[Git][security-tracker-team/security-tracker][master] goaccess triagging
Bastien Roucariès (@rouca)
rouca at debian.org
Tue Aug 4 21:34:53 BST 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c3019565 by Bastien Roucariès at 2026-08-04T22:34:43+02:00
goaccess triagging
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2234,10 +2234,14 @@ CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with a
NOT-FOR-US: ComfyUI
CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess <unfixed> (bug #1143181)
+ [bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
+ [bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg
NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81 (v1.11)
CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess <unfixed> (bug #1143181)
+ [bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
+ [bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46
NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5 (v1.11)
CVE-2026-55502 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
@@ -2252,6 +2256,8 @@ CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. P
NOT-FOR-US: Cloudreve
CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess <unfixed> (bug #1143181)
+ [bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
+ [bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr
NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/81f90d9dafd6956c188dea9f944d24946d3d3351 (v1.11)
CVE-2026-52539 (Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3019565ccc177f4f2058fc23f2675ffabe19e7d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3019565ccc177f4f2058fc23f2675ffabe19e7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/7880e2ce/attachment.htm>
More information about the debian-security-tracker-commits
mailing list