[Git][security-tracker-team/security-tracker][master] Add two new node-qs issus

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 30 09:25:31 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f0eab2f9 by Salvatore Bonaccorso at 2026-08-30T10:24:51+02:00
Add two new node-qs issus

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -100,7 +100,9 @@ CVE-2026-58581
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/702216619e2a1afd5039520114f4d245d7011f09 (v11.1.0-rc2)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e0397dbe1a295e037f16f154aaaa3cff3341fc3d (v11.0.4)
 CVE-2026-82562 (### Summary    When `qs.parse` is called with `comma: true` and `throw ...)
-	TODO: check
+	- node-qs <unfixed>
+	NOTE: https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx
+	NOTE: Fixed by: https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464 (v6.16.0)
 CVE-2026-82482 (A security vulnerability has been detected in coppermine-gallery Coppe ...)
 	TODO: check
 CVE-2026-82480 (A security flaw has been discovered in NASA cFS up to 7.0.1. The affec ...)
@@ -118,7 +120,9 @@ CVE-2026-82422 (A security flaw has been discovered in itsourcecode Sales and In
 CVE-2026-82421 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-82417 (### Summary    `qs.stringify` throws a `TypeError` when it serializes  ...)
-	TODO: check
+	- node-qs <unfixed>
+	NOTE: https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g
+	NOTE: Fixed by: https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6 (v6.16.0)
 CVE-2026-81766 (The Really Simple Security  WordPress plugin before 9.8.0 does not che ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81660 (The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation WordP ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f0eab2f9794d40596f5e313ed02fefaa43a95b2f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f0eab2f9794d40596f5e313ed02fefaa43a95b2f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/6ec495d0/attachment.htm>


More information about the debian-security-tracker-commits mailing list