[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 2 20:12:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f19ed518 by security tracker role at 2026-08-02T19:12:53+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,31 @@
+CVE-2026-9856 (A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allo ...)
+ TODO: check
+CVE-2026-68583 (luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scri ...)
+ TODO: check
+CVE-2026-68582 (Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level ...)
+ TODO: check
+CVE-2026-68581 (Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal t ...)
+ TODO: check
+CVE-2026-68578 (ArcadeDB versions before 26.7.3 fail to bind the authenticated princip ...)
+ TODO: check
+CVE-2026-67357 (ArcadeDB versions before 26.7.3 contain an information disclosure vuln ...)
+ TODO: check
+CVE-2026-67356 (ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaSc ...)
+ TODO: check
+CVE-2026-65321 (PyAthena prior to 3.35.4 contains a sql injection vulnerability that a ...)
+ TODO: check
+CVE-2026-12231 (The Exclusive Addons for Elementor plugin for WordPress is vulnerable ...)
+ TODO: check
+CVE-2026-10848 (The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC fra ...)
+ TODO: check
+CVE-2026-10774 (Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key ...)
+ TODO: check
+CVE-2025-71401 (better-auth (npm) before 1.4.2 allows an external request to configure ...)
+ TODO: check
+CVE-2025-71400 (better-auth passkey versions before 1.4.0 contain an insecure direct o ...)
+ TODO: check
+CVE-2025-71399 (Better Auth relies on better-call, which uses the rou3 router library. ...)
+ TODO: check
CVE-2026-9335 (A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrar ...)
- keras <removed>
[bullseye] - keras <end-of-life> (EOL in bullseye LTS)
@@ -141,7 +169,7 @@ CVE-2026-67323 (GitPython before 3.1.51 fails to guard against dangerous Git opt
CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable exfiltra ...)
- python-git <unfixed> (bug #1143454)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
-CVE-2026-67321 (axios before 0.33.0 contains an incomplete depth-limit bypass in toFor ...)
+CVE-2026-67321 (axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...)
- node-axios 1.18.0-1
NOTE: https://github.com/axios/axios/security/advisories/GHSA-hcpx-6fm6-wx23
CVE-2026-67320 (axios in a Node.js deployment using the HTTP adapter can route request ...)
@@ -165,7 +193,7 @@ CVE-2026-67317 (axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength
CVE-2026-67316 (axios is vulnerable to read-side prototype-pollution gadgets that can ...)
- node-axios 1.18.0-1
NOTE: https://github.com/axios/axios/security/advisories/GHSA-mmx7-hfxf-jppx
-CVE-2026-67315 (axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loo ...)
+CVE-2026-67315 (axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to r ...)
- node-axios 1.18.0-1
[trixie] - node-axios <not-affected> (Vulnerable code introduced later)
[bookworm] - node-axios <not-affected> (Vulnerable code introduced later)
@@ -193,11 +221,11 @@ CVE-2026-67308 (Wazuh workflows before 44bf114 contain a shell injection vulnera
NOT-FOR-US: Wazuh
CVE-2026-67307 (Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override ...)
NOT-FOR-US: Wazuh
-CVE-2026-68580
+CVE-2026-68580 (FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the ...)
- freerdp3 3.29.0+dfsg-1
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x
-CVE-2026-68579
+CVE-2026-68579 (FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflo ...)
- freerdp3 3.30.0+dfsg-1
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m37j-jcr2-8gcc
@@ -12373,6 +12401,7 @@ CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component. This
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16349
CVE-2026-15370 (A flaw was found in libssh. During SFTP server directory listing, the ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-15370.txt
@@ -12388,39 +12417,46 @@ CVE-2026-59842 (A flaw was found in libssh. During server-side GSSAPI key exchan
NOTE: Introduced with: https://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080 (libssh-0.12.0)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610 (libssh-0.12.1)
CVE-2026-59843 (A flaw was found in libssh. A remote authenticated peer can advertise ...)
+ {DSA-6410-1}
- libssh 0.12.2-1
NOTE: https://www.libssh.org/2026/07/28/libssh-0-12-2-security-release/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59843.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=3f785905760d2e2a87037285ab85b37b9924e409 (libssh-0.12.2)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=006ddd503566ee13e00db42bc111e898388f8664 (libssh-0.12.2)
CVE-2026-59844 (A flaw was found in libssh. A remote authenticated client can issue SS ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59844.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2544f22733ffcd59a2e51e2950f80901d063b946 (libssh-0.12.1)
CVE-2026-59845 (A flaw was found in libssh. When ProxyCommand is used, an unchecked fo ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59845.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f (libssh-0.12.1)
CVE-2026-59846 (A flaw was found in libssh. A malicious username expanded through %r i ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59846.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2e74267b034f00e8e36c86440364f885cead5f45 (libssh-0.12.1)
CVE-2026-59847 (A flaw was found in libssh. Incorrect AES-GCM finalization checks in b ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59847.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074 (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9 (libssh-0.12.1)
CVE-2026-59848 (A flaw was found in libssh. A malicious SFTP server can send responses ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59848.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=9563afc950f473daa355ca594e2e5f4d520460ac (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=e3dc89de9754790e49b26f03b70e8e4acc88bde8 (libssh-0.12.1)
CVE-2026-59849 (A flaw was found in libssh. Logic errors in automatic certificate-base ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59849.txt
@@ -12428,6 +12464,7 @@ CVE-2026-59849 (A flaw was found in libssh. Logic errors in automatic certificat
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2a40a20b4963e033c7c5a21e3dc5ea6572178a20 (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=a540e27659b08828ef61f2910a790f7cf2af9f8d (libssh-0.12.1)
CVE-2026-59850 (A flaw was found in libssh. If data packets are processed after a chan ...)
+ {DSA-6410-1}
- libssh 0.12.1-1 (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59850.txt
@@ -65296,7 +65333,7 @@ CVE-2026-42783 [openpgp: Reject nested embedded signatures]
[bookworm] - rust-sequoia-openpgp <no-dsa> (Minor issue)
[bullseye] - rust-sequoia-openpgp <postponed> (Minor issue)
NOTE: Fixed by: https://gitlab.com/sequoia-pgp/sequoia/-/commit/23403ff850352b420f19a8fb4724ce35bf963e08 (openpgp/v2.3.0)
-CVE-2026-5084 (WebDyne::Session versions through 2.075 for Perl generates the session ...)
+CVE-2026-5084 (WebDyne::Session versions before 3.003_704 for Perl generate the sessi ...)
NOT-FOR-US: WebDyne::Session Perl module
CVE-2026-8276 (A flaw has been found in bettercap up to 2.41.5. Affected by this issu ...)
- bettercap 2.33.0-3 (bug #1136448)
@@ -79378,6 +79415,7 @@ CVE-2026-5760 (SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Exe
CVE-2026-4048 (OS Command Injection Remote Code Execution Vulnerability in UI in Prog ...)
NOT-FOR-US: Progress Software
CVE-2026-41445 (KissFFT before commit8a8e66e contains an integer overflow vulnerabilit ...)
+ {DLA-4715-1}
- kissfft 131.1.0-4.1 (bug #1134493)
[trixie] - kissfft 131.1.0-4.1~deb13u1
[bookworm] - kissfft 131.1.0-4.1~deb12u1
@@ -102449,6 +102487,7 @@ CVE-2026-3733 (A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This
CVE-2026-3732 (A security vulnerability has been detected in Tenda F453 1.0.0.3. This ...)
NOT-FOR-US: Tenda
CVE-2026-3731 (A weakness has been identified in libssh up to 0.11.3. The impacted el ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -113624,6 +113663,7 @@ CVE-2019-25306 (BlackMoon FTP Server 3.1.2.1731 contains an unquoted service pat
CVE-2018-25157 (Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability ...)
NOT-FOR-US: Phraseanet
CVE-2026-0968 (A flaw was found in libssh in which a malicious SFTP (SSH File Transfe ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -113631,12 +113671,14 @@ CVE-2026-0968 (A flaw was found in libssh in which a malicious SFTP (SSH File Tr
NOTE: Tests: https://git.libssh.org/projects/libssh.git/commit/?id=212121971fb26e1e00b72bd5402c0454a4d84c03 (libssh-0.11.4)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=796d85f786dff62bd4bcc4408d9b7bbc855841e9 (libssh-0.11.4)
CVE-2026-0967 (A flaw was found in libssh. A remote attacker, by controlling client c ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0967.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=6d74aa6138895b3662bade9bd578338b0c4f8a15 (libssh-0.11.4)
CVE-2026-0966 (A flaw was found in libssh. The API function `ssh_get_hexa()` is vulne ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -113645,12 +113687,14 @@ CVE-2026-0966 (A flaw was found in libssh. The API function `ssh_get_hexa()` is
NOTE: Tests: https://git.libssh.org/projects/libssh.git/commit/?id=b156391833c66322436cf177d57e10b0325fbcc8 (libssh-0.11.4)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=6ba5ff1b7b1547a59f750fbc06b89737b7456117 (libssh-0.11.4)
CVE-2026-0965 (A flaw was found in libssh where it can attempt to open arbitrary file ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0965.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=bf390a042623e02abc8f421c4c5fadc0429a8a76 (libssh-0.11.4)
CVE-2026-0964 (A malicious SCP server can send unexpected paths that could make the c ...)
+ {DSA-6410-1}
- libssh 0.12.0-1 (bug #1127693)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
@@ -145356,6 +145400,7 @@ CVE-2025-41070 (Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's C
CVE-2025-3500 (Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1. ...)
NOT-FOR-US: Avast Antivirus
CVE-2025-34297 (KissFFT versions prior to the fix commit 1b083165 contain an integer o ...)
+ {DLA-4715-1}
- kissfft 131.1.0-4.1 (bug #1131147)
[trixie] - kissfft 131.1.0-4.1~deb13u1
[bookworm] - kissfft 131.1.0-4.1~deb12u1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f19ed5181b7239f4b4aa3a0ca793933151791dbd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f19ed5181b7239f4b4aa3a0ca793933151791dbd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/fee1b980/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list