Ad
 
Learn More

Last night's security cluster is the patch list

Gitea v1.27.3 and a Moleculer TCP DoS are the Important lines. Wekan version spam is not.

Written by Watch Changelog Team

1 min read

Last night's security cluster is the patch list

So Gitea dropped v1.27.3 last night with a pile of access-control fixes. Packages, attachments, API tokens, fork Actions trust. Same window, Moleculer shipped v0.14.36 for an unauthenticated denial of service in the TCP transporter. One crafted packet, no login. They published GHSA-h89v-g948-47vp at CVSS 7.5. That's the kind of sentence a SE has to carry into a Monday call, not a generic security-improvements line you can skip.

Kind of easy to miss, because Wekan also dumped a string of Important rows overnight, each named something-Bleed. I keep treating the flag like a badge when a vendor ships constantly. To the best of my understanding the useful cluster is the one that changes partner behavior. Gitea if you sell next to self-hosted git. Moleculer if anyone still runs the TCP transporter. Backstage 1.49.6 and 1.50.5 if the IDP is on those lines. They said recommended for all users of that version.

If you're the person who has to tell a customer what to do this week, those three are the list. Access control on git, an unauthenticated TCP hit, and an IDP bump marked for everyone. The Bleed names look urgent. Most of that is version noise.

The recency sort still wants you looking at Next.js canaries. Fine. Recency is not the patch list.

We pull those into a uniform entry shape. Same JSON as everything else. The talking point is unauthenticated, or recommended for all users. Everything else in last night's Important feed is decoration.

Share: