Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1f6f2ba0 by security tracker role at 2026-08-25T07:12:35+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,273 @@
+CVE-2026-7455 (A maliciously crafted FLT file, when parsed through Autodesk
3ds Max, ...)
+ TODO: check
+CVE-2026-78685 (Medical Practice Management System developed by Le-yan has a
Remote Co ...)
+ TODO: check
+CVE-2026-78683 (NLTK before 3.10.0 (affected versions <=3.9.4) contains an
unsafe pick ...)
+ TODO: check
+CVE-2026-78682 (NLTK before 3.10.3 contains a server-side request forgery
vulnerabilit ...)
+ TODO: check
+CVE-2026-78681 (NLTK versions before 3.10.3 use xml.etree.ElementTree to parse
XML in ...)
+ TODO: check
+CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute
paths when ...)
+ TODO: check
+CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read
vulnerability ...)
+ TODO: check
+CVE-2026-78678 (GitPython versions before 3.1.59 contain an incomplete
denylist in the ...)
+ TODO: check
+CVE-2026-78677 (GitPython before 3.1.59 omits --separate-git-dir from
unsafe_git_clone ...)
+ TODO: check
+CVE-2026-78676 (GitPython before 3.1.59 fails to safely re-serialize
multi-line git-co ...)
+ TODO: check
+CVE-2026-78675 (GitPython before 3.1.59 fails to disable merge_includes when
parsing . ...)
+ TODO: check
+CVE-2026-78656 (A vulnerability was found in itsourcecode Sales and Inventory
System 1 ...)
+ TODO: check
+CVE-2026-78654 (A vulnerability has been found in cleverbrush framework and
deep up to ...)
+ TODO: check
+CVE-2026-78638 (A flaw has been found in peerigon unzip-crx and unzip-crx-3 up
to 0.2. ...)
+ TODO: check
+CVE-2026-78637 (A vulnerability was detected in Fdawgs node-poppler up to
9.1.2/10.0.1 ...)
+ TODO: check
+CVE-2026-78555 (RansomLook exposed complete API keys in the HTML source of the
authent ...)
+ TODO: check
+CVE-2026-78553 (RansomLook created its Flask session-signing key without
explicitly re ...)
+ TODO: check
+CVE-2026-78551 (RansomLook contains multiple weaknesses in its authentication
endpoint ...)
+ TODO: check
+CVE-2026-78478 (The Mane theme for WordPress is vulnerable to Local File
Inclusion in ...)
+ TODO: check
+CVE-2026-78477 (The Jawn theme for WordPress is vulnerable to Privilege
Escalation in ...)
+ TODO: check
+CVE-2026-78470 (The WP Project Manager Pro plugin for WordPress is vulnerable
to SQL I ...)
+ TODO: check
+CVE-2026-78467 (The Fluent Support Pro plugin for WordPress is vulnerable to
unauthori ...)
+ TODO: check
+CVE-2026-78466 (The Fluent Boards Pro plugin for WordPress is vulnerable to
Insecure D ...)
+ TODO: check
+CVE-2026-78435 (A vulnerability has been found in Faveo Helpdesk up to 2.0.3.
Affected ...)
+ TODO: check
+CVE-2026-78434 (A flaw has been found in Faveo Helpdesk up to 2.0.3. This
impacts the ...)
+ TODO: check
+CVE-2026-78430 (A vulnerability was detected in sworddut mcp-ffmpeg-helper
0.1.0/0.1.1 ...)
+ TODO: check
+CVE-2026-78284 (Unauthenticated Arbitrary File Deletion in MasterStudy LMS <=
3.7.42 v ...)
+ TODO: check
+CVE-2026-78282 (Unauthenticated Cross Site Scripting (XSS) in Stripe Payments
<= 2.1.2 ...)
+ TODO: check
+CVE-2026-78268 (Unauthenticated Sensitive Data Exposure in Lead Generation
Contact Wid ...)
+ TODO: check
+CVE-2026-78267 (Unauthenticated Privilege Escalation in TranslatePress <=
3.3.2 versio ...)
+ TODO: check
+CVE-2026-78266 (Subscriber Broken Access Control in AutomatorWP <= 5.8.3
versions.)
+ TODO: check
+CVE-2026-78265 (Unauthenticated PHP Object Injection in The Events Calendar <=
6.17.2 ...)
+ TODO: check
+CVE-2026-78264 (Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks
<= 1.6.26 ...)
+ TODO: check
+CVE-2026-78263 (Unauthenticated Cross Site Scripting (XSS) in Event Tickets <=
5.29.2. ...)
+ TODO: check
+CVE-2026-78262 (Unauthenticated PHP Object Injection in WP Project Manager <=
4.0.6 ve ...)
+ TODO: check
+CVE-2026-78259 (Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0
version ...)
+ TODO: check
+CVE-2026-77923 (Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass
vulnera ...)
+ TODO: check
+CVE-2026-77635 (CakePHP is a rapid development framework for PHP. Prior to
versions 5. ...)
+ TODO: check
+CVE-2026-77634 (CakePHP is a rapid development framework for PHP. Prior to
versions 4. ...)
+ TODO: check
+CVE-2026-77567 (Filament is a collection of full-stack components for
accelerated Lara ...)
+ TODO: check
+CVE-2026-77384 (libp2p is a JavaScript implementation of the libp2p networking
stack. ...)
+ TODO: check
+CVE-2026-77337 (CakePHP Authentication is an authentication plugin for CakePHP
that ca ...)
+ TODO: check
+CVE-2026-77310 (jackson-databind contains the general-purpose data-binding
functionali ...)
+ TODO: check
+CVE-2026-76846 (Grav before 2.0.16 contains an incomplete default denylist in
the Twig ...)
+ TODO: check
+CVE-2026-76839 (Grav before 2.0.16 allows sandboxed Twig templates to access
sensitive ...)
+ TODO: check
+CVE-2026-76816 (Netty is an asynchronous, event-driven network application
framework. ...)
+ TODO: check
+CVE-2026-76098 (Mistune is a Python Markdown parser with renderers and
plugins. Versio ...)
+ TODO: check
+CVE-2026-76063 (The FundEngine \u2013 Donation and Crowdfunding Platform
plugin for Wo ...)
+ TODO: check
+CVE-2026-75982 (The LearnPress plugin for WordPress is vulnerable to
unauthorized modi ...)
+ TODO: check
+CVE-2026-75930 (The FundEngine \u2013 Donation and Crowdfunding Platform
plugin for Wo ...)
+ TODO: check
+CVE-2026-75575 (Rocket.Chat exposes the sendForgotPasswordEmail Meteor method
without ...)
+ TODO: check
+CVE-2026-75574 (The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2
renders ...)
+ TODO: check
+CVE-2026-75554 (Insufficient Session Expiration vulnerability in the OAuth
token refre ...)
+ TODO: check
+CVE-2026-75542 (Incorrect Authorization vulnerability in the OAuth token
endpoint in h ...)
+ TODO: check
+CVE-2026-75509 (joserfc is a Python library that provides an implementation of
several ...)
+ TODO: check
+CVE-2026-75464 (OneNav 1.2.4 contains an authenticated arbitrary file deletion
vulnera ...)
+ TODO: check
+CVE-2026-75369 (An out-of-bounds read vulnerability in the
CAN::Application::parsePerf ...)
+ TODO: check
+CVE-2026-75368 (A stack overflow in the loadRawData function of SpaceDot
AcubeSAT OBC ...)
+ TODO: check
+CVE-2026-75019 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE
with 70 ...)
+ TODO: check
+CVE-2026-72714 (Rocq Prover does not restore the universe graph's copy of the
universe ...)
+ TODO: check
+CVE-2026-72711 (The Lean 4 kernel does not check that the body of an opaque
declaratio ...)
+ TODO: check
+CVE-2026-72705 (The guard checker in Rocq Prover does not follow recursive
calls made ...)
+ TODO: check
+CVE-2026-72704 (The guard checker in Rocq Prover does not recheck the
recursive tree r ...)
+ TODO: check
+CVE-2026-72703 (The guard checker in Rocq Prover treats a parameter of a
nested mutual ...)
+ TODO: check
+CVE-2026-72702 (Grav CMS before 2.0.16 contains an origin validation bypass in
the Uri ...)
+ TODO: check
+CVE-2026-72701 (Grav CMS before 2.0.16 contains a timing vulnerability in
Utils::verif ...)
+ TODO: check
+CVE-2026-72700 (The getgrav/grav-plugin-login Composer plugin before 3.9.1
(used by Gr ...)
+ TODO: check
+CVE-2026-72699 (The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1
is vuln ...)
+ TODO: check
+CVE-2026-72698 (Grav CMS before 2.0.16 fails to filter system, site, and theme
configu ...)
+ TODO: check
+CVE-2026-72697 (Grav CMS before 2.0.16 contains a path traversal vulnerability
in the ...)
+ TODO: check
+CVE-2026-72696 (Grav CMS before 2.0.16 contains a symlink following
vulnerability in S ...)
+ TODO: check
+CVE-2026-72695 (Grav before 2.0.16 contains a path traversal vulnerability in
MediaUpl ...)
+ TODO: check
+CVE-2026-71511 (Dolibarr before 24.0.0 contains a sensitive data exposure
vulnerabilit ...)
+ TODO: check
+CVE-2026-71510 (Dolibarr before 24.0.0 contains a SQL injection vulnerability
in the u ...)
+ TODO: check
+CVE-2026-69665 (SKYSEA Client View and SKYMEC IT Manager contain an issue with
incorre ...)
+ TODO: check
+CVE-2026-68960 (A stack-based buffer overflow vulnerability exists in SKYSEA
Client Vi ...)
+ TODO: check
+CVE-2026-68959 (SKYSEA Client View and SKYMEC IT Manager contain a path
traversal vuln ...)
+ TODO: check
+CVE-2026-68516 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-68062 (SKYSEA Client View and SKYMEC IT Manager contain a path
traversal vuln ...)
+ TODO: check
+CVE-2026-66766 (SAP S/4HANA (Private Cloud) uses a third-party component that
contains ...)
+ TODO: check
+CVE-2026-66109 (A missing authorization vulnerability exists in SKYSEA Client
View and ...)
+ TODO: check
+CVE-2026-63693 (Dell Client BIOS contains an Improper Link Resolution Before
File Acce ...)
+ TODO: check
+CVE-2026-61419 (Dell ThinOS 10, versions prior to 2605_10.2518, contain an
Improper Ac ...)
+ TODO: check
+CVE-2026-5006 (A vulnerability was identified in HashiCorp Vault and Vault
Enterprise ...)
+ TODO: check
+CVE-2026-59183 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-56710 (Grav Login plugin versions before 1.0.16 fail to validate the
target a ...)
+ TODO: check
+CVE-2026-56709 (Grav before 3.9.2 fails to validate untrusted Host headers in
the send ...)
+ TODO: check
+CVE-2026-56708 (Grav API plugin before 1.0.16 contains a server-side request
forgery v ...)
+ TODO: check
+CVE-2026-56707 (Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain
an autho ...)
+ TODO: check
+CVE-2026-56706 (Adminer before 5.4.3 uses a CSRF token scheme that transmits
both the ...)
+ TODO: check
+CVE-2026-56705 (Adminer before 5.4.3 fails to sanitize the server field before
constru ...)
+ TODO: check
+CVE-2026-56704 (Adminer before 5.4.3 inserts unsanitized database server
version strin ...)
+ TODO: check
+CVE-2026-56703 (Adminer before 5.4.3 contains a remote code execution
vulnerability in ...)
+ TODO: check
+CVE-2026-56702 (Adminer versions before 5.4.3 contain an unrestricted file
upload vuln ...)
+ TODO: check
+CVE-2026-55468 (Wagtail is an open source content management system built on
Django. P ...)
+ TODO: check
+CVE-2026-55373 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-55371 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-55059 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-54920 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-53532 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-52492 (An integer overflow in the libtiff rgb2ycbcr utility's
cvtRaster() fun ...)
+ TODO: check
+CVE-2026-52490 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938
allows an ...)
+ TODO: check
+CVE-2026-45404 (OpenTelemetry-Go is the Go implementation of OpenTelemetry.
From versi ...)
+ TODO: check
+CVE-2026-34968 (Adminer before 5.4.3 contains an arbitrary file deletion
vulnerability ...)
+ TODO: check
+CVE-2026-34967 (Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin
enabled c ...)
+ TODO: check
+CVE-2026-34964 (Adminer before 5.5.0 contains a server-side request forgery
vulnerabil ...)
+ TODO: check
+CVE-2026-34959 (Adminer 4.6.0 before 5.5.0 prepends the client-supplied
X-Forwarded-Pr ...)
+ TODO: check
+CVE-2026-32563 (Subscriber PHP Object Injection in ACPT (Pro) - Custom Post
Types Plug ...)
+ TODO: check
+CVE-2026-32561 (Subscriber Privilege Escalation in Booking Hub <= 1.3.0
versions.)
+ TODO: check
+CVE-2026-32560 (Subscriber Local File Inclusion in MagicAI for WordPress - AI
Text, Im ...)
+ TODO: check
+CVE-2026-32559 (Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0
versions.)
+ TODO: check
+CVE-2026-32556 (Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4
versions.)
+ TODO: check
+CVE-2026-32555 (Unauthenticated SQL Injection in Boost <= 2.0.4 versions.)
+ TODO: check
+CVE-2026-32554 (Unauthenticated SQL Injection in WooBeWoo Product Filter Pro
<= 3.1.8 ...)
+ TODO: check
+CVE-2026-27364 (Subscriber Broken Access Control in Style Kits <= 2.6.5
versions.)
+ TODO: check
+CVE-2026-19943 (The Gutenverse \u2013 WordPress Blocks, Page Builder & Site
Editor plu ...)
+ TODO: check
+CVE-2026-19892 (The InfusedWoo Pro plugin for WordPress is vulnerable to
Privilege Esc ...)
+ TODO: check
+CVE-2026-19801 (The BetterLinks \u2013 Link Shortener, Link Cloaking,
Redirects, Affil ...)
+ TODO: check
+CVE-2026-19568 (A maliciously crafted SVG file, when parsed through Autodesk
3ds Max, ...)
+ TODO: check
+CVE-2026-17113 (A flaw was found in CRI-O's container-creation
environment-variable ha ...)
+ TODO: check
+CVE-2026-17089 (The Events Manager \u2013 Calendar, Bookings, Tickets, and
more! plugi ...)
+ TODO: check
+CVE-2026-16783 (A maliciously crafted ABC file, when parsed through Autodesk
3ds Max, ...)
+ TODO: check
+CVE-2026-16782 (A maliciously crafted SVG file, when parsed through Autodesk
3ds Max, ...)
+ TODO: check
+CVE-2026-16781 (A maliciously crafted SVG file, when parsed through Autodesk
3ds Max, ...)
+ TODO: check
+CVE-2026-16434 (Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an
incomplete fi ...)
+ TODO: check
+CVE-2026-15023 (The Events Manager \u2013 Calendar, Bookings, Tickets, and
more! plugi ...)
+ TODO: check
+CVE-2026-14280 (The Events Manager \u2013 Calendar, Bookings, Tickets, and
more! plugi ...)
+ TODO: check
+CVE-2026-13215 (The Zephyr ext2 filesystem driver fails to validate the
s_log_block_si ...)
+ TODO: check
+CVE-2026-13214 (The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a
stack b ...)
+ TODO: check
+CVE-2026-12561 (The tagDiv Composer plugin for WordPress is vulnerable to
Stored Cross ...)
+ TODO: check
+CVE-2026-10630 (The WP Courses LMS \u2013 Online Courses Builder, eLearning
Courses, C ...)
+ TODO: check
+CVE-2026-10627 (The Events Manager \u2013 Calendar, Bookings, Tickets, and
more! plugi ...)
+ TODO: check
+CVE-2025-9878 (The PPWP \u2013 Password Protect WordPress | #1 Most-Reviewed
Password ...)
+ TODO: check
+CVE-2025-41741
+ REJECTED
+CVE-2020-37268 (Print Assumptions does not report that a definition was
produced while ...)
+ TODO: check
CVE-2026-9728 (The userspace syscall verifier z_vrfy_mbox_send() in
drivers/mbox/mbox ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-9254 (An unauthenticated OS command injection vulnerability exists in
the pa ...)
@@ -16221,7 +16491,7 @@ CVE-2026-73374 (A stored cross-site scripting (XSS)
vulnerability existed in Vul
NOT-FOR-US: vulnerability-lookup
CVE-2026-73327
REJECTED
-CVE-2026-73325 (Fujitsu Research's OneCompression library 1.2.0 contains an
unsafe des ...)
+CVE-2026-73325 (Fujitsu Research's OneCompression library before 1.2.1
contains an uns ...)
NOT-FOR-US: Fujitsu Research's OneCompression library
CVE-2026-73301 (Budibase is an open-source low-code platform. Prior to
3.39.25, the GE ...)
NOT-FOR-US: Budibase
@@ -32167,6 +32437,7 @@ CVE-2026-59528 (Subscriber Sensitive Data Exposure in
ShipTime: Discounted Shipp
CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP
public_key certif ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-622p-qfh6-c352
NOTE: https://cna.erlef.org/cves/CVE-2026-59251.html
@@ -32175,6 +32446,7 @@ CVE-2026-59251 (Allocation of resources without limits
in Erlang/OTP public_key
NOTE: Fixed by:
https://github.com/erlang/otp/commit/f04c6bba38de1cf1b1836a7d9a9fbe239bd939e8
(OTP-27.3.4.15)
NOTE: Fixed by:
https://github.com/erlang/otp/commit/f8580fc117098c08165f46c26fd0750c5cfb2a90
(OTP-29.0.4, OTP-28.5.0.4)
CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner
C driver ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7
NOTE: https://cna.erlef.org/cves/CVE-2026-59250.html
@@ -32194,6 +32466,7 @@ CVE-2026-58389 (Allocation of Resources Without Limits
or Throttling vulnerabili
NOTE: https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw
NOTE: rust bindings not built in Debian package
CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when
reconstruct ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw
NOTE: https://cna.erlef.org/cves/CVE-2026-58227.html
@@ -32235,6 +32508,7 @@ CVE-2026-55968 (Inefficient Algorithmic Complexity,
Allocation of Resources With
NOTE: https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
NOTE: nodejs bindings not built in Debian package
CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does
not veri ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882
NOTE: https://cna.erlef.org/cves/CVE-2026-55953.html
@@ -32244,6 +32518,7 @@ CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and
earlier) and DTLS client does no
NOTE: Fixed by:
https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c
(OTP-28.5.0.4)
NOTE: Fixed by:
https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b
(OTP-29.0.4)
CVE-2026-55737 (Signed to Unsigned Conversion Error and Out-of-bounds Write
vulnerabil ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462
NOTE: https://cna.erlef.org/cves/CVE-2026-55737.html
@@ -32255,6 +32530,7 @@ CVE-2026-55579 (Pheditor is a single-file editor and
file manager written in PHP
CVE-2026-55578 (Pheditor is a single-file editor and file manager written in
PHP. From ...)
NOT-FOR-US: Pheditor
CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang
otp erl ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-54pw-5645-jh86
NOTE: https://cna.erlef.org/cves/CVE-2026-54890.html
@@ -32316,6 +32592,7 @@ CVE-2026-48051 (Papra is a minimalistic document
management and archiving platfo
CVE-2026-48030 (Pheditor is a single-file editor and file manager written in
PHP. From ...)
NOT-FOR-US: Pheditor
CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib
zip module ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-rf72-wp7h-jg3x
NOTE: https://cna.erlef.org/cves/CVE-2026-47078.html
@@ -32341,6 +32618,7 @@ CVE-2026-43871 (Loop with Unreachable Exit Condition
('Infinite Loop') vulnerabi
[trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in
Erlang OT ...)
+ {DSA-6464-1}
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-h6f3-hx58-xhj6
NOTE: https://cna.erlef.org/cves/CVE-2026-42792.html
@@ -45156,13 +45434,13 @@ CVE-2026-10673 (The Zephyr ADIN2111/ADIN1110
10BASE-T1S/T1L Ethernet driver (dri
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-32781 (Apollo is a reliable configuration management system suitable
for micr ...)
NOT-FOR-US: Apollo
-CVE-2026-56136
+CVE-2026-56136 (In NTFS-3G through 2026.2.25, an out-of-bounds read exists in
ntfs_ir_ ...)
{DSA-6389-1}
[experimental] - ntfs-3g 1:2026.7.7-1
- ntfs-3g 1:2026.7.7-2 (bug #1142144)
NOTE:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-r66g-c39x-cw95
NOTE: https://www.openwall.com/lists/oss-security/2026/07/15/6
-CVE-2026-56135
+CVE-2026-56135 (In NTFS-3G through 2026.2.25, a heap-based buffer overflow
exists in t ...)
{DSA-6389-1}
[experimental] - ntfs-3g 1:2026.7.7-1
- ntfs-3g 1:2026.7.7-2 (bug #1142144)
@@ -53434,6 +53712,7 @@ CVE-2026-56037 (Deserialization of Untrusted Data
vulnerability in Themify Themi
CVE-2026-56004 (A shellcode injection in the mercurial handler of the obs
tar_scm sour ...)
NOT-FOR-US: obs-service-tar_scm
CVE-2026-55952 (The Erlang/OTP ssl application does not validate that the PSK
identity ...)
+ {DSA-6464-1}
- erlang 1:29.0.3+dfsg-1 (bug #1141414)
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55952
NOTE: https://cna.erlef.org/cves/CVE-2026-55952.html
@@ -53441,6 +53720,7 @@ CVE-2026-55952 (The Erlang/OTP ssl application does not
validate that the PSK id
NOTE:
https://github.com/erlang/otp/commit/2c3e599797644310e5d4aa39c7193420e59dadff
(OTP-28.5.0.3)
NOTE:
https://github.com/erlang/otp/commit/9b5437c72fa3403a75c1aba28e5c532bc191c662
(OTP-27.3.4.14)
CVE-2026-55950 (Time-of-check Time-of-use (TOCTOU) race condition
vulnerability in Erl ...)
+ {DSA-6464-1}
- erlang 1:29.0.3+dfsg-1 (bug #1141414)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-hwfc-5hf4-gvr3
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55950
@@ -53467,18 +53747,21 @@ CVE-2026-55111 (A malicious actor with access to the
network could exploit a Pat
CVE-2026-55110 (A malicious actor who lures an authenticated user to a
malicious page ...)
NOT-FOR-US: UniFi
CVE-2026-54891 (Improper Enforcement of Message Integrity During Transmission
in a Com ...)
+ {DSA-6464-1}
- erlang 1:29.0.3+dfsg-1 (bug #1141414)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-gf6r-99xw-6qg6
NOTE: https://cna.erlef.org/cves/CVE-2026-54891.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-54891
NOTE:
https://github.com/erlang/otp/commit/07d2d0e93f6aaf7652a81e8df075fc1728da5e96
(OTP-29.0.3, OTP-28.5.0.3, OTP-27.3.4.14)
CVE-2026-54887 (Use of Default Cryptographic Key vulnerability in Erlang/OTP
ssl (DTLS ...)
+ {DSA-6464-1}
- erlang 1:29.0.3+dfsg-1 (bug #1141414)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-p2m2-3c2w-8jp8
NOTE: https://cna.erlef.org/cves/CVE-2026-54887.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-54887
NOTE:
https://github.com/erlang/otp/commit/888e3bcd72d5406016b9e0de741026bc2a6f114d
(OTP-29.0.3, OTP-28.5.0.3, OTP-27.3.4.14)
CVE-2026-54886 (Loop with Unreachable Exit Condition ('Infinite Loop')
vulnerability i ...)
+ {DSA-6464-1}
- erlang 1:29.0.3+dfsg-1 (bug #1141414)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-7wp4-pc27-2vj9
NOTE: https://cna.erlef.org/cves/CVE-2026-54886.html
@@ -53517,6 +53800,7 @@ CVE-2026-54401 (A malicious actor with access to the
network and low privileges
CVE-2026-54400 (A malicious actor with access to the network and high
privileges could ...)
NOT-FOR-US: UniFi
CVE-2026-53422 (Observable Response Discrepancy vulnerability in Erlang OTP
ssh (ssh_s ...)
+ {DSA-6464-1}
- erlang 1:29.0.3+dfsg-1 (bug #1141414)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-h9pw-h5w4-h976
NOTE: https://cna.erlef.org/cves/CVE-2026-53422.html
@@ -70528,11 +70812,13 @@ CVE-2026-49822 (Fission is an open-source,
Kubernetes-native serverless framewor
CVE-2026-49821 (Fission is an open-source, Kubernetes-native serverless
framework that ...)
NOT-FOR-US: Fission
CVE-2026-49760 (Stack-based Buffer Overflow vulnerability in Erlang OTP
(erl_interface ...)
+ {DSA-6464-1}
- erlang 1:29.0.2+dfsg-1 (bug #1139727)
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-49760
NOTE: https://cna.erlef.org/cves/CVE-2026-49760.html
NOTE: Fixed by:
https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111
(OTP-29.0.2, OTP-28.5.0.2, OTP-27.3.4.13)
CVE-2026-49759 (Stack-based Buffer Overflow vulnerability in Erlang OTP erts
(inet_drv ...)
+ {DSA-6464-1}
- erlang 1:29.0.2+dfsg-1 (bug #1139727)
NOTE: https://cna.erlef.org/cves/CVE-2026-49759.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-49759
@@ -70548,6 +70834,7 @@ CVE-2026-49495 (Ghidra 10.2 before 12.1 contains an
uncontrolled resource consum
CVE-2026-49069 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-48860 (Reliance on IP Address for Authentication vulnerability in
Erlang/OTP ...)
+ {DSA-6464-1}
- erlang 1:29.0.2+dfsg-1 (bug #1139727)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv
NOTE: https://cna.erlef.org/cves/CVE-2026-48860.html
@@ -70560,6 +70847,7 @@ CVE-2026-48859 (Observable Timing Discrepancy
vulnerability in Erlang/OTP ssh (s
NOTE: Introduced with:
https://github.com/erlang/otp/commit/032d1bc9491a3975c68faf9bc7776115d6ae3005
(OTP-29.0-rc2)
NOTE: Fixed by:
https://github.com/erlang/otp/commit/c342092ef4b369bb409d5b71ac8fd83bab74aedf
(OTP-29.0.2)
CVE-2026-48858 (Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP
ftp (ft ...)
+ {DSA-6464-1}
- erlang 1:29.0.2+dfsg-1 (bug #1139727)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-24cv-hwgr-37fq
NOTE: https://cna.erlef.org/cves/CVE-2026-48858.html
@@ -70567,12 +70855,14 @@ CVE-2026-48858 (Server-Side Request Forgery (SSRF)
vulnerability in Erlang/OTP f
NOTE: Fixed by:
https://github.com/erlang/otp/commit/2691a806231ffd0490a8a9e20500dec0c7e73727
(OTP-29.0.2, OTP-28.5.0.2)
NOTE: Fixed by:
https://github.com/erlang/otp/commit/521bcfa24407ee8cb5614823cf905c37ea3aa605
(OTP-27.3.4.13)
CVE-2026-48856 (Sensitive Data Exposure vulnerability in Erlang OTP inets
(httpc_respo ...)
+ {DSA-6464-1}
- erlang 1:29.0.2+dfsg-1 (bug #1139727)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-m75x-4vwg-ggjh
NOTE: https://cna.erlef.org/cves/CVE-2026-48856.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-48856
NOTE: Fixed by:
https://github.com/erlang/otp/commit/688d748d6f7a6a06b13b662a1d3de8af97079612
(OTP-29.0.2, OTP-28.5.0.2, OTP-27.3.4.13)
CVE-2026-48855 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
+ {DSA-6464-1}
- erlang 1:29.0.2+dfsg-1 (bug #1139727)
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh
NOTE: https://cna.erlef.org/cves/CVE-2026-48855.html
@@ -81899,6 +82189,7 @@ CVE-2026-42879 (FacturaScripts is an open source
accounting and invoicing softwa
CVE-2026-42878 (FacturaScripts is an open source accounting and invoicing
software. Pr ...)
NOT-FOR-US: FacturaScripts
CVE-2026-42791 (Improper Certificate Validation vulnerability in Erlang OTP
public_key ...)
+ {DSA-6464-1}
- erlang 1:27.3.4.12+dfsg-1
[bookworm] - erlang <not-affected> (Vulnerable code not present)
[bullseye] - erlang <not-affected> (Vulnerable code not present)
@@ -81908,6 +82199,7 @@ CVE-2026-42791 (Improper Certificate Validation
vulnerability in Erlang OTP publ
NOTE:
https://github.com/erlang/otp/commit/7995f1fdaee3da569bb810358ce0f546471d169b
(OTP-27.3.4.12)
NOTE:
https://github.com/erlang/otp/commit/b3870e02405c709a872b01ba6086065620cdfe76
(OTP-29.0.1, OTP-28.5.0.1)
CVE-2026-42790 (Improper Certificate Validation vulnerability in Erlang OTP
public_key ...)
+ {DSA-6464-1}
- erlang 1:27.3.4.12+dfsg-1
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-22cw-4ph4-6447
NOTE: https://cna.erlef.org/cves/CVE-2026-42790.html
@@ -81916,6 +82208,7 @@ CVE-2026-42790 (Improper Certificate Validation
vulnerability in Erlang OTP publ
NOTE:
https://github.com/erlang/otp/commit/fb67c6d1836f51105a96d8b769e71e4215a79457
(OTP-27.3.4.12)
NOTE:
https://github.com/erlang/otp/commit/21abed64eb2026b5f82f432709e4e932f9be389a
(OTP-29.0.1, OTP-28.5.0.1)
CVE-2026-42789 (Improper Following of a Certificate's Chain of Trust
vulnerability in ...)
+ {DSA-6464-1}
- erlang 1:27.3.4.12+dfsg-1
NOTE:
https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq
NOTE: https://cna.erlef.org/cves/CVE-2026-42789.html
@@ -90309,7 +90602,7 @@ CVE-2026-39803 (Allocation of Resources Without Limits
or Throttling vulnerabili
NOT-FOR-US: Bandit (mtrudel/bandit, not the same as src:bandit)
CVE-2026-39459 (A vulnerability exists in iControl REST and the TMOS Shell
(tmsh) wher ...)
NOT-FOR-US: F5
-CVE-2026-39458 (When a BIG-IP DNS profile enabled with DNS cache is configured
on a vi ...)
+CVE-2026-39458 (When a BIG-IP is configured with DNS caching (Such as a DNS
profile w ...)
NOT-FOR-US: F5
CVE-2026-39455 (When the BIG-IP Configuration utility is configured to use
Lightweight ...)
NOT-FOR-US: F5
@@ -106579,6 +106872,7 @@ CVE-2026-32604 (Spinnaker is an open source,
multi-cloud continuous delivery pla
CVE-2026-32311 (Flowsint is an open-source OSINT graph exploration tool
designed for c ...)
NOT-FOR-US: Flowsint
CVE-2026-32147 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
+ {DSA-6464-1}
- erlang 1:27.3.4.11+dfsg-1
[bookworm] - erlang <no-dsa> (Minor issue)
[bullseye] - erlang <postponed> (Minor issue, can be fixed with next
update)
@@ -113725,6 +114019,7 @@ CVE-2026-33227 (Improper validation and restriction
of a classpath path name vul
CVE-2026-32588 (Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0
allows au ...)
- cassandra <itp> (bug #585905)
CVE-2026-32144 (Improper Certificate Validation vulnerability in Erlang OTP
public_key ...)
+ {DSA-6464-1}
- erlang 1:27.3.4.10+dfsg-1
[bookworm] - erlang <not-affected> (Vulnerable code not present, only
affects 27 and later)
[bullseye] - erlang <not-affected> (Vulnerable code not present, only
affects 27 and later)
@@ -113749,6 +114044,7 @@ CVE-2026-30460 (Daylight Studio FuelCMS v1.5.2 was
discovered to contain an auth
CVE-2026-30079 (In OpenAirInterface V2.2.0 AMF, Out of sequence messages
causes incorr ...)
NOT-FOR-US: OpenAirInterface
CVE-2026-28810 (Generation of Predictable Numbers or Identifiers vulnerability
in Erla ...)
+ {DSA-6464-1}
- erlang 1:27.3.4.10+dfsg-1
[bookworm] - erlang <no-dsa> (Minor issue)
[bullseye] - erlang <postponed> (Minor issue, can be fixed with next
update)
@@ -113757,6 +114053,7 @@ CVE-2026-28810 (Generation of Predictable Numbers or
Identifiers vulnerability i
NOTE: Fixed by:
https://github.com/erlang/otp/commit/b057a9d995017b1be50d6dc02edd52382f3231b8
(OTP-26.2.5.19, OTP-27.3.4.10, OTP-28.4.2)
NOTE: https://cna.erlef.org/cves/CVE-2026-28810.html
CVE-2026-28808 (Incorrect Authorization vulnerability in Erlang OTP (inets
modules) al ...)
+ {DSA-6464-1}
- erlang 1:27.3.4.10+dfsg-1
[bookworm] - erlang <no-dsa> (Minor issue)
[bullseye] - erlang <postponed> (Minor issue, can be fixed with next
update)
@@ -501019,8 +501316,8 @@ CVE-2022-30985
RESERVED
CVE-2022-30984 (A buffer overflow vulnerability in the Rubrik Backup Service
(RBS) Age ...)
NOT-FOR-US: Rubrik CDM
-CVE-2022-30983
- RESERVED
+CVE-2022-30983 (A cross-site scripting (XSS) vulnerability in Support chatbot
in Nopap ...)
+ TODO: check
CVE-2022-30982 (An issue was discovered in Gentics CMS before 5.43.1. There is
stored ...)
NOT-FOR-US: Gentics CMS
CVE-2022-30981 (An issue was discovered in Gentics CMS before 5.43.1. By
uploading a m ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f6f2ba03f6c479e50772065895fbce3d58aea2e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f6f2ba03f6c479e50772065895fbce3d58aea2e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits