[Git][security-tracker-team/security-tracker][master] Add CVE-2026-54909/pion-stun
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 1 09:11:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
639b67f5 by Salvatore Bonaccorso at 2026-08-01T10:11:34+02:00
Add CVE-2026-54909/pion-stun
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -24,7 +24,11 @@ CVE-2026-62324 (Jodit Editor is a WYSIWYG editor with a built-in file browser &
CVE-2026-55825 (Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an auth ...)
NOT-FOR-US: Contao CMS
CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAdd ...)
- TODO: check
+ - golang-github-pion-stun-v3 <unfixed>
+ - golang-github-pion-stun <unfixed>
+ NOTE: https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc
+ NOTE: https://github.com/pion/stun/pull/278
+ NOTE: Fixed by: https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 (v3.1.3)
CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and verification. Pri ...)
TODO: check
CVE-2026-54785 (gemini-bridge is a lightweight MCP server bridging AI agents to Google ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/639b67f5a8814c66adfa2ec46756c27a59521baa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/639b67f5a8814c66adfa2ec46756c27a59521baa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/c4092e50/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list