[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 08:13:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3dc015f0 by security tracker role at 2026-08-11T07:13:33+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,293 @@
+CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Su ...)
+	TODO: check
+CVE-2026-8718 (tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/ ...)
+	TODO: check
+CVE-2026-8158 (The Signed Video Framework contained a buffer overflow issue  which co ...)
+	TODO: check
+CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84, contains a  ...)
+	TODO: check
+CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 contains a path ...)
+	TODO: check
+CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a path trave ...)
+	TODO: check
+CVE-2026-72919 (Rocket.Chat is an open-source, secure, fully customizable communicatio ...)
+	TODO: check
+CVE-2026-72918 (Rocket.Chat is an open-source, secure, fully customizable communicatio ...)
+	TODO: check
+CVE-2026-72917 (AnythingLLM is an application that turns pieces of content into contex ...)
+	TODO: check
+CVE-2026-72916 (Mastodon is a free, open-source social network server based on Activit ...)
+	TODO: check
+CVE-2026-72915 (Mastodon is a free, open-source social network server based on Activit ...)
+	TODO: check
+CVE-2026-72914 (Mastodon is a free, open-source social network server based on Activit ...)
+	TODO: check
+CVE-2026-72913 (Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @ki ...)
+	TODO: check
+CVE-2026-72912 (CyberChef is a web app for encryption, encoding, compression, and data ...)
+	TODO: check
+CVE-2026-72911 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+	TODO: check
+CVE-2026-72910 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+	TODO: check
+CVE-2026-72909 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+	TODO: check
+CVE-2026-72908 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+	TODO: check
+CVE-2026-72907 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+	TODO: check
+CVE-2026-72906 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+	TODO: check
+CVE-2026-72905
+	REJECTED
+CVE-2026-72904 (Firecrawl turns entire websites into LLM-ready markdown or structured  ...)
+	TODO: check
+CVE-2026-72903 (Tabby (formerly Terminus) is a highly configurable terminal emulator.  ...)
+	TODO: check
+CVE-2026-72902 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72901 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72886 (Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0. ...)
+	TODO: check
+CVE-2026-72885 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72884 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72883 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72882 (Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28 ...)
+	TODO: check
+CVE-2026-72881 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72880 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72879 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72878 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72877 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72876 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72875 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72874 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+	TODO: check
+CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cros ...)
+	TODO: check
+CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated c ...)
+	TODO: check
+CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated r ...)
+	TODO: check
+CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) ra ...)
+	TODO: check
+CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost inflight migra ...)
+	TODO: check
+CVE-2026-6181 (The Device Configuration Framework is vulnerable to an authentication  ...)
+	TODO: check
+CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection vulnera ...)
+	TODO: check
+CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering an ...)
+	TODO: check
+CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel message ...)
+	TODO: check
+CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path traversal vulne ...)
+	TODO: check
+CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver App ...)
+	TODO: check
+CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request headers b ...)
+	TODO: check
+CVE-2026-66777 (SAP Approuter does not sufficiently validate certain incoming requests ...)
+	TODO: check
+CVE-2026-66776 (SAP Approuter does not consistently enforce integrity verification on  ...)
+	TODO: check
+CVE-2026-66775 (SAP Approuter does not enforce cross-site request forgery protection o ...)
+	TODO: check
+CVE-2026-66774 (SAP Approuter does not consistently handle certain error conditions. A ...)
+	TODO: check
+CVE-2026-66773 (A malicious or compromised OData service could disclose sensitive auth ...)
+	TODO: check
+CVE-2026-66772 (SAP BusinessObjects Business Intelligence Platform (Admin Tools)  does ...)
+	TODO: check
+CVE-2026-66771 (SAPUI5 allows a key user with content adaptation privileges to inject  ...)
+	TODO: check
+CVE-2026-66770 (Due to an SQL Injection vulnerability in SAP Social intelligence, an a ...)
+	TODO: check
+CVE-2026-66764 (Reprocess Bank Statement Items in SAP S/4HANA does not perform the nec ...)
+	TODO: check
+CVE-2026-66763 (SAP BusinessObjects Business Intelligence Platform stores certain sens ...)
+	TODO: check
+CVE-2026-66761 (SAP Approuter does not enforce sufficient flow control in certain func ...)
+	TODO: check
+CVE-2026-66760 (SAP Approuter does not correctly validate client certificates in certa ...)
+	TODO: check
+CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a process  ...)
+	TODO: check
+CVE-2026-5304 (An ACAP configuration file lacks input validation, which could potenti ...)
+	TODO: check
+CVE-2026-5303 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) ra ...)
+	TODO: check
+CVE-2026-58248 (SAP BusinessObjects Business Intelligence Platform (Web Intelligence)  ...)
+	TODO: check
+CVE-2026-58247 (SAP ABAP Platform allows an unauthenticated user to send a specially c ...)
+	TODO: check
+CVE-2026-58245 (SAP Advanced Planning and Optimization (Model Mix Planning) contains a ...)
+	TODO: check
+CVE-2026-58244 (SAP Manufacturing Integration and Intelligence (MII) does not perform  ...)
+	TODO: check
+CVE-2026-58243 (SAP ABAP Development Tools does not perform necessary authorization ch ...)
+	TODO: check
+CVE-2026-58241 (SAP NetWeaver and ABAP Platform (Change and Transport System - Custome ...)
+	TODO: check
+CVE-2026-58239 (SAP Approuter does not sufficiently validate tenant context in inbound ...)
+	TODO: check
+CVE-2026-58238 (SAP Approuter does not sufficiently handle certain requests under spec ...)
+	TODO: check
+CVE-2026-58237 (WebSocket of SAP Approuter does not perform sufficient authorization c ...)
+	TODO: check
+CVE-2026-58236 (SAP NetWeaver Application Server ABAP and ABAP Platform allow an attac ...)
+	TODO: check
+CVE-2026-58235 (SAP NetWeaver Application Server Java (Adobe Document Service) uses ou ...)
+	TODO: check
+CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token content und ...)
+	TODO: check
+CVE-2026-4757 (A VAPIX API parameter had improper input validation which could allow  ...)
+	TODO: check
+CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 a ...)
+	TODO: check
+CVE-2026-48160 (react-tracked provides state usage tracking with Proxies. Between 2026 ...)
+	TODO: check
+CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
+	TODO: check
+CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
+	TODO: check
+CVE-2026-44763 (SAP Manufacturing Integration and Intelligence allows a privileged att ...)
+	TODO: check
+CVE-2026-44762 (SAP Data Services Management Console allows an overly permissive Conte ...)
+	TODO: check
+CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an attacke ...)
+	TODO: check
+CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site scripting vu ...)
+	TODO: check
+CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in the han ...)
+	TODO: check
+CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an unauthenticated attack ...)
+	TODO: check
+CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker, authenticated as  ...)
+	TODO: check
+CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated as an ad ...)
+	TODO: check
+CVE-2026-19518 (Improper Validation of Specified Quantity in Input vulnerability in Sa ...)
+	TODO: check
+CVE-2026-19517 (Improper Validation of Specified Quantity in Input and Allocation of R ...)
+	TODO: check
+CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the destinatio ...)
+	TODO: check
+CVE-2026-19425 (Travel Agency Management System developed by Win Men Intermational has ...)
+	TODO: check
+CVE-2026-19424 (Chiline Cloud developed by Inventec Appliances has a Insecure Direct O ...)
+	TODO: check
+CVE-2026-19411 (A NULL pointer vulnerability has been found in the the shim applicatio ...)
+	TODO: check
+CVE-2026-19391 (A flaw was found in insights-core where the password redaction layer f ...)
+	TODO: check
+CVE-2026-18982 (A flaw was found in the RHOAI training-operator. This vulnerability al ...)
+	TODO: check
+CVE-2026-18951 (A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the t ...)
+	TODO: check
+CVE-2026-18950 (A flaw was found in odh-dashboard. An authenticated user of the dashbo ...)
+	TODO: check
+CVE-2026-18949 (A flaw was found in odh-dashboard. This vulnerability allows an attack ...)
+	TODO: check
+CVE-2026-18948 (A flaw was found in Feast. The system improperly deserializes user-def ...)
+	TODO: check
+CVE-2026-18947 (A flaw was found in Feast. An authorization bypass vulnerability exist ...)
+	TODO: check
+CVE-2026-18942 (A flaw was found in the Feast operator. A malicious tenant could injec ...)
+	TODO: check
+CVE-2026-18941 (A flaw was found in Feast and feast-operator. The default configuratio ...)
+	TODO: check
+CVE-2026-18621 (A flaw was found in Data Science Pipelines (DSP). An attacker with nam ...)
+	TODO: check
+CVE-2026-18620 (A flaw was found in Data Science Pipelines. A restricted user, or tena ...)
+	TODO: check
+CVE-2026-18618 (A flaw was found in ml-metadata. The statically-linked gRPC stack in m ...)
+	TODO: check
+CVE-2026-18617 (A flaw was found in the Data Science Pipelines Operator (DSPO). A name ...)
+	TODO: check
+CVE-2026-18611 (A flaw was found in the Data Science Pipelines Operator. This vulnerab ...)
+	TODO: check
+CVE-2026-18608 (A flaw was found in the Data Science Pipelines Operator (DSPO). The op ...)
+	TODO: check
+CVE-2026-18348 (Missing authorization check in the upload_azure, upload_sftp, and uplo ...)
+	TODO: check
+CVE-2026-16974 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
+	TODO: check
+CVE-2026-16456 (A flaw was found in the `odh-model-controller`. An authenticated user  ...)
+	TODO: check
+CVE-2026-16053 (Zohocorp ManageEngineM365 Manager Plus and M365 Security Plus versions ...)
+	TODO: check
+CVE-2026-15581 (A flaw was found in the TrustyAI Service (TAS) deployment. This vulner ...)
+	TODO: check
+CVE-2026-15467 (A flaw was found in the trustyai-service-operator's LMEvalJob controll ...)
+	TODO: check
+CVE-2026-14886 (Vault Enterprise's identity entity batch-delete endpoint is vulnerable ...)
+	TODO: check
+CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
+	TODO: check
+CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
+	TODO: check
+CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows any pod wi ...)
+	TODO: check
+CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Imp ...)
+	TODO: check
+CVE-2026-13716 (Path traversal in server import and admin file upload in Crafty Contro ...)
+	TODO: check
+CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm ...)
+	TODO: check
+CVE-2026-12051 (The USB DFU class implementation in Zephyr's new (experimental) device ...)
+	TODO: check
+CVE-2026-11985 (On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces  ...)
+	TODO: check
+CVE-2026-11894 (The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send( ...)
+	TODO: check
+CVE-2026-11893 (The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL6 ...)
+	TODO: check
+CVE-2026-11812 (The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) ...)
+	TODO: check
+CVE-2026-11811 (The UpdateHub over-the-air update client's start_coap_client() in subs ...)
+	TODO: check
+CVE-2026-11810 (The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_ ...)
+	TODO: check
+CVE-2026-11809 (The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains ...)
+	TODO: check
+CVE-2025-32736 (Cross-Site Request Forgery weaknesses in the Administrative Console of ...)
+	TODO: check
+CVE-2025-30241 (Certain web interface components in affected TP-Link Aginet devices do ...)
+	TODO: check
+CVE-2025-30240 (The affected TP-Link Aginet devices do not properly validate symbolic  ...)
+	TODO: check
+CVE-2025-30239 (In affected TP-Link Aginet devices, use of hardcoded cryptographic key ...)
+	TODO: check
+CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization validat ...)
+	TODO: check
+CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web managemen ...)
+	TODO: check
+CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial ...)
+	TODO: check
+CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exh ...)
+	TODO: check
+CVE-2025-15681 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its ...)
+	TODO: check
+CVE-2025-15680 (TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's ...)
+	TODO: check
+CVE-2025-13294 (An unauthenticated SQL injection vulnerability exists in the web serve ...)
+	TODO: check
+CVE-2025-13293 (A hard-coded or default root account credential in TBEA TLogger V2.1.0 ...)
+	TODO: check
 CVE-2026-19349
 	- lemonldap-ng <unfixed>
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d (v2.23.3)
@@ -5818,7 +6108,7 @@ CVE-2026-18774 (A flaw has been found in NousResearch hermes-agent up to 0.16.0.
 	NOT-FOR-US: NousResearch
 CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up to 2026.6 ...)
 	NOT-FOR-US: NousResearch
-CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source rlottie ...)
+CVE-2026-18772 (Improperly controlled sequential memory allocation vulnerability in Sa ...)
 	- rlottie <unfixed> (bug #1143931)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/596
@@ -24318,22 +24608,22 @@ CVE-2023-49899 (An unauthenticated remote attacker canexecute any command on the
 CVE-2019-25764 (**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access C ...)
 	NOT-FOR-US: ASUS
 CVE-2026-57077 (YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read v ...)
-	{DSA-6428-1}
+	{DSA-6428-1 DLA-4730-1}
 	- libyaml-syck-perl 1.47-1 (bug #1142267)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898716/
 	NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
 CVE-2026-57076 (YAML::Syck versions before 1.47 for Perl allow a heap use-after-free v ...)
-	{DSA-6428-1}
+	{DSA-6428-1 DLA-4730-1}
 	- libyaml-syck-perl 1.47-1 (bug #1142267)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898718/
 	NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
 CVE-2026-57075 (YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read v ...)
-	{DSA-6428-1}
+	{DSA-6428-1 DLA-4730-1}
 	- libyaml-syck-perl 1.47-1 (bug #1142267)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898720/
 	NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
 CVE-2026-13713 (YAML::Syck versions before 1.47 for Perl allow a use-after-free and do ...)
-	{DSA-6428-1}
+	{DSA-6428-1 DLA-4730-1}
 	- libyaml-syck-perl 1.47-1 (bug #1142267)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898719/
 	NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
@@ -43322,9 +43612,11 @@ CVE-2026-53753 (Crawl4AI is an open-source LLM friendly web crawler & scraper. P
 CVE-2026-53662 (immich is a high performance self-hosted photo and video management so ...)
 	NOT-FOR-US: immich
 CVE-2026-52846 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
+	{DSA-6429-1}
 	- caddy 2.11.4-1 (bug #1140773)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-vcc4-2c75-vc9v
 CVE-2026-52845 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
+	{DSA-6429-1}
 	- caddy 2.11.4-1 (bug #1140773)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-f59h-q822-g45g
 CVE-2026-52844 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
@@ -43390,6 +43682,7 @@ CVE-2026-48519 (Langflow is a tool for building and deploying AI-powered agents
 CVE-2026-45732 (n8n is an open source workflow automation platform. Prior to 1.123.43, ...)
 	NOT-FOR-US: n8n
 CVE-2026-45692 (Caddy is an extensible server platform that uses TLS by default. From  ...)
+	{DSA-6429-1}
 	- caddy 2.11.4-1 (bug #1140773)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-x5w9-xh9r-mvfc
 CVE-2026-45135 (Caddy is an extensible server platform that uses TLS by default. From  ...)
@@ -71854,7 +72147,7 @@ CVE-2025-54518 (Improper isolation of shared resources within the CPU operation
 	NOTE: https://xenbits.xen.org/xsa/advisory-490.html
 	NOTE: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html
 CVE-2026-5089 (YAML::Syck versions before 1.38 for Perl  has an out-of-bounds read.   ...)
-	{DSA-6428-1}
+	{DSA-6428-1 DLA-4730-1}
 	- libyaml-syck-perl 1.36-3
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/39981051/
 	NOTE: https://github.com/cpan-authors/YAML-Syck/issues/132
@@ -114826,15 +115119,19 @@ CVE-2026-2459 (A vulnerability exists in REB500 for an authenticated user with I
 CVE-2026-27732 (WWBN AVideo is an open source video platform. Prior to version 22.0, t ...)
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-27590 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
+	{DSA-6429-1}
 	- caddy 2.11.2-1 (bug #1132041)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-5r3v-vc8m-m96g
 CVE-2026-27589 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
+	{DSA-6429-1}
 	- caddy 2.11.2-1 (bug #1132041)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-879p-475x-rqh2
 CVE-2026-27588 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
+	{DSA-6429-1}
 	- caddy 2.11.2-1 (bug #1132041)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-x76f-jf84-rqj8
 CVE-2026-27587 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
+	{DSA-6429-1}
 	- caddy 2.11.2-1 (bug #1132041)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-g7pc-pc7g-h8jh
 CVE-2026-27586 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
@@ -114848,6 +115145,7 @@ CVE-2026-27586 (Caddy is an extensible server platform that uses TLS by default.
 	NOTE: convertPEMFilesToDER() were all added by the trusted CA provider modularization
 	NOTE: in 2.8.0; 2.6.2 has no such function and no swallowed error to fail open on.
 CVE-2026-27585 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
+	{DSA-6429-1}
 	- caddy 2.11.2-1 (bug #1132041)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4
 CVE-2026-27584 (Actual is a local-first personal finance tool. Prior to version 26.2.1 ...)
@@ -143282,7 +143580,7 @@ CVE-2025-14849 (Advantech WebAccess/SCADA is vulnerable to unrestricted file upl
 	NOT-FOR-US: Advantech
 CVE-2025-14848 (Advantech WebAccess/SCADA is vulnerable to absolute directory traversa ...)
 	NOT-FOR-US: Advantech
-CVE-2025-14733 (An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may all ...)
+CVE-2025-14733 (An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS ike ...)
 	NOT-FOR-US: WatchGuard
 CVE-2025-14546 (Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cr ...)
 	NOT-FOR-US: fastapi-sso



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc015f04b27f901f9326e68d33226b9a64163f4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc015f04b27f901f9326e68d33226b9a64163f4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/860ea30d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list