[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 08:12:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
157b9e0f by security tracker role at 2026-08-04T07:12:19+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,281 @@
+CVE-2026-8508 (An improper authentication vulnerability in the "social_login.cgi" CGI ...)
+	TODO: check
+CVE-2026-6837 (A post-authentication command injection vulnerability in the "export-c ...)
+	TODO: check
+CVE-2026-69249 (python-cryptography is a package designed to expose cryptographic prim ...)
+	TODO: check
+CVE-2026-69248 (cryptography is a package designed to expose cryptographic primitives  ...)
+	TODO: check
+CVE-2026-69247 (cryptography is a package designed to expose cryptographic primitives  ...)
+	TODO: check
+CVE-2026-69246 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...)
+	TODO: check
+CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...)
+	TODO: check
+CVE-2026-69244 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
+	TODO: check
+CVE-2026-69243 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
+	TODO: check
+CVE-2026-69240 (Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is pos ...)
+	TODO: check
+CVE-2026-69198 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
+	TODO: check
+CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
+	TODO: check
+CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication for ever ...)
+	TODO: check
+CVE-2026-68981 (Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests fo ...)
+	TODO: check
+CVE-2026-68980 (Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleti ...)
+	TODO: check
+CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update R ...)
+	TODO: check
+CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function  ...)
+	TODO: check
+CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers  ...)
+	TODO: check
+CVE-2026-67977 (An integer overflow in the Svc::FileDownlink::SendPartial component of ...)
+	TODO: check
+CVE-2026-67976 (The Ref::SignalGen component of fprime framework v4.2.2 does not valid ...)
+	TODO: check
+CVE-2026-67975 (Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitr ...)
+	TODO: check
+CVE-2026-67974 (A parser boundary flaw in the Software Bus Network (SBN) application's ...)
+	TODO: check
+CVE-2026-67973 (An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers  ...)
+	TODO: check
+CVE-2026-67972 (An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows a ...)
+	TODO: check
+CVE-2026-67970 (Incorrect access control in the DS_SetDestPathCmd() component of NASA  ...)
+	TODO: check
+CVE-2026-67969 (An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1  ...)
+	TODO: check
+CVE-2026-67673 (A stack-based buffer overflow vulnerability exists in the cmd_edl func ...)
+	TODO: check
+CVE-2026-67617 (Microweber CMS through 2.0.20 contains a stored cross-site scripting v ...)
+	TODO: check
+CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missin ...)
+	TODO: check
+CVE-2026-67599 (ClearOS 7.9 contains an OS command injection vulnerability in the Log  ...)
+	TODO: check
+CVE-2026-67598 (Emlog Pro through 2.6.23 contains a disabled TLS certificate validatio ...)
+	TODO: check
+CVE-2026-66326 (Missing authorization in Microsoft Edge (Chromium-based) allows an una ...)
+	TODO: check
+CVE-2026-66325 (Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based)  ...)
+	TODO: check
+CVE-2026-66322 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
+	TODO: check
+CVE-2026-66321 (Access of resource using incompatible type ('type confusion') in Micro ...)
+	TODO: check
+CVE-2026-66318 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
+	TODO: check
+CVE-2026-66317 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
+	TODO: check
+CVE-2026-66316 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
+	TODO: check
+CVE-2026-66315 (Use after free in Microsoft Edge (Chromium-based) allows an unauthoriz ...)
+	TODO: check
+CVE-2026-66314 (Time-of-check time-of-use (toctou) race condition in Microsoft Edge (C ...)
+	TODO: check
+CVE-2026-66313 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
+	TODO: check
+CVE-2026-66312 (Buffer over-read in Microsoft Edge (Chromium-based) allows an authoriz ...)
+	TODO: check
+CVE-2026-66311 (Missing authorization in Microsoft Edge (Chromium-based) allows an una ...)
+	TODO: check
+CVE-2026-66310 (External control of file name or path in Microsoft Edge for Android al ...)
+	TODO: check
+CVE-2026-66296 (Improper Neutralization of Input During Web Page Generation (XSS) vuln ...)
+	TODO: check
+CVE-2026-66065 (Ouroboros is a local-first runtime for AI coding agents that records t ...)
+	TODO: check
+CVE-2026-65804 (Improper control of generation of code ('code injection') in Microsoft ...)
+	TODO: check
+CVE-2026-65802 (External control of file name or path in Microsoft Edge for Android al ...)
+	TODO: check
+CVE-2026-64565 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-64564 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-64563 (In the Linux kernel, the following vulnerability has been resolved:  r ...)
+	TODO: check
+CVE-2026-64562 (In the Linux kernel, the following vulnerability has been resolved:  K ...)
+	TODO: check
+CVE-2026-64561 (In the Linux kernel, the following vulnerability has been resolved:  K ...)
+	TODO: check
+CVE-2026-62870 (Use after free in Microsoft Office Excel allows an unauthorized attack ...)
+	TODO: check
+CVE-2026-62354 (Authorization handling for Parameter Context validation requests in Ap ...)
+	TODO: check
+CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy bypass  ...)
+	TODO: check
+CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists under /cu ...)
+	TODO: check
+CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated  ...)
+	TODO: check
+CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulne ...)
+	TODO: check
+CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md plugin  ...)
+	TODO: check
+CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an at ...)
+	TODO: check
+CVE-2026-51190 (The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 p ...)
+	TODO: check
+CVE-2026-49132 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
+	TODO: check
+CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
+	TODO: check
+CVE-2026-48399 (Adobe Campaign Classic (ACC) is affected by a Violation of Secure Desi ...)
+	TODO: check
+CVE-2026-48333 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
+	TODO: check
+CVE-2026-48331 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
+	TODO: check
+CVE-2026-48330 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+	TODO: check
+CVE-2026-48326 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+	TODO: check
+CVE-2026-48323 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+	TODO: check
+CVE-2026-48317 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+	TODO: check
+CVE-2026-48115 (Misskey is an open source, federated social media platform. All Misske ...)
+	TODO: check
+CVE-2026-48113 (Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. ...)
+	TODO: check
+CVE-2026-48063 (Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versi ...)
+	TODO: check
+CVE-2026-48061 (Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. ...)
+	TODO: check
+CVE-2026-48031 (go-base is a Go RESTful API Boilerplate template with JWT Authenticati ...)
+	TODO: check
+CVE-2026-47746 (Misskey is an open source, federated social media platform. Versions 1 ...)
+	TODO: check
+CVE-2026-47211 (Ouroboros is a local-first runtime for AI coding agents that records t ...)
+	TODO: check
+CVE-2026-46714 (Misskey is an open source, federated social media platform. IVersions  ...)
+	TODO: check
+CVE-2026-46713 (Misskey is an open source, federated social media platform. Versions 1 ...)
+	TODO: check
+CVE-2026-46712 (Misskey is an open source, federated social media platform. Versions 2 ...)
+	TODO: check
+CVE-2026-42169 (A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) ...)
+	TODO: check
+CVE-2026-41447 (FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerab ...)
+	TODO: check
+CVE-2026-18739 (A flaw was found in popt, a command-line option parsing library. An of ...)
+	TODO: check
+CVE-2026-18738 (Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vu ...)
+	TODO: check
+CVE-2026-18737 (Shlink contains a blind SQL injection vulnerability that allows any au ...)
+	TODO: check
+CVE-2026-18736 (Shlink contains a server-side request forgery vulnerability that allow ...)
+	TODO: check
+CVE-2026-18733 (A prompt injection vulnerability in the shell tool in Amazon Strands A ...)
+	TODO: check
+CVE-2026-18723 (A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The a ...)
+	TODO: check
+CVE-2026-18722 (A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted i ...)
+	TODO: check
+CVE-2026-18721 (A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This ...)
+	TODO: check
+CVE-2026-18720 (A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerab ...)
+	TODO: check
+CVE-2026-18719 (A vulnerability was detected in cemtan sar2html 4.0.0. This affects an ...)
+	TODO: check
+CVE-2026-18686 (A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The aff ...)
+	TODO: check
+CVE-2026-18685 (A security vulnerability has been detected in GL.iNet GL-MT3000 up to  ...)
+	TODO: check
+CVE-2026-18684 (A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This  ...)
+	TODO: check
+CVE-2026-18682 (A security flaw has been discovered in OpenAkita up to 1.27.12. This v ...)
+	TODO: check
+CVE-2026-18667 (A vulnerability in Tenable Sensor Proxy allows a remote attacker to ex ...)
+	TODO: check
+CVE-2026-18655 (Improper restriction of intended endpoints in the RabbitMQ broker conn ...)
+	TODO: check
+CVE-2026-18654 (Key exchange without entity authentication in the EMR SSH helper comma ...)
+	TODO: check
+CVE-2026-18648 (A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2. ...)
+	TODO: check
+CVE-2026-18647 (A security vulnerability has been detected in jina-ai reader up to 157 ...)
+	TODO: check
+CVE-2026-18646 (A weakness has been identified in danpros HTMLy up to 3.1.1. This vuln ...)
+	TODO: check
+CVE-2026-18645 (A security flaw has been discovered in danpros HTMLy up to 3.1.1. This ...)
+	TODO: check
+CVE-2026-18644 (A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected  ...)
+	TODO: check
+CVE-2026-18641 (A vulnerability was determined in Sangfor Operation and Maintenance Se ...)
+	TODO: check
+CVE-2026-18632 (A security flaw has been discovered in langgenius dify up to 1.14.2. T ...)
+	TODO: check
+CVE-2026-18631 (A vulnerability was identified in jeequan jeepay up to 3.2.9. This vul ...)
+	TODO: check
+CVE-2026-18569 (A flaw was found in the backchannel logout endpoint of the keycloak-se ...)
+	TODO: check
+CVE-2026-17614 (A path traversal flaw was found in WildFly's domain mode   implementat ...)
+	TODO: check
+CVE-2026-16881 (A code injection vulnerability exists in the LINE Android app prior to ...)
+	TODO: check
+CVE-2026-16623 (The Create Block  WordPress plugin before 2.10.0 does not correctly es ...)
+	TODO: check
+CVE-2026-16618 (The Improve SEO WordPress plugin through 2.0.11 does not properly vali ...)
+	TODO: check
+CVE-2026-16548 (The Chat Widget: Floating Customer Support Button for 30+ Channels, Su ...)
+	TODO: check
+CVE-2026-16547 (The REST API Log WordPress plugin before 1.7.1 does not bind the token ...)
+	TODO: check
+CVE-2026-16546 (The Wired Impact Volunteer Management WordPress plugin before 2.8.2 do ...)
+	TODO: check
+CVE-2026-16536 (The Simple Google Calendar Outlook Events Widget WordPress plugin befo ...)
+	TODO: check
+CVE-2026-16296 (The Clearfy Cache  WordPress plugin before 2.4.3 does not validate the ...)
+	TODO: check
+CVE-2026-16295 (The Clearfy Cache  WordPress plugin before 2.4.3 does not perform a ca ...)
+	TODO: check
+CVE-2026-16293 (The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11 ...)
+	TODO: check
+CVE-2026-16070 (The Brizy  WordPress plugin before 2.8.19 does not properly verify aut ...)
+	TODO: check
+CVE-2026-16069 (The Brizy  WordPress plugin before 2.8.19 does not sanitize or escape  ...)
+	TODO: check
+CVE-2026-16068 (The Brizy  WordPress plugin before 2.8.19 does not properly restrict w ...)
+	TODO: check
+CVE-2026-16056 (The Contest Gallery  WordPress plugin before 30.0.7 does not perform a ...)
+	TODO: check
+CVE-2026-16035 (The miniOrange 2FA  WordPress plugin before 6.2.7 does not restrict wh ...)
+	TODO: check
+CVE-2026-15958 (The Easy Integration for Dropbox  WordPress plugin before 2.2.0 does n ...)
+	TODO: check
+CVE-2026-15233 (The Nested Pages WordPress plugin before 3.2.15 does not properly esca ...)
+	TODO: check
+CVE-2026-14939 (The Visualizer  WordPress plugin before 4.0.6 does not restrict a user ...)
+	TODO: check
+CVE-2026-14872 (The Database for Contact Form 7, WPforms, Elementor forms WordPress pl ...)
+	TODO: check
+CVE-2026-14848 (The Paid Membership Subscriptions  WordPress plugin before 3.0.8 does  ...)
+	TODO: check
+CVE-2026-14824 (The Quiz and Survey Master (QSM)  WordPress plugin before 11.2.2 does  ...)
+	TODO: check
+CVE-2026-14818 (A path traversal vulnerability in the CLI command used to execute conf ...)
+	TODO: check
+CVE-2026-14816 (The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not p ...)
+	TODO: check
+CVE-2026-12698 (The wpForo Forum WordPress plugin before 3.1.3 does not restrict which ...)
+	TODO: check
+CVE-2026-11836 (Insufficient verification of data authenticity in Caliptra Core ROM an ...)
+	TODO: check
+CVE-2026-11835 (Time-of-check time-of-use (TOCTOU) vulnerability combined with missing ...)
+	TODO: check
+CVE-2026-11366 (The MonsterInsights  WordPress plugin before 11.1.0 does not correctly ...)
+	TODO: check
+CVE-2026-10849 (The hawkBit device management client in subsys/mgmt/hawkbit accumulate ...)
+	TODO: check
+CVE-2026-10526 (The EmbedPress  WordPress plugin before 4.6.1 does not validate user-s ...)
+	TODO: check
 CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its authen ...)
 	NOT-FOR-US: PaperCut
 CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive authentication att ...)
@@ -1115,7 +1393,7 @@ CVE-2026-68574
 	REJECTED
 CVE-2026-67822 (Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnera ...)
 	NOT-FOR-US: Tenda
-CVE-2026-67607 (LightFTP 2.3.1 contains a race condition vulnerability that allows rem ...)
+CVE-2026-67607 (LightFTP 2.3.1 contains a residual race condition vulnerability (an in ...)
 	NOT-FOR-US: LightFTP
 CVE-2026-67350 (Serendipity before 2.6.1 contains an open redirect vulnerability in ex ...)
 	- serendipity <removed>
@@ -2121,25 +2399,25 @@ CVE-2026-XXXX [OSSA-2026-030 Swift: S3API header authorization bypass]
 CVE-2022-4994 (In the Linux kernel, the following vulnerability has been resolved:  K ...)
 	- linux 6.0.2-1
 	NOTE: https://git.kernel.org/linus/dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3 (6.0-rc1)
-CVE-2026-58044
+CVE-2026-58044 (A flaw in Node.js HTTP client can cause a request desynchronization fo ...)
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http-parser-header-truncation-can-enable-request-smuggling-cve-2026-58044---low
 CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows process.report w ...)
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-process-reports-to-write-outside-the-allowlist-cve-2026-58039---low
-CVE-2026-58045
+CVE-2026-58045 (A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigge ...)
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodezlib-sync-apis-can-crash-on-spoofed-typedarray-length-cve-2026-58045---medium
-CVE-2026-58042
+CVE-2026-58042 (A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Proces ...)
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#dnsresolveany-can-abort-on-dns-responses-with-many-a-records-cve-2026-58042---medium
-CVE-2026-58041
+CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale StatementSyncIterator cre ...)
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodesqlite-sqltagstore-iterator-replay-can-re-execute-writes-cve-2026-58041---medium
 CVE-2026-56848
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-re-entrant-send-can-cause-heap-use-after-free-cve-2026-56848---high
-CVE-2026-56846
+CVE-2026-56846 (A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blo ...)
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-retained-headers-can-bypass-maxsessionmemory-limits-cve-2026-56846---high
 CVE-2026-66066 (Action Pack is a framework for handling and responding to web requests ...)
@@ -16753,7 +17031,7 @@ CVE-2026-54496 (ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad
 	NOT-FOR-US: ZEBRA
 CVE-2026-53712 (SCRAM (Salted Challenge Response Authentication Mechanism) is part of  ...)
 	NOT-FOR-US: com.ongres.scram:scram-client and com.ongres.scram:scram-common
-CVE-2026-52746 (JSONata is a JSON query and transformation language. Prior to 2.2.0, m ...)
+CVE-2026-52746 (JSONata is a JSON query and transformation language. Prior to 2.2.0 an ...)
 	NOT-FOR-US: jsonata-js
 CVE-2026-51083 (Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu ...)
 	NOT-FOR-US: Proxmox
@@ -23295,7 +23573,8 @@ CVE-2026-14361 (The consul-template library before version 0.42.1 is vulnerable
 	NOT-FOR-US: consul-template library
 CVE-2026-13320 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
-CVE-2026-13151 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+CVE-2026-13151
+	REJECTED
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-12517 (The Fediverse Embeds WordPress plugin before 1.5.8 does not validate t ...)
 	NOT-FOR-US: WordPress plugin
@@ -63813,7 +64092,7 @@ CVE-2026-44223 (vLLM is an inference and serving engine for large language model
 	- vllm <itp> (bug #1095237)
 CVE-2026-44222 (vLLM is an inference and serving engine for large language models (LLM ...)
 	- vllm <itp> (bug #1095237)
-CVE-2026-44221 (ArcadeDB is a Multi-Model DBMS. Prior to 2.6.4, authenticated users an ...)
+CVE-2026-44221 (ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior  ...)
 	NOT-FOR-US: ArcadeDB
 CVE-2026-44220 (ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 t ...)
 	NOT-FOR-US: ciguard
@@ -76834,6 +77113,7 @@ CVE-2026-41318 (AnythingLLM is an application that turns pieces of content into
 CVE-2026-41317 (Press, a Frappe custom app that runs Frappe Cloud, manages infrastruct ...)
 	NOT-FOR-US: Press (Frapp app)
 CVE-2026-41316 (ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was  ...)
+	{DLA-4716-1}
 	- ruby3.3 <unfixed> (bug #1134920)
 	- ruby3.1 <removed>
 	- ruby2.7 <removed>
@@ -81258,6 +81538,7 @@ CVE-2026-2336 (A privilege escalation vulnerability in Microchip IStaX allows an
 CVE-2026-28741 (Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 1 ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2026-27820 (zlib is a Ruby interface for the zlib compression/decompression librar ...)
+	{DLA-4716-1}
 	- ruby3.3 <unfixed> (bug #1134341)
 	- ruby3.1 <removed>
 	- ruby2.7 <removed>
@@ -100468,7 +100749,7 @@ CVE-2026-3060 (SGLang' encoder parallel disaggregation system is vulnerable to u
 	NOT-FOR-US: sgl-project sglang
 CVE-2026-3059 (SGLang's multimodal generation module is vulnerable to unauthenticated ...)
 	NOT-FOR-US: sgl-project sglang
-CVE-2026-32274 (Black is the uncompromising Python code formatter. Prior to 26.3.1, Bl ...)
+CVE-2026-32274 (Black is the uncompromising Python code formatter. Starting in version ...)
 	- black 26.3.1-1 (bug #1130657)
 	[trixie] - black 25.1.0-3+deb13u1
 	[bookworm] - black <no-dsa> (Minor issue)
@@ -130993,6 +131274,7 @@ CVE-2025-66723 (inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Perm
 CVE-2025-62753 (Improper Control of Filename for Include/Require Statement in PHP Prog ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2025-61594 (URI is a module providing classes to handle Uniform Resource Identifie ...)
+	{DLA-4716-1}
 	- ruby3.3 <unfixed> (bug #1124379)
 	[trixie] - ruby3.3 <no-dsa> (Minor issue)
 	- ruby3.1 <removed>
@@ -191796,6 +192078,7 @@ CVE-2025-53871
 CVE-2025-53636 (Open OnDemand is an open-source HPC portal. Users can flood logs by in ...)
 	NOT-FOR-US: Open OnDemand
 CVE-2025-24294 (The attack vector is a potential Denial of Service (DoS). The vulnerab ...)
+	{DLA-4716-1}
 	- ruby3.3 <unfixed> (bug #1109337)
 	[trixie] - ruby3.3 <no-dsa> (Minor issue)
 	- ruby3.1 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/157b9e0f75743b5a045b1510d45a54ca20ac679e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/157b9e0f75743b5a045b1510d45a54ca20ac679e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/2f6d5224/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list