[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 20:13:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d550a0b3 by security tracker role at 2026-08-17T19:13:47+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,329 @@
+CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() in dri ...)
+	TODO: check
+CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was possible via u ...)
+	TODO: check
+CVE-2026-75059 (In JetBrains PyCharm before 2026.2.1 code execution via Quick Document ...)
+	TODO: check
+CVE-2026-75058 (In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Ecl ...)
+	TODO: check
+CVE-2026-75057 (In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were writte ...)
+	TODO: check
+CVE-2026-75056 (In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export too ...)
+	TODO: check
+CVE-2026-75055 (In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager coul ...)
+	TODO: check
+CVE-2026-75054 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the O ...)
+	TODO: check
+CVE-2026-75053 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the D ...)
+	TODO: check
+CVE-2026-75052 (In JetBrains IntelliJ IDEA before 2026.2.1 command execution via craft ...)
+	TODO: check
+CVE-2026-75051 (In JetBrains YouTrack before 2026.2.17917 unauthorised project transfe ...)
+	TODO: check
+CVE-2026-75050 (In JetBrains YouTrack before 2026.1.13901,  2026.2.17950 doS attack wa ...)
+	TODO: check
+CVE-2026-75049 (In JetBrains YouTrack before 2026.1.13903,  2026.2.17950 an authentica ...)
+	TODO: check
+CVE-2026-75048 (In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced co ...)
+	TODO: check
+CVE-2026-75047 (In JetBrains YouTrack before 2026.2.18177 doS attack was possible via  ...)
+	TODO: check
+CVE-2026-75046 (In JetBrains YouTrack before 2026.2.18112 an authenticated user could  ...)
+	TODO: check
+CVE-2026-75045 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13913,  2026.2.181 ...)
+	TODO: check
+CVE-2026-75044 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13914,  2026.2.180 ...)
+	TODO: check
+CVE-2026-75011 (A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the ...)
+	TODO: check
+CVE-2026-74901 (openssl_encrypt versions before 1.4.0 contain an authentication bypass ...)
+	TODO: check
+CVE-2026-74900 (openssl_encrypt versions before 1.4.0 contain a critical vulnerability ...)
+	TODO: check
+CVE-2026-74899 (openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnera ...)
+	TODO: check
+CVE-2026-74896 (openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnera ...)
+	TODO: check
+CVE-2026-74895 (openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictio ...)
+	TODO: check
+CVE-2026-74894 (openssl_encrypt before 1.4.0 contains an authentication bypass vulnera ...)
+	TODO: check
+CVE-2026-74893 (openssl_encrypt versions before 1.4.0 contain hardcoded default JWT si ...)
+	TODO: check
+CVE-2026-74892 (openssl_encrypt versions before 1.4.0 contain a hardcoded default secr ...)
+	TODO: check
+CVE-2026-74891 (openssl_encrypt versions before 1.4.0 contain hardcoded database crede ...)
+	TODO: check
+CVE-2026-74890 (openssl_encrypt versions before 1.4.0 contain an authentication bypass ...)
+	TODO: check
+CVE-2026-74889 (openssl_encrypt versions before 1.4.0 use HKDF with no salt and static ...)
+	TODO: check
+CVE-2026-74888 (openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key de ...)
+	TODO: check
+CVE-2026-74887 (openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'rando ...)
+	TODO: check
+CVE-2026-74886 (openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass  ...)
+	TODO: check
+CVE-2026-74885 (openssl_encrypt versions before 1.4.0 contain a logging bug in restore ...)
+	TODO: check
+CVE-2026-74884 (openssl_encrypt versions before 1.4.0 contain a path traversal vulnera ...)
+	TODO: check
+CVE-2026-74883 (openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnera ...)
+	TODO: check
+CVE-2026-74882 (openssl_encrypt versions before 1.4.0 contain an insecure default conf ...)
+	TODO: check
+CVE-2026-74881 (openssl_encrypt versions before 1.4.0 configure CORS with allow_origin ...)
+	TODO: check
+CVE-2026-74880 (openssl_encrypt versions before 1.4.0 accept refresh tokens as URL que ...)
+	TODO: check
+CVE-2026-74879 (openssl_encrypt versions before 1.4.0 contain an information disclosur ...)
+	TODO: check
+CVE-2026-74878 (openssl_encrypt versions before 1.4.0 use an in-memory rate limiter fo ...)
+	TODO: check
+CVE-2026-74877 (openssl_encrypt versions before 1.4.0 contain a missing ownership veri ...)
+	TODO: check
+CVE-2026-74876 (openssl_encrypt versions before 1.4.0 contain a vulnerability in Publi ...)
+	TODO: check
+CVE-2026-74875 (openssl_encrypt versions before 1.4.0 silently skip JSON schema valida ...)
+	TODO: check
+CVE-2026-74874 (openssl_encrypt versions before 1.4.0 use Python's non-cryptographic r ...)
+	TODO: check
+CVE-2026-74873 (openssl_encrypt versions before 1.4.0 expose passwords passed via the  ...)
+	TODO: check
+CVE-2026-74872 (openssl_encrypt versions before 1.4.0 contain an arbitrary code execut ...)
+	TODO: check
+CVE-2026-74871 (openssl_encrypt versions before 1.4.6 contain a key derivation flaw in ...)
+	TODO: check
+CVE-2026-74870 (openssl_encrypt (pip) versions <= 1.4.7 contain an information exposur ...)
+	TODO: check
+CVE-2026-74869 (stoatchat before 0.15.0 contains a missing authorization vulnerability ...)
+	TODO: check
+CVE-2026-74868 (SiYuan versions before 3.7.4 contain an unthrottled brute-force vulner ...)
+	TODO: check
+CVE-2026-74867 (SiYuan versions before 3.7.4 contain a cross-site request forgery vuln ...)
+	TODO: check
+CVE-2026-74858 (A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Imp ...)
+	TODO: check
+CVE-2026-74845 (Official Document Management System developed by 2100 Technology has a ...)
+	TODO: check
+CVE-2026-74843 (A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. ...)
+	TODO: check
+CVE-2026-74842 (A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e ...)
+	TODO: check
+CVE-2026-74802 (SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking  ...)
+	TODO: check
+CVE-2026-74801 (SiYuan before 3.7.4 fails to properly escape workspace directory paths ...)
+	TODO: check
+CVE-2026-74800 (SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Ty ...)
+	TODO: check
+CVE-2026-74799 (SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints includ ...)
+	TODO: check
+CVE-2026-74798 (SiYuan kernel before v3.7.4 contains a path traversal vulnerability in ...)
+	TODO: check
+CVE-2026-74254 (Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3. ...)
+	TODO: check
+CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE through unver ...)
+	TODO: check
+CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerabil ...)
+	TODO: check
+CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
+	TODO: check
+CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
+	TODO: check
+CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation vulnerabi ...)
+	TODO: check
+CVE-2026-73522 (COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnera ...)
+	TODO: check
+CVE-2026-73424 (Astro is a web framework for content-driven websites. From 10.0.3 unti ...)
+	TODO: check
+CVE-2026-71980 (Belledonne Communications bcg729 through 1.1.2 contains an out-of-boun ...)
+	TODO: check
+CVE-2026-71979 (INDI (Instrument Neutral Distributed Interface) indiserver through 2.2 ...)
+	TODO: check
+CVE-2026-71693
+	REJECTED
+CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in some of the ...)
+	TODO: check
+CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to scripts ...)
+	TODO: check
+CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
+	TODO: check
+CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
+	TODO: check
+CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version p ...)
+	TODO: check
+CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket deco ...)
+	TODO: check
+CVE-2026-68520 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
+	TODO: check
+CVE-2026-68519 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
+	TODO: check
+CVE-2026-68518 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
+	TODO: check
+CVE-2026-68517 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
+	TODO: check
+CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription component. T ...)
+	TODO: check
+CVE-2026-64868 (New API is a large language mode (LLM) gateway and artificial intellig ...)
+	TODO: check
+CVE-2026-64866 (New API is a large language mode (LLM) gateway and artificial intellig ...)
+	TODO: check
+CVE-2026-64865 (New API is a large language mode (LLM) gateway and artificial intellig ...)
+	TODO: check
+CVE-2026-64859 (New API is a large language mode (LLM) gateway and artificial intellig ...)
+	TODO: check
+CVE-2026-62982 (Glances is an open-source system cross-platform monitoring tool. From  ...)
+	TODO: check
+CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
+	TODO: check
+CVE-2026-60107
+	REJECTED
+CVE-2026-60106
+	REJECTED
+CVE-2026-59911 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion o ...)
+	TODO: check
+CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
+	TODO: check
+CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
+	TODO: check
+CVE-2026-59903 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59902 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
+	TODO: check
+CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
+	TODO: check
+CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
+	TODO: check
+CVE-2026-58561 (Null pointer dereference issue in the image codec module.Impact: Succe ...)
+	TODO: check
+CVE-2026-58560 (Null pointer dereference issue in the image codec module.Impact: Succe ...)
+	TODO: check
+CVE-2026-56686 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
+	TODO: check
+CVE-2026-56685 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
+	TODO: check
+CVE-2026-56090 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolle ...)
+	TODO: check
+CVE-2026-56089 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
+	TODO: check
+CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 2026.1.6, 202 ...)
+	TODO: check
+CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
+	TODO: check
+CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
+	TODO: check
+CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
+	TODO: check
+CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x bef ...)
+	TODO: check
+CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE -  ...)
+	TODO: check
+CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to e ...)
+	TODO: check
+CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate ...)
+	TODO: check
+CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20  ...)
+	TODO: check
+CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker ...)
+	TODO: check
+CVE-2026-50771 (Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14. ...)
+	TODO: check
+CVE-2026-50770 (An issue in Squirro Cognitive Search before v.3.14.2 allows a remote a ...)
+	TODO: check
+CVE-2026-50769 (The CRM+ application before and including version 2025.6 from Brainfor ...)
+	TODO: check
+CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH ImageMaster  ...)
+	TODO: check
+CVE-2026-49308 (Permission control vulnerability in the clipboard module.Impact: Succe ...)
+	TODO: check
+CVE-2026-49307 (Permission control vulnerability in the multi-mode input module.Impact ...)
+	TODO: check
+CVE-2026-49306 (UAF vulnerability in the time and time zone module.Impact: Successful  ...)
+	TODO: check
+CVE-2026-49305 (Permission control vulnerability in the Wi-Fi enhancement module.Impac ...)
+	TODO: check
+CVE-2026-49304 (Permission control vulnerability in the device key management module.I ...)
+	TODO: check
+CVE-2026-49303 (Permission control vulnerability in the notification module.Impact: Su ...)
+	TODO: check
+CVE-2026-49302 (Permission control vulnerability in the notification service module.Im ...)
+	TODO: check
+CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact: Success ...)
+	TODO: check
+CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to version 0.19. ...)
+	TODO: check
+CVE-2026-46345 (compliance-trestle is a tooling platform for managing compliance as co ...)
+	TODO: check
+CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint Privilege ...)
+	TODO: check
+CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode component of ...)
+	TODO: check
+CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scri ...)
+	TODO: check
+CVE-2026-33437 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
+	TODO: check
+CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
+	TODO: check
+CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
+	TODO: check
+CVE-2026-19998 (A weakness has been identified in code-projects Online Shopping System ...)
+	TODO: check
+CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent directory ...)
+	TODO: check
+CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
+	TODO: check
+CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially vulnerabl ...)
+	TODO: check
+CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software Technologies  ...)
+	TODO: check
+CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software Technologies  ...)
+	TODO: check
+CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and  ...)
+	TODO: check
+CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and below versi ...)
+	TODO: check
+CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and below, a pa ...)
+	TODO: check
+CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost G ...)
+	TODO: check
+CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10. ...)
+	TODO: check
+CVE-2026-16047 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
+	TODO: check
+CVE-2026-16046 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enfo ...)
+	TODO: check
+CVE-2026-16045 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost f ...)
+	TODO: check
+CVE-2026-16044 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prev ...)
+	TODO: check
+CVE-2026-15754 (Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access cont ...)
+	TODO: check
+CVE-2026-15218 (A flaw was found in the maas-api and maas-controller ServiceAccounts w ...)
+	TODO: check
+CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim Software ...)
+	TODO: check
+CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows Input D ...)
+	TODO: check
+CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code conta ...)
+	TODO: check
+CVE-2026-12629 (The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to ackn ...)
+	TODO: check
+CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin (WJA) t ...)
+	TODO: check
+CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: ev ...)
+	TODO: check
+CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
+	TODO: check
+CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve generative  ...)
+	TODO: check
+CVE-2025-27771 (UpTrain is an open-source platform to evaluate and improve generative  ...)
+	TODO: check
+CVE-2025-27770 (UpTrain is an open-source platform to evaluate and improve generative  ...)
+	TODO: check
+CVE-2025-27621 (UpTrain is an open-source platform to evaluate and improve generative  ...)
+	TODO: check
 CVE-2026-XXXX [heap out-of-bounds write during Unicode font-name conversion]
 	- antiword <unfixed> (bug #1144645)
 CVE-2026-XXXX [heap out-of-bounds write during OLE PPS name decoding]
@@ -7499,7 +7825,8 @@ CVE-2026-73405 (An authorization bypass vulnerability in Vulnerability-Lookup al
 	NOT-FOR-US: vulnerability-lookup
 CVE-2026-73374 (A stored cross-site scripting (XSS) vulnerability existed in Vulnerabi ...)
 	NOT-FOR-US: vulnerability-lookup
-CVE-2026-73327 (Joomla 6.1.1 contains a path traversal vulnerability in the com_joomla ...)
+CVE-2026-73327
+	REJECTED
 	NOT-FOR-US: Joomla
 CVE-2026-73325 (Fujitsu Research's OneCompression library 1.2.0 contains an unsafe des ...)
 	NOT-FOR-US: Fujitsu Research's OneCompression library
@@ -8767,7 +9094,8 @@ CVE-2026-72542 (A missing authorization vulnerability in Windmill Labs Windmill
 	NOT-FOR-US: Windmill
 CVE-2026-72541 (A missing authorization vulnerability in Windmill Labs Windmill throug ...)
 	NOT-FOR-US: Windmill
-CVE-2026-72540 (An insecure direct object reference vulnerability in PhotoPrism throug ...)
+CVE-2026-72540
+	REJECTED
 	NOT-FOR-US: PhotoPrism
 CVE-2026-72539 (An information disclosure vulnerability in Windmill Labs Windmill thro ...)
 	NOT-FOR-US: Windmill
@@ -9436,7 +9764,7 @@ CVE-2026-62724 (Use after free in Windows Telephony Service allows an authorized
 	NOT-FOR-US: Microsoft
 CVE-2026-62723 (Use after free in Windows Telephony Service allows an authorized attac ...)
 	NOT-FOR-US: Microsoft
-CVE-2026-62722 (Heap-based buffer overflow in Windows Bind Filter Driver allows an aut ...)
+CVE-2026-62722 (Heap-based buffer overflow in Windows Brokering File System allows an  ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-62721 (Insufficient granularity of access control in User-Mode Power Service  ...)
 	NOT-FOR-US: Microsoft
@@ -10882,7 +11210,8 @@ CVE-2026-72570 (A stored cross-site scripting (XSS) vulnerability in cube-root/d
 	NOT-FOR-US: cube-root/directory-serve
 CVE-2026-72569 (A path traversal vulnerability in cube-root/directory-serve through 1. ...)
 	NOT-FOR-US: cube-root/directory-serve
-CVE-2026-72568 (An out-of-bounds read vulnerability in Redis through 8.8.1 allows an a ...)
+CVE-2026-72568
+	REJECTED
 	- redis <undetermined>
 	TODO: check, assigned by a "Turan Security" CNA without further details
 CVE-2026-72567 (An improper path validation vulnerability in AsyncFuncAI/deepwiki-open ...)
@@ -11263,36 +11592,36 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in Apache Airflow's Yandex pr
 	NOT-FOR-US: Apache Airflow provider
 CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager backends i ...)
 	NOT-FOR-US: Apache Airflow provider
-CVE-2026-74998 [Content proxied by the css proxy is not validated validation]
+CVE-2026-74998 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses f ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b (1.6.18)
-CVE-2026-75006 [SSRF bypass]
+CVE-2026-75006 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficien ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223 (1.6.18)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9 (1.6.18)
-CVE-2026-75003 [Remote content blocking bypass via unclosed url() in a FuncIRI attribute]
+CVE-2026-75003 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b (1.6.18)
-CVE-2026-75007 [LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`]
+CVE-2026-75007 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP se ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540 (1.6.18)
-CVE-2026-75004 [Arbitrary sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`]
+CVE-2026-75004 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper ru ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e (1.6.18)
-CVE-2026-74997 [RCE in the `cmd_learn` driver of markasjunk plugin]
+CVE-2026-74997 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_lea ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd (1.6.18)
 	NOTE: Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a (1.6.18)
-CVE-2026-75002 [IMAP command injection via mail search and LITERAL+ byte-count desynchronization]
+CVE-2026-75002 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea (1.6.18)
-CVE-2026-75010 [The modoboa driver of the passwd plugin leaks an authentication token to a user-controlled host]
+CVE-2026-75010 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c (1.6.18)
-CVE-2026-74999 [Stored XSS in "Add to address book" action]
+CVE-2026-74999 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8 (1.6.18)
-CVE-2026-75000 [HTML/CSS sanitization bypass via SVG animate `by` attribute]
+CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HT ...)
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (1.6.18)
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
@@ -13347,7 +13676,7 @@ CVE-2026-9030 (A denial-of-service vulnerability exists in httpd service on Arch
 	NOT-FOR-US: TPLink
 CVE-2026-8798 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the nati ...)
 	NOT-FOR-US: FIPS provider for Bouncycastle, not part of the Debian package for Bouncycastle
-CVE-2026-71381 (Adobe Genuine Software Integrity Service was affected by an Incorrect  ...)
+CVE-2026-71381 (Adobe Genuine Software Integrity Service on Windows is affected by an  ...)
 	NOT-FOR-US: Adobe
 CVE-2026-70624
 	REJECTED
@@ -15566,7 +15895,8 @@ CVE-2026-71247 (Documenso's sign-field-with-token.ts, used by the live document-
 	NOT-FOR-US: Documenso
 CVE-2026-71246 (Pixelfed's SearchController (behind the auth middleware) accepts a URL ...)
 	NOT-FOR-US: Pixelfed
-CVE-2026-71245 (Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxContr ...)
+CVE-2026-71245
+	REJECTED
 	NOT-FOR-US: Mautic
 CVE-2026-71244 (Paperless-ngx's MailAccountViewSet.test action, when called with an ex ...)
 	NOT-FOR-US: Paperless-ngx
@@ -34746,23 +35076,23 @@ CVE-2026-5674 (A flaw was found in PipeWire, a multimedia server. This vulnerabi
 	- pipewire <unfixed> (bug #1142416)
 	[trixie] - pipewire <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2455341
-CVE-2026-59867 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, ...)
+CVE-2026-59867 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59866 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, ...)
+CVE-2026-59866 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59865 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, ...)
+CVE-2026-59865 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59864 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, ...)
+CVE-2026-59864 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59863 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, ...)
+CVE-2026-59863 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59862 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, ...)
+CVE-2026-59862 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59861 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, ...)
+CVE-2026-59861 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59860 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, ...)
+CVE-2026-59860 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
-CVE-2026-59859 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, ...)
+CVE-2026-59859 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
 CVE-2026-59249 (Inconsistent interpretation of HTTP requests (HTTP response smuggling) ...)
 	NOT-FOR-US: elixir-mint mint
@@ -40605,9 +40935,11 @@ CVE-2026-57825
 	NOTE: Testcase: https://github.com/ocaml/opam/commit/362f5dc08c1436be964e14aa50a5837050124d36 (2.5.2)
 	NOTE: Fixed by: https://github.com/ocaml/opam/commit/175a5d777806ad32fa6cdd95f2501dc4bd5e584e (2.5.2)
 CVE-2026-44918 (OpenStack Ironic through before 37.0.1 allows creation or modification ...)
+	{DSA-6445-1}
 	- ironic 1:35.0.1-8 (bug #1141716)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-026.html
 CVE-2026-54423 (In OpenStack Ironic before 37.0.1, an Ironic user with the ability to  ...)
+	{DSA-6445-1}
 	- ironic 1:35.0.1-8 (bug #1141717)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-025.html
 CVE-2026-3886 [virtio-gpu: fix overflow check when allocating 2d image]
@@ -59686,7 +60018,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0176]
 	[bookworm] - rust-pyo3 <not-affected> (Vulnerable code not present, only affects 0.24 and later)
 	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0176.html
 CVE-2026-54421 (In OpenStack Ironic before 37.0.1, when applying a PATCH to update fie ...)
-	{DLA-4743-1}
+	{DSA-6445-1 DLA-4743-1}
 	- ironic 1:35.0.1-6 (bug #1140012)
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2155049
 CVE-2026-54420 (LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM  ...)
@@ -62493,7 +62825,7 @@ CVE-2026-41985 (UAF vulnerability in the package management module.Impact: Succe
 	NOT-FOR-US: Huawei
 CVE-2026-41984 (UAF vulnerability in the package management module.Impact: Successful  ...)
 	NOT-FOR-US: Huawei
-CVE-2026-41983 (DoS vulnerability in the browser kernel.Impact: Successful exploitatio ...)
+CVE-2026-41983 (Null pointer dereference vulnerability in the browser module.Impact: S ...)
 	NOT-FOR-US: Huawei
 CVE-2026-41982 (Race condition vulnerability in the IPC module.Impact: Successful expl ...)
 	NOT-FOR-US: Huawei
@@ -79847,7 +80179,7 @@ CVE-2026-45699 (Netatalk is a Free and Open Source file server suite for Unix-li
 	{DSA-6280-1}
 	- netatalk 4.4.3~ds-1 (bug #1137125)
 	NOTE: https://netatalk.io/security/CVE-2026-45699
-CVE-2026-45698
+CVE-2026-45698 (Netatalk is a Free and Open Source file server suite for Unix-like ope ...)
 	{DSA-6280-1}
 	- netatalk 4.4.3~ds-1 (bug #1137126)
 	NOTE: https://netatalk.io/security/CVE-2026-45698
@@ -90063,7 +90395,7 @@ CVE-2026-43504 (An issue was discovered in Prosody before 0.12.6 and 1.0.0 throu
 	NOTE: https://prosody.im/security/advisory_735dd9d3/
 	NOTE: https://hg.prosody.im/trunk/rev/4bbb17445ed9
 CVE-2026-43003 (An issue was discovered in OpenStack ironic-python-agent 1.0.0 through ...)
-	{DLA-4743-1}
+	{DSA-6445-1 DLA-4743-1}
 	- ironic 1:35.0.1-7 (bug #1140187)
 	- ironic-python-agent 11.5.0-3 (bug #1135646)
 	[trixie] - ironic-python-agent <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d550a0b34e1ca1ae2dcf52d31cfcb6dbf6347fcb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d550a0b34e1ca1ae2dcf52d31cfcb6dbf6347fcb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/6c4351da/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list