[Git][security-tracker-team/security-tracker][master] 14 commits: dla-needed: add logback

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Sun Jul 26 00:59:27 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
94ff396a by Utkarsh Gupta at 2026-07-26T01:32:11+05:30
dla-needed: add logback

- - - - -
aa63a786 by Utkarsh Gupta at 2026-07-26T01:35:41+05:30
lts: mapserver postponed in bookworm/bullseye

- - - - -
f53fcadc by Utkarsh Gupta at 2026-07-26T01:43:41+05:30
lts: modsecurity postponed in bookworm/bullseye

- - - - -
87c11790 by Utkarsh Gupta at 2026-07-26T05:28:13+05:30
lts: mupdf postponed in bookworm/bullseye

- - - - -
7c437591 by Utkarsh Gupta at 2026-07-26T05:28:18+05:30
lts: nltk postponed in bookworm/bullseye

- - - - -
eb82b1a1 by Utkarsh Gupta at 2026-07-26T05:28:18+05:30
lts: node-babel7 postponed in bookworm/bullseye

- - - - -
5c28c4f7 by Utkarsh Gupta at 2026-07-26T05:28:18+05:30
lts: node-extract-zip postponed in bookworm/bullseye

- - - - -
ea570912 by Utkarsh Gupta at 2026-07-26T05:28:25+05:30
lts: node-immutable postponed in bookworm/bullseye

- - - - -
290c308c by Utkarsh Gupta at 2026-07-26T05:28:25+05:30
lts: node-js-cookie postponed in bookworm/bullseye

- - - - -
028420b2 by Utkarsh Gupta at 2026-07-26T05:28:30+05:30
lts: node-js-yaml postponed in bookworm/bullseye

- - - - -
a5e15afc by Utkarsh Gupta at 2026-07-26T05:28:31+05:30
lts: node-markdown-it postponed in bookworm/bullseye

- - - - -
3c07f8a0 by Utkarsh Gupta at 2026-07-26T05:28:35+05:30
lts: node-tmp postponed in bookworm/bullseye

- - - - -
2312e65b by Utkarsh Gupta at 2026-07-26T05:28:40+05:30
lts: node-ws postponed in bookworm/bullseye

- - - - -
3f6e1cc2 by Utkarsh Gupta at 2026-07-26T05:28:44+05:30
lts: node-shell-quote postponed in bookworm

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -15068,11 +15068,15 @@ CVE-2026-54714 (Logto is the modern, open-source auth infrastructure for SaaS an
 CVE-2026-52761 (ModSecurity is an open source, cross platform web application firewall ...)
 	- modsecurity 3.0.16-1 (bug #1141961)
 	[trixie] - modsecurity <no-dsa> (Minor issue)
+	[bookworm] - modsecurity <postponed> (Minor issue; i386-only rule bypass in utf8toUnicode transform)
+	[bullseye] - modsecurity <postponed> (Minor issue; i386-only rule bypass in utf8toUnicode transform)
 	NOTE: https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-qjgm-7gp4-f8qq
 	NOTE: Fixed by: https://github.com/owasp-modsecurity/ModSecurity/commit/edcd010814e234d46e2ec55a0f1078ff9d3032e4 (v3.0.16)
 CVE-2026-52747 (ModSecurity is an open source, cross platform web application firewall ...)
 	- modsecurity 3.0.16-1 (bug #1141961)
 	[trixie] - modsecurity <no-dsa> (Minor issue; will be fixed via point release)
+	[bookworm] - modsecurity <postponed> (Minor issue; multipart parser differential, WAF-rule bypass only)
+	[bullseye] - modsecurity <postponed> (Minor issue; multipart parser differential, WAF-rule bypass only)
 	NOTE: https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-rcw9-2f5r-7p88
 	NOTE: Fixed by: https://github.com/owasp-modsecurity/ModSecurity/commit/875504c2758169c41be1ad2f0cc64d896b7815d7 (v3.0.16)
 CVE-2026-4661 (The WP CTA \u2013 Sticky CTA Builder, Generate Leads, Promote Sales pl ...)
@@ -16959,12 +16963,16 @@ CVE-2026-59882 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation i
 CVE-2026-59880 (Immutable.js provides many Persistent Immutable data structures. Prior ...)
 	- node-immutable <unfixed> (bug #1141821)
 	[trixie] - node-immutable <no-dsa> (Minor issue)
+	[bookworm] - node-immutable <postponed> (Minor issue)
+	[bullseye] - node-immutable <postponed> (Minor issue)
 	NOTE: https://github.com/immutable-js/immutable-js/security/advisories/GHSA-xvcm-6775-5m9r
 	NOTE: Fixed by: https://github.com/immutable-js/immutable-js/commit/3dd7e5655012597a41873e328bf9142a8901527b (v4.3.9)
 	NOTE: Fixed by: https://github.com/immutable-js/immutable-js/commit/e51d49fc612ded5ec4dfb94ff294d22074269b0f (v5.1.8)
 CVE-2026-59879 (Immutable.js provides many Persistent Immutable data structures. Prior ...)
 	- node-immutable <unfixed> (bug #1141821)
 	[trixie] - node-immutable <no-dsa> (Minor issue)
+	[bookworm] - node-immutable <postponed> (Minor issue)
+	[bullseye] - node-immutable <postponed> (Minor issue)
 	NOTE: https://github.com/immutable-js/immutable-js/security/advisories/GHSA-v56q-mh7h-f735
 	NOTE: Fixed by: https://github.com/immutable-js/immutable-js/commit/f0bc997d8eb9886aff2236635aa210a95a04304a (v4.3.9)
 	NOTE: Fixed by: https://github.com/immutable-js/immutable-js/commit/a1a1ee412dcaa380ab325196283d06594ffe4b84 (v5.1.8)
@@ -16999,6 +17007,8 @@ CVE-2026-59870 (js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 befor
 CVE-2026-59869 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15 ...)
 	- node-js-yaml <unfixed> (bug #1141820)
 	[trixie] - node-js-yaml <no-dsa> (Minor issue)
+	[bookworm] - node-js-yaml <postponed> (Minor issue)
+	[bullseye] - node-js-yaml <postponed> (Minor issue)
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m
 	NOTE: Fixed by: https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7 (3.15.0)
 	NOTE: Fixed by: https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4 (4.3.0)
@@ -19240,6 +19250,8 @@ CVE-2026-12481 (A vulnerability in keras-team/keras version 3.14.0 allows for ar
 CVE-2026-12252 (In nltk/nltk versions 3.9.3 and earlier, five Stanford interface class ...)
 	- nltk <unfixed>
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
+	[bullseye] - nltk <postponed> (Minor issue)
 	NOTE: https://huntr.com/bounties/f5c93982-0cc9-4e2e-bb85-1b6ab29a2efb
 CVE-2025-71380 (The Execute Command node in n8n allows authenticated users to execute  ...)
 	NOT-FOR-US: n8n
@@ -23821,6 +23833,8 @@ CVE-2026-12349 (The Premium Addons for KingComposer plugin for WordPress is vuln
 CVE-2026-12243 (NLTK version 3.9.4 is vulnerable to a path traversal attack due to an  ...)
 	- nltk <unfixed>
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
+	[bullseye] - nltk <postponed> (Minor issue)
 	NOTE: https://huntr.com/bounties/39aa9354-54ca-4e77-96da-580eb1fe6ed1
 CVE-2026-12240 (The Export User Data plugin for WordPress is vulnerable to arbitrary f ...)
 	NOT-FOR-US: WordPress plugin
@@ -25232,6 +25246,8 @@ CVE-2026-57231 (Podman is a tool for managing OCI containers and pods. From 1.8.
 CVE-2026-56876 (extract-zip does not validate symlink targets when extracting zip arch ...)
 	- node-extract-zip <unfixed> (bug #1141501)
 	[trixie] - node-extract-zip <no-dsa> (Minor issue)
+	[bookworm] - node-extract-zip <postponed> (Minor issue; requires extracting an attacker-supplied zip and later following the extracted symlink)
+	[bullseye] - node-extract-zip <postponed> (Minor issue; requires extracting an attacker-supplied zip and later following the extracted symlink)
 	NOTE: https://github.com/ziad626/extract-zip-security-research/security/advisories/GHSA-x7jf-2287-qcpf
 CVE-2026-56823 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
 	NOT-FOR-US: AutoGPT
@@ -27520,6 +27536,7 @@ CVE-2026-1606 (GitLab has remediated an issue in GitLab CE/EE affecting all vers
 CVE-2026-13311 (shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Ar ...)
 	- node-shell-quote 1.9.0+~1.7.5-1 (bug #1140921)
 	[trixie] - node-shell-quote <no-dsa> (Minor issue)
+	[bookworm] - node-shell-quote <postponed> (Minor issue; quadratic-complexity DoS in parse(), reachable only where a service parses attacker-supplied strings)
 	NOTE: https://github.com/ljharb/shell-quote/security/advisories/GHSA-395f-4hp3-45gv
 	NOTE: Fixed by: https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec (v1.9.0)
 CVE-2026-13038 (Use after free in Autofill in Google Chrome on Windows prior to 149.0. ...)
@@ -29892,6 +29909,8 @@ CVE-2026-0864 (When using the "configparser" module to write configuration files
 CVE-2025-71382 (MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerabili ...)
 	- mupdf 1.27.0+ds1-2
 	[trixie] - mupdf <no-dsa> (Minor issue)
+	[bookworm] - mupdf <postponed> (Minor issue; stack-exhaustion DoS via unbounded recursion over the CSS inheritance chain in html/css-apply.c, needs crafted EPUB opened by victim)
+	[bullseye] - mupdf <postponed> (Minor issue; stack-exhaustion DoS via unbounded recursion over the CSS inheritance chain in html/css-apply.c, needs crafted EPUB opened by victim)
 	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=708840
 	NOTE: Fixed by: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=70b71ab22e6de4d4c44cd301c88231f623a4e94e (1.27.0-rc1)
 CVE-2025-71376 (picklescan before 0.0.29 fails to detect malicious pickle files using  ...)
@@ -30344,6 +30363,8 @@ CVE-2026-54298 (Astro is a web framework. Prior to 6.4.6, the spreadAttributes f
 CVE-2026-54293 (NLTK (Natural Language Toolkit) is a suite of open source Python modul ...)
 	- nltk 3.10.0-1 (bug #1141500)
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
+	[bullseye] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-p4gq-832x-fm9v
 	NOTE: https://github.com/nltk/nltk/pull/3575
 CVE-2026-54290 (Hono is a Web application framework that provides support for any Java ...)
@@ -30472,6 +30493,8 @@ CVE-2026-53571 (Vite is a frontend tooling framework for JavaScript. Prior to 8.
 CVE-2026-53550 (js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.1 ...)
 	- node-js-yaml 4.2.0+~4.0.9-1
 	[trixie] - node-js-yaml <no-dsa> (Minor issue)
+	[bookworm] - node-js-yaml <postponed> (Minor issue)
+	[bullseye] - node-js-yaml <postponed> (Minor issue)
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-h67p-54hq-rp68
 CVE-2026-53540 (Python-Multipart is a streaming multipart parser for Python. Prior to  ...)
 	- python-multipart <unfixed> (bug #1140628)
@@ -30542,6 +30565,8 @@ CVE-2026-50146 (Astro is a web framework. Prior to 6.3.3, when a component uses
 CVE-2026-49356 (Babel is a compiler for writing next generation JavaScript. Prior to 8 ...)
 	- node-babel7 <unfixed> (bug #1140816)
 	[trixie] - node-babel7 <no-dsa> (Minor issue)
+	[bookworm] - node-babel7 <postponed> (Minor issue; requires compiling attacker-controlled code, arbitrary file read into output source map)
+	[bullseye] - node-babel7 <postponed> (Minor issue; requires compiling attacker-controlled code, arbitrary file read into output source map)
 	NOTE: https://github.com/babel/babel/security/advisories/GHSA-4x5r-pxfx-6jf8
 CVE-2026-49241 (The Angular Language Service VS Code Extension provides a rich editing ...)
 	NOT-FOR-US: VS Code extension
@@ -31898,6 +31923,8 @@ CVE-2026-48989 (Windows-MCP is an open-source project that integrates AI agents
 CVE-2026-48988 (markdown-it is a Markdown parser. Versions 14.1.1 and below contain a  ...)
 	- node-markdown-it 22.2.3+dfsg+~12.2.3-5 (bug #1140349)
 	[trixie] - node-markdown-it <no-dsa> (Minor issue)
+	[bookworm] - node-markdown-it <postponed> (Minor issue; quadratic smartquotes DoS, needs non-default typographer:true)
+	[bullseye] - node-markdown-it <postponed> (Minor issue; quadratic smartquotes DoS, needs non-default typographer:true)
 	NOTE: https://github.com/markdown-it/markdown-it/security/advisories/GHSA-6v5v-wf23-fmfq
 	NOTE: https://github.com/markdown-it/markdown-it/commit/9ce2087562c45d1e5ddd9f76b990f4b3fbe040e5 (14.2.0)
 CVE-2026-48979 (PHP Standard Library (PSL) is set of APIs covering async, collections, ...)
@@ -32443,6 +32470,8 @@ CVE-2026-12491 (A flaw was found in vLLM, an open-source library for large langu
 CVE-2026-12199 (A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows u ...)
 	- nltk <unfixed> (bug #1140486)
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
+	[bullseye] - nltk <postponed> (Minor issue)
 	NOTE: https://huntr.com/bounties/cee4ca6a-d17f-4746-abad-c68119633d37
 CVE-2026-12165 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell with PayP ...)
 	NOT-FOR-US: WordPress plugin
@@ -32682,6 +32711,8 @@ CVE-2026-48781 (Postiz is an AI social media scheduling tool. In versions prior
 CVE-2026-48779 (ws is an open source WebSocket client and server for Node.js. All vers ...)
 	- node-ws 8.21.0+~cs14.19.1-1 (bug #1140429)
 	[trixie] - node-ws <no-dsa> (Minor issue)
+	[bookworm] - node-ws <postponed> (Minor issue; memory-exhaustion DoS from a malicious peer, fixed in 8.21.0/7.5.11)
+	[bullseye] - node-ws <postponed> (Minor issue; memory-exhaustion DoS from a malicious peer, fixed in 8.21.0/7.5.11)
 	NOTE: https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p
 CVE-2026-48777 (FileBrowser Quantum is a free, self-hosted, web-based file manager. Ve ...)
 	NOT-FOR-US: FileBrowser Quantum
@@ -36355,6 +36386,8 @@ CVE-2026-46643 (Snappy is a PHP library allowing thumbnail, snapshot or PDF gene
 CVE-2026-46625 (JavaScript Cookie is a JavaScript API for handling cookies, client-sid ...)
 	- node-js-cookie 3.0.7+~3.0.6-1
 	[trixie] - node-js-cookie <no-dsa> (Minor issue)
+	[bookworm] - node-js-cookie <postponed> (Minor issue)
+	[bullseye] - node-js-cookie <postponed> (Minor issue)
 	NOTE: https://github.com/js-cookie/js-cookie/security/advisories/GHSA-qjx8-664m-686j
 	NOTE: https://github.com/js-cookie/js-cookie/commit/eb3c40e89731e99b8970faaf35ddad249c6c0020 (v3.0.7)
 CVE-2026-46519 (mcp-server-kubernetes is a Model Context Protocol server for Kubernete ...)
@@ -36376,6 +36409,8 @@ CVE-2026-45106 (Weblate is a web based localization tool. Prior to version 2026.
 CVE-2026-44705 (tmp is a temporary file and directory creator for node.js. Prior to 0. ...)
 	- node-tmp 0.2.7+dfsg+~0.2.6-1 (bug #1139827)
 	[trixie] - node-tmp <no-dsa> (Minor issue)
+	[bookworm] - node-tmp <postponed> (Minor issue)
+	[bullseye] - node-tmp <postponed> (Minor issue)
 	NOTE: https://github.com/raszi/node-tmp/security/advisories/GHSA-ph9p-34f9-6g65
 	NOTE: Fixed by: https://github.com/raszi/node-tmp/commit/efa4a06f24374797ae32ab2b6ae39b7a611ae429 (v0.2.6)
 	NOTE: When fixing this issue make sure to fix it completely to not open up CVE-2026-49982
@@ -47492,6 +47527,8 @@ CVE-2026-45108 (Himmelblau is an interoperability suite for Microsoft Azure Entr
 CVE-2026-45104 (MapServer is a system for developing web-based GIS applications. From  ...)
 	- mapserver 8.6.3-1
 	[trixie] - mapserver <no-dsa> (Minor issue)
+	[bookworm] - mapserver <postponed> (Minor issue, DoS in SLD ElseFilter parsing)
+	[bullseye] - mapserver <postponed> (Minor issue, DoS in SLD ElseFilter parsing)
 	NOTE: https://github.com/MapServer/MapServer/security/advisories/GHSA-4h8g-378q-r75m
 CVE-2026-45102 (OneUptime is an open-source monitoring and observability platform. Pri ...)
 	NOT-FOR-US: OneUptime
@@ -50524,6 +50561,8 @@ CVE-2026-44729 (Twenty is an open source CRM. In 1.18.0 and earlier, the file se
 CVE-2026-44728 (Babel is a compiler for writing next generation JavaScript. From 7.12. ...)
 	- node-babel7 <unfixed> (bug #1138712)
 	[trixie] - node-babel7 <no-dsa> (Minor issue)
+	[bookworm] - node-babel7 <postponed> (Minor issue; code injection into output only when compiling attacker-controlled code with modules systemjs)
+	[bullseye] - node-babel7 <postponed> (Minor issue; code injection into output only when compiling attacker-controlled code with modules systemjs)
 	NOTE: https://github.com/babel/babel/security/advisories/GHSA-fv7c-fp4j-7gwp
 CVE-2026-44723 (Vowpal Wabbit is a machine learning system. The workflow .github/workf ...)
 	NOT-FOR-US: Vowpal Wabbit
@@ -59628,6 +59667,7 @@ CVE-2026-42072 (Nornicdb is a distributed low-latency, Graph+Vector, Temporal MV
 CVE-2026-42030 (MapServer is a system for developing web-based GIS applications. From  ...)
 	- mapserver 8.6.2-1
 	[trixie] - mapserver <no-dsa> (Minor issue)
+	[bookworm] - mapserver <postponed> (Minor issue, reflected XSS)
 	[bullseye] - mapserver <postponed> (Minor issue, reflected XSS)
 	NOTE: https://github.com/MapServer/MapServer/security/advisories/GHSA-4g9f-ph64-hg2x
 CVE-2026-42028 (novaGallery is a php image gallery. Prior to version 2.1.1, a path tra ...)


=====================================
data/dla-needed.txt
=====================================
@@ -442,6 +442,14 @@ libxslt/bullseye
 linux (Ben Hutchings)
   NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
 --
+logback
+  NOTE: 20260726: Added by Front-Desk (utkarsh)
+  NOTE: 20260726: CVE-2026-13006, CVE-2025-11226: bullseye 1.2.3-6 and bookworm
+  NOTE: 20260726: 1.2.11-3 both evaluate conditional config via unrestricted
+  NOTE: 20260726: Janino. Already in ela-needed for buster, so worth fixing for
+  NOTE: 20260726: LTS too. Also fix the other postponed logback CVEs, and it
+  NOTE: 20260726: should be fixed for trixie too (1.2.11-6 affected). (utkarsh/front-desk)
+--
 lrzip/bookworm
   NOTE: 20260725: Added by Front-Desk (utkarsh)
   NOTE: 20260725: CVE-2025-15570; fixed in bullseye via DLA-4567-1. bookworm



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e1aad7da9ec1bca2cd27b29e4c04cf5b76cf29c2...3f6e1cc223f2a06e44fb603b72acf49190a33da4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e1aad7da9ec1bca2cd27b29e4c04cf5b76cf29c2...3f6e1cc223f2a06e44fb603b72acf49190a33da4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/62a12bba/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list