latest-dev
Pre-release
Pre-release
π¦ frappe-suite β v16.33.0-dev+f823a00
Release type: prerelease β’ Commit:
f823a00
Security: π‘οΈ β Critical β 45 critical and 419 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
| GitHub Container Registry | ghcr.io/homelabhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/frappe-suite
docker pull docker.io/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
cr.pcfae.com/hlhd/frappe-suite
docker pull cr.pcfae.com/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
ghcr.io/homelabhd/frappe-suite
docker pull ghcr.io/homelabhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
Notable Changes
Documentation
- refresh generated badges (stagefreight)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
Security
π‘οΈ β Critical β 45 critical and 419 high vulnerabilities detected
Vulnerability details (45 critical, 419 high, 558 medium, 387 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-58016 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with... |
| Critical | CVE-2026-33845 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read... |
| Critical | CVE-2026-42010 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw was found in gnutls. Servers configured with RSA-PSK (RivestβShamirβAdleman β Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames... |
| Critical | CVE-2026-13221 | libperl5.36 | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | libperl5.36 | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | libperl5.36 | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2025-7458 | libsqlite3-0 | 3.40.1-2+deb12u2 | β | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of... |
| Critical | CVE-2026-6653 | libxml2 | 2.9.14+dfsg-1.3~deb12u6 | β | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper... |
| Critical | CVE-2026-13221 | perl | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2026-13221 | perl-base | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl-base | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-base | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2026-13221 | perl-modules-5.36 | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl-modules-5.36 | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-modules-5.36 | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2023-45853 | zlib1g | 1:1.2.13.dfsg-1 | β | zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6 |
| Critical | CVE-2023-45133 | @babel/traverse | 7.21.5 | 7.23.2, 8.0.0-alpha.4 | babel: arbitrary code execution |
| Critical | CVE-2022-37601 | loader-utils | 0.2.17 | 2.0.3, 1.4.1 | loader-utils: prototype pollution in function parseQuery in parseQuery.js |
| Critical | CVE-2026-41242 | protobufjs | 7.2.6 | 8.0.1, 7.5.5 | protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields |
| Critical | CVE-2026-9277 | shell-quote | 1.8.1 | 1.8.4 | shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators |
| Critical | CVE-2026-59873 | tar | 7.5.1 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| Critical | CVE-2026-54466 | websocket-driver | 0.7.4 | 0.7.5 | websocket-driver is a WebSocket protocol handler with pluggable I/O. P ... |
| Critical | CVE-2023-24538 | stdlib | v1.19 | 1.19.8, 1.20.3 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals... |
| Critical | CVE-2023-24540 | stdlib | v1.19 | 1.19.9, 1.20.4 | Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript... |
| Critical | CVE-2024-24790 | stdlib | v1.19 | 1.21.11, 1.22.4 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms. |
| Critical | CVE-2025-68121 | stdlib | v1.19 | 1.24.13, 1.25.7, 1.26.0-rc.3 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may... |
| Critical | GHSA-76p3-8jx3-jpfq | loader-utils | 0.2.17 | 1.4.1 | Prototype pollution in webpack loader-utils |
| Critical | GO-2023-1703 | stdlib | go1.19 | 1.19.8 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals... |
| Critical | GO-2024-2887 | stdlib | go1.19 | 1.21.11 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms. |
| Critical | CVE-2023-29404 | stdlib | go1.19 | 1.19.10 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code... |
| Critical | CVE-2023-29405 | stdlib | go1.19 | 1.19.10 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code... |
| Critical | CVE-2023-29402 | stdlib | go1.19 | 1.19.10 | The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo... |
| Critical | GO-2023-1752 | stdlib | go1.19 | 1.19.9 | Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript... |
| Critical | CVE-2023-24531 | stdlib | go1.19 | 1.21.0-0 | Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad... |
| Critical | GHSA-w7jw-789q-3m8p | shell-quote | 1.8.1 | 1.8.4 | shell-quote quote() does not escape newlines in object .op values |
| Critical | GO-2026-4337 | stdlib | go1.19 | 1.24.13 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may... |
| Critical | GO-2025-3563 | stdlib | go1.19 | 1.23.8 | The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines... |
| Critical | GHSA-xq3m-2v4x-88gg | protobufjs | 7.2.6 | 7.5.5 | Arbitrary code execution in protobufjs |
| Critical | CVE-2026-27143 | stdlib | go1.19 | 1.25.9 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially... |
| Critical | GHSA-23hp-3jrh-7fpw | tar | 7.5.1 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| Critical | GHSA-67hx-6x53-jw92 | @babel/traverse | 7.21.5 | 7.23.2 | Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code |
| Critical | GHSA-xv26-6w52-cph6 | websocket-driver | 0.7.4 | 0.7.5 | websocket-driver: Message corruption via abuse of protocol length headers |
| Critical | GHSA-2jcg-qqmg-46q6 | monorepo-symlink-test | 0.0.0 | β | Malware in monorepo-symlink-test |
| High | CVE-2026-53613 | bsdutils | 1:2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-12064 | curl | 7.88.1-10+deb12u15 | β | When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl... |
| High | CVE-2026-6276 | curl | 7.88.1-10+deb12u15 | β | Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the... |
| High | CVE-2026-8286 | curl | 7.88.1-10+deb12u15 | β | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. |
| High | CVE-2026-8458 | curl | 7.88.1-10+deb12u15 | β | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent... |
| High | CVE-2026-8927 | curl | 7.88.1-10+deb12u15 | β | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests... |
| High | CVE-2026-41992 | gzip | 1.12-1 | β | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single... |
| High | CVE-2026-54369 | libacl1 | 2.3.1-3 | β | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that... |
| High | CVE-2026-53613 | libblkid1 | 2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-12064 | libcurl3-gnutls | 7.88.1-10+deb12u15 | β | When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl... |
| High | CVE-2026-6276 | libcurl3-gnutls | 7.88.1-10+deb12u15 | β | Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the... |
| High | CVE-2026-8286 | libcurl3-gnutls | 7.88.1-10+deb12u15 | β | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. |
| High | CVE-2026-8458 | libcurl3-gnutls | 7.88.1-10+deb12u15 | β | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent... |
| High | CVE-2026-8927 | libcurl3-gnutls | 7.88.1-10+deb12u15 | β | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests... |
| High | CVE-2026-12064 | libcurl4 | 7.88.1-10+deb12u15 | β | When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl... |
| High | CVE-2026-6276 | libcurl4 | 7.88.1-10+deb12u15 | β | Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the... |
| High | CVE-2026-8286 | libcurl4 | 7.88.1-10+deb12u15 | β | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. |
| High | CVE-2026-8458 | libcurl4 | 7.88.1-10+deb12u15 | β | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent... |
| High | CVE-2026-8927 | libcurl4 | 7.88.1-10+deb12u15 | β | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests... |
| High | CVE-2025-59375 | libexpat1 | 2.5.0-1+deb12u3 | β | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| High | CVE-2026-25210 | libexpat1 | 2.5.0-1+deb12u3 | β | In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation. |
| High | CVE-2026-45186 | libexpat1 | 2.5.0-1+deb12u3 | β | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. |
| High | CVE-2026-66046 | libexpat1 | 2.5.0-1+deb12u3 | β | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with... |
| High | CVE-2026-58010 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check... |
| High | CVE-2026-58011 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the... |
| High | CVE-2026-58012 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change replacement escapes because the string_append... |
| High | CVE-2026-58013 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing... |
| High | CVE-2026-58014 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value... |
| High | CVE-2026-58015 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server... |
| High | CVE-2026-33846 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS... |
| High | CVE-2026-3833 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of nameConstraints labels, specifically for dNSName (DNS) or rfc822Name (email)... |
| High | CVE-2026-42009 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic... |
| High | CVE-2023-25193 | libharfbuzz-subset0 | 6.0.0+dfsg-3 | β | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. |
| High | CVE-2023-25193 | libharfbuzz0b | 6.0.0+dfsg-3 | β | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. |
| High | CVE-2023-2953 | libldap-2.5-0 | 2.5.13+dfsg-5 | β | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
| High | CVE-2026-53613 | libmount1 | 2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2025-69720 | libncurses6 | 6.4-4 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2025-69720 | libncursesw6 | 6.4-4 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2026-42497 | libperl5.36 | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without... |
| High | CVE-2026-48962 | libperl5.36 | 5.36.0-7+deb12u3 | β | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string... |
| High | CVE-2026-57432 | libperl5.36 | 5.36.0-7+deb12u3 | β | Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count... |
| High | CVE-2026-57433 | libperl5.36 | 5.36.0-7+deb12u3 | β | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and... |
| High | CVE-2026-9538 | libperl5.36 | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with |
| High | CVE-2026-53613 | libsmartcols1 | 2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-37555 | libsndfile1 | 1.2.0-1+deb12u1 | β | An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not... |
| High | CVE-2026-11822 | libsqlite3-0 | 3.40.1-2+deb12u2 | β | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution... |
| High | CVE-2026-11824 | libsqlite3-0 | 3.40.1-2+deb12u2 | β | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a... |
| High | CVE-2026-58050 | libssh2-1 | 1.10.0-3+b1 | β | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without... |
| High | CVE-2026-7598 | libssh2-1 | 1.10.0-3+b1 | β | A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c... |
| High | CVE-2025-69720 | libtinfo6 | 6.4-4 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2026-53613 | libuuid1 | 2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-53613 | mount | 2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2025-69720 | ncurses-base | 6.4-4 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2025-69720 | ncurses-bin | 6.4-4 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2026-42533 | nginx | 1.22.1-9+deb12u9 | β | A vulnerability exists in NGINX Plus and NGINX Open Source when a mapΒ directive uses regex matching and a string expression references the map's regex capture variables before referencing the map... |
... and 1309 more of lower severity (see full report in release assets)
Full changelog
- [
f823a00] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
7349335] refresh generated badges (stagefreight)