[Git][security-tracker-team/security-tracker][master] Add two new calibre issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 12 08:40:58 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
981c916d by Salvatore Bonaccorso at 2026-08-12T09:40:31+02:00
Add two new calibre issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,9 +5,13 @@ CVE-2026-9318 (tablib prior to 3.10.0 contains a stored cross-site scripting vul
 CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
 	TODO: check
 CVE-2026-73249 (calibre is an e-book manager. Prior to 9.12.0, the calibre Content Ser ...)
-	TODO: check
+	- calibre 9.12.0+ds+~0.10.6-1
+	NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-5x64-w63v-x2g6
+	NOTE: Fixed by: https://github.com/kovidgoyal/calibre/commit/71295e8b62801e1ccecaa4fac47e6942f11cfe1e (v9.12.0)
 CVE-2026-73248 (calibre is an e-book manager. Prior to 9.12.0, calibre processes attac ...)
-	TODO: check
+	- calibre 9.12.0+ds+~0.10.6-1
+	NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx
+	NOTE: Fixed by: https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8 (v9.12.0)
 CVE-2026-73247 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
 	TODO: check
 CVE-2026-73246 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/981c916d315780fccdb92fffebd0b3d70fdd3e0f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/981c916d315780fccdb92fffebd0b3d70fdd3e0f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/bfb156ab/attachment.htm>


More information about the debian-security-tracker-commits mailing list