[Git][security-tracker-team/security-tracker][master] Add two node-re2 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 7 08:48:21 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
45d19dbb by Salvatore Bonaccorso at 2026-08-07T09:47:51+02:00
Add two node-re2 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13,7 +13,10 @@ CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. V
CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting vulnerability cau ...)
NOT-FOR-US: CTI-Transmute
CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
- TODO: check
+ - node-re2 <unfixed>
+ NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg
+ NOTE: https://github.com/uhop/node-re2/issues/272
+ NOTE: Fixed by: https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4 (1.26.1)
CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1.14.3 ...)
TODO: check
CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
@@ -43,7 +46,8 @@ CVE-2026-71434 (Statamic is a Laravel and Git powered content management system
CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres a ...)
NOT-FOR-US: LangGraph Checkpoint
CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
- TODO: check
+ - node-re2 <unfixed>
+ NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp
CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
TODO: check
CVE-2026-71326 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45d19dbbc6d294c60dc5a35f83ec5c26dfa34c39
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45d19dbbc6d294c60dc5a35f83ec5c26dfa34c39
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/6e2c5f18/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list