Subject: PSA-2026-00005-1: Bypass of mail filters through confusion of the MIME Parser
Advisory date: 2026-02-17
Packages: pmg-api, libmime-tools-perl
Details: The parser initially processing e-mails for further analysis was set to not cause...
Subject: PSA-2026-00004-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: proxmox-datacenter-manager
Details: Missing separation between options and package name arguments in an apt-get invocation...
Subject: PSA-2026-00003-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: proxmox-backup-server
Details: Missing separation between options and package name arguments in an apt-get invocation...
Subject: PSA-2026-00002-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: pve-manager
Details: Missing separation between options and package name arguments in an apt-get invocation exposed over the...
Subject: PSA-2026-00001-1: Authenticated Remote Code Execution via shell injection
Advisory date: 2026-01-13
Packages: pmg-api
Details: Missing separation between options and package name arguments in an apt-get invocation exposed over the API...
This is the list of security advisories since 2025-12-01 for the Proxmox Datacenter Manager.
For details about scope, coverage and timeline see the General FAQ about Proxmox Security Announcements.
Subject: PSA-2025-00021-1: Denial of Service via NULL pointer dereference in apparmor
Advisory date: 2025-12-02
Packages: proxmox-kernel-6.17-*
Details: Certain socket operations from within an unprivileged container can trigger a NULL pointer...