Security advisories
Security problems found and fixed in Cenovel, and what to do about each.
Updated October 4, 2026
Published advisories
No security advisories have been published. When one is, it is listed here, newest first.
What each advisory says
- Identifier
- CENOVEL-SA with the year and a number, such as CENOVEL-SA-2026-001, and a CVE identifier when one is assigned.
- Severity
- Critical, High, Medium or Low, with the CVSS 3.1 score and vector.
- Affected
- The releases that have the problem, such as Agate 1.0.0 to 1.1.0.
- Fixed in
- The first release of each supported major that fixes it.
- What happens
- What an attacker could do, and under what conditions, in plain words.
- What to do
- Install the fixed release, and any workaround until you can.
- Dates and credit
- When it was published and last updated, and who reported it, if they wish.
How you hear about one
Each advisory is published here when its fix is available, and emailed to the contacts each district names for security notices. For a vulnerability that is critical or being exploited, districts hear from us within one business day of our confirming it, even before a fix is ready.
To report a problem, see Report a vulnerability or write to [email protected].