[Git][security-tracker-team/security-tracker][master] Add new freecad issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 07:53:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ec2f188a by Salvatore Bonaccorso at 2026-08-20T08:39:21+02:00
Add new freecad issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4262,11 +4262,18 @@ CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the Vel
 CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3, automat ...)
 	NOT-FOR-US: n8n
 CVE-2026-34789 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
-	TODO: check
+	- freecad <unfixed>
+	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-493w-pp4h-h77v
+	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/81b73925ce22610542367301d8eff4259eb9596e (1.1.1)
+	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/e2dc6c8172673642c6856b8b3a5a6accefb18279 (1.1.2)
 CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
-	TODO: check
+	- freecad 1.1.1+dfsg-1
+	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-chv4-vm6r-wjqj
 CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
-	TODO: check
+	- freecad 1.1.1+dfsg-1
+	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-8rfj-7956-6gwf
+	NOTE: https://github.com/FreeCAD/FreeCAD/pull/28610
+	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/9ed351cc4700db0a94c46f020c34c58bbf1bdaba (1.1.1)
 CVE-2026-28984 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec2f188aee2e5ece3a4ecad3e72c4e2c4c0dcb16

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec2f188aee2e5ece3a4ecad3e72c4e2c4c0dcb16
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/6129b20b/attachment.htm>


More information about the debian-security-tracker-commits mailing list