[Git][security-tracker-team/security-tracker][master] Add new python-socketio issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 16 07:06:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3b763f0b by Salvatore Bonaccorso at 2026-08-16T08:05:55+02:00
Add new python-socketio issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7606,7 +7606,9 @@ CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The file-uploa
 CVE-2026-48813 (Flawfinder is a a static analysis tool for finding vulnerabilities in  ...)
 	NOT-FOR-US: Flawfinder
 CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO realtime c ...)
-	TODO: check
+	- python-engineio <unfixed>
+	NOTE: https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
+	NOTE: Fixed by: https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e (v5.16.4)
 CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
 	NOT-FOR-US: TypeBot
 CVE-2026-48763 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a d ...)
@@ -9143,9 +9145,12 @@ CVE-2026-50058 (A vulnerability has been identified in Solid Edge SE2025 (All ve
 CVE-2026-49179 (Improper neutralization of special elements used in a command ('comman ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
-	TODO: check
+	- python-engineio <unfixed>
+	NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9
+	TODO: checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue
 CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
-	TODO: check
+	- python-engineio <unfixed>
+	NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5
 CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the open-source datab ...)
 	NOT-FOR-US: Turso CLI
 CVE-2026-48771 (ishankportfolio is a portfolio website. Prior to version 1.0.1, contac ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b763f0b7f547172c3182a478b0925862b33c1f3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b763f0b7f547172c3182a478b0925862b33c1f3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/c869aadc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list