[Git][security-tracker-team/security-tracker][master] Add new issues in onnx

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Apr 2 07:19:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b612ed5f by Salvatore Bonaccorso at 2026-04-02T08:19:29+02:00
Add new issues in onnx

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -76,11 +76,16 @@ CVE-2026-34603 (Tina is a headless content management system. Prior to version 2
 CVE-2026-34510 (OpenClaw before 2026.3.22 contains a path traversal vulnerability in W ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-34447 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
-	TODO: check
+	- onnx <unfixed>
+	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-p433-9wv8-28xj
 CVE-2026-34446 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
-	TODO: check
+	- onnx <unfixed>
+	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-cmw6-hcpp-c6jp
+	NOTE: Fixed by: https://github.com/onnx/onnx/commit/4755f8053928dce18a61db8fec71b69c74f786cb
 CVE-2026-34445 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
-	TODO: check
+	- onnx <unfixed>
+	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-538c-55jv-c5g9
+	NOTE: https://github.com/onnx/onnx/pull/7751
 CVE-2026-34430 (ByteDance Deer-Flow versions prior to commit 92c7a20 containa sandbox  ...)
 	TODO: check
 CVE-2026-34397 (Himmelblau is an interoperability suite for Microsoft Azure Entra ID a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b612ed5f47a377e87c3d21de90f31e18e66a136a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b612ed5f47a377e87c3d21de90f31e18e66a136a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260402/d7964a26/attachment.htm>


More information about the debian-security-tracker-commits mailing list