[Git][security-tracker-team/security-tracker][master] Track fixed version for golang-1.26 issues fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 06:18:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
32a1a27e by Salvatore Bonaccorso at 2026-08-17T07:17:43+02:00
Track fixed version for golang-1.26 issues fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5644,7 +5644,7 @@ CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
 	- mongoose 7.23+ds-1
 CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two sumdb  ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5656,7 +5656,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
 	NOTE: Fixed by: https://github.com/golang/go/commit/b0b8c97d1386bb3eb978e727ed0b1df8e14df569 (go1.25.13)
 CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module content no ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5668,7 +5668,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
 	NOTE: Fixed by: https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb (go1.25.13)
 CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing it to  ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5680,7 +5680,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
 	NOTE: Fixed by: https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 (go1.25.13)
 CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it reads a  ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5692,7 +5692,7 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
 	NOTE: Fixed by: https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 (go1.25.13)
 CVE-2026-56860 (Previously, resolving relative paths containing parent directory ('..' ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5704,7 +5704,7 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
 	NOTE: Fixed by: https://github.com/golang/go/commit/962b300d32b68fd5f3c11674f711fc0e86251664 (go1.25.13)
 CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as state- ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5716,7 +5716,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
 	NOTE: Fixed by: https://github.com/golang/go/commit/677cfe54ecac147c4992e38204641bf61662524f (go1.25.13)
 CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' early, al ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
@@ -5728,7 +5728,7 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
 	NOTE: Fixed by: https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 (go1.25.13)
 CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...)
 	- golang-1.27 <unfixed> (bug #1144340)
-	- golang-1.26 <unfixed> (bug #1144341)
+	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32a1a27e02699300be5de5bd18e00500f44fb3f7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32a1a27e02699300be5de5bd18e00500f44fb3f7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/6e7ce84f/attachment.htm>


More information about the debian-security-tracker-commits mailing list