Full Disclosure Mailing List

A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.

List Archives

Latest Posts

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1 Apple Product Security via Fulldisclosure (Sep 28)
APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

macOS Sequoia 15.8.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149229.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Sequoia
Impact: Processing a maliciously crafted file may lead to arbitrary code...

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1 Apple Product Security via Fulldisclosure (Sep 28)
APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

macOS Tahoe 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149228.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Tahoe
Impact: Processing a maliciously crafted file may lead to arbitrary code...

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1 Apple Product Security via Fulldisclosure (Sep 28)
APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

iOS 26.7.1 and iPadOS 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149226.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation
and later, iPad Pro...

SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742 SEC Consult Vulnerability Lab via Fulldisclosure (Sep 26)
SEC Consult Vulnerability Lab Security Advisory < 20260923-0 >
=======================================================================
title: Local Privilege Escalation
product: Honeywell IQ MultiAccess Update Service
 vulnerable version: IQ V27 & IQ V28
fixed version: IQ V27 SP1 & IQ V28 SP1
         CVE number: CVE-2026-13742
             impact: high
homepage:...

[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134) Matthias Deeg via Fulldisclosure (Sep 26)
Advisory ID: SYSS-2026-071
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Format String (CWE-134)
Risk Level: Medium
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190) Matthias Deeg via Fulldisclosure (Sep 26)
Advisory ID: SYSS-2026-070
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190) Matthias Deeg via Fulldisclosure (Sep 26)
Advisory ID: SYSS-2026-069
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-068]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121) Matthias Deeg via Fulldisclosure (Sep 26)
Advisory ID: SYSS-2026-068
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Stack-based Buffer Overflow (CWE-121)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned...

[SYSS-2026-067]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121) Matthias Deeg via Fulldisclosure (Sep 26)
Advisory ID: SYSS-2026-067
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Stack-based Buffer Overflow (CWE-121)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned...

harness Gitspace hardcoded password for every user account Khashayar Fereidani (Sep 26)
# harness Gitspace hardcoded password for every user account

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/harness-gitspace-hardcoded-password-for-every-user-account
**Contact:** https://fereidani.com/contact

## Description

Gitspaces are Harness's hosted development environments: a container with
the user's source tree, running an SSH server and an IDE, with its ports
published on...

harness(gitness) registry webhook sort_order blind SQL injection Khashayar Fereidani (Sep 26)
# harness registry webhook sort_order blind SQL injection

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/harness-registry-webhook-sortorder-blind-sql-injection
**Contact:** https://fereidani.com/contact

## Description

Harness open source (Gitness) is a self-hosted platform for source control,
pipelines and artifact registries. The registry API lists the webhooks of a
registry at `GET...

dive tar-slip in image file extraction Khashayar Fereidani (Sep 26)
# dive tar-slip in image file extraction

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/dive-tar-slip-in-image-file-extraction
**Contact:** https://fereidani.com/contact

## Description

dive is a terminal UI for exploring Docker image layers, and inspecting images
pulled from public registries is its main use case. The filetree view has an
extract action (the default keybinding is `ctrl+e`,...

usvg SVGZ decompression bomb in `Tree::from_data` Khashayar Fereidani (Sep 26)
# usvg SVGZ decompression bomb in `Tree::from_data`

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-18
**Advisory:** https://fereidani.com/usvg-svgz-decompression-bomb-in-treefromdata
**Contact:** https://fereidani.com/contact

## Description

`Tree::from_data` in `crates/usvg/src/parser/mod.rs:102` detects the gzip magic
bytes at the start of the input and decompresses the data before parsing it:

```rust
//...

openEQUELLA authenticated RCE chain(s) evan via Fulldisclosure (Sep 26)
SUMMARY: an authenticated deserialization vuln in openEQUELLA allows
an attacker to inject a SignedObject payload, unwrap the SignedObject,
create an LDAP callback and serve a JNR response to get the server to
execute arbitrary code. alongside this sink is a SSTI vuln as well.

https://blog.evan.lat/posts/openeq/

openequella is an "open source digital repository" for educational
material. it is widely used in australian universities...

[0day-rubbish] Server Technology PRO3X PDU 030600 port_mux listener program override to root command execution (7.2) disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in Server
Technology (Legrand group) PRO3X series intelligent rack PDUs, firmware
spdu-pro3x-030600 build 46640 (ARM 32-bit uClibc Linux).

Type: authenticated listener program override leading to root command execution
(CWE-78, CWE-269; a separate hard-coded factory credential is reported as
CWE-798). PRO3X PDUs run port_mux, an inetd-style launcher that starts every
protocol...

More Lists

Dozens of other network security lists are archived at SecLists.Org.