View packages at a commit

Paste a `locked_commit` from your `minimal.toml`, or a recent commit from the list.

Security advisories

130 advisories affecting the catalog, most severe first.

Showing 130 advisories.

Security advisories affecting the package catalog
SeverityAdvisoryAffected packagesStatus
Critical: 9.1

AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()

opensslAffected
Critical: 9.8

Untrusted Sender DN Used as Format String in CMP Response Validation

opensslAffected
Critical

llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler

llama.cppResolved
Critical

Libevent: HTTP header handling bugs create risk of access control bypass.

libeventUnder investigation
Critical

libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling

libeventUnder investigation
Critical

libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c

libssh2Under investigation
Critical: 9.8

llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend

llama.cppResolved
High: 8.2pcre2Under investigation
High: 8.0

No summary provided.

libxml2Under investigation
High

Redis TLS pending-data list use-after-free

redisAffected
High: 7.5

Invalid Pointer Dereference in CMP Server via Crafted protectionAlg

opensslAffected
High: 7.5

QUIC ACK-only Packet Retention Can Cause Memory Exhaustion

opensslAffected
High: 7.5

Heap Buffer Overflow in CMS Key Unwrapping

opensslAffected
High: 7.5

Excessive Memory Use Buffering DTLS Records for a Future Epoch

opensslAffected
High: 7.5

QUIC Server May Trigger Double Free When Processing INITIAL Packet

opensslAffected
High: 7.5

RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate

opensslAffected
High

act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend

actUnder investigation
High

Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode

capstoneUnder investigation
High: 7.0

Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response

libeventUnder investigation
High

Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value.

libeventUnder investigation
High

Libevent: decode_tag_internal() can lead to out-of-bounds read

libeventUnder investigation
High: 8.4

Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept

libeventUnder investigation
High

Expat Denial of Service via storeAtts() Quadratic Complexity

expatUnder investigation
High: 7.5

Unbounded Memory Growth in QUIC Server Incoming Channel Queue

opensslAffected
High: 7.5

Client-Side Memory Leak in OCSP Response Checking

opensslAffected
High: 8.6

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

bisonUnder investigation
High

libssh2 Heap Buffer Overflow via ETM Cipher Negotiation

libssh2Under investigation
High

libssh2 Heap Out-of-Bounds Read via publickey subsystem

libssh2Under investigation
High

libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation

libssh2Under investigation
High

libssh2 Double-Free Heap Corruption via sftp_open()

libssh2Affected
High

GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing

wgetUnder investigation
High: 7.5

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer. This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.

gzipUnder investigation
High

libssh2 - Free of Uninitialized Pointer in publickey List Cleanup

libssh2Under investigation
High

libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation

libssh2Under investigation
High

libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c

libssh2Under investigation
High

libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler

libssh2Under investigation
High: 7.3

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

glibcUnder investigation
High: 7.5

CVE-2026-6069

nasmAffected
High: 7.5

CVE-2026-6067

nasmAffected
High: 7.8

llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsing

llama.cppResolved
High: 7.8

llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fix

llama.cppResolved
High

Heap-buffer-overflow in pcre2_compile_32

pcre2Under investigation
High

Heap-buffer-overflow in opj_j2k_read_tile_header

openjpegAffected
High

Heap-buffer-overflow in btf_ensure_modifiable

libbpfUnder investigation
High

Heap-buffer-overflow in opj_jp2_apply_pclr

opencvUnder investigation
High: 8.8libxml2Under investigation
Medium: 5.6

No summary provided.

libxml2Under investigation
Medium: 6.9

No summary provided.

libxml2Under investigation
Medium: 6.9

No summary provided.

libxml2Under investigation
Medium: 6.9

No summary provided.

libxml2Under investigation
Medium: 6.9

No summary provided.

libxml2Under investigation
Medium: 6.5

PCRE2: integer overflow in pcre2_compile_32() causes out-of-bounds write on 32-bit systems

pcre2Under investigation
Medium: 5.7

PCRE2: out-of-bounds write in pcre2_pattern_convert() with large patterns on 32-bit systems

pcre2Under investigation
Medium: 5.9

CMP Indefinite Cache Growth of ExtraCerts

opensslAffected
Medium

Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode

capstoneUnder investigation
Medium

Libevent: HTTP Header smuggling

libeventUnder investigation
Medium

Libevent: Null Pointer Dereference in `evws_new_session`

libeventAffected
Medium

Libevent: Dangling Pointer in `evbuffer_add_buffer_reference`

libeventUnder investigation
Medium: 4.9

No summary provided.

expatUnder investigation
Medium: 5.9

No summary provided.

expatUnder investigation
Medium

The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.

pythonUnder investigation
Medium

`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

pythonUnder investigation
MediumpythonUnder investigation
Medium: 5.1

Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and process crashes

capstoneUnder investigation
Medium: 5.5

ARM check_pop_return use-of-uninitialized-value

capstoneUnder investigation
Medium: 5.7

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch

perlUnder investigation
Medium

llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure

llama.cppResolved
Medium: 4.4

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

tarUnder investigation
Medium: 4.4

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

tarUnder investigation
Medium: 6.3

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

bisonUnder investigation
Medium

Out‑of‑bounds Read in GNU coreutils

coreutilsUnder investigation
Medium: 5.3

root-side banner file disclosure

cupsUnder investigation
Medium: 5.5

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

patchUnder investigation
Medium: 5.5

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313

patchUnder investigation
Medium

GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding

wgetUnder investigation
Medium

GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c

wgetUnder investigation
Medium

GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing

wgetUnder investigation
Medium: 4.7

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269

gzipUnder investigation
Medium

Use-of-uninitialized-value in iup_delta_optimize

harfbuzzUnder investigation
Medium: 6.7

Stack buffer overflow in sample/http-server via unbounded Unix socket path (strcpy)

libeventUnder investigation
Medium: 5.7

CUPS copy_model() creates a predictable PPD tempfile without O_EXCL/O_NOFOLLOW (symlink TOCTOU, lp → root)

cupsUnder investigation
Medium: 5.4

LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body

libpngUnder investigation
Medium

jq: stack overflow in module loading on mutual `include`

jqUnder investigation
Medium: 6.5

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

glibcUnder investigation
Medium: 6.5

CVE-2026-6068

nasmAffected
MediumpythonUnder investigation
Medium: 5.5

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.

numpyResolved
Medium: 5.5

__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.

numpyResolved
Low: 2.9

No summary provided.

libxml2Under investigation
Low: 2.9

No summary provided.

libxml2Under investigation
Low: 3.7

PCRE2: out-of-bounds reads in pcre2_match() when matching invalid UTF subjects with PCRE2_MATCH_INVALID_UTF

pcre2Under investigation
Low: 2.9

PCRE2: out-of-bounds read in pcre2_match() after JIT fallback with invalid UTF

pcre2Under investigation
Low

GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default

ghAffected
Low

zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

pythonUnder investigation
Low

broot Terminal Escape Sequence Injection via Unsanitized File and Directory Names in the Tree View

brootUnder investigation
Low

Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and parser desynchronization

capstoneUnder investigation
Low

Heap-based Buffer Overflow in GNU coreutils

coreutilsUnder investigation
Low: 3.3

Uncontrolled memory allocation in LIEF ELF Note parser (`Note::create`)

liefUnder investigation
Low

Stack-Based Buffer Overflow in libxml2

libxml2Under investigation
Low: 2.5

CUPS fax option values bypass the CVE-2026-34980 control-character sanitizer (incomplete fix)

cupsUnder investigation
Low: 3.3

CUPS ipp backend status-line injection can update queue PPD and lead to conditional RCE as lp via foomatic-rip

cupsUnder investigation
Low: 3.3

Rizin: Double free in cmd_search.c

rizinAffected
Low

WebAssembly Binaryen IRBuilder wasm-ir-builder.cpp makeLocalTee null pointer dereference

binaryenAffected
Low

WebAssembly Binaryen wasm-binary.cpp readExport heap-based overflow

binaryenAffected
Low: 2.9

PCRE2: uninitialized memory disclosure in pcre2_serialize_encode()

pcre2Under investigation
Low

UNKNOWN READ in std::__1::__function::__func<cv::PngDecoder::compose_frame

opencvUnder investigation
Low

UNKNOWN READ in boost::re_detail_500::basic_regex_formatter<std::__1::ostream_iterator<char, cha

boostFix unavailable
Low

UNKNOWN READ in init_struct_ops_maps

libbpfUnder investigation
Low: 3.3

A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

unzipUnder investigation
Unknown

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).

curlUnder investigation
Unknown

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected store is then incorrectly accepted.

curlUnder investigation
Unknown

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.

curlUnder investigation
Unknown

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

curlUnder investigation
Unknown

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.

curlUnder investigation
Unknown

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations.

curlUnder investigation
Unknown

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

curlUnder investigation
Unknown

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

curlUnder investigation
Unknown

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

curlUnder investigation
Unknown

Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688

vimAffected
Unknown

Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013

vimAffected
Unknown

Ex Command Injection via Unescaped '|' in tagfiles() Path (ccomplete.vim StructMembers)

vimAffected
Unknown

Connection created for the wrong upstream for forward_auth + reverse_proxy

caddyUnder investigation
Unknown

Bad-cast to cv::PngDecoder from invalid vptr

opencvUnder investigation
Unknown

Null-dereference READ in _libssh2_packet_add

libssh2Fix unavailable
Unknown

Null-dereference READ in session_startup

libssh2Affected
Unknown

Null-dereference READ in ubsan_GetStackTrace

libssh2Affected
Unknown

Null-dereference READ in _libssh2_packet_add

libssh2Affected
Unknown

Incorrect-function-pointer-type in cv::split

opencvUnder investigation
Unknown

Null-dereference READ in session_startup

libssh2Affected
Unknown

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.

lua51Under investigation

Join the waitlist

Confirm your identity by email or GitHub.

or