[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 20:13:02 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a7704169 by security tracker role at 2026-07-29T19:12:56+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,12 +1,360 @@
-CVE-2026-64560 [posix-cpu-timers: Prevent UAF caused by non-leader exec() race]
+CVE-2026-9720 (The Facturaci\xf3n Electr\xf3nica Costa Rica plugin for WordPress is v ...)
+	TODO: check
+CVE-2026-9177 (A Server-Side Template Injection (SSTI) vulnerability was identified   ...)
+	TODO: check
+CVE-2026-8791 (The Booking System Trafft plugin for WordPress is vulnerable to Stored ...)
+	TODO: check
+CVE-2026-8497 (Improper certificate validation in the Devolutions Server connection h ...)
+	TODO: check
+CVE-2026-8339 (A SQL injection vulnerability exists in the Coverity Connect SOAP API  ...)
+	TODO: check
+CVE-2026-8338 (A Spring Security authentication and authorization bypass exists in Co ...)
+	TODO: check
+CVE-2026-7436 (The WPC Badge Management for WooCommerce plugin for WordPress is vulne ...)
+	TODO: check
+CVE-2026-6089 (The WP CTA plugin for WordPress is vulnerable to Server-Side Request F ...)
+	TODO: check
+CVE-2026-67429 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
+	TODO: check
+CVE-2026-67428 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
+	TODO: check
+CVE-2026-67427 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
+	TODO: check
+CVE-2026-67426 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
+	TODO: check
+CVE-2026-67425 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
+	TODO: check
+CVE-2026-67424 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
+	TODO: check
+CVE-2026-67217 (cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomic ...)
+	TODO: check
+CVE-2026-67216 (cJSON through 1.7.19 contains an inefficient algorithmic complexity fl ...)
+	TODO: check
+CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading t ...)
+	TODO: check
+CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...)
+	TODO: check
+CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...)
+	TODO: check
+CVE-2026-67201 (V through 0.5.2, fixed in commit 85859f0, contains a server-side reque ...)
+	TODO: check
+CVE-2026-67194 (Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow a ...)
+	TODO: check
+CVE-2026-67193 (Xlight FTP Server before 3.9.5 contains an information disclosure vuln ...)
+	TODO: check
+CVE-2026-67192 (Xlight FTP Server before 3.9.5 contains a pre-authentication stack buf ...)
+	TODO: check
+CVE-2026-67191 (Xlight FTP Server before 3.9.5 contains a pre-authentication heap buff ...)
+	TODO: check
+CVE-2026-67188
+	REJECTED
+CVE-2026-66737
+	REJECTED
+CVE-2026-66724 (MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization ...)
+	TODO: check
+CVE-2026-66723 (MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization ...)
+	TODO: check
+CVE-2026-66490 (Joomla Extension - balbooa.com - Stored cross-site scripting via a com ...)
+	TODO: check
+CVE-2026-66489 (Joomla Extension - balbooa.com - Various unauthenticated file system d ...)
+	TODO: check
+CVE-2026-66488 (Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2)
+	TODO: check
+CVE-2026-66400 (Grav Login Plugin versions before 3.8.13 contain an insufficient sessi ...)
+	TODO: check
+CVE-2026-66051
+	REJECTED
+CVE-2026-65947 (Joomla Extension - balbooa.com - Various CSRF vectors in the admin int ...)
+	TODO: check
+CVE-2026-65946 (Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers ...)
+	TODO: check
+CVE-2026-65944 (Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handler ...)
+	TODO: check
+CVE-2026-65943 (Joomla Extension - rolandd.com - Unauthenticated directory creation RO ...)
+	TODO: check
+CVE-2026-65891 (Joomla Extension - joomlacontenteditor.net - Creation of hidden files  ...)
+	TODO: check
+CVE-2026-65890 (Joomla Extension - balbooa.com - Unauthenticated SQL injection in Grid ...)
+	TODO: check
+CVE-2026-65889 (Joomla Extension - balbooa.com - Unauthenticated recursive directory d ...)
+	TODO: check
+CVE-2026-65888 (Joomla Extension - balbooa.com - Account takeover vulnerability in Gri ...)
+	TODO: check
+CVE-2026-65887 (Joomla Extension - balbooa.com - Unauthenticated arbitrary password re ...)
+	TODO: check
+CVE-2026-65886 (Joomla Extension - balbooa.com - Unauthenticated arbitrary file read i ...)
+	TODO: check
+CVE-2026-65885 (Joomla Extension - balbooa.com - Authenticated arbitrary file upload i ...)
+	TODO: check
+CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.2 ...)
+	TODO: check
+CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object injection  ...)
+	TODO: check
+CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin connections wit ...)
+	TODO: check
+CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when dechunking  ...)
+	TODO: check
+CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table before co ...)
+	TODO: check
+CVE-2026-64557 (In the Linux kernel, the following vulnerability has been resolved:  B ...)
+	TODO: check
+CVE-2026-64556 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
+	TODO: check
+CVE-2026-62995 (joserfc is a Python library that provides an implementation of several ...)
+	TODO: check
+CVE-2026-60113 (AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface befo ...)
+	TODO: check
+CVE-2026-60112 (AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing aut ...)
+	TODO: check
+CVE-2026-5060 (The MasterStudy LMS WordPress Plugin \u2013 for Online Courses and Edu ...)
+	TODO: check
+CVE-2026-59920 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59919 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59901 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59900 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59899 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59898 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-59247 (Insufficient Verification of Data Authenticity vulnerability in Gleam  ...)
+	TODO: check
+CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted `verify_signatur ...)
+	TODO: check
+CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when plugins reset  ...)
+	TODO: check
+CVE-2026-58188 (Several Apache Traffic Server experimental plugins have memory-safety  ...)
+	TODO: check
+CVE-2026-58187 (The Apache Traffic Server multiplexer plugin overruns its chunk-decode ...)
+	TODO: check
+CVE-2026-58186 (The Apache Traffic Server webp_transform plugin can decode unsafely an ...)
+	TODO: check
+CVE-2026-58185 (The Apache Traffic Server intercept plugin has a use-after-free.  This ...)
+	TODO: check
+CVE-2026-58184 (The Apache Traffic Server header_rewrite plugin can crash or corrupt m ...)
+	TODO: check
+CVE-2026-58183 (The Apache Traffic Server prefetch plugin can crash when processing at ...)
+	TODO: check
+CVE-2026-58182 (The Apache Traffic Server ts_lua plugin mishandles initialization, tra ...)
+	TODO: check
+CVE-2026-58181 (The Apache Traffic Server uri_signing and url_sig plugins can exhaust  ...)
+	TODO: check
+CVE-2026-58180 (The Apache Traffic Server txn_box plugin overflows the stack from atta ...)
+	TODO: check
+CVE-2026-58179 (The Apache Traffic Server regex_remap plugin overflows the stack and i ...)
+	TODO: check
+CVE-2026-58178 (The Apache Traffic Server ESI plugin can recurse without bound and fet ...)
+	TODO: check
+CVE-2026-58177 (The Apache Traffic Server Cripts framework has out-of-bounds writes, p ...)
+	TODO: check
+CVE-2026-58175 (Apache Traffic Server leaks memory when handling HostDB SRV records.   ...)
+	TODO: check
+CVE-2026-58164 (Apache Traffic Server has use-after-free and time-of-check/time-of-use ...)
+	TODO: check
+CVE-2026-58163 (Apache Traffic Server mishandles on-disk cache fields and object lifet ...)
+	TODO: check
+CVE-2026-58162 (The Apache Traffic Server certifier plugin generates certificates base ...)
+	TODO: check
+CVE-2026-58161 (Apache Traffic Server can crash from null dereferences and dangling re ...)
+	TODO: check
+CVE-2026-58160 (Apache Traffic Server reads out of bounds while parsing DNS answers.   ...)
+	TODO: check
+CVE-2026-58159 (Apache Traffic Server can bypass IP access controls on UDS listeners a ...)
+	TODO: check
+CVE-2026-58158 (Apache Traffic Server mishandles PROXY protocol input, truncating port ...)
+	TODO: check
+CVE-2026-58157 (Apache Traffic Server can reuse server sessions and tunnels improperly ...)
+	TODO: check
+CVE-2026-58156 (Apache Traffic Server mis-parses ports in URLs and userinfo, allowing  ...)
+	TODO: check
+CVE-2026-58155 (Apache Traffic Server truncates over-long header names, allowing heade ...)
+	TODO: check
+CVE-2026-58154 (Apache Traffic Server can write out of bounds or overflow integers whi ...)
+	TODO: check
+CVE-2026-58153 (Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 client ...)
+	TODO: check
+CVE-2026-58152 (Apache Traffic Server mishandles integers while decoding HPACK/XPACK h ...)
+	TODO: check
+CVE-2026-58151 (Apache Traffic Server can be crashed or driven to resource exhaustion  ...)
+	TODO: check
+CVE-2026-58150 (Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requ ...)
+	TODO: check
+CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked messages are ...)
+	TODO: check
+CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output paths. Gramma ...)
+	TODO: check
+CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program during HTML  ...)
+	TODO: check
+CVE-2026-55995 (A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...)
+	TODO: check
+CVE-2026-54735 (Prebid Server is an open-source solution for running real-time adverti ...)
+	TODO: check
+CVE-2026-54727 (proot-distro is a utility for managing proot containers. Prior to vers ...)
+	TODO: check
+CVE-2026-54705 (MathLive provides web components for math display and input. Prior to  ...)
+	TODO: check
+CVE-2026-54693 (ZITADEL is an open source identity management platform. From 2.43.0 th ...)
+	TODO: check
+CVE-2026-54680 (Logging operator automates the deployment and configuration of Kuberne ...)
+	TODO: check
+CVE-2026-54666 (swagger-typescript-api generates API clients for Fetch or Axios from a ...)
+	TODO: check
+CVE-2026-54664 (swagger-typescript-api generates API clients for Fetch or Axios from a ...)
+	TODO: check
+CVE-2026-54663 (swagger-typescript-api generates API clients for Fetch or Axios from O ...)
+	TODO: check
+CVE-2026-54662 (swagger-typescript-api generates API clients for Fetch or Axios from O ...)
+	TODO: check
+CVE-2026-54661 (swagger-typescript-api generates API clients for Fetch or Axios from a ...)
+	TODO: check
+CVE-2026-54660 (swagger-typescript-api generates API clients for Fetch or Axios from O ...)
+	TODO: check
+CVE-2026-54574 (proot-distro is a utility for managing proot containers. Prior to vers ...)
+	TODO: check
+CVE-2026-54082 (veraPDF validation model is an implementation of the veraPDF validatio ...)
+	TODO: check
+CVE-2026-54081 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1. ...)
+	TODO: check
+CVE-2026-54080 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1. ...)
+	TODO: check
+CVE-2026-54079 (veraPDF validation provides PDF/A and PDF/UA validation, feature repor ...)
+	TODO: check
+CVE-2026-54078 (veraPDF validation model is an implementation of the veraPDF validatio ...)
+	TODO: check
+CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for rootless  ...)
+	TODO: check
+CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8  ...)
+	TODO: check
+CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize non\u2011SGR termin ...)
+	TODO: check
+CVE-2026-50641 (Streamsoft Business Intelligence (BI) stores users' passwords in plain ...)
+	TODO: check
+CVE-2026-50622 (Description: Missing Authorizationin Apache Atlas. A missing authoriza ...)
+	TODO: check
+CVE-2026-50558 (Penelope Shell Handler is a post-exploitation shell handler for author ...)
+	TODO: check
+CVE-2026-4604 (The Klubraum Membership Request plugin for WordPress is vulnerable to  ...)
+	TODO: check
+CVE-2026-44944 (An Incorrect Authorization vulnerability in open-iscsi allowsunprivili ...)
+	TODO: check
+CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory ('Path  ...)
+	TODO: check
+CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vuln ...)
+	TODO: check
+CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
+	TODO: check
+CVE-2026-40272 (Improper Input Validation in the decode() function of the traceparser  ...)
+	TODO: check
+CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS PROFINET ...)
+	TODO: check
+CVE-2026-33930 (Apache Traffic Server copies the client Host header into a fixed-size  ...)
+	TODO: check
+CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick.CMS.  ...)
+	TODO: check
+CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
+	TODO: check
+CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
+	TODO: check
+CVE-2026-24033 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
+	TODO: check
+CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the request path a ...)
+	TODO: check
+CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache Traffic Ser ...)
+	TODO: check
+CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall Manageme ...)
+	TODO: check
+CVE-2026-18257 (Improper validity period check for root issuer certificate in CycloneC ...)
+	TODO: check
+CVE-2026-18255 (A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_U ...)
+	TODO: check
+CVE-2026-18236 (A vulnerability in the Agent Development Kit (ADK) allows for continua ...)
+	TODO: check
+CVE-2026-18220 (An out-of-bounds write vulnerability was found in the BFD library's DL ...)
+	TODO: check
+CVE-2026-18207 (A flaw was found in the client policy enforcement mechanism of Keycloa ...)
+	TODO: check
+CVE-2026-18201 (Keycloak provides a way to manage identity providers and organizations ...)
+	TODO: check
+CVE-2026-18197 (Improper neutralization of input during web page generation ('cross-si ...)
+	TODO: check
+CVE-2026-18192 (VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerabi ...)
+	TODO: check
+CVE-2026-18191 (VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerabi ...)
+	TODO: check
+CVE-2026-18174 (@fastify/forwarded resolves client addresses from the X-Forwarded-For  ...)
+	TODO: check
+CVE-2026-17550 (A maliciously crafted DWG or DXF file, when parsed through Autodesk Au ...)
+	TODO: check
+CVE-2026-16751 (Authorization Bypass in the emergency recovery approval component in E ...)
+	TODO: check
+CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
+	TODO: check
+CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
+	TODO: check
+CVE-2026-16597 (The GTM4WP \u2013 A Google Tag Manager (GTM) plugin for WordPress plug ...)
+	TODO: check
+CVE-2026-16543 (Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allo ...)
+	TODO: check
+CVE-2026-16465 (A maliciously crafted DWG or DXF file, when parsed through Autodesk Au ...)
+	TODO: check
+CVE-2026-16463 (A maliciously crafted DXF file, when parsed through Autodesk AutoCAD,  ...)
+	TODO: check
+CVE-2026-16328 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how  ...)
+	TODO: check
+CVE-2026-16326 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isol ...)
+	TODO: check
+CVE-2026-15228 (Kong Kubernetes Ingress Controller (KIC) allows a user with namespace- ...)
+	TODO: check
+CVE-2026-15144 (@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verba ...)
+	TODO: check
+CVE-2026-14900 (The Cost Calculator Builder PRO plugin for WordPress is vulnerable to  ...)
+	TODO: check
+CVE-2026-14529 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+	TODO: check
+CVE-2026-14488 (The Meta Box AIO plugin for WordPress is vulnerable to Missing Authori ...)
+	TODO: check
+CVE-2026-14354 (CWE-522 Insufficiently Protected Credentials vulnerability exists that ...)
+	TODO: check
+CVE-2026-14270 (The Extra Checkout Options (addon for Extra Product Options & Add-Ons  ...)
+	TODO: check
+CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Develar's ap ...)
+	TODO: check
+CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
+	TODO: check
+CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
+	TODO: check
+CVE-2026-13346 (pip would incorrectly handle doubly-encoded package URLs from indexes  ...)
+	TODO: check
+CVE-2026-12935 (The TL-WR940N v6 router contains a vulnerability in its RTSP connectio ...)
+	TODO: check
+CVE-2026-12927 (CWE-787 Out-of-bounds write vulnerability exists that could cause loss ...)
+	TODO: check
+CVE-2026-12895 (SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frapp ...)
+	TODO: check
+CVE-2026-12703 (TeamViewer Full Client and Hostfor macOS before version 15.80containa  ...)
+	TODO: check
+CVE-2026-11973 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable to gene ...)
+	TODO: check
+CVE-2026-10684 (In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used t ...)
+	TODO: check
+CVE-2026-0667 (CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerab ...)
+	TODO: check
+CVE-2025-60931 (An Insecure Direct Object Reference (IDOR) in the Employee Compensatio ...)
+	TODO: check
+CVE-2025-10656 (The Spreadsheet Price Changer for WooCommerce and WP E-commerce \u2013 ...)
+	TODO: check
+CVE-2026-64560 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
 	- linux 7.1.5-1
 	NOTE: https://git.kernel.org/linus/920f893f735e92ba3a1cd9256899a186b161928d (7.2-rc3)
-CVE-2026-64559 [s390/pkey: Check length in PKEY_VERIFYPROTK ioctl]
+CVE-2026-64559 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.5-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/b3d4ab2d7df9426f7f1d3671d7e2108f2ca6e970 (7.2-rc1)
-CVE-2026-64558 [s390/pkey: Check length in pkey_pckmo handler implementation]
+CVE-2026-64558 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.5-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -1585,7 +1933,7 @@ CVE-2026-17529 (A vulnerability was identified in AstrBotDevs AstrBot up to 4.25
 	NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-17527 (In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:v ...)
 	NOT-FOR-US: Red Hat Red Hat OpenShift Virtualization
-CVE-2026-17523 (A flaw was found in the kernel. An unprivileged local user can exploit ...)
+CVE-2026-17523 (A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, whe ...)
 	TODO: check
 CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. ...)
 	NOT-FOR-US: ZJONSSON node-unzipper
@@ -12455,7 +12803,7 @@ CVE-2024-23565 (HCL Aftermarket EPC is vulnerable to email flooding as the appli
 	NOT-FOR-US: HCL
 CVE-2024-23564 (HCL Aftermarket EPC is affected by Business Logic Vulnerability using  ...)
 	NOT-FOR-US: HCL
-CVE-2026-14266
+CVE-2026-14266 (7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Executio ...)
 	- 7zip 26.02+dfsg-1 (bug #1142293)
 	- p7zip 16.02+transitional.1
 	[bookworm] - p7zip <postponed> (Wait for 7zip-26.02/trixie SPU approval, then backport)
@@ -13387,7 +13735,8 @@ CVE-2026-62685 (File Browser is a file managing interface for uploading, deletin
 	NOT-FOR-US: File Browser
 CVE-2026-62683 (File Browser is a file managing interface for uploading, deleting, pre ...)
 	NOT-FOR-US: File Browser
-CVE-2026-62389 (ws before 8.21.1 contains a memory exhaustion vulnerability in lib/rec ...)
+CVE-2026-62389
+	REJECTED
 	- node-ws 8.21.1+~cs14.19.1-1 (bug #1142271)
 	NOTE: https://github.com/websockets/ws/issues/2331
 	NOTE: Fixed by: https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d (8.21.1)
@@ -23593,7 +23942,7 @@ CVE-2026-11562 (The WS Form LITE  WordPress plugin before 1.11.8 does not have a
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11546 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i ...)
 	NOT-FOR-US: IBM
-CVE-2026-11541 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+CVE-2026-11541 (IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10. ...)
 	NOT-FOR-US: IBM
 CVE-2026-11380 (The JetWidgets For Elementor plugin for WordPress is vulnerable to Sto ...)
 	NOT-FOR-US: WordPress plugin
@@ -87311,11 +87660,13 @@ CVE-2026-33284 (GlobaLeaks is free and open-source whistleblowing software. Prio
 CVE-2026-33280 (Hidden functionality issue exists in BUFFALO Wi-Fi router products, wh ...)
 	NOT-FOR-US: BUFFALO
 CVE-2026-33206 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
+	{DLA-4705-1}
 	- calibre 9.6.0+ds+~0.10.5-1
 	[trixie] - calibre 8.5.0+ds-1+deb13u3
 	[bookworm] - calibre 6.13.0+repack-2+deb12u8
 	NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-h3p4-m74f-43g6
 CVE-2026-33205 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
+	{DLA-4705-1}
 	- calibre 9.6.0+ds+~0.10.5-1
 	[trixie] - calibre 8.5.0+ds-1+deb13u3
 	[bookworm] - calibre 6.13.0+repack-2+deb12u9
@@ -95557,6 +95908,7 @@ CVE-2026-30915 (SFTPGo is an open source, event-driven file transfer solution. S
 CVE-2026-30914 (SFTPGo is an open source, event-driven file transfer solution. In SFTP ...)
 	- sftpgo <itp> (bug #1050829)
 CVE-2026-30853 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
+	{DLA-4705-1}
 	- calibre 9.5.0+ds+~0.10.5-1
 	[trixie] - calibre 8.5.0+ds-1+deb13u3
 	[bookworm] - calibre 6.13.0+repack-2+deb12u8
@@ -101831,11 +102183,13 @@ CVE-2026-27836 (phpMyFAQ is an open source FAQ web application. Prior to version
 CVE-2026-27832 (Group-Office is an enterprise customer relationship management and gro ...)
 	NOT-FOR-US: Group-Office
 CVE-2026-27824 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
+	{DLA-4705-1}
 	- calibre 9.4.0+ds+~0.10.5-1
 	[trixie] - calibre 8.5.0+ds-1+deb13u2
 	[bookworm] - calibre 6.13.0+repack-2+deb12u6
 	NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vhxc-r7v8-2xrw
 CVE-2026-27810 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
+	{DLA-4705-1}
 	- calibre 9.4.0+ds+~0.10.5-1
 	[trixie] - calibre 8.5.0+ds-1+deb13u2
 	[bookworm] - calibre 6.13.0+repack-2+deb12u6



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a770416927ec81e95c639d7b5e574e73a80ce60f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a770416927ec81e95c639d7b5e574e73a80ce60f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/e0baf813/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list