Published issues
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- openexr_2
- openexrid-unstable
- haskellPackages.openexr-write
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion
openexr
-
==>= 3.3.0, < 3.3.11
-
==>= 3.0.0, < 3.2.9
-
==>= 3.4.0, < 3.4.11
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
reference https://g…
4 months, 1 week ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- incus-ui-canonical
- terraform-providers.incus
- terraform-providers.lxc_incus
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
Incus: Unbounded YAML Metadata Decode via Parsing
Permalink
CVE-2026-41413
5.0 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
reference https://g…
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
Istio Vulnerable to SSRF via RequestAuthentication jwksUri
istio
-
==< 1.28.6
-
==>= 1.29.0-alpha.0, < 1.29.2
Permalink
CVE-2026-42215
8.8 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
reference https://g…
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
GitPython: Command injection via Git options bypass
Permalink
CVE-2026-42284
8.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
reference https://g…
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
GitPython: Unsafe option check validates multi_options before shlex.split transforms it
Permalink
CVE-2026-44264
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
package python313Packages.weblate-fonts
4 months, 1 week ago
-
@LeSuisse
ignored
reference https://g…
4 months, 1 week ago
-
@LeSuisse
ignored
7 packages
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
Weblate is vulnerable to XSS via crafted Markdown
Permalink
CVE-2026-41685
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- incus-ui-canonical
- terraform-providers.incus
- terraform-providers.lxc_incus
4 months, 1 week ago
-
@LeSuisse
ignored
reference https://g…
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
Incus: Unbounded binary import disk exhaustion
Permalink
CVE-2026-41647
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- incus-ui-canonical
- terraform-providers.incus
- terraform-providers.lxc_incus
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
Incus: Nil-Pointer Dereference via S3 Bucket Import
Permalink
CVE-2026-41142
8.8 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
4 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
4 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- openexrid-unstable
- haskellPackages.openexr-write
- openexr_2
4 months, 1 week ago
-
@LeSuisse
accepted
4 months, 1 week ago
-
@LeSuisse
published on GitHub
4 months, 1 week ago
OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API
openexr
-
==>= 3.0.0, < 3.2.9
-
==>= 3.4.0, < 3.4.11
-
==>= 3.3.0, < 3.3.11