Statistics are grouped by month of the issue being reported to the private list.
| Month | All reports | Embargoed | Average | Median | Min | Max embargo days |
|---|---|---|---|---|---|---|
| 2026-01 | 3 | 3 | 7.42 | 6.81 | 1.28 | 14.15 |
| 2026-02 | 4 | 4 | 11.57 | 12.70 | 6.75 | 14.15 |
| 2026-03 | 15 | 15 | 10.40 | 5.35 | 1.11 | 49.69 |
| 2026-04 | 16 | 16 | 9.84 | 6.06 | 3.60 | 31.98 |
| 2026-05 | 17 | 17 | 6.79 | 6.02 | 0.14 | 17.14 |
| 2026-06 | 14 | 14 | 11.30 | 7.08 | 0.07 | 57.65 |
| 2026-07 | 22 | 22 | 11.24 | 7.47 | 1.16 | 43.40 |
| Total | 91 | 91 | 9.92 | 6.90 | 0.07 | 57.65 |
Non-embargoed reports (issue already posted to oss-security before being brought to (linux-)distros, which in 2026 didn't occur yet) are (would be) excluded from the calculation of average, median, and minimum embargo duration above.
For the statistics above, we only use the first embargo duration seen in this table, which is the delay between postings to (linux-)distros and oss-security.
For some reports, there's a second embargo duration - that one is the delay (sometimes negative) between a first public posting elsewhere and the posting to (linux-)distros. Such first public posting often does not fully (or at all) reveal security relevance of the issue/fix, making it not-too-unreasonable to allow a little bit (more) of embargo time on the full detail, especially when that's the issue reporter's and/or the upstream project's preference.
| Project | Subjects/titles/links | Time at distros (UTC) … oss-security (UTC) Elsewhere (UTC) | Embargo days | Planned CRD(s) (exact wording) | CVE(s) |
|---|---|---|---|---|---|
| OpenStack keystonemiddleware | [vs] Vulnerability in OpenStack keystonemiddleware (CVE pending) [oss-security] [CVE-2026-22797] OpenStack keystonemiddleware: Privilege Escalation via Identity Headers in External OAuth2 Tokens (CVE-2026-22797) | Thu Jan 08 20:01:47 2026 Thu Jan 15 15:32:58 2026 | 6.81 | Thursday, 2026-01-15, 1500UTC | |
| OpenSSL | [vs-plain] Embargoed OpenSSL security issue [oss-security] OpenSSL Security Advisory (corrected - added CVE-2026-22795 and CVE-2026-22796) | Tue Jan 13 13:44:01 2026 Tue Jan 27 17:19:21 2026 | 14.15 | 27th January 2026 | |
| BIND 9 | [vs] … [oss-security] ISC has disclosed one vulnerability in BIND 9 (CVE-2025-13878) | Tue Jan 20 09:27:28 2026 Wed Jan 21 16:14:45 2026 | 1.28 | 21 January 2026 | CVE-2025-13878 |
| MUNGE | [vs] MUNGE buffer overflow - embargo until 2026-02-10 [oss-security] CVE-2026-25506: MUNGE 0.5-0.5.17 buffer overflow allowing key leakage | Wed Feb 04 00:30:33 2026 Tue Feb 10 18:33:01 2026 | 6.75 | 2026-02-10 18:00 UTC (Tue, 10:00 PST) | CVE-2026-25506 |
| MIT/Heimdal Kerberos | [vs] Critical Kerberos Credential Theft (ADV-2026-005) [oss-security] MIT/Heimdal Kerberos credentials cache type FILE risks | Thu Feb 05 09:24:27 2026 Thu Feb 19 01:15:03 2026 | 13.66 | 2026-02-18 | ADV-2026-005 |
| OpenStack | [vs] … [oss-security] [OSSA-2026-002] OpenStack Nova: calls qemu-img without format restrictions for resize (CVE-2026-24708) | Thu Feb 05 21:18:36 2026 Tue Feb 17 15:01:45 2026 | 11.74 | 2026-02-17 1500UTC | CVE-2026-24708 |
| Linux | [vs-plain] Multiple vulnerabilities in AppArmor [oss-security] Re: Multiple vulnerabilities in AppArmor | Thu Feb 26 18:01:06 2026 Thu Mar 12 21:34:11 2026 | 14.15 | Tuesday, March 3, 17:00 UTC when the patches are published upstream in Linus's tree, in a few days and definitely before the maximum 14-day embargo will almost certainly be published upstream in Linus's tree on Tuesday, March 10 wait until the patches appear in Linus's tree, even if the maximum 14-day embargo is slightly exceeded | |
| OpenSSH GSSAPI patch | [vs-plain] OpenSSH GSSAPI patch issue [oss-security] OpenSSH GSSAPI keyex patch issue | Thu Mar 05 14:03:20 2026 Thu Mar 12 18:03:39 2026 | 7.17 | 2026-03-12 18:00:00 UTC | CVE-2026-3497 |
| OpenStack Glance | [vs] Vulnerability in OpenStack Glance (CVE-pending) [oss-security] [OSSA-2026-004] Glance: Server-Side Request Forgery (SSRF) vulnerabilities in OpenStack Glance image import functionality (CVE-2026-pending) | Thu Mar 05 20:09:33 2026 Thu Mar 19 15:21:06 2026 | 13.80 | 2026-03-19, 1500UTC | OSSA-2026-004 |
| curl | [vs-plain] : pre-notification curl CVE-2026-1965 (1/3) [oss-security] [ADVISORY] curl: CVE-2026-1965: bad reuse of HTTP Negotiate connection https://github.com/curl/curl/pull/20534 | Sun Mar 08 09:32:08 2026 Wed Mar 11 06:54:50 2026 | 2.89 | March 11, this coming Wednesday | CVE-2026-1965 |
| curl | [vs-plain] : pre-notification curl CVE-2026-3783 (2/3) [oss-security] [ADVISORY] curl: CVE-2026-3783: token leak with redirect and netrc https://github.com/curl/curl/pull/20843 | Sun Mar 08 09:32:12 2026 Wed Mar 11 06:54:55 2026 | 2.89 | March 11, this coming Wednesday | CVE-2026-3783 |
| curl | [vs-plain] : pre-notification curl CVE-2026-3784 (3/3) [oss-security] [ADVISORY] curl: CVE-2026-3784: wrong proxy connection reuse with credentials https://github.com/curl/curl/pull/20837 | Sun Mar 08 09:32:22 2026 Wed Mar 11 06:55:00 2026 | 2.89 | March 11, this coming Wednesday | CVE-2026-3784 |
| curl | [vs-plain] : pre-notification curl CVE-2026-3805 (4/3) [oss-security] [ADVISORY] curl: CVE-2026-3805: use after free in SMB connection reuse https://github.com/curl/curl/pull/20854 | Sun Mar 08 21:56:29 2026 Wed Mar 11 06:55:03 2026 | 2.37 | March 11th 2026 | CVE-2026-3805 |
| Linux | [vs] … [oss-security] KVM shadow EPT stale rmap use-after-free | Tue Mar 10 10:33:59 2026 Mon Mar 30 14:41:08 2026 | 20.17 | Sunday March 29, 2026, 16:00 UTC | |
| snapd | [vs] LPE in snapd [oss-security] snap-confine + systemd-tmpfiles = root (CVE-2026-3888) | Thu Mar 12 11:08:29 2026 Tue Mar 17 19:33:32 2026 | 5.35 | 2026-03-17 14:00:00 UTC | CVE-2026-3888 |
| Linux | [vs-plain] Vulnerability Report: KTLS + sockmap “Reverse Order” Use-After-Free / Data Corruption [oss-security] Linux kernel: KTLS + sockmap "Reverse Order" Use-After-Free / Data Corruption | Wed Mar 18 11:54:54 2026 Thu May 07 04:30:00 2026 | 49.69 | March 31st | |
| Dovecot | [vs] Dovecot Security Advisory 2026-01 [oss-security] Dovecot Security Advisory OXDC-2026-0001 | Mon Mar 23 14:57:55 2026 Fri Mar 27 14:48:06 2026 | 3.99 | 27th of March | CVE-2025-30189 CVE-2025-59028 CVE-2025-59032 CVE-2025-59031 CVE-2026-0394 CVE-2026-27860 CVE-2026-24031 CVE-2026-27859 CVE-2026-27857 CVE-2026-27858 CVE-2026-27856 CVE-2026-27855 |
| Kea | [vs] … [oss-security] ISC has disclosed one vulnerability in Kea (CVE-2026-3608) | Tue Mar 24 09:16:10 2026 Wed Mar 25 15:16:52 2026 | 1.25 | 25 March 2026 | CVE-2026-3608 |
| BIND 9 | [vs] … [oss-security] ISC has disclosed four vulnerabilities in BIND 9 (CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591) | Tue Mar 24 12:36:27 2026 Wed Mar 25 15:16:57 2026 | 1.11 | 25 March 2026 | CVE-2026-1519 CVE-2026-3104 CVE-2026-3119 CVE-2026-3591 |
| OpenSSL | [vs-plain] Embargoed OpenSSL security issue [oss-security] OpenSSL Security Advisory | Tue Mar 24 15:39:27 2026 Tue Apr 07 16:37:00 2026 | 14.04 | 7th April 2026 | CVE-2026-31790 CVE-2026-28386 CVE-2026-28387 CVE-2026-28388 CVE-2026-28389 CVE-2026-28390 CVE-2026-31789 |
| OpenStack Keystone | [vs-plain] Vulnerability in OpenStack Keystone (CVE-2026-33551) [oss-security] [OSSA-2026-005] Keystone: Restricted application credentials can create EC2 credentials (CVE-2026-33551) | Tue Mar 24 19:28:14 2026 Tue Apr 07 17:43:25 2026 | 13.93 | 2026-04-07, 1500UTC | CVE-2026-33551 |
| LiteLLM | [vs] … [oss-security] X41 Advisory X41-2026-001: Guardrail Sandbox Escape in LiteLLM | Wed Mar 25 14:19:55 2026 Thu Apr 09 00:09:16 2026 | 14.41 | as fast as possible | x41-2026-001 |
| OVN | [vs-plain] CVE-2026-5367: Heap Over-Read in ICMP Error Response Generation [oss-security] [ADVISORY] CVE-2026-5265: Heap Over-Read in ICMP Error Response Generation | Tue Apr 07 08:04:14 2026 Mon Apr 20 15:51:53 2026 | 13.32 | 13-Apr-2026 20-Apr-2026 | CVE-2026-5265 |
| OVN | [vs-plain] CVE-2026-5367: Heap over-read in OVN DHCPv6 Client ID processing [oss-security] [ADVISORY] CVE-2026-5367: Heap over-read in OVN DHCPv6 Client ID processing | Tue Apr 07 08:04:18 2026 Mon Apr 20 15:52:03 2026 | 13.32 | 13-Apr-2026 20-Apr-2026 | CVE-2026-5367 |
| X.Org X server and Xwayland | [vs-plain] Embargoed X.Org Security Advisory: Multiple security issues in X.Org X server and Xwayland for 2026-04-14 [oss-security] Fwd: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland | Tue Apr 07 08:20:45 2026 Tue Apr 14 15:38:28 2026 | 7.30 | 2026-04-14 at 13:00 UTC | CVE-2026-33999 CVE-2026-34000 CVE-2026-34001 CVE-2026-34002 CVE-2026-34003 |
| GNU sed | [vs-plain] GNU sed: CVE-2026-5958: TOCTOU race in sed -i –follow-symlinks [oss-security] CVE-2026-5958: GNU sed: TOCTOU race in sed -i --follow-symlinks https://savannah.gnu.org/news/?id=10885 | Sat Apr 11 01:40:42 2026 Wed May 13 01:14:29 2026 Wed Apr 22 02:00:45 2026 | 31.98 11.01 | 2026-04-19 the 20th | CVE-2026-5958 |
| libXpm | [vs-plain] Embargoed X.Org Security Advisory: Security issue in libXpm for 2026-04-21 [oss-security] Fwd: X.Org Security Advisory: CVE-2026-4367: libXpm Out-of-bounds read in xpmNextWord() | Tue Apr 14 17:09:39 2026 Tue Apr 21 16:30:10 2026 | 6.97 | 2026-04-21 at 13:00 UTC | CVE-2026-4367 |
| ntfs-3g | [vs] … [oss-security] CVE-2026-40706: ntfs-3g 2022.10.3: Heap buffer overflow | Thu Apr 16 10:27:32 2026 Tue Apr 21 16:30:37 2026 | 5.25 | April 21st (2026-04-21) 12:00 UTC | CVE-2026-40706 GHSA-4cwv-5285-63v9 |
| Kata Containers | [vs-plain] Vulnerability in Kata Containers (CVE Requested) [oss-security] CVE-2026-41326: Kata Containers: CopyFile Policy Subversion via Symlinks https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc | Thu Apr 16 13:42:39 2026 Wed May 13 01:31:41 2026 Wed Apr 22 19:55:00 2026 | 26.49 6.26 | 2026-04-22, 1800 UTC | CVE-2026-41326 |
| PackageKit | [vs] … [oss-security] CVE-2026-41651: TOCTOU vulnerability in PackageKit <= 1.3.4 leads to local root exploit | Sun Apr 19 01:11:19 2026 Wed Apr 22 15:38:54 2026 | 3.60 | next Wednesday (22.04.2026) 22.04.2026, after 12:00 CEST (12:00 PM, 12:00 24h format) | CVE-2026-41651 |
| curl | [vs-plain] : pre-notification curl CVE-2026-4873 (1/6) [oss-security] [ADVISORY] curl: CVE-2026-4873: connection reuse ignores TLS requirement https://github.com/curl/curl/commit/507e7be573b0a76fca597b75 | Thu Apr 23 06:08:11 2026 Wed Apr 29 06:01:05 2026 | 6.00 | April 29 | CVE-2026-4873 |
| curl | [vs-plain] : pre-notification curl CVE-2026-5545 (2/6) [oss-security] [ADVISORY] curl: CVE-2026-5545: wrong reuse of HTTP Negotiate connection https://github.com/curl/curl/commit/33e43985b8f3b9e6669 | Thu Apr 23 06:08:16 2026 Wed Apr 29 06:01:12 2026 | 6.00 | April 29 | CVE-2026-5545 |
| curl | [vs-plain] : pre-notification curl CVE-2026-5773 (3/6) [oss-security] [ADVISORY] curl: CVE-2026-5773: wrong reuse of SMB connection https://github.com/curl/curl/commit/74a169575d6412d | Thu Apr 23 06:08:24 2026 Wed Apr 29 06:01:18 2026 | 6.00 | April 29 | CVE-2026-5773 |
| curl | [vs-plain] : pre-notification curl CVE-2026-6253 (4/6) [oss-security] [ADVISORY] curl: CVE-2026-6253: proxy credentials leak over redirect-to proxy https://github.com/curl/curl/commit/188c2f166a20fa97c2325 | Thu Apr 23 06:08:31 2026 Wed Apr 29 06:01:23 2026 | 6.00 | April 29 | CVE-2026-6253 |
| curl | [vs-plain] : pre-notification curl CVE-2026-6276 (5/6) [oss-security] [ADVISORY] curl: CVE-2026-6276: stale custom cookie host causes cookie leak https://github.com/curl/curl/commit/3a19987a87f393d9394fe5ac | Thu Apr 23 06:08:39 2026 Wed Apr 29 06:01:27 2026 | 6.00 | April 29 | CVE-2026-6276 |
| curl | [vs-plain] : pre-notification curl CVE-2026-6429 (6/6) [oss-security] [ADVISORY] curl: CVE-2026-6429: netrc credential leak with reused proxy connection https://github.com/curl/curl/commit/b4024bf808bd558026fdc6 | Thu Apr 23 06:08:46 2026 Wed Apr 29 06:01:19 2026 | 5.99 | April 29 | CVE-2026-6429 |
| Exim | [vs-plain] EXIM-Security-2026-04-24 [oss-security] Exim 4.99.2 fixes 4 CVEs | Fri Apr 24 15:09:46 2026 Thu Apr 30 18:21:42 2026 | 6.13 | next Wednesday, 2026-04-29T12:00:00+0000 | CVE-2026-40684 CVE-2026-40685 CVE-2026-40686 CVE-2026-40687 |
| OpenStack Cyborg | [vs] … [oss-security] [OSSA-2026-011] OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management (CVE-2026-40213, CVE-2026-40214) | Thu Apr 30 15:02:08 2026 Thu May 07 18:27:34 2026 | 7.14 | 2026-05-07, 1500UTC | CVE-2026-40213 CVE-2026-40214 |
| Linux | [vs-plain] Dirty Frag: Universal LPE on all major Linux distributions [oss-security] Dirty Frag: Universal Linux LPE | Thu May 07 15:01:30 2026 Thu May 07 18:59:34 2026 | 0.17 | embargo of 5 days go out with fixes ASAP | Dirty Frag CVE-2026-43284 CVE-2026-43500 |
| Exim | [vs] EXIM-Security-2026-05-01.1: security release 4.99.3 ahead [oss-security] [EXIM-Security-2026-05-01.1] Security Release 4.99.3 | Thu May 07 22:00:56 2026 Tue May 12 14:15:13 2026 | 4.68 | Tuesday, May 12, 2026, at 14:00 UTC | EXIM-Security-2026-05-01.1 CVE-2026-45185 |
| rsync | [vs-plain] rsync 3.4.3 - 5 CVEs (CVE-2026-29518, CVE-2026-43617, -43618, -43619, -43620) - embargo until 2026-05-20 00:00 UTC [oss-security] rsync 3.4.3 released: six CVEs (CVE-2026-29518, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232) | Fri May 08 00:53:29 2026 Wed May 20 09:26:30 2026 | 12.36 | 2026-05-20 at 00:00 UTC (10:00 AEST, Wednesday morning Canberra time) | CVE-2026-29518 CVE-2026-43617 CVE-2026-43618 CVE-2026-43619 CVE-2026-43620 |
| OpenStack Keystone | [vs] … [oss-security] [OSSA-2026-015] OpenStack Keystone: Multiple credential delegation and authorization bypass vulnerabilities (CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394) | Thu May 14 18:51:47 2026 Thu May 28 20:56:12 2026 | 14.09 | 2026-05-28, 1500UTC | CVE-2026-42998 CVE-2026-42999 CVE-2026-43000 CVE-2026-43001 CVE-2026-44394 |
| Linux | [vs-plain] Logic bug in the Linux kernel's __ptrace_may_access() [oss-security] Logic bug in the Linux kernel's __ptrace_may_access() function | Thu May 14 22:58:25 2026 Fri May 15 02:21:01 2026 | 0.14 | Wednesday, May 20 now | CVE-2026-46333 |
| Linux | [vs-plain] net/tls: Use-After-Free via TOCTOU race in tls_sk_proto_close (local privilege escalation, no privs) [oss-security] Linux kernel TLS ULP use-after-free in tls_sk_proto_close() | Sat May 16 17:36:41 2026 Tue Jun 02 20:52:02 2026 | 17.14 | 2026-05-30 | |
| BIND 9 | [vs] … [oss-security] ISC has disclosed six vulnerabilities in BIND 9 (CVE-2026-3039, CVE-2026-3592, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, CVE-2026-5950) | Mon May 18 18:35:58 2026 Wed May 20 13:56:59 2026 | 1.81 | 20 May 2026 | CVE-2026-3039 CVE-2026-3592 CVE-2026-3593 CVE-2026-5946 CVE-2026-5947 CVE-2026-5950 |
| Kata Containers runtime-rs | [vs-plain] Vulnerability in Kata Containers runtime-rs (GHSA-2gv2-cffp-j227) [oss-security] CVE-2026-47243: Kata Containers runtime-rs 3.30: virtiofsd symlink escape | Mon May 18 19:12:13 2026 Thu May 21 18:27:40 2026 | 2.97 | 2026-05-21 1900UTC | GHSA-2gv2-cffp-j227 CVE-2026-47243 |
| Unbound | [vs] … [oss-security] Unbound: 1.25.1 addresses multiple CVE items | Mon May 18 19:36:33 2026 Wed May 20 09:17:52 2026 | 1.57 | 20 May 2026 | CVE-2026-33278 CVE-2026-42944 CVE-2026-42959 CVE-2026-32792 CVE-2026-40622 CVE-2026-41292 CVE-2026-42534 CVE-2026-42923 CVE-2026-42960 CVE-2026-44390 CVE-2026-44608 |
| OpenStack | [vs] … [oss-security] [OSSA-2026-020] OpenStack Mistral: Mistral policy enforcement bypass allows unauthorized public resource creation and arbitrary code execution (CVE-2026-41283) | Thu May 21 16:42:40 2026 Wed Jun 03 16:51:55 2026 | 13.01 | 2026-06-03 15:00 UTC | CVE-2026-41283 |
| Linux | [vs-plain] kernel+userspace LPE affecting several distros [oss-security] CIFSwitch: Linux kernel/cifs-utils local root via forged cifs.spnego upcall | Mon May 25 07:59:43 2026 Thu May 28 07:07:27 2026 | 2.96 | Wednesday, May 27, 7pm PT | CIFSwitch CVE-2026-46243 |
| Exim | [vs] … [oss-security] CVE-2026-48840: Exim 4.99.4: PROXY-protocol uninitialised-stack information disclosure | Mon May 25 22:41:34 2026 Fri May 29 14:39:08 2026 | 3.66 | Friday, 2026-05-29 14:00 UTC | EXIM-Security-2026-05-19.1 CVE-2026-48840 |
| OpenSSL | [vs-plain] Embargoed OpenSSL issues [oss-security] OpenSSL Security Advisory | Tue May 26 13:10:13 2026 Tue Jun 09 16:09:07 2026 | 14.12 | 9th June 2026 | |
| X.Org X server and Xwayland | [vs-plain] Preview of X.Org Security Advisory for 2026-06-02 [oss-security] FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland | Wed May 27 00:04:06 2026 Tue Jun 02 00:27:21 2026 | 6.02 | June 2, 2026 at 00:00 UTC | |
| OpenStack | [vs] … [oss-security] [OSSA-2026-019] Ironic: File Extraction from conductor via pxe_template (CVE-2026-44917) | Wed May 27 19:21:05 2026 Wed Jun 03 16:51:51 2026 | 6.90 | June 3 2026, 1500UTC | CVE-2026-44917 |
| OpenStack | [vs] … [oss-security] [OSSA-2026-017] Ironic: Script injection during node boot via linux command line override (CVE-2026-46447) | Wed May 27 19:23:10 2026 Wed Jun 03 16:51:36 2026 | 6.89 | June 3 2026, 1500 UTC | CVE-2026-46447 |
| OpenStack | [vs] … [oss-security] [OSSA-2026-018] Ironic: File overwrite on Ironic conductor via path traversal in ISO handling (CVE-2026-48681) | Wed May 27 19:23:11 2026 Wed Jun 03 16:51:41 2026 | 6.89 | June 3 2026, 1500UTC | CVE-2026-48681 |
| ldns | [vs] … [oss-security] ldns insufficiently verifies that responses belong to a query | Thu Jun 04 12:23:28 2026 Wed Jun 10 08:59:45 2026 | 5.86 | Tuesday the 9th of June 2026 | CVE-2026-10846 |
| OpenStack Nova | [vs] … [oss-security] [OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints (CVE-2026-46448) | Thu Jun 04 17:53:31 2026 Tue Jun 16 15:18:02 2026 | 11.89 | 2026-06-16 15:00 UTC | CVE-2026-46448 |
| Linux | [vs-plain] ITScape: Guest-to-Host Escape in KVM/arm64 [oss-security] ITScape: Guest-to-Host Escape in KVM/arm64 (CVE-2026-46316) | Fri Jun 05 23:06:10 2026 Wed Jun 10 18:24:31 2026 | 4.80 | a 5 day embargo | ITScape CVE-2026-46316 CVE-2026-46317 |
| rsync | [vs-plain] rsync 3.4.4 released, regression fixes [oss-security] rsync 3.4.4 released, regression fixes | Mon Jun 08 04:42:43 2026 Mon Jun 08 06:26:24 2026 | 0.07 | ||
| libxml2 | [vs] … [oss-security] CVE-2026-6653: libxml2: use after free in xmlParseInternalSubset (>=2.9.11, <2.11.0) | Mon Jun 08 12:02:00 2026 Mon Jun 22 16:05:48 2026 | 14.17 | 14 days 22 June 2026 | CVE-2026-6653 |
| OpenStack Swift | [vs] … [oss-security] [OSSA-2026-024] OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221) | Wed Jun 10 03:40:37 2026 Tue Jun 23 15:37:18 2026 | 13.50 | 2026-06-18 15:00 UTC 2026-06-23 15:00 UTC | CVE-2026-50221 |
| Pacemaker | [vs-plain] Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) [oss-security] Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) | Thu Jun 11 22:49:27 2026 Tue Jun 16 15:46:20 2026 | 4.71 | Jun 16th 2026 | CVE-2026-10649 |
| containerd | [vs-plain] [Embargoed] containerd patches for CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 [oss-security] [containerd] Patch releases addressing CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 | Tue Jun 16 17:51:02 2026 Fri Jun 19 01:02:16 2026 | 2.30 | Thursday, June 18, 2026 between 1pm and 5pm Pacific (20:00 to 00:00 UTC) | CVE-2026-50195 CVE-2026-53488 CVE-2026-53492 CVE-2026-53489 CVE-2026-47262 |
| curl | [vs-plain] : curl pre-notification of 18 security advisories [oss-security] [SECURITY ADVISORIES] for curl 8.21.0 | Wed Jun 17 06:08:02 2026 Wed Jun 24 16:37:41 2026 | 7.44 | June 24 | CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8925 CVE-2026-8926 CVE-2026-8927 CVE-2026-8932 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9546 CVE-2026-9547 CVE-2026-10536 CVE-2026-11352 CVE-2026-11564 CVE-2026-11586 CVE-2026-11856 CVE-2026-12064 |
| shim, GRUB2 | [vs-plain] Combined chain advisory — fallback.efi/SBAT/memdisk bypass (shim + GRUB2) [oss-security] AI slop "Combined chain advisory — fallback.efi/SBAT/memdisk bypass" | Sun Jun 21 13:42:20 2026 Tue Aug 18 05:20:12 2026 | 57.65 | 90-day embargo Wednesday, July 1st, 2026 | |
| NLnet Labs NSD | [vs] … [oss-security] Several vulnerabilities were found in NLnet Labs NSD | Mon Jun 22 06:48:25 2026 Thu Jun 25 17:30:12 2026 | 3.45 | Thursday 25 June | CVE-2026-12244 CVE-2026-12245 CVE-2026-12246 CVE-2026-12490 |
| acl, attr | [vs] Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl [oss-security] Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl | Mon Jun 22 21:56:42 2026 Mon Jun 29 15:26:07 2026 | 6.73 | 2026-06-29T13:00:00.000Z | CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 |
| OpenStack Ironic | [vs] … [oss-security] [OSSA-2026-026] Ironic: Insufficient Access Controls regarding parent/child nodes | Thu Jun 25 19:40:31 2026 Wed Jul 08 15:29:45 2026 | 12.83 | 2026-07-08, 1500UTC | CVE-2026-44918 |
| OpenStack Ironic | [vs] … [oss-security] [OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423) | Thu Jun 25 19:48:33 2026 Wed Jul 08 15:05:10 2026 | 12.80 | 2026-07-08, 1500UTC | CVE-2026-54423 |
| X.Org X server and Xwayland | [vs-plain] Preview of X.Org Security Advisory (xserver) for 2026-07-08 [oss-security] FW: X.Org Security Advisory: multiple security issues X.Org X server and Xwayland | Wed Jul 01 00:22:27 2026 Wed Jul 08 01:55:08 2026 | 7.06 | July 08, 2026 at 01:00 UTC | CVE-2026-55999 CVE-2026-56000 ZDI-CAN-30498 ZDI-CAN-30561 |
| libXfont2 | [vs-plain] Preview of X.Org Security Advisory (libXfont2) for 2026-07-08 [oss-security] FW: X.Org Security Advisory: multiple security issues in libXfont2 | Wed Jul 01 00:28:10 2026 Wed Jul 08 01:35:41 2026 | 7.05 | July 08, 2026 at 01:00 UTC | CVE-2026-56001 CVE-2026-56002 CVE-2026-56003 ZDI-CAN-30558 ZDI-CAN-30559 ZDI-CAN-30560 |
| Linux | [vs-plain] Januscape: Guest-to-Host Escape in KVM/x86 [oss-security] Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb | Wed Jul 01 15:02:52 2026 Mon Jul 06 16:26:14 2026 | 5.06 | 5 day embargo 2026-07-06 16:00 UTC | CVE-2026-53359 |
| ntfs-3g | [vs] … [oss-security] Multiple vulnerabilities in ntfs-3g | Wed Jul 08 20:22:55 2026 Wed Jul 15 19:00:04 2026 | 6.94 | 2026-07-15 12:00 UTC | CVE-2026-42616 CVE-2026-42617 CVE-2026-42618 CVE-2026-46569 CVE-2026-46570 CVE-2026-46571 CVE-2026-46572 CVE-2026-56135 CVE-2026-56136 |
| Kata Containers | [vs-plain] Subject: [pre-KCSA] Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540) [oss-security] Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540) | Sat Jul 11 09:18:33 2026 Sun Aug 23 18:51:59 2026 | 43.40 | 2026-07-20, 1200UTC | CVE-2026-50540 |
| BusyBox dpkg applet | [vs] BusyBox dpkg applet: OS command injection → root RCE (CWE-78) [oss-security] BusyBox dpkg applet: OS command injection | Mon Jul 13 03:14:45 2026 Mon Aug 24 05:01:24 2026 | 42.07 | 2026-07-27 I'm withdrawing this | |
| snapd | [vs] LPE in snapd and other vulnerabilities [oss-security] LPE in snapd and other vulnerabilities | Mon Jul 13 13:23:42 2026 Tue Jul 21 14:58:39 2026 | 8.07 | 2026-07-21 14:00:00 UTC | CVE-2026-8933 CVE-2024-5300 CVE-2026-15226 |
| Linux | [vs-plain] Advance notice of CVE-2026-53362 exploit publication [oss-security] CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel | Mon Jul 13 15:33:16 2026 Mon Jul 20 16:45:01 2026 | 7.05 | 2026-07-17 15:00 UTC | CVE-2026-53362 CVE-2026-53366 |
| Exim | [vs-plain] Exim GCVE-25-2026-07-45-1, GCVE-25-2026-07-45-3: security update 4.99.4 → 4.99.5 [oss-security] security release for Exim | Mon Jul 13 19:25:42 2026 Wed Jul 22 15:57:06 2026 | 8.86 | Wednesday, Jul 20th, 2026, at 14:00 UTC | GCVE-25-2026-07-45-1 GCVE-25-2026-07-45-3 EXIM-Security-2026-06-22.1 EXIM-Security-2026-06-22.3 |
| OpenStack Swift | [vs] … [oss-security] [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending) | Tue Jul 14 19:36:43 2026 Tue Jul 28 15:49:36 2026 | 13.84 | 2026-07-28 15:00 UTC | CVE-2026-71191 CVE-2026-71192 OSSA-2026-030 |
| OpenStack Swift | [vs] … [oss-security] [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending) | Tue Jul 14 19:41:38 2026 Tue Jul 28 15:49:39 2026 | 13.84 | 2026-07-28 15:00 UTC | CVE-2026-71190 OSSA-2026-031 |
| OpenStack ironic-python-agent | [vs] … [oss-security] [OSSA-2026-028] OpenStack Ironic Python Agent: Credential extraction via malicious container (CVE-2026-54422) | Wed Jul 15 20:46:39 2026 Thu Jul 23 19:21:09 2026 | 7.94 | 2026-07-23 15:00 UTC | CVE-2026-54422 OSSA-2026-028 |
| OpenStack ironic-python-agent | [vs] … [oss-security] [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending) | Wed Jul 15 20:51:01 2026 Thu Jul 23 19:21:36 2026 | 7.94 | 2026-07-23 15:00 UTC | CVE-2026-66138 OSSA-2026-027 |
| Linux | [vs] Qualys Security Advisory (2026-07-15) [oss-security] RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) | Wed Jul 15 21:55:23 2026 Wed Jul 22 16:47:30 2026 | 6.79 | aware of the 14-day embargo limit no later than July 30th Wednesday, July 22, 16:00 UTC | RefluXFS CVE-2026-64600 |
| GNU inetutils talkd | [vs-plain] GNU inetutils talkd buffer overflow with long DNS names. [oss-security] GNU Inetutils talkd buffer overflow with long DNS names. | Fri Jul 17 05:44:17 2026 Sat Jul 25 16:59:19 2026 | 8.47 | 2026-07-24 | |
| Unbound | [vs] … [oss-security] Unbound: 1.25.2 addresses multiple CVE items | Mon Jul 20 13:54:16 2026 Wed Jul 22 15:56:26 2026 | 2.08 | 22 July 2026 | CVE-2026-32665 CVE-2026-40691 CVE-2026-44690 CVE-2026-55973 CVE-2026-14586 CVE-2026-44621 CVE-2026-50045 CVE-2026-50046 CVE-2026-50243 CVE-2026-50248 CVE-2026-50251 CVE-2026-50252 CVE-2026-52863 CVE-2026-55717 CVE-2026-55990 CVE-2026-55991 CVE-2026-56416 CVE-2026-56444 CVE-2026-41637 CVE-2026-42955 CVE-2026-44687 CVE-2026-46582 CVE-2026-54478 CVE-2026-55708 |
| rsyslog | [vs-plain] EMBARGOED: rsyslog imptcp regex-framing remote denial of service [oss-security] rsyslog v8.36.0 through v8.2606.0: imptcp regex-framing remote denial of service | Mon Jul 20 15:41:50 2026 Wed Jul 22 15:56:09 2026 | 2.01 | 2027-07-22 12:00 CEST (10:00 UTC) 2026-07-22 12:00 CEST (10:00 UTC) | |
| BIND 9 | [vs] … [oss-security] ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321) | Tue Jul 21 11:59:43 2026 Wed Jul 22 15:56:35 2026 | 1.16 | 22 July 2026 | CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605 CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321 |
| OpenStack Neutron | [vs] … [oss-security] [OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707) | Tue Jul 21 18:10:22 2026 Wed Jul 29 15:09:19 2026 | 7.87 | 2026-07-29 15:00 UTC | CVE-2026-55707 |
| Linux | [vs-plain] Linux kernel LPE affecting a number of distros [oss-security] OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerability | Thu Jul 23 09:24:18 2026 Tue Jul 28 10:06:15 2026 | 5.03 | Monday, July 27, 6am UTC Tuesday 6am UTC may slip a couple of hours on the 6am UTC timeline | OVSwrap CVE-2026-64531 |
| gzip | [vs] … [oss-security] CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer access | Sat Jul 25 19:04:48 2026 Sun Aug 23 16:37:12 2026 | 28.90 | August 1 | CVE-2026-41992 |
| libXfont2 | [vs-plain] Preview of X.Org Security Advisory (libXfont2) for 2026-08-05 [oss-security] FW: X.Org Security Advisory: multiple security issues in libXfont2 | Thu Jul 30 06:07:01 2026 Wed Aug 05 02:15:57 2026 | 5.84 | Aug 05, 2026 at 01:00 UTC | CVE-2026-59679 CVE-2026-44950 |
These files were manually created based on review of the e-mail threads and external resources referenced from there. They were processed with this Perl script to produce the tables above. You should be able to reproduce that.