Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    Packages

    tomcat

    Summary

    Apache Tomcat: Servlet role references can bypass declarative role constraints

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Limited replay attack possible with DIGEST authentication

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Bypass longest prefix security constraint

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Security constraints for default servlet ignored method

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: EncryptInterceptor not protected against replay attacks

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Logged effective web.xml is incomplete

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Bad ornext processing in RewriteValve

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: XSS in number guess example

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Security constraints not correctly applied

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: AJP secret compared in non-constant time

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: LockOutRealm treats user names as case-sensitive

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Digest authenticator will authenticate any unknown user

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Incomplete escaping of JSON access logs

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Occasionally open redirect

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Request smuggling via invalid chunk extension

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Security constraint bypass with HTTP/0.9

    Published
    11 Sept 2026
    Packages

    tomcat

    Summary

    Apache Tomcat: Client certificate verification bypass due to virtual host mapping

    Published
    11 Sept 2026
    BIT-python-2026-17084
    No fix available
    Packages

    python

    Summary

    stringprep.map_table_b2() deviates from RFC 3454 Table B.2

    Published
    11 Sept 2026
    Packages

    python-min

    Summary

    stringprep.map_table_b2() deviates from RFC 3454 Table B.2

    Published
    11 Sept 2026
    BIT-python-2026-15806
    No fix available
    Packages

    python

    Summary

    `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

    Published
    11 Sept 2026
    Packages

    python-min

    Summary

    `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

    Published
    11 Sept 2026
    BIT-python-2026-15310
    No fix available
    Packages

    python

    Summary

    zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

    Published
    11 Sept 2026
    Packages

    python-min

    Summary

    zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

    Published
    11 Sept 2026
    Packages

    org.postgresql:postgresql, io.root.org.postgresql:postgresql

    Summary

    CVE-2025-49146 in org.postgresql:postgresql - Patched by Root

    Published
    11 Sept 2026
    BIT-libpython-2026-17084
    No fix available
    Packages

    libpython

    Summary

    stringprep.map_table_b2() deviates from RFC 3454 Table B.2

    Published
    11 Sept 2026
    BIT-libpython-2026-15806
    No fix available
    Packages

    libpython

    Summary

    `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

    Published
    11 Sept 2026
    BIT-libpython-2026-15310
    No fix available
    Packages

    libpython

    Summary

    zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

    Published
    11 Sept 2026
    DEBIAN-CVE-2026-89169
    No fix available
    Packages

    live-boot, live-boot, live-boot

    Summary

    Published
    11 Sept 2026
    Packages

    pcre2, pcre2

    Summary

    Published
    11 Sept 2026
    Packages

    libhttp-date-perl, rootio-libhttp-date-perl

    Summary

    CVE-2026-14741 in libhttp-date-perl - Patched by Root

    Published
    11 Sept 2026
    Packages

    libhttp-date-perl, rootio-libhttp-date-perl

    Summary

    CVE-2026-14741 in libhttp-date-perl - Patched by Root

    Published
    11 Sept 2026
    Packages

    pcre2, rootio-pcre2

    Summary

    CVE-2026-86145 in pcre2 - Patched by Root

    Published
    11 Sept 2026
    Packages

    pcre2, pcre2, pcre2

    Summary

    Published
    11 Sept 2026
    Packages

    pcre2, pcre2, pcre2

    Summary

    Published
    11 Sept 2026
    AZL-100056
    No fix available
    Packages

    pcre2

    Summary

    CVE-2026-89160 affecting package pcre2 10.42-3

    Published
    11 Sept 2026
    AZL-100053
    No fix available
    Packages

    pcre2

    Summary

    CVE-2026-89161 affecting package pcre2 10.42-3

    Published
    11 Sept 2026
    Packages

    pcre2, pcre2, pcre2

    Summary

    Published
    11 Sept 2026
    Packages

    pcre2, pcre2, pcre2

    Summary

    Published
    11 Sept 2026
    Packages

    pcre2, pcre2, pcre2

    Summary

    Published
    11 Sept 2026
    AZL-100065
    No fix available
    Packages

    pcre2

    Summary

    CVE-2026-89156 affecting package pcre2 10.42-3

    Published
    11 Sept 2026
    AZL-100062
    No fix available
    Packages

    pcre2

    Summary

    CVE-2026-89158 affecting package pcre2 10.42-3

    Published
    11 Sept 2026
    AZL-100059
    No fix available
    Packages

    pcre2

    Summary

    CVE-2026-89157 affecting package pcre2 10.42-3

    Published
    11 Sept 2026
    CVE-2026-89162
    Fix available
    Packages

    Summary

    Published
    11 Sept 2026
    CVE-2026-89161
    Fix available
    Packages

    Summary

    Published
    11 Sept 2026