[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 27 19:45:57 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8d5f9489 by Moritz Muehlenhoff at 2026-08-27T20:45:34+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2195,6 +2195,7 @@ CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat m
NOTE: https://github.com/apache/tomcat/commit/4b41a73a2f1a16647d7444ad6ee87d41a3ec414b (9.0.121)
CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28. ...)
- gh <unfixed>
+ [trixie] - gh <no-dsa> (Minor issue)
NOTE: https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh
CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication ...)
- ruby-doorkeeper-openid-connect 1.10.5-1
@@ -2232,14 +2233,22 @@ CVE-2026-68515 (OpenEXR is the reference implementation and specification for th
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/e2300a3d54a93d20a36a86b82f3a506c4c91476f (v3.2.11-rc)
CVE-2026-68514 (OpenEXR is the reference implementation and specification for the EXR ...)
- openexr 3.4.14-0.1
+ [trixie] - openexr <not-affected> (Vulnerable code not present)
+ [bookworm] - openexr <not-affected> (Vulnerable code not present)
+ [bullseye] - openexr <not-affected> (Vulnerable code not present)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-mw28-66qc-c883
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/c1f3ec0d91cfa5a8035ecd00920835ac76e01640 (v3.4.14-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/d134e3cd81a2e343f2919e86bf949f576b1ab16a (v3.3.13-rc)
+ NOTE: Introduced by: https://github.com/AcademySoftwareFoundation/openexr/commit/84d7d52e17a17e18d138d9d1aa9f4e2de2fcb2d6 (v3.3.0-rc)
CVE-2026-68513 (OpenEXR is the reference implementation and specification for the EXR ...)
- openexr 3.4.14-0.1
+ [trixie] - openexr <not-affected> (Vulnerable code not present)
+ [bookworm] - openexr <not-affected> (Vulnerable code not present)
+ [bullseye] - openexr <not-affected> (Vulnerable code not present)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-rw5h-3q4v-c3vc
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/c1f3ec0d91cfa5a8035ecd00920835ac76e01640 (v3.4.14-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/d134e3cd81a2e343f2919e86bf949f576b1ab16a (v3.3.13-rc)
+ NOTE: Introduced by: https://github.com/AcademySoftwareFoundation/openexr/commit/84d7d52e17a17e18d138d9d1aa9f4e2de2fcb2d6 (v3.3.0-rc)
CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by securit ...)
- tomcat11 <unfixed> (bug #1145698)
- tomcat10 <unfixed> (bug #1145699)
@@ -2348,11 +2357,11 @@ CVE-2026-62861 (TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenti
NOT-FOR-US: Typebot
CVE-2026-59981 (OpenEXR is the reference implementation and specification for the EXR ...)
- openexr 3.4.14-0.1
+ [trixie] - openexr <no-dsa> (Minor issue)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m799-ffc3-8pxc
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c (v3.4.14-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec (v3.3.13-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1 (v3.2.11-rc)
- TODO: check, the commits referenced are the same as for GHSA-hwmv-39v6-739m / CVE-2026-59189
CVE-2026-58108 (The personal access token removal query selects fromPersonalAccessToke ...)
NOT-FOR-US: Ericsson
CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value without leng ...)
@@ -2392,8 +2401,9 @@ CVE-2026-53965 (The MCP PHP SDK (Composer package mcp/sdk) is the official Model
CVE-2026-52776 (Compliance-trestle (Trestle) is a tooling platform for managing compli ...)
NOT-FOR-US: compliance-trestle
CVE-2026-52491 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an ...)
- - tiff 4.7.2-1
+ - tiff 4.7.2-1 (unimportant)
NOTE: Fixed by: https://gitlab.com/libtiff/libtiff/-/commit/9ce4d089bcf25496663776d9e6336738112f09a3 (v4.7.2rc2)
+ NOTE: thumbnail not included in Debian binary packages
CVE-2026-52489 (Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de ...)
- gpac <removed>
[bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
@@ -2630,9 +2640,11 @@ CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on the
NOT-FOR-US: Ech0
CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution vulnerabil ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw
CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos package. This ...)
- sos <unfixed>
+ [trixie] - sos <no-dsa> (Minor issue)
- sospreort <removed>
NOTE: https://github.com/sosreport/sos/issues/4460
NOTE: https://github.com/sosreport/sos/pull/4461
@@ -2682,9 +2694,10 @@ CVE-2026-78468
CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the python_ ...)
NOT-FOR-US: Amazon
CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a maliciou ...)
- - file-roller 44.7-1
+ - file-roller 44.7-1 (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/file-roller/-/issues/327
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/file-roller/-/commit/ffb76dc866342cef6a4914873faaa880d14d5aa4 (44.7)
+ NOTE: Crash in GUI tool, no security impact
CVE-2026-77998 (Joomla Extension - miniorange.com - Unauthenticated Authentication Byp ...)
NOT-FOR-US: Joomla
CVE-2026-77997 (Joomla Extension - yootheme.com - Authenticated, privileged informatio ...)
@@ -3215,6 +3228,7 @@ CVE-2026-63075 (Issue summary: When OpenSSL processes QUIC traffic from a peer t
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-19953
- liburi-perl 5.36-1
+ [trixie] - liburi-perl <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/libwww-perl/URI/commit/8c213ff92fdae45d0fabb7bc16f6a6f27e911395 (v5.36)
CVE-2026-7455 (A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, ...)
NOT-FOR-US: Autodesk
@@ -3328,6 +3342,7 @@ CVE-2026-76816 (Netty is an asynchronous, event-driven network application frame
NOTE: Fixed by: https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961 (netty-4.1.137.Final)
CVE-2026-76098 (Mistune is a Python Markdown parser with renderers and plugins. Versio ...)
- mistune <unfixed> (bug #1145881)
+ [trixie] - mistune <no-dsa> (Minor issue)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-6m44-fpc8-c3rq
NOTE: https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2 (v3.3.3)
CVE-2026-76063 (The FundEngine \u2013 Donation and Crowdfunding Platform plugin for Wo ...)
@@ -3346,6 +3361,7 @@ CVE-2026-75542 (Incorrect Authorization vulnerability in the OAuth token endpoin
NOT-FOR-US: hexpm (server side)
CVE-2026-75509 (joserfc is a Python library that provides an implementation of several ...)
- joserfc 1.7.3-1
+ [trixie] - joserfc <no-dsa> (Minor issue)
NOTE: https://github.com/authlib/joserfc/security/advisories/GHSA-r74j-q665-7rpj
NOTE: Fixed by: https://github.com/authlib/joserfc/commit/76ee6a59bf5773c0af00b99076c5e199031f97f1 (1.7.3)
CVE-2026-75464 (OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnera ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d5f948919fbe6b69d351e19a4561012806a7c6e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d5f948919fbe6b69d351e19a4561012806a7c6e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/720f8834/attachment.htm>
More information about the debian-security-tracker-commits
mailing list