[Git][security-tracker-team/security-tracker][master] Reserve DLA-4712-1 for node-tar
Daniel Leidert (@dleidert)
dleidert at debian.org
Sat Aug 1 16:16:25 BST 2026
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6c130286 by Daniel Leidert at 2026-08-01T17:15:28+02:00
Reserve DLA-4712-1 for node-tar
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -102199,7 +102199,6 @@ CVE-2026-29786 (node-tar is a full-featured Tar for Node.js. Prior to version 7.
{DLA-4552-1}
- node-tar 6.2.1+ds1+~cs6.1.13-8
[trixie] - node-tar 6.2.1+~cs7.0.8-1+deb13u1
- [bookworm] - node-tar <no-dsa> (Minor issue)
NOTE: https://github.com/isaacs/node-tar/security/advisories/GHSA-qffp-2rhf-9h96
NOTE: Fixed by: https://github.com/isaacs/node-tar/commit/7bc755dd85e623c0279e08eb3784909e6d7e4b9f (v7.5.10)
CVE-2026-29784 (Ghost is a Node.js content management system. From version 5.101.6 to ...)
@@ -109125,7 +109124,6 @@ CVE-2026-26960 (node-tar is a full-featured Tar for Node.js. When using default
{DLA-4552-1}
- node-tar 6.2.1+ds1+~cs6.1.13-8 (bug #1129378)
[trixie] - node-tar 6.2.1+~cs7.0.8-1+deb13u1
- [bookworm] - node-tar <no-dsa> (Minor issue)
NOTE: https://github.com/isaacs/node-tar/security/advisories/GHSA-83g3-92jg-28cx
NOTE: Fixed by: https://github.com/isaacs/node-tar/commit/d18e4e1f846f4ddddc153b0f536a19c050e7499f (v7.5.8)
NOTE: Fixed by: https://github.com/isaacs/node-tar/commit/2cb1120bcefe28d7ecc719b41441ade59c52e384 (v7.5.8)
@@ -122582,7 +122580,6 @@ CVE-2026-23745 (node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) f
{DLA-4552-1}
- node-tar 6.2.1+ds1+~cs6.1.13-6
[trixie] - node-tar 6.2.1+~cs7.0.8-1+deb13u1
- [bookworm] - node-tar <no-dsa> (Minor issue)
NOTE: https://github.com/isaacs/node-tar/security/advisories/GHSA-8qq5-rm4j-mr97
NOTE: Fixed by: https://github.com/isaacs/node-tar/commit/340eb285b6d986e91969a1170d7fe9b0face405e (v7.5.3)
CVE-2026-23744 (MCPJam inspector is the local-first development platform for MCP serve ...)
@@ -337106,7 +337103,6 @@ CVE-2024-28891 (SQL injection vulnerability exists in the script Handler_CFG.ash
CVE-2024-28863 (node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no ...)
{DLA-4552-1}
- node-tar 6.1.13+~cs7.0.5-2
- [bookworm] - node-tar <no-dsa> (Minor issue)
[buster] - node-tar <no-dsa> (Minor issue)
NOTE: https://github.com/isaacs/node-tar/security/advisories/GHSA-f5x3-32g6-xq36
NOTE: https://github.com/isaacs/node-tar/commit/fe8cd57da5686f8695415414bda49206a545f7f7 (v6.2.1)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[01 Aug 2026] DLA-4712-1 node-tar - security update
+ {CVE-2024-28863 CVE-2026-23745 CVE-2026-26960 CVE-2026-29786}
+ [bookworm] - node-tar 6.1.13+~cs7.0.5-1+deb12u1
[01 Aug 2026] DLA-4711-1 starlette - security update
{CVE-2026-48817 CVE-2026-54282 CVE-2026-54283}
[bookworm] - starlette 0.26.1-1+deb12u2
=====================================
data/dla-needed.txt
=====================================
@@ -539,13 +539,6 @@ node-lodash/bookworm (utkarsh)
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this (dleidert/front-desk)
--
-node-tar/bookworm (dleidert)
- NOTE: 20260717: Added by Front-Desk (Beuc)
- NOTE: 20260717: Follow DLA-4552-1/bullseye
- NOTE: 20260717: ELTS work underway (Beuc/front-desk)
- NOTE: 20260730: OSPU was denied due to the migration of Bookwotm to LTS (dleidert)
- NOTE: 20260730: I will upload this version to LTS instead (dleidert)
---
nodejs
NOTE: 20260622: Added by Front-Desk (lamby)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c130286f548075eb29c33b2dbaf756e9fe51936
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c130286f548075eb29c33b2dbaf756e9fe51936
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/9b8c0816/attachment.htm>
More information about the debian-security-tracker-commits
mailing list