Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
53859688 by Salvatore Bonaccorso at 2026-08-08T11:42:11+02:00
Track fixes via unstable for four node-re2 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -457,7 +457,7 @@ CVE-2026-71554 (h2 is a pure-Python implementation of a
HTTP/2 protocol stack. V
CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting
vulnerability cau ...)
NOT-FOR-US: CTI-Transmute
CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js.
Prior t ...)
- - node-re2 <unfixed> (bug #1143901)
+ - node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
NOTE:
https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg
NOTE: https://github.com/uhop/node-re2/issues/272
NOTE: Fixed by:
https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4
(1.26.1)
@@ -505,7 +505,7 @@ CVE-2026-71434 (Statamic is a Laravel and Git powered
content management system
CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the
Postgres a ...)
NOT-FOR-US: LangGraph Checkpoint
CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js.
Prior t ...)
- - node-re2 <unfixed> (bug #1143901)
+ - node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
NOTE:
https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp
CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load
balancer. From 3 ...)
- traefik <itp> (bug #983289)
@@ -5070,13 +5070,13 @@ CVE-2026-68501 (Sylius Mollie Plugin provides Mollie
payment integration for Syl
CVE-2026-68500 (Sylius Mollie Plugin provides Mollie payment integration for
Sylius ap ...)
NOT-FOR-US: Sylius Mollie Plugin
CVE-2026-68499 (re2 provides Node.js bindings for Google's RE2 regular
expression engi ...)
- - node-re2 <unfixed> (bug #1143179)
+ - node-re2 1.26.1+~cs1.7.0-1 (bug #1143179)
NOTE:
https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836
NOTE: Fixed by:
https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d
(1.25.2)
CVE-2026-67594 (Spikster through commit e1cdf8c contains a missing
authentication vuln ...)
NOT-FOR-US: Spikster
CVE-2026-67550 (re2 provides Node.js bindings for Google's RE2 regular
expression engi ...)
- - node-re2 <unfixed> (bug #1143179)
+ - node-re2 1.26.1+~cs1.7.0-1 (bug #1143179)
NOTE:
https://github.com/uhop/node-re2/security/advisories/GHSA-ff84-5f28-78qj
NOTE: Fixed by:
https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d
(1.25.2)
CVE-2026-67530 (WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0
and earli ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53859688556d407167856206c898062b4734aae6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53859688556d407167856206c898062b4734aae6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits