Skip to content
← All tracked CVEs

Updated 05:00

Low severity

Low90d SLA

Our service-level agreement (SLA) gives a low vulnerability a fix within 90 days of publication. 53 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
OpenPostgreSQL ECPG integer underflow enables DoS via bytea without prefix; client memory overwritesecure-packages-rollingAug 24, 2026Nov 22, 2026
OpenPostgreSQL ALTER TABLE ALTER TYPE misassigns stats ownership, enabling unauthorized DROP/ALTER STATISTICSsecure-packages-rollingAug 24, 2026Nov 22, 2026
OpenPostgreSQL amcheck EXECUTE privilege allows arbitrary function execution as expression index ownerssecure-packages-rollingAug 24, 2026Nov 22, 2026
OpenPostgreSQL ALTER TABLE ALTER TYPE misassigns stats ownership, allowing unauthorized DROP/ALTERsecure-packages-26.05Aug 25, 2026Nov 23, 2026
OpenPostgreSQL amcheck untrusted search_path permits arbitrary function execution via expression indexes in versions before 18.5/16.15/15.19/14.24secure-packages-26.05Aug 25, 2026Nov 23, 2026
OpenPostgreSQL ECPG integer underflow: client DoS via missing bytea prefix; pre-18.5/17.11/16.15/15.19/14.24secure-packages-26.05Aug 25, 2026Nov 23, 2026
OpenPostgreSQL amcheck untrusted search_path enables privilege escalation via expression indexes; affects <18.5/16.15/15.19/14.24secure-packages-25.11Aug 25, 2026Nov 23, 2026
OpenPostgreSQL ALTER TABLE ALTER TYPE reassigns stats ownership, enabling unauthorized DROP/ALTER; pre-18.5/17.11/16.15/15.19/14.24secure-packages-25.11Aug 25, 2026Nov 23, 2026
OpenServer-admin triggered PostgreSQL ECPG integer underflow DoS via malformed bytea; pre-18.5/17.11/16.15/15.19/14.24secure-packages-25.11Aug 25, 2026Nov 23, 2026
Fixed within SLAChrome pre-151.0.7922.169 GPU uninitialized resource leaks memory outside sandbox via crafted HTMLsecure-packages-rollingAug 24, 2026Nov 22, 2026Aug 25, 20261 day
Fixed within SLAChrome GPU uninitialized resource allows memory read outside sandbox post-renderer compromise (pre-151.0.7922.169)secure-packages-26.05Aug 25, 2026Nov 23, 2026Aug 25, 2026same day
Fixed within SLAsecure-packages-rollingJun 15, 2026Sep 13, 2026Aug 18, 202663 days
Fixed within SLAChrome GPU integer overflow allowed cross-origin data leak via crafted page (pre-151.0.7922.109)secure-packages-26.05Aug 11, 2026Nov 9, 2026Aug 11, 2026same day
Fixed within SLASkia uninitialized use in Chrome <151.0.7922.109 enables cross-origin data leak after renderer compromisesecure-packages-26.05Aug 11, 2026Nov 9, 2026Aug 11, 2026same day
Fixed within SLAUninitialized use in Skia allows cross-origin data leak in Chrome before 151.0.7922.109 after renderer compromisesecure-packages-26.05Aug 11, 2026Nov 9, 2026Aug 11, 2026same day
Fixed within SLAChrome GPU integer overflow allowed compromised renderer to leak cross-origin data pre-151.0.7922.109secure-packages-25.11Aug 10, 2026Nov 8, 2026Aug 11, 20261 day
Fixed within SLAChrome <151.0.7922.109 Skia uninitialized use leaks cross-origin data via crafted HTMLsecure-packages-25.11Aug 10, 2026Nov 8, 2026Aug 11, 20261 day
Fixed within SLASkia uninitialized use leaks cross-origin data in Chrome <151.0.7922.109 via crafted HTMLsecure-packages-25.11Aug 10, 2026Nov 8, 2026Aug 11, 20261 day
Fixed within SLAChrome <151.0.7922.109 GPU integer overflow leaks cross-origin data; requires renderer compromisesecure-packages-rollingAug 10, 2026Nov 8, 2026Aug 11, 20261 day
Fixed within SLASkia uninitialized use in Chrome <151.0.7922.109 leaks cross-origin data after renderer compromise via crafted HTMLsecure-packages-rollingAug 10, 2026Nov 8, 2026Aug 11, 20261 day
Fixed within SLAChrome <151.0.7922.109 Skia uninitialized use leaks cross-origin data post-renderer compromisesecure-packages-rollingAug 10, 2026Nov 8, 2026Aug 11, 20261 day
Fixed within SLAChrome for iOS <151.0.7922.72 exposes process memory to local physical attackersecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome Android USB policy flaw prior to 151.0.7922.72 leaks cross-origin data via compromised renderersecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome Passwords <151.0.7922.72 cross-origin data leak via renderer-compromised crafted HTMLsecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome Android <151.0.7922.72 cross-origin data leak via crafted HTML, local attackersecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome Android <151.0.7922.72 UI flaw enables cross-origin data leak via crafted pagesecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLALow-severity CORS flaw in Chrome <151.0.7922.72 enables cross-origin leak via compromised renderersecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome Linux Editing component leaks cross-origin data via crafted HTML prior to 151.0.7922.72secure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAAndroid Chrome <151.0.7922.72: Omnibox spoofing via malicious local file; insufficient input validationsecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML and UI gestures Medium severitysecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAAndroid Chrome Clipboard validation flaw prior to 151.0.7922.72 leaks cross-origin data locallysecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Chrome SVG flaw leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAHigh-severity Chrome Passwords policy flaw leaks cross-origin data via compromised renderer (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome Passwords before 151.0.7922.72: cross-origin data leak via crafted HTML, UI gesturessecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 Skia cross-origin data leak via crafted HTML with compromised renderersecure-packages-26.05Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAUnbound unbound-control view_local_data(s) omits default-protected zones; protected queries leak to public DNSsecure-packages-rollingJul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.18–1.25 PROXYv2 computes DNS cookie from proxy IP, enabling off-path UDP spoofingsecure-packages-rollingJul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.6.0–1.25.1 DNSSEC wildcard replay causes cache poisoning on serve-expiredsecure-packages-rollingJul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.13.2-1.25.1: harden-below-nxdomain off-by-one shadows stub/forward zones under DNSSECsecure-packages-rollingJul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.16.2–1.25.1 A/AAAA glue ghost domain TTL extension via cache overwritesecure-packages-rollingJul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.22–1.25.1 DoQ termination miscount inflates waiters, causing service degradation and silent dropssecure-packages-rollingJul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.6.0–1.25.1: unbound-control creates view local zones without defaults; protected queries leaksecure-packages-26.05Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound PROXYv2 server cookie keyed to proxy, enabling off-path UDP cookie replaysecure-packages-26.05Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLADNSSEC wildcard replay cache poisoning in Unbound 1.6.0–1.25.1 serve-expired pathsecure-packages-26.05Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.13.2–1.25.1 harden-below-nxdomain off-by-one returns parent NXDOMAIN, shadowing stub/forward zonessecure-packages-26.05Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.16.2–1.25.1 A/AAAA glue bug extends ghost-domain window; CVE-2026-40622 variantsecure-packages-26.05Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.22–1.25.1 DoQ termination misaccounting inflates waiters, causing silent query dropssecure-packages-26.05Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound control-created view local-zone tree lacks defaults; protected names resolve publiclysecure-packages-25.11Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound harden-below-nxdomain off-by-one bypasses stub/forward zones via parent secure NXDOMAINsecure-packages-25.11Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.16.2–1.25.1 ghost domain vuln extends A/AAAA glue TTL window, CVE-2026-40622 variantsecure-packages-25.11Jul 27, 2026Oct 25, 2026Jul 29, 20262 days