[Git][security-tracker-team/security-tracker][master] Add CVE-2026-77354

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 22 09:00:45 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c96b14c5 by Salvatore Bonaccorso at 2026-08-22T10:00:16+02:00
Add CVE-2026-77354

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11,7 +11,10 @@ CVE-2026-77414 (JSONata is a JSON query and transformation language. Prior to 1.
 CVE-2026-77413 (JSONata is a JSON query and transformation language. Prior to 1.8.8 an ...)
 	TODO: check
 CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 u ...)
-	TODO: check
+	- golang-github-getkin-kin-openapi <unfixed>
+	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-xhj3-7xw9-vr34
+	NOTE: https://github.com/getkin/kin-openapi/pull/923
+	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/1223a0f215d2cf9beb2d9eb9ea2649d001c21388 (v0.142.0)
 CVE-2026-77220 (PDFio before 1.6.5 contains a dangling pointer vulnerability in the di ...)
 	TODO: check
 CVE-2026-77219 (GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/P ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c96b14c582281b4a607b32aa046d8bf71783dc13

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c96b14c582281b4a607b32aa046d8bf71783dc13
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/a9895adf/attachment.htm>


More information about the debian-security-tracker-commits mailing list