[Git][security-tracker-team/security-tracker][master] Add two new rust-tiny-http issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 28 21:38:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9c2ab721 by Salvatore Bonaccorso at 2026-07-28T22:37:52+02:00
Add two new rust-tiny-http issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -54,9 +54,11 @@ CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulne
- rust-rouille <unfixed>
TODO: check upstream status
CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
- TODO: check
+ - rust-tiny-http <unfixed>
+ TODO: check upstream status
CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
- TODO: check
+ - rust-tiny-http <unfixed>
+ TODO: check upstream status
CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vuln ...)
NOT-FOR-US: Let's Chat
CVE-2026-66750 (Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulner ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9c2ab721385421430f0c3d5907eab5d9a618687d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9c2ab721385421430f0c3d5907eab5d9a618687d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/70881d0e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list