[Git][security-tracker-team/security-tracker][master] Add new sqlparse issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 20:58:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b1810d08 by Salvatore Bonaccorso at 2026-08-17T21:58:10+02:00
Add new sqlparse issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -149,7 +149,9 @@ CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in some
 CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to scripts ...)
 	NOT-FOR-US: FakeFish
 CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	TODO: check
+	- sqlparse <unfixed>
+	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
+	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87 (0.6.0)
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
 	NOT-FOR-US: New API
 CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version p ...)
@@ -193,9 +195,12 @@ CVE-2026-59903 (Netty is an asynchronous, event-driven network application frame
 CVE-2026-59902 (Netty is an asynchronous, event-driven network application framework.  ...)
 	TODO: check
 CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	TODO: check
+	- sqlparse <unfixed>
+	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x
 CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	TODO: check
+	- sqlparse <unfixed>
+	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
+	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e (0.6.0)
 CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-58561 (Null pointer dereference issue in the image codec module.Impact: Succe ...)
@@ -215,7 +220,9 @@ CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 2026.1.
 CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	TODO: check
+	- sqlparse <unfixed>
+	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
+	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f (0.6.0)
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x bef ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b1810d08862f97bfa994f64c4a406c7374ee892c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b1810d08862f97bfa994f64c4a406c7374ee892c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/d375cecd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list