Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d550a0b3 by security tracker role at 2026-08-17T19:13:47+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,329 @@
+CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy()
in dri ...)
+ TODO: check
+CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was
possible via u ...)
+ TODO: check
+CVE-2026-75059 (In JetBrains PyCharm before 2026.2.1 code execution via Quick
Document ...)
+ TODO: check
+CVE-2026-75058 (In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in
the Ecl ...)
+ TODO: check
+CVE-2026-75057 (In JetBrains IntelliJ IDEA before 2026.1.5 git credentials
were writte ...)
+ TODO: check
+CVE-2026-75056 (In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown
export too ...)
+ TODO: check
+CVE-2026-75055 (In JetBrains IntelliJ IDEA before 2026.2.1 hadoop
ResourceManager coul ...)
+ TODO: check
+CVE-2026-75054 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible
via the O ...)
+ TODO: check
+CVE-2026-75053 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible
via the D ...)
+ TODO: check
+CVE-2026-75052 (In JetBrains IntelliJ IDEA before 2026.2.1 command execution
via craft ...)
+ TODO: check
+CVE-2026-75051 (In JetBrains YouTrack before 2026.2.17917 unauthorised project
transfe ...)
+ TODO: check
+CVE-2026-75050 (In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS
attack wa ...)
+ TODO: check
+CVE-2026-75049 (In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an
authentica ...)
+ TODO: check
+CVE-2026-75048 (In JetBrains YouTrack before 2026.2.18068 stored XSS via the
fenced co ...)
+ TODO: check
+CVE-2026-75047 (In JetBrains YouTrack before 2026.2.18177 doS attack was
possible via ...)
+ TODO: check
+CVE-2026-75046 (In JetBrains YouTrack before 2026.2.18112 an authenticated
user could ...)
+ TODO: check
+CVE-2026-75045 (In JetBrains YouTrack before 2025.3.156085, 2026.1.13913,
2026.2.181 ...)
+ TODO: check
+CVE-2026-75044 (In JetBrains YouTrack before 2025.3.156085, 2026.1.13914,
2026.2.180 ...)
+ TODO: check
+CVE-2026-75011 (A flaw has been found in kylecui NetForensicMCP 2.1.0.
Impacted is the ...)
+ TODO: check
+CVE-2026-74901 (openssl_encrypt versions before 1.4.0 contain an
authentication bypass ...)
+ TODO: check
+CVE-2026-74900 (openssl_encrypt versions before 1.4.0 contain a critical
vulnerability ...)
+ TODO: check
+CVE-2026-74899 (openssl_encrypt versions before 1.4.0 contain a sandbox escape
vulnera ...)
+ TODO: check
+CVE-2026-74896 (openssl_encrypt versions before 1.4.0 contain a sandbox escape
vulnera ...)
+ TODO: check
+CVE-2026-74895 (openssl_encrypt versions before 1.4.0 fail to apply sandbox
restrictio ...)
+ TODO: check
+CVE-2026-74894 (openssl_encrypt before 1.4.0 contains an authentication bypass
vulnera ...)
+ TODO: check
+CVE-2026-74893 (openssl_encrypt versions before 1.4.0 contain hardcoded
default JWT si ...)
+ TODO: check
+CVE-2026-74892 (openssl_encrypt versions before 1.4.0 contain a hardcoded
default secr ...)
+ TODO: check
+CVE-2026-74891 (openssl_encrypt versions before 1.4.0 contain hardcoded
database crede ...)
+ TODO: check
+CVE-2026-74890 (openssl_encrypt versions before 1.4.0 contain an
authentication bypass ...)
+ TODO: check
+CVE-2026-74889 (openssl_encrypt versions before 1.4.0 use HKDF with no salt
and static ...)
+ TODO: check
+CVE-2026-74888 (openssl_encrypt versions before 1.4.0 use a non-standard
PBKDF2 key de ...)
+ TODO: check
+CVE-2026-74887 (openssl_encrypt before 1.4.0 imports Python's
non-cryptographic 'rando ...)
+ TODO: check
+CVE-2026-74886 (openssl_encrypt versions before 1.4.0 contain a plugin sandbox
bypass ...)
+ TODO: check
+CVE-2026-74885 (openssl_encrypt versions before 1.4.0 contain a logging bug in
restore ...)
+ TODO: check
+CVE-2026-74884 (openssl_encrypt versions before 1.4.0 contain a path traversal
vulnera ...)
+ TODO: check
+CVE-2026-74883 (openssl_encrypt versions before 1.4.0 contain a sandbox bypass
vulnera ...)
+ TODO: check
+CVE-2026-74882 (openssl_encrypt versions before 1.4.0 contain an insecure
default conf ...)
+ TODO: check
+CVE-2026-74881 (openssl_encrypt versions before 1.4.0 configure CORS with
allow_origin ...)
+ TODO: check
+CVE-2026-74880 (openssl_encrypt versions before 1.4.0 accept refresh tokens as
URL que ...)
+ TODO: check
+CVE-2026-74879 (openssl_encrypt versions before 1.4.0 contain an information
disclosur ...)
+ TODO: check
+CVE-2026-74878 (openssl_encrypt versions before 1.4.0 use an in-memory rate
limiter fo ...)
+ TODO: check
+CVE-2026-74877 (openssl_encrypt versions before 1.4.0 contain a missing
ownership veri ...)
+ TODO: check
+CVE-2026-74876 (openssl_encrypt versions before 1.4.0 contain a vulnerability
in Publi ...)
+ TODO: check
+CVE-2026-74875 (openssl_encrypt versions before 1.4.0 silently skip JSON
schema valida ...)
+ TODO: check
+CVE-2026-74874 (openssl_encrypt versions before 1.4.0 use Python's
non-cryptographic r ...)
+ TODO: check
+CVE-2026-74873 (openssl_encrypt versions before 1.4.0 expose passwords passed
via the ...)
+ TODO: check
+CVE-2026-74872 (openssl_encrypt versions before 1.4.0 contain an arbitrary
code execut ...)
+ TODO: check
+CVE-2026-74871 (openssl_encrypt versions before 1.4.6 contain a key derivation
flaw in ...)
+ TODO: check
+CVE-2026-74870 (openssl_encrypt (pip) versions <= 1.4.7 contain an information
exposur ...)
+ TODO: check
+CVE-2026-74869 (stoatchat before 0.15.0 contains a missing authorization
vulnerability ...)
+ TODO: check
+CVE-2026-74868 (SiYuan versions before 3.7.4 contain an unthrottled
brute-force vulner ...)
+ TODO: check
+CVE-2026-74867 (SiYuan versions before 3.7.4 contain a cross-site request
forgery vuln ...)
+ TODO: check
+CVE-2026-74858 (A vulnerability has been found in jae-jae fetcher-mcp up to
0.3.9. Imp ...)
+ TODO: check
+CVE-2026-74845 (Official Document Management System developed by 2100
Technology has a ...)
+ TODO: check
+CVE-2026-74843 (A vulnerability was determined in Wavlink WN531P3 and WN535M1
V250922. ...)
+ TODO: check
+CVE-2026-74842 (A vulnerability was found in Kira-Pgr PromptShopMCP up to
5bc0cd17358e ...)
+ TODO: check
+CVE-2026-74802 (SiYuan versions before 3.7.4 contain a cross-site WebSocket
hijacking ...)
+ TODO: check
+CVE-2026-74801 (SiYuan before 3.7.4 fails to properly escape workspace
directory paths ...)
+ TODO: check
+CVE-2026-74800 (SiYuan before v3.7.4 fails to set Content-Disposition and
X-Content-Ty ...)
+ TODO: check
+CVE-2026-74799 (SiYuan before 3.7.4 registers Go net/http/pprof debug
endpoints includ ...)
+ TODO: check
+CVE-2026-74798 (SiYuan kernel before v3.7.4 contains a path traversal
vulnerability in ...)
+ TODO: check
+CVE-2026-74254 (Joomla Extension - joomlack.fr - SQL injection in Page Builder
CK < 3. ...)
+ TODO: check
+CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE
through unver ...)
+ TODO: check
+CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read
vulnerabil ...)
+ TODO: check
+CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
+ TODO: check
+CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and
modify its ...)
+ TODO: check
+CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation
vulnerabi ...)
+ TODO: check
+CVE-2026-73522 (COVESA Open1722 through 0.9.2 contains a stack buffer overflow
vulnera ...)
+ TODO: check
+CVE-2026-73424 (Astro is a web framework for content-driven websites. From
10.0.3 unti ...)
+ TODO: check
+CVE-2026-71980 (Belledonne Communications bcg729 through 1.1.2 contains an
out-of-boun ...)
+ TODO: check
+CVE-2026-71979 (INDI (Instrument Neutral Distributed Interface) indiserver
through 2.2 ...)
+ TODO: check
+CVE-2026-71693
+ REJECTED
+CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in
some of the ...)
+ TODO: check
+CVE-2026-71566 (FakeFish handles incoming credentials by passing them down to
scripts ...)
+ TODO: check
+CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
+ TODO: check
+CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial
intellig ...)
+ TODO: check
+CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10,
version p ...)
+ TODO: check
+CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via
WebSocket deco ...)
+ TODO: check
+CVE-2026-68520 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
+ TODO: check
+CVE-2026-68519 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
+ TODO: check
+CVE-2026-68518 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
+ TODO: check
+CVE-2026-68517 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
+ TODO: check
+CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription
component. T ...)
+ TODO: check
+CVE-2026-64868 (New API is a large language mode (LLM) gateway and artificial
intellig ...)
+ TODO: check
+CVE-2026-64866 (New API is a large language mode (LLM) gateway and artificial
intellig ...)
+ TODO: check
+CVE-2026-64865 (New API is a large language mode (LLM) gateway and artificial
intellig ...)
+ TODO: check
+CVE-2026-64859 (New API is a large language mode (LLM) gateway and artificial
intellig ...)
+ TODO: check
+CVE-2026-62982 (Glances is an open-source system cross-platform monitoring
tool. From ...)
+ TODO: check
+CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with
pluggable I/O. P ...)
+ TODO: check
+CVE-2026-60107
+ REJECTED
+CVE-2026-60106
+ REJECTED
+CVE-2026-59911 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Insertion o ...)
+ TODO: check
+CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Improper Ne ...)
+ TODO: check
+CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path
Travers ...)
+ TODO: check
+CVE-2026-59903 (Netty is an asynchronous, event-driven network application
framework. ...)
+ TODO: check
+CVE-2026-59902 (Netty is an asynchronous, event-driven network application
framework. ...)
+ TODO: check
+CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
+ TODO: check
+CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
+ TODO: check
+CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to
2026.1.6, 20 ...)
+ TODO: check
+CVE-2026-58561 (Null pointer dereference issue in the image codec
module.Impact: Succe ...)
+ TODO: check
+CVE-2026-58560 (Null pointer dereference issue in the image codec
module.Impact: Succe ...)
+ TODO: check
+CVE-2026-56686 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Improper Ne ...)
+ TODO: check
+CVE-2026-56685 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Improper Ne ...)
+ TODO: check
+CVE-2026-56090 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Uncontrolle ...)
+ TODO: check
+CVE-2026-56089 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path
Travers ...)
+ TODO: check
+CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o
2026.1.6, 202 ...)
+ TODO: check
+CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to
2026.1.6, 20 ...)
+ TODO: check
+CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
+ TODO: check
+CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to
2026.1.6, 20 ...)
+ TODO: check
+CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and
5.4.x bef ...)
+ TODO: check
+CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs
Billetterie CSE - ...)
+ TODO: check
+CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1 allows a remote
attacker to e ...)
+ TODO: check
+CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to
escalate ...)
+ TODO: check
+CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED
2510.1.0.20 ...)
+ TODO: check
+CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote
attacker ...)
+ TODO: check
+CVE-2026-50771 (Cross Site Scripting vulnerability in Squirro Cognitive Search
< 3.14. ...)
+ TODO: check
+CVE-2026-50770 (An issue in Squirro Cognitive Search before v.3.14.2 allows a
remote a ...)
+ TODO: check
+CVE-2026-50769 (The CRM+ application before and including version 2025.6 from
Brainfor ...)
+ TODO: check
+CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH
ImageMaster ...)
+ TODO: check
+CVE-2026-49308 (Permission control vulnerability in the clipboard
module.Impact: Succe ...)
+ TODO: check
+CVE-2026-49307 (Permission control vulnerability in the multi-mode input
module.Impact ...)
+ TODO: check
+CVE-2026-49306 (UAF vulnerability in the time and time zone module.Impact:
Successful ...)
+ TODO: check
+CVE-2026-49305 (Permission control vulnerability in the Wi-Fi enhancement
module.Impac ...)
+ TODO: check
+CVE-2026-49304 (Permission control vulnerability in the device key management
module.I ...)
+ TODO: check
+CVE-2026-49303 (Permission control vulnerability in the notification
module.Impact: Su ...)
+ TODO: check
+CVE-2026-49302 (Permission control vulnerability in the notification service
module.Im ...)
+ TODO: check
+CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact:
Success ...)
+ TODO: check
+CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to
version 0.19. ...)
+ TODO: check
+CVE-2026-46345 (compliance-trestle is a tooling platform for managing
compliance as co ...)
+ TODO: check
+CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint
Privilege ...)
+ TODO: check
+CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode
component of ...)
+ TODO: check
+CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based
Cross-Site Scri ...)
+ TODO: check
+CVE-2026-33437 (Stirling-PDF is a locally hosted web application that
facilitates vari ...)
+ TODO: check
+CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital
Management Syste ...)
+ TODO: check
+CVE-2026-19999 (A security vulnerability has been detected in Open Asset
Import Librar ...)
+ TODO: check
+CVE-2026-19998 (A weakness has been identified in code-projects Online
Shopping System ...)
+ TODO: check
+CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent
directory ...)
+ TODO: check
+CVE-2026-18674 (On a Kong Mesh global control plane, resources received over
the zone- ...)
+ TODO: check
+CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially
vulnerabl ...)
+ TODO: check
+CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software
Technologies ...)
+ TODO: check
+CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software
Technologies ...)
+ TODO: check
+CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <=
5.12.5 and ...)
+ TODO: check
+CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and
below versi ...)
+ TODO: check
+CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and
below, a pa ...)
+ TODO: check
+CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The
Mattermost G ...)
+ TODO: check
+CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6,
10.11.x <= 10. ...)
+ TODO: check
+CVE-2026-16047 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21,
11.8.x <= 1 ...)
+ TODO: check
+CVE-2026-16046 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail
to enfo ...)
+ TODO: check
+CVE-2026-16045 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21
Mattermost f ...)
+ TODO: check
+CVE-2026-16044 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail
to prev ...)
+ TODO: check
+CVE-2026-15754 (Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The
access cont ...)
+ TODO: check
+CVE-2026-15218 (A flaw was found in the maas-api and maas-controller
ServiceAccounts w ...)
+ TODO: check
+CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim
Software ...)
+ TODO: check
+CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows
Input D ...)
+ TODO: check
+CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression
code conta ...)
+ TODO: check
+CVE-2026-12629 (The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails
to ackn ...)
+ TODO: check
+CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin
(WJA) t ...)
+ TODO: check
+CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited
%NOTIFYEV: ev ...)
+ TODO: check
+CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21,
11.8.x <= 1 ...)
+ TODO: check
+CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve
generative ...)
+ TODO: check
+CVE-2025-27771 (UpTrain is an open-source platform to evaluate and improve
generative ...)
+ TODO: check
+CVE-2025-27770 (UpTrain is an open-source platform to evaluate and improve
generative ...)
+ TODO: check
+CVE-2025-27621 (UpTrain is an open-source platform to evaluate and improve
generative ...)
+ TODO: check
CVE-2026-XXXX [heap out-of-bounds write during Unicode font-name conversion]
- antiword <unfixed> (bug #1144645)
CVE-2026-XXXX [heap out-of-bounds write during OLE PPS name decoding]
@@ -7499,7 +7825,8 @@ CVE-2026-73405 (An authorization bypass vulnerability in
Vulnerability-Lookup al
NOT-FOR-US: vulnerability-lookup
CVE-2026-73374 (A stored cross-site scripting (XSS) vulnerability existed in
Vulnerabi ...)
NOT-FOR-US: vulnerability-lookup
-CVE-2026-73327 (Joomla 6.1.1 contains a path traversal vulnerability in the
com_joomla ...)
+CVE-2026-73327
+ REJECTED
NOT-FOR-US: Joomla
CVE-2026-73325 (Fujitsu Research's OneCompression library 1.2.0 contains an
unsafe des ...)
NOT-FOR-US: Fujitsu Research's OneCompression library
@@ -8767,7 +9094,8 @@ CVE-2026-72542 (A missing authorization vulnerability in
Windmill Labs Windmill
NOT-FOR-US: Windmill
CVE-2026-72541 (A missing authorization vulnerability in Windmill Labs
Windmill throug ...)
NOT-FOR-US: Windmill
-CVE-2026-72540 (An insecure direct object reference vulnerability in
PhotoPrism throug ...)
+CVE-2026-72540
+ REJECTED
NOT-FOR-US: PhotoPrism
CVE-2026-72539 (An information disclosure vulnerability in Windmill Labs
Windmill thro ...)
NOT-FOR-US: Windmill
@@ -9436,7 +9764,7 @@ CVE-2026-62724 (Use after free in Windows Telephony
Service allows an authorized
NOT-FOR-US: Microsoft
CVE-2026-62723 (Use after free in Windows Telephony Service allows an
authorized attac ...)
NOT-FOR-US: Microsoft
-CVE-2026-62722 (Heap-based buffer overflow in Windows Bind Filter Driver
allows an aut ...)
+CVE-2026-62722 (Heap-based buffer overflow in Windows Brokering File System
allows an ...)
NOT-FOR-US: Microsoft
CVE-2026-62721 (Insufficient granularity of access control in User-Mode Power
Service ...)
NOT-FOR-US: Microsoft
@@ -10882,7 +11210,8 @@ CVE-2026-72570 (A stored cross-site scripting (XSS)
vulnerability in cube-root/d
NOT-FOR-US: cube-root/directory-serve
CVE-2026-72569 (A path traversal vulnerability in cube-root/directory-serve
through 1. ...)
NOT-FOR-US: cube-root/directory-serve
-CVE-2026-72568 (An out-of-bounds read vulnerability in Redis through 8.8.1
allows an a ...)
+CVE-2026-72568
+ REJECTED
- redis <undetermined>
TODO: check, assigned by a "Turan Security" CNA without further details
CVE-2026-72567 (An improper path validation vulnerability in
AsyncFuncAI/deepwiki-open ...)
@@ -11263,36 +11592,36 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in
Apache Airflow's Yandex pr
NOT-FOR-US: Apache Airflow provider
CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager
backends i ...)
NOT-FOR-US: Apache Airflow provider
-CVE-2026-74998 [Content proxied by the css proxy is not validated validation]
+CVE-2026-74998 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3,
responses f ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b
(1.6.18)
-CVE-2026-75006 [SSRF bypass]
+CVE-2026-75006 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3,
insufficien ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
(1.6.18)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9
(1.6.18)
-CVE-2026-75003 [Remote content blocking bypass via unclosed url() in a FuncIRI
attribute]
+CVE-2026-75003 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an
unclosed ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
(1.6.18)
-CVE-2026-75007 [LDAP filter injection via unescaped %u/%fu/%d substitution
into the `search_filter`]
+CVE-2026-75007 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the
LDAP se ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540
(1.6.18)
-CVE-2026-75004 [Arbitrary sieve script injection via a filter rule name
bypassing `managesieve_disabled_actions`]
+CVE-2026-75004 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3,
improper ru ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e
(1.6.18)
-CVE-2026-74997 [RCE in the `cmd_learn` driver of markasjunk plugin]
+CVE-2026-74997 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the
cmd_lea ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
(1.6.18)
NOTE: Follow-up:
https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a
(1.6.18)
-CVE-2026-75002 [IMAP command injection via mail search and LITERAL+ byte-count
desynchronization]
+CVE-2026-75002 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3,
mail search ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
(1.6.18)
-CVE-2026-75010 [The modoboa driver of the passwd plugin leaks an
authentication token to a user-controlled host]
+CVE-2026-75010 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the
modoboa ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
(1.6.18)
-CVE-2026-74999 [Stored XSS in "Add to address book" action]
+CVE-2026-74999 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the
"Add to ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8
(1.6.18)
-CVE-2026-75000 [HTML/CSS sanitization bypass via SVG animate `by` attribute]
+CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3,
improper HT ...)
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by:
https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f
(1.6.18)
CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a
usernam ...)
@@ -13347,7 +13676,7 @@ CVE-2026-9030 (A denial-of-service vulnerability exists
in httpd service on Arch
NOT-FOR-US: TPLink
CVE-2026-8798 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3,
the nati ...)
NOT-FOR-US: FIPS provider for Bouncycastle, not part of the Debian
package for Bouncycastle
-CVE-2026-71381 (Adobe Genuine Software Integrity Service was affected by an
Incorrect ...)
+CVE-2026-71381 (Adobe Genuine Software Integrity Service on Windows is
affected by an ...)
NOT-FOR-US: Adobe
CVE-2026-70624
REJECTED
@@ -15566,7 +15895,8 @@ CVE-2026-71247 (Documenso's sign-field-with-token.ts,
used by the live document-
NOT-FOR-US: Documenso
CVE-2026-71246 (Pixelfed's SearchController (behind the auth middleware)
accepts a URL ...)
NOT-FOR-US: Pixelfed
-CVE-2026-71245 (Mautic's getLeadIdsByFieldValueAction
(LeadBundle/Controller/AjaxContr ...)
+CVE-2026-71245
+ REJECTED
NOT-FOR-US: Mautic
CVE-2026-71244 (Paperless-ngx's MailAccountViewSet.test action, when called
with an ex ...)
NOT-FOR-US: Paperless-ngx
@@ -34746,23 +35076,23 @@ CVE-2026-5674 (A flaw was found in PipeWire, a
multimedia server. This vulnerabi
- pipewire <unfixed> (bug #1142416)
[trixie] - pipewire <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2455341
-CVE-2026-59867 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.5, ...)
+CVE-2026-59867 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59866 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.5, ...)
+CVE-2026-59866 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59865 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.5, ...)
+CVE-2026-59865 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59864 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.5, ...)
+CVE-2026-59864 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59863 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.5, ...)
+CVE-2026-59863 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59862 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.0, ...)
+CVE-2026-59862 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59861 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.0, ...)
+CVE-2026-59861 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59860 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.3, ...)
+CVE-2026-59860 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
-CVE-2026-59859 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.32.4, ...)
+CVE-2026-59859 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
NOT-FOR-US: Kiota
CVE-2026-59249 (Inconsistent interpretation of HTTP requests (HTTP response
smuggling) ...)
NOT-FOR-US: elixir-mint mint
@@ -40605,9 +40935,11 @@ CVE-2026-57825
NOTE: Testcase:
https://github.com/ocaml/opam/commit/362f5dc08c1436be964e14aa50a5837050124d36
(2.5.2)
NOTE: Fixed by:
https://github.com/ocaml/opam/commit/175a5d777806ad32fa6cdd95f2501dc4bd5e584e
(2.5.2)
CVE-2026-44918 (OpenStack Ironic through before 37.0.1 allows creation or
modification ...)
+ {DSA-6445-1}
- ironic 1:35.0.1-8 (bug #1141716)
NOTE: https://security.openstack.org/ossa/OSSA-2026-026.html
CVE-2026-54423 (In OpenStack Ironic before 37.0.1, an Ironic user with the
ability to ...)
+ {DSA-6445-1}
- ironic 1:35.0.1-8 (bug #1141717)
NOTE: https://security.openstack.org/ossa/OSSA-2026-025.html
CVE-2026-3886 [virtio-gpu: fix overflow check when allocating 2d image]
@@ -59686,7 +60018,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0176]
[bookworm] - rust-pyo3 <not-affected> (Vulnerable code not present,
only affects 0.24 and later)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0176.html
CVE-2026-54421 (In OpenStack Ironic before 37.0.1, when applying a PATCH to
update fie ...)
- {DLA-4743-1}
+ {DSA-6445-1 DLA-4743-1}
- ironic 1:35.0.1-6 (bug #1140012)
NOTE: https://bugs.launchpad.net/ironic/+bug/2155049
CVE-2026-54420 (LiteSpeed cPanel plugin before 2.4.8 (as distributed in
LiteSpeed WHM ...)
@@ -62493,7 +62825,7 @@ CVE-2026-41985 (UAF vulnerability in the package
management module.Impact: Succe
NOT-FOR-US: Huawei
CVE-2026-41984 (UAF vulnerability in the package management module.Impact:
Successful ...)
NOT-FOR-US: Huawei
-CVE-2026-41983 (DoS vulnerability in the browser kernel.Impact: Successful
exploitatio ...)
+CVE-2026-41983 (Null pointer dereference vulnerability in the browser
module.Impact: S ...)
NOT-FOR-US: Huawei
CVE-2026-41982 (Race condition vulnerability in the IPC module.Impact:
Successful expl ...)
NOT-FOR-US: Huawei
@@ -79847,7 +80179,7 @@ CVE-2026-45699 (Netatalk is a Free and Open Source file
server suite for Unix-li
{DSA-6280-1}
- netatalk 4.4.3~ds-1 (bug #1137125)
NOTE: https://netatalk.io/security/CVE-2026-45699
-CVE-2026-45698
+CVE-2026-45698 (Netatalk is a Free and Open Source file server suite for
Unix-like ope ...)
{DSA-6280-1}
- netatalk 4.4.3~ds-1 (bug #1137126)
NOTE: https://netatalk.io/security/CVE-2026-45698
@@ -90063,7 +90395,7 @@ CVE-2026-43504 (An issue was discovered in Prosody
before 0.12.6 and 1.0.0 throu
NOTE: https://prosody.im/security/advisory_735dd9d3/
NOTE: https://hg.prosody.im/trunk/rev/4bbb17445ed9
CVE-2026-43003 (An issue was discovered in OpenStack ironic-python-agent 1.0.0
through ...)
- {DLA-4743-1}
+ {DSA-6445-1 DLA-4743-1}
- ironic 1:35.0.1-7 (bug #1140187)
- ironic-python-agent 11.5.0-3 (bug #1135646)
[trixie] - ironic-python-agent <no-dsa> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d550a0b34e1ca1ae2dcf52d31cfcb6dbf6347fcb
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d550a0b34e1ca1ae2dcf52d31cfcb6dbf6347fcb
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits