[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-42500/golang-golang-x-image
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jun 15 19:36:53 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1f2658e5 by Salvatore Bonaccorso at 2026-06-15T20:34:19+02:00
Update status for CVE-2026-42500/golang-golang-x-image
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9678,10 +9678,11 @@ CVE-2026-44287 (FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1,
CVE-2026-44285 (FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Ser ...)
NOT-FOR-US: FastGPT
CVE-2026-42500 (Decoding a paletted BMP file with an out-of-range palette index result ...)
- - golang-golang-x-image <unfixed> (bug #1138257)
+ - golang-golang-x-image 0.42.0-1 (bug #1138257)
[bullseye] - golang-golang-x-image <no-dsa> (Minor issue)
NOTE: https://github.com/golang/go/issues/79576
NOTE: https://go-review.googlesource.com/c/image/+/781500
+ NOTE: Fixed by: https://github.com/golang/image/commit/0d61147654dcd60265f4bfa72e5f66f578630e22 (v0.41.0)
CVE-2026-34127 (A stored cross-site scripting (XSS) vulnerability has been identified ...)
NOT-FOR-US: TPLink
CVE-2026-10110 (A vulnerability was detected in code-projects Student Details Manageme ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f2658e557f1d4500d15088c4476f8875b760c96
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f2658e557f1d4500d15088c4476f8875b760c96
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260615/15e89fbd/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list