UBUNTU-CVE-2026-40960

Source
https://ubuntu.com/security/CVE-2026-40960
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40960.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-40960
Upstream
  • CVE-2026-40960
Downstream
Related
Published
2026-04-16T01:16:00Z
Modified
2026-06-02T18:15:58.580979727Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trustedmods or secure.httpmods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.

References

Affected packages

Ubuntu:25.10 / luanti

Package

Name
luanti
Purl
pkg:deb/ubuntu/luanti?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.0+dfsg-5+deb13u1build0.25.10.1

Affected versions

5.*
5.10.0+dfsg-5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "luanti",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.25.10.1"
        },
        {
            "binary_name": "luanti-data",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.25.10.1"
        },
        {
            "binary_name": "luanti-server",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.25.10.1"
        },
        {
            "binary_name": "minetest",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.25.10.1"
        },
        {
            "binary_name": "minetest-data",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.25.10.1"
        },
        {
            "binary_name": "minetest-server",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.25.10.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40960.json"

Ubuntu:26.04:LTS / luanti

Package

Name
luanti
Purl
pkg:deb/ubuntu/luanti?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.0+dfsg-5+deb13u1build0.26.04.1

Affected versions

5.*
5.10.0+dfsg-5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "luanti",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.26.04.1"
        },
        {
            "binary_name": "luanti-data",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.26.04.1"
        },
        {
            "binary_name": "luanti-server",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.26.04.1"
        },
        {
            "binary_name": "minetest",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.26.04.1"
        },
        {
            "binary_name": "minetest-data",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.26.04.1"
        },
        {
            "binary_name": "minetest-server",
            "binary_version": "5.10.0+dfsg-5+deb13u1build0.26.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40960.json"