Skip to content

Feeds

Subscribe to one feed, track every tool under it. Feeds are grouped by audience so you can stack what matters and ignore the rest.

Security releases

Past 7 days

Security insights
Upgrade now
freescout 1.8.225 Security relevant
Auth RCE / SSRF Dependencies

Path traversal fix + CVE patches

Upgrade now
Podman v5.8.3 Security relevant
RCE / SSRF

CVE-2026-44517 fix

Upgrade now
Hasura v2.45.5 Security relevant

Security fix + server/data connector bugs

Upgrade now
opentofu v1.11.9 Security relevant
Auth RCE / SSRF

SSH security fixes

Upgrade now
opentofu v1.12.2 Security relevant
Auth RCE / SSRF

Security fixes

Review required
Scoold 1.69.0 Security relevant
Auth RBAC

Security hardening

Review required
FileRise v3.15.0 Security relevant
Auth RBAC

Shared-folder boundary hardening

Upgrade now
SQLPage v0.44.1 Security relevant
Auth

OIDC protected path bypass fix

Config change
Oikos v0.71.12 Security relevant
Auth

OIDC email verification strictness

Upgrade now
wekan v9.37 Security relevant
Auth RBAC

BoardBleed fix

Upgrade now
Vvveb CMS 1.0.8.6 Security relevant
Auth RCE / SSRF

XSS fixes + filename filter

Config change
budibase 3.39.13 Security relevant
Auth

Login IP lockout

Upgrade now
perry v0.5.1159 Security relevant
RCE / SSRF

Path‑traversal fix

Upgrade now
langchain langchain-model-profiles==0.0.6 Security relevant
Dependencies

CVE-2026-4539 security fix

Upgrade now
wekan v9.36 Security relevant
Auth

TokenBleed fix + API expansions

Upgrade now
wiredoor v1.7.2 Security relevant
Dependencies

Security fixes

Review required
Flyimg 1.12.1 Security relevant
Dependencies

Dependency updates

Review required
Oikos v0.70.2 Security relevant
Auth RCE / SSRF

WebDAV security hardening

Review required
Tapflow v0.8.0-next.2 Security relevant
Dependencies

CVE-2026-9277 fix

Review required
Jenkins jenkins-2.568 Security relevant

Security fixes

Review required
great_cto v2.65.1 Security relevant
Auth

CSRF mitigation

Upgrade now
SoulSync 2.6.9 Security relevant
Auth

Server‑side PIN enforcement + secret masking

Upgrade now
Cronicle v0.9.118 Security
Dependencies

shell-quote bump

Upgrade now
langroid 0.65.3 Security relevant
RCE / SSRF

Sender verification in handle_message

Upgrade now
langroid 0.65.2 Security relevant
RCE / SSRF

RCE fix in pandas eval

Upgrade now
langroid 0.65.1 Security relevant
RCE / SSRF

SQL function‑name blocklist bypass fix

Upgrade now
fireshare v1.6.16 Security relevant
Auth RCE / SSRF

SSRF fix

Review required
Oikos v0.68.1 Security relevant
Auth RCE / SSRF

Documents preview hardening

No immediate action
grafana v12.2.9 Security relevant

CVE fixes + Docker + Go update

Upgrade now
Medialyze v0.15.0 Security relevant
Dependencies

Starlette update + duplication comparison

Review required
Oikos v0.67.5 Security relevant
Auth

CSP + referrer policy

Upgrade now
BookStack v26.05.1 Security relevant
Auth RCE / SSRF

Attachment leak + file protocol abuse

Review required
Froxlor 2.3.8 Security relevant
Auth

CSRF token validation

Monitor
Oikos v0.66.2 Security relevant
Crypto / TLS

Secure avatar color selection

Upgrade now
coder v2.33.7 Security relevant
Dependencies RCE / SSRF

CVE fixes + aibridge header fix

Beta — feedback welcome: [email protected]