[Git][security-tracker-team/security-tracker][master] Add two sabnzbdplus issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 17:11:45 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e399a402 by Salvatore Bonaccorso at 2026-08-25T18:08:33+02:00
Add two sabnzbdplus issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,11 @@
+CVE-2026-XXXX [GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution]
+	- sabnzbdplus <unfixed> (bug #1145563)
+	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/a0e24089338e4a9b214a439e6dba2ee489195847 (5.1.2)
+	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/6525703a94cfdb6c8add5c6f91bc073a7e928ed5 (5.1.2)
+CVE-2026-XXXX [GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path traversal enabling cross-job __verified__ pickle RCE]
+	- sabnzbdplus <unfixed> (bug #1145563)
+	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0 (5.1.2)
+	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8 (5.1.2)
 CVE-2026-18798
 	- openssl <unfixed>
 	[bookworm] - openssl <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e399a40213a21afea26e95cb8046d78833cc77ee

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e399a40213a21afea26e95cb8046d78833cc77ee
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/e7cfa4d6/attachment.htm>


More information about the debian-security-tracker-commits mailing list