Audit - security

Started by Karla, Today at 01:08:13 PM

Previous topic - Next topic
I made an audit - security and got this output:

***GOT REQUEST TO AUDIT SECURITY***
Currently running OPNsense 26.7.1_1 (amd64) at Wed Aug  5 13:06:29 CEST 2026
Fetching vuln.xml.xz: .......... done
unbound-1.25.1_1 is vulnerable:
  unbound -- multiple vulnerabilities
  CVE: CVE-2026-56444
  CVE: CVE-2026-56416
  CVE: CVE-2026-55991
  CVE: CVE-2026-55990
  CVE: CVE-2026-55973
  CVE: CVE-2026-55717
  CVE: CVE-2026-55708
  CVE: CVE-2026-54478
  CVE: CVE-2026-52863
  CVE: CVE-2026-50252
  CVE: CVE-2026-50251
  CVE: CVE-2026-50248
  CVE: CVE-2026-50243
  CVE: CVE-2026-50046
  CVE: CVE-2026-50045
  CVE: CVE-2026-46582
  CVE: CVE-2026-44690
  CVE: CVE-2026-44687
  CVE: CVE-2026-44621
  CVE: CVE-2026-42955
  CVE: CVE-2026-41637
  CVE: CVE-2026-40691
  CVE: CVE-2026-32665
  CVE: CVE-2026-14586
  WWW: https://vuxml.freebsd.org/freebsd/f63b4b88-6901-4c12-b13d-5a821e25e9bf.html

python313-3.13.14 is vulnerable:
  Python -- poplib module, when passed a user-controlled command, can have additional commands injected using newlines
  CVE: CVE-2025-15367
  WWW: https://vuxml.freebsd.org/freebsd/6d3488ae-2e0f-11f1-88c7-00a098b42aeb.html

  Python -- imaplib module, when passed a user-controlled command, can have additional commands injected using newlines
  CVE: CVE-2025-15366
  WWW: https://vuxml.freebsd.org/freebsd/0be929a5-2e0f-11f1-88c7-00a098b42aeb.html

3 problem(s) in 2 package(s) found.
***DONE***