[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Aug 14 11:43:52 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b2bc88ba by Moritz Muehlenhoff at 2026-08-14T12:43:00+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -441,6 +441,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80744
@@ -452,6 +453,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80745
@@ -463,6 +465,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80481
@@ -474,6 +477,7 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80205
@@ -485,6 +489,7 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80494
@@ -496,6 +501,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80528
@@ -507,6 +513,7 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80435
@@ -518,6 +525,7 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhausti
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80405
@@ -1468,15 +1476,18 @@ CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentica
NOT-FOR-US: WolfStack
CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
- golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
+ [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da (v0.144.0)
CVE-2026-73500 (etcd is a distributed key-value store for the data of a distributed sy ...)
- etcd <unfixed> (bug #1144346)
+ [trixie] - etcd <no-dsa> (Minor issue)
NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
NOTE: https://github.com/etcd-io/etcd/pull/22130
NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057 (v3.5.33)
CVE-2026-73499 (etcd is a distributed key-value store for the data of a distributed sy ...)
- etcd <unfixed> (bug #1144346)
+ [trixie] - etcd <no-dsa> (Minor issue)
NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7 (v3.5.33)
CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
@@ -2497,12 +2508,14 @@ CVE-2026-73243 (kkFileView is a universal file online preview project based on S
NOT-FOR-US: kkFileView
CVE-2026-73242 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
- freerdp3 3.30.0+dfsg-1
+ [trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc (3.30.0)
CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
- freerdp3 3.30.0+dfsg-1
+ [trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x
NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
@@ -2657,6 +2670,7 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure
- snipe-it <itp> (bug #1005172)
CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command is gated ...)
- freeipa <unfixed>
+ [trixie] - freeipa <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2514019
CVE-2026-19217 (The Royal Addons for Elementor WordPress plugin before 1.7.1065 does ...)
NOT-FOR-US: WordPress plugin
@@ -3154,10 +3168,12 @@ CVE-2026-72712 (Nmap versions up to and including 7.99 contains a denial of serv
NOTE: Crash in CLI tool, no security impact
CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a root us ...)
- mrtg <unfixed>
+ [trixie] - mrtg <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460973
NOTE: Fixed by: https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269
CVE-2026-72693 (`openvt -u` is intended to identify the owner of the current VT and th ...)
- kbd <unfixed>
+ [trixie] - kbd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462115
NOTE: Fixed by: https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698 (v2.10.0)
CVE-2026-72610 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
@@ -5004,6 +5020,7 @@ CVE-2026-66760 (SAP Approuter does not correctly validate client certificates in
NOT-FOR-US: SAP
CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a process ...)
- libvirt 12.6.0-1
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513065
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b (v12.6.0-rc2)
CVE-2026-5304 (An ACAP configuration file lacks input validation, which could potenti ...)
@@ -5445,6 +5462,7 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory
NOT-FOR-US: Nishishi Factory
CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or convert op ...)
- libvirt 12.6.0-1
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513066
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/69335a484768d550854da1133d5490074695e825 (v12.6.0-rc2)
CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection ...)
@@ -10725,6 +10743,7 @@ CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is vulnerable
NOT-FOR-US: WordPress plugin
CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with network access ...)
- isc-dhcp <removed>
+ [trixie] - isc-dhcp <ignored> (ISC DHCP not covered by security support in Trixie)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2508081
CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPr ...)
NOT-FOR-US: WordPress plugin
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/a55be9bb/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list