[Git][security-tracker-team/security-tracker][master] Add references for CVE-2026-76235/cockpit

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 05:09:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f80e7431 by Salvatore Bonaccorso at 2026-08-21T06:07:23+02:00
Add references for CVE-2026-76235/cockpit

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1367,6 +1367,8 @@ CVE-2026-76236 (stigmem-node before 0.9.0a12 contains a cross-tenant broken obje
 CVE-2026-76235 (A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
 	- cockpit <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519497
+	NOTE: https://github.com/cockpit-project/cockpit/pull/23633
+	NOTE: Fixed by: https://github.com/cockpit-project/cockpit/commit/233b1c178dcb95ccef356832afd9d60023d601e9
 CVE-2026-76234 (libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before  ...)
 	NOT-FOR-US: libcrux
 CVE-2026-76233 (Renovate versions from 39.53.0 before 40.33.0 contain a command inject ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f80e743169efb5d70a06a97ebe31c0fe1d8ab7f3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f80e743169efb5d70a06a97ebe31c0fe1d8ab7f3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/f93089f3/attachment.htm>


More information about the debian-security-tracker-commits mailing list