[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 16 14:08:30 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2aed2f37 by Salvatore Bonaccorso at 2026-08-16T15:07:58+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4942,10 +4942,10 @@ CVE-2026-49826 (Concourse is a container-based automation system written in Go.
CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4 ...)
NOT-FOR-US: erlang_quic
CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
- - capstone <unfixed>
+ - capstone <unfixed> (bug #1144518)
NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-jrw4-wj52-2vw8
CVE-2026-49263 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
- - capstone <unfixed>
+ - capstone <unfixed> (bug #1144519)
NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-5m9f-vqcm-g5pr
CVE-2026-48528 (Metacat is data repository software that helps researchers preserve, s ...)
NOT-FOR-US: Metacat
@@ -7794,7 +7794,7 @@ CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The file-uploa
CVE-2026-48813 (Flawfinder is a a static analysis tool for finding vulnerabilities in ...)
NOT-FOR-US: Flawfinder
CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO realtime c ...)
- - python-engineio <unfixed>
+ - python-engineio <unfixed> (bug #1144515)
NOTE: https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
NOTE: Fixed by: https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e (v5.16.4)
CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
@@ -9335,11 +9335,11 @@ CVE-2026-50058 (A vulnerability has been identified in Solid Edge SE2025 (All ve
CVE-2026-49179 (Improper neutralization of special elements used in a command ('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
- - python-engineio <unfixed>
+ - python-engineio <unfixed> (bug #1144516)
NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9
TODO: checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue
CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
- - python-engineio <unfixed>
+ - python-engineio <unfixed> (bug #1144517)
NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5
CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the open-source datab ...)
NOT-FOR-US: Turso CLI
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aed2f375227a9b36c62458ec91b6b283feb7eb6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aed2f375227a9b36c62458ec91b6b283feb7eb6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/85e855aa/attachment.htm>
More information about the debian-security-tracker-commits
mailing list