🚨 CVE-2026-10575
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
🎖@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-10575)
IBM MQ has addressed an heap buffer overflow vulnerability when processing MQPUT operations with malformed distribution headers that could allow a remote authenticated attacker to cause a denial of service or potentially escalate privileges.
🚨 CVE-2026-10744
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
🎖@cveNotify
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation (CVE-2026-10744)
IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation when CONNAUTH is being used.
🚨 CVE-2026-10747
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
🎖@cveNotify
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing (CVE-2026…
IBM MQ Appliance has addressed a heap buffer overflow vulnerability in protocol message processing that could allow a remote attacker to cause a denial of service or execute arbitrary code prior to authentication.
🚨 CVE-2026-10751
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
🎖@cveNotify
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ Java messaging is vulnerable to remote code execution (CVE-2026-10751)
IBM MQ has addressed a Java deserialization filter bypass in the IBM MQ JMS client that could allow a remote authenticated attacker to execute arbitrary code
🚨 CVE-2026-10841
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
🎖@cveNotify
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
🎖@cveNotify
Ibm
Security Bulletin: Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. IBM WebSphere Liberty has been updated within IBM CICS TX Advanced to address these vulnerabilities.
🚨 CVE-2026-10853
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
🎖@cveNotify
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-10853)
IBM MQ has addressed a heap buffer overflow vulnerability in the queue manager's cluster repository manager
🚨 CVE-2026-10858
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
🎖@cveNotify
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a denial of service attack (CVE-2026-10858)
IBM MQ for HPE NonStop is vulnerable to a denial of service issue caused by a heap buffer overflow.
🚨 CVE-2026-11375
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
🎖@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-11375)
IBM MQ has addressed a stack buffer overflow vulnerability in the queue manager's XA transaction handling that could allow a remote authenticated attacker to execute arbitrary code by sending a crafted transaction identifier
🚨 CVE-2026-11378
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
🎖@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-11378)
IBM MQ has addressed an integer overflow vulnerability in the queue manager's object descriptor conversion that could allow a remote authenticated attacker to write zeros to arbitrary heap memory locations, leading to remote code execution.
🚨 CVE-2026-11381
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
🎖@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
🎖@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a denial of service issue (CVE-2026-11381)
IBM MQ for HPE NonStop is vulnerable to a denial of service issue when using MQ distribution lists.
🚨 CVE-2026-11537
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
🎖@cveNotify
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
🎖@cveNotify
Ibm
Security Bulletin: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities.
🚨 CVE-2026-1025
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration…
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
🚨 CVE-2026-1029
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration…
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
🚨 CVE-2026-1031
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration…
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
🚨 CVE-2026-1037
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
🎖@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration…
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
🚨 CVE-2026-54147
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
🎖@cveNotify
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
🎖@cveNotify
GitHub
Fix DigestAuthProvider to use configured algorithm instead of hardcod… · http4k/http4k@65d23d9
…ed MD5
🚨 CVE-2026-54148
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-request-URI binding and potentially gaining unauthorized read or write access. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
🎖@cveNotify
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-request-URI binding and potentially gaining unauthorized read or write access. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
🎖@cveNotify
GitHub
[GHSA-p28p-j94q-pg32] http4k: `DigestAuthProvider.verify` did not bind to request URI by Kxrma47 · Pull Request #9477 · github/advisory…
Updates
Affected products
Comments
The publisher advisory and this record's Patches table identify 4.51.0.0 as the fixed release for the v4 LTS line, but the structured v4 product current...
Affected products
Comments
The publisher advisory and this record's Patches table identify 4.51.0.0 as the fixed release for the v4 LTS line, but the structured v4 product current...
🚨 CVE-2026-59156
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte header blocks without the mandatory end keyword makes fitsinput::read_fits_header() call itself without a depth bound. repeated recursive parsing exhausts the application stack, resulting in denial of service. The affected implementation is identified by src/fits.imageio/fitsinput.cpp, FitsInput::read_fits_header(), END keyword, and 2880-byte FITS header blocks, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
🎖@cveNotify
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte header blocks without the mandatory end keyword makes fitsinput::read_fits_header() call itself without a depth bound. repeated recursive parsing exhausts the application stack, resulting in denial of service. The affected implementation is identified by src/fits.imageio/fitsinput.cpp, FitsInput::read_fits_header(), END keyword, and 2880-byte FITS header blocks, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
🎖@cveNotify
GitHub
fix(fits): Fix recursion stack overflow with too many header blocks (… · AcademySoftwareFoundation/OpenImageIO@b0de7d4
…#5248)
FITS files are allowed to have multiple "header blocks".
Unfortunately, as originally written, our fits input used *recursion* to
read them. If there is a file with too ...
FITS files are allowed to have multiple "header blocks".
Unfortunately, as originally written, our fits input used *recursion* to
read them. If there is a file with too ...
🚨 CVE-2026-59181
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value greater than the format maximum of eight. cineoninput::open() uses that unchecked value as the loop bound while filling the fixed strings[8] array, writing pointers beyond the stack buffer and into adjacent state, resulting in memory corruption and denial of service. The affected implementation is identified by src/cineon.imageio/cineoninput.cpp, CineonInput::open(), numberOfElements, and strings[8], which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
🎖@cveNotify
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value greater than the format maximum of eight. cineoninput::open() uses that unchecked value as the loop bound while filling the fixed strings[8] array, writing pointers beyond the stack buffer and into adjacent state, resulting in memory corruption and denial of service. The affected implementation is identified by src/cineon.imageio/cineoninput.cpp, CineonInput::open(), numberOfElements, and strings[8], which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
🎖@cveNotify
GitHub
fix(cineon): more robust to invalid numbers of channels & bit depth (… · AcademySoftwareFoundation/OpenImageIO@908f22f
…#5250)
Guard against corrupted images, which if they said they had more than
the 8 channels allowed by Cineon format, would overrun array bounds
while reading the file. And check for valid bit de...
Guard against corrupted images, which if they said they had more than
the 8 channels allowed by Cineon format, would overrun array bounds
while reading the file. And check for valid bit de...
🚨 CVE-2026-59956
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffinput::readimg() allocate a temporary scanline from m_header.rgba_count but copy from it using m_header.pixel_bytes(), whose stride also includes z-buffer bytes. the oversized memcpy reads beyond the temporary heap buffer and copies adjacent memory into the output image, resulting in a crash or disclosure of adjacent heap data. The affected implementation is identified by src/iff.imageio/iffinput.cpp, IffInput::readimg(), m_header.rgba_count, and m_header.pixel_bytes(), which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
🎖@cveNotify
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffinput::readimg() allocate a temporary scanline from m_header.rgba_count but copy from it using m_header.pixel_bytes(), whose stride also includes z-buffer bytes. the oversized memcpy reads beyond the temporary heap buffer and copies adjacent memory into the output image, resulting in a crash or disclosure of adjacent heap data. The affected implementation is identified by src/iff.imageio/iffinput.cpp, IffInput::readimg(), m_header.rgba_count, and m_header.pixel_bytes(), which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
🎖@cveNotify
GitHub
fix(iff): Fix allocation bug when reading 16 bit RGBA + float z (#5251) · AcademySoftwareFoundation/OpenImageIO@f01bd16
We were allocating a temporary buffer big enough for the RGBA but
neglecting the z. Only for the 16 bit case.
Signed-off-by: Larry Gritz <lg@larrygritz.com>
neglecting the z. Only for the 16 bit case.
Signed-off-by: Larry Gritz <lg@larrygritz.com>
🚨 CVE-2026-61682
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.
🎖@cveNotify
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.
🎖@cveNotify
GitHub
Merge commit from fork · kcp-dev/kcp@7437cdc
* Adjust header handling
* wire in headerhandling in localproxy
* wire in headerhandling in localproxy