CVE-2026-47910
published 2026-06-09CVE-2026-47910: Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An…
PriorityP430medium6.3CVSS 3.1
AVLACLPRNUIRSCCHINAN
EPSS
0.14%
3.5th percentile
Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dreamweaver | < 21.8 | 21.8 |
| adobe | dreamweaver_desktop | <= 21.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read.
ghsa_unreviewed·2026-06-09
CVE-2026-47910 [MEDIUM] CWE-863 Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read.
Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
VulDB
Adobe Dreamweaver Desktop up to 21.7 File authorization (apsb26-62)
vuldb·2026-06-09·CVSS 6.3
CVE-2026-47910 [MEDIUM] Adobe Dreamweaver Desktop up to 21.7 File authorization (apsb26-62)
A vulnerability classified as problematic was found in Adobe Dreamweaver Desktop up to 21.7. This issue affects some unknown processing of the component File Handler. The manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-47910. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-47910 golang-k8s-sample-controller: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-k8s-sample-controller: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-k8s-sample-controller: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clos
Bugzilla
CVE-2025-47910 snapd: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 snapd: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 snapd: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-47910 golang-github-rubenv-sql-migrate: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-rubenv-sql-migrate: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-rubenv-sql-migrate: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to
Bugzilla
CVE-2025-47910 cri-tools1.32: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 cri-tools1.32: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 cri-tools1.32: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repor
Bugzilla
CVE-2025-47910 golang-github-gobwas-ws: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-gobwas-ws: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-gobwas-ws: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-47910 osbuild-composer: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 osbuild-composer: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 osbuild-composer: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug re
Bugzilla
CVE-2025-47910 cheat: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 cheat: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 cheat: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-47910 golang-github-projectdiscovery-chaos-client: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-projectdiscovery-chaos-client: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-projectdiscovery-chaos-client: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's
Bugzilla
CVE-2025-47910 golang-sigs-k8s-aws-iam-authenticator: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-sigs-k8s-aws-iam-authenticator: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-sigs-k8s-aws-iam-authenticator: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's polic
Bugzilla
CVE-2025-47910 cri-tools1.29: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 cri-tools1.29: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 cri-tools1.29: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repor
Bugzilla
CVE-2025-47910 golang-github-path-network-mmproxy: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-path-network-mmproxy: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-path-network-mmproxy: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy t
Bugzilla
CVE-2025-47910 hut: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 hut: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 hut: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from re
Bugzilla
CVE-2025-47910 golang-github-facebookincubator-go2chef: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-facebookincubator-go2chef: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-facebookincubator-go2chef: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's pol
Bugzilla
CVE-2025-47910 golang-github-schollz-croc: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-schollz-croc: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-schollz-croc: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-47910 aerc: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 aerc: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 aerc: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from r
Bugzilla
CVE-2025-47910 trustee-guest-components: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 trustee-guest-components: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 trustee-guest-components: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close al
Bugzilla
CVE-2025-47910 forgejo: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 forgejo: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 forgejo: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports fro
Bugzilla
CVE-2025-47910 golang-github-pdfcpu: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-pdfcpu: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-pdfcpu: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bu
Bugzilla
CVE-2025-47910 dnsx: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 dnsx: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 dnsx: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from r
Bugzilla
CVE-2025-47910 golang-github-cloudflare: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-cloudflare: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-cloudflare: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close al
Bugzilla
CVE-2025-47910 golang-gvisor: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-gvisor: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-gvisor: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repor
Bugzilla
CVE-2025-47910 etcd: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 etcd: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 etcd: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from r
Bugzilla
CVE-2025-47910 kubernetes1.30: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 kubernetes1.30: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 kubernetes1.30: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repo
Bugzilla
CVE-2025-47910 reposurgeon: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 reposurgeon: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 reposurgeon: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports
Bugzilla
CVE-2025-47910 golang-ariga-atlas: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-ariga-atlas: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-ariga-atlas: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-47910 golang-github-nicksnyder-i18n-2: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-nicksnyder-i18n-2: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-nicksnyder-i18n-2: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to c
Bugzilla
CVE-2025-47910 golang-x-text: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-x-text: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-x-text: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repor
Bugzilla
CVE-2025-47910 golang-k8s-code-generator: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-k8s-code-generator: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-k8s-code-generator: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close a
Bugzilla
CVE-2025-47910 yubihsm-connector: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 yubihsm-connector: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 yubihsm-connector: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug r
Bugzilla
CVE-2025-47910 asnmap: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 asnmap: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 asnmap: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-47910 lw-cli: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 lw-cli: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 lw-cli: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-47910 kappanhang: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 kappanhang: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 kappanhang: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports
Bugzilla
CVE-2025-47910 golang-github-pact-foundation: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-pact-foundation: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-pact-foundation: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clo
Bugzilla
CVE-2025-47910 golang-x-debug: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-x-debug: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-x-debug: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repo
Bugzilla
CVE-2025-47910 golang-google-appengine: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-google-appengine: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-google-appengine: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-47910 golang-github-valyala-fasthttp: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-valyala-fasthttp: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-valyala-fasthttp: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-47910 golang-github-redteampentesting-monsoon: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-redteampentesting-monsoon: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-redteampentesting-monsoon: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's pol
Bugzilla
CVE-2025-47910 golang-github-uber-athenadriver: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-uber-athenadriver: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-uber-athenadriver: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to c
Bugzilla
CVE-2025-47910 golang-github-colinmarc-hdfs-2: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-colinmarc-hdfs-2: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-colinmarc-hdfs-2: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-47910 golang-github-google-pprof: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-google-pprof: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-google-pprof: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-47910 exercism: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 exercism: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 exercism: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports fr
Bugzilla
CVE-2025-47910 direnv: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 direnv: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 direnv: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-47910 golang-github-liamg-scout: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-liamg-scout: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-liamg-scout: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close a
Bugzilla
CVE-2025-47910 golang-github-cucumber-godog: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-cucumber-godog: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-cucumber-godog: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clos
Bugzilla
CVE-2025-47910 cri-o: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 cri-o: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 cri-o: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-47910 golang-github-grpc-ecosystem-gateway: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-grpc-ecosystem-gateway: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-grpc-ecosystem-gateway: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy
Bugzilla
CVE-2025-47910 vultr: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 vultr: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 vultr: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-47910 golang-github-schollz-cli-2: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-schollz-cli-2: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-schollz-cli-2: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-47910 golang-github-envoyproxy-protoc-gen-validate: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-envoyproxy-protoc-gen-validate: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-envoyproxy-protoc-gen-validate: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora'
Bugzilla
CVE-2025-47910 golang-github-vmware-govmomi: CrossOriginProtection bypass in net/http [fedora-42]
bugzilla·2025-09-25·CVSS 5.4
CVE-2025-47910 [MEDIUM] CVE-2025-47910 golang-github-vmware-govmomi: CrossOriginProtection bypass in net/http [fedora-42]
CVE-2025-47910 golang-github-vmware-govmomi: CrossOriginProtection bypass in net/http [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clos
2026-06-09
Published