Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash

Our news and updates

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Choose category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    9 Jun 2026 Business and Enterprise Solutions
    Joomla! Core: Transport Encryption Downgrade in Password/Username Reset Links

    In Joomla! Core versions 3.9.0 up to and including 5.4.5 and 6.0.0 up to and including 6.1.0 a critical severity vulnerability CVE-2026-48902 was detected. This vulnerability may allow network attackers to intercept sensitive account recovery tokens. This occurs because the password and username reset features improperly generate plain HTTP links, even for HTTPS connections, if the “Force SSL” configuration flag is not explicitly enabled. As a result, the reset links are transmitted without transport encryption, potentially leading to unauthorized account access. To address this issue, users should upgrade Joomla! Core to version 5.4.6 or 6.1.1 (or later) or explicitly enable the “Force SSL” setting. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-48902.

    Read more
    CMS
    9 Jun 2026 Data Management and Analytics
    Milvus: Use of Weak Hash in Grantee ID Hash Handler

    In Milvus versions up to 2.6.13 a medium severity vulnerability CVE-2026-10814 was detected. This vulnerability may allow a local attacker to compromise the system through the exploitation of a weak cryptographic hash. This occurs because the Grantee ID Hash Handler component (specifically in internal/metastore/kv/rootcoord/kv_catalog.go) utilizes a weak hashing algorithm, which an attacker could potentially manipulate, despite the attack complexity being high. To address this issue, users should apply the recommended patch (commit 3d932f1c3e065351c4440c27abe1e6479752544d). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10814.

    Read more
    Database
    9 Jun 2026 Data Management and Analytics
    MLflow: Use of Weak Hash in Dataset Digest Computation

    In MLflow versions up to 3.10.0 a low severity vulnerability CVE-2026-10803 was detected. This vulnerability may allow a local attacker to compromise dataset integrity or cause hash collisions. This occurs because the Dataset Digest Computation component (specifically the mlflow.data.digest_utils function in mlflow/data/digest_utils.py) utilizes a weak cryptographic hashing algorithm. Although the attack complexity is rated as high and exploitability is difficult, a proof of concept has been published. There is no fix to this yet. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10803.

    Read more
    Data Analytics
    8 Jun 2026 DevOps
    Zabbix: Unauthorized Host Creation via configuration.import API

    In Zabbix versions prior to 6.0.41, 7.0.18, and 7.4.2 a high severity vulnerability CVE-2026-23925 was detected. This vulnerability allows an authenticated low-privileged user to create unauthorized hosts, potentially leading to a loss of confidentiality. This occurs because a user with the basic “User” role and template/host write permissions can bypass standard role restrictions by utilizing the configuration.import API to create objects, an action that should normally be restricted for this role. To address this issue, users should upgrade Zabbix to version 7.4.2 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-23925.

    Read more
    Monitoring
    8 Jun 2026 DevOps
    OneDev: Improper Authorization via Forked Project ID

    In OneDev versions up to 15.0.5 a medium severity vulnerability CVE-2026-11438 was detected. This vulnerability allows a remote attacker to bypass intended access controls. This occurs due to improper authorization validation when manipulating the project.forkedFromId argument within the /projects functionality. To address this issue, users should upgrade OneDev to version 15.0.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11438.

    Read more
    Developer Tools
    8 Jun 2026 DevOps
    Django: Unencrypted Email Transmission after STARTTLS Failure

    In Django versions 6.0 before 6.0.6 and 5.2 before 5.2.15 a low severity vulnerability CVE-2026-7666 was detected. This vulnerability allows an on-path network attacker to intercept and read email content in cleartext. This occurs because the django.core.mail.backends.smtp.EmailBackend fails to prevent the reuse of a partially-initialized connection after a failed STARTTLS handshake when the fail_silently parameter is set to True. To address this issue, users should upgrade Django to versions 6.0.6 or 5.2.15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7666.

    Read more
    Application Development
    8 Jun 2026 Communication and Collaboration
    Discourse: Information Disclosure via Outdated Cached AI Summaries

    In Discourse versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1 a medium severity vulnerability CVE-2026-32244 was detected. This vulnerability allows anonymous and unprivileged users to view removed content, leading to information disclosure. This occurs because the platform caches outdated AI-generated summaries which are not adequately purged when the original content is deleted. Consequently, users who lack the permissions to regenerate summaries can still access the leaked information through the stale cache. To address this issue, users should upgrade Discourse to versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1. As a temporary workaround, administrators can restrict summary generation by tightening the allowed groups on the summarization Personas. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32244.

    Read more
    Communication
    8 Jun 2026 Data Management and Analytics
    MLflow: Artifact Overwrite and Arbitrary Code Execution via Multipart Upload Endpoints

    In MLflow versions up to 3.10.1.dev0 a critical severity vulnerability CVE-2026-2651 was detected. This vulnerability allows an attacker to overwrite artifacts belonging to other users, potentially leading to model supply chain poisoning and arbitrary code execution when compromised models are loaded. This occurs because the authorization logic fails to enforce resource-level permission checks for multipart upload (MPU) endpoints (/mlflow-artifacts/mpu/*) when the –serve-artifacts mode is enabled, enabling unauthorized cross-user writes. To address this issue, users should upgrade MLflow to version 3.10.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2651.

    Read more
    Data Analytics
    5 Jun 2026 Infrastructure and Network
    authentik: Account Takeover via Source Connection Manipulation

    In authentik versions prior to 2025.12.6, 2026.2.4, and 2026.5.1 a high severity vulnerability CVE-2026-49443 was detected. This vulnerability allows an attacker to log into any user’s account (Account Takeover). This occurs because an attacker who has the ability to change a source connection and possesses an account in one of the configured sources can exploit improper validation of the source connection to bypass authentication. To address this issue, users should upgrade authentik to versions 2025.12.6, 2026.2.4, or 2026.5.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-4944.

    Read more
    Security
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}