[Git][security-tracker-team/security-tracker][master] Add CVE-2026-40171

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun May 17 14:32:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
45f7f626 by Salvatore Bonaccorso at 2026-05-17T15:31:58+02:00
Add CVE-2026-40171

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7065,7 +7065,9 @@ CVE-2026-40281 (Gotenberg is a Docker-powered stateless API for PDF files. In ve
 CVE-2026-40174 (Masa CMS is a content management system forked from Mura CMS. In versi ...)
 	NOT-FOR-US: Masa CMS
 CVE-2026-40171 (In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions  ...)
-	TODO: check
+	- jupyter-notebook <unfixed>
+	- jupyterlab <unfixed>
+	NOTE: https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9
 CVE-2026-40076 (OpenMRS Core is an open source electronic medical record system platfo ...)
 	NOT-FOR-US: OpenMRS
 CVE-2026-40004 (There exists an openssl.cnf privilege escalation vulnerability in ZTE  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45f7f6269ae3fe643cf27414e432456e58e8687a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45f7f6269ae3fe643cf27414e432456e58e8687a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260517/f8fdbbc6/attachment.htm>


More information about the debian-security-tracker-commits mailing list