Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a3cd012e by security tracker role at 2026-09-05T19:14:24+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,115 @@
+CVE-2026-86197 (Grav before 2.0.20 contains a cross-site scripting 
vulnerability in th ...)
+       TODO: check
+CVE-2026-86196 (Grav API plugin versions before 1.0.20 build password reset 
links from ...)
+       TODO: check
+CVE-2026-86195 (grav-plugin-api versions before 1.0.20 contain a privilege 
escalation  ...)
+       TODO: check
+CVE-2026-86194 (Grav Form Plugin before 9.1.22 fails to verify page 
authorization when ...)
+       TODO: check
+CVE-2026-86193 (grav-plugin-api before 1.0.20 fails to validate 
group-inherited super  ...)
+       TODO: check
+CVE-2026-86192 (SiYuan versions before v3.8.2 fail to properly filter private 
attribut ...)
+       TODO: check
+CVE-2026-86191 (SiYuan versions before v3.8.2 contain an information 
disclosure vulner ...)
+       TODO: check
+CVE-2026-86190 (WWBN AVideo contains a broken access control vulnerability in 
videoVie ...)
+       TODO: check
+CVE-2026-86189 (WWBN AVideo contains a path traversal vulnerability in 
notify.ffmpeg.j ...)
+       TODO: check
+CVE-2026-86188 (AVideo with YPTSocket plugin enabled contains a cross-site 
scripting v ...)
+       TODO: check
+CVE-2026-86187 (WWBN AVideo generates passwords for external-login accounts 
using rand ...)
+       TODO: check
+CVE-2026-86186 (AVideo API fails to enforce rate limits when clients send a 
bot User-A ...)
+       TODO: check
+CVE-2026-86185 (Bilibili Desktop through 1.18.0 disables TLS certificate 
verification  ...)
+       TODO: check
+CVE-2026-86184 (Lara Dashboard before 1.3.0 contains an authentication bypass 
vulnerab ...)
+       TODO: check
+CVE-2026-86178 (Pixelfed through 0.12.9 fails to validate follower status in 
StoryComp ...)
+       TODO: check
+CVE-2026-86177 (Pterodactyl Panel before 1.14.1 fails to validate 
action-specific perm ...)
+       TODO: check
+CVE-2026-86176 (NetBox through 4.7.0 fails to properly scope user-private 
records in R ...)
+       TODO: check
+CVE-2026-86175 (NetBox through 4.7.0 fails to redact sensitive data source 
backend cre ...)
+       TODO: check
+CVE-2026-86174 (Plane through 1.4.2 fails to validate that issues belong to 
the deploy ...)
+       TODO: check
+CVE-2026-86173 (MindsDB through 26.1.0 contains a server-side request forgery 
vulnerab ...)
+       TODO: check
+CVE-2026-86169 (Axolotl through 0.18.0 contains a remote code execution 
vulnerability  ...)
+       TODO: check
+CVE-2026-86124 (AutoAgent contains an unauthenticated remote code execution 
vulnerabil ...)
+       TODO: check
+CVE-2026-86123 (SQL Chat contains four unauthenticated API endpoints that 
accept clien ...)
+       TODO: check
+CVE-2026-86122 (Rowboat through 0.9.1 fails to validate custom MCP server and 
webhook  ...)
+       TODO: check
+CVE-2026-86121 (Cua computer-server versions before 0.3.42 skip authentication 
when th ...)
+       TODO: check
+CVE-2026-86120 (APITable through 1.13.0-beta.1 contains an incorrect 
authorization vul ...)
+       TODO: check
+CVE-2026-86119 (Webstudio through 0.296.0 contains an unauthenticated 
server-side requ ...)
+       TODO: check
+CVE-2026-86118 (gonic versions before 0.22.0 fail to validate administrator 
privileges ...)
+       TODO: check
+CVE-2026-86117 (Coolify through 4.3.17 contains an authentication bypass 
vulnerability ...)
+       TODO: check
+CVE-2026-86116 (Metabase versions before 0.63.1 fail to enforce data analyst 
permissio ...)
+       TODO: check
+CVE-2026-86115 (Sim before 0.8.14 classifies tool requests as internal based 
on URL pr ...)
+       TODO: check
+CVE-2026-86114 (Arcane versions before 2.0.0 fail to properly restrict 
template operat ...)
+       TODO: check
+CVE-2026-86113 (BookWyrm through 0.9.1 contains an authorization bypass 
vulnerability  ...)
+       TODO: check
+CVE-2026-86112 (BookWyrm through 0.9.1 fails to validate user visibility 
permissions i ...)
+       TODO: check
+CVE-2026-86111 (BookWyrm through 0.9.1 fails to validate user visibility 
permissions i ...)
+       TODO: check
+CVE-2026-85414 (The Gallery : FooGallery plugin for WordPress is vulnerable to 
Stored  ...)
+       TODO: check
+CVE-2026-83625 (The Contact Form by Supsystic plugin for WordPress is 
vulnerable to St ...)
+       TODO: check
+CVE-2026-82752 (Improper Validation of Specified Quantity in Input 
vulnerability in as ...)
+       TODO: check
+CVE-2026-81543 (The Abandoned Cart Pro for WooCommerce plugin for WordPress is 
vulnera ...)
+       TODO: check
+CVE-2026-76573 (The Pods \u2013 Custom Content Types and Fields plugin for 
WordPress i ...)
+       TODO: check
+CVE-2026-75586 (The Unlimited Elements For Elementor plugin for WordPress is 
vulnerabl ...)
+       TODO: check
+CVE-2026-75018 (The Custom Contact Forms plugin for WordPress is vulnerable to 
authori ...)
+       TODO: check
+CVE-2026-6554 (libpcap BPF interpreter treats the offset in the 'ja L' BPF 
instructio ...)
+       TODO: check
+CVE-2026-6244 (libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU 
instructions ...)
+       TODO: check
+CVE-2026-31912 (libpcap BPF interpreter detects neither reaching the end of 
the filter ...)
+       TODO: check
+CVE-2026-31911 (libpcap BPF interpreter calls abort() if it encounters a BPF 
instructi ...)
+       TODO: check
+CVE-2026-18313 (rpcapd can allocate up to 65536 bytes per each 
RPCAP_MSG_UPDATEFILTER_ ...)
+       TODO: check
+CVE-2026-18238 (The rpcap client code that processes a RPCAP_MSG_PACKET 
message receiv ...)
+       TODO: check
+CVE-2026-15550 (The Ninja Forms - Save Progress plugin for WordPress is 
vulnerable to  ...)
+       TODO: check
+CVE-2026-12843 (The LearnDash LMS plugin for WordPress is vulnerable to 
authorization  ...)
+       TODO: check
+CVE-2026-10196 (The Mail Mint \u2013 Email Marketing, Newsletter, Email 
Automation & W ...)
+       TODO: check
+CVE-2026-0799 (In BPF instructions that load/store a value from/to a scratch 
memory r ...)
+       TODO: check
+CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress 
is vuln ...)
+       TODO: check
+CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability 
in the o ...)
+       TODO: check
+CVE-2025-15614 (ugrep before 7.6.0 contains a heap buffer over-read 
vulnerability in t ...)
+       TODO: check
+CVE-2024-11080 (The Post Grid and Gutenberg Blocks \u2013 ComboBlocks plugin 
for WordP ...)
+       TODO: check
 CVE-2026-49275 [GHSA-hxph-pv7w-8649: Out of bounds read in CrwMap::decodeBasic]
        - exiv2 0.28.9+dfsg-1
        NOTE: 
https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649
@@ -140,7 +252,7 @@ CVE-2026-85667 (xiaobei through 5.5.2 fails to implement 
authentication or signa
        NOT-FOR-US: xiaobei
 CVE-2026-85666 (OGX (formerly Llama Stack, affected at commit fbe8e0f) 
contains an una ...)
        NOT-FOR-US: OGX
-CVE-2026-85665 (Bruno versions through 3.4.2 fail to validate file paths in 
request bo ...)
+CVE-2026-85665 (Bruno versions through 4.1.0 fail to validate file paths in 
request bo ...)
        NOT-FOR-US: Bruno
 CVE-2026-85664 (Chroma 1.5.9 fails to validate maximum bounds on HNSW index 
parameters ...)
        NOT-FOR-US: Chroma
@@ -216,7 +328,7 @@ CVE-2026-85606 (firecrawl-mcp-server 3.20.2 contains an 
arbitrary local file rea
        NOT-FOR-US: firecrawl-mcp-server
 CVE-2026-85605 (Slink before 1.12.3 fails to properly authorize access to 
image commen ...)
        NOT-FOR-US: Slink
-CVE-2026-85604 (Grav before 2.0.19 (affected versions <= 2.0.17) contains a 
remote cod ...)
+CVE-2026-85604 (Grav before 2.0.18 (affected versions <= 2.0.17) contains a 
remote cod ...)
        NOT-FOR-US: Grav CMS
 CVE-2026-85603 (Grav versions before 1.10.55 contain a path traversal 
vulnerability in ...)
        NOT-FOR-US: Grav CMS
@@ -230,11 +342,11 @@ CVE-2026-85599 (Grav Shortcode Core before 6.2.5 contains 
stored cross-site scri
        NOT-FOR-US: Grav plugin
 CVE-2026-85598 (Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS 
detecti ...)
        NOT-FOR-US: Grav CMS
-CVE-2026-85597 (Traefik before v2.11.55 contains a TLS option conflict 
resolution vuln ...)
+CVE-2026-85597 (Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a 
TLS optio ...)
        - traefik <itp> (bug #983289)
 CVE-2026-85596 (Traefik versions >= v3.7.0 and <= v3.7.10 contain an 
authentication by ...)
        - traefik <itp> (bug #983289)
-CVE-2026-85595 (Traefik versions before v2.11.55 contain an authentication 
bypass vuln ...)
+CVE-2026-85595 (Traefik versions before v2.11.55 and versions v3.0.0 through 
v3.7.10 c ...)
        - traefik <itp> (bug #983289)
 CVE-2026-85594 (Traefik versions from v3.7.1 fail to enforce 
crossProviderNamespaces r ...)
        - traefik <itp> (bug #983289)
@@ -5511,7 +5623,8 @@ CVE-2026-XXXX [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds 
write in pcre2_pattern_
        [bookworm] - pcre2 10.42-1+deb12u1
        NOTE: 
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
        NOTE: Fixed by: 
https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3
 (pcre2-10.48-RC1)
-CVE-2026-86145 [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match() 
with recursive patterns under a low heap limit]
+CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds 
write becaus ...)
+       {DLA-4772-1}
        - pcre2 10.48-1
        [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
        NOTE: 
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
@@ -47882,6 +47995,7 @@ CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 
42e33d8, contains a pre-
        NOTE: https://github.com/libssh2/libssh2/pull/2198
        NOTE: Fixed by: 
https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
 CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a 
missing bo ...)
+       {DLA-4773-1}
        - libssh2 1.11.1-5 (bug #1142856)
        [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point 
release)
        NOTE: https://github.com/libssh2/libssh2/pull/2202
@@ -47894,6 +48008,7 @@ CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit 
a2ed82d, contains a pre-
        NOTE: https://github.com/libssh2/libssh2/pull/2401
        NOTE: Fixed by: 
https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
 CVE-2026-66032 (libssh2 through 1.11.1, fixed in commit 5e47761, contains a 
double-fre ...)
+       {DLA-4773-1}
        - libssh2 1.11.1-5 (bug #1142856)
        [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point 
release)
        NOTE: https://github.com/libssh2/libssh2/pull/2180
@@ -71623,12 +71738,14 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails 
to preserve the Mark-of-th
        NOTE: 
https://github.com/bikini/exploitarium/tree/main/7zip-rar5-motw-chain-poc
        NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
 CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with 
SSH2_REALLOC but  ...)
+       {DLA-4773-1}
        - libssh2 1.11.1-6 (bug #1144415)
        [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point 
release)
        NOTE: 
https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
        NOTE: https://github.com/libssh2/libssh2/pull/2127
        NOTE: Fixed by: 
https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
 CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit 
attribute c ...)
+       {DLA-4773-1}
        - libssh2 1.11.1-6 (bug #1144415)
        [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point 
release)
        NOTE: 
https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
@@ -78886,7 +79003,7 @@ CVE-2026-10034 (The WP DSGVO Tools (GDPR) plugin for 
WordPress is vulnerable to
 CVE-2025-7737 (DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual 
Storage Pl ...)
        NOT-FOR-US: Hitachi
 CVE-2025-15661 (libssh2 through 1.11.1, fixed in commit 2dae302, contains an 
out-of-bo ...)
-       {DSA-6365-1}
+       {DSA-6365-1 DLA-4773-1}
        - libssh2 1.11.1-4 (bug #1140401)
        NOTE: https://github.com/libssh2/libssh2/pull/1705
        NOTE: https://github.com/libssh2/libssh2/pull/1717
@@ -112772,7 +112889,7 @@ CVE-2026-7600 (A flaw has been found in ArtMin96 
yii2-mcp-server 1.0.2. This imp
 CVE-2026-7599 (A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This 
affects  ...)
        NOT-FOR-US: Dayoooun hwpx-mcp
 CVE-2026-7598 (A security vulnerability has been detected in libssh2 up to 
1.11.1. Th ...)
-       {DSA-6365-1}
+       {DSA-6365-1 DLA-4773-1}
        - libssh2 1.11.1-3 (bug #1135647)
        [bullseye] - libssh2 <postponed> (Minor issue, unlikely user/pass 
length)
        NOTE: https://github.com/libssh2/libssh2/pull/1858



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3cd012e71a97c34fb525a317a275c0616b3810f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3cd012e71a97c34fb525a317a275c0616b3810f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to