[Git][security-tracker-team/security-tracker][master] Add two new starlette issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jun 22 20:57:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b6b6d306 by Salvatore Bonaccorso at 2026-06-22T21:57:24+02:00
Add two new starlette issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -93,9 +93,15 @@ CVE-2026-54286 (Hono is a Web application framework that provides support for an
 CVE-2026-54285 (opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8. ...)
 	TODO: check
 CVE-2026-54283 (Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1. ...)
-	TODO: check
+	- starlette <unfixed>
+	NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
+	NOTE: https://github.com/Kludex/starlette/pull/3329
+	NOTE: Fixed by: https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735 (1.3.1)
 CVE-2026-54282 (Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the ...)
-	TODO: check
+	- starlette <unfixed>
+	NOTE: https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3
+	NOTE: https://github.com/Kludex/starlette/pull/3326
+	NOTE: Fixed by: https://github.com/Kludex/starlette/commit/167b5850e809f38b27fbfed62d58bf6442855975 (1.3.0)
 CVE-2026-54280 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
 	TODO: check
 CVE-2026-54279 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6b6d30680d81f9f580b38f57b1995e27f16fdf1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6b6d30680d81f9f580b38f57b1995e27f16fdf1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260622/19e35948/attachment.htm>


More information about the debian-security-tracker-commits mailing list