[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jan 26 08:13:08 GMT 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a42e761b by security tracker role at 2026-01-26T08:13:00+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,45 @@
+CVE-2026-1425 (A security flaw has been discovered in pymumu SmartDNS up to 47.1. Thi ...)
+ TODO: check
+CVE-2026-1424 (A vulnerability was identified in PHPGurukul News Portal 1.0. This aff ...)
+ TODO: check
+CVE-2026-1423 (A vulnerability was determined in code-projects Online Examination Sys ...)
+ TODO: check
+CVE-2026-1422 (A vulnerability was found in code-projects Online Examination System 1 ...)
+ TODO: check
+CVE-2026-1421 (A vulnerability has been found in code-projects Online Examination Sys ...)
+ TODO: check
+CVE-2026-1420 (A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unkno ...)
+ TODO: check
+CVE-2026-1419 (A weakness has been identified in D-Link DCS700l 1.03.09. Affected is ...)
+ TODO: check
+CVE-2026-1418 (A security vulnerability has been detected in GPAC up to 2.4.0. This a ...)
+ TODO: check
+CVE-2026-1417 (A weakness has been identified in GPAC up to 2.4.0. Affected by this i ...)
+ TODO: check
+CVE-2026-1416 (A security flaw has been discovered in GPAC up to 2.4.0. Affected by t ...)
+ TODO: check
+CVE-2026-1415 (A vulnerability was identified in GPAC up to 2.4.0. Affected is the fu ...)
+ TODO: check
+CVE-2026-1414 (A vulnerability was determined in Sangfor Operation and Maintenance Se ...)
+ TODO: check
+CVE-2026-1413 (A vulnerability was found in Sangfor Operation and Maintenance Securit ...)
+ TODO: check
+CVE-2026-1412 (A vulnerability has been found in Sangfor Operation and Maintenance Se ...)
+ TODO: check
+CVE-2026-1411 (A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The ...)
+ TODO: check
+CVE-2026-1410 (A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_ ...)
+ TODO: check
+CVE-2026-1409 (A security vulnerability has been detected in Beetel 777VR1 up to 01.0 ...)
+ TODO: check
+CVE-2026-1408 (A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.0 ...)
+ TODO: check
+CVE-2026-1407 (A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01 ...)
+ TODO: check
+CVE-2025-14973 (The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sa ...)
+ TODO: check
+CVE-2025-14316 (The AhaChat Messenger Marketing WordPress plugin through 1.1 does not ...)
+ TODO: check
CVE-2025-27821
- hadoop <itp> (bug #793644)
CVE-2026-24656
@@ -497,6 +539,7 @@ CVE-2026-1364 (IAQS and I6 developed by JNC has a Missing Authentication vulnera
CVE-2026-1363 (IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-S ...)
NOT-FOR-US: IAQS / I6
CVE-2026-1299 (The email module, specifically the "BytesGenerator" class, didn\u2019 ...)
+ {DLA-4455-1}
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
@@ -2289,6 +2332,7 @@ CVE-2026-1035 (A flaw was found in the Keycloak server during refresh token proc
CVE-2026-0933 (SummaryA command injection vulnerability (CWE-78) has been found to ex ...)
NOT-FOR-US: cloudflare workers-sdk
CVE-2026-0865 (User-controlled header names and values containing newlines can allow ...)
+ {DLA-4455-1}
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
@@ -2312,6 +2356,7 @@ CVE-2026-0865 (User-controlled header names and values containing newlines can a
NOTE: https://github.com/python/cpython/commit/e4846a93ac07a8ae9aa18203af0dd13d6e7a6995 (3.11-branch)
NOTE: https://github.com/python/cpython/commit/2f840249550e082dc351743f474ba56da10478d2 (3.10-branch)
CVE-2026-0672 (When using http.cookies.Morsel, user-controlled cookie values and para ...)
+ {DLA-4455-1}
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
@@ -2350,6 +2395,7 @@ CVE-2025-57155 (NULL pointer dereference in the daap_reply_groups function in sr
CVE-2025-15521 (The Academy LMS \u2013 WordPress LMS Plugin for Complete eLearning Sol ...)
NOT-FOR-US: WordPress plugin
CVE-2025-15367 (The poplib module, when passed a user-controlled command, can have add ...)
+ {DLA-4455-1}
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
@@ -2368,6 +2414,7 @@ CVE-2025-15367 (The poplib module, when passed a user-controlled command, can ha
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/
NOTE: https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7 (main)
CVE-2025-15366 (The imaplib module, when passed a user-controlled command, can have ad ...)
+ {DLA-4455-1}
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
@@ -2386,6 +2433,7 @@ CVE-2025-15366 (The imaplib module, when passed a user-controlled command, can h
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/
NOTE: https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45 (main)
CVE-2025-15282 (User-controlled data URLs parsed by urllib.request.DataHandler allow i ...)
+ {DLA-4455-1}
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
@@ -2406,6 +2454,7 @@ CVE-2025-15282 (User-controlled data URLs parsed by urllib.request.DataHandler a
CVE-2025-14559 (A flaw was found in the keycloak-services component of Keycloak. This ...)
- keycloak <itp> (bug #1088287)
CVE-2025-11468 (When folding a long comment in an email header containing exclusively ...)
+ {DLA-4455-1}
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
@@ -24361,7 +24410,7 @@ CVE-2025-12385 (Allocation of Resources Without Limits or Throttling, Improper V
CVE-2025-12358 (The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPres ...)
NOT-FOR-US: WordPress plugin
CVE-2025-12084 (When building nested elements using xml.dom.minidom methods such as ap ...)
- {DLA-4445-1}
+ {DLA-4455-1 DLA-4445-1}
- python3.14 3.14.2-1
- python3.13 3.13.11-1
[trixie] - python3.13 <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a42e761b249656162942b40410686e80ddbceab1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a42e761b249656162942b40410686e80ddbceab1
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260126/d4842ddd/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list