Subject: PSA-2026-00004-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: proxmox-datacenter-manager
Details: Missing separation between options and package name arguments in an apt-get invocation...
Subject: PSA-2026-00003-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: proxmox-backup-server
Details: Missing separation between options and package name arguments in an apt-get invocation...
Subject: PSA-2026-00002-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: pve-manager
Details: Missing separation between options and package name arguments in an apt-get invocation exposed over the...
Subject: PSA-2026-00001-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: pmg-api
Details: Missing separation between options and package name arguments in an apt-get invocation exposed over the API...
This is the list of security advisories since 2025-12-01 for the Proxmox Datacenter Manager.
For details about scope, coverage and timeline see the General FAQ about Proxmox Security Announcements.
Subject: PSA-2025-00021-1: Denial of Service via NULL pointer dereference in apparmor
Advisory date: 2025-12-02
Packages: proxmox-kernel-6.17-*
Details: Certain socket operations from within an unprivileged container can trigger a NULL pointer...
Subject: PSA-2025-00020-1: Missing protections against malicious backup clients with S3-backed datastores
Advisory date: 2025-10-27
Packages: proxmox-backup-server
Details: On datastores configured with an S3 backend, a malicious client could...
Subject: PSA-2025-00019-1: Race condition during long-running garbage collection and pruning of recent snapshots may lead to back up corruption before Proxmox Backup Server 3.4
Advisory date: 2025-10-27
Packages: proxmox-backup-server
Details...