Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2025-48043
    Fix available
    Packages

    Summary

    Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization

    Published
    10 Oct 2025
    EEF-CVE-2025-48043
    Fix available
    Packages

    ash,

    Summary

    Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization

    Published
    10 Oct 2025
    GHSA-rpjr-pcmr-9ppw
    Fix available
    Packages

    alt-design/alt-redirect

    Summary

    Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw

    Published
    10 Oct 2025
    GHSA-m4g9-5mg6-gfr3
    Fix available
    Packages

    com.liferay.commerce:com.liferay.commerce.order.web

    Summary

    Liferay Portal Commerce is vulnerable to XSS through account "name" field

    Published
    10 Oct 2025
    GHSA-xcvw-hh99-qm73
    Fix available
    Packages

    com.liferay:com.liferay.portal.workflow.kaleo.designer.web

    Summary

    Liferay Portal is vulnerable to XSS through its workflow process builder

    Published
    10 Oct 2025
    GHSA-xw6m-3m5q-mxpm
    Fix available
    Packages

    com.liferay:com.liferay.account.admin.web

    Summary

    Liferay Portal's Membership page is vulnerable to XSS through “name“ text field

    Published
    10 Oct 2025
    Packages

    expat, expat, expat, expat, expat, expat

    Summary

    Security update for expat

    Published
    10 Oct 2025
    Packages

    expat, expat

    Summary

    Security update for expat

    Published
    10 Oct 2025
    CVE-2025-60378
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    Packages

    open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools

    Summary

    Security update for open-vm-tools

    Published
    10 Oct 2025
    Packages

    podman, podman, podman, podman, podman, podman

    Summary

    Security update for podman

    Published
    10 Oct 2025
    Packages

    podofo

    Summary

    Security update for podofo

    Published
    10 Oct 2025
    JLSEC-2025-38
    Fix available
    Packages

    CURL_jll, LibCURL_jll

    Summary

    libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized...

    Published
    10 Oct 2025
    JLSEC-2025-37
    Fix available
    Packages

    LibCURL_jll

    Summary

    libcurl's URL API function [`curl_url_get()`](https://curl.se/libcurl/c/curl_url_get.html) offers...

    Published
    10 Oct 2025
    JLSEC-2025-36
    Fix available
    Packages

    CURL_jll, LibCURL_jll

    Summary

    libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string

    Published
    10 Oct 2025
    JLSEC-2025-33
    Fix available
    Packages

    CURL_jll, LibCURL_jll

    Summary

    An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a...

    Published
    10 Oct 2025
    JLSEC-2025-32
    Fix available
    Packages

    LibCURL_jll

    Summary

    A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate...

    Published
    10 Oct 2025
    JLSEC-2025-31
    Fix available
    Packages

    CURL_jll, LibCURL_jll

    Summary

    An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature...

    Published
    10 Oct 2025
    JLSEC-2025-30
    Fix available
    Packages

    CURL_jll, LibCURL_jll

    Summary

    An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which...

    Published
    10 Oct 2025
    JLSEC-2025-29
    Fix available
    Packages

    LibCURL_jll

    Summary

    When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances...

    Published
    10 Oct 2025
    JLSEC-2025-28
    Fix available
    Packages

    LibCURL_jll

    Summary

    libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if...

    Published
    10 Oct 2025
    JLSEC-2025-26
    Fix available
    Packages

    LibCURL_jll

    Summary

    curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to...

    Published
    10 Oct 2025
    JLSEC-2025-25
    Fix available
    Packages

    LibCURL_jll

    Summary

    curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to...

    Published
    10 Oct 2025
    JLSEC-2025-23
    Fix available
    Packages

    LibCURL_jll

    Summary

    Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when...

    Published
    10 Oct 2025
    JLSEC-2025-24
    Fix available
    Packages

    LibCURL_jll

    Summary

    curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow...

    Published
    10 Oct 2025
    JLSEC-2025-27
    Fix available
    Packages

    LibCURL_jll

    Summary

    curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to...

    Published
    10 Oct 2025
    JLSEC-2025-34
    Fix available
    Packages

    CURL_jll, LibCURL_jll

    Summary

    This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.

    Published
    10 Oct 2025
    JLSEC-2025-35
    Fix available
    Packages

    CURL_jll, LibCURL_jll

    Summary

    This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the...

    Published
    10 Oct 2025
    CGA-vf3r-jmrx-6v96
    Fix available
    Packages

    python-3.9, python-3.9-base, python-3.9-base-dev, python-3.9-dev, python-3.9-doc

    Summary

    Published
    10 Oct 2025
    CGA-w4mf-7pqf-pr6v
    Fix available
    Packages

    kibana-7

    Summary

    Published
    10 Oct 2025
    Packages

    redis, redis-devel, redis-doc

    Summary

    redis: Fix of CVE-2025-49844

    Published
    10 Oct 2025
    Packages

    exiv2, exiv2-devel, exiv2-doc, exiv2-libs

    Summary

    exiv2: Fix of CVE-2025-55304

    Published
    10 Oct 2025
    ECHO-34b9-8f36-6eee
    No fix available
    Packages

    linux

    Summary

    Kernel vulnerabilities are irrelevant in container environments.

    Published
    10 Oct 2025
    ECHO-82cb-5860-a1fc
    Fix available
    Packages

    linux

    Summary

    Kernel vulnerabilities are irrelevant in container environments.

    Published
    10 Oct 2025
    ECHO-29bf-fe74-2a5d
    Fix available
    Packages

    linux

    Summary

    Kernel vulnerabilities are irrelevant in container environments.

    Published
    10 Oct 2025
    ECHO-5782-8486-d87b
    Fix available
    Packages

    linux

    Summary

    Kernel vulnerabilities are irrelevant in container environments.

    Published
    10 Oct 2025
    JLSEC-2025-22
    Fix available
    Packages

    Dbus_jll

    Summary

    D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon

    Published
    10 Oct 2025
    JLSEC-2025-21
    Fix available
    Packages

    Dbus_jll

    Summary

    An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...

    Published
    10 Oct 2025
    JLSEC-2025-20
    Fix available
    Packages

    Dbus_jll

    Summary

    An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...

    Published
    10 Oct 2025
    JLSEC-2025-19
    Fix available
    Packages

    Dbus_jll

    Summary

    An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...

    Published
    10 Oct 2025
    JLSEC-2025-18
    Fix available
    Packages

    Dbus_jll

    Summary

    An issue was discovered in dbus >= 1.3.0 before 1.12.18

    Published
    10 Oct 2025
    Packages

    nss, nss-devel, nss-pkcs11-devel, nss-sysinit, nss-tools

    Summary

    nss: Fix of CVE-2020-25648

    Published
    10 Oct 2025
    Packages

    binutils, binutils-devel

    Summary

    binutils: Fix of CVE-2017-9042

    Published
    10 Oct 2025
    DEBIAN-CVE-2025-61152
    No fix available
    Packages

    python-jose

    Summary

    Published
    10 Oct 2025
    CVE-2025-61152
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    UBUNTU-CVE-2025-61152
    No fix available
    Packages

    python-jose, python-jose

    Summary

    Published
    10 Oct 2025
    JLSEC-2025-16
    Fix available
    Packages

    Cairo_jll

    Summary

    An issue was discovered in cairo 1.16.0

    Published
    10 Oct 2025
    JLSEC-2025-15
    Fix available
    Packages

    Cairo_jll

    Summary

    An issue was discovered in cairo 1.16.0

    Published
    10 Oct 2025
    JLSEC-2025-14
    Fix available
    Packages

    Cairo_jll

    Summary

    cairo 1.16.0, in `cairo_ft_apply_variations()` in cairo-ft-font.c, would free memory using a free...

    Published
    10 Oct 2025
    JLSEC-2025-13
    Fix available
    Packages

    Cairo_jll

    Summary

    cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted...

    Published
    10 Oct 2025