[Git][security-tracker-team/security-tracker][master] Mark CVE-2026-52844 as Windows specific in all suites
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 15:10:21 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
465db349 by Salvatore Bonaccorso at 2026-08-14T16:10:08+02:00
Mark CVE-2026-52844 as Windows specific in all suites
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -48643,15 +48643,9 @@ CVE-2026-52845 (Caddy is an extensible server platform that uses TLS by default.
- caddy 2.11.4-1 (bug #1140773)
NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-f59h-q822-g45g
CVE-2026-52844 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
- - caddy 2.11.4-1 (bug #1140773)
- [trixie] - caddy <not-affected> (Windows-specific)
- [bookworm] - caddy <not-affected> (Windows-specific)
+ - caddy <not-affected> (Windows-specific)
NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-qrp7-cvwr-j2c6
NOTE: Fixed by: https://github.com/caddyserver/caddy/commit/217a78582465e33498276aff83d9aaeb63a2f88a (v2.11.4)
- NOTE: The bypass needs the OS to treat backslash as a path separator: the path matcher
- NOTE: cleans with path.Clean() (POSIX, never splits on backslash) while file_server
- NOTE: resolves with filepath.Join(). On Linux both agree, and the fix is guarded by
- NOTE: runtime.GOOS == "windows".
CVE-2026-52680 (Apache Kyuubi REST batch multipart upload handling uses the client-sup ...)
NOT-FOR-US: Apache Kyuubi
CVE-2026-52673 (SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remo ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/465db349e976f27cbd7249a260458087627234be
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/465db349e976f27cbd7249a260458087627234be
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/2ba1d6ce/attachment.htm>
More information about the debian-security-tracker-commits
mailing list