[Git][security-tracker-team/security-tracker][master] Add new erlang issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 28 10:00:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d538ff7a by Salvatore Bonaccorso at 2026-07-28T10:59:17+02:00
Add new erlang issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -722,9 +722,20 @@ CVE-2026-59528 (Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipp
 CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key certif ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-622p-qfh6-c352
+	NOTE: https://cna.erlef.org/cves/CVE-2026-59251.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-59251
+	NOTE: Introduced with: https://github.com/erlang/otp/commit/9d1dda7bad5a64b58c10a1554751689e94131a73 (OTP-26.2)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/f04c6bba38de1cf1b1836a7d9a9fbe239bd939e8 (OTP-27.3.4.15)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/f8580fc117098c08165f46c26fd0750c5cfb2a90 (OTP-29.0.4, OTP-28.5.0.4)
 CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7
+	NOTE: https://cna.erlef.org/cves/CVE-2026-59250.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-59250
+	NOTE: Introduced with: https://github.com/erlang/otp/commit/84adefa331c4159d432d22840663c38f155cd4c1 (OTP_R13B03)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/8704c8f550a11ed5f825e3c011ecb03565b79c4f (OTP-27.3.4.15, OTP-28.5.0.4, OTP-29.0.4)
 CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in the email module in Roskus Pro ...)
 	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-58662 (Improper Validation of Specified Quantity in Input, Out-of-bounds Read ...)
@@ -732,7 +743,13 @@ CVE-2026-58662 (Improper Validation of Specified Quantity in Input, Out-of-bound
 CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
 	TODO: check
 CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when reconstruct ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw
+	NOTE: https://cna.erlef.org/cves/CVE-2026-58227.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-58227
+	NOTE: Introduced with: https://github.com/erlang/otp/commit/addc42df113f8f15fc20e9dff45490b3ce0d3d6b (OTP-23.2)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/241d43703989fec4b6bf637beaeb366d92dcc4c2 (OTP-28.5.0.4)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/7db64720177961e04545681480d691c4be81c54d (OTP-29.0.4)
 CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.  Th ...)
 	TODO: check
 CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary crafted ...)
@@ -752,15 +769,32 @@ CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift C+
 CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources Without Li ...)
 	TODO: check
 CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not veri ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882
+	NOTE: https://cna.erlef.org/cves/CVE-2026-55953.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55953
+	NOTE: Introduced with: https://github.com/erlang/otp/commit/84adefa331c4159d432d22840663c38f155cd4c1 (OTP_R13B03)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/e6ff938116b2872bccc478af7fefb56627285b77 (OTP-27.3.4.15)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c (OTP-28.5.0.4)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b (OTP-29.0.4)
 CVE-2026-55737 (Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerabil ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462
+	NOTE: https://cna.erlef.org/cves/CVE-2026-55737.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55737
+	NOTE: Introduced with; https://github.com/erlang/otp/commit/ebcbb97b4ec223464cac3d94375739a248ddef6e (OTP-25.0-rc2)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761 (OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
 CVE-2026-55579 (Pheditor is a single-file editor and file manager written in PHP. From ...)
 	NOT-FOR-US: Pheditor
 CVE-2026-55578 (Pheditor is a single-file editor and file manager written in PHP. From ...)
 	NOT-FOR-US: Pheditor
 CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erl ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-54pw-5645-jh86
+	NOTE: https://cna.erlef.org/cves/CVE-2026-54890.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-54890
+	NOTE: Introduced with: https://github.com/erlang/otp/commit/24ef4cbaeda9b9c26682cba75f2f15b0c58722aa (OTP-27.0-rc1)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/dc1bf9344c0ce62717cf60866590cea0242780fd (OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
 CVE-2026-54540 (Pheditor is a single-file editor and file manager written in PHP. Prio ...)
 	NOT-FOR-US: Pheditor
 CVE-2026-54272 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
@@ -804,7 +838,12 @@ CVE-2026-48051 (Papra is a minimalistic document management and archiving platfo
 CVE-2026-48030 (Pheditor is a single-file editor and file manager written in PHP. From ...)
 	NOT-FOR-US: Pheditor
 CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-rf72-wp7h-jg3x
+	NOTE: https://cna.erlef.org/cves/CVE-2026-47078.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-47078
+	NOTE: Introduced with: https://github.com/erlang/otp/commit/8d537f51a4262d24f3395c4148323eaca9facbbd (OTP-27.1)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/8a933c9c7835b06776d31d17b79b7336627d887a (OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
 CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
 	- node-postcss 8.5.12+~cs9.3.32-1
 	NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-6g55-p6wh-862q
@@ -817,7 +856,11 @@ CVE-2026-45112 (Allocation of Resources Without Limits or Throttling vulnerabili
 CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
 	TODO: check
 CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erlang OT ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-h6f3-hx58-xhj6
+	NOTE: https://cna.erlef.org/cves/CVE-2026-42792.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-42792
+	NOTE: Fixed by; https://github.com/erlang/otp/commit/865d203e4a6a8f44179eced9e1428f9259e4a3bb (OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
 CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
 	TODO: check
 CVE-2026-40000 (The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d538ff7a901fdac7be32aea620e4f805d9beb3d0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d538ff7a901fdac7be32aea620e4f805d9beb3d0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/ba0a4ae5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list