[Git][security-tracker-team/security-tracker][master] Add CVE-2026-73646/node-postcss

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 20:57:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b6f09dc3 by Salvatore Bonaccorso at 2026-08-17T21:56:57+02:00
Add CVE-2026-73646/node-postcss

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -129,7 +129,9 @@ CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read vuln
 CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
 	NOT-FOR-US: Kiota
 CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
-	TODO: check
+	- node-postcss 8.5.19+~cs10.2.23-1
+	NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849
+	NOTE: Fixed by: https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c (8.5.18)
 CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation vulnerabi ...)
 	NOT-FOR-US: COVESA Open1722
 CVE-2026-73522 (COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnera ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6f09dc3b25166e423803783049ff934345a4231

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6f09dc3b25166e423803783049ff934345a4231
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/47e67619/attachment.htm>


More information about the debian-security-tracker-commits mailing list