[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 27 16:35:51 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
344b9eee by Moritz Muehlenhoff at 2026-08-27T17:35:28+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -40,6 +40,7 @@ CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via th
NOT-FOR-US: Joomla
CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia diagram e ...)
- dia <unfixed>
+ [trixie] - dia <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/580
CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
- seaweedfs <itp> (bug #956957)
@@ -346,6 +347,7 @@ CVE-2026-78360
NOT-FOR-US: fedora-infra/anitya
CVE-2026-77117
- glibc <unfixed>
+ [trixie] - glibc <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523274
CVE-2026-9668 (With legitimate user credentials in hand, attackers can construct mali ...)
NOT-FOR-US: ZTE
@@ -2147,7 +2149,9 @@ CVE-2026-77693 (The Order Tip for WooCommerce WordPress plugin before 1.6.0 does
NOT-FOR-US: WordPress plugin
CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range header p ...)
- libsoup3 <unfixed> (bug #1145785)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/538
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
CVE-2026-77585 (The Okta Privileged Access client does not reject a leading hyphen in ...)
@@ -2412,8 +2416,10 @@ CVE-2026-41707 (Authentication Bypass by Capture-replay vulnerability in Spring
CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecosystem ...)
NOT-FOR-US: WordPress plugin
CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)
- - sqlite3 <unfixed>
- TODO: check upstream details
+ - sqlite3 3.53.2-1
+ [trixie] - sqlite3 <no-dsa> (Minor issue)
+ NOTE: https://github.com/20000419/CVE-2026-39113
+ NOTE: https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508 (version-3.53.0)
CVE-2026-38474 (GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d1 ...)
NOT-FOR-US: GazellePW
CVE-2026-38473 (A Stored XSS vulnerability in the subtitle deletion flow in GazellePW ...)
@@ -2580,12 +2586,15 @@ CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found in
NOT-FOR-US: Ansible Galaxy server plugin for Pulp
CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal vulnerability in ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-p4rw-rvv2-7xwr
CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed through the pe ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3
CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:rea ...)
NOT-FOR-US: Ech0
@@ -3069,10 +3078,10 @@ CVE-2026-17548 (Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50
CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations in a fe ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY auth ...)
- - wget <unfixed>
- [trixie] - wget <no-dsa> (Minor issue)
+ - wget <unfixed> (unimportant)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-16599/
NOTE: Fixed by: https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
+ NOTE: Hang in CLI tool, no security impact
CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability in TRtek ...)
NOT-FOR-US: TRtek Software Repository Management
CVE-2026-16234 (There is a memory corruption vulnerability recently discovered in NI L ...)
@@ -3123,6 +3132,7 @@ CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby implementation only, when the pack
TODO: check
CVE-2026-63676
- libyaml-perl 1.321-1
+ [trixie] - libyaml-perl <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1 (v1.320.0)
CVE-2026-XXXX [GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution]
- sabnzbdplus 5.1.2+dfsg-1 (bug #1145563)
@@ -3579,6 +3589,7 @@ CVE-2026-78369 (RansomLook contains a missing authentication vulnerability in th
NOT-FOR-US: RansomLook
CVE-2026-78367 (A vulnerability was found in RPM's rpmbuild tarball processing. When p ...)
- rpm <unfixed>
+ [trixie] - rpm <no-dsa> (Minor issue)
NOTE: https://github.com/rpm-software-management/rpm/issues/4314
CVE-2026-78365 (Authorization Bypass Through User-Controlled Key in the supplier API i ...)
NOT-FOR-US: Roskus Prospero Flow CRM
=====================================
data/dsa-needed.txt
=====================================
@@ -57,6 +57,8 @@ jupyterlab
--
kamailio
--
+keystone
+--
kitty
--
libapache2-mod-auth-openidc (jmm)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/344b9eee707b3fe2ee651d12e0ba46b71f6760a7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/344b9eee707b3fe2ee651d12e0ba46b71f6760a7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/034b19a5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list