[Git][security-tracker-team/security-tracker][master] goaccess triagging

Bastien Roucariès (@rouca) rouca at debian.org
Tue Aug 4 21:34:53 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c3019565 by Bastien Roucariès at 2026-08-04T22:34:43+02:00
goaccess triagging

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2234,10 +2234,14 @@ CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with a
 	NOT-FOR-US: ComfyUI
 CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
 	- goaccess <unfixed> (bug #1143181)
+	[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
+	[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
 	NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg
 	NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81 (v1.11)
 CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
 	- goaccess <unfixed> (bug #1143181)
+	[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
+	[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
 	NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46
 	NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5 (v1.11)
 CVE-2026-55502 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
@@ -2252,6 +2256,8 @@ CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. P
 	NOT-FOR-US: Cloudreve
 CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
 	- goaccess <unfixed> (bug #1143181)
+	[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
+	[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
 	NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr
 	NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/81f90d9dafd6956c188dea9f944d24946d3d3351 (v1.11)
 CVE-2026-52539 (Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3019565ccc177f4f2058fc23f2675ffabe19e7d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3019565ccc177f4f2058fc23f2675ffabe19e7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/7880e2ce/attachment.htm>


More information about the debian-security-tracker-commits mailing list