[Git][security-tracker-team/security-tracker][master] Add CVE-2026-1145/quickjs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jan 20 21:12:43 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9dc6a204 by Salvatore Bonaccorso at 2026-01-20T22:12:22+01:00
Add CVE-2026-1145/quickjs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -439,7 +439,10 @@ CVE-2026-1147 (A vulnerability was found in SourceCodester/Patrick Mvuma Patient
 CVE-2026-1146 (A vulnerability has been found in SourceCodester/Patrick Mvuma Patient ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-1145 (A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by  ...)
-	TODO: check
+	- quickjs <unfixed>
+	NOTE: https://github.com/quickjs-ng/quickjs/issues/1305
+	NOTE: https://github.com/quickjs-ng/quickjs/pull/1306
+	NOTE: https://github.com/paralin/quickjs/commit/53aebe66170d545bb6265906fe4324e4477de8b4
 CVE-2026-1007 (Incorrect Authorization vulnerability in virtual gateway component in  ...)
 	NOT-FOR-US: Devolutions
 CVE-2026-0610 (SQL Injection vulnerability in remote-sessions in Devolutions Server.T ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9dc6a204a4ca61095e40da0ff7114270b2e35df5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9dc6a204a4ca61095e40da0ff7114270b2e35df5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260120/d44e27e4/attachment.htm>


More information about the debian-security-tracker-commits mailing list