Security Advisory – 03 Mar 2026

New security notices published since yesterday. 03 Mar 2026 12:00 GMT.

Top items

Ubuntu

USN-8067-1: Mailman vulnerability

Mailman incorrectly handled CSRF tokens. A remote list member or moderator could possibly use their own token to craft an admin request CSRF attack and set a new admin password or make other changes.

  • Published: 02 Mar 2026 17:29 GMT
  • CVEs: Not stated in the advisory excerpt
  • Notes: incorrectly handled CSRF tokens

USN-5376-6: Git regression

USN-5376-4 fixed a regression in Git. An attacker could possibly use this issue to run arbitrary commands.

  • Published: 02 Mar 2026 16:15 GMT
  • CVEs: Not stated in the advisory excerpt
  • Notes: could possibly use this issue to run arbitrary commands

Related posts

Privacy boundaries when AI touches government records

AI governance gets awkward fast when government records are involved, because the model is rarely the problem. The problem is the sloppy boundary around it, the sort I have seen quietly turn a...

Metadata schema choices for content libraries

Structured metadata only works when it matches how people actually retrieve content. I have seen neat schemas fail as soon as the library meets real records, and tarot makes the problem obvious. If...

Federation trade-offs in self-hosted social feeds

Federation looks tidy until you let it touch the edges, and then the odd cases arrive fast. I prefer self-hosted social feeds that stay explicit about what is local, what is remote, and what should...