[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 08:14:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e17c4c27 by security tracker role at 2026-08-31T07:13:52+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,277 @@
+CVE-2026-82727 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
+	TODO: check
+CVE-2026-82726 (Permissive Regular Expression vulnerability in ash-project ash_phoenix ...)
+	TODO: check
+CVE-2026-82725 (Authorization Bypass Through User-Controlled Key vulnerability in ash- ...)
+	TODO: check
+CVE-2026-82724 (Incorrect Authorization vulnerability in ash-project ash_phoenix invok ...)
+	TODO: check
+CVE-2026-82722 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
+	TODO: check
+CVE-2026-82681 (Improper Encoding or Escaping of Output vulnerability in ash-project a ...)
+	TODO: check
+CVE-2026-82673 (Improper Limitation of a Pathname to a Restricted Directory (Path Trav ...)
+	TODO: check
+CVE-2026-82658 (Admidio versions before 5.0.12 contain a broken access control vulnera ...)
+	TODO: check
+CVE-2026-82657 (Admidio before 5.0.12 fails to enforce login-only module restrictions  ...)
+	TODO: check
+CVE-2026-82656 (Admidio before 5.0.12 fails to sanitize album names in the photo ZIP d ...)
+	TODO: check
+CVE-2026-82655 (Admidio before 5.0.12 contains a blind SQL injection vulnerability in  ...)
+	TODO: check
+CVE-2026-82654 (SiYuan before v3.8.1 fails to properly escape block name, alias, and m ...)
+	TODO: check
+CVE-2026-82653 (SiYuan before v3.8.1 contains a stored cross-site scripting vulnerabil ...)
+	TODO: check
+CVE-2026-82652 (SiYuan before v3.8.1 fails to filter invisible-tier content from SQL e ...)
+	TODO: check
+CVE-2026-82651 (SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (intr ...)
+	TODO: check
+CVE-2026-82650 (SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulne ...)
+	TODO: check
+CVE-2026-82649 (SiYuan Windows installer before version 3.8.1 (affected versions >= 2. ...)
+	TODO: check
+CVE-2026-82648 (WWBN AVideo contains a server-side request forgery filter bypass vulne ...)
+	TODO: check
+CVE-2026-82647 (WWBN AVideo contains a cross-site request forgery vulnerability in sen ...)
+	TODO: check
+CVE-2026-82646 (WWBN AVideo contains an unauthenticated reflected cross-site scripting ...)
+	TODO: check
+CVE-2026-82645 (AVideo (current commit e01e41ecc and earlier) exposes stream credentia ...)
+	TODO: check
+CVE-2026-82644 (WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rat ...)
+	TODO: check
+CVE-2026-82643 (WWBN AVideo contains an unauthenticated credential submission vulnerab ...)
+	TODO: check
+CVE-2026-82642 (Readest is an open-source e-book reader built on Tauri. In versions pr ...)
+	TODO: check
+CVE-2026-82641 (keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP ...)
+	TODO: check
+CVE-2026-82640 (browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM A ...)
+	TODO: check
+CVE-2026-82639 (NextChat versions from 2.15.8 through 2.16.1 contain an improper URL v ...)
+	TODO: check
+CVE-2026-82638 (jina-ai reader disables its private-address guard outside Google Cloud ...)
+	TODO: check
+CVE-2026-82637 (browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate brows ...)
+	TODO: check
+CVE-2026-82636 (Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injecti ...)
+	TODO: check
+CVE-2026-82635 (Pake before 3.13.1 joins the JavaScript-supplied filename for the down ...)
+	TODO: check
+CVE-2026-82634 (Frappe Framework development builds contain an authorization flaw in t ...)
+	TODO: check
+CVE-2026-82633 (Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object auth ...)
+	TODO: check
+CVE-2026-82628 (A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulne ...)
+	TODO: check
+CVE-2026-82625 (A vulnerability has been found in code-projects Simple Inventory Syste ...)
+	TODO: check
+CVE-2026-82624 (A flaw has been found in code-projects Simple Inventory System 1.0. Af ...)
+	TODO: check
+CVE-2026-82623 (A vulnerability was detected in open62541 up to 1.5.5. Affected by thi ...)
+	TODO: check
+CVE-2026-82622 (A security vulnerability has been detected in code-projects Employee L ...)
+	TODO: check
+CVE-2026-82621 (A weakness has been identified in Soarkey StudentManagement and \u5b66 ...)
+	TODO: check
+CVE-2026-82620 (A security flaw has been discovered in Soarkey StudentManagement and \ ...)
+	TODO: check
+CVE-2026-82619 (A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impa ...)
+	TODO: check
+CVE-2026-82618 (A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affe ...)
+	TODO: check
+CVE-2026-82616 (A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. I ...)
+	TODO: check
+CVE-2026-82615 (A vulnerability has been found in itsourcecode Online Medicine Deliver ...)
+	TODO: check
+CVE-2026-82614 (A flaw has been found in itsourcecode Online Medicine Delivery System  ...)
+	TODO: check
+CVE-2026-82613 (A vulnerability was detected in itsourcecode Online Medicine Delivery  ...)
+	TODO: check
+CVE-2026-82612 (A security vulnerability has been detected in itsourcecode Online Medi ...)
+	TODO: check
+CVE-2026-82611 (A weakness has been identified in itsourcecode Online Medicine Deliver ...)
+	TODO: check
+CVE-2026-82610 (A security flaw has been discovered in itsourcecode Online Medicine De ...)
+	TODO: check
+CVE-2026-82609 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-82608 (A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This aff ...)
+	TODO: check
+CVE-2026-82607 (A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3 ...)
+	TODO: check
+CVE-2026-82605 (A vulnerability has been found in BareBones BBEdit up to 15.5.5. The a ...)
+	TODO: check
+CVE-2026-82604 (A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an ...)
+	TODO: check
+CVE-2026-82603 (A vulnerability was detected in SeaCMS up to 13.6. This issue affects  ...)
+	TODO: check
+CVE-2026-82602 (A security vulnerability has been detected in SeaCMS up to 13.6. This  ...)
+	TODO: check
+CVE-2026-82601 (A weakness has been identified in SeaCMS up to 13.6. This affects an u ...)
+	TODO: check
+CVE-2026-82600 (A security flaw has been discovered in SeaCMS up to 13.6. Affected by  ...)
+	TODO: check
+CVE-2026-82599 (A vulnerability was identified in SeaCMS up to 13.6. Affected by this  ...)
+	TODO: check
+CVE-2026-82598 (A vulnerability was determined in SeaCMS up to 13.6. Affected is the f ...)
+	TODO: check
+CVE-2026-82597 (A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B202307 ...)
+	TODO: check
+CVE-2026-82596 (A vulnerability was determined in LatencyUtils up to 2.0.3. Affected b ...)
+	TODO: check
+CVE-2026-82595 (A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this v ...)
+	TODO: check
+CVE-2026-82594 (A vulnerability has been found in LogNet grpc-spring-boot-starter up t ...)
+	TODO: check
+CVE-2026-82593 (A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the funct ...)
+	TODO: check
+CVE-2026-82592 (A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects th ...)
+	TODO: check
+CVE-2026-82591 (A security vulnerability has been detected in Open Asset Import Librar ...)
+	TODO: check
+CVE-2026-82590 (A weakness has been identified in Open5GS up to 2.7.7. The affected el ...)
+	TODO: check
+CVE-2026-82589 (A security flaw has been discovered in Open5GS up to 2.7.7. Impacted i ...)
+	TODO: check
+CVE-2026-82588 (A vulnerability was identified in Open5GS up to 2.7.7. This issue affe ...)
+	TODO: check
+CVE-2026-82587 (A vulnerability was determined in Open5GS up to 2.7.7. This vulnerabil ...)
+	TODO: check
+CVE-2026-82580 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
+	TODO: check
+CVE-2026-82579 (Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in  ...)
+	TODO: check
+CVE-2026-82564 (Authorization Bypass Through User-Controlled Key vulnerability in ash- ...)
+	TODO: check
+CVE-2026-82556 (A vulnerability was found in Forgejo up to 15.0.4. This issue affects  ...)
+	TODO: check
+CVE-2026-82555 (A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B2022050 ...)
+	TODO: check
+CVE-2026-82554 (A flaw has been found in SourceCodester Queue Management System 1.0. T ...)
+	TODO: check
+CVE-2026-82553 (A vulnerability was detected in sambitraj Student Management System up ...)
+	TODO: check
+CVE-2026-82552 (A security vulnerability has been detected in Linux Foundation Magma 1 ...)
+	TODO: check
+CVE-2026-82551 (A weakness has been identified in Linux Foundation Magma 1.9.0. Affect ...)
+	TODO: check
+CVE-2026-82550 (A security flaw has been discovered in Linux Foundation Magma 1.9.0. T ...)
+	TODO: check
+CVE-2026-82549 (A vulnerability was identified in Linux Foundation Magma 1.9.0. This a ...)
+	TODO: check
+CVE-2026-82548 (A vulnerability was determined in Linux Foundation Magma 1.9.0. The im ...)
+	TODO: check
+CVE-2026-82547 (A vulnerability was found in Linux Foundation Magma 1.9.0. The affecte ...)
+	TODO: check
+CVE-2026-82545 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-82544 (A flaw has been found in wger-project wger up to 2.6.0-alpha2. This is ...)
+	TODO: check
+CVE-2026-82543 (A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vul ...)
+	TODO: check
+CVE-2026-82542 (A weakness has been identified in Tenda HG10 300001138. Affected by th ...)
+	TODO: check
+CVE-2026-82541 (A security flaw has been discovered in itsourcecode Sales and Inventor ...)
+	TODO: check
+CVE-2026-82540 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-82539 (A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509 ...)
+	TODO: check
+CVE-2026-82488 (A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vuln ...)
+	TODO: check
+CVE-2026-82487 (A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affe ...)
+	TODO: check
+CVE-2026-82486 (A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this  ...)
+	TODO: check
+CVE-2026-82485 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-82484 (A flaw has been found in itsourcecode Sales and Inventory System 1.0.  ...)
+	TODO: check
+CVE-2026-82483 (A vulnerability was detected in coppermine-gallery Coppermine Photo Ga ...)
+	TODO: check
+CVE-2026-82367 (Exposure of Data Element to Wrong Session vulnerability in ash-project ...)
+	TODO: check
+CVE-2026-81853 (Authorization Bypass Through User-Controlled Key vulnerability in ash- ...)
+	TODO: check
+CVE-2026-81852 (Use of Insufficiently Random Values vulnerability in ash-project ash_a ...)
+	TODO: check
+CVE-2026-81643 (Incorrect Authorization vulnerability in ash-project ash_graphql deliv ...)
+	TODO: check
+CVE-2026-81636 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
+	TODO: check
+CVE-2026-81633 (Improper Input Validation vulnerability in ash-project ash_graphql all ...)
+	TODO: check
+CVE-2026-81322 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+	TODO: check
+CVE-2026-81319 (Deserialization of Untrusted Data vulnerability in ash-project ash_clo ...)
+	TODO: check
+CVE-2026-81318 (Incorrect Authorization vulnerability in ash-project ash_sql allows a  ...)
+	TODO: check
+CVE-2026-81316 (Incorrect Authorization vulnerability in ash-project ash_sql allows a  ...)
+	TODO: check
+CVE-2026-81315 (Origin Validation Error vulnerability in ash-project ash_ai allows a m ...)
+	TODO: check
+CVE-2026-80227 (Incorrect Comparison vulnerability in ash-project ash_sql allows a use ...)
+	TODO: check
+CVE-2026-80223 (Incorrect Authorization vulnerability in ash-project ash_graphql allow ...)
+	TODO: check
+CVE-2026-78699 (Unchecked Return Value vulnerability in ash-project ash_postgres allow ...)
+	TODO: check
+CVE-2026-78693 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
+	TODO: check
+CVE-2026-78691 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
+	TODO: check
+CVE-2026-78228 (Uncontrolled Recursion vulnerability in ash-project ash_oban allows a  ...)
+	TODO: check
+CVE-2026-78038 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
+	TODO: check
+CVE-2026-77956 (Improper Control of Generation of Code (Code Injection) vulnerability  ...)
+	TODO: check
+CVE-2026-77850 (Stored Cross-site Scripting vulnerability in ash-project ash_admin exe ...)
+	TODO: check
+CVE-2026-77454 (Incorrect Authorization vulnerability in ash-project ash_sql allows a  ...)
+	TODO: check
+CVE-2026-77013 (The \u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
+	TODO: check
+CVE-2026-75760 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
+	TODO: check
+CVE-2026-75757 (Reliance on Cookies without Validation and Integrity Checking vulnerab ...)
+	TODO: check
+CVE-2026-68951 (GROWI contains an incorrect authorization vulnerability. If this vulne ...)
+	TODO: check
+CVE-2026-64844
+	REJECTED
+CVE-2026-64843
+	REJECTED
+CVE-2026-64842
+	REJECTED
+CVE-2026-64841
+	REJECTED
+CVE-2026-64840
+	REJECTED
+CVE-2026-64839
+	REJECTED
+CVE-2026-58574 (Dell PowerStore contains a Missing Authentication for Critical Functio ...)
+	TODO: check
+CVE-2026-56718 (AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a pa ...)
+	TODO: check
+CVE-2026-56716
+	REJECTED
+CVE-2026-56715
+	REJECTED
+CVE-2026-56713
+	REJECTED
+CVE-2026-53620 (GROWI contains a vulnerability with an authorization bypass through us ...)
+	TODO: check
+CVE-2026-40465 (NSP is vulnerable to an open redirect due to insufficient server-side  ...)
+	TODO: check
+CVE-2026-40464 (NSP is vulnerable to a stored XSS due to insufficient validation or en ...)
+	TODO: check
+CVE-2026-40463 (WaveSuite is affected by an insufficient role-based access control vul ...)
+	TODO: check
 CVE-2026-18054
 	- qemu 1:11.1.0+ds-1
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba (v11.1.0-rc3)
@@ -26871,45 +27145,45 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in Apache Airflow's Yandex pr
 CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager backends i ...)
 	NOT-FOR-US: Apache Airflow provider
 CVE-2026-74998 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses f ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b (1.6.18)
 CVE-2026-75006 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficien ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223 (1.6.18)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9 (1.6.18)
 CVE-2026-75003 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b (1.6.18)
 CVE-2026-75007 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP se ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540 (1.6.18)
 CVE-2026-75004 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper ru ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e (1.6.18)
 CVE-2026-74997 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_lea ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd (1.6.18)
 	NOTE: Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a (release-1.6)
 CVE-2026-75002 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea (1.6.18)
 CVE-2026-75010 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c (1.6.18)
 CVE-2026-74999 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8 (1.6.18)
 CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HT ...)
-	{DLA-4760-1}
+	{DSA-6479-1 DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (1.6.18)
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
@@ -46954,7 +47228,7 @@ CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG ima
 	NOTE: https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
 	NOTE: https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419acbd0cbcc8340f41a383f35aae12 (2.2.0)
 CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of Service via de ...)
-	{DSA-6459-1}
+	{DSA-6459-1 DLA-4761-1}
 	- libnet-dns-perl 1.56-1 (bug #1142503)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/
 	NOTE: https://rt.cpan.org/Ticket/Display.html?id=179946
@@ -65067,17 +65341,17 @@ CVE-2026-77640 (tor before 0.4.9.9 was prone to an infinite loop when decompress
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41274
 CVE-2026-77584 (Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on ...)
-	{DSA-6372-1}
+	{DSA-6372-1 DLA-4656-1}
 	- tor 0.4.9.11-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41258 (private ATM)
 CVE-2026-77587 (Tor before 0.4.9.11 is prone to a use-after-free (and potential double ...)
-	{DSA-6372-1}
+	{DSA-6372-1 DLA-4656-1}
 	- tor 0.4.9.11-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41306
 CVE-2026-77638 (Tor before 0.4.9.11 is prone to a race condition where in just the rig ...)
-	{DSA-6372-1}
+	{DSA-6372-1 DLA-4656-1}
 	- tor 0.4.9.11-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41297
@@ -70980,14 +71254,14 @@ CVE-2026-54286 (Hono is a Web application framework that provides support for an
 CVE-2026-54285 (opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8. ...)
 	NOT-FOR-US: opentelemetry-js
 CVE-2026-54283 (Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1. ...)
-	{DLA-4711-1}
+	{DSA-6478-1 DLA-4711-1}
 	- starlette 1.3.1-1 (bug #1140631)
 	[bullseye] - starlette <ignored> (Minor issue; requires intrusive backport for CVE-2023-30798)
 	NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
 	NOTE: https://github.com/Kludex/starlette/pull/3329
 	NOTE: Fixed by: https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735 (1.3.1)
 CVE-2026-54282 (Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the ...)
-	{DLA-4711-1}
+	{DSA-6478-1 DLA-4711-1}
 	- starlette 1.3.1-1 (bug #1140632)
 	[bullseye] - starlette <ignored> (Minor issue)
 	NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3
@@ -72605,7 +72879,7 @@ CVE-2026-48821 (Shaarli is a personal bookmarking service. Versions 0.16.1 and p
 CVE-2026-48820 (CakePHP is a rapid development framework for PHP. In versions 4.5.11 a ...)
 	- cakephp <removed>
 CVE-2026-48817 (Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 a ...)
-	{DLA-4711-1}
+	{DSA-6478-1 DLA-4711-1}
 	- starlette 1.1.0-1
 	[bullseye] - starlette <ignored> (Minor issue)
 	NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e17c4c27f767d8dd0229a89931d7e3f5ecbba4a6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e17c4c27f767d8dd0229a89931d7e3f5ecbba4a6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/deb54925/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list