[Git][security-tracker-team/security-tracker][master] Add CVE-2026-18446/node-ajv (providing fast-uri)
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 31 21:18:38 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bfafec33 by Salvatore Bonaccorso at 2026-07-31T22:14:43+02:00
Add CVE-2026-18446/node-ajv (providing fast-uri)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -197,7 +197,10 @@ CVE-2026-21662 (Unrestricted upload of file with dangerous type vulnerability in
CVE-2026-18481 (Stored cross-site scripting in the participant URL handling in AWS Ops ...)
NOT-FOR-US: Amazon
CVE-2026-18446 (fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forw ...)
- TODO: check
+ - node-ajv <unfixed>
+ [trixie] - node-ajv <no-dsa> (Minor issue)
+ NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7
+ NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
CVE-2026-18437 (The MailerPress \u2013 Newsletter, email marketing & AI automation plu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18436 (The MailPress plugin for WordPress is vulnerable to unauthorized acces ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bfafec331d64c5676ab35b449b03f1382c1a624a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bfafec331d64c5676ab35b449b03f1382c1a624a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/191c4f79/attachment.htm>
More information about the debian-security-tracker-commits
mailing list