Subject: PSA-2025-00020-1: Missing protections against malicious backup clients with S3-backed datastores
Advisory date: 2025-10-27
Packages: proxmox-backup-server
Details: On datastores configured with an S3 backend, a malicious client could...
Subject: PSA-2025-00019-1: Race condition during long-running garbage collection and pruning of recent snapshots may lead to back up corruption before Proxmox Backup Server 3.4
Advisory date: 2025-10-27
Packages: proxmox-backup-server
Details...
Subject: PSA-2025-00018-1: buffer overflow in vncterm/spiceterm handling of ANSI escape sequences
Advisory date: 2025-09-22
Packages: vncterm, spiceterm
Details: vncterm and spiceterm are utilies that are spawned when initiating a VNC or SPICE...
Subject: PSA-2025-00017-1: pre-generated "snakeoil" certificate in container templates
Advisory date: 2025-09-17
Packages: pve-container
Details: Any Debian-based container template that includes the "ssl-cert" package contains a self-signed...
Subject: PSA-2025-00015-1: stored XSS in config values
Advisory date: 2025-09-04
Packages: pmg-gui
Details: The HTTP proxy setting dialogue in the web interface was susceptible to XSS. Editing this setting is only available to users with admin...
Subject: PSA-2025-00014-1: stored XSS in config values
Advisory date: 2025-08-14
Packages: proxmox-backup-server
Details: The WebAuthN setting dialogue in the web interface was susceptible to XSS. Editing these settings requires root...
Subject: PSA-2025-00013-1: stored XSS in config values
Advisory date: 2025-08-14
Packages: pve-manager
Details: The HTTP proxy, WebAuthN and U2F setting dialogues in the web interface were susceptible to XSS. Editing these settings requires...