[Git][security-tracker-team/security-tracker][master] Add CVE-2026-66046/expat

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 21:59:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7f52362a by Salvatore Bonaccorso at 2026-08-19T22:59:21+02:00
Add CVE-2026-66046/expat

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3582,7 +3582,10 @@ CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard
 CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused  ...)
-	TODO: check
+	- expat <unfixed>
+	NOTE: https://github.com/libexpat/libexpat/pull/1321
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
 CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
 	NOT-FOR-US: Vitess
 CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f52362a56d4249284da0f31ae3e934e0032a40e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f52362a56d4249284da0f31ae3e934e0032a40e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/fdb7f0b7/attachment.htm>


More information about the debian-security-tracker-commits mailing list