Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b2053690 by Utkarsh Gupta at 2026-07-22T14:12:45+05:30
lts: node-ajv not-affected in bullseye/bookworm (uses uri-js, not fast-uri)

- - - - -
b237d293 by Utkarsh Gupta at 2026-07-22T14:12:46+05:30
lts: simplesamlphp postponed in bookworm/bullseye (CVE-2026-49284)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3881,6 +3881,8 @@ CVE-2026-16222 (A vulnerability was found in 1Panel-dev 
CordysCRM up to 1.4.1. T
 CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including 
the 3.x  ...)
        - node-ajv <unfixed>
        [trixie] - node-ajv <no-dsa> (Minor issue)
+       [bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable 
fast-uri; fast-uri adopted only in ajv 8.x)
+       [bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable 
fast-uri; fast-uri adopted only in ajv 8.x)
        NOTE: 
https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx
 CVE-2026-16220 (A vulnerability has been found in code-projects Online 
Examination Sys ...)
        NOT-FOR-US: code-projects
@@ -6657,6 +6659,8 @@ CVE-2026-49485 (HAPI FHIR is a complete implementation of 
the HL7 FHIR standard
        NOT-FOR-US: HAPI FHIR
 CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information 
disclosure ...)
        - simplesamlphp <unfixed>
+       [bookworm] - simplesamlphp <postponed> (Reachability-gated: multi-IdP 
mixed-trust deployments only; SP warns-and-continues on issuer mismatch and 
accepts unsigned Response InResponseTo; fix along with the next DLA)
+       [bullseye] - simplesamlphp <postponed> (Reachability-gated: multi-IdP 
mixed-trust deployments only; SP warns-and-continues on issuer mismatch and 
accepts unsigned Response InResponseTo; fix along with the next DLA)
        NOTE: 
https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
 CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to 
2.6.1, au ...)
        - golang-oras-oras-go <unfixed> (bug #1142456)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to