[Git][security-tracker-team/security-tracker][master] 2 commits: lts: node-ajv not-affected in bullseye/bookworm (uses uri-js, not fast-uri)

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Wed Jul 22 09:43:12 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b2053690 by Utkarsh Gupta at 2026-07-22T14:12:45+05:30
lts: node-ajv not-affected in bullseye/bookworm (uses uri-js, not fast-uri)

- - - - -
b237d293 by Utkarsh Gupta at 2026-07-22T14:12:46+05:30
lts: simplesamlphp postponed in bookworm/bullseye (CVE-2026-49284)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3881,6 +3881,8 @@ CVE-2026-16222 (A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. T
 CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...)
 	- node-ajv <unfixed>
 	[trixie] - node-ajv <no-dsa> (Minor issue)
+	[bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
+	[bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
 	NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx
 CVE-2026-16220 (A vulnerability has been found in code-projects Online Examination Sys ...)
 	NOT-FOR-US: code-projects
@@ -6657,6 +6659,8 @@ CVE-2026-49485 (HAPI FHIR is a complete implementation of the HL7 FHIR standard
 	NOT-FOR-US: HAPI FHIR
 CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information disclosure ...)
 	- simplesamlphp <unfixed>
+	[bookworm] - simplesamlphp <postponed> (Reachability-gated: multi-IdP mixed-trust deployments only; SP warns-and-continues on issuer mismatch and accepts unsigned Response InResponseTo; fix along with the next DLA)
+	[bullseye] - simplesamlphp <postponed> (Reachability-gated: multi-IdP mixed-trust deployments only; SP warns-and-continues on issuer mismatch and accepts unsigned Response InResponseTo; fix along with the next DLA)
 	NOTE: https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
 CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)
 	- golang-oras-oras-go <unfixed> (bug #1142456)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/eabe3de6/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list