tls
38 articles with this tag
INFO
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
INFO
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
CRITICAL
MEDIUM
MEDIUM
CRITICAL
INFO
CRITICAL
LOW
LOW
LOW
INFO
HIGH
MEDIUM
HIGH
HIGH
LOW
INFO
MEDIUM
INFO
INFO
INFO
INFO
MEDIUM
Post-quantum authentication to origins is now supported
CVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tls
Confidential computing's remote attestation protocol may have fundamental flaw
CVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
USN-8487-1: curl vulnerabilities
FreeBSD-EN-26:17.rpcsec_tls
RHSA-2026:32962: Important: gnutls security update
CVE-2026-9697 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
USN-8431-1: Ruby vulnerabilities
[NEU] [hoch] OpenSSL: Mehrere Schwachstellen
RHSA-2026:22713: Important: rhc security update
RHSA-2026:22130: Important: rhc security update
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
CVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation
RHSA-2026:20611: Important: gnutls security update
Critical Exim vulnerability allows remote code execution
CVE-2026-42246 net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-31533 net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
[NEU] [hoch] GnuTLS: Mehrere Schwachstellen
CVE-2026-34477 Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Microsoft to block legacy TLS connections for POP and IMAP in Exchange Online
Microsoft to deprecate legacy TLS in Exchange Online starting July
TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates
CVE-2026-23414 tls: Purge async_hold in tls_decrypt_async_wait()
Protecting your secrets from tomorrow’s quantum risks
CVE-2026-21637 HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers
CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
[NEU] [UNGEPATCHT] [hoch] GnuTLS: Schwachstelle ermöglicht Denial of Service
Certificate lifespans are shrinking and most organizations aren’t ready
Chrome Is Thinking Quantum - Threat Wire
VU#772695: A flawed TLS handshake implementation affects Viber Proxy in multiple platforms
Google and Cloudflare testing Merkel Tree Certificates instead of normal signatures for TLS
Google Working Towards Quantum-Safe Chrome HTTPS Certificates
Cultivating a robust and efficient quantum-safe HTTPS
How likely is a man-in-the-middle attack?
Tenable Discovers SSRF Vulnerability in Java TLS Handshakes That Creates DoS Risk