[Git][security-tracker-team/security-tracker][master] Add CVE-2026-9496/npm

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jun 4 23:09:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e2bc05ff by Salvatore Bonaccorso at 2026-06-05T00:09:08+02:00
Add CVE-2026-9496/npm

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8264,7 +8264,8 @@ CVE-2026-9498 (A vulnerability has been found in Dromara lamp-cloud up to 5.6.2.
 CVE-2026-9497 (A flaw has been found in changmingxie tcc-transaction up to 2.1.0. Thi ...)
 	NOT-FOR-US: changmingxie tcc-transaction
 CVE-2026-9496 (Versions of the package pacote from 11.2.7 are vulnerable to Denial of ...)
-	TODO: check
+	- npm <unfixed>
+	NOTE: https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084
 CVE-2026-9495 (Versions of the package @koa/router from 14.0.0 and before 15.0.0 are  ...)
 	NOT-FOR-US: koa/router
 CVE-2026-9486 (A security flaw has been discovered in SourceCodester Student Grades M ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2bc05ff0178c95579984974e922c61d18c4dc3e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2bc05ff0178c95579984974e922c61d18c4dc3e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260604/1bd11cce/attachment.htm>


More information about the debian-security-tracker-commits mailing list