[Git][security-tracker-team/security-tracker][master] Add more trafficserver issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 29 22:51:12 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9140a4e9 by Salvatore Bonaccorso at 2026-07-29T23:50:46+02:00
Add more trafficserver issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -312,25 +312,30 @@ CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory (
CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vuln ...)
NOT-FOR-US: Care Everywhere Gateway
CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic Server. This ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-40272 (Improper Input Validation in the decode() function of the traceparser ...)
NOT-FOR-US: Blackberry
CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS PROFINET ...)
NOT-FOR-US: CODESYS
CVE-2026-33930 (Apache Traffic Server copies the client Host header into a fixed-size ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick.CMS. ...)
NOT-FOR-US: Quick.CMS
CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic Server. Thi ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
NOT-FOR-US: IBM
CVE-2026-24033 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the request path a ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache Traffic Ser ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall Manageme ...)
NOT-FOR-US: Cisco
CVE-2026-18257 (Improper validity period check for root issuer certificate in CycloneC ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9140a4e9a79f548a3fcd45b823c632cd5f8ad39b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9140a4e9a79f548a3fcd45b823c632cd5f8ad39b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/c63468c3/attachment.htm>
More information about the debian-security-tracker-commits
mailing list