[Git][security-tracker-team/security-tracker][master] Add new websocket-driver issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jul 18 13:22:39 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eff1a086 by Salvatore Bonaccorso at 2026-07-18T14:22:15+02:00
Add new websocket-driver issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -57,15 +57,25 @@ CVE-2026-54498 (view_component is a framework for building reusable, testable, a
CVE-2026-54497 (view_component is a framework for building reusable, testable, and enc ...)
NOT-FOR-US: view_component framework
CVE-2026-54490 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- TODO: check
+ - node-websocket-driver <unfixed>
+ NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-mp7j-qc5w-4988
+ NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/c55679a5b18251dd0a55d18a0cc6a4fd8822b92f (0.7.5)
CVE-2026-54466 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- TODO: check
+ - node-websocket-driver <unfixed>
+ NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6
+ NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680 (0.7.5)
CVE-2026-54465 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- TODO: check
+ - ruby-websocket-driver 0.8.1-1
+ NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-8j3g-f24p-4mpw
+ NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/17b569f232896e71d458404ccf4854f80e987710 (0.8.1)
CVE-2026-54464 (### Impact If this library is used in tandem with the `permessage-def ...)
- TODO: check
+ - ruby-websocket-driver 0.8.1-1
+ NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-33ph-fccm-39pj
+ NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/fa8641724f10bf3273585f1dcf9041f540bbd036 (0.8.1)
CVE-2026-54463 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- TODO: check
+ - ruby-websocket-driver 0.8.1-1
+ NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p
+ NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/d0141f041f6e3677a951255d547a313e732ccbe0 (0.8.1)
CVE-2026-54335 (Feathersjs is a framework for creating web APIs and real-time applicat ...)
NOT-FOR-US: Feathersjs
CVE-2026-54244 (Statamic is a Laravel and Git powered content management system (CMS). ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff1a08664d338ec86dcb09572dc8f342a9fd680
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff1a08664d338ec86dcb09572dc8f342a9fd680
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260718/263973f5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list