Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3dc015f0 by security tracker role at 2026-08-11T07:13:33+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,293 @@
+CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III,
GPUTweakII, AI Su ...)
+ TODO: check
+CVE-2026-8718 (tls_opt_dtls_peer_connection_id_value_get() in
subsys/net/lib/sockets/ ...)
+ TODO: check
+CVE-2026-8158 (The Signed Video Framework contained a buffer overflow issue
which co ...)
+ TODO: check
+CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84,
contains a ...)
+ TODO: check
+CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3
contains a path ...)
+ TODO: check
+CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a
path trave ...)
+ TODO: check
+CVE-2026-72919 (Rocket.Chat is an open-source, secure, fully customizable
communicatio ...)
+ TODO: check
+CVE-2026-72918 (Rocket.Chat is an open-source, secure, fully customizable
communicatio ...)
+ TODO: check
+CVE-2026-72917 (AnythingLLM is an application that turns pieces of content
into contex ...)
+ TODO: check
+CVE-2026-72916 (Mastodon is a free, open-source social network server based on
Activit ...)
+ TODO: check
+CVE-2026-72915 (Mastodon is a free, open-source social network server based on
Activit ...)
+ TODO: check
+CVE-2026-72914 (Mastodon is a free, open-source social network server based on
Activit ...)
+ TODO: check
+CVE-2026-72913 (Kitty is a cross-platform GPU based terminal. Prior to 0.48.2,
the @ki ...)
+ TODO: check
+CVE-2026-72912 (CyberChef is a web app for encryption, encoding, compression,
and data ...)
+ TODO: check
+CVE-2026-72911 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-72910 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-72909 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-72908 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-72907 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-72906 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-72905
+ REJECTED
+CVE-2026-72904 (Firecrawl turns entire websites into LLM-ready markdown or
structured ...)
+ TODO: check
+CVE-2026-72903 (Tabby (formerly Terminus) is a highly configurable terminal
emulator. ...)
+ TODO: check
+CVE-2026-72902 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72901 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72886 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
From 0. ...)
+ TODO: check
+CVE-2026-72885 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72884 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72883 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72882 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
In 0.28 ...)
+ TODO: check
+CVE-2026-72881 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72880 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72879 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72878 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72877 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72876 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72875 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72874 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a
stored cros ...)
+ TODO: check
+CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an
authenticated c ...)
+ TODO: check
+CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an
authenticated r ...)
+ TODO: check
+CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use
(TOCTOU) ra ...)
+ TODO: check
+CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost
inflight migra ...)
+ TODO: check
+CVE-2026-6181 (The Device Configuration Framework is vulnerable to an
authentication ...)
+ TODO: check
+CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection
vulnera ...)
+ TODO: check
+CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown
rendering an ...)
+ TODO: check
+CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel
message ...)
+ TODO: check
+CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path
traversal vulne ...)
+ TODO: check
+CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP
NetWeaver App ...)
+ TODO: check
+CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request
headers b ...)
+ TODO: check
+CVE-2026-66777 (SAP Approuter does not sufficiently validate certain incoming
requests ...)
+ TODO: check
+CVE-2026-66776 (SAP Approuter does not consistently enforce integrity
verification on ...)
+ TODO: check
+CVE-2026-66775 (SAP Approuter does not enforce cross-site request forgery
protection o ...)
+ TODO: check
+CVE-2026-66774 (SAP Approuter does not consistently handle certain error
conditions. A ...)
+ TODO: check
+CVE-2026-66773 (A malicious or compromised OData service could disclose
sensitive auth ...)
+ TODO: check
+CVE-2026-66772 (SAP BusinessObjects Business Intelligence Platform (Admin
Tools) does ...)
+ TODO: check
+CVE-2026-66771 (SAPUI5 allows a key user with content adaptation privileges to
inject ...)
+ TODO: check
+CVE-2026-66770 (Due to an SQL Injection vulnerability in SAP Social
intelligence, an a ...)
+ TODO: check
+CVE-2026-66764 (Reprocess Bank Statement Items in SAP S/4HANA does not perform
the nec ...)
+ TODO: check
+CVE-2026-66763 (SAP BusinessObjects Business Intelligence Platform stores
certain sens ...)
+ TODO: check
+CVE-2026-66761 (SAP Approuter does not enforce sufficient flow control in
certain func ...)
+ TODO: check
+CVE-2026-66760 (SAP Approuter does not correctly validate client certificates
in certa ...)
+ TODO: check
+CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a
process ...)
+ TODO: check
+CVE-2026-5304 (An ACAP configuration file lacks input validation, which could
potenti ...)
+ TODO: check
+CVE-2026-5303 (The ACAP framework contains a Time-of-Check to Time-of-Use
(TOCTOU) ra ...)
+ TODO: check
+CVE-2026-58248 (SAP BusinessObjects Business Intelligence Platform (Web
Intelligence) ...)
+ TODO: check
+CVE-2026-58247 (SAP ABAP Platform allows an unauthenticated user to send a
specially c ...)
+ TODO: check
+CVE-2026-58245 (SAP Advanced Planning and Optimization (Model Mix Planning)
contains a ...)
+ TODO: check
+CVE-2026-58244 (SAP Manufacturing Integration and Intelligence (MII) does not
perform ...)
+ TODO: check
+CVE-2026-58243 (SAP ABAP Development Tools does not perform necessary
authorization ch ...)
+ TODO: check
+CVE-2026-58241 (SAP NetWeaver and ABAP Platform (Change and Transport System -
Custome ...)
+ TODO: check
+CVE-2026-58239 (SAP Approuter does not sufficiently validate tenant context in
inbound ...)
+ TODO: check
+CVE-2026-58238 (SAP Approuter does not sufficiently handle certain requests
under spec ...)
+ TODO: check
+CVE-2026-58237 (WebSocket of SAP Approuter does not perform sufficient
authorization c ...)
+ TODO: check
+CVE-2026-58236 (SAP NetWeaver Application Server ABAP and ABAP Platform allow
an attac ...)
+ TODO: check
+CVE-2026-58235 (SAP NetWeaver Application Server Java (Adobe Document Service)
uses ou ...)
+ TODO: check
+CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token
content und ...)
+ TODO: check
+CVE-2026-4757 (A VAPIX API parameter had improper input validation which could
allow ...)
+ TODO: check
+CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19
01:07:01 a ...)
+ TODO: check
+CVE-2026-48160 (react-tracked provides state usage tracking with Proxies.
Between 2026 ...)
+ TODO: check
+CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP
Manufacturin ...)
+ TODO: check
+CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP
Manufacturin ...)
+ TODO: check
+CVE-2026-44763 (SAP Manufacturing Integration and Intelligence allows a
privileged att ...)
+ TODO: check
+CVE-2026-44762 (SAP Data Services Management Console allows an overly
permissive Conte ...)
+ TODO: check
+CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an
attacke ...)
+ TODO: check
+CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site
scripting vu ...)
+ TODO: check
+CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in
the han ...)
+ TODO: check
+CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an
unauthenticated attack ...)
+ TODO: check
+CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker,
authenticated as ...)
+ TODO: check
+CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated
as an ad ...)
+ TODO: check
+CVE-2026-19518 (Improper Validation of Specified Quantity in Input
vulnerability in Sa ...)
+ TODO: check
+CVE-2026-19517 (Improper Validation of Specified Quantity in Input and
Allocation of R ...)
+ TODO: check
+CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the
destinatio ...)
+ TODO: check
+CVE-2026-19425 (Travel Agency Management System developed by Win Men
Intermational has ...)
+ TODO: check
+CVE-2026-19424 (Chiline Cloud developed by Inventec Appliances has a Insecure
Direct O ...)
+ TODO: check
+CVE-2026-19411 (A NULL pointer vulnerability has been found in the the shim
applicatio ...)
+ TODO: check
+CVE-2026-19391 (A flaw was found in insights-core where the password redaction
layer f ...)
+ TODO: check
+CVE-2026-18982 (A flaw was found in the RHOAI training-operator. This
vulnerability al ...)
+ TODO: check
+CVE-2026-18951 (A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay
for the t ...)
+ TODO: check
+CVE-2026-18950 (A flaw was found in odh-dashboard. An authenticated user of
the dashbo ...)
+ TODO: check
+CVE-2026-18949 (A flaw was found in odh-dashboard. This vulnerability allows
an attack ...)
+ TODO: check
+CVE-2026-18948 (A flaw was found in Feast. The system improperly deserializes
user-def ...)
+ TODO: check
+CVE-2026-18947 (A flaw was found in Feast. An authorization bypass
vulnerability exist ...)
+ TODO: check
+CVE-2026-18942 (A flaw was found in the Feast operator. A malicious tenant
could injec ...)
+ TODO: check
+CVE-2026-18941 (A flaw was found in Feast and feast-operator. The default
configuratio ...)
+ TODO: check
+CVE-2026-18621 (A flaw was found in Data Science Pipelines (DSP). An attacker
with nam ...)
+ TODO: check
+CVE-2026-18620 (A flaw was found in Data Science Pipelines. A restricted user,
or tena ...)
+ TODO: check
+CVE-2026-18618 (A flaw was found in ml-metadata. The statically-linked gRPC
stack in m ...)
+ TODO: check
+CVE-2026-18617 (A flaw was found in the Data Science Pipelines Operator
(DSPO). A name ...)
+ TODO: check
+CVE-2026-18611 (A flaw was found in the Data Science Pipelines Operator. This
vulnerab ...)
+ TODO: check
+CVE-2026-18608 (A flaw was found in the Data Science Pipelines Operator
(DSPO). The op ...)
+ TODO: check
+CVE-2026-18348 (Missing authorization check in the upload_azure, upload_sftp,
and uplo ...)
+ TODO: check
+CVE-2026-16974 (The Kirki \u2013 Freeform Page Builder, Website Builder &
Customizer p ...)
+ TODO: check
+CVE-2026-16456 (A flaw was found in the `odh-model-controller`. An
authenticated user ...)
+ TODO: check
+CVE-2026-16053 (Zohocorp ManageEngineM365 Manager Plus and M365 Security Plus
versions ...)
+ TODO: check
+CVE-2026-15581 (A flaw was found in the TrustyAI Service (TAS) deployment.
This vulner ...)
+ TODO: check
+CVE-2026-15467 (A flaw was found in the trustyai-service-operator's LMEvalJob
controll ...)
+ TODO: check
+CVE-2026-14886 (Vault Enterprise's identity entity batch-delete endpoint is
vulnerable ...)
+ TODO: check
+CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3
does not ...)
+ TODO: check
+CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3
does not ...)
+ TODO: check
+CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows
any pod wi ...)
+ TODO: check
+CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS
Gateway. Imp ...)
+ TODO: check
+CVE-2026-13716 (Path traversal in server import and admin file upload in
Crafty Contro ...)
+ TODO: check
+CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler
usbd_cdc_ncm ...)
+ TODO: check
+CVE-2026-12051 (The USB DFU class implementation in Zephyr's new
(experimental) device ...)
+ TODO: check
+CVE-2026-11985 (On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU)
forces ...)
+ TODO: check
+CVE-2026-11894 (The Realtek BEE Bluetooth HCI driver's send callback,
bt_hci_bee_send( ...)
+ TODO: check
+CVE-2026-11893 (The Bluetooth HCI driver for Bouffalo Lab on-chip BLE
controllers (BL6 ...)
+ TODO: check
+CVE-2026-11812 (The UpdateHub management subsystem
(subsys/mgmt/updatehub/updatehub.c) ...)
+ TODO: check
+CVE-2026-11811 (The UpdateHub over-the-air update client's start_coap_client()
in subs ...)
+ TODO: check
+CVE-2026-11810 (The UpdateHub firmware-update agent's probe handler
(z_impl_updatehub_ ...)
+ TODO: check
+CVE-2026-11809 (The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c
contains ...)
+ TODO: check
+CVE-2025-32736 (Cross-Site Request Forgery weaknesses in the Administrative
Console of ...)
+ TODO: check
+CVE-2025-30241 (Certain web interface components in affected TP-Link Aginet
devices do ...)
+ TODO: check
+CVE-2025-30240 (The affected TP-Link Aginet devices do not properly validate
symbolic ...)
+ TODO: check
+CVE-2025-30239 (In affected TP-Link Aginet devices, use of hardcoded
cryptographic key ...)
+ TODO: check
+CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization
validat ...)
+ TODO: check
+CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web
managemen ...)
+ TODO: check
+CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple
unauthenticated denial ...)
+ TODO: check
+CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated
resource exh ...)
+ TODO: check
+CVE-2025-15681 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication
bypass in its ...)
+ TODO: check
+CVE-2025-15680 (TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the
device's ...)
+ TODO: check
+CVE-2025-13294 (An unauthenticated SQL injection vulnerability exists in the
web serve ...)
+ TODO: check
+CVE-2025-13293 (A hard-coded or default root account credential in TBEA
TLogger V2.1.0 ...)
+ TODO: check
CVE-2026-19349
- lemonldap-ng <unfixed>
NOTE:
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d
(v2.23.3)
@@ -5818,7 +6108,7 @@ CVE-2026-18774 (A flaw has been found in NousResearch
hermes-agent up to 0.16.0.
NOT-FOR-US: NousResearch
CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up
to 2026.6 ...)
NOT-FOR-US: NousResearch
-CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source
rlottie ...)
+CVE-2026-18772 (Improperly controlled sequential memory allocation
vulnerability in Sa ...)
- rlottie <unfixed> (bug #1143931)
[trixie] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/596
@@ -24318,22 +24608,22 @@ CVE-2023-49899 (An unauthenticated remote attacker
canexecute any command on the
CVE-2019-25764 (**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient
Access C ...)
NOT-FOR-US: ASUS
CVE-2026-57077 (YAML::Syck versions before 1.47 for Perl allow an
out-of-bounds read v ...)
- {DSA-6428-1}
+ {DSA-6428-1 DLA-4730-1}
- libyaml-syck-perl 1.47-1 (bug #1142267)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898716/
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
CVE-2026-57076 (YAML::Syck versions before 1.47 for Perl allow a heap
use-after-free v ...)
- {DSA-6428-1}
+ {DSA-6428-1 DLA-4730-1}
- libyaml-syck-perl 1.47-1 (bug #1142267)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898718/
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
CVE-2026-57075 (YAML::Syck versions before 1.47 for Perl allow an
out-of-bounds read v ...)
- {DSA-6428-1}
+ {DSA-6428-1 DLA-4730-1}
- libyaml-syck-perl 1.47-1 (bug #1142267)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898720/
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
CVE-2026-13713 (YAML::Syck versions before 1.47 for Perl allow a
use-after-free and do ...)
- {DSA-6428-1}
+ {DSA-6428-1 DLA-4730-1}
- libyaml-syck-perl 1.47-1 (bug #1142267)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898719/
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
@@ -43322,9 +43612,11 @@ CVE-2026-53753 (Crawl4AI is an open-source LLM
friendly web crawler & scraper. P
CVE-2026-53662 (immich is a high performance self-hosted photo and video
management so ...)
NOT-FOR-US: immich
CVE-2026-52846 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
+ {DSA-6429-1}
- caddy 2.11.4-1 (bug #1140773)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-vcc4-2c75-vc9v
CVE-2026-52845 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
+ {DSA-6429-1}
- caddy 2.11.4-1 (bug #1140773)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-f59h-q822-g45g
CVE-2026-52844 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
@@ -43390,6 +43682,7 @@ CVE-2026-48519 (Langflow is a tool for building and
deploying AI-powered agents
CVE-2026-45732 (n8n is an open source workflow automation platform. Prior to
1.123.43, ...)
NOT-FOR-US: n8n
CVE-2026-45692 (Caddy is an extensible server platform that uses TLS by
default. From ...)
+ {DSA-6429-1}
- caddy 2.11.4-1 (bug #1140773)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-x5w9-xh9r-mvfc
CVE-2026-45135 (Caddy is an extensible server platform that uses TLS by
default. From ...)
@@ -71854,7 +72147,7 @@ CVE-2025-54518 (Improper isolation of shared resources
within the CPU operation
NOTE: https://xenbits.xen.org/xsa/advisory-490.html
NOTE:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html
CVE-2026-5089 (YAML::Syck versions before 1.38 for Perl has an out-of-bounds
read. ...)
- {DSA-6428-1}
+ {DSA-6428-1 DLA-4730-1}
- libyaml-syck-perl 1.36-3
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39981051/
NOTE: https://github.com/cpan-authors/YAML-Syck/issues/132
@@ -114826,15 +115119,19 @@ CVE-2026-2459 (A vulnerability exists in REB500 for
an authenticated user with I
CVE-2026-27732 (WWBN AVideo is an open source video platform. Prior to version
22.0, t ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-27590 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
+ {DSA-6429-1}
- caddy 2.11.2-1 (bug #1132041)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-5r3v-vc8m-m96g
CVE-2026-27589 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
+ {DSA-6429-1}
- caddy 2.11.2-1 (bug #1132041)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-879p-475x-rqh2
CVE-2026-27588 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
+ {DSA-6429-1}
- caddy 2.11.2-1 (bug #1132041)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-x76f-jf84-rqj8
CVE-2026-27587 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
+ {DSA-6429-1}
- caddy 2.11.2-1 (bug #1132041)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-g7pc-pc7g-h8jh
CVE-2026-27586 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
@@ -114848,6 +115145,7 @@ CVE-2026-27586 (Caddy is an extensible server
platform that uses TLS by default.
NOTE: convertPEMFilesToDER() were all added by the trusted CA provider
modularization
NOTE: in 2.8.0; 2.6.2 has no such function and no swallowed error to
fail open on.
CVE-2026-27585 (Caddy is an extensible server platform that uses TLS by
default. Prior ...)
+ {DSA-6429-1}
- caddy 2.11.2-1 (bug #1132041)
NOTE:
https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4
CVE-2026-27584 (Actual is a local-first personal finance tool. Prior to
version 26.2.1 ...)
@@ -143282,7 +143580,7 @@ CVE-2025-14849 (Advantech WebAccess/SCADA is
vulnerable to unrestricted file upl
NOT-FOR-US: Advantech
CVE-2025-14848 (Advantech WebAccess/SCADA is vulnerable to absolute directory
traversa ...)
NOT-FOR-US: Advantech
-CVE-2025-14733 (An Out-of-bounds Write vulnerability in WatchGuard Fireware OS
may all ...)
+CVE-2025-14733 (An Out-of-bounds Write vulnerability in the WatchGuard
Fireware OS ike ...)
NOT-FOR-US: WatchGuard
CVE-2025-14546 (Versions of the package fastapi-sso before 0.19.0 are
vulnerable to Cr ...)
NOT-FOR-US: fastapi-sso
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc015f04b27f901f9326e68d33226b9a64163f4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc015f04b27f901f9326e68d33226b9a64163f4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits