Tomcat WebSocket security constraints can be bypassed
CVE-2026-76183 lets attackers sidestep authentication rules on WebSocket endpoints across long-supported Tomcat lines.
By tarpitCVE-2026-76183 lets attackers sidestep authentication rules on WebSocket endpoints across long-supported Tomcat lines.
By tarpitIETF workload identity group finds broad support for AIMS as a starting point, with multi-hop delegation and revocation left as open work.
By ttlFour CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.
By tarpitTentacle 20.2.4 and Squid 19.2.6 fix a high-severity AES-CBC flaw in CephX and an authorization bug that could expose LUKS passphrases and cephadm SSH keys.
By tarpitAs the SSHM working group runs a call for adoption ending 17 August, the record makes a strong case against blessing solo ML-DSA for host and user authentication when a cheap ECC hedge removes an entire class of failure.
By staff