Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e171651e by Salvatore Bonaccorso at 2026-06-27T10:07:21+02:00
Add some new golang-golang-x-image issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -73,7 +73,9 @@ CVE-2026-47193 (OpenProject is open-source, web-based project 
management softwar
 CVE-2026-46710 (Notepad++ is a free and open-source source code editor. From 
8.9.4 unt ...)
        NOT-FOR-US: Notepad++
 CVE-2026-46604 (The TIFF decoder can panic when decoding an invalid image with 
an out- ...)
-       TODO: check
+       - golang-golang-x-image <unfixed>
+       NOTE: https://github.com/golang/go/issues/80122
+       NOTE: Fixed by: 
https://github.com/golang/image/commit/7c04344368b6bcc71df693702522f4f03af45250 
(v0.43.0)
 CVE-2026-46386 (OpenProject is open-source, web-based project management 
software. Pri ...)
        NOT-FOR-US: OpenProject
 CVE-2026-45807 (Kestra is an open-source, event-driven orchestration platform. 
Prior t ...)
@@ -954,9 +956,13 @@ CVE-2026-50739 (A bypass for CVE\u20112026\u201134913 
exists with proper ownersh
 CVE-2026-50176 (The WebSocket Application Programming Interface lacks 
restrictions on  ...)
        NOT-FOR-US: Evoke
 CVE-2026-46602 (The TIFF decoder does not set a limit on the size of tiles in 
tiled im ...)
-       TODO: check
+       - golang-golang-x-image <unfixed>
+       NOTE: https://github.com/golang/go/issues/79905
+       NOTE: Fixed by: 
https://github.com/golang/image/commit/304d4cc4ee82f96f864f1a4c9a3ae30a4016c9ce 
(v0.43.0)
 CVE-2026-46601 (The webp decoder can panic when processing a VP8 chunk with 
dimensions ...)
-       TODO: check
+       - golang-golang-x-image <unfixed>
+       NOTE: https://github.com/golang/go/issues/79869
+       NOTE: Fixed by: 
https://github.com/golang/image/commit/c5511df3ee92e86ce3fa383fdd247080019257c7 
(v0.43.0)
 CVE-2026-44622 (Charging station authentication identifiers are publicly 
accessible vi ...)
        TODO: check
 CVE-2026-43920 (FOSSBilling is a free, open-source billing and client 
management syste ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e171651eaf0880091a6910555ec3e605438f92ea

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e171651eaf0880091a6910555ec3e605438f92ea
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to