[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 27 20:55:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2e8e74a6 by Salvatore Bonaccorso at 2026-08-27T21:54:56+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1600,7 +1600,7 @@ CVE-2026-51106 (An issue in TokTok qTox v1.18.4 allows a local attacker to cause
 CVE-2026-48786 (Fleet is an open-source device management platform built on osquery. I ...)
 	NOT-FOR-US: Fleet
 CVE-2026-48549 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSR ...)
-	- nagios4 <unfixed>
+	- nagios4 <unfixed> (bug #1145888)
 CVE-2026-48548 (Nagios Core before 4.5.12 contains a cross-site request forgery vulner ...)
 	- nagios4 4.5.12+ds-1
 CVE-2026-47841 (An application using Spring Security's WebAuthn support may be vulnera ...)
@@ -2814,7 +2814,7 @@ CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat m
 	NOTE: https://github.com/apache/tomcat/commit/83427cbdb92ca41244dc3d242ca4308ed8ade7d3 (10.1.58)
 	NOTE: https://github.com/apache/tomcat/commit/4b41a73a2f1a16647d7444ad6ee87d41a3ec414b (9.0.121)
 CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28. ...)
-	- gh <unfixed>
+	- gh <unfixed> (bug #1145883)
 	[trixie] - gh <no-dsa> (Minor issue)
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh
 CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication  ...)
@@ -3151,7 +3151,7 @@ CVE-2026-80182 (In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2153453
 CVE-2026-19499
-	- glibc <unfixed>
+	- glibc <unfixed> (bug #1145891)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523258
 CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not  ...)
 	NOT-FOR-US: github.com/graphql-go/graphql (GraphQL for Go)
@@ -4422,7 +4422,7 @@ CVE-2026-76830
 CVE-2026-76829
 	REJECTED
 CVE-2026-76172 (fast-uri is a URI parser for Node.js. During parsing it runs a legacy  ...)
-	- node-ajv <unfixed>
+	- node-ajv <unfixed> (bug #1145882)
 	[trixie] - node-ajv <no-dsa> (Minor issue)
 	[bookworm] - node-ajv <not-affected> (fast-uri not present)
 	[bullseye] - node-ajv <not-affected> (fast-uri not present)
@@ -4441,21 +4441,21 @@ CVE-2026-76055 (Improper Neutralization of Special Elements used in an OS Comman
 CVE-2026-76054 (Invocation of Process Using Visible Sensitive Information in Black Duc ...)
 	NOT-FOR-US: Black Duck
 CVE-2026-75975 (fast-uri is a URI parser for Node.js. Its custom parser for bracketed  ...)
-	- node-ajv <unfixed>
+	- node-ajv <unfixed> (bug #1145882)
 	[trixie] - node-ajv <no-dsa> (Minor issue)
 	[bookworm] - node-ajv <not-affected> (fast-uri not present)
 	[bullseye] - node-ajv <not-affected> (fast-uri not present)
 	NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc
 	NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
 CVE-2026-75931 (fast-uri is a URI parser for Node.js. It canonicalizes a host to its A ...)
-	- node-ajv <unfixed>
+	- node-ajv <unfixed> (bug #1145882)
 	[trixie] - node-ajv <no-dsa> (Minor issue)
 	[bookworm] - node-ajv <not-affected> (fast-uri not present)
 	[bullseye] - node-ajv <not-affected> (fast-uri not present)
 	NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8
 	NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
 CVE-2026-75899 (fast-uri is a URI parser for Node.js. It decodes percent escapes in a  ...)
-	- node-ajv <unfixed>
+	- node-ajv <unfixed> (bug #1145882)
 	[trixie] - node-ajv <no-dsa> (Minor issue)
 	[bookworm] - node-ajv <not-affected> (fast-uri not present)
 	[bullseye] - node-ajv <not-affected> (fast-uri not present)
@@ -4609,7 +4609,7 @@ CVE-2026-66585 (Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15
 CVE-2026-66584 (Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <=  ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65053 (Horde IMP's AppleDouble MIME viewer writes an attacker-controlled atta ...)
-	- php-horde-imp <unfixed>
+	- php-horde-imp <unfixed> (bug #1145884)
 	NOTE: https://github.com/horde/imp/pull/107
 	NOTE: https://github.com/horde/imp/commit/f31449a12e3f945c90015d29524925c4c43f6324
 	NOTE: https://blog.evan.lat/posts/CVE-2026-65053/
@@ -7218,7 +7218,7 @@ CVE-2026-18917 (A flaw was found in libvirt. An unprivileged local user could ex
 CVE-2026-18482 (Neo.mjs contains a command injection vulnerability within the FileSyst ...)
 	NOT-FOR-US: Neo.mjs
 CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerab ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145900)
 	[trixie] - gimp <not-affected> (Vulnerable code not present)
 	[bookworm] - gimp <not-affected> (Vulnerable code not present)
 	[bullseye] - gimp <not-affected> (Vulnerable code not present)
@@ -7227,42 +7227,42 @@ CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution Vu
 	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104 (GIMP_3_1_2)
 CVE-2026-18308 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145899)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-461/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/d84f8e58f56681a0b4c66129c568cb796725ab9d
 CVE-2026-18307 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145898)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-460/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bace3e7fd54104fe6b70c1703e9b982a4770811d
 CVE-2026-18306 (GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145897)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-459/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/76531da9732f38566e5fd8f8f80c837158511ae5
 CVE-2026-18305 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145896)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-458/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0a45a2b51b877829ef523131b50c0eb2a933b8a1
 CVE-2026-18304 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145895)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-457/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ad32d22c347674fa1bb5b60935c376b673d946e7
 CVE-2026-18303 (GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Executio ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145894)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-456/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/5633b362026c6e5b2beb559a10cd76fa32a47592
 CVE-2026-18302 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145893)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-455/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/77e1a11636fae53c922fe92273b8f4e33c7a9176
 CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
 	{DSA-6470-1}
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145892)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-454/
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2772
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/b1f46e63c82065bd60e84359fb729380d5b043bf
@@ -12988,7 +12988,7 @@ CVE-2026-33437 (Stirling-PDF is a locally hosted web application that facilitate
 CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
-	- assimp <unfixed>
+	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <no-dsa> (Minor issue)
 	NOTE: https://github.com/assimp/assimp/issues/6633
 	NOTE: https://github.com/assimp/assimp/pull/6759
@@ -13128,15 +13128,15 @@ CVE-2026-19972 (A vulnerability has been found in itsourcecode Hospital Manageme
 CVE-2026-19971 (A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the funct ...)
 	NOT-FOR-US: LB-Link
 CVE-2026-19970 (A vulnerability was detected in Open Asset Import Library Assimp 17c12 ...)
-	- assimp <unfixed>
+	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/assimp/assimp/issues/6632
 CVE-2026-19969 (A security vulnerability has been detected in Open Asset Import Librar ...)
-	- assimp <unfixed>
+	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/assimp/assimp/issues/6631
 CVE-2026-19968 (A weakness has been identified in Open Asset Import Library Assimp 17c ...)
-	- assimp <unfixed>
+	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <no-dsa> (Minor issue)
 	NOTE: https://github.com/assimp/assimp/issues/6630
 	NOTE: https://github.com/assimp/assimp/pull/6717
@@ -13144,7 +13144,7 @@ CVE-2026-19968 (A weakness has been identified in Open Asset Import Library Assi
 	NOTE: https://github.com/assimp/assimp/commit/0f6bcfe7acd4c16bc198560db1be848757f953a8
 	NOTE: https://github.com/assimp/assimp/commit/924bb602e387e10ca7c64acaac83a26d6ad1d8c6
 CVE-2026-19967 (A security flaw has been discovered in Open Asset Import Library Assim ...)
-	- assimp <unfixed>
+	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/assimp/assimp/issues/6624
 CVE-2026-19966 (A vulnerability was identified in CodeCanyon TimeCamp Integration for  ...)
@@ -67389,7 +67389,7 @@ CVE-2026-54588 (Poweradmin is a web-based DNS administration tool for PowerDNS s
 CVE-2026-54555 (rtk filters and compresses command outputs before they reach your LLM  ...)
 	NOT-FOR-US: rtk-ai rtk
 CVE-2026-54518 (jackson-databind contains the general-purpose data-binding functionali ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1145887)
 	[bookworm] - jackson-databind <not-affected> (introduced in 2.21.0; bookworm ships 2.14)
 	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rcqc-6cw3-h962
@@ -67398,7 +67398,7 @@ CVE-2026-54518 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/721fa07ebbd4aab4a659a1a68940878315c3e341 (jackson-databind-2.21.4)
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/d633bc038f200c1397c07f1a2b46f58e72c91eea (jackson-databind-3.1.4)
 CVE-2026-54517 (jackson-databind contains the general-purpose data-binding functionali ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1145887)
 	[bookworm] - jackson-databind <not-affected> (introduced in 2.21.0; bookworm ships 2.14)
 	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5hh8-q8hv-fr38
@@ -67407,7 +67407,7 @@ CVE-2026-54517 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/94c5d215b3af1505098c686405d9641f041a9962 (jackson-databind-2.21.4)
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d (jackson-databind-3.1.4)
 CVE-2026-54516 (jackson-databind contains the general-purpose data-binding functionali ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1145887)
 	[bookworm] - jackson-databind <not-affected> (introduced in 2.21.0; bookworm ships 2.14)
 	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-9fxm-vc8v-hj55
@@ -67416,20 +67416,20 @@ CVE-2026-54516 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a (jackson-databind-2.21.4)
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af (jackson-databind-3.1.4)
 CVE-2026-54515 (jackson-databind contains the general-purpose data-binding functionali ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1145887)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v
 	NOTE: https://github.com/FasterXML/jackson-databind/issues/5962
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5964
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa (jackson-databind-3.1.4)
 CVE-2026-54514 (jackson-databind contains the general-purpose data-binding functionali ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1145887)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5951
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4 (jackson-databind-2.18.8)
 	NOTE: When fixing this issue make sure to fix it completly and not open up CVE-2026-77310
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd (jackson-databind-2.18.9)
 CVE-2026-54513 (jackson-databind contains the general-purpose data-binding functionali ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1145887)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f
 	NOTE: https://github.com/FasterXML/jackson-databind/issues/5981
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5983
@@ -67437,7 +67437,7 @@ CVE-2026-54513 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5 (jackson-databind-2.18.8)
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e (jackson-databind-3.1.4)
 CVE-2026-54512 (jackson-databind contains the general-purpose data-binding functionali ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1145887)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm
 	NOTE: https://github.com/FasterXML/jackson-databind/issues/5988
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5 (jackson-databind-2.18.8)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e8e74a6197eac7c7af6e562dab201ef5d119278

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e8e74a6197eac7c7af6e562dab201ef5d119278
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/8168f413/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list