latest-dev
Pre-release
Pre-release
π¦ synapse β v0.0.0-dev+8614544
Release type: prerelease β’ Commit:
8614544
Security: π‘οΈ β Critical β 7 critical and 136 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/synapse |
dev-8614544 latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/synapse |
dev-8614544 latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/synapse |
dev-8614544 latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/synapse
docker pull docker.io/hlhd/synapse@sha256:031573d6ae4b635ae794561dbc2e64d146e77c14ce6f3af1308586335372c096
cr.pcfae.com/hlhd/synapse
docker pull cr.pcfae.com/hlhd/synapse@sha256:031573d6ae4b635ae794561dbc2e64d146e77c14ce6f3af1308586335372c096
ghcr.io/homelabhd/synapse
docker pull ghcr.io/homelabhd/synapse@sha256:031573d6ae4b635ae794561dbc2e64d146e77c14ce6f3af1308586335372c096
Notable Changes
Features
- image: package a hardened synapse image with s3 media and the antispam hook (SoFMeRight)
Documentation
- refresh generated badges (stagefreight) Γ2
- drop the decorative emoji from the title (SoFMeRight)
- follow the org readme structure and document configuration (SoFMeRight)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) Γ3
Security
π‘οΈ β Critical β 7 critical and 136 high vulnerabilities detected
Vulnerability details (7 critical, 136 high, 173 medium, 106 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-6653 | libxml2 | 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | β | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper... |
| Critical | CVE-2026-13221 | perl-base | 5.40.1-6 | 5.40.1-6+deb13u1 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string... |
| Critical | CVE-2026-42496 | perl-base | 5.40.1-6 | 5.40.1-6+deb13u1 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-base | 5.40.1-6 | 5.40.1-6+deb13u1 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit... |
| Critical | CVE-2025-68121 | stdlib | v1.24.4 | 1.24.13, 1.25.7, 1.26.0-rc.3 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may... |
| Critical | GO-2026-4337 | stdlib | go1.24.4 | 1.24.13 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may... |
| Critical | CVE-2026-27143 | stdlib | go1.24.4 | 1.25.9 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially... |
| High | CVE-2026-76642 | bsdutils | 1:2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | bsdutils | 1:2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | bsdutils | 1:2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | bsdutils | 1:2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-12064 | curl | 8.14.1-2+deb13u4 | 8.21.0 | When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl... |
| High | CVE-2026-8286 | curl | 8.14.1-2+deb13u4 | 8.21.0 | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. |
| High | CVE-2026-8458 | curl | 8.14.1-2+deb13u4 | 8.21.0 | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent... |
| High | CVE-2026-8927 | curl | 8.14.1-2+deb13u4 | 8.21.0 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests... |
| High | CVE-2026-41992 | gzip | 1.13-1 | 1.13-1+deb13u1 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single... |
| High | CVE-2026-54369 | libacl1 | 2.3.2-2+b1 | β | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that... |
| High | CVE-2026-76642 | libblkid1 | 2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libblkid1 | 2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | libblkid1 | 2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | libblkid1 | 2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-12064 | libcurl4t64 | 8.14.1-2+deb13u4 | β | When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl... |
| High | CVE-2026-8286 | libcurl4t64 | 8.14.1-2+deb13u4 | β | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. |
| High | CVE-2026-8458 | libcurl4t64 | 8.14.1-2+deb13u4 | β | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent... |
| High | CVE-2026-8927 | libcurl4t64 | 8.14.1-2+deb13u4 | β | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests... |
| High | CVE-2026-76642 | liblastlog2-2 | 2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | liblastlog2-2 | 2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | liblastlog2-2 | 2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | liblastlog2-2 | 2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-76642 | libmount1 | 2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libmount1 | 2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | libmount1 | 2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | libmount1 | 2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2025-69720 | libncursesw6 | 6.5+20250216-2 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2026-86145 | libpcre2-8-0 | 10.46-1~deb13u1 | 10.46-1~deb13u2 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated... |
| High | CVE-2026-89161 | libpcre2-8-0 | 10.46-1~deb13u1 | 10.46-1~deb13u2 | In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. |
| High | CVE-2026-76642 | libsmartcols1 | 2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libsmartcols1 | 2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | libsmartcols1 | 2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | libsmartcols1 | 2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-11822 | libsqlite3-0 | 3.46.1-7+deb13u1 | 3.46.1-7+deb13u2 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution... |
| High | CVE-2026-11824 | libsqlite3-0 | 3.46.1-7+deb13u1 | 3.46.1-7+deb13u2 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a... |
| High | CVE-2026-58050 | libssh2-1t64 | 1.11.1-1+deb13u1 | 1.11.1-1+deb13u2 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without... |
| High | CVE-2026-16742 | libsystemd0 | 257.13-1~deb13u1 | β | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user |
| High | CVE-2025-69720 | libtinfo6 | 6.5+20250216-2 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2026-16742 | libudev1 | 257.13-1~deb13u1 | β | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user |
| High | CVE-2026-76642 | libuuid1 | 2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libuuid1 | 2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | libuuid1 | 2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | libuuid1 | 2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-74860 | libxml2 | 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | β | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition... |
| High | CVE-2026-86140 | libxml2 | 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | β | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. |
| High | CVE-2026-76642 | login | 1:4.16.0-2+really2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | login | 1:4.16.0-2+really2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | login | 1:4.16.0-2+really2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | login | 1:4.16.0-2+really2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-76642 | mount | 2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | mount | 2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | mount | 2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | mount | 2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2025-69720 | ncurses-base | 6.5+20250216-2 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2025-69720 | ncurses-bin | 6.5+20250216-2 | β | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. |
| High | CVE-2026-42497 | perl-base | 5.40.1-6 | 5.40.1-6+deb13u1 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without... |
| High | CVE-2026-48962 | perl-base | 5.40.1-6 | 5.40.1-6+deb13u1 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string... |
| High | CVE-2026-57432 | perl-base | 5.40.1-6 | 5.40.1-6+deb13u1 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack... |
| High | CVE-2026-57433 | perl-base | 5.40.1-6 | 5.40.1-6+deb13u1 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and... |
| High | CVE-2026-9538 | perl-base | 5.40.1-6 | β | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with |
| High | CVE-2026-76642 | util-linux | 2.41.5-0+deb13u1 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | util-linux | 2.41.5-0+deb13u1 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | util-linux | 2.41.5-0+deb13u1 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | util-linux | 2.41.5-0+deb13u1 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-42304 | Twisted | 25.5.0 | 26.4.0rc2 | python-twisted: Twisted: Denial of Service via crafted DNS packets in twisted.names |
| High | CVE-2026-69247 | cryptography | 46.0.7 | 50.0.0 | python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing |
| High | CVE-2026-69249 | cryptography | 46.0.7 | 49.0.0 | python-cryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-building |
| High | GHSA-537c-gmf6-5ccf | cryptography | 46.0.7 | 48.0.1 | Vulnerable OpenSSL included in cryptography wheels |
| High | CVE-2026-41608 | thrift | 0.22.0 | 0.24.0 | thrift: Apache Thrift Python bindings: Denial of Service via data amplification |
| High | CVE-2026-43871 | thrift | 0.22.0 | 0.24.0 | thrift: Apache Thrift: Denial of Service via infinite loop |
| High | CVE-2026-82397 | tornado | 6.5.7 | 6.5.8 | Tornado is a Python web framework and asynchronous networking library. ... |
| High | CVE-2025-61726 | stdlib | v1.24.4 | 1.24.12, 1.25.6 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size... |
| High | CVE-2025-61729 | stdlib | v1.24.4 | 1.24.11, 1.25.5 | Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out... |
| High | CVE-2026-25679 | stdlib | v1.24.4 | 1.25.8, 1.26.1 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. |
| High | CVE-2026-27145 | stdlib | v1.24.4 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries... |
| High | CVE-2026-32280 | stdlib | v1.24.4 | 1.25.9, 1.26.2 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a... |
| High | CVE-2026-32281 | stdlib | v1.24.4 | 1.25.9, 1.26.2 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service... |
| High | CVE-2026-32283 | stdlib | v1.24.4 | 1.25.9, 1.26.2 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources... |
| High | CVE-2026-33811 | stdlib | v1.24.4 | 1.25.10, 1.26.3 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. |
| High | CVE-2026-33814 | stdlib | v1.24.4 | 1.25.10, 1.26.3 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. |
| High | CVE-2026-33818 | stdlib | v1.24.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. |
| High | CVE-2026-39820 | stdlib | v1.24.4 | 1.25.10, 1.26.3 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. |
| High | CVE-2026-39821 | stdlib | v1.24.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing |
| High | CVE-2026-39822 | stdlib | v1.24.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /... |
| High | CVE-2026-39836 | stdlib | v1.24.4 | 1.25.10, 1.26.3 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). |
| High | CVE-2026-42499 | stdlib | v1.24.4 | 1.25.10, 1.26.3 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. |
| High | CVE-2026-42504 | stdlib | v1.24.4 | 1.25.11, 1.26.4 | Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. |
| High | CVE-2026-56853 | stdlib | v1.24.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface... |
| High | CVE-2026-56858 | stdlib | v1.24.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. |
| High | CVE-2026-56859 | stdlib | v1.24.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. |
| High | CVE-2026-56860 | stdlib | v1.24.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high... |
| High | CVE-2026-56862 | stdlib | v1.24.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not... |
| High | GO-2026-4341 | stdlib | go1.24.4 | 1.24.12 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size... |
... and 322 more of lower severity (see full report in release assets)
Full changelog
- [
8614544] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
a100b9e] refresh generated badges (stagefreight) - [
c853881] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
4d2de19] refresh generated badges (stagefreight) - [
4e88235] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
1d2a22f] drop the decorative emoji from the title (SoFMeRight) - [
1c2230d] follow the org readme structure and document configuration (SoFMeRight) - [
c7ceb60] package a hardened synapse image with s3 media and the antispam hook (SoFMeRight)