[Git][security-tracker-team/security-tracker][master] new rustsec issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Jul 6 15:30:28 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0d61d978 by Moritz Muehlenhoff at 2026-07-06T16:30:05+02:00
new rustsec issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,26 @@
+CVE-2026-XXXX [RUSTSEC-2026-0195]
+	- rust-quick-xml <unfixed>
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0195.html
+	NOTE: https://github.com/tafia/quick-xml/issues/970
+	NOTE: https://github.com/tafia/quick-xml/commit/7ca25266e94987210daa864889ab15c9332c8a2a (v0.41.0)
+CVE-2026-XXXX [RUSTSEC-2026-0197]
+	- rust-cgmath <unfixed>
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0197.html
+	NOTE: https://github.com/rustgd/cgmath/issues/565
+CVE-2026-XXXX [RUSTSEC-2026-0199]
+	- rust-bcrypt <not-affected> (Only affects 19.x)
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0199.html
+CVE-2026-XXXX [RUSTSEC-2026-0202]
+	- rust-cxx <unfixed>
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0202.html
+	NOTE: https://github.com/dtolnay/cxx/issues/1729
+CVE-2026-XXXX [RUSTSEC-2026-0166]
+	- rust-stackvector <unfixed>
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0166.html
+	NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/3
+	NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/5
+	NOTE: https://github.com/Alexhuszagh/rust-stackvector/commit/02b947afdeeb1be95ec0888354aa76afdd9d0357
+	NOTE: https://github.com/Alexhuszagh/rust-stackvector/pull/6
 CVE-2026-59520 (Cross-Site Request Forgery (CSRF) vulnerability in properfraction Craw ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59519 (Insertion of Sensitive Information Into Sent Data vulnerability in Sof ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d61d978fa5be3885c0b3a3f302cac079367e835

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d61d978fa5be3885c0b3a3f302cac079367e835
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260706/2e9cf4d2/attachment.htm>


More information about the debian-security-tracker-commits mailing list