[Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2026-46600/golang-golang-x-net

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 23 13:26:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7abc8e67 by Salvatore Bonaccorso at 2026-07-23T14:24:06+02:00
Add CVE-2026-46600/golang-golang-x-net

- - - - -
095cd434 by Salvatore Bonaccorso at 2026-07-23T14:24:23+02:00
Add one new issue in kibana, itp'ed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2882,7 +2882,9 @@ CVE-2026-46923 (Vulnerability in the Oracle Public Sector Financials (Internatio
 CVE-2026-46876 (Vulnerability in Oracle Application Testing Suite.   The supported ver ...)
 	NOT-FOR-US: Oracle
 CVE-2026-46600 (Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...)
-	TODO: check
+	- golang-golang-x-net 1:0.56.0-1
+	NOTE: https://github.com/golang/go/issues/79795
+	NOTE: Fixed by: https://github.com/golang/net/commit/82e7868a02167540748b74780b0bf825985256f7 (v0.56.0)
 CVE-2026-46556 (FlaskBB is a Forum Software written in Python using the micro framewor ...)
 	NOT-FOR-US: FlaskBB
 CVE-2026-46403 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
@@ -2898,7 +2900,7 @@ CVE-2026-43946 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard)
 CVE-2026-43945 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
 	NOT-FOR-US: FUXA
 CVE-2026-42397 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-3821 (Supermicro (SMC) SMASH services contain an Arbitrary code execution is ...)
 	NOT-FOR-US: Supermicro
 CVE-2026-35290 (Vulnerability in Oracle Application Testing Suite.   The supported ver ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/661573124ba9e3b05ababc880c1de1164f6b3a69...095cd43499af1e1be647c1b0396fd70b6518e38b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/661573124ba9e3b05ababc880c1de1164f6b3a69...095cd43499af1e1be647c1b0396fd70b6518e38b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/35fb3a07/attachment.htm>


More information about the debian-security-tracker-commits mailing list