[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-12804/lemonldap-ng

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 16:32:42 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e201c0c8 by Salvatore Bonaccorso at 2026-07-30T17:32:08+02:00
Update status for CVE-2026-12804/lemonldap-ng

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -34930,12 +34930,13 @@ CVE-2026-56236 (Capgo CLI before 12.128.2 contains arbitrary file overwrite vuln
 CVE-2026-56229 (Capgo before 12.128.2 contains an authorization bypass vulnerability i ...)
 	NOT-FOR-US: Cap-go
 CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is ...)
-	- lemonldap-ng <unfixed>
+	- lemonldap-ng 2.23.1+ds-1
 	[trixie] - lemonldap-ng <no-dsa> (Minor issue)
 	[bookworm] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
 	[bullseye] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979
+	NOTE: Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/478bed8e58f0457235e0916e3f73a85a2f19471f (v2.23.1)
 CVE-2026-12799 (A security vulnerability has been detected in BerriAI litellm up to 1. ...)
 	NOT-FOR-US: LiteLLM
 CVE-2026-12798 (A weakness has been identified in BerriAI litellm up to 1.82.2. Affect ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e201c0c8eeed2d5feb3edac63c2dea313a3ab678

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e201c0c8eeed2d5feb3edac63c2dea313a3ab678
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/93a8a19c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list