Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • Infrastructure and Network

Infrastructure and Network

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • Virtualization
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    10 Sep 2026 Infrastructure and Network
    Keycloak: Authorization flaw in keycloak-services component

    In the keycloak-services component for Keycloak in unpatched versions a medium severity vulnerability CVE-2026-79652 was detected. This vulnerability allows an authenticated attacker to bypass user consent requirements and gain unauthorized access. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-79652.

    Read more
    Security
    9 Sep 2026 Infrastructure and Network
    Keycloak: Insufficient Access Control Vulnerability

    In Keycloak in affected versions a medium severity vulnerability CVE-2025-68833 was detected. This vulnerability allows an attacker unauthorized access to resources. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68833.

    Read more
    Security
    2 Sep 2026 Infrastructure and Network
    Keycloak: Incorrect authorization in group policy provider

    In Keycloak versions prior to the latest patch a medium severity vulnerability CVE-2026-19608 was detected. This vulnerability allows an attacker to potentially bypass group-based access control policies. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19608.

    Read more
    Security
    2 Sep 2026 Infrastructure and Network
    Keycloak: Improper Authorization in Group Policy Provider

    In Keycloak a medium severity vulnerability CVE-2026-19608 was detected. This vulnerability allows an attacker to gain unauthorized access to protected resources. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19608.

    Read more
    Security
    26 Aug 2026 Infrastructure and Network
    FreeIPA: Unauthenticated Denial of Service via Unbounded Request Body Read

    In FreeIPA versions before 4.13.3 a high severity vulnerability CVE-2026-73197 was detected. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by exhausting system memory and disrupting service availability. This occurs due to an unbounded request body read flaw in the /ipa/migration/migration.py endpoint. When processing form POST requests, the migration handler reads the entire, attacker-controlled request body directly into memory without enforcing size limits. By sending oversized requests, an attacker can force excessive memory consumption and severely slow down request handling. There’s no fix available for this issue at the moment. . For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-73197.

    Read more
    Security
    25 Aug 2026 Infrastructure and Network
    Authentik: Privilege Escalation Vulnerability

    In Authentik versions 2026.5.6 and earlier a high severity vulnerability CVE-2026-72534 was detected. This vulnerability allows an attacker to gain superuser privileges. To address this issue, users should upgrade Authentik to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-72534.

    Read more
    Security
    19 Aug 2026 Infrastructure and Network
    OpenWebUI: Authentication Bypass Vulnerability

    In OpenWebUI versions 0.8.8 up to 0.11.0 a medium severity vulnerability CVE-2026-70490 was detected. This vulnerability allows an attacker to bypass user verification on terminal routes. To address this issue, users should upgrade OpenWebUI to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-70490.

    Read more
    Security
    5 Aug 2026 Infrastructure and Network
    Wazuh: Remote Code Execution Vulnerability

    In Wazuh versions prior to 4.14.5 a high severity vulnerability CVE-2026-28220 was detected. This vulnerability allows an authenticated actor to execute arbitrary code on the master node. To address this issue, users should upgrade Wazuh to version 4.14.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28220.

    Read more
    Security
    24 Jul 2026 Infrastructure and Network
    Zeek: Denial of Service Vulnerability

    In Zeek versions before 8.0.9 a high severity vulnerability CVE-2026-60109 was detected. This vulnerability allows unauthenticated remote attackers to cause a denial of service. To address this issue, users should upgrade Zeek to version 8.0.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60109.

    Read more
    Security
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}