[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 1 08:12:55 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
174b9773 by security tracker role at 2026-09-01T07:12:48+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,303 @@
+CVE-2026-83772 (A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satell ...)
+ TODO: check
+CVE-2026-83744 (A security vulnerability has been detected in invoiceninja Invoice Nin ...)
+ TODO: check
+CVE-2026-83743 (A weakness has been identified in invoiceninja Invoice Ninja up to 5.1 ...)
+ TODO: check
+CVE-2026-83596 (A flaw was found in WebKitGTK. Processing malicious web content can ca ...)
+ TODO: check
+CVE-2026-83524 (A security vulnerability has been detected in RedPort Optimizer wXa-20 ...)
+ TODO: check
+CVE-2026-82971 (A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera1 ...)
+ TODO: check
+CVE-2026-82957 (A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. ...)
+ TODO: check
+CVE-2026-82954 (A vulnerability was detected in Dokploy up to 0.29.7. This issue affec ...)
+ TODO: check
+CVE-2026-82922 (A security vulnerability has been detected in ShopEx ECShop up to 2.5. ...)
+ TODO: check
+CVE-2026-82921 (A weakness has been identified in ShopEx ECShop up to 2.5.1. This affe ...)
+ TODO: check
+CVE-2026-82919 (A vulnerability was identified in cu silicon up to 0.1.5. Affected by ...)
+ TODO: check
+CVE-2026-82914 (A security flaw has been discovered in kishan0725 Hospital-Management- ...)
+ TODO: check
+CVE-2026-82909 (A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.1 ...)
+ TODO: check
+CVE-2026-82908 (A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affect ...)
+ TODO: check
+CVE-2026-82906 (A flaw has been found in sdcb chats up to 1.12.0. This impacts the fun ...)
+ TODO: check
+CVE-2026-82905 (A vulnerability was detected in sdcb chats up to 1.12.0. This affects ...)
+ TODO: check
+CVE-2026-82882 (Devtron through 2.2.0 fails to enforce authorization checks on the GET ...)
+ TODO: check
+CVE-2026-82852 (Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 ...)
+ TODO: check
+CVE-2026-82835 (A weakness has been identified in caoqianming django-vue-admin 1.0. Th ...)
+ TODO: check
+CVE-2026-82834 (A security flaw has been discovered in Doccano Open Source Annotation ...)
+ TODO: check
+CVE-2026-82833 (A vulnerability was identified in Doccano Open Source Annotation Tools ...)
+ TODO: check
+CVE-2026-82749 (Incorrect Authorization vulnerability in ash-project ash widens a rela ...)
+ TODO: check
+CVE-2026-82748 (Incorrect Authorization vulnerability in ash-project ash authorizes an ...)
+ TODO: check
+CVE-2026-82747 (Incorrect Authorization vulnerability in ash-project ash returns recor ...)
+ TODO: check
+CVE-2026-82746 (Missing Authorization vulnerability in ash-project ash allows an actor ...)
+ TODO: check
+CVE-2026-82745 (Improper Access Control vulnerability in ash-project ash lets a create ...)
+ TODO: check
+CVE-2026-82744 (Not Failing Securely (Failing Open) vulnerability in ash-project ash s ...)
+ TODO: check
+CVE-2026-82743 (Uncontrolled Resource Consumption vulnerability in ash-project ash let ...)
+ TODO: check
+CVE-2026-82742 (Uncontrolled Resource Consumption vulnerability in ash-project ash let ...)
+ TODO: check
+CVE-2026-82741 (Improper Validation of Specified Type of Input vulnerability in ash-pr ...)
+ TODO: check
+CVE-2026-82740 (Improper Input Validation vulnerability in ash-project ash fails to en ...)
+ TODO: check
+CVE-2026-82739 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
+ TODO: check
+CVE-2026-82738 (Improper Input Validation vulnerability in ash-project ash allows an a ...)
+ TODO: check
+CVE-2026-82737 (Integer Overflow or Wraparound vulnerability in ash-project ash lets a ...)
+ TODO: check
+CVE-2026-82736 (Incorrect Behavior Order: Validate Before Canonicalize vulnerability i ...)
+ TODO: check
+CVE-2026-82735 (Uncontrolled Resource Consumption vulnerability in ash-project ash all ...)
+ TODO: check
+CVE-2026-82734 (Improper Validation of Specified Quantity in Input vulnerability in as ...)
+ TODO: check
+CVE-2026-82733 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
+ TODO: check
+CVE-2026-82732 (Improper Input Validation vulnerability in ash-project ash_typescript ...)
+ TODO: check
+CVE-2026-82731 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in a ...)
+ TODO: check
+CVE-2026-82730 (Incorrect Authorization vulnerability in ash-project ash_typescript al ...)
+ TODO: check
+CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
+ TODO: check
+CVE-2026-82397 (Tornado is a Python web framework and asynchronous networking library. ...)
+ TODO: check
+CVE-2026-82396 (Sulu is an open-source PHP content management system based on the Symf ...)
+ TODO: check
+CVE-2026-82395 (Sulu is an open-source PHP content management system based on the Symf ...)
+ TODO: check
+CVE-2026-82394 (Sulu is an open-source PHP content management system based on the Symf ...)
+ TODO: check
+CVE-2026-82393 (pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts ...)
+ TODO: check
+CVE-2026-82392 (pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.1 ...)
+ TODO: check
+CVE-2026-82346 (A potential security vulnerability has been identified in the HP Image ...)
+ TODO: check
+CVE-2026-82229 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login a ...)
+ TODO: check
+CVE-2026-82228 (Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 v ...)
+ TODO: check
+CVE-2026-82226 (Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.)
+ TODO: check
+CVE-2026-82225 (Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 ...)
+ TODO: check
+CVE-2026-82224 (Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versio ...)
+ TODO: check
+CVE-2026-82221 (Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0 ...)
+ TODO: check
+CVE-2026-81892 (EasyAdmin is a fast and modern admin generator for Symfony application ...)
+ TODO: check
+CVE-2026-81891 (elFinder is an open-source file manager for web, written in JavaScript ...)
+ TODO: check
+CVE-2026-81890 (elFinder is an open-source file manager for web, written in JavaScript ...)
+ TODO: check
+CVE-2026-81889 (elFinder is an open-source file manager for web, written in JavaScript ...)
+ TODO: check
+CVE-2026-81888 (@hono/oauth-providers is Authentication middleware for Hono. Prior to ...)
+ TODO: check
+CVE-2026-81887 (Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 unti ...)
+ TODO: check
+CVE-2026-81780 (Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.)
+ TODO: check
+CVE-2026-81779 (Improper Validation of Specified Quantity in Input vulnerability in Si ...)
+ TODO: check
+CVE-2026-81778 (Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versio ...)
+ TODO: check
+CVE-2026-81768 (Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7. ...)
+ TODO: check
+CVE-2026-81765 (Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 ...)
+ TODO: check
+CVE-2026-81764 (Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0. ...)
+ TODO: check
+CVE-2026-81763 (Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.)
+ TODO: check
+CVE-2026-81762 (Subscriber Broken Access Control in Booking and Rental Manager <= 2.7. ...)
+ TODO: check
+CVE-2026-81758 (Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.)
+ TODO: check
+CVE-2026-81756 (Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters F ...)
+ TODO: check
+CVE-2026-81298 (Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 v ...)
+ TODO: check
+CVE-2026-81297 (Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2 ...)
+ TODO: check
+CVE-2026-81296 (Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack ...)
+ TODO: check
+CVE-2026-81293 (Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.)
+ TODO: check
+CVE-2026-81291 (Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 version ...)
+ TODO: check
+CVE-2026-81290 (Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & News ...)
+ TODO: check
+CVE-2026-81287 (Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.)
+ TODO: check
+CVE-2026-81280 (Subscriber Sensitive Data Exposure in Print Barcode Labels for your Wo ...)
+ TODO: check
+CVE-2026-81278 (Missing Authorization vulnerability in WPExperts Post SMTP allows Expl ...)
+ TODO: check
+CVE-2026-81267 (A malicious webpage could stall a popup's cross-origin navigation afte ...)
+ TODO: check
+CVE-2026-79483 (FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a No ...)
+ TODO: check
+CVE-2026-79408 (An OS command injection vulnerability in MetaGPT 0.8.1 allows an attac ...)
+ TODO: check
+CVE-2026-79407 (A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 a ...)
+ TODO: check
+CVE-2026-78319 (A service running on the affected products contains a potential Time-o ...)
+ TODO: check
+CVE-2026-77950 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
+ TODO: check
+CVE-2026-77856 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
+ TODO: check
+CVE-2026-77823 (The LearnPress plugin for WordPress is vulnerable to SQL Injection via ...)
+ TODO: check
+CVE-2026-77353 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-77352 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-77351 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-77348 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-77189 (The Charitable \u2013 Donation & Fundraising Platform (Donation Forms, ...)
+ TODO: check
+CVE-2026-76006 (The Photo Gallery by Ays \u2013 Responsive Image Gallery plugin for Wo ...)
+ TODO: check
+CVE-2026-75980 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, F ...)
+ TODO: check
+CVE-2026-75965 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
+ TODO: check
+CVE-2026-75964 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
+ TODO: check
+CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons, Widgets, Mega ...)
+ TODO: check
+CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent Management for ...)
+ TODO: check
+CVE-2026-75594 (Kirby is an open-source content management system. Prior to 4.9.5 and ...)
+ TODO: check
+CVE-2026-75592 (Kirby is an open-source content management system. Prior to 4.9.5 and ...)
+ TODO: check
+CVE-2026-75460 (XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation v ...)
+ TODO: check
+CVE-2026-75458 (The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhi ...)
+ TODO: check
+CVE-2026-74837 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
+ TODO: check
+CVE-2026-71415 (Kirby is an open-source content management system. From 5.0.0 until 5. ...)
+ TODO: check
+CVE-2026-67395 (A path traversal vulnerability exists in Sage Employee Self Service\u2 ...)
+ TODO: check
+CVE-2026-67394 (A critical local privilege escalation via OS command injection vulnera ...)
+ TODO: check
+CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote authenti ...)
+ TODO: check
+CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
+ TODO: check
+CVE-2026-61641 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-61640 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-61639 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-61638 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-54600 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-54599 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-54598 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-54179 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions ...)
+ TODO: check
+CVE-2026-52730 (Xibo is an open source digital signage platform with a web content man ...)
+ TODO: check
+CVE-2026-51740 (Incorrect access control in the killProcess function of TOTOLINK T6 4. ...)
+ TODO: check
+CVE-2026-51739 (Incorrect access control in the CloudSrvVersionCheck function of TOTOL ...)
+ TODO: check
+CVE-2026-51738 (Incorrect access control in the LoadDefSettings function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51737 (Incorrect access control in the clearTracerouteLog function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51736 (Incorrect access control in the clearSyslog function of TOTOLINK T6 4. ...)
+ TODO: check
+CVE-2026-51735 (Incorrect access control in the showSyslog function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51734 (Incorrect access control in the informSlaveUpdate function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51733 (Incorrect access control in the FirmwareUpgrade function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51731 (Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
+ TODO: check
+CVE-2026-4560
+ REJECTED
+CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request desynchronization fo ...)
+ TODO: check
+CVE-2026-38577 (Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0 ...)
+ TODO: check
+CVE-2026-19952 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2026-19948 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 70 ...)
+ TODO: check
+CVE-2026-19820 (A vulnerability in the Backblaze Client allows a local user to make th ...)
+ TODO: check
+CVE-2026-19806 (The Support Genix \u2013 Helpdesk, AI Chatbot, Knowledge Base & Custom ...)
+ TODO: check
+CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds Ads Listin ...)
+ TODO: check
+CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is vulnerable to St ...)
+ TODO: check
+CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path resolves an att ...)
+ TODO: check
+CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to generic SQL ...)
+ TODO: check
+CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an attacker to pro ...)
+ TODO: check
+CVE-2026-18488 (The Blocksy Companion plugin for WordPress is vulnerable to Stored Cro ...)
+ TODO: check
+CVE-2026-17589 (The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable ...)
+ TODO: check
+CVE-2026-16787 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
+ TODO: check
+CVE-2026-14697 (net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit ne ...)
+ TODO: check
+CVE-2026-13732 (A flaw was found in GDB's STABS debug format parser. The read_member_f ...)
+ TODO: check
+CVE-2026-13203 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
+ TODO: check
+CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_ ...)
+ TODO: check
CVE-2026-XXXX [GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items]
- libheif 1.23.2-1
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
@@ -10595,6 +10895,7 @@ CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an
CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was identified in T ...)
NOT-FOR-US: TPLink
CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with custom en ...)
+ {DLA-4765-1}
- expat 2.8.4-1 (bug #1144927)
[trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1322
@@ -29687,7 +29988,7 @@ CVE-2026-XXXX [Neutron sub-resource APIs do not verify parent ownership]
NOTE: https://review.opendev.org/c/openstack/neutron/+/989624/
NOTE: https://review.opendev.org/c/openstack/neutron/+/991586
CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant infinite ...)
- {DSA-6446-1}
+ {DSA-6446-1 DLA-4765-1}
- expat 2.8.3-1 (bug #1144064)
NOTE: https://github.com/libexpat/libexpat/pull/1296
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
@@ -72225,52 +72526,52 @@ CVE-2026-11745 (A vulnerability has been identified in centraldogma-server-mirro
CVE-2026-10530 (The Pie Register WordPress plugin before 3.8.4.10 does not use suffic ...)
NOT-FOR-US: WordPress plugin
CVE-2026-56412 (libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataS ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1278
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/d19e834794060d18c061d94452c35d725393ea58
CVE-2026-56411 (xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDe ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1263
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5
CVE-2026-56410 (xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSyste ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1252
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea
CVE-2026-56409 (xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1259
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e
CVE-2026-56408 (libexpat before 2.8.2 has an integer overflow in copyString.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817
CVE-2026-56407 (libexpat before 2.8.2 has an integer overflow in doProlog that is rela ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1262
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13
CVE-2026-56406 (libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer becau ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1255
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d
CVE-2026-56405 (libexpat before 2.8.2 has an integer overflow in getAttributeId.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1251
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0
CVE-2026-56404 (libexpat before 2.8.2 has an integer overflow in addBinding.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1249
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164
CVE-2026-56403 (libexpat before 2.8.2 has an integer overflow in storeAtts.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1232
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648
@@ -72940,7 +73241,7 @@ CVE-2026-56132 (In libexpat before 2.8.2, there is a heap-based buffer overflow
- expat 2.8.2-1 (bug #1140388)
NOTE: https://github.com/libexpat/libexpat/pull/1272
CVE-2026-56131 (libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140387)
NOTE: https://github.com/libexpat/libexpat/pull/1267
CVE-2026-56099 (OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds r ...)
@@ -84128,7 +84429,7 @@ CVE-2026-50292 (In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-dev
NOTE: Fixed by: https://gitlab.freedesktop.org/libinput/libinput/-/commit/b2bde9504d42a5976d76e1f27c640dc561fbd99b (1.30.4)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/04/5
CVE-2026-50219 (libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1138862)
NOTE: https://github.com/libexpat/libexpat/pull/1246
CVE-2026-8829 (HTML::Entities versions before 3.84 for Perl read freed heap memory in ...)
@@ -162176,7 +162477,7 @@ CVE-2026-22246 (Mastodon is a free, open-source social network server based on A
- mastodon <itp> (bug #859741)
CVE-2026-22245 (Mastodon is a free, open-source social network server based on Activit ...)
- mastodon <itp> (bug #859741)
-CVE-2026-22244 (OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 ...)
+CVE-2026-22244 (OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1. ...)
NOT-FOR-US: OpenMetadata
CVE-2026-22242 (CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4. ...)
NOT-FOR-US: CoreShop
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174b9773ede45a4b75ae17de8b406f6b5bf44561
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174b9773ede45a4b75ae17de8b406f6b5bf44561
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/c976268e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list