[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 05:48:40 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bb8f7550 by Salvatore Bonaccorso at 2026-08-21T06:42:53+02:00
Add Debian bug references for some issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -64,7 +64,7 @@ CVE-2026-77020 (A vulnerability was identified in CodeAstro Apartment Visitor Ma
CVE-2026-77019 (A vulnerability was determined in CodeAstro Apartment Visitor Manageme ...)
NOT-FOR-US: CodeAstro
CVE-2026-77014 (A flaw was found in libsoup's SoupServer HTTP Range header processing. ...)
- - libsoup3 <unfixed>
+ - libsoup3 <unfixed> (bug #1144976)
- libsoup2.4 <removed>
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/e82c13ba03defcee10f981ac964f4d570b21a251
@@ -125,7 +125,7 @@ CVE-2026-75526 (django CMS is an easy-to-use and developer-friendly enterprise c
CVE-2026-75514 (BunkerWeb is an open-source, next-generation Web Application Firewall. ...)
NOT-FOR-US: BunkerWeb
CVE-2026-75140 (jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolle ...)
- - jsoup <unfixed>
+ - jsoup <unfixed> (bug #1144972)
NOTE: https://github.com/jhy/jsoup/pull/2556
NOTE: Fixed by: https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a
CVE-2026-74021 (Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.)
@@ -1402,7 +1402,7 @@ CVE-2026-76237 (stigmem-node before 0.9.0a12 contains a broken object level auth
CVE-2026-76236 (stigmem-node before 0.9.0a12 contains a cross-tenant broken object lev ...)
NOT-FOR-US: stigmem-node
CVE-2026-76235 (A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
- - cockpit <unfixed>
+ - cockpit <unfixed> (bug #1144975)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519497
NOTE: https://github.com/cockpit-project/cockpit/pull/23633
NOTE: Fixed by: https://github.com/cockpit-project/cockpit/commit/233b1c178dcb95ccef356832afd9d60023d601e9
@@ -4260,7 +4260,7 @@ CVE-2026-76045 (Use after free in WebGL in Google Chrome prior to 151.0.7922.169
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-75926 (Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permis ...)
- - hugo <unfixed>
+ - hugo <unfixed> (bug #1144973)
[trixie] - hugo <not-affected> (Vulnerable code introduced later)
[bookworm] - hugo <not-affected> (Vulnerable code introduced later)
[bullseye] - hugo <not-affected> (Vulnerable code introduced later)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb8f7550eb813c9dae97c89503024202020b304e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb8f7550eb813c9dae97c89503024202020b304e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/8056da0b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list