[Git][security-tracker-team/security-tracker][master] Track fixed version for golang-1.26 issues fixed via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 17 06:18:13 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
32a1a27e by Salvatore Bonaccorso at 2026-08-17T07:17:43+02:00
Track fixed version for golang-1.26 issues fixed via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5644,7 +5644,7 @@ CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
- mongoose 7.23+ds-1
CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two sumdb ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5656,7 +5656,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
NOTE: Fixed by: https://github.com/golang/go/commit/b0b8c97d1386bb3eb978e727ed0b1df8e14df569 (go1.25.13)
CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module content no ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5668,7 +5668,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
NOTE: Fixed by: https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb (go1.25.13)
CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing it to ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5680,7 +5680,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
NOTE: Fixed by: https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 (go1.25.13)
CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it reads a ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5692,7 +5692,7 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
NOTE: Fixed by: https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 (go1.25.13)
CVE-2026-56860 (Previously, resolving relative paths containing parent directory ('..' ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5704,7 +5704,7 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
NOTE: Fixed by: https://github.com/golang/go/commit/962b300d32b68fd5f3c11674f711fc0e86251664 (go1.25.13)
CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as state- ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5716,7 +5716,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
NOTE: Fixed by: https://github.com/golang/go/commit/677cfe54ecac147c4992e38204641bf61662524f (go1.25.13)
CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' early, al ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5728,7 +5728,7 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
NOTE: Fixed by: https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 (go1.25.13)
CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...)
- golang-1.27 <unfixed> (bug #1144340)
- - golang-1.26 <unfixed> (bug #1144341)
+ - golang-1.26 1.26.6-1 (bug #1144341)
- golang-1.25 1.25.13-1 (bug #1144342)
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32a1a27e02699300be5de5bd18e00500f44fb3f7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32a1a27e02699300be5de5bd18e00500f44fb3f7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/6e7ce84f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list