Freenet: Deanonymization Vulnerability — GLSA 202608-33

A vulnerability has been discovered in Freenet, where an XSS vulnerability could lead to deanonymization.

Affected packages

net-p2p/freenet on all architectures
Affected versions < 0.7.5_p1505
Unaffected versions >= 0.7.5_p1505

Background

Freenet is an encrypted network without censorship.

Description

A vulnerability has been discovered in Freenet. Please review the CVE identifier referenced below for details.

Impact

This release fixes as an XSS vulnerability that may allow an attacker to deanonymize the user.

Workaround

There is no known workaround at this time.

Resolution

All Freenet users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-p2p/freenet-0.7.5_p1505"
 

References

Release date
August 29, 2026

Latest revision
August 29, 2026: 1

Severity
high

Exploitable
remote

Bugzilla entries