Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 38 additions & 0 deletions gems/css_parser/GHSA-84w7-hpvm-rxx2.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
---
gem: css_parser
ghsa: 84w7-hpvm-rxx2
url: https://github.com/premailer/css_parser/security/advisories/GHSA-84w7-hpvm-rxx2
title: ReDoS - expand_shorthand! regex (RE_FUNCTIONS) backtracks
exponentially on an unclosed CSS function value
date: 2021-09-20
description: |
## SUMMARY

expand_shorthand! (and the expand_dimensions_shorthand! it calls)
runs the RE_FUNCTIONS regex over declaration values. That regex
has a nested quantifier inside a group that can recurse, so on a
value that opens a CSS function and never closes it, the match
degrades into exponential backtracking. A CSS string of a few dozen
bytes pins one CPU core for minutes to hours.

## IMPACT

Any code that parses untrusted CSS and then expands shorthands is
affected. That includes premailer, whose adapters call expand_shorthand!
while inlining styles, so an application that runs premailer over
attacker-supplied email or user CSS can be stalled by a tiny payload.
The property has to be one of the dimension shorthands (margin,
padding, border-*), all of which an attacker can name freely.
unaffected_versions:
- "< 1.10.0"
patched_versions:
- ">= 3.2.0"
related:
url:
- https://rubygems.org/gems/css_parser/versions/3.2.0
- https://github.com/premailer/css_parser/blob/master/CHANGELOG.md#version-320
- https://github.com/premailer/css_parser/compare/v3.1.0...v3.2.0
- https://github.com/premailer/css_parser/security/advisories/GHSA-84w7-hpvm-rxx2
notes: |
- No CVE in GHSA URL, but has "Moderate" (no value) severity.
- date from rubygems.org URL.
66 changes: 66 additions & 0 deletions gems/css_parser/GHSA-w3mx-4vv9-hjpg.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
---
gem: css_parser
ghsa: w3mx-4vv9-hjpg
url: https://github.com/premailer/css_parser/security/advisories/GHSA-w3mx-4vv9-hjpg
title: Arbitrary local-file read via attacker-controlled `@import`
into `load_file!` (the `base_dir` branch of `add_block!`) -
incomplete fix of GHSA-9pmc-p236-855h
date: 2026-10-07
description: |
## Summary

When css_parser parses CSS that contains an @import rule and the caller
has supplied a :base_dir option (but not a :base_uri), the
attacker-controlled import path is passed directly into load_file!,
which does File.expand_path(file_name, base_dir) followed by File.read
with no path containment, no traversal guard, and no allow_file_uris
gate. An attacker who controls CSS content can therefore cause the
library to read an arbitrary local file — either by absolute path
(@import "/etc/…") or by ../ traversal escaping base_dir — and the
file's content is merged into the parser's ruleset. To the extent
the loose CSS grammar turns that content into selectors/declarations,
it is surfaced to the consumer.

This is the base_dir sibling of the SSRF/file:// issue fixed as
GHSA-9pmc-p236-855h / CVE-2026-53727. That advisory and its fix only
closed the file://-via-base_uri arm of the same @import handler;
the base_dir arm and load_file! itself were left untouched, and the
fix's own docstring incorrectly assumes load_file! only ever receives
caller-supplied paths.

The primary downstream consumer, Premailer, reaches this arm
automatically for local-file / HTML-file input (it sets @base_dir
from the file's directory while leaving @base_url nil), so an
attacker-supplied local email/HTML file causes Premailer to read
a file outside the email directory and inline its content into
the returned HTML.

## IMPACT

An attacker who controls CSS content (a submitted stylesheet, an
email/HTML template processed server-side by Premailer from a
local file, etc.) can:

* Read arbitrary local files by absolute path or ../ traversal,
bounded by process file permissions.

* Use the always-executed File.read (visible via loaded_uris /
circular_reference_check) as a file-existence / read oracle
even when content is not fully surfaced.

* Exfiltrate file content through the CSS-parse channel: files
that the loose CSS grammar turns into selectors/declarations (CSS,
many config/.env-style/JSON-ish files) leak strongly; arbitrary
binary content leaks only partially.
cvss_v3: 5.3
patched_versions:
- ">= 3.3.0"
related:
url:
- https://rubygems.org/gems/css_parser/versions/3.3.0
- https://github.com/premailer/css_parser/blob/master/CHANGELOG.md#version-330
- https://github.com/premailer/css_parser/compare/v3.2.0...v3.3.0
- https://github.com/premailer/css_parser/security/advisories/GHSA-w3mx-4vv9-hjpg
notes: |
- No CVE value in GHSA URL.
- cvss_v3 from GHSA URL.
42 changes: 42 additions & 0 deletions gems/katello/CVE-2026-79654.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
---
gem: katello
cve: 2026-79654
ghsa: xqhp-pxqr-f7m6
url: https://nvd.nist.gov/vuln/detail/CVE-2026-79654
title: Katello - Unauthorized disclosure of Content View lifecycle information
date: 2026-10-05
description: |
A flaw was found in Katello where the Content View History API does
not properly enforce authorization when accessing a Content View
specified by the user. An authenticated user with permission to
view Content Views in one organization may be able to access the
lifecycle history of a Content View belonging to another organization
by supplying its identifier to the affected API endpoint. This can
result in unauthorized disclosure of Content View lifecycle
information, including publication and promotion events, associated
users, and timestamps.
cvss_v3: 4.3
patched_versions:
- "~> 4.21.2"
- ">= 5.0.1"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-79654
- https://rubygems.org/gems/katello/versions/5.0.1
- https://github.com/Katello/katello/compare/5.0.0...5.0.1
- https://rubygems.org/gems/katello/versions/4.21.2
- https://github.com/Katello/katello/compare/4.21.1.1...4.21.2
- https://github.com/Katello/katello/pull/11847
- https://github.com/Katello/katello/commit/2a80275ce766a7b370d09123e3e9e063b33d8df3
- https://access.redhat.com/security/cve/CVE-2026-79654
- https://bugzilla.redhat.com/show_bug.cgi?id=2523348
- https://projects.theforeman.org/issues/39701
- https://access.redhat.com/errata/RHSA-2026:74503
- https://access.redhat.com/errata/RHSA-2026:74504
- https://access.redhat.com/errata/RHSA-2026:74506
- https://access.redhat.com/errata/RHSA-2026:74505
- https://github.com/advisories/GHSA-xqhp-pxqr-f7m6
notes: |
- GHSA Unreviewed RedHat advisory
- cvss_v3 from nvd.nist.gov URL
- Both /compare/ URLs mentioned CVE number.
Loading