[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 20:13:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cf67cf12 by security tracker role at 2026-07-30T19:13:27+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,279 @@
-CVE-2026-60075
+CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+ TODO: check
+CVE-2026-7849 (Due to improper neutralization of special elements, an unauthenticated ...)
+ TODO: check
+CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which enforce ...)
+ TODO: check
+CVE-2026-67596 (CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak e ...)
+ TODO: check
+CVE-2026-67351 (Serendipity before 2.6.1 contains an authentication context confusion ...)
+ TODO: check
+CVE-2026-67349 (OpenCost before 1.121.0 fails to authenticate the GET /helmValues endp ...)
+ TODO: check
+CVE-2026-67348 (Julep contains an insecure direct object reference vulnerability in th ...)
+ TODO: check
+CVE-2026-67347 (Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-chann ...)
+ TODO: check
+CVE-2026-67346 (Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side ...)
+ TODO: check
+CVE-2026-67345 (MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficie ...)
+ TODO: check
+CVE-2026-66416 (Leantime 3.6.2 contains a cross-site request forgery vulnerability tha ...)
+ TODO: check
+CVE-2026-66415 (Leantime 3.6.2 contains a server-side request forgery and local file i ...)
+ TODO: check
+CVE-2026-66414 (Leantime 3.6.2 contains an open redirect vulnerability in the Login co ...)
+ TODO: check
+CVE-2026-65635 (Improper Isolation or Compartmentalization vulnerability in malach-it ...)
+ TODO: check
+CVE-2026-64870 (MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 ...)
+ TODO: check
+CVE-2026-62663 (Banks generates meaningful LLM prompts using a simple template languag ...)
+ TODO: check
+CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template languag ...)
+ TODO: check
+CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Fo ...)
+ TODO: check
+CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information ...)
+ TODO: check
+CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
+ TODO: check
+CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in the Sys ...)
+ TODO: check
+CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability in the ...)
+ TODO: check
+CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request forgery vulne ...)
+ TODO: check
+CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution vulnerability in ...)
+ TODO: check
+CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules contains a pl ...)
+ TODO: check
+CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta allows a ...)
+ TODO: check
+CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of utilities and ...)
+ TODO: check
+CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack binary se ...)
+ TODO: check
+CVE-2026-54368 (CentreStack before 17.4 contains a SQL injection vulnerability in Glad ...)
+ TODO: check
+CVE-2026-54367 (CentreStack before 17.2 contains an authentication bypass vulnerabilit ...)
+ TODO: check
+CVE-2026-54366 (CentreStack before 17.4 contains an XML external entity (XXE) injectio ...)
+ TODO: check
+CVE-2026-54365 (CentreStack before 17.3 contains an unauthenticated deserialization vu ...)
+ TODO: check
+CVE-2026-54364 (CentreStack before 17.4 contains a session variable injection vulnerab ...)
+ TODO: check
+CVE-2026-54363 (CentreStack before 17.5 contains a hardcoded cryptographic key vulnera ...)
+ TODO: check
+CVE-2026-53431 (Authentication Bypass by Capture-replay vulnerability in malach-it Bor ...)
+ TODO: check
+CVE-2026-51295 (SQLite 3.41 is vulnerable to use after free in the jsonExtractFunc fun ...)
+ TODO: check
+CVE-2026-51294 (SQLite 3.41 is vulnerable to use after free in the jsonArrayLengthFunc ...)
+ TODO: check
+CVE-2026-51293 (A use-after-free vulnerability exists in SQLite 3.41 when the jsonBlob ...)
+ TODO: check
+CVE-2026-51292 (sqlite 3.41 has a use-after-free vulnerability in the memory buffer pr ...)
+ TODO: check
+CVE-2026-51291 (sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheIns ...)
+ TODO: check
+CVE-2026-51290 (SQLite 3.41 has a use-after-free vulnerability in the shared cache loc ...)
+ TODO: check
+CVE-2026-51272 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
+ TODO: check
+CVE-2026-4978 (Improper neutralization of special elements used in an SQL command ('S ...)
+ TODO: check
+CVE-2026-48910 (A carefully crafted editing request could trigger an XSS vulnerability ...)
+ TODO: check
+CVE-2026-48499 (Activepieces is an open source AI workflow automation platform. Prior ...)
+ TODO: check
+CVE-2026-47876 (VMware ESX contains an out-of-bounds write vulnerability in the VMXNET ...)
+ TODO: check
+CVE-2026-44108 (Due to a flaw in the execution order of scripts during shutdown, the f ...)
+ TODO: check
+CVE-2026-44107 (A reboot of the charging controller can be triggered via Modbus TCP wi ...)
+ TODO: check
+CVE-2026-44106 (A privilege escalation vulnerability in the init-script for user-appli ...)
+ TODO: check
+CVE-2026-44105 (The credentials for the local user "user-app" may be exposed in log fi ...)
+ TODO: check
+CVE-2026-44104 (The firmware update process for the basemodule of the charging control ...)
+ TODO: check
+CVE-2026-44103 (An unauthenticated remote attacker can inject malicious firmware into ...)
+ TODO: check
+CVE-2026-44102 (An unauthenticated remote attacker can trigger a firmware update downl ...)
+ TODO: check
+CVE-2026-44101 (Due to missing authentication the CHARX OCPP Agent service allows an u ...)
+ TODO: check
+CVE-2026-44100 (The CHARX JupiCore service allows an unauthenticated remote attacker t ...)
+ TODO: check
+CVE-2026-44099 (A privilege escalation vulnerability in the system configuration allow ...)
+ TODO: check
+CVE-2026-44098 (This vulnerability allows an unauthenticated remote attacker with cont ...)
+ TODO: check
+CVE-2026-44097 (A low-privileged remote attacker with "operator" access can upload arb ...)
+ TODO: check
+CVE-2026-44096 (A privilege escalation vulnerability in udhcpc allows a local user "ch ...)
+ TODO: check
+CVE-2026-44095 (A privilege escalation vulnerability in a script used for network conf ...)
+ TODO: check
+CVE-2026-44094 (An unauthenticated remote attacker can enforce the system to fall back ...)
+ TODO: check
+CVE-2026-44093 (A local privilege escalation vulnerability in the init-script for user ...)
+ TODO: check
+CVE-2026-44092 (An unauthenticated remote attacker can inject malicious input into the ...)
+ TODO: check
+CVE-2026-44091 (An unauthenticated remote attacker can post a malicious ID to the MQTT ...)
+ TODO: check
+CVE-2026-44090 (Due to missing authentication, an unauthenticated remote attacker may ...)
+ TODO: check
+CVE-2026-41709 (VMware ESX contains an insufficient logging vulnerability.A malicious ...)
+ TODO: check
+CVE-2026-41703 (VMware ESX,Workstation, and Fusioncontain an out-of-bounds read vulner ...)
+ TODO: check
+CVE-2026-41187 (Calico's apiserver wraps tier-scoped resources so that every operation ...)
+ TODO: check
+CVE-2026-41186 (When Calico's shared debug server is enabled (disabled by default), th ...)
+ TODO: check
+CVE-2026-28814 (Arbitrary Wiki Markup rendering due to lack of authentication in Apach ...)
+ TODO: check
+CVE-2026-28813 (Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which l ...)
+ TODO: check
+CVE-2026-28812 (UserManager lack of checks allows impersonation in Apache JSPWiki up t ...)
+ TODO: check
+CVE-2026-28811 (Debug Messages Revealing Unnecessary Information in Apache JSPWiki up ...)
+ TODO: check
+CVE-2026-28323 (SolarWinds Web Help Desk is found to be affected by a SAML authenticat ...)
+ TODO: check
+CVE-2026-22622 (Improper input validation in one of the session management interface o ...)
+ TODO: check
+CVE-2026-22621 (Improper input validation in one of the session management interface o ...)
+ TODO: check
+CVE-2026-22620 (Improper input validation in the authentication component ofEaton's Tr ...)
+ TODO: check
+CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's CostManageme ...)
+ TODO: check
+CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat OpenShift. T ...)
+ TODO: check
+CVE-2026-18378 (A flaw was found in koku-metrics-operator. The operator's CostManageme ...)
+ TODO: check
+CVE-2026-18369 (A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 chal ...)
+ TODO: check
+CVE-2026-18363 (A logic vulnerability in the password reset token validation routine i ...)
+ TODO: check
+CVE-2026-18362 (The IRIS web application in version 2.4.26 and possibly others does no ...)
+ TODO: check
+CVE-2026-18361 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
+ TODO: check
+CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
+ TODO: check
+CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks ...)
+ TODO: check
+CVE-2026-18245 (Improper control of code generation in Amazon @aws-amplify/codegen-ui- ...)
+ TODO: check
+CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the aws-smithy- ...)
+ TODO: check
+CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others does no ...)
+ TODO: check
+CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others contain ...)
+ TODO: check
+CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
+ TODO: check
+CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 ...)
+ TODO: check
+CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when no API ...)
+ TODO: check
+CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the /server_info ...)
+ TODO: check
+CVE-2026-15976 (SGLang contains a RCE vulnerability when attempting to load model weig ...)
+ TODO: check
+CVE-2026-15974 (SGLang contains an SSRF and local file read in the multimodal generati ...)
+ TODO: check
+CVE-2026-15971 (SGLang contains an RCE vulnerability when the optional dumper subsyste ...)
+ TODO: check
+CVE-2026-15969 (SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tens ...)
+ TODO: check
+CVE-2026-15658 (A vulnerability in the foreUP customer REST API allows any authenticat ...)
+ TODO: check
+CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any authenticat ...)
+ TODO: check
+CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
+ TODO: check
+CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is vulnerable t ...)
+ TODO: check
+CVE-2026-14980 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
+ TODO: check
+CVE-2026-14522 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
+ TODO: check
+CVE-2026-14519 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
+ TODO: check
+CVE-2026-14227 (An API session\u2011management flaw in products with the MikroTik Rout ...)
+ TODO: check
+CVE-2026-13584 (Improper Enforcement of Message Integrity During Transmission in a Com ...)
+ TODO: check
+CVE-2026-13444 (IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access ...)
+ TODO: check
+CVE-2026-13435 (IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input valid ...)
+ TODO: check
+CVE-2026-13379 (The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 al ...)
+ TODO: check
+CVE-2026-12947 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
+ TODO: check
+CVE-2026-12945 (IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to ac ...)
+ TODO: check
+CVE-2026-12943 (IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 thro ...)
+ TODO: check
+CVE-2026-12942 (IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to ...)
+ TODO: check
+CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticate ...)
+ TODO: check
+CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a denial ...)
+ TODO: check
+CVE-2026-12722 (Missing authentication for critical function vulnerability in FTC Soft ...)
+ TODO: check
+CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unaut ...)
+ TODO: check
+CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code e ...)
+ TODO: check
+CVE-2026-11904 (IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify ...)
+ TODO: check
+CVE-2026-11897 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i ...)
+ TODO: check
+CVE-2026-11885 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through ...)
+ TODO: check
+CVE-2026-11707 (IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere ...)
+ TODO: check
+CVE-2026-11383 (IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere ...)
+ TODO: check
+CVE-2026-10842 (IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Applic ...)
+ TODO: check
+CVE-2026-10700 (IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access c ...)
+ TODO: check
+CVE-2026-10695 (IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a deni ...)
+ TODO: check
+CVE-2026-10545 (IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an ...)
+ TODO: check
+CVE-2026-10535 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable ...)
+ TODO: check
+CVE-2025-36431 (IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling ...)
+ TODO: check
+CVE-2025-36374 (IBM DataPower Gateway is vulnerable to an XML external entity injectio ...)
+ TODO: check
+CVE-2025-36298 (IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through ...)
+ TODO: check
+CVE-2025-0152 (IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7 ...)
+ TODO: check
+CVE-2024-40683 (IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3 ...)
+ TODO: check
+CVE-2024-25039 (IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7 ...)
+ TODO: check
+CVE-2026-60075 (Date::Manip versions through 6.99 for Perl allow CPU exhaustion via qu ...)
- libdate-manip-perl <unfixed> (bug #1143125)
[trixie] - libdate-manip-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42266599/
NOTE: https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch
-CVE-2026-60074
+CVE-2026-60074 (Date::Manip versions through 6.99 for Perl return corrupted dates via ...)
- libdate-manip-perl <unfixed> (bug #1143125)
[trixie] - libdate-manip-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42266594/
@@ -41,19 +311,19 @@ CVE-2026-62268
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/4f37fdfed10b50559a0dd333b0d5581c642af329 (2.0.0b22)
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/3e9ed6d1ad6d3531b39c07b8ef3ecf41fce4437f (1.4.5)
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/141888f2fabcd57a300547c2aa63212cb213924d (1.4.5)
-CVE-2026-17544
+CVE-2026-17544 (Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...)
- php8.4 <unfixed>
- php8.2 <removed>
- php7.4 <removed>
NOTE: https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f
NOTE: Fixed by: https://github.com/php/php-src/commit/fa18dab73f9340448c0d5c0a1d75d3fec844b358 (php-8.4.24)
-CVE-2026-17543
+CVE-2026-17543 (Improper escaping of backslashes in attacker-provided parameters would ...)
- php8.4 <unfixed>
- php8.2 <removed>
- php7.4 <removed>
NOTE: https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4
NOTE: Fixed by: https://github.com/php/php-src/commit/53ac7025451c6481d44cf1835bb8385299a6a3a3 (php-8.4.24)
-CVE-2026-7260
+CVE-2026-7260 (Circular symbolic links in phar archives could lead to unbounded recur ...)
- php8.4 <unfixed>
- php8.2 <removed>
- php7.4 <removed>
@@ -67,7 +337,7 @@ CVE-2026-XXXX [OSSA-2026-030 Swift: S3API header authorization bypass]
- swift 2.37.1-6 (bug #1142972)
NOTE: https://security.openstack.org/ossa/OSSA-2026-030.html
NOTE: https://bugs.launchpad.net/swift/+bug/2158733
-CVE-2022-4994 [KVM: x86: wean fast IN from emulator_pio_in]
+CVE-2022-4994 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 6.0.2-1
NOTE: https://git.kernel.org/linus/dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3 (6.0-rc1)
CVE-2026-58044
@@ -91,7 +361,7 @@ CVE-2026-56848
CVE-2026-56846
- nodejs <unfixed>
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-retained-headers-can-bypass-maxsessionmemory-limits-cve-2026-56846---high
-CVE-2026-66066 [Possible arbitrary file read and remote code execution in Active Storage variant processing]
+CVE-2026-66066 (Action Pack is a framework for handling and responding to web requests ...)
- rails <unfixed> (bug #1143080)
NOTE: https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm
NOTE: Fixed by: https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a (v7.2.3.2)
@@ -2591,7 +2861,7 @@ CVE-2026-58224 [The CTDB protocol has bounds checking issues]
{DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58224-advisory.html
-CVE-2026-58222 [Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes]
+CVE-2026-58222 (A security flaw combining LDAP filter injection and improper authoriza ...)
{DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58222-advisory.html
@@ -2599,11 +2869,11 @@ CVE-2026-58221 [Samba AD authenticated LDAP access domain takeover]
{DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58221-advisory.html
-CVE-2026-58218 [DNS signing DoS via TKEY name cache exhaustion]
+CVE-2026-58218 (A flaw was found in Samba's internal DNS server where unauthenticated ...)
{DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58218-advisory.html
-CVE-2026-58216 [An authenticated user could possibly crash a KDC process]
+CVE-2026-58216 (An out-of-bounds read flaw was found in Samba's Kerberos Key Distribut ...)
{DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58216-advisory.html
@@ -14144,7 +14414,7 @@ CVE-2026-9202 (IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated atta
NOT-FOR-US: IBM
CVE-2026-9198 (IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers ...)
NOT-FOR-US: IBM
-CVE-2026-9171 (IBM PowerVM Novalink are vulnerable to a denial of service, caused by ...)
+CVE-2026-9171 (IBM WebSphere Application Server and WebSphere Application Server Libe ...)
NOT-FOR-US: IBM
CVE-2026-9135 (IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (c ...)
NOT-FOR-US: IBM
@@ -23729,11 +23999,11 @@ CVE-2026-13698 (A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 thr
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/b005e4709ce1afbee7c571788cffd915280d646e (v2.7.5)
-CVE-2026-11771
+CVE-2026-11771 (OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...)
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/04309bfe0313c09edd02c29945893b9d7e2ca920 (v2.7.5)
-CVE-2026-12932
+CVE-2026-12932 (A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5 ...)
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/19c9ad5bb75942f66608d2ae28c0614a0a5c6073 (v2.7.5)
@@ -23741,12 +24011,12 @@ CVE-2026-13122 (OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/010b6c833b7fdbe889c0c7f8fc33f588a658b81f (v2.7.5)
-CVE-2026-13117
+CVE-2026-13117 (An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 thr ...)
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
[bullseye] - openvpn <not-affected> (Dynamic tls-crypt got introduced in 2.6/2.7)
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/3ce0242e68527fd1e8d378aecb57c466e8058b44 (v2.7.5)
-CVE-2026-12996
+CVE-2026-12996 (A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 throug ...)
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/5ee1f9b90fe03ecf7cef5431147ecaabbe96db9e (v2.7.5)
@@ -25616,7 +25886,7 @@ CVE-2025-15666 (A security vulnerability has been detected in Open Asset Import
[bookworm] - assimp <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - assimp <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/assimp/assimp/issues/6079
-CVE-2025-12530 (IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch ...)
+CVE-2025-12530 (IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch ...)
NOT-FOR-US: IBM
CVE-2026-56016 (CGI::Session::ID::md5 versions before 4.49 for Perl generate predictab ...)
- libcgi-session-perl 4.49-1 (bug #1141197)
@@ -33908,7 +34178,7 @@ CVE-2026-52845 (Caddy is an extensible server platform that uses TLS by default.
CVE-2026-52844 (Caddy is an extensible server platform that uses TLS by default. Prior ...)
- caddy 2.11.4-1 (bug #1140773)
NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-qrp7-cvwr-j2c6
-CVE-2026-52680
+CVE-2026-52680 (Apache Kyuubi REST batch multipart upload handling uses the client-sup ...)
NOT-FOR-US: Apache Kyuubi
CVE-2026-52673 (SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remo ...)
NOT-FOR-US: Cboard
@@ -34887,42 +35157,52 @@ CVE-2026-11745 (A vulnerability has been identified in centraldogma-server-mirro
CVE-2026-10530 (The Pie Register WordPress plugin before 3.8.4.10 does not use suffic ...)
NOT-FOR-US: WordPress plugin
CVE-2026-56412 (libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataS ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1278
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/d19e834794060d18c061d94452c35d725393ea58
CVE-2026-56411 (xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDe ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1263
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5
CVE-2026-56410 (xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSyste ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1252
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea
CVE-2026-56409 (xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1259
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e
CVE-2026-56408 (libexpat before 2.8.2 has an integer overflow in copyString.)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817
CVE-2026-56407 (libexpat before 2.8.2 has an integer overflow in doProlog that is rela ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1262
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13
CVE-2026-56406 (libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer becau ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1255
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d
CVE-2026-56405 (libexpat before 2.8.2 has an integer overflow in getAttributeId.)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1251
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0
CVE-2026-56404 (libexpat before 2.8.2 has an integer overflow in addBinding.)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1249
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164
CVE-2026-56403 (libexpat before 2.8.2 has an integer overflow in storeAtts.)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1232
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648
@@ -35587,9 +35867,11 @@ CVE-2026-7515 (The BetterDocs Pro plugin for WordPress is vulnerable to Local Fi
CVE-2026-6716
REJECTED
CVE-2026-56132 (In libexpat before 2.8.2, there is a heap-based buffer overflow in doP ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140388)
NOTE: https://github.com/libexpat/libexpat/pull/1272
CVE-2026-56131 (libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1140387)
NOTE: https://github.com/libexpat/libexpat/pull/1267
CVE-2026-56099 (OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds r ...)
@@ -46709,6 +46991,7 @@ CVE-2026-50292 (In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-dev
NOTE: Fixed by: https://gitlab.freedesktop.org/libinput/libinput/-/commit/b2bde9504d42a5976d76e1f27c640dc561fbd99b (1.30.4)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/04/5
CVE-2026-50219 (libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...)
+ {DSA-6404-1}
- expat 2.8.2-1 (bug #1138862)
NOTE: https://github.com/libexpat/libexpat/pull/1246
CVE-2026-8829 (HTML::Entities versions before 3.84 for Perl read freed heap memory in ...)
@@ -61119,13 +61402,13 @@ CVE-2026-44853 (Command injection vulnerabilities exist in the web-based managem
NOT-FOR-US: HPE
CVE-2026-44852 (An authenticated remote code execution vulnerability exists in the AOS ...)
NOT-FOR-US: HPE
-CVE-2026-44617
+CVE-2026-44617 (LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used ...)
NOT-FOR-US: Apache Zeppelin
-CVE-2026-44616
+CVE-2026-44616 (LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupR ...)
NOT-FOR-US: Apache Zeppelin
CVE-2026-44615
NOT-FOR-US: Apache Zeppelin
-CVE-2026-44613
+CVE-2026-44613 (Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. Th ...)
NOT-FOR-US: Apache Zeppelin
CVE-2026-44612 (Bytello Share (Windows Edition) installer executable provided by Bytel ...)
NOT-FOR-US: Bytello
@@ -63570,6 +63853,7 @@ CVE-2026-8195 (A vulnerability was detected in JeecgBoot up to 3.9.1. The affect
CVE-2026-8194 (A security vulnerability has been detected in osTicket up to 1.18.3. I ...)
- osticket <itp> (bug #998157)
CVE-2026-45186 (In libexpat before 2.8.1, the computational complexity of attribute na ...)
+ {DSA-6404-1}
- expat 2.8.0-2 (bug #1136164)
NOTE: https://github.com/libexpat/libexpat/pull/1216
NOTE: https://blog.hartwork.org/posts/expat-2-8-1-released/
@@ -78359,6 +78643,7 @@ CVE-2026-41082 (In OCaml opam before 2.5.1, a .install field containing a destin
- opam 2.5.1-1
NOTE: https://github.com/ocaml/security-advisories/blob/main/advisories/2026/OSEC-2026-03.md
CVE-2026-41080 (libexpat before 2.8.0 uses insufficient entropy, and thus hash floodin ...)
+ {DSA-6404-1}
- expat 2.8.0-1 (bug #1134732)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
@@ -86287,6 +86572,7 @@ CVE-2026-34835 (Rack is a modular Ruby web server interface. From versions 3.0.0
NOTE: Fixed by: https://github.com/rack/rack/commit/224662608dad63b31ba138d7e76e4ca8e42e9fc6 (v3.2.6)
NOTE: Fixed by: https://github.com/rack/rack/commit/c49558af795b4c1978d16db071c8344db05a2b0d (v3.1.21)
CVE-2026-34831 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-q2ww-5357-x388
@@ -86294,6 +86580,7 @@ CVE-2026-34831 (Rack is a modular Ruby web server interface. Prior to versions 2
NOTE: Fixed by: https://github.com/rack/rack/commit/c3645d377f0335a779812bf3f36e238d87d9b4e6 (v3.1.21)
NOTE: Fixed by: https://github.com/rack/rack/commit/a75847314e8ad847a5b66e7215381c4ed51f6aa7 (v2.2.23)
CVE-2026-34830 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-qv7j-4883-hwh7
@@ -86301,6 +86588,7 @@ CVE-2026-34830 (Rack is a modular Ruby web server interface. Prior to versions 2
NOTE: Fixed by: https://github.com/rack/rack/commit/59a0966a484f2903833fa3e4c81919d3c645738d (v3.1.21)
NOTE: Fixed by: https://github.com/rack/rack/commit/7f288de93768b5cc44a5f4ed1ac02470d8fe52f4 (v2.2.23)
CVE-2026-34829 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-8vqr-qjwx-82mw
@@ -86318,6 +86606,7 @@ CVE-2026-34827 (Rack is a modular Ruby web server interface. From versions 3.0.0
NOTE: Fixed by: https://github.com/rack/rack/commit/bfb69142dbe2a1e3298ad52d12935938d1b58205 (v3.2.6)
NOTE: Fixed by: https://github.com/rack/rack/commit/17ce7836be1523a7b453f3c06fe070ad7c954708 (v3.1.21)
CVE-2026-34826 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-x8cg-fq8g-mxfx
@@ -86393,6 +86682,7 @@ CVE-2026-34791 (Endian Firewall version 3.3.25 and prior allow authenticated use
CVE-2026-34790 (Endian Firewall version 3.3.25 and prior allow authenticated users to ...)
NOT-FOR-US: Endian Firewall
CVE-2026-34786 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-q4qf-9j86-f5mh
@@ -86400,6 +86690,7 @@ CVE-2026-34786 (Rack is a modular Ruby web server interface. Prior to versions 2
NOTE: Fixed by: https://github.com/rack/rack/commit/84937c38065d0a7630828fdd526201c5241a9619 (v3.1.21)
NOTE: Fixed by: https://github.com/rack/rack/commit/4207d22e58a41d57a2c6e1ed2602170504b000c7 (v2.2.23)
CVE-2026-34785 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-h2jq-g4cq-5ppq
@@ -86407,6 +86698,7 @@ CVE-2026-34785 (Rack is a modular Ruby web server interface. Prior to versions 2
NOTE: Fixed by: https://github.com/rack/rack/commit/a17cb99b3440a4db09fb920407adf5ead127704c (v3.1.21)
NOTE: Fixed by: https://github.com/rack/rack/commit/203730e4abb2fac3a0514d6dc3ac56de82bdff9a (v2.2.23)
CVE-2026-34763 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-7mqq-6cf9-v2qp
@@ -86489,6 +86781,7 @@ CVE-2026-34426 (OpenClaw versions prior to commit b57b680contain an approval byp
CVE-2026-34425 (OpenClaw versions prior to commit 8aceaf5 contain a preflight validati ...)
NOT-FOR-US: OpenClaw
CVE-2026-34230 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-v569-hp3g-36wr
@@ -86658,6 +86951,7 @@ CVE-2026-26962 (Rack is a modular Ruby web server interface. From version 3.2.0
NOTE: https://github.com/rack/rack/security/advisories/GHSA-rx22-g9mx-qrhv
NOTE: Fixed by: https://github.com/rack/rack/commit/d50c4d3dab62fa80b2a276271d0d4fb338cfa7df (v3.2.6)
CVE-2026-26961 (Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...)
+ {DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE: https://github.com/rack/rack/security/advisories/GHSA-vgpv-f759-9wx3
@@ -96843,6 +97137,7 @@ CVE-2026-4172 (A vulnerability was detected in TRENDnet TEW-632BRP 1.010B32. Thi
CVE-2026-4171 (A security vulnerability has been detected in CodeGenieApp serverless- ...)
NOT-FOR-US: CodeGenieApp serverless-express
CVE-2026-32778 (libexpat before 2.7.5 allows a NULL pointer dereference in the functio ...)
+ {DSA-6404-1}
- expat 2.7.5-1 (bug #1131119)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
@@ -96850,6 +97145,7 @@ CVE-2026-32778 (libexpat before 2.7.5 allows a NULL pointer dereference in the f
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/576b61e42feeea704253cb7c7bedb2eeb3754387
NOTE: Test: https://github.com/libexpat/libexpat/commit/d5fa769b7a7290a7e2c4a0b2287106dec9b3c030
CVE-2026-32777 (libexpat before 2.7.5 allows an infinite loop while parsing DTD conten ...)
+ {DSA-6404-1}
- expat 2.7.5-1 (bug #1131118)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
@@ -96858,6 +97154,7 @@ CVE-2026-32777 (libexpat before 2.7.5 allows an infinite loop while parsing DTD
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/55cda8c7125986e17d7e1825cba413bd94a35d02
NOTE: Test: https://github.com/libexpat/libexpat/commit/a7805c1a8a48d2ce83ef289cf55bdc8b45de76a8
CVE-2026-32776 (libexpat before 2.7.5 allows a NULL pointer dereference with empty ext ...)
+ {DSA-6404-1}
- expat 2.7.5-1 (bug #1131117)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
@@ -105312,9 +105609,9 @@ CVE-2026-23983 (A Sensitive Data Exposure vulnerability exists in Apache Superse
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-23982 (An Improper Authorization vulnerability exists in Apache Superset that ...)
NOT-FOR-US: Apache software not packaged in Debian
-CVE-2026-23985
+CVE-2026-23985 (A Regular Expression Denial of Service (ReDoS) vulnerability exists in ...)
NOT-FOR-US: Apache Superset
-CVE-2026-23981
+CVE-2026-23981 (An Improper Authorization vulnerability exists in Apache Superset allo ...)
NOT-FOR-US: Apache Superset
CVE-2026-23980 (Improper Neutralization of Special Elements used in a SQL Command ('SQ ...)
NOT-FOR-US: Apache software not packaged in Debian
@@ -116085,6 +116382,7 @@ CVE-2025-15288 (Tanium addressed an improper access controls vulnerability in In
CVE-2025-12899 (A flaw in Zephyr\u2019s network stack allows an IPv4 packet containing ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-25210 (In libexpat before 2.7.4, the doContent function does not properly det ...)
+ {DSA-6404-1}
- expat 2.7.4-1 (bug #1126697)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
@@ -118482,6 +118780,7 @@ CVE-2025-71146 (In the Linux kernel, the following vulnerability has been resolv
CVE-2025-71145 (In the Linux kernel, the following vulnerability has been resolved: u ...)
- linux <not-affected> (Vulnerable code not present)
CVE-2026-24515 (In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy ...)
+ {DSA-6404-1}
- expat 2.7.3-2 (bug #1126277)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue, DoS)
@@ -170147,7 +170446,7 @@ CVE-2025-59378 (In guix-daemon in GNU Guix before 1618ca7, a content-addressed-m
NOTE: Fixed by: https://codeberg.org/guix/guix/commit/f607aaaaaafe19257ef09ca519d325df6ae97e05
NOTE: Fixed by: https://codeberg.org/guix/guix/commit/9202921e812708b23788b2209cdb576d456f56db
CVE-2025-59375 (libexpat in Expat before 2.7.2 allows attackers to trigger large dynam ...)
- {DSA-6179-1 DSA-6178-1 DLA-4511-1 DLA-4510-1}
+ {DSA-6404-1 DSA-6179-1 DSA-6178-1 DLA-4511-1 DLA-4510-1}
- firefox 149.0-1
- firefox-esr 140.9.0esr-1
- thunderbird 1:140.9.0esr-1
@@ -437912,7 +438211,7 @@ CVE-2022-42987
CVE-2022-3567 (A vulnerability has been found in Linux Kernel and classified as probl ...)
- linux 6.1.4-1
NOTE: https://git.kernel.org/linus/364f997b5cfe1db0d63a390fe7c801fa2b3115f6 (6.1-rc1)
-CVE-2022-3566 (A vulnerability, which was classified as problematic, was found in Lin ...)
+CVE-2022-3566 (A vulnerability was identified in Linux Kernel up to 4.19.316/5.4.278/ ...)
- linux 6.1.4-1
NOTE: https://git.kernel.org/linus/f49cd2f4d6170d27a2c61f1fecb03d8a70c91f57 (6.1-rc1)
CVE-2022-3565 (A vulnerability, which was classified as critical, has been found in L ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf67cf121cb9ae81d24be3bc4e06f0cef446a5e3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf67cf121cb9ae81d24be3bc4e06f0cef446a5e3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/009ddd6c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list