[Git][security-tracker-team/security-tracker][master] Mark CVE-2026-52844 as Windows specific in all suites

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 15:10:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
465db349 by Salvatore Bonaccorso at 2026-08-14T16:10:08+02:00
Mark CVE-2026-52844 as Windows specific in all suites

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -48643,15 +48643,9 @@ CVE-2026-52845 (Caddy is an extensible server platform that uses TLS by default.
 	- caddy 2.11.4-1 (bug #1140773)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-f59h-q822-g45g
 CVE-2026-52844 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
-	- caddy 2.11.4-1 (bug #1140773)
-	[trixie] - caddy <not-affected> (Windows-specific)
-	[bookworm] - caddy <not-affected> (Windows-specific)
+	- caddy <not-affected> (Windows-specific)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-qrp7-cvwr-j2c6
 	NOTE: Fixed by: https://github.com/caddyserver/caddy/commit/217a78582465e33498276aff83d9aaeb63a2f88a (v2.11.4)
-	NOTE: The bypass needs the OS to treat backslash as a path separator: the path matcher
-	NOTE: cleans with path.Clean() (POSIX, never splits on backslash) while file_server
-	NOTE: resolves with filepath.Join(). On Linux both agree, and the fix is guarded by
-	NOTE: runtime.GOOS == "windows".
 CVE-2026-52680 (Apache Kyuubi REST batch multipart upload handling uses the client-sup ...)
 	NOT-FOR-US: Apache Kyuubi
 CVE-2026-52673 (SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/465db349e976f27cbd7249a260458087627234be

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/465db349e976f27cbd7249a260458087627234be
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/2ba1d6ce/attachment.htm>


More information about the debian-security-tracker-commits mailing list