[Git][security-tracker-team/security-tracker][master] new zabbix issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 19 08:42:53 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d6c76032 by Moritz Muehlenhoff at 2026-08-19T09:41:08+02:00
new zabbix issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2970,7 +2970,8 @@ CVE-2026-59940 (Seroval facilitates JS value stringification, including complex
 CVE-2026-59825 (Mastodon is a free, open-source social network server based on Activit ...)
 	TODO: check
 CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom installation  ...)
-	TODO: check
+	- zabbix <not-affected> (Windows-specific)
+	NOTE: https://support.zabbix.com/browse/ZBX-28077
 CVE-2026-57580 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
 	TODO: check
 CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
@@ -3168,25 +3169,49 @@ CVE-2026-24184 (NVIDIA Cumulus Linux contains a vulnerability in the Link Layer
 CVE-2026-24183 (NVIDIA Cumulus Linux contains a vulnerability in the user management c ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-23938 (An authenticated administrator is able to crash Zabbix server or proxy ...)
-	TODO: check
+	- zabbix <unfixed>
+	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	NOTE: https://support.zabbix.com/browse/ZBX-28075
 CVE-2026-23937 (The Zabbix API host.get action can be exploited by authenticated users ...)
-	TODO: check
+	- zabbix <unfixed>
+	NOTE: https://support.zabbix.com/browse/ZBX-28074
 CVE-2026-23935 (A Zabbix administrator is able to read out of bounds memory by utilizi ...)
-	TODO: check
+	- zabbix <unfixed>
+	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	NOTE: https://support.zabbix.com/browse/ZBX-28073
 CVE-2026-23934 (An authenticated user is able to cause disproportionate CPU load on th ...)
-	TODO: check
+	- zabbix <unfixed>
+	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	NOTE: https://support.zabbix.com/browse/ZBX-28072
 CVE-2026-23933 (In Zabbix 7.4 the cryptographic key used for signing Frontend sessions ...)
-	TODO: check
+	- zabbix <not-affected> (Only affects 7.4.x)
+	NOTE: https://support.zabbix.com/browse/ZBX-28071
 CVE-2026-23931 (The frontend validatate.api.exists action can be exploited by authenti ...)
-	TODO: check
+	- zabbix <unfixed>
+	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	NOTE: https://support.zabbix.com/browse/ZBX-28070
 CVE-2026-23930 (An unauthenticated user is able to cause disproportionate CPU load on  ...)
-	TODO: check
+	- zabbix <unfixed>
+	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	NOTE: https://support.zabbix.com/browse/ZBX-28069
 CVE-2026-23929 (Prototype pollution vulnerability in searchParamsToObject() is leading ...)
-	TODO: check
+	- zabbix <unfixed>
+	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	NOTE: https://support.zabbix.com/browse/ZBX-28068
 CVE-2026-23922 (The email media OAuth field 'Client secret' cannot be read after savin ...)
-	TODO: check
+	- zabbix <not-affected> (Only affects 7.4.x)
+	NOTE: https://support.zabbix.com/browse/ZBX-28067
 CVE-2026-1199 (Zabbix API and Frontend login lockout mechanism has a flaw where sever ...)
-	TODO: check
+	- zabbix <unfixed>
+	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
+	NOTE: https://support.zabbix.com/browse/ZBX-28076
 CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the patched versions fails to enforce fie ...)
 	TODO: check
 CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak authorizatio ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6c760326cf1c963631563085d9ebd738f924215

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6c760326cf1c963631563085d9ebd738f924215
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/a6fe5ca4/attachment.htm>


More information about the debian-security-tracker-commits mailing list