Overview
- composer
- composer
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Composer (the dominant PHP package manager) shipped 2.9.6 and 2.2.27 LTS in April. The release fixes two command-injection bugs in the Perforce driver. CVE-2026-40261, severity 8.8. A malicious composer.json declares a Perforce repository and the shell runs whether or not Perforce is installed. Packagist disabled Perforce metadata April 10. Most CI build agents kept no audit trail across the ninety days the bug was live.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
RE: https://mastodon.bsd.cafe/@grahamperrin/116475400039936346
3/
CVE-2026-7270 <https://www.cve.org/CVERecord?id=CVE-2026-7270> FreeBSD-SA-26:13.exec <https://security.freebsd.org/advisories/FreeBSD-SA-26:13.exec.asc> credited to Ryan of Calif.io.
Calif is recently known for post-CVE attention to an earlier CVE, <https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd>. This work by Calif was wrongly attributed to Nicholas Carlini (an error by Devansh in 'Artificial Intelligence Made Simple').
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
@thesaigoneer thanks!
Looking at the various credits …
1/
CVE-2026-35547 <https://www.cve.org/CVERecord?id=CVE-2026-35547> FreeBSD-SA-26:17.libnv <https://security.freebsd.org/advisories/FreeBSD-SA-26:17.libnv.asc> credited to Mariusz Zaborski.
<https://papers.freebsd.org/author/mariusz-zaborski/> is currently empty (<https://github.com/freebsd/freebsd-papers/issues/152> relates), should probably comprise:
<https://papers.freebsd.org/2016/asiabsdcon/oshogbo-capsicum_and_casper/>
<https://papers.freebsd.org/2019/bsdcan/zaborski-building_a_security_appliance_based_on_freebsd/>
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 1 Post
Fediverse
2/
CVE-2026-7164 <https://www.cve.org/CVERecord?id=CVE-2026-7164> FreeBSD-SA-26:14.pf <https://security.freebsd.org/advisories/FreeBSD-SA-26:14.pf.asc> credited to Igor Gabriel Sousa e Souza.
I can't easily find any information about this person.
Overview
Description
Statistics
- 1 Post
Fediverse
Microsoft Update causing Print Spooler Problems - CVE-2019-1367 | https://techygeekshome.info/cve-2019-1367/?fsp_sid=40138 | #Guide #Microsoft #News #security #Updates #Windows
https://techygeekshome.info/cve-2019-1367/?fsp_sid=40138
Overview
- cryptomator
- cryptomator
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
Remote Code Execution in Apache ActiveMQ
"By calling addNetworkConnector through Jolokia with a crafted URI, an attacker can chain these mechanisms together to force the broker to fetch and execute a remote Spring XML configuration file"
https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/
Overview
- arc53
- DocsGPT
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: CVE-2026-26015 in DocsGPT 0.15.0-0.16.0 enables unauthenticated RCE via command injection (CVSS 10). All deployments at risk — patch to 0.16.0 or later now! https://radar.offseq.com/threat/cve-2026-26015-cwe-77-improper-neutralization-of-s-ba83675d #OffSeq #Vuln #RCE #DocsGPT