Rails Patches Critical Active Storage Flaw That Lets Unauthenticated Attackers Read Secrets and Escalate to RCE
CVE-2026-66066 lets attackers upload a crafted image to steal a Rails app's secret_key_base and escalate to remote code execution.
Signal
305 articles covering "open-source"
CVE-2026-66066 lets attackers upload a crafted image to steal a Rails app's secret_key_base and escalate to remote code execution.
FFmpeg 9.0 lands August 4 with Vulkan-accelerated APV decoding, animated WebP support, and expanded AMD, NVIDIA, and Apple hardware acceleration filters.
SQLite's own CVE tracker and the National Vulnerability Database both rejected six reports as AI-hallucinated after a JFrog researcher found the underlying code and PoCs didn't exist or didn't work.
Collabora, funded by Valve, has ported an early version of the open-source RADV Vulkan driver from Linux to Windows, reaching the point where it can launch Counter-Strike 2.
Henrique Dias is retiring File Browser, archiving its GitHub repo on September 1 after concluding the decade-old codebase can't be patched into shape.
GCC's Steering Committee will decline copyright-significant contributions derived from LLM output, carving out exceptions for small changes and test cases.
GitHub says its Sponsors program has funneled more than $100 million to open source maintainers since 2019, with growth accelerating sharply.
System76 released COSMIC Epoch 1.5.0, fixing Chromium/Electron scaling bugs, a D-Bus deadlock, and raising the wallpaper limit from 100 to 500.
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
A critical Gitea vulnerability lets a repository writer convert a crafted patch into a live Git hook and run shell commands as the service account.
JFrog researchers turned a 16-year-old FFmpeg decoder bug, CVE-2026-8461, into working remote-code-execution exploits against Jellyfin and Nextcloud using one 50 KB video file.
Debian has opened a General Resolution with four competing proposals on AI-assisted contributions, from an outright ban to conditional acceptance, with no vote date set yet.