Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • DevOps
  • Developer Tools

Developer Tools

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • Virtualization
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    11 Jun 2026 DevOps
    Jenkins: Information Disclosure via Missing Permission Checks

    In Jenkins versions 2.567 and earlier, and LTS 2.555.2 and earlier a medium severity vulnerability CVE-2026-53439 was detected. This vulnerability allows an attacker with Overall/Read permission to access sensitive user configuration data, leading to information disclosure. This occurs due to missing permission checks, which enable the attacker to determine other users’ configured timezones and enumerate the view names of other users’ “My Views”. To address this issue, users should upgrade Jenkins to a patched version 3.1.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-53439.

    Read more
    Developer Tools
    10 Jun 2026 DevOps
    Prefect: Authentication Bypass via Health Check Path Exemptions

    In Prefect version 3.6.19 a high severity vulnerability CVE-2026-3514 was detected. This vulnerability allows an unauthenticated attacker to bypass authentication and gain unauthorized access to sensitive information, such as API keys and database credentials. This occurs due to the improper handling of URL path exemptions for health check probes. The authentication middleware incorrectly exempts any URL path ending with ‘health’ or ‘ready’ from authentication checks. An attacker can exploit this by creating resources (such as variables, flows, work pools, work queues, and deployments) with names ending in ‘health’ or ‘ready’ to access them without authentication. To address this issue, users should upgrade Prefect to version 3.6.22 or higher. For more details, visit https://avd.aquasec.com/nvd/2026/cve-2026-3514.

    Read more
    Developer Tools
    10 Jun 2026 DevOps
    OneDev: Improper Authorization via Parent Project ID

    In OneDev versions up to 15.0.5 a medium severity vulnerability CVE-2026-11439 was detected. This vulnerability allows a remote attacker to bypass intended access controls. This occurs due to improper authorization validation when manipulating the project.parentId argument within the Parent Project Handler for the /projects/ functionality. To address this issue, users should upgrade OneDev to version 15.0.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11439.

    Read more
    Developer Tools
    8 Jun 2026 DevOps
    OneDev: Improper Authorization via Forked Project ID

    In OneDev versions up to 15.0.5 a medium severity vulnerability CVE-2026-11438 was detected. This vulnerability allows a remote attacker to bypass intended access controls. This occurs due to improper authorization validation when manipulating the project.forkedFromId argument within the /projects functionality. To address this issue, users should upgrade OneDev to version 15.0.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11438.

    Read more
    Developer Tools
    5 Jun 2026 DevOps
    Portainer Community Edition: Remote Code Execution via Missing Authorization on Docker Plugin Endpoints

    In Portainer Community Edition versions 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0 a high severity vulnerability CVE-2026-44848 was detected. This vulnerability allows a standard non-admin user with endpoint access to potentially achieve Remote Code Execution (RCE) on the host system. This occurs because the Docker plugin management endpoints (/plugins/*) lack proper authorization handler registration. As a result, standard users can bypass Resource Control access restrictions and directly call privileged operations, such as installing and enabling plugins, against the underlying Docker daemon. To address this issue, users should upgrade Portainer Community Edition to versions 2.33.8, 2.39.2, or 2.41.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44848.

    Read more
    Developer Tools
    3 Jun 2026 DevOps
    Kubernetes: Man-in-the-Middle (MitM) via LoadBalancer or ExternalIPs

    In Kubernetes (all versions) a medium severity vulnerability CVE-2020-8554 was detected. This vulnerability allows an attacker to intercept traffic intended for specific IP addresses, resulting in a Man-in-the-Middle (MitM) attack. This occurs because the Kubernetes API server allows users who can create a ClusterIP service to freely set the spec.externalIPs field. Additionally, an attacker with privileged access to patch the status of a LoadBalancer service can set the status.loadBalancer.ingress.ip field to achieve a similar effect. There’s no fix available for this issue at the moment. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2020-8554.

    Read more
    Developer Tools
    3 Jun 2026 DevOps
    Portainer Community Edition: Information Disclosure via Missing Authorization in Custom Templates

    In Portainer Community Edition versions 2.33.0 to before 2.33.8 and 2.39.1 a medium severity vulnerability CVE-2026-44884 was detected. This vulnerability allows any authenticated user to read the file content of any custom template, potentially exposing sensitive environment-specific values such as connection strings, API tokens, or registry credentials. This occurs due to missing authorization checks in the Custom Template file endpoint (GET /api/custom_templates/{id}/file), enabling users to bypass Resource Control access restrictions by enumerating sequential integer IDs. To address this issue, users should upgrade Portainer Community Edition to versions 2.33.8 or 2.39.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44884.

    Read more
    Developer Tools
    2 Jun 2026 DevOps
    GitLab EE: Authorization Bypass Through User-Controlled Key in Duo AI Workflows

    In GitLab EE versions 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 a high severity vulnerability CVE-2026-4868 was detected. This vulnerability allows an authenticated user to cause specific Duo AI workflows to run under another user’s identity. This occurs due to an authorization bypass caused by improper user identity resolution when triggering Duo AI workflow runners. To address this issue, users should upgrade GitLab EE to versions 18.10.7, 18.11.4, or 19.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-4868.

    Read more
    Developer Tools
    2 Jun 2026 DevOps
    Portainer Community Edition: Arbitrary File Read via Git Symlink Injection

    In Portainer Community Edition versions 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0 a high severity vulnerability CVE-2026-44881 was detected. This vulnerability allows an authenticated user with rights to create or update a Git-backed stack to read arbitrary files on the host filesystem that are accessible to the Portainer process. This occurs because Portainer clones Git repositories using a library that translates symlink entries into real OS symlinks without adequate validation. When the stack entry point (such as docker-compose.yml) is a symlink pointing to an arbitrary path, the API endpoint reading this file transparently follows the symlink and returns the target file’s contents in the HTTP response. To address this issue, users should upgrade Portainer Community Edition to versions 2.33.8, 2.39.2, or 2.41.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44881.

    Read more
    Developer Tools
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}