[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 7 08:13:38 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bd9ca69b by security tracker role at 2026-08-07T07:13:31+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,451 @@
+CVE-2026-8325 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
+ TODO: check
+CVE-2026-7406 (A maliciously crafted BMP file, when parsed through certain Autodesk p ...)
+ TODO: check
+CVE-2026-7405 (A maliciously crafted TIF file, when parsed through certain Autodesk p ...)
+ TODO: check
+CVE-2026-71555 (PILOS (Platform for Interactive Live-Online Seminars) is a frontend fo ...)
+ TODO: check
+CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...)
+ TODO: check
+CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting vulnerability cau ...)
+ TODO: check
+CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
+ TODO: check
+CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1.14.3 ...)
+ TODO: check
+CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
+ TODO: check
+CVE-2026-71478 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
+ TODO: check
+CVE-2026-71476 (Nx is a monorepo solution for TypeScript and polyglot codebases. From ...)
+ TODO: check
+CVE-2026-71447 (AIL Project contains a stored cross-site scripting vulnerability in th ...)
+ TODO: check
+CVE-2026-71446 (AIL Framework contains a stored cross-site scripting vulnerability in ...)
+ TODO: check
+CVE-2026-71445 (AIL Framework contained a reflected cross-site scripting vulnerability ...)
+ TODO: check
+CVE-2026-71439 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
+ TODO: check
+CVE-2026-71438 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
+ TODO: check
+CVE-2026-71437 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
+ TODO: check
+CVE-2026-71436 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
+ TODO: check
+CVE-2026-71435 (Statamic is a Laravel and Git powered content management system (CMS). ...)
+ TODO: check
+CVE-2026-71434 (Statamic is a Laravel and Git powered content management system (CMS). ...)
+ TODO: check
+CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres a ...)
+ TODO: check
+CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
+ TODO: check
+CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
+ TODO: check
+CVE-2026-71326 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
+ TODO: check
+CVE-2026-71325 (Traefik is an open-source edge router that makes publishing services a ...)
+ TODO: check
+CVE-2026-71324 (Traefik is an open source HTTP reverse proxy and load balancer. Prior ...)
+ TODO: check
+CVE-2026-70640 (llama.cpp builds b1886 through b7445 contain a race condition use-afte ...)
+ TODO: check
+CVE-2026-70639 (llama.cpp builds b1886 through b7445 contain a null pointer dereferenc ...)
+ TODO: check
+CVE-2026-70638 (llama.cpp builds b1886 through b7445 contain an integer overflow vulne ...)
+ TODO: check
+CVE-2026-70636 (Flowise through 3.1.4 contains an authentication bypass vulnerability ...)
+ TODO: check
+CVE-2026-70635 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-o ...)
+ TODO: check
+CVE-2026-70634 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-o ...)
+ TODO: check
+CVE-2026-70633 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-o ...)
+ TODO: check
+CVE-2026-70632 (FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out- ...)
+ TODO: check
+CVE-2026-70631 (FFmpeg versions from 0.5 up to, but not including, 9.0 contain an unin ...)
+ TODO: check
+CVE-2026-70630 (FFmpeg versions from 3.0 up to, but not including, 9.0 contain an unin ...)
+ TODO: check
+CVE-2026-70629 (FFmpeg versions from 3.0 up to, but not including, 9.0 contain an unin ...)
+ TODO: check
+CVE-2026-70628 (FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signe ...)
+ TODO: check
+CVE-2026-70559 (Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/ge ...)
+ TODO: check
+CVE-2026-70558 (Dinky's POST /download/uploadFromRsByLocal handler passes the caller-s ...)
+ TODO: check
+CVE-2026-70557 (diboot-core's POST /common/load-related-data endpoint resolves caller- ...)
+ TODO: check
+CVE-2026-70332 (Server-side request forgery (ssrf) in Microsoft Office SharePoint allo ...)
+ TODO: check
+CVE-2026-69125
+ REJECTED
+CVE-2026-69124
+ REJECTED
+CVE-2026-69123
+ REJECTED
+CVE-2026-68948
+ REJECTED
+CVE-2026-68947
+ REJECTED
+CVE-2026-68946
+ REJECTED
+CVE-2026-68944
+ REJECTED
+CVE-2026-68943
+ REJECTED
+CVE-2026-68942
+ REJECTED
+CVE-2026-68941
+ REJECTED
+CVE-2026-68823 (Exposed dangerous method or function in Azure Confidential Ledger allo ...)
+ TODO: check
+CVE-2026-67689 (SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker ...)
+ TODO: check
+CVE-2026-67688 (ICS-Park Smart Park Management System v2.0 contains an unrestricted fi ...)
+ TODO: check
+CVE-2026-67687 (Insecure Permissions vulnerability in ics-park v.2.0 allows a remote a ...)
+ TODO: check
+CVE-2026-67622 (Flowise through 3.1.4 contains an insecure direct object reference vul ...)
+ TODO: check
+CVE-2026-67621 (Flowise through 3.1.4 contains a missing authorization vulnerability t ...)
+ TODO: check
+CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and detects violations of a define ...)
+ TODO: check
+CVE-2026-67422 (pymdown-extensions is a collection of extensions for the Python Markdo ...)
+ TODO: check
+CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows an auth ...)
+ TODO: check
+CVE-2026-65667 (Missing authorization in Microsoft Teams allows an unauthorized attack ...)
+ TODO: check
+CVE-2026-65400 (An authentication issue was addressed with improved state management. ...)
+ TODO: check
+CVE-2026-64677 (Anki is a program for creating and reviewing flashcards. Prior to 25.0 ...)
+ TODO: check
+CVE-2026-64665 (Statamic is a Laravel and Git powered content management system (CMS). ...)
+ TODO: check
+CVE-2026-64664 (Statamic is a Laravel and Git powered content management system (CMS). ...)
+ TODO: check
+CVE-2026-64663 (Statamic is a Laravel and Git powered content management system (CMS). ...)
+ TODO: check
+CVE-2026-64662 (Statamic is a Laravel and Git powered content management system (CMS). ...)
+ TODO: check
+CVE-2026-64655 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to ...)
+ TODO: check
+CVE-2026-64654 (GitHub CLI (gh) is GitHub's official command line tool. Prior to versi ...)
+ TODO: check
+CVE-2026-64653 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to ...)
+ TODO: check
+CVE-2026-64652 (GitHub CLI (gh) is GitHub's official command line tool. Prior to versi ...)
+ TODO: check
+CVE-2026-63725 (sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup ...)
+ TODO: check
+CVE-2026-63637 (Dgraph is an open source distributed GraphQL database. Prior to 25.3.8 ...)
+ TODO: check
+CVE-2026-63508 (Missing authentication for critical function in Microsoft Planetary Co ...)
+ TODO: check
+CVE-2026-62918 (Improper verification of cryptographic signature in Microsoft Teams al ...)
+ TODO: check
+CVE-2026-62896 (Improper authentication in Microsoft Teams allows an authorized attack ...)
+ TODO: check
+CVE-2026-62873 (Improper verification of cryptographic signature in Microsoft 365 Admi ...)
+ TODO: check
+CVE-2026-62857 (Fedify is a TypeScript library for building federated server apps powe ...)
+ TODO: check
+CVE-2026-62836 (Improper restriction of communication channel to intended endpoints in ...)
+ TODO: check
+CVE-2026-62830 (Missing authorization in Azure SRE Agent allows an authorized attacker ...)
+ TODO: check
+CVE-2026-61632 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
+ TODO: check
+CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt ...)
+ TODO: check
+CVE-2026-5856 (Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resol ...)
+ TODO: check
+CVE-2026-5855 (Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lw ...)
+ TODO: check
+CVE-2026-5336 (The DataPress (Dataverse Integration) WordPress plugin before 2.91 doe ...)
+ TODO: check
+CVE-2026-59118 (Improper authorization in Microsoft Power Apps allows an unauthorized ...)
+ TODO: check
+CVE-2026-59115 ('.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allow ...)
+ TODO: check
+CVE-2026-56162 (Improper authentication in Azure SQL Database allows an unauthorized a ...)
+ TODO: check
+CVE-2026-56161 (Improper access control in Azure Logic Apps allows an authorized attac ...)
+ TODO: check
+CVE-2026-54717 (Silverstripe CMS is an open source content management system. Prior to ...)
+ TODO: check
+CVE-2026-53984 (Ground Station prior to0.6.0 contains an unauthenticated database-dest ...)
+ TODO: check
+CVE-2026-53983 (Ground Station prior to0.6.0contains an unauthenticated blind server-s ...)
+ TODO: check
+CVE-2026-50515 (Deserialization of untrusted data in Azure Service Bus allows an autho ...)
+ TODO: check
+CVE-2026-50481 (Modification of assumed-immutable data (maid) in Azure Active Director ...)
+ TODO: check
+CVE-2026-50159 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
+ TODO: check
+CVE-2026-49746 (Software installed and run as a non-privileged user may conduct improp ...)
+ TODO: check
+CVE-2026-49391 (Frappe is a full-stack web application framework. Prior to 16.19.0 and ...)
+ TODO: check
+CVE-2026-49163 (Improper limitation of a pathname to a restricted directory ('path tra ...)
+ TODO: check
+CVE-2026-49005 (The root password hash of the device can be obtained through unencrypt ...)
+ TODO: check
+CVE-2026-48088 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48087 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48086 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48085 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48084 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48083 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48082 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48081 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48080 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48079 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48078 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48077 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48076 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48075 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48074 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48071 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-48054 (OpenZeppelin Contracts Wizardis a web application to interactively bui ...)
+ TODO: check
+CVE-2026-47765 (Frappe is a full-stack web application framework. Prior to 15.110.0 an ...)
+ TODO: check
+CVE-2026-47194 (Frappe is a full-stack web application framework. Prior to 15.108.0 an ...)
+ TODO: check
+CVE-2026-47185 (Frappe is a full-stack web application framework. Prior to 16.18.0, th ...)
+ TODO: check
+CVE-2026-45573 (Decidim is a participatory democracy framework. Prior to 0.30.9, from ...)
+ TODO: check
+CVE-2026-45572 (Decidim is a participatory democracy framework. Prior to 0.30.9, from ...)
+ TODO: check
+CVE-2026-45415 (Decidim is a participatory democracy framework. Prior to 0.30.9, from ...)
+ TODO: check
+CVE-2026-45414 (Decidim is a participatory democracy framework. Prior to 0.31.5 and in ...)
+ TODO: check
+CVE-2026-45378 (Decidim is a participatory democracy framework. Prior to 0.30.9, from ...)
+ TODO: check
+CVE-2026-45204 (Software installed and run as a non-privileged user may conduct improp ...)
+ TODO: check
+CVE-2026-45198 (Kernel software from a non-secure operating system on a platform with ...)
+ TODO: check
+CVE-2026-43632 (llama.cpp builds b7492 through the latest b9060 contains a use-after-f ...)
+ TODO: check
+CVE-2026-43631 (llama.cpp builds b7492 through the latest b9060 contains a use-after-f ...)
+ TODO: check
+CVE-2026-43630 (llama.cpp builds b5702 through b7653 contain an out-of-bounds read vul ...)
+ TODO: check
+CVE-2026-43629 (llama.cpp builds b4882 through b9058 contain a heap buffer overflow vu ...)
+ TODO: check
+CVE-2026-43628 (llama.cpp builds b3978 through b9058 contain an integer underflow and ...)
+ TODO: check
+CVE-2026-43627 (llama.cpp builds b1283 through b9058 contain an integer overflow vulne ...)
+ TODO: check
+CVE-2026-41861 (Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attack ...)
+ TODO: check
+CVE-2026-3418 (The System REST API accepts user-supplied file uploads without enforci ...)
+ TODO: check
+CVE-2026-3415 (The XML and schema validation functionalities within the SchemaValidat ...)
+ TODO: check
+CVE-2026-33181
+ REJECTED
+CVE-2026-1289 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
+ TODO: check
+CVE-2026-19196 (A vulnerability was found in SourceCodester Photo Share Website 1.0. T ...)
+ TODO: check
+CVE-2026-19195 (A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. ...)
+ TODO: check
+CVE-2026-19193 (A flaw has been found in Jiangmin Antivirus 21. Impacted is the functi ...)
+ TODO: check
+CVE-2026-19192 (A vulnerability was detected in DeepCool DisplayService 1.2.12. This i ...)
+ TODO: check
+CVE-2026-19191 (A security vulnerability has been detected in StableBit DrivePool 2.3. ...)
+ TODO: check
+CVE-2026-19190 (A weakness has been identified in StableBit Scanner 2.6.13.4088. This ...)
+ TODO: check
+CVE-2026-19189 (A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. ...)
+ TODO: check
+CVE-2026-19127 (An issue in the billing and license activation subsystem allows remote ...)
+ TODO: check
+CVE-2026-19111 (Insecure direct object reference in the mongodb_memory, elasticsearch_ ...)
+ TODO: check
+CVE-2026-19110 (A vulnerability was determined in DataGear up to 5.0.0. The impacted e ...)
+ TODO: check
+CVE-2026-19108 (A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. Th ...)
+ TODO: check
+CVE-2026-19071 (A flaw has been found in itsourcecode Hospital Management System 1.0. ...)
+ TODO: check
+CVE-2026-19070 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
+ TODO: check
+CVE-2026-19069 (A security vulnerability has been detected in itsourcecode Hospital Ma ...)
+ TODO: check
+CVE-2026-19068 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
+ TODO: check
+CVE-2026-19067 (A security flaw has been discovered in itsourcecode Hospital Managemen ...)
+ TODO: check
+CVE-2026-19066 (A vulnerability was identified in SourceCodester Online Examination & ...)
+ TODO: check
+CVE-2026-19065 (A vulnerability was determined in SourceCodester Online Examination & ...)
+ TODO: check
+CVE-2026-19064 (A vulnerability was found in SourceCodester Online Examination & Learn ...)
+ TODO: check
+CVE-2026-19062 (A vulnerability has been found in chiuwingyan house up to dea6bcceaebe ...)
+ TODO: check
+CVE-2026-19061 (A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected ...)
+ TODO: check
+CVE-2026-19060 (A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2 ...)
+ TODO: check
+CVE-2026-19059 (A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2 ...)
+ TODO: check
+CVE-2026-19058 (A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The ...)
+ TODO: check
+CVE-2026-19054 (A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5 ...)
+ TODO: check
+CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser reads web ad ...)
+ TODO: check
+CVE-2026-18367 (A privilege escalation vulnerability allows local users to execute arb ...)
+ TODO: check
+CVE-2026-17264 (Opening a crafted DICOM file containing malicious JPEG-compressed pixe ...)
+ TODO: check
+CVE-2026-17032 (Multiple Supsystic Pro plugins were distributed with malicious code th ...)
+ TODO: check
+CVE-2026-16620 (The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 ...)
+ TODO: check
+CVE-2026-16619 (The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly li ...)
+ TODO: check
+CVE-2026-16265 (The WP Maps WordPress plugin before 4.9.7 does not perform a capabili ...)
+ TODO: check
+CVE-2026-16263 (The WP Maps WordPress plugin before 4.9.7 does not perform a capabili ...)
+ TODO: check
+CVE-2026-16262 (The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not ...)
+ TODO: check
+CVE-2026-16258 (The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent ...)
+ TODO: check
+CVE-2026-16067 (The Event Booking Manager for WooCommerce (Pro) WordPress plugin befor ...)
+ TODO: check
+CVE-2026-16041 (The MStore API WordPress plugin before 4.21.0 does not perform author ...)
+ TODO: check
+CVE-2026-16039 (The MStore API WordPress plugin before 4.21.0 does not restrict its v ...)
+ TODO: check
+CVE-2026-16038 (The MStore API WordPress plugin before 4.21.0 does not verify the pay ...)
+ TODO: check
+CVE-2026-16030 (The MStore API WordPress plugin before 4.21.0 does not correctly veri ...)
+ TODO: check
+CVE-2026-15805
+ REJECTED
+CVE-2026-15734 (A Server-Side Template Injection (SSTI) vulnerability in WGDashboard v ...)
+ TODO: check
+CVE-2026-15733 (A Remote Code Execution (RCE) vulnerability exist in WGDashboard versi ...)
+ TODO: check
+CVE-2026-15732 (A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboar ...)
+ TODO: check
+CVE-2026-15386 (The Meow Gallery WordPress plugin before 5.5.2 does not escape an atta ...)
+ TODO: check
+CVE-2026-15361 (The Content Views WordPress plugin before 4.5 does not perform a capa ...)
+ TODO: check
+CVE-2026-15359 (The Templately WordPress plugin before 3.7.1 does not have an authori ...)
+ TODO: check
+CVE-2026-15256 (The Ninja Forms WordPress plugin before 3.14.10 does not prevent user- ...)
+ TODO: check
+CVE-2026-15245 (The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly ...)
+ TODO: check
+CVE-2026-15215 (The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does n ...)
+ TODO: check
+CVE-2026-15214 (The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does n ...)
+ TODO: check
+CVE-2026-15208 (The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare ...)
+ TODO: check
+CVE-2026-15152 (The WP Hotel Booking WordPress plugin before 2.3.2 does not verify tha ...)
+ TODO: check
+CVE-2026-15149 (The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure tha ...)
+ TODO: check
+CVE-2026-15147 (The Five Star Restaurant Reservations WordPress plugin before 2.7.23 d ...)
+ TODO: check
+CVE-2026-15032 (The Comments WordPress plugin before 7.6.60 does not properly escape ...)
+ TODO: check
+CVE-2026-14943 (The Password Protected \u2014 Lock Entire Site, Pages, Posts, Categori ...)
+ TODO: check
+CVE-2026-14936 (The Simple Membership WordPress plugin before 4.7.7 does not verify th ...)
+ TODO: check
+CVE-2026-14842 (The Events Made Easy WordPress plugin before 3.1.2 does not bind the p ...)
+ TODO: check
+CVE-2026-14831 (The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a b ...)
+ TODO: check
+CVE-2026-14812 (The Premium SEO WordPress plugin is malicious: it ships an unauthentic ...)
+ TODO: check
+CVE-2026-14365 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin ...)
+ TODO: check
+CVE-2026-14364 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin ...)
+ TODO: check
+CVE-2026-14331 (The Subscribe2 WordPress plugin before 10.46 does not properly escape ...)
+ TODO: check
+CVE-2026-14306 (The Tutor LMS WordPress plugin before 3.9.14 does not properly verify ...)
+ TODO: check
+CVE-2026-14225 (The Easy Appointments WordPress plugin through 3.12.26 does not correc ...)
+ TODO: check
+CVE-2026-14205 (The WP Events Manager WordPress plugin before 2.2.5 does not validate ...)
+ TODO: check
+CVE-2026-13399 (The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0 ...)
+ TODO: check
+CVE-2026-13342 (The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not c ...)
+ TODO: check
+CVE-2026-12901 (The GetPaid WordPress plugin before 2.8.55 does not verify the authent ...)
+ TODO: check
+CVE-2026-12801 (The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable ...)
+ TODO: check
+CVE-2026-12584 (The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin bef ...)
+ TODO: check
+CVE-2026-12501 (The WP Travel Engine WordPress plugin before 6.8.2 does not verify tha ...)
+ TODO: check
+CVE-2026-12261 (A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 al ...)
+ TODO: check
+CVE-2026-11976 (The official MonsterInsights Pro update distribution bucket (`monster- ...)
+ TODO: check
+CVE-2026-11907 (The Stream plugin for WordPress is vulnerable to authorization bypass ...)
+ TODO: check
+CVE-2026-11803 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
+ TODO: check
+CVE-2026-11361 (The Formidable Forms WordPress plugin before 6.32.1 does not properly ...)
+ TODO: check
+CVE-2026-10599 (The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 ...)
+ TODO: check
+CVE-2026-10524 (The CoCart WordPress plugin before 4.9.0 does not validate a user-supp ...)
+ TODO: check
+CVE-2025-6508 (The Swagger UI Try-out console within the API Publisher documentation ...)
+ TODO: check
+CVE-2025-15674 (The Passster WordPress plugin before 4.3.7 does not restrict low-privi ...)
+ TODO: check
+CVE-2025-14561 (In multi-tenant deployments, the Publisher REST APIs fail to enforce t ...)
+ TODO: check
+CVE-2025-12317 (When internal roles are removed from a user within the WSO2 product, t ...)
+ TODO: check
+CVE-2024-6541 (The Class Mediator fails to correctly validate or sanitize `messageCon ...)
+ TODO: check
+CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows authenticat ...)
+ TODO: check
CVE-2026-18938
- p11-kit <unfixed>
NOTE: https://github.com/p11-glue/p11-kit/pull/777
@@ -6,127 +454,127 @@ CVE-2026-64638
- wordpress <unfixed> (bug #1143843)
NOTE: https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
-CVE-2026-19137
+CVE-2026-19137 (Use after free in WebGL in Google Chrome on Android prior to 151.0.792 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19149
+CVE-2026-19149 (Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.1 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19154
+CVE-2026-19154 (Use after free in Skia in Google Chrome on Android prior to 151.0.7922 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19157
+CVE-2026-19157 (Out of bounds write in ANGLE in Google Chrome on Android prior to 151. ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19170
+CVE-2026-19170 (Use after free in WebGL in Google Chrome on Android prior to 151.0.792 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19172
+CVE-2026-19172 (Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19169
+CVE-2026-19169 (Insufficient validation of untrusted input in Contextual Tasks in Goog ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19168
+CVE-2026-19168 (Inappropriate implementation in V8 in Google Chrome prior to 151.0.792 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19138
+CVE-2026-19138 (Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19139
+CVE-2026-19139 (Race in CredentialProvider in Google Chrome on Windows prior to 151.0. ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19140
+CVE-2026-19140 (Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19141
+CVE-2026-19141 (Use after free in Resources in Google Chrome on Android prior to 151.0 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19142
+CVE-2026-19142 (Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19143
+CVE-2026-19143 (Insufficient validation of untrusted input in WebAPKs in Google Chrome ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19144
+CVE-2026-19144 (Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowe ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19145
+CVE-2026-19145 (Use after free in Translate in Google Chrome prior to 151.0.7922.109 a ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19146
+CVE-2026-19146 (Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.79 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19147
+CVE-2026-19147 (Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.1 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19148
+CVE-2026-19148 (Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.79 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19150
+CVE-2026-19150 (Inappropriate implementation in V8 in Google Chrome prior to 151.0.792 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19151
+CVE-2026-19151 (Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19152
+CVE-2026-19152 (Insufficient policy enforcement in Navigation in Google Chrome prior t ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19153
+CVE-2026-19153 (Insufficient validation of untrusted input in Workers in Google Chrome ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19155
+CVE-2026-19155 (Use after free in Payments in Google Chrome prior to 151.0.7922.109 al ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19156
+CVE-2026-19156 (Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19158
+CVE-2026-19158 (Use after free in Views in Google Chrome on Windows prior to 151.0.792 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19159
+CVE-2026-19159 (Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19160
+CVE-2026-19160 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 all ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19161
+CVE-2026-19161 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 all ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19162
+CVE-2026-19162 (Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 all ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19163
+CVE-2026-19163 (Use after free in Media in Google Chrome on Windows prior to 151.0.792 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19164
+CVE-2026-19164 (Insufficient validation of untrusted input in Codecs in Google Chrome ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19165
+CVE-2026-19165 (Use after free in Extensions in Google Chrome prior to 151.0.7922.109 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19166
+CVE-2026-19166 (Use after free in Web Authentication in Google Chrome prior to 151.0.7 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19167
+CVE-2026-19167 (Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allow ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19171
+CVE-2026-19171 (Use after free in Media in Google Chrome on Windows prior to 151.0.792 ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19173
+CVE-2026-19173 (Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 a ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19174
+CVE-2026-19174 (Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowe ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19175
+CVE-2026-19175 (Use after free in Payments in Google Chrome prior to 151.0.7922.109 al ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19176
+CVE-2026-19176 (Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowe ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19177
+CVE-2026-19177 (Insufficient validation of untrusted input in UI in Google Chrome prio ...)
- chromium <unfixed>
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-61477
@@ -393,7 +841,8 @@ CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 ver
CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...)
- apr-util <unfixed> (bug #1143837)
NOTE: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
-CVE-2026-28183 (Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 ver ...)
+CVE-2026-28183
+ REJECTED
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28180 (Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pa ...)
NOT-FOR-US: WordPress plugin or theme
@@ -538,7 +987,7 @@ CVE-2023-7354
REJECTED
CVE-2023-7353
REJECTED
-CVE-2026-68480 [x86/bugs: Make Safe-RET robust against interrupt injection]
+CVE-2026-68480 (In the Linux kernel, the following vulnerability has been resolved: x ...)
- linux 7.1.7-1
NOTE: https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf
CVE-2026-52682 [A crafted DNS packet can cause increased memory and CPU consumption]
@@ -782,7 +1231,7 @@ CVE-2026-19025 (H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not
- hdf5 <unfixed> (unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/6491
NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
-CVE-2026-19024 (NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 all ...)
+CVE-2026-19024 (NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 all ...)
- hdf5 <unfixed> (unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/6487
NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
@@ -979,7 +1428,7 @@ CVE-2026-8029 (The ZTE Smart Life app contains an SQL injection vulnerability th
NOT-FOR-US: ZTE
CVE-2026-7869 (IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal ...)
NOT-FOR-US: IBM
-CVE-2026-7867 [Local privilege escalation via as-user mount spoofing]
+CVE-2026-7867 (A flaw was found in udisks2. A local attacker with an active console s ...)
{DSA-6414-1}
- udisks2 2.11.2-1
[bookworm] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not affected)
@@ -7159,7 +7608,7 @@ CVE-2026-15344 (The WP Photo Album Plus plugin for WordPress is vulnerable to ge
NOT-FOR-US: WordPress plugin
CVE-2026-15328 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
NOT-FOR-US: IBM
-CVE-2026-15325 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+CVE-2026-15325 (IBM WebSphere Application Server and IBM WebSphere Application Server ...)
NOT-FOR-US: IBM
CVE-2026-15280 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 N ...)
NOT-FOR-US: IBM
@@ -10386,6 +10835,7 @@ CVE-2026-64257 (In the Linux kernel, the following vulnerability has been resolv
- linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8986c932905ea508d66da421eb2eb6e676ace1fe (7.2-rc4)
CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...)
+ {DLA-4722-1}
- redis <unfixed>
NOTE: Fixed by: https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c (8.6.5)
NOTE: Fixed by: https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf (7.2.15)
@@ -20980,7 +21430,8 @@ CVE-2026-57821 (A SQL Injection vulnerability exists in Apache Fineract's Office
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-56764 (Hono before 4.11.10 contains a timing attack vulnerability in the basi ...)
NOT-FOR-US: Hono
-CVE-2026-56699 (Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index f ...)
+CVE-2026-56699
+ REJECTED
NOT-FOR-US: Wazuh Manager
CVE-2026-56687 (Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Fe ...)
NOT-FOR-US: Dell / EMC
@@ -30938,7 +31389,7 @@ CVE-2026-11806 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0
NOT-FOR-US: IBM
CVE-2026-11794 (The Advanced Form Integration \u2014 Connect Forms to 200+ Apps WordPr ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-11714 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i ...)
+CVE-2026-11714 (IBM WebSphere Application Server Liberty is affected by a server-side ...)
NOT-FOR-US: IBM
CVE-2026-11712 (IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-s ...)
NOT-FOR-US: IBM
@@ -35743,7 +36194,7 @@ CVE-2026-54822 (Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versi
CVE-2026-54821 (Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 ver ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-54679 (jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, ...)
- {DLA-4662-1 DLA-4661-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4661-1}
- jq 1.8.2-1
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx
CVE-2026-54573 (Outline is a service that allows for collaborative documentation. Prio ...)
@@ -46952,7 +47403,7 @@ CVE-2026-11791 (A flaw was found in 389 Directory Server. During schema reload,
- 389-ds-base <unfixed> (bug #1139816)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485414
CVE-2026-49839 (jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` ca ...)
- {DLA-4662-1 DLA-4661-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4661-1}
- jq 1.8.1-8
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm
CVE-2026-44236
@@ -58162,7 +58613,7 @@ CVE-2026-48805 (Twig is a template language for PHP. Prior to 3.27.0, deprecated
[bookworm] - php-twig <ignored> (Minor issue, too intrusive to backport)
NOTE: https://symfony.com/blog/cve-2026-48805-sandbox-state-regression-in-deprecated-internal-wrappers-in-src-resources-core-php
CVE-2026-47770 (jq is a command-line JSON processor. Prior to 1.8.2, comparing two suf ...)
- {DLA-4662-1 DLA-4661-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4661-1}
- jq 1.8.1-7
NOTE: https://github.com/jqlang/jq/commit/7122866869960b55cea3646bc91334ef55787831
NOTE: https://github.com/jqlang/jq/pull/3539
@@ -68462,7 +68913,7 @@ CVE-2026-44992 (OpenClaw versions 2026.4.5 before 2026.4.20 contain an environme
CVE-2026-44991 (OpenClaw before 2026.4.21 contains an authorization bypass vulnerabili ...)
NOT-FOR-US: OpenClaw
CVE-2026-44777 (jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordi ...)
- {DLA-4662-1 DLA-4599-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9
CVE-2026-44738 (Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandb ...)
@@ -68502,15 +68953,15 @@ CVE-2026-43968 (Improper Neutralization of CRLF Sequences ('CRLF Injection') vul
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-43968
NOTE: https://github.com/ninenines/cowlib/commit/6165fc40efa159ba1cceee7e7981e790acba5d9c
CVE-2026-43896 (jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded r ...)
- {DLA-4662-1 DLA-4599-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846
CVE-2026-43895 (jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts ...)
- {DLA-4662-1 DLA-4599-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr
CVE-2026-43894 (jq is a command-line JSON processor. In 1.8.1 and earlier, when decNum ...)
- {DLA-4662-1 DLA-4661-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4661-1}
- jq 1.8.1-6 (bug #1136445)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g
CVE-2026-43826 (The OpenSearch logging provider, when configured with a `host` URL tha ...)
@@ -68585,11 +69036,11 @@ CVE-2026-41951 (Path traversal vulnerability exists in GROWI v7.5.0 and earlier,
CVE-2026-41431 (Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a ...)
NOT-FOR-US: Zen
CVE-2026-41257 (jq is a command-line JSON processor. In 1.8.1 and earlier, the jq byte ...)
- {DLA-4662-1 DLA-4599-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539
CVE-2026-41256 (jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level j ...)
- {DLA-4662-1 DLA-4599-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg
CVE-2026-41250 (Taiga is a project management platform for startups and agile develope ...)
@@ -68599,6 +69050,7 @@ CVE-2026-41018 (The Elasticsearch logging provider, when configured with a `host
CVE-2026-40636 (Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale version ...)
NOT-FOR-US: Dell / EMC
CVE-2026-40612 (jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains ...)
+ {DSA-6416-1}
- jq 1.8.1-6 (bug #1136445; unimportant)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j
NOTE: Crash in CLI tool, no security impact
@@ -85819,7 +86271,7 @@ CVE-2026-33555 (An issue was discovered in HAProxy before 3.3.6. The HTTP/3 pars
NOTE: Fixed by: https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=425b969d6ea4114f4ae260f57802c65ccafc319c (v3.0.19)
NOTE: Fixed by: https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=3d8388d089170f8544c4a43bf0575f296c885f94 (v2.6.25)
CVE-2026-32316 (jq is a command-line JSON processor. An integer overflow vulnerability ...)
- {DLA-4662-1 DLA-4599-1}
+ {DSA-6416-1 DLA-4662-1 DLA-4599-1}
- jq 1.8.1-5 (bug #1133921)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-q3h9-m34w-h76f
NOTE: Fixed by: https://github.com/jqlang/jq/commit/e47e56d226519635768e6aab2f38f0ab037c09e5 (jq-1.8.2rc1)
@@ -239513,6 +239965,7 @@ CVE-2025-0719 (IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerabl
CVE-2024-6810 (The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross- ...)
NOT-FOR-US: WordPress plugin
CVE-2024-53427 (decNumberCopy in decNumber.c in jq through 1.7.1 does not properly con ...)
+ {DSA-6416-1}
- jq 1.7.1-5 (bug #1102679)
[bookworm] - jq <not-affected> (Vulnerable code introduced later)
[bullseye] - jq <not-affected> (Vulnerable code introduced later)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd9ca69ba2bdb3600850ac17317469902de16219
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd9ca69ba2bdb3600850ac17317469902de16219
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/4511ebe1/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list