[Git][security-tracker-team/security-tracker][master] Add note for CVE-2026-16221
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 31 21:26:09 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3a2dfbd2 by Salvatore Bonaccorso at 2026-07-31T22:25:41+02:00
Add note for CVE-2026-16221
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -12191,6 +12191,7 @@ CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including th
[bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
[bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx
+ NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
CVE-2026-16220 (A vulnerability has been found in code-projects Online Examination Sys ...)
NOT-FOR-US: code-projects
CVE-2026-16219 (A flaw has been found in Croogo CMS up to 4.0.7. This affects the func ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3a2dfbd2180024cd60feba124d2edf2df06b3982
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3a2dfbd2180024cd60feba124d2edf2df06b3982
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/1c293e61/attachment.htm>
More information about the debian-security-tracker-commits
mailing list