[Git][security-tracker-team/security-tracker][master] Track fixed version for some jupyterlab issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 16 13:56:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6d336f47 by Salvatore Bonaccorso at 2026-08-16T14:56:12+02:00
Track fixed version for some jupyterlab issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5186,11 +5186,11 @@ CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth
CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
NOT-FOR-US: Next.js
CVE-2026-73417 (jupyterlab is an extensible environment for interactive and reproducib ...)
- - jupyterlab <unfixed> (bug #1144463)
+ - jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144463)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
- - jupyterlab <unfixed> (bug #1144464)
+ - jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144464)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-89vp-jrxv-24w8
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 3.39.18, packag ...)
@@ -5721,11 +5721,11 @@ CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request forgery
CVE-2026-73628 (Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-s ...)
- serendipity <removed>
CVE-2026-73627 (JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4 ...)
- - jupyterlab <unfixed> (bug #1144343)
+ - jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/b ...)
- - jupyterlab <unfixed> (bug #1144343)
+ - jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code execution vulne ...)
@@ -6695,7 +6695,7 @@ CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/c
CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
NOT-FOR-US: Next.js
CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
- - jupyterlab <unfixed> (bug #1144343)
+ - jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
NOTE: https://github.com/jupyterlab/jupyterlab/pull/19186
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
@@ -17340,7 +17340,7 @@ CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolat
[trixie] - guzzle <no-dsa> (Minor issue)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
- - jupyterlab <unfixed> (bug #1144343)
+ - jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
NOTE: https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6 (v4.6.0rc0)
NOTE: https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12 (v4.6.0rc1)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d336f47a9bc872d1fae3f01c9f1596cb79c57ea
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d336f47a9bc872d1fae3f01c9f1596cb79c57ea
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/c2891d7b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list