Open Source Vulnerabilities
git-bug
git-bug-0.10.1-7.1 on GA media
ffmpeg-4
ffmpeg-4-4.4.8-5.1 on GA media
corosync
corosync-3.1.10-5.1 on GA media
rclone
rclone-1.75.1-1.1 on GA media
rpcbind
rpcbind-1.2.9-2.1 on GA media
skopeo, skopeo-tests
Important: skopeo security update
python3.14-cryptography
Important: python3.14-cryptography security update
python3.14-cryptography
Important: python3.14-cryptography security update
python3.14-cryptography
Important: python3.14-cryptography security update
python3.14-cryptography
Important: python3.14-cryptography security update
redis, redis-devel, redis-doc
Important: redis:6 security update
redis/ redis-devel/ redis-doc
Important: redis:6 security update
expat, expat-devel
Moderate: expat security update
git-lfs
Important: git-lfs security update
xmlrpc-c, xmlrpc-c-c++, xmlrpc-c-client, xmlrpc-c-client++, xmlrpc-c-devel
Important: xmlrpc-c security update
xmlrpc-c/ xmlrpc-c-c++/ xmlrpc-c-client/ xmlrpc-c-client++/ xmlrpc-c-devel
Important: xmlrpc-c security update
kernel-rt, kernel-rt-core, kernel-rt-debug, kernel-rt-debug-core, kernel-rt-debug-devel, kernel-rt-debug-modules, kernel-rt-debug-modules-extra, kernel-rt-devel, kernel-rt-modules, kernel-rt-modules-extra
Important: kernel-rt security update
kernel-rt/ kernel-rt-core/ kernel-rt-debug/ kernel-rt-debug-core/ kernel-rt-debug-devel/ kernel-rt-debug-modules/ kernel-rt-debug-modules-extra/ kernel-rt-devel/ kernel-rt-modules/ kernel-rt-modules-extra
Important: kernel-rt security update
osbuild-composer, osbuild-composer-core, osbuild-composer-worker
Important: osbuild-composer security update
osbuild-composer/ osbuild-composer-core/ osbuild-composer-worker
Important: osbuild-composer security update
chromium
chromedriver-152.0.7977.82-1.1 on GA media
valkey, valkey-devel
Important: valkey security, bug fix, and enhancement update
valkey/ valkey-devel
Important: valkey security, bug fix, and enhancement update
389-ds-base, 389-ds-base-devel, 389-ds-base-libs, 389-ds-base-snmp, python3-lib389
Critical: 389-ds-base security, bug fix, and enhancement update
389-ds-base/ 389-ds-base-devel/ 389-ds-base-libs/ 389-ds-base-snmp/ python3-lib389
Critical: 389-ds-base security, bug fix, and enhancement update
knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions
knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions
knowns before 0.30.0 Unauthenticated Management API Exposure
knowns before 0.30.0 Path Traversal via Import Name
knowns before 0.30.0 Path Traversal via code.replace MCP action
knowns before 0.30.0 Path Traversal via code.replace MCP action
knowns before 0.30.0 Arbitrary Code Execution via LSP Binary
knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint
knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint
knowns before 0.30.0 Path Traversal via templateFile parameter
knowns before 0.30.0 Path Traversal via templateFile parameter
knowns before 0.30.0 Path Traversal via MCP doc and memory tools
knowns before 0.30.0 Path Traversal via MCP doc and memory tools
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
igniter,
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
igniter/
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ash_lua,
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ash_lua/
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_double_entry,
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_double_entry/
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server,
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server/
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server,
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server/
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server,
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server/
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server,
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server/
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
org.springframework.integration:spring-integration, org.springframework.integration:spring-integration-amqp, org.springframework.integration:spring-integration-bom, org.springframework.integration:spring-integration-core, org.springframework.integration:spring-integration-event, org.springframework.integration:spring-integration-feed, org.springframework.integration:spring-integration-file, org.springframework.integration:spring-integration-ftp, org.springframework.integration:spring-integration-gemfire, org.springframework.integration:spring-integration-groovy, org.springframework.integration:spring-integration-http, org.springframework.integration:spring-integration-ip, org.springframework.integration:spring-integration-jdbc, org.springframework.integration:spring-integration-jms, org.springframework.integration:spring-integration-jmx, org.springframework.integration:spring-integration-jpa, org.springframework.integration:spring-integration-kafka, org.springframework.integration:spring-integration-mail, org.springframework.integration:spring-integration-mongodb, org.springframework.integration:spring-integration-mqtt, org.springframework.integration:spring-integration-r2dbc, org.springframework.integration:spring-integration-redis, org.springframework.integration:spring-integration-rmi, org.springframework.integration:spring-integration-rsocket, org.springframework.integration:spring-integration-scripting, org.springframework.integration:spring-integration-security, org.springframework.integration:spring-integration-sftp, org.springframework.integration:spring-integration-stomp, org.springframework.integration:spring-integration-stream, org.springframework.integration:spring-integration-syslog, org.springframework.integration:spring-integration-test, org.springframework.integration:spring-integration-test-support, org.springframework.integration:spring-integration-webflux, org.springframework.integration:spring-integration-websocket, org.springframework.integration:spring-integration-ws, org.springframework.integration:spring-integration-xml, org.springframework.integration:spring-integration-xmpp, org.springframework.integration:spring-integration-zeromq, org.springframework.integration:spring-integration-zookeeper
TuxCare security update for org.springframework.integration (5 CVEs)
org.springframework.integration:spring-integration/ org.springframework.integration:spring-integration-amqp/ org.springframework.integration:spring-integration-bom/ org.springframework.integration:spring-integration-core/ org.springframework.integration:spring-integration-event/ org.springframework.integration:spring-integration-feed/ org.springframework.integration:spring-integration-file/ org.springframework.integration:spring-integration-ftp/ org.springframework.integration:spring-integration-gemfire/ org.springframework.integration:spring-integration-groovy/ org.springframework.integration:spring-integration-http/ org.springframework.integration:spring-integration-ip/ org.springframework.integration:spring-integration-jdbc/ org.springframework.integration:spring-integration-jms/ org.springframework.integration:spring-integration-jmx/ org.springframework.integration:spring-integration-jpa/ org.springframework.integration:spring-integration-kafka/ org.springframework.integration:spring-integration-mail/ org.springframework.integration:spring-integration-mongodb/ org.springframework.integration:spring-integration-mqtt/ org.springframework.integration:spring-integration-r2dbc/ org.springframework.integration:spring-integration-redis/ org.springframework.integration:spring-integration-rmi/ org.springframework.integration:spring-integration-rsocket/ org.springframework.integration:spring-integration-scripting/ org.springframework.integration:spring-integration-security/ org.springframework.integration:spring-integration-sftp/ org.springframework.integration:spring-integration-stomp/ org.springframework.integration:spring-integration-stream/ org.springframework.integration:spring-integration-syslog/ org.springframework.integration:spring-integration-test/ org.springframework.integration:spring-integration-test-support/ org.springframework.integration:spring-integration-webflux/ org.springframework.integration:spring-integration-websocket/ org.springframework.integration:spring-integration-ws/ org.springframework.integration:spring-integration-xml/ org.springframework.integration:spring-integration-xmpp/ org.springframework.integration:spring-integration-zeromq/ org.springframework.integration:spring-integration-zookeeper
TuxCare security update for org.springframework.integration (5 CVEs)
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server,
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server/
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
ash_authentication_oauth2_server,
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
ash_authentication_oauth2_server/
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
