[Git][security-tracker-team/security-tracker][master] 2 commits: add one tag
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Apr 6 13:31:39 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6ca7d808 by Moritz Muehlenhoff at 2026-04-06T12:39:43+02:00
add one tag
- - - - -
9246c941 by Moritz Muehlenhoff at 2026-04-06T14:30:59+02:00
python updates
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -27924,7 +27924,7 @@ CVE-2026-25547 (@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of b
- node-brace-expansion <unfixed> (bug #1127313)
[bullseye] - node-brace-expansion <postponed> (minor issue; DoS)
NOTE: https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2
- NOTE: Fixed by: https://github.com/isaacs/brace-expansion/commit/59d12f1e23accdec8c395ca824cf942c1fdea860
+ NOTE: Fixed by: https://github.com/isaacs/brace-expansion/commit/59d12f1e23accdec8c395ca824cf942c1fdea860 (v5.0.1)
CVE-2026-25546 (Godot MCP is a Model Context Protocol (MCP) server for interacting wit ...)
NOT-FOR-US: Godot MCP
CVE-2026-25543 (HtmlSanitizer is a .NET library for cleaning HTML fragments and docume ...)
@@ -32384,7 +32384,7 @@ CVE-2026-1299 (The email module, specifically the "BytesGenerator" class, didn\
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/6ZZULGALJTITEAGEXLDJE2C6FORDXPBT/
NOTE: https://github.com/python/cpython/commit/052e55e7d44718fe46cbba0ca995cb8fcc359413 (main)
NOTE: https://github.com/python/cpython/commit/7877fe424415bc4a13045e62a90a7277413d8cb9 (3.14 branch)
- NOTE: https://github.com/python/cpython/commit/0a925ab591c45d6638f37b5e57796f36fa0e56d8 (3.13 branch)
+ NOTE: https://github.com/python/cpython/commit/0a925ab591c45d6638f37b5e57796f36fa0e56d8 (v3.13.12)
NOTE: https://github.com/python/cpython/commit/842ce19a0c0b58d61591e8f6a708c38db1fb94e4 (3.11 branch)
CVE-2026-0994 (A denial-of-service (DoS) vulnerability exists in google.protobuf.json ...)
[experimental] - protobuf 3.25.7-1
@@ -34326,6 +34326,7 @@ CVE-2025-15367 (The poplib module, when passed a user-controlled command, can ha
- python3.11 <removed>
[bookworm] - python3.11 <ignored> (Not backported to older Python releases due to compat concerns)
- python3.9 <removed>
+ [bullseye] - python3.9 <ignored> (Not backported to older Python releases due to compat concerns)
- pypy3 <unfixed>
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <no-dsa> (Minor issue)
@@ -34349,6 +34350,7 @@ CVE-2025-15366 (The imaplib module, when passed a user-controlled command, can h
- python3.11 <removed>
[bookworm] - python3.11 <ignored> (Not backported to older Python releases due to compat concerns)
- python3.9 <removed>
+ [bullseye] - python3.9 <ignored> (Not backported to older Python releases due to compat concerns)
- pypy3 <unfixed>
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <no-dsa> (Minor issue)
@@ -121352,6 +121354,7 @@ CVE-2025-4516 (There is an issue in CPython when using `bytes.decode("unicode_es
NOTE: https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e (main)
NOTE: https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142 (v3.14.0b2)
NOTE: https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d (v3.13.4)
+ NOTE: https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f (v3.11.13)
CVE-2025-48051 (powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some ap ...)
NOT-FOR-US: Lichess Lila
CVE-2025-48050 (In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1fe18697b9fee5e3d5913bb859e0eee024d92a16...9246c941ad70f22a928f89e790036499201d0c1d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1fe18697b9fee5e3d5913bb859e0eee024d92a16...9246c941ad70f22a928f89e790036499201d0c1d
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260406/b7f13107/attachment.htm>
More information about the debian-security-tracker-commits
mailing list