<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/osv_homebrew/10</id>
  <title>Most recent entries from osv_homebrew</title>
  <updated>2026-10-02T11:57:42.188064+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-augeas-cve-2025-2588</id>
    <title>BREW-augeas-CVE-2025-2588 — Hercules Augeas fa.c re_case_expand null pointer dereference</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: augeas</p>
<p>A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-augeas-cve-2025-2588"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2025-15661</id>
    <title>BREW-libssh2-CVE-2025-15661 — libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: libssh2</p>
<p>libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2025-15661"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-55199</id>
    <title>BREW-libssh2-CVE-2026-55199 — libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: libssh2</p>
<p>libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-55199"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-55200</id>
    <title>BREW-libssh2-CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: libssh2</p>
<p>libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-55200"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-58050</id>
    <title>BREW-libssh2-CVE-2026-58050 — libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: libssh2</p>
<p>libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-58050"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-58051</id>
    <title>BREW-libssh2-CVE-2026-58051 — libssh2 - Free of Uninitialized Pointer in publickey List Cleanup</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: libssh2</p>
<p>libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-libssh2-cve-2026-58051"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-unzip-cve-2022-0529</id>
    <title>BREW-unzip-CVE-2022-0529</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: unzip</p>
<p>A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-unzip-cve-2022-0529"/>
    <published>2026-06-28T21:29:54+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-unzip-cve-2022-0530</id>
    <title>BREW-unzip-CVE-2022-0530</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: unzip</p>
<p>A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-unzip-cve-2022-0530"/>
    <published>2026-06-28T21:29:54+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-yajl-cve-2017-16516</id>
    <title>BREW-yajl-CVE-2017-16516</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: yajl</p>
<p>In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-yajl-cve-2017-16516"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-yajl-cve-2022-24795</id>
    <title>BREW-yajl-CVE-2022-24795 — Buffer Overflow and Integer Overflow in yajl-ruby</title>
    <updated>2026-07-18T04:02:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: yajl</p>
<p>yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf-&gt;alloc into a small heap chunk. These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer. Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. This vulnerability mostly impacts process availability. Maintainers believe exploitation for arbitrary code execution is unlikely. A patch is available and anticipated to be part of yajl-ruby version 1.4.2. As a workaround, avoid passing large inputs to YAJL.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-yajl-cve-2022-24795"/>
    <published>2026-07-18T04:02:33+00:00</published>
  </entry>
</feed>
