[Git][security-tracker-team/security-tracker][master] 18 commits: lts: triage node-undici in bookworm
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 26 06:50:11 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
36b48aa3 by Utkarsh Gupta at 2026-07-26T08:45:06+05:30
lts: triage node-undici in bookworm
- - - - -
b9d98d7f by Utkarsh Gupta at 2026-07-26T08:48:53+05:30
lts: triage pypy3 in bookworm/bullseye
- - - - -
fda219c8 by Utkarsh Gupta at 2026-07-26T08:54:29+05:30
lts: ruby-concurrent postponed in bookworm/bullseye
- - - - -
5bd5a680 by Utkarsh Gupta at 2026-07-26T08:58:41+05:30
lts: r-cran-readxl postponed in bookworm/bullseye
- - - - -
07ec0ce2 by Utkarsh Gupta at 2026-07-26T09:03:14+05:30
lts: triage python-multipart in bookworm/bullseye
- - - - -
669fae5f by Utkarsh Gupta at 2026-07-26T09:07:58+05:30
lts: ruby-puppet-resource-api postponed in bookworm
- - - - -
c0ebb7dc by Utkarsh Gupta at 2026-07-26T09:12:33+05:30
lts: rtklib postponed in bookworm/bullseye
- - - - -
19b4bcb0 by Utkarsh Gupta at 2026-07-26T09:16:09+05:30
lts: openimageio not-affected in bookworm/bullseye
- - - - -
11a857f1 by Utkarsh Gupta at 2026-07-26T09:22:46+05:30
lts: triage node-axios in bookworm/bullseye
- - - - -
15789907 by Utkarsh Gupta at 2026-07-26T09:25:21+05:30
lts: redir postponed in bookworm/bullseye
- - - - -
ede2b3c0 by Utkarsh Gupta at 2026-07-26T09:30:02+05:30
lts: php-guzzlehttp-psr7 postponed in bookworm/bullseye
- - - - -
df61fb5e by Utkarsh Gupta at 2026-07-26T09:34:50+05:30
lts: redmine postponed in bookworm
- - - - -
2f3166f4 by Utkarsh Gupta at 2026-07-26T10:02:37+05:30
lts: triage rclone in bookworm/bullseye
- - - - -
79dd6590 by Utkarsh Gupta at 2026-07-26T10:09:16+05:30
lts: ruby-concurrent postponed in bookworm/bullseye
- - - - -
f1344f7d by Utkarsh Gupta at 2026-07-26T10:18:44+05:30
lts: node-undici postponed in bookworm
- - - - -
092445f2 by Utkarsh Gupta at 2026-07-26T10:30:25+05:30
dla-needed: add python-git
- - - - -
195fdafc by Utkarsh Gupta at 2026-07-26T10:41:11+05:30
dla-needed: add openimageio
- - - - -
dad51200 by Utkarsh Gupta at 2026-07-26T10:57:38+05:30
dla-needed: add shiro
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -16957,6 +16957,8 @@ CVE-2026-59883 (Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, Cookie
CVE-2026-59882 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.12.3-1
[trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [bookworm] - php-guzzlehttp-psr7 <postponed> (Minor issue; weak URI host validation, getHost() can disagree with the authority)
+ [bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue; weak URI host validation, getHost() can disagree with the authority)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-c2w2-prh8-qm98
NOTE: https://github.com/guzzle/psr7/pull/811
NOTE: Fixed by: https://github.com/guzzle/psr7/commit/ddd64f17d4cc1f7e5ffe6fd2c989ec7221712580 (2.12.3)
@@ -19356,6 +19358,7 @@ CVE-2026-9148 (The Comments \u2013 wpDiscuz plugin for WordPress is vulnerable t
CVE-2026-8804 (Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise ...)
- ruby-puppet-resource-api 2.0.1-1 (bug #1141432)
[trixie] - ruby-puppet-resource-api <no-dsa> (Minor issue)
+ [bookworm] - ruby-puppet-resource-api <postponed> (Minor issue; local-only cleartext exposure, values land in the 0640 root-owned $vardir/state/transactionstore.yaml, and only for provider modules written against the Resource API that declare sensitive parameters)
NOTE: https://github.com/puppetlabs/puppet-resource_api/pull/384
NOTE: Fixed by: https://github.com/puppetlabs/puppet-resource_api/commit/87737def98e5b299fcd78b198159bca88be991e7 (v1.9.2)
CVE-2026-8351 (The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
@@ -26062,18 +26065,24 @@ CVE-2026-56790 (CANBoat through 6.22, fixed in commit a5a22b7, contains an off-b
CVE-2026-56789 (RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in ...)
- rtklib <unfixed> (bug #1140766)
[trixie] - rtklib <no-dsa> (Minor issue)
+ [bookworm] - rtklib <postponed> (Minor issue; unclamped RINEX epoch satellite count leads to out-of-bounds access in readrnxobsb, requires processing an attacker-supplied RINEX observation file)
+ [bullseye] - rtklib <postponed> (Minor issue; unclamped RINEX epoch satellite count leads to out-of-bounds access in readrnxobsb, requires processing an attacker-supplied RINEX observation file)
NOTE: https://github.com/tomojitakasu/RTKLIB/issues/796
CVE-2026-56788 (RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in g ...)
- rtklib <unfixed> (bug #1140766)
[trixie] - rtklib <no-dsa> (Minor issue)
+ [bullseye] - rtklib <postponed> (Minor issue; codepris[i][-1] over-read on an unrecognised observation code, requires processing an attacker-supplied RINEX observation file)
NOTE: https://github.com/tomojitakasu/RTKLIB/issues/797
CVE-2026-56787 (RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnera ...)
- rtklib <unfixed> (bug #1140766)
[trixie] - rtklib <no-dsa> (Minor issue)
+ [bullseye] - rtklib <postponed> (Minor issue; one-element global over-read of the codes_* tables in decode_ssr3, requires an attacker-controlled RTCM3/NTRIP correction stream)
NOTE: https://github.com/tomojitakasu/RTKLIB/issues/798
CVE-2026-56786 (RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in ...)
- rtklib <unfixed> (bug #1140766)
[trixie] - rtklib <no-dsa> (Minor issue)
+ [bookworm] - rtklib <postponed> (Minor issue; the decode_type1033 overflow past the 64-byte sta_t descriptor fields consists only of strncpy NUL padding, no attacker-controlled bytes escape the field, and it requires an attacker-controlled RTCM3/NTRIP correction stream)
+ [bullseye] - rtklib <postponed> (Minor issue; the decode_type1033 overflow past the 64-byte sta_t descriptor fields consists only of strncpy NUL padding, no attacker-controlled bytes escape the field, and it requires an attacker-controlled RTCM3/NTRIP correction stream)
NOTE: https://github.com/tomojitakasu/RTKLIB/issues/799
CVE-2026-56779 (MaxKB before 2.10.0 contains a server-side request forgery vulnerabili ...)
NOT-FOR-US: MaxKB
@@ -27824,14 +27833,20 @@ CVE-2026-55488 (motionEye (mEye) is an online interface for a piece of software
CVE-2026-54906 (concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7 ...)
- ruby-concurrent 1.3.7-1
[trixie] - ruby-concurrent <no-dsa> (Minor issue)
+ [bookworm] - ruby-concurrent <postponed> (Minor issue; requires an application to release a ReadWriteLock it does not hold via the manual acquire_*/release_* API, and the upstream fix changes release_read_lock/release_write_lock to raise IllegalOperationError)
+ [bullseye] - ruby-concurrent <postponed> (Minor issue; requires an application to release a ReadWriteLock it does not hold via the manual acquire_*/release_* API, and the upstream fix changes release_read_lock/release_write_lock to raise IllegalOperationError)
NOTE: https://github.com/ruby-concurrency/concurrent-ruby/security/advisories/GHSA-6wx8-w4f5-wwcr
CVE-2026-54905 (concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7 ...)
- ruby-concurrent 1.3.7-1
[trixie] - ruby-concurrent <no-dsa> (Minor issue)
+ [bookworm] - ruby-concurrent <postponed> (Minor issue; requires 32768 reentrant read acquisitions on one thread before the per-thread hold count overflows into WRITE_LOCK_HELD)
+ [bullseye] - ruby-concurrent <postponed> (Minor issue; requires 32768 reentrant read acquisitions on one thread before the per-thread hold count overflows into WRITE_LOCK_HELD)
NOTE: https://github.com/ruby-concurrency/concurrent-ruby/security/advisories/GHSA-wv3x-4vxv-whpp
CVE-2026-54904 (concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7 ...)
- ruby-concurrent 1.3.7-1
[trixie] - ruby-concurrent <no-dsa> (Minor issue)
+ [bookworm] - ruby-concurrent <postponed> (Minor issue; requires an application to store Float::NAN in a Concurrent::AtomicReference and then call #update on it)
+ [bullseye] - ruby-concurrent <postponed> (Minor issue; requires an application to store Float::NAN in a Concurrent::AtomicReference and then call #update on it)
NOTE: https://github.com/ruby-concurrency/concurrent-ruby/security/advisories/GHSA-h8w8-99g7-qmvj
CVE-2026-54699 (Warp is an agentic development environment. From 0.2024.03.12.08.02.st ...)
NOT-FOR-US: Warp
@@ -27886,6 +27901,8 @@ CVE-2026-50698 (A Stored Cross-Site Scripting (XSS) vulnerability exists in Frap
CVE-2026-49980 (Rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1140817)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue; requires an rclone rcd --rc-serve listener reachable by the attacker without rc HTTP auth)
+ [bullseye] - rclone <postponed> (Limited support, minor issue; requires an rclone rcd --rc-serve listener reachable by the attacker without rc HTTP auth)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv
CVE-2026-49851 (Mistune is a Python Markdown parser with renderers and plugins. Prior ...)
- mistune <unfixed> (bug #1141770)
@@ -29401,6 +29418,8 @@ CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed> (bug #1141534)
[trixie] - pypy3 <no-dsa> (Minor issue)
+ [bookworm] - pypy3 <postponed> (Minor issue; CPU DoS in tarfile._Stream.seek() looping over attacker-declared block count past EOF, needs a crafted archive opened in streaming mode)
+ [bullseye] - pypy3 <postponed> (Minor issue; CPU DoS in tarfile._Stream.seek() looping over attacker-declared block count past EOF, needs a crafted archive opened in streaming mode)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/
NOTE: https://github.com/python/cpython/issues/151981
NOTE: https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec (3.14)
@@ -29914,6 +29933,8 @@ CVE-2026-0864 (When using the "configparser" module to write configuration files
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed> (bug #1141524)
[trixie] - pypy3 <no-dsa> (Minor issue)
+ [bookworm] - pypy3 <postponed> (Minor issue; configparser._write_section() escapes only LF, so CR/CRLF in a value injects config lines on write-back)
+ [bullseye] - pypy3 <postponed> (Minor issue; configparser._write_section() escapes only LF, so CR/CRLF in a value injects config lines on write-back)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/
NOTE: https://github.com/python/cpython/issues/143927
NOTE: https://github.com/python/cpython/pull/152003 (3.14)
@@ -30033,6 +30054,8 @@ CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar' filter could be b
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed> (bug #1141533)
[trixie] - pypy3 <no-dsa> (Minor issue)
+ [bookworm] - pypy3 <not-affected> (Extraction filters (PEP 706) absent in the embedded CPython stdlib; tarfile.extractall() has no filter parameter)
+ [bullseye] - pypy3 <not-affected> (Extraction filters (PEP 706) absent in the embedded CPython stdlib; tarfile.extractall() has no filter parameter)
NOTE: https://github.com/python/cpython/issues/151558
NOTE: https://github.com/python/cpython/pull/151559
NOTE: https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df (3.15 branch)
@@ -30513,6 +30536,8 @@ CVE-2026-53550 (js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 a
CVE-2026-53540 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- python-multipart <unfixed> (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
+ [bookworm] - python-multipart <postponed> (Minor issue; negative Content-Length unvalidated in parse_form(), which starlette/fastapi do not use)
+ [bullseye] - python-multipart <postponed> (Minor issue; negative Content-Length unvalidated in parse_form(), which starlette/fastapi do not use)
NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-v9pg-7xvm-68hf
NOTE: https://github.com/Kludex/python-multipart/pull/297
NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/c814948acf509cef7881fa75c969969b19239bbf (0.0.31)
@@ -30524,11 +30549,15 @@ CVE-2026-53539 (Python-Multipart is a streaming multipart parser for Python. Pri
CVE-2026-53538 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- python-multipart <unfixed> (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
+ [bookworm] - python-multipart <postponed> (Minor issue; parser differential, QuerystringParser accepts ';' as a urlencoded field separator)
+ [bullseye] - python-multipart <postponed> (Minor issue; parser differential, QuerystringParser accepts ';' as a urlencoded field separator)
NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-6jv3-5f52-599m
NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8 (0.0.30)
CVE-2026-53537 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- python-multipart <unfixed> (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
+ [bookworm] - python-multipart <not-affected> (parse_options_header uses a custom regex with no RFC 2231/5987 decoding; email.message.Message introduced in 0.0.7)
+ [bullseye] - python-multipart <not-affected> (parse_options_header uses a custom regex with no RFC 2231/5987 decoding; email.message.Message introduced in 0.0.7)
NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-vffw-93wf-4j4q
NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/3506c15ce99cb62faf2d5ceb3c4c1e5800cb843d (0.0.30)
CVE-2026-52725 (Angular is a development platform for building mobile and desktop web ...)
@@ -31605,6 +31634,8 @@ CVE-2025-15661 (libssh2 through 1.11.1, fixed in commit 2dae302, contains an out
CVE-2026-55766 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.12.1-1
[trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [bookworm] - php-guzzlehttp-psr7 <postponed> (Minor issue; CR/LF accepted in method/protocol-version/reason-phrase)
+ [bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue; CR/LF accepted in method/protocol-version/reason-phrase)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-vm85-hxw5-5432
CVE-2026-48931 (A flaw in Node.js HTTP Agent can cause a client to accept as valid a r ...)
- nodejs 24.17.0+dfsg+~cs24.13.2-1
@@ -32055,16 +32086,19 @@ CVE-2024-24769 (vantage6 is an open-source infrastructure for privacy preserving
CVE-2026-9697 (Impact: undici's ProxyAgent silently drops the requestTls option when ...)
- node-undici 8.5.0+dfsg+~cs3.2.0-1 (bug #1140363)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <not-affected> (SOCKS5 proxy support not present; Socks5ProxyAgent introduced in 7.23.0)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g
CVE-2026-9690 (Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-9679 (Impact: undici's cookie parser in parseSetCookie percent-decodes cooki ...)
- node-undici 8.5.0+dfsg+~cs3.2.0-1 (bug #1140363)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <not-affected> (parseSetCookie does not percent-decode cookie values; querystring unescape() introduced in 7.0.0)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv
CVE-2026-9678 (Impact: Undici's cache interceptor incorrectly classifies some respons ...)
- node-undici 8.5.0+dfsg+~cs3.2.0-1 (bug #1140363)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <not-affected> (Cache interceptor not present; interceptors.cache() introduced in 7.0.0)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6
CVE-2026-9675 (Impact: The undici WebSocket client enforces maxPayloadSize per-frame ...)
- node-undici <not-affected> (Vulnerable code not present)
@@ -32089,10 +32123,12 @@ CVE-2026-7300 (Buffer Copy without Checking Size of Input ('Classic Buffer Overf
CVE-2026-6734 (Impact: When using Socks5ProxyAgent, undici reuses a single connection ...)
- node-undici 8.5.0+dfsg+~cs3.2.0-1 (bug #1140363)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <not-affected> (SOCKS5 proxy support not present; Socks5ProxyAgent introduced in 7.23.0)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj
CVE-2026-6733 (Impact: Undici's HTTP/1.1 client is vulnerable to response queue poiso ...)
- node-undici 8.5.0+dfsg+~cs3.2.0-1 (bug #1140363)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue; requires an attacker-controlled upstream HTTP/1.1 server and keep-alive socket reuse)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52
CVE-2026-5667 (Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Roo ...)
NOT-FOR-US: Mitsubishi
@@ -32502,6 +32538,7 @@ CVE-2026-12165 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell wit
CVE-2026-12151 (Impact: The undici WebSocket client enforces maxPayloadSize on the cum ...)
- node-undici 8.5.0+dfsg+~cs3.2.0-1 (bug #1140363)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue; requires connecting to an attacker-controlled WebSocket endpoint, and the WebSocket API is experimental in 5.15.0)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q
CVE-2026-12115 (The Counter Box \u2013 Add Countdowns, Timers & Dynamic Counters to Wo ...)
NOT-FOR-US: WordPress plugin
@@ -32514,6 +32551,7 @@ CVE-2026-11857 (Quanos SCHEMA ST4 on-premises contains a local privilege escalat
CVE-2026-11525 (Impact: When undici parses a Set-Cookie header, it accepts any SameSit ...)
- node-undici 8.5.0+dfsg+~cs3.2.0-1 (bug #1140363)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue; impact limited to consumers that forward the parsed sameSite attribute)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m
CVE-2026-11311 (When NGINX Plus is configured as the data plane for NGINX Gateway Fabr ...)
NOT-FOR-US: NGINX Gateway Fabric
@@ -35821,6 +35859,7 @@ CVE-2026-28742 (Naxclow devices use a uniform request-signing scheme based on a
CVE-2026-1836 (The system stores the username and password from the login form after ...)
- redmine <unfixed> (bug #1140483)
[trixie] - redmine <no-dsa> (Minor issue)
+ [bookworm] - redmine <postponed> (Minor issue; credential-bearing responses lack Cache-Control: no-store, exposure limited to local access to the victim's browser cache)
NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/stored-credentials-redmine
CVE-2026-12143 (form-data is a library for creating readable multipart/form-data strea ...)
- node-form-data 4.0.6+~2.1.0-1 (bug #1139959)
@@ -36449,22 +36488,32 @@ CVE-2026-44692 (Sharp is a content management framework built for Laravel as a p
CVE-2026-44496 (Axios is a promise based HTTP client for the browser and Node.js. Axio ...)
- node-axios 1.16.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <postponed> (Minor issue; browser-only XSRF cookie read, needs an attacker-controlled xsrfCookieName)
+ [bullseye] - node-axios <postponed> (Minor issue; browser-only XSRF cookie read, needs an attacker-controlled xsrfCookieName)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf
CVE-2026-44495 (Axios is a promise based HTTP client for the browser and Node.js. From ...)
- node-axios 1.15.2-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <postponed> (Minor issue; prototype-pollution gadget, needs a separate pollution primitive in the same process)
+ [bullseye] - node-axios <postponed> (Minor issue; prototype-pollution gadget, needs a separate pollution primitive in the same process)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
CVE-2026-44494 (Axios is a promise based HTTP client for the browser and Node.js. From ...)
- node-axios 1.16.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <postponed> (Minor issue; prototype-pollution gadget, needs a separate pollution primitive in the same process)
+ [bullseye] - node-axios <postponed> (Minor issue; prototype-pollution gadget, needs a separate pollution primitive in the same process)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-35jp-ww65-95wh
CVE-2026-44492 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
- node-axios 1.16.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <not-affected> (Vulnerable code not present, shouldBypassProxy() introduced in 1.15.0)
+ [bullseye] - node-axios <postponed> (Minor issue; NO_PROXY host matching does not normalise IPv4-mapped IPv6 addresses)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv
CVE-2026-44490 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
- node-axios 1.16.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <postponed> (Minor issue; prototype-pollution gadget in utils.merge(), needs a separate pollution primitive in the same process)
+ [bullseye] - node-axios <postponed> (Minor issue; prototype-pollution gadget in utils.merge(), needs a separate pollution primitive in the same process)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-898c-q2cr-xwhg
CVE-2026-44489 (Axios is a promise based HTTP client for the browser and Node.js. From ...)
- node-axios 1.16.0-1
@@ -36475,14 +36524,20 @@ CVE-2026-44489 (Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44488 (Axios is a promise based HTTP client for the browser and Node.js. Axio ...)
- node-axios 1.16.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <not-affected> (Vulnerable code not present, fetch adapter introduced in 1.7.0)
+ [bullseye] - node-axios <not-affected> (Vulnerable code not present, fetch adapter introduced in 1.7.0)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-777c-7fjr-54vf
CVE-2026-44487 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
- node-axios 1.16.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <postponed> (Minor issue; needs an authenticated proxy and a redirect to an unproxied target)
+ [bullseye] - node-axios <not-affected> (Vulnerable code not present, per-redirect proxy re-resolution in setProxy() introduced in 1.x)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v
CVE-2026-44486 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
- node-axios 1.16.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
+ [bookworm] - node-axios <postponed> (Minor issue; needs an authenticated proxy and a redirect to an unproxied target)
+ [bullseye] - node-axios <not-affected> (Vulnerable code not present, per-redirect proxy re-resolution in setProxy() introduced in 1.x)
NOTE: https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc
CVE-2026-42568 (Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.1 ...)
NOT-FOR-US: Yamcs
@@ -42288,10 +42343,14 @@ CVE-2026-28318 (SolarWinds Serv-U is susceptible to specially crafted POST reque
CVE-2026-26825 (A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 whe ...)
- r-cran-readxl <unfixed> (bug #1139808)
[trixie] - r-cran-readxl <no-dsa> (Minor issue)
+ [bookworm] - r-cran-readxl <postponed> (Minor issue; uninitialized heap from the bundled libxls OLE layer reaches xls_parseWorkBook(), only via an attacker-supplied .xls; unfixed upstream)
+ [bullseye] - r-cran-readxl <postponed> (Minor issue; uninitialized heap from the bundled libxls OLE layer reaches xls_parseWorkBook(), only via an attacker-supplied .xls; unfixed upstream)
NOTE: https://github.com/libxls/libxls/issues/156
CVE-2026-26824 (libxls through version 1.6.3 contains a use of uninitialized memory vu ...)
- r-cran-readxl <unfixed> (bug #1139808)
[trixie] - r-cran-readxl <no-dsa> (Minor issue)
+ [bookworm] - r-cran-readxl <postponed> (Minor issue; uninitialized MSAT from read_MSAT() read by ole2_validate_sector_chain() in the bundled libxls, only via an attacker-supplied .xls; unfixed upstream)
+ [bullseye] - r-cran-readxl <postponed> (Minor issue; uninitialized MSAT from read_MSAT() read by ole2_validate_sector_chain() in the bundled libxls, only via an attacker-supplied .xls; unfixed upstream)
NOTE: https://github.com/libxls/libxls/issues/155
CVE-2026-25551 (Seagull Software BarTender 2021 R1 through 12.0.1contains an insecure ...)
NOT-FOR-US: Seagull Software BarTender
@@ -54895,6 +54954,8 @@ CVE-2026-44212 (PrestaShop is an open source e-commerce web application. Prior t
CVE-2026-43996 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- openimageio <unfixed> (bug #1139915)
[trixie] - openimageio <no-dsa> (Minor issue)
+ [bookworm] - openimageio <not-affected> (The wrapping palette bounds check in TGAInput::decode_pixel was introduced in 2.4.8.1 by the CVE-2023-22845 fix; palette_alloc_size not present)
+ [bullseye] - openimageio <not-affected> (The wrapping palette bounds check in TGAInput::decode_pixel was introduced in 2.4.8.1 by the CVE-2023-22845 fix; palette_alloc_size not present)
NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-mq8j-73c4-cr55
CVE-2026-43909 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- openimageio <unfixed> (bug #1139915)
@@ -54915,6 +54976,8 @@ CVE-2026-43906 (OpenImageIO is a toolset for reading, writing, and manipulating
CVE-2026-43905 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- openimageio <unfixed> (bug #1139915)
[trixie] - openimageio <no-dsa> (Minor issue)
+ [bookworm] - openimageio <not-affected> (HTJ2K/OpenJPH decoder introduced in 3.0.11.0; built against OpenJPEG only, USE_OPENJPH code path not present)
+ [bullseye] - openimageio <not-affected> (HTJ2K/OpenJPH decoder introduced in 3.0.11.0; built against OpenJPEG only, USE_OPENJPH code path not present)
NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-pj45-cf3g-28gq
CVE-2026-43904 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- openimageio <unfixed> (bug #1139915)
@@ -70434,6 +70497,8 @@ CVE-2026-41180 (PsiTransfer is an open source, self-hosted file sharing solution
CVE-2026-41179 (Rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1134735)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue; requires an rclone rc listener reachable by the attacker without rc HTTP auth)
+ [bullseye] - rclone <not-affected> (Inline backend option overrides via connection strings introduced in 1.55.0; operations/fsinfo in 1.53.3 cannot instantiate an attacker-defined backend)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-jfwf-28xr-xw6q
NOTE: https://github.com/rclone/rclone/commit/9e3e68d00c3ecf475a1432fc206400cfb4df7e3f (v1.74.0)
CVE-2026-41177 (Squidex is an open source headless content management system and conte ...)
@@ -70441,6 +70506,8 @@ CVE-2026-41177 (Squidex is an open source headless content management system and
CVE-2026-41176 (Rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1134734)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue; requires an rclone rc listener reachable by the attacker without rc HTTP auth)
+ [bullseye] - rclone <postponed> (Limited support, minor issue; requires an rclone rc listener reachable by the attacker without rc HTTP auth)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-25qr-6mpr-f7qx
NOTE: https://github.com/rclone/rclone/commit/06aa958ad6fd18ac14b9de9b5066ae09880196b1 (v1.74.0)
NOTE: https://github.com/rclone/rclone/commit/08490972a53e4e838a594a4ccbe8fbac8c4815e3 (v1.74.0)
@@ -106927,6 +106994,8 @@ CVE-2020-37183 (Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stac
CVE-2020-37182 (Redir 3.3 contains a stack overflow vulnerability in the doproxyconnec ...)
- redir <unfixed>
[trixie] - redir <no-dsa> (Minor issue)
+ [bookworm] - redir <postponed> (Minor issue; the overflowed connect_str is only ever set from the operator's own -x/--connect command line argument, never from network input)
+ [bullseye] - redir <postponed> (Minor issue; the overflowed connect_str is only ever set from the operator's own -x/--connect command line argument, never from network input)
NOTE: https://www.exploit-db.com/exploits/47919
NOTE: Fixed by: https://github.com/troglobit/redir/commit/372c792e9d320012490d8eca170f0462a92013fa (master)
CVE-2020-37181 (Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnera ...)
=====================================
data/dla-needed.txt
=====================================
@@ -571,6 +571,23 @@ openexr
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260713: Also add for bookworm (Beuc/front-desk)
--
+openimageio
+ NOTE: 20260726: Added by Front-Desk (utkarsh)
+ NOTE: 20260726: Six memory-corruption flaws in image readers that are
+ NOTE: 20260726: built by default and reached by decoding an untrusted
+ NOTE: 20260726: file: CVE-2026-43903, CVE-2026-43904, CVE-2026-43906,
+ NOTE: 20260726: CVE-2026-43907, CVE-2026-43908 and CVE-2026-43909.
+ NOTE: 20260726: Fixed upstream in 3.0.18.0/3.1.13.0; the vulnerable code
+ NOTE: 20260726: is identical in bullseye 2.2.10.1, bookworm 2.4.7.1 and
+ NOTE: 20260726: trixie, so one backport serves all. Sponsored in bookworm.
+ NOTE: 20260726: CVE-2026-43996 and CVE-2026-43905 are not-affected in both
+ NOTE: 20260726: LTS suites and are already tagged.
+ NOTE: 20260726: Also fix the postponed CVE-2026-7582, CVE-2024-55194 and
+ NOTE: 20260726: CVE-2024-55193 in the same upload.
+ NOTE: 20260726: Should be fixed for trixie too, which ships an affected
+ NOTE: 20260726: 2.5.18.0. Note trixie also lacks USE_OPENJPH, so it looks
+ NOTE: 20260726: not-affected by CVE-2026-43905. (utkarsh/front-desk)
+--
openjdk-11/bullseye (Emilio)
NOTE: 20260724: Added by pochu
--
@@ -672,6 +689,22 @@ python-geopandas/bookworm
NOTE: 20260725: Should be fixed for trixie too, which still ships an
NOTE: 20260725: affected 1.0.1-2. (utkarsh/front-desk)
--
+python-git
+ NOTE: 20260726: Added by Front-Desk (utkarsh)
+ NOTE: 20260726: CVE-2026-42215 bypasses the check_unsafe_options guard
+ NOTE: 20260726: that DLA-3939-1 itself backported, so our own earlier fix
+ NOTE: 20260726: is incomplete; same class as CVE-2023-40267 (DLA-3502-1,
+ NOTE: 20260726: DLA-3939-1). Sponsored in both LTS suites and the code is
+ NOTE: 20260726: shared, so one backport serves both.
+ NOTE: 20260726: Also fix CVE-2026-42284, CVE-2026-44243 and CVE-2026-44244
+ NOTE: 20260726: in the same upload; upstream fixes are in 3.1.47, 3.1.48
+ NOTE: 20260726: and 3.1.49.
+ NOTE: 20260726: bullseye ships 3.1.14-1+deb11u1 and is affected despite
+ NOTE: 20260726: being below the upstream >= 3.1.30 range, because
+ NOTE: 20260726: DLA-3939-1 backported the guard in its pre-3.1.47 form.
+ NOTE: 20260726: Should be fixed for trixie too, which still ships an
+ NOTE: 20260726: affected 3.1.44-1. (utkarsh/front-desk)
+--
python-httplib2 (eamanu)
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-59939 (fixed 0.32.0); Debian <=0.20.4 affected.
@@ -761,6 +794,22 @@ shim/bullseye (Emilio)
NOTE: 20260715: the update will happen once bullseye becomes ELTS since
NOTE: 20260715: it adds Freexian's CA (pochu)
--
+shiro
+ NOTE: 20260726: Added by Front-Desk (utkarsh)
+ NOTE: 20260726: CVE-2026-56091: SimpleFilterChainResolver in shiro-guice
+ NOTE: 20260726: does not normalise a trailing slash, so a request for
+ NOTE: 20260726: /path/ bypasses a "/path = authc" chain entirely. Debian
+ NOTE: 20260726: does build and ship shiro-guice (support/guice/pom.xml is
+ NOTE: 20260726: --java-lib in debian/libshiro-java.poms), so the code is
+ NOTE: 20260726: reachable; the fix is small and applies to 1.3.2.
+ NOTE: 20260726: bullseye 1.3.2-4+deb11u1 and bookworm 1.3.2-5 carry
+ NOTE: 20260726: byte-identical patch series, so one backport serves both.
+ NOTE: 20260726: Also fix the other open issues in the same upload,
+ NOTE: 20260726: notably CVE-2026-49268 (LDAP DN injection via an
+ NOTE: 20260726: unescaped userDnTemplate) and CVE-2026-56130.
+ NOTE: 20260726: Should be fixed for trixie too, which ships the same
+ NOTE: 20260726: affected 1.3.2. (utkarsh/front-desk)
+--
smb4k/bullseye
NOTE: 20251217: Added by Front-Desk (pochu)
NOTE: 20260531: bookworm EOL.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1cd7ab22c78eceaad5559685212ccbaca83aad90...dad512002348e07a2cb6dd7c1548b5a8a773e414
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1cd7ab22c78eceaad5559685212ccbaca83aad90...dad512002348e07a2cb6dd7c1548b5a8a773e414
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/a1b2a1b8/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list