[Git][security-tracker-team/security-tracker][master] Add CVE-2026-54522/ruby-msgpack
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 21:33:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4dba3389 by Salvatore Bonaccorso at 2026-07-30T22:31:06+02:00
Add CVE-2026-54522/ruby-msgpack
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -59,7 +59,9 @@ CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta al
CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of utilities and ...)
NOT-FOR-US: DSSRF
CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack binary se ...)
- TODO: check
+ - ruby-msgpack 1.8.3-1
+ NOTE: https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938
+ NOTE: Fixed by: https://github.com/msgpack/msgpack-ruby/commit/5627d71606b565641d2dd501b82aae862f4abe90 (v1.8.2)
CVE-2026-54368 (CentreStack before 17.4 contains a SQL injection vulnerability in Glad ...)
NOT-FOR-US: CentreStack
CVE-2026-54367 (CentreStack before 17.2 contains an authentication bypass vulnerabilit ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4dba3389175b3617e9041c2e92cb75489b593c32
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4dba3389175b3617e9041c2e92cb75489b593c32
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/c2e61624/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list