[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 20 20:13:52 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3b28f1ec by security tracker role at 2026-07-20T19:13:46+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,40 +1,334 @@
-CVE-2026-64207 [net/sched: dualpi2: fix GSO backlog accounting]
+CVE-2026-8170 (The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) ...)
+ TODO: check
+CVE-2026-8169 (ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize acc ...)
+ TODO: check
+CVE-2026-6793 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-64623 (Network-AI before 5.13.4 contains an improper cryptographic signature ...)
+ TODO: check
+CVE-2026-64622 (Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to ap ...)
+ TODO: check
+CVE-2026-64621 (FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double- ...)
+ TODO: check
+CVE-2026-64620 (FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer ...)
+ TODO: check
+CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG image rea ...)
+ TODO: check
+CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of Service via de ...)
+ TODO: check
+CVE-2026-64193 (Net::DNS versions through 1.55 for Perl allow remote execution injecti ...)
+ TODO: check
+CVE-2026-63763 (SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused dep ...)
+ TODO: check
+CVE-2026-63762 (SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial o ...)
+ TODO: check
+CVE-2026-63761 (SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a ...)
+ TODO: check
+CVE-2026-63760 (SurrealDB before 3.1.0 fails to enforce the configured recursion depth ...)
+ TODO: check
+CVE-2026-63759 (SurrealDB before 3.1.0 fails to enforce recursion depth limits in the ...)
+ TODO: check
+CVE-2026-63758 (SurrealDB versions before 3.1.0 contain an authorization bypass vulner ...)
+ TODO: check
+CVE-2026-63757 (SurrealDB versions before 3.1.0 contain a session hijacking vulnerabil ...)
+ TODO: check
+CVE-2026-63756 (SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use ra ...)
+ TODO: check
+CVE-2026-63755 (SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT ...)
+ TODO: check
+CVE-2026-63754 (SurrealDB versions before 3.1.0 contain a denial of service vulnerabil ...)
+ TODO: check
+CVE-2026-63753 (SurrealDB before 3.1.0 fails to refresh authentication state in LIVE S ...)
+ TODO: check
+CVE-2026-63752 (SurrealDB before 3.1.0 contains an authorization bypass vulnerability ...)
+ TODO: check
+CVE-2026-63751 (SurrealDB versions before 3.1.0 contain a field-level permission bypas ...)
+ TODO: check
+CVE-2026-63750 (SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MA ...)
+ TODO: check
+CVE-2026-63749 (SurrealDB versions before 3.1.0 contain an authentication bypass vulne ...)
+ TODO: check
+CVE-2026-63748 (SurrealDB versions before 3.1.0 contain an information disclosure vuln ...)
+ TODO: check
+CVE-2026-63747 (SurrealDB versions before 3.1.0 contain a denial of service vulnerabil ...)
+ TODO: check
+CVE-2026-63746 (SurrealDB versions before 3.1.0 fail to enforce table SELECT permissio ...)
+ TODO: check
+CVE-2026-63745 (SurrealDB versions before 3.1.0 contain an authorization bypass vulner ...)
+ TODO: check
+CVE-2026-63744 (SurrealDB before 3.1.5 contains a server-side request forgery vulnerab ...)
+ TODO: check
+CVE-2026-63743 (SurrealDB before 3.1.0 contains a capability bypass vulnerability in H ...)
+ TODO: check
+CVE-2026-63742 (SurrealDB versions before 3.1.0 contain a field-level SELECT permissio ...)
+ TODO: check
+CVE-2026-63741 (SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or D ...)
+ TODO: check
+CVE-2026-63740 (SurrealDB versions before 3.1.4 fail to properly enforce SELECT permis ...)
+ TODO: check
+CVE-2026-63739 (SurrealDB before 3.1.5 contains an arbitrary file read vulnerability i ...)
+ TODO: check
+CVE-2026-63738 (SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELE ...)
+ TODO: check
+CVE-2026-63737 (SurrealDB versions before 3.1.5 contain a denial of service vulnerabil ...)
+ TODO: check
+CVE-2026-63736 (SurrealDB before 3.2.0 contains a server-side request forgery vulnerab ...)
+ TODO: check
+CVE-2026-63735 (SurrealDB versions before 3.2.0 fail to validate namespace and databas ...)
+ TODO: check
+CVE-2026-63734 (SurrealDB versions before 3.2.0 contain a denial of service vulnerabil ...)
+ TODO: check
+CVE-2026-63733 (SurrealDB versions before 3.2.0 contain a permissions bypass vulnerabi ...)
+ TODO: check
+CVE-2026-63429 (HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, ` ...)
+ TODO: check
+CVE-2026-63428 (HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, ` ...)
+ TODO: check
+CVE-2026-63108 (Roo Code through 3.54.0 contains a command injection vulnerability in ...)
+ TODO: check
+CVE-2026-63107 (LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request fo ...)
+ TODO: check
+CVE-2026-63102 (rConfig Core before 8.2.8 contains a privilege escalation vulnerabilit ...)
+ TODO: check
+CVE-2026-63071 (Improper Isolation or Compartmentalization vulnerability in Apache Syn ...)
+ TODO: check
+CVE-2026-62418 (Low-privileged authenticated Server-Side Request Forgery (SSRF) vulne ...)
+ TODO: check
+CVE-2026-62183 (Improper Privilege Management vulnerability in Apache Syncope. When: ...)
+ TODO: check
+CVE-2026-60034 (The Joomla extension JMedia is vulnerable to a stored XSS vulnerabilit ...)
+ TODO: check
+CVE-2026-60033 (The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Re ...)
+ TODO: check
+CVE-2026-60032 (The Joomla extension JMedia is vulnerable to an authenticated arbitrar ...)
+ TODO: check
+CVE-2026-60031 (The Joomla extension Quix Page Builder Pro is vulnerable to an informa ...)
+ TODO: check
+CVE-2026-60030 (The Joomla extension Quix Page Builder Pro is vulnerable to an imprope ...)
+ TODO: check
+CVE-2026-60029 (The Joomla extension Quix Page Builder Pro is vulnerable to an authent ...)
+ TODO: check
+CVE-2026-60028 (The Joomla extension Quix Page Builder Pro is vulnerable to an authent ...)
+ TODO: check
+CVE-2026-60027 (The Joomla extension Quix Page Builder Pro is vulnerable to a unauthen ...)
+ TODO: check
+CVE-2026-60026 (The Joomla extension Quix Page Builder Pro is vulnerable to an authent ...)
+ TODO: check
+CVE-2026-59238 (Stored Cross-site Scripting (CWE-79) in the client-side report renderi ...)
+ TODO: check
+CVE-2026-58484 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to ...)
+ TODO: check
+CVE-2026-58482 (Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipp ...)
+ TODO: check
+CVE-2026-58481 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to ...)
+ TODO: check
+CVE-2026-58414 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to ...)
+ TODO: check
+CVE-2026-58413 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to ...)
+ TODO: check
+CVE-2026-57311 (Windu CMS does not validate types of uploaded files. An authenticated ...)
+ TODO: check
+CVE-2026-57310 (Windu CMS uses hashing algorithm based on MD5 and SHA1 with static sal ...)
+ TODO: check
+CVE-2026-57309 (A Blind SQL injection vulnerability has been identified in Windu CMS. ...)
+ TODO: check
+CVE-2026-57308 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+ TODO: check
+CVE-2026-54910 (FileBrowser Quantum is a free, self-hosted, web-based file manager. Pr ...)
+ TODO: check
+CVE-2026-54685 (FileBrowser Quantum is a free, self-hosted, web-based file manager. Pr ...)
+ TODO: check
+CVE-2026-54051 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to ...)
+ TODO: check
+CVE-2026-53421 (Improper Isolation or Compartmentalization vulnerability in Apache Syn ...)
+ TODO: check
+CVE-2026-53405 (Improper Isolation or Compartmentalization vulnerability in Apache Syn ...)
+ TODO: check
+CVE-2026-52349 (Directory Traversal vulnerability in Menyoo 2.0 Versions before commit ...)
+ TODO: check
+CVE-2026-51386
+ REJECTED
+CVE-2026-51027 (An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sen ...)
+ TODO: check
+CVE-2026-51026 (Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remo ...)
+ TODO: check
+CVE-2026-50743 (A CSRF vulnerability exists in the `zone-include.php` script in Revive ...)
+ TODO: check
+CVE-2026-48824 (Mailpit is an email testing tool and API for developers. Prior to vers ...)
+ TODO: check
+CVE-2026-48812 (FreeScout is a free help desk and shared inbox built with PHP's Larave ...)
+ TODO: check
+CVE-2026-48389 (DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based ...)
+ TODO: check
+CVE-2026-47276 (In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in ...)
+ TODO: check
+CVE-2026-47275 (In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in ...)
+ TODO: check
+CVE-2026-46715 (Flask-Security-Too allows users to add security features to their Flas ...)
+ TODO: check
+CVE-2026-46701 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to ...)
+ TODO: check
+CVE-2026-46671 (Rust OneNote File Parser is a parser for Microsoft OneNote files imple ...)
+ TODO: check
+CVE-2026-46555 (WhatsApp MCP Server is a Model Context Protocol (MCP) server for Whats ...)
+ TODO: check
+CVE-2026-46516 (Frogman provides headless FreePBX control. Prior to version 1.6.6, Fro ...)
+ TODO: check
+CVE-2026-46428 (lettre is a a mailer library for Rust. Starting in version 0.10.1 and ...)
+ TODO: check
+CVE-2026-46415 (The Caddy Defender plugin is a middleware for Caddy that allows users ...)
+ TODO: check
+CVE-2026-46412 (@beproduct/nestjs-auth is a NestJS authentication module for BeProduct ...)
+ TODO: check
+CVE-2026-46410 (FileBrowser Quantum is a free, self-hosted, web-based file manager. Ve ...)
+ TODO: check
+CVE-2026-45797 (HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, t ...)
+ TODO: check
+CVE-2026-45713 (Mailpit is an email testing tool and API for developers. Prior to vers ...)
+ TODO: check
+CVE-2026-45712 (Mailpit is an email testing tool and API for developers. Prior to vers ...)
+ TODO: check
+CVE-2026-45711 (Mailpit is an email testing tool and API for developers. Prior to vers ...)
+ TODO: check
+CVE-2026-45709 (Mailpit is an email testing tool and API for developers. The fix for G ...)
+ TODO: check
+CVE-2026-45295 (FreeScout is a free help desk and shared inbox built with PHP's Larave ...)
+ TODO: check
+CVE-2026-45270 (CI4MS is a CodeIgniter 4-based content management system skeleton. Pri ...)
+ TODO: check
+CVE-2026-45139 (CI4MS is a CodeIgniter 4-based content management system skeleton. Pri ...)
+ TODO: check
+CVE-2026-44228 (RT is an open source, enterprise-grade issue and ticket tracking syste ...)
+ TODO: check
+CVE-2026-42210 (Webmin is a web-based system administration tool for Unix-like servers ...)
+ TODO: check
+CVE-2026-40187 (In egroupware version 26.0 and earlier, an authenticated administrator ...)
+ TODO: check
+CVE-2026-39879 (Due to a missing sanitization call in [`afsql_dd_run_query`](https://g ...)
+ TODO: check
+CVE-2026-39878 (Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site s ...)
+ TODO: check
+CVE-2026-39385 (Frappe LMS is an open source learning management system. In version 2. ...)
+ TODO: check
+CVE-2026-35591 (libvips is a fast image processing library with low memory needs. The ...)
+ TODO: check
+CVE-2026-35590 (libvips is a fast image processing library with low memory needs. The ...)
+ TODO: check
+CVE-2026-35217 (NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` h ...)
+ TODO: check
+CVE-2026-35198 (HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a ...)
+ TODO: check
+CVE-2026-35048 (The Piwigo installer in versions 16.3.0 and earlier accepts POST param ...)
+ TODO: check
+CVE-2026-34239 (Chamilo version 1.11.40 and earlier are vulnerable to authenticated re ...)
+ TODO: check
+CVE-2026-33328 (libvips is a fast image processing library with low memory needs. On 3 ...)
+ TODO: check
+CVE-2026-33327 (libvips is a fast image processing library with low memory needs. The ...)
+ TODO: check
+CVE-2026-32825 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32824 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32823 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32822 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32821 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32820 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32819 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32807 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-32806 (dataCycle is a data management system for centrally storing, managing, ...)
+ TODO: check
+CVE-2026-2445 (The affected product accepts user-supplied input within a URL paramete ...)
+ TODO: check
+CVE-2026-28220 (Wazuh is a free and open source platform used for threat prevention, d ...)
+ TODO: check
+CVE-2026-27823 (A vulnerability has been identified in EGroupware that may lead to Rem ...)
+ TODO: check
+CVE-2026-26483 (Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scrip ...)
+ TODO: check
+CVE-2026-26199 (HDF5 is a high-performance library and a file format specification tha ...)
+ TODO: check
+CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)
+ TODO: check
+CVE-2026-25039 (Parsec is a cloud-based application for simple and cryptographically s ...)
+ TODO: check
+CVE-2026-21824 (HCL Commerce contains an privilege escalation vulnerability that could ...)
+ TODO: check
+CVE-2026-16312
+ REJECTED
+CVE-2026-16277 (A stack-based buffer overflow was found in rpcbind's rpcinfo utility. ...)
+ TODO: check
+CVE-2026-16254 (A flaw was found in claircore's apk package scanner. Malformed package ...)
+ TODO: check
+CVE-2026-16252 (A security flaw has been discovered in Beijing Shenzhou Shihan Technol ...)
+ TODO: check
+CVE-2026-16248 (A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This ...)
+ TODO: check
+CVE-2026-16247 (In _connect.BRAIN versions prior to 5.06, the application LogPathConfi ...)
+ TODO: check
+CVE-2026-16246 (In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is ...)
+ TODO: check
+CVE-2026-16244 (A security vulnerability has been detected in itsourcecode Hospital Ma ...)
+ TODO: check
+CVE-2026-16242 (A flaw was found in the Konnectivity proxy-server configuration for ho ...)
+ TODO: check
+CVE-2026-15813 (A vulnerability was found in the network packet de-fragmentation engin ...)
+ TODO: check
+CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability exists withi ...)
+ TODO: check
+CVE-2026-14448 (An high privileged remote attacker can exploit an authenticated OS com ...)
+ TODO: check
+CVE-2026-13724 (Client-Side Enforcement of Server-Side Security vulnerability in Gobit ...)
+ TODO: check
+CVE-2026-12701 (A path traversal vulnerability was found in pulpcore. The relative_pat ...)
+ TODO: check
+CVE-2026-12341 (This vulnerability impacts all versions of IdentityIQ and allows an un ...)
+ TODO: check
+CVE-2026-12080 (A flaw was found in the QEMU Guest Agent (qga). A local unprivileged u ...)
+ TODO: check
+CVE-2026-64207 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.4-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/05ed733b65ab977dd931e7f7ac0f62fdb81205c2 (7.2-rc1)
-CVE-2026-64206 [Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock]
+CVE-2026-64206 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/2641a9e0a1dd4af2e21995470a21d55dd35e5203 (7.2-rc3)
-CVE-2026-64205 [i2c: i801: fix hardware state machine corruption in error path]
+CVE-2026-64205 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/10dd1a736d557e310a77117832874729a0175d57 (7.2-rc1)
-CVE-2026-64192 [bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized]
+CVE-2026-64192 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4 (7.2-rc2)
-CVE-2026-64191 [i2c: stub: Reject I2C block transfers with invalid length]
+CVE-2026-64191 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.0.14-1
[trixie] - linux 6.12.95-1
[bookworm] - linux 6.1.177-1
NOTE: https://git.kernel.org/linus/6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e (7.1-rc3)
-CVE-2026-64190 [net: team: fix NULL pointer dereference in team_xmit during mode change]
+CVE-2026-64190 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/25fe708bbc59289d3d1ea4b126fbc1b460a072a5 (7.1-rc6)
-CVE-2026-64189 [netfilter: ipset: fix race between dump and ip_set_list resize]
+CVE-2026-64189 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/7cd9103283b26b917360ec99d7d2f2d761bcf1ab (7.2-rc2)
-CVE-2026-64188 [net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()]
+CVE-2026-64188 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.0.14-1
[trixie] - linux 6.12.95-1
[bookworm] - linux 6.1.177-1
NOTE: https://git.kernel.org/linus/d00c953a8f69921f484b629801766da68f27f658 (7.1-rc5)
-CVE-2026-64187 [xfs: fail recovery on a committed log item with no regions]
+CVE-2026-64187 (In the Linux kernel, the following vulnerability has been resolved: x ...)
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
-CVE-2026-13577
+CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure session ids ...)
- libdancer2-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41975698/
CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy Terms Word ...)
@@ -6860,11 +7154,11 @@ CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial
- libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792358/
NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2 (2.1.3)
-CVE-2026-63090 [Authenticated SFTP sessions can overflow the SFTP packet buffer]
+CVE-2026-63090 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overf ...)
- proftpd-dfsg 1.3.9c~dfsg-1
NOTE: https://github.com/proftpd/proftpd/issues/2190
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/ce13286900a7e25f1e3403620496868d73292f6b (v1.3.9c)
-CVE-2026-63091 [SCP signed-size integer overflow; heap over-read]
+CVE-2026-63091 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow ...)
- proftpd-dfsg 1.3.9c~dfsg-1
NOTE: https://github.com/proftpd/proftpd/pull/2201
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/baf4b7929758c72cdb6cf16325fa25f435d23db6 (v1.3.9c)
@@ -10545,45 +10839,45 @@ CVE-2026-42505 (Handshakes which used Encrypted Client Hello could be de-anonymi
NOTE: https://github.com/golang/go/issues/79282
NOTE: Fixed by: https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 (go1.26.5)
NOTE: Fixed by: https://github.com/golang/go/commit/fc9f821bb660c1dcb9e57868b62f62bf3afb5842 (go1.25.12)
-CVE-2026-41252
+CVE-2026-41252 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j
-CVE-2026-41521
+CVE-2026-41521 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-v8w6-pf78-9458
-CVE-2026-44178
+CVE-2026-44178 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hh7r-2rmq-q4g4
-CVE-2026-42218
+CVE-2026-42218 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3wr5-fwmh-qh34
-CVE-2026-44978
+CVE-2026-44978 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9cg5-f7m7-ppvj
-CVE-2026-54538
+CVE-2026-54538 (xrdp is an open source RDP server. In versions 0.10.6 and prior, a n i ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9j3q-9mvw-qv7j
-CVE-2026-55238
+CVE-2026-55238 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-mg8j-x9rw-9xv3
-CVE-2026-55626
+CVE-2026-55626 (xrdp is an open source RDP server. In versions 0.10.6 and prior, when ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
[trixie] - xrdp <not-affected> (Vulnerable code introduced later)
[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r
-CVE-2026-55639
+CVE-2026-55639 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-6g36-mxcf-r3gc
-CVE-2026-55645
+CVE-2026-55645 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3m4m-h22g-c7xx
@@ -16595,7 +16889,7 @@ CVE-2026-57958 (Mixpost through 2.6.0 contains a reflected cross-site scripting
NOT-FOR-US: Mixpost
CVE-2026-57957 (Papermark through 0.22.0 contains a cross-origin resource sharing (COR ...)
NOT-FOR-US: Papermark
-CVE-2026-57956 (SigNoz through 0.130.1 contains a broken access control vulnerability ...)
+CVE-2026-57956 (SigNoz before 0.133.0 contains a broken access control vulnerability t ...)
NOT-FOR-US: SigNoz
CVE-2026-57955 (SigNoz through 0.130.1 contains a SQL injection vulnerability that all ...)
NOT-FOR-US: SigNoz
@@ -27358,7 +27652,7 @@ CVE-2026-23970 (Unauthenticated Cross Site Scripting (XSS) in Redirection for Co
NOT-FOR-US: WordPress plugin or theme
CVE-2026-12162 (Improper host validation in the social login autofill feature in Devo ...)
NOT-FOR-US: Devolutions
-CVE-2026-12161 (Improper input validation in the SSH Elevate Shell feature in Devolut ...)
+CVE-2026-12161 (Improper input validation in the SSH Elevate Shell feature allows an a ...)
NOT-FOR-US: Devolutions
CVE-2026-11931 (Incorrect default permissions in Kiro IDE on macOS and Linux before ve ...)
NOT-FOR-US: Amazon
@@ -45508,7 +45802,7 @@ CVE-2026-44230
NOTE: https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
NOTE: Introduced with: https://github.com/bestpractical/rt/commit/1db06229c5839a158f2365c436d9aa325d6ea459 (rt-5.0.4beta1)
NOTE: Fixed by: https://github.com/bestpractical/rt/commit/510d8d6c6a260da22830039e362c990a6c029665 (rt-5.0.10)
-CVE-2026-44227
+CVE-2026-44227 (RT is an open source, enterprise-grade issue and ticket tracking syste ...)
- request-tracker5 <not-affected> (Only affects RT6)
- request-tracker4 <not-affected> (Only affects RT6)
NOTE: https://github.com/bestpractical/rt/releases/tag/rt-6.0.3
@@ -98899,14 +99193,14 @@ CVE-2026-2003 (Improper validation of type "oidvector" in PostgreSQL allows a da
- postgresql-13 <removed>
NOTE: https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/
NOTE: Fixed by: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=3b6588cd902faa967f61f539f057f9b7643cf6a5 (REL_18_2)
-CVE-2026-26081 [BUG/MAJOR: quic: reject invalid token]
+CVE-2026-26081 (HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length ...)
{DSA-6130-1}
- haproxy 3.2.11-2
[bookworm] - haproxy <not-affected> (Vulnerable code introduced later)
[bullseye] - haproxy <not-affected> (Vulnerable code introduced later)
NOTE: Fixed by: https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=a05eade0f07483e6b6d0b61b1749e9093647e802 (v3.0.16)
NOTE: Fixed by: https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=4765277f4f915baac2d57db63538ff0a59966deb (v3.2.12)
-CVE-2026-26080 [BUG/MAJOR: quic: fix parsing frame type]
+CVE-2026-26080 (HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a ...)
- haproxy 3.2.11-2
[trixie] - haproxy <not-affected> (Vulnerable code introduced later)
[bookworm] - haproxy <not-affected> (Vulnerable code introduced later)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b28f1ec9095c3821bed06e932afa003e22f6719
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b28f1ec9095c3821bed06e932afa003e22f6719
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/69a311b3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list