Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3e71f80c by Moritz Muehlenhoff at 2026-09-03T08:42:18+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -598,6 +598,7 @@ CVE-2026-84423 (A vulnerability has been found in Casdoor 
up to 4.0.0. This affe
        NOT-FOR-US: Casdoor
 CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 
until 3.15. ...)
        - node-js-yaml <unfixed>
+       [trixie] - node-js-yaml <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
        NOTE: https://github.com/nodeca/js-yaml/pull/797
        NOTE: Fixed by: 
https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b
 (4.3.2)
@@ -1005,6 +1006,7 @@ CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 
through 8.0 contains an aut
        NOT-FOR-US: Proxmox Virtual Environment
 CVE-2026-82209
        - curl 8.22.0-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-82209.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 
(curl-7_46_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6 
(curl-8_22_0)
@@ -1017,6 +1019,7 @@ CVE-2026-82208
        NOTE: curl in Debian not built with wolfSSL support
 CVE-2026-80255
        - curl 8.22.0-1
+       [trixie] - curl <no-dsa> (Minor issue)
        [bookworm] - curl <not-affected> (Vulnerable code introduced later)
        NOTE: https://curl.se/docs/CVE-2026-80255.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603 
(curl-8_13_0)
@@ -1028,11 +1031,13 @@ CVE-2026-80231
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42 
(rc-8_22_0-3)
 CVE-2026-80230
        - curl 8.22.0~rc3-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-80230.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591 
(curl-7_45_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef 
(rc-8_22_0-3)
 CVE-2026-80229
        - curl 8.22.0~rc3-1
+       [trixie] - curl <no-dsa> (Minor issue)
        [bookworm] - curl <not-affected> (Vulnerable code introduced later)
        NOTE: https://curl.se/docs/CVE-2026-80229.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 
(rc-8_14_0-1)
@@ -1203,18 +1208,21 @@ CVE-2026-84303 (gRPC-Go is the Go language 
implementation of gRPC. Prior to 1.83
        NOTE: Fixed by: 
https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe 
(v1.83.1)
 CVE-2026-84270 (A flaw was found in the MTP backend in gvfs. When reading a 
file from  ...)
        - gvfs <unfixed> (bug #1146478)
+       [trixie] - gvfs <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/864
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/070e5e4223c97f7e793a342ba6e64df1095ccb0d
 (1.61.90)
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/25add8b5103384c7edc8ad74722ed93eb3f6f077
 (1.60.2)
 CVE-2026-84269 (A flaw was found in the AFP backend in gvfs. When mounting a 
share, a  ...)
        - gvfs <unfixed> (bug #1146478)
+       [trixie] - gvfs <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/863
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/072a7e02d11f5b7dfa324b70dd0e16d60f9b9e60
 (1.61.90)
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/81525b2c917950554255784542674222bfee797d
 (1.60.2)
 CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a 
share an ...)
        - gvfs <unfixed> (bug #1146478)
+       [trixie] - gvfs <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/862
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/5ab77256f9c071c7c99a5298db1729cf143bff05
 (1.61.90)
        NOTE: Follow up: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/1ff24454d1c9b964a5f0efdd54c6d1421e770d64
 (1.61.90)
@@ -1222,6 +1230,7 @@ CVE-2026-84268 (A flaw was found in the SFTP backend in 
gvfs. When mounting a sh
        NOTE: Follow up: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/1590471ad9c382de4fc544bdf49c8f424eea96f8
 (1.60.2)
 CVE-2026-84267 (A flaw was found in the SFTP backend in gvfs. When mounting a 
share, a ...)
        - gvfs <unfixed> (bug #1146478)
+       [trixie] - gvfs <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/861
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gvfs/-/commit/d9a59b8e385189b4783d9b66ca475f530fb26693
 (1.61.90)
@@ -1230,6 +1239,7 @@ CVE-2026-84235 (A denial-of-service security issue exists 
in the affected produc
        NOT-FOR-US: Rockwell Automation
 CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a 
specially cra ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478409
        TODO: check upstream details
 CVE-2026-84232 (A flaw was found in pulpcore's content serving application. 
Files uplo ...)
@@ -2316,15 +2326,19 @@ CVE-2026-82664 (A security vulnerability has been 
detected in yaojingang GEOFlow
        NOT-FOR-US: yaojingang GEOFlow
 CVE-2026-82662 (Nodemailer before 8.0.8 disables TLS certificate verification 
in lib/f ...)
        - node-nodemailer 8.0.11+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-r7g4-qg5f-qqm2
 CVE-2026-82661 (Nodemailer before 8.0.9 fails to sanitize carriage return and 
line fee ...)
        - node-nodemailer 8.0.11+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-268h-hp4c-crq3
 CVE-2026-82660 (Nodemailer before 8.0.9 fails to enforce disableFileAccess and 
disable ...)
        - node-nodemailer 8.0.11+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
 CVE-2026-82659 (nodemailer before 9.0.1 fails to apply disableFileAccess and 
disableUr ...)
        - node-nodemailer 9.0.3+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f
 CVE-2026-82631 (A security flaw has been discovered in valkey-io valkey 9.1.0. 
The aff ...)
        - valkey <unfixed>



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e71f80c22453a39342751c4dd1d4d693a0bc9b6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e71f80c22453a39342751c4dd1d4d693a0bc9b6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to