[Git][security-tracker-team/security-tracker][master] Two node-ajv issues fixed via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 14:18:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6bc3d666 by Salvatore Bonaccorso at 2026-07-30T15:18:21+02:00
Two node-ajv issues fixed via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11132,7 +11132,7 @@ CVE-2026-16223 (A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4
CVE-2026-16222 (A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This is ...)
NOT-FOR-US: 1Panel-dev CordysCRM
CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...)
- - node-ajv <unfixed> (bug #1143064)
+ - node-ajv 8.20.0~ds+~cs7.1.2-1 (bug #1143064)
[trixie] - node-ajv <no-dsa> (Minor issue)
[bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
[bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
@@ -28112,7 +28112,7 @@ CVE-2026-13744 (Improper neutralization of attacker-controlled content in Snowfl
CVE-2026-13742 (Honeywell IQ MultiAccess, all versions prior to and including version ...)
NOT-FOR-US: Honeywell
CVE-2026-13676 (fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize U ...)
- - node-ajv <unfixed> (bug #1143071)
+ - node-ajv 8.20.0~ds+~cs7.1.2-1 (bug #1143071)
[trixie] - node-ajv <no-dsa> (Minor issue)
[bookworm] - node-ajv <not-affected> (fast-uri not embedded; ajv <8 uses uri-js)
[bullseye] - node-ajv <not-affected> (fast-uri not embedded; ajv <8 uses uri-js)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6bc3d666fa3d4c337733a15bc8ed2d4aa39fa3b6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6bc3d666fa3d4c337733a15bc8ed2d4aa39fa3b6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/35988781/attachment.htm>
More information about the debian-security-tracker-commits
mailing list