[Git][security-tracker-team/security-tracker][master] Add CVE-2026-16626/jasperreports

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 18 06:13:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1de30a6d by Salvatore Bonaccorso at 2026-08-18T07:13:22+02:00
Add CVE-2026-16626/jasperreports

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11615,7 +11615,7 @@ CVE-2026-16742 (systemd-homed contains a local privilege escalation bug via arbi
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/8735bb63b7902b6824f4d171bca994252eb04a71 (v258.10)
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/04cba0a78da9d161c2f6426751d0460fb8193263 (v258.10)
 CVE-2026-16626 (Improper restriction of XML external entity reference vulnerability (u ...)
-	TODO: check
+	- jasperreports <removed>
 CVE-2026-15060 (When systemd-machined >= v259 (or v258 with a custom `polkit` policy t ...)
 	- systemd 261.2-1
 	[trixie] - systemd <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1de30a6dbc1123a0eb0be72345905da0566ef1a8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1de30a6dbc1123a0eb0be72345905da0566ef1a8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/b7a1a2d4/attachment.htm>


More information about the debian-security-tracker-commits mailing list