[Git][security-tracker-team/security-tracker][master] Reference upstream commits for nbconvert issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Apr 25 12:33:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5f26a3ec by Salvatore Bonaccorso at 2026-04-25T13:32:39+02:00
Reference upstream commits for nbconvert issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3219,9 +3219,11 @@ CVE-2026-39386 (Neko is a a self-hosted virtual browser that runs in Docker and
 CVE-2026-39378 (The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to v ...)
 	- nbconvert <unfixed>
 	NOTE: https://github.com/jupyter/nbconvert/security/advisories/GHSA-7jqv-fw35-gmx9
+	NOTE: Fixed by: https://github.com/jupyter/nbconvert/commit/0e6b8ccabf2aca6c18fac8c574f22b7155f441fb (v7.17.1)
 CVE-2026-39377 (The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to v ...)
 	- nbconvert <unfixed>
 	NOTE: https://github.com/jupyter/nbconvert/security/advisories/GHSA-4c99-qj7h-p3vg
+	NOTE: Fixed by: https://github.com/jupyter/nbconvert/commit/ba5e5cdd737704388251fa55fa9e58f5752fa39d (v7.17.1)
 CVE-2026-39320 (Signal K Server is a server application that runs on a central hub in  ...)
 	NOT-FOR-US: Signal K Server
 CVE-2026-38835 (Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection v ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f26a3ec068fbdf8574fa2e07297a972c6f64c8a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f26a3ec068fbdf8574fa2e07297a972c6f64c8a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260425/4c828fca/attachment.htm>


More information about the debian-security-tracker-commits mailing list