[Git][security-tracker-team/security-tracker][master] Add CVE-2026-71290 but retain TODO item for now

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 13 14:29:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
13b337fc by Salvatore Bonaccorso at 2026-08-13T15:28:34+02:00
Add CVE-2026-71290 but retain TODO item for now

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1088,7 +1088,10 @@ CVE-2026-71468 (A flaw was found in acm-search-v2-api-rhel9. When the `getFedera
 CVE-2026-71467 (A flaw was found in search-v2-api. The authentication middleware in th ...)
 	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache HttpCompone ...)
-	TODO: check
+	- httpcomponents-core5 <unfixed>
+	- httpcomponents-client <undetermined>
+	NOTE: https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq
+	TODO: check, claimed to affect only version 5.2 onwards
 CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of Red Hat Ad ...)
 	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-70339 (Access of resource using incompatible type ('type confusion') in Micro ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13b337fc7bd264a98a5dc5524d8dae36d9f1cee6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13b337fc7bd264a98a5dc5524d8dae36d9f1cee6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/3e1c1c48/attachment.htm>


More information about the debian-security-tracker-commits mailing list