[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 05:48:40 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bb8f7550 by Salvatore Bonaccorso at 2026-08-21T06:42:53+02:00
Add Debian bug references for some issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -64,7 +64,7 @@ CVE-2026-77020 (A vulnerability was identified in CodeAstro Apartment Visitor Ma
 CVE-2026-77019 (A vulnerability was determined in CodeAstro Apartment Visitor Manageme ...)
 	NOT-FOR-US: CodeAstro
 CVE-2026-77014 (A flaw was found in libsoup's SoupServer HTTP Range header processing. ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1144976)
 	- libsoup2.4 <removed>
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/e82c13ba03defcee10f981ac964f4d570b21a251
@@ -125,7 +125,7 @@ CVE-2026-75526 (django CMS is an easy-to-use and developer-friendly enterprise c
 CVE-2026-75514 (BunkerWeb is an open-source, next-generation Web Application Firewall. ...)
 	NOT-FOR-US: BunkerWeb
 CVE-2026-75140 (jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolle ...)
-	- jsoup <unfixed>
+	- jsoup <unfixed> (bug #1144972)
 	NOTE: https://github.com/jhy/jsoup/pull/2556
 	NOTE: Fixed by: https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a
 CVE-2026-74021 (Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.)
@@ -1402,7 +1402,7 @@ CVE-2026-76237 (stigmem-node before 0.9.0a12 contains a broken object level auth
 CVE-2026-76236 (stigmem-node before 0.9.0a12 contains a cross-tenant broken object lev ...)
 	NOT-FOR-US: stigmem-node
 CVE-2026-76235 (A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
-	- cockpit <unfixed>
+	- cockpit <unfixed> (bug #1144975)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519497
 	NOTE: https://github.com/cockpit-project/cockpit/pull/23633
 	NOTE: Fixed by: https://github.com/cockpit-project/cockpit/commit/233b1c178dcb95ccef356832afd9d60023d601e9
@@ -4260,7 +4260,7 @@ CVE-2026-76045 (Use after free in WebGL in Google Chrome prior to 151.0.7922.169
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-75926 (Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permis ...)
-	- hugo <unfixed>
+	- hugo <unfixed> (bug #1144973)
 	[trixie] - hugo <not-affected> (Vulnerable code introduced later)
 	[bookworm] - hugo <not-affected> (Vulnerable code introduced later)
 	[bullseye] - hugo <not-affected> (Vulnerable code introduced later)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb8f7550eb813c9dae97c89503024202020b304e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb8f7550eb813c9dae97c89503024202020b304e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/8056da0b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list