[Git][security-tracker-team/security-tracker][master] Mark CVE-2026-34827 CVE-2026-34835 as not-affected for bookworm

Abhijith PA (@abhijith) abhijith at debian.org
Sun Jul 26 07:53:52 BST 2026



Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b92af8c6 by Abhijith PA at 2026-07-26T12:20:32+05:30
Mark CVE-2026-34827 CVE-2026-34835 as not-affected for bookworm
bullseye. Vulnerable code introduced from 3.x series.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -82092,6 +82092,8 @@ CVE-2026-34876 (An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-
 CVE-2026-34835 (Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 ...)
 	[experimental] - ruby-rack 3.2.6-1
 	- ruby-rack 3.2.6-2
+	[bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
+	[bullseye] - ruby-rack <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/rack/rack/security/advisories/GHSA-g2pf-xv49-m2h5
 	NOTE: Fixed by: https://github.com/rack/rack/commit/224662608dad63b31ba138d7e76e4ca8e42e9fc6 (v3.2.6)
 	NOTE: Fixed by: https://github.com/rack/rack/commit/c49558af795b4c1978d16db071c8344db05a2b0d (v3.1.21)
@@ -82121,6 +82123,8 @@ CVE-2026-34828 (listmonk is a standalone, self-hosted, newsletter and mailing li
 CVE-2026-34827 (Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 ...)
 	[experimental] - ruby-rack 3.2.6-1
 	- ruby-rack 3.2.6-2
+	[bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
+	[bullseye] - ruby-rack <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/rack/rack/security/advisories/GHSA-v6x5-cg8r-vv6x
 	NOTE: Fixed by: https://github.com/rack/rack/commit/bfb69142dbe2a1e3298ad52d12935938d1b58205 (v3.2.6)
 	NOTE: Fixed by: https://github.com/rack/rack/commit/17ce7836be1523a7b453f3c06fe070ad7c954708 (v3.1.21)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b92af8c6a85363899b4d142d4baa06aee6b6d234

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b92af8c6a85363899b4d142d4baa06aee6b6d234
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/fd33d549/attachment.htm>


More information about the debian-security-tracker-commits mailing list