[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 10 11:11:39 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0eb0c0cb by Moritz Muehlenhoff at 2026-08-10T11:02:57+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -609,6 +609,7 @@ CVE-2026-71558 (Heap type confusion vulnerability in Apache Fory C++ deserializa
CVE-2026-71557 (go-git is an extensible git implementation library written in pure Go. ...)
- golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
- golang-github-go-git-go-git <unfixed> (bug #1143903)
+ [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j
NOTE: https://github.com/go-git/go-git/pull/2247
NOTE: Fixed by (merge): https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36 (v6.0.0-alpha.5)
@@ -617,6 +618,7 @@ CVE-2026-71557 (go-git is an extensible git implementation library written in pu
CVE-2026-71556 (go-git is an extensible git implementation library written in pure Go. ...)
- golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
- golang-github-go-git-go-git <unfixed> (bug #1143903)
+ [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm
NOTE: Fixed by: https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac (v6.0.0-alpha.5)
NOTE: Fixed by: https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab (v5.19.2)
@@ -3726,12 +3728,14 @@ CVE-2026-69247 (cryptography is a package designed to expose cryptographic primi
CVE-2026-69246 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...)
[experimental] - guzzle 8.0.1-1
- guzzle 7.15.2-1 (bug #1143595)
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33
NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...)
[experimental] - guzzle 8.0.1-1
- guzzle 7.15.2-1 (bug #1143595)
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r
NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
@@ -4144,6 +4148,7 @@ CVE-2026-61523 (WebsiteBaker CMS before 2.13.10 contains a code injection vulner
NOT-FOR-US: WebsiteBaker CMS
CVE-2026-61372 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
- apache-jena <unfixed> (bug #1143599)
+ [trixie] - apache-jena <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/h206tpxtbzts7m254og6ffqljjdjkm84
CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly a ...)
NOT-FOR-US: Sharp and Toshiba Tec MFPs
@@ -4686,12 +4691,15 @@ CVE-2026-6453 (The CubeWP Framework plugin for WordPress is vulnerable to SQL In
NOT-FOR-US: WordPress plugin
CVE-2026-67355 (guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...)
- guzzle 7.15.1-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577
CVE-2026-67354 (guzzlehttp/guzzle versions before 7.15.1 contain an information disclo ...)
- guzzle 7.15.1-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8
CVE-2026-67353 (guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...)
- guzzle 7.15.1-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79
CVE-2026-67352 (luci-app-https-dns-proxy contains a stored cross-site scripting vulner ...)
NOT-FOR-US: luci-app-https-dns-proxy
@@ -4707,6 +4715,7 @@ CVE-2026-67340 (ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts
NOT-FOR-US: ArcadeDB
CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...)
- guzzle 7.14.2-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
- jupyterlab <unfixed>
@@ -12698,6 +12707,7 @@ CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext
NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability ...)
- knot 3.5.4-1
+ [trixie] - knot <no-dsa> (Minor issue)
[bookworm] - knot <postponed> (Minor issue)
[bullseye] - knot <postponed> (Minor issue)
NOTE: https://www.knot-dns.cz/2026-04-01-version-3410.html
@@ -17760,13 +17770,16 @@ CVE-2026-64620 (FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc
CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG image rea ...)
- libcupsfilters <unfixed> (bug #1142687)
+ [trixie] - libcupsfilters <no-dsa> (Minor issue)
[bookworm] - libcupsfilters <postponed> (Minor issue)
[bullseye] - libcupsfilters <postponed> (Minor issue)
- cups-filters <unfixed>
+ [trixie] - cups-filters <no-dsa> (Minor issue)
[bookworm] - cups-filters <postponed> (Minor issue)
[bullseye] - cups-filters <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502801
- NOTE: https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch (not public)
+ NOTE: https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
+ NOTE: https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 (2.2.0)
CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of Service via de ...)
- libnet-dns-perl 1.56-1 (bug #1142503)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eb0c0cb4f7aed9d850e5ea9347b8434fc65526a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eb0c0cb4f7aed9d850e5ea9347b8434fc65526a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/13266901/attachment.htm>
More information about the debian-security-tracker-commits
mailing list