Open Source Vulnerabilities
corosync, corosync, corosync
corosync
CVE-2026-81665 affecting package corosync 3.0.4-4
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
openssl-3
Security update for openssl-3
java-21-openjdk
Security update for java-21-openjdk
MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete Attributes
MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete Attributes
transformers
TuxCare security update for transformers (1 CVE)
transformers
TuxCare security update for transformers (1 CVE)
MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter
MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter
joomla
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2
joomla
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2
joomla
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2
joomla
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2
joomla
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2
joomla
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2
podman, podman, podman, podman, podman, podman, podman, podman
Security update for podman
podman/ podman/ podman/ podman/ podman/ podman/ podman/ podman
Security update for podman
c-ares, helm
Security update for helm
Snowflake JDBC Driver auto-configuration account validation permits credential redirection
Snowflake JDBC Driver auto-configuration account validation permits credential redirection
argo-events, argo-events-fips, bento, bento-fips, dapr-daprd-1.16, dapr-daprd-1.17, dapr-daprd-1.18, dapr-daprd-fips-1.16, dapr-daprd-fips-1.17, falcosidekick, falcosidekick-fips, guac, guacingest, guacone, keda-2.18, keda-2.18-metrics-apiserver, keda-2.19-metrics-apiserver, keda-2.20, keda-2.20-metrics-apiserver, keda-fips-2.18, keda-fips-2.19, keda-fips-2.19-metrics-apiserver, keda-fips-2.20, keda-fips-2.20-metrics-apiserver, minio, minio-fips, nuclio-controller, nuclio-controller-fips, opentelemetry-collector-contrib, opentelemetry-collector-contrib-fips, sftpgo-plugin-pubsub, telegraf-1.36, telegraf-1.37, telegraf-1.38, trufflehog, trufflehog-fips, versitygw, versitygw-fips, argo-events, bento, dapr-daprd-1.16, dapr-daprd-1.17, falcosidekick, guac, guacingest, guacone, keda-2.19-metrics-apiserver, keda-2.20, keda-2.20-metrics-apiserver, minio, opentelemetry-collector-contrib, sftpgo-plugin-pubsub, telegraf-1.36, telegraf-1.37, telegraf-1.38, trufflehog
argo-events/ argo-events-fips/ bento/ bento-fips/ dapr-daprd-1.16/ dapr-daprd-1.17/ dapr-daprd-1.18/ dapr-daprd-fips-1.16/ dapr-daprd-fips-1.17/ falcosidekick/ falcosidekick-fips/ guac/ guacingest/ guacone/ keda-2.18/ keda-2.18-metrics-apiserver/ keda-2.19-metrics-apiserver/ keda-2.20/ keda-2.20-metrics-apiserver/ keda-fips-2.18/ keda-fips-2.19/ keda-fips-2.19-metrics-apiserver/ keda-fips-2.20/ keda-fips-2.20-metrics-apiserver/ minio/ minio-fips/ nuclio-controller/ nuclio-controller-fips/ opentelemetry-collector-contrib/ opentelemetry-collector-contrib-fips/ sftpgo-plugin-pubsub/ telegraf-1.36/ telegraf-1.37/ telegraf-1.38/ trufflehog/ trufflehog-fips/ versitygw/ versitygw-fips/ argo-events/ bento/ dapr-daprd-1.16/ dapr-daprd-1.17/ falcosidekick/ guac/ guacingest/ guacone/ keda-2.19-metrics-apiserver/ keda-2.20/ keda-2.20-metrics-apiserver/ minio/ opentelemetry-collector-contrib/ sftpgo-plugin-pubsub/ telegraf-1.36/ telegraf-1.37/ telegraf-1.38/ trufflehog
Improper OCSP response validation in Snowflake drivers
libsoup2, libsoup2, libsoup2
Security update for libsoup2
python-h2
Security update for python-h2
python-h2
Security update for python-h2
python, python-base
Security update for python
