[Git][security-tracker-team/security-tracker][master] Add new goaccess issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 31 09:26:56 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cedb3f42 by Salvatore Bonaccorso at 2026-07-31T10:26:23+02:00
Add new goaccess issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -115,9 +115,13 @@ CVE-2026-56671 (ComfyUI is a modular diffusion model GUI, api and backend with a
CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with a graph ...)
NOT-FOR-US: ComfyUI
CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- TODO: check
+ - goaccess <unfixed>
+ NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg
+ NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81 (v1.11)
CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- TODO: check
+ - goaccess <unfixed>
+ NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46
+ NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5 (v1.11)
CVE-2026-55502 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
NOT-FOR-US: Cloudreve
CVE-2026-55499 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
@@ -129,7 +133,9 @@ CVE-2026-55496 (Cloudreve is a self-hosted file management and sharing system. P
CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
NOT-FOR-US: Cloudreve
CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- TODO: check
+ - goaccess <unfixed>
+ NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr
+ NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/81f90d9dafd6956c188dea9f944d24946d3d3351 (v1.11)
CVE-2026-52539 (Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When t ...)
NOT-FOR-US: Outstatic CMS
CVE-2026-43833 (Full details and mitigation steps are currently restricted and will be ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cedb3f422fc10de4bf453726b122f4ef4cf474e2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cedb3f422fc10de4bf453726b122f4ef4cf474e2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/92c1585c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list