[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 16 20:14:28 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
58a26869 by security tracker role at 2026-08-16T19:14:21+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,14 +1,62 @@
-CVE-2026-72888
+CVE-2026-74797 (OpenTofu versions before 1.11.4 contain a denial of service vulnerabil ...)
+ TODO: check
+CVE-2026-74796 (OpenTofu before 1.11.7 fails to validate existing symlinks in the prov ...)
+ TODO: check
+CVE-2026-74795 (Scriban before 6.6.0 contains an uncontrolled recursion vulnerability ...)
+ TODO: check
+CVE-2026-74794 (Scriban before 6.6.0 contains an infinite recursion vulnerability in o ...)
+ TODO: check
+CVE-2026-74792 (Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack ove ...)
+ TODO: check
+CVE-2026-74791 (Scriban before 7.0.0 fails to clear the CachedTemplates dictionary whe ...)
+ TODO: check
+CVE-2026-74790 (Scriban before 7.0.0 caches TypedObjectAccessor by Type only without c ...)
+ TODO: check
+CVE-2026-74789 (Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constra ...)
+ TODO: check
+CVE-2026-74788 (Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontro ...)
+ TODO: check
+CVE-2026-74787 (Scriban before 7.0.0 contains an uncontrolled recursion vulnerability ...)
+ TODO: check
+CVE-2026-74786 (Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of ...)
+ TODO: check
+CVE-2026-74785 (Scriban before 7.0.0 contains three distinct denial-of-service vulnera ...)
+ TODO: check
+CVE-2026-74784 (Scriban before 7.2.0 contains a denial of service vulnerability in the ...)
+ TODO: check
+CVE-2026-74783 (Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing Expressio ...)
+ TODO: check
+CVE-2026-74251 (Joomla Extension - phoca.cz - Unauthenticated SQL injection via attri ...)
+ TODO: check
+CVE-2026-73062 (Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulne ...)
+ TODO: check
+CVE-2026-73061 (Scriban before 7.2.2 contains an access-modifier bypass vulnerability ...)
+ TODO: check
+CVE-2026-73060 (Scriban versions from 3.0.0 through 7.2.5 contain a denial of service ...)
+ TODO: check
+CVE-2026-73059 (stoatchat before 0.15.0 contains a permission bypass vulnerability in ...)
+ TODO: check
+CVE-2026-73058 (stoatchat versions before 0.15.0 fail to block the IPv6 unspecified ad ...)
+ TODO: check
+CVE-2026-73057 (stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in th ...)
+ TODO: check
+CVE-2026-73056 (SiYuan kernel versions before 3.7.4 contain an improper restriction of ...)
+ TODO: check
+CVE-2024-58375 (OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensiti ...)
+ TODO: check
+CVE-2024-13784 (The Contact Form, Survey, Quiz & Popup Form Builder \u2013 ARForms plu ...)
+ TODO: check
+CVE-2026-72888 (Net::OAuth versions before 0.32 for Perl allow memory exhaustion via u ...)
- libnet-oauth-perl 0.32-1 (bug #1144539)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733455/
NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-m2cv-cq5x-47ph
NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/ee713fc96263c70b3b9a5280612618b474576f8f
-CVE-2026-72887
+CVE-2026-72887 (Net::OAuth::Client versions before 0.32 for Perl allow the service pro ...)
- libnet-oauth-perl 0.32-1 (bug #1144539)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733454/
NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-jh72-4qq2-8j6g
NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/fd505dac1988723ed96721657663f2e4ac731644
-CVE-2026-74578 [crypto: algif_skcipher - force synchronous processing on trees without ctx->state]
+CVE-2026-74578 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
@@ -10378,7 +10426,7 @@ CVE-2025-13294 (An unauthenticated SQL injection vulnerability exists in the web
NOT-FOR-US: TBEA TLogger
CVE-2025-13293 (A hard-coded or default root account credential in TBEA TLogger V2.1.0 ...)
NOT-FOR-US: TBEA TLogger
-CVE-2026-19349
+CVE-2026-19349 (Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 b ...)
{DSA-6434-1 DLA-4734-1}
- lemonldap-ng 2.23.3+ds-1
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d (v2.23.3)
@@ -14429,16 +14477,17 @@ CVE-2026-43622 (llama.cpp builds b1886 through b7445 contain a double free vulne
CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not saniti ...)
NOT-FOR-US: WordPress plugin
CVE-2026-34502 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
- {DSA-6437-1}
+ {DSA-6437-1 DLA-4742-1}
- apr-util 1.6.4-1 (bug #1143837)
NOTE: https://lists.apache.org/thread/spk5643m4vq0mb8h5b9hz9gkp57ombl8
NOTE: Fixed by: https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872 (1.6.4-rc1-candidate)
CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
- {DSA-6437-1}
+ {DSA-6437-1 DLA-4742-1}
- apr-util 1.6.4-1 (bug #1143837)
NOTE: https://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv
NOTE: Fixed by: https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2 (1.6.4-rc1-candidate)
CVE-2026-34191 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+ {DLA-4742-1}
- apr-util 1.6.4-1 (bug #1143837; unimportant)
[trixie] - apr-util 1.6.3-3+deb13u1
NOTE: https://lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtf
@@ -14449,7 +14498,7 @@ CVE-2026-32548 (Unauthenticated Broken Access Control in SureCart <= 4.6.2 versi
CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...)
- {DSA-6437-1}
+ {DSA-6437-1 DLA-4742-1}
- apr-util 1.6.4-1 (bug #1143837)
NOTE: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
NOTE: Fixed by: https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8 (1.6.4-rc1-candidate)
@@ -14573,7 +14622,7 @@ CVE-2026-0637 (When an Event Publisher output adapter is configured with irrelev
CVE-2025-9266 (The Accelerate theme for WordPress is vulnerable to unauthorized modif ...)
NOT-FOR-US: WordPress plugin
CVE-2025-49506 (APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...)
- {DSA-6437-1}
+ {DSA-6437-1 DLA-4742-1}
- apr-util 1.6.4-1 (bug #1143837)
NOTE: https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
NOTE: Fixed by: https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e (1.6.4-rc1-candidate)
@@ -18191,7 +18240,7 @@ CVE-2026-62313 [Project isolation restriction bypass by omitting security.idmap.
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
NOTE: https://github.com/lxc/incus/pull/3750
CVE-2026-55707 (In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does ...)
- {DLA-4735-1}
+ {DSA-6444-1 DLA-4735-1}
- neutron 2:28.0.1-2 (bug #1143170)
NOTE: https://security.openstack.org/ossa/OSSA-2026-032.html
NOTE: https://bugs.launchpad.net/neutron/+bug/2152113
@@ -59932,12 +59981,14 @@ CVE-2026-42947 (A flaw in Naxclow's platform\u2019s onboarding workflow allows a
CVE-2026-42932 (Naxclow device identifiers use fixed manufacturing prefixes combined w ...)
NOT-FOR-US: Naxclow
CVE-2026-42306 (Moby is an open source container framework. In Docker Engine prior to ...)
+ {DSA-6443-1}
- docker.io 28.5.2+dfsg4-3 (bug #1139967)
NOTE: https://github.com/moby/moby/security/advisories/GHSA-rg2x-37c3-w2rh
NOTE: Fixed by: https://github.com/moby/moby/commit/43fa458a9c40873867e75221454de10709b04236 (docker-v29.5.1)
CVE-2026-41581 (Frappe is a full-stack web application framework. Prior to versions 15 ...)
NOT-FOR-US: Frappe
CVE-2026-41568 (Moby is an open source container framework. In Docker Engine prior to ...)
+ {DSA-6443-1}
- docker.io 28.5.2+dfsg4-3 (bug #1139966)
NOTE: https://github.com/moby/moby/security/advisories/GHSA-vp62-88p7-qqf5
NOTE: Fixed by: https://github.com/moby/moby/commit/64a22d80b93ddc1416b501b5145df02947312249 (docker-v29.5.1)
@@ -64382,6 +64433,7 @@ CVE-2026-45290 (Cloudburst Network provides network components used within Cloud
CVE-2026-42824 (Improper neutralization of special elements used in a command ('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-41567 (Moby is an open source container framework. In versions prior to 29.5. ...)
+ {DSA-6443-1}
- docker.io 28.5.2+dfsg4-3 (bug #1139965)
NOTE: https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r
NOTE: Fixed by: https://github.com/moby/moby/commit/2022313ffe5a8c04890b5295bc52670ee6df8070 (docker-v29.5.1)
@@ -108232,6 +108284,7 @@ CVE-2026-34042 (act is a project which allows for local running of github action
CVE-2026-34041 (act is a project which allows for local running of github actions. Pri ...)
NOT-FOR-US: nektos act
CVE-2026-34040 (Moby is an open source container framework. Prior to version 29.3.1, a ...)
+ {DSA-6443-1}
- docker.io 28.5.2+dfsg4-2 (bug #1136031)
[bookworm] - docker.io <no-dsa> (Minor issue)
NOTE: https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2
@@ -108240,6 +108293,7 @@ CVE-2026-34040 (Moby is an open source container framework. Prior to version 29.
CVE-2026-34036 (Dolibarr is an enterprise resource planning (ERP) and customer relatio ...)
- dolibarr <removed>
CVE-2026-33997 (Moby is an open source container framework. Prior to version 29.3.1, a ...)
+ {DSA-6443-1}
- docker.io 28.5.2+dfsg4-2 (bug #1136031)
[bookworm] - docker.io <no-dsa> (Minor issue)
NOTE: https://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9
@@ -109223,9 +109277,11 @@ CVE-2026-33750 (The brace-expansion library generates arbitrary strings containi
NOTE: https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v
NOTE: Fixed by: https://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5 (v2.0.3)
CVE-2026-33748 (BuildKit is a toolkit for converting source code to build artifacts in ...)
+ {DSA-6443-1}
- docker.io 28.5.2+dfsg4-3 (bug #1140189)
- golang-github-moby-buildkit <itp> (bug #1094971)
CVE-2026-33747 (BuildKit is a toolkit for converting source code to build artifacts in ...)
+ {DSA-6443-1}
- docker.io 28.5.2+dfsg4-3 (bug #1140189)
- golang-github-moby-buildkit <itp> (bug #1094971)
CVE-2026-33745 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58a2686924535e8385e3f53fc24c8022d50e8e40
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58a2686924535e8385e3f53fc24c8022d50e8e40
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/c2366de4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list