[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 10 18:05:41 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
da2bd0df by Moritz Muehlenhoff at 2026-08-10T17:05:08+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1825,6 +1825,7 @@ CVE-2026-12570 (A vulnerability in keras-team/keras versions <= 3.15.0 allows fo
[bullseye] - keras <end-of-life> (EOL in bullseye LTS)
CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk ...)
- nltk <unfixed>
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513003
CVE-2026-70395 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
NOT-FOR-US: ash-project ash
@@ -5129,6 +5130,7 @@ CVE-2026-69098 (kotaemon through 0.12.0 contains an insecure deserialization vul
NOT-FOR-US: kotaemon
CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in the PAM ...)
- sssd <unfixed> (bug #1143947)
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509760
CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 ...)
- jackson-core <not-affected> (Incomplete fix for CVE-2026-18401 not applied)
@@ -5461,6 +5463,7 @@ CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context up
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function ...)
- sssd <unfixed> (bug #1143600)
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509761
CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers ...)
NOT-FOR-US: NASA cFS
@@ -5794,8 +5797,8 @@ CVE-2026-68869
REJECTED
CVE-2026-68742 (A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function i ...)
- sssd <unfixed> (bug #1143600)
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509762
- TODO: check upstream status
CVE-2026-68587 (SiYuan versions before v3.7.3 contain an information disclosure vulner ...)
NOT-FOR-US: SiYuan
CVE-2026-68586 (SiYuan before v3.7.3 fails to apply publish-access filters to the getB ...)
@@ -9779,6 +9782,7 @@ CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion lea
NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...)
- node-postcss 8.5.15+~cs9.3.39-1
+ [trixie] - node-postcss <no-dsa> (Minor issue)
- node-mocha 9.1.4+ds1+~cs28.2.8-1
[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
NOTE: node-postcss bundles nanoid
@@ -9786,6 +9790,7 @@ CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the
NOTE: Fixed by: https://github.com/ai/nanoid/commit/6de05d794f62eeac3f527c74c34c6af0c1d32e49 (5.1.16)
CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...)
- node-postcss 8.5.8+~cs9.3.30-1
+ [trixie] - node-postcss <no-dsa> (Minor issue)
- node-mocha 9.1.4+ds1+~cs28.2.8-1
[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
NOTE: node-postcss bundles nanoid
@@ -13785,6 +13790,7 @@ CVE-2026-66374 (Knot Resolver before 6.4.1 allows remote code execution via a he
[bullseye] - knot-resolver <not-affected> (Vulnerable code not present, quic support added in 6.2)
NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
NOTE: https://github.com/venglin/knot-doq
+ NOTE: https://lists.nic.cz/hyperkitty/list/knot-resolver-announce@lists.nic.cz/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
CVE-2026-9765 (Note: The CVE and blog post don't exist because we determined this is ...)
NOT-FOR-US: Grafana
CVE-2026-8789 (The Easy Appointments plugin for WordPress is vulnerable to unauthoriz ...)
@@ -14135,6 +14141,7 @@ CVE-2026-64208 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/2b50aceafe6606ea52ed42aadd1b4d44a188aade (7.1-rc5)
CVE-2026-63317 (Arbitrary Class Instantiation via XML Feature Generator Descriptor and ...)
- apache-opennlp <unfixed> (bug #1142855)
+ [trixie] - apache-opennlp <no-dsa> (Minor issue)
[bookworm] - apache-opennlp <postponed> (minor issue)
[bullseye] - apache-opennlp <postponed> (minor issue)
NOTE: https://lists.apache.org/thread/myr446n8t3gv8gq8wbpxm41olx16d8yj
@@ -14500,10 +14507,6 @@ CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected b
NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerabl ...)
NOT-FOR-US: Cal.com (calcom/cal.diy)
-CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
- - knot-resolver 6.4.1-1
- NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
- NOTE: https://lists.nic.cz/hyperkitty/list/knot-resolver-announce@lists.nic.cz/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious bootc cont ...)
- ironic-python-agent 11.5.0-4 (bug #1142854)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
@@ -15564,6 +15567,7 @@ CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId creation
NOT-FOR-US: Cal.com OSS
CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth authori ...)
- librest <unfixed> (bug #1142715)
+ [trixie] - librest <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2504432
NOTE: https://gitlab.gnome.org/GNOME/librest/-/issues/25
CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
@@ -19469,6 +19473,7 @@ CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG ima
NOTE: https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 (2.2.0)
CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of Service via de ...)
- libnet-dns-perl 1.56-1 (bug #1142503)
+ [trixie] - libnet-dns-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/
NOTE: https://rt.cpan.org/Ticket/Display.html?id=179946
CVE-2026-64193 (Net::DNS versions through 1.55 for Perl allow remote execution injecti ...)
@@ -19665,6 +19670,7 @@ CVE-2026-40187 (In egroupware version 26.0 and earlier, an authenticated adminis
- egroupware <removed>
CVE-2026-39879 (Due to a missing sanitization call in [`afsql_dd_run_query`](https://g ...)
- syslog-ng <unfixed> (bug #1143061)
+ [trixie] - syslog-ng <no-dsa> (Minor issue)
[bookworm] - syslog-ng <postponed> (Minor issue)
[bullseye] - syslog-ng <postponed> (Minor issue)
NOTE: https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-qwf9-6222-m24m
@@ -23043,6 +23049,7 @@ CVE-2026-45162 (Pimcore is an Open Source Data & Experience Management Platform.
NOT-FOR-US: Pimcore
CVE-2026-44722 (pyzipper is a replacement for Python's zipfile that can read and write ...)
- python-pyzipper <unfixed> (bug #1142473)
+ [trixie] - python-pyzipper <no-dsa> (Minor issue)
NOTE: https://github.com/danifus/pyzipper/security/advisories/GHSA-crqm-m339-7m2p
NOTE: Fixed by; https://github.com/danifus/pyzipper/commit/93ce88e7dfd1635443197dab3fb8d477cff579ae (v0.4.0)
CVE-2026-22104 (Improper access control in Hashtopolis server web-interface chunk acti ...)
@@ -26207,6 +26214,7 @@ CVE-2026-47767 (Symfony is a PHP framework for web and console applications and
NOTE: https://github.com/symfony/symfony/commit/3228c3806ee511008bea19a95084d460b17e5d25 (v5.4.52, v6.4.40, v7.4.12, v8.0.12)
CVE-2026-47737 (Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until ...)
- puma 8.0.2-1
+ [trixie] - puma <no-dsa> (Minor issue)
NOTE: https://github.com/puma/puma/security/advisories/GHSA-2vqw-3mp8-cgmx
NOTE: https://github.com/puma/puma/pull/3944
NOTE: https://github.com/puma/puma/pull/3947
@@ -26214,6 +26222,7 @@ CVE-2026-47737 (Puma is a Ruby/Rack web server built for parallelism. From 5.5.0
NOTE: https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58 (v7.2.1)
CVE-2026-47736 (Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until ...)
- puma 8.0.2-1
+ [trixie] - puma <no-dsa> (Minor issue)
NOTE: https://github.com/puma/puma/security/advisories/GHSA-qpgp-93vx-g8v8
NOTE: https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f (v8.0.2)
NOTE: https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58 (v7.2.1)
@@ -26664,6 +26673,7 @@ CVE-2026-42491
NOTE: https://xenbits.xen.org/xsa/advisory-498.html
CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a stable re ...)
- libmojolicious-perl 9.48+dfsg-1
+ [trixie] - libmojolicious-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41816171/
NOTE: Fixed by: https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27 (v9.48)
CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the table file ...)
@@ -26987,12 +26997,10 @@ CVE-2026-61462 (mcp-gitlab contains a path traversal vulnerability in the job_id
CVE-2026-60121 (Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection ...)
NOT-FOR-US: Vitec Flamingo
CVE-2026-60103 (Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerabili ...)
- - blender <unfixed> (bug #1143049)
- [trixie] - blender <no-dsa> (Minor issue)
- [bookworm] - blender <postponed> (Minor issue, OOB read)
- [bullseye] - blender <postponed> (Minor issue, OOB read)
+ - blender <unfixed> (bug #1143049; unimportant)
NOTE: https://projects.blender.org/blender/blender/pulls/161273
NOTE: Fixed by: https://projects.blender.org/blender/blender/commit/968972a918b5ed2d534295b639c54449d7de11cd
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-59523 (Missing Authorization vulnerability in NSquared Simply Schedule Appoin ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-59521 (Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Re ...)
@@ -27932,6 +27940,7 @@ CVE-2026-4661 (The WP CTA \u2013 Sticky CTA Builder, Generate Leads, Promote Sal
NOT-FOR-US: WordPress plugin
CVE-2026-49844 (Improper encoding of non-finite floating-point values during MapMessag ...)
- apache-log4j2 <unfixed> (bug #1141960)
+ [trixie] - apache-log4j2 <no-dsa> (Minor issue)
NOTE: https://logging.apache.org/security.html#CVE-2026-49844
NOTE: https://github.com/apache/logging-log4j2/pull/4163
NOTE: Fixed by: https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300 (2.x branch)
@@ -264265,6 +264274,7 @@ CVE-2024-52046 (The ObjectSerializationDecoder in Apache MINA uses Java\u2019s n
[bookworm] - mina <no-dsa> (Minor issue)
[bullseye] - mina <postponed> (Minor issue; need specific conditions)
- mina2 2.2.9-1 (bug #1091530)
+ [trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <no-dsa> (Minor issue)
[bullseye] - mina2 <postponed> (Minor issue; need specific conditions)
NOTE: https://lists.apache.org/thread/4wxktgjpggdbto15d515wdctohb0qmv8
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da2bd0df13d9e2cca7613b647069548ca9395084
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da2bd0df13d9e2cca7613b647069548ca9395084
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/33c744e1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list