[Git][security-tracker-team/security-tracker][master] Add CVE-2026-56684/valkey
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 20 08:57:45 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b6b260bf by Salvatore Bonaccorso at 2026-08-20T09:26:30+02:00
Add CVE-2026-56684/valkey
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4360,7 +4360,11 @@ CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom install
CVE-2026-57580 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
NOT-FOR-US: authentik
CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
- TODO: check
+ - valkey <unfixed>
+ NOTE: https://github.com/valkey-io/valkey/security/advisories/GHSA-53mc-f3m3-99vh
+ NOTE: https://github.com/valkey-io/valkey/pull/4234
+ NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/33b14adf2026cfd8728607b026edb24843805844 (8.1.9)
+ TODO: check redis and redict
CVE-2026-55839 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
TODO: check
CVE-2026-55166 (Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6b260bf3777054af461e92ef0adc7640183cff3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6b260bf3777054af461e92ef0adc7640183cff3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/82a825d6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list