The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Update to v3.0.50; contains fix for CVE-2026-32935
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that fixes four vulnerabilities is now available.
Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute. (CVE-2024-56519) An issue was discovered in TCPDF …
Security fix for CVE-2023-52892, CVE-2024-27354
A previously undocumented backdoor named Msupedge has been put to use against a cyber attack targeting an unnamed university in Taiwan."The most notable featur…
* bsc#1226181 * bsc#1226182 Cross-References: * CVE-2024-35241
* bsc#1226181 * bsc#1226182 Cross-References: * CVE-2024-35241
* bsc#1219757 Cross-References: * CVE-2024-24821
Libxml - GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). (CVE-2023-3823) Phar - GHSA-jqcx-ccgc-xwhv (Buffer misma…
Ubuntu security team noted after extensive testing that DLA-3495-1 was incomplete as one PoC for CVE-2022-2400 (particularly the chroot escape) was still worki…
Fixed SOAP bug GHSA-76gg-c692-v2mw (Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP). (CVE-2023-3247) References: - ht…
**Version 2.25.2** * This release provides a patch for **CVE-2023-29530** / GHSA-xv3h-4844-9h36 / LP2023-01.
Cross site scripting vulnerability in Javascript escaping. (CVE-2023-28447) Additional bug fixes included. See referenced release notes for details.
**Version 4.4.50** (2023-02-01) * **security cve-2022-24895** [Security/Http] Remove CSRF tokens from storage on successful login (nicolas-grekas) * **security…
**Version 4.4.50** (2023-02-01) * **security cve-2022-24895** [Security/Http] Remove CSRF tokens from storage on successful login (nicolas-grekas) * **security…
**Changes in version 1.6.0** Bug Fixes: * Introduce required service_name constructor argument to fix service hostname discovery exploitation vulnerability **C…
**Changes in version 1.6.0** Bug Fixes: * Introduce required service_name constructor argument to fix service hostname discovery exploitation vulnerability **C…
**Changes in version 1.6.0** Bug Fixes: * Introduce required service_name constructor argument to fix service hostname discovery exploitation vulnerability **C…
Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked (CVE-2020-28948) * Archive_Tar: improper filename sanitization …
GD - Fixed bug #81739: OOB read due to insufficient input validation in imageloadfont(). Hash - Fixed bug #81738: buffer overflow in hash_update() on long para…