Live stack monitoring for frameworks, packages, and vendor incidents
Feed synced 21m ago

Security news for developers, not just security teams.

HackTribune turns supply-chain incidents, framework advisories, and malicious package reports into searchable incident pages, watchlists, and upgrade-worthy alerts.

19,027
incidents tracked
1,712
exploited in the wild
15
ecosystems covered

Latest incidents

View all →
UNKNOWNunknown

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

56 years ago
MEDIUMunknown

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.

1 day ago
MEDIUMunknown

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-9

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)

1 day ago
MEDIUMunknown

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

1 day ago
MEDIUMunknown

(containerd is an open-source container runtime. Prior to 1.7.35, 2.0.1 ...)

(containerd is an open-source container runtime. Prior to 1.7.35, 2.0.1 ...)

1 day ago
MEDIUMunknown

(WeasyPrint helps web developers to create PDF documents. Prior to 70.0 ...)

(WeasyPrint helps web developers to create PDF documents. Prior to 70.0 ...)

1 day ago