Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3dc015f0 by security tracker role at 2026-08-11T07:13:33+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,293 @@
+CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, 
GPUTweakII, AI Su ...)
+       TODO: check
+CVE-2026-8718 (tls_opt_dtls_peer_connection_id_value_get() in 
subsys/net/lib/sockets/ ...)
+       TODO: check
+CVE-2026-8158 (The Signed Video Framework contained a buffer overflow issue  
which co ...)
+       TODO: check
+CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84, 
contains a  ...)
+       TODO: check
+CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 
contains a path ...)
+       TODO: check
+CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a 
path trave ...)
+       TODO: check
+CVE-2026-72919 (Rocket.Chat is an open-source, secure, fully customizable 
communicatio ...)
+       TODO: check
+CVE-2026-72918 (Rocket.Chat is an open-source, secure, fully customizable 
communicatio ...)
+       TODO: check
+CVE-2026-72917 (AnythingLLM is an application that turns pieces of content 
into contex ...)
+       TODO: check
+CVE-2026-72916 (Mastodon is a free, open-source social network server based on 
Activit ...)
+       TODO: check
+CVE-2026-72915 (Mastodon is a free, open-source social network server based on 
Activit ...)
+       TODO: check
+CVE-2026-72914 (Mastodon is a free, open-source social network server based on 
Activit ...)
+       TODO: check
+CVE-2026-72913 (Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, 
the @ki ...)
+       TODO: check
+CVE-2026-72912 (CyberChef is a web app for encryption, encoding, compression, 
and data ...)
+       TODO: check
+CVE-2026-72911 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-72910 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-72909 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-72908 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-72907 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-72906 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-72905
+       REJECTED
+CVE-2026-72904 (Firecrawl turns entire websites into LLM-ready markdown or 
structured  ...)
+       TODO: check
+CVE-2026-72903 (Tabby (formerly Terminus) is a highly configurable terminal 
emulator.  ...)
+       TODO: check
+CVE-2026-72902 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72901 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72886 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
From 0. ...)
+       TODO: check
+CVE-2026-72885 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72884 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72883 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72882 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
In 0.28 ...)
+       TODO: check
+CVE-2026-72881 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72880 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72879 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72878 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72877 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72876 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72875 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72874 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a 
stored cros ...)
+       TODO: check
+CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
authenticated c ...)
+       TODO: check
+CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
authenticated r ...)
+       TODO: check
+CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use 
(TOCTOU) ra ...)
+       TODO: check
+CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost 
inflight migra ...)
+       TODO: check
+CVE-2026-6181 (The Device Configuration Framework is vulnerable to an 
authentication  ...)
+       TODO: check
+CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection 
vulnera ...)
+       TODO: check
+CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown 
rendering an ...)
+       TODO: check
+CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel 
message ...)
+       TODO: check
+CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path 
traversal vulne ...)
+       TODO: check
+CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP 
NetWeaver App ...)
+       TODO: check
+CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request 
headers b ...)
+       TODO: check
+CVE-2026-66777 (SAP Approuter does not sufficiently validate certain incoming 
requests ...)
+       TODO: check
+CVE-2026-66776 (SAP Approuter does not consistently enforce integrity 
verification on  ...)
+       TODO: check
+CVE-2026-66775 (SAP Approuter does not enforce cross-site request forgery 
protection o ...)
+       TODO: check
+CVE-2026-66774 (SAP Approuter does not consistently handle certain error 
conditions. A ...)
+       TODO: check
+CVE-2026-66773 (A malicious or compromised OData service could disclose 
sensitive auth ...)
+       TODO: check
+CVE-2026-66772 (SAP BusinessObjects Business Intelligence Platform (Admin 
Tools)  does ...)
+       TODO: check
+CVE-2026-66771 (SAPUI5 allows a key user with content adaptation privileges to 
inject  ...)
+       TODO: check
+CVE-2026-66770 (Due to an SQL Injection vulnerability in SAP Social 
intelligence, an a ...)
+       TODO: check
+CVE-2026-66764 (Reprocess Bank Statement Items in SAP S/4HANA does not perform 
the nec ...)
+       TODO: check
+CVE-2026-66763 (SAP BusinessObjects Business Intelligence Platform stores 
certain sens ...)
+       TODO: check
+CVE-2026-66761 (SAP Approuter does not enforce sufficient flow control in 
certain func ...)
+       TODO: check
+CVE-2026-66760 (SAP Approuter does not correctly validate client certificates 
in certa ...)
+       TODO: check
+CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a 
process  ...)
+       TODO: check
+CVE-2026-5304 (An ACAP configuration file lacks input validation, which could 
potenti ...)
+       TODO: check
+CVE-2026-5303 (The ACAP framework contains a Time-of-Check to Time-of-Use 
(TOCTOU) ra ...)
+       TODO: check
+CVE-2026-58248 (SAP BusinessObjects Business Intelligence Platform (Web 
Intelligence)  ...)
+       TODO: check
+CVE-2026-58247 (SAP ABAP Platform allows an unauthenticated user to send a 
specially c ...)
+       TODO: check
+CVE-2026-58245 (SAP Advanced Planning and Optimization (Model Mix Planning) 
contains a ...)
+       TODO: check
+CVE-2026-58244 (SAP Manufacturing Integration and Intelligence (MII) does not 
perform  ...)
+       TODO: check
+CVE-2026-58243 (SAP ABAP Development Tools does not perform necessary 
authorization ch ...)
+       TODO: check
+CVE-2026-58241 (SAP NetWeaver and ABAP Platform (Change and Transport System - 
Custome ...)
+       TODO: check
+CVE-2026-58239 (SAP Approuter does not sufficiently validate tenant context in 
inbound ...)
+       TODO: check
+CVE-2026-58238 (SAP Approuter does not sufficiently handle certain requests 
under spec ...)
+       TODO: check
+CVE-2026-58237 (WebSocket of SAP Approuter does not perform sufficient 
authorization c ...)
+       TODO: check
+CVE-2026-58236 (SAP NetWeaver Application Server ABAP and ABAP Platform allow 
an attac ...)
+       TODO: check
+CVE-2026-58235 (SAP NetWeaver Application Server Java (Adobe Document Service) 
uses ou ...)
+       TODO: check
+CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token 
content und ...)
+       TODO: check
+CVE-2026-4757 (A VAPIX API parameter had improper input validation which could 
allow  ...)
+       TODO: check
+CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19 
01:07:01 a ...)
+       TODO: check
+CVE-2026-48160 (react-tracked provides state usage tracking with Proxies. 
Between 2026 ...)
+       TODO: check
+CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP 
Manufacturin ...)
+       TODO: check
+CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP 
Manufacturin ...)
+       TODO: check
+CVE-2026-44763 (SAP Manufacturing Integration and Intelligence allows a 
privileged att ...)
+       TODO: check
+CVE-2026-44762 (SAP Data Services Management Console allows an overly 
permissive Conte ...)
+       TODO: check
+CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an 
attacke ...)
+       TODO: check
+CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site 
scripting vu ...)
+       TODO: check
+CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in 
the han ...)
+       TODO: check
+CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an 
unauthenticated attack ...)
+       TODO: check
+CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker, 
authenticated as  ...)
+       TODO: check
+CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated 
as an ad ...)
+       TODO: check
+CVE-2026-19518 (Improper Validation of Specified Quantity in Input 
vulnerability in Sa ...)
+       TODO: check
+CVE-2026-19517 (Improper Validation of Specified Quantity in Input and 
Allocation of R ...)
+       TODO: check
+CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the 
destinatio ...)
+       TODO: check
+CVE-2026-19425 (Travel Agency Management System developed by Win Men 
Intermational has ...)
+       TODO: check
+CVE-2026-19424 (Chiline Cloud developed by Inventec Appliances has a Insecure 
Direct O ...)
+       TODO: check
+CVE-2026-19411 (A NULL pointer vulnerability has been found in the the shim 
applicatio ...)
+       TODO: check
+CVE-2026-19391 (A flaw was found in insights-core where the password redaction 
layer f ...)
+       TODO: check
+CVE-2026-18982 (A flaw was found in the RHOAI training-operator. This 
vulnerability al ...)
+       TODO: check
+CVE-2026-18951 (A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay 
for the t ...)
+       TODO: check
+CVE-2026-18950 (A flaw was found in odh-dashboard. An authenticated user of 
the dashbo ...)
+       TODO: check
+CVE-2026-18949 (A flaw was found in odh-dashboard. This vulnerability allows 
an attack ...)
+       TODO: check
+CVE-2026-18948 (A flaw was found in Feast. The system improperly deserializes 
user-def ...)
+       TODO: check
+CVE-2026-18947 (A flaw was found in Feast. An authorization bypass 
vulnerability exist ...)
+       TODO: check
+CVE-2026-18942 (A flaw was found in the Feast operator. A malicious tenant 
could injec ...)
+       TODO: check
+CVE-2026-18941 (A flaw was found in Feast and feast-operator. The default 
configuratio ...)
+       TODO: check
+CVE-2026-18621 (A flaw was found in Data Science Pipelines (DSP). An attacker 
with nam ...)
+       TODO: check
+CVE-2026-18620 (A flaw was found in Data Science Pipelines. A restricted user, 
or tena ...)
+       TODO: check
+CVE-2026-18618 (A flaw was found in ml-metadata. The statically-linked gRPC 
stack in m ...)
+       TODO: check
+CVE-2026-18617 (A flaw was found in the Data Science Pipelines Operator 
(DSPO). A name ...)
+       TODO: check
+CVE-2026-18611 (A flaw was found in the Data Science Pipelines Operator. This 
vulnerab ...)
+       TODO: check
+CVE-2026-18608 (A flaw was found in the Data Science Pipelines Operator 
(DSPO). The op ...)
+       TODO: check
+CVE-2026-18348 (Missing authorization check in the upload_azure, upload_sftp, 
and uplo ...)
+       TODO: check
+CVE-2026-16974 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
+       TODO: check
+CVE-2026-16456 (A flaw was found in the `odh-model-controller`. An 
authenticated user  ...)
+       TODO: check
+CVE-2026-16053 (Zohocorp ManageEngineM365 Manager Plus and M365 Security Plus 
versions ...)
+       TODO: check
+CVE-2026-15581 (A flaw was found in the TrustyAI Service (TAS) deployment. 
This vulner ...)
+       TODO: check
+CVE-2026-15467 (A flaw was found in the trustyai-service-operator's LMEvalJob 
controll ...)
+       TODO: check
+CVE-2026-14886 (Vault Enterprise's identity entity batch-delete endpoint is 
vulnerable ...)
+       TODO: check
+CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3 
does not ...)
+       TODO: check
+CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3 
does not ...)
+       TODO: check
+CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows 
any pod wi ...)
+       TODO: check
+CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS 
Gateway. Imp ...)
+       TODO: check
+CVE-2026-13716 (Path traversal in server import and admin file upload in 
Crafty Contro ...)
+       TODO: check
+CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler 
usbd_cdc_ncm ...)
+       TODO: check
+CVE-2026-12051 (The USB DFU class implementation in Zephyr's new 
(experimental) device ...)
+       TODO: check
+CVE-2026-11985 (On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) 
forces  ...)
+       TODO: check
+CVE-2026-11894 (The Realtek BEE Bluetooth HCI driver's send callback, 
bt_hci_bee_send( ...)
+       TODO: check
+CVE-2026-11893 (The Bluetooth HCI driver for Bouffalo Lab on-chip BLE 
controllers (BL6 ...)
+       TODO: check
+CVE-2026-11812 (The UpdateHub management subsystem 
(subsys/mgmt/updatehub/updatehub.c) ...)
+       TODO: check
+CVE-2026-11811 (The UpdateHub over-the-air update client's start_coap_client() 
in subs ...)
+       TODO: check
+CVE-2026-11810 (The UpdateHub firmware-update agent's probe handler 
(z_impl_updatehub_ ...)
+       TODO: check
+CVE-2026-11809 (The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c 
contains ...)
+       TODO: check
+CVE-2025-32736 (Cross-Site Request Forgery weaknesses in the Administrative 
Console of ...)
+       TODO: check
+CVE-2025-30241 (Certain web interface components in affected TP-Link Aginet 
devices do ...)
+       TODO: check
+CVE-2025-30240 (The affected TP-Link Aginet devices do not properly validate 
symbolic  ...)
+       TODO: check
+CVE-2025-30239 (In affected TP-Link Aginet devices, use of hardcoded 
cryptographic key ...)
+       TODO: check
+CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization 
validat ...)
+       TODO: check
+CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web 
managemen ...)
+       TODO: check
+CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple 
unauthenticated denial ...)
+       TODO: check
+CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated 
resource exh ...)
+       TODO: check
+CVE-2025-15681 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication 
bypass in its ...)
+       TODO: check
+CVE-2025-15680 (TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the 
device's ...)
+       TODO: check
+CVE-2025-13294 (An unauthenticated SQL injection vulnerability exists in the 
web serve ...)
+       TODO: check
+CVE-2025-13293 (A hard-coded or default root account credential in TBEA 
TLogger V2.1.0 ...)
+       TODO: check
 CVE-2026-19349
        - lemonldap-ng <unfixed>
        NOTE: 
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d
 (v2.23.3)
@@ -5818,7 +6108,7 @@ CVE-2026-18774 (A flaw has been found in NousResearch 
hermes-agent up to 0.16.0.
        NOT-FOR-US: NousResearch
 CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up 
to 2026.6 ...)
        NOT-FOR-US: NousResearch
-CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source 
rlottie ...)
+CVE-2026-18772 (Improperly controlled sequential memory allocation 
vulnerability in Sa ...)
        - rlottie <unfixed> (bug #1143931)
        [trixie] - rlottie <no-dsa> (Minor issue)
        NOTE: https://github.com/Samsung/rlottie/pull/596
@@ -24318,22 +24608,22 @@ CVE-2023-49899 (An unauthenticated remote attacker 
canexecute any command on the
 CVE-2019-25764 (**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient 
Access C ...)
        NOT-FOR-US: ASUS
 CVE-2026-57077 (YAML::Syck versions before 1.47 for Perl allow an 
out-of-bounds read v ...)
-       {DSA-6428-1}
+       {DSA-6428-1 DLA-4730-1}
        - libyaml-syck-perl 1.47-1 (bug #1142267)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898716/
        NOTE: Fixed by: 
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
 (1.47)
 CVE-2026-57076 (YAML::Syck versions before 1.47 for Perl allow a heap 
use-after-free v ...)
-       {DSA-6428-1}
+       {DSA-6428-1 DLA-4730-1}
        - libyaml-syck-perl 1.47-1 (bug #1142267)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898718/
        NOTE: Fixed by: 
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
 (1.47)
 CVE-2026-57075 (YAML::Syck versions before 1.47 for Perl allow an 
out-of-bounds read v ...)
-       {DSA-6428-1}
+       {DSA-6428-1 DLA-4730-1}
        - libyaml-syck-perl 1.47-1 (bug #1142267)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898720/
        NOTE: Fixed by: 
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
 (1.47)
 CVE-2026-13713 (YAML::Syck versions before 1.47 for Perl allow a 
use-after-free and do ...)
-       {DSA-6428-1}
+       {DSA-6428-1 DLA-4730-1}
        - libyaml-syck-perl 1.47-1 (bug #1142267)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898719/
        NOTE: Fixed by: 
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
 (1.47)
@@ -43322,9 +43612,11 @@ CVE-2026-53753 (Crawl4AI is an open-source LLM 
friendly web crawler & scraper. P
 CVE-2026-53662 (immich is a high performance self-hosted photo and video 
management so ...)
        NOT-FOR-US: immich
 CVE-2026-52846 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
+       {DSA-6429-1}
        - caddy 2.11.4-1 (bug #1140773)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-vcc4-2c75-vc9v
 CVE-2026-52845 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
+       {DSA-6429-1}
        - caddy 2.11.4-1 (bug #1140773)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-f59h-q822-g45g
 CVE-2026-52844 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
@@ -43390,6 +43682,7 @@ CVE-2026-48519 (Langflow is a tool for building and 
deploying AI-powered agents
 CVE-2026-45732 (n8n is an open source workflow automation platform. Prior to 
1.123.43, ...)
        NOT-FOR-US: n8n
 CVE-2026-45692 (Caddy is an extensible server platform that uses TLS by 
default. From  ...)
+       {DSA-6429-1}
        - caddy 2.11.4-1 (bug #1140773)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-x5w9-xh9r-mvfc
 CVE-2026-45135 (Caddy is an extensible server platform that uses TLS by 
default. From  ...)
@@ -71854,7 +72147,7 @@ CVE-2025-54518 (Improper isolation of shared resources 
within the CPU operation
        NOTE: https://xenbits.xen.org/xsa/advisory-490.html
        NOTE: 
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html
 CVE-2026-5089 (YAML::Syck versions before 1.38 for Perl  has an out-of-bounds 
read.   ...)
-       {DSA-6428-1}
+       {DSA-6428-1 DLA-4730-1}
        - libyaml-syck-perl 1.36-3
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/39981051/
        NOTE: https://github.com/cpan-authors/YAML-Syck/issues/132
@@ -114826,15 +115119,19 @@ CVE-2026-2459 (A vulnerability exists in REB500 for 
an authenticated user with I
 CVE-2026-27732 (WWBN AVideo is an open source video platform. Prior to version 
22.0, t ...)
        NOT-FOR-US: WWBN AVideo
 CVE-2026-27590 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
+       {DSA-6429-1}
        - caddy 2.11.2-1 (bug #1132041)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-5r3v-vc8m-m96g
 CVE-2026-27589 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
+       {DSA-6429-1}
        - caddy 2.11.2-1 (bug #1132041)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-879p-475x-rqh2
 CVE-2026-27588 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
+       {DSA-6429-1}
        - caddy 2.11.2-1 (bug #1132041)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-x76f-jf84-rqj8
 CVE-2026-27587 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
+       {DSA-6429-1}
        - caddy 2.11.2-1 (bug #1132041)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-g7pc-pc7g-h8jh
 CVE-2026-27586 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
@@ -114848,6 +115145,7 @@ CVE-2026-27586 (Caddy is an extensible server 
platform that uses TLS by default.
        NOTE: convertPEMFilesToDER() were all added by the trusted CA provider 
modularization
        NOTE: in 2.8.0; 2.6.2 has no such function and no swallowed error to 
fail open on.
 CVE-2026-27585 (Caddy is an extensible server platform that uses TLS by 
default. Prior ...)
+       {DSA-6429-1}
        - caddy 2.11.2-1 (bug #1132041)
        NOTE: 
https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4
 CVE-2026-27584 (Actual is a local-first personal finance tool. Prior to 
version 26.2.1 ...)
@@ -143282,7 +143580,7 @@ CVE-2025-14849 (Advantech WebAccess/SCADA is 
vulnerable to unrestricted file upl
        NOT-FOR-US: Advantech
 CVE-2025-14848 (Advantech WebAccess/SCADA is vulnerable to absolute directory 
traversa ...)
        NOT-FOR-US: Advantech
-CVE-2025-14733 (An Out-of-bounds Write vulnerability in WatchGuard Fireware OS 
may all ...)
+CVE-2025-14733 (An Out-of-bounds Write vulnerability in the WatchGuard 
Fireware OS ike ...)
        NOT-FOR-US: WatchGuard
 CVE-2025-14546 (Versions of the package fastapi-sso before 0.19.0 are 
vulnerable to Cr ...)
        NOT-FOR-US: fastapi-sso



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc015f04b27f901f9326e68d33226b9a64163f4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc015f04b27f901f9326e68d33226b9a64163f4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to