Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1a83eaa9 by Salvatore Bonaccorso at 2026-07-29T15:11:45+02:00
Remove todo status for rust-rouille issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -269,10 +269,10 @@ CVE-2026-67183 (TinyWeb through 0.0.8 contains a memory 
leak vulnerability that
        NOT-FOR-US: TinyWeb
 CVE-2026-67182 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling 
vulnera ...)
        - rust-rouille <unfixed>
-       TODO: check upstream details
+       NOTE: 
https://github.com/theopaid/CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille-
 CVE-2026-67181 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling 
vulnera ...)
        - rust-rouille <unfixed>
-       TODO: check upstream details
+       NOTE: 
https://github.com/theopaid/CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille-
 CVE-2026-67178 (MISP installation scripts generated an Apache HTTP 
virtual-host config ...)
        NOT-FOR-US: MISP
 CVE-2026-67174 (Pivotick contains a DOM-based cross-site scripting 
vulnerability in it ...)
@@ -293,7 +293,7 @@ CVE-2026-66913 (Lookyloo did not enforce limits on the 
decompressed size of uplo
        NOT-FOR-US: Lookyloo
 CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion 
vulnerabili ...)
        - rust-rouille <unfixed>
-       TODO: check upstream status
+       NOTE: 
https://github.com/theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-
 CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection 
vulnerabili ...)
        - rust-tiny-http <unfixed>
        NOTE: 
https://github.com/theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-/tree/master
@@ -312,7 +312,7 @@ CVE-2026-66748 (Camaleon CMS versions 2.1.1 through 2.9.1 
contains an authentica
        NOT-FOR-US: Camaleon CMS
 CVE-2026-66746 (Rouille 0.4.0 through 3.6.2 contains an HTTP response 
splitting vulner ...)
        - rust-rouille <unfixed>
-       TODO: check upstream status
+       NOTE: 
https://github.com/theopaid/CVE-2026-66746-HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille-
 CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in 
hotfix 202607 ...)
        NOT-FOR-US: Artica Proxy
 CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the 
Tribes-based cluste ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a83eaa94f2bac1e2c9100c20113a93adf3a3b50

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a83eaa94f2bac1e2c9100c20113a93adf3a3b50
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to