Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    MINI-6rxp-pwjp-qvpq
    Fix available
    Packages

    aws-network-policy-agent

    Summary

    Published
    4 Sept 2026
    DEBIAN-CVE-2026-81665
    No fix available
    Packages

    corosync, corosync, corosync

    Summary

    Published
    4 Sept 2026
    AZL-99888
    No fix available
    Packages

    corosync

    Summary

    CVE-2026-81665 affecting package corosync 3.0.4-4

    Published
    4 Sept 2026
    CVE-2026-85184
    Fix available
    Packages

    Summary

    @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target

    Published
    4 Sept 2026
    Packages

    openssl-3

    Summary

    Security update for openssl-3

    Published
    4 Sept 2026
    Packages

    helm

    Summary

    Security update for helm

    Published
    4 Sept 2026
    Packages

    curl

    Summary

    Security update for curl

    Published
    4 Sept 2026
    Packages

    wget

    Summary

    Security update for wget

    Published
    4 Sept 2026
    Packages

    java-21-openjdk

    Summary

    Security update for java-21-openjdk

    Published
    4 Sept 2026
    CGA-7vmh-764r-v3mx
    Fix available
    Packages

    open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-f5gv-4r32-2rm4
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-jcfj-cjgw-xc3r
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-32g3-pcwp-rj37
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-r2rg-cc7j-x877
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-hvw9-g56p-xpq8
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-4rrw-wx3w-cv46
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-572v-8hf4-jhj5
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-6672-5565-7wf6
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-m76r-4xj2-mxx7
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CGA-cmjv-284g-48rv
    Fix available
    Packages

    nemo, open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    CVE-2026-85538
    Fix available
    Packages

    Summary

    MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete Attributes

    Published
    4 Sept 2026
    CGA-mp2j-7m82-rj9m
    Fix available
    Packages

    open-webui, open-webui

    Summary

    Published
    4 Sept 2026
    Packages

    transformers

    Summary

    TuxCare security update for transformers (1 CVE)

    Published
    4 Sept 2026
    CVE-2026-85533
    Fix available
    Packages

    Summary

    MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    Packages

    joomla

    Summary

    Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2

    Published
    4 Sept 2026
    SUSE-SU-2026:3974-1
    Fix available
    Packages

    podman, podman, podman, podman, podman, podman, podman, podman

    Summary

    Security update for podman

    Published
    4 Sept 2026
    CGA-5q5g-hvj7-v789
    Fix available
    Packages

    cilium-fips-1.20

    Summary

    Published
    4 Sept 2026
    CGA-cf32-m3g8-vw27
    Fix available
    Packages

    cilium-fips-1.20

    Summary

    Published
    4 Sept 2026
    CGA-wcv3-5396-4w82
    Fix available
    Packages

    telegraf-1.39

    Summary

    Published
    4 Sept 2026
    Packages

    c-ares, helm

    Summary

    Security update for helm

    Published
    4 Sept 2026
    Packages

    wget

    Summary

    Security update for wget

    Published
    4 Sept 2026
    CGA-492f-2g8x-fxrp
    Fix available
    Packages

    telegraf-1.37, telegraf-1.37

    Summary

    Published
    4 Sept 2026
    CVE-2026-85528
    Fix available
    Packages

    Summary

    Snowflake JDBC Driver auto-configuration account validation permits credential redirection

    Published
    4 Sept 2026
    CGA-736x-vgxv-39vv
    Fix available
    Packages

    telegraf-1.39

    Summary

    Published
    4 Sept 2026
    CGA-vjxv-mx2c-9vm3
    Fix available
    Packages

    argo-events, argo-events-fips, bento, bento-fips, dapr-daprd-1.16, dapr-daprd-1.17, dapr-daprd-1.18, dapr-daprd-fips-1.16, dapr-daprd-fips-1.17, falcosidekick, falcosidekick-fips, guac, guacingest, guacone, keda-2.18, keda-2.18-metrics-apiserver, keda-2.19-metrics-apiserver, keda-2.20, keda-2.20-metrics-apiserver, keda-fips-2.18, keda-fips-2.19, keda-fips-2.19-metrics-apiserver, keda-fips-2.20, keda-fips-2.20-metrics-apiserver, minio, minio-fips, nuclio-controller, nuclio-controller-fips, opentelemetry-collector-contrib, opentelemetry-collector-contrib-fips, sftpgo-plugin-pubsub, telegraf-1.36, telegraf-1.37, telegraf-1.38, trufflehog, trufflehog-fips, versitygw, versitygw-fips, argo-events, bento, dapr-daprd-1.16, dapr-daprd-1.17, falcosidekick, guac, guacingest, guacone, keda-2.19-metrics-apiserver, keda-2.20, keda-2.20-metrics-apiserver, minio, opentelemetry-collector-contrib, sftpgo-plugin-pubsub, telegraf-1.36, telegraf-1.37, telegraf-1.38, trufflehog

    Summary

    Published
    4 Sept 2026
    CGA-mh5w-gfqr-7hrv
    Fix available
    Packages

    cilium-fips-1.20-operator-aws

    Summary

    Published
    4 Sept 2026
    CVE-2026-85525
    Fix available
    Packages

    Summary

    Improper OCSP response validation in Snowflake drivers

    Published
    4 Sept 2026
    SUSE-SU-2026:3973-1
    Fix available
    Packages

    libsoup2, libsoup2, libsoup2

    Summary

    Security update for libsoup2

    Published
    4 Sept 2026
    SUSE-SU-2026:3972-1
    Fix available
    Packages

    python-h2

    Summary

    Security update for python-h2

    Published
    4 Sept 2026
    SUSE-SU-2026:3970-1
    Fix available
    Packages

    python-h2

    Summary

    Security update for python-h2

    Published
    4 Sept 2026
    SUSE-SU-2026:3969-1
    Fix available
    Packages

    python, python-base

    Summary

    Security update for python

    Published
    4 Sept 2026