[Git][security-tracker-team/security-tracker][master] Add more libevent issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 06:31:15 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6666622f by Salvatore Bonaccorso at 2026-08-21T07:26:50+02:00
Add more libevent issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -334,7 +334,9 @@ CVE-2026-64777 (A malicious builder peer may be able to request an in-context fi
CVE-2026-63654 (Frappe is a full-stack web application framework. In version 16.31.0 a ...)
NOT-FOR-US: Frappe
CVE-2026-63495 (Libevent is an event notification library. From 2.2.0-alpha-dev until ...)
- TODO: check
+ - libevent <not-affected> (Vulnerable code not present)
+ NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-qx89-wf2v-vgmx
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/291c4d1cd75695e898030ebd5c4ddf26c094077b (release-2.2.2-alpha)
CVE-2026-63490 (Handlebars.java provides logic-less and semantic Mustache templates wi ...)
TODO: check
CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests defined ...)
@@ -343,13 +345,25 @@ CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests de
NOTE: https://github.com/Orange-OpenSource/hurl/pull/5119
NOTE: Fixed by: https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e
CVE-2026-63388 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72 (release-2.1.13-stable)
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9 (release-2.2.2-alpha)
CVE-2026-63387 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/377b9022c3ac61aa4540b5dc4b70c60bf74c663d (release-2.1.13-stable)
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/9877a7205ea024d0120effb040e1b8e034435407 (release-2.2.2-alpha)
CVE-2026-63385 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2 (release-2.1.13-stable)
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0 (release-2.2.2-alpha)
CVE-2026-63384 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416 (release-2.1.13-stable)
+ NOTE: Fixed by: https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda (release-2.2.2-alpha)
CVE-2026-63383 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6666622ff163f5953248c9b84c0123ee78037b11
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6666622ff163f5953248c9b84c0123ee78037b11
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/8e04d794/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list