[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 17 17:09:09 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1d46475e by Moritz Muehlenhoff at 2026-08-17T18:08:57+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -16780,6 +16780,7 @@ CVE-2026-69198 (ip-address is a library for parsing and manipulating IPv4 and IP
 	NOTE: Address6 in 10.2.0.
 CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
 	- node-ip-address 10.3.1-1
+	[trixie] - node-ip-address <no-dsa> (Minor issue)
 	NOTE: https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr
 	NOTE: Fixed by: https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e (v10.3.1)
 CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication for ever ...)
@@ -20941,6 +20942,7 @@ CVE-2026-17650 (Use after free in Compositing in Google Chrome prior to 151.0.79
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16728 (undici's retry interceptor can deliver a response whose body length do ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1
+	[trixie] - node-undici <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
 CVE-2026-16727 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
 	NOT-FOR-US: ASUS
@@ -20998,6 +21000,7 @@ CVE-2026-15235 (The MotoPress Hotel Booking WordPress plugin before 6.0.4 does n
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15157 (undici does not validate the type property of a duck-typed blob-like r ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1
+	[trixie] - node-undici <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
 CVE-2026-15153 (The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise a ...)
 	NOT-FOR-US: WordPress plugin
@@ -21009,6 +21012,7 @@ CVE-2026-14923 (The Sync Post With Other Site WordPress plugin before 1.9.3 does
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14643 (undici's cache interceptor mishandles optional whitespace placed aroun ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1
+	[trixie] - node-undici <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54
 CVE-2026-14602 (The Remote API WordPress plugin through 0.2 does not authenticate a re ...)
 	NOT-FOR-US: WordPress plugin
@@ -21500,6 +21504,7 @@ CVE-2026-16751 (Authorization Bypass in the emergency recovery approval componen
 	NOT-FOR-US: Ente Technologies Ente Museum Server
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143063)
+	[trixie] - node-undici <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
 	NOT-FOR-US: WordPress plugin
@@ -21533,6 +21538,7 @@ CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Devela
 	NOT-FOR-US: Develar app-builder
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143070)
+	[trixie] - node-undici <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
 	NOT-FOR-US: WordPress plugin
@@ -25692,6 +25698,7 @@ CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass via
 	NOTE: https://launchpad.net/bugs/2161254
 CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped user  ...)
 	- ironic-python-agent 11.5.0-4 (bug #1142857)
+	[trixie] - ironic-python-agent <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/5
 	NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2160050
 CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulne ...)
@@ -25895,6 +25902,7 @@ CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vul
 	NOT-FOR-US: Cal.com (calcom/cal.diy)
 CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious bootc cont ...)
 	- ironic-python-agent 11.5.0-4 (bug #1142854)
+	[trixie] - ironic-python-agent <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
 CVE-2026-58264 [heap-based buffer overrun in command handler]
@@ -29300,6 +29308,7 @@ CVE-2026-59143 (Data::RoaringBitmap::Shared versions before 0.02 for Perl allow
 	NOT-FOR-US: Data::RoaringBitmap::Shared Perl module
 CVE-2026-56852 (A norm.Iter can enter an infinite loop when handling input containing  ...)
 	- golang-golang-x-text 0.40.0-1 (bug #1142674)
+	[trixie] - golang-golang-x-text <no-dsa> (Minor issue)
 	[bookworm] - golang-golang-x-text <postponed> (Limited support, minor issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8)
 	[bullseye] - golang-golang-x-text <postponed> (Limited support, minor issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8)
 	NOTE: https://github.com/golang/go/issues/80142


=====================================
data/dsa-needed.txt
=====================================
@@ -144,7 +144,7 @@ rust-wasmtime
 --
 shaarli
 --
-srt
+srt (jmm)
 --
 starlette
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d46475e441242989edb3adce87d7409590e2f17

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d46475e441242989edb3adce87d7409590e2f17
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/f42d1255/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list