Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    BELL-CVE-2026-80726
    Fix available
    Packages

    linux-lts, linux-lts, linux-lts

    Summary

    Published
    8 Sept 2026
    Packages

    openssl, rootio-openssl

    Summary

    CVE-2026-75803 in openssl - Patched by Root

    Published
    8 Sept 2026
    Packages

    openssl, rootio-openssl

    Summary

    CVE-2026-63076 in openssl - Patched by Root

    Published
    8 Sept 2026
    Packages

    openssl, rootio-openssl

    Summary

    CVE-2026-14456 in openssl - Patched by Root

    Published
    8 Sept 2026
    Packages

    openssl, rootio-openssl

    Summary

    CVE-2026-42767 in openssl - Patched by Root

    Published
    8 Sept 2026
    Packages

    openssl, rootio-openssl

    Summary

    CVE-2026-63072 in openssl - Patched by Root

    Published
    8 Sept 2026
    Packages

    openssl, rootio-openssl

    Summary

    CVE-2026-54874 in openssl - Patched by Root

    Published
    8 Sept 2026
    Packages

    org.apache.httpcomponents.core5:httpcore5-h2, io.root.org.apache.httpcomponents.core5:httpcore5-h2

    Summary

    CVE-2026-54428 in org.apache.httpcomponents.core5:httpcore5-h2 - Patched by Root

    Published
    8 Sept 2026
    MINI-647x-35h3-c7cr
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-c3qm-g8wc-94rq
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-j66m-3m3q-9wx4
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-m5jc-7f2w-x6vf
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-q6w4-wv8f-gj77
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-v5q9-vpm3-c34m
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-4wvw-wjxr-9q94
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-w58v-wfwr-v67h
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-r9hp-rh3f-pcxc
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-p946-8hqf-c2f8
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-87qv-9cjr-36jv
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    MINI-96vq-p83f-cjw8
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    MINI-pvxx-r446-9h9c
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    MINI-338w-jffv-m3w8
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    GHSA-955m-rr6m-2f9v
    Fix available
    Packages

    @sap/cds-mtxs, @sap/cds-mtxs, @sap/cds-mtxs, @sap/cds-mtxs

    Summary

    @sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)

    Published
    8 Sept 2026
    CVE-2026-86516
    Fix available
    Packages

    Summary

    elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management

    Published
    8 Sept 2026
    CVE-2026-86515
    Fix available
    Packages

    Summary

    vgmstream txtp txtp_parser.c add_entry resource consumption

    Published
    8 Sept 2026
    MGASA-2026-0383
    Fix available
    Packages

    freerdp

    Summary

    Updated freerdp packages fix security vulnerabilities

    Published
    8 Sept 2026
    MGASA-2026-0382
    Fix available
    Packages

    tor, tor

    Summary

    Updated tor packages fix security vulnerabilities

    Published
    8 Sept 2026
    CVE-2026-86514
    Fix available
    Packages

    Summary

    vgmstream txth-txtp txth.c sscanf stack-based overflow

    Published
    8 Sept 2026
    CVE-2026-86513
    No fix available
    Packages

    Summary

    java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources

    Published
    8 Sept 2026
    CVE-2026-86512
    No fix available
    Packages

    Summary

    java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control

    Published
    8 Sept 2026
    Packages

    kubernetes

    Summary

    etcd is a distributed key-value store for the data of a distributed system

    Published
    8 Sept 2026
    Packages

    step

    Summary

    gRPC-Go is the Go language implementation of gRPC

    Published
    8 Sept 2026
    Packages

    victoriametrics-operator-fips

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    cert-manager

    Summary

    OpenTelemetry-Go is the Go implementation of OpenTelemetry

    Published
    8 Sept 2026
    Packages

    langfuse

    Summary

    Hono is a Web application framework that provides support for any JavaScript runtime

    Published
    8 Sept 2026
    Packages

    aws-network-policy-agent

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    trust-manager

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    git-lfs

    Summary

    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log

    Published
    8 Sept 2026
    CVE-2026-86511
    No fix available
    Packages

    Summary

    java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    step

    Summary

    gRPC-Go is the Go language implementation of gRPC

    Published
    8 Sept 2026
    Packages

    step-issuer

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    step-issuer

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    vault-k8s

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    sealed-secrets

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    step

    Summary

    gRPC-Go is the Go language implementation of gRPC

    Published
    8 Sept 2026
    Packages

    sealed-secrets

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026