Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
44a4c3c0 by Moritz Muehlenhoff at 2026-06-25T23:16:39+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2901,6 +2901,7 @@ CVE-2026-9612 (The WhatsOrder \u2013 Instant Checkout for
WooCommerce plugin for
NOT-FOR-US: WordPress plugin
CVE-2026-9539 (An out-of-bounds heap read and integer underflow in the TCP
urgent dat ...)
- libslirp 4.9.2-1
+ [trixie] - libslirp <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/slirp/libslirp/-/work_items/93
NOTE:
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/927bca7344e31fd58e2f7afaca784aad4400eb84
(v4.9.2)
CVE-2026-9184 (The 24liveblog - live blog tool plugin for WordPress is
vulnerable to ...)
@@ -3176,16 +3177,19 @@ CVE-2025-64105 (FOSSBilling is a billing and client
management system that autom
NOT-FOR-US: FOSSBilling
CVE-2026-8286
- curl 8.21.0~rc2-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-8286.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/a1701eea289fe7ea80651f801cf992838a491dde
(curl-7_30_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/a86efdd7ca5433de9231e650f18247de8319ad16
(rc-8_21_0-1, curl-8_21_0)
CVE-2026-8458
- curl 8.21.0~rc2-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-8458.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/97c272e5d173ad5f706443e2477f0a84f0044edd
(curl-7_43_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/5e99b73cf441d9c369768b9cd48b5389b9a2503d
(rc-8_21_0-1, curl-8_21_0)
CVE-2026-8924
- curl 8.21.0~rc2-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-8924.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465
(curl-7_46_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acce60c630c070ce8
(rc-8_21_0-1, curl-8_21_0)
@@ -3199,6 +3203,7 @@ CVE-2026-8925
NOTE: Fixed by:
https://github.com/curl/curl/commit/3da249e1f0716c06644ed3522a37a8bf81808012
(rc-8_21_0-1, curl-8_21_0)
CVE-2026-8926
- curl 8.21.0~rc2-1
+ [trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <not-affected> (Vulnerable code not present)
[bullseye] - curl <not-affected> (Vulnerable code not present)
NOTE: https://curl.se/docs/CVE-2026-8926.html
@@ -3206,6 +3211,7 @@ CVE-2026-8926
NOTE: Fixed by:
https://github.com/curl/curl/commit/4ae1d7cc2643e4773a136395f12bc02fc6867854
(rc-8_21_0-1, curl-8_21_0)
CVE-2026-8927
- curl 8.21.0~rc2-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-8927.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/fc6eff13b5414caf6edf22d73a3239e074a04216
(curl-7_12_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/5c225384b8d52c67ce8259c6e4203bc57aacb567
(rc-8_21_0-1, curl-8_21_0)
@@ -3255,6 +3261,7 @@ CVE-2026-9547
NOTE: Fixed by:
https://github.com/curl/curl/commit/0b8dbbc63c98777e4584cb9fbd71df3464008ad1
(rc-8_21_0-1, curl-8_21_0)
CVE-2026-10536
- curl 8.21.0~rc2-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-10536.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/71b7e0161032927cdfb4e75ea40f65b8898b3956
(curl-7_88_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/bfbff7852f050232edd3e5ca5c6bf2021c340f5a
(rc-8_21_0-1, curl-8_21_0)
@@ -3284,11 +3291,13 @@ CVE-2026-11586
NOTE: Fixed by:
https://github.com/curl/curl/commit/849317ff5c5a5e13f50ec3d001e46ddffa77d8a4
(rc-8_21_0-3, curl-8_21_0)
CVE-2026-11856
- curl 8.21.0~rc3-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-11856.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/334d78cd18a7310144383929bdcef34ffbf6159b
(curl-7_10_6)
NOTE: Fixed by:
https://github.com/curl/curl/commit/5c6b4880357ab3e72967c1c45cae0f96ffabc535
(rc-8_21_0-3, curl-8_21_0)
CVE-2026-12064
- curl 8.21.0~rc3-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-12064.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/18270893abdb19f0ca170c118f8a2847dbd304be
(curl-7_81_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/ab3bb8cd8be8f9d4acb97da0418abc279182041e
(rc-8_21_0-3, curl-8_21_0)
@@ -3737,8 +3746,11 @@ CVE-2026-55603 (http-proxy-middleware is node.js
http-proxy middleware. From 3.0
NOT-FOR-US: http-proxy-middleware Node.js module
CVE-2026-55599 (phpseclib is a PHP secure communications library. From 0.1.1
until 1.0 ...)
- php-phpseclib3 3.0.55-1
+ [trixie] - php-phpseclib3 <no-dsa> (Minor issue)
- php-phpseclib 2.0.55-1
+ [trixie] - php-phpseclib <no-dsa> (Minor issue)
- phpseclib 1.0.30-1
+ [trixie] - phpseclib <no-dsa> (Minor issue)
NOTE:
https://github.com/phpseclib/phpseclib/security/advisories/GHSA-m557-wrgg-6rp4
NOTE: Fixed by:
https://github.com/phpseclib/phpseclib/commit/0987dd98832b20fcdc223148c35e22de0f521de9
(3.0.54, 2.0.55, 1.0.30)
CVE-2026-55409 (Filament is a collection of full-stack components for
accelerated Lara ...)
@@ -3749,16 +3761,19 @@ CVE-2026-54911 (UltraJSON is a fast JSON encoder and
decoder written in pure C w
NOTE:
https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf
(5.13.0)
CVE-2026-54651 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
- pypdf <unfixed> (bug #1140629)
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9xf-7f8q-9mcj
NOTE: https://github.com/py-pdf/pypdf/pull/3839
CVE-2026-54531 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
- pypdf <unfixed> (bug #1140629)
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-m2v9-299j-rv96
NOTE: https://github.com/py-pdf/pypdf/pull/3830
CVE-2026-54530 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
- pypdf <unfixed> (bug #1140629)
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-52x6-gq3r-vpf4
NOTE: https://github.com/py-pdf/pypdf/pull/3830
@@ -3834,6 +3849,7 @@ CVE-2026-45034 (PhpSpreadsheet is a pure PHP library for
reading and writing spr
NOT-FOR-US: PhpSpreadsheet
CVE-2026-44889 (WebOb provides objects for HTTP requests and responses. Prior
to 1.8.1 ...)
- python-webob <unfixed>
+ [trixie] - python-webob <no-dsa> (Minor issue)
NOTE:
https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95
CVE-2026-44727 (Jupyter Server is the backend for Jupyter web applications.
Prior to 2 ...)
- jupyter-server 2.20.0-1
@@ -3853,6 +3869,7 @@ CVE-2026-41523 (vLLM is an inference and serving engine
for large language model
- vllm <itp> (bug #1095237)
CVE-2026-41479 (Authlib is a Python library which builds OAuth and OpenID
Connect serv ...)
- python-authlib 1.7.2-1
+ [trixie] - python-authlib <no-dsa> (Minor issue)
NOTE:
https://github.com/authlib/authlib/security/advisories/GHSA-w8p2-r796-3vmq
NOTE: Fixed by:
https://github.com/authlib/authlib/commit/3be08468201a7766a93012ce149ea12822cab096
(v1.7.1, v1.6.10)
CVE-2026-39904 (Gophish through 0.12.1 contains a denial of service
vulnerability that ...)
@@ -4061,6 +4078,7 @@ CVE-2026-53663 (React Router is a router for React. From
7.12.0 until 7.15.1, ce
CVE-2026-53655 (node-tar is a full-featured Tar for Node.js. Prior to 7.5.16,
tar (nod ...)
[experimental] - node-tar 7.5.16+~4.0.1-1
- node-tar 7.5.16+~4.0.1-2
+ [trixie] - node-tar <no-dsa> (Minor issue)
NOTE:
https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh
CVE-2026-53632 (launch-editor allows users to open files with line numbers in
editor f ...)
NOT-FOR-US: Node launch-editor
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44a4c3c0dd30bc4fa2ae781f78e409ca0d4fdc4e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44a4c3c0dd30bc4fa2ae781f78e409ca0d4fdc4e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits