[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 27 16:35:51 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
344b9eee by Moritz Muehlenhoff at 2026-08-27T17:35:28+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -40,6 +40,7 @@ CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via th
 	NOT-FOR-US: Joomla
 CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia diagram e ...)
 	- dia <unfixed>
+	[trixie] - dia <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/580
 CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
 	- seaweedfs <itp> (bug #956957)
@@ -346,6 +347,7 @@ CVE-2026-78360
 	NOT-FOR-US: fedora-infra/anitya
 CVE-2026-77117
 	- glibc <unfixed>
+	[trixie] - glibc <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523274
 CVE-2026-9668 (With legitimate user credentials in hand, attackers can construct mali ...)
 	NOT-FOR-US: ZTE
@@ -2147,7 +2149,9 @@ CVE-2026-77693 (The Order Tip for WooCommerce WordPress plugin before 1.6.0 does
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range header p ...)
 	- libsoup3 <unfixed> (bug #1145785)
+	[trixie] - libsoup3 <no-dsa> (Minor issue)
 	- libsoup2.4 <removed>
+	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/538
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
 CVE-2026-77585 (The Okta Privileged Access client does not reject a leading hyphen in  ...)
@@ -2412,8 +2416,10 @@ CVE-2026-41707 (Authentication Bypass by Capture-replay vulnerability in Spring
 CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecosystem ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)
-	- sqlite3 <unfixed>
-	TODO: check upstream details
+	- sqlite3 3.53.2-1
+	[trixie] - sqlite3 <no-dsa> (Minor issue)
+	NOTE: https://github.com/20000419/CVE-2026-39113
+	NOTE: https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508 (version-3.53.0)
 CVE-2026-38474 (GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d1 ...)
 	NOT-FOR-US: GazellePW
 CVE-2026-38473 (A Stored XSS vulnerability in the subtitle deletion flow in GazellePW  ...)
@@ -2580,12 +2586,15 @@ CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found in
 	NOT-FOR-US: Ansible Galaxy server plugin for Pulp
 CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal vulnerability in  ...)
 	- nltk 3.10.3-1
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-p4rw-rvv2-7xwr
 CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed through the pe ...)
 	- nltk 3.10.3-1
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3
 CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ...)
 	- nltk 3.10.3-1
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
 CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:rea ...)
 	NOT-FOR-US: Ech0
@@ -3069,10 +3078,10 @@ CVE-2026-17548 (Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50
 CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations in a fe ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY auth ...)
-	- wget <unfixed>
-	[trixie] - wget <no-dsa> (Minor issue)
+	- wget <unfixed> (unimportant)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-16599/
 	NOTE: Fixed by: https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
+	NOTE: Hang in CLI tool, no security impact
 CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability in TRtek ...)
 	NOT-FOR-US: TRtek Software Repository Management
 CVE-2026-16234 (There is a memory corruption vulnerability recently discovered in NI L ...)
@@ -3123,6 +3132,7 @@ CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby implementation only, when the pack
 	TODO: check
 CVE-2026-63676
 	- libyaml-perl 1.321-1
+	[trixie] - libyaml-perl <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1 (v1.320.0)
 CVE-2026-XXXX [GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution]
 	- sabnzbdplus 5.1.2+dfsg-1 (bug #1145563)
@@ -3579,6 +3589,7 @@ CVE-2026-78369 (RansomLook contains a missing authentication vulnerability in th
 	NOT-FOR-US: RansomLook
 CVE-2026-78367 (A vulnerability was found in RPM's rpmbuild tarball processing. When p ...)
 	- rpm <unfixed>
+	[trixie] - rpm <no-dsa> (Minor issue)
 	NOTE: https://github.com/rpm-software-management/rpm/issues/4314
 CVE-2026-78365 (Authorization Bypass Through User-Controlled Key in the supplier API i ...)
 	NOT-FOR-US: Roskus Prospero Flow CRM


=====================================
data/dsa-needed.txt
=====================================
@@ -57,6 +57,8 @@ jupyterlab
 --
 kamailio
 --
+keystone
+--
 kitty
 --
 libapache2-mod-auth-openidc (jmm)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/344b9eee707b3fe2ee651d12e0ba46b71f6760a7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/344b9eee707b3fe2ee651d12e0ba46b71f6760a7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/034b19a5/attachment.htm>


More information about the debian-security-tracker-commits mailing list