[Git][security-tracker-team/security-tracker][master] Add more libevent issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 06:31:15 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6666622f by Salvatore Bonaccorso at 2026-08-21T07:26:50+02:00
Add more libevent issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -334,7 +334,9 @@ CVE-2026-64777 (A malicious builder peer may be able to request an in-context fi
 CVE-2026-63654 (Frappe is a full-stack web application framework. In version 16.31.0 a ...)
 	NOT-FOR-US: Frappe
 CVE-2026-63495 (Libevent is an event notification library. From 2.2.0-alpha-dev until  ...)
-	TODO: check
+	- libevent <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-qx89-wf2v-vgmx
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/291c4d1cd75695e898030ebd5c4ddf26c094077b (release-2.2.2-alpha)
 CVE-2026-63490 (Handlebars.java provides logic-less and semantic Mustache templates wi ...)
 	TODO: check
 CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests defined  ...)
@@ -343,13 +345,25 @@ CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests de
 	NOTE: https://github.com/Orange-OpenSource/hurl/pull/5119
 	NOTE: Fixed by: https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e
 CVE-2026-63388 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
-	TODO: check
+	- libevent 2.1.13-stable-1
+	NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72 (release-2.1.13-stable)
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9 (release-2.2.2-alpha)
 CVE-2026-63387 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
-	TODO: check
+	- libevent 2.1.13-stable-1
+	NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/377b9022c3ac61aa4540b5dc4b70c60bf74c663d (release-2.1.13-stable)
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/9877a7205ea024d0120effb040e1b8e034435407 (release-2.2.2-alpha)
 CVE-2026-63385 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
-	TODO: check
+	- libevent 2.1.13-stable-1
+	NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2 (release-2.1.13-stable)
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0 (release-2.2.2-alpha)
 CVE-2026-63384 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
-	TODO: check
+	- libevent 2.1.13-stable-1
+	NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416 (release-2.1.13-stable)
+	NOTE: Fixed by: https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda (release-2.2.2-alpha)
 CVE-2026-63383 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
 	- libevent 2.1.13-stable-1
 	NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6666622ff163f5953248c9b84c0123ee78037b11

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6666622ff163f5953248c9b84c0123ee78037b11
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/8e04d794/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list