[Git][security-tracker-team/security-tracker][master] Add references bugs for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 2 06:39:37 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b48d401c by Salvatore Bonaccorso at 2026-08-02T07:39:05+02:00
Add references bugs for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -55,16 +55,16 @@ CVE-2026-67326 (GitPython before 3.1.50 fails to validate newline characters in
 	- python-git 3.1.50-1
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w
 CVE-2026-67325 (GitPython before 3.1.51 contains an incomplete command injection block ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx
 CVE-2026-67324 (GitPython 3.1.50 fails to recognize joined short-option forms such as  ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v396-v7q4-x2qj
 CVE-2026-67323 (GitPython before 3.1.51 fails to guard against dangerous Git options p ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v
 CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable exfiltra ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
 CVE-2026-67321 (axios before 0.33.0 contains an incomplete depth-limit bypass in toFor ...)
 	- node-axios 1.18.0-1
@@ -650,7 +650,7 @@ CVE-2026-21662 (Unrestricted upload of file with dangerous type vulnerability in
 CVE-2026-18481 (Stored cross-site scripting in the participant URL handling in AWS Ops ...)
 	NOT-FOR-US: Amazon
 CVE-2026-18446 (fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forw ...)
-	- node-ajv <unfixed>
+	- node-ajv <unfixed> (bug #1143457)
 	[trixie] - node-ajv <no-dsa> (Minor issue)
 	NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7
 	NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
@@ -715,12 +715,12 @@ CVE-2026-16503 (Deployment of the VPS.org one-click Supabase template deploys a
 CVE-2026-16105 (A flaw was found in the RoleContainerResource component of Keycloak. T ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2026-15722 (A stack buffer overflow flaw was found in 389 Directory Server (389-ds ...)
-	- 389-ds-base <unfixed>
+	- 389-ds-base <unfixed> (bug #1143455)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499961
 CVE-2026-15227 (Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and  ...)
 	- ckeck-mk <removed>
 CVE-2026-11770 (A flaw was found in 389 Directory Server. An unauthenticated remote at ...)
-	- 389-ds-base <unfixed>
+	- 389-ds-base <unfixed> (bug #1143455)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484802
 CVE-2026-10686 (Zephyr's IPv6 forwarding path re-sent routed unicast packets without e ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
@@ -25172,7 +25172,7 @@ CVE-2026-12481 (A vulnerability in keras-team/keras version 3.14.0 allows for ar
 	- keras <removed>
 	[bullseye] - keras <end-of-life> (EOL in bullseye LTS)
 CVE-2026-12252 (In nltk/nltk versions 3.9.3 and earlier, five Stanford interface class ...)
-	- nltk <unfixed>
+	- nltk <unfixed> (bug #1143456)
 	[trixie] - nltk <no-dsa> (Minor issue)
 	[bookworm] - nltk <postponed> (Minor issue)
 	[bullseye] - nltk <postponed> (Minor issue)
@@ -29761,7 +29761,7 @@ CVE-2026-12560 (The Editorial Rating \u2013 Product Review & Rating System plugi
 CVE-2026-12349 (The Premium Addons for KingComposer plugin for WordPress is vulnerable ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12243 (NLTK version 3.9.4 is vulnerable to a path traversal attack due to an  ...)
-	- nltk <unfixed>
+	- nltk <unfixed> (bug #1143456)
 	[trixie] - nltk <no-dsa> (Minor issue)
 	[bookworm] - nltk <postponed> (Minor issue)
 	[bullseye] - nltk <postponed> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b48d401ca1d573c76d0b154b73162a4c910eddd3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b48d401ca1d573c76d0b154b73162a4c910eddd3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/75d7e6d9/attachment.htm>


More information about the debian-security-tracker-commits mailing list