[Git][security-tracker-team/security-tracker][master] Add CVE-2026-72924/gh

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 12:32:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
af604761 by Salvatore Bonaccorso at 2026-08-26T13:31:33+02:00
Add CVE-2026-72924/gh

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1117,7 +1117,8 @@ CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat m
 	NOTE: https://github.com/apache/tomcat/commit/83427cbdb92ca41244dc3d242ca4308ed8ade7d3 (10.1.58)
 	NOTE: https://github.com/apache/tomcat/commit/4b41a73a2f1a16647d7444ad6ee87d41a3ec414b (9.0.121)
 CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28. ...)
-	TODO: check
+	- gh <unfixed>
+	NOTE: https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh
 CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication  ...)
 	TODO: check
 CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af604761887e67c7a97b85b5f35e7b4f9d270f7e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af604761887e67c7a97b85b5f35e7b4f9d270f7e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/0fe35148/attachment.htm>


More information about the debian-security-tracker-commits mailing list