[Git][security-tracker-team/security-tracker][master] new zabbix issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 19 08:42:53 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d6c76032 by Moritz Muehlenhoff at 2026-08-19T09:41:08+02:00
new zabbix issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2970,7 +2970,8 @@ CVE-2026-59940 (Seroval facilitates JS value stringification, including complex
CVE-2026-59825 (Mastodon is a free, open-source social network server based on Activit ...)
TODO: check
CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom installation ...)
- TODO: check
+ - zabbix <not-affected> (Windows-specific)
+ NOTE: https://support.zabbix.com/browse/ZBX-28077
CVE-2026-57580 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
TODO: check
CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
@@ -3168,25 +3169,49 @@ CVE-2026-24184 (NVIDIA Cumulus Linux contains a vulnerability in the Link Layer
CVE-2026-24183 (NVIDIA Cumulus Linux contains a vulnerability in the user management c ...)
NOT-FOR-US: NVIDIA
CVE-2026-23938 (An authenticated administrator is able to crash Zabbix server or proxy ...)
- TODO: check
+ - zabbix <unfixed>
+ [trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ [bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ NOTE: https://support.zabbix.com/browse/ZBX-28075
CVE-2026-23937 (The Zabbix API host.get action can be exploited by authenticated users ...)
- TODO: check
+ - zabbix <unfixed>
+ NOTE: https://support.zabbix.com/browse/ZBX-28074
CVE-2026-23935 (A Zabbix administrator is able to read out of bounds memory by utilizi ...)
- TODO: check
+ - zabbix <unfixed>
+ [trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ [bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ NOTE: https://support.zabbix.com/browse/ZBX-28073
CVE-2026-23934 (An authenticated user is able to cause disproportionate CPU load on th ...)
- TODO: check
+ - zabbix <unfixed>
+ [trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ [bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ NOTE: https://support.zabbix.com/browse/ZBX-28072
CVE-2026-23933 (In Zabbix 7.4 the cryptographic key used for signing Frontend sessions ...)
- TODO: check
+ - zabbix <not-affected> (Only affects 7.4.x)
+ NOTE: https://support.zabbix.com/browse/ZBX-28071
CVE-2026-23931 (The frontend validatate.api.exists action can be exploited by authenti ...)
- TODO: check
+ - zabbix <unfixed>
+ [trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ [bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ NOTE: https://support.zabbix.com/browse/ZBX-28070
CVE-2026-23930 (An unauthenticated user is able to cause disproportionate CPU load on ...)
- TODO: check
+ - zabbix <unfixed>
+ [trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ [bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ NOTE: https://support.zabbix.com/browse/ZBX-28069
CVE-2026-23929 (Prototype pollution vulnerability in searchParamsToObject() is leading ...)
- TODO: check
+ - zabbix <unfixed>
+ [trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ [bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ NOTE: https://support.zabbix.com/browse/ZBX-28068
CVE-2026-23922 (The email media OAuth field 'Client secret' cannot be read after savin ...)
- TODO: check
+ - zabbix <not-affected> (Only affects 7.4.x)
+ NOTE: https://support.zabbix.com/browse/ZBX-28067
CVE-2026-1199 (Zabbix API and Frontend login lockout mechanism has a flaw where sever ...)
- TODO: check
+ - zabbix <unfixed>
+ [trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ [bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+ NOTE: https://support.zabbix.com/browse/ZBX-28076
CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the patched versions fails to enforce fie ...)
TODO: check
CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak authorizatio ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6c760326cf1c963631563085d9ebd738f924215
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6c760326cf1c963631563085d9ebd738f924215
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/a6fe5ca4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list