[Git][security-tracker-team/security-tracker][master] new rustsec issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Jul 6 15:30:28 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0d61d978 by Moritz Muehlenhoff at 2026-07-06T16:30:05+02:00
new rustsec issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,26 @@
+CVE-2026-XXXX [RUSTSEC-2026-0195]
+ - rust-quick-xml <unfixed>
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0195.html
+ NOTE: https://github.com/tafia/quick-xml/issues/970
+ NOTE: https://github.com/tafia/quick-xml/commit/7ca25266e94987210daa864889ab15c9332c8a2a (v0.41.0)
+CVE-2026-XXXX [RUSTSEC-2026-0197]
+ - rust-cgmath <unfixed>
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0197.html
+ NOTE: https://github.com/rustgd/cgmath/issues/565
+CVE-2026-XXXX [RUSTSEC-2026-0199]
+ - rust-bcrypt <not-affected> (Only affects 19.x)
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0199.html
+CVE-2026-XXXX [RUSTSEC-2026-0202]
+ - rust-cxx <unfixed>
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0202.html
+ NOTE: https://github.com/dtolnay/cxx/issues/1729
+CVE-2026-XXXX [RUSTSEC-2026-0166]
+ - rust-stackvector <unfixed>
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0166.html
+ NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/3
+ NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/5
+ NOTE: https://github.com/Alexhuszagh/rust-stackvector/commit/02b947afdeeb1be95ec0888354aa76afdd9d0357
+ NOTE: https://github.com/Alexhuszagh/rust-stackvector/pull/6
CVE-2026-59520 (Cross-Site Request Forgery (CSRF) vulnerability in properfraction Craw ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-59519 (Insertion of Sensitive Information Into Sent Data vulnerability in Sof ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d61d978fa5be3885c0b3a3f302cac079367e835
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d61d978fa5be3885c0b3a3f302cac079367e835
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260706/2e9cf4d2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list