[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 20:58:17 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac7d5825 by Salvatore Bonaccorso at 2026-08-20T21:17:12+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4701,7 +4701,7 @@ CVE-2026-73834 (A flaw was found in the must-gather component of Red Hat Advance
 CVE-2026-73692
 	REJECTED
 CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 unt ...)
-	- golang-github-getkin-kin-openapi <unfixed>
+	- golang-github-getkin-kin-openapi <unfixed> (bug #1144951)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-jpcw-4wr7-c3vq
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/68ac2affa325514d7d6e731204d6a1edf6bdff64 (v0.144.0)
 CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
@@ -4842,7 +4842,7 @@ CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based appli
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2008
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/db89e34809fbc6ba4e946615f297f3684ccd0acc (v5.33.1)
 CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	- rabbitmq-java-client <unfixed>
+	- rabbitmq-java-client <unfixed> (bug #1144958)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2 (main)
@@ -4948,7 +4948,7 @@ CVE-2026-63641 (MagicMirror\xb2 is an open source modular smart mirror platform.
 CVE-2026-63640 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
 	NOT-FOR-US: MagicMirror
 CVE-2026-63639 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
-	- valkey <unfixed>
+	- valkey <unfixed> (bug #1144957)
 	NOTE: https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4
 	NOTE: https://github.com/valkey-io/valkey/pull/4073
 	NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291 (8.1.9)
@@ -4960,21 +4960,21 @@ CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for mach
 	NOTE: https://github.com/onnx/onnx/pull/7880
 	NOTE: Fixed by: https://github.com/onnx/onnx/commit/e9c74f596eaa0250f89e52a54160a25bbcb25b66 (v1.22.0)
 CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	- rabbitmq-java-client <unfixed>
+	- rabbitmq-java-client <unfixed> (bug #1144958)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-pxv4-2wfj
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2000
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e96232ae7efa75ea4fa8 (main)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2002
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b85a16119250bf63cb (v5.33.0)
 CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	- rabbitmq-java-client <unfixed>
+	- rabbitmq-java-client <unfixed> (bug #1144958)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1999
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01 (main)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2001
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339 (v5.33.0)
 CVE-2026-63335 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	- rabbitmq-java-client <unfixed>
+	- rabbitmq-java-client <unfixed> (bug #1144958)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-qx7j-jv8m-fppr
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1959
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/31735344d9f9dfc53740b67f06e560e8846b9322 (main)
@@ -4989,7 +4989,7 @@ CVE-2026-62357 (Dragonfly is an in-memory data store built for modern applicatio
 CVE-2026-61696 (Forem is open source software for building communities. In versions be ...)
 	NOT-FOR-US: Forem
 CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	- rabbitmq-java-client <unfixed>
+	- rabbitmq-java-client <unfixed> (bug #1144958)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1994
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591 (main)
@@ -5015,7 +5015,7 @@ CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom install
 CVE-2026-57580 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
 	NOT-FOR-US: authentik
 CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
-	- valkey <unfixed>
+	- valkey <unfixed> (bug #1144956)
 	NOTE: https://github.com/valkey-io/valkey/security/advisories/GHSA-53mc-f3m3-99vh
 	NOTE: https://github.com/valkey-io/valkey/pull/4234
 	NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/33b14adf2026cfd8728607b026edb24843805844 (8.1.9)
@@ -5428,7 +5428,7 @@ CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap buffer
 	NOTE: Introduced with: https://github.com/hashcat/hashcat/commit/ef52453de9523f6a010652847b61cb340ed5daa5
 	NOTE: Fixed by: https://github.com/hashcat/hashcat/commit/6f374c4ff7d5dc951530fbbbcf6b45e3c169b100
 CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to ...)
-	- mini-httpd <unfixed>
+	- mini-httpd <unfixed> (bug #1144953)
 CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remo ...)
 	NOT-FOR-US: OSSRS SRS (Simple Realtime Server)
 CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an ...)
@@ -5473,7 +5473,7 @@ CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to continuou
 CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
 	NOT-FOR-US: ERPNext
 CVE-2026-65640 (WordPress is vulnerable to a remote code execution vulnerability via m ...)
-	- wordpress <unfixed>
+	- wordpress <unfixed> (bug #1144955)
 	NOTE: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
 	NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
 CVE-2026-65351 (This issue was addressed through improved state management. This issue ...)
@@ -749121,7 +749121,7 @@ CVE-2018-1000646 (LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticat
 CVE-2018-1000645 (LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Loca ...)
 	NOT-FOR-US: LibreHealthIO
 CVE-2018-1000644 (Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Enti ...)
-	- rdf4j <unfixed>
+	- rdf4j <unfixed> (bug #1144952)
 	NOTE: https://github.com/eclipse-rdf4j/rdf4j/issues/1056
 	NOTE: Fixed by: https://github.com/eclipse-rdf4j/rdf4j/commit/50f2f51950227a4ec595a2922d81da487aba5135 (2.4.1)
 	NOTE: When fixing this issue make sure to make the fix complete and not open CVE-2026-15803



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac7d58258d46854c8e83c81b3643b201a7c03395

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac7d58258d46854c8e83c81b3643b201a7c03395
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/32a26d4e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list