Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CGA-cfr3-h9fj-r97x
    Fix available
    Packages

    py3.12-httpx2, py3.12-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-mpv7-v75f-336m
    Fix available
    Packages

    py3.12-httpx2, py3.12-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-c34q-4w9v-m844
    Fix available
    Packages

    py3.12-httpx2, py3.12-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-j2pg-xvmm-vm2j
    Fix available
    Packages

    py3.13-httpx2, py3.13-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-83wc-3x37-349f
    Fix available
    Packages

    py3.13-httpx2, py3.13-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-xhqw-wv99-pf22
    Fix available
    Packages

    py3.13-httpx2, py3.13-httpx2

    Summary

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2026-44573 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2026-64645 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2024-46982 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2024-51479 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2025-29927 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    GHSA-5j59-xgg2-r9c4 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    GHSA-q4gf-8mx6-v5v3 in next - Patched by Root

    Published
    11 Sept 2026
    CVE-2026-81909
    No fix available
    Packages

    Summary

    Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks

    Published
    11 Sept 2026
    CGA-4g8v-3q74-vc8v
    Fix available
    Packages

    external-secrets-operator-fips-2.10

    Summary

    Published
    11 Sept 2026
    CGA-cm2r-ch47-hv5j
    Fix available
    Packages

    external-secrets-operator-fips-2.10

    Summary

    Published
    11 Sept 2026
    CGA-9xg6-rgc8-xgjf
    Fix available
    Packages

    external-secrets-operator-fips-2.10

    Summary

    Published
    11 Sept 2026
    CVE-2026-68528
    No fix available
    Packages

    Summary

    Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item title

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2026-64641 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    GHSA-h25m-26qc-wcjf in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2024-34351 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    GHSA-mwv6-3258-q52c in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2026-44578 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    GHSA-8h8q-6873-q5fj in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2026-64649 in next - Patched by Root

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2024-56332 in next - Patched by Root

    Published
    11 Sept 2026
    MGASA-2026-0391
    Fix available
    Packages

    glibc

    Summary

    Updated glibc package fixes security vulnerabilities

    Published
    11 Sept 2026
    CGA-42cc-2cmg-9946
    Fix available
    Packages

    py3.11-httpx2, py3.11-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-7fwf-4rr5-rf2r
    Fix available
    Packages

    py3.11-httpx2, py3.11-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-q3gm-xj8r-jvwc
    Fix available
    Packages

    py3.11-httpx2, py3.11-httpx2

    Summary

    Published
    11 Sept 2026
    Packages

    spip, spip

    Summary

    Published
    11 Sept 2026
    Packages

    spip, spip

    Summary

    Published
    11 Sept 2026
    Packages

    spip, spip

    Summary

    Published
    11 Sept 2026
    CGA-7q69-m5x5-gcq7
    Fix available
    Packages

    wget, wget

    Summary

    Published
    11 Sept 2026
    CGA-j4gw-5vrq-m7mf
    Fix available
    Packages

    wget, wget

    Summary

    Published
    11 Sept 2026
    CVE-2026-18122
    No fix available
    Packages

    Summary

    Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization

    Published
    11 Sept 2026
    Packages

    dompurify

    Summary

    TuxCare security update for dompurify (1 CVE)

    Published
    11 Sept 2026
    CVE-2026-81908
    No fix available
    Packages

    Summary

    Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups

    Published
    11 Sept 2026
    Packages

    dompurify

    Summary

    TuxCare security update for dompurify (1 CVE)

    Published
    11 Sept 2026
    CVE-2026-82535
    No fix available
    Packages

    Summary

    Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php

    Published
    11 Sept 2026
    Packages

    org.springframework.ldap:spring-ldap-core

    Summary

    TuxCare security update for org.springframework.ldap:spring-ldap-core (2 CVEs)

    Published
    11 Sept 2026
    Packages

    next, @rootio/next

    Summary

    CVE-2025-48068 in next - Patched by Root

    Published
    11 Sept 2026
    CVE-2026-89090
    Fix available
    Packages

    Summary

    Denial of service in the event stream header decoder in AWS SDK for Go v2

    Published
    11 Sept 2026
    Packages

    io.netty:netty-all, io.netty:netty-bom, io.netty:netty-buffer, io.netty:netty-codec, io.netty:netty-codec-dns, io.netty:netty-codec-haproxy, io.netty:netty-codec-http, io.netty:netty-codec-http2, io.netty:netty-codec-memcache, io.netty:netty-codec-mqtt, io.netty:netty-codec-redis, io.netty:netty-codec-smtp, io.netty:netty-codec-socks, io.netty:netty-codec-stomp, io.netty:netty-codec-xml, io.netty:netty-common, io.netty:netty-dev-tools, io.netty:netty-example, io.netty:netty-handler, io.netty:netty-handler-proxy, io.netty:netty-handler-ssl-ocsp, io.netty:netty-microbench, io.netty:netty-parent, io.netty:netty-resolver, io.netty:netty-resolver-dns, io.netty:netty-resolver-dns-classes-macos, io.netty:netty-resolver-dns-native-macos, io.netty:netty-testsuite, io.netty:netty-testsuite-autobahn, io.netty:netty-testsuite-http2, io.netty:netty-testsuite-native, io.netty:netty-testsuite-native-image, io.netty:netty-testsuite-native-image-client, io.netty:netty-testsuite-native-image-client-runtime-init, io.netty:netty-testsuite-osgi, io.netty:netty-testsuite-shading, io.netty:netty-transport, io.netty:netty-transport-blockhound-tests, io.netty:netty-transport-classes-epoll, io.netty:netty-transport-classes-kqueue, io.netty:netty-transport-native-epoll, io.netty:netty-transport-native-kqueue, io.netty:netty-transport-native-unix-common, io.netty:netty-transport-native-unix-common-tests, io.netty:netty-transport-rxtx, io.netty:netty-transport-sctp, io.netty:netty-transport-udt

    Summary

    TuxCare security update for io.netty (1 CVE)

    Published
    11 Sept 2026
    CGA-28h4-h5wq-gwmc
    Fix available
    Packages

    py3.12-httpx2, py3.12-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-jgpc-7x4m-hw69
    Fix available
    Packages

    py3.12-httpx2, py3.12-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-9pcm-3454-6rpm
    Fix available
    Packages

    py3.12-httpx2, py3.12-httpx2

    Summary

    Published
    11 Sept 2026
    CGA-7955-fhww-9pv3
    Fix available
    Packages

    zlib, zlib

    Summary

    Published
    11 Sept 2026
    CGA-6ph6-75jp-484p
    Fix available
    Packages

    zlib, zlib

    Summary

    Published
    11 Sept 2026
    CVE-2026-18061
    No fix available
    Packages

    Summary

    Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin

    Published
    11 Sept 2026