[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 28 20:14:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1ee63e60 by security tracker role at 2026-07-28T19:14:11+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,325 @@
+CVE-2026-9680 (Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-se ...)
+ TODO: check
+CVE-2026-8167 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-8164 (Uncontrolled Search Path Element vulnerability in ArkSigner Software a ...)
+ TODO: check
+CVE-2026-8058 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060. ...)
+ TODO: check
+CVE-2026-7868 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060. ...)
+ TODO: check
+CVE-2026-7775 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6 ...)
+ TODO: check
+CVE-2026-7769 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through ...)
+ TODO: check
+CVE-2026-7521 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6 ...)
+ TODO: check
+CVE-2026-7362 (IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 thr ...)
+ TODO: check
+CVE-2026-7187 (Missing authentication for critical function vulnerability in Universa ...)
+ TODO: check
+CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O ...)
+ TODO: check
+CVE-2026-67185 (TinyWeb through 0.0.8 contains a path traversal vulnerability that all ...)
+ TODO: check
+CVE-2026-67184 (TinyWeb through 0.0.8 contains a null pointer dereference vulnerabilit ...)
+ TODO: check
+CVE-2026-67183 (TinyWeb through 0.0.8 contains a memory leak vulnerability that allows ...)
+ TODO: check
+CVE-2026-67182 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
+ TODO: check
+CVE-2026-67181 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
+ TODO: check
+CVE-2026-67178 (MISP installation scripts generated an Apache HTTP virtual-host config ...)
+ TODO: check
+CVE-2026-67174 (Pivotick contains a DOM-based cross-site scripting vulnerability in it ...)
+ TODO: check
+CVE-2026-67173 (Pivotick did not validate the URL scheme of node imagePath values deri ...)
+ TODO: check
+CVE-2026-66922 (Pivotick used plain JavaScript objects as lookup tables indexed by cal ...)
+ TODO: check
+CVE-2026-66921 (Pivotick\u2019s Markdown node-reference renderer failed to HTML-escape ...)
+ TODO: check
+CVE-2026-66920 (Pivotick contains an uncontrolled-recursion vulnerability when process ...)
+ TODO: check
+CVE-2026-66919 (Pivotick contains a cross-site scripting vulnerability in the inspect ...)
+ TODO: check
+CVE-2026-66918 (Pivotick fails to sanitize attacker-controlled SVG markup supplied thr ...)
+ TODO: check
+CVE-2026-66913 (Lookyloo did not enforce limits on the decompressed size of uploaded c ...)
+ TODO: check
+CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerabili ...)
+ TODO: check
+CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
+ TODO: check
+CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
+ TODO: check
+CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vuln ...)
+ TODO: check
+CVE-2026-66750 (Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulner ...)
+ TODO: check
+CVE-2026-66749 (Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerabili ...)
+ TODO: check
+CVE-2026-66748 (Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated re ...)
+ TODO: check
+CVE-2026-66746 (Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulner ...)
+ TODO: check
+CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 202607 ...)
+ TODO: check
+CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the Tribes-based cluste ...)
+ TODO: check
+CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat's Web ...)
+ TODO: check
+CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdl ...)
+ TODO: check
+CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default configuration allows ...)
+ TODO: check
+CVE-2026-65880 (Joomla Extension - balbooa.com - Unauthenticated remote code execution ...)
+ TODO: check
+CVE-2026-65624 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
+ TODO: check
+CVE-2026-63727 (Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an ...)
+ TODO: check
+CVE-2026-63303 (A Path Traversal vulnerability exists in Quick.CMS through the URI pat ...)
+ TODO: check
+CVE-2026-63302 (Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php ...)
+ TODO: check
+CVE-2026-63301 (In Quick.CMS, the administrative user interface restricts deletion of ...)
+ TODO: check
+CVE-2026-62828 (Improper input validation in Microsoft Edge for Android allows an unau ...)
+ TODO: check
+CVE-2026-61609 (Pterodactyl is a free, open-source game server management panel. From ...)
+ TODO: check
+CVE-2026-61487 (Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ...)
+ TODO: check
+CVE-2026-61376 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
+ TODO: check
+CVE-2026-5114 (The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File R ...)
+ TODO: check
+CVE-2026-59933 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
+ TODO: check
+CVE-2026-59932 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
+ TODO: check
+CVE-2026-59931 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
+ TODO: check
+CVE-2026-59878 (Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apach ...)
+ TODO: check
+CVE-2026-59764 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
+ TODO: check
+CVE-2026-59248 (Allocation of resources without limits vulnerability in ninenines cowl ...)
+ TODO: check
+CVE-2026-58246 (SAP NetWeaver Application Server for ABAP and ABAP Platform writes sen ...)
+ TODO: check
+CVE-2026-55977 (Successful exploitation of this vulnerability could allow an attacker ...)
+ TODO: check
+CVE-2026-54635 (pytonapi is a Python SDK for TONAPI that provides REST API, streaming, ...)
+ TODO: check
+CVE-2026-54620 (sqlite3 provides Ruby bindings for the SQLite3 embedded database. From ...)
+ TODO: check
+CVE-2026-54619 (sqlite3 provides Ruby bindings for the SQLite3 embedded database. In v ...)
+ TODO: check
+CVE-2026-54609 (QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer prot ...)
+ TODO: check
+CVE-2026-54605 (OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providin ...)
+ TODO: check
+CVE-2026-54603 (OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frame ...)
+ TODO: check
+CVE-2026-54593 (Pterodactyl is a free, open-source game server management panel. Prior ...)
+ TODO: check
+CVE-2026-54545 (wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 u ...)
+ TODO: check
+CVE-2026-54345 (gopacket provides packet processing capabilities for Go. In version 1. ...)
+ TODO: check
+CVE-2026-54332 (gopacket provides packet processing capabilities for Go. In version 1. ...)
+ TODO: check
+CVE-2026-51275 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in ...)
+ TODO: check
+CVE-2026-51274 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in ...)
+ TODO: check
+CVE-2026-51273 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-51271 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-51270 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-51269 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-51268 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-51267 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-51266 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-51263 (schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. Th ...)
+ TODO: check
+CVE-2026-51261 (Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfa ...)
+ TODO: check
+CVE-2026-51260 (Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of sch ...)
+ TODO: check
+CVE-2026-51259 (Unchecked unsigned integer overflow in buffer size calculation in schr ...)
+ TODO: check
+CVE-2026-51254 (schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerabil ...)
+ TODO: check
+CVE-2026-51252 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability ...)
+ TODO: check
+CVE-2026-51251 (Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability ...)
+ TODO: check
+CVE-2026-50738 (A use-after-free condition exists in pglogical's worker signaling code ...)
+ TODO: check
+CVE-2026-50737 (When applying replicated changes for a row that is missing one or more ...)
+ TODO: check
+CVE-2026-50736 (The pglogical queue mechanism, used to convey out-of-band commands suc ...)
+ TODO: check
+CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the length of ...)
+ TODO: check
+CVE-2026-4932 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 thro ...)
+ TODO: check
+CVE-2026-4912 (The Media Cleaner: Clean your WordPress! plugin for WordPress is vulne ...)
+ TODO: check
+CVE-2026-4648 (Use of an insecure cryptographic algorithm in the cashless payment sys ...)
+ TODO: check
+CVE-2026-49332 (A flaw was found in openshift/oauth-proxy. The proxy sets authenticate ...)
+ TODO: check
+CVE-2026-49258 (Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh V ...)
+ TODO: check
+CVE-2026-48396 (Bridge is affected by an Incorrect Authorization vulnerability that co ...)
+ TODO: check
+CVE-2026-48395 (Bridge is affected by an Untrusted Search Path vulnerability that coul ...)
+ TODO: check
+CVE-2026-48394 (Bridge is affected by an out-of-bounds write vulnerability that could ...)
+ TODO: check
+CVE-2026-48393 (Bridge is affected by an out-of-bounds write vulnerability that could ...)
+ TODO: check
+CVE-2026-48392 (Bridge is affected by an out-of-bounds write vulnerability that could ...)
+ TODO: check
+CVE-2026-48391 (Bridge is affected by an Untrusted Search Path vulnerability that coul ...)
+ TODO: check
+CVE-2026-48390 (Bridge is affected by an Incorrect Authorization vulnerability that co ...)
+ TODO: check
+CVE-2026-48388 (Adobe Photoshop Installer was affected by an Uncontrolled Search Path ...)
+ TODO: check
+CVE-2026-48374 (Bridge is affected by an Improper Limitation of a Pathname to a Restri ...)
+ TODO: check
+CVE-2026-48372 (Format Plugins is affected by a Heap-based Buffer Overflow vulnerabili ...)
+ TODO: check
+CVE-2026-48058 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+ TODO: check
+CVE-2026-48025 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+ TODO: check
+CVE-2026-47768 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+ TODO: check
+CVE-2026-47726 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+ TODO: check
+CVE-2026-47725 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+ TODO: check
+CVE-2026-47483 (NVIDIA DCGM Exporter for all platforms contains a vulnerability in the ...)
+ TODO: check
+CVE-2026-47427 (GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the ...)
+ TODO: check
+CVE-2026-45293 (WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) ...)
+ TODO: check
+CVE-2026-44387 (ELECOM wireless LAN routers and access points devices contain a reflec ...)
+ TODO: check
+CVE-2026-43910 (Appium Java Client is the Java language binding for writing Appium tes ...)
+ TODO: check
+CVE-2026-41874 (Quick.Cart stores hard-coded, plaintext admin credentials in a configu ...)
+ TODO: check
+CVE-2026-21047 (Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allo ...)
+ TODO: check
+CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences (rseq) du ...)
+ TODO: check
+CVE-2026-18085 (An Improper Input Validation in the BlackBerry UEMManagementConsoleofB ...)
+ TODO: check
+CVE-2026-18084 (Improper Neutralization of Input During Web Page Generation vulnerabil ...)
+ TODO: check
+CVE-2026-18047 (A flaw was found in Dogtag PKI's ACME responder where the web.xml secu ...)
+ TODO: check
+CVE-2026-18038 (A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affecte ...)
+ TODO: check
+CVE-2026-18029 (Our payment integration with GiroCheckout did not properly validate p ...)
+ TODO: check
+CVE-2026-18028 (The "quick setup" view presented to users after they first create an ...)
+ TODO: check
+CVE-2026-17072 (A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of- ...)
+ TODO: check
+CVE-2026-16774 (The Chatbot plugin for WordPress is vulnerable to Missing Authorizatio ...)
+ TODO: check
+CVE-2026-16773 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation, AI Serv ...)
+ TODO: check
+CVE-2026-16771 (In firmware versions 2.7.7 and earlier, the Arris BGW210\u2011700 gate ...)
+ TODO: check
+CVE-2026-16498 (The terraform-mcp-server before version 1.1.0 is vulnerable to a cross ...)
+ TODO: check
+CVE-2026-16496 (The terraform-mcp-server before version 1.1.0 is vulnerable to an auth ...)
+ TODO: check
+CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitiz ...)
+ TODO: check
+CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...)
+ TODO: check
+CVE-2026-15992 (The WP Password Policy plugin for WordPress is vulnerable to Privilege ...)
+ TODO: check
+CVE-2026-15730 (The GamiPress \u2013 Gamification plugin to reward points, achievement ...)
+ TODO: check
+CVE-2026-15673 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications & ...)
+ TODO: check
+CVE-2026-15671 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications & ...)
+ TODO: check
+CVE-2026-15670 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications & ...)
+ TODO: check
+CVE-2026-15444 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
+ TODO: check
+CVE-2026-15411 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, ...)
+ TODO: check
+CVE-2026-15393 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 60 ...)
+ TODO: check
+CVE-2026-15304 (The Plugin Organizer plugin for WordPress is vulnerable to SQL Injecti ...)
+ TODO: check
+CVE-2026-15267 (The Taskbuilder \u2013 Project Management & Task Management Tool With ...)
+ TODO: check
+CVE-2026-15025 (The Uncanny Automator \u2013 Easy Automation, Integration, Webhooks & ...)
+ TODO: check
+CVE-2026-15016 (The Paid Memberships Pro \u2013 Content Restriction, User Registration ...)
+ TODO: check
+CVE-2026-15014 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications & ...)
+ TODO: check
+CVE-2026-14869 (The terraform-mcp-server before version 1.1.0 is vulnerable to a serve ...)
+ TODO: check
+CVE-2026-14785 (The Web Directory Free plugin for WordPress is vulnerable to generic S ...)
+ TODO: check
+CVE-2026-14516 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)
+ TODO: check
+CVE-2026-14328 (The Eazy Plugin Manager \u2013 Powerful Plugin Management Solution for ...)
+ TODO: check
+CVE-2026-14171 (An unauthenticated remote attacker can abuse the improper validation o ...)
+ TODO: check
+CVE-2026-14170
+ REJECTED
+CVE-2026-14169 (Due to incorrect behavior order a low privileged remote attacker could ...)
+ TODO: check
+CVE-2026-14168 (A low privileged remote attacker can gain administrator privileges due ...)
+ TODO: check
+CVE-2026-14167 (A low privileged remote attacker can perform privileged configuration ...)
+ TODO: check
+CVE-2026-13440 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, ...)
+ TODO: check
+CVE-2026-13161 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin ...)
+ TODO: check
+CVE-2026-13110 (The Storegrowth Sales Booster plugin for WordPress is vulnerable to Mi ...)
+ TODO: check
+CVE-2026-12800 (The Premium Packages \u2013 Sell Digital Products Securely plugin for ...)
+ TODO: check
+CVE-2026-12741 (The WP Fast Total Search \u2013 The Power of Indexed Search plugin for ...)
+ TODO: check
+CVE-2026-11841 (An attacker may perform unauthenticated read and write operations on s ...)
+ TODO: check
+CVE-2026-11756 (A Deserialization of Untrusted Data vulnerability affecting Station La ...)
+ TODO: check
+CVE-2026-11598 (The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Sit ...)
+ TODO: check
+CVE-2026-10207 (The PickPlugins Question Answer plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2024-14041 (In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYS ...)
+ TODO: check
CVE-2026-59986
- librabbitmq 0.17.0-1
NOTE: https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jgjf-7fwf-f3c7
@@ -7,21 +329,27 @@ CVE-2026-61547
NOTE: https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
NOTE: Fixed by: https://github.com/alanxz/rabbitmq-c/commit/02d278663f3a93db9fe4fb4e7e34dc96b83c107b (v0.17.0)
CVE-2026-58224 [The CTDB protocol has bounds checking issues]
+ {DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58224-advisory.html
CVE-2026-58222 [Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes]
+ {DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58222-advisory.html
CVE-2026-58221 [Samba AD authenticated LDAP access domain takeover]
+ {DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58221-advisory.html
CVE-2026-58218 [DNS signing DoS via TKEY name cache exhaustion]
+ {DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58218-advisory.html
CVE-2026-58216 [An authenticated user could possibly crash a KDC process]
+ {DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58216-advisory.html
CVE-2026-6949 [TSIG packet with name compression can crash DNS]
+ {DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-6949-advisory.html
CVE-2026-6251 (The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time ...)
@@ -7002,6 +7330,7 @@ CVE-2026-10675 (In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bl
CVE-2026-10674 (The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-47010 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7010,6 +7339,7 @@ CVE-2026-47010 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-46917 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7018,6 +7348,7 @@ CVE-2026-46917 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-47021 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7026,6 +7357,7 @@ CVE-2026-47021 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-47027 (Vulnerability in Oracle Java SE (component: Libraries). Supported ver ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7034,6 +7366,7 @@ CVE-2026-47027 (Vulnerability in Oracle Java SE (component: Libraries). Support
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-47059 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7042,6 +7375,7 @@ CVE-2026-47059 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-46968 (Vulnerability in Oracle Java SE (component: JSSE). Supported versions ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7050,6 +7384,7 @@ CVE-2026-46968 (Vulnerability in Oracle Java SE (component: JSSE). Supported ve
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-60147 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7058,10 +7393,12 @@ CVE-2026-60147 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-47058 (Vulnerability in Oracle Java SE (component: Scripting). Supported ver ...)
+ {DLA-4702-1}
- openjdk-11 11.0.32+9-1
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-47063 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
+ {DLA-4703-1 DLA-4702-1}
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
- openjdk-21 21.0.12+8-1
@@ -7070,6 +7407,7 @@ CVE-2026-47063 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
CVE-2026-47057 (Vulnerability in Oracle Java SE (component: Scripting). Supported ver ...)
+ {DLA-4702-1}
- openjdk-11 11.0.32+9-1
- openjdk-8 <unfixed>
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
@@ -21425,7 +21763,7 @@ CVE-2026-4770 (Improper neutralization of input during web page generation ('cro
NOT-FOR-US: Web Application Firewall
CVE-2026-4767 (Missing authentication for critical function vulnerability in TR7 Cybe ...)
NOT-FOR-US: WAF-ASP
-CVE-2026-49779 (Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 version ...)
+CVE-2026-49779 (Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for Woo ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-44941 (A relative path traversal in the "keyhint" option in repomd.xml parsin ...)
- libzypp 17.38.12-1
@@ -39948,75 +40286,75 @@ CVE-2026-45447 (Issue summary: A specially crafted PKCS#7 or S/MIME signed messa
NOTE: https://openssl-library.org/news/secadv/20260609.txt
NOTE: Fixed by: https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54 (openssl-3.0.21)
NOTE: Fixed by: https://github.com/openssl/openssl/commit/18de9aba8294b5fb0915866cf3a1bb45f9599b8d (openssl-3.0.21)
-CVE-2026-62434
+CVE-2026-62434 (A guest started with Populated on Demand enabled (PoD) can attempt to ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-507.html
-CVE-2026-62433
+CVE-2026-62433 (Parts of the DM_OP handling code assumes the caller has provided the r ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-506.html
-CVE-2026-62432
+CVE-2026-62432 (The EVTCHNOP_expand_array hypercall checks for whether FIFO event chan ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-505.html
-CVE-2026-62431
+CVE-2026-62431 (The logic to handle periodic Viridian STIMERs performs a division with ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-504.html
-CVE-2026-62430
+CVE-2026-62430 (Accesses to the CMOS memory contents are done using an indirect IO por ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-503.html
-CVE-2026-62429
+CVE-2026-62429 (Accessing the vNUMA configuration data of a guest is still possible wh ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-502.html
-CVE-2026-62435
+CVE-2026-62435 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-501.html
-CVE-2026-62436
+CVE-2026-62436 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-501.html
-CVE-2026-62428
+CVE-2026-62428 (When grant-copy operations are processed, the respective grant may or ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-500.html
-CVE-2026-62426
+CVE-2026-62426 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-499.html
-CVE-2026-62427
+CVE-2026-62427 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-499.html
-CVE-2026-42494
+CVE-2026-42494 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-497.html
-CVE-2026-42495
+CVE-2026-42495 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-497.html
-CVE-2026-62423
+CVE-2026-62423 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-497.html
-CVE-2026-62424
+CVE-2026-62424 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-497.html
-CVE-2026-62425
+CVE-2026-62425 ([This CNA information record relates to multiple CVEs; the text explai ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-497.html
-CVE-2026-42492 [vIRQ event channel binding may break Xenstore]
+CVE-2026-42492 (Xenstore, to have an up-to-date picture of the entire system, wants to ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-496.html
-CVE-2026-42493 [x86 shadow paging is deprecated]
+CVE-2026-42493 (Addressing certain issues, in particular related to operations which m ...)
- xen <unfixed>
[bullseye] - xen <end-of-life> (out of LTS support)
NOTE: https://xenbits.xen.org/xsa/advisory-495.html
@@ -54228,11 +54566,11 @@ CVE-2026-9102 (A path traversal vulnerability exists in the Altium Enterprise Se
CVE-2026-9082 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: Drupal core and addons
CVE-2026-8632 (A potential security vulnerability has been identified in the HP Linux ...)
- {DLA-4699-1}
+ {DSA-6402-1 DLA-4699-1}
- hplip 3.26.4+dfsg0-1 (bug #1137374)
NOTE: https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118
CVE-2026-8631 (A potential security vulnerability has been identified in the HP Linux ...)
- {DLA-4699-1}
+ {DSA-6402-1 DLA-4699-1}
- hplip 3.26.4+dfsg0-1 (bug #1137374)
NOTE: https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118
CVE-2026-8399
@@ -75026,7 +75364,7 @@ CVE-2026-5250
CVE-2026-4801 (The Page Builder Gutenberg Blocks \u2013 CoBlocks plugin for WordPress ...)
NOT-FOR-US: WordPress plugin
CVE-2026-41254 (Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in ...)
- {DSA-6262-1 DLA-4568-1}
+ {DSA-6262-1 DLA-4703-1 DLA-4702-1 DLA-4568-1}
- lcms2 2.17-1.1 (bug #1134335)
- openjdk-26 26.0.2+10-1
- openjdk-25 25.0.4+7-1
@@ -93771,7 +94109,7 @@ CVE-2026-4285 (A vulnerability was identified in taoofagi easegen-admin up to 8f
NOT-FOR-US: taoofagi easegen-admin
CVE-2026-4284 (A vulnerability was determined in taoofagi easegen-admin up to 8f87936 ...)
NOT-FOR-US: taoofagi easegen-admin
-CVE-2026-4258 (All versions of the package sjcl are vulnerable to Improper Verificati ...)
+CVE-2026-4258 (Versions of the package sjcl before 1.0.9 are vulnerable to Improper V ...)
- node-sjcl <itp> (bug #924588)
CVE-2026-3237 (In affected versions of Octopus Server it was possible for a low privi ...)
NOT-FOR-US: Octopus Deploy
@@ -434030,7 +434368,7 @@ CVE-2022-3637 (A vulnerability has been found in Linux Kernel and classified as
- bluez <not-affected> (Vulnerable code introduced and fixed in between 5.64 and 5.65, no Debian release affected)
NOTE: Fixed by: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=1d6cfb8e625a944010956714c1802bc1e1fc6c4f (5.65)
NOTE: Introduced by: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=6f02010ce0043ec2e17eb15f2a1dd42f6c64e223 (5.65)
-CVE-2022-3636 (A vulnerability, which was classified as critical, was found in Linux ...)
+CVE-2022-3636 (A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f33 ...)
- linux <not-affected> (No vulnerable code in any upstream or Debian released version)
NOTE: https://git.kernel.org/linus/17a5f6a78dc7b8db385de346092d7d9f9dc24df6
CVE-2022-3635 (A vulnerability, which was classified as critical, has been found in L ...)
@@ -435410,7 +435748,7 @@ CVE-2022-42970 (A CWE-306: Missing Authentication for Critical Function The soft
NOT-FOR-US: Schneider
CVE-2022-3535
REJECTED
-CVE-2022-3534 (A vulnerability classified as critical has been found in Linux Kernel. ...)
+CVE-2022-3534 (A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/ ...)
{DLA-4137-1}
- libbpf 1.1.0-1 (bug #1023717)
NOTE: Introduced by: https://github.com/libbpf/libbpf/commit/7ac1547f32f060d84b06c74edbb2c6896cc07949 (v0.2)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1ee63e603ad931e61b38f8ddbece05bae94b3ae6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1ee63e603ad931e61b38f8ddbece05bae94b3ae6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/92becf1b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list