[Git][security-tracker-team/security-tracker][master] Add more node-undici issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 09:31:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
278f019d by Salvatore Bonaccorso at 2026-07-30T10:31:27+02:00
Add more node-undici issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1246,7 +1246,8 @@ CVE-2026-17650 (Use after free in Compositing in Google Chrome prior to 151.0.79
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16728 (undici's retry interceptor can deliver a response whose body length do ...)
-	TODO: check
+	- node-undici <unfixed>
+	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
 CVE-2026-16727 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
 	NOT-FOR-US: ASUS
 CVE-2026-16610 (The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vuln ...)
@@ -1290,7 +1291,8 @@ CVE-2026-15240 (The Customer Switching WordPress plugin before 2.1.3 does not se
 CVE-2026-15235 (The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not per ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15157 (undici does not validate the type property of a duck-typed blob-like r ...)
-	TODO: check
+	- node-undici <unfixed>
+	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
 CVE-2026-15153 (The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise a ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15077 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
@@ -1300,7 +1302,8 @@ CVE-2026-15054 (The Bit Form  WordPress plugin before 3.1.2 does not enforce a f
 CVE-2026-14923 (The Sync Post With Other Site WordPress plugin before 1.9.3 does not c ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14643 (undici's cache interceptor mishandles optional whitespace placed aroun ...)
-	TODO: check
+	- node-undici <unfixed>
+	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54
 CVE-2026-14602 (The Remote API WordPress plugin through 0.2 does not authenticate a re ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14592 (The WP Real IP-based Access Control WordPress plugin through 1.3.1 doe ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/278f019dd4189fb05d553bf1d72cb5f983ef71e9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/278f019dd4189fb05d553bf1d72cb5f983ef71e9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/2a9ca98c/attachment.htm>


More information about the debian-security-tracker-commits mailing list