Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5e8b2957 by security tracker role at 2026-08-13T07:13:22+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,373 @@
+CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM 
DataPower Gate ...)
+       TODO: check
+CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded 
cluster-authentication s ...)
+       TODO: check
+CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior 
to 0.144 ...)
+       TODO: check
+CVE-2026-73500 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
+       TODO: check
+CVE-2026-73499 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
+       TODO: check
+CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for 
Atlassian p ...)
+       TODO: check
+CVE-2026-73495 (blaze is a Scala library for building asynchronous pipelines, 
with a f ...)
+       TODO: check
+CVE-2026-73493 (Http4s (http4s-blaze-server) is a minimal, idiomatic Scala 
interface f ...)
+       TODO: check
+CVE-2026-73492 (Loofah is a general library for manipulating and transforming 
HTML/XML ...)
+       TODO: check
+CVE-2026-73491 (Loofah is a general library for manipulating and transforming 
HTML/XML ...)
+       TODO: check
+CVE-2026-73490 (Loofah is a general library for manipulating and transforming 
HTML/XML ...)
+       TODO: check
+CVE-2026-73434 (A flaw was found in GStreamer gst-plugins-good (avidemux). In 
gst_avi_ ...)
+       TODO: check
+CVE-2026-73433 (A flaw was found in GStreamer gst-plugins-good (avidemux). 
When parsin ...)
+       TODO: check
+CVE-2026-73430 (Russh is a Rust SSH client & server library. Prior to 0.62.4, 
an unaut ...)
+       TODO: check
+CVE-2026-73429 (Russh is a Rust SSH client & server library. Prior to 0.62.4, 
a malici ...)
+       TODO: check
+CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
+       TODO: check
+CVE-2026-73425 (Astro is a web framework for content-driven websites. Prior to 
8.1.2,  ...)
+       TODO: check
+CVE-2026-73423 (Astro is a web framework for content-driven websites. From 
7.0.0 until ...)
+       TODO: check
+CVE-2026-73422 (Astro is a web framework for content-driven websites. From 
2.9.0 until ...)
+       TODO: check
+CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior 
to@auth/core 0. ...)
+       TODO: check
+CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to 
@auth/core 0 ...)
+       TODO: check
+CVE-2026-73415 (jupyterlab is an extensible environment for interactive and 
reproducib ...)
+       TODO: check
+CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript. 
Prior to 2.1 ...)
+       TODO: check
+CVE-2026-73413 (Shescape is a simple shell escape library for JavaScript. From 
2.1.11  ...)
+       TODO: check
+CVE-2026-73412 (Shescape is a simple shell escape library for JavaScript. 
Prior to 2.1 ...)
+       TODO: check
+CVE-2026-73411 (Shescape is a simple shell escape library for JavaScript. 
Prior to 2.1 ...)
+       TODO: check
+CVE-2026-73409 (Budibase is an open-source low-code platform. Prior to 3.40.1, 
package ...)
+       TODO: check
+CVE-2026-73407 (Budibase is an open-source low-code platform. Prior to 3.40.1, 
RestInt ...)
+       TODO: check
+CVE-2026-73406 (Budibase is an open-source low-code platform. Prior to 
3.39.32, GET /a ...)
+       TODO: check
+CVE-2026-73332 (CamaleonCMS contains a stored cross-site scripting 
vulnerability in th ...)
+       TODO: check
+CVE-2026-73331 (CamaleonCMS 2.9.1 contains an authenticated SQL injection 
vulnerabilit ...)
+       TODO: check
+CVE-2026-73330 (CamaleonCMS 2.9.1 contains a server-side template injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-73329 (CamaleonCMS contains a stored cross-site scripting 
vulnerability that  ...)
+       TODO: check
+CVE-2026-73326 (CamaleonCMS contains a missing authorization vulnerability 
that allows ...)
+       TODO: check
+CVE-2026-73308 (Budibase is an open-source low-code platform. Prior to 
3.39.25, packag ...)
+       TODO: check
+CVE-2026-73307 (Budibase is an open-source low-code platform. Prior to 3.39.4, 
uploadU ...)
+       TODO: check
+CVE-2026-73306 (Budibase is an open-source low-code platform. Prior to 
3.39.25, POST / ...)
+       TODO: check
+CVE-2026-73303 (Budibase is an open-source low-code platform. Prior to 3.40.0, 
POST /a ...)
+       TODO: check
+CVE-2026-73269 (A flaw was found in the cluster-curator-controller component. 
A local  ...)
+       TODO: check
+CVE-2026-73268 (A flaw was found in the cluster-curator-controller component 
of multic ...)
+       TODO: check
+CVE-2026-72809 (SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an 
authenticatio ...)
+       TODO: check
+CVE-2026-72808 (SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) 
contain a ...)
+       TODO: check
+CVE-2026-72807 (SiYuan versions before v3.7.4 contain a second-order SQL 
injection vul ...)
+       TODO: check
+CVE-2026-72806 (SiYuan versions before v3.7.4 contain an authentication bypass 
vulnera ...)
+       TODO: check
+CVE-2026-72805 (SiYuan versions before v3.7.4 fail to enforce publish-access 
checks on ...)
+       TODO: check
+CVE-2026-72804 (SiYuan versions before v3.7.4 fail to validate 
publish-password tier i ...)
+       TODO: check
+CVE-2026-72803 (SiYuan versions before v3.7.4 fail to enforce publish-access 
checks in ...)
+       TODO: check
+CVE-2026-72802 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
+       TODO: check
+CVE-2026-72801 (SiYuan versions before v3.7.4 disclose encrypted-notebook 
key-derivati ...)
+       TODO: check
+CVE-2026-72800 (SiYuan versions before v3.7.4 fail to apply publish-access 
filtering t ...)
+       TODO: check
+CVE-2026-72799 (SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce 
publish-acce ...)
+       TODO: check
+CVE-2026-72798 (SiYuan versions before v3.7.4 fail to properly filter 
related-database ...)
+       TODO: check
+CVE-2026-72797 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
+       TODO: check
+CVE-2026-72796 (SiYuan before v3.7.4 contains an access control bypass 
vulnerability w ...)
+       TODO: check
+CVE-2026-72795 (SiYuan versions before v3.7.4 fail to filter embedded block 
content by ...)
+       TODO: check
+CVE-2026-72794 (siyuan versions before v3.7.4 expose the session cookie 
signing key th ...)
+       TODO: check
+CVE-2026-72793 (SiYuan versions before v3.7.4 fail to mask sensitive 
configuration fie ...)
+       TODO: check
+CVE-2026-72792 (SiYuan before v3.7.4 contains an information disclosure 
vulnerability  ...)
+       TODO: check
+CVE-2026-72791 (SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not 
exist in s ...)
+       TODO: check
+CVE-2026-72790 (SiYuan before v3.7.4 contains an information disclosure 
vulnerability  ...)
+       TODO: check
+CVE-2026-72789 (SiYuan before v3.7.4 fails to properly validate publish access 
for enc ...)
+       TODO: check
+CVE-2026-72788 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
+       TODO: check
+CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site 
scripting ...)
+       TODO: check
+CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication 
bypass vuln ...)
+       TODO: check
+CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription 
component of ...)
+       TODO: check
+CVE-2026-72506 (VoiceTra provided by National Institute of Information and 
Communicati ...)
+       TODO: check
+CVE-2026-71846 (A flaw was found in insights-client. The component's 
ServiceAccount is ...)
+       TODO: check
+CVE-2026-71473 (A flaw was found in the `search-v2-operator` component. A user 
with sp ...)
+       TODO: check
+CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with 
administrati ...)
+       TODO: check
+CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker 
can exp ...)
+       TODO: check
+CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project 
ash all ...)
+       TODO: check
+CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to 
manipulate ...)
+       TODO: check
+CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed 
Transfer-Encoding w ...)
+       TODO: check
+CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability 
that all ...)
+       TODO: check
+CVE-2026-63300 (An improper validation vulnerability in the 
instancePostMigration func ...)
+       TODO: check
+CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an 
authenticated u ...)
+       TODO: check
+CVE-2026-63298 (An improper neutralization of special elements vulnerability 
in LXD's  ...)
+       TODO: check
+CVE-2026-63297 (An authorization bypass vulnerability in LXD due to a timing 
flaw duri ...)
+       TODO: check
+CVE-2026-63296 (An authorization bypass vulnerability in LXD allows an 
authenticated a ...)
+       TODO: check
+CVE-2026-63295 (An authorization bypass vulnerability in LXD allows an 
authenticated a ...)
+       TODO: check
+CVE-2026-63294 (A link following vulnerability in LXD allows an attacker to 
achieve ro ...)
+       TODO: check
+CVE-2026-63293 (A link following vulnerability in LXD allows an attacker to 
achieve ar ...)
+       TODO: check
+CVE-2026-62421
+       REJECTED
+CVE-2026-62420 (An authorization bypass vulnerability in LXD allows an 
authenticated a ...)
+       TODO: check
+CVE-2026-59917 (Dell Display and Peripheral Manager (DDPM Windows), versions 
prior to  ...)
+       TODO: check
+CVE-2026-59916 (Dell Display and Peripheral Manager (DDPM Windows), versions 
prior to  ...)
+       TODO: check
+CVE-2026-59914 (Dell Display and Peripheral Manager (DDPM Windows), versions 
prior to  ...)
+       TODO: check
+CVE-2026-50544 (NortheBridge/luminalshine is a Sunshine-compatible game stream 
host fo ...)
+       TODO: check
+CVE-2026-4879 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-49819 (UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 
are vuln ...)
+       TODO: check
+CVE-2026-49481 (UpSnap is a wake on lan web app. Versions prior to 5.4.0 have 
an OS co ...)
+       TODO: check
+CVE-2026-49473 (@cedar-policy/authorization-for-expressjs is an open-source 
Express.js ...)
+       TODO: check
+CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote 
unpublished con ...)
+       TODO: check
+CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with 
sigstore  ...)
+       TODO: check
+CVE-2026-47718 (FUXA is a web-based Process Visualization 
(SCADA/HMI/Dashboard) softwa ...)
+       TODO: check
+CVE-2026-47717 (FUXA is a web-based Process Visualization 
(SCADA/HMI/Dashboard) softwa ...)
+       TODO: check
+CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions 
prior to  ...)
+       TODO: check
+CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based 
application for  ...)
+       TODO: check
+CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based 
application for  ...)
+       TODO: check
+CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin 
for Wo ...)
+       TODO: check
+CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML 
response wit ...)
+       TODO: check
+CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks 
authorization  ...)
+       TODO: check
+CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due 
to a flaw ...)
+       TODO: check
+CVE-2026-19643 (An out-of-bounds read issue in the Base64 decoder in Amazon 
aws-sdk-cp ...)
+       TODO: check
+CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon 
aws-sdk-c ...)
+       TODO: check
+CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do 
not valida ...)
+       TODO: check
+CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup 
configuration to st ...)
+       TODO: check
+CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in 
OpenNMS M ...)
+       TODO: check
+CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions 
of OpenNM ...)
+       TODO: check
+CVE-2026-19130 (A flaw was found in the provider-credential-controller 
component of mu ...)
+       TODO: check
+CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon  WordPress 
plugin b ...)
+       TODO: check
+CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may 
experien ...)
+       TODO: check
+CVE-2026-19003 (A data source definition containing an over-length file path 
setting m ...)
+       TODO: check
+CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter 
metadat ...)
+       TODO: check
+CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the 
bounds of a ...)
+       TODO: check
+CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not 
verify th ...)
+       TODO: check
+CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point 
column va ...)
+       TODO: check
+CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches 
VinceComm ...)
+       TODO: check
+CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case) 
only an ...)
+       TODO: check
+CVE-2026-18744 (Any authenticated case participant can fetch any OTHER 
vendor's CaseSt ...)
+       TODO: check
+CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow 
vulnerability in  ...)
+       TODO: check
+CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This 
vulnerabilit ...)
+       TODO: check
+CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a 
remote att ...)
+       TODO: check
+CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the 
operato ...)
+       TODO: check
+CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18148 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18146 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, 
Quiz, & Co ...)
+       TODO: check
+CVE-2026-18099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18097 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for 
Linux, UN ...)
+       TODO: check
+CVE-2026-18096 (IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 
Connect Serve ...)
+       TODO: check
+CVE-2026-17642 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17616 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-17485 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
+       TODO: check
+CVE-2026-17445 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17417 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17111 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A 
remote a ...)
+       TODO: check
+CVE-2026-17083 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
execute  ...)
+       TODO: check
+CVE-2026-17082 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-16695 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could 
allow a l ...)
+       TODO: check
+CVE-2026-16494 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-16480 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is 
affected b ...)
+       TODO: check
+CVE-2026-16033 (A path traversal vulnerability in LXD allows an attacker to 
achieve ar ...)
+       TODO: check
+CVE-2026-15424
+       REJECTED
+CVE-2026-15217 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-15216 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-15141 (The web interface of the affected device relies on the HTTP 
referrer h ...)
+       TODO: check
+CVE-2026-14866 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is 
vulnerable t ...)
+       TODO: check
+CVE-2026-14213 (The Booking for Appointments and Events Calendar  WordPress 
plugin bef ...)
+       TODO: check
+CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress 
plugin befor ...)
+       TODO: check
+CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's 
virt-handler ...)
+       TODO: check
+CVE-2026-13610 (The KiviCare  WordPress plugin before 4.5.2 does not restrict 
the role ...)
+       TODO: check
+CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow 
an unau ...)
+       TODO: check
+CVE-2026-13433 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) 
is vulner ...)
+       TODO: check
+CVE-2026-13367 (IBM Informix Dynamic Server 14.10, and 15.0 contain a local 
privilege  ...)
+       TODO: check
+CVE-2026-13361 (IBM Informix oninit sq_sgkprepare RCE via unchecked SQL 
Interface leng ...)
+       TODO: check
+CVE-2026-13328 (The Food Menu  WordPress plugin before 6.0.2 does not perform 
any capa ...)
+       TODO: check
+CVE-2026-13267 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-13105 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is 
vulnerable t ...)
+       TODO: check
+CVE-2026-13094 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is 
vulnerable t ...)
+       TODO: check
+CVE-2026-12618 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-12359 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-12005 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-12004 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-11937 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-11932 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-11923 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM 
Verify Identi ...)
+       TODO: check
+CVE-2026-10543 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is 
vulnerable ...)
+       TODO: check
+CVE-2026-10534 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is 
vulnerable ...)
+       TODO: check
+CVE-2026-0301 (An information disclosure vulnerability in the URL Filtering 
feature o ...)
+       TODO: check
+CVE-2026-0299 (Local privilege escalation vulnerabilities in the Palo Alto 
Networks G ...)
+       TODO: check
+CVE-2026-0298 (An improper input validation vulnerability exists in the 
Windows Pre-L ...)
+       TODO: check
+CVE-2026-0297 (A buffer overflow vulnerability exists in the Palo Alto 
Networks Globa ...)
+       TODO: check
+CVE-2026-0296 (Improper certificate validation vulnerabilities in Palo Alto 
Networks  ...)
+       TODO: check
+CVE-2026-0295 (A race condition in the Palo Alto Networks GlobalProtect\u2122 
client  ...)
+       TODO: check
+CVE-2026-0294 (A privilege escalation (PE) vulnerability in the Palo Alto 
Networks Pr ...)
+       TODO: check
+CVE-2026-0293 (A vulnerability in Palo Alto Networks Prisma\xae Access Agent 
on Windo ...)
+       TODO: check
+CVE-2026-0292 (An authentication bypass vulnerability in the network driver of 
Palo A ...)
+       TODO: check
+CVE-2026-0291 (An improper link resolution before file access vulnerability 
exists in ...)
+       TODO: check
+CVE-2026-0290 (An information disclosure vulnerability in the Account 
Protection feat ...)
+       TODO: check
+CVE-2026-0289 (A  security bypass vulnerability in the Account Protection 
feature of  ...)
+       TODO: check
+CVE-2025-9486 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow 
an auth ...)
+       TODO: check
 CVE-2026-53802
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
@@ -97,9 +467,9 @@ CVE-2026-70462
 CVE-2026-70454
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-17431
+CVE-2026-17431 (PDF::WebKit versions through 1.2 for Perl allow OS command 
injection v ...)
        NOT-FOR-US: PDF::WebKit Perl module
-CVE-2026-16770
+CVE-2026-16770 (PDF::WebKit versions through 1.2 for Perl allow argument 
injection int ...)
        NOT-FOR-US: PDF::WebKit Perl module
 CVE-2026-8667 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
@@ -2763,11 +3133,11 @@ CVE-2025-31936 (Improper handling of overlap between 
protected memory ranges for
        [trixie] - intel-microcode <postponed> (As usual fixed top-down, expose 
first in unstable, then likely point release)
        NOTE: 
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
        NOTE: 
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html
-CVE-2026-71194
+CVE-2026-71194 (In OpenStack Designate before 22.0.2, the mDNS handler 
performs pool-b ...)
        - designate 1:22.0.0-2 (bug #1144145)
        NOTE: https://bugs.launchpad.net/designate/+bug/2160533
        NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
-CVE-2026-71193
+CVE-2026-71193 (In OpenStack Designate before 22.0.1, zone creation checks 
(_is_subzon ...)
        - designate 1:22.0.0-2 (bug #1144145)
        NOTE: https://bugs.launchpad.net/designate/+bug/2160533
        NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
@@ -3464,6 +3834,7 @@ CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the 
GNU C Library version 2.0
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in 
Fabrik < 4. ...)
        NOT-FOR-US: Joomla
 CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in 
SQLite-b ...)
+       {DSA-6435-1}
        - spip 4.4.18+dfsg-1
        NOTE: 
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html
 CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella 
allows  ...)
@@ -9169,6 +9540,7 @@ CVE-2017-20242 (Keysight IxChariot Endpoint before 
9.5.102 contains a stack-base
 CVE-2017-20241 (Keysight IxChariot Endpoint before 9.5.102 contains a 
heap-based buffe ...)
        NOT-FOR-US: Keysight IxChariot Endpoint
 CVE-2026-15920 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 
before 6.0 ...)
+       {DLA-4736-1}
        - python-django 3:5.2.17-1 (bug #1143611)
        NOTE: 
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
        NOTE: Fixed by: 
https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349
 (5.2.17)
@@ -9179,6 +9551,7 @@ CVE-2026-15830 (An issue was discovered in Django 5.2 
before 5.2.17 and 6.0 befo
        NOTE: 
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
        NOTE: Fixed by: 
https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080
 (5.2.17)
 CVE-2026-15337 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 
before 6.0 ...)
+       {DLA-4736-1}
        - python-django 3:5.2.17-1 (bug #1143611)
        NOTE: 
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
        NOTE: Fixed by: 
https://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959
 (5.2.17)
@@ -60950,7 +61323,7 @@ CVE-2018-25428 (Paroiciel 11.20 contains an SQL 
injection vulnerability that all
 CVE-2018-25427 (Arm Whois 3.11 contains a stack-based buffer overflow 
vulnerability th ...)
        NOT-FOR-US: Arm whois
 CVE-2026-50256 (A stack-based buffer overflow flaw was found in the X.Org X 
server and ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -60959,7 +61332,7 @@ CVE-2026-50256 (A stack-based buffer overflow flaw was 
found in the X.Org X serv
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/a569eb4f36ed96a9e445ececd7e8d98c223461a0
 (xorg-server-21.1.23)
 CVE-2026-50257 (A use-after-free flaw was found in the X.Org X server and 
Xwayland in  ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -60968,7 +61341,7 @@ CVE-2026-50257 (A use-after-free flaw was found in the 
X.Org X server and Xwayla
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f304b57444be3991fd9d3389f309c6eeb056a6c4
 (xorg-server-21.1.23)
 CVE-2026-50258 (A stack-based buffer overflow flaw was found in the X.Org X 
server and ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -60977,7 +61350,7 @@ CVE-2026-50258 (A stack-based buffer overflow flaw was 
found in the X.Org X serv
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/543e108516428fc8c3bea91d6563ad266f9a801e
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/eced7e74cad4a46c3a3c17b2df13b70b8bedfc25
 (xorg-server-21.1.23)
 CVE-2026-50259 (A stack-based buffer overflow flaw was found in the X.Org X 
server and ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -60986,7 +61359,7 @@ CVE-2026-50259 (A stack-based buffer overflow flaw was 
found in the X.Org X serv
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/867b59b33bee669cb412f1314e47c52eacf6e00b
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/54c3d9fad0f2f97835da9d275b53255f4963029f
 (xorg-server-21.1.23)
 CVE-2026-50260 (A use-after-free flaw was found in the X.Org X server and 
Xwayland in  ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -60995,7 +61368,7 @@ CVE-2026-50260 (A use-after-free flaw was found in the 
X.Org X server and Xwayla
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f304b57444be3991fd9d3389f309c6eeb056a6c4
 (xorg-server-21.1.23)
 CVE-2026-50261 (A use-after-free flaw was found in the X.Org X server and 
Xwayland in  ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -61004,7 +61377,7 @@ CVE-2026-50261 (A use-after-free flaw was found in the 
X.Org X server and Xwayla
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/bdd7bf57af208b1ddf57d4683d67104443b44812
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/92a167ab3fda0bee41cf97f6a40a4c01c67d85d4
 (xorg-server-21.1.23)
 CVE-2026-50262 (An out-of-bounds read flaw was found in the X.Org X server and 
Xwaylan ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -61013,7 +61386,7 @@ CVE-2026-50262 (An out-of-bounds read flaw was found in 
the X.Org X server and X
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/6d459e4daf715bea8abdafa8fb130be2f8a1d145
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/94341bd715d62ba8da4c1851f517018996da1af8
 (xorg-server-21.1.23)
 CVE-2026-50263 (A use-after-free flaw was found in the X.Org X server and 
Xwayland in  ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -61022,7 +61395,7 @@ CVE-2026-50263 (A use-after-free flaw was found in the 
X.Org X server and Xwayla
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/ecc634f1b2f7aa473d3a267eada98c4918bf9e05
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/182c23f780402062ab31963776a19d5b87e25ac8
 (xorg-server-21.1.23)
 CVE-2026-50264 (An out-of-bounds write flaw was found in the X.Org X server 
and Xwayla ...)
-       {DSA-6371-1}
+       {DSA-6371-1 DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.23-1 (bug #1138680)
        - xwayland 2:24.1.12-1 (bug #1138703)
        [trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be 
running as root)
@@ -92702,6 +93075,7 @@ CVE-2024-9168
 CVE-2024-23104 (An exposure of sensitive information to an unauthorized actor 
vulnerab ...)
        NOT-FOR-US: Fortinet
 CVE-2026-34003 (A flaw was found in the X.Org X server's XKB key types request 
validat ...)
+       {DLA-4738-1}
        - xorg-server 2:21.1.22-1
        [trixie] - xorg-server 2:21.1.16-1.3+deb13u2
        [bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92712,6 +93086,7 @@ CVE-2026-34003 (A flaw was found in the X.Org X 
server's XKB key types request v
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/b85b00dd7b9eee05e3c12e7ad1fce4fc6671507b
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/d38c563fab5c4a554e0939da39e4d1dadef7cbae
 CVE-2026-34002 (A flaw was found in the X.Org X server. This vulnerability, an 
out-of- ...)
+       {DLA-4738-1}
        - xorg-server 2:21.1.22-1
        [trixie] - xorg-server 2:21.1.16-1.3+deb13u2
        [bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92721,6 +93096,7 @@ CVE-2026-34002 (A flaw was found in the X.Org X server. 
This vulnerability, an o
        NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
        NOTE: fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f056ce1cc96ed9261052c31524162c78e458f98c
 CVE-2026-34001 (A flaw was found in the X.Org X server. This use-after-free 
vulnerabil ...)
+       {DLA-4738-1}
        - xorg-server 2:21.1.22-1
        [trixie] - xorg-server 2:21.1.16-1.3+deb13u2
        [bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92730,6 +93106,7 @@ CVE-2026-34001 (A flaw was found in the X.Org X server. 
This use-after-free vuln
        NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f19ab94ba9c891d801231654267556dc7f32b5e0
 CVE-2026-34000 (A flaw was found in the X.Org X server. This out-of-bounds 
read vulner ...)
+       {DLA-4738-1}
        - xorg-server 2:21.1.22-1
        [trixie] - xorg-server 2:21.1.16-1.3+deb13u2
        [bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92739,6 +93116,7 @@ CVE-2026-34000 (A flaw was found in the X.Org X server. 
This out-of-bounds read
        NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
        NOTE: Fixed by: 
ttps://gitlab.freedesktop.org/xorg/xserver/-/commit/81b6a34f90b28c32ad499a78a4f391b7c06daea2
 CVE-2026-33999 (A flaw was found in the X.Org X server. This integer underflow 
vulnera ...)
+       {DLA-4738-1}
        - xorg-server 2:21.1.22-1
        [trixie] - xorg-server 2:21.1.16-1.3+deb13u2
        [bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -158768,7 +159146,8 @@ CVE-2025-64076 (Multiple vulnerabilities exist in 
cbor2 through version 5.7.0 in
        NOTE: Introduced with: 
https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542
 (5.6.0)
        NOTE: Fixed by: 
https://github.com/agronholm/cbor2/commit/2349197bea8ebd1bf57a68f4a6549d8fd7585e66
 (5.7.1)
        NOTE: Debian builds src:cbor2 with CBOR2_BUILD_C_EXTENSION=0 (not 
building C extensions)
-CVE-2025-63994 (An arbitrary file upload vulnerability in the 
/php/UploadHandler.php c ...)
+CVE-2025-63994
+       REJECTED
        NOT-FOR-US: RichFilemanager
 CVE-2025-63955 (A Cross-Site Request Forgery (CSRF) vulnerability in the 
manage-studen ...)
        NOT-FOR-US: PHPGurukul
@@ -241362,6 +241741,7 @@ CVE-2024-13602 (The Poll Maker  WordPress plugin 
before 5.5.4 does not sanitise
 CVE-2024-13126 (The Download Manager WordPress plugin before 3.3.07 doesn't 
prevent di ...)
        NOT-FOR-US: WordPress plugin
 CVE-2022-49737 (In X.Org X server 20.11 through 21.1.16, when a client 
application use ...)
+       {DLA-4738-1 DLA-4737-1}
        - xorg-server 2:21.1.16-1.1 (bug #1081338)
        NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260
        NOTE: 
https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0
 (master)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e8b295787367fbd071362bece2934fbe9830ca5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e8b295787367fbd071362bece2934fbe9830ca5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to