Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f19ed518 by security tracker role at 2026-08-02T19:12:53+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,31 @@
+CVE-2026-9856 (A vulnerability in huggingface/transformers versions
<=5.8.0.dev0 allo ...)
+ TODO: check
+CVE-2026-68583 (luci-app-adblock-fast before 1.2.4-4 contains a stored
cross-site scri ...)
+ TODO: check
+CVE-2026-68582 (Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken
object level ...)
+ TODO: check
+CVE-2026-68581 (Vikunja versions 0.22.0 through 2.3.0 fail to validate the
principal t ...)
+ TODO: check
+CVE-2026-68578 (ArcadeDB versions before 26.7.3 fail to bind the authenticated
princip ...)
+ TODO: check
+CVE-2026-67357 (ArcadeDB versions before 26.7.3 contain an information
disclosure vuln ...)
+ TODO: check
+CVE-2026-67356 (ArcadeDB before 26.7.3 binds the real LocalDatabase object
into JavaSc ...)
+ TODO: check
+CVE-2026-65321 (PyAthena prior to 3.35.4 contains a sql injection
vulnerability that a ...)
+ TODO: check
+CVE-2026-12231 (The Exclusive Addons for Elementor plugin for WordPress is
vulnerable ...)
+ TODO: check
+CVE-2026-10848 (The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP
RPC fra ...)
+ TODO: check
+CVE-2026-10774 (Zephyr's Bluetooth Mesh subnet key management leaks one PSA
Crypto key ...)
+ TODO: check
+CVE-2025-71401 (better-auth (npm) before 1.4.2 allows an external request to
configure ...)
+ TODO: check
+CVE-2025-71400 (better-auth passkey versions before 1.4.0 contain an insecure
direct o ...)
+ TODO: check
+CVE-2025-71399 (Better Auth relies on better-call, which uses the rou3 router
library. ...)
+ TODO: check
CVE-2026-9335 (A vulnerability in keras-team/keras versions <= 3.14.0 allows
arbitrar ...)
- keras <removed>
[bullseye] - keras <end-of-life> (EOL in bullseye LTS)
@@ -141,7 +169,7 @@ CVE-2026-67323 (GitPython before 3.1.51 fails to guard
against dangerous Git opt
CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable
exfiltra ...)
- python-git <unfixed> (bug #1143454)
NOTE:
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
-CVE-2026-67321 (axios before 0.33.0 contains an incomplete depth-limit bypass
in toFor ...)
+CVE-2026-67321 (axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0
contain a ...)
- node-axios 1.18.0-1
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-hcpx-6fm6-wx23
CVE-2026-67320 (axios in a Node.js deployment using the HTTP adapter can route
request ...)
@@ -165,7 +193,7 @@ CVE-2026-67317 (axios versions 1.7.0 before 1.18.0 fail to
enforce maxBodyLength
CVE-2026-67316 (axios is vulnerable to read-side prototype-pollution gadgets
that can ...)
- node-axios 1.18.0-1
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-mmx7-hfxf-jppx
-CVE-2026-67315 (axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0
as a loo ...)
+CVE-2026-67315 (axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0
fail to r ...)
- node-axios 1.18.0-1
[trixie] - node-axios <not-affected> (Vulnerable code introduced later)
[bookworm] - node-axios <not-affected> (Vulnerable code introduced
later)
@@ -193,11 +221,11 @@ CVE-2026-67308 (Wazuh workflows before 44bf114 contain a
shell injection vulnera
NOT-FOR-US: Wazuh
CVE-2026-67307 (Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or
override ...)
NOT-FOR-US: Wazuh
-CVE-2026-68580
+CVE-2026-68580 (FreeRDP before 3.29.0 contains integer overflow
vulnerabilities in the ...)
- freerdp3 3.29.0+dfsg-1
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x
-CVE-2026-68579
+CVE-2026-68579 (FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer
overflo ...)
- freerdp3 3.30.0+dfsg-1
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m37j-jcr2-8gcc
@@ -12373,6 +12401,7 @@ CVE-2026-16349 (Same-origin policy bypass in the DOM:
Navigation component. This
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16349
CVE-2026-15370 (A flaw was found in libssh. During SFTP server directory
listing, the ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-15370.txt
@@ -12388,39 +12417,46 @@ CVE-2026-59842 (A flaw was found in libssh. During
server-side GSSAPI key exchan
NOTE: Introduced with:
https://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080
(libssh-0.12.0)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610
(libssh-0.12.1)
CVE-2026-59843 (A flaw was found in libssh. A remote authenticated peer can
advertise ...)
+ {DSA-6410-1}
- libssh 0.12.2-1
NOTE: https://www.libssh.org/2026/07/28/libssh-0-12-2-security-release/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59843.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=3f785905760d2e2a87037285ab85b37b9924e409
(libssh-0.12.2)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=006ddd503566ee13e00db42bc111e898388f8664
(libssh-0.12.2)
CVE-2026-59844 (A flaw was found in libssh. A remote authenticated client can
issue SS ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59844.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=2544f22733ffcd59a2e51e2950f80901d063b946
(libssh-0.12.1)
CVE-2026-59845 (A flaw was found in libssh. When ProxyCommand is used, an
unchecked fo ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59845.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f
(libssh-0.12.1)
CVE-2026-59846 (A flaw was found in libssh. A malicious username expanded
through %r i ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59846.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=2e74267b034f00e8e36c86440364f885cead5f45
(libssh-0.12.1)
CVE-2026-59847 (A flaw was found in libssh. Incorrect AES-GCM finalization
checks in b ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59847.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9
(libssh-0.12.1)
CVE-2026-59848 (A flaw was found in libssh. A malicious SFTP server can send
responses ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59848.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=9563afc950f473daa355ca594e2e5f4d520460ac
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=e3dc89de9754790e49b26f03b70e8e4acc88bde8
(libssh-0.12.1)
CVE-2026-59849 (A flaw was found in libssh. Logic errors in automatic
certificate-base ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59849.txt
@@ -12428,6 +12464,7 @@ CVE-2026-59849 (A flaw was found in libssh. Logic
errors in automatic certificat
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=2a40a20b4963e033c7c5a21e3dc5ea6572178a20
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=a540e27659b08828ef61f2910a790f7cf2af9f8d
(libssh-0.12.1)
CVE-2026-59850 (A flaw was found in libssh. If data packets are processed
after a chan ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59850.txt
@@ -65296,7 +65333,7 @@ CVE-2026-42783 [openpgp: Reject nested embedded
signatures]
[bookworm] - rust-sequoia-openpgp <no-dsa> (Minor issue)
[bullseye] - rust-sequoia-openpgp <postponed> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/sequoia-pgp/sequoia/-/commit/23403ff850352b420f19a8fb4724ce35bf963e08
(openpgp/v2.3.0)
-CVE-2026-5084 (WebDyne::Session versions through 2.075 for Perl generates the
session ...)
+CVE-2026-5084 (WebDyne::Session versions before 3.003_704 for Perl generate
the sessi ...)
NOT-FOR-US: WebDyne::Session Perl module
CVE-2026-8276 (A flaw has been found in bettercap up to 2.41.5. Affected by
this issu ...)
- bettercap 2.33.0-3 (bug #1136448)
@@ -79378,6 +79415,7 @@ CVE-2026-5760 (SGLang's reranking endpoint (/v1/rerank)
achieves Remote Code Exe
CVE-2026-4048 (OS Command Injection Remote Code Execution Vulnerability in UI
in Prog ...)
NOT-FOR-US: Progress Software
CVE-2026-41445 (KissFFT before commit8a8e66e contains an integer overflow
vulnerabilit ...)
+ {DLA-4715-1}
- kissfft 131.1.0-4.1 (bug #1134493)
[trixie] - kissfft 131.1.0-4.1~deb13u1
[bookworm] - kissfft 131.1.0-4.1~deb12u1
@@ -102449,6 +102487,7 @@ CVE-2026-3733 (A vulnerability was detected in
xuxueli xxl-job up to 3.3.2. This
CVE-2026-3732 (A security vulnerability has been detected in Tenda F453
1.0.0.3. This ...)
NOT-FOR-US: Tenda
CVE-2026-3731 (A weakness has been identified in libssh up to 0.11.3. The
impacted el ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -113624,6 +113663,7 @@ CVE-2019-25306 (BlackMoon FTP Server 3.1.2.1731
contains an unquoted service pat
CVE-2018-25157 (Phraseanet 4.0.3 contains a stored cross-site scripting
vulnerability ...)
NOT-FOR-US: Phraseanet
CVE-2026-0968 (A flaw was found in libssh in which a malicious SFTP (SSH File
Transfe ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -113631,12 +113671,14 @@ CVE-2026-0968 (A flaw was found in libssh in which
a malicious SFTP (SSH File Tr
NOTE: Tests:
https://git.libssh.org/projects/libssh.git/commit/?id=212121971fb26e1e00b72bd5402c0454a4d84c03
(libssh-0.11.4)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=796d85f786dff62bd4bcc4408d9b7bbc855841e9
(libssh-0.11.4)
CVE-2026-0967 (A flaw was found in libssh. A remote attacker, by controlling
client c ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0967.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=6d74aa6138895b3662bade9bd578338b0c4f8a15
(libssh-0.11.4)
CVE-2026-0966 (A flaw was found in libssh. The API function `ssh_get_hexa()`
is vulne ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -113645,12 +113687,14 @@ CVE-2026-0966 (A flaw was found in libssh. The API
function `ssh_get_hexa()` is
NOTE: Tests:
https://git.libssh.org/projects/libssh.git/commit/?id=b156391833c66322436cf177d57e10b0325fbcc8
(libssh-0.11.4)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=6ba5ff1b7b1547a59f750fbc06b89737b7456117
(libssh-0.11.4)
CVE-2026-0965 (A flaw was found in libssh where it can attempt to open
arbitrary file ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0965.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=bf390a042623e02abc8f421c4c5fadc0429a8a76
(libssh-0.11.4)
CVE-2026-0964 (A malicious SCP server can send unexpected paths that could
make the c ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -145356,6 +145400,7 @@ CVE-2025-41070 (Reflected Cross-site Scripting (XSS)
vulnerability in Sanoma's C
CVE-2025-3500 (Integer Overflow or Wraparound vulnerability in Avast Antivirus
(25.1. ...)
NOT-FOR-US: Avast Antivirus
CVE-2025-34297 (KissFFT versions prior to the fix commit 1b083165 contain an
integer o ...)
+ {DLA-4715-1}
- kissfft 131.1.0-4.1 (bug #1131147)
[trixie] - kissfft 131.1.0-4.1~deb13u1
[bookworm] - kissfft 131.1.0-4.1~deb12u1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f19ed5181b7239f4b4aa3a0ca793933151791dbd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f19ed5181b7239f4b4aa3a0ca793933151791dbd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits