[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 31 18:53:25 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
66290f4f by Moritz Muehlenhoff at 2026-08-31T19:53:16+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -20,6 +20,7 @@ CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in pcre2_match() a
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5 pcre2-10.48-RC1)
CVE-2026-19873
- libhtml-formfu-perl <unfixed> (bug #1146310)
+ [trixie] - libhtml-formfu-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43141785/
NOTE: https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch
CVE-2026-82727 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
@@ -96,6 +97,7 @@ CVE-2026-82624 (A flaw has been found in code-projects Simple Inventory System 1
NOT-FOR-US: code-projects
CVE-2026-82623 (A vulnerability was detected in open62541 up to 1.5.5. Affected by thi ...)
- open62541 <unfixed>
+ [trixie] - open62541 <no-dsa> (Minor issue)
NOTE: https://github.com/open62541/open62541/issues/8199
CVE-2026-82622 (A security vulnerability has been detected in code-projects Employee L ...)
NOT-FOR-US: code-projects
@@ -13129,11 +13131,15 @@ CVE-2026-62441 (Vulnerability in the Oracle Hyperion Calculation Manager product
NOT-FOR-US: Oracle
CVE-2026-62377 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ...)
- libheif 1.23.1-1
+ [trixie] - libheif <no-dsa> (Minor issue)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-9ww4-9v47-m7pj
NOTE: https://github.com/strukturag/libheif/issues/1844
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3 (v1.23.1)
CVE-2026-62291 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ...)
- libheif 1.23.1-1
+ [trixie] - libheif <not-affected> (Vulnerable code not present, introduced in 1.20)
+ [bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.20)
+ [bullseye] - libheif <not-affected> (Vulnerable code not present, introduced in 1.20)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-xpw3-9rhw-482x
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/ac5521ad50399885de96bb6a0733a5d2442740f9 (v1.23.1)
CVE-2026-61342 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
@@ -83745,6 +83751,7 @@ CVE-2026-5241 (A vulnerability in the LightGlue model loading path of huggingfac
NOT-FOR-US: huggingface/transformers
CVE-2026-5078 (Impact: The morgan logging middleware's :remote-user token extracts th ...)
- node-morgan 1.12.0+~1.9.10-1
+ [trixie] - node-morgan <no-dsa> (Minor issue)
NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m
CVE-2026-4035 (A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for t ...)
NOT-FOR-US: mlflow
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66290f4f26ec88eb685b62de176574f31708b20a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66290f4f26ec88eb685b62de176574f31708b20a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/6a075d9e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list