[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 13 08:13:29 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5e8b2957 by security tracker role at 2026-08-13T07:13:22+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,373 @@
+CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gate ...)
+	TODO: check
+CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentication s ...)
+	TODO: check
+CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
+	TODO: check
+CVE-2026-73500 (etcd is a distributed key-value store for the data of a distributed sy ...)
+	TODO: check
+CVE-2026-73499 (etcd is a distributed key-value store for the data of a distributed sy ...)
+	TODO: check
+CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+	TODO: check
+CVE-2026-73495 (blaze is a Scala library for building asynchronous pipelines, with a f ...)
+	TODO: check
+CVE-2026-73493 (Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface f ...)
+	TODO: check
+CVE-2026-73492 (Loofah is a general library for manipulating and transforming HTML/XML ...)
+	TODO: check
+CVE-2026-73491 (Loofah is a general library for manipulating and transforming HTML/XML ...)
+	TODO: check
+CVE-2026-73490 (Loofah is a general library for manipulating and transforming HTML/XML ...)
+	TODO: check
+CVE-2026-73434 (A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_ ...)
+	TODO: check
+CVE-2026-73433 (A flaw was found in GStreamer gst-plugins-good (avidemux). When parsin ...)
+	TODO: check
+CVE-2026-73430 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an unaut ...)
+	TODO: check
+CVE-2026-73429 (Russh is a Rust SSH client & server library. Prior to 0.62.4, a malici ...)
+	TODO: check
+CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
+	TODO: check
+CVE-2026-73425 (Astro is a web framework for content-driven websites. Prior to 8.1.2,  ...)
+	TODO: check
+CVE-2026-73423 (Astro is a web framework for content-driven websites. From 7.0.0 until ...)
+	TODO: check
+CVE-2026-73422 (Astro is a web framework for content-driven websites. From 2.9.0 until ...)
+	TODO: check
+CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/core 0. ...)
+	TODO: check
+CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
+	TODO: check
+CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
+	TODO: check
+CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
+	TODO: check
+CVE-2026-73413 (Shescape is a simple shell escape library for JavaScript. From 2.1.11  ...)
+	TODO: check
+CVE-2026-73412 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
+	TODO: check
+CVE-2026-73411 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
+	TODO: check
+CVE-2026-73409 (Budibase is an open-source low-code platform. Prior to 3.40.1, package ...)
+	TODO: check
+CVE-2026-73407 (Budibase is an open-source low-code platform. Prior to 3.40.1, RestInt ...)
+	TODO: check
+CVE-2026-73406 (Budibase is an open-source low-code platform. Prior to 3.39.32, GET /a ...)
+	TODO: check
+CVE-2026-73332 (CamaleonCMS contains a stored cross-site scripting vulnerability in th ...)
+	TODO: check
+CVE-2026-73331 (CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerabilit ...)
+	TODO: check
+CVE-2026-73330 (CamaleonCMS 2.9.1 contains a server-side template injection vulnerabil ...)
+	TODO: check
+CVE-2026-73329 (CamaleonCMS contains a stored cross-site scripting vulnerability that  ...)
+	TODO: check
+CVE-2026-73326 (CamaleonCMS contains a missing authorization vulnerability that allows ...)
+	TODO: check
+CVE-2026-73308 (Budibase is an open-source low-code platform. Prior to 3.39.25, packag ...)
+	TODO: check
+CVE-2026-73307 (Budibase is an open-source low-code platform. Prior to 3.39.4, uploadU ...)
+	TODO: check
+CVE-2026-73306 (Budibase is an open-source low-code platform. Prior to 3.39.25, POST / ...)
+	TODO: check
+CVE-2026-73303 (Budibase is an open-source low-code platform. Prior to 3.40.0, POST /a ...)
+	TODO: check
+CVE-2026-73269 (A flaw was found in the cluster-curator-controller component. A local  ...)
+	TODO: check
+CVE-2026-73268 (A flaw was found in the cluster-curator-controller component of multic ...)
+	TODO: check
+CVE-2026-72809 (SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authenticatio ...)
+	TODO: check
+CVE-2026-72808 (SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain a ...)
+	TODO: check
+CVE-2026-72807 (SiYuan versions before v3.7.4 contain a second-order SQL injection vul ...)
+	TODO: check
+CVE-2026-72806 (SiYuan versions before v3.7.4 contain an authentication bypass vulnera ...)
+	TODO: check
+CVE-2026-72805 (SiYuan versions before v3.7.4 fail to enforce publish-access checks on ...)
+	TODO: check
+CVE-2026-72804 (SiYuan versions before v3.7.4 fail to validate publish-password tier i ...)
+	TODO: check
+CVE-2026-72803 (SiYuan versions before v3.7.4 fail to enforce publish-access checks in ...)
+	TODO: check
+CVE-2026-72802 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+	TODO: check
+CVE-2026-72801 (SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivati ...)
+	TODO: check
+CVE-2026-72800 (SiYuan versions before v3.7.4 fail to apply publish-access filtering t ...)
+	TODO: check
+CVE-2026-72799 (SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-acce ...)
+	TODO: check
+CVE-2026-72798 (SiYuan versions before v3.7.4 fail to properly filter related-database ...)
+	TODO: check
+CVE-2026-72797 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+	TODO: check
+CVE-2026-72796 (SiYuan before v3.7.4 contains an access control bypass vulnerability w ...)
+	TODO: check
+CVE-2026-72795 (SiYuan versions before v3.7.4 fail to filter embedded block content by ...)
+	TODO: check
+CVE-2026-72794 (siyuan versions before v3.7.4 expose the session cookie signing key th ...)
+	TODO: check
+CVE-2026-72793 (SiYuan versions before v3.7.4 fail to mask sensitive configuration fie ...)
+	TODO: check
+CVE-2026-72792 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
+	TODO: check
+CVE-2026-72791 (SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in s ...)
+	TODO: check
+CVE-2026-72790 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
+	TODO: check
+CVE-2026-72789 (SiYuan before v3.7.4 fails to properly validate publish access for enc ...)
+	TODO: check
+CVE-2026-72788 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+	TODO: check
+CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site scripting ...)
+	TODO: check
+CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication bypass vuln ...)
+	TODO: check
+CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription component of ...)
+	TODO: check
+CVE-2026-72506 (VoiceTra provided by National Institute of Information and Communicati ...)
+	TODO: check
+CVE-2026-71846 (A flaw was found in insights-client. The component's ServiceAccount is ...)
+	TODO: check
+CVE-2026-71473 (A flaw was found in the `search-v2-operator` component. A user with sp ...)
+	TODO: check
+CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with administrati ...)
+	TODO: check
+CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker can exp ...)
+	TODO: check
+CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)
+	TODO: check
+CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to manipulate ...)
+	TODO: check
+CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding w ...)
+	TODO: check
+CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability that all ...)
+	TODO: check
+CVE-2026-63300 (An improper validation vulnerability in the instancePostMigration func ...)
+	TODO: check
+CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an authenticated u ...)
+	TODO: check
+CVE-2026-63298 (An improper neutralization of special elements vulnerability in LXD's  ...)
+	TODO: check
+CVE-2026-63297 (An authorization bypass vulnerability in LXD due to a timing flaw duri ...)
+	TODO: check
+CVE-2026-63296 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
+	TODO: check
+CVE-2026-63295 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
+	TODO: check
+CVE-2026-63294 (A link following vulnerability in LXD allows an attacker to achieve ro ...)
+	TODO: check
+CVE-2026-63293 (A link following vulnerability in LXD allows an attacker to achieve ar ...)
+	TODO: check
+CVE-2026-62421
+	REJECTED
+CVE-2026-62420 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
+	TODO: check
+CVE-2026-59917 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
+	TODO: check
+CVE-2026-59916 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
+	TODO: check
+CVE-2026-59914 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
+	TODO: check
+CVE-2026-50544 (NortheBridge/luminalshine is a Sunshine-compatible game stream host fo ...)
+	TODO: check
+CVE-2026-4879 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-49819 (UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vuln ...)
+	TODO: check
+CVE-2026-49481 (UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS co ...)
+	TODO: check
+CVE-2026-49473 (@cedar-policy/authorization-for-expressjs is an open-source Express.js ...)
+	TODO: check
+CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote unpublished con ...)
+	TODO: check
+CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with sigstore  ...)
+	TODO: check
+CVE-2026-47718 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
+	TODO: check
+CVE-2026-47717 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
+	TODO: check
+CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
+	TODO: check
+CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based application for  ...)
+	TODO: check
+CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based application for  ...)
+	TODO: check
+CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin for Wo ...)
+	TODO: check
+CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML response wit ...)
+	TODO: check
+CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks authorization  ...)
+	TODO: check
+CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due to a flaw ...)
+	TODO: check
+CVE-2026-19643 (An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cp ...)
+	TODO: check
+CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-c ...)
+	TODO: check
+CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not valida ...)
+	TODO: check
+CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup configuration to st ...)
+	TODO: check
+CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in OpenNMS M ...)
+	TODO: check
+CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions of OpenNM ...)
+	TODO: check
+CVE-2026-19130 (A flaw was found in the provider-credential-controller component of mu ...)
+	TODO: check
+CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin b ...)
+	TODO: check
+CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may experien ...)
+	TODO: check
+CVE-2026-19003 (A data source definition containing an over-length file path setting m ...)
+	TODO: check
+CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter metadat ...)
+	TODO: check
+CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the bounds of a ...)
+	TODO: check
+CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not verify th ...)
+	TODO: check
+CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point column va ...)
+	TODO: check
+CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches VinceComm ...)
+	TODO: check
+CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case) only an ...)
+	TODO: check
+CVE-2026-18744 (Any authenticated case participant can fetch any OTHER vendor's CaseSt ...)
+	TODO: check
+CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow vulnerability in  ...)
+	TODO: check
+CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This vulnerabilit ...)
+	TODO: check
+CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a remote att ...)
+	TODO: check
+CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the operato ...)
+	TODO: check
+CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-18148 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-18146 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
+	TODO: check
+CVE-2026-18099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-18097 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UN ...)
+	TODO: check
+CVE-2026-18096 (IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Serve ...)
+	TODO: check
+CVE-2026-17642 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17616 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-17485 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17445 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17417 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17111 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote a ...)
+	TODO: check
+CVE-2026-17083 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute  ...)
+	TODO: check
+CVE-2026-17082 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16695 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a l ...)
+	TODO: check
+CVE-2026-16494 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-16480 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected b ...)
+	TODO: check
+CVE-2026-16033 (A path traversal vulnerability in LXD allows an attacker to achieve ar ...)
+	TODO: check
+CVE-2026-15424
+	REJECTED
+CVE-2026-15217 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
+	TODO: check
+CVE-2026-15216 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
+	TODO: check
+CVE-2026-15141 (The web interface of the affected device relies on the HTTP referrer h ...)
+	TODO: check
+CVE-2026-14866 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
+	TODO: check
+CVE-2026-14213 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
+	TODO: check
+CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress plugin befor ...)
+	TODO: check
+CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's virt-handler ...)
+	TODO: check
+CVE-2026-13610 (The KiviCare  WordPress plugin before 4.5.2 does not restrict the role ...)
+	TODO: check
+CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unau ...)
+	TODO: check
+CVE-2026-13433 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulner ...)
+	TODO: check
+CVE-2026-13367 (IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege  ...)
+	TODO: check
+CVE-2026-13361 (IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface leng ...)
+	TODO: check
+CVE-2026-13328 (The Food Menu  WordPress plugin before 6.0.2 does not perform any capa ...)
+	TODO: check
+CVE-2026-13267 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-13105 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
+	TODO: check
+CVE-2026-13094 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
+	TODO: check
+CVE-2026-12618 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-12359 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-12005 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-12004 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-11937 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-11932 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-11923 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
+	TODO: check
+CVE-2026-10543 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable ...)
+	TODO: check
+CVE-2026-10534 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable ...)
+	TODO: check
+CVE-2026-0301 (An information disclosure vulnerability in the URL Filtering feature o ...)
+	TODO: check
+CVE-2026-0299 (Local privilege escalation vulnerabilities in the Palo Alto Networks G ...)
+	TODO: check
+CVE-2026-0298 (An improper input validation vulnerability exists in the Windows Pre-L ...)
+	TODO: check
+CVE-2026-0297 (A buffer overflow vulnerability exists in the Palo Alto Networks Globa ...)
+	TODO: check
+CVE-2026-0296 (Improper certificate validation vulnerabilities in Palo Alto Networks  ...)
+	TODO: check
+CVE-2026-0295 (A race condition in the Palo Alto Networks GlobalProtect\u2122 client  ...)
+	TODO: check
+CVE-2026-0294 (A privilege escalation (PE) vulnerability in the Palo Alto Networks Pr ...)
+	TODO: check
+CVE-2026-0293 (A vulnerability in Palo Alto Networks Prisma\xae Access Agent on Windo ...)
+	TODO: check
+CVE-2026-0292 (An authentication bypass vulnerability in the network driver of Palo A ...)
+	TODO: check
+CVE-2026-0291 (An improper link resolution before file access vulnerability exists in ...)
+	TODO: check
+CVE-2026-0290 (An information disclosure vulnerability in the Account Protection feat ...)
+	TODO: check
+CVE-2026-0289 (A  security bypass vulnerability in the Account Protection feature of  ...)
+	TODO: check
+CVE-2025-9486 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an auth ...)
+	TODO: check
 CVE-2026-53802
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
@@ -97,9 +467,9 @@ CVE-2026-70462
 CVE-2026-70454
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-17431
+CVE-2026-17431 (PDF::WebKit versions through 1.2 for Perl allow OS command injection v ...)
 	NOT-FOR-US: PDF::WebKit Perl module
-CVE-2026-16770
+CVE-2026-16770 (PDF::WebKit versions through 1.2 for Perl allow argument injection int ...)
 	NOT-FOR-US: PDF::WebKit Perl module
 CVE-2026-8667 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
@@ -2763,11 +3133,11 @@ CVE-2025-31936 (Improper handling of overlap between protected memory ranges for
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html
-CVE-2026-71194
+CVE-2026-71194 (In OpenStack Designate before 22.0.2, the mDNS handler performs pool-b ...)
 	- designate 1:22.0.0-2 (bug #1144145)
 	NOTE: https://bugs.launchpad.net/designate/+bug/2160533
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
-CVE-2026-71193
+CVE-2026-71193 (In OpenStack Designate before 22.0.1, zone creation checks (_is_subzon ...)
 	- designate 1:22.0.0-2 (bug #1144145)
 	NOTE: https://bugs.launchpad.net/designate/+bug/2160533
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
@@ -3464,6 +3834,7 @@ CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
 	NOT-FOR-US: Joomla
 CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in SQLite-b ...)
+	{DSA-6435-1}
 	- spip 4.4.18+dfsg-1
 	NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html
 CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows  ...)
@@ -9169,6 +9540,7 @@ CVE-2017-20242 (Keysight IxChariot Endpoint before 9.5.102 contains a stack-base
 CVE-2017-20241 (Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffe ...)
 	NOT-FOR-US: Keysight IxChariot Endpoint
 CVE-2026-15920 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
+	{DLA-4736-1}
 	- python-django 3:5.2.17-1 (bug #1143611)
 	NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
 	NOTE: Fixed by: https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349 (5.2.17)
@@ -9179,6 +9551,7 @@ CVE-2026-15830 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 befo
 	NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
 	NOTE: Fixed by: https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080 (5.2.17)
 CVE-2026-15337 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
+	{DLA-4736-1}
 	- python-django 3:5.2.17-1 (bug #1143611)
 	NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
 	NOTE: Fixed by: https://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959 (5.2.17)
@@ -60950,7 +61323,7 @@ CVE-2018-25428 (Paroiciel 11.20 contains an SQL injection vulnerability that all
 CVE-2018-25427 (Arm Whois 3.11 contains a stack-based buffer overflow vulnerability th ...)
 	NOT-FOR-US: Arm whois
 CVE-2026-50256 (A stack-based buffer overflow flaw was found in the X.Org X server and ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -60959,7 +61332,7 @@ CVE-2026-50256 (A stack-based buffer overflow flaw was found in the X.Org X serv
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/a569eb4f36ed96a9e445ececd7e8d98c223461a0 (xorg-server-21.1.23)
 CVE-2026-50257 (A use-after-free flaw was found in the X.Org X server and Xwayland in  ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -60968,7 +61341,7 @@ CVE-2026-50257 (A use-after-free flaw was found in the X.Org X server and Xwayla
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f304b57444be3991fd9d3389f309c6eeb056a6c4 (xorg-server-21.1.23)
 CVE-2026-50258 (A stack-based buffer overflow flaw was found in the X.Org X server and ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -60977,7 +61350,7 @@ CVE-2026-50258 (A stack-based buffer overflow flaw was found in the X.Org X serv
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/543e108516428fc8c3bea91d6563ad266f9a801e
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/eced7e74cad4a46c3a3c17b2df13b70b8bedfc25 (xorg-server-21.1.23)
 CVE-2026-50259 (A stack-based buffer overflow flaw was found in the X.Org X server and ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -60986,7 +61359,7 @@ CVE-2026-50259 (A stack-based buffer overflow flaw was found in the X.Org X serv
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/867b59b33bee669cb412f1314e47c52eacf6e00b
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/54c3d9fad0f2f97835da9d275b53255f4963029f (xorg-server-21.1.23)
 CVE-2026-50260 (A use-after-free flaw was found in the X.Org X server and Xwayland in  ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -60995,7 +61368,7 @@ CVE-2026-50260 (A use-after-free flaw was found in the X.Org X server and Xwayla
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f304b57444be3991fd9d3389f309c6eeb056a6c4 (xorg-server-21.1.23)
 CVE-2026-50261 (A use-after-free flaw was found in the X.Org X server and Xwayland in  ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -61004,7 +61377,7 @@ CVE-2026-50261 (A use-after-free flaw was found in the X.Org X server and Xwayla
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/bdd7bf57af208b1ddf57d4683d67104443b44812
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/92a167ab3fda0bee41cf97f6a40a4c01c67d85d4 (xorg-server-21.1.23)
 CVE-2026-50262 (An out-of-bounds read flaw was found in the X.Org X server and Xwaylan ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -61013,7 +61386,7 @@ CVE-2026-50262 (An out-of-bounds read flaw was found in the X.Org X server and X
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/6d459e4daf715bea8abdafa8fb130be2f8a1d145
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/94341bd715d62ba8da4c1851f517018996da1af8 (xorg-server-21.1.23)
 CVE-2026-50263 (A use-after-free flaw was found in the X.Org X server and Xwayland in  ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -61022,7 +61395,7 @@ CVE-2026-50263 (A use-after-free flaw was found in the X.Org X server and Xwayla
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ecc634f1b2f7aa473d3a267eada98c4918bf9e05
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/182c23f780402062ab31963776a19d5b87e25ac8 (xorg-server-21.1.23)
 CVE-2026-50264 (An out-of-bounds write flaw was found in the X.Org X server and Xwayla ...)
-	{DSA-6371-1}
+	{DSA-6371-1 DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.23-1 (bug #1138680)
 	- xwayland 2:24.1.12-1 (bug #1138703)
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -92702,6 +93075,7 @@ CVE-2024-9168
 CVE-2024-23104 (An exposure of sensitive information to an unauthorized actor vulnerab ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-34003 (A flaw was found in the X.Org X server's XKB key types request validat ...)
+	{DLA-4738-1}
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92712,6 +93086,7 @@ CVE-2026-34003 (A flaw was found in the X.Org X server's XKB key types request v
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b85b00dd7b9eee05e3c12e7ad1fce4fc6671507b
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/d38c563fab5c4a554e0939da39e4d1dadef7cbae
 CVE-2026-34002 (A flaw was found in the X.Org X server. This vulnerability, an out-of- ...)
+	{DLA-4738-1}
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92721,6 +93096,7 @@ CVE-2026-34002 (A flaw was found in the X.Org X server. This vulnerability, an o
 	NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
 	NOTE: fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f056ce1cc96ed9261052c31524162c78e458f98c
 CVE-2026-34001 (A flaw was found in the X.Org X server. This use-after-free vulnerabil ...)
+	{DLA-4738-1}
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92730,6 +93106,7 @@ CVE-2026-34001 (A flaw was found in the X.Org X server. This use-after-free vuln
 	NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
 	NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f19ab94ba9c891d801231654267556dc7f32b5e0
 CVE-2026-34000 (A flaw was found in the X.Org X server. This out-of-bounds read vulner ...)
+	{DLA-4738-1}
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -92739,6 +93116,7 @@ CVE-2026-34000 (A flaw was found in the X.Org X server. This out-of-bounds read
 	NOTE: https://lists.x.org/archives/xorg-announce/2026-April/003677.html
 	NOTE: Fixed by: ttps://gitlab.freedesktop.org/xorg/xserver/-/commit/81b6a34f90b28c32ad499a78a4f391b7c06daea2
 CVE-2026-33999 (A flaw was found in the X.Org X server. This integer underflow vulnera ...)
+	{DLA-4738-1}
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
@@ -158768,7 +159146,8 @@ CVE-2025-64076 (Multiple vulnerabilities exist in cbor2 through version 5.7.0 in
 	NOTE: Introduced with: https://github.com/agronholm/cbor2/commit/387755eacf0be35591a478d3c67fe10618a6d542 (5.6.0)
 	NOTE: Fixed by: https://github.com/agronholm/cbor2/commit/2349197bea8ebd1bf57a68f4a6549d8fd7585e66 (5.7.1)
 	NOTE: Debian builds src:cbor2 with CBOR2_BUILD_C_EXTENSION=0 (not building C extensions)
-CVE-2025-63994 (An arbitrary file upload vulnerability in the /php/UploadHandler.php c ...)
+CVE-2025-63994
+	REJECTED
 	NOT-FOR-US: RichFilemanager
 CVE-2025-63955 (A Cross-Site Request Forgery (CSRF) vulnerability in the manage-studen ...)
 	NOT-FOR-US: PHPGurukul
@@ -241362,6 +241741,7 @@ CVE-2024-13602 (The Poll Maker  WordPress plugin before 5.5.4 does not sanitise
 CVE-2024-13126 (The Download Manager WordPress plugin before 3.3.07 doesn't prevent di ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-49737 (In X.Org X server 20.11 through 21.1.16, when a client application use ...)
+	{DLA-4738-1 DLA-4737-1}
 	- xorg-server 2:21.1.16-1.1 (bug #1081338)
 	NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260
 	NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0 (master)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e8b295787367fbd071362bece2934fbe9830ca5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e8b295787367fbd071362bece2934fbe9830ca5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/95c08ab4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list