| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_6 29 Aug 2026 16:38:42
    |
Vasil Dimov (vd)  |
security/vuxml: document net-p2p/c-lightning vulnerabilities |
1.1_6 28 Aug 2026 21:03:40
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document phpBB vulnerabilities
Sponsored by: Netzkommune GmbH |
1.1_6 28 Aug 2026 13:23:04
    |
Dave Cottlehuber (dch)  |
security/vuxml: Document Elixir vulnerabilities
Sponsored by: SkunkWerks, GmbH |
1.1_6 28 Aug 2026 10:51:27
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/nsd vulnerabilities
PR: 297994
Reported by: Jaap Akkerhuis <jaap@NLnetLabs.nl> (maintainer)
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 28 Aug 2026 04:50:42
    |
Matthias Fechner (mfechner)  |
security/vuxml: document Gitlab vulnerabilities |
1.1_6 27 Aug 2026 17:58:39
    |
Guido Falsi (madpilot)  |
security/vuxml: Document new php-composer vulnerabilities |
1.1_6 26 Aug 2026 21:09:25
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: Document rsync vulnerability |
1.1_6 26 Aug 2026 11:11:03
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document matrix-conduit vulnerability |
1.1_6 26 Aug 2026 04:16:57
    |
Philip Paeps (philip)  |
security/vuxml: correct a tpyo
FreeBSD-SA-26:61.openssl not FreeBSD-SA-26:62.openssl.
Fixes: 6caee4041ace ("security/vuxml: reference
FreeBSD-SA-26:61.openssl")
Pointy hat to: philip |
1.1_6 26 Aug 2026 04:08:06
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2026-08-25
FreeBSD-SA-26:56.hwpmc affects all supported releases
FreeBSD-SA-26:57.unix affects 15.0R and 15.1R
FreeBSD-SA-26:58.sound affects all supported releases
FreeBSD-SA-26:59.mac_do affects 15.0R and 15.1R
FreeBSD-SA-26:60.ppp affects all supported releases
FreeBSD-SA-26:62.tty affects all supported releases
FreeBSD-SA-26:63.posixshm affects all supported releases |
1.1_6 26 Aug 2026 04:08:06
    |
Philip Paeps (philip)  |
security/vuxml: reference FreeBSD-SA-26:61.openssl
Add a reference to FreeBSD-SA-26:61.openssl (issued 2026-08-25) to the
vuxml entry for OpenSSL CVE-2026-14457, CVE-2026-18798, CVE-2026-54874,
CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075 and
CVE-2026-63076
FreeBSD-SA-26:61.openssl affects all supported versions of FreeBSD |
1.1_6 26 Aug 2026 04:08:06
    |
Philip Paeps (philip)  |
security/vuxml: remove duplicate OpenSSL entry
Reference FreeBSD-SA-26:35.openssl in the existing entry for OpenSSL
CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181,
CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-42766,
CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770,
CVE-2026-45445, CVE-2026-45446 and CVE-2026-45447 instead of duplicating
the entry.
FreeBSD-SA-26:35.openssl affected all supported versions of FreeBSD. |
1.1_6 25 Aug 2026 18:16:03
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSL vulnerabilities |
1.1_6 25 Aug 2026 08:56:26
    |
Bernard Spil (brnrd)  |
security/vuxml: Document MariaDB vulnerabilities |
1.1_6 24 Aug 2026 10:04:33
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document mod_gnutls -- multiple vulnerabilities
CVE-2026-33307 is an out-of-bounds write when mod_gnutls receives a client
certificate chain longer than its buffer, CVE-2026-33308 a missing Key
Purpose check during client certificate verification. Upstream fixed both
on 2026-03-20; in the tree the fix arrives with www/mod_gnutls 0.13.0.
Sponsored by: Netzkommune GmbH |
1.1_6 23 Aug 2026 17:48:29
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document jackson vulnerabilities
jackson-databind before 2.22.2 by-passes @JsonView and @JsonIgnore in
several ways and validates polymorphic types incompletely, jackson-core
before 2.22.2 can be driven past StreamReadConstraints.
Security: 0cb401f9-9f19-11f1-a655-3497f65b111b
Security: 0cb42b4a-9f19-11f1-a655-3497f65b111b
Sponsored by: Netzkommune GmbH |
1.1_6 23 Aug 2026 17:34:55
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in traefik |
1.1_6 21 Aug 2026 17:02:28
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document terraform exclusion bypass
go-slug before v0.18.3, bundled in terraform, does not consistently
match .terraformignore rules against canonically equivalent Unicode
filenames, so files meant to be excluded can end up in uploads to
HCP Terraform or Terraform Enterprise. Fixed in terraform 1.15.9.
Security: CVE-2026-14978
Sponsored by: Netzkommune GmbH |
1.1_6 21 Aug 2026 10:57:21
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document tailscale vulnerability |
1.1_6 21 Aug 2026 01:44:09
    |
Jason E. Hale (jhale)  |
security/vuxml: Document qt6-webengine < 6.11.2 |
1.1_6 20 Aug 2026 14:36:41
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 151.0.7922.169
Obtained
from: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html |
1.1_6 19 Aug 2026 20:01:50
    |
Craig Leres (leres)  |
security/vuxml: Mark security/zeek < 8.0.10 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v8.0.10
This release fixes the following vulnerabilities:
- HIGH: SMB: Chains of AndX messages can crash Zeek
- HIGH: DNP3: Memory exhaustion via file control (g70v1) fields
- HIGH: SIP: Memory exhaustion from long request/response paths
- HIGH: DHCP: Memory exhaustion from retained options after analyzer
violation
(Only the first 15 lines of the commit message are shown above ) |
1.1_6 19 Aug 2026 03:14:24
    |
Sergey A. Osokin (osa)  |
security/vuxml: document podman vulnerability
Sponsored by: tipi.work |
1.1_6 18 Aug 2026 05:07:57
    |
Matthias Fechner (mfechner)  |
security/vuxml: document Gitlab vulnerabilities |
1.1_6 16 Aug 2026 18:31:22
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document gitea < 1.27.0 vulnerabilities
Gitea 1.27.0 fixed 45 security issues, including privilege
escalation, remote denial of service, SSRF, authorization and
token scope bypasses, and information disclosure.
Sponsored by: Netzkommune GmbH |
1.1_6 16 Aug 2026 17:03:01
    |
Palle Girgensohn (girgen)  |
security/vuxml: Add databases/postgreql??-* vulnerabilities |
1.1_6 15 Aug 2026 03:12:13
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python31{0,1} entries for new releases |
1.1_6 15 Aug 2026 02:48:03
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python315 poplib entry
Commit existed since 3.15.0.a6 |
1.1_6 14 Aug 2026 10:07:56
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document security/openexr < 3.4.14 multiple vulnerabilities
PR: 297486
Reported by: mandree
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 13 Aug 2026 13:51:47
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 13 Aug 2026 07:29:20
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 151.0.7922.{108,137}
Obtained
from: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01193673229.html
Obtained
from: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01815628406.html |
1.1_6 12 Aug 2026 20:32:38
    |
Florian Smeets (flo)  |
security/vuxml: Add phpmyfaq vulnerabilities |
1.1_6 11 Aug 2026 18:13:16
    |
Fernando ApesteguÃa (fernape)  |
security/vuxml: Add gitea vulnerabilities
* CVE-2026-59774
* CVE-2026-60004 |
1.1_6 11 Aug 2026 17:59:46
    |
Fernando ApesteguÃa (fernape)  |
security/vuxml: Add Chromium vulnerabilities
* CVE-2026-19137
* CVE-2026-19149
* CVE-2026-19154
* CVE-2026-19157
* CVE-2026-19170
* CVE-2026-19172 |
1.1_6 11 Aug 2026 09:20:32
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSH vulnerabilities |
1.1_6 09 Aug 2026 16:32:07
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document www/py-calibreweb vulnerabilities
PR: 297375
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 09 Aug 2026 09:34:00
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Roundcube vulnerabilities |
1.1_6 09 Aug 2026 07:55:59
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python312 entries |
1.1_6 08 Aug 2026 21:52:34
    |
Charlie Li (vishwin)  |
security/vuxml: update python poplib and imaplib entries |
1.1_6 08 Aug 2026 04:16:07
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1* <= 1.28.6 |
1.1_6 07 Aug 2026 16:42:53
    |
Kousuke Kannagi (mce)  |
security/vuxml: Document multiple security issues in libXfont2
PR: 297327
Approved by: osa (mentor) |
1.1_6 07 Aug 2026 14:10:44
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/{dnsdist,powerdns,powerdns-recursor} vulnerability
PR: 297320, 297321, 297322
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 07 Aug 2026 07:25:06
    |
Kai Knoblich (kai)  |
security/vuxml: Amend entry for py-mkdocs-material
* Python 3.10 is still in the ports tree, so add the related entry. |
1.1_6 07 Aug 2026 07:25:06
    |
Kai Knoblich (kai)  |
security/vuxml: Document py-djangorestframework vulnerabilities |
1.1_6 06 Aug 2026 18:38:25
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document net/keycloak vulnerabilities
PR: 297306
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 06 Aug 2026 07:59:08
    |
Jimmy Olgeni (olgeni)  |
security/vuxml: Document SSH packet alignment issue in erlang |
1.1_6 05 Aug 2026 18:47:53
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix firefox-esr PORTEPOCH in two Mozilla entries
www/firefox-esr has PORTEPOCH=2, but the firefox-esr ranges in these
two do not have it so they cannot match any installed package.
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Aug 2026 18:23:54
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2026-08-05
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Aug 2026 13:40:30
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document MySQL vulnerabilities from CPU Jul 2026
The Oracle Critical Patch Update of July 2026 fixes 54 issues in
Oracle MySQL. 31 of them affect the 8.4 series, 43 the 9.7 series,
including the MySQL Router shipped with the server ports.
Three issues require no credentials: one in the X Plugin and two in
MySQL Router, the latter of which allows unauthorized read and write
access. The remaining ones mostly need a privileged account and lead
to a denial of service.
Fixed in 8.4.11 and 9.7.2 respectively.
Sponsored by: Netzkommune GmbH |
1.1_6 05 Aug 2026 04:44:34
    |
Koichiro Iwao (meta)  |
security/vuxml: Document dns/powerdns-recursor vulnerabilities
PR: 296983 |
1.1_6 05 Aug 2026 02:48:08
    |
Koichiro Iwao (meta)  |
security/vuxml: Fix affected port version of mail/thunderbird by CVE-2026-6778
Although mail/thunderbird does not actually have PORTEPOCH, one is included in
vuxml.
As a result, even fixed versions were still incorrectly reported as vulnerable.
The incorrect report was as follows:
===> thunderbird-153.0.2 has known vulnerabilities:
thunderbird-153.0.2 is vulnerable:
Mozilla -- Invalid pointer
CVE: CVE-2026-6778
WWW:
https://vuxml.FreeBSD.org/freebsd/5124ce36-430a-11f1-a627-b42e991fc52e.html |
1.1_6 03 Aug 2026 16:08:08
    |
Fernando ApesteguÃa (fernape)  |
security/vuxml: Fix giflib entry
The update to 6.1.3 already contains in files/ a patch for CVE-2026-26740 so use
lt instead of le to fix the version range.
PR: 296876 |
1.1_6 03 Aug 2026 16:02:33
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document www/angie vulnerabilities
PR: 297154
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 03 Aug 2026 10:49:18
    |
Bernard Spil (brnrd)  |
security/vuxml: Remove spurious file |
1.1_6 02 Aug 2026 20:17:20
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Weechat vulnerabilities |
1.1_6 01 Aug 2026 01:28:36
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document ejabberd vulnerabilities |
1.1_6 31 Jul 2026 14:18:21
    |
Kai Knoblich (kai)  |
security/vuxml: Document py-mkdocs-material vulnerability |
1.1_6 30 Jul 2026 16:09:35
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Update existing tailscale vulnerability |
1.1_6 30 Jul 2026 15:29:43
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Weechat vulnerabilities |
1.1_6 30 Jul 2026 13:50:12
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Add security/netbird vulnerability
PR: 297167
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 30 Jul 2026 08:40:12
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 151.0.7922.71
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html |
1.1_6 30 Jul 2026 05:50:27
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 30 Jul 2026 01:52:43
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2026-07-29
FreeBSD-SA-26:50.kqueue affects 15.1R
FreeBSD-SA-26:51.ktimer affects 15.0R and 15.1R
FreeBSD-SA-26:52.if_wg affects all supported releases
FreeBSD-SA-26:53.ktrace affects 15.0R and 15.1R
FreeBSD-SA-26:54.sysvsem affects all supported releases
FreeBSD-SA-26:55.elf affects all supported releases |
1.1_6 29 Jul 2026 11:24:07
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 150.0.7871.{114,128,181,186}
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html |
1.1_6 28 Jul 2026 17:43:31
    |
Fernando ApesteguÃa (fernape)  |
security/vuxml: Add jetbrains-goland vulnerabilities
* CVE-2026-64800
* CVE-2026-64802 |
1.1_6 28 Jul 2026 17:18:42
    |
Fernando ApesteguÃa (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2026-16411
* CVE-2026-16412
* CVE-2026-16360 |
1.1_6 28 Jul 2026 11:31:41
    |
Guido Falsi (madpilot)  |
security/vuxml: Report new mailpit vulnerability |
1.1_6 28 Jul 2026 00:30:26
    |
Jimmy Olgeni (olgeni)  |
security/vuxml: Document Erlang/OTP vulnerabilities fixed in OTP 29.0.4,
28.5.0.4 and 27.3.4.15 |
1.1_6 25 Jul 2026 12:13:23
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Vaultwarden vulnerabilities |
1.1_6 25 Jul 2026 08:18:15
    |
Xin LI (delphij)  |
security/vuxml: Document unbound multiple vulnerabilities. |
1.1_6 25 Jul 2026 06:03:28
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1* < 1.28.5 |
1.1_6 21 Jul 2026 20:54:12
    |
Daniel Engberg (diizzy)  |
security/vuxml: Add entry for giflib CVE-2026-26740 |
1.1_6 21 Jul 2026 07:26:50
    |
Yuri Victorovich (yuri)  |
security/vuxml: Add vulnerability records for CVEs fixed in www/srt
* CVE-2026-55869
* CVE-2026-55868 |
1.1_6 20 Jul 2026 16:55:21
    |
Bernard Spil (brnrd)  |
security/vuxml: Fix version in previous Weechat vuln |
1.1_6 20 Jul 2026 16:53:53
    |
Bernard Spil (brnrd)  |
security/vuxml: Register Weechat vulnerabilities |
1.1_6 20 Jul 2026 06:53:36
    |
Guido Falsi (madpilot)  |
security/vuxml: Document new mailpit vulnerability |
1.1_6 19 Jul 2026 11:52:12
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document vulnerabilities in Tailscale |
1.1_6 18 Jul 2026 13:00:54
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in traefik |
1.1_6 18 Jul 2026 10:12:32
    |
Florian Smeets (flo)  |
security/vuxml: Add phpmyfaq vulnerabilities |
1.1_6 18 Jul 2026 05:28:36
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document nginx multiple vulnerabilities
PR: 296830
Sponsored by: Netzkommune GmbH |
1.1_6 16 Jul 2026 08:30:41
    |
Bernard Spil (brnrd)  |
security/vuxml: Document liboqs vulnerabilities |
1.1_6 14 Jul 2026 15:56:22
    |
Sergey A. Osokin (osa)  |
security/vuxml: fix warning for the ffmpeg record |
1.1_6 14 Jul 2026 15:08:33
    |
Sergey A. Osokin (osa)  |
security/vuxml: fix package name
Fixes: 25fdff6924a2ffc740d7102a0940c896cc8c35d0 |
1.1_6 14 Jul 2026 13:07:04
    |
Kousuke Kannagi (mce)  |
security/vuxml: Document Poppler vulnerability
PR: 296769
Approved by: osa (mentor)
Security: CVE-2026-10118 |
1.1_6 14 Jul 2026 10:43:14
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Add devel/ocaml-opam vulnerability
While here, fix whitespaces of two previous entries after the
feedback of `make validate`.
PR: 296642
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 10 Jul 2026 13:34:23
    |
Ronald Klop (ronald)  |
security/vuxml: fix the version of *-commons-httpclient
I learned that <eq> does not match portrevision, so <ge> works better.
And CVE-2020-13956 only mentions 3.1 and later and not earlier CPE versions. |
1.1_6 10 Jul 2026 13:18:13
    |
Ronald Klop (ronald)  |
security/vuxml: also mention the predecessor package name of
apache-commons-httpclient |
1.1_6 10 Jul 2026 12:47:20
    |
Ronald Klop (ronald)  |
security/vuxml: add some CVEs for Apache HttpClient |
1.1_6 09 Jul 2026 06:55:21
    |
Guido Falsi (madpilot)  |
security/vuxml: Report new mail/mailpit vulnerabilities |
1.1_6 09 Jul 2026 04:33:46
    |
Matthias Fechner (mfechner)  |
security/vuxml: document Gitlab vulnerabilities |
1.1_6 08 Jul 2026 21:10:16
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document libXfont2 vulnerabilities
Sponsored by: tipi.work |
1.1_6 08 Jul 2026 16:41:03
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document xwayland vulnerabilities |
1.1_6 08 Jul 2026 14:01:49
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document xorg-server vulnerabilities |
1.1_6 07 Jul 2026 16:49:44
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add net-mgmt/cacti vuln entries |
1.1_6 07 Jul 2026 07:25:27
    |
Koichiro Iwao (meta)  |
security/vuxml: Document net/xrdp{,-devel} vulnerabilities |
1.1_6 06 Jul 2026 22:59:53
    |
Craig Leres (leres)  |
security/vuxml: Mark security/zeek < 8.0.9 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v8.0.9
This release fixes the following potential DoS vulnerabilities:
- The NVT, Rlogin, and RSH analyzers have received fixes to avoid
unbounded state growth. Due to the fact that these packets can
be received from remote hosts, these are considered DoS risks.
- A specially crafted WebSocket payload can cause the Spicy WebSocket
analyzer to use excessive memory when processing close, ping,
and pong frames. Due to the fact that these packets can be
received from remote hosts, these are considered a DoS risk.
(Only the first 15 lines of the commit message are shown above ) |
1.1_6 06 Jul 2026 04:27:51
    |
Joseph Mingrone (jrm)  |
security/vuxml: Document Emacs vulnerability
PR: 296546
Security: CVE-2026-6861
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Jul 2026 16:12:22
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Weechat vulnerability |
1.1_6 05 Jul 2026 16:01:32
    |
Bernard Spil (brnrd)  |
security/roundcube: Document vulnerabilities |
1.1_6 04 Jul 2026 14:09:19
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in traefik |