[Git][security-tracker-team/security-tracker][master] Add CVE-2026-66046/expat
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 19 21:59:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7f52362a by Salvatore Bonaccorso at 2026-08-19T22:59:21+02:00
Add CVE-2026-66046/expat
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3582,7 +3582,10 @@ CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard
CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused ...)
- TODO: check
+ - expat <unfixed>
+ NOTE: https://github.com/libexpat/libexpat/pull/1321
+ NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
+ NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
NOT-FOR-US: Vitess
CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f52362a56d4249284da0f31ae3e934e0032a40e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f52362a56d4249284da0f31ae3e934e0032a40e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/fdb7f0b7/attachment.htm>
More information about the debian-security-tracker-commits
mailing list