[Git][security-tracker-team/security-tracker][master] Add two new rabbitmq-java-client issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 07:38:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d1555d9c by Salvatore Bonaccorso at 2026-08-19T08:38:21+02:00
Add two new rabbitmq-java-client issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -684,9 +684,19 @@ CVE-2026-70657 (Copyparty is a portable file server. Prior to 1.20.17, copyparty
 CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	TODO: check
+	- rabbitmq-java-client <unfixed>
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-93j5-89vc-pph4
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/09af76fce136f3136931654a0a1d43095c80e2f0 (main)
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2008
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/db89e34809fbc6ba4e946615f297f3684ccd0acc (v5.33.1)
 CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	TODO: check
+	- rabbitmq-java-client <unfixed>
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2 (main)
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2008
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/388209356c6478088efce4d8a07b68e73837a7a0 (v5.33.1)
 CVE-2026-69189 (Hoppscotch is an open source API development ecosystem. Prior to 2026. ...)
 	TODO: check
 CVE-2026-69160 (OpenList a file list program that supports multiple storage. Prior to  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1555d9c7c07c0322931a595d824537b9e530919

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1555d9c7c07c0322931a595d824537b9e530919
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/358677b8/attachment.htm>


More information about the debian-security-tracker-commits mailing list