Overview
- AMD
- AMD Ryzen™ Master
Description
Statistics
- 1 Post
Overview
- AMD
- AMD Ryzen™ Master
Description
Statistics
- 1 Post
Overview
- mastodon
- mastodon
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Vulnerabilities in #Mastodon
URL: https://github.com/mastodon/mastodon/security/advisories/GHSA-7jvv-fhmg-wpfw
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj
- https://github.com/mastodon/mastodon/security/advisories/GHSA-vwhj-3g83-v276
CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.
CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.
CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.
Overview
- mastodon
- mastodon
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Vulnerabilities in #Mastodon
URL: https://github.com/mastodon/mastodon/security/advisories/GHSA-7jvv-fhmg-wpfw
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj
- https://github.com/mastodon/mastodon/security/advisories/GHSA-vwhj-3g83-v276
CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.
CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.
CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.
Overview
- mastodon
- mastodon
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Vulnerabilities in #Mastodon
URL: https://github.com/mastodon/mastodon/security/advisories/GHSA-7jvv-fhmg-wpfw
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj
- https://github.com/mastodon/mastodon/security/advisories/GHSA-vwhj-3g83-v276
CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.
CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.
CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.
Overview
- Phoenix Contact
- AXC F 1152
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771
https://certvde.com/en/advisories/vde-2025-056/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
Overview
- Phoenix Contact
- AXC F 1152
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771
https://certvde.com/en/advisories/vde-2025-056/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
Overview
- Phoenix Contact
- AXC F 1152
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771
https://certvde.com/en/advisories/vde-2025-056/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
Overview
- Johnson Control
- victor
Description
Statistics
- 1 Post
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post