[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 08:14:15 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dd25db84 by security tracker role at 2026-08-14T07:14:08+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,431 @@
+CVE-2026-8715 (Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary ...)
+	TODO: check
+CVE-2026-73843 (OpenChoreo is a complete, open-source developer platform for Kubernete ...)
+	TODO: check
+CVE-2026-73842 (OpenChoreo is a complete, open-source developer platform for Kubernete ...)
+	TODO: check
+CVE-2026-73841 (OpenChoreo is a complete, open-source developer platform for Kubernete ...)
+	TODO: check
+CVE-2026-73840 (OpenChoreo is a complete, open-source developer platform for Kubernete ...)
+	TODO: check
+CVE-2026-73669 (The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT br ...)
+	TODO: check
+CVE-2026-73667 (OpenChoreo is a complete, open-source developer platform for Kubernete ...)
+	TODO: check
+CVE-2026-73666 (OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1 ...)
+	TODO: check
+CVE-2026-73665 (FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server ...)
+	TODO: check
+CVE-2026-73664 (FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the pu ...)
+	TODO: check
+CVE-2026-73663 (FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4 ...)
+	TODO: check
+CVE-2026-73662 (FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePB ...)
+	TODO: check
+CVE-2026-73661 (FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the Fr ...)
+	TODO: check
+CVE-2026-73660 (FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the Fr ...)
+	TODO: check
+CVE-2026-73659 (Trigger.dev is the open-source platform for building AI workflows in T ...)
+	TODO: check
+CVE-2026-73658 (Trigger.dev is a platform for building and deploying fully managed AI  ...)
+	TODO: check
+CVE-2026-73657 (Trigger.dev is a platform for building and deploying fully managed AI  ...)
+	TODO: check
+CVE-2026-73656 (Trigger.dev is a platform for building and deploying fully managed AI  ...)
+	TODO: check
+CVE-2026-73655 (Trigger.dev is a platform for building and deploying fully managed AI  ...)
+	TODO: check
+CVE-2026-73654 (Trigger.dev is a platform for building and deploying fully managed AI  ...)
+	TODO: check
+CVE-2026-73531 (django-helpdesk before 2.3.3 contains a stored cross-site scripting vu ...)
+	TODO: check
+CVE-2026-73530 (Flyto2 Core before 2.28.0 contains a server-side request forgery guard ...)
+	TODO: check
+CVE-2026-73489 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an authe ...)
+	TODO: check
+CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and file n ...)
+	TODO: check
+CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when printing marked ...)
+	TODO: check
+CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
+	TODO: check
+CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth 5.0.0- ...)
+	TODO: check
+CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
+	TODO: check
+CVE-2026-73417 (jupyterlab is an extensible environment for interactive and reproducib ...)
+	TODO: check
+CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
+	TODO: check
+CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 3.39.18, packag ...)
+	TODO: check
+CVE-2026-73305 (Budibase is an open-source low-code platform. Prior to 3.39.24, POST / ...)
+	TODO: check
+CVE-2026-73304 (Budibase is an open-source low-code platform. Prior to 3.39.25, GET /a ...)
+	TODO: check
+CVE-2026-73302 (Budibase is an open-source low-code platform. Prior to 3.39.30, the OI ...)
+	TODO: check
+CVE-2026-73039 (streama contains an insecure direct object reference vulnerability in  ...)
+	TODO: check
+CVE-2026-72857 (Budibase before 3.40.0 fails to redact datasource credentials stored i ...)
+	TODO: check
+CVE-2026-72856 (Budibase versions before 3.40.0 contain an authorization/authenticatio ...)
+	TODO: check
+CVE-2026-72855 (Budibase before 3.40.0 contains server-side request forgery vulnerabil ...)
+	TODO: check
+CVE-2026-72853 (Budibase before 3.40.0 contains a SQL injection vulnerability in the O ...)
+	TODO: check
+CVE-2026-72851 (Budibase before 3.40.0 contains an unauthenticated SQL injection vulne ...)
+	TODO: check
+CVE-2026-72850 (Budibase before 3.40.0 fails to properly sanitize S3 object keys, allo ...)
+	TODO: check
+CVE-2026-72849 (Budibase before 3.40.0 contains a cross-site request forgery vulnerabi ...)
+	TODO: check
+CVE-2026-72842 (luci-app-lxc contains an ACL inconsistency vulnerability that allows l ...)
+	TODO: check
+CVE-2026-72841 (luci-app-openvpn fails to properly validate the instance_name2 paramet ...)
+	TODO: check
+CVE-2026-72840 (OpenWrt LuCI contains an overly permissive ACL definition in luci-mod- ...)
+	TODO: check
+CVE-2026-72839 (filebrowser through 2.63.16 fails to properly restrict scope and permi ...)
+	TODO: check
+CVE-2026-72776 (AgenticSeek (commit fc242c7) contains an unauthenticated remote code e ...)
+	TODO: check
+CVE-2026-72687 (A flaw in Elasticsearch allows a low-privileged authenticated user to  ...)
+	TODO: check
+CVE-2026-72686 (A flaw in Elasticsearch allows a low-privileged authenticated user to  ...)
+	TODO: check
+CVE-2026-72685 (A flaw in Elasticsearch allows a low-privileged authenticated user who ...)
+	TODO: check
+CVE-2026-72684 (A flaw in Elasticsearch allows an authenticated user holding only read ...)
+	TODO: check
+CVE-2026-72683 (A flaw in Elasticsearch allows an authenticated user with the privileg ...)
+	TODO: check
+CVE-2026-72681 (Kibana Agent Builder does not correctly verify that the requesting use ...)
+	TODO: check
+CVE-2026-72680 (Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier  ...)
+	TODO: check
+CVE-2026-72679 (Elasticsearch does not apply its configurable input length restriction ...)
+	TODO: check
+CVE-2026-72678 (Elasticsearch does not validate a size value taken from a user-supplie ...)
+	TODO: check
+CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...)
+	TODO: check
+CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') (CWE-94) in  ...)
+	TODO: check
+CVE-2026-72675 (Missing Authorization (CWE-862) in Kibana can lead to cross-space info ...)
+	TODO: check
+CVE-2026-72674 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-72673 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized d ...)
+	TODO: check
+CVE-2026-72672 (The Elastic Security capability that suggests existing field values wh ...)
+	TODO: check
+CVE-2026-72671 (A Kibana Machine Learning capability that removes a saved object from  ...)
+	TODO: check
+CVE-2026-72670 (A lower privileged user who holds only the privilege to read agent pol ...)
+	TODO: check
+CVE-2026-72669 (The state that Kibana stores for an Observability Onboarding flow is n ...)
+	TODO: check
+CVE-2026-72667 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-72666 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
+	TODO: check
+CVE-2026-72665 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized exe ...)
+	TODO: check
+CVE-2026-72664 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized exe ...)
+	TODO: check
+CVE-2026-72663 (Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to den ...)
+	TODO: check
+CVE-2026-72661 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
+	TODO: check
+CVE-2026-72660 (Uncaught Exception (CWE-248), resulting from Improper Input Validation ...)
+	TODO: check
+CVE-2026-72659 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege e ...)
+	TODO: check
+CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Se ...)
+	TODO: check
+CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL que ...)
+	TODO: check
+CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
+	TODO: check
+CVE-2026-72653 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-72651 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
+	TODO: check
+CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment Variable  ...)
+	TODO: check
+CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
+	TODO: check
+CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch ...)
+	TODO: check
+CVE-2026-72643 (Kibana Agent Builder determines whether a caller owns a private agent  ...)
+	TODO: check
+CVE-2026-72642 (The native inference process that Elasticsearch uses to evaluate uploa ...)
+	TODO: check
+CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret  ...)
+	TODO: check
+CVE-2026-72639 (Elasticsearch does not enforce an upper bound on a user-supplied count ...)
+	TODO: check
+CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
+	TODO: check
+CVE-2026-72636 (Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matchin ...)
+	TODO: check
+CVE-2026-72632 (Observable Discrepancy (CWE-203) in Kibana Fleet can lead to informati ...)
+	TODO: check
+CVE-2026-72631 (Improper Privilege Management (CWE-269) in Kibana Fleet can lead to pr ...)
+	TODO: check
+CVE-2026-72630 (Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privileg ...)
+	TODO: check
+CVE-2026-72629 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
+	TODO: check
+CVE-2026-59714 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
+	TODO: check
+CVE-2026-49864 (wetty provides terminal access in browser over http/https. Prior to ve ...)
+	TODO: check
+CVE-2026-49096 (Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of ser ...)
+	TODO: check
+CVE-2026-49089 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-45774 (compliance-trestle is a tooling platform for managing compliance as co ...)
+	TODO: check
+CVE-2026-45725 (compliance-trestle is a tooling platform for managing compliance as co ...)
+	TODO: check
+CVE-2026-3883
+	REJECTED
+CVE-2026-19811 (A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20 ...)
+	TODO: check
+CVE-2026-19792 (A security flaw has been discovered in Tenda G0 up to 20260625. Impact ...)
+	TODO: check
+CVE-2026-19791 (A weakness has been identified in Tenda G0 up to 20260625. The affecte ...)
+	TODO: check
+CVE-2026-19790 (A vulnerability was identified in Tenda G0 up to 20260625. This issue  ...)
+	TODO: check
+CVE-2026-19789 (A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. ...)
+	TODO: check
+CVE-2026-19788 (A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This ...)
+	TODO: check
+CVE-2026-19787 (A vulnerability was determined in SourceCodester Air Cargo Management  ...)
+	TODO: check
+CVE-2026-19786 (A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. Th ...)
+	TODO: check
+CVE-2026-19785 (A vulnerability has been found in francoisjacquet RosarioSIS up to 12. ...)
+	TODO: check
+CVE-2026-19784 (A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This a ...)
+	TODO: check
+CVE-2026-19771 (A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_N ...)
+	TODO: check
+CVE-2026-19770 (A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affect ...)
+	TODO: check
+CVE-2026-19767 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
+	TODO: check
+CVE-2026-19765 (A security flaw has been discovered in eyaushev swagger-testcase-mcp 5 ...)
+	TODO: check
+CVE-2026-19764 (A vulnerability was identified in Raisecom Communication Command and D ...)
+	TODO: check
+CVE-2026-19763 (A vulnerability was determined in DTStack Taier 1.4.0. Affected by thi ...)
+	TODO: check
+CVE-2026-19762 (A vulnerability was found in DTStack Taier 1.4.0. Affected by this vul ...)
+	TODO: check
+CVE-2026-19761 (A vulnerability has been found in DTStack Taier 1.4.0. Affected is the ...)
+	TODO: check
+CVE-2026-19758 (A vulnerability was determined in dromara lamp-cloud up to 5.10.0. Thi ...)
+	TODO: check
+CVE-2026-19757 (A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vul ...)
+	TODO: check
+CVE-2026-19756 (A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. Thi ...)
+	TODO: check
+CVE-2026-19753 (A vulnerability was detected in Model Context Protocol mcp-rdf-explore ...)
+	TODO: check
+CVE-2026-19752 (A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39d ...)
+	TODO: check
+CVE-2026-19751 (A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373 ...)
+	TODO: check
+CVE-2026-19750 (A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/ ...)
+	TODO: check
+CVE-2026-19749 (A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, C ...)
+	TODO: check
+CVE-2026-19748 (A security vulnerability has been detected in Tenda CH7, CH7G, CH10, C ...)
+	TODO: check
+CVE-2026-19747 (A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, ...)
+	TODO: check
+CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The affected ...)
+	TODO: check
+CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknow ...)
+	TODO: check
+CVE-2026-19617 (A flaw was found in libdm. A remote attacker could craft a malicious L ...)
+	TODO: check
+CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 ...)
+	TODO: check
+CVE-2026-19297 (IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to  ...)
+	TODO: check
+CVE-2026-18846 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from im ...)
+	TODO: check
+CVE-2026-18741 (Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site s ...)
+	TODO: check
+CVE-2026-18715 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-18671 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to  ...)
+	TODO: check
+CVE-2026-18532
+	REJECTED
+CVE-2026-18511 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
+	TODO: check
+CVE-2026-18509 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
+	TODO: check
+CVE-2026-18249 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-18193 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass s ...)
+	TODO: check
+CVE-2026-18164 (An undocumented hard-coded credential, shared by all device units, is  ...)
+	TODO: check
+CVE-2026-18109 (The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross- ...)
+	TODO: check
+CVE-2026-18101 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elev ...)
+	TODO: check
+CVE-2026-18086 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute a ...)
+	TODO: check
+CVE-2026-18077 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-18068 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
+	TODO: check
+CVE-2026-18039 (The Essential Addons for Elementor  WordPress plugin before 6.7.2 does ...)
+	TODO: check
+CVE-2026-18020 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17649 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
+	TODO: check
+CVE-2026-17502 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17482 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17481 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17476 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17473 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17468 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17438 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain se ...)
+	TODO: check
+CVE-2026-17272 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17229 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17226 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17223 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17216 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17212 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17206 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute  ...)
+	TODO: check
+CVE-2026-17199 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17101 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute  ...)
+	TODO: check
+CVE-2026-17099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
+	TODO: check
+CVE-2026-17088 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17077 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17076 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17075 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
+	TODO: check
+CVE-2026-17074 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17069 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17045 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17043 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-17029 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute a ...)
+	TODO: check
+CVE-2026-17004 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-16987 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elev ...)
+	TODO: check
+CVE-2026-16982 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-16975 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16967 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16961 (IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attack ...)
+	TODO: check
+CVE-2026-16929 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16908 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16898 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
+	TODO: check
+CVE-2026-16896 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
+	TODO: check
+CVE-2026-16887 (IBM i 7.6 could allow a remote attacker to cause a denial of service d ...)
+	TODO: check
+CVE-2026-16878 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16871 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16868 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-16867 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access s ...)
+	TODO: check
+CVE-2026-16861 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-16859 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
+	TODO: check
+CVE-2026-16853 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
+	TODO: check
+CVE-2026-16815 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-16810 (The Bit Form \u2013 Contact Form, Payment Forms, Multi Step Forms, Cal ...)
+	TODO: check
+CVE-2026-16739 (The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 do ...)
+	TODO: check
+CVE-2026-16722 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16713 (IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could  ...)
+	TODO: check
+CVE-2026-16692 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-16674 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+	TODO: check
+CVE-2026-15205 (The Paymob for WooCommerce WordPress plugin before 4.1.9 does not prop ...)
+	TODO: check
+CVE-2026-14875 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
+	TODO: check
+CVE-2026-14525 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 I ...)
+	TODO: check
+CVE-2026-14290 (The Embed Google Photos album WordPress plugin through 2.2.1 does not  ...)
+	TODO: check
+CVE-2026-13460 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 ...)
+	TODO: check
+CVE-2026-13365 (IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site  ...)
+	TODO: check
+CVE-2026-12949 (The Wishlist Member plugin for WordPress is vulnerable to Account Take ...)
+	TODO: check
+CVE-2026-12743 (The affiliate-toolkit \u2013 Multi-Network Affiliate & Amazon Product  ...)
+	TODO: check
+CVE-2026-10571 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
+	TODO: check
+CVE-2025-10308 (The Astro Booking Engine plugin for WordPress is vulnerable to Cross-S ...)
+	TODO: check
 CVE-2026-73261 [Built-in TCP/IP malformed TCP option handling]
 	- mongoose 7.23+ds-1
 CVE-2026-73260 [Built-in TLS X.509 DER parsing bounds check]
@@ -8,7 +436,7 @@ CVE-2026-73252 [Built-in TLS short-record handling]
 	- mongoose 7.23+ds-1
 CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
 	- mongoose 7.23+ds-1
-CVE-2026-56865
+CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two sumdb  ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -19,7 +447,7 @@ CVE-2026-56865
 	NOTE: Fixed by: https://github.com/golang/go/commit/b0365c1777662ae45534c0e728a12a8b19874759 (go1.27rc3)
 	NOTE: Fixed by: https://github.com/golang/go/commit/115eb476aaca4531374c42e19e6f199265c2e25e (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/b0b8c97d1386bb3eb978e727ed0b1df8e14df569 (go1.25.13)
-CVE-2026-56864
+CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module content no ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -30,7 +458,7 @@ CVE-2026-56864
 	NOTE: Fixed by: https://github.com/golang/go/commit/a3876703796b5d3db7a7c6f2193e8663399f2339 (go1.27rc3)
 	NOTE: Fixed by: https://github.com/golang/go/commit/9f6980fd5c03840b0f6764e8ec7c705b90989eee (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb (go1.25.13)
-CVE-2026-56859
+CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing it to  ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -41,7 +469,7 @@ CVE-2026-56859
 	NOTE: Fixed by: https://github.com/golang/go/commit/d5eeaa7de337f01173036096619cba09e31bde1a (go1.27rc3)
 	NOTE: Fixed by: https://github.com/golang/go/commit/9918f26ab31a6bf9209ecc06465cab0e287e90f1 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 (go1.25.13)
-CVE-2026-56853
+CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it reads a  ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -52,7 +480,7 @@ CVE-2026-56853
 	NOTE: Fixed by: https://github.com/golang/go/commit/cb4d292bb634ab89a62995f2384df9389d876333 (go1.27rc3)
 	NOTE: Fixed by: https://github.com/golang/go/commit/5bbd22ff78daf010c5bd19c466a0c45ac78503d4 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 (go1.25.13)
-CVE-2026-56860
+CVE-2026-56860 (Previously, resolving relative paths containing parent directory ('..' ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -63,7 +491,7 @@ CVE-2026-56860
 	NOTE: Fixed by: https://github.com/golang/go/commit/bd62f0c26450224a26857a6d38a738d31f8fbaf6 (go1.27rc3)
 	NOTE: Fixed by: https://github.com/golang/go/commit/128893dbf9a6b4d6e7c99942096e2c0018d6fe57 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/962b300d32b68fd5f3c11674f711fc0e86251664 (go1.25.13)
-CVE-2026-56862
+CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as state- ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -74,7 +502,7 @@ CVE-2026-56862
 	NOTE: Fixed by: https://github.com/golang/go/commit/95ae6418f3d8c588ecd6fb366707e04b6009028d (go1.27rc3)
 	NOTE: Fixed by: https://github.com/golang/go/commit/b6432317a176b1b5595aa597dc1864a4cc4a81b2 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/677cfe54ecac147c4992e38204641bf61662524f (go1.25.13)
-CVE-2026-56858
+CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' early, al ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -85,7 +513,7 @@ CVE-2026-56858
 	NOTE: Fixed by: https://github.com/golang/go/commit/bcdba48a6adcaceabb3696e46b50be21dc739b5e (go1.27rc3)
 	NOTE: Fixed by: https://github.com/golang/go/commit/33ecb966ca47e55034272a9146e23e9909507f6d (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 (go1.25.13)
-CVE-2026-33818
+CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...)
 	- golang-1.27 <unfixed>
 	- golang-1.26 <unfixed>
 	- golang-1.25 <unfixed>
@@ -797,6 +1225,7 @@ CVE-2026-13048 (Data::MuForm::Localizer versions through 0.05 for Perl execute P
 CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 f ...)
 	NOT-FOR-US: Form::Processor Perl module
 CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a server ad ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -804,6 +1233,7 @@ CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a serv
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -811,6 +1241,7 @@ CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TY
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an object crea ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -818,6 +1249,7 @@ CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an object
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a non-supe ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -825,6 +1257,7 @@ CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a non
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data type functi ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -832,6 +1265,7 @@ CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data type
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -839,6 +1273,7 @@ CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query author to e ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -846,6 +1281,7 @@ CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query autho
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role membership, role  ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -853,6 +1289,7 @@ CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role membership,
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type selectivit ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -860,6 +1297,7 @@ CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type sele
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -867,6 +1305,7 @@ CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows t
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied hash allows ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -874,6 +1313,7 @@ CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied hash
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object creator  ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -881,6 +1321,7 @@ CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object cr
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14671/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM authentication all ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <not-affected> ((Vulnerable code not present)
@@ -888,6 +1329,7 @@ CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM authenticati
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -902,6 +1344,7 @@ CVE-2026-14676 (Heap buffer overflow in PostgreSQL pg_stat_statements allows the
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl all ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -909,6 +1352,7 @@ CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and plpe
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit function reads  ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -916,6 +1360,7 @@ CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit function
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching allows an o ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -923,6 +1368,7 @@ CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching allow
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments allows a ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -930,6 +1376,7 @@ CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments al
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14680/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI support ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <not-affected> (Vulnerable code not present)
@@ -937,6 +1384,7 @@ CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI s
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -944,6 +1392,7 @@ CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object o
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -958,6 +1407,7 @@ CVE-2026-16238 (Type confusion in PostgreSQL pg_restore_attribute_stats() allows
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -965,6 +1415,7 @@ CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows a
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server administ ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -972,6 +1423,7 @@ CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server ad
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a user to d ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -979,6 +1431,7 @@ CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a use
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -986,6 +1439,7 @@ CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a malic
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function transform  ...)
+	{DSA-6438-1}
 	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
@@ -8521,7 +8975,7 @@ CVE-2026-70646 (aiosend is a synchronous and asynchronous Crypto Pay API client.
 	NOT-FOR-US: aiosend
 CVE-2026-70637 (LightFTP through 2.4 contains multiple data race vulnerabilities in ft ...)
 	NOT-FOR-US: LightFTP
-CVE-2026-70556 (Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in ...)
+CVE-2026-70556 (Hubzilla  versions prior to 11.4 contains a cross-site request forgery ...)
 	NOT-FOR-US: Hubzilla
 CVE-2026-68750 (Inefficient Algorithmic Complexity vulnerability in the traversal engi ...)
 	NOT-FOR-US: rrrene html_sanitize_ex
@@ -69513,7 +69967,7 @@ CVE-2025-71310 (The GDPR cookies module for Backdrop CMS (before   1.x-1.3.5) do
 	NOT-FOR-US: GDPR cookies module for Backdrop CMS
 CVE-2025-62745 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-48099
+CVE-2026-48099 (WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiD ...)
 	- python-wsgidav <itp> (bug #1032213)
 CVE-2026-48715 (radvd is a router advertisement daemon for IPv6. Prior to version 2.21 ...)
 	- radvd <unfixed> (bug #1138049; unimportant)
@@ -74401,7 +74855,7 @@ CVE-2026-6479 (Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allo
 	- postgresql-13 <removed>
 	NOTE: https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
 CVE-2026-6473 (Integer wraparound in multiple PostgreSQL server features allows an un ...)
-	{DSA-6270-1 DSA-6269-1 DLA-4646-1}
+	{DSA-6438-1 DSA-6270-1 DSA-6269-1 DLA-4646-1}
 	- postgresql-18 18.4-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dd25db846c8e47a46ccf98cc2610c165c0e5e84c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dd25db846c8e47a46ccf98cc2610c165c0e5e84c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/a10202c3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list