[Git][security-tracker-team/security-tracker][master] trixie/bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Feb 27 11:53:25 GMT 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1d2d2695 by Moritz Muehlenhoff at 2026-02-27T12:52:49+01:00
trixie/bookworm triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -295,9 +295,13 @@ CVE-2026-2244 (A vulnerability in Google Cloud Vertex AI Workbench from7/21/2025
 	NOT-FOR-US: Google Cloud Vertex AI Workbench
 CVE-2026-28296 (A flaw was found in the FTP GVfs backend. A remote attacker could expl ...)
 	- gvfs <unfixed>
+	[trixie] - gvfs <no-dsa> (Minor issue)
+	[bookworm] - gvfs <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/833
 CVE-2026-28295 (A flaw was found in the FTP GVfs backend. A malicious FTP server can e ...)
 	- gvfs <unfixed>
+	[trixie] - gvfs <no-dsa> (Minor issue)
+	[bookworm] - gvfs <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/832
 CVE-2026-28138 (Deserialization of Untrusted Data vulnerability in Stylemix uListing u ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -499,6 +503,8 @@ CVE-2026-27840 (ZITADEL is an open source identity management platform. Starting
 	NOT-FOR-US: Zitadel
 CVE-2026-27837 (Dottie provides nested object access and manipulation in JavaScript. V ...)
 	- node-dottie <unfixed> (bug #1129097)
+	[trixie] - node-dottie <no-dsa> (Minor issue)
+	[bookworm] - node-dottie <no-dsa> (Minor issue)
 	NOTE: https://github.com/mickhansen/dottie.js/security/advisories/GHSA-r5mx-6wc6-7h9w
 	NOTE: Fixed by: https://github.com/mickhansen/dottie.js/commit/7e8fa1345a4b46325f0eab8d7aeb1c4deaefdb14 (v2.0.7)
 	NOTE: CVE exists because of an incomplete fix for CVE-2023-26132.
@@ -1746,6 +1752,7 @@ CVE-2026-26981 (OpenEXR provides the specification and reference implementation
 	NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/d2be382758adc3e9ab83a3de35138ec28d93ebd8 (v3.3.7-rc)
 CVE-2026-26331 (yt-dlp is a command-line audio/video downloader. Starting in version 2 ...)
 	- yt-dlp 2026.02.21-1
+	[trixie] - yt-dlp <no-dsa> (Minor issue)
 	[bookworm] - yt-dlp <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-g3gw-q23r-pgqm
 	NOTE: Introduced with: https://github.com/yt-dlp/yt-dlp/commit/db3ad8a67661d7b234a6954d9c6a4a9b1749f5eb (2023.06.21)
@@ -15889,6 +15896,7 @@ CVE-2025-15282 (User-controlled data URLs parsed by urllib.request.DataHandler a
 	- python3.13 3.13.12-1 (bug #1126780)
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
+	[bookworm] - python3.11 <no-dsa> (Minor issue)
 	- python3.9 <removed>
 	- pypy3 <unfixed> (bug #1126781)
 	[trixie] - pypy3 <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d2d2695de43523e4c6a3c0d16cc3360f4b50b16

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d2d2695de43523e4c6a3c0d16cc3360f4b50b16
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260227/a1dac731/attachment.htm>


More information about the debian-security-tracker-commits mailing list