[Git][security-tracker-team/security-tracker][master] Add two new node-undici issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 22:55:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a3aa1b4a by Salvatore Bonaccorso at 2026-07-29T23:54:56+02:00
Add two new node-undici issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -365,7 +365,8 @@ CVE-2026-17550 (A maliciously crafted DWG or DXF file, when parsed through Autod
 CVE-2026-16751 (Authorization Bypass in the emergency recovery approval component in E ...)
 	NOT-FOR-US: Ente Technologies Ente Museum Server
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
-	TODO: check
+	- node-undici <unfixed>
+	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16597 (The GTM4WP \u2013 A Google Tag Manager (GTM) plugin for WordPress plug ...)
@@ -397,7 +398,8 @@ CVE-2026-14270 (The Extra Checkout Options (addon for Extra Product Options & Ad
 CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Develar's ap ...)
 	NOT-FOR-US: Develar app-builder
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
-	TODO: check
+	- node-undici <unfixed>
+	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13346 (pip would incorrectly handle doubly-encoded package URLs from indexes  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3aa1b4a2181ef91ad1933a7cc421361cde2e35c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3aa1b4a2181ef91ad1933a7cc421361cde2e35c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/80a04e1f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list