[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 8 10:05:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1bc82dc8 by Salvatore Bonaccorso at 2026-08-08T11:03:45+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -172,13 +172,13 @@ CVE-2026-66808
 CVE-2026-9169 (DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on ...)
 	NOT-FOR-US: LUCID Vision Labs Arena SDK
 CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
-	- pypdf <unfixed>
+	- pypdf <unfixed> (bug #1143902)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
 	NOTE: https://github.com/py-pdf/pypdf/pull/3944
 	NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/afba8080e19d29a3c256a742b340995e695b35aa (6.15.0)
 CVE-2026-71852 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
-	- pypdf <unfixed>
+	- pypdf <unfixed> (bug #1143902)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42
 	NOTE: https://github.com/py-pdf/pypdf/pull/3946
@@ -203,16 +203,16 @@ CVE-2026-71559 (Deserialization of Untrusted Data vulnerability in the Go implem
 CVE-2026-71558 (Heap type confusion vulnerability in Apache Fory C++ deserialization.  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71557 (go-git is an extensible git implementation library written in pure Go. ...)
-	- golang-github-go-git-go-git-v6 <unfixed>
-	- golang-github-go-git-go-git <unfixed>
+	- golang-github-go-git-go-git-v6 <unfixed> (bug #1143904)
+	- golang-github-go-git-go-git <unfixed> (bug #1143903)
 	NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j
 	NOTE: https://github.com/go-git/go-git/pull/2247
 	NOTE: Fixed by (merge): https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36 (v6.0.0-alpha.5)
 	NOTE: https://github.com/go-git/go-git/pull/2254
 	NOTE: Fixed by (merge): https://github.com/go-git/go-git/commit/4a0e66d555de5f9a30c31e2df64f445f42bd01e7 (v5.19.2)
 CVE-2026-71556 (go-git is an extensible git implementation library written in pure Go. ...)
-	- golang-github-go-git-go-git-v6 <unfixed>
-	- golang-github-go-git-go-git <unfixed>
+	- golang-github-go-git-go-git-v6 <unfixed> (bug #1143904)
+	- golang-github-go-git-go-git <unfixed> (bug #1143903)
 	NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm
 	NOTE: Fixed by: https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac (v6.0.0-alpha.5)
 	NOTE: Fixed by: https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab (v5.19.2)
@@ -451,18 +451,18 @@ CVE-2026-7405 (A maliciously crafted TIF file, when parsed through certain Autod
 CVE-2026-71555 (PILOS (Platform for Interactive Live-Online Seminars) is a frontend fo ...)
 	NOT-FOR-US: PILOS (Platform for Interactive Live-Online Seminars)
 CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...)
-	- python-h2 <unfixed>
+	- python-h2 <unfixed> (bug #1143905)
 	NOTE: https://github.com/python-hyper/h2/security/advisories/GHSA-6hr6-w5qg-qmwg
 	NOTE: Fixed by: https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6 (4.4.1)
 CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting vulnerability cau ...)
 	NOT-FOR-US: CTI-Transmute
 CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
-	- node-re2 <unfixed>
+	- node-re2 <unfixed> (bug #1143901)
 	NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg
 	NOTE: https://github.com/uhop/node-re2/issues/272
 	NOTE: Fixed by: https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4 (1.26.1)
 CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1.14.3  ...)
-	- jsoup <unfixed>
+	- jsoup <unfixed> (bug #1143906)
 	NOTE: https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8
 	NOTE: https://github.com/jhy/jsoup/issues/2538
 	NOTE: Fixed by: https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70 (jsoup-1.23.1)
@@ -479,22 +479,22 @@ CVE-2026-71446 (AIL Framework contains a stored cross-site scripting vulnerabili
 CVE-2026-71445 (AIL Framework contained a reflected cross-site scripting vulnerability ...)
 	NOT-FOR-US: AIL framework
 CVE-2026-71439 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1143907)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e (mermaid at 11.16.1)
 	TODO: check introducing commit, might then be only 11.6.0 and above.
 CVE-2026-71438 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1143907)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43 (mermaid at 11.16.1)
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956 (v10.9.7)
 CVE-2026-71437 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1143907)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf (mermaid at 11.16.1)
 	TODO: check introducing commit for further assessment
 CVE-2026-71436 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1143907)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289 (mermaid at 11.16.1)
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a (v10.9.7)
@@ -505,7 +505,7 @@ CVE-2026-71434 (Statamic is a Laravel and Git powered content management system
 CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres a ...)
 	NOT-FOR-US: LangGraph Checkpoint
 CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
-	- node-re2 <unfixed>
+	- node-re2 <unfixed> (bug #1143901)
 	NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp
 CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
 	- traefik <itp> (bug #983289)
@@ -682,7 +682,7 @@ CVE-2026-50515 (Deserialization of untrusted data in Azure Service Bus allows an
 CVE-2026-50481 (Modification of assumed-immutable data (maid) in Azure Active Director ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-50159 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1143907)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed (mermaid at 11.16.1)
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e (v10.9.7)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1bc82dc8a73837973059c073de91d3ee77672f2c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1bc82dc8a73837973059c073de91d3ee77672f2c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/509bf843/attachment.htm>


More information about the debian-security-tracker-commits mailing list