Table of Contents

Distros list statistics and data for 2026

Statistics by month

Statistics are grouped by month of the issue being reported to the private list.

Month All reports Embargoed Average Median Min Max embargo days
2026-01 3 3 7.42 6.81 1.28 14.15
2026-02 4 4 11.57 12.70 6.75 14.15
2026-03 15 15 10.40 5.35 1.11 49.69
2026-04 16 16 9.84 6.06 3.60 31.98
2026-05 17 17 6.79 6.02 0.14 17.14
2026-06 14 14 11.30 7.08 0.07 57.65
2026-07 22 22 11.24 7.47 1.16 43.40
Total 91 91 9.92 6.90 0.07 57.65

Non-embargoed reports (issue already posted to oss-security before being brought to (linux-)distros, which in 2026 didn't occur yet) are (would be) excluded from the calculation of average, median, and minimum embargo duration above.

Formatted input data

For the statistics above, we only use the first embargo duration seen in this table, which is the delay between postings to (linux-)distros and oss-security.

For some reports, there's a second embargo duration - that one is the delay (sometimes negative) between a first public posting elsewhere and the posting to (linux-)distros. Such first public posting often does not fully (or at all) reveal security relevance of the issue/fix, making it not-too-unreasonable to allow a little bit (more) of embargo time on the full detail, especially when that's the issue reporter's and/or the upstream project's preference.

Project Subjects/titles/links Time at distros (UTC)
… oss-security (UTC)
Elsewhere (UTC)
Embargo days Planned CRD(s)
(exact wording)
CVE(s)
OpenStack keystonemiddleware [vs] Vulnerability in OpenStack keystonemiddleware (CVE pending)
[oss-security] [CVE-2026-22797] OpenStack keystonemiddleware: Privilege Escalation via Identity Headers in External OAuth2 Tokens (CVE-2026-22797)
Thu Jan 08 20:01:47 2026
Thu Jan 15 15:32:58 2026
6.81 Thursday, 2026-01-15, 1500UTC
OpenSSL [vs-plain] Embargoed OpenSSL security issue
[oss-security] OpenSSL Security Advisory (corrected - added CVE-2026-22795 and CVE-2026-22796)
Tue Jan 13 13:44:01 2026
Tue Jan 27 17:19:21 2026
14.15 27th January 2026
BIND 9 [vs] …
[oss-security] ISC has disclosed one vulnerability in BIND 9 (CVE-2025-13878)
Tue Jan 20 09:27:28 2026
Wed Jan 21 16:14:45 2026
1.28 21 January 2026 CVE-2025-13878
MUNGE [vs] MUNGE buffer overflow - embargo until 2026-02-10
[oss-security] CVE-2026-25506: MUNGE 0.5-0.5.17 buffer overflow allowing key leakage
Wed Feb 04 00:30:33 2026
Tue Feb 10 18:33:01 2026
6.75 2026-02-10 18:00 UTC (Tue, 10:00 PST) CVE-2026-25506
MIT/Heimdal Kerberos [vs] Critical Kerberos Credential Theft (ADV-2026-005)
[oss-security] MIT/Heimdal Kerberos credentials cache type FILE risks
Thu Feb 05 09:24:27 2026
Thu Feb 19 01:15:03 2026
13.66 2026-02-18 ADV-2026-005
OpenStack [vs] …
[oss-security] [OSSA-2026-002] OpenStack Nova: calls qemu-img without format restrictions for resize (CVE-2026-24708)
Thu Feb 05 21:18:36 2026
Tue Feb 17 15:01:45 2026
11.74 2026-02-17 1500UTC CVE-2026-24708
Linux [vs-plain] Multiple vulnerabilities in AppArmor
[oss-security] Re: Multiple vulnerabilities in AppArmor
Thu Feb 26 18:01:06 2026
Thu Mar 12 21:34:11 2026
14.15 Tuesday, March 3, 17:00 UTC
when the patches are published upstream in Linus's tree, in a few days and definitely before the maximum 14-day embargo
will almost certainly be published upstream in Linus's tree on Tuesday, March 10
wait until the patches appear in Linus's tree, even if the maximum 14-day embargo is slightly exceeded
OpenSSH GSSAPI patch [vs-plain] OpenSSH GSSAPI patch issue
[oss-security] OpenSSH GSSAPI keyex patch issue
Thu Mar 05 14:03:20 2026
Thu Mar 12 18:03:39 2026
7.17 2026-03-12 18:00:00 UTC CVE-2026-3497
OpenStack Glance [vs] Vulnerability in OpenStack Glance (CVE-pending)
[oss-security] [OSSA-2026-004] Glance: Server-Side Request Forgery (SSRF) vulnerabilities in OpenStack Glance image import functionality (CVE-2026-pending)
Thu Mar 05 20:09:33 2026
Thu Mar 19 15:21:06 2026
13.80 2026-03-19, 1500UTC OSSA-2026-004
curl [vs-plain] : pre-notification curl CVE-2026-1965 (1/3)
[oss-security] [ADVISORY] curl: CVE-2026-1965: bad reuse of HTTP Negotiate connection
https://github.com/curl/curl/pull/20534
Sun Mar 08 09:32:08 2026
Wed Mar 11 06:54:50 2026
2.89 March 11, this coming Wednesday CVE-2026-1965
curl [vs-plain] : pre-notification curl CVE-2026-3783 (2/3)
[oss-security] [ADVISORY] curl: CVE-2026-3783: token leak with redirect and netrc
https://github.com/curl/curl/pull/20843
Sun Mar 08 09:32:12 2026
Wed Mar 11 06:54:55 2026
2.89 March 11, this coming Wednesday CVE-2026-3783
curl [vs-plain] : pre-notification curl CVE-2026-3784 (3/3)
[oss-security] [ADVISORY] curl: CVE-2026-3784: wrong proxy connection reuse with credentials
https://github.com/curl/curl/pull/20837
Sun Mar 08 09:32:22 2026
Wed Mar 11 06:55:00 2026
2.89 March 11, this coming Wednesday CVE-2026-3784
curl [vs-plain] : pre-notification curl CVE-2026-3805 (4/3)
[oss-security] [ADVISORY] curl: CVE-2026-3805: use after free in SMB connection reuse
https://github.com/curl/curl/pull/20854
Sun Mar 08 21:56:29 2026
Wed Mar 11 06:55:03 2026
2.37 March 11th 2026 CVE-2026-3805
Linux [vs] …
[oss-security] KVM shadow EPT stale rmap use-after-free
Tue Mar 10 10:33:59 2026
Mon Mar 30 14:41:08 2026
20.17 Sunday March 29, 2026, 16:00 UTC
snapd [vs] LPE in snapd
[oss-security] snap-confine + systemd-tmpfiles = root (CVE-2026-3888)
Thu Mar 12 11:08:29 2026
Tue Mar 17 19:33:32 2026
5.35 2026-03-17 14:00:00 UTC CVE-2026-3888
Linux [vs-plain] Vulnerability Report: KTLS + sockmap “Reverse Order” Use-After-Free / Data Corruption
[oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption
Wed Mar 18 11:54:54 2026
Thu May 07 04:30:00 2026
49.69 March 31st
Dovecot [vs] Dovecot Security Advisory 2026-01
[oss-security] Dovecot Security Advisory OXDC-2026-0001
Mon Mar 23 14:57:55 2026
Fri Mar 27 14:48:06 2026
3.99 27th of March CVE-2025-30189
CVE-2025-59028
CVE-2025-59032
CVE-2025-59031
CVE-2026-0394
CVE-2026-27860
CVE-2026-24031
CVE-2026-27859
CVE-2026-27857
CVE-2026-27858
CVE-2026-27856
CVE-2026-27855
Kea [vs] …
[oss-security] ISC has disclosed one vulnerability in Kea (CVE-2026-3608)
Tue Mar 24 09:16:10 2026
Wed Mar 25 15:16:52 2026
1.25 25 March 2026 CVE-2026-3608
BIND 9 [vs] …
[oss-security] ISC has disclosed four vulnerabilities in BIND 9 (CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591)
Tue Mar 24 12:36:27 2026
Wed Mar 25 15:16:57 2026
1.11 25 March 2026 CVE-2026-1519
CVE-2026-3104
CVE-2026-3119
CVE-2026-3591
OpenSSL [vs-plain] Embargoed OpenSSL security issue
[oss-security] OpenSSL Security Advisory
Tue Mar 24 15:39:27 2026
Tue Apr 07 16:37:00 2026
14.04 7th April 2026 CVE-2026-31790
CVE-2026-28386
CVE-2026-28387
CVE-2026-28388
CVE-2026-28389
CVE-2026-28390
CVE-2026-31789
OpenStack Keystone [vs-plain] Vulnerability in OpenStack Keystone (CVE-2026-33551)
[oss-security] [OSSA-2026-005] Keystone: Restricted application credentials can create EC2 credentials (CVE-2026-33551)
Tue Mar 24 19:28:14 2026
Tue Apr 07 17:43:25 2026
13.93 2026-04-07, 1500UTC CVE-2026-33551
LiteLLM [vs] …
[oss-security] X41 Advisory X41-2026-001: Guardrail Sandbox Escape in LiteLLM
Wed Mar 25 14:19:55 2026
Thu Apr 09 00:09:16 2026
14.41 as fast as possible x41-2026-001
OVN [vs-plain] CVE-2026-5367: Heap Over-Read in ICMP Error Response Generation
[oss-security] [ADVISORY] CVE-2026-5265: Heap Over-Read in ICMP Error Response Generation
Tue Apr 07 08:04:14 2026
Mon Apr 20 15:51:53 2026
13.32 13-Apr-2026
20-Apr-2026
CVE-2026-5265
OVN [vs-plain] CVE-2026-5367: Heap over-read in OVN DHCPv6 Client ID processing
[oss-security] [ADVISORY] CVE-2026-5367: Heap over-read in OVN DHCPv6 Client ID processing
Tue Apr 07 08:04:18 2026
Mon Apr 20 15:52:03 2026
13.32 13-Apr-2026
20-Apr-2026
CVE-2026-5367
X.Org X server and Xwayland [vs-plain] Embargoed X.Org Security Advisory: Multiple security issues in X.Org X server and Xwayland for 2026-04-14
[oss-security] Fwd: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland
Tue Apr 07 08:20:45 2026
Tue Apr 14 15:38:28 2026
7.30 2026-04-14 at 13:00 UTC CVE-2026-33999
CVE-2026-34000
CVE-2026-34001
CVE-2026-34002
CVE-2026-34003
GNU sed [vs-plain] GNU sed: CVE-2026-5958: TOCTOU race in sed -i –follow-symlinks
[oss-security] CVE-2026-5958: GNU sed: TOCTOU race in sed -i --follow-symlinks
https://savannah.gnu.org/news/?id=10885
Sat Apr 11 01:40:42 2026
Wed May 13 01:14:29 2026
Wed Apr 22 02:00:45 2026
31.98
11.01
2026-04-19
the 20th
CVE-2026-5958
libXpm [vs-plain] Embargoed X.Org Security Advisory: Security issue in libXpm for 2026-04-21
[oss-security] Fwd: X.Org Security Advisory: CVE-2026-4367: libXpm Out-of-bounds read in xpmNextWord()
Tue Apr 14 17:09:39 2026
Tue Apr 21 16:30:10 2026
6.97 2026-04-21 at 13:00 UTC CVE-2026-4367
ntfs-3g [vs] …
[oss-security] CVE-2026-40706: ntfs-3g 2022.10.3: Heap buffer overflow
Thu Apr 16 10:27:32 2026
Tue Apr 21 16:30:37 2026
5.25 April 21st (2026-04-21) 12:00 UTC CVE-2026-40706
GHSA-4cwv-5285-63v9
Kata Containers [vs-plain] Vulnerability in Kata Containers (CVE Requested)
[oss-security] CVE-2026-41326: Kata Containers: CopyFile Policy Subversion via Symlinks
https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc
Thu Apr 16 13:42:39 2026
Wed May 13 01:31:41 2026
Wed Apr 22 19:55:00 2026
26.49
6.26
2026-04-22, 1800 UTC CVE-2026-41326
PackageKit [vs] …
[oss-security] CVE-2026-41651: TOCTOU vulnerability in PackageKit <= 1.3.4 leads to local root exploit
Sun Apr 19 01:11:19 2026
Wed Apr 22 15:38:54 2026
3.60 next Wednesday (22.04.2026)
22.04.2026, after 12:00 CEST (12:00 PM, 12:00 24h format)
CVE-2026-41651
curl [vs-plain] : pre-notification curl CVE-2026-4873 (1/6)
[oss-security] [ADVISORY] curl: CVE-2026-4873: connection reuse ignores TLS requirement
https://github.com/curl/curl/commit/507e7be573b0a76fca597b75
Thu Apr 23 06:08:11 2026
Wed Apr 29 06:01:05 2026
6.00 April 29 CVE-2026-4873
curl [vs-plain] : pre-notification curl CVE-2026-5545 (2/6)
[oss-security] [ADVISORY] curl: CVE-2026-5545: wrong reuse of HTTP Negotiate connection
https://github.com/curl/curl/commit/33e43985b8f3b9e6669
Thu Apr 23 06:08:16 2026
Wed Apr 29 06:01:12 2026
6.00 April 29 CVE-2026-5545
curl [vs-plain] : pre-notification curl CVE-2026-5773 (3/6)
[oss-security] [ADVISORY] curl: CVE-2026-5773: wrong reuse of SMB connection
https://github.com/curl/curl/commit/74a169575d6412d
Thu Apr 23 06:08:24 2026
Wed Apr 29 06:01:18 2026
6.00 April 29 CVE-2026-5773
curl [vs-plain] : pre-notification curl CVE-2026-6253 (4/6)
[oss-security] [ADVISORY] curl: CVE-2026-6253: proxy credentials leak over redirect-to proxy
https://github.com/curl/curl/commit/188c2f166a20fa97c2325
Thu Apr 23 06:08:31 2026
Wed Apr 29 06:01:23 2026
6.00 April 29 CVE-2026-6253
curl [vs-plain] : pre-notification curl CVE-2026-6276 (5/6)
[oss-security] [ADVISORY] curl: CVE-2026-6276: stale custom cookie host causes cookie leak
https://github.com/curl/curl/commit/3a19987a87f393d9394fe5ac
Thu Apr 23 06:08:39 2026
Wed Apr 29 06:01:27 2026
6.00 April 29 CVE-2026-6276
curl [vs-plain] : pre-notification curl CVE-2026-6429 (6/6)
[oss-security] [ADVISORY] curl: CVE-2026-6429: netrc credential leak with reused proxy connection
https://github.com/curl/curl/commit/b4024bf808bd558026fdc6
Thu Apr 23 06:08:46 2026
Wed Apr 29 06:01:19 2026
5.99 April 29 CVE-2026-6429
Exim [vs-plain] EXIM-Security-2026-04-24
[oss-security] Exim 4.99.2 fixes 4 CVEs
Fri Apr 24 15:09:46 2026
Thu Apr 30 18:21:42 2026
6.13 next Wednesday, 2026-04-29T12:00:00+0000 CVE-2026-40684
CVE-2026-40685
CVE-2026-40686
CVE-2026-40687
OpenStack Cyborg [vs] …
[oss-security] [OSSA-2026-011] OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management (CVE-2026-40213, CVE-2026-40214)
Thu Apr 30 15:02:08 2026
Thu May 07 18:27:34 2026
7.14 2026-05-07, 1500UTC CVE-2026-40213
CVE-2026-40214
Linux [vs-plain] Dirty Frag: Universal LPE on all major Linux distributions
[oss-security] Dirty Frag: Universal Linux LPE
Thu May 07 15:01:30 2026
Thu May 07 18:59:34 2026
0.17 embargo of 5 days
go out with fixes ASAP
Dirty Frag
CVE-2026-43284
CVE-2026-43500
Exim [vs] EXIM-Security-2026-05-01.1: security release 4.99.3 ahead
[oss-security] [EXIM-Security-2026-05-01.1] Security Release 4.99.3
Thu May 07 22:00:56 2026
Tue May 12 14:15:13 2026
4.68 Tuesday, May 12, 2026, at 14:00 UTC EXIM-Security-2026-05-01.1
CVE-2026-45185
rsync [vs-plain] rsync 3.4.3 - 5 CVEs (CVE-2026-29518, CVE-2026-43617, -43618, -43619, -43620) - embargo until 2026-05-20 00:00 UTC
[oss-security] rsync 3.4.3 released: six CVEs (CVE-2026-29518, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232)
Fri May 08 00:53:29 2026
Wed May 20 09:26:30 2026
12.36 2026-05-20 at 00:00 UTC (10:00 AEST, Wednesday morning Canberra time) CVE-2026-29518
CVE-2026-43617
CVE-2026-43618
CVE-2026-43619
CVE-2026-43620
OpenStack Keystone [vs] …
[oss-security] [OSSA-2026-015] OpenStack Keystone: Multiple credential delegation and authorization bypass vulnerabilities (CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394)
Thu May 14 18:51:47 2026
Thu May 28 20:56:12 2026
14.09 2026-05-28, 1500UTC CVE-2026-42998
CVE-2026-42999
CVE-2026-43000
CVE-2026-43001
CVE-2026-44394
Linux [vs-plain] Logic bug in the Linux kernel's __ptrace_may_access()
[oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function
Thu May 14 22:58:25 2026
Fri May 15 02:21:01 2026
0.14 Wednesday, May 20
now
CVE-2026-46333
Linux [vs-plain] net/tls: Use-After-Free via TOCTOU race in tls_sk_proto_close (local privilege escalation, no privs)
[oss-security] Linux kernel TLS ULP use-after-free in tls_sk_proto_close()
Sat May 16 17:36:41 2026
Tue Jun 02 20:52:02 2026
17.14 2026-05-30
BIND 9 [vs] …
[oss-security] ISC has disclosed six vulnerabilities in BIND 9 (CVE-2026-3039, CVE-2026-3592, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, CVE-2026-5950)
Mon May 18 18:35:58 2026
Wed May 20 13:56:59 2026
1.81 20 May 2026 CVE-2026-3039
CVE-2026-3592
CVE-2026-3593
CVE-2026-5946
CVE-2026-5947
CVE-2026-5950
Kata Containers runtime-rs [vs-plain] Vulnerability in Kata Containers runtime-rs (GHSA-2gv2-cffp-j227)
[oss-security] CVE-2026-47243: Kata Containers runtime-rs 3.30: virtiofsd symlink escape
Mon May 18 19:12:13 2026
Thu May 21 18:27:40 2026
2.97 2026-05-21 1900UTC GHSA-2gv2-cffp-j227
CVE-2026-47243
Unbound [vs] …
[oss-security] Unbound: 1.25.1 addresses multiple CVE items
Mon May 18 19:36:33 2026
Wed May 20 09:17:52 2026
1.57 20 May 2026 CVE-2026-33278
CVE-2026-42944
CVE-2026-42959
CVE-2026-32792
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-42923
CVE-2026-42960
CVE-2026-44390
CVE-2026-44608
OpenStack [vs] …
[oss-security] [OSSA-2026-020] OpenStack Mistral: Mistral policy enforcement bypass allows unauthorized public resource creation and arbitrary code execution (CVE-2026-41283)
Thu May 21 16:42:40 2026
Wed Jun 03 16:51:55 2026
13.01 2026-06-03 15:00 UTC CVE-2026-41283
Linux [vs-plain] kernel+userspace LPE affecting several distros
[oss-security] CIFSwitch: Linux kernel/cifs-utils local root via forged cifs.spnego upcall
Mon May 25 07:59:43 2026
Thu May 28 07:07:27 2026
2.96 Wednesday, May 27, 7pm PT CIFSwitch
CVE-2026-46243
Exim [vs] …
[oss-security] CVE-2026-48840: Exim 4.99.4: PROXY-protocol uninitialised-stack information disclosure
Mon May 25 22:41:34 2026
Fri May 29 14:39:08 2026
3.66 Friday, 2026-05-29 14:00 UTC EXIM-Security-2026-05-19.1
CVE-2026-48840
OpenSSL [vs-plain] Embargoed OpenSSL issues
[oss-security] OpenSSL Security Advisory
Tue May 26 13:10:13 2026
Tue Jun 09 16:09:07 2026
14.12 9th June 2026
X.Org X server and Xwayland [vs-plain] Preview of X.Org Security Advisory for 2026-06-02
[oss-security] FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland
Wed May 27 00:04:06 2026
Tue Jun 02 00:27:21 2026
6.02 June 2, 2026 at 00:00 UTC
OpenStack [vs] …
[oss-security] [OSSA-2026-019] Ironic: File Extraction from conductor via pxe_template (CVE-2026-44917)
Wed May 27 19:21:05 2026
Wed Jun 03 16:51:51 2026
6.90 June 3 2026, 1500UTC CVE-2026-44917
OpenStack [vs] …
[oss-security] [OSSA-2026-017] Ironic: Script injection during node boot via linux command line override (CVE-2026-46447)
Wed May 27 19:23:10 2026
Wed Jun 03 16:51:36 2026
6.89 June 3 2026, 1500 UTC CVE-2026-46447
OpenStack [vs] …
[oss-security] [OSSA-2026-018] Ironic: File overwrite on Ironic conductor via path traversal in ISO handling (CVE-2026-48681)
Wed May 27 19:23:11 2026
Wed Jun 03 16:51:41 2026
6.89 June 3 2026, 1500UTC CVE-2026-48681
ldns [vs] …
[oss-security] ldns insufficiently verifies that responses belong to a query
Thu Jun 04 12:23:28 2026
Wed Jun 10 08:59:45 2026
5.86 Tuesday the 9th of June 2026 CVE-2026-10846
OpenStack Nova [vs] …
[oss-security] [OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints (CVE-2026-46448)
Thu Jun 04 17:53:31 2026
Tue Jun 16 15:18:02 2026
11.89 2026-06-16 15:00 UTC CVE-2026-46448
Linux [vs-plain] ITScape: Guest-to-Host Escape in KVM/arm64
[oss-security] ITScape: Guest-to-Host Escape in KVM/arm64 (CVE-2026-46316)
Fri Jun 05 23:06:10 2026
Wed Jun 10 18:24:31 2026
4.80 a 5 day embargo ITScape
CVE-2026-46316
CVE-2026-46317
rsync [vs-plain] rsync 3.4.4 released, regression fixes
[oss-security] rsync 3.4.4 released, regression fixes
Mon Jun 08 04:42:43 2026
Mon Jun 08 06:26:24 2026
0.07
libxml2 [vs] …
[oss-security] CVE-2026-6653: libxml2: use after free in xmlParseInternalSubset (>=2.9.11, <2.11.0)
Mon Jun 08 12:02:00 2026
Mon Jun 22 16:05:48 2026
14.17 14 days
22 June 2026
CVE-2026-6653
OpenStack Swift [vs] …
[oss-security] [OSSA-2026-024] OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221)
Wed Jun 10 03:40:37 2026
Tue Jun 23 15:37:18 2026
13.50 2026-06-18 15:00 UTC
2026-06-23 15:00 UTC
CVE-2026-50221
Pacemaker [vs-plain] Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649)
[oss-security] Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649)
Thu Jun 11 22:49:27 2026
Tue Jun 16 15:46:20 2026
4.71 Jun 16th 2026 CVE-2026-10649
containerd [vs-plain] [Embargoed] containerd patches for CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262
[oss-security] [containerd] Patch releases addressing CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262
Tue Jun 16 17:51:02 2026
Fri Jun 19 01:02:16 2026
2.30 Thursday, June 18, 2026 between 1pm and 5pm Pacific (20:00 to 00:00 UTC) CVE-2026-50195
CVE-2026-53488
CVE-2026-53492
CVE-2026-53489
CVE-2026-47262
curl [vs-plain] : curl pre-notification of 18 security advisories
[oss-security] [SECURITY ADVISORIES] for curl 8.21.0
Wed Jun 17 06:08:02 2026
Wed Jun 24 16:37:41 2026
7.44 June 24 CVE-2026-8286
CVE-2026-8458
CVE-2026-8924
CVE-2026-8925
CVE-2026-8926
CVE-2026-8927
CVE-2026-8932
CVE-2026-9079
CVE-2026-9080
CVE-2026-9545
CVE-2026-9546
CVE-2026-9547
CVE-2026-10536
CVE-2026-11352
CVE-2026-11564
CVE-2026-11586
CVE-2026-11856
CVE-2026-12064
shim, GRUB2 [vs-plain] Combined chain advisory — fallback.efi/SBAT/memdisk bypass (shim + GRUB2)
[oss-security] AI slop "Combined chain advisory — fallback.efi/SBAT/memdisk bypass"
Sun Jun 21 13:42:20 2026
Tue Aug 18 05:20:12 2026
57.65 90-day embargo
Wednesday, July 1st, 2026
NLnet Labs NSD [vs] …
[oss-security] Several vulnerabilities were found in NLnet Labs NSD
Mon Jun 22 06:48:25 2026
Thu Jun 25 17:30:12 2026
3.45 Thursday 25 June CVE-2026-12244
CVE-2026-12245
CVE-2026-12246
CVE-2026-12490
acl, attr [vs] Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl
[oss-security] Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl
Mon Jun 22 21:56:42 2026
Mon Jun 29 15:26:07 2026
6.73 2026-06-29T13:00:00.000Z CVE-2026-54369
CVE-2026-54370
CVE-2026-54371
OpenStack Ironic [vs] …
[oss-security] [OSSA-2026-026] Ironic: Insufficient Access Controls regarding parent/child nodes
Thu Jun 25 19:40:31 2026
Wed Jul 08 15:29:45 2026
12.83 2026-07-08, 1500UTC CVE-2026-44918
OpenStack Ironic [vs] …
[oss-security] [OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423)
Thu Jun 25 19:48:33 2026
Wed Jul 08 15:05:10 2026
12.80 2026-07-08, 1500UTC CVE-2026-54423
X.Org X server and Xwayland [vs-plain] Preview of X.Org Security Advisory (xserver) for 2026-07-08
[oss-security] FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland
Wed Jul 01 00:22:27 2026
Wed Jul 08 01:55:08 2026
7.06 July 08, 2026 at 01:00 UTC CVE-2026-55999
CVE-2026-56000
ZDI-CAN-30498
ZDI-CAN-30561
libXfont2 [vs-plain] Preview of X.Org Security Advisory (libXfont2) for 2026-07-08
[oss-security] FW: X.Org Security Advisory: multiple security issues in libXfont2
Wed Jul 01 00:28:10 2026
Wed Jul 08 01:35:41 2026
7.05 July 08, 2026 at 01:00 UTC CVE-2026-56001
CVE-2026-56002
CVE-2026-56003
ZDI-CAN-30558
ZDI-CAN-30559
ZDI-CAN-30560
Linux [vs-plain] Januscape: Guest-to-Host Escape in KVM/x86
[oss-security] Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb
Wed Jul 01 15:02:52 2026
Mon Jul 06 16:26:14 2026
5.06 5 day embargo
2026-07-06 16:00 UTC
CVE-2026-53359
ntfs-3g [vs] …
[oss-security] Multiple vulnerabilities in ntfs-3g
Wed Jul 08 20:22:55 2026
Wed Jul 15 19:00:04 2026
6.94 2026-07-15 12:00 UTC CVE-2026-42616
CVE-2026-42617
CVE-2026-42618
CVE-2026-46569
CVE-2026-46570
CVE-2026-46571
CVE-2026-46572
CVE-2026-56135
CVE-2026-56136
Kata Containers [vs-plain] Subject: [pre-KCSA] Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540)
[oss-security] Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540)
Sat Jul 11 09:18:33 2026
Sun Aug 23 18:51:59 2026
43.40 2026-07-20, 1200UTC CVE-2026-50540
BusyBox dpkg applet [vs] BusyBox dpkg applet: OS command injection → root RCE (CWE-78)
[oss-security] BusyBox dpkg applet: OS command injection
Mon Jul 13 03:14:45 2026
Mon Aug 24 05:01:24 2026
42.07 2026-07-27
I'm withdrawing this
snapd [vs] LPE in snapd and other vulnerabilities
[oss-security] LPE in snapd and other vulnerabilities
Mon Jul 13 13:23:42 2026
Tue Jul 21 14:58:39 2026
8.07 2026-07-21 14:00:00 UTC CVE-2026-8933
CVE-2024-5300
CVE-2026-15226
Linux [vs-plain] Advance notice of CVE-2026-53362 exploit publication
[oss-security] CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel
Mon Jul 13 15:33:16 2026
Mon Jul 20 16:45:01 2026
7.05 2026-07-17 15:00 UTC CVE-2026-53362
CVE-2026-53366
Exim [vs-plain] Exim GCVE-25-2026-07-45-1, GCVE-25-2026-07-45-3: security update 4.99.4 → 4.99.5
[oss-security] security release for Exim
Mon Jul 13 19:25:42 2026
Wed Jul 22 15:57:06 2026
8.86 Wednesday, Jul 20th, 2026, at 14:00 UTC GCVE-25-2026-07-45-1
GCVE-25-2026-07-45-3
EXIM-Security-2026-06-22.1
EXIM-Security-2026-06-22.3
OpenStack Swift [vs] …
[oss-security] [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending)
Tue Jul 14 19:36:43 2026
Tue Jul 28 15:49:36 2026
13.84 2026-07-28 15:00 UTC CVE-2026-71191
CVE-2026-71192
OSSA-2026-030
OpenStack Swift [vs] …
[oss-security] [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)
Tue Jul 14 19:41:38 2026
Tue Jul 28 15:49:39 2026
13.84 2026-07-28 15:00 UTC CVE-2026-71190
OSSA-2026-031
OpenStack ironic-python-agent [vs] …
[oss-security] [OSSA-2026-028] OpenStack Ironic Python Agent: Credential extraction via malicious container (CVE-2026-54422)
Wed Jul 15 20:46:39 2026
Thu Jul 23 19:21:09 2026
7.94 2026-07-23 15:00 UTC CVE-2026-54422
OSSA-2026-028
OpenStack ironic-python-agent [vs] …
[oss-security] [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending)
Wed Jul 15 20:51:01 2026
Thu Jul 23 19:21:36 2026
7.94 2026-07-23 15:00 UTC CVE-2026-66138
OSSA-2026-027
Linux [vs] Qualys Security Advisory (2026-07-15)
[oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
Wed Jul 15 21:55:23 2026
Wed Jul 22 16:47:30 2026
6.79 aware of the 14-day embargo limit
no later than July 30th
Wednesday, July 22, 16:00 UTC
RefluXFS
CVE-2026-64600
GNU inetutils talkd [vs-plain] GNU inetutils talkd buffer overflow with long DNS names.
[oss-security] GNU Inetutils talkd buffer overflow with long DNS names.
Fri Jul 17 05:44:17 2026
Sat Jul 25 16:59:19 2026
8.47 2026-07-24
Unbound [vs] …
[oss-security] Unbound: 1.25.2 addresses multiple CVE items
Mon Jul 20 13:54:16 2026
Wed Jul 22 15:56:26 2026
2.08 22 July 2026 CVE-2026-32665
CVE-2026-40691
CVE-2026-44690
CVE-2026-55973
CVE-2026-14586
CVE-2026-44621
CVE-2026-50045
CVE-2026-50046
CVE-2026-50243
CVE-2026-50248
CVE-2026-50251
CVE-2026-50252
CVE-2026-52863
CVE-2026-55717
CVE-2026-55990
CVE-2026-55991
CVE-2026-56416
CVE-2026-56444
CVE-2026-41637
CVE-2026-42955
CVE-2026-44687
CVE-2026-46582
CVE-2026-54478
CVE-2026-55708
rsyslog [vs-plain] EMBARGOED: rsyslog imptcp regex-framing remote denial of service
[oss-security] rsyslog v8.36.0 through v8.2606.0: imptcp regex-framing remote denial of service
Mon Jul 20 15:41:50 2026
Wed Jul 22 15:56:09 2026
2.01 2027-07-22 12:00 CEST (10:00 UTC)
2026-07-22 12:00 CEST (10:00 UTC)
BIND 9 [vs] …
[oss-security] ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)
Tue Jul 21 11:59:43 2026
Wed Jul 22 15:56:35 2026
1.16 22 July 2026 CVE-2026-10723
CVE-2026-10822
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321
OpenStack Neutron [vs] …
[oss-security] [OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707)
Tue Jul 21 18:10:22 2026
Wed Jul 29 15:09:19 2026
7.87 2026-07-29 15:00 UTC CVE-2026-55707
Linux [vs-plain] Linux kernel LPE affecting a number of distros
[oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability
Thu Jul 23 09:24:18 2026
Tue Jul 28 10:06:15 2026
5.03 Monday, July 27, 6am UTC
Tuesday 6am UTC
may slip a couple of hours on the 6am UTC timeline
OVSwrap
CVE-2026-64531
gzip [vs] …
[oss-security] CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access
Sat Jul 25 19:04:48 2026
Sun Aug 23 16:37:12 2026
28.90 August 1 CVE-2026-41992
libXfont2 [vs-plain] Preview of X.Org Security Advisory (libXfont2) for 2026-08-05
[oss-security] FW: X.Org Security Advisory: multiple security issues in libXfont2
Thu Jul 30 06:07:01 2026
Wed Aug 05 02:15:57 2026
5.84 Aug 05, 2026 at 01:00 UTC CVE-2026-59679
CVE-2026-44950

Source input data

These files were manually created based on review of the e-mail threads and external resources referenced from there. They were processed with this Perl script to produce the tables above. You should be able to reproduce that.