Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
18d9be06 by Salvatore Bonaccorso at 2026-01-21T22:17:45+01:00
Add two keycloak issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -368,7 +368,7 @@ CVE-2026-21641 (HackerOne community member Jad Ghamloush
(0xjad) has reported an
CVE-2026-21640 (HackerOne community member Faraz Ahmed (PakCyberbot) has
reported a fo ...)
NOT-FOR-US: Revive Adserver
CVE-2026-1035 (A flaw was found in the Keycloak server during refresh token
processin ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-0933 (SummaryA command injection vulnerability (CWE-78) has been
found to ex ...)
TODO: check
CVE-2026-0865 (User-controlled header names and values containing newlines can
allow ...)
@@ -408,7 +408,7 @@ CVE-2025-15366 (The imaplib module, when passed a
user-controlled command, can h
CVE-2025-15282 (User-controlled data URLs parsed by urllib.request.DataHandler
allow i ...)
TODO: check
CVE-2025-14559 (A flaw was found in the keycloak-services component of
Keycloak. This ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2025-11468 (When folding a long comment in an email header containing
exclusively ...)
TODO: check
CVE-2026-24061 (telnetd in GNU Inetutils through 2.7 allows remote
authentication bypa ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18d9be06fa174575d5dd98957b5c8c3c2388344f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18d9be06fa174575d5dd98957b5c8c3c2388344f
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits