[Git][security-tracker-team/security-tracker][master] Add CVE-2026-13221/perl
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 13 21:40:16 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bf76aad8 by Salvatore Bonaccorso at 2026-07-13T22:39:52+02:00
Add CVE-2026-13221/perl
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -460,7 +460,11 @@ CVE-2026-14453 (This vulnerability is a critical Server-Side Template Injection
CVE-2026-14165 (An Authorization Bypass Through User-Controlled Key vulnerability affe ...)
NOT-FOR-US: Dassault Systemes
CVE-2026-13221 (Perl versions through 5.43.9 produce silently incorrect regular expres ...)
- TODO: check
+ - perl <unfixed>
+ NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780104/
+ NOTE: https://github.com/Perl/perl5/issues/23388
+ NOTE: Introduced with: https://github.com/Perl/perl5/commit/acababb42be12ff2986b73c1bfa963b70bb5d54e (v5.37.10)
+ NOTE: Fixed by: https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7 (v5.43.10)
CVE-2026-13014 (A vulnerability inThales CERT "Suspicious" application =< 1.3.4 allows ...)
TODO: check
CVE-2026-12257 (Versions of Mura CMS prior to 10.0.712 contain a critical remote code ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf76aad88d4a2bf615c3a03653608a72104886c3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf76aad88d4a2bf615c3a03653608a72104886c3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260713/e8db6923/attachment.htm>
More information about the debian-security-tracker-commits
mailing list