[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 08:47:07 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0c85ff9c by Salvatore Bonaccorso at 2026-08-14T09:46:55+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -437,9 +437,9 @@ CVE-2026-73252 [Built-in TLS short-record handling]
CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
- mongoose 7.23+ds-1
CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two sumdb ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -448,9 +448,9 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
NOTE: Fixed by: https://github.com/golang/go/commit/115eb476aaca4531374c42e19e6f199265c2e25e (go1.26.6)
NOTE: Fixed by: https://github.com/golang/go/commit/b0b8c97d1386bb3eb978e727ed0b1df8e14df569 (go1.25.13)
CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module content no ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -459,9 +459,9 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
NOTE: Fixed by: https://github.com/golang/go/commit/9f6980fd5c03840b0f6764e8ec7c705b90989eee (go1.26.6)
NOTE: Fixed by: https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb (go1.25.13)
CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing it to ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -470,9 +470,9 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
NOTE: Fixed by: https://github.com/golang/go/commit/9918f26ab31a6bf9209ecc06465cab0e287e90f1 (go1.26.6)
NOTE: Fixed by: https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 (go1.25.13)
CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it reads a ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -481,9 +481,9 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
NOTE: Fixed by: https://github.com/golang/go/commit/5bbd22ff78daf010c5bd19c466a0c45ac78503d4 (go1.26.6)
NOTE: Fixed by: https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 (go1.25.13)
CVE-2026-56860 (Previously, resolving relative paths containing parent directory ('..' ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -492,9 +492,9 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
NOTE: Fixed by: https://github.com/golang/go/commit/128893dbf9a6b4d6e7c99942096e2c0018d6fe57 (go1.26.6)
NOTE: Fixed by: https://github.com/golang/go/commit/962b300d32b68fd5f3c11674f711fc0e86251664 (go1.25.13)
CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as state- ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -503,9 +503,9 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
NOTE: Fixed by: https://github.com/golang/go/commit/b6432317a176b1b5595aa597dc1864a4cc4a81b2 (go1.26.6)
NOTE: Fixed by: https://github.com/golang/go/commit/677cfe54ecac147c4992e38204641bf61662524f (go1.25.13)
CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' early, al ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -514,9 +514,9 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
NOTE: Fixed by: https://github.com/golang/go/commit/33ecb966ca47e55034272a9146e23e9909507f6d (go1.26.6)
NOTE: Fixed by: https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 (go1.25.13)
CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...)
- - golang-1.27 <unfixed>
- - golang-1.26 <unfixed>
- - golang-1.25 <unfixed>
+ - golang-1.27 <unfixed> (bug #1144340)
+ - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
- golang-1.19 <removed>
- golang-1.15 <removed>
@@ -578,32 +578,32 @@ CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request forgery
CVE-2026-73628 (Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-s ...)
- serendipity <removed>
CVE-2026-73627 (JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4 ...)
- - jupyterlab <unfixed>
+ - jupyterlab <unfixed> (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm
CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/b ...)
- - jupyterlab <unfixed>
+ - jupyterlab <unfixed> (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j
CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code execution vulne ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144344)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3
CVE-2026-73624 (GitPython versions before 3.1.54 contain an arbitrary file overwrite v ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144344)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-x663-mwxc
CVE-2026-73623 (GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_ ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144344)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-6p8h-3wgx-97gf
CVE-2026-73622 (GitPython before 3.1.55 fails to disable environment variable expansio ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144344)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-94p4-4cq8-9g67
NOTE: Distinct but releated to CVE-2026-67322
CVE-2026-73621 (GitPython before 3.1.56 contains an argument injection vulnerability i ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144344)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-p538-c434-8v24
CVE-2026-73620 (GitPython before 3.1.57 fails to guard git option forwarding in IndexF ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144344)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3f7w-8rr8-f37f
CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the unsafe_ ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144344)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-539m-9xh6-q6rr
CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection vulnerability ...)
NOT-FOR-US: Budibase
@@ -1467,16 +1467,16 @@ CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower
CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentication s ...)
NOT-FOR-US: WolfStack
CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
- - golang-github-getkin-kin-openapi <unfixed>
+ - golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da (v0.144.0)
CVE-2026-73500 (etcd is a distributed key-value store for the data of a distributed sy ...)
- - etcd <unfixed>
+ - etcd <unfixed> (bug #1144346)
NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
NOTE: https://github.com/etcd-io/etcd/pull/22130
NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057 (v3.5.33)
CVE-2026-73499 (etcd is a distributed key-value store for the data of a distributed sy ...)
- - etcd <unfixed>
+ - etcd <unfixed> (bug #1144346)
NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7 (v3.5.33)
CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
@@ -1526,11 +1526,11 @@ CVE-2026-73433 (A flaw was found in GStreamer gst-plugins-good (avidemux). When
NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/c429d2a33496b54b8e6c00dbf1fdc4e3f52d8481 (1.26.8)
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0072.html
CVE-2026-73430 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an unaut ...)
- - rust-russh <unfixed>
+ - rust-russh <unfixed> (bug #1144347)
NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-5xvq-cp9x-6p6r
NOTE: Fixed by: https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d (v0.62.4)
CVE-2026-73429 (Russh is a Rust SSH client & server library. Prior to 0.62.4, a malici ...)
- - rust-russh <unfixed>
+ - rust-russh <unfixed> (bug #1144347)
NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-g9hv-x236-4qp3
NOTE: Fixed by: https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d (v0.62.4)
CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
@@ -1546,7 +1546,7 @@ CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/c
CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
NOT-FOR-US: Next.js
CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
- - jupyterlab <unfixed>
+ - jupyterlab <unfixed> (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
NOTE: https://github.com/jupyterlab/jupyterlab/pull/19186
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
@@ -2008,7 +2008,7 @@ CVE-2026-73297 (Microsoft UFO open-source framework for intelligent automation a
CVE-2026-73296 (Microsoft UFO open-source framework for intelligent automation across ...)
NOT-FOR-US: Microsoft UFO
CVE-2026-73295 (Material for MkDocs is a powerful documentation framework built on top ...)
- - mkdocs-material <unfixed>
+ - mkdocs-material <unfixed> (bug #1144348)
NOTE: https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
NOTE: Fixed by: https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25 (9.7.7)
CVE-2026-73294 (Semaphore UI is a web interface for managing DevOps tools. Prior to 2. ...)
@@ -2509,19 +2509,19 @@ CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop Protocol.
NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695 (3.30.0)
NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/pull/13065
CVE-2026-73235 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
- - freecad <unfixed>
+ - freecad <unfixed> (bug #1144349)
[trixie] - freecad <no-dsa> (Minor issue)
NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-cp6c-87x9-xf49
NOTE: https://github.com/FreeCAD/FreeCAD/pull/31280
NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/7d1b8f5806db578db99feb348e55a6b0eaff7c73 (1.1.2)
CVE-2026-73234 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
- - freecad <unfixed>
+ - freecad <unfixed> (bug #1144349)
[trixie] - freecad <no-dsa> (Minor issue)
NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-5vqh-3v38-jw2r
NOTE: https://github.com/FreeCAD/FreeCAD/pull/31281
NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/f19b18b7d93729a29a90e96e0ae192b5d054b86d (1.1.2)
CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
- - freecad <unfixed>
+ - freecad <unfixed> (bug #1144349)
[trixie] - freecad <no-dsa> (Minor issue)
NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-2rq3-gx3h-489q
NOTE: https://github.com/FreeCAD/FreeCAD/pull/31312
@@ -2537,7 +2537,7 @@ CVE-2026-73231 (Faker generates massive amounts of fake data in the browser and
CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security tools. ...)
NOT-FOR-US: Ente
CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building ...)
- - djangorestframework <unfixed>
+ - djangorestframework <unfixed> (bug #1144350)
NOTE: https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
NOTE: https://github.com/encode/django-rest-framework/pull/10012
NOTE: Fixed by: https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e (3.17.2)
@@ -2912,7 +2912,7 @@ CVE-2026-19560 (Use after free in Blink in Google Chrome prior to 151.0.7922.137
CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR R7000 model ...)
NOT-FOR-US: Netgear
CVE-2026-73228 (Django REST framework is a toolkit for building Web APIs. Prior to 3.1 ...)
- - djangorestframework <unfixed>
+ - djangorestframework <unfixed> (bug #1144350)
NOTE: https://github.com/encode/django-rest-framework/security/advisories/GHSA-2m8g-3cmr-wg3w
NOTE: https://github.com/encode/django-rest-framework/pull/10013
NOTE: Fixed by: https://github.com/encode/django-rest-framework/commit/2912dc98042f78e27636551fc22eeaf10f725fdd (3.17.2)
@@ -12157,7 +12157,7 @@ CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolat
[trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
- - jupyterlab <unfixed>
+ - jupyterlab <unfixed> (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
NOTE: https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6 (v4.6.0rc0)
NOTE: https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12 (v4.6.0rc1)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c85ff9cbf1ff2a7c0d8cbc782b02fd0444c6a97
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c85ff9cbf1ff2a7c0d8cbc782b02fd0444c6a97
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/89dfbaf6/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list