[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Aug 30 21:44:59 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5002e994 by Moritz Muehlenhoff at 2026-08-30T22:44:05+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -736,6 +736,7 @@ CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
- libsolv <unfixed>
+ [trixie] - libsolv <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
TODO: check upstream status, no references from Red Hat
CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
@@ -2482,6 +2483,7 @@ CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker
NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3
NOTE: https://github.com/rsyslog/rsyslog/pull/7525
NOTE: https://github.com/rsyslog/rsyslog/commit/667e3f61aec5ee02c5c2ee6f0f8accf6fe4301a9
+ NOTE: https://www.openwall.com/lists/oss-security/2026/08/29/1
CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-75573 (In MongoDB Connector for BI, mongodrdl may write a TLS private-key pas ...)
@@ -5270,6 +5272,7 @@ CVE-2026-55805 (Improper Neutralization of Input During Web Page Generation ("Cr
NOT-FOR-US: Drupal core and addons
CVE-2026-55588 (ORAS (OCI Registry As Storage) is a CLI and library for managing artif ...)
- oras 1.3.3-1
+ [trixie] - oras <no-dsa> (Minor issue)
NOTE: https://github.com/oras-project/oras/security/advisories/GHSA-298f-872v-2rcx
NOTE: Fixed by: https://github.com/oras-project/oras/commit/440eb65d07a0631f131944d28e7c29d562ec17f3 (v1.3.3)
CVE-2026-54757 (Compliance-trestle (Trestle) is a Python SDK and command-line tool for ...)
@@ -5412,6 +5415,7 @@ CVE-2026-80182 (In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1
NOTE: https://bugs.launchpad.net/keystone/+bug/2153453
CVE-2026-19499
- glibc <unfixed> (bug #1145891)
+ [trixie] - glibc <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523258
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34510
CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not ...)
@@ -13483,7 +13487,7 @@ CVE-2026-75911 (CodeWhale versions before 0.8.64 fail to properly validate the a
NOT-FOR-US: CodeWhale
CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplo ...)
- libmodplug 1:0.8.9.0-4 (bug #1144933)
- [trixie] - libmodplug <postponed> (Minor issue, revisit when fixed upstream)
+ [trixie] - libmodplug <no-dsa> (Minor issue)
NOTE: https://github.com/Konstanty/libmodplug/issues/103
CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
NOT-FOR-US: RAGFlow
@@ -15076,6 +15080,7 @@ CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1
NOT-FOR-US: Kiota
CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
- node-postcss 8.5.19+~cs10.2.23-1
+ [trixie] - node-postcss <no-dsa> (Minor issue)
NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849
NOTE: Fixed by: https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c (8.5.18)
CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation vulnerabi ...)
@@ -23632,6 +23637,7 @@ CVE-2026-48813 (Flawfinder is a a static analysis tool for finding vulnerabiliti
NOT-FOR-US: Flawfinder
CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO realtime c ...)
- python-engineio <unfixed> (bug #1144515)
+ [trixie] - python-engineio <no-dsa> (Minor issue)
NOTE: https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
NOTE: Fixed by: https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e (v5.16.4)
CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
@@ -25195,10 +25201,12 @@ CVE-2026-49179 (Improper neutralization of special elements used in a command ('
NOT-FOR-US: Microsoft
CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
- python-engineio <unfixed> (bug #1144516)
+ [trixie] - python-engineio <no-dsa> (Minor issue)
NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9
TODO: checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue
CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
- python-engineio <unfixed> (bug #1144517)
+ [trixie] - python-engineio <no-dsa> (Minor issue)
NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5
CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the open-source datab ...)
NOT-FOR-US: Turso CLI
@@ -29215,6 +29223,7 @@ CVE-2026-58262 (Klever-Go is the Go implementation of the Klever blockchain prot
NOT-FOR-US: Klever-Go
CVE-2026-54338 (JupyterHub is software that allows users to create a multi-user server ...)
- jupyterhub <unfixed> (bug #1143967)
+ [trixie] - jupyterhub <no-dsa> (Minor issue)
NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h
NOTE: Fixed by: https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d69e7fce0a (5.5.0)
CVE-2026-52880 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
@@ -52166,6 +52175,7 @@ CVE-2026-59205 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow's Im
NOTE: Fixed by: https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721 (12.3.0)
CVE-2026-59204 (Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/lib ...)
- pillow 12.3.0-1 (bug #1142274)
+ [trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue, DoS)
[bullseye] - pillow <ignored> (JPEG2000 support not built)
NOTE: https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j
@@ -56578,6 +56588,7 @@ CVE-2026-12593 (The implementation of an internalandundocumentedDashboardAPI end
NOT-FOR-US: QT Axivion
CVE-2026-12590 (Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ...)
- node-body-parser 2.3.0+~1.19.6-1 (bug #1143074)
+ [trixie] - node-body-parser <no-dsa> (Minor issue)
NOTE: https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6
NOTE: https://github.com/expressjs/body-parser/pull/698
NOTE: Fixed by: https://github.com/expressjs/body-parser/commit/2322e111cc321413ec2b7b76d01be533d3de9d7d (v2.3.0)
=====================================
data/dsa-needed.txt
=====================================
@@ -62,7 +62,7 @@ jupyterlab
--
kamailio
--
-keystone
+keystone (jmm)
--
kitty
--
@@ -116,6 +116,8 @@ py7zr
python-authlib
possibly move trixie to 1.6.12
--
+python-django
+--
python-git
--
python-msgpack
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5002e9949dc4a577dfba6ba82c2cad62dc64c172
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5002e9949dc4a577dfba6ba82c2cad62dc64c172
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/37c52f4f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list