[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 18:11:30 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0843f80b by Salvatore Bonaccorso at 2026-08-20T18:59:21+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3641,7 +3641,7 @@ CVE-2026-75912 (CodeWhale versions before 0.8.64 contain an argument injection v
 CVE-2026-75911 (CodeWhale versions before 0.8.64 fail to properly validate the allow_s ...)
 	NOT-FOR-US: CodeWhale
 CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplo ...)
-	- libmodplug <unfixed>
+	- libmodplug <unfixed> (bug #1144933)
 	NOTE: https://github.com/Konstanty/libmodplug/issues/103
 CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
 	NOT-FOR-US: RAGFlow
@@ -5215,7 +5215,7 @@ CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in some
 CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to scripts ...)
 	NOT-FOR-US: FakeFish
 CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	- sqlparse <unfixed>
+	- sqlparse <unfixed> (bug #1144932)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87 (0.6.0)
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
@@ -5289,11 +5289,11 @@ CVE-2026-59902 (Netty is an asynchronous, event-driven network application frame
 	NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
 	NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
 CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	- sqlparse <unfixed>
+	- sqlparse <unfixed> (bug #1144932)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/53ff44b53e27cff78259acc1af015506fea60f63 (0.6.0)
 CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	- sqlparse <unfixed>
+	- sqlparse <unfixed> (bug #1144932)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e (0.6.0)
 CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -5315,7 +5315,7 @@ CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 2026.1.
 CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
-	- sqlparse <unfixed>
+	- sqlparse <unfixed> (bug #1144932)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f (0.6.0)
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -5379,7 +5379,7 @@ CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import
 CVE-2026-19998 (A weakness has been identified in code-projects Online Shopping System ...)
 	NOT-FOR-US: code-projects
 CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent directory ...)
-	- node-extract-zip <unfixed>
+	- node-extract-zip <unfixed> (bug #1144934)
 	NOTE: https://github.com/max-mapper/extract-zip/pull/160
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
 	TODO: check
@@ -5566,14 +5566,14 @@ CVE-2026-66798
 CVE-2026-66797
 	NOT-FOR-US: Red Hat cluster-backup-operator
 CVE-2026-18725
-	- open-iscsi <unfixed>
+	- open-iscsi <unfixed> (bug #1144935)
 	[trixie] - open-iscsi <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462023
 	NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 	NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
 	NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
 CVE-2026-18724
-	- open-iscsi <unfixed>
+	- open-iscsi <unfixed> (bug #1144935)
 	[trixie] - open-iscsi <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2461994
 	NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
@@ -12706,21 +12706,21 @@ CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case) o
 CVE-2026-18744 (Any authenticated case participant can fetch any OTHER vendor's CaseSt ...)
 	NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow vulnerability in  ...)
-	- open-iscsi <unfixed>
+	- open-iscsi <unfixed> (bug #1144935)
 	[trixie] - open-iscsi <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2463029
 	NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 	NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
 	NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
 CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This vulnerabilit ...)
-	- open-iscsi <unfixed>
+	- open-iscsi <unfixed> (bug #1144935)
 	[trixie] - open-iscsi <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462956
 	NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 	NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
 	NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
 CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a remote att ...)
-	- open-iscsi <unfixed>
+	- open-iscsi <unfixed> (bug #1144935)
 	[trixie] - open-iscsi <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462331
 	NOTE: https://github.com/open-iscsi/open-iscsi/issues/543



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0843f80bfb570e23a8762052dde2f34e31d4b920

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0843f80bfb570e23a8762052dde2f34e31d4b920
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/e4f50d22/attachment.htm>


More information about the debian-security-tracker-commits mailing list