Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5e8b2957 by security tracker role at 2026-08-13T07:13:22+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,373 @@
+CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM
DataPower Gate ...)
+ TODO: check
+CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded
cluster-authentication s ...)
+ TODO: check
+CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior
to 0.144 ...)
+ TODO: check
+CVE-2026-73500 (etcd is a distributed key-value store for the data of a
distributed sy ...)
+ TODO: check
+CVE-2026-73499 (etcd is a distributed key-value store for the data of a
distributed sy ...)
+ TODO: check
+CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for
Atlassian p ...)
+ TODO: check
+CVE-2026-73495 (blaze is a Scala library for building asynchronous pipelines,
with a f ...)
+ TODO: check
+CVE-2026-73493 (Http4s (http4s-blaze-server) is a minimal, idiomatic Scala
interface f ...)
+ TODO: check
+CVE-2026-73492 (Loofah is a general library for manipulating and transforming
HTML/XML ...)
+ TODO: check
+CVE-2026-73491 (Loofah is a general library for manipulating and transforming
HTML/XML ...)
+ TODO: check
+CVE-2026-73490 (Loofah is a general library for manipulating and transforming
HTML/XML ...)
+ TODO: check
+CVE-2026-73434 (A flaw was found in GStreamer gst-plugins-good (avidemux). In
gst_avi_ ...)
+ TODO: check
+CVE-2026-73433 (A flaw was found in GStreamer gst-plugins-good (avidemux).
When parsin ...)
+ TODO: check
+CVE-2026-73430 (Russh is a Rust SSH client & server library. Prior to 0.62.4,
an unaut ...)
+ TODO: check
+CVE-2026-73429 (Russh is a Rust SSH client & server library. Prior to 0.62.4,
a malici ...)
+ TODO: check
+CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for
everyday w ...)
+ TODO: check
+CVE-2026-73425 (Astro is a web framework for content-driven websites. Prior to
8.1.2, ...)
+ TODO: check
+CVE-2026-73423 (Astro is a web framework for content-driven websites. From
7.0.0 until ...)
+ TODO: check
+CVE-2026-73422 (Astro is a web framework for content-driven websites. From
2.9.0 until ...)
+ TODO: check
+CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior
to@auth/core 0. ...)
+ TODO: check
+CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to
@auth/core 0 ...)
+ TODO: check
+CVE-2026-73415 (jupyterlab is an extensible environment for interactive and
reproducib ...)
+ TODO: check
+CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript.
Prior to 2.1 ...)
+ TODO: check
+CVE-2026-73413 (Shescape is a simple shell escape library for JavaScript. From
2.1.11 ...)
+ TODO: check
+CVE-2026-73412 (Shescape is a simple shell escape library for JavaScript.
Prior to 2.1 ...)
+ TODO: check
+CVE-2026-73411 (Shescape is a simple shell escape library for JavaScript.
Prior to 2.1 ...)
+ TODO: check
+CVE-2026-73409 (Budibase is an open-source low-code platform. Prior to 3.40.1,
package ...)
+ TODO: check
+CVE-2026-73407 (Budibase is an open-source low-code platform. Prior to 3.40.1,
RestInt ...)
+ TODO: check
+CVE-2026-73406 (Budibase is an open-source low-code platform. Prior to
3.39.32, GET /a ...)
+ TODO: check
+CVE-2026-73332 (CamaleonCMS contains a stored cross-site scripting
vulnerability in th ...)
+ TODO: check
+CVE-2026-73331 (CamaleonCMS 2.9.1 contains an authenticated SQL injection
vulnerabilit ...)
+ TODO: check
+CVE-2026-73330 (CamaleonCMS 2.9.1 contains a server-side template injection
vulnerabil ...)
+ TODO: check
+CVE-2026-73329 (CamaleonCMS contains a stored cross-site scripting
vulnerability that ...)
+ TODO: check
+CVE-2026-73326 (CamaleonCMS contains a missing authorization vulnerability
that allows ...)
+ TODO: check
+CVE-2026-73308 (Budibase is an open-source low-code platform. Prior to
3.39.25, packag ...)
+ TODO: check
+CVE-2026-73307 (Budibase is an open-source low-code platform. Prior to 3.39.4,
uploadU ...)
+ TODO: check
+CVE-2026-73306 (Budibase is an open-source low-code platform. Prior to
3.39.25, POST / ...)
+ TODO: check
+CVE-2026-73303 (Budibase is an open-source low-code platform. Prior to 3.40.0,
POST /a ...)
+ TODO: check
+CVE-2026-73269 (A flaw was found in the cluster-curator-controller component.
A local ...)
+ TODO: check
+CVE-2026-73268 (A flaw was found in the cluster-curator-controller component
of multic ...)
+ TODO: check
+CVE-2026-72809 (SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an
authenticatio ...)
+ TODO: check
+CVE-2026-72808 (SiYuan versions up to and including v3.7.2 (fixed in v3.7.4)
contain a ...)
+ TODO: check
+CVE-2026-72807 (SiYuan versions before v3.7.4 contain a second-order SQL
injection vul ...)
+ TODO: check
+CVE-2026-72806 (SiYuan versions before v3.7.4 contain an authentication bypass
vulnera ...)
+ TODO: check
+CVE-2026-72805 (SiYuan versions before v3.7.4 fail to enforce publish-access
checks on ...)
+ TODO: check
+CVE-2026-72804 (SiYuan versions before v3.7.4 fail to validate
publish-password tier i ...)
+ TODO: check
+CVE-2026-72803 (SiYuan versions before v3.7.4 fail to enforce publish-access
checks in ...)
+ TODO: check
+CVE-2026-72802 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
+ TODO: check
+CVE-2026-72801 (SiYuan versions before v3.7.4 disclose encrypted-notebook
key-derivati ...)
+ TODO: check
+CVE-2026-72800 (SiYuan versions before v3.7.4 fail to apply publish-access
filtering t ...)
+ TODO: check
+CVE-2026-72799 (SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce
publish-acce ...)
+ TODO: check
+CVE-2026-72798 (SiYuan versions before v3.7.4 fail to properly filter
related-database ...)
+ TODO: check
+CVE-2026-72797 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
+ TODO: check
+CVE-2026-72796 (SiYuan before v3.7.4 contains an access control bypass
vulnerability w ...)
+ TODO: check
+CVE-2026-72795 (SiYuan versions before v3.7.4 fail to filter embedded block
content by ...)
+ TODO: check
+CVE-2026-72794 (siyuan versions before v3.7.4 expose the session cookie
signing key th ...)
+ TODO: check
+CVE-2026-72793 (SiYuan versions before v3.7.4 fail to mask sensitive
configuration fie ...)
+ TODO: check
+CVE-2026-72792 (SiYuan before v3.7.4 contains an information disclosure
vulnerability ...)
+ TODO: check
+CVE-2026-72791 (SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not
exist in s ...)
+ TODO: check
+CVE-2026-72790 (SiYuan before v3.7.4 contains an information disclosure
vulnerability ...)
+ TODO: check
+CVE-2026-72789 (SiYuan before v3.7.4 fails to properly validate publish access
for enc ...)
+ TODO: check
+CVE-2026-72788 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
+ TODO: check
+CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site
scripting ...)
+ TODO: check
+CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication
bypass vuln ...)
+ TODO: check
+CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription
component of ...)
+ TODO: check
+CVE-2026-72506 (VoiceTra provided by National Institute of Information and
Communicati ...)
+ TODO: check
+CVE-2026-71846 (A flaw was found in insights-client. The component's
ServiceAccount is ...)
+ TODO: check
+CVE-2026-71473 (A flaw was found in the `search-v2-operator` component. A user
with sp ...)
+ TODO: check
+CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with
administrati ...)
+ TODO: check
+CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker
can exp ...)
+ TODO: check
+CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
+ TODO: check
+CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project
ash all ...)
+ TODO: check
+CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to
manipulate ...)
+ TODO: check
+CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed
Transfer-Encoding w ...)
+ TODO: check
+CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability
that all ...)
+ TODO: check
+CVE-2026-63300 (An improper validation vulnerability in the
instancePostMigration func ...)
+ TODO: check
+CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an
authenticated u ...)
+ TODO: check
+CVE-2026-63298 (An improper neutralization of special elements vulnerability
in LXD's ...)
+ TODO: check
+CVE-2026-63297 (An authorization bypass vulnerability in LXD due to a timing
flaw duri ...)
+ TODO: check
+CVE-2026-63296 (An authorization bypass vulnerability in LXD allows an
authenticated a ...)
+ TODO: check
+CVE-2026-63295 (An authorization bypass vulnerability in LXD allows an
authenticated a ...)
+ TODO: check
+CVE-2026-63294 (A link following vulnerability in LXD allows an attacker to
achieve ro ...)
+ TODO: check
+CVE-2026-63293 (A link following vulnerability in LXD allows an attacker to
achieve ar ...)
+ TODO: check
+CVE-2026-62421
+ REJECTED
+CVE-2026-62420 (An authorization bypass vulnerability in LXD allows an
authenticated a ...)
+ TODO: check
+CVE-2026-59917 (Dell Display and Peripheral Manager (DDPM Windows), versions
prior to ...)
+ TODO: check
+CVE-2026-59916 (Dell Display and Peripheral Manager (DDPM Windows), versions
prior to ...)
+ TODO: check
+CVE-2026-59914 (Dell Display and Peripheral Manager (DDPM Windows), versions
prior to ...)
+ TODO: check
+CVE-2026-50544 (NortheBridge/luminalshine is a Sunshine-compatible game stream
host fo ...)
+ TODO: check
+CVE-2026-4879 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
+ TODO: check
+CVE-2026-49819 (UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5
are vuln ...)
+ TODO: check
+CVE-2026-49481 (UpSnap is a wake on lan web app. Versions prior to 5.4.0 have
an OS co ...)
+ TODO: check
+CVE-2026-49473 (@cedar-policy/authorization-for-expressjs is an open-source
Express.js ...)
+ TODO: check
+CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote
unpublished con ...)
+ TODO: check
+CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with
sigstore ...)
+ TODO: check
+CVE-2026-47718 (FUXA is a web-based Process Visualization
(SCADA/HMI/Dashboard) softwa ...)
+ TODO: check
+CVE-2026-47717 (FUXA is a web-based Process Visualization
(SCADA/HMI/Dashboard) softwa ...)
+ TODO: check
+CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions
prior to ...)
+ TODO: check
+CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based
application for ...)
+ TODO: check
+CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based
application for ...)
+ TODO: check
+CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin
for Wo ...)
+ TODO: check
+CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML
response wit ...)
+ TODO: check
+CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks
authorization ...)
+ TODO: check
+CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due
to a flaw ...)
+ TODO: check
+CVE-2026-19643 (An out-of-bounds read issue in the Base64 decoder in Amazon
aws-sdk-cp ...)
+ TODO: check
+CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon
aws-sdk-c ...)
+ TODO: check
+CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do
not valida ...)
+ TODO: check
+CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup
configuration to st ...)
+ TODO: check
+CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
+ TODO: check
+CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in
OpenNMS M ...)
+ TODO: check
+CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions
of OpenNM ...)
+ TODO: check
+CVE-2026-19130 (A flaw was found in the provider-credential-controller
component of mu ...)
+ TODO: check
+CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon WordPress
plugin b ...)
+ TODO: check
+CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may
experien ...)
+ TODO: check
+CVE-2026-19003 (A data source definition containing an over-length file path
setting m ...)
+ TODO: check
+CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter
metadat ...)
+ TODO: check
+CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the
bounds of a ...)
+ TODO: check
+CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not
verify th ...)
+ TODO: check
+CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point
column va ...)
+ TODO: check
+CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches
VinceComm ...)
+ TODO: check
+CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case)
only an ...)
+ TODO: check
+CVE-2026-18744 (Any authenticated case participant can fetch any OTHER
vendor's CaseSt ...)
+ TODO: check
+CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow
vulnerability in ...)
+ TODO: check
+CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This
vulnerabilit ...)
+ TODO: check
+CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a
remote att ...)
+ TODO: check
+CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the
operato ...)
+ TODO: check
+CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
+ TODO: check
+CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-18148 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-18146 (The Fluent Forms \u2013 Customizable Contact Forms, Survey,
Quiz, & Co ...)
+ TODO: check
+CVE-2026-18099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-18097 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for
Linux, UN ...)
+ TODO: check
+CVE-2026-18096 (IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2
Connect Serve ...)
+ TODO: check
+CVE-2026-17642 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-17616 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-17485 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
cause a ...)
+ TODO: check
+CVE-2026-17445 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-17417 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-17111 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A
remote a ...)
+ TODO: check
+CVE-2026-17083 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
execute ...)
+ TODO: check
+CVE-2026-17082 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-16695 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could
allow a l ...)
+ TODO: check
+CVE-2026-16494 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
+ TODO: check
+CVE-2026-16480 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is
affected b ...)
+ TODO: check
+CVE-2026-16033 (A path traversal vulnerability in LXD allows an attacker to
achieve ar ...)
+ TODO: check
+CVE-2026-15424
+ REJECTED
+CVE-2026-15217 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
+ TODO: check
+CVE-2026-15216 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
+ TODO: check
+CVE-2026-15141 (The web interface of the affected device relies on the HTTP
referrer h ...)
+ TODO: check
+CVE-2026-14866 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is
vulnerable t ...)
+ TODO: check
+CVE-2026-14213 (The Booking for Appointments and Events Calendar WordPress
plugin bef ...)
+ TODO: check
+CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress
plugin befor ...)
+ TODO: check
+CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's
virt-handler ...)
+ TODO: check
+CVE-2026-13610 (The KiviCare WordPress plugin before 4.5.2 does not restrict
the role ...)
+ TODO: check
+CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow
an unau ...)
+ TODO: check
+CVE-2026-13433 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS)
is vulner ...)
+ TODO: check
+CVE-2026-13367 (IBM Informix Dynamic Server 14.10, and 15.0 contain a local
privilege ...)
+ TODO: check
+CVE-2026-13361 (IBM Informix oninit sq_sgkprepare RCE via unchecked SQL
Interface leng ...)
+ TODO: check
+CVE-2026-13328 (The Food Menu WordPress plugin before 6.0.2 does not perform
any capa ...)
+ TODO: check
+CVE-2026-13267 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-13105 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is
vulnerable t ...)
+ TODO: check
+CVE-2026-13094 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is
vulnerable t ...)
+ TODO: check
+CVE-2026-12618 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-12359 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-12005 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-12004 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-11937 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-11932 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-11923 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM
Verify Identi ...)
+ TODO: check
+CVE-2026-10543 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is
vulnerable ...)
+ TODO: check
+CVE-2026-10534 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is
vulnerable ...)
+ TODO: check
+CVE-2026-0301 (An information disclosure vulnerability in the URL Filtering
feature o ...)
+ TODO: check
+CVE-2026-0299 (Local privilege escalation vulnerabilities in the Palo Alto
Networks G ...)
+ TODO: check
+CVE-2026-0298 (An improper input validation vulnerability exists in the
Windows Pre-L ...)
+ TODO: check
+CVE-2026-0297 (A buffer overflow vulnerability exists in the Palo Alto
Networks Globa ...)
+ TODO: check
+CVE-2026-0296 (Improper certificate validation vulnerabilities in Palo Alto
Networks ...)
+ TODO: check
+CVE-2026-0295 (A race condition in the Palo Alto Networks GlobalProtect\u2122
client ...)
+ TODO: check
+CVE-2026-0294 (A privilege escalation (PE) vulnerability in the Palo Alto
Networks Pr ...)
+ TODO: check
+CVE-2026-0293 (A vulnerability in Palo Alto Networks Prisma\xae Access Agent
on Windo ...)
+ TODO: check
+CVE-2026-0292 (An authentication bypass vulnerability in the network driver of
Palo A ...)
+ TODO: check
+CVE-2026-0291 (An improper link resolution before file access vulnerability
exists in ...)
+ TODO: check
+CVE-2026-0290 (An information disclosure vulnerability in the Account
Protection feat ...)
+ TODO: check
+CVE-2026-0289 (A security bypass vulnerability in the Account Protection
feature of ...)
+ TODO: check
+CVE-2025-9486 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
+ TODO: check
+CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow
an auth ...)
+ TODO: check
CVE-2026-53802
- rsync <unfixed>
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
@@ -97,9 +467,9 @@ CVE-2026-70462
CVE-2026-70454
- rsync <unfixed>
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-17431
+CVE-2026-17431 (PDF::WebKit versions through 1.2 for Perl allow OS command
injection v ...)
NOT-FOR-US: PDF::WebKit Perl module
-CVE-2026-16770
+CVE-2026-16770 (PDF::WebKit versions through 1.2 for Perl allow argument
injection int ...)
NOT-FOR-US: PDF::WebKit Perl module
CVE-2026-8667 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
@@ -2763,11 +3133,11 @@ CVE-2025-31936 (Improper handling of overlap between
protected memory ranges for
[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose
first in unstable, then likely point release)
NOTE:
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
NOTE:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html
-CVE-2026-71194
+CVE-2026-71194 (In OpenStack Designate before 22.0.2, the mDNS handler
performs pool-b ...)
- designate 1:22.0.0-2 (bug #1144145)
NOTE: https://bugs.launchpad.net/designate/+bug/2160533
NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
-CVE-2026-71193
+CVE-2026-71193 (In OpenStack Designate before 22.0.1, zone creation checks
(_is_subzon ...)
- designate 1:22.0.0-2 (bug #1144145)
NOTE: https://bugs.launchpad.net/designate/+bug/2160533
NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
@@ -3464,6 +3834,7 @@ CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the
GNU C Library version 2.0
CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in
Fabrik < 4. ...)
NOT-FOR-US: Joomla
CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in
SQLite-b ...)
+ {DSA-6435-1}
- spip 4.4.18+dfsg-1
NOTE:
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html
CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella
allows ...)
@@ -9169,6 +9540,7 @@ CVE-2017-20242 (Keysight IxChariot Endpoint before
9.5.102 contains a stack-base
CVE-2017-20241 (Keysight IxChariot Endpoint before 9.5.102 contains a
heap-based buffe ...)
NOT-FOR-US: Keysight IxChariot Endpoint
CVE-2026-15920 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0
before 6.0 ...)
+ {DLA-4736-1}
- python-django 3:5.2.17-1 (bug #1143611)
NOTE:
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by:
https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349
(5.2.17)
@@ -9179,6 +9551,7 @@ CVE-2026-15830 (An issue was discovered in Django 5.2
before 5.2.17 and 6.0 befo
NOTE:
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by:
https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080
(5.2.17)
CVE-2026-15337 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0
before 6.0 ...)
+ {DLA-4736-1}
- python-django 3:5.2.17-1 (bug #1143611)
NOTE:
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by:
https://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959
(5.2.17)
@@ -60950,7 +61323,7 @@ CVE-2018-25428 (Paroiciel 11.20 contains an SQL
injection vulnerability that all
CVE-2018-25427 (Arm Whois 3.11 contains a stack-based buffer overflow
vulnerability th ...)
NOT-FOR-US: Arm whois
CVE-2026-50256 (A stack-based buffer overflow flaw was found in the X.Org X
server and ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -60959,7 +61332,7 @@ CVE-2026-50256 (A stack-based buffer overflow flaw was
found in the X.Org X serv
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/a569eb4f36ed96a9e445ececd7e8d98c223461a0
(xorg-server-21.1.23)
CVE-2026-50257 (A use-after-free flaw was found in the X.Org X server and
Xwayland in ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -60968,7 +61341,7 @@ CVE-2026-50257 (A use-after-free flaw was found in the
X.Org X server and Xwayla
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f304b57444be3991fd9d3389f309c6eeb056a6c4
(xorg-server-21.1.23)
CVE-2026-50258 (A stack-based buffer overflow flaw was found in the X.Org X
server and ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -60977,7 +61350,7 @@ CVE-2026-50258 (A stack-based buffer overflow flaw was
found in the X.Org X serv
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/543e108516428fc8c3bea91d6563ad266f9a801e
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/eced7e74cad4a46c3a3c17b2df13b70b8bedfc25
(xorg-server-21.1.23)
CVE-2026-50259 (A stack-based buffer overflow flaw was found in the X.Org X
server and ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -60986,7 +61359,7 @@ CVE-2026-50259 (A stack-based buffer overflow flaw was
found in the X.Org X serv
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/867b59b33bee669cb412f1314e47c52eacf6e00b
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/54c3d9fad0f2f97835da9d275b53255f4963029f
(xorg-server-21.1.23)
CVE-2026-50260 (A use-after-free flaw was found in the X.Org X server and
Xwayland in ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -60995,7 +61368,7 @@ CVE-2026-50260 (A use-after-free flaw was found in the
X.Org X server and Xwayla
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f304b57444be3991fd9d3389f309c6eeb056a6c4
(xorg-server-21.1.23)
CVE-2026-50261 (A use-after-free flaw was found in the X.Org X server and
Xwayland in ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -61004,7 +61377,7 @@ CVE-2026-50261 (A use-after-free flaw was found in the
X.Org X server and Xwayla
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/bdd7bf57af208b1ddf57d4683d67104443b44812
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/92a167ab3fda0bee41cf97f6a40a4c01c67d85d4
(xorg-server-21.1.23)
CVE-2026-50262 (An out-of-bounds read flaw was found in the X.Org X server and
Xwaylan ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -61013,7 +61386,7 @@ CVE-2026-50262 (An out-of-bounds read flaw was found in
the X.Org X server and X
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/6d459e4daf715bea8abdafa8fb130be2f8a1d145
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/94341bd715d62ba8da4c1851f517018996da1af8
(xorg-server-21.1.23)
CVE-2026-50263 (A use-after-free flaw was found in the X.Org X server and
Xwayland in ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -61022,7 +61395,7 @@ CVE-2026-50263 (A use-after-free flaw was found in the
X.Org X server and Xwayla
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/ecc634f1b2f7aa473d3a267eada98c4918bf9e05
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/182c23f780402062ab31963776a19d5b87e25ac8
(xorg-server-21.1.23)
CVE-2026-50264 (An out-of-bounds write flaw was found in the X.Org X server
and Xwayla ...)
- {DSA-6371-1}
+ {DSA-6371-1 DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.23-1 (bug #1138680)
- xwayland 2:24.1.12-1 (bug #1138703)
[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be
running as root)
@@ -92702,6 +93075,7 @@ CVE-2024-9168
CVE-2024-23104 (An exposure of sensitive information to an unauthorized actor
vulnerab ...)
NOT-FOR-US: Fortinet
CVE-2026-34003 (A flaw was found in the X.Org X server's XKB key types request
validat ...)
+ {DLA-4738-1}
- xorg-server 2:21.1.22-1
[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92712,6 +93086,7 @@ CVE-2026-34003 (A flaw was found in the X.Org X
server's XKB key types request v
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/b85b00dd7b9eee05e3c12e7ad1fce4fc6671507b
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/d38c563fab5c4a554e0939da39e4d1dadef7cbae
CVE-2026-34002 (A flaw was found in the X.Org X server. This vulnerability, an
out-of- ...)
+ {DLA-4738-1}
- xorg-server 2:21.1.22-1
[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92721,6 +93096,7 @@ CVE-2026-34002 (A flaw was found in the X.Org X server.
This vulnerability, an o
NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
NOTE: fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f056ce1cc96ed9261052c31524162c78e458f98c
CVE-2026-34001 (A flaw was found in the X.Org X server. This use-after-free
vulnerabil ...)
+ {DLA-4738-1}
- xorg-server 2:21.1.22-1
[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92730,6 +93106,7 @@ CVE-2026-34001 (A flaw was found in the X.Org X server.
This use-after-free vuln
NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f19ab94ba9c891d801231654267556dc7f32b5e0
CVE-2026-34000 (A flaw was found in the X.Org X server. This out-of-bounds
read vulner ...)
+ {DLA-4738-1}
- xorg-server 2:21.1.22-1
[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92739,6 +93116,7 @@ CVE-2026-34000 (A flaw was found in the X.Org X server.
This out-of-bounds read
NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
NOTE: Fixed by:
ttps://gitlab.freedesktop.org/xorg/xserver/-/commit/81b6a34f90b28c32ad499a78a4f391b7c06daea2
CVE-2026-33999 (A flaw was found in the X.Org X server. This integer underflow
vulnera ...)
+ {DLA-4738-1}
- xorg-server 2:21.1.22-1
[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -158768,7 +159146,8 @@ CVE-2025-64076 (Multiple vulnerabilities exist in
cbor2 through version 5.7.0 in
NOTE: Introduced with:
https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542
(5.6.0)
NOTE: Fixed by:
https://github.com/agronholm/cbor2/commit/2349197bea8ebd1bf57a68f4a6549d8fd7585e66
(5.7.1)
NOTE: Debian builds src:cbor2 with CBOR2_BUILD_C_EXTENSION=0 (not
building C extensions)
-CVE-2025-63994 (An arbitrary file upload vulnerability in the
/php/UploadHandler.php c ...)
+CVE-2025-63994
+ REJECTED
NOT-FOR-US: RichFilemanager
CVE-2025-63955 (A Cross-Site Request Forgery (CSRF) vulnerability in the
manage-studen ...)
NOT-FOR-US: PHPGurukul
@@ -241362,6 +241741,7 @@ CVE-2024-13602 (The Poll Maker WordPress plugin
before 5.5.4 does not sanitise
CVE-2024-13126 (The Download Manager WordPress plugin before 3.3.07 doesn't
prevent di ...)
NOT-FOR-US: WordPress plugin
CVE-2022-49737 (In X.Org X server 20.11 through 21.1.16, when a client
application use ...)
+ {DLA-4738-1 DLA-4737-1}
- xorg-server 2:21.1.16-1.1 (bug #1081338)
NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260
NOTE:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0
(master)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e8b295787367fbd071362bece2934fbe9830ca5
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e8b295787367fbd071362bece2934fbe9830ca5
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits