Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
62fd926d by Salvatore Bonaccorso at 2026-07-30T09:43:13+02:00
Update status for node-ws issues

CVE-2026-62389 got rejected because it is a duplicate of CVE-2026-48779.
Merge useful tracking information from CVE-2026-62389 to CVE-2026-48779.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15209,9 +15209,6 @@ CVE-2026-62683 (File Browser is a file managing 
interface for uploading, deletin
        NOT-FOR-US: File Browser
 CVE-2026-62389
        REJECTED
-       - node-ws 8.21.1+~cs14.19.1-1 (bug #1142271)
-       NOTE: https://github.com/websockets/ws/issues/2331
-       NOTE: Fixed by: 
https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d
 (8.21.1)
 CVE-2026-62378 (RustFS Console is a web management console for the RustFS 
distributed  ...)
        NOT-FOR-US: RustFS
 CVE-2026-62294 (Flameshot is powerful yet simple to use screenshot software. 
Prior to  ...)
@@ -36734,11 +36731,13 @@ CVE-2026-48782 (Pydantic AI is a Python agent 
framework for building application
 CVE-2026-48781 (Postiz is an AI social media scheduling tool. In versions 
prior to 2.2 ...)
        NOT-FOR-US: Postiz
 CVE-2026-48779 (ws is an open source WebSocket client and server for Node.js. 
All vers ...)
-       - node-ws 8.21.0+~cs14.19.1-1 (bug #1140429)
+       - node-ws 8.21.0+~cs14.19.1-1 (bug #1140429; bug #1142271)
        [trixie] - node-ws <no-dsa> (Minor issue)
        [bookworm] - node-ws <postponed> (Minor issue; memory-exhaustion DoS 
from a malicious peer, fixed in 8.21.0/7.5.11)
        [bullseye] - node-ws <postponed> (Minor issue; memory-exhaustion DoS 
from a malicious peer, fixed in 8.21.0/7.5.11)
        NOTE: 
https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p
+       NOTE: https://github.com/websockets/ws/issues/2331
+       NOTE: Fixed by: 
https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d
 (8.21.1)
 CVE-2026-48777 (FileBrowser Quantum is a free, self-hosted, web-based file 
manager. Ve ...)
        NOT-FOR-US: FileBrowser Quantum
 CVE-2026-48776 (LangGraph Python SDK is used to connect to running LangGraph 
API serve ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to