| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_6 14 Aug 2026 10:07:56
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document security/openexr < 3.4.14 multiple vulnerabilities
PR: 297486
Reported by: mandree
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 13 Aug 2026 13:51:47
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 13 Aug 2026 07:29:20
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 151.0.7922.{108,137}
Obtained
from: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01193673229.html
Obtained
from: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01815628406.html |
1.1_6 12 Aug 2026 20:32:38
    |
Florian Smeets (flo)  |
security/vuxml: Add phpmyfaq vulnerabilities |
1.1_6 11 Aug 2026 18:13:16
    |
Fernando ApesteguĂa (fernape)  |
security/vuxml: Add gitea vulnerabilities
* CVE-2026-59774
* CVE-2026-60004 |
1.1_6 11 Aug 2026 17:59:46
    |
Fernando ApesteguĂa (fernape)  |
security/vuxml: Add Chromium vulnerabilities
* CVE-2026-19137
* CVE-2026-19149
* CVE-2026-19154
* CVE-2026-19157
* CVE-2026-19170
* CVE-2026-19172 |
1.1_6 11 Aug 2026 09:20:32
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSH vulnerabilities |
1.1_6 09 Aug 2026 16:32:07
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document www/py-calibreweb vulnerabilities
PR: 297375
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 09 Aug 2026 09:34:00
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Roundcube vulnerabilities |
1.1_6 09 Aug 2026 07:55:59
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python312 entries |
1.1_6 08 Aug 2026 21:52:34
    |
Charlie Li (vishwin)  |
security/vuxml: update python poplib and imaplib entries |
1.1_6 08 Aug 2026 04:16:07
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1* <= 1.28.6 |
1.1_6 07 Aug 2026 16:42:53
    |
Kousuke Kannagi (mce)  |
security/vuxml: Document multiple security issues in libXfont2
PR: 297327
Approved by: osa (mentor) |
1.1_6 07 Aug 2026 14:10:44
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/{dnsdist,powerdns,powerdns-recursor} vulnerability
PR: 297320, 297321, 297322
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 07 Aug 2026 07:25:06
    |
Kai Knoblich (kai)  |
security/vuxml: Amend entry for py-mkdocs-material
* Python 3.10 is still in the ports tree, so add the related entry. |
1.1_6 07 Aug 2026 07:25:06
    |
Kai Knoblich (kai)  |
security/vuxml: Document py-djangorestframework vulnerabilities |
1.1_6 06 Aug 2026 18:38:25
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document net/keycloak vulnerabilities
PR: 297306
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 06 Aug 2026 07:59:08
    |
Jimmy Olgeni (olgeni)  |
security/vuxml: Document SSH packet alignment issue in erlang |
1.1_6 05 Aug 2026 18:47:53
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix firefox-esr PORTEPOCH in two Mozilla entries
www/firefox-esr has PORTEPOCH=2, but the firefox-esr ranges in these
two do not have it so they cannot match any installed package.
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Aug 2026 18:23:54
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2026-08-05
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Aug 2026 13:40:30
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document MySQL vulnerabilities from CPU Jul 2026
The Oracle Critical Patch Update of July 2026 fixes 54 issues in
Oracle MySQL. 31 of them affect the 8.4 series, 43 the 9.7 series,
including the MySQL Router shipped with the server ports.
Three issues require no credentials: one in the X Plugin and two in
MySQL Router, the latter of which allows unauthorized read and write
access. The remaining ones mostly need a privileged account and lead
to a denial of service.
Fixed in 8.4.11 and 9.7.2 respectively.
Sponsored by: Netzkommune GmbH |
1.1_6 05 Aug 2026 04:44:34
    |
Koichiro Iwao (meta)  |
security/vuxml: Document dns/powerdns-recursor vulnerabilities
PR: 296983 |
1.1_6 05 Aug 2026 02:48:08
    |
Koichiro Iwao (meta)  |
security/vuxml: Fix affected port version of mail/thunderbird by CVE-2026-6778
Although mail/thunderbird does not actually have PORTEPOCH, one is included in
vuxml.
As a result, even fixed versions were still incorrectly reported as vulnerable.
The incorrect report was as follows:
===> thunderbird-153.0.2 has known vulnerabilities:
thunderbird-153.0.2 is vulnerable:
Mozilla -- Invalid pointer
CVE: CVE-2026-6778
WWW:
https://vuxml.FreeBSD.org/freebsd/5124ce36-430a-11f1-a627-b42e991fc52e.html |
1.1_6 03 Aug 2026 16:08:08
    |
Fernando ApesteguĂa (fernape)  |
security/vuxml: Fix giflib entry
The update to 6.1.3 already contains in files/ a patch for CVE-2026-26740 so use
lt instead of le to fix the version range.
PR: 296876 |
1.1_6 03 Aug 2026 16:02:33
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document www/angie vulnerabilities
PR: 297154
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 03 Aug 2026 10:49:18
    |
Bernard Spil (brnrd)  |
security/vuxml: Remove spurious file |
1.1_6 02 Aug 2026 20:17:20
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Weechat vulnerabilities |
1.1_6 01 Aug 2026 01:28:36
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document ejabberd vulnerabilities |
1.1_6 31 Jul 2026 14:18:21
    |
Kai Knoblich (kai)  |
security/vuxml: Document py-mkdocs-material vulnerability |
1.1_6 30 Jul 2026 16:09:35
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Update existing tailscale vulnerability |
1.1_6 30 Jul 2026 15:29:43
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Weechat vulnerabilities |
1.1_6 30 Jul 2026 13:50:12
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Add security/netbird vulnerability
PR: 297167
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 30 Jul 2026 08:40:12
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 151.0.7922.71
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html |
1.1_6 30 Jul 2026 05:50:27
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 30 Jul 2026 01:52:43
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2026-07-29
FreeBSD-SA-26:50.kqueue affects 15.1R
FreeBSD-SA-26:51.ktimer affects 15.0R and 15.1R
FreeBSD-SA-26:52.if_wg affects all supported releases
FreeBSD-SA-26:53.ktrace affects 15.0R and 15.1R
FreeBSD-SA-26:54.sysvsem affects all supported releases
FreeBSD-SA-26:55.elf affects all supported releases |
1.1_6 29 Jul 2026 11:24:07
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 150.0.7871.{114,128,181,186}
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
Obtained
from: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html |
1.1_6 28 Jul 2026 17:43:31
    |
Fernando ApesteguĂa (fernape)  |
security/vuxml: Add jetbrains-goland vulnerabilities
* CVE-2026-64800
* CVE-2026-64802 |
1.1_6 28 Jul 2026 17:18:42
    |
Fernando ApesteguĂa (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2026-16411
* CVE-2026-16412
* CVE-2026-16360 |
1.1_6 28 Jul 2026 11:31:41
    |
Guido Falsi (madpilot)  |
security/vuxml: Report new mailpit vulnerability |
1.1_6 28 Jul 2026 00:30:26
    |
Jimmy Olgeni (olgeni)  |
security/vuxml: Document Erlang/OTP vulnerabilities fixed in OTP 29.0.4,
28.5.0.4 and 27.3.4.15 |
1.1_6 25 Jul 2026 12:13:23
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Vaultwarden vulnerabilities |
1.1_6 25 Jul 2026 08:18:15
    |
Xin LI (delphij)  |
security/vuxml: Document unbound multiple vulnerabilities. |
1.1_6 25 Jul 2026 06:03:28
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1* < 1.28.5 |
1.1_6 21 Jul 2026 20:54:12
    |
Daniel Engberg (diizzy)  |
security/vuxml: Add entry for giflib CVE-2026-26740 |
1.1_6 21 Jul 2026 07:26:50
    |
Yuri Victorovich (yuri)  |
security/vuxml: Add vulnerability records for CVEs fixed in www/srt
* CVE-2026-55869
* CVE-2026-55868 |
1.1_6 20 Jul 2026 16:55:21
    |
Bernard Spil (brnrd)  |
security/vuxml: Fix version in previous Weechat vuln |
1.1_6 20 Jul 2026 16:53:53
    |
Bernard Spil (brnrd)  |
security/vuxml: Register Weechat vulnerabilities |
1.1_6 20 Jul 2026 06:53:36
    |
Guido Falsi (madpilot)  |
security/vuxml: Document new mailpit vulnerability |
1.1_6 19 Jul 2026 11:52:12
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document vulnerabilities in Tailscale |
1.1_6 18 Jul 2026 13:00:54
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in traefik |
1.1_6 18 Jul 2026 10:12:32
    |
Florian Smeets (flo)  |
security/vuxml: Add phpmyfaq vulnerabilities |
1.1_6 18 Jul 2026 05:28:36
    |
Jochen Neumeister (joneum)  |
security/vuxml: Document nginx multiple vulnerabilities
PR: 296830
Sponsored by: Netzkommune GmbH |
1.1_6 16 Jul 2026 08:30:41
    |
Bernard Spil (brnrd)  |
security/vuxml: Document liboqs vulnerabilities |
1.1_6 14 Jul 2026 15:56:22
    |
Sergey A. Osokin (osa)  |
security/vuxml: fix warning for the ffmpeg record |
1.1_6 14 Jul 2026 15:08:33
    |
Sergey A. Osokin (osa)  |
security/vuxml: fix package name
Fixes: 25fdff6924a2ffc740d7102a0940c896cc8c35d0 |
1.1_6 14 Jul 2026 13:07:04
    |
Kousuke Kannagi (mce)  |
security/vuxml: Document Poppler vulnerability
PR: 296769
Approved by: osa (mentor)
Security: CVE-2026-10118 |
1.1_6 14 Jul 2026 10:43:14
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Add devel/ocaml-opam vulnerability
While here, fix whitespaces of two previous entries after the
feedback of `make validate`.
PR: 296642
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 10 Jul 2026 13:34:23
    |
Ronald Klop (ronald)  |
security/vuxml: fix the version of *-commons-httpclient
I learned that <eq> does not match portrevision, so <ge> works better.
And CVE-2020-13956 only mentions 3.1 and later and not earlier CPE versions. |
1.1_6 10 Jul 2026 13:18:13
    |
Ronald Klop (ronald)  |
security/vuxml: also mention the predecessor package name of
apache-commons-httpclient |
1.1_6 10 Jul 2026 12:47:20
    |
Ronald Klop (ronald)  |
security/vuxml: add some CVEs for Apache HttpClient |
1.1_6 09 Jul 2026 06:55:21
    |
Guido Falsi (madpilot)  |
security/vuxml: Report new mail/mailpit vulnerabilities |
1.1_6 09 Jul 2026 04:33:46
    |
Matthias Fechner (mfechner)  |
security/vuxml: document Gitlab vulnerabilities |
1.1_6 08 Jul 2026 21:10:16
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document libXfont2 vulnerabilities
Sponsored by: tipi.work |
1.1_6 08 Jul 2026 16:41:03
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document xwayland vulnerabilities |
1.1_6 08 Jul 2026 14:01:49
    |
Sergey A. Osokin (osa)  |
security/vuxml: Document xorg-server vulnerabilities |
1.1_6 07 Jul 2026 16:49:44
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add net-mgmt/cacti vuln entries |
1.1_6 07 Jul 2026 07:25:27
    |
Koichiro Iwao (meta)  |
security/vuxml: Document net/xrdp{,-devel} vulnerabilities |
1.1_6 06 Jul 2026 22:59:53
    |
Craig Leres (leres)  |
security/vuxml: Mark security/zeek < 8.0.9 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v8.0.9
This release fixes the following potential DoS vulnerabilities:
- The NVT, Rlogin, and RSH analyzers have received fixes to avoid
unbounded state growth. Due to the fact that these packets can
be received from remote hosts, these are considered DoS risks.
- A specially crafted WebSocket payload can cause the Spicy WebSocket
analyzer to use excessive memory when processing close, ping,
and pong frames. Due to the fact that these packets can be
received from remote hosts, these are considered a DoS risk.
(Only the first 15 lines of the commit message are shown above ) |
1.1_6 06 Jul 2026 04:27:51
    |
Joseph Mingrone (jrm)  |
security/vuxml: Document Emacs vulnerability
PR: 296546
Security: CVE-2026-6861
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Jul 2026 16:12:22
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Weechat vulnerability |
1.1_6 05 Jul 2026 16:01:32
    |
Bernard Spil (brnrd)  |
security/roundcube: Document vulnerabilities |
1.1_6 04 Jul 2026 14:09:19
    |
Thomas Zander (riggs)  |
security/vuxml: Document multiple vulnerabilities in traefik |
1.1_6 04 Jul 2026 09:07:39
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add www/p5-CGI-Session security fixes |
1.1_6 03 Jul 2026 06:32:00
    |
Gleb Popov (arrowd)  Author: Matthias Andree |
security/vuxml: add security/openvpn[-devel] vuln entries.
Aligned with Gert Doering for openvpn-devel.
PR: 296429
Security: ffa897a0-756f-11f1-b291-a74de6bb0320
Security: CVE-2026-11771
Security: CVE-2026-12932
Security: CVE-2026-12996
Security: CVE-2026-13117
Security: CVE-2026-13122
Security: CVE-2026-13698
Pull Request: https://github.com/freebsd/freebsd-ports/pull/550 |
1.1_6 03 Jul 2026 06:31:59
    |
Gleb Popov (arrowd)  Author: Matthias Andree |
security/vuxml: Fix invalid escape sequence in Python re
ports/security/vuxml/files/extra-validation.py:13:
SyntaxWarning: invalid escape sequence '\|'
re_invalid_package_name = re.compile('[@!#$%^&*()<>?/\|}{~:]')
This can be fixed by making the re.compile argument a raw R'...' string,
capital R avoids issues with some Microsoft IDEs.
(Alternative is doubling the backslash, but that's less readable.)
Pull Request: https://github.com/freebsd/freebsd-ports/pull/550 |
1.1_6 02 Jul 2026 07:44:52
    |
Piotr Smyrak (smyru)  |
security/vuxml: extend ffmpeg announcement to ffmpeg4 and ffmpeg6
Approved by: 0mp (mentor)
Reviewed by: fernape
Security: CVE-2026-8461 |
1.1_6 02 Jul 2026 06:03:50
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 150.0.7871.46
Obtained
from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html |
1.1_6 01 Jul 2026 00:38:02
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2026-06-30
FreeBSD-SA-26:37.vm affects all supported releases
FreeBSD-SA-26:38.jail affects 15.0R and 15.1R
FreeBSD-SA-26:39.execve affects all supported releases
FreeBSD-SA-26:40.zfs affects all supported releases
FreeBSD-SA-26:41.libalias affects all supported releases
FreeBSD-SA-26:42.unlinkat affects all supported releases
FreeBSD-SA-26:43.tcp affects all supported releases
FreeBSD-SA-26:44.posixshm affects all supported releases
FreeBSD-SA-26:45.audit affects all supported releases
FreeBSD-SA-26:46.ktls affects all supported releases
FreeBSD-SA-26:47.linux affects 14.3R, 14.4R and 15.0R
FreeBSD-SA-26:48.compat32 affects 14.3R, 14.4R and 15.0R
FreeBSD-SA-26:49.iconv affects all supported releases |
1.1_6 30 Jun 2026 16:46:45
    |
Florian Smeets (flo)  |
security/vuxml: Document net-mgmt/icinga2 vulnerabilities |
1.1_6 30 Jun 2026 11:11:40
    |
Palle Girgensohn (girgen)  |
security/vuxml: Document databases/postgresql-jdbc vulnerability |
1.1_6 30 Jun 2026 10:59:41
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 149.0.7827.200
Obtained
from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html |
1.1_6 29 Jun 2026 16:28:35
    |
Yusuf Yaman (nxjoseph)  Author: Jaap Akkerhuis |
security/vuxml: Document dns/nsd vulnerabilities
PR: 296375
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 13:07:14
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document net/rclone vulnerability
PR: 296192
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 12:32:18
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/powerdns vulnerabilities
PR: 296312
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 11:14:13
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/powerdns-recursor vulnerabilities
PR: 296313
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 10:07:44
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/dnsdist vulnerabilities
PR: 296314
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 29 Jun 2026 09:04:18
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1* < 1.28.4 |
1.1_6 28 Jun 2026 18:45:30
    |
Sergey A. Osokin (osa)  |
security/vuxml: document expat2 vulberabilities
Sponsored by: tipi.work |
1.1_6 28 Jun 2026 14:27:32
    |
Yusuf Yaman (nxjoseph)  Author: ports@foss-daily.org |
security/vuxml: Document www/gitea vulnerabilities
PR: 296351
Approved by: osa, vvd (Mentors, implicit) |
1.1_6 27 Jun 2026 12:39:32
    |
Piotr Smyrak (smyru)  |
security/vuxml: document ffmpeg vulnerability
Approved by: 0mp (mentor)
Approved by: fernape
Security: CVE-2026-8461
Differential Revision: https://reviews.freebsd.org/D57843 |
1.1_6 26 Jun 2026 04:41:08
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 24 Jun 2026 14:59:22
    |
Bernard Spil (brnrd)  |
security/vuxml: Document go-git vulnerability |
1.1_6 24 Jun 2026 10:38:03
    |
Yusuf Yaman (nxjoseph)  |
security/vuxml: Document dns/{ldns,py-ldns} vulnerability
PR: 296232
Approved by: osa, vvd (Mentors, implicit)
Security: CVE-2026-10846 |
1.1_6 23 Jun 2026 10:37:01
    |
Dave Cottlehuber (dch)  |
security/vuxml: Document podman vulnerability
Reviewed by: dfr
Sponsored by: SkunkWerks, GmbH
Differential Revision: https://reviews.freebsd.org/D57736 |
1.1_6 21 Jun 2026 13:00:15
    |
Bernard Spil (brnrd)  |
security/vuxml: Fix month error on latest MariaDB entry |
1.1_6 20 Jun 2026 06:39:47
    |
Jason E. Hale (jhale)  |
security/vuxml: Unbreak 'validate' target
73ebb85ec34a introduced basic CVE ID checking, which is fantastic. It
kind of broke the 'validate' target for a sane VuXML DB, though.
This fixes the 'validate' target keeping to the orginal idea and with
pretty-print as an added bonus. |
1.1_6 19 Jun 2026 13:32:41
    |
Piotr Smyrak (smyru)  |
security/vuxml: refuse non CVE vuln IDs in validate target
PR: 295994
Approved by: 0mp (mentor)
Reviewed by: 0mp, fernape, philip
Differential Revision: https://reviews.freebsd.org/D57539 |
1.1_6 19 Jun 2026 04:21:14
    |
Charlie Li (vishwin)  |
security/vuxml: fix lang/python311 version typo
Event: BSDCan 2026 |
1.1_6 19 Jun 2026 04:16:15
    |
Charlie Li (vishwin)  |
security/vuxml: update python entries with upstream commits
Event: BSDCan 2026 |
1.1_6 18 Jun 2026 15:19:19
    |
Jochen Neumeister (joneum)  |
security/vuxml: Add entry for NGINX
Add entry for NGINX
Sponsored by: Netzkommune GmbH |