Date: Sun, 12 Apr 2026 19:01:05 +0000 From: Bernard Spil <brnrd@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 7161d76c68c7 - main - security/vuxml: Document Vaultwarden vulnerabilities Message-ID: <69dbebf1.3c1bb.3042267e@gitrepo.freebsd.org>
index | next in thread | raw e-mail
The branch main has been updated by brnrd: URL: https://cgit.FreeBSD.org/ports/commit/?id=7161d76c68c7626bd601d2cb4f595dc2ea7e90ad commit 7161d76c68c7626bd601d2cb4f595dc2ea7e90ad Author: Bernard Spil <brnrd@FreeBSD.org> AuthorDate: 2026-04-12 19:00:46 +0000 Commit: Bernard Spil <brnrd@FreeBSD.org> CommitDate: 2026-04-12 19:00:46 +0000 security/vuxml: Document Vaultwarden vulnerabilities --- security/vuxml/vuln/2026.xml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml index 4597973c97f6..cf959d97c61a 100644 --- a/security/vuxml/vuln/2026.xml +++ b/security/vuxml/vuln/2026.xml @@ -1,3 +1,30 @@ + <vuln vid="57f31f61-36a1-11f1-9839-8447094a420f"> + <topic>Vaultwarden -- Multiple vulnerabilities</topic> + <affects> + <package> + <name>vaultwarden</name> + <range><lt>1.35.5</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The Vaultwarden project reports:</p> + <blockquote cite="https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.5"> + <p>GHSA-937x-3j8m-7w7p Unconfirmed Owner Can Purge Entire Organization Vault.</p> + <p>GHSA-569v-845w-g82p Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization</p> + <p>GHSA-6j4w-g4jh-xjfx Refresh tokens not invalidated on security stamp rotation</p> + </blockquote> + </body> + </description> + <references> + <url>https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.5</url> + </references> + <dates> + <discovery>2026-04-12</discovery> + <entry>2026-04-12</entry> + </dates> + </vuln> + <vuln vid="30bda1c3-369b-11f1-b51c-6dd25bec137b"> <topic>Python -- HTTP proxy CONNECT tunnel does not sanitize CR/LF</topic> <affects>home | help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?69dbebf1.3c1bb.3042267e>
