Collected every two hours from specialised publications — each link leads to the original article.
Moderate: libsoup security update
Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes…
Multiple vulnerabilities were discovered in dovecot, a POP3/IMAP server, which could lead to Denial of Service, information leak, path traversal, authenticatio…
An update that solves one vulnerability and has one security fix can now be installed.
An update that solves seven vulnerabilities can now be installed.
Several security issues were fixed in Python marshmallow.
Update the package, including fix for CVE-2026-34080. See also: upstream security advisory
Several security issues were fixed in follow-redirects.
Backport fix for race condition leading to root compromise (GHSA-f55j-vvr9-69xv)
CVE-2025-59438 Observable Timing Discrepancy. The presence of a padding error could leak through timings, enabling the attacker to recover information about th…
Backport fix for race condition leading to root compromise (GHSA-f55j-vvr9-69xv)
Update to 0.6.26, fixing several CVEs https://github.com/libexif/libexif/releases/tag/v0.6.26
fix bad reuse of HTTP Negotiate connection (CVE-2026-1965) fix token leak with redirect and netrc (CVE-2026-3783) fix wrong proxy connection reuse with credent…
Update to 0.6.26, fixing several CVEs https://github.com/libexif/libexif/releases/tag/v0.6.26
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities and has two fixes can now be installed.
Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosu…
An update that solves six vulnerabilities can now be installed.
Important: perl-YAML-Syck security update
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit, which may result in denial of service, information leaks, or potentia…
The first week of April 2026 marked a significant escalation in supply chain tactics. A coordinated campaign involving 36 malicious npm packages, disguised as …
Update to 9.21.20 (rhbz#2440560) Security Fixes: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations. (CVE-2026-1519) Fix memory l…
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.