279 counted public security records across 136 projects

security research in software and hardware trust infrastructure

all research follows coordinated vulnerability disclosure (cvd). public statements reference only published advisories and released fixes. counted records are public evidence units, not a unique vulnerability count; current mechanically deduplicated finding IDs: 273.

95 CVEs published
14 GHSAs published
28 researcher-authored security PRs
14 credited upstream fixes
5 authored hardening/testing contributions
123 reported fixes landed publicly

top infrastructure brands in the current portfolio by public footprint include:

Linux Google Apple Nvidia AWS Microsoft Meta OpenSSL Telegram Ledger Intel AMD TON Decred Docker GitHub Hugging Face PurpleLlama Signal Proton Let's Encrypt Caddy Mozilla Trezor Prometheus OpenTelemetry HashiCorp OpenClaw Sigstore Aquasecurity Trivy Chainguard

how findings are found

found via ai-augmented detection pipeline. deterministic proof, human-verified — every finding has reproducible artifacts that maintainers can rerun independently.

no llm in the decision path. detection generates hypotheses; local harness confirms or rejects with canonical/control logs and witness files.

research focus

  • trust infrastructure — certificate validation, transparency, signing, update security, attestation, and policy enforcement
  • focus — boundary failures in systems that decide what is authentic, authorized, and safe to run across software, cloud, and hardware-backed environments

advisories

detailed technical write-ups for selected findings.

1SEAL-2026-011

torvalds/linux · F-TORVALDS-LINUX-BT-SMP-001

Linux Bluetooth SMP legacy pairing can satisfy BT_SECURITY_HIGH without MITM — CVSS 7.1, CWE-287, fixed in mainline commits d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7 and 20756fec2f0108cb88e815941f1ffff88dc286fe.

high

1SEAL-2026-010

theopolis/uefi-firmware-parser · F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003 / F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002

Two critical out-of-bounds writes in the imported Tiano decompressor — CWE-787, fixed in master contains bf3dfaa8a05675bae6ea0cbfa082ddcebfcde23e; no post-fix release observed.

critical

1SEAL-2026-009

openssl/openssl · F-OPENSSL-OCSP-001

OpenSSL 3.6 stapled OCSP verification can accept unauthorized responders from the peer chain — CWE-295, fixed in master and openssl-3.6 fixes published.

high

1SEAL-2026-008

TelegramMessenger/Telegram-iOS · F-TELEGRAM-WEBAPP-001

Telegram iOS Web App bridge exposed to third-party iframes — CWE-863, CWE-346, fixed in release-12.4.

medium

1SEAL-2026-007

TelegramMessenger/Telegram-iOS · F-TELEGRAM-TL-001

heap buffer over-read in TL deserialization from operator precedence bug — CVSS 5.3, CWE-125, fixed in release-12.4.

medium

1SEAL-2026-006

moby/buildkit · F-BUILDKIT-001-001 · CVE-2026-33747 · GHSA-4c29-8rgm-jvjj

ContainerID path traversal in gateway frontend can escape runc executor root — CVSS 8.4, CWE-22, fixed in v0.28.1+.

high

1SEAL-2026-002

aws/aws-lc · F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002

Name Constraints bypass via CommonName fallback — CVSS 7.4, CWE-295, fixed in aws-lc 2026-03-19 release.

high

1SEAL-2026-001

awslabs/aws-c-event-stream · F-AWS-EVENT-STREAM-001 · CVE-2026-5190

remote out-of-bounds write in streaming decoder — CVSS 8.1, CWE-787, fixed in v0.6.0.

high

1SEAL-2026-003

tektoncd/pipeline · F-TEKTON-001-001 · CVE-2026-33211 · GHSA-j5q5-j9gm-2w5c

path traversal in git resolver — tenant to cluster-wide secret access — CVSS 9.6, CWE-22, fixed in v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2.

critical

1SEAL-2026-005

LedgerHQ/app-bitcoin-new · F-LEDGER-BTC-MERKLE-001

signing-path integrity gate bypass via merkle preimage binding break — CWE-825, fixed in commit 0586ab2.

high

CVEs

F-TREZOR-005

trezor/trezor-firmware · CVE-2026-65058

cvss 5.3 · CWE-358 · patched in Trezor Safe 3, Safe 5, and Safe 7 (commit 70c9b0c) · on-device confirmation in Ethereum sign_tx and sign_tx_eip1559 covered only the initial calldata chunk while the signature committed to the full streamed calldata. CISA published CSAF VA-26-202-02 through cisagov/CSAF PR #436; fixed in commit 70c9b0c. · credit: Oleh Konko / 1seal

patched

F-SIG-036-001

sigstore/cosign · CVE-2026-22703

cvss 5.5 · patched in cosign v2.6.2, v3.0.4

patched

F-SIG-038-001

sigstore/rekor · CVE-2026-23831

cvss 5.3 · patched in rekor 1.5.0

patched

F-REKOR-SSRF-001

sigstore/rekor · CVE-2026-24117

cvss 5.3 · patched in rekor 1.5.0

patched

F-COSIGN-001-003

sigstore/cosign · CVE-2026-24122

cvss 3.7 · patched in cosign 3.0.5

patched

F-SIGSTORE-005

sigstore/sigstore · CVE-2026-24137

cvss 5.8 · patched in sigstore 1.10.4

patched

F-SIG-JS-TLOGTIME-001

sigstore/sigstore-js · CVE-2026-48816

cvss 6.5 · CWE-345 · patched in @sigstore/verify 3.1.1 · GHSA-xgjw-pm74-86q4; inclusionProof-only bundle integratedTime was treated as a trusted timestamp without cryptographic binding. · credit: reporter: @1seal

patched

F-TUF-003

theupdateframework/go-tuf/v2 · CVE-2026-23991

cvss 5.9 · patched in go-tuf/v2 2.3.1

patched

F-TUF-001

theupdateframework/go-tuf/v2 · CVE-2026-23992

cvss 5.9 · patched in go-tuf/v2 2.3.1

patched

F-TUF-008

theupdateframework/go-tuf/v2 · CVE-2026-24686

cvss 8.1 · patched in go-tuf/v2 2.4.1

patched

F-MALCONTENT-003

chainguard-dev/malcontent · CVE-2026-24845

cvss 6.5 · patched in malcontent 1.20.3

patched

F-MALCONTENT-001

chainguard-dev/malcontent · CVE-2026-24846

cvss 5.5 · patched in malcontent 1.20.3

patched

F-APKO-001

chainguard-dev/apko · CVE-2026-25121

cvss 7.5 · patched in apko (commit d8b7887)

patched

F-APKO-007

chainguard-dev/apko · CVE-2026-25140

cvss 7.5 · patched in apko (commit 2be3903)

patched

F-APKO-003

chainguard-dev/apko · CVE-2026-25122

cvss 5.5 · patched in apko v1.1.0 · unbounded resource consumption in expandapk.Split · credit: reporter: @1seal

patched

F-APKO-SYMLINK-001

chainguard-dev/apko · CVE-2026-42574

cvss 7.5 · patched in apko v1.2.5 · symlink-following path traversal in apko dirFS allows multiple entry points to escape the build root · credit: reporter: @1seal

patched

F-APKO-002

chainguard-dev/apko · CVE-2026-42576

cvss 6.5 · patched in apko v1.2.7 · panic on non-RSA JWKS key in apko DiscoverKeys causes crash during key discovery · credit: reporter: @1seal

patched

F-APKO-CHECKSUM-001

chainguard-dev/apko · CVE-2026-42575

cvss 7.5 · patched in apko v1.2.7 · downloaded APK packages are not verified against APKINDEX checksum (package substitution possible) · credit: reporter: @1seal

patched

F-GNUTLS-NAMECONSTRAINTS-001

gnutls/gnutls · CVE-2026-3833

patched in GnuTLS 3.8.13 · x509/name-constraints: compare domain names case-insensitive · credit: independently reported by Oleh Konko (1seal) and Joshua Rogers

patched

F-GNUTLS-OCSP-001

gnutls/gnutls · CVE-2026-3832

patched in GnuTLS 3.8.13 · cert-session: fix multi-entry OCSP revocation bypass · credit: independently reported by Oleh Konko (1seal) and Joshua Rogers

patched

F-GNUTLS-HOSTNAME-001

gnutls/gnutls · CVE-2026-42012

patched in GnuTLS 3.8.13 · x509/hostname-verify: make URI/SRV SAN preclude CN fallback · credit: reported by Oleh Konko (1seal)

patched

F-MELANGE-001

chainguard-dev/melange · CVE-2026-24844

cvss 7.9 · patched in melange (commit e51ca30c)

patched

F-MELANGE-005

chainguard-dev/melange · CVE-2026-24843

cvss 8.2 · patched in melange (commit 6e243d0d)

patched

F-MELANGE-007

chainguard-dev/melange · CVE-2026-25143

cvss 7.8 · patched in melange (commit bd132535)

patched

F-MELANGE-006

chainguard-dev/melange · CVE-2026-25145

cvss 5.5 · patched in melange (commit 2f95c9f)

patched

F-CERTMGR-DNS-001

cert-manager/cert-manager · CVE-2026-25518

cvss 5.9 · patched in cert-manager v1.18.5, v1.19.3

patched

F-TRIVY-ACTION-001

aquasecurity/trivy-action · CVE-2026-26189

cvss 5.9 · patched in trivy-action >= 0.34.0

patched

F-TRAEFIK-003

traefik/traefik · CVE-2026-29054

cvss 7.5 · unpatched

unpatched

F-TRAEFIK-004

traefik/traefik · CVE-2026-26999

cvss 7.5 · unpatched

unpatched

F-TRAEFIK-006

traefik/traefik · CVE-2026-29777

cvss 8.7 · patched in v3.6.10

patched

F-NIMIQ-HISTORYINDEX-PANIC-001

nimiq/core-rs-albatross · CVE-2026-35468

cvss 5.3 · patched in nimiq-blockchain v1.3.0 · GHSA-xr78-2jhh-9wf9; patched in v1.3.0 via PR #3667 · credit: finder: @1seal

patched

F-NIMIQ-DISCOVERY-EMPTY-ADDRLIST-PANIC-001

nimiq/core-rs-albatross · CVE-2026-40094

cvss 4.3 · patched in nimiq-network-libp2p v1.4.0 · GHSA-c45m-6x25-3cjq; patched in v1.4.0 via PR #3715 · credit: finder: @1seal

patched

F-NIMIQ-DHTGET-HANG-001

nimiq/core-rs-albatross · CVE-2026-44505

cvss 5.3 · patched in network-libp2p v1.4.0 · GHSA-g39c-jcgg-qwvr; patched in v1.4.0 via PR #3716 · credit: finder: @1seal

patched

F-NIMIQ-DISCOVERY-DOUBLE-SUBSTREAM-PANIC-001

nimiq/core-rs-albatross · CVE-2026-34063

cvss 7.5 · patched in network-libp2p v1.3.0 · GHSA-74hp-mhfx-m45h; patched in v1.3.0 via PR #3666 / release v1.3.0 · credit: finder: @1seal

patched

F-NIMIQ-REQRES-STREAMS-STALL-001

nimiq/core-rs-albatross · CVE-2026-34062

cvss 5.3 · patched in network-libp2p v1.3.0 · GHSA-gh7r-qh4p-q4fr; patched in v1.3.0 via PR #3663 · credit: finder: @1seal

patched

F-FREEIPA-389DS-001

389ds/389-ds-base · CVE-2026-9064

cvss 7.5 · CWE-770 · affected · 389-ds-base get_ldapmessage_controls_ext() unbounded LDAP controls count; remote unauthenticated CPU and heap amplification DoS. · credit: Red Hat acknowledgement: Oleh Konko (1seal.org)

affected

F-BUILDKIT-001-001

moby/buildkit · CVE-2026-33747

cvss 8.4 · patched in v0.28.1+

patched

F-OPENCLAW-001

openclaw/openclaw · CVE-2026-28457

cvss 7.1 · patched in openclaw >= 2026.2.14

patched

F-ZOT-AUTHZ-001

project-zot/zot · CVE-2026-31801

cvss 7.7 · unpatched

unpatched

F-ISTIO-JWKS-002

istio/istio · CVE-2026-31837

cvss 8.7 · patched in 1.29.1, 1.28.5, 1.27.8 · credit: reported by 1seal (ISTIO-SECURITY-2026-001)

patched

F-ISTIO-XDSDEBUG-002

istio/istio · CVE-2026-31838

cvss 6.9 · patched in 1.29.1, 1.28.5, 1.27.8 · credit: reported by 1seal (ISTIO-SECURITY-2026-001)

patched

F-ISTIO-JWKS-001

istio/istio · CVE-2026-41413

cvss 5.0 · patched in 1.29.2, 1.28.6 · GHSA-fgw5-hp8f-xfhc · SSRF via RequestAuthentication jwksUri · credit: reporter: @1seal

patched

F-MALCONTENT-010

chainguard-dev/malcontent · CVE-2026-28407

patched in malcontent v1.21.0

patched

F-TEKTON-001-001

tektoncd/pipeline · CVE-2026-33211

cvss 9.6 · patched in v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2

patched

F-WOLFSSL-ALPN-001

wolfSSL/wolfssl · CVE-2026-3547

cvss 7.5 · patched in wolfSSL 5.9.0 · credit: thanks to Oleh Konko (1seal) for the report (wolfSSL v5.9.0-stable release note)

patched

F-WOLFSSL-ECH-001

wolfSSL/wolfssl · CVE-2026-3549

cvss 8.3 · patched in wolfSSL 5.9.0 · credit: thanks to Oleh Konko (1seal) for testing (wolfSSL v5.9.0-stable release note)

patched

F-WOLFSSL-NC-URI-001

wolfSSL/wolfssl · CVE-2026-5263

cvss 7.0 · patched in wolfSSL 5.9.1 · GHSA-9xmr-c663-3rpr · fixed in PR 10048 · credit: finder: Oleh Konko @1seal (wolfSSL CNA / v5.9.1-stable release note)

patched

F-TEKTON-PANIC-001

tektoncd/pipeline · CVE-2026-33022

cvss 6.5 · unpatched · credit: reporter: @1seal

unpatched

F-TEKTON-REGEX-001

tektoncd/pipeline · CVE-2026-25542

cvss 6.5 · unpatched · credit: reporter: @1seal

unpatched

F-NIMIQ-TENDERMINT-001

nimiq/core-rs-albatross · CVE-2026-28402

cvss 7.1 · patched in nimiq-blockchain v1.2.2

patched

F-NIMIQ-INTERLINK-001

nimiq/core-rs-albatross · CVE-2026-34061

cvss 4.9 · patched in nimiq-blockchain v1.3.0 · GHSA-gr83-j5f8-p2r5; patched in v1.3.0 via PR #3668 · credit: finder: @1seal

patched

F-NIMIQ-ROGUEKEY-001

nimiq/core-rs-albatross · CVE-2026-34068

cvss 6.8 · patched in v1.3.0 · GHSA-pf4j-pf3w-95f9; patched in v1.3.0 via PR #3654 · credit: finder: @1seal

patched

F-MELANGE-003

chainguard-dev/melange · CVE-2026-29049

cvss 4.3 · unpatched

unpatched

F-MELANGE-008

chainguard-dev/melange · CVE-2026-29050

cvss 6.1 · patched in melange v0.43.4 · GHSA-98f2-w9h9-7fp9 · external pipeline resolver path traversal · credit: reporter: @1seal

patched

F-MELANGE-004

chainguard-dev/melange · CVE-2026-29051

cvss 4.4 · patched in melange v0.43.4 · GHSA-q2pw-xx38-p64j · --persist-lint-results path traversal · credit: reporter: @1seal

patched

F-VSCODE-MCP-001

microsoft/vscode · CVE-2026-21518

patched in VS Code 1.109.1 · GHSA-6xq8-9qf3-p6qv · metadata correction requested

patched

F-VSCODE-COPILOT-001

microsoft/vscode · CVE-2026-21523

cvss 8.0 · patched in VS Code 1.110.1; VS Code Copilot Chat Extension 0.37.1 · MSRC: GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability. MSRC revision history added acknowledgements on 2026-04-20 as an informational change; official acknowledgement lists Oleh Konko with 1seal. caveat: the public MCP-specific advisory GHSA-6xq8-9qf3-p6qv maps to CVE-2026-21518, so exact local finding-to-CVE mapping for F-VSCODE-MCP-001 vs CVE-2026-21523 depends on the private MSRC thread. · credit: MSRC acknowledgement: Oleh Konko with 1seal

patched

F-ESO-LABELBYPASS-001

external-secrets/external-secrets · CVE-2026-26287

cvss 7.1 · patched in external-secrets v1.3.2 · GHSA-q7hv-xx6h-q2x8 · accepted 2026-01-31 · silentfix via PR #5901 (webhook initialization order) · credit: reporter: @1seal

patched

F-QEMU-001-001

qemu/qemu · CVE-2026-3842

patched in upstream commit 4f28b87fdd24 · public Red Hat CVE record; upstream QEMU commit 4f28b87fdd24df2049626106b7c24d0180952115 from 2026-03-09 carries Fixes: CVE-2026-3842 and Reported-by: Oleh Konko; public backport/cherry-pick 85af4e93 followed on 2026-03-13. · credit: Reported-by: Oleh Konko <https://github.com/1seal>

patched

F-MOBY-001-001

moby/moby · CVE-2026-34040

cvss 8.8 · unpatched · GHSA-x744-4wpc-v9h2 · credit: 1seal / Oleh Konko (@1seal)

unpatched

F-DIST-PROXY-SSRF-001

distribution/distribution · CVE-2026-33540

cvss 7.5 · unpatched · GHSA-3p65-76g6-3w7r

unpatched

F-DIST-REDIS-REVIVAL-001

distribution/distribution · CVE-2026-35172

cvss 7.5 · unpatched · GHSA-f2g3-hh2r-cwgc

unpatched

F-OTELGO-001

open-telemetry/opentelemetry-go · CVE-2026-29181

cvss 7.5 · unpatched · GHSA-mh2q-q3fh-2475

unpatched

F-OTELGO-002

open-telemetry/opentelemetry-go · CVE-2026-39882

cvss 6.5 · unpatched · GHSA-w8rr-5gcm-pp58

unpatched

F-OTELGO-002

open-telemetry/opentelemetry-dotnet · CVE-2026-40182

cvss 5.3 · patched in 1.15.2 · GHSA-q834-8qmm-v933 · surfaced during investigation of GHSA-w8rr-5gcm-pp58 · credit: reporter: @1seal

patched

F-GO-X509-WILDCARD-CASE-001

golang/go · CVE-2026-33810

cvss 8.1 · patched in go1.26.2 · GHSA-fv83-x2xw-2j55 · credit: public credit to @1seal in golang/go#78332

patched

F-HELM-UNTAR-ROOT-COLLAPSE-001

helm/helm · CVE-2026-35206

cvss 4.8 · patched in 3.20.2, 4.1.4 · GHSA-hr2v-4r36-88hr · credit: Oleh Konko (@1seal)

patched

F-SMALLSTEP-AK-EKU-001

smallstep/certificates · CVE-2026-40097

cvss 3.7 · patched in v0.30.0 · GHSA-9qq8-cgcv-qmc9 · credit: Oleh Konko (@1seal)

patched

F-NIMIQ-PROPOSAL-001

nimiq/core-rs-albatross · CVE-2026-32605

cvss 7.5 · patched in v1.3.0 · GHSA-g99c-h7j7-rfhv · credit: finder: @1seal

patched

F-NIMIQ-MACROCHAIN-001

nimiq/core-rs-albatross · CVE-2026-34069

cvss 5.3 · patched in v1.3.0 · GHSA-48m6-486p-9j8p; patched in v1.3.0 via PR #3660 · credit: finder: @1seal

patched

F-KYVERNO-APICALL-001

kyverno/kyverno · CVE-2026-40868

cvss 8.1 · patched in 1.16.4 · GHSA-q93q-v844-jrqp · credit: reporter: @1seal

patched

F-VAULT-AUTHZ-BEARER-TOKEN-LEAK-001

hashicorp/vault · CVE-2026-4525

cvss 7.5 · patched in 2.0.0, 1.21.5, 1.20.10, 1.19.16 · Vault token leaked to auth plugin backends via Authorization: Bearer passthrough header · credit: identified and reported by Oleh Konko of 1seal (HCSEC-2026-07)

patched

F-VAULT-ACME-SSRF-001

hashicorp/vault · CVE-2026-5052

cvss 5.3 · patched in Vault CE 2.0.0; Vault Enterprise 2.0.0, 1.21.5, 1.20.10, 1.19.16 · GHSA-8r5m-3f66-qpr3 / HCSEC-2026-06; Vault ACME validation did not reject local targets for http-01 and tls-alpn-01 challenges. v2.0.0 adds isValidChallengeIP and dialACMEValidationTarget, plus challenge_permitted_ip_ranges and challenge_excluded_ip_ranges configuration. · credit: independently identified and reported by Oleh Konko of 1seal (HCSEC-2026-06)

patched

F-KEYCLOAK-SAML-001

keycloak/keycloak · CVE-2026-2092

cvss 7.7 · CWE-1287 · patched in 26.2.14, 26.4.10, 26.5.5, 26.6.0 · GHSA-794g-x443-36f7; improper validation of encrypted SAML assertions can allow unauthorized access via crafted SAML response. · credit: reporter: @1seal

patched

F-AWS-ENCRYPTION-SDK-PYTHON-001

aws/aws-encryption-sdk-python · CVE-2026-6550

cvss 6.8 · patched in 3.3.1, 4.0.5 · GHSA-v638-38fc-rhfv · AWS-2026-017 · credit: acknowledgement: 1seal.org

patched

F-AWS-EVENT-STREAM-001

aws/aws-sdk-cpp · CVE-2026-5190

cvss 7.7 · patched in aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764 · GHSA-xvjw-fjq5-68hf / AWS-2026-011; AWS Common Runtime event-stream decoder memory corruption affecting aws-sdk-cpp <1.11.764 and other SDKs that expose event-stream functionality. · credit: acknowledgement: Oleh Konko from 1seal / 1seal.org

patched

F-AWS-TOUGH-001

awslabs/tough · CVE-2026-6966

cvss 5.3 · patched in tough 0.22.0, tuftool 0.15.0 · GHSA-8m7c-8m39-rv4x · signature threshold bypass in delegated roles · credit: reporter: @1seal; acknowledgement: Oleh Konko of 1seal

patched

F-AWS-TOUGH-002 / F-AWS-TOUGH-003 / F-AWS-TOUGH-004 / F-AWS-TOUGH-005

awslabs/tough · CVE-2026-6967

cvss 5.9 · patched in tough 0.22.0, tuftool 0.15.0 · GHSA-4v58-8p28-2rq3 · missing expiration, hash, and length enforcement in delegated metadata validation; includes the local metadata cache poisoning variant tracked as F-AWS-TOUGH-005 · credit: reporter: @1seal; acknowledgement: Oleh Konko of 1seal

patched

F-AWS-TOUGH-007 / F-AWS-TOUGH-008 / F-AWS-TOUGH-009

awslabs/tough · CVE-2026-6968

cvss 5.9 · patched in tough 0.22.0, tuftool 0.15.0 · GHSA-v57p-gppj-p9vg · multiple path traversal variants in tough write paths · credit: reporter: @1seal; acknowledgement: Oleh Konko of 1seal

patched

F-TORVALDS-LINUX-RXRPC-001

torvalds/linux · CVE-2026-31641

patched in Linux kernel upstream · GHSA-p4pm-x7ch-5mvc · rxrpc: Fix RxGK token loading to check bounds · Linux CNA/GHSA credit fields are empty; credit is carried by upstream patch artifacts (Author/Signed-off-by)

patched

F-TORVALDS-LINUX-TIPC-001

torvalds/linux · CVE-2026-31662

patched in Linux kernel upstream · GHSA-895h-4xx6-r95p · Red Hat also tracks this as a kernel CVE · Linux CNA/GHSA credit fields are empty; credit is carried by upstream patch artifacts (Author/Signed-off-by)

patched

F-ZEPHYR-BLE-001

zephyrproject-rtos/zephyr · CVE-2026-5068

cvss 7.3 · CWE-787 · patched in main PR #104913, v4.3 PR #108335; v3.7 backport pending · GHSA-qrcq-hxwj-mqxm · bt l2cap le coc remote out-of-bounds write via segment counter stored in net_buf user_data. advisory credits @1seal as reporter; main PR #104913 merged 2026-03-28 and v4.3 backport PR #108335 merged 2026-06-03; v3.7 backport #108336 remained pending at verification time and the advisory listed patched versions as none. · credit: reporter: @1seal

patched

F-ORAS-AUTH-001

oras-project/oras-go · CVE-2026-48978

CWE-319, CWE-918 · patched in oras-go v2.7.0 · GHSA-xf85-363p-868w · Bearer realm URL not validated, enabling SSRF to internal networks and TLS downgrade. maps to local F-ORAS-AUTH-001; the public advisory credits @1seal as Analyst rather than reporter. · credit: @1seal credited as Analyst; advisory says reported by bugbunny.ai

patched

F-ORAS-LOCATION-UPLOAD-001

oras-project/oras-go · CVE-2026-50151

cvss 7.5 · CWE-918 · patched in main PR #1192; no patched version listed · GHSA-jxpm-75mh-9fp7 · credential forwarding via unvalidated Location header in oras-go blob upload. advisory credits @1seal as reporter; maintainer notes say the fix was cherry-picked to main in PR #1192. · credit: reporter: @1seal

fixed on main

F-ELEMENTX-IOS-001

element-hq/element-x-ios · CVE-2026-55644

cvss 7.5 · patched in Element X iOS 26.05.0 · GHSA-54w7-rw44-49m7 · io.element.call deeplink allowed attacker-controlled HTTPS origin inside the call WKWebView with microphone/camera permissions. PR #5515 removed in-app SPA call link handling on 2026-04-29; Element X iOS 26.05.0 released on 2026-05-06 with the security fix. versions 26.05.0+ are fixed for this deeplink issue.

patched

F-ENVOY-001-002

envoyproxy/envoy · CVE-2026-48497

cvss 5.9 · CWE-480 · patched in Envoy 1.35.12, 1.36.8, 1.37.4, 1.38.2 · GHSA-j6g2-wf95-q66q · abnormal process termination in the Envoy DNS UDP filter for a 255-octet DNS query name. maps to local F-ENVOY-001-002; affected versions are <1.39 and patched versions are 1.35.12, 1.36.8, 1.37.4, and 1.38.2. · credit: finder: @1seal

patched

GHSAs published

published security advisories without a known cve id.

F-AUTHZED-SPICEDB-001

authzed/spicedb · ghsa published · GHSA-vhvq-fv9f-wh4q

patched in spicedb v1.49.1

patched

F-RUSTLS-WEBPKI-001

rustls/webpki · ghsa published · GHSA-pwjx-qhcg-rvj4

cvss 4.4 · patched in 0.104.0-alpha.5, 0.103.10

patched

F-RUSTLS-WEBPKI-NAMECONSTRAINTS-URI-001

rustls/webpki · ghsa published · GHSA-965h-392x-2mh5

cvss 2.2 · patched in >= 0.103.12, >= 0.104.0-alpha.6 · Name constraints for URI names were incorrectly accepted · credit: reporter: @1seal

patched

F-RUSTLS-WEBPKI-NAMECONSTRAINTS-WILDCARD-001

rustls/webpki · ghsa published · GHSA-xgp8-3hg3-c2mh

cvss 2.2 · patched in >= 0.103.12, >= 0.104.0-alpha.6 · Name constraints were accepted for certificates asserting a wildcard name · credit: reporter: @1seal

patched

F-NIMIQ-REQRES-INBOUNDLEAK-001

nimiq/core-rs-albatross · ghsa published · GHSA-w5f8-87h2-m573

cvss 0.0 · patched in nimiq-network-libp2p v1.3.0 · GHSA-w5f8-87h2-m573; patched in v1.3.0 via PR #3665 · credit: finder: @1seal

patched

F-NIMIQ-BLOCKINCLUSIONPROOF-INTERLINK-HOPS-001

nimiq/core-rs-albatross · ghsa published · GHSA-799f-29jm-gr6c

cvss 5.9 · patched in nimiq-primitives v1.4.0 · BlockInclusionProof::is_block_proven accepted an empty interlink-hop proof path without cryptographic verification. · credit: finder: @1seal

patched

F-MALCONTENT-006

chainguard-dev/malcontent · ghsa published · GHSA-54p8-x2m9-c593

cvss 5.3 · patched in malcontent v1.21.0 · primary mapping; advisory text matches the late-defer/resource-leak fix train

patched

F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003

theopolis/uefi-firmware-parser · ghsa published · GHSA-hm2w-vr2p-hq7w

cvss 9.8 · patched in 1.13 · PR #145 · fix commit bf3dfaa8a05675bae6ea0cbfa082ddcebfcde23e · credit: reporter: @1seal

patched

F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002

theopolis/uefi-firmware-parser · ghsa published · GHSA-2689-5p89-6j3j

cvss 9.8 · patched in 1.13 · PR #145 · fix commit bf3dfaa8a05675bae6ea0cbfa082ddcebfcde23e · credit: reporter: @1seal

patched

F-INTOTO-CROSS-IMPL-001

in-toto/in-toto-golang · ghsa published · GHSA-pmwq-pjrm-6p5r

cvss 4.1 · patched in in-toto-golang v0.11.0 · public advisory GHSA-pmwq-pjrm-6p5r covers the cross-implementation negation mismatch; affected <0.11.0, patched in 0.11.0 via in-toto-golang PR #462 / commit 36d782f. the earlier GHSA-28fv-f52p-hvwh reference is not publicly accessible. · credit: finder: @1seal

patched

F-AWS-SDK-GO-V2-ES-001

aws/aws-sdk-go-v2 · ghsa published · GHSA-xmrv-pmrh-hhx2

patched · GHSA published on 2026-04-07 for the unknown eventstream header value type panic fixed upstream in #3355.

patched

researcher-authored security PRs

public security PRs opened and authored by the researcher: vulnerability fixes and security hardening.

caddyserver/website #529

F-CADDY-FILESERVER-HIDE-CASE-001 · security hardening

security hardening — docs: clarify file_server hide case-sensitivity · why: documents that hide comparisons are case-sensitive; on case-insensitive filesystems, differently-cased request paths may still resolve to the same on-disk path, so hide should not be treated as a security boundary for sensitive paths. · submitted 2026-03-04

merged

google/certificate-transparency-go #1754

F-CTGO-S2A-001 · security hardening

security hardening — Cap request body size in submission proxy · why: caps request body size in the submission proxy to reduce resource exhaustion / DoS risk. · submitted 2026-01-26

merged

goharbor/website #706

F-HARBOR-REALM-001 · security hardening

security hardening — docs: clarify proxy cache trust boundary for upstream token-service discovery · why: clarifies the proxy cache trust boundary to reduce the risk of misconfiguration around token-service discovery. · submitted 2026-01-31

merged

caddyserver/caddy #7469

F-CADDY-ACME-POLICY-001 · security hardening

security hardening — acmeserver: warn when policy rules unset · why: mitigates policy misconfiguration risk by warning when policy rules are unset. · submitted 2026-02-11

merged

caddyserver/certmagic #378

F-CADDY-CERTMAGIC-OCSP-001 · security fix (no cve assigned)

security fix (no cve assigned) — More validation of delegated OCSP responders · why: rejects forged Good OCSP responses signed by same-issuer responder certificates that lack delegated OCSPSigning authorization under RFC 6960 section 4.2.2.2. public PR #378 merged on 2026-04-24. · submitted 2026-04-20

merged

caddyserver/certmagic #383

F-CADDY-CERTMAGIC-OCSP-001 · testing

testing — ocsp: add delegated responder authorization regression test · why: adds regression coverage for the delegated OCSP responder authorization path fixed for F-CADDY-CERTMAGIC-OCSP-001, including rejection of same-issuer non-OCSPSigning responders. · submitted 2026-05-12

merged

google/certificate-transparency-go #1755

F-CTGO-TIMEOUT-001 · security hardening

security hardening — set explicit http server timeouts · why: prevents hangs via slow-client / slowloris-style connections. · patched in v1.3.3 · submitted 2026-01-31

merged

sigstore/cosign #4652

F-COSIGN-005 · security fix (no cve assigned)

security fix (no cve assigned) — remote crash in rekor response handling via unsafe e.body.(string) type assertion · why: prevents remote crash via malformed rekor responses. · submitted 2026-01-20

merged

sigstore/cosign #4651

F-COSIGN-006 · security fix (no cve assigned)

security fix (no cve assigned) — remote crash in policy evaluation via unsafe attestation payload type assertion · why: prevents remote crash via malformed attestation payloads. · submitted 2026-01-20

merged

sigstore/sigstore-go #567

F-SIG-GO-000-001 · security fix (no cve assigned)

security fix (no cve assigned) — bundle parsing dos via unbounded tlogentries · why: mitigates resource exhaustion via unbounded tlogentries. · submitted 2026-01-17

merged

sigstore/sigstore-go #566

F-SIG-GO-004 · security fix (no cve assigned)

security fix (no cve assigned) — nil pointer dereference in publickey() via malformed pem · why: prevents crash on malformed pem input. · submitted 2026-01-17

merged

sigstore/cosign #4649

F-COSIGN-004 · security fix (no cve assigned)

security fix (no cve assigned) — remote crash in online tlog verification via nil pointer dereference in verifytlogentryoffline · why: prevents remote crash in online tlog verification. · submitted 2026-01-17

merged

sigstore/timestamp-authority #1277

F-TSA-001-002 · security fix (no cve assigned)

security fix (no cve assigned) — timestamp response verification accepts revoked tsa certificate (no crl/ocsp checking) · why: prevents accepting revoked tsa certificates (crl/ocsp). · submitted 2026-01-10

merged

sigstore/timestamp-authority #1276

F-SIG-040-001 · security hardening

security hardening — ntp drift does not gate timestamp issuance · why: mitigates time manipulation risk via excessive ntp drift. · submitted 2026-01-10

merged

sigstore/sigstore-go #562

F-SIG-004-002 · security fix (no cve assigned)

security fix (no cve assigned) — tlog entry validation fail-open (rekor v2 protojson parsing) · why: prevents fail-open behavior on malformed tlog entries. · submitted 2026-01-10

merged

sigstore/sigstore-go #558

F-SIG-016-001 · security fix (no cve assigned)

security fix (no cve assigned) — certificate identity regex not auto-anchored enables identity policy bypass · why: prevents identity policy bypass via unanchored regex matching. · submitted 2026-01-10

merged

sigstore/policy-controller #1923

F-SIG-034-001 · security fix (no cve assigned)

security fix (no cve assigned) — tlog verification disabled by empty ctlog URL · why: prevents disabling tlog verification via empty ctlog URL. · submitted 2026-01-10

merged

sigstore/cosign #4642

F-SIG-014-001 · security fix (no cve assigned)

security fix (no cve assigned) — rfc3161 timestamp verification accepts revoked tsa certificate (no crl/ocsp checking) · why: prevents accepting revoked tsa certificates (crl/ocsp). · submitted 2026-01-10

merged

prometheus/prometheus #17969

F-PROMETHEUS-RELABEL-001 · security hardening

security hardening — security hardening: relabel perf/dos guard · why: reduces resource-exhaustion surface in relabel processing.

merged

theupdateframework/python-tuf #2903

F-TUF-PYTUF-002 · security hardening

security hardening — feat(ngclient): require explicit bootstrap argument · why: prevents accidental insecure bootstrap behavior by requiring explicit bootstrap intent. · submitted 2026-01-25

merged

openssl/openssl #30319

F-OPENSSL-NC-URI-AUTHORITY-001 · security fix (no cve assigned)

security fix (no cve assigned) — fix OSSL_parse_url userinfo scan to respect authority boundary · why: prevents URI authority confusion when certificate verification reuses parsed hosts for nameConstraints decisions. · submitted 2026-03-09

applied upstream

openssl/openssl #30323

F-OPENSSL-OCSP-001 · security fix (no cve assigned)

security fix (no cve assigned) — x509: reject unauthorized stapled OCSP response signers · why: prevents accepting stapled OCSP responses signed by unauthorized responder certificates. · submitted 2026-03-09

applied upstream

openssl/openssl #30329

F-OPENSSL-NC-SMTPUTF8MAILBOX-001 · security fix (no cve assigned)

security fix (no cve assigned) — Forbid GEN_OTHERNAME SMTP UTF8 email name constraints. · why: rejects SMTPUTF8 mailbox name constraints encoded as GEN_OTHERNAME to avoid ambiguous email name-constraint handling. public upstream commits 3eab35f and 945cc69 landed on master after PR #30329. · submitted 2026-03-09

applied upstream

getsops/sops #2155

F-MOZILLA-SOPS-002 · security fix (no cve assigned)

security fix (no cve assigned) — sops exec-file: improve error handling, reject non-local paths in `--filename` · why: rejects non-local exec-file output paths so decrypted plaintext cannot escape the temp dir and persist outside the cleanup boundary. public PR #2155 merged on 2026-04-21; GHSA-x4cm-pcq4-39j4 maps to this finding and sops v3.13.0 includes the fix, so v3.13.0+ including v3.13.1 is fixed. · submitted 2026-02-04

merged

hashicorp/vault #31828

F-VAULT-ACME-SSRF-001 · opened PR

opened PR — pki/acme: reject unsafe validation targets during challenge verification · why: hardens ACME validation so HTTP-01 and TLS-ALPN-01 challenge dials reject loopback, link-local, unspecified, multicast, and similar unsafe targets before outbound connections. public PR #31828 was opened from the reporter branch, approved by the Vault maintainer, and copied into vault-enterprise #12959, which merged on 2026-03-12. · submitted 2026-01-31

enterprise merged

wolfSSL/wolfssl #10239

F-WOLFSSL-CRL-001 · security fix (no cve assigned)

security fix (no cve assigned) — reject crls with unrecognized critical extensions · why: rejects CRLs with unrecognized critical extensions per RFC 5280 section 5.2 instead of silently accepting a revocation scope-bypass condition. public PR #10239 merged on 2026-04-21. · submitted 2026-04-15

merged

aws/aws-nitro-enclaves-sdk-c #167

F-NITRO-IVLEN-001 · security fix (no cve assigned)

security fix (no cve assigned) — cms: Reject AES-256-CBC IV with invalid length · why: rejects malformed CMS AES-256-CBC IV lengths before decryption so short IV buffers cannot reach EVP_DecryptInit_ex unchecked. · submitted 2026-03-30

merged

cilium/cilium #44772

F-CILIUM-001-002 · security hardening

security hardening — Add a warning when TLS isn't enabled for Hubble Relay · why: warns that Hubble Relay without TLS exposes sensitive observability data to any reachable in-cluster client outside the intended trust boundary. public PR #44772 merged on 2026-04-22 and is present in main / v1.20.0-pre.* only; not fixed for stable users in v1.19.5, v1.18.11, or v1.17.17. · credit: Reported by @1seal · submitted 2026-03-13

merged to main/pre-release only

credited upstream fixes

public upstream fixes where the maintainer-side record explicitly credits the report.

open-policy-agent/gatekeeper #4351

credited upstream fix · F-GK-EXT-001

fix: enforce timeout on external data provider requests · credit: thanks @1seal for raising the issue

merged

openssl/openssl #30001

credited upstream fix · F-OPENSSL-SRTPKDF-002

srtpkdf input bounds checking · credit: reported by https://github.com/1seal (merged from #30001)

applied upstream

sigstore/sigstore-go #590

credited upstream fix · F-SIG-GO-THRESHOLD-001

hardening: minimum threshold for withintegratedtimestamps · credit: thanks @1seal for reporting this improvement

merged

letsencrypt/boulder #8641

credited upstream fix · F-BOULDER-009

Don't modify http.DefaultTransport · credit: thanks to Oleh Konko (@1seal) for reporting this issue (comment by @aarongable).

merged

theopolis/uefi-firmware-parser #145

credited upstream fix · F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003

Apply hardening fixes from upstream Tiano implementation · credit: PR body: "Thank you @1seal for mentioning this!" · note: GHSA-hm2w-vr2p-hq7w published for ReadCLen heap out-of-bounds write.

merged

sigstore/rekor #2755

credited upstream fix · F-REKOR-VERIFY-002

Type assert the entry bundle when verifying inclusion proof · credit: PR body: "Thanks to @1seal for reporting this."

merged

spiffe/spire

credited upstream fix · F-SPIRE-HTTPCHALLENGE-001

http_challenge SSRF fixed in v1.14.2 and v1.13.4 · credit: Thank you, Oleh Konko (@1seal) for reporting this issue. also credited in v1.13.4 and CHANGELOG.md.

released

containerd/containerd #13189

credited upstream fix · F-GO-X509-WILDCARD-CASE-001

[release/2.1] update to Go 1.25.9, 1.26.2 · credit: PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2. · note: merged into release/2.1 on 2026-04-08; merge commit e4244c720f20.

merged

containerd/containerd #13190

credited upstream fix · F-GO-X509-WILDCARD-CASE-001

[release/2.2] update to Go 1.25.9, 1.26.2 · credit: PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2. · note: merged into release/2.2 on 2026-04-09; merge commit 17847ac84599.

merged

helm/helm

credited upstream fix · F-HELM-UNTAR-ROOT-COLLAPSE-001

Helm Chart extraction output directory collapse via Chart.yaml name dot-segment · credit: v4.1.4 release note thanks @1seal among the reporters. · note: GHSA-hr2v-4r36-88hr / CVE-2026-35206 published; fixed in Helm v4.1.4. changelog lists commit 4e7994d44671 for the chart dot-name path bug.

released

testcontainers/testcontainers-go #3647

credited upstream fix · F-GO-X509-WILDCARD-CASE-001

chore: update to Go 1.25.9, 1.26.9 · credit: PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2. · note: merged into main on 2026-04-09; merge commit 580abf68d440. PR title says 1.26.9, body references Go 1.26.2.

merged

google/go-containerregistry #2255

credited upstream fix · F-GO-X509-WILDCARD-CASE-001

update to Go 1.26.2 · credit: PR body includes @1seal in the upstream Go security credit text for Go 1.26.2. · note: merged into main on 2026-04-11; merge commit f8be1d442e6f.

merged

rustls/webpki #469

credited upstream fix · F-RUSTLS-WEBPKI-001

Rewrite constraint matching to avoid permissive catch-all branch · credit: PR description says it addresses an issue privately reported by @1seal. · note: merged into main on 2026-04-13; merge commit 9e1f4822932b. GHSA-pwjx-qhcg-rvj4 already published for the same finding.

merged

wolfSSL/wolfssl #9991

credited upstream fix · F-WOLFSSL-NC-WILDCARD-001

Disallow wildcard partial domains when using MatchDomainName. · credit: PR body says: Thanks to Oleh Konko for the report. · note: merged into master on 2026-03-19; merge commit 679366a5a49f. v5.9.1-stable release note also credits @1seal for the report.

merged

authored hardening/testing contributions

researcher-authored upstream hardening, testing, and fuzzing contributions outside the main security PR bucket.

openssl/fuzz-corpora #32

testing/fuzzing contribution · F-OPENSSL-ASN1-001

asn1parse: add small ber/der edge-case seeds · note: closed without github-merge; maintainer applied with tweaked commit message.

applied upstream

google/go-attestation #496

testing/fuzzing contribution · F-GO-ATTESTATION-004

test: add ECDSA activation regression coverage · note: merged on 2026-05-19 as commit 33eb399; adds activation_test.go coverage that CheckAKParameters rejects ECC AK public-key parse failures and invalid ECDSA signatures after the verifyECDSASignature fail-open fix.

merged

reported fixes landed publicly

reported via security contacts or public trackers; fixes landed upstream.

TelegramMessenger/Telegram-iOS

reported via Telegram bug bounty · F-TELEGRAM-JSBRIDGE-001

JSON injection in Mini App custom method response enables arbitrary JavaScript execution in WebAppWebView · accepted as LOW, bounty declined. public fix commit 687cefb2914539e2a42d3a10e91fe4ce1c7fbf7f on 2026-02-25 serializes the custom method result through JSONSerialization before sendEvent; the fix is present in release-12.5.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram bug bounty · F-TELEGRAM-E2E-001

Non-Constant-Time Message Key Comparison in Secret Chat Decryption Violates Security Guidelines · accepted as LOW, bounty declined. public fix commit 9d33962c013e68dcecd8c26bb23ca232bc52c2a2 on 2026-02-13 replaces direct message-key comparison with constTimeIsEqual; the fix is present in release-12.5.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram bug bounty · F-TELEGRAM-IOS-BOTPAY-001

WKWebView payment bridge accepts payment_form_submit from untrusted subframes without frame validation · accepted as LOW, bounty declined. public fix commit a8a308d7a6843cb41e4e0e76908e552a4aeb1ee9 on 2026-02-13 switches the payment bridge script to forMainFrameOnly: true; the fix is present in release-12.5.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram bug bounty · F-TELEGRAM-WEBAPP-001

Telegram iOS Web App bridge exposed to third-party iframes · public fix commit c5a0ad267cbd2a61a0d4548490f6af5521fa55df in release-12.4. see 1SEAL-2026-008.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram bug bounty · F-TELEGRAM-TL-001

heap buffer over-read in TL deserialization from operator precedence bug · public fix commit 8e9cd79855683efb9a3cbf14a1ecd637cfbf7b54 in release-12.4. see 1SEAL-2026-007.

fixed publicly

torvalds/linux

reported via bluetooth maintainers · F-TORVALDS-LINUX-BT-HCI-001

Bluetooth: hci_event: move wake reason storage into validated event handlers · accepted into bluetooth-next: 3e7e7f4bdbe5. short HCI event frames could reach bacpy() before per-event minimum-length validation.

merged

torvalds/linux

reported via netdev maintainers · F-TORVALDS-LINUX-TIPC-001

tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG · accepted upstream in netdev/net: 48a5fe38772b. duplicate or stale GRP_ACK_MSG packets could underflow bc_ackers, wrap to 65535, and leave later group broadcasts congestion-blocked until the group was recreated. stable backports are queued for 5.10-stable, 5.15-stable, 6.1-stable, and 6.6-stable.

merged

torvalds/linux

reported via bluetooth maintainers · F-TORVALDS-LINUX-BT-SMP-001

Bluetooth: SMP: force responder MITM requirements before building the pairing response · public mainline commits d05111bfe37b and 20756fec2f01 in torvalds/linux. the fix bundle aligns responder pairing policy and legacy STK authentication with actual MITM state. author is publicly listed as Oleh Konko <security@1seal.org> with Signed-off-by.

merged

mozilla/gecko-dev

reported via Bugzilla · F-MOZILLA-FIREFOX-001

WebGPU presentation sizing hardening after integer-overflow report · bug 2018451. public fix 2f8a8fdd43a4 / autoland 67153f39ea54. public case is a hardening fix after report, not a confirmed exploitable security bug.

fixed publicly

mozilla/gecko-dev

reported via Bugzilla · F-FIREFOX-IPC-PUSH-012

Push IPC observer path removed after bug 2022681 report · bug 2022681 remains UNCONFIRMED, but the related fix bug 1862090 was resolved FIXED on 2026-03-13 with status-firefox150 = fixed. the patch removed RecvNotifyPushObservers* and the affected push IPC path. Firefox 150 shipped on 2026-04-21, so this surface is already gone in release.

fixed publicly

open-telemetry/opentelemetry-collector #15253

reported via GitHub Security Advisory GHSA-xp52-4g49-prf2 · F-OTELCOLLECTOR-001

[confighttp] Enforce max_request_body_size before snappy decompression · accepted private advisory opened 2026-02-23 with reporter credit to @1seal; public issue #15252 and PR #15253 fixed the confighttp snappy decode allocation-before-cap bug. release v1.58.0/v0.152.0, published 2026-05-11, includes the bugfix: Enforce max_request_body_size on Content-Encoding: snappy requests before the decoded buffer is allocated. collector-releases v0.152.0 binaries followed on 2026-05-12. fixed from v0.152.0; v0.151.x and below in the affected range should not be treated as fixed.

fixed publicly in v0.152.0

traefik/traefik #12642

reported via security contact · F-TRAEFIK-002

Validate healthcheck path configuration · merged into v2.11 on 2026-02-10.

merged

traefik/traefik #12653

reported via security contact · F-TRAEFIK-002

Reject absolute URL in healthcheck path configuration · merged into v3.6 on 2026-02-11.

merged

juanfont/headscale

reported via security contact · F-HEADSCALE-001-001

bound request-body reads in the machine map endpoint · the public fix is available in Headscale v0.29.0 and v0.29.1. no public GHSA was observed, so this is tracked as a landed fix rather than a published advisory.

fixed publicly

istio/istio #59054

reported via security contact (email) · F-ISTIO-001

XDS debug endpoints to require authentication · severity: HIGH. emailed 2026-02-02; PR #59054 merged on 2026-02-17 as the XDS debug endpoints authentication fix. fixed releases: Istio 1.27.8, 1.28.5, and 1.29.1. release/advisory notes credit: Reported by 1seal, so the earlier not-credited status is no longer current.

fixed publicly with release-note credit

istio/istio #59970

reported via security contact (email) · F-ISTIO-XDS-DEBUG-001

fix cross-namespace access in statusgen xds debug endpoints · follow-up to CVE-2026-31838 / GHSA-974c-2wxh-g4ww; PR #59970 merged on 2026-04-23 and backports #59973, #59974, and #59975 for releases 1.28, 1.29, and 1.30 also merged. fixed in Istio 1.28.7, 1.29.3, and 1.30.0. release notes credit 1seal for the StatusGen XDS debug endpoint same-namespace authorization fix.

fixed publicly with release-note credit

aws/s2n-tls #5804

reported via security contact (email) · F-AWS-S2N-TLS-IP-CN-001

fix: reject certs with literal-IP CN and no SAN · separate public s2n-tls fix for the literal-IP CN and no SAN case. this is not the same public fix chain as F-AWS-LC-NAMECONSTRAINTS-001.

merged

aws/aws-lc

reported via security contact (email) · F-AWS-LC-NAMECONSTRAINTS-001

Fix CN fallback handling in name constraints checking · public fix in aws/aws-lc on 2026-03-19 via main commit 2aa522465f69 (#3107) and fips branch commit 35bfa4362e45 (#3108). AWS linked GHSA-3jrg-j22w-mpmc and GHSA-394x-vwmw-crm3 and said CNA scope was not met; the same PRs also close the unicode CN vector tracked as F-AWS-LC-NAMECONSTRAINTS-002.

fixed publicly

qemu/qemu

reported via private security contact · F-QEMU-001-001

hyperv/syndbg: check length returned by cpu_physical_memory_map() · public upstream commit 4f28b87fdd24 on 2026-03-09 adds the returned-length check before writing mapped guest memory, includes Fixes: CVE-2026-3842 and Reported-by: Oleh Konko, with public backport/cherry-pick 85af4e93 on 2026-03-13.

merged

aws/rolesanywhere-credential-helper

reported via security contact · F-AWS-ROLESANYWHERE-GHA-001

pin github actions versions · fixed in the release/signing path on 2026-03-10. public PR merge commit b4207adb8856 via #172, with payload commit 2e5072bf6e88.

fixed publicly

aws/aws-xray-daemon

reported via security contact · F-AWS-XRAY-DAEMON-GHA-002

Fix SHA pinning: use correct SHAs matching original action versions · initial fix landed on 2026-03-12 via 135c99db10b5 (#268), then corrected/finalized on 2026-03-17 via 4abe89b868ba (#269).

fixed publicly

aws/aws-xray-daemon

reported via security contact · F-AWS-XRAY-DAEMON-GHA-001

Pin GitHub Action references to commit SHAs · same public fix chain as F-AWS-XRAY-DAEMON-GHA-002 via 135c99db10b5 and 4abe89b868ba, plus broader hardening on 2026-03-18 via 946763a48ab5 (#270).

fixed publicly

aws/eks-pod-identity-agent

reported via security contact · F-EKSPIA-GHA-001

chore: Updating action dependencies to pin to commit sha · fixed in the release workflow on 2026-02-05 via cdb0dd49a89f (#117).

fixed publicly

aws/eks-pod-identity-agent

reported via security contact · F-EKSPIA-GHA-002

chore: Pinning aws-actions/configure-aws-credentials to commit sha · follow-up fix for the remaining configure-aws-credentials reference on 2026-02-20 via dcae60b05e53 (#133).

fixed publicly

aws/amazon-cloudwatch-agent

reported via security contact · F-AWS-CW-AGENT-GHA-001

Pin GitHub Actions to commit SHAs · fixed by #2071, merged 2026-04-01, merge commit e360ba430b55.

fixed publicly

aws/karpenter-provider-aws

reported via security contact · F-KARPENTER-TOOLCHAIN-001

ci: remove latest from toolchain · fixed by #9038, merged 2026-03-27, merge commit efb5ea52a479.

fixed publicly

awslabs/soci-snapshotter

reported via security contact · F-SOCI-OOB-001

Fast-fail on incorrect MaxSpanID · fixed by #1916, merged 2026-04-01, merge commit 0a1984bb2ffb. AWS said it was still determining whether a GHSA would be published.

fixed publicly

smithy-lang/smithy-rs #4584

reported via security contact · F-AWSRUST-CACHE-001

Update standard FS impl to write files with `0o600` permissions · public fix PR #4584 merged on 2026-03-27. updates unix cache-file writes to owner-only `0o600` permissions; AWS advised no separate advisory will be published.

fixed publicly

cedar-policy/cedar

reported via security contact · F-CEDAR-PST-ERRORCONSTRAINT-001

PST fail-closed + protobuf compatibility fix · public fixes #2246 and #2247 merged on 2026-03-23. AWS stated no customer action was required because the affected paths needed two experimental flags enabled together and were not used in AWS authorization paths.

fixed publicly

meta-llama/PurpleLlama

reported via security contact · F-PURPLELLAMA-003

Fix RCE for canary exploit · public fix commit 48fa920b7ace on 2026-03-11 changes CybersecurityBenchmarks/datasets/canary_exploit/verify_response.py from eval() to ast.literal_eval(). maintainer status confirmation and public credit are still pending.

fixed publicly

denoland/deno #33203

reported via security advisory · F-DENO-001-001

fix(permissions): check deny rules against resolved IPs to prevent numeric hostname bypass · accepted on 2026-03-05. public fix PR #33203 merged on 2026-04-09 and shipped in Deno v2.7.12 on 2026-04-09; the release notes include fix(permissions): check deny rules against resolved IPs to prevent numeric hostname bypass. Deno later closed the Node TCP compatibility path through PR #33880, merged on 2026-05-07, which adds a post-resolution deny check in TCPWrap connect and shipped in Deno v2.8.0. internal advisory metadata credits @1seal as reporter, but public credit is not yet confirmed. GHSA id provided in the disclosure thread: GHSA-j65g-6x8f-87c5; the public advisory URL is not currently reachable.

fixed publicly in v2.7.12; Node compat follow-up in v2.8.0

signalapp/Signal-Desktop

reported via security contact · F-SIGNAL-DESKTOP-EXPIRE-001

Ignore expireTimerVersion=0 messages · the public fix chain landed in two steps. partial closure began on 2026-03-10 via c4ee32e9ee32, which switched expiration-timer serialization to nullish semantics and stopped dropping zero values. full fix landed on 2026-03-20 via c863dfa66bdf, which added explicit reject logic for version === 0. current mainline v8.10.0-alpha.1 (272465e1b21f, 2026-04-15) contains both changes.

fixed publicly

LedgerHQ/app-ethereum

reported via security contact · F-LEDGER-ETH-GCS-CLEANUP-DOUBLEFREE-001

Fix 'use-after-free' or 'double-free' issues · public fix commit 601c828 landed on 2026-04-01. the first public release confirmed to contain the fix is app-ethereum 1.22.0, released on 2026-04-15.

fixed publicly

LedgerHQ/app-ethereum

reported via security contact · F-LEDGER-ETH-EIP712-CALLDATA-001

Fixed dead condition in EIP-712 calldata filtering code · public fix commit d61639c landed on 2026-03-24. the fix shipped in app-ethereum 1.22.0, released on 2026-04-15.

fixed publicly

telegramdesktop/tdesktop

reported via Telegram security contact · F-TELEGRAM-DESKTOP-FILENAME-TRAVERSAL-001

Fixed path traversal in bulk file download via filename sanitization. · public commit 82f9aa1a2a09 on 2026-03-31 sanitizes document filenames through FileNameFromUserString(...) in the affected bulk-download path.

fixed publicly

DrKLO/Telegram

reported via Telegram security contact · F-TGAND-SECRETCHAT-VECTOR-001

update to 12.6.2 (6655) · public android commit fb98f157afb3 on 2026-04-05 (12.6.2) adds validateSize(...) checks in the affected Vector.java path and appears to close the reported secret-chat vector-size issue.

fixed publicly

DrKLO/Telegram

reported via Telegram security contact · F-TGAND-GIFVIDEO-OOB-001 / F-TGAND-GIFVIDEO-001

update to 12.7.0 (6740) · public Android 12.7.0 commit 63f86ef on 2026-05-21 updates the native gifvideo.cpp history. the fix is mapped with high confidence to the GIF/video OOB class because the path is hardened around SwsContextHolder, bitmapStride handling, and sws recreation on size/format changes.

fixed publicly (mapped by code area)

telegramdesktop/tdesktop

reported via Telegram security contact · F-TELEGRAM-DESKTOP-FFMPEG-LINESIZE-MEMCPY-001

More strict checks in ffmpeg decodiing. · public commit eeafe9761409 on 2026-04-07 adds stricter negative-linesize handling in the affected ffmpeg render path.

fixed publicly

TGX-Android/Telegram-X

reported via Telegram security contact · F-TGX-PATHTRAVERSAL-001

Upgrade TDLib to tdlib/td@8fc2344 · public commit c3b01454df69 on 2026-05-03 updates U.java so getSecureFileName returns the sanitized buffer via b.toString() instead of the original fileName string, closing the path traversal sink.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram security contact · F-TELEGRAM-IOS-SSRF-001

Fix web · public commit 6eb201465096 on 2026-04-29 adds allowed-bot-media URL validation with canonical IPv4 parsing and public IPv4/IPv6 checks before Web App media_url fetches.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram security contact · F-TELEGRAM-IOS-FFMPEG-LINESIZE-MEMCPY-001

Update tgcalls · public commits 615becca7ae7 and 9ed75ca048e7 on 2026-04-21 add isPlanarYUV420Safe() before memcpy paths, rejecting negative frame.lineSize[0..3] for the affected ffmpeg decoded-frame flows.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram security contact · F-TELEGRAM-IOS-FFMPEG-PREVIEW-PIXFMT-001

Update tgcalls · public commits 615becca7ae7 and 9ed75ca048e7 on 2026-04-21 add isPlanarYUV420Safe(), including a format guard that blocks non-YUV/YUVA planar-420 layouts from the preview conversion and planar copy paths.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram security contact · F-TELEGRAM-IOS-SECRETAPI-LOCKOUT-001

TelegramApi: regenerate Api*/SecretApiLayer*.swift with safe flag unwrap · public commit 2dd07ef8cc79 on 2026-04-21 replaces Int(_1!) flag checks with Int(_1 ?? 0), removing the SecretApiLayer force-unwrap crash on truncated decryptedMessage inputs.

fixed publicly

TelegramMessenger/Telegram-iOS

reported via Telegram security contact · F-TELEGRAM-IOS-TGLINK-001

Filter url · public iOS commit cbf8f6b on 2026-06-04 removes the special tg-link hostoverride handler from OpenUrl.swift. this is mapped as fixed for the reported TGLINK host-override class.

fixed publicly (mapped by code area)

TelegramMessenger/tgcalls

reported via Telegram security contact · F-TELEGRAM-IOS-TGCALLS-SIGNALING-001

feat: SCTP signaling improvements for reliable connection establishment · public tgcalls commit 24fd51b on 2026-04-15 adds SCTP signaling reliability fixes, including writable gating and timer backoff bounds. Telegram iOS later pulled a tgcalls submodule revision that includes this fix.

fixed publicly (upstream tgcalls)

telegramdesktop/tdesktop

reported via Telegram security contact · F-TELEGRAM-INTOVF-001

More strict checks in ffmpeg decodiing. · public commits eeafe9761409 on 2026-04-07 and 9eda44ca316b on 2026-04-30 add stricter ffmpeg linesize handling, ValidFrameSize checks, max_pixels propagation, and null-allocation failure handling for the reported integer-overflow paths.

fixed publicly

telegramdesktop/tdesktop

reported via Telegram security contact · F-TELEGRAM-DESKTOP-FFMPEG-FRAMEAREA-001

More strict checks in ffmpeg decodiing. · public commit eeafe9761409 on 2026-04-07 adds decoded frame area guards; follow-up commit 9eda44ca316b on 2026-04-30 strengthens frame-size validation with ValidFrameSize and max_pixels handling for the same ffmpeg frame-size class.

fixed publicly

morethanwords/tweb

reported via Telegram security contact · F-TELEGRAM-WEBK-TGIV-DECODE-001

restrict tg://iv decode to safe links · public WebK/tweb commit 6af7087389c0 restricts tg://iv local decode handling to safe links; unsafe or broken links no longer keep the local handler.

fixed publicly

telegramdesktop/tdesktop

reported via Telegram security contact · F-TGDESKTOP-WEBVIEW-004

Harden interaction app<->shell<->webapp. · public tdesktop commit 55768ee on 2026-05-15 hardens the app<->shell<->webapp interaction across bot_webview_shell_html, attach_bot_webview, and lib_webview paths. this is mapped as a likely fix for F-TGDESKTOP-WEBVIEW-004; later same-origin webapp support also appears in the 6.8.x release line.

likely fixed publicly (mapped by hardening area)

Ajaxy/telegram-tt

reported via Telegram security contact · F-WEBA-POSTMSG-001

General: Better validation for iframe event origins (#6856) · public WebA commit 7e789e6 on 2026-04-17 adds isMessageFromIframe(...) checks so iframe events are accepted only from the expected iframe. caveat: outbound postMessage(..., '*') patterns may still exist, so this is tracked as partial/likely fixed pending re-test if the original issue was specifically targetOrigin='*'.

partially likely fixed publicly (re-test needed)

google/go-attestation

reported via security contact · F-GO-ATTESTATION-001

attest: fix uint32 underflow in parseEfiSignatureList · public issue #485, PR #486, merged on 2026-03-06. upstream added the lower-bound validation for malformed EFI_SIGNATURE_LIST parsing in parseEfiSignatureList.

fixed publicly

flutter/flutter

reported via public Flutter PR · F-FLUTTER-APNG-001

Fix a potential buffer overflow in the animated PNG decoder when parsing malformed fdAT chunks · merged on 2026-05-21 as commit 9cf97ce9d21d. maintainer note says the fix is based on #184301 and our #183180; it rejects malformed fdAT chunks with data_length below the 4-byte sequence-number minimum. stable cherry-pick #188038 merged to flutter-3.44-candidate.0 on 2026-06-18 as commit a4ce257.

fixed publicly

protocolbuffers/protobuf

reported via security contact · F-PROTOBUF-UPB-STRTOF-LOCALE-OVERFLOW-001

upb: add bounds check to LocalizeRadix() · public fix commit 880f66e17234 on 2026-03-23. commit message states: closes a memory corruption vulnerability. release v34.1 from 2026-03-19 still predates the fix.

fixed publicly

nginx/nginx

reported via private security contact · F-NGINX-HTTP-REQ-002

bare LF accepted in chunked transfer encoding · public fix commit f405ef11fde6 on 2025-12-06, first released in nginx 1.29.4 on 2025-12-09. stable 1.28.x appears unpatched as of 1.28.3 (2026-03-24).

fixed publicly

apache/apisix

reported via security contact · F-APISIX-CLS-HTTP-001

feat: make scheme configurable with default set to https · public fix commit f609ea332af7 appears to address the reported issue.

fixed publicly

apache/apisix

reported via security contact · F-APISIX-OIDC-TLS-001

chore: set default value of ssl_verify to true · public fix commit dd42b19feb15 appears to address the reported issue.

fixed publicly

aquasecurity/trivy

reported via private reporting channel · F-TRIVY-CONFIG-TEMPLATE-001

fix(flag): validate template file extension · public remediation commit 20458b836b71 appears to address the earlier repo-local template/config issue.

fixed publicly

smallstep/certificates

reported via security contact · F-SMALLSTEP-AK-EKU-001

Validate tcg-kp-AIKCertificate EKU · TPM attestation EKU panic. public fix PR #2569, first released in v0.30.0. GHSA-9qq8-cgcv-qmc9 / CVE-2026-40097 published.

fixed publicly

smallstep/certificates

reported via security contact · F-SMALLSTEP-WEBHOOK-001

Validate webhooks · request-influenced webhook destination rendering. public fix PR #2570, first released in v0.30.0.

fixed publicly

signalapp/libsignal

reported via security contact · F-LIBSIGNAL-JNI-DESTROY-UB-001

jni: Avoid forming &mut when destroying a bridged handle · public fix commit 895b07944839 on 2026-03-13, first released in v0.89.0 on 2026-03-17.

fixed publicly

gnupg/gnupg

reported via private reporting channel · F-GNUPG-001-002

tool:gpgtar: Check the output directory with --directory. · public GnuPG T8159 tracks gpgtar write outside --directory via symlink traversal with Reported-by: Oleh Konko; commit 7a2692fe5e58 landed on 2026-03-24 and GnuPG 2.5.19 announced the fix for gpgtar -C/--directory output-directory checking on 2026-04-24.

fixed publicly

confluentinc/schema-registry

reported via private security contact · F-CONFLUENTIC-SCHEMA-REGISTRY-REST-BODY-NOCAP-001

add size limit handler to limit req/resp size (#4310) (#4313) · public commit bd56596 on 2026-05-18 adds Jetty SizeLimitHandler, size.limit.handler.enabled and max.request.body.size configuration, plus RestApiRequestBodySizeClusterTest coverage for HTTP 413 on oversized request bodies. releases v8.0.6, v8.1.4, v8.2.2, and v8.3.0 contain the fix; v8.0.6 was tagged 2026-06-19.

fixed publicly

NVIDIA/TensorRT-LLM

reported via NVIDIA security contact · F-TRTLLM-DESER-001

Security Bulletin: NVIDIA TensorRT-LLM - May 2026 · NVIDIA TensorRT-LLM May 2026 bulletin lists unsafe deserialization CVE-2025-33255 and CVE-2026-24163 as fixed for versions prior to v1.2, and recommends TensorRT-LLM v1.2.1. this is mapped to F-TRTLLM-DESER-001 if the private report corresponds to the unsafe deserialization class; public acknowledgement credits a different reporter, so this is tracked as reported-fix mapping rather than public CVE credit.

fixed publicly (mapped to unsafe deserialization class)

across-protocol/contracts

reported via private security contact · F-ACROSS-009-001

chore: deploy Polygon_SpokePool · nested tryMulticall bypass in Polygon_SpokePool multicall validation. initial PR #1363 added commit 3d163b8 on 2026-03-11 to block MultiCallerUpgradeable.tryMulticall.selector alongside multicall.selector, then closed unmerged for audit. PR #1405 merged the same fix on 2026-04-08 via merge commit 5388448 and deployed a new Polygon_SpokePool implementation. Across docs list Polygon chain id 137 SpokePool proxy 0x9295...F096; verified production implementation mapping reported as 0x4a84a43274f5f99e94aa0ebef53bc06af8bc3dfb.

fixed and deployed publicly

moby/moby

reported via security contact · F-MOBY-001-001

pkg/authz: Reject requests exceeding body size limit · public fix commit 7a767b27fd12 appears to address the reported issue. GHSA-x744-4wpc-v9h2 / CVE-2026-34040 published with credit to 1seal / Oleh Konko.

fixed publicly

decred/dcrd

reported via security contact · F-DECRED-DCRD-RPC-LIMITED-ONLY-001

rpcserver: Ensure limited user is always limited · public master fix commit 2d6b77049f1c on 2026-03-10. backported to release-v2.1 in 771100562a83 on 2026-04-06 and released in v1.10.6 on 2026-04-07. changes the old auth check so limited-only access is no longer bypassed when admin auth is unset.

fixed publicly

decred/dcrwallet

reported via security contact · F-DCRWALLET-001

jsonrpc: Fix bugs in authenticate RPC. · public fix PR #2617 merged on 2026-04-06. closes fail-open handling in the authenticate RPC path where ParseParams and the cmd type assertion could incorrectly treat bad credentials as not invalid.

fixed publicly

ProtonMail/WebClients

reported via security contact · F-PROTON-WEBCL-001

sanitize iframe bodyClasses and bodyStyles in getIframeHtml · public fix merge c65861cab0a3 on 2026-03-31. first released in proton-mail@5.0.110.0 on 2026-04-02; live mail.proton.me was observed on proton-mail@5.0.111.4 as of 2026-04-23, and current WebClients main still shows getIframeHtml.ts applying escapeHTMLAttribute(...) to bodyClasses and bodyStyles before attribute insertion. production web is treated as fixed.

fixed publicly

protonpass/android-pass

reported via security contact · F-PROTON-ANDROID-PASS-PASSKEY-ORIGIN-001

fix(passkeys): validate caller origin before signing WebAuthn assertions · public Proton Pass Android commit 855c602584bd adds PasskeyOriginVerifier, Digital Asset Links validation, and passkey_privileged_browsers_allowlist.json before signing WebAuthn assertions. Play/APKMirror/APKPure 1.40.0 builds contain the fix; F-Droid was still on 1.39.2 at verification time and therefore should not be treated as fixed until it updates.

fixed publicly in 1.40.0 (F-Droid 1.39.2 still behind)

bcgit/bc-java

reported via security contact · F-BC-NC-TRAILINGDOT-001

normalize trailing-dot DNS names before name-constraint matching · current Bouncy Castle main normalizes DNS names for PKIXNameConstraintValidator so trailing-dot DNS constraints are stripped before matching. release confirmation is intentionally not claimed: 1.84 release notes do not call out this fix and 1.85 was still pending at verification time.

fixed in main (released fix not confirmed)

aws/aws-network-policy-agent

reported via AWS security contact · F-NPA-REVERSE-CONNTRACK-001

Fix conntrack reverse flow bypass · public PR #584 merged on 2026-06-01 and adds ifindex scoping to prevent cross-pod reverse-flow conntrack poisoning. release is intentionally not claimed: the latest aws-network-policy-agent release observed was v1.3.5 from May 2026, and current VPC CNI v1.22.2 still ships amazon/aws-network-policy-agent:v1.3.5.

fixed on main (release not confirmed)

huggingface/datasets

reported via private reporting channel · F-HUGGINGFACE-003

Don't extract bad files · public fix commit 1bd0a5c087b7 appears to address the reported issue.

fixed publicly

google/boringssl

reported via Google OSS VRP / Chromium issue 487821920 · F-BORINGSSL-001-005

crypto/x509: Fix interaction of DNS exclude constraints with wildcard DNS names. · excluded dNSName wildcard SAN bypass. accepted via Google OSS VRP; public BoringSSL commit 5774eca6004e landed on 2026-03-04 as CL 90167 and updates crypto/x509/v3_ncons.cc plus tests for excluded DNS constraints interacting with wildcard SANs. the commit message references Bug: 488306305, while the tracked external report id is 487821920.

fixed publicly

google/boringssl

reported via Google OSS VRP / Chromium issue 487820706 · F-BORINGSSL-001-004

crypto/x509: Tighten URI name constraints parsing and matching · public landed commit b84dc606410e; reviewed as CL 92687. commit message references Bug: 487820706, 502006234. fix tightens URI nameConstraints parsing and matching, rejecting userinfo@ misleading hosts, nonnumeric ports, malformed hosts, and IP/IPv6 URI hosts.

fixed publicly

trezor/trezor-firmware

reported via security contact · F-TREZOR-THP-DOS-001

chore(core): improve handling of large messages · public fix commit 15975901acf6 on 2026-03-20 adds the missing `if buffer is None: return False` guard in the THP reassembly path, so oversized payload_length no longer passes as in the vulnerable pin 5ba0333910c1.

fixed publicly

trezor/trezor-suite

reported via security contact · F-TREZOR-SUITE-PT-001

feat(suite-desktop-core): add check for path traversal · public fix commit cb76104f1068 on 2026-02-26 canonicalizes paths inside userData through resolvePathInUserDataDir and blocks traversal from the affected metadata IPC path.

fixed publicly

trezor/trezor-firmware

reported via security contact · F-TREZOR-SYSCALL-TRANSLATIONS-001

fix(core): use verifiers for translations syscalls · public fix commit 1811d3bb9629 on 2026-02-27. routes translation syscalls through verified wrappers instead of raw implementations.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-008

fix(core): fix jpegdec syscall verifier · public fix commit fb4aa180cf6f on 2026-02-27. adds the missing jpegdec verifier-side input pointer validation.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-CRYPTO-MEMZERO-002

fix(crypto): add missing memzero to `ed25519.c` · public fix commit 48db49fa67eb on 2026-02-26. clears extsk on the invalid-nonce early return path in ed25519_cosi_sign.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-CRYPTO-MEMZERO-005

fix(crypto): add missing memzero to `cardano.c` · public fix commit 40d4f9027d3b on 2026-02-25. clears extended private key material on hdnode_private_ckd_cardano failure paths.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-CRYPTO-MEMZERO-001

fix(crypto): add missing memzero to `ecdsa.c` · public fix commit bddd38b47d92 on 2026-02-26. clears tc_ecdsa_sign_digest secret material on error returns.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-CRYPTO-MEMZERO-006

fix(crypto): add missing memzero to `bip32.c` · public fix commit 09e55d8c9cb2 on 2026-02-26. clears the NEM AES context key schedule after use.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-THP-FRAGMENT-001

fix(rust/trezor-thp): check `payload_len` is not less than `CHECKSUM_LEN` · public fix commit d63fe0e88377 on 2026-02-25. prevents the small-payload underflow in THP fragment reassembly.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-009

fix(core): fix dma2d syscall verifiers · public fix commit e5c51d5ee4b3 on 2026-02-27. fixes signed-overflow handling in the dma2d syscall verifier macros.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-011

fix(core): fix syscall set filter verifier · public fix commit f60f535403e6 on 2026-02-27. moves syslog filter validation ahead of strlen-driven access.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-004

refactor: stellar confirmations · public fix commit 663569c40b60 on 2026-02-24. tightens Stellar payment request confirmation flow so extra operations cannot ride past the displayed confirmation set.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-FW-007-001

fix(core): fix bug in multisig verification. · public fix commit ab9b4feaff30 on 2026-01-16. closes an ECDSA multisig verification loop flaw that could permit signature-acceptance bypass.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-BIP32-001

fix(crypto): Avoid caching uncacheable nodes in bip32.c · public fix commit 26914ff49628 on 2026-02-20. prevents the Stellar derivation path from overflowing the bounded BIP32 cache depth on Trezor One.

merged

trezor/trezor-firmware

reported via security contact · F-TREZOR-CRYPTO-MEMZERO-003

fix(crypto): clean up stack in hdnode_deserialize() · public fix commit 477cbb365a29 on 2026-02-16. clears stack-resident key material in hdnode_deserialize(); the fix is present in public release tags including core/v2.11.0 and legacy/v1.14.1.

merged

trezor/trezor-suite

reported via security contact · F-TREZOR-SUITE-PM-001

feat(connect-webextension): now uses externally_connectable api · public fix commit c84e94b607f3 on 2026-03-12. replaces wildcard postMessage response delivery in the connect popup flow with origin-scoped handling; the change is contained in public trezor-suite tags v26.4.1 and v26.4.2.

merged

trezor/trezor-suite

reported via security contact · F-TREZOR-SUITE-OAUTH-001

feat: enhance OAuth handling with zod validation and update response structure · public fix commit f02a8d4ceca5 on 2026-03-20. enforces state binding in the OAuth request/response flow and is contained in public trezor-suite tags v26.4.1 and v26.4.2.

merged

trezor/blockbook

reported via security contact · F-TREZOR-BLOCKBOOK-WS-READLIMIT-001

enhancement: reject oversized websocket messages · public fix commit f8349fcebcdf on 2026-03-11. adds a websocket read limit to stop unbounded message-driven memory growth.

merged

trezor/blockbook

reported via security contact · F-TREZOR-BLOCKBOOK-API-SENDTX-READALL-001

enhancement: limit /api/sendtx body size · public fix commit 33b99cc7d440 on 2026-03-11. replaces unbounded request-body handling in /api/sendtx with a size limit.

merged

trezor/blockbook

reported via security contact · F-TREZOR-BLOCKBOOK-001

fix: add validation for negative ranges · public fix commit 496f8e0f3272 on 2026-02-25. rejects negative From/To ranges before they can reach a recoverable panic path.

merged

trezor/blockbook

reported via security contact · F-TREZOR-BLOCKBOOK-NFT-URI-XSS-001

enhancement: avoid template.JSStr · public fix commit e4fdb5ee25a5 on 2026-03-16. removes the template.JSStr path in token detail rendering and adds regression coverage for XSS-safe escaping.

merged

aws/amazon-ecs-agent

reported via security contact · F-ECS-FSX-001

Use env variable to read user input when mounting FSx volumes · PR #4934 merged 2026-04-21, merge commit 09f274e0157d. replaces direct argv passing to powershell.exe with env-variable reads in agent/taskresource/fsxwindowsfileserver/fsxwindowsfileserver_windows.go.

merged

aws/amazon-eks-pod-identity-webhook

reported via security contact · F-AWS-EKS-PIWEBHOOK-GHA-001

pinning github action dependencies to commit sha · PR #303 merged 2026-04-13, merge commit 75a29dfa4349. pins .github/workflows/build.yaml third-party actions to immutable commit shas.

merged

awslabs/tough

reported via security contact · F-AWS-TOUGH-006

containment-check for targets_base_url in fetch_target · public code in tough 0.22.0 appears to close this read-side variant even though no separate advisory line was published for it. inferred from public diff 0ba39c5, which adds a containment-check for targets_base_url in fetch_target.

fixed publicly

awslabs/tough

reported via security contact · F-AWS-TOUGH-DELEGATION-CHAIN-001

compound delegation chain decomposed across CVE-2026-6966 and CVE-2026-6967 · upstream fixed and publicly released on 2026-04-24 in tough 0.22.0 / tuftool 0.15.0. the reported compound chain is publicly decomposed across GHSA-8m7c-8m39-rv4x / CVE-2026-6966 and GHSA-4v58-8p28-2rq3 / CVE-2026-6967 rather than published as a single bundled advisory.

fixed publicly

aws/aws-lc

reported via AWS Security · F-AWSLC-OCSP-RESPONDER-REVOC-0

Handle id-pkix-ocsp-nocheck in OCSP responder verification · AWS determined the report did not present a security vulnerability to AWS-LC or s2n-tls, but released public aws-lc PR #3169 on 2026-04-30 to handle id-pkix-ocsp-nocheck in delegated OCSP responder verification. AWS also released s2n-tls PR #5859 on 2026-05-01 to document that OCSP_basic_verify() does not verify OCSP delegated responder certificates and that this is caller configuration responsibility.

fixed/documented publicly

intel/cryptography-primitives

reported via security contact · F-INTEL-IPP-CRYPTO-SM2-VERIFY-T0-FORGERY-001

Fix SM2 signature forgery via missing t == 0 rejection in ippsGFpECVerifySM2 · public fix commit 8c4a863575f9 landed on 2026-05-19 via #899 and shipped in Intel Cryptography Primitives Library v2.2.0, published on 2026-05-28. release notes state: fixed SM2 signature forgery vulnerability by adding missing input validation in ippsGFpECVerifySM2.

fixed publicly

intel/confidential-computing.tee.dcap

reported via security contact · F-INTEL-SGX-DCAP-QCNL-OVERFLOW-001

fix(qcnl): fix integer overflow in write_callback() on Linux · public fix commit 393cbd9e3cf6 landed on 2026-04-28 and shipped in Intel SGX/TDX DCAP 1.26, published on 2026-04-30. the Linux QCNL write_callback path changes integer arithmetic and adds a bounded buffer-growth guard.

fixed publicly

intel/intel-ipsec-mb

reported via security contact · F-INTEL-IPSEC-MB-AES-CBC-LEN0-OOB-001

lib: [aes-cbc] fix zero-length message handling in decrypt direction · public fix commit 78e272a08a7c landed on 2026-04-11 and shipped in intel-ipsec-mb v2.0.2, tagged on 2026-04-21. the AES-CBC decrypt path now checks for zero-length messages before loading the IV/message buffers, avoiding the no-check API out-of-bounds read class.

fixed publicly

actions/download-artifact

reported via HackerOne · F-GHA-ARTNAME-001

download-artifact v8: content-type gated artifact decompression · public hardening shipped in actions/download-artifact v8.0.0 on 2026-02-26: the action no longer attempts to unzip every downloaded file and checks Content-Type before extraction via PR #460. v8.0.1 on 2026-03-11 added a regression test for artifact name + content-type mismatches via PR #472. attribution linkage is inferred from topic and timing; no GHSA/CVE was published.

fixed publicly (no GHSA/CVE)

Xilinx/bootgen

reported via AMD PSIRT · F-AMD-BOOTGEN-003

Bug fixes ported from 2026.1 · AMD tracked SWSPLAT-9457 as a functional bug rather than a CVE. public commit d06a738b6e99 on 2026-06-01 updates the Versal verify path so unauthenticated images fail closed when neither the image header table nor any partition has authentication metadata, closing the bootgen -arch versal -verify false-positive behavior reported in F-AMD-BOOTGEN-003.

fixed publicly (functional bug, no CVE)

ton-blockchain/ton

reported via TON contest / security process · F-TON-006-001

validator/node fixes merged to testnet · PR #2191 merged on 2026-03-09 with merge commit d9bc8b9520964817a704949cd6eb50527f595559. public ancestry shows the commit remains present in current testnet and master. the finding ID is not publicly indexed, so this is mapped by reported fix date and affected area rather than advisory disclosure.

fixed publicly (mapped by date and fix area)

ton-blockchain/ton

reported via TON contest / security process · F-TON-009-001

node/security-relevant fixes · PR #2208 merged on 2026-03-17 with merge commit 3abee30359120c51bfbbd05a589ae31ffa7d453d. the public PR includes node/security-relevant fixes including error handling and memory allocation fixes; the merge commit remains present in current testnet and master.

fixed publicly (mapped by date and fix area)

ton-blockchain/ton

reported via TON contest / security process · F-TON-010-001

Fix empty collated data / Removing null-consensus · two strong public fix candidates landed on 2026-03-19: PR #2211 commit 4d49b714ecfbc2e1bf23e75b9fadc75399122fb0 (Fix empty collated data) and PR #2209 commit 39731934d4fbbf6dce4d84509afed424a44c853c (Removing null-consensus). both commits remain present in current testnet and master; mapping is by reported fix date and consensus-area change, not public F-TON disclosure.

fixed publicly (mapped by date and fix area)

libressl/openbsd

reported via private security contact · F-LIBRESSL-NC-WILDCARD-001

fix SAN dNSName constraints matching · public OpenBSD/LibreSSL commit cf3eec32e7a6 on 2026-04-13 fixes SAN dNSName name-constraints matching by replacing substring/suffix matching with exact DNSName constraint semantics and adding regression coverage. LibreSSL 4.3.0/4.3.1 include the fix; 4.3.1 release notes explicitly mention the SAN dNSName constraints fix and 4.3.2 stable includes it. GHSA-h674-q4g3-3g47 was not publicly accessible at verification time, so this is tracked as a public upstream fixed mapping rather than confirmed GHSA/CVE metadata.

fixed publicly (GHSA metadata unconfirmed)

signalapp/Signal-Android

reported via private security contact · F-SIGANDROID-INTENT-001

mark ApkUpdatePackageInstallerReceiver non-exported · maps to GHSL-2026-102: Intent redirection through the website APK updater. public commit fecb30a86eaa on Signal-Android changes ApkUpdatePackageInstallerReceiver from android:exported="true" to false; the commit is included in v8.4.2 and the official latest channel was at 8.15.3 at verification time.

fixed publicly (high confidence mapping)

signalapp/Signal-Server

reported via private security contact · F-SIGNAL-SERVER-PREKEY-001

validate pre-key key-id ranges · public Signal-Server commits b7d455ed1140, b441fde2130, and fb84066f09df validate pre-key key-id ranges, enforce positive signed 32-bit ids, and align gRPC prekey rate-limit keys; these commits are present in tag v20260618.2.0. mapped to F-SIGNAL-SERVER-PREKEY-001 only if the private report concerned prekey key_id ranges / invalid ids / gRPC prekey limiter behavior; if it concerned depletion or last-resort semantics, an exact public fix was not observed.

likely fixed publicly (conditional mapping)

envoyproxy/envoy

reported via public GitHub issue · F-ENVOY-001-003

uhv: use-after-free read in sanitizeHeadersWithUnderscores with duplicate underscore headers · public issue #44032 was opened by @1seal and describes a UHV use-after-free read in HeaderValidator::sanitizeHeadersWithUnderscores() when duplicate underscore headers are dropped via non-owning string_view references. the issue is closed and cross-references #44086; tracked as fixed based on the public issue status, without a separate CVE/GHSA or release claim.

fixed publicly via issue closure

LedgerHQ/app-monero

reported via Ledger Donjon · F-LEDGER-MONERO-PROTOCOL-001

LSB 022: Monero secret key recovery through Keccak state exposure · Ledger Security Bulletin 022, published on 2026-06-04, describes Monero secret key recovery through Keccak state exposure in the Ledger Monero app. Ledger states the vulnerability is fixed in Monero app version 2.1.4, released on 2026-03-20, and recommends updating to 2.1.4 or later.

fixed publicly via Ledger Security Bulletin

LedgerHQ/ledger-live

reported via security contact · F-LEDGER-LIVE-DESKTOP-CUSTOMDAPPURL-001

fix(wallet-api): add domain validation for customDappUrl · Ledger Live Desktop @ledgerhq/live-desktop@2.135.2, released on 2026-01-09, includes PR #13602 / commit 48d299c adding domain validation for customDappUrl. release notes state customDappUrl is only applied when it matches the original manifest URL domain, preventing cross-domain URL manipulation.

fixed publicly

fwupd/fwupd

reported via security contact · F-UEFI-FIRMWARE-PATH-TRAVERSAL-001

Fix path traversal vulnerability in firmware backup · fwupd PR #10363 merged on 2026-05-22 with commit 7e62b0d. the fix sanitizes device-controlled firmware backup path components such as serial and version strings so traversal payloads like ../../../etc/passwd cannot escape the intended backup directory. shipped in fwupd 2.1.4, released on 2026-05-29.

fixed publicly in fwupd 2.1.4

fwupd/fwupd

reported via security contact · F-UEFI-FIRMWARE-PATH-TRAVERSAL-002

Prevent NVRAM-seeded path traversal when loading ESP files · fwupd PR #10369 merged on 2026-05-22 with commit 23304a3. the fix adds safe path validation before using Boot#### FilePath-derived ESP filenames, preventing NVRAM-seeded path traversal when loading ESP files. fwupd 2.1.4 release notes include this NVRAM-seeded path traversal fix. no public CVE id was added here because the exact CVE for this local ID was not confirmed in public metadata.

fixed publicly in fwupd 2.1.4

ProtonDriveApps/sdk

reported via security contact · F-PROTON-DRIVE-SDK-001

Avoid content key packet verification fallback on publicly shared nodes · public Proton Drive SDK commit 451c1bf disables content-key packet verification fallback for publicly shared nodes by setting allowContentKeyPacketFallbackVerification=false in SharingPublicNodesCryptoService. mapped as a strong public fix match; no CVE/GHSA claim is made for this record.

likely fixed publicly

kyverno/kyverno

reported via security contact · F-NOTARYPROJECT-KYVERNO-001

Notary verification path fixed in current Kyverno code · local PoC status: canonical reproduces on the vulnerable pinned revision, control passes, and the added control regression passes against current Kyverno commit 1f8a2c874. the vulnerable early return is no longer present; the code now continues instead of returning from the Notary verification path. commit 1f8a2c874 is used as the latest revalidation pin, not claimed as the original fix commit.

fixed in current public code (verified against latest pin)

LedgerHQ/erc7730-analyzer

reported via security contact · F-LEDGER-ERC7730-API-TRAVERSAL-001

fix: constrain descriptor includes to trusted roots · public Ledger erc7730-analyzer commit 42c0f58 landed on 2026-03-26 and constrains descriptor includes to trusted roots. the fix rejects URL and absolute-path includes, rejects ../ traversal outside the allowed root, hardens bundle zip extraction against zip-slip, and adds regression tests including test_parse_rejects_traversal_outside_root, test_safe_extract_rejects_zip_slip, and test_normalize_bundle_entrypoint_rejects_traversal. no GitHub release or tag is published for this repo, so production deployment is not publicly verifiable.

fixed in public main branch (no public release/tag)

aquasecurity/trivy

reported via security contact · F-TRIVY-TF-FILE-001

sandbox Terraform filesystem functions · revalidated with a minimal Terraform file("../secret.txt") PoC through mapfs.WithUnderlyingRoot: Trivy v0.70.0 reads POC_SECRET from outside the scan root, while v0.71.0 and v0.71.2 block traversal with no file exists at ../secret.txt. upstream fix commit 9d91b888cf63 shipped in v0.71.0 and makes Terraform filesystem functions use a sandboxed FS without access to the underlying OS root.

fixed in Trivy v0.71.0+

nimiq/wallet

reported via security contact · F-NIMIQ-SCANQR-JSREDIRECT-001

ScanQrModal: fix domain check for cashlinks · public wallet commit df954de fixes the domain check for cashlinks in ScanQrModal; Nimiq wallet release v3.2.3 contains the fix.

fixed publicly in wallet v3.2.3

historical public fixes predating report

historical closure notes for cases where public upstream code already contained the fix before the report was sent. excluded from counts.

LedgerHQ/app-plugin-yearn

public fix predates report · F-LEDGER-YEARN-RECIPIENT-HIDDEN-001

Updated to use the latest plugin SDK · public repo history shows the issue was already closed before the 2026-02-18 report. commit 1ba98ff, landed on 2023-10-17, already contains the Recipient screen in public code.

fixed before report

LedgerHQ/ledger-live

public fix predates report · F-LEDGER-LIVE-WSBRIDGE-001

Farewell 'Device Bridge' in LLD (#2635) · this appears closed in the current public product as a removal/sunset rather than a direct security fix. public ledger-live commit 28fd570 removed websocketBridge.js on 2023-03-14, and dd642a4 followed on 2023-03-16 to fully sunset internal commands. caveat: the original finding referenced the older LedgerHQ/ledger-live-desktop path.

feature removed publicly

telegramdesktop/tdesktop

public fix predates report · F-TGDESKTOP-CLIPBOARD-001

Track interactions in webview for clipboard access · public commit d349a28d7645 on 2026-02-28 gates clipboard reads on a recent real webview interaction within kClipboardReadTimeout. the fix predates the submitted Telegram bundle and is tracked as a parallel public closure rather than report-driven remediation.

fixed before report

tdlib/td

public fix predates report · F-TELEGRAM-VECOVF-001

public tdlib commit predating submitted bundle · public tdlib commit 9722906f9a0b on 2026-03-02 appears to address the same vector-length check in the reported callsite. because the public change predates the 2026-03-03 bundle email by one day, this is tracked as a historical pre-existing fix rather than a report-driven public remediation.

fixed before report

disclosure policy

1seal follows coordinated vulnerability disclosure (cvd). findings are reported to maintainers first, with reasonable time for patches before public disclosure.

no testing on production systems with real user data. no trading on non-public vulnerability knowledge. no pressure tactics or threats of disclosure.