[Git][security-tracker-team/security-tracker][master] Add new set of vips issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 21:41:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1879c6d3 by Salvatore Bonaccorso at 2026-07-20T22:40:40+02:00
Add new set of vips issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -227,9 +227,15 @@ CVE-2026-39878 (Chamilo LMS versions 1.11.38 and earlier contain a stored cross-
 CVE-2026-39385 (Frappe LMS is an open source learning management system. In version 2. ...)
 	NOT-FOR-US: Frappe LMS
 CVE-2026-35591 (libvips is a fast image processing library with low memory needs. The  ...)
-	TODO: check
+	- vips 8.18.2-1
+	NOTE: https://github.com/libvips/libvips/security/advisories/GHSA-523x-vhfw-6r76
+	NOTE: https://github.com/libvips/libvips/pull/4973
+	NOTE: Fixed by: https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe (v8.18.2)
 CVE-2026-35590 (libvips is a fast image processing library with low memory needs. The  ...)
-	TODO: check
+	- vips 8.18.2-1
+	NOTE: https://github.com/libvips/libvips/security/advisories/GHSA-jmwm-wc68-mhwm
+	NOTE: https://github.com/libvips/libvips/pull/4972
+	NOTE: Fixed by: https://github.com/libvips/libvips/commit/91ebd4d35341a8353ea490392d556d582e4b846f (v8.18.2)
 CVE-2026-35217 (NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` h ...)
 	TODO: check
 CVE-2026-35198 (HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a ...)
@@ -239,9 +245,15 @@ CVE-2026-35048 (The Piwigo installer in versions 16.3.0 and earlier accepts POST
 CVE-2026-34239 (Chamilo version 1.11.40 and earlier are vulnerable to authenticated re ...)
 	TODO: check
 CVE-2026-33328 (libvips is a fast image processing library with low memory needs. On 3 ...)
-	TODO: check
+	- vips 8.18.1-1
+	NOTE: https://github.com/libvips/libvips/security/advisories/GHSA-r98w-4fp7-m9c7
+	NOTE: https://github.com/libvips/libvips/pull/4935
+	NOTE: Fixed by: https://github.com/libvips/libvips/commit/9b633e45abfcf1fc4c84847007c81805193c0969 (v8.18.1)
 CVE-2026-33327 (libvips is a fast image processing library with low memory needs. The  ...)
-	TODO: check
+	- vips 8.18.1-1
+	NOTE: https://github.com/libvips/libvips/security/advisories/GHSA-2fcj-gj27-279x
+	NOTE: https://github.com/libvips/libvips/pull/4934
+	NOTE: Fixed by; https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9 (v8.18.1)
 CVE-2026-32825 (dataCycle is a data management system for centrally storing, managing, ...)
 	TODO: check
 CVE-2026-32824 (dataCycle is a data management system for centrally storing, managing, ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1879c6d3874741a5b5836ba67d1f6735a8d0afce

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1879c6d3874741a5b5836ba67d1f6735a8d0afce
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/22c8bf38/attachment.htm>


More information about the debian-security-tracker-commits mailing list