299d27ed0d","upstream: https://github.com/alanxz/rabbitmq-c/commit/f6eca262f04d2e2c03c3755cb085fb6c191a0867"]},"tags":{},"packages":[{"name":"librabbitmq","source":"https://ubuntu.com/security/cve?package=librabbitmq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=librabbitmq","debian":"https://tracker.debian.org/pkg/librabbitmq","statuses":[{"release_codename":"jammy","status":"released","description":"0.10.0-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.11.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.15.0-1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.15.0-1ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.16.0-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.8.0-1ubuntu0.18.04.2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.10.0-1ubuntu0.20.04.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"0.4.1-1ubuntu0.1~esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"0.7.1-1ubuntu0.2+esm1","component":null,"pocket":"esm-apps-legacy"}]}],"notices_ids":["USN-8437-1","USN-8724-1"],"notices":[{"id":"USN-8437-1","title":"rabbitmq-c vulnerabilities","summary":"Several security issues were fixed in rabbitmq-c.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T14:48:17.728446","description":"It was discovered that rabbitmq-c exposed credentials in command-line\narguments under certain circumstances. A local attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n22.04 LTS and Ubuntu 24.04 LTS. (CVE-2023-35789)\n\nIt was discovered that rabbitmq-c incorrectly handled AMQP frame lengths\nunder certain circumstances, which could lead to an out-of-bounds read. A\nremote attacker could possibly use this issue to cause rabbitmq-c to crash,\nresulting in a denial of service. (CVE-2026-44235)\n\nIt was discovered that rabbitmq-c incorrectly handled AMQP login handshakes\nunder certain circumstances, which could lead to a heap buffer overflow. A\nremote attacker could possibly use this issue to cause rabbitmq-c to crash,\nresulting in a denial of service, or execute arbitrary code.\n(CVE-2026-44236)","is_hidden":false,"release_packages":{"jammy":[{"name":"librabbitmq","version":"0.10.0-1ubuntu2.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.10.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.10.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.1","pocket":"security"},{"name":"librabbitmq4","version":"0.10.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.1","pocket":"security"}],"noble":[{"name":"librabbitmq","version":"0.11.0-1ubuntu0.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.11.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.11.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.1","pocket":"security"},{"name":"librabbitmq4","version":"0.11.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.1","pocket":"security"}],"questing":[{"name":"librabbitmq","version":"0.15.0-1ubuntu0.25.10.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.15.0-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.25.10.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.15.0-1ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.25.10.1","pocket":"security"},{"name":"librabbitmq4","version":"0.15.0-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"librabbitmq","version":"0.15.0-1ubuntu0.26.04.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.15.0-1ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.15.0-1ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.1","pocket":"security"},{"name":"librabbitmq4","version":"0.15.0-1ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44235","CVE-2026-44236","CVE-2023-35789"]},{"id":"USN-8724-1","title":"rabbitmq-c vulnerabilities","summary":"Several security issues were fixed in rabbitmq-c.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-03T15:51:03.015109","description":"It was discovered that the rabbitmq-c command-line tools only accepted\ncredentials on the command line, making them visible to other local users\nthrough the process list. An attacker could possibly use this to obtain\nsensitive credentials. This issue only affected Ubuntu 14.04 LTS, Ubuntu\n16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2023-35789)\n\nIt was discovered that rabbitmq-c did not correctly compute AMQP frame\nlengths, leading to a size_t underflow. A remote attacker could possibly\nuse this to cause rabbitmq-c to crash, resulting in a denial of service, or\npossibly expose sensitive information. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2026-44235)\n\nIt was discovered that rabbitmq-c did not properly validate the frame size\nduring the AMQP login handshake. A remote attacker could possibly use this\nto cause a heap buffer overflow, resulting in a denial of service or\npossibly the execution of arbitrary code. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2026-44236)\n\nIt was discovered that rabbitmq-c did not correctly validate the length of\ndecoded bytes fields, leading to an integer overflow in a bounds check on\n32-bit systems. A remote attacker controlling a broker, or able to\nintercept an unencrypted connection, could possibly use this to cause an\nout-of-bounds read, resulting in a denial of service or the exposure of\nsensitive information. (CVE-2026-59986)\n\nIt was discovered that rabbitmq-c did not validate the body fragment length\nwhen serialising an AMQP body frame with the amqp_send_frame() API. An\nattacker could possibly use this to cause a heap buffer overflow, resulting\nin a denial of service (application crash) or possibly the execution of\narbitrary code. This issue did not affect Ubuntu 14.04 LTS.\n(CVE-2026-61547)","is_hidden":false,"release_packages":{"bionic":[{"name":"librabbitmq","version":"0.8.0-1ubuntu0.18.04.2+esm1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.8.0-1ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps"},{"name":"librabbitmq-dev","version":"0.8.0-1ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps"},{"name":"librabbitmq4","version":"0.8.0-1ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"librabbitmq","version":"0.10.0-1ubuntu0.20.04.1~esm1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.10.0-1ubuntu0.20.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra"},{"name":"librabbitmq-dev","version":"0.10.0-1ubuntu0.20.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra"},{"name":"librabbitmq4","version":"0.10.0-1ubuntu0.20.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"librabbitmq","version":"0.10.0-1ubuntu2.2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.10.0-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.2","pocket":"security"},{"name":"librabbitmq-dev","version":"0.10.0-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.2","pocket":"security"},{"name":"librabbitmq4","version":"0.10.0-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.2","pocket":"security"}],"noble":[{"name":"librabbitmq","version":"0.11.0-1ubuntu0.2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.11.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.2","pocket":"security"},{"name":"librabbitmq-dev","version":"0.11.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.2","pocket":"security"},{"name":"librabbitmq4","version":"0.11.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.2","pocket":"security"}],"resolute":[{"name":"librabbitmq","version":"0.15.0-1ubuntu0.26.04.2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.15.0-1ubuntu0.26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.2","pocket":"security"},{"name":"librabbitmq-dev","version":"0.15.0-1ubuntu0.26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.2","pocket":"security"},{"name":"librabbitmq4","version":"0.15.0-1ubuntu0.26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.2","pocket":"security"}],"trusty":[{"name":"librabbitmq","version":"0.4.1-1ubuntu0.1~esm2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.4.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librabbitmq-dev","version":"0.4.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librabbitmq1","version":"0.4.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"librabbitmq","version":"0.7.1-1ubuntu0.2+esm1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.7.1-1ubuntu0.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps-legacy"},{"name":"librabbitmq-dev","version":"0.7.1-1ubuntu0.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps-legacy"},{"name":"librabbitmq4","version":"0.7.1-1ubuntu0.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-59986","CVE-2026-61547","CVE-2023-35789","CVE-2026-44235","CVE-2026-44236"]}]},{"id":"CVE-2026-44235","published":"2026-06-11T00:00:00","updated_at":"2026-09-04T00:18:51.499933+00:00","description":"\nsize_t underflow in AMQP frame length computation leads to out-of-bounds\nread in rabbitmq-c","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44235","https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-9mmv-r8g3-qp46","https://ubuntu.com/security/notices/USN-8437-1","https://ubuntu.com/security/notices/USN-8724-1"],"bugs":[""],"patches":{"librabbitmq":["upstream: https://github.com/alanxz/rabbitmq-c/commit/1d3afbb056fee5cc9ea05680bf32288715d0d802"]},"tags":{},"packages":[{"name":"librabbitmq","source":"https://ubuntu.com/security/cve?package=librabbitmq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=librabbitmq","debian":"https://tracker.debian.org/pkg/librabbitmq","statuses":[{"release_codename":"jammy","status":"released","description":"0.10.0-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.11.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.15.0-1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.15.0-1ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.16.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.7.1-1ubuntu0.2+esm1","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"bionic","status":"released","description":"0.8.0-1ubuntu0.18.04.2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.10.0-1ubuntu0.20.04.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"0.4.1-1ubuntu0.1~esm2","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8437-1","USN-8724-1"],"notices":[{"id":"USN-8437-1","title":"rabbitmq-c vulnerabilities","summary":"Several security issues were fixed in rabbitmq-c.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T14:48:17.728446","description":"It was discovered that rabbitmq-c exposed credentials in command-line\narguments under certain circumstances. A local attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n22.04 LTS and Ubuntu 24.04 LTS. (CVE-2023-35789)\n\nIt was discovered that rabbitmq-c incorrectly handled AMQP frame lengths\nunder certain circumstances, which could lead to an out-of-bounds read. A\nremote attacker could possibly use this issue to cause rabbitmq-c to crash,\nresulting in a denial of service. (CVE-2026-44235)\n\nIt was discovered that rabbitmq-c incorrectly handled AMQP login handshakes\nunder certain circumstances, which could lead to a heap buffer overflow. A\nremote attacker could possibly use this issue to cause rabbitmq-c to crash,\nresulting in a denial of service, or execute arbitrary code.\n(CVE-2026-44236)","is_hidden":false,"release_packages":{"jammy":[{"name":"librabbitmq","version":"0.10.0-1ubuntu2.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.10.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.10.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.1","pocket":"security"},{"name":"librabbitmq4","version":"0.10.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.1","pocket":"security"}],"noble":[{"name":"librabbitmq","version":"0.11.0-1ubuntu0.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.11.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.11.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.1","pocket":"security"},{"name":"librabbitmq4","version":"0.11.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.1","pocket":"security"}],"questing":[{"name":"librabbitmq","version":"0.15.0-1ubuntu0.25.10.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.15.0-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.25.10.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.15.0-1ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.25.10.1","pocket":"security"},{"name":"librabbitmq4","version":"0.15.0-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"librabbitmq","version":"0.15.0-1ubuntu0.26.04.1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.15.0-1ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.1","pocket":"security"},{"name":"librabbitmq-dev","version":"0.15.0-1ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.1","pocket":"security"},{"name":"librabbitmq4","version":"0.15.0-1ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44235","CVE-2026-44236","CVE-2023-35789"]},{"id":"USN-8724-1","title":"rabbitmq-c vulnerabilities","summary":"Several security issues were fixed in rabbitmq-c.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-03T15:51:03.015109","description":"It was discovered that the rabbitmq-c command-line tools only accepted\ncredentials on the command line, making them visible to other local users\nthrough the process list. An attacker could possibly use this to obtain\nsensitive credentials. This issue only affected Ubuntu 14.04 LTS, Ubuntu\n16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2023-35789)\n\nIt was discovered that rabbitmq-c did not correctly compute AMQP frame\nlengths, leading to a size_t underflow. A remote attacker could possibly\nuse this to cause rabbitmq-c to crash, resulting in a denial of service, or\npossibly expose sensitive information. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2026-44235)\n\nIt was discovered that rabbitmq-c did not properly validate the frame size\nduring the AMQP login handshake. A remote attacker could possibly use this\nto cause a heap buffer overflow, resulting in a denial of service or\npossibly the execution of arbitrary code. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2026-44236)\n\nIt was discovered that rabbitmq-c did not correctly validate the length of\ndecoded bytes fields, leading to an integer overflow in a bounds check on\n32-bit systems. A remote attacker controlling a broker, or able to\nintercept an unencrypted connection, could possibly use this to cause an\nout-of-bounds read, resulting in a denial of service or the exposure of\nsensitive information. (CVE-2026-59986)\n\nIt was discovered that rabbitmq-c did not validate the body fragment length\nwhen serialising an AMQP body frame with the amqp_send_frame() API. An\nattacker could possibly use this to cause a heap buffer overflow, resulting\nin a denial of service (application crash) or possibly the execution of\narbitrary code. This issue did not affect Ubuntu 14.04 LTS.\n(CVE-2026-61547)","is_hidden":false,"release_packages":{"bionic":[{"name":"librabbitmq","version":"0.8.0-1ubuntu0.18.04.2+esm1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.8.0-1ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps"},{"name":"librabbitmq-dev","version":"0.8.0-1ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps"},{"name":"librabbitmq4","version":"0.8.0-1ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"librabbitmq","version":"0.10.0-1ubuntu0.20.04.1~esm1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.10.0-1ubuntu0.20.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra"},{"name":"librabbitmq-dev","version":"0.10.0-1ubuntu0.20.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra"},{"name":"librabbitmq4","version":"0.10.0-1ubuntu0.20.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"librabbitmq","version":"0.10.0-1ubuntu2.2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.10.0-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.2","pocket":"security"},{"name":"librabbitmq-dev","version":"0.10.0-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.2","pocket":"security"},{"name":"librabbitmq4","version":"0.10.0-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1ubuntu2.2","pocket":"security"}],"noble":[{"name":"librabbitmq","version":"0.11.0-1ubuntu0.2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.11.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.2","pocket":"security"},{"name":"librabbitmq-dev","version":"0.11.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.2","pocket":"security"},{"name":"librabbitmq4","version":"0.11.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1ubuntu0.2","pocket":"security"}],"resolute":[{"name":"librabbitmq","version":"0.15.0-1ubuntu0.26.04.2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.15.0-1ubuntu0.26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.2","pocket":"security"},{"name":"librabbitmq-dev","version":"0.15.0-1ubuntu0.26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.2","pocket":"security"},{"name":"librabbitmq4","version":"0.15.0-1ubuntu0.26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":"https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1ubuntu0.26.04.2","pocket":"security"}],"trusty":[{"name":"librabbitmq","version":"0.4.1-1ubuntu0.1~esm2","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.4.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librabbitmq-dev","version":"0.4.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librabbitmq1","version":"0.4.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"librabbitmq","version":"0.7.1-1ubuntu0.2+esm1","description":"AMQP client library written in C","is_source":true},{"name":"amqp-tools","version":"0.7.1-1ubuntu0.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps-legacy"},{"name":"librabbitmq-dev","version":"0.7.1-1ubuntu0.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps-legacy"},{"name":"librabbitmq4","version":"0.7.1-1ubuntu0.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librabbitmq","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-59986","CVE-2026-61547","CVE-2023-35789","CVE-2026-44235","CVE-2026-44236"]}]},{"id":"CVE-2026-53465","published":"2026-06-10T23:16:00","updated_at":"2026-06-19T08:07:14.564125+00:00","description":"\nImageMagick is free and open-source software used for editing and\nmanipulating digital images. Prior to version 7.1.2-25, a crafted\nmulti-frame can result in a heap buffer over-write when encoding it with\nthe SF3 encoder. This issue has been patched in version 7.1.2-25.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53465","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-44cp-c3ww-9rv5"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53464","published":"2026-06-10T23:16:00","updated_at":"2026-06-19T08:07:04.455099+00:00","description":"\nImageMagick is free and open-source software used for editing and\nmanipulating digital images. Prior to version 7.1.2-25, when providing\ninvalid options to the wand option parser a small memory leak will occur.\nThis issue has been patched in version 7.1.2-25.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53464","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j989-f892-2335"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":9760,"limit":20,"total_results":79316}