[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 22 08:13:35 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6b4dbd66 by security tracker role at 2026-08-22T07:13:28+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,224 @@
-CVE-2026-77781
+CVE-2026-9052
+ REJECTED
+CVE-2026-77811 (Improper input validation in the dashboards-observability plugin in Op ...)
+ TODO: check
+CVE-2026-77810 (In the Neptune connector, a user with access to Neptune through Athena ...)
+ TODO: check
+CVE-2026-77415 (JSONata is a JSON query and transformation language. Prior to 1.8.8 an ...)
+ TODO: check
+CVE-2026-77414 (JSONata is a JSON query and transformation language. Prior to 1.8.8 an ...)
+ TODO: check
+CVE-2026-77413 (JSONata is a JSON query and transformation language. Prior to 1.8.8 an ...)
+ TODO: check
+CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 u ...)
+ TODO: check
+CVE-2026-77220 (PDFio before 1.6.5 contains a dangling pointer vulnerability in the di ...)
+ TODO: check
+CVE-2026-77219 (GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/P ...)
+ TODO: check
+CVE-2026-77002 (The SmilePass Selfie Login WordPress plugin through 1.0.2 does not per ...)
+ TODO: check
+CVE-2026-77001 (The Social Login & Sharing buttons with Analytics By SoClever WordPres ...)
+ TODO: check
+CVE-2026-77000 (The WP Social Media Login WordPress plugin through 1.0.6 does not veri ...)
+ TODO: check
+CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 un ...)
+ TODO: check
+CVE-2026-76904 (GeoTools is an open source Java library that provides tools for geospa ...)
+ TODO: check
+CVE-2026-76876 (Craftplan before 0.5.1 contains a broken access control vulnerability ...)
+ TODO: check
+CVE-2026-76793 (The Firebase Authentication WordPress plugin before 1.7.1 does not req ...)
+ TODO: check
+CVE-2026-76789 (The Slider Hero with Video Background, Animation WordPress plugin befo ...)
+ TODO: check
+CVE-2026-76074 (The AutomatorWP \u2013 Automator plugin for no-code automations, webho ...)
+ TODO: check
+CVE-2026-76069
+ REJECTED
+CVE-2026-76057 (The AutomatorWP \u2013 Automator plugin for no-code automations, webho ...)
+ TODO: check
+CVE-2026-75027 (The Themify Builder plugin for WordPress is vulnerable to authorizatio ...)
+ TODO: check
+CVE-2026-74252 (Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2 ...)
+ TODO: check
+CVE-2026-73323
+ REJECTED
+CVE-2026-69238 (There is an HTML injection vulnerability in Esri Portal for ArcGIS ver ...)
+ TODO: check
+CVE-2026-69237 (There is an HTML injection vulnerability in Esri Portal for ArcGIS ver ...)
+ TODO: check
+CVE-2026-69236 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
+ TODO: check
+CVE-2026-69235 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
+ TODO: check
+CVE-2026-69234 (There is a reflected cross site scripting vulnerability in Esri Portal ...)
+ TODO: check
+CVE-2026-69233 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
+ TODO: check
+CVE-2026-69232 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
+ TODO: check
+CVE-2026-69231 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
+ TODO: check
+CVE-2026-69230 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
+ TODO: check
+CVE-2026-69229 (There is an HTML injection vulnerability in Esri Portal for ArcGIS ver ...)
+ TODO: check
+CVE-2026-69228 (There is a missing authentication vulnerability in Esri Portal for Arc ...)
+ TODO: check
+CVE-2026-69225 (There is an information disclosure vulnerability in Esri Portal for Ar ...)
+ TODO: check
+CVE-2026-69224 (There is an information disclosure vulnerability in Esri Portal for Ar ...)
+ TODO: check
+CVE-2026-68508 (Hydra is a framework for elegantly configuring complex applications. P ...)
+ TODO: check
+CVE-2026-67619
+ REJECTED
+CVE-2026-67362 (Joomla Extension - j2commerce.com - Open redirect in cart controller i ...)
+ TODO: check
+CVE-2026-67361 (Joomla Extension - j2commerce.com - Unauthenticated file upload with m ...)
+ TODO: check
+CVE-2026-67360 (Joomla Extension - j2commerce.com - Cross-customer order replication i ...)
+ TODO: check
+CVE-2026-67359 (Joomla Extension - j2commerce.com - Order content disclosure J2Store 1 ...)
+ TODO: check
+CVE-2026-67358 (Joomla Extension - j2commerce.com - Download quota manipulation in J2S ...)
+ TODO: check
+CVE-2026-64679 (Atlantis is a self-hosted golang application that listens for Terrafor ...)
+ TODO: check
+CVE-2026-63421 (Keystone is a content management system for Node.js. Prior to 6.5.3, t ...)
+ TODO: check
+CVE-2026-63135 (YOURLS is a self-hosted, customizable URL shortener written in PHP. Fr ...)
+ TODO: check
+CVE-2026-62960 (Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, ...)
+ TODO: check
+CVE-2026-62316 (Microsoft UFO open-source framework for intelligent automation across ...)
+ TODO: check
+CVE-2026-62283 (Nezha Monitoring is a self-hostable, lightweight, servers and websites ...)
+ TODO: check
+CVE-2026-61824 (Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interp ...)
+ TODO: check
+CVE-2026-61539 (Xinference is an inference API for running open-source, speech, and mu ...)
+ TODO: check
+CVE-2026-59989 (Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and ...)
+ TODO: check
+CVE-2026-55185 (Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePa ...)
+ TODO: check
+CVE-2026-55168 (Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, ...)
+ TODO: check
+CVE-2026-54457 (TensorZero is an open-source LLMOps platform that unifies an LLM gatew ...)
+ TODO: check
+CVE-2026-53656 (FiftyOne is an open-source platform for refining high-quality datasets ...)
+ TODO: check
+CVE-2026-53572 (KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior t ...)
+ TODO: check
+CVE-2026-53541 (OliveTin gives access to predefined shell commands from a web interfac ...)
+ TODO: check
+CVE-2026-53531 (RaTeX is a KaTeX-compatible math rendering engine written in Rust. Pri ...)
+ TODO: check
+CVE-2026-53530 (RaTeX is a KaTeX-compatible math rendering engine written in Rust. Pri ...)
+ TODO: check
+CVE-2026-53529 (LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles r ...)
+ TODO: check
+CVE-2026-53528 (LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a p ...)
+ TODO: check
+CVE-2026-53527 (LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a p ...)
+ TODO: check
+CVE-2026-53509 (CKAN MCP Server is a tool for querying CKAN open data portals. A known ...)
+ TODO: check
+CVE-2026-53499 (FORT Validator is a Resource Public Key Infrastructure (RPKI) relying- ...)
+ TODO: check
+CVE-2026-53497 (CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, ...)
+ TODO: check
+CVE-2026-53487 (Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated ...)
+ TODO: check
+CVE-2026-53468 (Typemill is a flat-file, Markdown-based content management system desi ...)
+ TODO: check
+CVE-2026-50290 (SpecifyJS is a declarative TypeScript user interface framework. Prior ...)
+ TODO: check
+CVE-2026-50288 (SpecifyJS is a declarative TypeScript user interface framework. Prior ...)
+ TODO: check
+CVE-2026-49849 (xShop is an open-source shop developed in Laravel. An Unrestricted Fil ...)
+ TODO: check
+CVE-2026-49360 (Recce is a data-validation toolkit for enhanced dbt (data build tool) ...)
+ TODO: check
+CVE-2026-48106 (Arc is an open, SQL-native time-series database for telemetry. Prior t ...)
+ TODO: check
+CVE-2026-48105 (Arc is an open, SQL-native time-series database for telemetry. Prior t ...)
+ TODO: check
+CVE-2026-48050 (Arc is an open, SQL-native time-series database for telemetry. Version ...)
+ TODO: check
+CVE-2026-47735 (Arc is an open, SQL-native time-series database for telemetry. Prior t ...)
+ TODO: check
+CVE-2026-45271 (Picotls is a TLS protocol library that allows users select different c ...)
+ TODO: check
+CVE-2026-45099 (Terragrunt is a flexible orchestration tool that allows Infrastructure ...)
+ TODO: check
+CVE-2026-43980 (Malla is a web analyzer for Meshtastic networks based on MQTT data. Pr ...)
+ TODO: check
+CVE-2026-34949 (Combodo iTop is a web based IT service management tool.Prior to 3.2.3, ...)
+ TODO: check
+CVE-2026-34948 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-34836 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-34741 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-33333 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-33240 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-33047 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-31936 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-31880 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-31803 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-30890 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-30866 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-30865 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-30826 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-30819 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-27490 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-27463 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-27462 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
+ TODO: check
+CVE-2026-19883 (The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to u ...)
+ TODO: check
+CVE-2026-19222 (The Forminator Forms WordPress plugin before 1.57.0.7 does not consis ...)
+ TODO: check
+CVE-2026-19221 (The Forminator Forms WordPress plugin before 1.57.0.5 does not restri ...)
+ TODO: check
+CVE-2026-19093 (The Tutor LMS WordPress plugin before 4.0.6 does not validate a store ...)
+ TODO: check
+CVE-2026-18052 (The ManageWP Worker WordPress plugin before 4.9.37 does not bind the a ...)
+ TODO: check
+CVE-2026-16738 (The Conekta Payment Gateway WordPress plugin before 6.2.2 does not ver ...)
+ TODO: check
+CVE-2026-16612 (The FiboSearch WordPress plugin before 1.34.1 does not consistently e ...)
+ TODO: check
+CVE-2026-16260 (The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8 ...)
+ TODO: check
+CVE-2026-14187 (The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-obje ...)
+ TODO: check
+CVE-2026-11805
+ REJECTED
+CVE-2026-11615
+ REJECTED
+CVE-2026-11609
+ REJECTED
+CVE-2026-11418
+ REJECTED
+CVE-2026-77781 (Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exceptio ...)
- libtie-hash-regex-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42893692/
NOTE: Fixed by: https://github.com/davorg-cpan/tie-hash-regex/commit/4239732cb76233543e2ded8ff5e0f238af152e0c (RELEASE_2.0.0)
@@ -5026,6 +5246,7 @@ CVE-2026-70906 (Vulnerability in Oracle Java SE (component: 2D). Supported vers
- openjdk-8 <not-affected> (Vulnerable code not present)
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
CVE-2026-61308 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DSA-6457-1}
- openjdk-26 26.0.2.1+1-1
- openjdk-25 25.0.4.1+1-1
- openjdk-21 21.0.12.1+1-1
@@ -5034,6 +5255,7 @@ CVE-2026-61308 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 8u504-ga-1
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
CVE-2026-70907 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DSA-6457-1}
- openjdk-26 26.0.2.1+1-1
- openjdk-25 25.0.4.1+1-1
- openjdk-21 21.0.12.1+1-1
@@ -5042,6 +5264,7 @@ CVE-2026-70907 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 8u504-ga-1
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
CVE-2026-60589 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DSA-6457-1}
- openjdk-26 26.0.2.1+1-1
- openjdk-25 25.0.4.1+1-1
- openjdk-21 21.0.12.1+1-1
@@ -17963,7 +18186,8 @@ CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014
CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
NOT-FOR-US: Joomla
-CVE-2026-77806 [RCE fixed in 4.4.21]
+CVE-2026-77806 (SPIP before 4.4.21 allows unauthenticated remote attackers to execute ...)
+ {DSA-6456-1}
- spip 4.4.21+dfsg-1
NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
CVE-2026-77647 (SPIP before 4.4.20 allows unauthenticated remote attackers to execute ...)
@@ -20262,6 +20486,7 @@ CVE-2026-19389 (Multiple integer overflow and underflow vulnerabilities were fou
NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a598edfef83878f714ea53925ae802f49c3b31a6 (1.28.6)
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0075.html
CVE-2026-19387 (A heap out-of-bounds write vulnerability was found in the GStreamer gs ...)
+ {DSA-6458-1}
- gst-plugins-bad1.0 1.28.6-1
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12235
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12245
@@ -30887,14 +31112,14 @@ CVE-2026-XXXX [WSA-2026-3: irc: Missing size limit for the unterminated IRC mess
NOTE: Fixed by: https://github.com/weechat/weechat/commit/8b1b06a40766445bd69afdddf7c66ca691e5a697 (v4.9.2)
NOTE: Fixed by: https://github.com/weechat/weechat/commit/8d3180fa78cb71cc04e05bd098b44c9cbf922f94 (v4.9.2)
NOTE: https://weechat.org/doc/weechat/security/WSA-2026-3/
-CVE-2026-53525 [GHSA-vhv8-g2r9-cwcc: Non-Constant-Time Password Hash Comparison in Relay Authentication]
+CVE-2026-53525 (WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In ...)
- weechat 4.9.3-1
NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-vhv8-g2r9-cwcc
NOTE: Fixed by: https://github.com/weechat/weechat/commit/30230498b290fc7e2228e336356b69b5be3a76b0 (v4.9.1)
NOTE: Fixed by: https://github.com/weechat/weechat/commit/c737373d17070035b77acf21a01f21eabfb0e0fb (v4.9.1)
NOTE: Fixed by: https://github.com/weechat/weechat/commit/1ca2a0025513812885146f5e5d7fe06978167516 (v4.9.1)
NOTE: https://weechat.org/doc/weechat/security/WSA-2026-2/
-CVE-2026-53524 [GHSA-v2v4-45wm-5cr3: Decompression Bomb in Relay WebSocket (DoS)]
+CVE-2026-53524 (WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In ...)
- weechat 4.9.3-1
NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-v2v4-45wm-5cr3
NOTE: Fixed by: https://github.com/weechat/weechat/commit/35699ea8025e5bcd37cca2b1c22f041c38b8a624 (v4.9.1)
@@ -61209,6 +61434,7 @@ CVE-2026-13006 (ACE vulnerability in conditional configuration file processing
[trixie] - logback <no-dsa> (Minor issue)
NOTE: https://logback.qos.ch/news.html#1.5.35
CVE-2026-12892 (A flaw was found in GStreamer's gst-plugins-bad package. When processi ...)
+ {DSA-6458-1}
- gst-plugins-bad1.0 1.28.5-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491321
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0047.html
@@ -61218,6 +61444,7 @@ CVE-2026-12892 (A flaw was found in GStreamer's gst-plugins-bad package. When pr
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/82c694705e864ab825694464a1a83082cbb976b3 (1.28.5)
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/dfd0be05499d3315b0d125b3be5f06f7ace52259 (1.26 branch)
CVE-2026-12891 (A flaw was found in the GStreamer gst-plugins-bad package. When proces ...)
+ {DSA-6458-1}
- gst-plugins-bad1.0 1.28.5-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491318
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0048.html
@@ -61909,7 +62136,7 @@ CVE-2025-13162 (Uncontrolled Search Path Element vulnerability in ABB Control Bu
NOT-FOR-US: ABB group
CVE-2023-54365 (Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-servi ...)
- traefik <itp> (bug #983289)
-CVE-2026-44517
+CVE-2026-44517 (Buildah is a tool that facilitates building OCI images. From 1.38.1 un ...)
- golang-github-containers-buildah 1.43.2+ds1-1 (bug #1140619)
[trixie] - golang-github-containers-buildah <no-dsa> (Minor issue)
[bookworm] - golang-github-containers-buildah <not-affected> (Vulnerable build-context URL refactor introduced in 1.38.1; 1.28.2 predates it)
@@ -66208,6 +66435,7 @@ CVE-2026-54292
CVE-2026-53430 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
NOT-FOR-US: elixir-grpc grpc
CVE-2026-52722 (A signed integer overflow vulnerability was found in GStreamer's VMnc ...)
+ {DSA-6458-1}
- gst-plugins-bad1.0 1.28.5-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2486733
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0046.html
@@ -66224,6 +66452,7 @@ CVE-2026-52721 (Multiple out-of-bounds read vulnerabilities were found in GStrea
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/7ff8a2811b83f11c48f61a6e5a1d74c912a7f5c4 (1.28.5)
NOTE: Negligible security impact
CVE-2026-52720 (A heap buffer overflow vulnerability was found in GStreamer's librfb ( ...)
+ {DSA-6458-1}
- gst-plugins-bad1.0 1.28.5-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2486731
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0043.html
@@ -76980,7 +77209,7 @@ CVE-2026-9334 (Cpanel::JSON::XS versions before 4.41 for Perl allow type confusi
[bullseye] - libcpanel-json-xs-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40653179/
NOTE: Fixed by: https://github.com/rurban/Cpanel-JSON-XS/commit/11a7c550a0d8fac2f84414f24d5df9b2bfe346e2 (4.41)
-CVE-2026-50538 [Attacker-controlled heap out-of-bounds write in libvncclient Tight decoder]
+CVE-2026-50538 (LibVNCClient is a library for easy implementation of a VNC client. In ...)
- libvncserver 0.9.15+dfsg-6 (bug #1138253)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4dbd66a59cb28486d668ff1288572041301f4e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4dbd66a59cb28486d668ff1288572041301f4e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/1ab65521/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list