The Lab · 2026-04-02 19:27:03 · GitHub Issues
A Trivy security scan has flagged five HIGH-severity vulnerabilities within a critical software component, exposing a potential attack surface for denial-of-service, arbitrary code execution, and information disclosure. The scan, conducted on April 2, 2026, targeted the `7002370412/news-feed:latest` container image, wh...
The Lab · 2026-04-13 08:22:31 · GitHub Issues
A critical security patch cycle for the FraiseQL project has resolved three high-severity vulnerabilities, but a significant TLS-related flaw in GnuTLS remains unaddressed, creating a mixed security posture. The fixed vulnerabilities include a heap buffer overread in util-linux (CVE-2025-14104), a stack buffer overflow...
The Lab · 2026-05-14 08:48:29 · Mastodon:mastodon.social:#infosec
A critical use-after-free vulnerability in Exim mail server software allows unauthenticated remote attackers to execute arbitrary code by sending specially crafted BDAT SMTP traffic. The flaw, tracked as CVE-2026-45185, exists specifically in Exim versions 4.97 through 4.99.2 when built with GnuTLS cryptographic suppor...