[Git][security-tracker-team/security-tracker][master] Add two new rust-tiny-http issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 28 21:38:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9c2ab721 by Salvatore Bonaccorso at 2026-07-28T22:37:52+02:00
Add two new rust-tiny-http issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -54,9 +54,11 @@ CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulne
 	- rust-rouille <unfixed>
 	TODO: check upstream status
 CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
-	TODO: check
+	- rust-tiny-http <unfixed>
+	TODO: check upstream status
 CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
-	TODO: check
+	- rust-tiny-http <unfixed>
+	TODO: check upstream status
 CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vuln ...)
 	NOT-FOR-US: Let's Chat
 CVE-2026-66750 (Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulner ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9c2ab721385421430f0c3d5907eab5d9a618687d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9c2ab721385421430f0c3d5907eab5d9a618687d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/70881d0e/attachment.htm>


More information about the debian-security-tracker-commits mailing list