[Git][security-tracker-team/security-tracker][master] Add new rust-rouille issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 28 21:25:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ca6fcb41 by Salvatore Bonaccorso at 2026-07-28T22:23:45+02:00
Add new  rust-rouille issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -27,9 +27,11 @@ CVE-2026-67184 (TinyWeb through 0.0.8 contains a null pointer dereference vulner
 CVE-2026-67183 (TinyWeb through 0.0.8 contains a memory leak vulnerability that allows ...)
 	NOT-FOR-US: TinyWeb
 CVE-2026-67182 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
-	TODO: check
+	- rust-rouille <unfixed>
+	TODO: check upstream details
 CVE-2026-67181 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
-	TODO: check
+	- rust-rouille <unfixed>
+	TODO: check upstream details
 CVE-2026-67178 (MISP installation scripts generated an Apache HTTP virtual-host config ...)
 	NOT-FOR-US: MISP
 CVE-2026-67174 (Pivotick contains a DOM-based cross-site scripting vulnerability in it ...)
@@ -49,7 +51,8 @@ CVE-2026-66918 (Pivotick fails to sanitize attacker-controlled SVG markup suppli
 CVE-2026-66913 (Lookyloo did not enforce limits on the decompressed size of uploaded c ...)
 	NOT-FOR-US: Lookyloo
 CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerabili ...)
-	TODO: check
+	- rust-rouille <unfixed>
+	TODO: check upstream status
 CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
 	TODO: check
 CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
@@ -63,7 +66,8 @@ CVE-2026-66749 (Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulne
 CVE-2026-66748 (Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated re ...)
 	NOT-FOR-US: Camaleon CMS
 CVE-2026-66746 (Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulner ...)
-	TODO: check
+	- rust-rouille <unfixed>
+	TODO: check upstream status
 CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 202607 ...)
 	NOT-FOR-US: Artica Proxy
 CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the Tribes-based cluste ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca6fcb41d2d1f07f50b52f9e144a6886f39ff07e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca6fcb41d2d1f07f50b52f9e144a6886f39ff07e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/b51f100e/attachment.htm>


More information about the debian-security-tracker-commits mailing list