[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-54388

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 1 15:55:58 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f12448b6 by Salvatore Bonaccorso at 2026-08-01T16:55:09+02:00
Update status for CVE-2026-54388

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37612,13 +37612,15 @@ CVE-2026-54445 (vantage6 is an open-source infrastructure for privacy preserving
 	NOT-FOR-US: vantage6
 CVE-2026-54388 (Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject req ...)
 	- tinyproxy <unfixed> (bug #1140350)
-	[trixie] - tinyproxy <no-dsa> (Minor issue)
+	[trixie] - tinyproxy <not-affected> (Vulnerable code introduced later)
 	[bookworm] - tinyproxy <not-affected> (Duplicate header keys are rejected by orderedmap_append()/htab_insert(); duplicate Content-Length emission only exists in the hashmap era (<= 1.10.x) and again since the pseudomap switch in 1.11.3)
 	[bullseye] - tinyproxy <postponed> (Minor issue; hashmap_insert() keeps duplicate Content-Length headers, but the desync needs a shared upstream proxy/cache, no upstream release with the fix)
 	NOTE: https://github.com/tinyproxy/tinyproxy/issues/609
 	NOTE: https://github.com/tinyproxy/tinyproxy/pull/610
 	NOTE: Fixed by: https://github.com/tinyproxy/tinyproxy/commit/364cdb67e0ea00a8e4a7037e2693e0711e816adb
-	NOTE: Reintroduced by https://github.com/tinyproxy/tinyproxy/commit/56404a3dd68e (pseudomap, 1.11.3); not present in 1.11.0-1.11.2 (orderedmap)
+	NOTE: Reintroduced by: with switch to pseudomap in 1.11.3:
+	NOTE: https://github.com/tinyproxy/tinyproxy/commit/56404a3dd68e15d5502716c835ecc9de2dc7a8ec (1.11.3)
+	NOTE: Not present in 1.11.0-1.11.2 (with orderedmap use)
 CVE-2026-54387 (Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile  ...)
 	- tinyproxy <unfixed> (bug #1140350)
 	[trixie] - tinyproxy <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f12448b688161bbcdb9e4b383064fcbefb1de284

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f12448b688161bbcdb9e4b383064fcbefb1de284
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/aa167fed/attachment.htm>


More information about the debian-security-tracker-commits mailing list