Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    JLSEC-2025-12
    Fix available
    Packages

    Cairo_jll

    Summary

    cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of...

    Published
    10 Oct 2025
    JLSEC-2025-17
    Fix available
    Packages

    Cairo_jll

    Summary

    A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4

    Published
    10 Oct 2025
    CVE-2025-62239
    Fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-62238
    Fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-62237
    Fix available
    Packages

    Summary

    Published
    10 Oct 2025
    Packages

    kernel-livepatch-SLE15-SP3_Update_55

    Summary

    Security update for the Linux Kernel (Live Patch 55 for SLE 15 SP3)

    Published
    10 Oct 2025
    GHSA-rwvp-r38j-9rgg
    Fix available
    Packages

    github.com/nwaples/rardecode/v2, github.com/nwaples/rardecode

    Summary

    rardecode: DoS risk due to unrestricted RAR dictionary sizes

    Published
    10 Oct 2025
    GHSA-6wwv-6mm3-pp76
    No fix available
    Packages

    org.apache.streampark:streampark

    Summary

    Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerability

    Published
    10 Oct 2025
    GHSA-56r7-h6mw-rcfv
    Fix available
    Packages

    org.elasticsearch.plugin:reindex-client, org.elasticsearch.plugin:reindex-client, org.elasticsearch.plugin:reindex-client, org.elasticsearch.plugin:reindex-client

    Summary

    Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

    Published
    10 Oct 2025
    RHSA-2025:17715
    Fix available
    Packages

    vim-X11, vim-X11-debuginfo, vim-common, vim-common-debuginfo, vim-debuginfo, vim-debugsource, vim-enhanced, vim-enhanced-debuginfo, vim-filesystem, vim-minimal-debuginfo, vim, vim-X11-debuginfo, vim-common-debuginfo, vim-debuginfo, vim-debugsource, vim-enhanced-debuginfo, vim-minimal, vim-minimal-debuginfo

    Summary

    Red Hat Security Advisory: vim security update

    Published
    10 Oct 2025
    RHSA-2025:17710
    Fix available
    Packages

    compat-libtiff3

    Summary

    Red Hat Security Advisory: compat-libtiff3 security update

    Published
    10 Oct 2025
    RHSA-2025:17693
    Fix available
    Packages

    puppet-agent, puppet-agent

    Summary

    Red Hat Security Advisory: Satellite 6 Client Bug Fix Update

    Published
    10 Oct 2025
    RHSA-2025:17675
    Fix available
    Packages

    compat-libtiff3, compat-libtiff3-debuginfo, compat-libtiff3-debugsource

    Summary

    Red Hat Security Advisory: compat-libtiff3 security update

    Published
    10 Oct 2025
    RHSA-2025:17651
    Fix available
    Packages

    compat-libtiff3, compat-libtiff3

    Summary

    Red Hat Security Advisory: compat-libtiff3 security update

    Published
    10 Oct 2025
    RHSA-2025:17649
    Fix available
    Packages

    ipa, ipa-client, ipa-client-common, ipa-common, ipa-debuginfo, ipa-python-compat, ipa-server, ipa-server-common, ipa-server-dns, ipa-server-trust-ad, python2-ipaclient, python2-ipalib, python2-ipaserver

    Summary

    Red Hat Security Advisory: ipa security update

    Published
    10 Oct 2025
    RHSA-2025:17648
    Fix available
    Packages

    bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-idoverride-memberof, ipa-idoverride-memberof-plugin, ipa-python-compat, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel

    Summary

    Red Hat Security Advisory: idm:DL1 security update

    Published
    10 Oct 2025
    RHSA-2025:17647
    Fix available
    Packages

    bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-epn, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-python-compat, ipa-selinux, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-ipatests, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel, bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-epn, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-python-compat, ipa-selinux, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-ipatests, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel

    Summary

    Red Hat Security Advisory: idm:DL1 security update

    Published
    10 Oct 2025
    RHSA-2025:17646
    Fix available
    Packages

    bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-epn, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-python-compat, ipa-selinux, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-ipatests, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel, bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-epn, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-python-compat, ipa-selinux, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-ipatests, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel, bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-epn, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-python-compat, ipa-selinux, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-ipatests, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel

    Summary

    Red Hat Security Advisory: idm:client security update

    Published
    10 Oct 2025
    RHSA-2025:17645
    Fix available
    Packages

    bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-epn, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-python-compat, ipa-selinux, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-ipatests, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel, bind-dyndb-ldap, bind-dyndb-ldap-debuginfo, bind-dyndb-ldap-debugsource, custodia, ipa, ipa-client, ipa-client-common, ipa-client-debuginfo, ipa-client-epn, ipa-client-samba, ipa-common, ipa-debuginfo, ipa-debugsource, ipa-healthcheck, ipa-healthcheck-core, ipa-python-compat, ipa-selinux, ipa-server, ipa-server-common, ipa-server-debuginfo, ipa-server-dns, ipa-server-trust-ad, ipa-server-trust-ad-debuginfo, opendnssec, opendnssec-debuginfo, opendnssec-debugsource, python-jwcrypto, python-kdcproxy, python-qrcode, python-yubico, python3-custodia, python3-ipaclient, python3-ipalib, python3-ipaserver, python3-ipatests, python3-jwcrypto, python3-kdcproxy, python3-pyusb, python3-qrcode, python3-qrcode-core, python3-yubico, pyusb, slapi-nis, slapi-nis-debuginfo, slapi-nis-debugsource, softhsm, softhsm-debuginfo, softhsm-debugsource, softhsm-devel

    Summary

    Red Hat Security Advisory: idm:client security update

    Published
    10 Oct 2025
    Packages

    golang-github-nwaples-rardecode

    Summary

    Published
    10 Oct 2025
    UBUNTU-CVE-2025-11579
    No fix available
    Packages

    golang-github-nwaples-rardecode, golang-github-nwaples-rardecode

    Summary

    Published
    10 Oct 2025
    Packages

    kernel-livepatch-SLE15-SP3_Update_54

    Summary

    Security update for the Linux Kernel (Live Patch 54 for SLE 15 SP3)

    Published
    10 Oct 2025
    CVE-2025-61864
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61863
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61862
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61861
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61860
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61859
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61858
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61857
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-61856
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-52635
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-52625
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-52624
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-11190
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-11189
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-11188
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-11579
    Fix available
    Packages

    Summary

    DoS via Out Of Memory Crash

    Published
    10 Oct 2025
    Packages

    go1.25-openssl, go1.25-openssl, go1.25-openssl

    Summary

    Security update for go1.25-openssl

    Published
    10 Oct 2025
    Packages

    go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl, go1.25-openssl

    Summary

    Security update for go1.25-openssl

    Published
    10 Oct 2025
    CVE-2025-52650
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-52634
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-52632
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    CVE-2025-52630
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025
    UBUNTU-CVE-2025-37727
    No fix available
    Packages

    elasticsearch

    Summary

    Published
    10 Oct 2025
    CVE-2025-37727
    Fix available
    Packages

    Summary

    Elasticsearch Insertion of sensitive information in log file

    Published
    10 Oct 2025
    CVE-2025-25017
    Fix available
    Packages

    ,

    Summary

    Kibana Stored Cross-Site Scripting (XSS)

    Published
    10 Oct 2025
    CVE-2025-30001
    Fix available
    Packages

    Summary

    Apache StreamPark: Authenticated users can trigger remote command execution

    Published
    10 Oct 2025
    CVE-2025-25018
    Fix available
    Packages

    ,

    Summary

    Kibana Stored Cross-Site Scripting (XSS)

    Published
    10 Oct 2025
    CVE-2025-40640
    No fix available
    Packages

    Summary

    Published
    10 Oct 2025