[Git][security-tracker-team/security-tracker][master] Track node-undici fixes via unstable upload

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 15:55:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5287d833 by Salvatore Bonaccorso at 2026-07-30T16:54:28+02:00
Track node-undici fixes via unstable upload

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1282,7 +1282,7 @@ CVE-2026-17650 (Use after free in Compositing in Google Chrome prior to 151.0.79
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16728 (undici's retry interceptor can deliver a response whose body length do ...)
-	- node-undici <unfixed>
+	- node-undici 8.9.0+dfsg+~cs3.2.0-1
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
 CVE-2026-16727 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
 	NOT-FOR-US: ASUS
@@ -1333,7 +1333,7 @@ CVE-2026-15240 (The Customer Switching WordPress plugin before 2.1.3 does not se
 CVE-2026-15235 (The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not per ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15157 (undici does not validate the type property of a duck-typed blob-like r ...)
-	- node-undici <unfixed>
+	- node-undici 8.9.0+dfsg+~cs3.2.0-1
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
 CVE-2026-15153 (The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise a ...)
 	NOT-FOR-US: WordPress plugin
@@ -1344,7 +1344,7 @@ CVE-2026-15054 (The Bit Form  WordPress plugin before 3.1.2 does not enforce a f
 CVE-2026-14923 (The Sync Post With Other Site WordPress plugin before 1.9.3 does not c ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14643 (undici's cache interceptor mishandles optional whitespace placed aroun ...)
-	- node-undici <unfixed>
+	- node-undici 8.9.0+dfsg+~cs3.2.0-1
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54
 CVE-2026-14602 (The Remote API WordPress plugin through 0.2 does not authenticate a re ...)
 	NOT-FOR-US: WordPress plugin
@@ -1817,7 +1817,7 @@ CVE-2026-17550 (A maliciously crafted DWG or DXF file, when parsed through Autod
 CVE-2026-16751 (Authorization Bypass in the emergency recovery approval component in E ...)
 	NOT-FOR-US: Ente Technologies Ente Museum Server
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
-	- node-undici <unfixed> (bug #1143063)
+	- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143063)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
 	NOT-FOR-US: WordPress plugin
@@ -1850,7 +1850,7 @@ CVE-2026-14270 (The Extra Checkout Options (addon for Extra Product Options & Ad
 CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Develar's ap ...)
 	NOT-FOR-US: Develar app-builder
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
-	- node-undici <unfixed> (bug #1143070)
+	- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143070)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
 	NOT-FOR-US: WordPress plugin



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5287d833b979e7b32e48004cc7145645f9be95b8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5287d833b979e7b32e48004cc7145645f9be95b8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/8fc2b245/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list