[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 08:12:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2fa5cad0 by security tracker role at 2026-08-05T07:12:32+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,311 @@
+CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for WordPress  ...)
+	TODO: check
+CVE-2026-8790 (The Football Pool plugin for WordPress is vulnerable to Reflected Cros ...)
+	TODO: check
+CVE-2026-8761 (The Dokan plugin for WordPress is vulnerable to Privilege Escalation i ...)
+	TODO: check
+CVE-2026-7753 (The Cost Calculator Builder plugin for WordPress is vulnerable to unau ...)
+	TODO: check
+CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that makes a craf ...)
+	TODO: check
+CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does not sanit ...)
+	TODO: check
+CVE-2026-71191 (In OpenStack Swift through 2.38.0, S3API middleware does not enforce t ...)
+	TODO: check
+CVE-2026-71190 (In OpenStack Swift through 2.38.0, the proxy server Accept header pars ...)
+	TODO: check
+CVE-2026-70620 (Odysseus before commit 87babb5 contains a server-side request forgery  ...)
+	TODO: check
+CVE-2026-70619 (Odysseus before commit bf325f6 contains a missing authorization vulner ...)
+	TODO: check
+CVE-2026-70594 (Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, ...)
+	TODO: check
+CVE-2026-70593 (Ghost is a Node.js content management system. From 0.10.0 until 6.54.1 ...)
+	TODO: check
+CVE-2026-70592 (Ghost is a Node.js content management system. From 1.20.1 until 6.54.1 ...)
+	TODO: check
+CVE-2026-70591 (Ghost is a Node.js content management system. From 0.10.0 until 6.54.1 ...)
+	TODO: check
+CVE-2026-70590 (Ghost is a Node.js content management system. Prior to 6.54.1, any sta ...)
+	TODO: check
+CVE-2026-70589 (Ghost is a Node.js content management system. From 4.22.0 until 6.54.1 ...)
+	TODO: check
+CVE-2026-70588 (Ghost is a Node.js content management system. From 5.26.0 until 6.54.1 ...)
+	TODO: check
+CVE-2026-70554 (MaxSite CMS contains a PHP object injection vulnerability that allows  ...)
+	TODO: check
+CVE-2026-70553 (MaxSite CMS contains a remote code execution vulnerability that allows ...)
+	TODO: check
+CVE-2026-70552 (MaxSite CMS 109.5 and earlier contains an authentication bypass vulner ...)
+	TODO: check
+CVE-2026-70494 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70493 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70492 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70491 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70490 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70489 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70488 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70487 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70486 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70485 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70484 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70483 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70482 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70481 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70480 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70479 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-70478 (Flowise is a drag & drop user interface to build a customized large la ...)
+	TODO: check
+CVE-2026-70477 (Flowise is a drag & drop user interface to build a customized large la ...)
+	TODO: check
+CVE-2026-70476 (Flowise is a drag & drop user interface to build a customized large la ...)
+	TODO: check
+CVE-2026-70475 (Flowise is a drag & drop user interface to build a customized large la ...)
+	TODO: check
+CVE-2026-70375 (HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerabi ...)
+	TODO: check
+CVE-2026-70374 (HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerabi ...)
+	TODO: check
+CVE-2026-68080 (It was not possible to govern the rate at which the broker would respo ...)
+	TODO: check
+CVE-2026-68078 (It was not possible to govern the maximum number of transfer frames pe ...)
+	TODO: check
+CVE-2026-68077 (An authenticated attacker can craft a disposition frame with large or  ...)
+	TODO: check
+CVE-2026-68075 (An authenticated attacker could exceed the session flow control incomi ...)
+	TODO: check
+CVE-2026-68074 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
+	TODO: check
+CVE-2026-68073 (A pre-authentication attacker could leverage type nesting to cause a S ...)
+	TODO: check
+CVE-2026-68060 (A pre-authentication attacker could leverage type size/count handling  ...)
+	TODO: check
+CVE-2026-67979 (Incorrect access control in the Executive Services dynamic application ...)
+	TODO: check
+CVE-2026-67862 (open62541 1.5.5 contains a buffer-overflow in the high-level attribute ...)
+	TODO: check
+CVE-2026-67861 (An issue in open62541 v.1.5.5 and before allows a remote attacker to c ...)
+	TODO: check
+CVE-2026-67860 (open62541 1.5.5 contains a heap-based buffer overflow in the default H ...)
+	TODO: check
+CVE-2026-67859 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote atta ...)
+	TODO: check
+CVE-2026-67858 (Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local ...)
+	TODO: check
+CVE-2026-67857 (open62541 1.5.5 contains an out-of-bounds read in the client-side func ...)
+	TODO: check
+CVE-2026-67856 (An issue in open62541 v.1.5.5 and before allows a remote attacker to c ...)
+	TODO: check
+CVE-2026-67855 (open62541 contains a heap use-after-free in the GDS PushManagement cer ...)
+	TODO: check
+CVE-2026-67592 (It was not possible to govern the maximum number of transfer frames pe ...)
+	TODO: check
+CVE-2026-67591 (An authenticated attacker could exceed the session flow control incomi ...)
+	TODO: check
+CVE-2026-67590 (A pre-authentication attacker could leverage type nesting to cause a S ...)
+	TODO: check
+CVE-2026-67589 (A pre-authentication attacker could leverage type size/count handling  ...)
+	TODO: check
+CVE-2026-67588 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
+	TODO: check
+CVE-2026-67555 (It was not possible to govern the maximum number of transfer frames pe ...)
+	TODO: check
+CVE-2026-67554 (An authenticated attacker can craft a disposition frame with large or  ...)
+	TODO: check
+CVE-2026-67553 (An authenticated attacker could exceed the session flow control incomi ...)
+	TODO: check
+CVE-2026-67552 (A pre-authentication attacker could leverage type nesting to cause a S ...)
+	TODO: check
+CVE-2026-67551 (pre-authentication attacker could leverage type size/count handling to ...)
+	TODO: check
+CVE-2026-67465 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
+	TODO: check
+CVE-2026-66839 (NetKids iMark, provided by Integrated Systems Technologies, Inc., cont ...)
+	TODO: check
+CVE-2026-66344 (NetKids iMark, provided by Integrated Systems Technologies, Inc., cont ...)
+	TODO: check
+CVE-2026-66277 (It was not possible to govern the maximum number of transfer frames pe ...)
+	TODO: check
+CVE-2026-66276 (An authenticated attacker can craft a disposition frame with large or  ...)
+	TODO: check
+CVE-2026-66275 (An authenticated attacker could exceed the session flow control incomi ...)
+	TODO: check
+CVE-2026-66274 (A pre-authentication attacker could leverage type nesting to cause a S ...)
+	TODO: check
+CVE-2026-66273 (A pre-authentication attacker could leverage type size/count handling  ...)
+	TODO: check
+CVE-2026-66257 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
+	TODO: check
+CVE-2026-65986 (CVAT is an open source interactive video and image annotation tool for ...)
+	TODO: check
+CVE-2026-5062 (The PrettyLinks \u2013 Affiliate Links, Link Branding, Link Tracking,  ...)
+	TODO: check
+CVE-2026-54020 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-52370 (A reflected cross-site scripting (XSS) vulnerability in the Forum post ...)
+	TODO: check
+CVE-2026-51401 (An issue in Vim Project v9.2.0389 and earlier allows a local attacker  ...)
+	TODO: check
+CVE-2026-51400 (An issue in Vim Project v9.2.0389 and earlier allows a local attacker  ...)
+	TODO: check
+CVE-2026-51144 (Cross Site Scripting vulnerability in Soliton Systems MailZen Manageme ...)
+	TODO: check
+CVE-2026-49004 (The built-in PostgreSQL service on the mobile device suffers from misc ...)
+	TODO: check
+CVE-2026-48154 (GoRest is a Golang starter kit built with the Gin framework for protot ...)
+	TODO: check
+CVE-2026-47682 (CVAT is an open source interactive video and image annotation tool for ...)
+	TODO: check
+CVE-2026-46334 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-45809 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-45705 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-45538 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-45537 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-45103 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-45100 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-45084 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
+	TODO: check
+CVE-2026-18907 (Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1. ...)
+	TODO: check
+CVE-2026-18903 (A vulnerability was determined in yeqifu warehouse up to aaf29962ba407 ...)
+	TODO: check
+CVE-2026-18902 (A vulnerability was detected in H3C NX15 V100R017. Affected by this vu ...)
+	TODO: check
+CVE-2026-18901 (A security vulnerability has been detected in H3C NX15 V100R017. Affec ...)
+	TODO: check
+CVE-2026-18900 (A weakness has been identified in H3C NX15 V100R017. This impacts the  ...)
+	TODO: check
+CVE-2026-18898 (A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-1 ...)
+	TODO: check
+CVE-2026-18897 (A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907 ...)
+	TODO: check
+CVE-2026-18896 (A vulnerability was determined in lavkush-maurya Student-Registration- ...)
+	TODO: check
+CVE-2026-18895 (A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-18053 ...)
+	TODO: check
+CVE-2026-18859 (A vulnerability was identified in ESAFENET CDG up to 20260615. Affecte ...)
+	TODO: check
+CVE-2026-18856 (A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This ...)
+	TODO: check
+CVE-2026-18854 (A vulnerability has been found in Shandong Hoteam PDM Product Data Man ...)
+	TODO: check
+CVE-2026-18853 (A security vulnerability has been detected in ZomboDroid Meme Generato ...)
+	TODO: check
+CVE-2026-18852 (A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/ ...)
+	TODO: check
+CVE-2026-18819 (A security vulnerability has been detected in RackTables up to 0.22.0/ ...)
+	TODO: check
+CVE-2026-18818 (A weakness has been identified in Ehco1996 django-sspanel up to 2023.1 ...)
+	TODO: check
+CVE-2026-18817 (A security flaw has been discovered in Baserow up to 2.3.2. Affected b ...)
+	TODO: check
+CVE-2026-18816 (A vulnerability was identified in Baserow up to 2.3.2. Affected by thi ...)
+	TODO: check
+CVE-2026-18814 (A vulnerability was found in H3C NX15 V100R017. This impacts the funct ...)
+	TODO: check
+CVE-2026-18813 (A vulnerability has been found in H3C NX15 V100R017. This affects the  ...)
+	TODO: check
+CVE-2026-18812 (A flaw has been found in H3C NX15 V100R017. The impacted element is th ...)
+	TODO: check
+CVE-2026-18811 (A vulnerability was detected in H3C NX15 V100R017. The affected elemen ...)
+	TODO: check
+CVE-2026-18810 (A security vulnerability has been detected in H3C NX15 V100R017. Impac ...)
+	TODO: check
+CVE-2026-18657 (An uncontrolled search path element in Kiro CLI before version 2.10.0  ...)
+	TODO: check
+CVE-2026-18656 (An uncontrolled search path element in Kiro IDE before version 1.0.228 ...)
+	TODO: check
+CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is vulnerable to Pri ...)
+	TODO: check
+CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with network access ...)
+	TODO: check
+CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPr ...)
+	TODO: check
+CVE-2026-16993 (The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 ...)
+	TODO: check
+CVE-2026-16981 (The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 ...)
+	TODO: check
+CVE-2026-16968 (The GeoDirectory  WordPress plugin before 2.8.168 does not restrict a  ...)
+	TODO: check
+CVE-2026-16942 (The WP Custom HTML Page WordPress plugin through 0.6.2 does not saniti ...)
+	TODO: check
+CVE-2026-16940 (The Custom Fields WordPress plugin before 1.5.1 does not validate a us ...)
+	TODO: check
+CVE-2026-16793 (An improper neutralization of special elements used in an operating sy ...)
+	TODO: check
+CVE-2026-16792 (An improper certificate validation vulnerability was reported in multi ...)
+	TODO: check
+CVE-2026-16791 (A temporary file creation vulnerability in the Linux version of Lenovo ...)
+	TODO: check
+CVE-2026-16746 (The MultiVendorX  WordPress plugin before 5.0.11 does not verify that  ...)
+	TODO: check
+CVE-2026-16736 (The User Registration & Membership  WordPress plugin before 5.2.6 does ...)
+	TODO: check
+CVE-2026-16613 (The GDPR Cookie Compliance  WordPress plugin before 5.1.0 expires the  ...)
+	TODO: check
+CVE-2026-16605 (The MultiVendorX  WordPress plugin before 5.0.11 does not verify that  ...)
+	TODO: check
+CVE-2026-16604 (The Passster  WordPress plugin before 4.3.6 outputs password-protected ...)
+	TODO: check
+CVE-2026-16603 (The Passster  WordPress plugin before 4.3.6 does not enforce its categ ...)
+	TODO: check
+CVE-2026-16602 (The Passster  WordPress plugin before 4.3.6 does not perform a post-st ...)
+	TODO: check
+CVE-2026-16583 (The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, ...)
+	TODO: check
+CVE-2026-16573 (The Bit Form  WordPress plugin before 3.2.0 does not sanitize an uploa ...)
+	TODO: check
+CVE-2026-16561 (The Sunshine Photo Cart  WordPress plugin before 3.6.12 does not perfo ...)
+	TODO: check
+CVE-2026-16143 (The VikRentItems \u2013 Flexible Rental Management System plugin for W ...)
+	TODO: check
+CVE-2026-16055 (The Contest Gallery  WordPress plugin before 30.0.7 does not route its ...)
+	TODO: check
+CVE-2026-16036 (The miniOrange 2FA  WordPress plugin before 6.2.7 does not bind the se ...)
+	TODO: check
+CVE-2026-15941 (The plugin provides an Admin Search page that allows users with the `e ...)
+	TODO: check
+CVE-2026-15918 (VikAppointments Service Booking Calendar wordpress plugin is vulnerabl ...)
+	TODO: check
+CVE-2026-15372 (The WP 2FA  WordPress plugin before 4.1.0 does not validate the second ...)
+	TODO: check
+CVE-2026-15360 (The Ajax Load More  WordPress plugin before 8.0.1 does not properly sa ...)
+	TODO: check
+CVE-2026-15230 (The YayPricing  WordPress plugin before 3.5.7 does not perform capabil ...)
+	TODO: check
+CVE-2026-15210 (The OTP Login With Phone Number, OTP Verification WordPress plugin bef ...)
+	TODO: check
+CVE-2026-14553 (The zportals WordPress plugin before 6.3.4 does not properly validate  ...)
+	TODO: check
+CVE-2026-13227 (An Improper Authorization vulnerability exists in ERPNext version <v16 ...)
+	TODO: check
+CVE-2026-11421 (The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Supp ...)
+	TODO: check
+CVE-2025-15677 (The GeoDirectory  WordPress plugin before 2.8.110 does not sanitise an ...)
+	TODO: check
 CVE-2026-42170
 	- gimp 3.2.4-1
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161
@@ -13,9 +321,9 @@ CVE-2026-59679 [Font Server Client encoding Out-Of-Bounds Read/Write]
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/05/1
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/668fea81f40bcb48ec67fb55d0b851049d265290 (libXfont2-2.0.9)
 	NOTE: Disabled support to connect to font server since 1:1.4.7-1
-CVE-2026-66902
+CVE-2026-66902 (Google::Auth versions before 0.06 for Perl run a command named in an e ...)
 	NOT-FOR-US: Google::Auth Perl module
-CVE-2026-66901
+CVE-2026-66901 (Google::Auth versions before 0.09 for Perl allow server side request f ...)
 	NOT-FOR-US: Google::Auth Perl module
 CVE-2026-70474 (Flowise is a drag-and-drop user interface for building customized larg ...)
 	NOT-FOR-US: Flowise
@@ -2120,7 +2428,7 @@ CVE-2026-62313 [Project isolation restriction bypass by omitting security.idmap.
 	- incus 7.0.1-2
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
 	NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-55707
+CVE-2026-55707 (In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does ...)
 	- neutron 2:28.0.1-2 (bug #1143170)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-032.html
 	NOTE: https://bugs.launchpad.net/neutron/+bug/2152113
@@ -5173,7 +5481,7 @@ CVE-2026-54659 (Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.
 	NOTE: https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc
 	NOTE: https://github.com/ddnexus/pagy/pull/908
 	NOTE: Fixed by: https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df (43.5.6)
-CVE-2026-54658 (Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0. ...)
+CVE-2026-54658 (Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5. ...)
 	NOT-FOR-US: Hypequery
 CVE-2026-54656 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
 	NOT-FOR-US: datamodel-code-generator
@@ -38540,24 +38848,28 @@ CVE-2026-8296 (In affected versions of Octopus Server with certain access levels
 CVE-2026-6798 (The 2Download Connector for 2DL Hosted Checkout plugin for WordPress i ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-56211 (A remote code execution vulnerability was found in libaom, the referen ...)
+	{DSA-6411-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t encoder control, introduced in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490802
 	NOTE: https://issues.chromium.org/issues/503993985
 CVE-2026-56210 (A heap-buffer-overflow read vulnerability was found in libaom, the ref ...)
+	{DSA-6411-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks the SVC encoder layer_context array, introduced in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490801
 	NOTE: https://issues.chromium.org/issues/503975732
 CVE-2026-56209 (An arbitrary address write vulnerability was found in libaom, the refe ...)
+	{DSA-6411-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t encoder control, introduced in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490800
 	NOTE: https://issues.chromium.org/issues/503993984
 CVE-2026-56208 (A heap buffer overflow vulnerability was found in libaom, the referenc ...)
+	{DSA-6411-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks LAP two-pass mode (encoder), introduced upstream in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/243f8ae84bfbc495b3a3c12948abc4dff3af2f84
@@ -64728,6 +65040,7 @@ CVE-2025-11159 (Hitachi Vantara Pentaho Data Integration & Analytics of all vers
 CVE-2024-36315 (Improper enforcement of the LFENCE serialization property may allow an ...)
 	NOT-FOR-US: AMD
 CVE-2026-44378 (Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns ...)
+	{DSA-6412-1}
 	[experimental] - botan3 3.12.0+dfsg-1
 	- botan3 3.12.0+dfsg-2
 	NOTE: https://github.com/randombit/botan/security/advisories/GHSA-7q2v-3g27-6g3j



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2fa5cad065f114c5607b6bd720e691782844cfdb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2fa5cad065f114c5607b6bd720e691782844cfdb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/dba1cfdb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list