[Git][security-tracker-team/security-tracker][master] 16 commits: lts: aardvark-dns not-affected in bookworm
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Tue Jul 21 22:53:19 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
237c5de5 by Utkarsh Gupta at 2026-07-22T03:22:23+05:30
lts: aardvark-dns not-affected in bookworm
(CVE-2026-35406, TCP serving absent in 1.4.0)
- - - - -
2601f637 by Utkarsh Gupta at 2026-07-22T03:22:24+05:30
lts: busybox postponed in bookworm
(ash/awk memory-safety, CVE-2026-38752 to CVE-2026-38755)
- - - - -
7ddb1f8b by Utkarsh Gupta at 2026-07-22T03:22:25+05:30
lts: c3p0 postponed in bookworm (CVE-2026-27830)
- - - - -
800dc08b by Utkarsh Gupta at 2026-07-22T03:22:26+05:30
dla-needed: extend calibre to bookworm (CVE-2026-53511)
- - - - -
83b14a14 by Utkarsh Gupta at 2026-07-22T03:22:27+05:30
lts: capnproto postponed in bookworm
(CVE-2026-32239, CVE-2026-32240)
- - - - -
e645a6f8 by Utkarsh Gupta at 2026-07-22T03:22:28+05:30
lts: coturn postponed in bookworm
(CVE-2026-27624/40613/43915/43994)
- - - - -
1f8bf381 by Utkarsh Gupta at 2026-07-22T03:22:30+05:30
lts: geary postponed in bookworm/bullseye (CVE-2026-13324)
- - - - -
810bd2b0 by Utkarsh Gupta at 2026-07-22T03:22:31+05:30
lts: triage glances in bookworm
(CVE-2026-46606/46607/46608/46611/53925)
- - - - -
4b7ae7d2 by Utkarsh Gupta at 2026-07-22T03:22:33+05:30
lts: guzzle postponed in bookworm (CVE-2026-55568/55767/59883)
- - - - -
0b745686 by Utkarsh Gupta at 2026-07-22T03:22:34+05:30
lts: hdrhistogram postponed in bookworm/bullseye
(CVE-2026-14683 to CVE-2026-14686)
- - - - -
56e22bc1 by Utkarsh Gupta at 2026-07-22T03:22:36+05:30
lts: httpcomponents-core5 postponed in bookworm
(CVE-2026-54399, CVE-2026-54428)
- - - - -
bee598be by Utkarsh Gupta at 2026-07-22T03:22:37+05:30
lts: triage hugo in bookworm/bullseye
(CVE-2026-50133 to CVE-2026-58404)
- - - - -
dde4df23 by Utkarsh Gupta at 2026-07-22T03:22:39+05:30
lts: inspircd postponed in bookworm/bullseye
- - - - -
e3b93549 by Utkarsh Gupta at 2026-07-22T03:22:40+05:30
lts: jansi1 not-affected in bookworm (CVE-2026-8484, no native code)
- - - - -
996b1ede by Utkarsh Gupta at 2026-07-22T03:22:42+05:30
lts: jupyter-server postponed in bookworm/bullseye
- - - - -
4ed36ba8 by Utkarsh Gupta at 2026-07-22T03:22:43+05:30
dla-needed: extend busybox to bookworm; drop postponed tags
busybox is sponsored across all suites and already queued for bullseye
(dla-needed) and buster+stretch (ela-needed). CVE-2026-38752..38755 are
in shared ash/awk code, so fix bookworm alongside the others rather than
postponing the newest LTS release. Per-CVE bookworm postponed tags are
redundant once bookworm is queued, so drop them.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -10883,6 +10883,7 @@ CVE-2026-59887 (linkify-it is a links recognition library with full Unicode supp
CVE-2026-59883 (Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar di ...)
- guzzle 7.12.3-1
[trixie] - guzzle <no-dsa> (Minor issue)
+ [bookworm] - guzzle <postponed> (Minor issue; SetCookie::matchesDomain IP-domain suffix match)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-g446-98w2-8p5w
NOTE: https://github.com/guzzle/guzzle/pull/3694
NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/b9944c161b12d9ee9c9334cfc5b9659ecd7451f8 (7.12.3)
@@ -11859,6 +11860,8 @@ CVE-2026-48588 (An issue was discovered in Django 6.0 before 6.0.7 and 5.2 befor
CVE-2026-XXXX [InspIRCd Security Advisory 2026-01]
- inspircd <unfixed> (bug #1141625)
[trixie] - inspircd <no-dsa> (Minor issue)
+ [bookworm] - inspircd <postponed> (Minor issue; only exploitable with non-default ldapauth/ldapoper module loaded and LDAP configured)
+ [bullseye] - inspircd <postponed> (Minor issue; only exploitable with non-default ldapauth/ldapoper module loaded and LDAP configured)
NOTE: https://docs.inspircd.org/security/2026-01/
NOTE: https://github.com/inspircd/inspircd/commit/b7e5357b144c2e20c72431e22f0f2b13e5be82ce (v4.11.0)
NOTE: https://github.com/inspircd/inspircd/commit/6319ae4fb8c10dabc9464ad49faec532096fbcb5 (v4.11.0)
@@ -11887,18 +11890,24 @@ CVE-2026-59710 (showdown contains a stored cross-site scripting vulnerability in
CVE-2026-58404 (Hugo is a static site generator. From v0.162.0 through v0.163.0, the d ...)
- hugo <unfixed> (bug #1141772)
[trixie] - hugo <no-dsa> (Minor issue)
+ [bookworm] - hugo <not-affected> (Alt-IPv4-encoding bypass of security.http.urls added in v0.162.0)
+ [bullseye] - hugo <not-affected> (Alt-IPv4-encoding bypass of security.http.urls added in v0.162.0)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-r46f-3rpw-hxrv
NOTE: https://github.com/gohugoio/hugo/pull/15020
NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/a00b5c72ac57afe26df6688ece3ca544a56df372 (v0.163.1)
CVE-2026-58403 (Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo' ...)
- hugo <unfixed> (bug #1141772)
[trixie] - hugo <no-dsa> (Minor issue)
+ [bookworm] - hugo <not-affected> (RootMappingFs.statRoot symlink regression introduced in v0.123.0)
+ [bullseye] - hugo <not-affected> (RootMappingFs.statRoot symlink regression introduced in v0.123.0)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-c3wq-j5vh-68rc
NOTE: https://github.com/gohugoio/hugo/pull/15020
NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/cf9c8f93ca2a2838ce378f9e36d052ac2f79e229 (v0.163.1)
CVE-2026-58402 (Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's def ...)
- hugo <unfixed> (bug #1141772)
[trixie] - hugo <no-dsa> (Minor issue)
+ [bookworm] - hugo <postponed> (Minor issue; code-fence info-string XSS, only exploitable without control of content; mirrors trixie)
+ [bullseye] - hugo <postponed> (Minor issue; code-fence info-string XSS, only exploitable without control of content; mirrors trixie)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-q76j-gcg9-vxc6
NOTE: https://github.com/gohugoio/hugo/pull/15051
NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/ce1a7e0bce3713af40496ded3c2c0ceeed49231d (v0.163.3)
@@ -11965,16 +11974,22 @@ CVE-2026-53640 (FOSSBilling is a free, open-source billing and client management
CVE-2026-50135 (Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression ...)
- hugo 0.162.1-1
[trixie] - hugo <no-dsa> (Minor issue)
+ [bookworm] - hugo <not-affected> (resources.Get symlink-following regression in RootMappingFs.statRoot introduced in v0.123.0)
+ [bullseye] - hugo <not-affected> (resources.Get symlink-following regression in RootMappingFs.statRoot introduced in v0.123.0)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpw
NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7a (v0.162.0)
CVE-2026-50134 (Hugo is a static site generator. From 0.91.0 until 0.162.0, resources. ...)
- hugo 0.162.1-1
[trixie] - hugo <no-dsa> (Minor issue)
+ [bookworm] - hugo <postponed> (Minor issue; redirect targets not re-validated against security.http.urls; mirrors trixie)
+ [bullseye] - hugo <not-affected> (security.http.urls policy introduced in v0.91.0; config/security package absent in 0.80.0)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8g
NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50 (v0.162.0)
CVE-2026-50133 (Hugo is a static site generator. Prior to 0.162.0, Hugo accepts conten ...)
- hugo 0.162.1-1
[trixie] - hugo <no-dsa> (Minor issue)
+ [bookworm] - hugo <postponed> (Minor issue; unsanitized text/html content files, fixed by security.allowContent default-deny in v0.162.0; mirrors trixie)
+ [bullseye] - hugo <postponed> (Minor issue; unsanitized text/html content files, fixed by security.allowContent default-deny in v0.162.0; mirrors trixie)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-c54g-xjwj-8g82
NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1 (v0.162.0)
CVE-2026-4375 (The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPres ...)
@@ -12759,18 +12774,26 @@ CVE-2026-14687 (A vulnerability was determined in 666ghj BettaFish up to 1.2.1.
CVE-2026-14686 (A vulnerability was found in HdrHistogram up to 2.2.2. This issue affe ...)
- hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
+ [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/222
CVE-2026-14685 (A vulnerability has been found in HdrHistogram up to 2.2.2. This vulne ...)
- hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
+ [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/221
CVE-2026-14684 (A flaw has been found in HdrHistogram up to 2.2.2. This affects the fu ...)
- hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
+ [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/220
CVE-2026-14683 (A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by ...)
- hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
+ [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input DoS/integrity; unfixed upstream, revisit when fixed)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/219
CVE-2026-14660 (A vulnerability was found in code-projects Online Job Portal 1.0. The ...)
NOT-FOR-US: code-projects
@@ -14507,6 +14530,7 @@ CVE-2026-55510 (ImageMagick is free and open-source software used for editing an
CVE-2026-54428 (Allocation of resources without limits or throttling in the HTTP/2 HPA ...)
- httpcomponents-core5 <unfixed> (bug #1141387)
[trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
+ [bookworm] - httpcomponents-core5 <postponed> (Minor issue; HTTP/2 HPACK decoder present in 5.x, unlike 4.x)
- httpcomponents-core <unfixed>
[trixie] - httpcomponents-core <no-dsa> (Minor issue)
[bookworm] - httpcomponents-core <not-affected> (HTTP/2 HPACK not implemented in httpcomponents-core 4.x (v5-only feature))
@@ -14516,6 +14540,7 @@ CVE-2026-54428 (Allocation of resources without limits or throttling in the HTTP
CVE-2026-54399 (Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 messag ...)
- httpcomponents-core5 <unfixed> (bug #1141387)
[trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
+ [bookworm] - httpcomponents-core5 <postponed> (Minor issue)
- httpcomponents-core <unfixed>
[trixie] - httpcomponents-core <no-dsa> (Minor issue)
[bookworm] - httpcomponents-core <postponed> (Minor issue)
@@ -19360,6 +19385,8 @@ CVE-2026-11625 (Bytes::Random::Secure versions through 0.29 for Perl share inter
CVE-2026-13324
- geary <unfixed>
[trixie] - geary <no-dsa> (Minor issue)
+ [bookworm] - geary <postponed> (Minor issue; mailto ?attach= silently attaches local files, follow trixie)
+ [bullseye] - geary <postponed> (Minor issue; mailto ?attach= silently attaches local files, follow trixie)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2492860
CVE-2026-9222 (Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 a ...)
NOT-FOR-US: Setracker2 Android Companion App com.tgelec.setracker
@@ -20083,6 +20110,7 @@ CVE-2026-54024 (LibreChat is an enhanced ChatGPT clone that supports multiple AI
CVE-2026-53925 (Glances is an open-source system cross-platform monitoring tool. From ...)
- glances 4.5.5+dfsg-1
[trixie] - glances <no-dsa> (Minor issue)
+ [bookworm] - glances <postponed> (Minor issue; secure_popen operator interpretation present in secure.py, reachable via actions.py; requires config write access)
NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-3vwc-qwhc-3mj7
CVE-2026-50573 (pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` ...)
- pnpm <itp> (bug #985669)
@@ -20157,18 +20185,22 @@ CVE-2026-46732 (Dell Display and Peripheral Manager (DDPM Mac), versions prior t
CVE-2026-46611 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- glances 4.5.5+dfsg-1
[trixie] - glances <no-dsa> (Minor issue)
+ [bookworm] - glances <postponed> (Minor issue; XML-RPC GlancesXMLRPCHandler lacks Host-header validation, DNS-rebinding defense-in-depth)
NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-w856-8p3r-p338
CVE-2026-46608 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- glances 4.5.5+dfsg-1
[trixie] - glances <no-dsa> (Minor issue)
+ [bookworm] - glances <not-affected> (XML-RPC cors_origins allowlist mechanism introduced in 4.5.3; absent in 3.3.1.1)
NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-87qc-fj39-wccr
CVE-2026-46607 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- glances 4.5.5+dfsg-1
[trixie] - glances <no-dsa> (Minor issue)
+ [bookworm] - glances <postponed> (Minor issue; outdated.py _load_cache pickle.load of cached glances-version.db present; requires local cache write)
NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-9837-48hr-q32j
CVE-2026-46606 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- glances 4.5.5+dfsg-1
[trixie] - glances <no-dsa> (Minor issue)
+ [bookworm] - glances <not-affected> (KVM/virsh vms monitoring plugin is a 4.x feature; no vms/virsh plugin in 3.3.1.1)
NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-v5r2-qh84-fjx5
CVE-2026-45233 (HTMLy CMS through 3.1.1 contains a path traversal vulnerability that a ...)
NOT-FOR-US: HTMLy CMS
@@ -24041,6 +24073,8 @@ CVE-2026-44889 (WebOb provides objects for HTTP requests and responses. Prior to
CVE-2026-44727 (Jupyter Server is the backend for Jupyter web applications. Prior to 2 ...)
- jupyter-server 2.20.0-1
[trixie] - jupyter-server <no-dsa> (Minor issue)
+ [bookworm] - jupyter-server <postponed> (Minor issue; stored XSS in nbconvert handlers, present, revisit with next update)
+ [bullseye] - jupyter-server <postponed> (Minor issue; stored XSS in nbconvert handlers, present, revisit with next update)
NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp
NOTE: Fixed by: https://github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bd (v2.20.0)
CVE-2026-44311 (Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a pote ...)
@@ -25167,10 +25201,12 @@ CVE-2016-20085 (Realtek High Definition Audio Driver 6.0.1.6730 contains an unqu
CVE-2026-55568 (Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain c ...)
- guzzle 7.12.1-1
[trixie] - guzzle <no-dsa> (Minor issue)
+ [bookworm] - guzzle <postponed> (Minor issue; curl handler HTTPS-proxy downgrade, needs libcurl older than 7.50.2)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-wpwq-4j6v-78m3
CVE-2026-55767 (Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar in ...)
- guzzle 7.12.1-1
[trixie] - guzzle <no-dsa> (Minor issue)
+ [bookworm] - guzzle <postponed> (Minor issue; SetCookie dot-only Domain matches any host)
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-cwxw-98qj-8qjx
CVE-2026-52910 (In the Linux kernel, the following vulnerability has been resolved: b ...)
{DSA-6355-1 DLA-4671-1 DLA-4665-1 DLA-4664-1}
@@ -25317,11 +25353,13 @@ CVE-2026-44663 (OpenEXR is the reference implementation and specification for th
CVE-2026-43994 (Coturn is a free open source implementation of TURN and STUN Server. V ...)
- coturn 4.12.0-1 (bug #1140563)
[trixie] - coturn <no-dsa> (Minor issue)
+ [bookworm] - coturn <postponed> (Minor issue; decode_oauth_token_gcm() OAuth nonce stack overflow present in 4.6.1, only reachable with non-default --oauth)
NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-74pg-rfh2-5qw5
NOTE: Fixed by: https://github.com/coturn/coturn/commit/46368b3e1ecda2175f8db8b05ece8bbdbf844cea (4.10.0)
CVE-2026-43915 (Coturn is a free open source implementation of TURN and STUN Server. V ...)
- coturn 4.12.0-1
[trixie] - coturn <no-dsa> (Minor issue)
+ [bookworm] - coturn <postponed> (Minor issue; web-admin stored XSS, is_secure_string()/raw username rendering present in 4.6.1)
NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-xxf5-9vj2-g84j
CVE-2026-40624 (Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115 ...)
NOT-FOR-US: AVer
@@ -27438,6 +27476,7 @@ CVE-2026-8484 (A heap buffer overflow vulnerability exists in the Jansi JNI "ioc
[bullseye] - jansi <not-affected> (jansi 1.x ships no native code; the vulnerable JNI ioctl is in jansi-native)
- jansi1 <unfixed>
[trixie] - jansi1 <no-dsa> (Minor issue)
+ [bookworm] - jansi1 <not-affected> (jansi1 1.18 ships no native code; the vulnerable JNI ioctl is in jansi-native)
- jansi-native <unfixed>
[trixie] - jansi-native <no-dsa> (Minor issue)
[bookworm] - jansi-native <postponed> (Minor issue)
@@ -36291,6 +36330,8 @@ CVE-2026-7888 (Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection vi
CVE-2026-6657 (A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allow ...)
- jupyter-server <unfixed>
[trixie] - jupyter-server <no-dsa> (Minor issue)
+ [bookworm] - jupyter-server <postponed> (Minor issue; unanchored allow_origin_pat re.match present, revisit with next update)
+ [bullseye] - jupyter-server <postponed> (Minor issue; unanchored allow_origin_pat re.match present, revisit with next update)
NOTE: https://huntr.com/bounties/18f642db-3569-43b3-b58d-ff97be4b09d7
CVE-2026-5241 (A vulnerability in the LightGlue model loading path of huggingface/tra ...)
NOT-FOR-US: huggingface/transformers
@@ -37068,6 +37109,8 @@ CVE-2026-7195 (CWE-20: Improper Input Validation in web services in Progress Sit
CVE-2026-5422 (A path traversal vulnerability exists in jupyter-server version 2.17.0 ...)
- jupyter-server <unfixed>
[trixie] - jupyter-server <no-dsa> (Minor issue)
+ [bookworm] - jupyter-server <postponed> (Minor issue; _get_os_path startswith(root) sibling-prefix traversal present, revisit with next update)
+ [bullseye] - jupyter-server <postponed> (Minor issue; _get_os_path startswith(root) sibling-prefix traversal present, revisit with next update)
NOTE: https://huntr.com/bounties/24a36953-6490-466f-8cb2-a90d1ca56e0f
CVE-2026-5191 (The Tiled Gallery Carousel Without JetPack plugin for WordPress is vul ...)
NOT-FOR-US: WordPress plugin
@@ -57495,6 +57538,8 @@ CVE-2026-41950 (Dify before version 1.14.0 contains an authorization bypass vuln
CVE-2026-40934 (Jupyter Server is the backend for Jupyter web applications. In version ...)
- jupyter-server 2.20.0-1 (bug #1136022)
[trixie] - jupyter-server <no-dsa> (Minor issue)
+ [bookworm] - jupyter-server <postponed> (Minor issue; cookie_secret_file persistence present, revisit with next update)
+ [bullseye] - jupyter-server <postponed> (Minor issue; cookie_secret_file persistence present, revisit with next update)
NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f
CVE-2026-40331 (Masa CMS is an open source content management system. In versions 7.2. ...)
NOT-FOR-US: Masa CMS
@@ -57507,6 +57552,8 @@ CVE-2026-40280 (Gotenberg is an API-based document conversion tool. In versions
CVE-2026-40110 (Jupyter Server is the backend for Jupyter web applications. In version ...)
- jupyter-server 2.20.0-1 (bug #1136022)
[trixie] - jupyter-server <no-dsa> (Minor issue)
+ [bookworm] - jupyter-server <postponed> (Minor issue; unanchored allow_origin_pat re.match present, revisit with next update)
+ [bullseye] - jupyter-server <postponed> (Minor issue; unanchored allow_origin_pat re.match present, revisit with next update)
NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p
NOTE: https://github.com/jupyter-server/jupyter_server/pull/603
NOTE: https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea (v2.18.0)
@@ -57530,6 +57577,8 @@ CVE-2026-35453 (PhpSpreadsheet is a library for reading and writing spreadsheet
CVE-2026-35397 (Jupyter Server is the backend for Jupyter web applications. In version ...)
- jupyter-server 2.20.0-1 (bug #1136022)
[trixie] - jupyter-server <no-dsa> (Minor issue)
+ [bookworm] - jupyter-server <postponed> (Minor issue; contents root_dir sibling-prefix traversal present, revisit with next update)
+ [bullseye] - jupyter-server <postponed> (Minor issue; contents root_dir sibling-prefix traversal present, revisit with next update)
NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3
CVE-2026-34596 (Sandboxie-Plus is an open source sandbox-based isolation software for ...)
NOT-FOR-US: Sandboxie-Plus
@@ -57798,6 +57847,8 @@ CVE-2025-66369 (An issue was discovered in MM in Samsung Mobile Processor, Weara
CVE-2025-61669 (Jupyter Server is the backend for Jupyter web applications. In jupyter ...)
- jupyter-server 2.20.0-1 (bug #1136022)
[trixie] - jupyter-server <no-dsa> (Minor issue)
+ [bookworm] - jupyter-server <postponed> (Minor issue; _redirect_safe next-param open redirect present, revisit with next update)
+ [bullseye] - jupyter-server <postponed> (Minor issue; _redirect_safe next-param open redirect present, revisit with next update)
NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-qh7q-6qm3-653w
CVE-2025-52206 (ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the sy ...)
NOT-FOR-US: ISPConfig
@@ -66015,6 +66066,7 @@ CVE-2026-40614 (PJSIP is a free and open source multimedia communication library
CVE-2026-40613 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
- coturn 4.12.0-1 (bug #1134577)
[trixie] - coturn <no-dsa> (Minor issue)
+ [bookworm] - coturn <postponed> (Minor issue; unaligned STUN attr pointer casts present in 4.6.1, ARM64-only DoS)
NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-j662-9wcj-mf36
NOTE: Fixed by: https://github.com/coturn/coturn/commit/eaa9e7920e98cd10d24ade07f474ddb4e05dc1ea (4.10.0)
CVE-2026-40611 (Let's Encrypt client and ACME library written in Go (Lego). Prior to 4 ...)
@@ -72765,6 +72817,7 @@ CVE-2026-35533 (mise manages dev tools like node, python, cmake, and terraform.
CVE-2026-35406 (Aardvark-dns is an authoritative dns server for A/AAAA container recor ...)
- aardvark-dns 1.16.0-3
[trixie] - aardvark-dns <no-dsa> (Minor issue)
+ [bookworm] - aardvark-dns <not-affected> (TCP DNS serving not implemented in 1.4.0; register_port() is UDP-only, the vulnerable TCP loop in src/dns/coredns.rs was added upstream later; advisory affects 1.16.0 and later)
NOTE: https://github.com/containers/aardvark-dns/security/advisories/GHSA-hfpq-x728-986j
NOTE: Fixed by: https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1 (main)
NOTE: Fixed by: https://github.com/containers/aardvark-dns/commit/b66c50e88ead4416ae3cd86044e5905cb33f2d4b (v1.17.1)
@@ -87171,6 +87224,7 @@ CVE-2026-32240 (Cap'n Proto is a data interchange format and capability-based RP
[experimental] - capnproto 1.4.0-1
- capnproto 1.4.0-2 (bug #1130877)
[trixie] - capnproto <no-dsa> (Minor issue)
+ [bookworm] - capnproto <postponed> (minor issue)
[bullseye] - capnproto <postponed> (minor issue)
NOTE: https://github.com/capnproto/capnproto/security/advisories/GHSA-vpcq-mx5v-32wm
NOTE: Fixed by: https://github.com/capnproto/capnproto/commit/2744b3c012b4aa3c31cefb61ec656829fa5c0e36 (v1.4.0)
@@ -87178,6 +87232,7 @@ CVE-2026-32239 (Cap'n Proto is a data interchange format and capability-based RP
[experimental] - capnproto 1.4.0-1
- capnproto 1.4.0-2 (bug #1130877)
[trixie] - capnproto <no-dsa> (Minor issue)
+ [bookworm] - capnproto <postponed> (minor issue)
[bullseye] - capnproto <postponed> (minor issue)
NOTE: https://github.com/capnproto/capnproto/security/advisories/GHSA-qjx3-pp3m-9jpm
NOTE: Fixed by: https://github.com/capnproto/capnproto/commit/2744b3c012b4aa3c31cefb61ec656829fa5c0e36 (v1.4.0)
@@ -93799,6 +93854,7 @@ CVE-2026-27831 (rldns is an open source DNS server. Version 1.3 has a heap-based
CVE-2026-27830 (c3p0, a JDBC Connection pooling library, is vulnerable to attack via m ...)
- c3p0 <unfixed> (bug #1129318)
[trixie] - c3p0 <no-dsa> (Minor issue)
+ [bookworm] - c3p0 <postponed> (Minor issue; userOverridesAsString deserialization reachable only via attacker-controlled bean property or JNDI Reference; fix needs 0.12.0 rewrite)
NOTE: https://github.com/swaldman/c3p0/security/advisories/GHSA-5476-xc4j-rqcv
NOTE: Fixed by: https://github.com/swaldman/c3p0/commit/e14cbd8166e423e2e9a9d6f08b2add3433492d6e (v0.12.0)
CVE-2026-27829 (Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in As ...)
@@ -94486,6 +94542,7 @@ CVE-2025-0976 (Information Exposure Vulnerability inHitachi Ops Center API Confi
CVE-2026-27624 (Coturn is a free open source implementation of TURN and STUN Server. C ...)
- coturn 4.12.0-1 (bug #1129267)
[trixie] - coturn <no-dsa> (Minor issue)
+ [bookworm] - coturn <postponed> (Minor issue; denied-peer-ip ACL bypass via v4-mapped IPv6, address-check functions lack IN6_IS_ADDR_V4MAPPED in 4.6.1)
NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-j8mm-mpf8-gvjg
NOTE: https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b (4.9.0)
CVE-2026-3121 (A flaw was found in Keycloak. An administrator with `manage-clients` p ...)
=====================================
data/dla-needed.txt
=====================================
@@ -80,9 +80,11 @@ bouncycastle
NOTE: 20260417: Priority: Fix CVE-2026-5588 then try to fix other pilled CVE (rouca/FD)
NOTE: 20260717: Also add for bookworm (Beuc/front-desk)
--
-busybox/bullseye
+busybox
NOTE: 20260511: Added by Front-Desk (dleidert)
NOTE: 20260511: A bunch of issues has piled up and last update was in early 2025 (dleidert/front-desk)
+ NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
+ NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
--
c3p0/bullseye
NOTE: 20260414: Added by Front-Desk (rouca)
@@ -109,10 +111,13 @@ caddy/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
-calibre/bullseye
+calibre
NOTE: 20260222: Added by Front-Desk (rouca)
NOTE: 20260429: partial update (abhijith)
NOTE: 20260430: Revisit when rest of the CVEs are fixed upstream (abhijith)
+ NOTE: 20260722: Also add for bookworm; CVE-2026-53511 arbitrary code exec
+ NOTE: 20260722: via composite python: template in a malicious ebook,
+ NOTE: 20260722: auto-evaluated on Add books (utkarsh)
--
chromium/bookworm (Emilio)
NOTE: 20260721: Added by Front-Desk (utkarsh)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d8472697b7da15b42345174acb606fffff8c7f23...4ed36ba85c92dcf239b24ea7978088f20ba6b8f5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d8472697b7da15b42345174acb606fffff8c7f23...4ed36ba85c92dcf239b24ea7978088f20ba6b8f5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/fbc742e8/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list