[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jan 26 08:13:08 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a42e761b by security tracker role at 2026-01-26T08:13:00+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,45 @@
+CVE-2026-1425 (A security flaw has been discovered in pymumu SmartDNS up to 47.1. Thi ...)
+	TODO: check
+CVE-2026-1424 (A vulnerability was identified in PHPGurukul News Portal 1.0. This aff ...)
+	TODO: check
+CVE-2026-1423 (A vulnerability was determined in code-projects Online Examination Sys ...)
+	TODO: check
+CVE-2026-1422 (A vulnerability was found in code-projects Online Examination System 1 ...)
+	TODO: check
+CVE-2026-1421 (A vulnerability has been found in code-projects Online Examination Sys ...)
+	TODO: check
+CVE-2026-1420 (A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unkno ...)
+	TODO: check
+CVE-2026-1419 (A weakness has been identified in D-Link DCS700l 1.03.09. Affected is  ...)
+	TODO: check
+CVE-2026-1418 (A security vulnerability has been detected in GPAC up to 2.4.0. This a ...)
+	TODO: check
+CVE-2026-1417 (A weakness has been identified in GPAC up to 2.4.0. Affected by this i ...)
+	TODO: check
+CVE-2026-1416 (A security flaw has been discovered in GPAC up to 2.4.0. Affected by t ...)
+	TODO: check
+CVE-2026-1415 (A vulnerability was identified in GPAC up to 2.4.0. Affected is the fu ...)
+	TODO: check
+CVE-2026-1414 (A vulnerability was determined in Sangfor Operation and Maintenance Se ...)
+	TODO: check
+CVE-2026-1413 (A vulnerability was found in Sangfor Operation and Maintenance Securit ...)
+	TODO: check
+CVE-2026-1412 (A vulnerability has been found in Sangfor Operation and Maintenance Se ...)
+	TODO: check
+CVE-2026-1411 (A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The ...)
+	TODO: check
+CVE-2026-1410 (A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_ ...)
+	TODO: check
+CVE-2026-1409 (A security vulnerability has been detected in Beetel 777VR1 up to 01.0 ...)
+	TODO: check
+CVE-2026-1408 (A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.0 ...)
+	TODO: check
+CVE-2026-1407 (A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01 ...)
+	TODO: check
+CVE-2025-14973 (The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sa ...)
+	TODO: check
+CVE-2025-14316 (The AhaChat Messenger Marketing WordPress plugin through 1.1 does not  ...)
+	TODO: check
 CVE-2025-27821
 	- hadoop <itp> (bug #793644)
 CVE-2026-24656
@@ -497,6 +539,7 @@ CVE-2026-1364 (IAQS and I6 developed by JNC has a Missing Authentication vulnera
 CVE-2026-1363 (IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-S ...)
 	NOT-FOR-US: IAQS / I6
 CVE-2026-1299 (The  email module, specifically the "BytesGenerator" class, didn\u2019 ...)
+	{DLA-4455-1}
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
@@ -2289,6 +2332,7 @@ CVE-2026-1035 (A flaw was found in the Keycloak server during refresh token proc
 CVE-2026-0933 (SummaryA command injection vulnerability (CWE-78) has been found to ex ...)
 	NOT-FOR-US: cloudflare workers-sdk
 CVE-2026-0865 (User-controlled header names and values containing newlines can allow  ...)
+	{DLA-4455-1}
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
@@ -2312,6 +2356,7 @@ CVE-2026-0865 (User-controlled header names and values containing newlines can a
 	NOTE: https://github.com/python/cpython/commit/e4846a93ac07a8ae9aa18203af0dd13d6e7a6995 (3.11-branch)
 	NOTE: https://github.com/python/cpython/commit/2f840249550e082dc351743f474ba56da10478d2 (3.10-branch)
 CVE-2026-0672 (When using http.cookies.Morsel, user-controlled cookie values and para ...)
+	{DLA-4455-1}
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
@@ -2350,6 +2395,7 @@ CVE-2025-57155 (NULL pointer dereference in the daap_reply_groups function in sr
 CVE-2025-15521 (The Academy LMS \u2013 WordPress LMS Plugin for Complete eLearning Sol ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-15367 (The poplib module, when passed a user-controlled command, can have add ...)
+	{DLA-4455-1}
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
@@ -2368,6 +2414,7 @@ CVE-2025-15367 (The poplib module, when passed a user-controlled command, can ha
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/
 	NOTE: https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7 (main)
 CVE-2025-15366 (The imaplib module, when passed a user-controlled command, can have ad ...)
+	{DLA-4455-1}
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
@@ -2386,6 +2433,7 @@ CVE-2025-15366 (The imaplib module, when passed a user-controlled command, can h
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/
 	NOTE: https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45 (main)
 CVE-2025-15282 (User-controlled data URLs parsed by urllib.request.DataHandler allow i ...)
+	{DLA-4455-1}
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
@@ -2406,6 +2454,7 @@ CVE-2025-15282 (User-controlled data URLs parsed by urllib.request.DataHandler a
 CVE-2025-14559 (A flaw was found in the keycloak-services component of Keycloak. This  ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2025-11468 (When folding a long comment in an email header containing exclusively  ...)
+	{DLA-4455-1}
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
@@ -24361,7 +24410,7 @@ CVE-2025-12385 (Allocation of Resources Without Limits or Throttling, Improper V
 CVE-2025-12358 (The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPres ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-12084 (When building nested elements using xml.dom.minidom methods such as ap ...)
-	{DLA-4445-1}
+	{DLA-4455-1 DLA-4445-1}
 	- python3.14 3.14.2-1
 	- python3.13 3.13.11-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a42e761b249656162942b40410686e80ddbceab1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a42e761b249656162942b40410686e80ddbceab1
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260126/d4842ddd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list