Collected every two hours from specialised publications — each link leads to the original article.
The updated package fixes a security vulnerability: A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with tr…
The updated packages fix security vulnerabilities: Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to …
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
Update to version 1.9.4. Resolves CVE-2019-10086.
Update to version 1.9.4. Resolves CVE-2019-10086.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Update to version 1.19. Resolves CVE-2019-12402.
Update to version 1.19. Resolves CVE-2019-12402.
An update is now available for JBoss Core Services on RHEL 6 and RHEL 7. Red Hat Product Security has rated this update as having a security impact of Importan…
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There…
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Multiple vulnerabilities in the Apache Portable Runtime Utility library apr-util could lead to denial of service or arbitrary code execution; updates are avail…
Fedora 44 has released apr-util version 1.6.5 with security fixes, enhancing its Apache Portable Runtime Utility library for better handling of XML, LDAP, and …
The Fedora 44 update for Apache Traffic Server version 10.1.4 addresses multiple security vulnerabilities, including request smuggling and memory-safety issues…
Oracle Linux released updates for Apache HTTP Server and related modules addressing multiple CVEs for security vulnerabilities, along with package version chan…
A newly disclosed attack technique called HTTP/2 Bomb is drawing attention because it targets the software that sits at the front of much of the Linux internet…
Resolves: CVE-2025-58136 - A simple legitimate POST request causes a crash CVE-2025-65114 - Malformed chunked message body allows request smuggling Changes wit…
Two vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or HTTP request smugg…
CVE-2023-46604 is not just another box on your patching to-do list''it's a major remote code execution (RCE) vulnerability in Apache ActiveMQ that admins need …
Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privile…