[Git][security-tracker-team/security-tracker][master] trixie/bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Feb 16 10:49:19 GMT 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c37f60e0 by Moritz Muehlenhoff at 2026-02-16T11:49:00+01:00
trixie/bookworm triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -843,7 +843,11 @@ CVE-2023-45291
 	REJECTED
 CVE-2026-2443 (A flaw was identified in libsoup, a widely used HTTP library in GNOME- ...)
 	- libsoup3 3.6.6-1 (bug #1127905)
+	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <no-dsa> (Minor issue)
 	- libsoup2.4 <removed>
+	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+	[bookworm] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/487
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/508
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/b9964993a32b2fa734a6b5ba2d465c2c14e22de17 (3.6.6)
@@ -1868,7 +1872,10 @@ CVE-2025-69874 (nanotar through 0.2.0 has a path traversal vulnerability in pars
 	NOT-FOR-US: nanotar Node.js module
 CVE-2025-69873 (ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerab ...)
 	- node-ajv <unfixed> (bug #1128140)
+	[trixie] - node-ajv <no-dsa> (Minor issue)
+	[bookworm] - node-ajv <no-dsa> (Minor issue)
 	NOTE: https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md
+	NOTE: https://github.com/ajv-validator/ajv/issues/2581
 	NOTE: Fixed by: https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5 (v8.18.0)
 CVE-2025-69872 (DiskCache (python-diskcache) through 5.6.3 uses Python pickle for seri ...)
 	- diskcache <unfixed>


=====================================
data/dsa-needed.txt
=====================================
@@ -65,7 +65,7 @@ php8.2/oldstable (jmm)
 --
 php-laravel-framework/oldstable
 --
-pillow/stable
+pillow/stable (jmm)
 --
 python-aiohttp
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37f60e059b615f95c84c52cd89b044014dd9656

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37f60e059b615f95c84c52cd89b044014dd9656
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260216/518b21e3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list