[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 20 18:11:30 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0843f80b by Salvatore Bonaccorso at 2026-08-20T18:59:21+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3641,7 +3641,7 @@ CVE-2026-75912 (CodeWhale versions before 0.8.64 contain an argument injection v
CVE-2026-75911 (CodeWhale versions before 0.8.64 fail to properly validate the allow_s ...)
NOT-FOR-US: CodeWhale
CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplo ...)
- - libmodplug <unfixed>
+ - libmodplug <unfixed> (bug #1144933)
NOTE: https://github.com/Konstanty/libmodplug/issues/103
CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
NOT-FOR-US: RAGFlow
@@ -5215,7 +5215,7 @@ CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in some
CVE-2026-71566 (FakeFish handles incoming credentials by passing them down to scripts ...)
NOT-FOR-US: FakeFish
CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- - sqlparse <unfixed>
+ - sqlparse <unfixed> (bug #1144932)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87 (0.6.0)
CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
@@ -5289,11 +5289,11 @@ CVE-2026-59902 (Netty is an asynchronous, event-driven network application frame
NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- - sqlparse <unfixed>
+ - sqlparse <unfixed> (bug #1144932)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/53ff44b53e27cff78259acc1af015506fea60f63 (0.6.0)
CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- - sqlparse <unfixed>
+ - sqlparse <unfixed> (bug #1144932)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e (0.6.0)
CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -5315,7 +5315,7 @@ CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 2026.1.
CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
NOT-FOR-US: Discourse
CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- - sqlparse <unfixed>
+ - sqlparse <unfixed> (bug #1144932)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f (0.6.0)
CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -5379,7 +5379,7 @@ CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import
CVE-2026-19998 (A weakness has been identified in code-projects Online Shopping System ...)
NOT-FOR-US: code-projects
CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent directory ...)
- - node-extract-zip <unfixed>
+ - node-extract-zip <unfixed> (bug #1144934)
NOTE: https://github.com/max-mapper/extract-zip/pull/160
CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
TODO: check
@@ -5566,14 +5566,14 @@ CVE-2026-66798
CVE-2026-66797
NOT-FOR-US: Red Hat cluster-backup-operator
CVE-2026-18725
- - open-iscsi <unfixed>
+ - open-iscsi <unfixed> (bug #1144935)
[trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462023
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
CVE-2026-18724
- - open-iscsi <unfixed>
+ - open-iscsi <unfixed> (bug #1144935)
[trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2461994
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
@@ -12706,21 +12706,21 @@ CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case) o
CVE-2026-18744 (Any authenticated case participant can fetch any OTHER vendor's CaseSt ...)
NOT-FOR-US: CERT/CC VINCE
CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow vulnerability in ...)
- - open-iscsi <unfixed>
+ - open-iscsi <unfixed> (bug #1144935)
[trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2463029
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This vulnerabilit ...)
- - open-iscsi <unfixed>
+ - open-iscsi <unfixed> (bug #1144935)
[trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462956
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a remote att ...)
- - open-iscsi <unfixed>
+ - open-iscsi <unfixed> (bug #1144935)
[trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462331
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0843f80bfb570e23a8762052dde2f34e31d4b920
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0843f80bfb570e23a8762052dde2f34e31d4b920
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/e4f50d22/attachment.htm>
More information about the debian-security-tracker-commits
mailing list