Количество 84
Количество 84
BDU:2026-07950
Уязвимость функций LookupCNAME() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2026-57231
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
CVE-2026-57231
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
CVE-2026-57231
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVE-2026-57231
Podman is a tool for managing OCI containers and pods. From 1.8.1 unti ...
ROS-20260710-73-0007
Уязвимость mimir
ROS-20260622-73-0032
Уязвимость golang
RLSA-2026:35832
Important: golang-github-openprinting-ipp-usb security update
ELSA-2026-35832
ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT)
RLSA-2026:39573
Important: yggdrasil security update
ELSA-2026-39573
ELSA-2026-39573: yggdrasil security update (IMPORTANT)
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without set ...
RLSA-2026:34359
Important: opentelemetry-collector security update
RLSA-2026:34357
Important: opentelemetry-collector security update
GHSA-78mq-xcr3-xm33
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07950 Уязвимость функций LookupCNAME() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-57231 Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57231 Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57231 Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the container | 0% Низкий | около 1 месяца назад | ||
CVE-2026-57231 Podman is a tool for managing OCI containers and pods. From 1.8.1 unti ... | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260710-73-0007 Уязвимость mimir | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
ROS-20260622-73-0032 Уязвимость golang | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
RLSA-2026:35832 Important: golang-github-openprinting-ipp-usb security update | 24 дня назад | |||
ELSA-2026-35832 ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT) | 15 дней назад | |||
RLSA-2026:39573 Important: yggdrasil security update | 16 дней назад | |||
ELSA-2026-39573 ELSA-2026-39573: yggdrasil security update (IMPORTANT) | 15 дней назад | |||
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 5.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 5.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | CVSS3: 5.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without set ... | CVSS3: 5.3 | 1% Низкий | 2 месяца назад | |
RLSA-2026:34359 Important: opentelemetry-collector security update | 26 дней назад | |||
RLSA-2026:34357 Important: opentelemetry-collector security update | 24 дня назад | |||
GHSA-78mq-xcr3-xm33 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | CVSS3: 5.3 | 1% Низкий | около 1 месяца назад |
Уязвимостей на страницу