[Git][security-tracker-team/security-tracker][master] Track fixed version for starlet via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue May 5 16:32:52 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
94829b0c by Salvatore Bonaccorso at 2026-05-05T17:31:59+02:00
Track fixed version for starlet via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -751,7 +751,7 @@ CVE-2026-2052 (The Widget Options \u2013 Advanced Conditional Visibility for Gut
CVE-2026-0703 (The NextMove Lite \u2013 Thank You Page for WooCommerce plugin for Wor ...)
NOT-FOR-US: WordPress plugin
CVE-2026-40561 (Starlet versions through 0.31 for Perl allows HTTP Request Smuggling v ...)
- - starlet <unfixed> (bug #1135584)
+ - starlet 0.31-3 (bug #1135584)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39593408/
NOTE: Fixed by: https://github.com/kazuho/Starlet/commit/a7d5dfd1862aafa43e5eaca0fdb6acf4cc15b2d0
CVE-2026-7647 (The Profile Builder Pro plugin for WordPress is vulnerable to PHP Obje ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/94829b0c6231d86464cd4cc47d2c749b888d26d6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/94829b0c6231d86464cd4cc47d2c749b888d26d6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260505/bf004e25/attachment.htm>
More information about the debian-security-tracker-commits
mailing list