| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_6 21 Jul 2026 20:54:12
    |
Daniel Engberg (diizzy)  |
security/vuxml: Add entry for giflib CVE-2026-26740 |
1.1_6 21 Jul 2026 07:26:50
    |
Yuri Victorovich (yuri)  |
security/vuxml: Add vulnerability records for CVEs fixed in www/srt
* CVE-2026-55869
* CVE-2026-55868 |
1.1_6 20 Jul 2026 16:55:21
    |
Bernard Spil (brnrd)  |
security/vuxml: Fix version in previous Weechat vuln |
1.1_6 20 Jul 2026 16:53:53
    |
Bernard Spil (brnrd)  |
security/vuxml: Register Weechat vulnerabilities |
1.1_6 20 Jul 2026 06:53:36
    |
Guido Falsi (madpilot)  |
security/vuxml: Document new mailpit vulnerability |
1.1_6 19 Jul 2026 11:52:12
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document vulnerabilities in Tailscale |
1.1_6 18 Jul 2026 13:00:54
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in traefik |
1.1_6 18 Jul 2026 10:12:32
    |
Florian Smeets (flo)  |
security/vuxml: Add phpmyfaq vulnerabilities |
1.1_6 18 Jul 2026 05:28:36
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document nginx multiple vulnerabilities
PR: 296830
Sponsored by: Netzkommune GmbH |
1.1_6 16 Jul 2026 08:30:41
    |
Bernard Spil (brnrd)  |
security/vuxml: Document liboqs vulnerabilities |
1.1_6 14 Jul 2026 15:56:22
    |
Sergey A. Osokin (osa)  |
security/vuxml: fix warning for the ffmpeg record |
1.1_6 14 Jul 2026 15:08:33
    |
Sergey A. Osokin (osa)  |
security/vuxml: fix package name
Fixes: 25fdff6924a2ffc740d7102a0940c896cc8c35d0 |
1.1_6 14 Jul 2026 13:07:04
    |
Kousuke Kannagi (mce)  |
security/vuxml: Document Poppler vulnerability
PR: 296769
Approved by: osa (mentor)
Security: CVE-2026-10118 |
1.1_6 14 Jul 2026 10:43:14
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Add devel/ocaml-opam vulnerability
While here, fix whitespaces of two previous entries after the
feedback of `make validate`.
PR: 296642
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 10 Jul 2026 13:34:23
    |
Ronald Klop (ronald)  |
security/vuxml: fix the version of *-commons-httpclient
I learned that <eq> does not match portrevision, so <ge> works better.
And CVE-2020-13956 only mentions 3.1 and later and not earlier CPE versions. |
1.1_6 10 Jul 2026 13:18:13
    |
Ronald Klop (ronald)  |
security/vuxml: also mention the predecessor package name of
apache-commons-httpclient |
1.1_6 10 Jul 2026 12:47:20
    |
Ronald Klop (ronald)  |
security/vuxml: add some CVEs for Apache HttpClient |
1.1_6 09 Jul 2026 06:55:21
    |
Guido Falsi (madpilot)  |
security/vuxml: Report new mail/mailpit vulnerabilities |
1.1_6 09 Jul 2026 04:33:46
    |
Matthias Fechner (mfechner)  |
security/vuxml: document Gitlab vulnerabilities |
1.1_6 08 Jul 2026 21:10:16
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document libXfont2 vulnerabilities
Sponsored by: tipi.work |
1.1_6 08 Jul 2026 16:41:03
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document xwayland vulnerabilities |
1.1_6 08 Jul 2026 14:01:49
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document xorg-server vulnerabilities |
1.1_6 07 Jul 2026 16:49:44
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add net-mgmt/cacti vuln entries |
1.1_6 07 Jul 2026 07:25:27
    |
Koichiro Iwao (meta)  |
security/vuxml: Document net/xrdp{,-devel} vulnerabilities |
1.1_6 06 Jul 2026 22:59:53
    |
Craig Leres (leres)  |
security/vuxml: Mark security/zeek < 8.0.9 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v8.0.9
This release fixes the following potential DoS vulnerabilities:
- The NVT, Rlogin, and RSH analyzers have received fixes to avoid
unbounded state growth. Due to the fact that these packets can
be received from remote hosts, these are considered DoS risks.
- A specially crafted WebSocket payload can cause the Spicy WebSocket
analyzer to use excessive memory when processing close, ping,
and pong frames. Due to the fact that these packets can be
received from remote hosts, these are considered a DoS risk.
(Only the first 15 lines of the commit message are shown above ) |
1.1_6 06 Jul 2026 04:27:51
    |
Joseph Mingrone (jrm)  |
security/vuxml: Document Emacs vulnerability
PR: 296546
Security: CVE-2026-6861
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Jul 2026 16:12:22
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Weechat vulnerability |
1.1_6 05 Jul 2026 16:01:32
    |
Bernard Spil (brnrd)  |
security/roundcube: Document vulnerabilities |
1.1_6 04 Jul 2026 14:09:19
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in traefik |
1.1_6 04 Jul 2026 09:07:39
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add www/p5-CGI-Session security fixes |
1.1_6 03 Jul 2026 06:32:00
    |
Gleb Popov (arrowd)  Author: Matthias Andree |
security/vuxml: add security/openvpn[-devel] vuln entries.
Aligned with Gert Doering for openvpn-devel.
PR: 296429
Security: ffa897a0-756f-11f1-b291-a74de6bb0320
Security: CVE-2026-11771
Security: CVE-2026-12932
Security: CVE-2026-12996
Security: CVE-2026-13117
Security: CVE-2026-13122
Security: CVE-2026-13698
Pull Request: https://github.com/freebsd/freebsd-ports/pull/550 |
1.1_6 03 Jul 2026 06:31:59
    |
Gleb Popov (arrowd)  Author: Matthias Andree |
security/vuxml: Fix invalid escape sequence in Python re
ports/security/vuxml/files/extra-validation.py:13:
SyntaxWarning: invalid escape sequence '\|'
re_invalid_package_name = re.compile('[@!#$%^&*()<>?/\|}{~:]')
This can be fixed by making the re.compile argument a raw R'...' string,
capital R avoids issues with some Microsoft IDEs.
(Alternative is doubling the backslash, but that's less readable.)
Pull Request: https://github.com/freebsd/freebsd-ports/pull/550 |
1.1_6 02 Jul 2026 07:44:52
    |
Piotr Smyrak (smyru)  |
security/vuxml: extend ffmpeg announcement to ffmpeg4 and ffmpeg6
Approved by: 0mp (mentor)
Reviewed by: fernape
Security: CVE-2026-8461 |
1.1_6 02 Jul 2026 06:03:50
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 150.0.7871.46
Obtained
from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html |
1.1_6 01 Jul 2026 00:38:02
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2026-06-30
FreeBSD-SA-26:37.vm affects all supported releases
FreeBSD-SA-26:38.jail affects 15.0R and 15.1R
FreeBSD-SA-26:39.execve affects all supported releases
FreeBSD-SA-26:40.zfs affects all supported releases
FreeBSD-SA-26:41.libalias affects all supported releases
FreeBSD-SA-26:42.unlinkat affects all supported releases
FreeBSD-SA-26:43.tcp affects all supported releases
FreeBSD-SA-26:44.posixshm affects all supported releases
FreeBSD-SA-26:45.audit affects all supported releases
FreeBSD-SA-26:46.ktls affects all supported releases
FreeBSD-SA-26:47.linux affects 14.3R, 14.4R and 15.0R
FreeBSD-SA-26:48.compat32 affects 14.3R, 14.4R and 15.0R
FreeBSD-SA-26:49.iconv affects all supported releases |
1.1_6 30 Jun 2026 16:46:45
    |
Florian Smeets (flo)  |
security/vuxml: Document net-mgmt/icinga2 vulnerabilities |
1.1_6 30 Jun 2026 11:11:40
    |
Palle Girgensohn (girgen)  |
security/vuxml: Document databases/postgresql-jdbc vulnerability |
1.1_6 30 Jun 2026 10:59:41
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 149.0.7827.200
Obtained
from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html |
1.1_6 29 Jun 2026 16:28:35
    |
Yusuf Yaman (nxjoseph)  Author: Jaap Akkerhuis |
security/vuxml: Document dns/nsd vulnerabilities
PR: 296375
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 13:07:14
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document net/rclone vulnerability
PR: 296192
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 12:32:18
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/powerdns vulnerabilities
PR: 296312
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 11:14:13
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/powerdns-recursor vulnerabilities
PR: 296313
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 10:07:44
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/dnsdist vulnerabilities
PR: 296314
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 09:04:18
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1* < 1.28.4 |
1.1_6 28 Jun 2026 18:45:30
    |
Sergey A. Osokin (osa)  |
security/vuxml: document expat2 vulberabilities
Sponsored by: tipi.work |
1.1_6 28 Jun 2026 14:27:32
    |
Yusuf Yaman (nxjoseph)  Author: ports@foss-daily.org |
security/vuxml: Document www/gitea vulnerabilities
PR: 296351
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 27 Jun 2026 12:39:32
    |
Piotr Smyrak (smyru)  |
security/vuxml: document ffmpeg vulnerability
Approved by: 0mp (mentor)
Approved by: fernape
Security: CVE-2026-8461
Differential Revision: https://reviews.freebsd.org/D57843 |
1.1_6 26 Jun 2026 04:41:08
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 24 Jun 2026 14:59:22
    |
Bernard Spil (brnrd)  |
security/vuxml: Document go-git vulnerability |
1.1_6 24 Jun 2026 10:38:03
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/{ldns,py-ldns} vulnerability
PR: 296232
Approved by: osa, vvd (Mentors, implicit)
Security: CVE-2026-10846 |
1.1_6 23 Jun 2026 10:37:01
    |
Dave Cottlehuber (dch)  |
security/vuxml: Document podman vulnerability
Reviewed by: dfr
Sponsored by: SkunkWerks, GmbH
Differential Revision: https://reviews.freebsd.org/D57736 |
1.1_6 21 Jun 2026 13:00:15
    |
Bernard Spil (brnrd)  |
security/vuxml: Fix month error on latest MariaDB entry |
1.1_6 20 Jun 2026 06:39:47
    |
Jason E. Hale (jhale)  |
security/vuxml: Unbreak 'validate' target
73ebb85ec34a introduced basic CVE ID checking, which is fantastic. It
kind of broke the 'validate' target for a sane VuXML DB, though.
This fixes the 'validate' target keeping to the orginal idea and with
pretty-print as an added bonus. |
1.1_6 19 Jun 2026 13:32:41
    |
Piotr Smyrak (smyru)  |
security/vuxml: refuse non CVE vuln IDs in validate target
PR: 295994
Approved by: 0mp (mentor)
Reviewed by: 0mp, fernape, philip
Differential Revision: https://reviews.freebsd.org/D57539 |
1.1_6 19 Jun 2026 04:21:14
    |
Charlie Li (vishwin)  |
security/vuxml: fix lang/python311 version typo
Event: BSDCan 2026 |
1.1_6 19 Jun 2026 04:16:15
    |
Charlie Li (vishwin)  |
security/vuxml: update python entries with upstream commits
Event: BSDCan 2026 |
1.1_6 18 Jun 2026 15:19:19
    |
Jochen Neumeister (joneum)  |
security/vuxml: Add entry for NGINX
Add entry for NGINX
Sponsored by: Netzkommune GmbH |
1.1_6 17 Jun 2026 20:17:56
    |
Jochen Neumeister (joneum)  |
security/vuxml: fix NGINX entry again
That's what happens when you're not focused.
Edit the entry again, since it's for nginx-devel
Sponsored by: Netzkommune GmbH |
1.1_6 17 Jun 2026 20:02:26
    |
Jochen Neumeister (joneum)  |
security/vuxml: fix NGINX entry
Fix NGINX entry
Sponsored by: Netzkommune GmbH |
1.1_6 17 Jun 2026 19:58:44
    |
Jochen Neumeister (joneum)  |
security/vuxml: add entry for NGINX
Add entry for NGINX
Sponsored by: Netzkommune GmbH |
1.1_6 17 Jun 2026 17:18:10
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2026-06-10
Sponsored by: The FreeBSD Foundation |
1.1_6 17 Jun 2026 14:40:58
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document net/routinator vulnerabilities
PR: 295979
Security: CVE-2026-49232
Security: CVE-2026-49233
Security: CVE-2026-49234
Security: CVE-2026-49235
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 17 Jun 2026 07:35:45
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 149.0.7827.155 + fix prev version
Obtained
from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html |
1.1_6 17 Jun 2026 06:52:38
    |
Guido Falsi (madpilot)  |
security/vuxml: Report mailpit vulnerability |
1.1_6 15 Jun 2026 12:00:35
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 149.0.7827.114
Obtained
from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html |
1.1_6 14 Jun 2026 22:09:37
    |
Sergey A. Osokin (osa)  |
security/vuxml: improve recent change
Fixes: a90e0c311e44e5916df1d0b26f288bac063d1688 |
1.1_6 14 Jun 2026 21:53:08
    |
Kousuke Kannagi (mce)  |
security/vuxml: Add libsmi 0.4.8 vulnerability
PR: 295866
Approved by: osa (mentor) |
1.1_6 14 Jun 2026 06:28:02
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in net/traefik |
1.1_6 13 Jun 2026 22:39:21
    |
Adam Weinberger (adamw)  |
security/vuxml: Add caddy < 2.11.4 |
1.1_6 12 Jun 2026 04:50:03
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 11 Jun 2026 23:01:44
    |
Dave Cottlehuber (dch)  |
security/vuxml: Document h2o vulnerabilities
Sponsored by: SkunkWerks, GmbH |
1.1_6 11 Jun 2026 08:04:14
    |
Philip Paeps (philip)  |
security/vuxml: remove bogus <cvename/s> tags
Unbreak the vuxml build (again).
Fixes: 81a6669e034d07e3db13eff0688b32365ceff302 |
1.1_6 11 Jun 2026 01:49:13
    |
Jimmy Olgeni (olgeni)  |
security/vuxml: Document Erlang/OTP June 2026 vulnerabilities |
1.1_6 10 Jun 2026 12:41:40
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: Document p5-ack vulnerabilities |
1.1_6 10 Jun 2026 11:22:41
    |
Piotr Smyrak (smyru)  |
security/vuxml: document devel/tree-sitter-cli vulnerabilities
PR: 294982
Approved by: 0mp
Differential Revision: https://reviews.freebsd.org/D57502 |
1.1_6 10 Jun 2026 09:25:07
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSL vulnerabilities |
1.1_6 10 Jun 2026 08:00:34
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 149.0.7827.102
Obtained
from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html |
1.1_6 10 Jun 2026 02:59:06
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2026-06-09
FreeBSD-SA-26:25.thr affects all supported releases
FreeBSD-SA-26:26.ktls affects all supported releases
FreeBSD-SA-26:27.sound affects all supported releases
FreeBSD-SA-26:28.capsicum affects all supported releases
FreeBSD-SA-26:29.ip6_multicast affects all supported releases
FreeBSD-SA-26:30.linux affects all supported releases
FreeBSD-SA-26:31.arm64 affects all supported releases
FreeBSD-SA-26:32.elf affects all supported releases
FreeBSD-SA-26:33.unbound affects all supported releases
FreeBSD-SA-26:34.vt affects all supported releases
FreeBSD-SA-26:35.openssl affects all supported releases
FreeBSD-SA-26:36.ldns affects all supported releases |
1.1_6 09 Jun 2026 21:29:43
    |
Dave Cottlehuber (dch)  |
security/vuxml: Document Elixir vulnerabilities
- CVE-2026-49762, GHSA-w2h8-8x3g-278p
References:
https://github.com/elixir-lang/elixir/releases/tag/v1.20.1
Sponsored by: SkunkWerks, GmbH |
1.1_6 08 Jun 2026 21:10:23
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache httpd 2.4.67 vulnerabilities |
1.1_6 08 Jun 2026 18:33:18
    |
R. Christian McDonald (rcm)  |
security/vuxml: Document multiple Unbound vulnerabilities
* CVE-2026-32792
* CVE-2026-33278
* CVE-2026-40622
* CVE-2026-41292
* CVE-2026-42534
* CVE-2026-42923
* CVE-2026-42944
* CVE-2026-42959
* CVE-2026-42960
* CVE-2026-44390
* CVE-2026-44608
References:
https://www.nlnetlabs.nl/projects/unbound/security-advisories/
PR: 295442
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 08 Jun 2026 17:24:09
    |
R. Christian McDonald (rcm)  |
security/vuxml: Add entry for strongSwan CVE-2026-47895
PR: 295936
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 07 Jun 2026 09:02:52
    |
Bernard Spil (brnrd)  |
security/vuxml: Document WeeChat 4.9.0 vulnerabilities |
1.1_6 07 Jun 2026 08:55:11
    |
Bernard Spil (brnrd)  |
security/vuxml: Document WeeChat vulnerabilities |
1.1_6 06 Jun 2026 05:08:24
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 06 Jun 2026 01:23:46
    |
Sergey A. Osokin (osa)  |
security/vuxml: add CVEs for xorg-server and xwayland
Sponsored by: tipi.work |
1.1_6 04 Jun 2026 21:01:17
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix nginx entry
PR: 295797
Reported by: tomas@ciernik.sk and others |
1.1_6 04 Jun 2026 18:58:21
    |
Florian Smeets (flo)  |
security/vuxml: Document PowerDNS vulnerabilities |
1.1_6 04 Jun 2026 08:15:04
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache DoS vulnerability |
1.1_6 04 Jun 2026 00:52:50
    |
Philip Paeps (philip)  |
security/vuxml: remove bogus <cvename/> references
ZDI-CAN-* references are not CVEs. They are internal references from a
security company. CVEs that don't exist upset the vuxmlbuild. |
1.1_6 02 Jun 2026 01:37:15
    |
Sergey A. Osokin (osa)  |
security/vuxml: add xwayland vulnerabilities
Sponsored by: tipi.work |
1.1_6 02 Jun 2026 01:21:51
    |
Sergey A. Osokin (osa)  |
security/vuxml: add xorg-server vulnerabilities |
1.1_6 02 Jun 2026 01:12:20
    |
Sergey A. Osokin (osa)  |
security/vuxml: fix x11-servers/xorg-server's PORTEPOCH
% make -V PORTEPOCH -f /usr/ports/x11-servers/xorg-server/Makefile
1
Sponsored by: tipi.work |
1.1_6 31 May 2026 16:12:33
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix nginx entry
The range seems wrong according to https://nginx.org/en/CHANGES:
Changes with nginx 1.31.1 22 May 2026
*) Security: a heap memory buffer overflow might occur in a worker
process when using a configuration with overlapping captures in
ngx_http_rewrite_module, potentially resulting in arbitrary code
execution (CVE-2026-9256).
Thanks to Mufeed VH of Winfunc Research. |
1.1_6 30 May 2026 12:44:19
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 148.0.7778.215
Obtained
from: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html |
1.1_6 30 May 2026 09:12:34
    |
Bernard Spil (brnrd)  |
security/vuxml: Add missing PORTEPOCH for many entries
fixes portepoch warnings from `make validate`
While here: fix some whitespace |
1.1_6 30 May 2026 08:52:12
    |
Bernard Spil (brnrd)  |
security/vuxml: Only MariaDB Cluster vulnerable |
1.1_6 30 May 2026 08:43:05
    |
Bernard Spil (brnrd)  |
security/vuxml: Add missing CVE for MariaDB |
1.1_6 29 May 2026 21:33:24
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add www/gohugo vulnerabilities
* CVE-2026-39826
* CVE-2026-39823 |
1.1_6 29 May 2026 12:58:27
    |
Bernard Spil (brnrd)  |
security/vuxml: Document MariaDB vulnerabilities |