[Git][security-tracker-team/security-tracker][master] LTS triagging

Bastien Roucariès (@rouca) rouca at debian.org
Thu Aug 6 08:52:58 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6fb57bd1 by Bastien Roucariès at 2026-08-06T09:52:42+02:00
LTS triagging

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -64653,6 +64653,8 @@ CVE-2026-41932 (Vvveb before 1.0.8.3 contains a stored cross-site scripting vuln
 CVE-2026-41888 (Distribution is a toolkit to pack, ship, store, and deliver container  ...)
 	- docker-registry <unfixed>
 	[trixie] - docker-registry <no-dsa> (Minor issue)
+	[bookworm] - docker-registry <postponed> (Minor issue)
+	[bullseye] - docker-registry <postponed> (Minor issue)
 	NOTE: https://github.com/distribution/distribution/security/advisories/GHSA-6pjf-3r9x-m592
 	NOTE: https://github.com/distribution/distribution/commit/8baf3e08266a19590cc5d4725f3976a9a876d4bf (v3.1.1)
 CVE-2026-41615 (Exposure of sensitive information to an unauthorized actor in Microsof ...)
@@ -109232,6 +109234,7 @@ CVE-2026-27830 (c3p0, a JDBC Connection pooling library, is vulnerable to attack
 	- c3p0 <unfixed> (bug #1129318)
 	[trixie] - c3p0 <no-dsa> (Minor issue)
 	[bookworm] - c3p0 <postponed> (Minor issue; userOverridesAsString deserialization reachable only via attacker-controlled bean property or JNDI Reference; fix needs 0.12.0 rewrite)
+	[bullseye] - c3p0 <postponed> (Minor issue; userOverridesAsString deserialization reachable only via attacker-controlled bean property or JNDI Reference; fix needs 0.12.0 rewrite)
 	NOTE: https://github.com/swaldman/c3p0/security/advisories/GHSA-5476-xc4j-rqcv
 	NOTE: Fixed by: https://github.com/swaldman/c3p0/commit/e14cbd8166e423e2e9a9d6f08b2add3433492d6e (v0.12.0)
 CVE-2026-27829 (Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in As ...)
@@ -179788,6 +179791,7 @@ CVE-2025-47909 (Hosts listed in TrustedOrigins implicitly allow requests from th
 	- golang-github-gorilla-csrf <unfixed> (bug #1118966)
 	[trixie] - golang-github-gorilla-csrf <no-dsa> (Minor issue)
 	[bookworm] - golang-github-gorilla-csrf <no-dsa> (Minor issue)
+	[bullseye] - golang-github-gorilla-csrf <postponed> (Minor issue; limited support)
 	NOTE: https://github.com/golang/vulndb/issues/3884
 	NOTE: https://github.com/advisories/GHSA-82ff-hg59-8x73
 CVE-2025-44033 (SQL injection vulnerability in oa_system oasys v.1.1 allows a remote a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fb57bd17895bfd3cf39d1cf2f43b4b2c6e7f09e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fb57bd17895bfd3cf39d1cf2f43b4b2c6e7f09e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/6194ed24/attachment.htm>


More information about the debian-security-tracker-commits mailing list