[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 08:47:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0c85ff9c by Salvatore Bonaccorso at 2026-08-14T09:46:55+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -437,9 +437,9 @@ CVE-2026-73252 [Built-in TLS short-record handling]
 CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
 	- mongoose 7.23+ds-1
 CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two sumdb  ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -448,9 +448,9 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
 	NOTE: Fixed by: https://github.com/golang/go/commit/115eb476aaca4531374c42e19e6f199265c2e25e (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/b0b8c97d1386bb3eb978e727ed0b1df8e14df569 (go1.25.13)
 CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module content no ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -459,9 +459,9 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
 	NOTE: Fixed by: https://github.com/golang/go/commit/9f6980fd5c03840b0f6764e8ec7c705b90989eee (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb (go1.25.13)
 CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing it to  ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -470,9 +470,9 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
 	NOTE: Fixed by: https://github.com/golang/go/commit/9918f26ab31a6bf9209ecc06465cab0e287e90f1 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 (go1.25.13)
 CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it reads a  ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -481,9 +481,9 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
 	NOTE: Fixed by: https://github.com/golang/go/commit/5bbd22ff78daf010c5bd19c466a0c45ac78503d4 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 (go1.25.13)
 CVE-2026-56860 (Previously, resolving relative paths containing parent directory ('..' ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -492,9 +492,9 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
 	NOTE: Fixed by: https://github.com/golang/go/commit/128893dbf9a6b4d6e7c99942096e2c0018d6fe57 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/962b300d32b68fd5f3c11674f711fc0e86251664 (go1.25.13)
 CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as state- ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -503,9 +503,9 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
 	NOTE: Fixed by: https://github.com/golang/go/commit/b6432317a176b1b5595aa597dc1864a4cc4a81b2 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/677cfe54ecac147c4992e38204641bf61662524f (go1.25.13)
 CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' early, al ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -514,9 +514,9 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
 	NOTE: Fixed by: https://github.com/golang/go/commit/33ecb966ca47e55034272a9146e23e9909507f6d (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 (go1.25.13)
 CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...)
-	- golang-1.27 <unfixed>
-	- golang-1.26 <unfixed>
-	- golang-1.25 <unfixed>
+	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
@@ -578,32 +578,32 @@ CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request forgery
 CVE-2026-73628 (Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-s ...)
 	- serendipity <removed>
 CVE-2026-73627 (JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4 ...)
-	- jupyterlab <unfixed>
+	- jupyterlab <unfixed> (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm
 CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/b ...)
-	- jupyterlab <unfixed>
+	- jupyterlab <unfixed> (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j
 CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code execution vulne ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3
 CVE-2026-73624 (GitPython versions before 3.1.54 contain an arbitrary file overwrite v ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-x663-mwxc
 CVE-2026-73623 (GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_ ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-6p8h-3wgx-97gf
 CVE-2026-73622 (GitPython before 3.1.55 fails to disable environment variable expansio ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-94p4-4cq8-9g67
 	NOTE: Distinct but releated to CVE-2026-67322
 CVE-2026-73621 (GitPython before 3.1.56 contains an argument injection vulnerability i ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-p538-c434-8v24
 CVE-2026-73620 (GitPython before 3.1.57 fails to guard git option forwarding in IndexF ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3f7w-8rr8-f37f
 CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the unsafe_ ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-539m-9xh6-q6rr
 CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection vulnerability ...)
 	NOT-FOR-US: Budibase
@@ -1467,16 +1467,16 @@ CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower
 CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentication s ...)
 	NOT-FOR-US: WolfStack
 CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
-	- golang-github-getkin-kin-openapi <unfixed>
+	- golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da (v0.144.0)
 CVE-2026-73500 (etcd is a distributed key-value store for the data of a distributed sy ...)
-	- etcd <unfixed>
+	- etcd <unfixed> (bug #1144346)
 	NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
 	NOTE: https://github.com/etcd-io/etcd/pull/22130
 	NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057 (v3.5.33)
 CVE-2026-73499 (etcd is a distributed key-value store for the data of a distributed sy ...)
-	- etcd <unfixed>
+	- etcd <unfixed> (bug #1144346)
 	NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
 	NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7 (v3.5.33)
 CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
@@ -1526,11 +1526,11 @@ CVE-2026-73433 (A flaw was found in GStreamer gst-plugins-good (avidemux). When
 	NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/c429d2a33496b54b8e6c00dbf1fdc4e3f52d8481 (1.26.8)
 	NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0072.html
 CVE-2026-73430 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an unaut ...)
-	- rust-russh <unfixed>
+	- rust-russh <unfixed> (bug #1144347)
 	NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-5xvq-cp9x-6p6r
 	NOTE: Fixed by: https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d (v0.62.4)
 CVE-2026-73429 (Russh is a Rust SSH client & server library. Prior to 0.62.4, a malici ...)
-	- rust-russh <unfixed>
+	- rust-russh <unfixed> (bug #1144347)
 	NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-g9hv-x236-4qp3
 	NOTE: Fixed by: https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d (v0.62.4)
 CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
@@ -1546,7 +1546,7 @@ CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/c
 CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
 	NOT-FOR-US: Next.js
 CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
-	- jupyterlab <unfixed>
+	- jupyterlab <unfixed> (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
 	NOTE: https://github.com/jupyterlab/jupyterlab/pull/19186
 	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
@@ -2008,7 +2008,7 @@ CVE-2026-73297 (Microsoft UFO open-source framework for intelligent automation a
 CVE-2026-73296 (Microsoft UFO open-source framework for intelligent automation across  ...)
 	NOT-FOR-US: Microsoft UFO
 CVE-2026-73295 (Material for MkDocs is a powerful documentation framework built on top ...)
-	- mkdocs-material <unfixed>
+	- mkdocs-material <unfixed> (bug #1144348)
 	NOTE: https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
 	NOTE: Fixed by: https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25 (9.7.7)
 CVE-2026-73294 (Semaphore UI is a web interface for managing DevOps tools. Prior to 2. ...)
@@ -2509,19 +2509,19 @@ CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop Protocol.
 	NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695 (3.30.0)
 	NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/pull/13065
 CVE-2026-73235 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
-	- freecad <unfixed>
+	- freecad <unfixed> (bug #1144349)
 	[trixie] - freecad <no-dsa> (Minor issue)
 	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-cp6c-87x9-xf49
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/31280
 	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/7d1b8f5806db578db99feb348e55a6b0eaff7c73 (1.1.2)
 CVE-2026-73234 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
-	- freecad <unfixed>
+	- freecad <unfixed> (bug #1144349)
 	[trixie] - freecad <no-dsa> (Minor issue)
 	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-5vqh-3v38-jw2r
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/31281
 	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/f19b18b7d93729a29a90e96e0ae192b5d054b86d (1.1.2)
 CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
-	- freecad <unfixed>
+	- freecad <unfixed> (bug #1144349)
 	[trixie] - freecad <no-dsa> (Minor issue)
 	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-2rq3-gx3h-489q
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/31312
@@ -2537,7 +2537,7 @@ CVE-2026-73231 (Faker generates massive amounts of fake data in the browser and
 CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security tools.  ...)
 	NOT-FOR-US: Ente
 CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building  ...)
-	- djangorestframework <unfixed>
+	- djangorestframework <unfixed> (bug #1144350)
 	NOTE: https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
 	NOTE: https://github.com/encode/django-rest-framework/pull/10012
 	NOTE: Fixed by: https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e (3.17.2)
@@ -2912,7 +2912,7 @@ CVE-2026-19560 (Use after free in Blink in Google Chrome prior to 151.0.7922.137
 CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR R7000 model ...)
 	NOT-FOR-US: Netgear
 CVE-2026-73228 (Django REST framework is a toolkit for building Web APIs. Prior to 3.1 ...)
-	- djangorestframework <unfixed>
+	- djangorestframework <unfixed> (bug #1144350)
 	NOTE: https://github.com/encode/django-rest-framework/security/advisories/GHSA-2m8g-3cmr-wg3w
 	NOTE: https://github.com/encode/django-rest-framework/pull/10013
 	NOTE: Fixed by: https://github.com/encode/django-rest-framework/commit/2912dc98042f78e27636551fc22eeaf10f725fdd (3.17.2)
@@ -12157,7 +12157,7 @@ CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolat
 	[trixie] - guzzle <no-dsa> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
-	- jupyterlab <unfixed>
+	- jupyterlab <unfixed> (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
 	NOTE: https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6 (v4.6.0rc0)
 	NOTE: https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12 (v4.6.0rc1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c85ff9cbf1ff2a7c0d8cbc782b02fd0444c6a97

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c85ff9cbf1ff2a7c0d8cbc782b02fd0444c6a97
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/89dfbaf6/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list