Recent content by ProxmoxSecurityAdvisory

  1. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00050-1: password change via incomplete username validation Advisory date: 2026-09-21 Packages: pve-access-control Details: An attacker with sufficient privileges to create new PAM user entries (Realm.AllocateUser on /access/realm/pam) could change the PAM password of...
  2. ProxmoxSecurityAdvisory

    Proxmox Mail Gateway - Security Advisories

    Subject: PSA-2026-00049-1: PMG: Bypass of mail filters by crafted boundary parameters Advisory date: 2026-09-21 Packages: pmg-api, libmime-tools-perl Details: Certain problematic strings used as Content-Type boundaries were not covered by the fixes for PSA-2026-00005-1. With a fitting...
  3. ProxmoxSecurityAdvisory

    Proxmox Mail Gateway - Security Advisories

    Subject: PSA-2026-00048-1: PMG: XSS in filename display in attachment quarantine Advisory date: 2026-09-21 Packages: pmg-gui Details: The filename field in the AttachementGrid component shown in the Attachment Quarantine view takes its data from the Content-Disposition header of the...
  4. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00047-1: newline injection into firewall config files Advisory date: 2026-09-21 Packages: pve-firewall, proxmox-firewall Details: Incomplete validation of API parameters allowed the injection of newlines or invalid lines into firewall configuration files. The original...
  5. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00046-1: Privilege escalation through malicious OCI container image Advisory date: 2026-09-10 Packages: pve-container Details: The check for control characters in the configuration keys of OCI container images was too permissive, allowing a user with privileges to upload a...
  6. ProxmoxSecurityAdvisory

    Proxmox Backup Server - Security Advisories

    Subject: PSA-2026-00045-1: ACME directory ToS URL XSS Advisory date: 2026-09-10 Packages: proxmox-backup, proxmox-widget-toolkit Details: The terms of service URL returned by an ACME directory was not escaped properly when displaying it on the web UI. An attacker with privileges to register...
  7. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00044-1: XSS in various UI components Advisory date: 2026-09-10 Packages: pve-manager...
  8. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00043-1: Authentication bypass in EOL Proxmox VE 7 release Advisory date: 2026-09-01 Packages: libpve-access-control Affected: libpve-access-control >= 7.0-7 and < 8.0.4 Roughly corresponding to Proxmox VE 7.0 up to and including 7.4 (end of life since July 2024), and, for...
  9. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00042-1: missing privilege checks for vzdump stop API calls Advisory date: 2026-08-17 Packages: pve-manager Details: Any authenticated user/API token could trigger a stop of running backups. This issue was reported privately by Geoffrey McClinsey...
  10. ProxmoxSecurityAdvisory

    Proxmox Backup Server - Security Advisories

    Subject: PSA-2026-00041-1: missing filename reference validation in backup manifests Advisory date: 2026-08-13 Packages: proxmox-backup-server Details: Missing validation of a backup manifest's archive/blob filename references allowed a malicious pull source to trigger reads or writes of...
  11. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00040-1: incomplete privilege checks for unused volumes Advisory date: 2026-08-12 Packages: qemu-server, pve-container Details: Incomplete privilege checks when adding an unused volume to a guest allowed accessing volumes that were out of scope for the user/API token adding...
  12. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00039-1: missing parameter validation in remote migration Advisory date: 2026-08-12 Packages: qemu-server Details: Missing parameter validation in Proxmox VE's remote migration code allowed an attacker with Sys.Incoming privileges to inject arbitrary values in parts of the...
  13. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00038-1: TONTOU kernel memory leak via branch predictor re-poisoning Advisory date: 2026-08-10 Packages: proxmox-kernel-* Details: A new technique to leak kernel memory despite spectre v2 mitigations being in place to neutralize the branch predictor state was discovered...
  14. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue Advisory date: 2026-08-10 Packages: proxmox-kernel-* Details: A use-after-free issue in the Linux kernels SCTP code allowed a unprivileged local attacker to obtain root privileges, and potentially escape from unprivileged...
  15. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00036-1: "Zapscape" KVM guest to host escape on x86_64 Advisory date: 2026-08-10 Packages: proxmox-kernel-* Details: A use-after-free issue was discovered in the Linux kernel's KVM module's shadow MMU code. On hosts with nested virtualization enabled, this issue can be...