Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1d46475e by Moritz Muehlenhoff at 2026-08-17T18:08:57+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -16780,6 +16780,7 @@ CVE-2026-69198 (ip-address is a library for parsing and
manipulating IPv4 and IP
NOTE: Address6 in 10.2.0.
CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and
IPv6 add ...)
- node-ip-address 10.3.1-1
+ [trixie] - node-ip-address <no-dsa> (Minor issue)
NOTE:
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr
NOTE: Fixed by:
https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e
(v10.3.1)
CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication
for ever ...)
@@ -20941,6 +20942,7 @@ CVE-2026-17650 (Use after free in Compositing in Google
Chrome prior to 151.0.79
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16728 (undici's retry interceptor can deliver a response whose body
length do ...)
- node-undici 8.9.0+dfsg+~cs3.2.0-1
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE:
https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
CVE-2026-16727 (Concurrent Execution using Shared Resource with Improper
Synchronizati ...)
NOT-FOR-US: ASUS
@@ -20998,6 +21000,7 @@ CVE-2026-15235 (The MotoPress Hotel Booking WordPress
plugin before 6.0.4 does n
NOT-FOR-US: WordPress plugin
CVE-2026-15157 (undici does not validate the type property of a duck-typed
blob-like r ...)
- node-undici 8.9.0+dfsg+~cs3.2.0-1
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE:
https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
CVE-2026-15153 (The WP Hotel Booking WordPress plugin before 2.3.2 does not
sanitise a ...)
NOT-FOR-US: WordPress plugin
@@ -21009,6 +21012,7 @@ CVE-2026-14923 (The Sync Post With Other Site WordPress
plugin before 1.9.3 does
NOT-FOR-US: WordPress plugin
CVE-2026-14643 (undici's cache interceptor mishandles optional whitespace
placed aroun ...)
- node-undici 8.9.0+dfsg+~cs3.2.0-1
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE:
https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54
CVE-2026-14602 (The Remote API WordPress plugin through 0.2 does not
authenticate a re ...)
NOT-FOR-US: WordPress plugin
@@ -21500,6 +21504,7 @@ CVE-2026-16751 (Authorization Bypass in the emergency
recovery approval componen
NOT-FOR-US: Ente Technologies Ente Museum Server
CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie
attributes. ...)
- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143063)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE:
https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey,
Quiz, & Co ...)
NOT-FOR-US: WordPress plugin
@@ -21533,6 +21538,7 @@ CVE-2026-13723 (A vulnerability in the `zipx.Unzip`
extraction routine of Devela
NOT-FOR-US: Develar app-builder
CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control
private ...)
- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143070)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE:
https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272
CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to
Stored Cros ...)
NOT-FOR-US: WordPress plugin
@@ -25692,6 +25698,7 @@ CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows
authentication bypass via
NOTE: https://launchpad.net/bugs/2161254
CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0,
aproject-scoped user ...)
- ironic-python-agent 11.5.0-4 (bug #1142857)
+ [trixie] - ironic-python-agent <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/5
NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2160050
CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds
write vulne ...)
@@ -25895,6 +25902,7 @@ CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in
versions <= 4.7.15 is vul
NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious
bootc cont ...)
- ironic-python-agent 11.5.0-4 (bug #1142854)
+ [trixie] - ironic-python-agent <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
CVE-2026-58264 [heap-based buffer overrun in command handler]
@@ -29300,6 +29308,7 @@ CVE-2026-59143 (Data::RoaringBitmap::Shared versions
before 0.02 for Perl allow
NOT-FOR-US: Data::RoaringBitmap::Shared Perl module
CVE-2026-56852 (A norm.Iter can enter an infinite loop when handling input
containing ...)
- golang-golang-x-text 0.40.0-1 (bug #1142674)
+ [trixie] - golang-golang-x-text <no-dsa> (Minor issue)
[bookworm] - golang-golang-x-text <postponed> (Limited support, minor
issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8)
[bullseye] - golang-golang-x-text <postponed> (Limited support, minor
issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8)
NOTE: https://github.com/golang/go/issues/80142
=====================================
data/dsa-needed.txt
=====================================
@@ -144,7 +144,7 @@ rust-wasmtime
--
shaarli
--
-srt
+srt (jmm)
--
starlette
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d46475e441242989edb3adce87d7409590e2f17
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d46475e441242989edb3adce87d7409590e2f17
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits