Collected every two hours from specialised publications — each link leads to the original article.
Upstream release 2.98.0. https://github.com/jfrog/jfrog-cli/releases/tag/v2.98.0 Resolves the following security issues: CVE-2025-11579 CVE-2025-66564 CVE-2026…
Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged p…
An update to patch a security vulnerability. Advisory: https://github.com/AndrewGMorgan/libcap_mirror/security/advisories/GHS A-f78v-p5hx-m7hh Changelog * Mon …
update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj
Update to 0.6.26, fixing several CVEs https://github.com/libexif/libexif/releases/tag/v0.6.26
update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860): https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj
Security fix for CVE-2026-31899: https://nvd.nist.gov/vuln/detail/CVE-2026-31899 / https://github.com/Kozea/CairoSVG/security/advisories/GHSA-f38f-5xpm-9r7c Ex…
An update to patch a security vulnerability. Advisory: https://github.com/AndrewGMorgan/libcap_mirror/security/advisories/GHS A-f78v-p5hx-m7hh Changelog * Mon …
Too many changes to list. See: https://github.com/domoticz/domoticz/blob/2026.1/History.txt This also fixes a security vulnerability.
Update to 0.37.2 Fixes silent TLS certificate verification bypass on HTTPS Redirect via proxy (CVE-2026-32627, rhbz#2448105) Source: https://github.com/yhirose…
Update to version 1.7.1. Includes the fix for CVE-2026-26076: https://github.com/pendulum-project/ntpd- rs/security/advisories/GHSA-c7j7-rmvr-fjmv Release note…
A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim's clo…
Update uv and python-uv-build to 0.10.2. There are some minor breaking changes in uv; most users should not have to change anything. See https://github.com/ast…
Update to 0.30.1 Denial of service (DOS) using zip bomb (CVE-2026-22776) CRLF injection in http headers (CVE-2026-21428) Untrusted HTTP Header Handling: X-Forw…
Update to Upstream version 0.1.2 - https://github.com/complytime/complyctl/releases/tag/v0.1.2
Update to 20251230: security fix for CVE-2025-64512 https://github.com/pdfminer/pdfminer.six/blob/20251230/CHANGELOG.md
https://github.com/wb2osz/direwolf/releases/tag/1.8.1
In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In Au…
Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechan…
This update includes the latest upstream release of mod_md, with various bug fixes and enhancements. See https://github.com/icing/mod_md/releases for more info…
This update includes the latest upstream release of mod_md, with various bug fixes and enhancements. See https://github.com/icing/mod_md/releases for more info…
Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 https://github.com/nothings/stb/issues/1861
A vulnerability has been discovered in r-cran-gh, a GNU R Minimal client to access the 'GitHub' 'API'. CVE-2025-54956
uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydan…