[Git][security-tracker-team/security-tracker][master] Track fixes via unstable for jupyterlab issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 05:20:51 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
17182aea by Salvatore Bonaccorso at 2026-07-29T06:20:13+02:00
Track fixes via unstable for jupyterlab issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -58241,7 +58241,7 @@ CVE-2026-42561 (Python-Multipart is a streaming multipart parser for Python. Pri
 	NOTE: https://github.com/Kludex/python-multipart/pull/267
 	NOTE: https://github.com/Kludex/python-multipart/commit/3e64f5f8caba0e5d391b0c1ad0f1c2edf9e8f911 (0.0.27)
 CVE-2026-42557 (jupyterlab is an extensible environment for interactive and reproducib ...)
-	- jupyterlab <unfixed>
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-3
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg
 CVE-2026-42552 (Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the  ...)
 	NOT-FOR-US: Flight
@@ -58264,7 +58264,7 @@ CVE-2026-42406 (A vulnerability exists in BIG-IP and BIG-IQ systems where a high
 CVE-2026-42290 (protobufjs-cli is the command line add-on for protobuf.js. Prior to 1. ...)
 	NOT-FOR-US: protobufjs-cli
 CVE-2026-42266 (JupyterLab is an extensible environment for interactive and reproducib ...)
-	- jupyterlab <unfixed>
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-3
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4
 CVE-2026-42063 (A vulnerability exists in iControl SOAP where an authenticated attacke ...)
 	NOT-FOR-US: F5
@@ -63911,7 +63911,7 @@ CVE-2026-40171 (In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab ver
 	[trixie] - jupyter-notebook <not-affected> (Vulnerable code not present, introduced in 7.0)
 	[bookworm] - jupyter-notebook <not-affected> (Vulnerable code not present, introduced in 7.0)
 	[bullseye] - jupyter-notebook <not-affected> (Vulnerable code not present, introduced in 7.0)
-	- jupyterlab <unfixed>
+	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-3
 	NOTE: https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9
 	NOTE: https://github.com/jupyter/notebook/commit/50e5222c9670121c3369900c7dce01aae53823fc
 CVE-2026-40076 (OpenMRS Core is an open source electronic medical record system platfo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17182aeac07a3d11033625d92670ed1691c1461c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/17182aeac07a3d11033625d92670ed1691c1461c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/16bf390c/attachment.htm>


More information about the debian-security-tracker-commits mailing list