[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Aug 8 17:01:10 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e9646a48 by Moritz Muehlenhoff at 2026-08-08T18:00:28+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -382,6 +382,7 @@ CVE-2026-19206 (A security flaw has been discovered in MZ Automation libiec61850
NOT-FOR-US: mz-automation libiec61850
CVE-2026-19082 (Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent ...)
- libimager-perl 1.034+dfsg-1
+ [trixie] - libimager-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42492379/
NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-hx46-55wp-hv6m
NOTE: Fixed by: https://github.com/tonycoz/imager/commit/24bde0427a113264d53f45a9c29ae756d84c82fe (v1.034)
@@ -482,6 +483,7 @@ CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. P
NOTE: Fixed by: https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4 (1.26.1)
CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1.14.3 ...)
- jsoup <unfixed> (bug #1143906)
+ [trixie] - jsoup <no-dsa> (Minor issue)
NOTE: https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8
NOTE: https://github.com/jhy/jsoup/issues/2538
NOTE: Fixed by: https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70 (jsoup-1.23.1)
@@ -3174,6 +3176,7 @@ CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up to
NOT-FOR-US: NousResearch
CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source rlottie ...)
- rlottie <unfixed>
+ [trixie] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/596
CVE-2026-18770 (A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d5 ...)
NOT-FOR-US: vibesurf-ai VibeSurf
@@ -3811,6 +3814,7 @@ CVE-2026-15430 (Improper access control in the IRP_MJ_WRITE command interface in
NOT-FOR-US: Wellbia XIGNCODE3
CVE-2026-12259 (In nltk version 3.9.4, the `nltk.downloader.Downloader._download_packa ...)
- nltk <unfixed>
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://huntr.com/bounties/659ccf6d-12d4-4d4a-84c0-078633c35a5d
CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0 retrieve ...)
NOT-FOR-US: Latvijas Valsts radio un televizijas centrs (LVRTC)
@@ -11585,6 +11589,7 @@ CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for WordP
NOT-FOR-US: WordPress plugin
CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...)
- nltk 3.9.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/
NOTE: https://github.com/nltk/nltk/pull/3465
NOTE: Fixed by: https://github.com/nltk/nltk/commit/e373c8c3d10e236672ef65c38ca7d24612941553 (3.9.3)
@@ -16511,13 +16516,17 @@ CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor Temp
NOT-FOR-US: WordPress plugin
CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...)
- libsoup3 <unfixed> (bug #1142838)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/512
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/524
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/commit/7334c38f1f6aa5e64207cb415cf2509838c52b37 (3.7.1)
CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without scopin ...)
- libsoup3 <unfixed> (bug #1142837)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
NOT-FOR-US: zenml
@@ -20410,26 +20419,31 @@ CVE-2026-54497 (view_component is a framework for building reusable, testable, a
NOT-FOR-US: view_component framework
CVE-2026-54490 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- node-websocket-driver <unfixed> (bug #1142415)
+ [trixie] - node-websocket-driver <no-dsa> (Minor issue)
NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-mp7j-qc5w-4988
NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/c55679a5b18251dd0a55d18a0cc6a4fd8822b92f (0.7.5)
CVE-2026-54466 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- node-websocket-driver <unfixed> (bug #1142415)
+ [trixie] - node-websocket-driver <no-dsa> (Minor issue)
NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6
NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680 (0.7.5)
CVE-2026-54465 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- ruby-websocket-driver 0.8.1-1
+ [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
[bookworm] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
[bullseye] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-8j3g-f24p-4mpw
NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/17b569f232896e71d458404ccf4854f80e987710 (0.8.1)
CVE-2026-54464 (### Impact If this library is used in tandem with the `permessage-def ...)
- ruby-websocket-driver 0.8.1-1
+ [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
[bookworm] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
[bullseye] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-33ph-fccm-39pj
NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/fa8641724f10bf3273585f1dcf9041f540bbd036 (0.8.1)
CVE-2026-54463 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- ruby-websocket-driver 0.8.1-1
+ [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
[bookworm] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
[bullseye] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p
@@ -25160,6 +25174,7 @@ CVE-2026-15552 (Enterprise Cloud Database developed by Ragic has a Stored Cross-
NOT-FOR-US: Ragic
CVE-2026-15551 (Integer overflow or wraparound vulnerability in Samsung Open Source rl ...)
- rlottie <unfixed>
+ [trixie] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/595
NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/f487eff2f8086b84ae1c7faa0418abec909e874b
CVE-2026-15539 (A security vulnerability has been detected in SourceCodester Online Bo ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9646a48b4c348ca7498966c82bce70b7751222a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9646a48b4c348ca7498966c82bce70b7751222a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/0f183e13/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list