CVE-2025-31123

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of ...

Continue Reading
FreeBSD : gitea — Multiple vulnerabilities (300f86de-0e4d-11f0-ae40-b42e991fc52e)

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the 300f86de-0e4d-11f0-ae40-b42e991fc52e advisor ...

Continue Reading
Amazon Linux 2 : runfinch-finch (ALASDOCKER-2025-053)

The version of runfinch-finch installed on the remote host is prior to 1.7.1-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2DOCKER-2025-053 advisory. SSH servers w ...

Continue Reading
Amazon Linux 2 : runfinch-finch (ALASDOCKER-2025-053)

The version of runfinch-finch installed on the remote host is prior to 1.7.1-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2DOCKER-2025-053 advisory. SSH servers w ...

Continue Reading
(RHSA-2025:3503) Important: Red Hat build of Cryostat security update

An update is now available for the Red Hat build of Cryostat 4 on RHEL 9. Security Fix(es): golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE ...

Continue Reading
Securing Spring AI MCP servers with OAuth2

Spring AI offers support for Model Context Protocol, or MCP for short, which allows AI models to interact with and access external tools and resources in a structured way. With Spring AI, developers c ...

Continue Reading
Securing Spring AI MCP servers with OAuth2

Spring AI offers support for Model Context Protocol, or MCP for short, which allows AI models to interact with and access external tools and resources in a structured way. With Spring AI, developers c ...

Continue Reading
ALSA-2025:3344 Important: grafana security update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): golang-jwt/jwt: jwt-go allows excessive memory allocation ...

Continue Reading

Back to Main

Subscribe for the latest news: