{"items":[{"cve_id":"CVE-2026-95104","description":"Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition.","status":"Received","severity":"HIGH","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:08.697Z","modified_at":"2026-09-28T09:17:08.697Z","cwes":["CWE-121"],"references":[{"url":"https://jvn.jp/en/vu/JVNVU94863997/","source":"vultures@jpcert.or.jp"},{"url":"https://www.buffalo.jp/news/detail/20260928-01.html","source":"vultures@jpcert.or.jp"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-95104","sourceIdentifier":"vultures@jpcert.or.jp","published":"2026-09-28T09:17:08.697","lastModified":"2026-09-28T09:17:08.697","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"BUFFALO INC.","product":"WSR-300HP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"Ver.2.55","versionType":"semver","status":"affected"}]},{"vendor":"BUFFALO INC.","product":"WEX-G300","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"Ver.1.71","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://jvn.jp/en/vu/JVNVU94863997/","source":"vultures@jpcert.or.jp"},{"url":"https://www.buffalo.jp/news/detail/20260928-01.html","source":"vultures@jpcert.or.jp"}]}},"created_at":"2026-09-28T09:17:45.073102057Z","updated_at":"2026-09-28T09:17:45.073102057Z"},{"cve_id":"CVE-2026-94287","description":"A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.","status":"Received","severity":"MEDIUM","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:08.577Z","modified_at":"2026-09-28T09:17:08.577Z","cwes":["CWE-1050"],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/32/diffs?commit_id=3a68f818b1628d7ad96245b0f4d15a32a015b0ab","source":"meissner@suse.de"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-94287","sourceIdentifier":"meissner@suse.de","published":"2026-09-28T09:17:08.577","lastModified":"2026-09-28T09:17:08.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"x.org","product":"libXpm","defaultStatus":"unaffected","packageName":"libXpm","repo":"https://gitlab.freedesktop.org/xorg/lib/libxpm","versions":[{"version":"0","lessThan":"3.5.19","versionType":"rpm","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-1050"}]}],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/32/diffs?commit_id=3a68f818b1628d7ad96245b0f4d15a32a015b0ab","source":"meissner@suse.de"}]}},"created_at":"2026-09-28T09:17:45.072748462Z","updated_at":"2026-09-28T09:17:45.072748462Z"},{"cve_id":"CVE-2026-94286","description":"An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.","status":"Received","severity":"HIGH","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:08.463Z","modified_at":"2026-09-28T09:17:08.463Z","cwes":["CWE-126"],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10/diffs?commit_id=16023c86070e6af9407330deea3938fcef75815b","source":"meissner@suse.de"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-94286","sourceIdentifier":"meissner@suse.de","published":"2026-09-28T09:17:08.463","lastModified":"2026-09-28T09:17:08.463","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"x.org","product":"libXtst","defaultStatus":"unaffected","packageName":"libXtst","repo":"https://gitlab.freedesktop.org/xorg/lib/libxtst","versions":[{"version":"0","lessThan":"1.2.6","versionType":"rpm","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-126"}]}],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10/diffs?commit_id=16023c86070e6af9407330deea3938fcef75815b","source":"meissner@suse.de"}]}},"created_at":"2026-09-28T09:17:45.072528939Z","updated_at":"2026-09-28T09:17:45.072528939Z"},{"cve_id":"CVE-2026-94285","description":"An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.","status":"Received","severity":"MEDIUM","cvss_score":5.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","cvss_version":"3.1","published_at":"2026-09-28T09:17:08.353Z","modified_at":"2026-09-28T09:17:08.353Z","cwes":["CWE-125"],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a","source":"meissner@suse.de"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-94285","sourceIdentifier":"meissner@suse.de","published":"2026-09-28T09:17:08.353","lastModified":"2026-09-28T09:17:08.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"x.org","product":"libX11","defaultStatus":"unaffected","packageName":"libX11","repo":"https://gitlab.freedesktop.org/xorg/lib/libx11","versions":[{"version":"0","lessThan":"1.8.14","versionType":"rpm","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.5,"impactScore":2.5}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a","source":"meissner@suse.de"}]}},"created_at":"2026-09-28T09:17:45.072301141Z","updated_at":"2026-09-28T09:17:45.072301141Z"},{"cve_id":"CVE-2026-94284","description":"An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.","status":"Received","severity":"MEDIUM","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:08.247Z","modified_at":"2026-09-28T09:17:08.247Z","cwes":["CWE-125"],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2","source":"meissner@suse.de"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-94284","sourceIdentifier":"meissner@suse.de","published":"2026-09-28T09:17:08.247","lastModified":"2026-09-28T09:17:08.247","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"x.org","product":"libX11","defaultStatus":"unaffected","packageName":"libX11","repo":"https://gitlab.freedesktop.org/xorg/lib/libx11","versions":[{"version":"0","lessThan":"1.8.14","versionType":"rpm","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2","source":"meissner@suse.de"}]}},"created_at":"2026-09-28T09:17:45.072142592Z","updated_at":"2026-09-28T09:17:45.072142592Z"},{"cve_id":"CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.","status":"Received","severity":"MEDIUM","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:08.133Z","modified_at":"2026-09-28T09:17:08.133Z","cwes":["CWE-125"],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd","source":"meissner@suse.de"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-94283","sourceIdentifier":"meissner@suse.de","published":"2026-09-28T09:17:08.133","lastModified":"2026-09-28T09:17:08.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"x.org","product":"libX11","defaultStatus":"unaffected","packageName":"libX11","repo":"https://gitlab.freedesktop.org/xorg/lib/libx11","versions":[{"version":"0","lessThan":"1.8.14","versionType":"rpm","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd","source":"meissner@suse.de"}]}},"created_at":"2026-09-28T09:17:45.071920263Z","updated_at":"2026-09-28T09:17:45.071920263Z"},{"cve_id":"CVE-2026-94282","description":"An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.","status":"Received","severity":"MEDIUM","cvss_score":5.6,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:08.003Z","modified_at":"2026-09-28T09:17:08.003Z","cwes":["CWE-125"],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=cecf160e9731fe01f3632f875f29ffcb598b052a","source":"meissner@suse.de"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-94282","sourceIdentifier":"meissner@suse.de","published":"2026-09-28T09:17:08.003","lastModified":"2026-09-28T09:17:08.003","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"x.org","product":"libXi","defaultStatus":"unaffected","packageName":"libXi","repo":"https://gitlab.freedesktop.org/xorg/lib/libxi","versions":[{"version":"0","lessThan":"1.8.4","versionType":"rpm","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","baseScore":5.6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.3,"impactScore":4.2}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=cecf160e9731fe01f3632f875f29ffcb598b052a","source":"meissner@suse.de"}]}},"created_at":"2026-09-28T09:17:45.071704137Z","updated_at":"2026-09-28T09:17:45.071704137Z"},{"cve_id":"CVE-2026-91206","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values.","status":"Received","severity":"MEDIUM","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:43.013Z","modified_at":"2026-09-28T09:17:07.907Z","cwes":["CWE-79"],"references":[{"url":"https://github.com/apache/roller/pull/191","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/tljwqdttq8tgg6hr8sxlcnwpxl6pch4s","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/24","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-91206","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:43.013","lastModified":"2026-09-28T09:17:07.907","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/apache/roller/pull/191","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/tljwqdttq8tgg6hr8sxlcnwpxl6pch4s","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/24","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.645812448Z","updated_at":"2026-09-28T09:17:45.069280007Z"},{"cve_id":"CVE-2026-91204","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.","status":"Received","severity":"MEDIUM","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.887Z","modified_at":"2026-09-28T09:17:07.807Z","cwes":["CWE-79"],"references":[{"url":"https://github.com/apache/roller/pull/190","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/4qzp8m0438056l5t6m6719ob79gx72lz","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/23","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-91204","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.887","lastModified":"2026-09-28T09:17:07.807","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/apache/roller/pull/190","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/4qzp8m0438056l5t6m6719ob79gx72lz","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/23","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.645617732Z","updated_at":"2026-09-28T09:17:45.069027591Z"},{"cve_id":"CVE-2026-86530","description":"BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.","status":"Received","severity":"HIGH","cvss_score":7.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:07.653Z","modified_at":"2026-09-28T09:17:07.653Z","cwes":["CWE-78"],"references":[{"url":"https://jvn.jp/en/vu/JVNVU94863997/","source":"vultures@jpcert.or.jp"},{"url":"https://www.buffalo.jp/news/detail/20260928-01.html","source":"vultures@jpcert.or.jp"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-86530","sourceIdentifier":"vultures@jpcert.or.jp","published":"2026-09-28T09:17:07.653","lastModified":"2026-09-28T09:17:07.653","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"BUFFALO INC.","product":"WSR-300HP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"Ver.2.55","versionType":"semver","status":"affected"}]},{"vendor":"BUFFALO INC.","product":"WEX-G300","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"Ver.1.71","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://jvn.jp/en/vu/JVNVU94863997/","source":"vultures@jpcert.or.jp"},{"url":"https://www.buffalo.jp/news/detail/20260928-01.html","source":"vultures@jpcert.or.jp"}]}},"created_at":"2026-09-28T09:17:45.07147686Z","updated_at":"2026-09-28T09:17:45.07147686Z"},{"cve_id":"CVE-2026-86507","description":"Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose moderator subsequently reviews the submitted comment; no non-default server setting is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later.","status":"Received","severity":"MEDIUM","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T09:17:07.52Z","modified_at":"2026-09-28T09:17:07.52Z","cwes":["CWE-79"],"references":[{"url":"https://github.com/apache/roller/pull/181","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/rjyxvm0fgtdfxwkj5qv532htdbs05wff","source":"security@apache.org"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-86507","sourceIdentifier":"security@apache.org","published":"2026-09-28T09:17:07.520","lastModified":"2026-09-28T09:17:07.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose moderator subsequently reviews the submitted comment; no non-default server setting is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/apache/roller/pull/181","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/rjyxvm0fgtdfxwkj5qv532htdbs05wff","source":"security@apache.org"}]}},"created_at":"2026-09-28T09:17:45.071261865Z","updated_at":"2026-09-28T09:17:45.071261865Z"},{"cve_id":"CVE-2026-85134","description":"Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server.\n\nThis issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.","status":"Received","severity":"HIGH","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","published_at":"2026-09-28T09:17:07.38Z","modified_at":"2026-09-28T09:17:07.38Z","cwes":["CWE-434"],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1197","source":"iletisim@usom.gov.tr"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-85134","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-28T09:17:07.380","lastModified":"2026-09-28T09:17:07.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server.\n\nThis issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Bimser Solution Software Trade Inc.","product":"eBA Plus Document and Workflow Management System","defaultStatus":"unaffected","versions":[{"version":"6.7.141","lessThan":"10.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1197","source":"iletisim@usom.gov.tr"}]}},"created_at":"2026-09-28T09:17:45.071093438Z","updated_at":"2026-09-28T09:17:45.071093438Z"},{"cve_id":"CVE-2026-82969","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS.\n\nThis issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.","status":"Received","severity":"MEDIUM","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T09:17:07.267Z","modified_at":"2026-09-28T09:17:07.267Z","cwes":["CWE-79"],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1197","source":"iletisim@usom.gov.tr"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82969","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-28T09:17:07.267","lastModified":"2026-09-28T09:17:07.267","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS.\n\nThis issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Bimser Solution Software Trade Inc.","product":"eBA Plus Document and Workflow Management System","defaultStatus":"unaffected","versions":[{"version":"6.7.141","lessThan":"10.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1197","source":"iletisim@usom.gov.tr"}]}},"created_at":"2026-09-28T09:17:45.070897089Z","updated_at":"2026-09-28T09:17:45.070897089Z"},{"cve_id":"CVE-2026-82915","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal.\n\nThis issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.","status":"Received","severity":"MEDIUM","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cvss_version":"3.1","published_at":"2026-09-28T09:17:07.13Z","modified_at":"2026-09-28T09:17:07.13Z","cwes":["CWE-22"],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1197","source":"iletisim@usom.gov.tr"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82915","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-28T09:17:07.130","lastModified":"2026-09-28T09:17:07.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal.\n\nThis issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Bimser Solution Software Trade Inc.","product":"eBA Plus Document and Workflow Management System","defaultStatus":"unaffected","versions":[{"version":"6.7.141","lessThan":"10.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1197","source":"iletisim@usom.gov.tr"}]}},"created_at":"2026-09-28T09:17:45.070677476Z","updated_at":"2026-09-28T09:17:45.070677476Z"},{"cve_id":"CVE-2026-82546","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments.","status":"Received","severity":"MEDIUM","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.763Z","modified_at":"2026-09-28T09:17:07.037Z","cwes":["CWE-79"],"references":[{"url":"https://github.com/apache/roller/pull/178","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/ddrykzvs67zpmzwsbqyfjmlydboln8x1","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/21","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82546","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.763","lastModified":"2026-09-28T09:17:07.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","repo":"https://github.com/apache/roller","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/apache/roller/pull/178","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/ddrykzvs67zpmzwsbqyfjmlydboln8x1","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/21","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.645442042Z","updated_at":"2026-09-28T09:17:45.068656023Z"},{"cve_id":"CVE-2026-82387","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.","status":"Received","severity":"MEDIUM","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.647Z","modified_at":"2026-09-28T09:17:06.94Z","cwes":["CWE-79"],"references":[{"url":"https://github.com/apache/roller/pull/174","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/9h1d77xjjk6q90k7l8y7nyffg6ltdzxo","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/20","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82387","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.647","lastModified":"2026-09-28T09:17:06.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/apache/roller/pull/174","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/9h1d77xjjk6q90k7l8y7nyffg6ltdzxo","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/20","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.645275318Z","updated_at":"2026-09-28T09:17:45.068320992Z"},{"cve_id":"CVE-2026-82386","description":"Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations.","status":"Received","severity":"HIGH","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.527Z","modified_at":"2026-09-28T09:17:06.843Z","cwes":["CWE-611"],"references":[{"url":"https://github.com/apache/roller/pull/173","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/mrtstv8odj7l9mcrto445lftrcpw0sxl","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/19","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82386","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.527","lastModified":"2026-09-28T09:17:06.843","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-611"}]}],"references":[{"url":"https://github.com/apache/roller/pull/173","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/mrtstv8odj7l9mcrto445lftrcpw0sxl","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/19","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.645113463Z","updated_at":"2026-09-28T09:17:45.068065752Z"},{"cve_id":"CVE-2026-82385","description":"Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.","status":"Received","severity":"MEDIUM","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.403Z","modified_at":"2026-09-28T09:17:06.743Z","cwes":["CWE-200"],"references":[{"url":"https://github.com/apache/roller/pull/172","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/wfy8jrwf4xk6r8xgd4rosnxwjwdn4znx","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/18","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82385","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.403","lastModified":"2026-09-28T09:17:06.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://github.com/apache/roller/pull/172","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/wfy8jrwf4xk6r8xgd4rosnxwjwdn4znx","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/18","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.644918156Z","updated_at":"2026-09-28T09:17:45.067730661Z"},{"cve_id":"CVE-2026-82384","description":"Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.","status":"Received","severity":"CRITICAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.273Z","modified_at":"2026-09-28T09:17:06.65Z","cwes":["CWE-502"],"references":[{"url":"https://github.com/apache/roller/pull/171","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/21p1dh6x179gmcdpw84kkx9yclrdp410","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/17","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82384","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.273","lastModified":"2026-09-28T09:17:06.650","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://github.com/apache/roller/pull/171","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/21p1dh6x179gmcdpw84kkx9yclrdp410","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/17","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.644752224Z","updated_at":"2026-09-28T09:17:45.067330439Z"},{"cve_id":"CVE-2026-82383","description":"Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default configuration is required; the result can redirect or break the site's public frontpage, with administrative recovery available. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts the write to global administrators.","status":"Received","severity":"HIGH","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.153Z","modified_at":"2026-09-28T09:17:06.55Z","cwes":["CWE-306"],"references":[{"url":"https://github.com/apache/roller/pull/170","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/7oof135zr05zfkslj9s6m5o0brll47dz","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/16","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82383","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.153","lastModified":"2026-09-28T09:17:06.550","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default configuration is required; the result can redirect or break the site's public frontpage, with administrative recovery available. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts the write to global administrators."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/apache/roller/pull/170","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/7oof135zr05zfkslj9s6m5o0brll47dz","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/16","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.644570943Z","updated_at":"2026-09-28T09:17:45.06708095Z"},{"cve_id":"CVE-2026-82382","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This affects only weblogs that use the bundled frontpage theme, and a victim must follow a crafted link for the script to execute. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates and contextually escapes the reflected parameter.","status":"Received","severity":"MEDIUM","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:42.037Z","modified_at":"2026-09-28T09:17:06.457Z","cwes":["CWE-79"],"references":[{"url":"https://github.com/apache/roller/pull/169","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/mt01qhjq701o3v7kddgskn2ryb6l6y2x","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/15","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82382","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:42.037","lastModified":"2026-09-28T09:17:06.457","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This affects only weblogs that use the bundled frontpage theme, and a victim must follow a crafted link for the script to execute. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates and contextually escapes the reflected parameter."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/apache/roller/pull/169","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/mt01qhjq701o3v7kddgskn2ryb6l6y2x","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/15","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.644385735Z","updated_at":"2026-09-28T09:17:45.066722324Z"},{"cve_id":"CVE-2026-82381","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author's or administrator's browser. No optional feature or non-default configuration is required; this affects weblogs with multiple authors or administrators who are not mutually trusted. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which moves those values out of JavaScript literals and writes them as text.","status":"Received","severity":"MEDIUM","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cvss_version":"3.1","published_at":"2026-09-28T08:16:41.913Z","modified_at":"2026-09-28T09:17:06.363Z","cwes":["CWE-79"],"references":[{"url":"https://github.com/apache/roller/pull/168","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/5qvk6j5r8ttm4vx4ntxqt6bjz6pg4r46","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/14","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82381","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:41.913","lastModified":"2026-09-28T09:17:06.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author's or administrator's browser. No optional feature or non-default configuration is required; this affects weblogs with multiple authors or administrators who are not mutually trusted. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which moves those values out of JavaScript literals and writes them as text."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/apache/roller/pull/168","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/5qvk6j5r8ttm4vx4ntxqt6bjz6pg4r46","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/14","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.644211888Z","updated_at":"2026-09-28T09:17:45.066325398Z"},{"cve_id":"CVE-2026-82380","description":"Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration is required; any logged-in author or administrator is affected when induced to visit a crafted page. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates only the submitted salt and applies the same check to multipart forms.","status":"Received","severity":"HIGH","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","cvss_version":"3.1","published_at":"2026-09-28T08:16:41.787Z","modified_at":"2026-09-28T09:17:06.263Z","cwes":["CWE-352"],"references":[{"url":"https://github.com/apache/roller/pull/167","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/db5zl0wrf2c888qwkqmxymddfjc594q8","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/13","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82380","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:41.787","lastModified":"2026-09-28T09:17:06.263","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration is required; any logged-in author or administrator is affected when induced to visit a crafted page. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates only the submitted salt and applies the same check to multipart forms."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://github.com/apache/roller/pull/167","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/db5zl0wrf2c888qwkqmxymddfjc594q8","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/13","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.644047709Z","updated_at":"2026-09-28T09:17:45.066054718Z"},{"cve_id":"CVE-2026-82379","description":"Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method.","status":"Received","severity":"HIGH","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","cvss_version":"3.1","published_at":"2026-09-28T08:16:41.663Z","modified_at":"2026-09-28T09:17:06.167Z","cwes":["CWE-294"],"references":[{"url":"https://github.com/apache/roller/pull/166","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/bg5r225c3z4148z6kf7s3fwwgrs2lx02","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/12","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82379","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:41.663","lastModified":"2026-09-28T09:17:06.167","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":5.5}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-294"}]}],"references":[{"url":"https://github.com/apache/roller/pull/166","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/bg5r225c3z4148z6kf7s3fwwgrs2lx02","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/12","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.643863853Z","updated_at":"2026-09-28T09:17:45.065657521Z"},{"cve_id":"CVE-2026-82378","description":"Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session.","status":"Received","severity":"CRITICAL","cvss_score":9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_version":"3.1","published_at":"2026-09-28T08:16:41.54Z","modified_at":"2026-09-28T09:17:06.07Z","cwes":["CWE-863"],"references":[{"url":"https://github.com/apache/roller/pull/165","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/fq512gy70zj9yx8v4c4zm54x43wqb04b","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/11","source":"af854a3a-2127-422b-91ae-364da2661108"}],"source":"nvd","is_kev":false,"raw_data":{"cve":{"id":"CVE-2026-82378","sourceIdentifier":"security@apache.org","published":"2026-09-28T08:16:41.540","lastModified":"2026-09-28T09:17:06.070","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Roller","defaultStatus":"unknown","versions":[{"version":"6.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":6.0}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/apache/roller/pull/165","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/fq512gy70zj9yx8v4c4zm54x43wqb04b","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/11","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},"created_at":"2026-09-28T08:17:44.64366085Z","updated_at":"2026-09-28T09:17:45.065313744Z"}],"page":1,"page_size":25,"total":145}
