[Git][security-tracker-team/security-tracker][master] Triage CVE-2025-30153, CVE-2026-73501, CVE-2026-73502, CVE-2026-76905 &...

Chris Lamb (@lamby) lamby at debian.org
Sat Aug 22 19:04:49 BST 2026



Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d74812c by Chris Lamb at 2026-08-22T11:04:33-07:00
Triage CVE-2025-30153, CVE-2026-73501, CVE-2026-73502, CVE-2026-76905 & CVE-2026-77354 in golang-github-getkin-kin-openapi for bookworm and bullseye LTS.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -619,6 +619,8 @@ CVE-2026-77413 (JSONata is a JSON query and transformation language. Prior to 1.
 	NOT-FOR-US: jsonata-js
 CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 u ...)
 	- golang-github-getkin-kin-openapi <unfixed>
+	[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
+	[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-xhj3-7xw9-vr34
 	NOTE: https://github.com/getkin/kin-openapi/pull/923
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/1223a0f215d2cf9beb2d9eb9ea2649d001c21388 (v0.142.0)
@@ -637,6 +639,8 @@ CVE-2026-77000 (The WP Social Media Login WordPress plugin through 1.0.6 does no
 	NOT-FOR-US: WordPress plugin
 CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 un ...)
 	- golang-github-getkin-kin-openapi <unfixed>
+	[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
+	[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-mmfr-pmjx-hw9w
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/1d0a337c9b1570fab283be8a04c8af6e43b9a22c (v0.141.0)
 CVE-2026-76904 (GeoTools is an open source Java library that provides tools for geospa ...)
@@ -6463,6 +6467,8 @@ CVE-2026-73692
 CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 unt ...)
 	- golang-github-getkin-kin-openapi <unfixed> (bug #1144951)
 	[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
+	[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
+	[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-jpcw-4wr7-c3vq
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/68ac2affa325514d7d6e731204d6a1edf6bdff64 (v0.144.0)
 CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
@@ -14786,6 +14792,8 @@ CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentica
 CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
 	- golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
 	[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
+	[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
+	[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da (v0.144.0)
 CVE-2026-73500 (etcd is a distributed key-value store for the data of a distributed sy ...)
@@ -256511,6 +256519,8 @@ CVE-2025-30154 (reviewdog/action-setup is a GitHub action that installs reviewdo
 	NOT-FOR-US: reviewdog/action-setup GitHub action
 CVE-2025-30153 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131 ...)
 	- golang-github-getkin-kin-openapi 0.135.0-1
+	[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
+	[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-wq9g-9vfc-cfq9
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/67f0b233ffc01332f7d993f79490fbea5f4455f1 (v0.131.0)
 CVE-2025-30152 (The Syliud PayPal Plugin is the Sylius Core Team\u2019s plugin for the ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d74812c9deef653fca19cffde33a074e646b4d9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d74812c9deef653fca19cffde33a074e646b4d9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/9206ff68/attachment.htm>


More information about the debian-security-tracker-commits mailing list