[Git][security-tracker-team/security-tracker][master] 2 commits: lts: node-ajv not-affected in bullseye/bookworm (uses uri-js, not fast-uri)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Wed Jul 22 09:43:12 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b2053690 by Utkarsh Gupta at 2026-07-22T14:12:45+05:30
lts: node-ajv not-affected in bullseye/bookworm (uses uri-js, not fast-uri)
- - - - -
b237d293 by Utkarsh Gupta at 2026-07-22T14:12:46+05:30
lts: simplesamlphp postponed in bookworm/bullseye (CVE-2026-49284)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3881,6 +3881,8 @@ CVE-2026-16222 (A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. T
CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...)
- node-ajv <unfixed>
[trixie] - node-ajv <no-dsa> (Minor issue)
+ [bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
+ [bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx
CVE-2026-16220 (A vulnerability has been found in code-projects Online Examination Sys ...)
NOT-FOR-US: code-projects
@@ -6657,6 +6659,8 @@ CVE-2026-49485 (HAPI FHIR is a complete implementation of the HL7 FHIR standard
NOT-FOR-US: HAPI FHIR
CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information disclosure ...)
- simplesamlphp <unfixed>
+ [bookworm] - simplesamlphp <postponed> (Reachability-gated: multi-IdP mixed-trust deployments only; SP warns-and-continues on issuer mismatch and accepts unsigned Response InResponseTo; fix along with the next DLA)
+ [bullseye] - simplesamlphp <postponed> (Reachability-gated: multi-IdP mixed-trust deployments only; SP warns-and-continues on issuer mismatch and accepts unsigned Response InResponseTo; fix along with the next DLA)
NOTE: https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)
- golang-oras-oras-go <unfixed> (bug #1142456)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/eabe3de6/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list