| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_6 03 Mar 2026 16:28:24
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python310 entry
gh-143935 has been committed upstream |
1.1_6 02 Mar 2026 18:02:02
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Amend sqlite entry
Fix vulnerable version range for sqlite-based ports (CVE-2025-7709)
PR: 292617
Reported by: jcfyecrayz@liamekaens.com (maintainer)
Reviewed by: fluffy@ |
1.1_6 27 Feb 2026 19:15:42
    |
Jesús Daniel Colmenares Oviedo (dtxdf)  |
security/vuxml: Add www/oauth2-proxy < 7.14.2 |
1.1_6 27 Feb 2026 18:06:53
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2026-2809
* CVE-2026-2808 |
1.1_6 27 Feb 2026 18:02:02
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2026-2795
* CVE-2026-2796
* CVE-2026-2797
* CVE-2026-2798
* CVE-2026-2799
* CVE-2026-2801
* CVE-2026-2802
* CVE-2026-2803
* CVE-2026-2804
* CVE-2026-2805
* CVE-2026-2806
* CVE-2026-2807
Changes to be committed: |
1.1_6 26 Feb 2026 13:28:11
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 25 Feb 2026 17:18:54
    |
Guido Falsi (madpilot)  |
security/vuxml: Document new mail/mailpit vulnerability |
1.1_6 25 Feb 2026 01:35:45
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2026-02-24
FreeBSD-SA-26:04.jail affects FreeBSD 13.5 and FreeBSD 14.3
FreeBSD-SA-26:05.route affects all supported versions of FreeBSD |
1.1_6 24 Feb 2026 07:28:13
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Vaultwarden vulnerabilities |
1.1_6 23 Feb 2026 00:22:11
    |
Daniel Engberg (diizzy)  Author: Matthias Andree |
security/vuxml: Add openexr < 3.4.5
Security: 716d25a6-0fdc-11f1-bfdf-ff9355aecb00 |
1.1_6 20 Feb 2026 19:48:29
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2026-02-18
Sponsored by: The FreeBSD Foundation |
1.1_6 20 Feb 2026 18:41:59
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerability
* CVE-2026-2447 |
1.1_6 19 Feb 2026 10:31:09
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 145.0.7632.109
Obtained
from: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_18.html |
1.1_6 17 Feb 2026 13:25:19
    |
Robert Nagy (rnagy)  |
security/vuxml: fix chromium version number in latest entry |
1.1_6 16 Feb 2026 17:29:38
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document vulnerability in dns/powerdns-recursor |
1.1_6 16 Feb 2026 16:18:42
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add png vulnerability
* CVE-2026-25646 |
1.1_6 14 Feb 2026 23:02:17
    |
Thomas Zander (riggs)  |
security/vuxml: Document TCP readTimeout bypass in traefik |
1.1_6 14 Feb 2026 18:24:30
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add munge vulnerability
* CVE-2026-25506
Reported by: Chris Dunlap <chris.m.dunlap@gmail.com> |
1.1_6 14 Feb 2026 18:15:01
    |
Fernando Apesteguía (fernape)  |
security/vuxml: make newentry: Fix providers init.
An init fail shouldn't exit the script.
Initialize registered providers only.
Use successfully initialized providers only.
Keep euvd for now although it's been down for the last few days. |
1.1_6 14 Feb 2026 16:45:22
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 144.0.7559.75
Obtained
from: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html |
1.1_6 13 Feb 2026 18:01:59
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python312 entry
CVE-2024-6923 fix has been committed upstream |
1.1_6 13 Feb 2026 09:30:39
    |
Fernando Apesteguía (fernape)  Author: Tomáš Čiernik |
security/vuxml: document expat vulnerabilities
* CVE-2026-24515
* CVE-2026-25210
PR: 293078 |
1.1_6 12 Feb 2026 15:07:39
    |
Palle Girgensohn (girgen)  |
security/vuxml: add info about PostgreSQL vulnerabilities |
1.1_6 12 Feb 2026 14:51:39
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb[78] vulnerabilities
* CVE-2026-1847
* CVE-2026-1849
* CVE-2026-1850
* CVE-2026-25610
* CVE-2026-25613 |
1.1_6 11 Feb 2026 07:46:32
    |
Matthias Fechner (mfechner)  |
security/vuxml: document Gitlab vulnerabilities |
1.1_6 11 Feb 2026 04:55:52
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA issued on 2026-02-10
FreeBSD-SA-26:03.blocklistd affects 15.0R |
1.1_6 09 Feb 2026 13:50:50
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix roundcube entry
mail/roundcube is php-flavorized
PR: 293058
Reported by: tomas@ciernik.sk
Fixes: a1ebf7d994441 |
1.1_6 09 Feb 2026 11:11:59
    |
Robert Nagy (rnagy)  |
security/vuxml: fix CVE ids for the latest chromium entry
Reported by: fernape@ |
1.1_6 09 Feb 2026 07:11:50
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 144.0.7559.132
Obtained
from: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html |
1.1_6 08 Feb 2026 10:25:27
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Roundcube vulnerabilities |
1.1_6 08 Feb 2026 06:21:25
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt6-webengine < 6.10.2 |
1.1_6 07 Feb 2026 17:37:42
    |
Jesús Daniel Colmenares Oviedo (dtxdf)  |
security/vuxml: Add multimedia/navidrome < 0.60.0 |
1.1_6 07 Feb 2026 11:28:58
    |
Thomas Zander (riggs)  |
security/vuxml: Document potential DoS in traefik |
1.1_6 05 Feb 2026 01:58:58
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python311 entry
Upstream are still reviewing and reworking the following:
- lang/python312: CVE-2024-6923
- lang/python310: gh-143935
Updated version ranges to be provided after those commits land there.
While here, remove nonexistent and EOL lang/python39 |
1.1_6 05 Feb 2026 00:14:28
    |
Matthias Andree (mandree)  |
security/vuxml: add python <3.14.3 <3.13.12 security issues
Security: CVE-2026-0865
Security: CVE-2026-1299
Security: bfe9adc8-0224-11f1-8790-c5fb948922ad |
1.1_6 30 Jan 2026 13:02:08
    |
Koichiro Iwao (meta)  |
security/vuxml: Document xrdp RCE vulnerability
Security: https://www.cve.org/CVERecord?id=CVE-2025-68670
Security: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-rwvg-gp87-gh6f |
1.1_6 29 Jan 2026 23:55:09
    |
Craig Leres (leres)  |
security/vuxml: populate missing <name> for security/zeek
Reported by: Dan Langille
Fixes: 03bfa3969e0d |
1.1_6 29 Jan 2026 22:44:39
    |
Craig Leres (leres)  |
security/vuxml: Mark security/zeek < 8.0.6 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v8.0.6
This release fixes the following potential DoS vulnerability:
- Zeek's HTTP analyzer can be tricked into interpreting Transfer-Encoding
or Content-Length headers set in MIME entities within HTTP bodies
and change the analyzer behavior.
Reported by: Tim Wojtulewicz |
1.1_6 29 Jan 2026 07:18:26
    |
Bernard Spil (brnrd)  |
security/vuxml: Update recent OpenSSL vulns
Was missing 2 CVEs. |
1.1_6 28 Jan 2026 16:57:09
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox vulnerabilities
* CVE-2026-24868
* CVE-2026-24869 |
1.1_6 28 Jan 2026 12:38:16
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 144.0.7559.109
Obtained
from: https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_27.html |
1.1_6 28 Jan 2026 01:15:48
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA issued on 2026-01-27
FreeBSD-SA-26:02.jail affects 13.5R and 14.3R |
1.1_6 28 Jan 2026 01:13:36
    |
Philip Paeps (philip)  |
security/vuxml: reference FreeBSD-SA-26:01.openssl
Add a reference to FreeBSD-SA-26:01.openssl (issued 2026-01-27) to the
vuxml entry for OpenSSL CVE-2025-11187, CVE-2025-15467, CVE-2025-15468,
CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418,
CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795 and
CVE-2026-22796.
FreeBSD-SA-26:01.openssl affects all supported versions of FreeBSD |
1.1_6 27 Jan 2026 15:31:11
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSL vulnerabilities |
1.1_6 26 Jan 2026 04:52:35
    |
Charlie Li (vishwin)  |
security/vuxml: update/simplify Python vulnerability version ranges
Event: Winter Field Day 2026
PR: 291609 |
1.1_6 24 Jan 2026 11:05:22
    |
Bernard Spil (brnrd)  |
security/vuxml: Add MySQL vulnerabilities |
1.1_6 22 Jan 2026 10:39:07
    |
Nicola Vitale (nivit)  |
security/vuxml: Add devel/py-wheel < 0.46.2 |
1.1_6 22 Jan 2026 09:19:28
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 144.0.7559.96
Obtained
from: https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_20.html |
1.1_6 21 Jan 2026 16:27:51
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 19 Jan 2026 18:01:25
    |
Guido Falsi (madpilot)  |
security/vuxml: Document multiple mail/mailpit vulnerabilities |
1.1_6 19 Jan 2026 00:07:39
    |
Jesús Daniel Colmenares Oviedo (dtxdf)  |
security/vuxml: Add www/oauth2-proxy < 7.14.1 |
1.1_6 16 Jan 2026 17:49:53
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2026-0892
* CVE-2026-0889
* CVE-2026-0888
* CVE-2026-0881
* CVE-2026-0891
* CVE-2026-0890
* CVE-2026-0887
* CVE-2026-0885
* CVE-2026-0884
* CVE-2026-0883
* CVE-2026-0878
* CVE-2026-0886
* CVE-2026-0882
* CVE-2026-0880
* CVE-2026-0879
* CVE-2026-0877 |
1.1_6 15 Jan 2026 20:26:18
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 144.0.7559.59
Obtained
from: https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_13.html |
1.1_6 12 Jan 2026 13:52:48
    |
Nicola Vitale (nivit)  |
security/vuxml: Add devel/py-virtualenv <= 20.36.0 |
1.1_6 11 Jan 2026 15:33:05
    |
Roman Bogorodskiy (novel)  |
security/vuxml: document libtasn1 vulnerability
Security: CVE-2025-13151 |
1.1_6 11 Jan 2026 09:10:32
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulerabilities |
1.1_6 10 Jan 2026 18:18:01
    |
Guido Falsi (madpilot)  |
security/vuxml: security/vuxml: Document mail/mailpit vulnerability
(CVE-2026-22689) |
1.1_6 10 Jan 2026 12:58:28
    |
Florian Smeets (flo)  |
security/vuxml: Record phpmyfaq vulenrabilities |
1.1_6 07 Jan 2026 14:54:50
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.192
Obtained
from: https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop.html |
1.1_6 07 Jan 2026 10:21:50
    |
Vsevolod Stakhov (vsevolod)  |
security/vuxml: Document libsodium vuln CVE-2025-69277 |
1.1_6 06 Jan 2026 22:44:13
    |
Guido Falsi (madpilot)  |
security/vuxml: Document mail/mailpit vulnerability (CVE-2026-21859) |
1.1_6 06 Jan 2026 15:44:49
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document nets-snmp vuln (CVE-2025-68615) |
1.1_6 04 Jan 2026 07:27:57
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1-plugins-bad < 1.26.10
Update for 2026. |
1.1_6 04 Jan 2026 00:18:22
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix 613d0f9e-d477-11f0-9e85-03ddfea11990 syntax
PR: 291609
Fixes: 119cc45cd5f2 security/vuxml: update lang/python312 entry
Sponsored by: The FreeBSD Foundation |
1.1_6 03 Jan 2026 23:33:18
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python312 entry
PR: 291609 |
1.1_6 03 Jan 2026 22:47:51
    |
Matthias Andree (mandree)  |
security/vuxml: revise libxslt ~1.1.43 advisory of 2025
Security: b0a3466f-5efc-11f0-ae84-99047d0a6bcc |
1.1_6 02 Jan 2026 16:07:06
    |
Matthias Andree (mandree)  |
security/vuxml: update security entry for libxslt
PR: 289213 |
1.1_6 30 Dec 2025 20:39:04
    |
Kai Knoblich (kai)  |
security/vuxml: Adjust version range for py-pdfminer.six
* The fix for CVE-2025-64512 introduced with release 20251107 was
incomplete. This has been remedied with release 20251230, adjust
the entry accordingly. |
1.1_6 29 Dec 2025 16:47:24
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add forgejo vulnerability
* CVE-2025-68937 |
1.1_6 27 Dec 2025 18:55:34
    |
Ronald Klop (ronald)  |
security/vuxml: MongoBleed is also in 8.0.16 and before
Fixes: a69bda1
Fixes: b587cd0
Security: CVE-2025-14847 |
1.1_6 25 Dec 2025 11:07:26
    |
Thomas Zander (riggs)  |
security/vuxml: Document use-after-free in fluidsynth |
1.1_6 24 Dec 2025 18:23:18
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Amend entry for Mongodb
The port is for mongodb 8.0 and not 8.2
Reported by: ronald-lists@klop.ws |
1.1_6 22 Dec 2025 09:21:17
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb{78}0 vulnerability
* CVE-2025-14847 |
1.1_6 21 Dec 2025 12:27:27
    |
Thomas Zander (riggs)  |
security/vuxml: Document k8s / nginx cert validation bypass in traefik |
1.1_6 21 Dec 2025 12:23:03
    |
Thomas Zander (riggs)  |
security/vuxml: Document vuln via special characters in traefik |
1.1_6 20 Dec 2025 17:53:29
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add smb4k vulnerabilities
* CVE-2025-66002
* CVE-2025-66003 |
1.1_6 20 Dec 2025 16:51:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox vulnerabilities
* CVE-2025-14860
* CVE-2025-14861 |
1.1_6 19 Dec 2025 09:10:23
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.146
Obtained
from: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html |
1.1_6 18 Dec 2025 15:20:57
    |
Dan Langille (dvl)  |
security/vuxml: Correct the step-cli vuln
It's not the client, it's only the server: step-certificates |
1.1_6 17 Dec 2025 14:15:37
    |
Dan Langille (dvl)  |
security/vuxml: add security/step-cli vuln
re: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=291741
PR: 291741 |
1.1_6 17 Dec 2025 01:43:45
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2025-12-17
FreeBSD-SA-25:11.ipfw affects FreeBSD 13.5 and FreeBSD 14.3
FreeBSD-SA-25:12.rtsold affects all supported versions of FreeBSD |
1.1_6 14 Dec 2025 09:42:11
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Roundcube vulnerabilitie |
1.1_6 13 Dec 2025 16:45:31
    |
Jesús Daniel Colmenares Oviedo (dtxdf)  |
security/vuxml: Add www/github-release-monitor < 1.4.1 |
1.1_6 12 Dec 2025 18:32:10
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document vulnerability in www/varnish-libvmod-digest |
1.1_6 12 Dec 2025 16:21:41
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2025-12-10
PR: 291580
Sponsored by: The FreeBSD Foundation |
1.1_6 12 Dec 2025 12:57:39
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add c-ares vulnerability
* CVE-2025-62408
PR: 291503
Reported by: polarian@polarian.dev |
1.1_6 12 Dec 2025 08:07:09
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.109
Obtained
from: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html |
1.1_6 11 Dec 2025 16:21:50
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mozilla, mongo vulnerabilities
* CVE-2025-14345
* CVE-2025-14333
* CVE-2025-14332
* CVE-2025-14331
* CVE-2025-14330
* CVE-2025-14329
* CVE-2025-14328
* CVE-2025-14327
* CVE-2025-14326
* CVE-2025-14325
* CVE-2025-14324
* CVE-2025-14323
* CVE-2025-14322
* CVE-2025-14321 |
1.1_6 11 Dec 2025 04:06:38
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 08 Dec 2025 21:15:42
    |
Matthias Andree (mandree)  |
security/vuxml: version Python vuln entries
Security: 613d0f9e-d477-11f0-9e85-03ddfea11990
Security: CVE-2025-12084
Security: CVE-2025-13836 |
1.1_6 08 Dec 2025 21:01:11
    |
Matthias Andree (mandree)  |
security/vuxml: add Python <3.13.11/<3.14.2 vulns
Security: 613d0f9e-d477-11f0-9e85-03ddfea11990
Security: CVE-2025-12084
Security: CVE-2025-13836 |
1.1_6 06 Dec 2025 10:05:30
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.40
Obtained
from: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop.html |
1.1_6 06 Dec 2025 08:31:43
    |
Nicola Vitale (nivit)  |
security/vuxml: Add audio/py-spotipy <= 2.25.1 |
1.1_6 05 Dec 2025 19:09:52
    |
Fernando Apesteguía (fernape)  Author: Polarian |
security/vuxml: Add xkbcomp vulnerabilities
* CVE-2018-15853
* CVE-2018-15859
* CVE-2018-15861
* CVE-2018-15863
PR: 291407
Reported by: Polarian <polarian@polarian.dev> |
1.1_6 05 Dec 2025 06:14:17
    |
Charlie Li (vishwin)  Author: Polarian |
security/vuxml: Out of bounds read in graphics/png
PR: 291266, 291410 |
1.1_6 04 Dec 2025 19:26:59
    |
Roman Bogorodskiy (novel)  |
security/vuxml: add entry for libvirt vulnerabilities
* CVE-2025-12748
* CVE-2025-13193 |
1.1_6 04 Dec 2025 17:46:49
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache httpd vulnerabilities |
1.1_6 04 Dec 2025 16:18:57
    |
Fernando Apesteguía (fernape)  Author: Einar Bjarni Halldórsson |
security/vuxml: Add entry for go124, go125
* CVE-2025-61729
PR: 291366
Reported by: einar@isnic.is |
1.1_6 01 Dec 2025 16:56:30
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb multiple vulnerabilities
* CVE-2025-13644
* CVE-2025-13507
* CVE-2025-13643 |
1.1_6 30 Nov 2025 21:57:25
    |
Santhosh Raju (fox)  |
security/vuxml: Document wolfSSL multiple vulnerabilities. |