[Git][security-tracker-team/security-tracker][master] Add three new issues in hiawatha, itp'ed

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jan 26 20:54:34 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5bd9cd67 by Salvatore Bonaccorso at 2026-01-26T21:54:14+01:00
Add three new issues in hiawatha, itp'ed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -95,11 +95,11 @@ CVE-2025-59091 (Multiple hardcoded credentials have been identified, which are a
 CVE-2025-59090 (On the exos 9300 server, a SOAP API is reachable on port 8002. This AP ...)
 	NOT-FOR-US: dormakaba
 CVE-2025-57785 (A Double Free in XSLT `show_index` has been identified in Hiawatha web ...)
-	TODO: check
+	- hiawatha <itp> (bug #1094318)
 CVE-2025-57784 (Tomahawk auth timing attack due to usage of `strcmp` has been identifi ...)
-	TODO: check
+	- hiawatha <itp> (bug #1094318)
 CVE-2025-57783 (Improper header parsing may lead to request smuggling has been identif ...)
-	TODO: check
+	- hiawatha <itp> (bug #1094318)
 CVE-2025-50537 (Stack overflow vulnerability in eslint before 9.26.0 when serializing  ...)
 	TODO: check
 CVE-2025-41083 (Vulnerability in Altitude Authentication Service and Altitude Communic ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bd9cd673bca4eb5452eb8522fef6dafe6ac2413

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bd9cd673bca4eb5452eb8522fef6dafe6ac2413
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260126/3a24f874/attachment.htm>


More information about the debian-security-tracker-commits mailing list