[Git][security-tracker-team/security-tracker][master] Add three new weechat issues without CVE
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 29 05:32:50 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fbf4ec81 by Salvatore Bonaccorso at 2026-07-29T06:32:20+02:00
Add three new weechat issues without CVE
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,15 @@
+CVE-2026-XXXX [relay: use-after-free and double free when a remote relay sends an event with an array as body]
+ - weechat 4.9.5-1 (bug #1142894)
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-hx59-4hq9-6vmw
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-14/
+CVE-2026-XXXX [Use-after-free in the irc plugin when a batched message disconnects the server]
+ - weechat 4.9.5-1 (bug #1142894)
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-rfmh-3r7f-jpx5
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-13/
+CVE-2026-XXXX [Stack buffer overflow in irc_message_split_join when building a JOIN with keys]
+ - weechat 4.9.5-1 (bug #1142894)
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-q2xg-9ggx-77mr
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-12/
CVE-2026-9680 (Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-se ...)
NOT-FOR-US: alibabacloud-rds-openapi-mcp-server
CVE-2026-8167 (Improper neutralization of input during web page generation ('cross-si ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbf4ec81cbe00126a5269fd72c5ddc7f81416973
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbf4ec81cbe00126a5269fd72c5ddc7f81416973
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/2f8cb571/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list