[Git][security-tracker-team/security-tracker][master] Add CVE-2026-18809/firefox
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 4 21:27:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c37b8647 by Salvatore Bonaccorso at 2026-08-04T22:26:44+02:00
Add CVE-2026-18809/firefox
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -202,7 +202,8 @@ CVE-2026-21366 (Memory corruption while processing a packet with a size close to
CVE-2026-18830 (Insufficient input validation in Amazon Bedrock AgentCore harness migh ...)
NOT-FOR-US: Amazon
CVE-2026-18809 (Information disclosure in Firefox for Android and Firefox Focus for An ...)
- TODO: check
+ - firefox <not-affected> (Only affects Firefox on Android)
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-73/#CVE-2026-18809
CVE-2026-18806 (External control of file name or path vulnerability in T\xdcB\u0130TAK ...)
NOT-FOR-US: pardus-image-writer
CVE-2026-18801 (OpenMeter contains a stored, or second-order, SQL injection vulnerabil ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37b86476837c41ee2d7f5c6025d2feb864a5c61
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37b86476837c41ee2d7f5c6025d2feb864a5c61
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/8b99bf6e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list