[Git][security-tracker-team/security-tracker][master] Add references bugs for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 2 06:39:37 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b48d401c by Salvatore Bonaccorso at 2026-08-02T07:39:05+02:00
Add references bugs for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -55,16 +55,16 @@ CVE-2026-67326 (GitPython before 3.1.50 fails to validate newline characters in
- python-git 3.1.50-1
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w
CVE-2026-67325 (GitPython before 3.1.51 contains an incomplete command injection block ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1143454)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx
CVE-2026-67324 (GitPython 3.1.50 fails to recognize joined short-option forms such as ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1143454)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v396-v7q4-x2qj
CVE-2026-67323 (GitPython before 3.1.51 fails to guard against dangerous Git options p ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1143454)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v
CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable exfiltra ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1143454)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
CVE-2026-67321 (axios before 0.33.0 contains an incomplete depth-limit bypass in toFor ...)
- node-axios 1.18.0-1
@@ -650,7 +650,7 @@ CVE-2026-21662 (Unrestricted upload of file with dangerous type vulnerability in
CVE-2026-18481 (Stored cross-site scripting in the participant URL handling in AWS Ops ...)
NOT-FOR-US: Amazon
CVE-2026-18446 (fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forw ...)
- - node-ajv <unfixed>
+ - node-ajv <unfixed> (bug #1143457)
[trixie] - node-ajv <no-dsa> (Minor issue)
NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7
NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
@@ -715,12 +715,12 @@ CVE-2026-16503 (Deployment of the VPS.org one-click Supabase template deploys a
CVE-2026-16105 (A flaw was found in the RoleContainerResource component of Keycloak. T ...)
- keycloak <itp> (bug #1088287)
CVE-2026-15722 (A stack buffer overflow flaw was found in 389 Directory Server (389-ds ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1143455)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499961
CVE-2026-15227 (Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and ...)
- ckeck-mk <removed>
CVE-2026-11770 (A flaw was found in 389 Directory Server. An unauthenticated remote at ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1143455)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484802
CVE-2026-10686 (Zephyr's IPv6 forwarding path re-sent routed unicast packets without e ...)
NOT-FOR-US: Zephyr, different from src:zephyr
@@ -25172,7 +25172,7 @@ CVE-2026-12481 (A vulnerability in keras-team/keras version 3.14.0 allows for ar
- keras <removed>
[bullseye] - keras <end-of-life> (EOL in bullseye LTS)
CVE-2026-12252 (In nltk/nltk versions 3.9.3 and earlier, five Stanford interface class ...)
- - nltk <unfixed>
+ - nltk <unfixed> (bug #1143456)
[trixie] - nltk <no-dsa> (Minor issue)
[bookworm] - nltk <postponed> (Minor issue)
[bullseye] - nltk <postponed> (Minor issue)
@@ -29761,7 +29761,7 @@ CVE-2026-12560 (The Editorial Rating \u2013 Product Review & Rating System plugi
CVE-2026-12349 (The Premium Addons for KingComposer plugin for WordPress is vulnerable ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12243 (NLTK version 3.9.4 is vulnerable to a path traversal attack due to an ...)
- - nltk <unfixed>
+ - nltk <unfixed> (bug #1143456)
[trixie] - nltk <no-dsa> (Minor issue)
[bookworm] - nltk <postponed> (Minor issue)
[bullseye] - nltk <postponed> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b48d401ca1d573c76d0b154b73162a4c910eddd3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b48d401ca1d573c76d0b154b73162a4c910eddd3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/75d7e6d9/attachment.htm>
More information about the debian-security-tracker-commits
mailing list