Collected every two hours from specialised publications — each link leads to the original article.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged tok…
A recent security update for snphost addresses seven vulnerabilities in OpenSSL affecting various SUSE Linux products, with multiple CVEs linked to critical is…
SUSE released an important security update for libkrun fixing eight vulnerabilities, including issues with OpenSSL related to buffer overflows and memory manag…
SUSE released an important security update for afterburn, addressing 13 vulnerabilities, including multiple critical OpenSSL issues, along with various updates…
A new SUSE update addresses eight vulnerabilities, including buffer overflows in OpenSSL, with patches available for several products like SUSE Linux Enterpris…
Oracle Linux 8 has received security updates, including fixes for CVE-2026-14355 related to memory corruption in OpenSSL, along with various package updates an…
A new version 7.6 of the Squid proxy caching server for Fedora 44 has been released, featuring enhancements in performance and updates for OpenSSL compatibilit…
A security update for SUSE Linux Micro 6.0 addresses 13 vulnerabilities in afterburn, enhancing security with fixes for issues related to openssl, regex, and o…
A security update for rust-keylime addresses eight vulnerabilities, enhances OpenSSL, and provides fixes in SUSE Linux Micro 6.0, urging users to install throu…
SUSE released an important security update for afterburn, addressing nine vulnerabilities related to OpenSSL and other components, with instructions for instal…
Fedora has released an update for libwebsockets, version 4.5.8, addressing various bugs and ensuring compatibility with OpenSSL 4.0, available via the dnf upda…
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general …
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general …
Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Add upstream patches to build against openssl 4.0 Make configure.ac work with autoconf 2.73
0.088 2026-04-23 - Crypt::KeyDerivation - new functions: pbkdf1_openssl, bcrypt_pbkdf, scrypt_pbkdf, argon2_pbkdf - Crypt::Misc - new functions: random_v7uuid,…
Update pyOpenSSL to v26.0.0 (security update) Update python-cryptography to v46.0.5 (dependency of pyOpenSSL 26) Update rust-asn1 to 0.22 (dependency of python…
Coturn 4.9.0 Multiple security fixes Fix to Web Admin password check Cleanup of deprecated OpenSSL APIs Fix for CVE-2026-27624: Bypass localhost and IP range b…
Coturn 4.9.0 Multiple security fixes Fix to Web Admin password check Cleanup of deprecated OpenSSL APIs Fix for CVE-2026-27624: Bypass localhost and IP range b…
A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an m…
This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function. The openssl cr…
Changes in v1.4.13: server: Cover edge-case in the EventFilter validation client: Cover edge-case in the UserTokenPolicy validation arch: Process delayed callb…