[Git][security-tracker-team/security-tracker][master] Track fixed version for two sabnzbdplus and reference GHSA's
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 25 18:13:14 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e4763c39 by Salvatore Bonaccorso at 2026-08-25T19:06:58+02:00
Track fixed version for two sabnzbdplus and reference GHSA's
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,11 @@
CVE-2026-XXXX [GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution]
- - sabnzbdplus <unfixed> (bug #1145563)
+ - sabnzbdplus 5.1.2+dfsg-1 (bug #1145563)
+ NOTE: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-rgqj-28c2-gxwp
NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/a0e24089338e4a9b214a439e6dba2ee489195847 (5.1.2)
NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/6525703a94cfdb6c8add5c6f91bc073a7e928ed5 (5.1.2)
CVE-2026-XXXX [GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path traversal enabling cross-job __verified__ pickle RCE]
- - sabnzbdplus <unfixed> (bug #1145563)
+ - sabnzbdplus 5.1.2+dfsg-1 (bug #1145563)
+ NOTE: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-75g3-96fr-7p2r
NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0 (5.1.2)
NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8 (5.1.2)
CVE-2026-18798
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4763c3990c3dd5c79c476089360261702795f60
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4763c3990c3dd5c79c476089360261702795f60
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/5297086a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list