[Git][security-tracker-team/security-tracker][master] Track fixed version for some jupyterlab issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 16 13:56:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6d336f47 by Salvatore Bonaccorso at 2026-08-16T14:56:12+02:00
Track fixed version for some jupyterlab issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5186,11 +5186,11 @@ CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth
 CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
 	NOT-FOR-US: Next.js
 CVE-2026-73417 (jupyterlab is an extensible environment for interactive and reproducib ...)
-	- jupyterlab <unfixed> (bug #1144463)
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144463)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj
 	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
 CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
-	- jupyterlab <unfixed> (bug #1144464)
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144464)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-89vp-jrxv-24w8
 	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
 CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 3.39.18, packag ...)
@@ -5721,11 +5721,11 @@ CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request forgery
 CVE-2026-73628 (Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-s ...)
 	- serendipity <removed>
 CVE-2026-73627 (JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4 ...)
-	- jupyterlab <unfixed> (bug #1144343)
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm
 	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
 CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/b ...)
-	- jupyterlab <unfixed> (bug #1144343)
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j
 	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
 CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code execution vulne ...)
@@ -6695,7 +6695,7 @@ CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/c
 CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
 	NOT-FOR-US: Next.js
 CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
-	- jupyterlab <unfixed> (bug #1144343)
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
 	NOTE: https://github.com/jupyterlab/jupyterlab/pull/19186
 	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
@@ -17340,7 +17340,7 @@ CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolat
 	[trixie] - guzzle <no-dsa> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
-	- jupyterlab <unfixed> (bug #1144343)
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
 	NOTE: https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6 (v4.6.0rc0)
 	NOTE: https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12 (v4.6.0rc1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d336f47a9bc872d1fae3f01c9f1596cb79c57ea

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d336f47a9bc872d1fae3f01c9f1596cb79c57ea
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/c2891d7b/attachment.htm>


More information about the debian-security-tracker-commits mailing list