Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
44a4c3c0 by Moritz Muehlenhoff at 2026-06-25T23:16:39+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2901,6 +2901,7 @@ CVE-2026-9612 (The WhatsOrder \u2013 Instant Checkout for 
WooCommerce plugin for
        NOT-FOR-US: WordPress plugin
 CVE-2026-9539 (An out-of-bounds heap read and integer underflow in the TCP 
urgent dat ...)
        - libslirp 4.9.2-1
+       [trixie] - libslirp <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/slirp/libslirp/-/work_items/93
        NOTE: 
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/927bca7344e31fd58e2f7afaca784aad4400eb84
 (v4.9.2)
 CVE-2026-9184 (The 24liveblog - live blog tool plugin for WordPress is 
vulnerable to  ...)
@@ -3176,16 +3177,19 @@ CVE-2025-64105 (FOSSBilling is a billing and client 
management system that autom
        NOT-FOR-US: FOSSBilling
 CVE-2026-8286
        - curl 8.21.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-8286.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/a1701eea289fe7ea80651f801cf992838a491dde 
(curl-7_30_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/a86efdd7ca5433de9231e650f18247de8319ad16 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-8458
        - curl 8.21.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-8458.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/97c272e5d173ad5f706443e2477f0a84f0044edd 
(curl-7_43_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/5e99b73cf441d9c369768b9cd48b5389b9a2503d 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-8924
        - curl 8.21.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-8924.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 
(curl-7_46_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acce60c630c070ce8 
(rc-8_21_0-1, curl-8_21_0)
@@ -3199,6 +3203,7 @@ CVE-2026-8925
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/3da249e1f0716c06644ed3522a37a8bf81808012 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-8926
        - curl 8.21.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        [bookworm] - curl <not-affected> (Vulnerable code not present)
        [bullseye] - curl <not-affected> (Vulnerable code not present)
        NOTE: https://curl.se/docs/CVE-2026-8926.html
@@ -3206,6 +3211,7 @@ CVE-2026-8926
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/4ae1d7cc2643e4773a136395f12bc02fc6867854 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-8927
        - curl 8.21.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-8927.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/fc6eff13b5414caf6edf22d73a3239e074a04216 
(curl-7_12_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/5c225384b8d52c67ce8259c6e4203bc57aacb567 
(rc-8_21_0-1, curl-8_21_0)
@@ -3255,6 +3261,7 @@ CVE-2026-9547
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/0b8dbbc63c98777e4584cb9fbd71df3464008ad1 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-10536
        - curl 8.21.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-10536.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/71b7e0161032927cdfb4e75ea40f65b8898b3956 
(curl-7_88_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/bfbff7852f050232edd3e5ca5c6bf2021c340f5a 
(rc-8_21_0-1, curl-8_21_0)
@@ -3284,11 +3291,13 @@ CVE-2026-11586
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/849317ff5c5a5e13f50ec3d001e46ddffa77d8a4 
(rc-8_21_0-3, curl-8_21_0)
 CVE-2026-11856
        - curl 8.21.0~rc3-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-11856.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/334d78cd18a7310144383929bdcef34ffbf6159b 
(curl-7_10_6)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/5c6b4880357ab3e72967c1c45cae0f96ffabc535 
(rc-8_21_0-3, curl-8_21_0)
 CVE-2026-12064
        - curl 8.21.0~rc3-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-12064.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/18270893abdb19f0ca170c118f8a2847dbd304be 
(curl-7_81_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/ab3bb8cd8be8f9d4acb97da0418abc279182041e 
(rc-8_21_0-3, curl-8_21_0)
@@ -3737,8 +3746,11 @@ CVE-2026-55603 (http-proxy-middleware is node.js 
http-proxy middleware. From 3.0
        NOT-FOR-US: http-proxy-middleware Node.js module
 CVE-2026-55599 (phpseclib is a PHP secure communications library. From 0.1.1 
until 1.0 ...)
        - php-phpseclib3 3.0.55-1
+       [trixie] - php-phpseclib3 <no-dsa> (Minor issue)
        - php-phpseclib 2.0.55-1
+       [trixie] - php-phpseclib <no-dsa> (Minor issue)
        - phpseclib 1.0.30-1
+       [trixie] - phpseclib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/phpseclib/phpseclib/security/advisories/GHSA-m557-wrgg-6rp4
        NOTE: Fixed by: 
https://github.com/phpseclib/phpseclib/commit/0987dd98832b20fcdc223148c35e22de0f521de9
 (3.0.54, 2.0.55, 1.0.30)
 CVE-2026-55409 (Filament is a collection of full-stack components for 
accelerated Lara ...)
@@ -3749,16 +3761,19 @@ CVE-2026-54911 (UltraJSON is a fast JSON encoder and 
decoder written in pure C w
        NOTE: 
https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf
 (5.13.0)
 CVE-2026-54651 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
        - pypdf <unfixed> (bug #1140629)
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9xf-7f8q-9mcj
        NOTE: https://github.com/py-pdf/pypdf/pull/3839
 CVE-2026-54531 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
        - pypdf <unfixed> (bug #1140629)
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-m2v9-299j-rv96
        NOTE: https://github.com/py-pdf/pypdf/pull/3830
 CVE-2026-54530 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
        - pypdf <unfixed> (bug #1140629)
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-52x6-gq3r-vpf4
        NOTE: https://github.com/py-pdf/pypdf/pull/3830
@@ -3834,6 +3849,7 @@ CVE-2026-45034 (PhpSpreadsheet is a pure PHP library for 
reading and writing spr
        NOT-FOR-US: PhpSpreadsheet
 CVE-2026-44889 (WebOb provides objects for HTTP requests and responses. Prior 
to 1.8.1 ...)
        - python-webob <unfixed>
+       [trixie] - python-webob <no-dsa> (Minor issue)
        NOTE: 
https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95
 CVE-2026-44727 (Jupyter Server is the backend for Jupyter web applications. 
Prior to 2 ...)
        - jupyter-server 2.20.0-1
@@ -3853,6 +3869,7 @@ CVE-2026-41523 (vLLM is an inference and serving engine 
for large language model
        - vllm <itp> (bug #1095237)
 CVE-2026-41479 (Authlib is a Python library which builds OAuth and OpenID 
Connect serv ...)
        - python-authlib 1.7.2-1
+       [trixie] - python-authlib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/authlib/authlib/security/advisories/GHSA-w8p2-r796-3vmq
        NOTE: Fixed by: 
https://github.com/authlib/authlib/commit/3be08468201a7766a93012ce149ea12822cab096
 (v1.7.1, v1.6.10)
 CVE-2026-39904 (Gophish through 0.12.1 contains a denial of service 
vulnerability that ...)
@@ -4061,6 +4078,7 @@ CVE-2026-53663 (React Router is a router for React. From 
7.12.0 until 7.15.1, ce
 CVE-2026-53655 (node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, 
tar (nod ...)
        [experimental] - node-tar 7.5.16+~4.0.1-1
        - node-tar 7.5.16+~4.0.1-2
+       [trixie] - node-tar <no-dsa> (Minor issue)
        NOTE: 
https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh
 CVE-2026-53632 (launch-editor allows users to open files with line numbers in 
editor f ...)
        NOT-FOR-US: Node launch-editor



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44a4c3c0dd30bc4fa2ae781f78e409ca0d4fdc4e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44a4c3c0dd30bc4fa2ae781f78e409ca0d4fdc4e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to