Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3266caca by security tracker role at 2026-09-11T07:12:44+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,302 @@
-CVE-2026-88914
+CVE-2026-9768
+       REJECTED
+CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
server- ...)
+       TODO: check
+CVE-2026-9327 (IBM WebSphere Application Server 9.0, and 8.5 could allow an 
authentic ...)
+       TODO: check
+CVE-2026-9225 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an 
authenti ...)
+       TODO: check
+CVE-2026-9176 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
a secur ...)
+       TODO: check
+CVE-2026-8778 (The MIPL Grouped Checkout Fields for WooCommerce \u2013 
Customize & Or ...)
+       TODO: check
+CVE-2026-89169 (live-boot ff8867c allows attackers to bypass the 
dm-verity-enforce-roo ...)
+       TODO: check
+CVE-2026-89162 (In PCRE2 before 10.48, pcre2_serialize_encode might disclose 
two bytes ...)
+       TODO: check
+CVE-2026-89161 (In PCRE2 before 10.48, pcre2_jit_match mishandles a previously 
copied  ...)
+       TODO: check
+CVE-2026-89160 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read during 
the PCR ...)
+       TODO: check
+CVE-2026-89158 (PCRE2 before 10.48, on 32-bit platforms, has a 
pcre2_compile_32 intege ...)
+       TODO: check
+CVE-2026-89157 (PCRE2 before 10.48, on 32-bit platforms, has a 
pcre2_pattern_convert o ...)
+       TODO: check
+CVE-2026-89156 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read after 
a JIT fa ...)
+       TODO: check
+CVE-2026-89151 (Forgejo before 16.0.4 allows use of restricted API tokens for 
unintend ...)
+       TODO: check
+CVE-2026-89145 (Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to 
HTML-escape  ...)
+       TODO: check
+CVE-2026-89094 (Forgejo before 16.0.4 allows remote code execution via a 
crafted templ ...)
+       TODO: check
+CVE-2026-89089 (A SQL injection vulnerability exists in the 
JasperReports-based report ...)
+       TODO: check
+CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
+       TODO: check
+CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to 
validate ...)
+       TODO: check
+CVE-2026-89060 (A flaw was found in multicluster-observability-addon. This 
vulnerabili ...)
+       TODO: check
+CVE-2026-89054 (A missing authorization vulnerability in OpenNMS Horizon 
allows config ...)
+       TODO: check
+CVE-2026-88260 (Authentication bypass using an alternate path or channel and 
Improper  ...)
+       TODO: check
+CVE-2026-88062 (OmniRoute is an open-source AI gateway providing a single 
endpoint for ...)
+       TODO: check
+CVE-2026-88061 (career-ops is an open-source AI-assisted job search and 
application ma ...)
+       TODO: check
+CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is 
vulnerable ...)
+       TODO: check
+CVE-2026-87908 (multiparty is a Node.js library for parsing 
multipart/form-data reques ...)
+       TODO: check
+CVE-2026-86815 (The BackWPup  WordPress plugin before 5.7.5 does not properly 
restrict ...)
+       TODO: check
+CVE-2026-86812 (The WPCafe  WordPress plugin before 3.0.18 does not correctly 
restrict ...)
+       TODO: check
+CVE-2026-86782 (The Visualizer  WordPress plugin before 4.0.6 does not 
properly author ...)
+       TODO: check
+CVE-2026-86781 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects 
WordPre ...)
+       TODO: check
+CVE-2026-86780 (The Featured Image with URL WordPress plugin before 1.0.6 does 
not san ...)
+       TODO: check
+CVE-2026-86779 (The Visualizer  WordPress plugin before 4.0.6 does not 
properly author ...)
+       TODO: check
+CVE-2026-86093 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could 
allow a ...)
+       TODO: check
+CVE-2026-86087 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could 
allow a ...)
+       TODO: check
+CVE-2026-85678 (The AI Builder  WordPress plugin before 2.7.8 does not 
sanitise custom ...)
+       TODO: check
+CVE-2026-85677 (The Gutenverse News  WordPress plugin before 3.3.3 does not 
restrict t ...)
+       TODO: check
+CVE-2026-85025 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an 
unauthen ...)
+       TODO: check
+CVE-2026-84960 (The WP-Members Membership Plugin plugin for WordPress is 
vulnerable to ...)
+       TODO: check
+CVE-2026-84941 (An information disclosure vulnerability in the SAML Single 
Sign-On (SS ...)
+       TODO: check
+CVE-2026-84889 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-84432 (Concrete CMS 9 through  9.5.2 did not validate an anti-CSRF 
token in t ...)
+       TODO: check
+CVE-2026-83546 (The CoolClock WordPress plugin before 4.3.8 does not properly 
escape a ...)
+       TODO: check
+CVE-2026-83545 (The CoolClock WordPress plugin before 4.3.8 does not properly 
escape a ...)
+       TODO: check
+CVE-2026-82305 (The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 
does not  ...)
+       TODO: check
+CVE-2026-82107 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-82100 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-82099 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-82098 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-82097 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-82095 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-82092 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-81941 (IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated 
non-admi ...)
+       TODO: check
+CVE-2026-81940 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-81906 (Concrete CMS OAuth callback login path prior to version 9.5.3 
did not  ...)
+       TODO: check
+CVE-2026-81905 (Concrete CMS below 9.5.3 stores user validation hashes for 
multiple pu ...)
+       TODO: check
+CVE-2026-81825 (The Simple Ajax Chat \u2013 Add a Fast, Secure Chat Box plugin 
for Wor ...)
+       TODO: check
+CVE-2026-81754 (The Vigilant \u2013 100% Free Security Suite: Firewall, 2FA, 
Login, He ...)
+       TODO: check
+CVE-2026-81554 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-81551 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-81550 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-81540 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-81268 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-81265 (IBM Langflow OSS 1.0.0 through 1.11.5.)
+       TODO: check
+CVE-2026-81213 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
attacker to ...)
+       TODO: check
+CVE-2026-81211 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-81210 (IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three 
caller- ...)
+       TODO: check
+CVE-2026-81207 (IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any 
authenticated t ...)
+       TODO: check
+CVE-2026-81204 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
attacker to ...)
+       TODO: check
+CVE-2026-80436 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-80434 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-80424 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-80380 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote attac ...)
+       TODO: check
+CVE-2026-80378 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
+       TODO: check
+CVE-2026-7438 (The Bold Timeline Lite plugin for WordPress is vulnerable to 
Stored Cr ...)
+       TODO: check
+CVE-2026-79742 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-79725 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-79724 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
attacker to ...)
+       TODO: check
+CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-79592 (An out-of-bounds read vulnerability exists in the 
xls_dumpSummary() fu ...)
+       TODO: check
+CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists 
in the  ...)
+       TODO: check
+CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism 
parser co ...)
+       TODO: check
+CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-78573 (IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a 
remote  ...)
+       TODO: check
+CVE-2026-78571 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
+       TODO: check
+CVE-2026-78569 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow an 
authenticated att ...)
+       TODO: check
+CVE-2026-78172 (The Themify \u2013 WooCommerce Product Filter plugin for 
WordPress is  ...)
+       TODO: check
+CVE-2026-77807 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and 
Marketing Auto ...)
+       TODO: check
+CVE-2026-77150 (The Unlimited Elements For Elementor plugin for WordPress is 
vulnerabl ...)
+       TODO: check
+CVE-2026-76653 (A missing authentication vulnerability in the VPN 
configuration manage ...)
+       TODO: check
+CVE-2026-76652 (An authenticated directory traversal vulnerability in file 
upload func ...)
+       TODO: check
+CVE-2026-76059 (IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could 
submit cus ...)
+       TODO: check
+CVE-2026-75940 (A vulnerability was reported in Lenovo Health Android 
Application, dis ...)
+       TODO: check
+CVE-2026-75777 (IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow 
a local  ...)
+       TODO: check
+CVE-2026-75624 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
+       TODO: check
+CVE-2026-74925 (The MultiVendorX  WordPress plugin before 5.0.16 does not 
restrict who ...)
+       TODO: check
+CVE-2026-73785 (A potential security vulnerability in HPE IceWall Federation 
Agent and ...)
+       TODO: check
+CVE-2026-73784 (A potential security vulnerability in HPE IceWall products 
could be ex ...)
+       TODO: check
+CVE-2026-71647 (An issue in EGO-Planner-v2 All versions up to commit 
5c99a95880401e259 ...)
+       TODO: check
+CVE-2026-71645 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested 
affected  ...)
+       TODO: check
+CVE-2026-71643 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to 
commit 5c99 ...)
+       TODO: check
+CVE-2026-71642 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to 
commit 5c99 ...)
+       TODO: check
+CVE-2026-71640 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to 
commit 5c99 ...)
+       TODO: check
+CVE-2026-63427 (An authentication bypass vulnerability was discovered in 
Lenovo Softwa ...)
+       TODO: check
+CVE-2026-57844
+       REJECTED
+CVE-2026-54054 (Transmute is a free, open-source, self-hosted file conversion 
and comp ...)
+       TODO: check
+CVE-2026-49836 (psd-tools is a Python package for working with Adobe Photoshop 
PSD fil ...)
+       TODO: check
+CVE-2026-45770 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45769 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45768 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45767 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45766 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45765 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45764 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45762 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45761 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45759 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45752 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45751 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-3096 (The product's web portals allow external links to be opened in 
a new b ...)
+       TODO: check
+CVE-2026-36392 (FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site 
Scriptin ...)
+       TODO: check
+CVE-2026-2310 (IBM webMethods Integration Server 11.1 IBM webMethods 
Integration is v ...)
+       TODO: check
+CVE-2026-19991 (The UsersWP plugin for WordPress is vulnerable to Arbitrary 
File Delet ...)
+       TODO: check
+CVE-2026-19985 (The Relevanssi \u2013 A Better Search plugin for WordPress is 
vulnerab ...)
+       TODO: check
+CVE-2026-19646 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, 
ART 9.0, ...)
+       TODO: check
+CVE-2026-19596 (An XML External Entity (XXE) vulnerability exists in the XML 
collector ...)
+       TODO: check
+CVE-2026-19136 (A potential command injection vulnerability was reported in 
the Tianxi ...)
+       TODO: check
+CVE-2026-18994 (A potential improper authorization vulnerability was reported 
in the L ...)
+       TODO: check
+CVE-2026-18964 (The Floating Chat Widget: Contact Chat Icons, Telegram Chat, 
Line Mess ...)
+       TODO: check
+CVE-2026-18579 (The WP Photo Album Plus plugin for WordPress is vulnerable to 
Stored C ...)
+       TODO: check
+CVE-2026-18562 (The HUSKY \u2013 Products Filter Professional for WooCommerce 
plugin f ...)
+       TODO: check
+CVE-2026-18561 (The Unlimited Elements For Elementor plugin for WordPress is 
vulnerabl ...)
+       TODO: check
+CVE-2026-18121 (Concrete CMS 9.5.2 and below is vulnerable to an authorization 
bypass  ...)
+       TODO: check
+CVE-2026-17176 (An OS command injection vulnerability in the TDDP module of 
Deco BE110 ...)
+       TODO: check
+CVE-2026-16174 (Netskope was notified about a potential gap in Netskope 
Endpoint DLP ( ...)
+       TODO: check
+CVE-2026-16172 (Netskope was notified of an out-of-bounds heap read affecting 
the Endp ...)
+       TODO: check
+CVE-2026-15462 (The Sticky Chat Widget plugin for WordPress is vulnerable to 
SQL Injec ...)
+       TODO: check
+CVE-2026-14566 (The advanced-customized-prompts WordPress plugin through 1.0.1 
does no ...)
+       TODO: check
+CVE-2026-14565 (The advanced-customized-prompts WordPress plugin through 1.0.1 
does no ...)
+       TODO: check
+CVE-2026-14563 (The advanced-customized-prompts WordPress plugin through 1.0.1 
does no ...)
+       TODO: check
+CVE-2026-14562 (The teddy-bear-customize-addon WordPress plugin through 1.0.5 
does not ...)
+       TODO: check
+CVE-2026-14560 (The teddy-bear-customize-addon WordPress plugin through 1.0.5 
does not ...)
+       TODO: check
+CVE-2026-14559 (The teddy-bear-customize-addon WordPress plugin through 1.0.5 
does not ...)
+       TODO: check
+CVE-2026-13326 (An out-of-bounds read in Qt NFC's language code length parsing 
allows  ...)
+       TODO: check
+CVE-2026-12215 (The OTP Login & Register Woocommerce plugin for WordPress is 
vulnerabl ...)
+       TODO: check
+CVE-2026-11813 (A potential improper permissions vulnerability was reported in 
the Len ...)
+       TODO: check
+CVE-2026-11496 (The Woo PDF Invoice Builder plugin (also distributed as "PDF 
Builder f ...)
+       TODO: check
+CVE-2026-11446 (The Booktics \u2013 Booking Calendar for Appointments and 
Service Busi ...)
+       TODO: check
+CVE-2025-57231 (Path Traversal in avatar attachments in Docmost v0.21.0 allows 
an unau ...)
+       TODO: check
+CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin 
before 3.0.10 ...)
+       TODO: check
+CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4 
plugin. When p ...)
        - gst-plugins-good1.0 1.28.7-1
        NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0079.html
        NOTE: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5235
@@ -6,9 +304,9 @@ CVE-2026-88914
        NOTE: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12437
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a2a14d1b23d4a74d388f43745f000ea4999bf1d3
 (1.28.7)
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/c297f67b20d6284e58ebb2bcd61a1a3ffa0eedab
 (1.28.7)
-CVE-2026-89011
+CVE-2026-89011 (isomorphic-git before 1.42.0 contains a prototype pollution 
vulnerabil ...)
        NOT-FOR-US: isomorphic-git
-CVE-2026-89092 [Stack overflow in nscd due to unbounded alloca use]
+CVE-2026-89092 (The nscd service in the GNU C Library 2.3.4 onwards may crash 
due to a ...)
        - glibc <unfixed>
        NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34624
        NOTE: 
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016
@@ -5768,58 +6066,58 @@ CVE-2026-78254 (The ftp and scp tasks of Apache Ant can 
download files from a re
        NOTE: 
https://github.com/apache/ant/commit/07ee9c418e3bd3e7d0287fc9aaba3011e88f0dc2 
(ANT_1.10.18_RC1)
        NOTE: 
https://github.com/apache/ant/commit/9252566cab812c59a5695679ba11f497e85aabb0 
(ANT_1.10.18_RC1)
        NOTE: 
https://github.com/apache/ant/commit/3807d672ea18d9f8dafd5eb9b2fe1de05f664539 
(ANT_1.10.18_RC1)
-CVE-2026-78123
+CVE-2026-78123 (strongSwan 5.0.2 through 6.0.7 has an Expired Pointer 
Dereference in P ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78123
-CVE-2026-78124
+CVE-2026-78124 (strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate 
enumeration i ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78124
-CVE-2026-78126
+CVE-2026-78126 (strongSwan 4.1.10 through 6.0.7 allows a NULL pointer 
dereference in t ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78126).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78126
-CVE-2026-78127
+CVE-2026-78127 (libcharon in strongSwan 4.1.2 through 6.0.7 has a missing 
release of m ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78127).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78127
-CVE-2026-78129
+CVE-2026-78129 (strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 
decrypti ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78129).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78129/
-CVE-2026-78130
+CVE-2026-78130 (strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference 
in the x ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78130).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78130
-CVE-2026-78131
+CVE-2026-78131 (strongSwan 4.2.0 through 6.0.7 has a missing release of memory 
after i ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78131).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78131
-CVE-2026-78132
+CVE-2026-78132 (strongSwan 5.1.3 through 6.0.7 has an infinite loop in the 
x509 plugin ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78132).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78132
-CVE-2026-78133
+CVE-2026-78133 (libcharon in strongSwan 6.0.0 through 6.0.7 has a 
use-after-free in IK ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        [bookworm] - strongswan <not-affected> (Vulnerable code introduced 
later)
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78133).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78133/
-CVE-2026-78134
+CVE-2026-78134 (strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in 
the eap ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html
        NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78134/
-CVE-2026-78135
+CVE-2026-78135 (libcharon in strongSwan 5.9.7 through 6.0.7 mishandles 
behavioral work ...)
        {DSA-6487-1}
        - strongswan 6.1.0-1
        NOTE: 
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html
@@ -22304,31 +22602,37 @@ CVE-2026-63481 (Hurl is a command line tool that runs 
and tests HTTP requests de
        NOTE: https://github.com/Orange-OpenSource/hurl/pull/5119
        NOTE: Fixed by: 
https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e
 CVE-2026-63388 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72
 (release-2.1.13-stable)
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9
 (release-2.2.2-alpha)
 CVE-2026-63387 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/377b9022c3ac61aa4540b5dc4b70c60bf74c663d
 (release-2.1.13-stable)
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/9877a7205ea024d0120effb040e1b8e034435407
 (release-2.2.2-alpha)
 CVE-2026-63385 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2
 (release-2.1.13-stable)
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0
 (release-2.2.2-alpha)
 CVE-2026-63384 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416
 (release-2.1.13-stable)
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda
 (release-2.2.2-alpha)
 CVE-2026-63383 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb
 (release-2.1.13-stable)
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321
 (release-2.2.2-alpha)
 CVE-2026-63382 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6
 (release-2.1.13-stable)
@@ -22336,6 +22640,7 @@ CVE-2026-63382 (Libevent is an event notification 
library. Prior to 2.1.13 and 2
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e
 (release-2.2.2-alpha)
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660
 (release-2.2.2-alpha)
 CVE-2026-63381 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c
 (release-2.1.13-stable)
@@ -22345,6 +22650,7 @@ CVE-2026-63380 (Libevent is an event notification 
library. Prior to 2.2.2-alpha,
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/825c18bd99f556b59d61200523237f264d5cc734
 (release-2.2.2-alpha)
 CVE-2026-63379 (Libevent is an event notification library. Prior to 2.1.13 and 
2.2.2-a ...)
+       {DSA-6493-1}
        - libevent 2.1.13-stable-1
        NOTE: 
https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6
        NOTE: Fixed by: 
https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636
 (release-2.1.13-stable)
@@ -73479,7 +73785,7 @@ CVE-2026-12996 (A use-after-free in OpenVPN 2.6.0 
through 2.6.20 and 2.7_alpha1
        [bullseye] - openvpn 2.5.1-3+deb11u4
        NOTE: Fixed by: 
https://github.com/OpenVPN/openvpn/commit/5ee1f9b90fe03ecf7cef5431147ecaabbe96db9e
 (v2.7.5)
        NOTE: The issue is caused by the patch for CVE-2026-40215. Bullseye's 
version contains the fix for both.
-CVE-2026-49838
+CVE-2026-49838 (GoBGP is an open source Border Gateway Protocol (BGP) 
implementation i ...)
        - gobgp 4.7.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
        [bookworm] - gobgp <postponed> (Minor issue, DoS via empty AS_PATH in 
confed eBGP validation)
@@ -96152,7 +96458,7 @@ CVE-2026-50593 (Graphite before 1.3.15 has an integer 
underflow and resultant ou
        [bookworm] - graphite2 1.3.14-1+deb12u1
        [bullseye] - graphite2 <postponed> (Minor issue)
        NOTE: Fixed by: 
https://github.com/silnrsi/graphite/commit/ad78c6b7319909e1540c1b134e115ced03417866
 (1.3.15)
-CVE-2026-49837
+CVE-2026-49837 (GoBGP is an open source Border Gateway Protocol (BGP) 
implementation i ...)
        - gobgp 4.6.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
        [bookworm] - gobgp <postponed> (Minor issue, OPEN capability length 
under-enforcement)
@@ -136261,6 +136567,7 @@ CVE-2026-34876 (An issue was discovered in Mbed TLS 
3.x before 3.6.6. An out-of-
        [bullseye] - mbedtls <not-affected> (Vulnerable code not present)
        NOTE: 
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ccm-finish-boundary-check/
 CVE-2026-34835 (Rack is a modular Ruby web server interface. From versions 
3.0.0.beta1 ...)
+       {DSA-6492-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        [bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136269,7 +136576,7 @@ CVE-2026-34835 (Rack is a modular Ruby web server 
interface. From versions 3.0.0
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/224662608dad63b31ba138d7e76e4ca8e42e9fc6 
(v3.2.6)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/c49558af795b4c1978d16db071c8344db05a2b0d 
(v3.1.21)
 CVE-2026-34831 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-q2ww-5357-x388
@@ -136277,7 +136584,7 @@ CVE-2026-34831 (Rack is a modular Ruby web server 
interface. Prior to versions 2
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/c3645d377f0335a779812bf3f36e238d87d9b4e6 
(v3.1.21)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/a75847314e8ad847a5b66e7215381c4ed51f6aa7 
(v2.2.23)
 CVE-2026-34830 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-qv7j-4883-hwh7
@@ -136285,7 +136592,7 @@ CVE-2026-34830 (Rack is a modular Ruby web server 
interface. Prior to versions 2
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/59a0966a484f2903833fa3e4c81919d3c645738d 
(v3.1.21)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/7f288de93768b5cc44a5f4ed1ac02470d8fe52f4 
(v2.2.23)
 CVE-2026-34829 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-8vqr-qjwx-82mw
@@ -136295,6 +136602,7 @@ CVE-2026-34829 (Rack is a modular Ruby web server 
interface. Prior to versions 2
 CVE-2026-34828 (listmonk is a standalone, self-hosted, newsletter and mailing 
list man ...)
        NOT-FOR-US: listmonk
 CVE-2026-34827 (Rack is a modular Ruby web server interface. From versions 
3.0.0.beta1 ...)
+       {DSA-6492-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        [bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136303,7 +136611,7 @@ CVE-2026-34827 (Rack is a modular Ruby web server 
interface. From versions 3.0.0
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/bfb69142dbe2a1e3298ad52d12935938d1b58205 
(v3.2.6)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/17ce7836be1523a7b453f3c06fe070ad7c954708 
(v3.1.21)
 CVE-2026-34826 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-x8cg-fq8g-mxfx
@@ -136379,7 +136687,7 @@ CVE-2026-34791 (Endian Firewall version 3.3.25 and 
prior allow authenticated use
 CVE-2026-34790 (Endian Firewall version 3.3.25 and prior allow authenticated 
users to  ...)
        NOT-FOR-US: Endian Firewall
 CVE-2026-34786 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-q4qf-9j86-f5mh
@@ -136387,7 +136695,7 @@ CVE-2026-34786 (Rack is a modular Ruby web server 
interface. Prior to versions 2
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/84937c38065d0a7630828fdd526201c5241a9619 
(v3.1.21)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/4207d22e58a41d57a2c6e1ed2602170504b000c7 
(v2.2.23)
 CVE-2026-34785 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-h2jq-g4cq-5ppq
@@ -136395,7 +136703,7 @@ CVE-2026-34785 (Rack is a modular Ruby web server 
interface. Prior to versions 2
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/a17cb99b3440a4db09fb920407adf5ead127704c 
(v3.1.21)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/203730e4abb2fac3a0514d6dc3ac56de82bdff9a 
(v2.2.23)
 CVE-2026-34763 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-7mqq-6cf9-v2qp
@@ -136478,7 +136786,7 @@ CVE-2026-34426 (OpenClaw versions prior to commit 
b57b680contain an approval byp
 CVE-2026-34425 (OpenClaw versions prior to commit 8aceaf5 contain a preflight 
validati ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-34230 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-v569-hp3g-36wr
@@ -136534,6 +136842,7 @@ CVE-2026-33271 (Local privilege escalation due to 
insecure folder permissions. T
 CVE-2026-32871 (FastMCP is a Pythonic way to build MCP servers and clients. 
Prior to v ...)
        NOT-FOR-US: FastMCP
 CVE-2026-32762 (Rack is a modular Ruby web server interface. From versions 
3.0.0.beta1 ...)
+       {DSA-6492-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        [bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136641,6 +136950,7 @@ CVE-2026-28728 (Local privilege escalation due to DLL 
hijacking vulnerability. T
 CVE-2026-27774 (Local privilege escalation due to DLL hijacking vulnerability. 
The fol ...)
        NOT-FOR-US: Acronis
 CVE-2026-26962 (Rack is a modular Ruby web server interface. From version 
3.2.0 to bef ...)
+       {DSA-6492-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        [bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136649,7 +136959,7 @@ CVE-2026-26962 (Rack is a modular Ruby web server 
interface. From version 3.2.0
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/d50c4d3dab62fa80b2a276271d0d4fb338cfa7df 
(v3.2.6)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/ae320b46617e9131c34ad77ea15f1c3b036c43e6 
(v3.1.22)
 CVE-2026-26961 (Rack is a modular Ruby web server interface. Prior to versions 
2.2.23, ...)
-       {DLA-4706-1}
+       {DSA-6492-1 DLA-4706-1}
        [experimental] - ruby-rack 3.2.6-1
        - ruby-rack 3.2.6-2
        NOTE: 
https://github.com/rack/rack/security/advisories/GHSA-vgpv-f759-9wx3
@@ -306288,14 +306598,12 @@ CVE-2024-48943
        NOTE: https://nicmx.github.io/FORT-validator/CVE.html
        NOTE: 
https://github.com/NICMx/FORT-validator/commit/4ee88d1c3fa7df763dd52312134cd93c1ce50870
 (1.6.4)
 CVE-2024-56170 (A validation integrity issue was discovered in Fort through 
1.6.4 befo ...)
-       {DSA-6490-1}
        - fort-validator <unfixed> (bug #1090916)
        [trixie] - fort-validator <postponed> (Minor issue, revisit when fixed 
upstream)
        [bookworm] - fort-validator <postponed> (Minor issue, revisit when 
fixed upstream)
        [bullseye] - fort-validator <postponed> (Minor issue, wait until it's 
fixed upstream)
        NOTE: https://github.com/NICMx/FORT-validator/issues/82
 CVE-2024-56169 (A validation integrity issue was discovered in Fort through 
1.6.4 befo ...)
-       {DSA-6490-1}
        - fort-validator <unfixed> (bug #1090916)
        [trixie] - fort-validator <postponed> (Minor issue, revisit when fixed 
upstream)
        [bookworm] - fort-validator <postponed> (Minor issue, revisit when 
fixed upstream)
@@ -533640,8 +533948,8 @@ CVE-2022-26964 (Weak password derivation for export 
in Devolutions Remote Deskto
        NOT-FOR-US: Devolutions Remote Desktop Manager
 CVE-2022-26963
        RESERVED
-CVE-2022-26962
-       RESERVED
+CVE-2022-26962 (Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under 
NP_BCCAS- ...)
+       TODO: check
 CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS 
under NP_ ...)
        NOT-FOR-US: Italtel NetMatch-S
 CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is 
affected by  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3266cacadf9f78f5842555c6e04bf13a0b6e4cf4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3266cacadf9f78f5842555c6e04bf13a0b6e4cf4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to