[Git][security-tracker-team/security-tracker][master] 11 commits: lts: triage fastdds in bookworm/bullseye
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Fri Jul 24 23:40:01 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
25be8f09 by Utkarsh Gupta at 2026-07-24T23:18:25+05:30
lts: triage fastdds in bookworm/bullseye
- - - - -
d3f09ca9 by Utkarsh Gupta at 2026-07-24T23:21:40+05:30
lts: triage jupyterhub in bookworm
- - - - -
f8c98d54 by Utkarsh Gupta at 2026-07-24T23:25:02+05:30
lts: kas postponed in bookworm/bullseye (CVE-2026-54548)
- - - - -
6eb64cfe by Utkarsh Gupta at 2026-07-24T23:28:20+05:30
lts: kcoreaddons postponed in bookworm/bullseye (CVE-2026-41526)
- - - - -
4101c104 by Utkarsh Gupta at 2026-07-24T23:31:45+05:30
lts: ldns postponed in bookworm/bullseye (CVE-2026-10846)
- - - - -
84b28e5a by Utkarsh Gupta at 2026-07-24T23:35:10+05:30
lts: lemonldap-ng postponed in bookworm/bullseye (CVE-2026-12804)
- - - - -
4169488c by Utkarsh Gupta at 2026-07-24T23:38:30+05:30
lts: triage liboauth2 in bookworm/bullseye
- - - - -
c9d29434 by Utkarsh Gupta at 2026-07-24T23:41:55+05:30
lts: triage libzypp in bookworm/bullseye
- - - - -
27067676 by Utkarsh Gupta at 2026-07-24T23:45:20+05:30
lts: triage mistune in bookworm/bullseye
- - - - -
f1f7eebd by Utkarsh Gupta at 2026-07-24T23:48:50+05:30
lts: neovim not-affected in bookworm/bullseye (CVE-2026-11487)
- - - - -
7e4a890e by Utkarsh Gupta at 2026-07-24T23:52:11+05:30
lts: nix not-affected in bookworm (CVE-2026-39860)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15453,47 +15453,65 @@ CVE-2026-59937 (pypdf is a free and open-source pure-python PDF library. Prior t
CVE-2026-59930 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <postponed> (Minor issue)
+ [bullseye] - mistune <not-affected> (Directive system introduced after 0.8.4)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9
NOTE: Fixed by: https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b581b (v3.3.0)
CVE-2026-59929 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <postponed> (Minor issue)
+ [bullseye] - mistune <postponed> (Minor issue)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-qfrw-5rxm-mhh2
NOTE: Fixed by: https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc (v3.3.0)
CVE-2026-59928 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+ [bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q
NOTE: Fixed by: https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69 (v3.3.0)
CVE-2026-59927 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <postponed> (Minor issue)
+ [bullseye] - mistune <not-affected> (Directive system introduced after 0.8.4)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-8mpj-m6qm-5qr8
NOTE: Fixed by: https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993 (v3.3.0)
CVE-2026-59926 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <not-affected> (Admonition :class: option introduced in 3.x)
+ [bullseye] - mistune <not-affected> (Admonition :class: option introduced in 3.x)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-g97x-gvcm-x72h
NOTE: Fixed by: https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2 (v3.2.1)
CVE-2026-59925 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+ [bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45
NOTE: Fixed by: https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f (v3.3.0)
CVE-2026-59924 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <postponed> (Minor issue)
+ [bullseye] - mistune <not-affected> (Directive system introduced after 0.8.4)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf
NOTE: Fixed by: https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993 (v3.3.0)
CVE-2026-59923 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <postponed> (Minor issue)
+ [bullseye] - mistune <postponed> (Minor issue)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3
NOTE: Fixed by: https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc (v3.3.0)
CVE-2026-59922 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+ [bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq
NOTE: Fixed by: https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7 (v3.3.0)
CVE-2026-59897 (Hono is a Web application framework that provides support for any Java ...)
@@ -16787,46 +16805,68 @@ CVE-2024-56141 (Minosoft is an open-source, multi-version Minecraft Java Edition
CVE-2026-49861
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-53589
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <not-affected> (RTPSEndpointQos deserializer introduced upstream in 3.2)
+ [bullseye] - fastdds <not-affected> (RTPSEndpointQos deserializer introduced upstream in 3.2)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-45098
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-49862
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <not-affected> (regex-based IPLocator::isIPv4 introduced after 2.1.0)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-55063
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-49863
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-53588
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-53590
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
CVE-2026-45096
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104 (v3.6.2)
CVE-2026-45095
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104 (v3.6.2)
CVE-2026-45094
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104 (v3.6.2)
CVE-2026-59089 (A flaw was found in GIMP. The PlayStation TIM loader, responsible for ...)
- gimp <unfixed>
@@ -18442,10 +18482,14 @@ CVE-2026-54886 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerabi
CVE-2026-54431 (In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier acc ...)
- liboauth2 2.3.0-1
[trixie] - liboauth2 <no-dsa> (Minor issue)
+ [bookworm] - liboauth2 <postponed> (Minor issue)
+ [bullseye] - liboauth2 <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/OpenIDC/liboauth2/commit/c0b57152ed6a0af33aeb04a60bd7f5bff5ab8800 (v2.3.0)
CVE-2026-54430 (liboauth2 is vulnerable to Server-Side Request Forgery inoauth2_jose_j ...)
- liboauth2 2.3.0-1
[trixie] - liboauth2 <no-dsa> (Minor issue)
+ [bookworm] - liboauth2 <not-affected> (Vulnerable code introduced in 2.1.0)
+ [bullseye] - liboauth2 <not-affected> (Vulnerable code introduced in 2.1.0)
NOTE: Fixed by: https://github.com/OpenIDC/liboauth2/commit/347507ac5b51f48c2933bbe49b2ee07c2af4712b (v2.3.0)
CVE-2026-54409 (A malicious actor with access to the network and under certain conditi ...)
NOT-FOR-US: UniFi
@@ -18496,7 +18540,10 @@ CVE-2026-49779 (Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 v
CVE-2026-44941 (A relative path traversal in the "keyhint" option in repomd.xml parsin ...)
- libzypp 17.38.12-1
[trixie] - libzypp <no-dsa> (Minor issue)
+ [bookworm] - libzypp <not-affected> (keyhint support introduced in 17.26.0; absent in 17.25.7)
+ [bullseye] - libzypp <not-affected> (keyhint support introduced in 17.26.0; absent in 17.25.7)
NOTE: Fixed by: https://github.com/openSUSE/libzypp/commit/294b1bad442d089ca671c5c03adc8031e3b29e04 (17.38.12)
+ NOTE: Introduced with: https://github.com/openSUSE/libzypp/commit/beb0e764a86e7effc13cde04ff3db652c5c758a4 (17.26.0)
CVE-2026-44935 (Missing validation of "valuesFrom" references in Helm Deployer of SUSE ...)
NOT-FOR-US: Rancher Fleet
CVE-2026-42382 (Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.)
@@ -22587,6 +22634,8 @@ CVE-2026-36848 (Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traver
CVE-2026-25707 (A relative path traversal bug problem when processing repository metad ...)
- libzypp 17.38.11-1
[trixie] - libzypp <no-dsa> (Minor issue)
+ [bookworm] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized metadata paths present in 17.25.7)
+ [bullseye] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized metadata paths present in 17.25.7)
NOTE: https://github.com/openSUSE/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b (17.38.10)
CVE-2026-22078 (Because O+ Connect's IPC service does not authenticate clients, extern ...)
NOT-FOR-US: Oppo
@@ -25769,6 +25818,8 @@ CVE-2026-53131 (In the Linux kernel, the following vulnerability has been resolv
CVE-2026-54548
- kas 5.4-1
[trixie] - kas <no-dsa> (Minor issue)
+ [bookworm] - kas <postponed> (Minor issue)
+ [bullseye] - kas <postponed> (Minor issue)
NOTE: https://github.com/siemens/kas/security/advisories/GHSA-mv8m-v9v6-5f94
CVE-2026-9787 (Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Exec ...)
NOT-FOR-US: Quest
@@ -26379,6 +26430,8 @@ CVE-2026-49980 (Rclone is a command-line program to sync files and directories t
CVE-2026-49851 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
[trixie] - mistune <no-dsa> (Minor issue)
+ [bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+ [bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p
CVE-2026-49269 (Apple M1 GPUs retain register file data between compute shader dispatc ...)
NOT-FOR-US: Apple Silicon HW issue
@@ -29315,6 +29368,8 @@ CVE-2026-56229 (Capgo before 12.128.2 contains an authorization bypass vulnerabi
CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is ...)
- lemonldap-ng <unfixed>
[trixie] - lemonldap-ng <no-dsa> (Minor issue)
+ [bookworm] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
+ [bullseye] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979
CVE-2026-12799 (A security vulnerability has been detected in BerriAI litellm up to 1. ...)
@@ -30229,6 +30284,8 @@ CVE-2026-46580 (In Eclipse Theia versions prior to 1.71.0, files matching the pa
CVE-2026-44942 (A path traversal in handling the "path" component of .repo files proce ...)
- libzypp 17.38.13-1
[trixie] - libzypp <no-dsa> (Minor issue)
+ [bookworm] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
+ [bullseye] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
NOTE: https://bugzilla.suse.com/show_bug.cgi?id=1267874
CVE-2026-44691 (In Eclipse Theia versions prior to 1.69.0, custom task definitions in ...)
NOT-FOR-US: Eclipse
@@ -35718,6 +35775,8 @@ CVE-2026-11799 (UXSS in Focus for iOS / Klar Webkit navigation. This vulnerabili
CVE-2026-10846 (NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in ...)
- ldns 1.9.2-1 (bug #1139627)
[trixie] - ldns <no-dsa> (Minor issue)
+ [bookworm] - ldns <postponed> (Minor issue; off-path response spoofing only for apps using ldns as UDP stub resolver, e.g. drill; no addr/port/ID matching in ldns_udp_send_from)
+ [bullseye] - ldns <postponed> (Minor issue; off-path response spoofing only for apps using ldns as UDP stub resolver, e.g. drill; no addr/port/ID matching in ldns_udp_send_from)
NOTE: https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt
CVE-2026-10238
REJECTED
@@ -38092,6 +38151,8 @@ CVE-2026-11488 (A vulnerability has been found in code-projects Simple Flight Ti
CVE-2026-11487 (A flaw has been found in Neovim up to 0.12.2. Affected by this issue i ...)
- neovim 0.12.3-1 (bug #1139999)
[trixie] - neovim <no-dsa> (Minor issue)
+ [bookworm] - neovim <not-affected> (Vulnerable code not present; vim.secure added upstream in 0.9)
+ [bullseye] - neovim <not-affected> (Vulnerable code not present; vim.secure added upstream in 0.9)
NOTE: https://github.com/neovim/neovim/issues/39914
NOTE: https://github.com/neovim/neovim/pull/39918
NOTE: https://github.com/neovim/neovim/commit/f83e0dcaf8cf18de94828341b0a1a61a86c75baf (v0.12.3)
@@ -50027,6 +50088,7 @@ CVE-2026-41069 (libheif is a HEIF and AVIF file format decoder and encoder. In v
CVE-2026-40864 (JupyterHub is software that allows users to create a multi-user server ...)
- jupyterhub <unfixed>
[trixie] - jupyterhub <no-dsa> (Minor issue)
+ [bookworm] - jupyterhub <not-affected> (Vulnerable Sec-Fetch-Mode handling introduced with the 4.1.0 XSRF rework)
NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9
NOTE: Fixed by: https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127 (5.4.5)
CVE-2026-40610 (BentoML is a Python library for building online serving systems optimi ...)
@@ -66347,6 +66409,8 @@ CVE-2026-41602 (Integer Overflow or Wraparound vulnerability in Apache Thrift TF
CVE-2026-41526 (In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safel ...)
- kcoreaddons 5.116.0-2 (bug #1135179)
[trixie] - kcoreaddons <no-dsa> (Minor issue)
+ [bookworm] - kcoreaddons <postponed> (Minor issue)
+ [bullseye] - kcoreaddons <postponed> (Minor issue)
- kf6-kcoreaddons 6.26.0-1 (bug #1135178)
[trixie] - kf6-kcoreaddons <no-dsa> (Minor issue)
NOTE: https://kde.org/info/security/advisory-20260427-1.txt
@@ -77815,6 +77879,7 @@ CVE-2025-14732 (The Elementor Website Builder \u2013 More Than Just a Page Build
CVE-2026-39860 (Nix is a package manager for Linux and other Unix systems. A bug in th ...)
- nix 2.34.6+dfsg-1 (bug #1133004)
[trixie] - nix <no-dsa> (Minor issue)
+ [bookworm] - nix <not-affected> (Vulnerable code introduced by the CVE-2024-27297 fix in 2.21; that fix was never applied to 2.8.0)
[bullseye] - nix <postponed> (regresssion of postponed CVE-2024-27297; revisit when fixing CVE-2024-27297)
NOTE: https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj
NOTE: Introduced with: https://github.com/NixOS/nix/commit/a3163b9eabb952b4aa96e376dea95ebcca97b31a (2.21.0)
@@ -79567,6 +79632,7 @@ CVE-2026-34052 (LTI JupyterHub Authenticator is a JupyterHub authenticator for L
CVE-2026-33709 (JupyterHub is software that allows one to create a multi-user server f ...)
- jupyterhub <unfixed> (bug #1132715)
[trixie] - jupyterhub <no-dsa> (Minor issue)
+ [bookworm] - jupyterhub <postponed> (Minor issue; open redirect requiring user interaction)
NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-3vff-hjqv-m7h8
CVE-2026-33184 (nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of ...)
NOT-FOR-US: nimiq/core-rs-albatross
@@ -126891,18 +126957,26 @@ CVE-2025-66845 (A reflected Cross-Site Scripting (XSS) vulnerability has been id
CVE-2026-45097
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <not-affected> (xtypes DynamicDataImpl introduced in 3.0; 2.x ships legacy dynamic-types)
+ [bullseye] - fastdds <not-affected> (xtypes DynamicDataImpl introduced in 3.0; 2.x ships legacy dynamic-types)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
CVE-2026-45092
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
CVE-2026-45093
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
CVE-2025-65865 (An integer overflow in eProsima Fast-DDS v3.3 allows attackers to caus ...)
- fastdds <unfixed> (bug #1141768)
[trixie] - fastdds <no-dsa> (Minor issue)
+ [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+ [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
CVE-2025-65713 (Home Assistant Core before v2025.8.0 is vulnerable to Directory Traver ...)
NOT-FOR-US: Home Assistant Core
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee0457739c13ffbf0086719cc26a5f2225dbe7e3...7e4a890e49fd3b4131a905d5e5fd29b02e3115f7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee0457739c13ffbf0086719cc26a5f2225dbe7e3...7e4a890e49fd3b4131a905d5e5fd29b02e3115f7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/314abd11/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list