Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
157b9e0f by security tracker role at 2026-08-04T07:12:19+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,281 @@
+CVE-2026-8508 (An improper authentication vulnerability in the
"social_login.cgi" CGI ...)
+ TODO: check
+CVE-2026-6837 (A post-authentication command injection vulnerability in the
"export-c ...)
+ TODO: check
+CVE-2026-69249 (python-cryptography is a package designed to expose
cryptographic prim ...)
+ TODO: check
+CVE-2026-69248 (cryptography is a package designed to expose cryptographic
primitives ...)
+ TODO: check
+CVE-2026-69247 (cryptography is a package designed to expose cryptographic
primitives ...)
+ TODO: check
+CVE-2026-69246 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and
8.0.1, Gu ...)
+ TODO: check
+CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and
8.0.1, Se ...)
+ TODO: check
+CVE-2026-69244 (AIOHTTP is an asynchronous HTTP client/server framework for
asyncio an ...)
+ TODO: check
+CVE-2026-69243 (AIOHTTP is an asynchronous HTTP client/server framework for
asyncio an ...)
+ TODO: check
+CVE-2026-69240 (Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL
injection is pos ...)
+ TODO: check
+CVE-2026-69198 (ip-address is a library for parsing and manipulating IPv4 and
IPv6 add ...)
+ TODO: check
+CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and
IPv6 add ...)
+ TODO: check
+CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication
for ever ...)
+ TODO: check
+CVE-2026-68981 (Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP
requests fo ...)
+ TODO: check
+CVE-2026-68980 (Apache NiFi 2.0.0 through 2.10.0 support creating, reading,
and deleti ...)
+ TODO: check
+CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context
update R ...)
+ TODO: check
+CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr()
function ...)
+ TODO: check
+CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows
attackers ...)
+ TODO: check
+CVE-2026-67977 (An integer overflow in the Svc::FileDownlink::SendPartial
component of ...)
+ TODO: check
+CVE-2026-67976 (The Ref::SignalGen component of fprime framework v4.2.2 does
not valid ...)
+ TODO: check
+CVE-2026-67975 (Incorrect access control in NASA cFS v7.0.1 allows attackers
to arbitr ...)
+ TODO: check
+CVE-2026-67974 (A parser boundary flaw in the Software Bus Network (SBN)
application's ...)
+ TODO: check
+CVE-2026-67973 (An issue in the CFDP receive path of NASA cFS v7.0.1 allows
attackers ...)
+ TODO: check
+CVE-2026-67972 (An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1
allows a ...)
+ TODO: check
+CVE-2026-67970 (Incorrect access control in the DS_SetDestPathCmd() component
of NASA ...)
+ TODO: check
+CVE-2026-67969 (An issue in the HS_MonitorApplications() component of NASA cFS
v7.0.1 ...)
+ TODO: check
+CVE-2026-67673 (A stack-based buffer overflow vulnerability exists in the
cmd_edl func ...)
+ TODO: check
+CVE-2026-67617 (Microweber CMS through 2.0.20 contains a stored cross-site
scripting v ...)
+ TODO: check
+CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains
a missin ...)
+ TODO: check
+CVE-2026-67599 (ClearOS 7.9 contains an OS command injection vulnerability in
the Log ...)
+ TODO: check
+CVE-2026-67598 (Emlog Pro through 2.6.23 contains a disabled TLS certificate
validatio ...)
+ TODO: check
+CVE-2026-66326 (Missing authorization in Microsoft Edge (Chromium-based)
allows an una ...)
+ TODO: check
+CVE-2026-66325 (Server-side request forgery (ssrf) in Microsoft Edge
(Chromium-based) ...)
+ TODO: check
+CVE-2026-66322 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
+ TODO: check
+CVE-2026-66321 (Access of resource using incompatible type ('type confusion')
in Micro ...)
+ TODO: check
+CVE-2026-66318 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
+ TODO: check
+CVE-2026-66317 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
+ TODO: check
+CVE-2026-66316 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
+ TODO: check
+CVE-2026-66315 (Use after free in Microsoft Edge (Chromium-based) allows an
unauthoriz ...)
+ TODO: check
+CVE-2026-66314 (Time-of-check time-of-use (toctou) race condition in Microsoft
Edge (C ...)
+ TODO: check
+CVE-2026-66313 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
+ TODO: check
+CVE-2026-66312 (Buffer over-read in Microsoft Edge (Chromium-based) allows an
authoriz ...)
+ TODO: check
+CVE-2026-66311 (Missing authorization in Microsoft Edge (Chromium-based)
allows an una ...)
+ TODO: check
+CVE-2026-66310 (External control of file name or path in Microsoft Edge for
Android al ...)
+ TODO: check
+CVE-2026-66296 (Improper Neutralization of Input During Web Page Generation
(XSS) vuln ...)
+ TODO: check
+CVE-2026-66065 (Ouroboros is a local-first runtime for AI coding agents that
records t ...)
+ TODO: check
+CVE-2026-65804 (Improper control of generation of code ('code injection') in
Microsoft ...)
+ TODO: check
+CVE-2026-65802 (External control of file name or path in Microsoft Edge for
Android al ...)
+ TODO: check
+CVE-2026-64565 (In the Linux kernel, the following vulnerability has been
resolved: I ...)
+ TODO: check
+CVE-2026-64564 (In the Linux kernel, the following vulnerability has been
resolved: s ...)
+ TODO: check
+CVE-2026-64563 (In the Linux kernel, the following vulnerability has been
resolved: r ...)
+ TODO: check
+CVE-2026-64562 (In the Linux kernel, the following vulnerability has been
resolved: K ...)
+ TODO: check
+CVE-2026-64561 (In the Linux kernel, the following vulnerability has been
resolved: K ...)
+ TODO: check
+CVE-2026-62870 (Use after free in Microsoft Office Excel allows an
unauthorized attack ...)
+ TODO: check
+CVE-2026-62354 (Authorization handling for Parameter Context validation
requests in Ap ...)
+ TODO: check
+CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy
bypass ...)
+ TODO: check
+CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists
under /cu ...)
+ TODO: check
+CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows
authenticated ...)
+ TODO: check
+CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting
(XSS) vulne ...)
+ TODO: check
+CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md
plugin ...)
+ TODO: check
+CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430
allows an at ...)
+ TODO: check
+CVE-2026-51190 (The "s init" command in Serverless-Devs @serverless-devs/s <=
3.1.11 p ...)
+ TODO: check
+CVE-2026-49132 (OPNsense before 26.1.9 contains a stored cross-site scripting
vulnerab ...)
+ TODO: check
+CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting
vulnerab ...)
+ TODO: check
+CVE-2026-48399 (Adobe Campaign Classic (ACC) is affected by a Violation of
Secure Desi ...)
+ TODO: check
+CVE-2026-48333 (Adobe Campaign Classic (ACC) is affected by an Incorrect
Authorization ...)
+ TODO: check
+CVE-2026-48331 (Adobe Campaign Classic (ACC) is affected by a Server-Side
Request Forg ...)
+ TODO: check
+CVE-2026-48330 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
+ TODO: check
+CVE-2026-48326 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
+ TODO: check
+CVE-2026-48323 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
+ TODO: check
+CVE-2026-48317 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
+ TODO: check
+CVE-2026-48115 (Misskey is an open source, federated social media platform.
All Misske ...)
+ TODO: check
+CVE-2026-48113 (Chisel is a TCP/UDP tunnel, transported over HTTP and secured
via SSH. ...)
+ TODO: check
+CVE-2026-48063 (Baileys is a cocket-based TS/JavaScript API for WhatsApp Web.
In versi ...)
+ TODO: check
+CVE-2026-48061 (Litestar is an Asynchronous Server Gateway Interface (ASGI)
framework. ...)
+ TODO: check
+CVE-2026-48031 (go-base is a Go RESTful API Boilerplate template with JWT
Authenticati ...)
+ TODO: check
+CVE-2026-47746 (Misskey is an open source, federated social media platform.
Versions 1 ...)
+ TODO: check
+CVE-2026-47211 (Ouroboros is a local-first runtime for AI coding agents that
records t ...)
+ TODO: check
+CVE-2026-46714 (Misskey is an open source, federated social media platform.
IVersions ...)
+ TODO: check
+CVE-2026-46713 (Misskey is an open source, federated social media platform.
Versions 1 ...)
+ TODO: check
+CVE-2026-46712 (Misskey is an open source, federated social media platform.
Versions 2 ...)
+ TODO: check
+CVE-2026-42169 (A heap-buffer-overflow vulnerability exists in the APNG
(Animated PNG) ...)
+ TODO: check
+CVE-2026-41447 (FirmaCheck for Windows before 1.3.16 contains a dll hijacking
vulnerab ...)
+ TODO: check
+CVE-2026-18739 (A flaw was found in popt, a command-line option parsing
library. An of ...)
+ TODO: check
+CVE-2026-18738 (Shlink versions 5.0.0 through 5.1.5 contain a CSV formula
injection vu ...)
+ TODO: check
+CVE-2026-18737 (Shlink contains a blind SQL injection vulnerability that
allows any au ...)
+ TODO: check
+CVE-2026-18736 (Shlink contains a server-side request forgery vulnerability
that allow ...)
+ TODO: check
+CVE-2026-18733 (A prompt injection vulnerability in the shell tool in Amazon
Strands A ...)
+ TODO: check
+CVE-2026-18723 (A vulnerability was determined in diaowen DWSurvey up to
6.14.0. The a ...)
+ TODO: check
+CVE-2026-18722 (A vulnerability was found in diaowen DWSurvey up to 6.14.0.
Impacted i ...)
+ TODO: check
+CVE-2026-18721 (A vulnerability has been found in kalcaddle kodbox 1.67 Build
02. This ...)
+ TODO: check
+CVE-2026-18720 (A flaw has been found in kalcaddle kodbox 1.67 Build 02. This
vulnerab ...)
+ TODO: check
+CVE-2026-18719 (A vulnerability was detected in cemtan sar2html 4.0.0. This
affects an ...)
+ TODO: check
+CVE-2026-18686 (A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5.
The aff ...)
+ TODO: check
+CVE-2026-18685 (A security vulnerability has been detected in GL.iNet
GL-MT3000 up to ...)
+ TODO: check
+CVE-2026-18684 (A weakness has been identified in GL.iNet GL-MT3000 up to
4.4.5. This ...)
+ TODO: check
+CVE-2026-18682 (A security flaw has been discovered in OpenAkita up to
1.27.12. This v ...)
+ TODO: check
+CVE-2026-18667 (A vulnerability in Tenable Sensor Proxy allows a remote
attacker to ex ...)
+ TODO: check
+CVE-2026-18655 (Improper restriction of intended endpoints in the RabbitMQ
broker conn ...)
+ TODO: check
+CVE-2026-18654 (Key exchange without entity authentication in the EMR SSH
helper comma ...)
+ TODO: check
+CVE-2026-18648 (A vulnerability was detected in Blix Email Blue Mail Calendar
App 2.2. ...)
+ TODO: check
+CVE-2026-18647 (A security vulnerability has been detected in jina-ai reader
up to 157 ...)
+ TODO: check
+CVE-2026-18646 (A weakness has been identified in danpros HTMLy up to 3.1.1.
This vuln ...)
+ TODO: check
+CVE-2026-18645 (A security flaw has been discovered in danpros HTMLy up to
3.1.1. This ...)
+ TODO: check
+CVE-2026-18644 (A vulnerability was identified in danpros HTMLy up to 3.1.1.
Affected ...)
+ TODO: check
+CVE-2026-18641 (A vulnerability was determined in Sangfor Operation and
Maintenance Se ...)
+ TODO: check
+CVE-2026-18632 (A security flaw has been discovered in langgenius dify up to
1.14.2. T ...)
+ TODO: check
+CVE-2026-18631 (A vulnerability was identified in jeequan jeepay up to 3.2.9.
This vul ...)
+ TODO: check
+CVE-2026-18569 (A flaw was found in the backchannel logout endpoint of the
keycloak-se ...)
+ TODO: check
+CVE-2026-17614 (A path traversal flaw was found in WildFly's domain mode
implementat ...)
+ TODO: check
+CVE-2026-16881 (A code injection vulnerability exists in the LINE Android app
prior to ...)
+ TODO: check
+CVE-2026-16623 (The Create Block WordPress plugin before 2.10.0 does not
correctly es ...)
+ TODO: check
+CVE-2026-16618 (The Improve SEO WordPress plugin through 2.0.11 does not
properly vali ...)
+ TODO: check
+CVE-2026-16548 (The Chat Widget: Floating Customer Support Button for 30+
Channels, Su ...)
+ TODO: check
+CVE-2026-16547 (The REST API Log WordPress plugin before 1.7.1 does not bind
the token ...)
+ TODO: check
+CVE-2026-16546 (The Wired Impact Volunteer Management WordPress plugin before
2.8.2 do ...)
+ TODO: check
+CVE-2026-16536 (The Simple Google Calendar Outlook Events Widget WordPress
plugin befo ...)
+ TODO: check
+CVE-2026-16296 (The Clearfy Cache WordPress plugin before 2.4.3 does not
validate the ...)
+ TODO: check
+CVE-2026-16295 (The Clearfy Cache WordPress plugin before 2.4.3 does not
perform a ca ...)
+ TODO: check
+CVE-2026-16293 (The PowerPress Podcasting plugin by Blubrry WordPress plugin
before 11 ...)
+ TODO: check
+CVE-2026-16070 (The Brizy WordPress plugin before 2.8.19 does not properly
verify aut ...)
+ TODO: check
+CVE-2026-16069 (The Brizy WordPress plugin before 2.8.19 does not sanitize or
escape ...)
+ TODO: check
+CVE-2026-16068 (The Brizy WordPress plugin before 2.8.19 does not properly
restrict w ...)
+ TODO: check
+CVE-2026-16056 (The Contest Gallery WordPress plugin before 30.0.7 does not
perform a ...)
+ TODO: check
+CVE-2026-16035 (The miniOrange 2FA WordPress plugin before 6.2.7 does not
restrict wh ...)
+ TODO: check
+CVE-2026-15958 (The Easy Integration for Dropbox WordPress plugin before
2.2.0 does n ...)
+ TODO: check
+CVE-2026-15233 (The Nested Pages WordPress plugin before 3.2.15 does not
properly esca ...)
+ TODO: check
+CVE-2026-14939 (The Visualizer WordPress plugin before 4.0.6 does not
restrict a user ...)
+ TODO: check
+CVE-2026-14872 (The Database for Contact Form 7, WPforms, Elementor forms
WordPress pl ...)
+ TODO: check
+CVE-2026-14848 (The Paid Membership Subscriptions WordPress plugin before
3.0.8 does ...)
+ TODO: check
+CVE-2026-14824 (The Quiz and Survey Master (QSM) WordPress plugin before
11.2.2 does ...)
+ TODO: check
+CVE-2026-14818 (A path traversal vulnerability in the CLI command used to
execute conf ...)
+ TODO: check
+CVE-2026-14816 (The GDPR Framework By Data443 WordPress plugin before 2.4.0
does not p ...)
+ TODO: check
+CVE-2026-12698 (The wpForo Forum WordPress plugin before 3.1.3 does not
restrict which ...)
+ TODO: check
+CVE-2026-11836 (Insufficient verification of data authenticity in Caliptra
Core ROM an ...)
+ TODO: check
+CVE-2026-11835 (Time-of-check time-of-use (TOCTOU) vulnerability combined with
missing ...)
+ TODO: check
+CVE-2026-11366 (The MonsterInsights WordPress plugin before 11.1.0 does not
correctly ...)
+ TODO: check
+CVE-2026-10849 (The hawkBit device management client in subsys/mgmt/hawkbit
accumulate ...)
+ TODO: check
+CVE-2026-10526 (The EmbedPress WordPress plugin before 4.6.1 does not
validate user-s ...)
+ TODO: check
CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its
authen ...)
NOT-FOR-US: PaperCut
CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive
authentication att ...)
@@ -1115,7 +1393,7 @@ CVE-2026-68574
REJECTED
CVE-2026-67822 (Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow
vulnera ...)
NOT-FOR-US: Tenda
-CVE-2026-67607 (LightFTP 2.3.1 contains a race condition vulnerability that
allows rem ...)
+CVE-2026-67607 (LightFTP 2.3.1 contains a residual race condition
vulnerability (an in ...)
NOT-FOR-US: LightFTP
CVE-2026-67350 (Serendipity before 2.6.1 contains an open redirect
vulnerability in ex ...)
- serendipity <removed>
@@ -2121,25 +2399,25 @@ CVE-2026-XXXX [OSSA-2026-030 Swift: S3API header
authorization bypass]
CVE-2022-4994 (In the Linux kernel, the following vulnerability has been
resolved: K ...)
- linux 6.0.2-1
NOTE:
https://git.kernel.org/linus/dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3 (6.0-rc1)
-CVE-2026-58044
+CVE-2026-58044 (A flaw in Node.js HTTP client can cause a request
desynchronization fo ...)
- nodejs <unfixed>
NOTE:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http-parser-header-truncation-can-enable-request-smuggling-cve-2026-58044---low
CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows
process.report w ...)
- nodejs <unfixed>
NOTE:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-process-reports-to-write-outside-the-allowlist-cve-2026-58039---low
-CVE-2026-58045
+CVE-2026-58045 (A flaw in Node.js allows a spoofed `TypedArray` `byteLength`
to trigge ...)
- nodejs <unfixed>
NOTE:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodezlib-sync-apis-can-crash-on-spoofed-typedarray-length-cve-2026-58045---medium
-CVE-2026-58042
+CVE-2026-58042 (A flaw in Node.js can cause dns.resolveAny() Aborts the
Node.js Proces ...)
- nodejs <unfixed>
NOTE:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#dnsresolveany-can-abort-on-dns-responses-with-many-a-records-cve-2026-58042---medium
-CVE-2026-58041
+CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale
StatementSyncIterator cre ...)
- nodejs <unfixed>
NOTE:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodesqlite-sqltagstore-iterator-replay-can-re-execute-writes-cve-2026-58041---medium
CVE-2026-56848
- nodejs <unfixed>
NOTE:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-re-entrant-send-can-cause-heap-use-after-free-cve-2026-56848---high
-CVE-2026-56846
+CVE-2026-56846 (A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
header blo ...)
- nodejs <unfixed>
NOTE:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-retained-headers-can-bypass-maxsessionmemory-limits-cve-2026-56846---high
CVE-2026-66066 (Action Pack is a framework for handling and responding to web
requests ...)
@@ -16753,7 +17031,7 @@ CVE-2026-54496 (ZEBRA is a Zcash node written entirely
in Rust. Prior to zebrad
NOT-FOR-US: ZEBRA
CVE-2026-53712 (SCRAM (Salted Challenge Response Authentication Mechanism) is
part of ...)
NOT-FOR-US: com.ongres.scram:scram-client and
com.ongres.scram:scram-common
-CVE-2026-52746 (JSONata is a JSON query and transformation language. Prior to
2.2.0, m ...)
+CVE-2026-52746 (JSONata is a JSON query and transformation language. Prior to
2.2.0 an ...)
NOT-FOR-US: jsonata-js
CVE-2026-51083 (Incorrect access control in Proxmox Virtual Environment (PVE)
9.x qemu ...)
NOT-FOR-US: Proxmox
@@ -23295,7 +23573,8 @@ CVE-2026-14361 (The consul-template library before
version 0.42.1 is vulnerable
NOT-FOR-US: consul-template library
CVE-2026-13320 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
-CVE-2026-13151 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
+CVE-2026-13151
+ REJECTED
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-12517 (The Fediverse Embeds WordPress plugin before 1.5.8 does not
validate t ...)
NOT-FOR-US: WordPress plugin
@@ -63813,7 +64092,7 @@ CVE-2026-44223 (vLLM is an inference and serving engine
for large language model
- vllm <itp> (bug #1095237)
CVE-2026-44222 (vLLM is an inference and serving engine for large language
models (LLM ...)
- vllm <itp> (bug #1095237)
-CVE-2026-44221 (ArcadeDB is a Multi-Model DBMS. Prior to 2.6.4, authenticated
users an ...)
+CVE-2026-44221 (ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1
and prior ...)
NOT-FOR-US: ArcadeDB
CVE-2026-44220 (ciguard is a static security auditor for CI/CD pipelines. From
0.8.0 t ...)
NOT-FOR-US: ciguard
@@ -76834,6 +77113,7 @@ CVE-2026-41318 (AnythingLLM is an application that
turns pieces of content into
CVE-2026-41317 (Press, a Frappe custom app that runs Frappe Cloud, manages
infrastruct ...)
NOT-FOR-US: Press (Frapp app)
CVE-2026-41316 (ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB
2.2.0 was ...)
+ {DLA-4716-1}
- ruby3.3 <unfixed> (bug #1134920)
- ruby3.1 <removed>
- ruby2.7 <removed>
@@ -81258,6 +81538,7 @@ CVE-2026-2336 (A privilege escalation vulnerability in
Microchip IStaX allows an
CVE-2026-28741 (Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0,
11.4.x <= 1 ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-27820 (zlib is a Ruby interface for the zlib
compression/decompression librar ...)
+ {DLA-4716-1}
- ruby3.3 <unfixed> (bug #1134341)
- ruby3.1 <removed>
- ruby2.7 <removed>
@@ -100468,7 +100749,7 @@ CVE-2026-3060 (SGLang' encoder parallel
disaggregation system is vulnerable to u
NOT-FOR-US: sgl-project sglang
CVE-2026-3059 (SGLang's multimodal generation module is vulnerable to
unauthenticated ...)
NOT-FOR-US: sgl-project sglang
-CVE-2026-32274 (Black is the uncompromising Python code formatter. Prior to
26.3.1, Bl ...)
+CVE-2026-32274 (Black is the uncompromising Python code formatter. Starting in
version ...)
- black 26.3.1-1 (bug #1130657)
[trixie] - black 25.1.0-3+deb13u1
[bookworm] - black <no-dsa> (Minor issue)
@@ -130993,6 +131274,7 @@ CVE-2025-66723 (inMusic Brands Engine DJ before 4.3.4
suffers from Insecure Perm
CVE-2025-62753 (Improper Control of Filename for Include/Require Statement in
PHP Prog ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2025-61594 (URI is a module providing classes to handle Uniform Resource
Identifie ...)
+ {DLA-4716-1}
- ruby3.3 <unfixed> (bug #1124379)
[trixie] - ruby3.3 <no-dsa> (Minor issue)
- ruby3.1 <removed>
@@ -191796,6 +192078,7 @@ CVE-2025-53871
CVE-2025-53636 (Open OnDemand is an open-source HPC portal. Users can flood
logs by in ...)
NOT-FOR-US: Open OnDemand
CVE-2025-24294 (The attack vector is a potential Denial of Service (DoS). The
vulnerab ...)
+ {DLA-4716-1}
- ruby3.3 <unfixed> (bug #1109337)
[trixie] - ruby3.3 <no-dsa> (Minor issue)
- ruby3.1 <removed>
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/157b9e0f75743b5a045b1510d45a54ca20ac679e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/157b9e0f75743b5a045b1510d45a54ca20ac679e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits