[Git][security-tracker-team/security-tracker][master] lts: drop starlette from dla-needed and mark all CVEs is Bullseye as ignored
Daniel Leidert (@dleidert)
dleidert at debian.org
Sat Aug 8 22:41:39 BST 2026
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker
Commits:
75870980 by Daniel Leidert at 2026-08-08T23:40:36+02:00
lts: drop starlette from dla-needed and mark all CVEs is Bullseye as ignored
Bullseye requires an intrusive backport and no customer has expressed interest.
Dropping starlette/bullseye from dla-needed and marking all issues in Bullseye
as ignored.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -41212,12 +41212,14 @@ CVE-2026-54285 (opentelemetry-js is the OpenTelemetry JavaScript Client. Prior t
CVE-2026-54283 (Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1. ...)
{DLA-4711-1}
- starlette 1.3.1-1 (bug #1140631)
+ [bullseye] - starlette <ignored> (Minor issue; requires intrusive backport for CVE-2023-30798)
NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
NOTE: https://github.com/Kludex/starlette/pull/3329
NOTE: Fixed by: https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735 (1.3.1)
CVE-2026-54282 (Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the ...)
{DLA-4711-1}
- starlette 1.3.1-1 (bug #1140632)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3
NOTE: https://github.com/Kludex/starlette/pull/3326
NOTE: Fixed by: https://github.com/Kludex/starlette/commit/167b5850e809f38b27fbfed62d58bf6442855975 (1.3.0)
@@ -42838,6 +42840,7 @@ CVE-2026-48817 (Starlette is a lightweight ASGI framework/toolkit. In versions 1
{DLA-4711-1}
- starlette 1.1.0-1
[trixie] - starlette <no-dsa> (Minor issue)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c
NOTE: https://github.com/Kludex/starlette/pull/3286
NOTE: https://github.com/Kludex/starlette/commit/e3f972225adb1d84b80dba132f520cc24cb84229 (1.1.0)
@@ -62848,6 +62851,7 @@ CVE-2025-26483 (Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Op
CVE-2026-48710 (Starlette is a lightweight ASGI framework/toolkit. Prior to version 1. ...)
{DSA-6302-1}
- starlette 1.1.0-1 (bug #1137375)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE: https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/
NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr
NOTE: https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6 (1.0.1)
@@ -193765,7 +193769,7 @@ CVE-2025-5681 (Authorization Bypass Through User-Controlled Key vulnerability in
CVE-2025-54121 (Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface ...)
- starlette 0.46.1-3 (bug #1109805)
[bookworm] - starlette 0.26.1-1+deb12u1
- [bullseye] - starlette <postponed> (minor issue; Dos can be fixed in next update)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE: https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73
NOTE: Fixed by: https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1 (0.47.2)
NOTE: https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403
@@ -283227,7 +283231,7 @@ CVE-2024-47876 (Sakai is a Collaboration and Learning Environment. Starting in v
CVE-2024-47874 (Starlette is an Asynchronous Server Gateway Interface (ASGI) framework ...)
- starlette 0.41.0-1 (bug #1085295)
[bookworm] - starlette 0.26.1-1+deb12u1
- [bullseye] - starlette <postponed> (Minor issue; can be fixed in next update)
+ [bullseye] - starlette <ignored> (Minor issue; requires intrusive backport for CVE-2023-30798)
NOTE: https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw
NOTE: https://github.com/encode/starlette/commit/fd038f3070c302bff17ef7d173dbb0b007617733 (0.40.0)
CVE-2024-47824 (matrix-react-sdk is react-based software development kit for inserting ...)
@@ -394176,7 +394180,7 @@ CVE-2023-30758 (Cross-site scripting vulnerability in Pleasanter 1.3.38.1 and ea
CVE-2023-29159 (Directory traversal vulnerability in Starlette versions 0.13.5 and lat ...)
- starlette 0.28.0-1
[bookworm] - starlette 0.26.1-1+deb12u1
- [bullseye] - starlette <no-dsa> (Minor issue)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE: https://github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84px
NOTE: https://github.com/encode/starlette/commit/1797de464124b090f10cf570441e8292936d63e3 (0.27.0)
CVE-2023-29154 (SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) v ...)
@@ -398278,7 +398282,7 @@ CVE-2023-30799 (MikroTik RouterOS stable before 6.49.7 and long-term through 6.4
NOT-FOR-US: MikroTik RouterOS
CVE-2023-30798 (There MultipartParser usage in Encode's Starlette python framework bef ...)
- starlette 0.25.0-1
- [bullseye] - starlette <no-dsa> (Minor issue)
+ [bullseye] - starlette <ignored> (Too intrusive to backport)
NOTE: https://github.com/encode/starlette/commit/8c74c2c8dba7030154f8af18e016136bea1938fa (0.25.0)
NOTE: https://github.com/encode/starlette/security/advisories/GHSA-74m5-2c7w-9w3x
CVE-2023-30797 (Netflix Lemur before version 1.3.2 used insufficiently random values w ...)
=====================================
data/dla-needed.txt
=====================================
@@ -872,12 +872,6 @@ sssd
NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
NOTE: 20260804: SSSD should be tested carefully, with integration test (rouca/FD)
--
-starlette/bullseye (dleidert)
- NOTE: 20260528: Added by Front-Desk (dleidert)
- NOTE: 20260528: follow DSA-6302-1 (dleidert/front-desk)
- NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
- NOTE: 20260801: Bullseye requires a very intrusive patch (CVE-2023-30798) that is the base to fix other CVEs as well (dleidert)
---
strongswan/bullseye
NOTE: 20260423: Added by Front-Desk (pochu)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/758709801c3f463889595dc1b3954f248a0a12cd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/758709801c3f463889595dc1b3954f248a0a12cd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/577b80a1/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list