[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 10 18:08:56 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4211d9dd by Moritz Muehlenhoff at 2026-08-10T18:56:26+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -7249,12 +7249,14 @@ CVE-2026-68500 (Sylius Mollie Plugin provides Mollie payment integration for Syl
NOT-FOR-US: Sylius Mollie Plugin
CVE-2026-68499 (re2 provides Node.js bindings for Google's RE2 regular expression engi ...)
- node-re2 1.26.1+~cs1.7.0-1 (bug #1143179)
+ [trixie] - node-re2 <no-dsa> (Minor issue)
NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836
NOTE: Fixed by: https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d (1.25.2)
CVE-2026-67594 (Spikster through commit e1cdf8c contains a missing authentication vuln ...)
NOT-FOR-US: Spikster
CVE-2026-67550 (re2 provides Node.js bindings for Google's RE2 regular expression engi ...)
- node-re2 1.26.1+~cs1.7.0-1 (bug #1143179)
+ [trixie] - node-re2 <no-dsa> (Minor issue)
NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-ff84-5f28-78qj
NOTE: Fixed by: https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d (1.25.2)
CVE-2026-67530 (WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earli ...)
@@ -7368,12 +7370,14 @@ CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with a
NOT-FOR-US: ComfyUI
CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess <unfixed> (bug #1143181)
+ [trixie] - goaccess <no-dsa> (Minor issue)
[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg
NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81 (v1.11)
CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess <unfixed> (bug #1143181)
+ [trixie] - goaccess <no-dsa> (Minor issue)
[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46
@@ -7390,6 +7394,7 @@ CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. P
NOT-FOR-US: Cloudreve
CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess <unfixed> (bug #1143181)
+ [trixie] - goaccess <no-dsa> (Minor issue)
[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr
@@ -7831,6 +7836,7 @@ CVE-2026-60074 (Date::Manip versions through 6.99 for Perl return corrupted date
NOTE: https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch
CVE-2026-53587
- libgit2 1.9.6+ds-1
+ [trixie] - libgit2 <no-dsa> (Minor issue)
NOTE: https://github.com/libgit2/libgit2/security/advisories/GHSA-pm24-4jhq-3xvm
NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/affda60c10fcef16723451c0d7dc71b71dc20ad3 (v1.9.5)
CVE-2026-53586
@@ -10072,9 +10078,11 @@ CVE-2026-4604 (The Klubraum Membership Request plugin for WordPress is vulnerabl
NOT-FOR-US: WordPress plugin
CVE-2026-44944 (An Incorrect Authorization vulnerability in open-iscsi allowsunprivili ...)
- open-iscsi 2.1.12-1 (bug #1143059)
+ [trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e (2.1.12)
CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory ('Path ...)
- open-iscsi 2.1.12-1 (bug #1143059)
+ [trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e (2.1.12)
CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vuln ...)
NOT-FOR-US: Care Everywhere Gateway
@@ -26685,16 +26693,19 @@ CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a sta
NOTE: Fixed by: https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27 (v9.48)
CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the table file ...)
- libdbi-perl 1.651-1 (bug #1142072)
+ [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813967/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728 (1.651)
CVE-2026-60082 (DBI versions before 1.651 for Perl do not enforce statement handle con ...)
- libdbi-perl 1.651-1 (bug #1142072)
+ [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813803/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2 (1.651)
CVE-2026-60081 (DBI::ProfileData versions before 1.651 for Perl do not limit the path ...)
- libdbi-perl 1.651-1 (bug #1142072)
+ [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813962/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ww49-w4mv-jrr4
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/6764e755e83ee1ebb1b40760e5b53eb50960bd7a (1.651)
@@ -28544,6 +28555,7 @@ CVE-2026-59832 (SiYuan is an open-source personal knowledge management system. P
NOT-FOR-US: SiYuan
CVE-2026-59831 (GitHub CLI (gh) is GitHub\u2019s official command line tool. From 2.10 ...)
- gh <unfixed>
+ [trixie] - gh <no-dsa> (Minor issue)
NOTE: https://github.com/cli/cli/security/advisories/GHSA-8cg3-r6g9-fpg2
NOTE: Fixed by: https://github.com/cli/cli/commit/b300f2ec7ec9dc9addc39b2ad88c54097ded7ca0 (v2.96.0)
CVE-2026-59828 (Discourse is an open-source discussion platform. Prior to 2026.6.0, 20 ...)
@@ -29398,6 +29410,7 @@ CVE-2026-54772 (CoreWCF is a port of the service side of Windows Communication F
NOT-FOR-US: CoreWCF
CVE-2026-54591 (AsyncSSH is a Python package which provides an asynchronous client and ...)
- python-asyncssh <unfixed> (bug #1141818)
+ [trixie] - python-asyncssh <no-dsa> (Minor issue)
NOTE: https://github.com/ronf/asyncssh/security/advisories/GHSA-2wxc-x7rj-hg8f
NOTE: Fixed by: https://github.com/ronf/asyncssh/commit/d730803b8e4e94c20c7580d90f94d1e05f9f58de (v2.23.1)
CVE-2026-54590 (AsyncSSH is a Python package which provides an asynchronous client and ...)
@@ -29409,6 +29422,7 @@ CVE-2026-54590 (AsyncSSH is a Python package which provides an asynchronous clie
NOTE: Fixed by: https://github.com/ronf/asyncssh/commit/3d515ba9ba0cd9990d248bdf62bcf05d51261a88 (v2.23.1)
CVE-2026-45309 (AsyncSSH is a Python package which provides an asynchronous client and ...)
- python-asyncssh 2.23.0-1
+ [trixie] - python-asyncssh <no-dsa> (Minor issue)
NOTE: https://github.com/advisories/GHSA-g794-3fmp-753h
NOTE: Fixed by: https://github.com/ronf/asyncssh/commit/2af2382cce946c959a378a62f257af253dc4ab51 (v2.23.0)
NOTE: When fixing this issue for older versions make sure to fix the issue and not
@@ -30148,6 +30162,7 @@ CVE-2026-15044 (A flaw was found in the TrustyAI Service Operator. When deployin
NOT-FOR-US: TrustyAI Service Operator
CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted ...)
- libdbi-perl 1.651-1 (bug #1142072)
+ [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41805128/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d (1.651)
=====================================
data/dsa-needed.txt
=====================================
@@ -63,6 +63,8 @@ jupyterlab
--
kamailio
--
+libde265
+--
librabbitmq
Florian Ernst is preparing updates
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4211d9dd074bdcf7ebb91d7382065c2c5866e2b3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4211d9dd074bdcf7ebb91d7382065c2c5866e2b3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/c09e7c86/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list