[Git][security-tracker-team/security-tracker][master] Track fixed version for various pytho-git issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 1 04:36:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b46ca187 by Salvatore Bonaccorso at 2026-09-01T05:36:00+02:00
Track fixed version for various pytho-git issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6975,19 +6975,19 @@ CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute paths
 	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6hwm-xvph-95vm
 CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read vulnerability  ...)
-	- python-git <unfixed> (bug #1145672)
+	- python-git 3.1.61-1 (bug #1145672)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg
 CVE-2026-78678 (GitPython versions before 3.1.59 contain an incomplete denylist in the ...)
-	- python-git <unfixed> (bug #1145672)
+	- python-git 3.1.61-1 (bug #1145672)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287
 CVE-2026-78677 (GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone ...)
-	- python-git <unfixed> (bug #1145672)
+	- python-git 3.1.61-1 (bug #1145672)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc
 CVE-2026-78676 (GitPython before 3.1.59 fails to safely re-serialize multi-line git-co ...)
-	- python-git <unfixed> (bug #1145672)
+	- python-git 3.1.61-1 (bug #1145672)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w
 CVE-2026-78675 (GitPython before 3.1.59 fails to disable merge_includes when parsing . ...)
-	- python-git <unfixed> (bug #1145672)
+	- python-git 3.1.61-1 (bug #1145672)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q
 CVE-2026-78656 (A vulnerability was found in itsourcecode Sales and Inventory System 1 ...)
 	NOT-FOR-US: itsourcecode System
@@ -11437,22 +11437,22 @@ CVE-2026-76224 (ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) co
 CVE-2026-76223 (ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce th ...)
 	NOT-FOR-US: ArcadeDB
 CVE-2026-76222 (GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)
-	- python-git <unfixed> (bug #1144929)
+	- python-git 3.1.61-1 (bug #1144929)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc
 CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection vulnerability ...)
-	- python-git <unfixed> (bug #1144929)
+	- python-git 3.1.61-1 (bug #1144929)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgr
 CVE-2026-76220 (GitPython before 3.1.58 contains a command execution vulnerability in  ...)
-	- python-git <unfixed> (bug #1144929)
+	- python-git 3.1.61-1 (bug #1144929)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j
 CVE-2026-76219 (GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...)
-	- python-git <unfixed> (bug #1144929)
+	- python-git 3.1.61-1 (bug #1144929)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p
 CVE-2026-76218 (GitPython before 3.1.58 contains a remote code execution vulnerability ...)
-	- python-git <unfixed> (bug #1144929)
+	- python-git 3.1.61-1 (bug #1144929)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r
 CVE-2026-76217 (GitPython versions before 3.1.58 fail to validate options passed to gi ...)
-	- python-git <unfixed> (bug #1144929)
+	- python-git 3.1.61-1 (bug #1144929)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc
 CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion vulnerabilit ...)
 	NOT-FOR-US: Vikunja
@@ -22368,26 +22368,26 @@ CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allow
 	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j
 	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
 CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code execution vulne ...)
-	- python-git <unfixed> (bug #1144344)
+	- python-git 3.1.61-1 (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3
 CVE-2026-73624 (GitPython versions before 3.1.54 contain an arbitrary file overwrite v ...)
-	- python-git <unfixed> (bug #1144344)
+	- python-git 3.1.61-1 (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-x663-mwxc
 CVE-2026-73623 (GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_ ...)
-	- python-git <unfixed> (bug #1144344)
+	- python-git 3.1.61-1 (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-6p8h-3wgx-97gf
 CVE-2026-73622 (GitPython before 3.1.55 fails to disable environment variable expansio ...)
-	- python-git <unfixed> (bug #1144344)
+	- python-git 3.1.61-1 (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-94p4-4cq8-9g67
 	NOTE: Distinct but releated to CVE-2026-67322
 CVE-2026-73621 (GitPython before 3.1.56 contains an argument injection vulnerability i ...)
-	- python-git <unfixed> (bug #1144344)
+	- python-git 3.1.61-1 (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-p538-c434-8v24
 CVE-2026-73620 (GitPython before 3.1.57 fails to guard git option forwarding in IndexF ...)
-	- python-git <unfixed> (bug #1144344)
+	- python-git 3.1.61-1 (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3f7w-8rr8-f37f
 CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the unsafe_ ...)
-	- python-git <unfixed> (bug #1144344)
+	- python-git 3.1.61-1 (bug #1144344)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-539m-9xh6-q6rr
 CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection vulnerability ...)
 	NOT-FOR-US: Budibase
@@ -33842,7 +33842,7 @@ CVE-2026-69151 (Angular is a development platform for building mobile and deskto
 CVE-2026-69149 (Angular is a development platform for building mobile and desktop web  ...)
 	- angular.js <unfixed>
 CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names in git  ...)
-	- python-git <unfixed> (bug #1143602)
+	- python-git 3.1.61-1 (bug #1143602)
 	[trixie] - python-git <no-dsa> (Minor issue)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2
 CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots co ...)
@@ -34532,16 +34532,16 @@ CVE-2026-67326 (GitPython before 3.1.50 fails to validate newline characters in
 	- python-git 3.1.50-1
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w
 CVE-2026-67325 (GitPython before 3.1.51 contains an incomplete command injection block ...)
-	- python-git <unfixed> (bug #1143454)
+	- python-git 3.1.61-1 (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx
 CVE-2026-67324 (GitPython 3.1.50 fails to recognize joined short-option forms such as  ...)
-	- python-git <unfixed> (bug #1143454)
+	- python-git 3.1.61-1 (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v396-v7q4-x2qj
 CVE-2026-67323 (GitPython before 3.1.51 fails to guard against dangerous Git options p ...)
-	- python-git <unfixed> (bug #1143454)
+	- python-git 3.1.61-1 (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v
 CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable exfiltra ...)
-	- python-git <unfixed> (bug #1143454)
+	- python-git 3.1.61-1 (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
 CVE-2026-67321 (axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...)
 	- node-axios 1.18.0-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b46ca1875b661a5b73d8bb15f10e22d9e43e4bb5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b46ca1875b661a5b73d8bb15f10e22d9e43e4bb5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/5dd28a66/attachment.htm>


More information about the debian-security-tracker-commits mailing list