[Git][security-tracker-team/security-tracker][master] Add Debian bug references for reported issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 08:04:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e31f795c by Salvatore Bonaccorso at 2026-07-30T09:04:05+02:00
Add Debian bug references for reported issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -27,13 +27,13 @@ CVE-2026-67425 (Flyto2 Core is an execution kernel for automation and AI-agent w
 CVE-2026-67424 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
 	NOT-FOR-US: Flyto2 Core
 CVE-2026-67217 (cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomic ...)
-	- cjson <unfixed>
+	- cjson <unfixed> (bug #1143048)
 	NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
 CVE-2026-67216 (cJSON through 1.7.19 contains an inefficient algorithmic complexity fl ...)
-	- cjson <unfixed>
+	- cjson <unfixed> (bug #1143048)
 	NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
 CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading t ...)
-	- cjson <unfixed>
+	- cjson <unfixed> (bug #1143048)
 	NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
 CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...)
 	- node-postcss 8.5.15+~cs9.3.39-1
@@ -103,13 +103,13 @@ CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege Escalation in Gridbox
 CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object injection  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin connections wit ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when dechunking  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table before co ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-64557 (In the Linux kernel, the following vulnerability has been resolved:  B ...)
 	- linux 7.1.5-1
@@ -129,116 +129,116 @@ CVE-2026-60112 (AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missi
 CVE-2026-5060 (The MasterStudy LMS WordPress Plugin \u2013 for Online Courses and Edu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-59920 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-3g8r-4pfx-jmfh
 CVE-2026-59919 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h
 CVE-2026-59901 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4
 CVE-2026-59900 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj
 CVE-2026-59899 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww
 CVE-2026-59898 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg
 CVE-2026-59247 (Insufficient Verification of Data Authenticity vulnerability in Gleam  ...)
 	- gleam <itp> (bug #1103795)
 CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted `verify_signatur ...)
 	NOT-FOR-US: Apache Airflow FAB provider
 CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when plugins reset  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58188 (Several Apache Traffic Server experimental plugins have memory-safety  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58187 (The Apache Traffic Server multiplexer plugin overruns its chunk-decode ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58186 (The Apache Traffic Server webp_transform plugin can decode unsafely an ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58185 (The Apache Traffic Server intercept plugin has a use-after-free.  This ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58184 (The Apache Traffic Server header_rewrite plugin can crash or corrupt m ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58183 (The Apache Traffic Server prefetch plugin can crash when processing at ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58182 (The Apache Traffic Server ts_lua plugin mishandles initialization, tra ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58181 (The Apache Traffic Server uri_signing and url_sig plugins can exhaust  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58180 (The Apache Traffic Server txn_box plugin overflows the stack from atta ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58179 (The Apache Traffic Server regex_remap plugin overflows the stack and i ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58178 (The Apache Traffic Server ESI plugin can recurse without bound and fet ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58177 (The Apache Traffic Server Cripts framework has out-of-bounds writes, p ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58175 (Apache Traffic Server leaks memory when handling HostDB SRV records.   ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58164 (Apache Traffic Server has use-after-free and time-of-check/time-of-use ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58163 (Apache Traffic Server mishandles on-disk cache fields and object lifet ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58162 (The Apache Traffic Server certifier plugin generates certificates base ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58161 (Apache Traffic Server can crash from null dereferences and dangling re ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58160 (Apache Traffic Server reads out of bounds while parsing DNS answers.   ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58159 (Apache Traffic Server can bypass IP access controls on UDS listeners a ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58158 (Apache Traffic Server mishandles PROXY protocol input, truncating port ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58157 (Apache Traffic Server can reuse server sessions and tunnels improperly ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58156 (Apache Traffic Server mis-parses ports in URLs and userinfo, allowing  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58155 (Apache Traffic Server truncates over-long header names, allowing heade ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58154 (Apache Traffic Server can write out of bounds or overflow integers whi ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58153 (Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 client ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58152 (Apache Traffic Server mishandles integers while decoding HPACK/XPACK h ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58151 (Apache Traffic Server can be crashed or driven to resource exhaustion  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58150 (Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requ ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked messages are ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output paths. Gramma ...)
 	- bison <unfixed>
@@ -251,7 +251,7 @@ CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program during
 	NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389
 	NOTE: https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b
 CVE-2026-55995 (A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...)
-	- open-isns <unfixed>
+	- open-isns <unfixed> (bug #1143053)
 	NOTE: Fixed by: https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb
 CVE-2026-54735 (Prebid Server is an open-source solution for running real-time adverti ...)
 	NOT-FOR-US: Prebid Server
@@ -288,7 +288,7 @@ CVE-2026-54079 (veraPDF validation provides PDF/A and PDF/UA validation, feature
 CVE-2026-54078 (veraPDF validation model is an implementation of the veraPDF validatio ...)
 	NOT-FOR-US: veraPDF
 CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for rootless  ...)
-	- fuse-overlayfs <unfixed>
+	- fuse-overlayfs <unfixed> (bug #1143058)
 	NOTE: https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
 	NOTE: Fixed by: https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f (v1.17)
 CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8  ...)
@@ -304,37 +304,37 @@ CVE-2026-50558 (Penelope Shell Handler is a post-exploitation shell handler for
 CVE-2026-4604 (The Klubraum Membership Request plugin for WordPress is vulnerable to  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-44944 (An Incorrect Authorization vulnerability in open-iscsi allowsunprivili ...)
-	- open-iscsi <unfixed>
+	- open-iscsi <unfixed> (bug #1143059)
 	NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e (2.1.12)
 CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory ('Path  ...)
-	- open-iscsi <unfixed>
+	- open-iscsi <unfixed> (bug #1143059)
 	NOTE: Fixed by: https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e (2.1.12)
 CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vuln ...)
 	NOT-FOR-US: Care Everywhere Gateway
 CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-40272 (Improper Input Validation in the decode() function of the traceparser  ...)
 	NOT-FOR-US: Blackberry
 CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS PROFINET ...)
 	NOT-FOR-US: CODESYS
 CVE-2026-33930 (Apache Traffic Server copies the client Host header into a fixed-size  ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick.CMS.  ...)
 	NOT-FOR-US: Quick.CMS
 CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
 	NOT-FOR-US: IBM
 CVE-2026-24033 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the request path a ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache Traffic Ser ...)
-	- trafficserver <unfixed>
+	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall Manageme ...)
 	NOT-FOR-US: Cisco
@@ -365,7 +365,7 @@ CVE-2026-17550 (A maliciously crafted DWG or DXF file, when parsed through Autod
 CVE-2026-16751 (Authorization Bypass in the emergency recovery approval component in E ...)
 	NOT-FOR-US: Ente Technologies Ente Museum Server
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1143063)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
 	NOT-FOR-US: WordPress plugin
@@ -398,12 +398,12 @@ CVE-2026-14270 (The Extra Checkout Options (addon for Extra Product Options & Ad
 CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Develar's ap ...)
 	NOT-FOR-US: Develar app-builder
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1143070)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13346 (pip would incorrectly handle doubly-encoded package URLs from indexes  ...)
-	- python-pip <unfixed>
+	- python-pip <unfixed> (bug #1143072)
 	[trixie] - python-pip <no-dsa> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/
 	NOTE: https://github.com/pypa/pip/pull/14110
@@ -497,17 +497,17 @@ CVE-2026-59941 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and pr
 	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-8hg6-c449-896m
 	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0 (v3.1.6)
 CVE-2026-59921 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g
 CVE-2026-57511 (SuperPlane before 0.30.0 contains an SMTP header injection vulnerabili ...)
 	NOT-FOR-US: SuperPlane
 CVE-2026-57510 (SuperPlane before 0.27.0 contains a broken object-level authorization  ...)
 	NOT-FOR-US: SuperPlane
 CVE-2026-56822 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-wc96-39fc-566f
 CVE-2026-56821 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1143052)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr
 CVE-2026-56722 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
 	- php-dompdf <unfixed> (bug #1142987)
@@ -839,7 +839,7 @@ CVE-2026-54605 (OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, pr
 	NOTE: Introduced with: https://github.com/ruby-oauth/oauth/commit/d74b767f464ee045cec75504974ff897b3dc0076 (v0.5.5)
 	NOTE: Fixed by: https://github.com/ruby-oauth/oauth/commit/d069dc8c4c9631947451215f07460d6cdf0caf3f (v1.1.6)
 CVE-2026-54603 (OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frame ...)
-	- ruby-oauth2 <unfixed>
+	- ruby-oauth2 <unfixed> (bug #1143054)
 	NOTE: https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9
 	NOTE: Fixed by: https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9 (v2.0.22)
 CVE-2026-54593 (Pterodactyl is a free, open-source game server management panel. Prior ...)
@@ -853,8 +853,8 @@ CVE-2026-54345 (gopacket provides packet processing capabilities for Go. In vers
 	NOTE: Introduced with: https://github.com/gopacket/gopacket/commit/fe11a243b3365bf877ddd91f9ba37206c25d96df (v1.6.0)
 	NOTE: Fixed by: https://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311 (v1.6.1)
 CVE-2026-54332 (gopacket provides packet processing capabilities for Go. In version 1. ...)
-	- golang-github-gopacket-gopacket <unfixed>
-	- gopacket <unfixed>
+	- golang-github-gopacket-gopacket <unfixed> (bug #1143056)
+	- gopacket <unfixed> (bug #1143055)
 	NOTE: https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563
 	NOTE: Fixed by: https://github.com/gopacket/gopacket/commit/76119086f5936aacd7088bdf97d565501bb6c4cc (v1.6.1)
 CVE-2026-51275 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in  ...)
@@ -1904,7 +1904,7 @@ CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang o
 CVE-2026-54540 (Pheditor is a single-file editor and file manager written in PHP. Prio ...)
 	NOT-FOR-US: Pheditor
 CVE-2026-54272 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
-	- node-ip-address <unfixed>
+	- node-ip-address <unfixed> (bug #1143057)
 	[trixie] - node-ip-address <not-affected> (Vulnerable code introduced later)
 	[bookworm] - node-ip-address <not-affected> (Vulnerable code introduced later)
 	[bullseye] - node-ip-address <not-affected> (Vulnerable code introduced later)
@@ -2031,7 +2031,7 @@ CVE-2026-17191 (An input validation vulnerability exists in an API component of
 CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has a security issue where this i ...)
 	NOT-FOR-US: Arista Networks
 CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the print_string ...)
-	- cjson <unfixed>
+	- cjson <unfixed> (bug #1143047)
 	NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-16554
 CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential exfiltration vulne ...)
 	NOT-FOR-US: googleapis/mcp-toolbox
@@ -2095,7 +2095,7 @@ CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp d006858/e15ef
 	NOTE: https://github.com/ggml-org/llama.cpp/issues/25284
 	NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
 CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a ref ...)
-	- xmlrpc-c <unfixed>
+	- xmlrpc-c <unfixed> (bug #1143065)
 	TODO: check upstream status
 CVE-2026-14827 (The Calendar WordPress plugin before 1.3.18 does not properly escape a ...)
 	NOT-FOR-US: WordPress plugin
@@ -2186,7 +2186,7 @@ CVE-2026-16566
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506113
 	TODO: check upstream report and status on fix
 CVE-2026-14957
-	- libreswan <unfixed>
+	- libreswan <unfixed> (bug #1143067)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2501764
 	NOTE: https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt
 	NOTE: Patch: https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.patch
@@ -9433,7 +9433,7 @@ CVE-2026-42210 (Webmin is a web-based system administration tool for Unix-like s
 CVE-2026-40187 (In egroupware version 26.0 and earlier, an authenticated administrator ...)
 	- egroupware <removed>
 CVE-2026-39879 (Due to a missing sanitization call in [`afsql_dd_run_query`](https://g ...)
-	- syslog-ng <unfixed>
+	- syslog-ng <unfixed> (bug #1143061)
 	NOTE: https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-qwf9-6222-m24m
 	NOTE: https://github.com/syslog-ng/syslog-ng/commit/1e872e301436efa5d3fcd54e7628ac82c57698d2 (syslog-ng-4.12.0)
 	NOTE: https://github.com/syslog-ng/syslog-ng/commit/1aba7537f0c406090f98a649475acbf517440220 (syslog-ng-4.12.0)
@@ -9679,7 +9679,7 @@ CVE-2026-16223 (A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4
 CVE-2026-16222 (A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This is ...)
 	NOT-FOR-US: 1Panel-dev CordysCRM
 CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...)
-	- node-ajv <unfixed>
+	- node-ajv <unfixed> (bug #1143064)
 	[trixie] - node-ajv <no-dsa> (Minor issue)
 	[bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
 	[bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
@@ -16191,7 +16191,7 @@ CVE-2026-15692 (A weakness has been identified in Tenda BE12 Pro 16.03.66.23. Th
 CVE-2026-15691 (A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. Thi ...)
 	NOT-FOR-US: Tenda
 CVE-2026-15690 (A vulnerability was identified in open62541 up to 1.5.5. Affected by t ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143066)
 	NOTE: https://github.com/open62541/open62541/issues/8104
 CVE-2026-15643 (AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model C ...)
 	NOT-FOR-US: Amazon
@@ -16680,7 +16680,7 @@ CVE-2026-61462 (mcp-gitlab contains a path traversal vulnerability in the job_id
 CVE-2026-60121 (Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection ...)
 	NOT-FOR-US: Vitec Flamingo
 CVE-2026-60103 (Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerabili ...)
-	- blender <unfixed>
+	- blender <unfixed> (bug #1143049)
 	[trixie] - blender <no-dsa> (Minor issue)
 	[bookworm] - blender <postponed> (Minor issue, OOB read)
 	[bullseye] - blender <postponed> (Minor issue, OOB read)
@@ -18135,7 +18135,7 @@ CVE-2026-15026 (The Import and export users and customers plugin for WordPress i
 CVE-2026-14475 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent plugin fo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14461 (mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup( ...)
-	- mtr <unfixed>
+	- mtr <unfixed> (bug #1143069)
 	[trixie] - mtr <no-dsa> (Minor issue)
 	[bookworm] - mtr <postponed> (Minor issue, OOB read)
 	[bullseye] - mtr <postponed> (Minor issue, OOB read)
@@ -18811,7 +18811,7 @@ CVE-2026-12879 (An Improper Input Validation vulnerability in BigQuery DAO in Go
 CVE-2026-12593 (The implementation of an internalandundocumentedDashboardAPI endpoint( ...)
 	NOT-FOR-US: QT Axivion
 CVE-2026-12590 (Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ...)
-	- node-body-parser <unfixed>
+	- node-body-parser <unfixed> (bug #1143074)
 	NOTE: https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6
 	NOTE: https://github.com/expressjs/body-parser/pull/698
 	NOTE: Fixed by: https://github.com/expressjs/body-parser/commit/2322e111cc321413ec2b7b76d01be533d3de9d7d (v2.3.0)
@@ -21487,7 +21487,7 @@ CVE-2026-14570 (Crypt::DSA versions before 1.22 for Perl draw the DSA signing no
 	[bullseye] - libcrypt-dsa-perl <postponed> (Minor issue; biased makerandom nonce/key generation; obsolete leaf module, removed from sid)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41542402/
 CVE-2026-14647 (A weakness has been identified in onnx up to 1.21.x. This vulnerabilit ...)
-	- onnx <unfixed>
+	- onnx <unfixed> (bug #1143068)
 	[trixie] - onnx <no-dsa> (Minor issue)
 	[bookworm] - onnx <postponed> (Minor issue; OOB read in Conv shape inference when parsing a crafted model)
 	[bullseye] - onnx <postponed> (Minor issue; OOB read in Conv shape inference when parsing a crafted model)
@@ -26662,7 +26662,7 @@ CVE-2026-13744 (Improper neutralization of attacker-controlled content in Snowfl
 CVE-2026-13742 (Honeywell IQ MultiAccess, all versions prior to and including version  ...)
 	NOT-FOR-US: Honeywell
 CVE-2026-13676 (fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize U ...)
-	- node-ajv <unfixed>
+	- node-ajv <unfixed> (bug #1143071)
 	[trixie] - node-ajv <no-dsa> (Minor issue)
 	[bookworm] - node-ajv <not-affected> (fast-uri not embedded; ajv <8 uses uri-js)
 	[bullseye] - node-ajv <not-affected> (fast-uri not embedded; ajv <8 uses uri-js)
@@ -28090,7 +28090,7 @@ CVE-2026-11625 (Bytes::Random::Secure versions through 0.29 for Perl share inter
 	NOTE: https://github.com/daoswald/Bytes-Random-Secure/pull/4
 	NOTE: https://security.metacpan.org/patches/B/Bytes-Random-Secure/0.29/CVE-2026-11625-r1.patch
 CVE-2026-13324
-	- geary <unfixed>
+	- geary <unfixed> (bug #1143073)
 	[trixie] - geary <no-dsa> (Minor issue)
 	[bookworm] - geary <postponed> (Minor issue; mailto ?attach= silently attaches local files, follow trixie)
 	[bullseye] - geary <postponed> (Minor issue; mailto ?attach= silently attaches local files, follow trixie)
@@ -54307,7 +54307,7 @@ CVE-2026-41069 (libheif is a HEIF and AVIF file format decoder and encoder. In v
 	- libheif 1.23.1-1 (bug #1137524)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-p82x-fpmv-576r
 CVE-2026-40864 (JupyterHub is software that allows users to create a multi-user server ...)
-	- jupyterhub <unfixed>
+	- jupyterhub <unfixed> (bug #1143060)
 	[trixie] - jupyterhub <no-dsa> (Minor issue)
 	[bookworm] - jupyterhub <not-affected> (Vulnerable Sec-Fetch-Mode handling introduced with the 4.1.0 XSRF rework)
 	NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e31f795c055150aba6064b3431906749a267ec76

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e31f795c055150aba6064b3431906749a267ec76
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/bcf483f3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list