[Git][security-tracker-team/security-tracker][master] new gh issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 12 11:47:21 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
749953e4 by Moritz Muehlenhoff at 2026-08-12T12:46:46+02:00
new gh issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5873,13 +5873,25 @@ CVE-2026-64663 (Statamic is a Laravel and Git powered content management system
 CVE-2026-64662 (Statamic is a Laravel and Git powered content management system (CMS). ...)
 	NOT-FOR-US: Statamic CMS
 CVE-2026-64655 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to  ...)
-	TODO: check
+	- gh <unfixed>
+	[trixie] - gh <no-dsa> (Minor issue)
+	NOTE: https://github.com/cli/cli/security/advisories/GHSA-mm27-mwq9-fr5g
+	NOTE: https://github.com/cli/cli/commit/55dbb4dc6b7edb10b48e3d7fc5bccd32318d1b55 (v2.97.0)
 CVE-2026-64654 (GitHub CLI (gh) is GitHub's official command line tool. Prior to versi ...)
-	TODO: check
+	- gh <unfixed>
+	[trixie] - gh <no-dsa> (Minor issue)
+	NOTE: https://github.com/cli/cli/security/advisories/GHSA-3m3g-3wcr-px46
+	NOTE: https://github.com/cli/cli/commit/2a1409fe88d416cc85fc96fb5bc473f83ed5a054 (v2.97.0)
 CVE-2026-64653 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to  ...)
-	TODO: check
+	- gh <unfixed>
+	[trixie] - gh <no-dsa> (Minor issue)
+	NOTE: https://github.com/cli/cli/security/advisories/GHSA-4fjg-2h4q-fwg3
+	NOTE: https://github.com/cli/cli/commit/0c2eea6338a2323cfff000160b9b5a56a38d2a06 (v2.97.0)
 CVE-2026-64652 (GitHub CLI (gh) is GitHub's official command line tool. Prior to versi ...)
-	TODO: check
+	- gh <unfixed>
+	[trixie] - gh <no-dsa> (Minor issue)
+	NOTE: https://github.com/cli/cli/security/advisories/GHSA-cg6r-mpgc-h9mm
+	NOTE: https://github.com/cli/cli/commit/3f6a16a9f8c7fe9676aa8d8f47b399310dd231c3 (v2.97.0)
 CVE-2026-63725 (sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup ...)
 	NOT-FOR-US: sysPass
 CVE-2026-63637 (Dgraph is an open source distributed GraphQL database. Prior to 25.3.8 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/749953e4b5cd337a5415a1d57bf20662758dddf6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/749953e4b5cd337a5415a1d57bf20662758dddf6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/7e0a9318/attachment.htm>


More information about the debian-security-tracker-commits mailing list