Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a3cd012e by security tracker role at 2026-09-05T19:14:24+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,115 @@
+CVE-2026-86197 (Grav before 2.0.20 contains a cross-site scripting
vulnerability in th ...)
+ TODO: check
+CVE-2026-86196 (Grav API plugin versions before 1.0.20 build password reset
links from ...)
+ TODO: check
+CVE-2026-86195 (grav-plugin-api versions before 1.0.20 contain a privilege
escalation ...)
+ TODO: check
+CVE-2026-86194 (Grav Form Plugin before 9.1.22 fails to verify page
authorization when ...)
+ TODO: check
+CVE-2026-86193 (grav-plugin-api before 1.0.20 fails to validate
group-inherited super ...)
+ TODO: check
+CVE-2026-86192 (SiYuan versions before v3.8.2 fail to properly filter private
attribut ...)
+ TODO: check
+CVE-2026-86191 (SiYuan versions before v3.8.2 contain an information
disclosure vulner ...)
+ TODO: check
+CVE-2026-86190 (WWBN AVideo contains a broken access control vulnerability in
videoVie ...)
+ TODO: check
+CVE-2026-86189 (WWBN AVideo contains a path traversal vulnerability in
notify.ffmpeg.j ...)
+ TODO: check
+CVE-2026-86188 (AVideo with YPTSocket plugin enabled contains a cross-site
scripting v ...)
+ TODO: check
+CVE-2026-86187 (WWBN AVideo generates passwords for external-login accounts
using rand ...)
+ TODO: check
+CVE-2026-86186 (AVideo API fails to enforce rate limits when clients send a
bot User-A ...)
+ TODO: check
+CVE-2026-86185 (Bilibili Desktop through 1.18.0 disables TLS certificate
verification ...)
+ TODO: check
+CVE-2026-86184 (Lara Dashboard before 1.3.0 contains an authentication bypass
vulnerab ...)
+ TODO: check
+CVE-2026-86178 (Pixelfed through 0.12.9 fails to validate follower status in
StoryComp ...)
+ TODO: check
+CVE-2026-86177 (Pterodactyl Panel before 1.14.1 fails to validate
action-specific perm ...)
+ TODO: check
+CVE-2026-86176 (NetBox through 4.7.0 fails to properly scope user-private
records in R ...)
+ TODO: check
+CVE-2026-86175 (NetBox through 4.7.0 fails to redact sensitive data source
backend cre ...)
+ TODO: check
+CVE-2026-86174 (Plane through 1.4.2 fails to validate that issues belong to
the deploy ...)
+ TODO: check
+CVE-2026-86173 (MindsDB through 26.1.0 contains a server-side request forgery
vulnerab ...)
+ TODO: check
+CVE-2026-86169 (Axolotl through 0.18.0 contains a remote code execution
vulnerability ...)
+ TODO: check
+CVE-2026-86124 (AutoAgent contains an unauthenticated remote code execution
vulnerabil ...)
+ TODO: check
+CVE-2026-86123 (SQL Chat contains four unauthenticated API endpoints that
accept clien ...)
+ TODO: check
+CVE-2026-86122 (Rowboat through 0.9.1 fails to validate custom MCP server and
webhook ...)
+ TODO: check
+CVE-2026-86121 (Cua computer-server versions before 0.3.42 skip authentication
when th ...)
+ TODO: check
+CVE-2026-86120 (APITable through 1.13.0-beta.1 contains an incorrect
authorization vul ...)
+ TODO: check
+CVE-2026-86119 (Webstudio through 0.296.0 contains an unauthenticated
server-side requ ...)
+ TODO: check
+CVE-2026-86118 (gonic versions before 0.22.0 fail to validate administrator
privileges ...)
+ TODO: check
+CVE-2026-86117 (Coolify through 4.3.17 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-86116 (Metabase versions before 0.63.1 fail to enforce data analyst
permissio ...)
+ TODO: check
+CVE-2026-86115 (Sim before 0.8.14 classifies tool requests as internal based
on URL pr ...)
+ TODO: check
+CVE-2026-86114 (Arcane versions before 2.0.0 fail to properly restrict
template operat ...)
+ TODO: check
+CVE-2026-86113 (BookWyrm through 0.9.1 contains an authorization bypass
vulnerability ...)
+ TODO: check
+CVE-2026-86112 (BookWyrm through 0.9.1 fails to validate user visibility
permissions i ...)
+ TODO: check
+CVE-2026-86111 (BookWyrm through 0.9.1 fails to validate user visibility
permissions i ...)
+ TODO: check
+CVE-2026-85414 (The Gallery : FooGallery plugin for WordPress is vulnerable to
Stored ...)
+ TODO: check
+CVE-2026-83625 (The Contact Form by Supsystic plugin for WordPress is
vulnerable to St ...)
+ TODO: check
+CVE-2026-82752 (Improper Validation of Specified Quantity in Input
vulnerability in as ...)
+ TODO: check
+CVE-2026-81543 (The Abandoned Cart Pro for WooCommerce plugin for WordPress is
vulnera ...)
+ TODO: check
+CVE-2026-76573 (The Pods \u2013 Custom Content Types and Fields plugin for
WordPress i ...)
+ TODO: check
+CVE-2026-75586 (The Unlimited Elements For Elementor plugin for WordPress is
vulnerabl ...)
+ TODO: check
+CVE-2026-75018 (The Custom Contact Forms plugin for WordPress is vulnerable to
authori ...)
+ TODO: check
+CVE-2026-6554 (libpcap BPF interpreter treats the offset in the 'ja L' BPF
instructio ...)
+ TODO: check
+CVE-2026-6244 (libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU
instructions ...)
+ TODO: check
+CVE-2026-31912 (libpcap BPF interpreter detects neither reaching the end of
the filter ...)
+ TODO: check
+CVE-2026-31911 (libpcap BPF interpreter calls abort() if it encounters a BPF
instructi ...)
+ TODO: check
+CVE-2026-18313 (rpcapd can allocate up to 65536 bytes per each
RPCAP_MSG_UPDATEFILTER_ ...)
+ TODO: check
+CVE-2026-18238 (The rpcap client code that processes a RPCAP_MSG_PACKET
message receiv ...)
+ TODO: check
+CVE-2026-15550 (The Ninja Forms - Save Progress plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-12843 (The LearnDash LMS plugin for WordPress is vulnerable to
authorization ...)
+ TODO: check
+CVE-2026-10196 (The Mail Mint \u2013 Email Marketing, Newsletter, Email
Automation & W ...)
+ TODO: check
+CVE-2026-0799 (In BPF instructions that load/store a value from/to a scratch
memory r ...)
+ TODO: check
+CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress
is vuln ...)
+ TODO: check
+CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability
in the o ...)
+ TODO: check
+CVE-2025-15614 (ugrep before 7.6.0 contains a heap buffer over-read
vulnerability in t ...)
+ TODO: check
+CVE-2024-11080 (The Post Grid and Gutenberg Blocks \u2013 ComboBlocks plugin
for WordP ...)
+ TODO: check
CVE-2026-49275 [GHSA-hxph-pv7w-8649: Out of bounds read in CrwMap::decodeBasic]
- exiv2 0.28.9+dfsg-1
NOTE:
https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649
@@ -140,7 +252,7 @@ CVE-2026-85667 (xiaobei through 5.5.2 fails to implement
authentication or signa
NOT-FOR-US: xiaobei
CVE-2026-85666 (OGX (formerly Llama Stack, affected at commit fbe8e0f)
contains an una ...)
NOT-FOR-US: OGX
-CVE-2026-85665 (Bruno versions through 3.4.2 fail to validate file paths in
request bo ...)
+CVE-2026-85665 (Bruno versions through 4.1.0 fail to validate file paths in
request bo ...)
NOT-FOR-US: Bruno
CVE-2026-85664 (Chroma 1.5.9 fails to validate maximum bounds on HNSW index
parameters ...)
NOT-FOR-US: Chroma
@@ -216,7 +328,7 @@ CVE-2026-85606 (firecrawl-mcp-server 3.20.2 contains an
arbitrary local file rea
NOT-FOR-US: firecrawl-mcp-server
CVE-2026-85605 (Slink before 1.12.3 fails to properly authorize access to
image commen ...)
NOT-FOR-US: Slink
-CVE-2026-85604 (Grav before 2.0.19 (affected versions <= 2.0.17) contains a
remote cod ...)
+CVE-2026-85604 (Grav before 2.0.18 (affected versions <= 2.0.17) contains a
remote cod ...)
NOT-FOR-US: Grav CMS
CVE-2026-85603 (Grav versions before 1.10.55 contain a path traversal
vulnerability in ...)
NOT-FOR-US: Grav CMS
@@ -230,11 +342,11 @@ CVE-2026-85599 (Grav Shortcode Core before 6.2.5 contains
stored cross-site scri
NOT-FOR-US: Grav plugin
CVE-2026-85598 (Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS
detecti ...)
NOT-FOR-US: Grav CMS
-CVE-2026-85597 (Traefik before v2.11.55 contains a TLS option conflict
resolution vuln ...)
+CVE-2026-85597 (Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a
TLS optio ...)
- traefik <itp> (bug #983289)
CVE-2026-85596 (Traefik versions >= v3.7.0 and <= v3.7.10 contain an
authentication by ...)
- traefik <itp> (bug #983289)
-CVE-2026-85595 (Traefik versions before v2.11.55 contain an authentication
bypass vuln ...)
+CVE-2026-85595 (Traefik versions before v2.11.55 and versions v3.0.0 through
v3.7.10 c ...)
- traefik <itp> (bug #983289)
CVE-2026-85594 (Traefik versions from v3.7.1 fail to enforce
crossProviderNamespaces r ...)
- traefik <itp> (bug #983289)
@@ -5511,7 +5623,8 @@ CVE-2026-XXXX [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds
write in pcre2_pattern_
[bookworm] - pcre2 10.42-1+deb12u1
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
NOTE: Fixed by:
https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3
(pcre2-10.48-RC1)
-CVE-2026-86145 [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match()
with recursive patterns under a low heap limit]
+CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds
write becaus ...)
+ {DLA-4772-1}
- pcre2 10.48-1
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
@@ -47882,6 +47995,7 @@ CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit
42e33d8, contains a pre-
NOTE: https://github.com/libssh2/libssh2/pull/2198
NOTE: Fixed by:
https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a
missing bo ...)
+ {DLA-4773-1}
- libssh2 1.11.1-5 (bug #1142856)
[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point
release)
NOTE: https://github.com/libssh2/libssh2/pull/2202
@@ -47894,6 +48008,7 @@ CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit
a2ed82d, contains a pre-
NOTE: https://github.com/libssh2/libssh2/pull/2401
NOTE: Fixed by:
https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
CVE-2026-66032 (libssh2 through 1.11.1, fixed in commit 5e47761, contains a
double-fre ...)
+ {DLA-4773-1}
- libssh2 1.11.1-5 (bug #1142856)
[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point
release)
NOTE: https://github.com/libssh2/libssh2/pull/2180
@@ -71623,12 +71738,14 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails
to preserve the Mark-of-th
NOTE:
https://github.com/bikini/exploitarium/tree/main/7zip-rar5-motw-chain-poc
NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with
SSH2_REALLOC but ...)
+ {DLA-4773-1}
- libssh2 1.11.1-6 (bug #1144415)
[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point
release)
NOTE:
https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
NOTE: https://github.com/libssh2/libssh2/pull/2127
NOTE: Fixed by:
https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit
attribute c ...)
+ {DLA-4773-1}
- libssh2 1.11.1-6 (bug #1144415)
[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point
release)
NOTE:
https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
@@ -78886,7 +79003,7 @@ CVE-2026-10034 (The WP DSGVO Tools (GDPR) plugin for
WordPress is vulnerable to
CVE-2025-7737 (DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual
Storage Pl ...)
NOT-FOR-US: Hitachi
CVE-2025-15661 (libssh2 through 1.11.1, fixed in commit 2dae302, contains an
out-of-bo ...)
- {DSA-6365-1}
+ {DSA-6365-1 DLA-4773-1}
- libssh2 1.11.1-4 (bug #1140401)
NOTE: https://github.com/libssh2/libssh2/pull/1705
NOTE: https://github.com/libssh2/libssh2/pull/1717
@@ -112772,7 +112889,7 @@ CVE-2026-7600 (A flaw has been found in ArtMin96
yii2-mcp-server 1.0.2. This imp
CVE-2026-7599 (A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This
affects ...)
NOT-FOR-US: Dayoooun hwpx-mcp
CVE-2026-7598 (A security vulnerability has been detected in libssh2 up to
1.11.1. Th ...)
- {DSA-6365-1}
+ {DSA-6365-1 DLA-4773-1}
- libssh2 1.11.1-3 (bug #1135647)
[bullseye] - libssh2 <postponed> (Minor issue, unlikely user/pass
length)
NOTE: https://github.com/libssh2/libssh2/pull/1858
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3cd012e71a97c34fb525a317a275c0616b3810f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3cd012e71a97c34fb525a317a275c0616b3810f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits