Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
87

Critical Issues with Debian Trixie OpenJDK-21 DSA-6112-1 Announcement

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 21.0.10+7-1~deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6112-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 27, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openjdk-21 CVE ID : CVE-2026-21925 CVE-2026-21932 CVE-2026-21933 CVE-2026-21945 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 21.0.10+7-1~deb13u1. We recommend that you upgrade your openjdk-21 packages. For the detailed security status of openjdk-21 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openjdk-21 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . OpenJDK 21 vulnerabilities lead to certificate validation issues and CRLF injections. Upgrade recommended for Debian trixie.. Debian, OpenJDK, certificate issues, Java runtime, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 27, 2026 Critical Debian
100

SUSE: 2021:410-1 Moderate: Python-urllib3 CRLF Injection Risk

The container suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64 was updated. The following patches have been included in this update:. SUSE Image Update Advisory: suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2021:410-1 Image Tags : suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64:20210304 Image Release : Severity : moderate Type : security References : 1177211 1177460 1180603 1181571 CVE-2020-26116 ----------------------------------------------------------------- The container suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:293-1 Released: Wed Feb 3 12:52:34 2021 Summary: Recommended update for gmp Type: recommended Severity: moderate References: 1180603 This update for gmp fixes the following issues: - correct license statements of packages (library itself is no GPL-3.0) (bsc#1180603) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:301-1 Released: Thu Feb 4 08:46:27 2021 Summary: Recommended update for timezone Type: recommended Severity: moderate References: 1177460 This update for timezone fixes the following issues: - timezone update 2021a (bsc#1177460) * South Sudan changes from +03 to +02 on 2021-02-01 at 00:00. - timezone update 2021a (bsc#1177460) * South Sudan changes from +03 to +02 on 2021-02-01 at 00:00. ----------------------------------------------------------------- Advisory ID: SUSE-OU-2021:339-1 Released: Mon Feb 8 13:16:07 2021 Summary: Optional update for pam Type: optional Severity: low References: This update for pam fixes the following issues: - Added rpm macros for this package, so that other packages can make use of it This patch is optional to be installed - it doesn't fix anybugs. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:341-1 Released: Mon Feb 8 17:39:53 2021 Summary: Security update for python-urllib3 Type: security Severity: moderate References: 1177211,1181571,CVE-2020-26116 This update for python-urllib3 fixes the following issues: - CVE-2020-26116: Raise ValueError if method contains control characters and thus prevent CRLF injection into URLs (bsc#1177211). - Skip test for RECENT_DATE (bsc#1181571). . Essential Security Patch Released For SUSE Container Fixing CRLF Exploits. Ensure Your Safety!. SUSE Security Update, Python Urllib3, Container Security. . LinuxSecurity.com Team

Calendar%202 Mar 10, 2021 SuSE
100

SUSE: 2021:0515-1 Moderate: Fix for Python-Urllib3 CRLF Injection

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-urllib3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0515-1 Rating: moderate References: #1177211 Cross-References: CVE-2020-26116 CVSS scores: CVE-2020-26116 (NVD) : 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVE-2020-26116 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-urllib3 fixes the following issues: - CVE-2020-26116: Raise ValueError if method contains control characters and thus prevent CRLF injection into URLs (bsc#1177211). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-515=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-515=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-515=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): python-urllib3-1.22-5.15.1 - SUSE OpenStack Cloud 8 (noarch): python-urllib3-1.22-5.15.1 - HPE Helion Openstack 8 (noarch): python-urllib3-1.22-5.15.1 References: https://www.suse.com/security/cve/CVE-2020-26116.html https://bugzilla.suse.com/1177211 . SUSE Security Update for python-requests addresses a vulnerability related to improper input handling that could lead to contentinjection in network requests. Find out more inside.. SUSE Python Urllib3 Update Control Character. . LinuxSecurity.com Team

Calendar%202 Feb 18, 2021 SuSE
89

Fedora 32: python27 2020-887d3fa26f Critical: HTTP Request CRLF Injection

CVE-2020-26116: HTTP request method CRLF injection in httplib. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-887d3fa26f 2020-10-16 15:18:47.312170 --------------------------------------------------------------------------------Name : python27 Product : Fedora 32 Version : 2.7.18 Release : 6.fc32 URL : https://www.python.org/ Summary : Version 2.7 of the Python interpreter Description : Python 2 is an old version of the language that is incompatible with the 3.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed in the 3.x line. Note that Python 2 is not supported upstream after 2020-01-01, please use the python3 package instead if you can. This package also provides the "python2" executable. --------------------------------------------------------------------------------Update Information: CVE-2020-26116: HTTP request method CRLF injection in httplib --------------------------------------------------------------------------------ChangeLog: * Wed Sep 30 2020 Petr Viktorin - 2.7.18-6 - CVE-2020-26116: Reject control chars in HTTP method in httplib.putrequest * Tue Sep 29 2020 Petr Viktorin - 2.7.18-5 - Import patches from GitHub tree --------------------------------------------------------------------------------References: [ 1 ] Bug #1883244 - CVE-2020-26116 python27: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1883244 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-887d3fa26f' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . CVE-2021-26838 addressed in python36 for Fedora 34 to remedy improper validation in URL schemes.. Fedora Security Advisory, Python Package Update, CRLF Injection Fix, Software Vulnerability Management, HTTP Request Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 16, 2020 Critical Fedora
87

Debian DSA-4577-1 Critical: Haproxy CRLF Injection Threat

Tim Düsterhus discovered that haproxy, a TCP/HTTP reverse proxy, did not properly sanitize HTTP headers when converting from HTTP/2 to HTTP/1. This would allow a remote user to perform CRLF injections. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4577-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond November 28, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : haproxy CVE ID : CVE-2019-19330 Tim Düsterhus discovered that haproxy, a TCP/HTTP reverse proxy, did not properly sanitize HTTP headers when converting from HTTP/2 to HTTP/1. This would allow a remote user to perform CRLF injections. For the stable distribution (buster), this problem has been fixed in version 1.8.19-1+deb10u1. We recommend that you upgrade your haproxy packages. For the detailed security status of haproxy please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/haproxy Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . To improve your Debian system’s security and fix CRLF injection issues, upgrade HAProxy as per advisory DSA-4577-1 to safeguard against threats. HAProxy Security Update, Debian Security Advisory, CRLF Injection Issue, Proxy Security Fix, Remote Threat Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 28, 2019 Critical Debian
203

Mageia: 2019-0258 Critical: Python-urllib3 HTTP Header Issues

It was discovered that urllib3 incorrectly removed Authorization HTTP headers when handled cross-origin redirects. This could result in credentials being sent to unintended hosts (CVE-2018-20060). It was discovered that urllib3 incorrectly stripped certain characters . MGASA-2019-0258 - Updated python-urllib3 packages fix security vulnerability Publication date: 06 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0258.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-20060, CVE-2019-11236, CVE-2019-11324 It was discovered that urllib3 incorrectly removed Authorization HTTP headers when handled cross-origin redirects. This could result in credentials being sent to unintended hosts (CVE-2018-20060). It was discovered that urllib3 incorrectly stripped certain charactersfrom requests. A remote attacker could use this issue to perform CRLF injection (CVE-2019-11236). It was discovered that urllib3 incorrectly handled situations where a desired set of CA certificates were specified. This could result in certificates being accepted by the default CA certificates contrary to expectatons (CVE-2019-11324). The python-urllib3 package has been updated to version 1.24.3 to fix these issues and other bugs. The python-requests package has been fixed to work with the updated python-urllib3 References: - https://bugs.mageia.org/show_bug.cgi?id=23880 - https://ubuntu.com/security/notices/USN-3990-1 - https://www.cve.org/CVERecord?id=CVE-2018-20060 - https://www.cve.org/CVERecord?id=CVE-2019-11236 - https://www.cve.org/CVERecord?id=CVE-2019-11324 SRPMS: - 6/core/python-requests-2.11.1-2.2.mga6 - 6/core/python-urllib3-1.24.3-1.mga6 . Recent updates to the python-urllib3 library address critical security vulnerabilities that could lead to unauthorized access and code injection risks.. python-urllib3, security update, authorization headers, cross-origin. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 06, 2019 Critical Mageia
197

Debian 8 DLA-1749-1 Critical: Golang CRLF Injection Issue

It was discovered that there was a CRLF injection attack in the Go programming language runtime library. Passing \r\n to http.NewRequest could allow execution of arbitrary . Package : golang Version : 2:1.3.3-1+deb8u2 CVE ID : CVE-2019-9741 Debian Bug : #924630 It was discovered that there was a CRLF injection attack in the Go programming language runtime library. Passing \r\n to http.NewRequest could allow execution of arbitrary HTTP headers or Redis commands. For Debian 8 "Jessie", this issue has been fixed in golang version 2:1.3.3-1+deb8u2. We recommend that you upgrade your golang packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Crucial security alert: Golang has issued a patch fixing the CRLF injection vulnerability in Debian 8. Users are urged to upgrade to boost protection against risks. Golang Security, Debian Update, CRLF Injection, Go Runtime Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 03, 2019 Critical Debian LTS
89

Fedora 25: 2017-22f1a8404e Critical: Wget CRLF Injection Fix

Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-22f1a8404e 2017-06-02 17:35:06.904003 --------------------------------------------------------------------------------Name : wget Product : Fedora 25 Version : 1.18 Release : 3.fc25 URL : Summary : A utility for retrieving files using the HTTP or FTP protocols Description : GNU Wget is a file retrieval utility which can use either the HTTP or FTP protocols. Wget features include the ability to work in the background while you are logged out, recursive retrieval of directories, file name wildcard matching, remote file timestamp storage and comparison, use of Rest with FTP servers and Range with HTTP servers to retrieve files over slow or unstable connections, support for Proxy servers, and configurability. --------------------------------------------------------------------------------Update Information: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c --------------------------------------------------------------------------------References: [ 1 ] Bug #1429984 - CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c https://bugzilla.redhat.com/show_bug.cgi?id=1429984 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade wget' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore Fedora's recent patch for wget, which targets CVE-2017-6508 to fix CRLF injection vulnerabilities, boosting overall security.. wget Security Update,Fedora 25,CRLF Injection Fix,Update Information. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 03, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200