[Git][security-tracker-team/security-tracker][master] Add more trafficserver issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 22:51:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9140a4e9 by Salvatore Bonaccorso at 2026-07-29T23:50:46+02:00
Add more trafficserver issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -312,25 +312,30 @@ CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory (
 CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vuln ...)
 	NOT-FOR-US: Care Everywhere Gateway
 CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-40272 (Improper Input Validation in the decode() function of the traceparser  ...)
 	NOT-FOR-US: Blackberry
 CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS PROFINET ...)
 	NOT-FOR-US: CODESYS
 CVE-2026-33930 (Apache Traffic Server copies the client Host header into a fixed-size  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick.CMS.  ...)
 	NOT-FOR-US: Quick.CMS
 CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
 	NOT-FOR-US: IBM
 CVE-2026-24033 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the request path a ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache Traffic Ser ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall Manageme ...)
 	NOT-FOR-US: Cisco
 CVE-2026-18257 (Improper validity period check for root issuer certificate in CycloneC ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9140a4e9a79f548a3fcd45b823c632cd5f8ad39b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9140a4e9a79f548a3fcd45b823c632cd5f8ad39b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/c63468c3/attachment.htm>


More information about the debian-security-tracker-commits mailing list