[Git][security-tracker-team/security-tracker][master] Reserve DSA number for starlette update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 30 20:04:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b948ef04 by Salvatore Bonaccorso at 2026-08-30T21:04:19+02:00
Reserve DSA number for starlette update

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -72533,7 +72533,6 @@ CVE-2026-48820 (CakePHP is a rapid development framework for PHP. In versions 4.
 CVE-2026-48817 (Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 a ...)
 	{DLA-4711-1}
 	- starlette 1.1.0-1
-	[trixie] - starlette <no-dsa> (Minor issue)
 	[bullseye] - starlette <ignored> (Minor issue)
 	NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c
 	NOTE: https://github.com/Kludex/starlette/pull/3286


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[30 Aug 2026] DSA-6478-1 starlette - security update
+	{CVE-2026-48817 CVE-2026-54282 CVE-2026-54283}
+	[trixie] - starlette 0.46.1-3+deb13u3
 [29 Aug 2026] DSA-6477-1 linux - security update
 	{CVE-2025-40074 CVE-2026-64216 CVE-2026-64581 CVE-2026-74626 CVE-2026-74653 CVE-2026-74662 CVE-2026-80536 CVE-2026-80557 CVE-2026-80562 CVE-2026-80572 CVE-2026-80583 CVE-2026-80590 CVE-2026-80725}
 	[trixie] - linux 6.12.107-1


=====================================
data/dsa-needed.txt
=====================================
@@ -152,9 +152,6 @@ shaarli
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --
-starlette (carnil)
-  Matheus Polkorny is proposing an update for review, acked for upload
---
 tomcat10
 --
 tomcat11



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b948ef04372de1c57e9e4a7c706a18a47ac60c8a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b948ef04372de1c57e9e4a7c706a18a47ac60c8a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/fe09793e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list