[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 1 17:00:43 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
635491ca by Moritz Muehlenhoff at 2026-09-01T18:00:27+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -169,6 +169,7 @@ CVE-2026-82730 (Incorrect Authorization vulnerability in ash-project ash_typescr
 	NOT-FOR-US: ash-project
 CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
 	- pypdf <unfixed>
+	[trixie] - pypdf <no-dsa> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m
 	NOTE: https://github.com/py-pdf/pypdf/pull/3947
@@ -3264,18 +3265,22 @@ CVE-2026-3129 (The LiteSpeed Cache plugin for WordPress is vulnerable to Stored
 	NOT-FOR-US: WordPress plugin
 CVE-2026-38822 (In openNDS before 11.0.0, the client_params.sh script, invoked by the  ...)
 	- opennds <unfixed>
+	[trixie] - opennds <no-dsa> (Minor issue)
 	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/294983e859bb678eef7db06fc9f6afab0b489d8e (v11.0.0)
 CVE-2026-38821 (A heap-based buffer overflow vulnerability exists in openNDS before 11 ...)
 	- opennds <unfixed>
+	[trixie] - opennds <no-dsa> (Minor issue)
 	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9 (v11.0.0)
 CVE-2026-38820 (openNDS before 11.0.0 is susceptible to unauthenticated OS command exe ...)
 	- opennds <unfixed>
+	[trixie] - opennds <no-dsa> (Minor issue)
 	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252 (v11.0.0)
 CVE-2026-38819 (Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticate ...)
 	- opennds <unfixed>
+	[trixie] - opennds <no-dsa> (Minor issue)
 	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c (v11.0.0)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c (v11.0.0)
@@ -3445,6 +3450,7 @@ CVE-2026-80489
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34568
 CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a specially c ...)
 	- python-jwcrypto <unfixed> (bug #1145983)
+	[trixie] - python-jwcrypto <no-dsa> (Minor issue)
 	NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
 CVE-2026-81501
 	- incus 7.0.1-3
@@ -4460,6 +4466,7 @@ CVE-2023-27503
 	REJECTED
 CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the community.general  ...)
 	- ansible <unfixed>
+	[trixie] - ansible <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
 CVE-2026-78360
 	NOT-FOR-US: fedora-infra/anitya
@@ -6335,6 +6342,7 @@ CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh
 CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication  ...)
 	- ruby-doorkeeper-openid-connect 1.10.5-1
+	[trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
 	NOTE: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-8r7r-wh7x-27ff
 	NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/abb47dc5e6012ea05eda0b7979cc6bd41904011b (v1.10.4)
 CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
@@ -6552,6 +6560,7 @@ CVE-2026-45018 (Chainlit is a Python framework for building production-ready con
 	NOT-FOR-US: Chainlit
 CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, ...)
 	- ruby-doorkeeper-openid-connect 1.10.1-1
+	[trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
 	NOTE: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-m6vc-f87m-cc2h
 	NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/561af83dcf71b95b3772dfbc0a1796c7f50b2175 (v1.10.0)
 CVE-2026-43670 (A Content Security Policy bypass was addressed with improved enforceme ...)
@@ -10686,6 +10695,7 @@ CVE-2026-55095 (OpenProject is open-source, web-based project management softwar
 	NOT-FOR-US: OpenProject
 CVE-2026-54770 (WebOb provides objects for HTTP requests and responses. Prior to 1.8.1 ...)
 	- python-webob <unfixed>
+	[trixie] - python-webob <no-dsa> (Minor issue)
 	NOTE: https://github.com/Pylons/webob/security/advisories/GHSA-6hx8-3wjj-gr8g
 	NOTE: Fixed by: https://github.com/Pylons/webob/commit/ff89560643fb252751b4db8806a283b5377f1f07 (1.8.11)
 CVE-2026-54625 (django CMS is a content management system powered by Django. Prior to  ...)
@@ -16442,6 +16452,7 @@ CVE-2026-62982 (Glances is an open-source system cross-platform monitoring tool.
 	NOTE: CVE exists because of an incomplete fix for CVE-2026-32608.
 CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
 	- ruby-websocket-driver 0.8.2-1
+	[trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
 	NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-2x63-gw47-w4mm
 	NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/7d6fd87759a2fdc83590d3b49ffa661dc53fa128 (0.8.2)
 CVE-2026-60107
@@ -24882,10 +24893,11 @@ CVE-2026-71467 (A flaw was found in search-v2-api. The authentication middleware
 	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache HttpCompone ...)
 	- httpcomponents-core5 <unfixed>
-	- httpcomponents-client <undetermined>
+	[trixie] - httpcomponents-core5 <not-affected> (Vulnerable code not present, introduced in 5.4)
+	[bookworm] - httpcomponents-core5 <not-affected> (Vulnerable code not present, introduced in 5.4)
+	- httpcomponents-client <not-affected> (Introduced in 5.4)
 	NOTE: https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/6
-	TODO: check, claimed to affect only version 5.2 onwards
 CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of Red Hat Ad ...)
 	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-70339 (Access of resource using incompatible type ('type confusion') in Micro ...)
@@ -51926,6 +51938,7 @@ CVE-2024-23564 (HCL Aftermarket EPC is affected by Business Logic Vulnerability
 CVE-2026-14266 (7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Executio ...)
 	{DLA-4719-1 DLA-4718-1}
 	- 7zip 26.02+dfsg-1 (bug #1142293)
+	[trixie] - 7zip <no-dsa> (Minor issue, will be fixed via spu)
 	- p7zip 16.02+transitional.1
 	NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only an empty source package
 	NOTE: depending on 7zip. Mark this version as fixed version.
@@ -140388,11 +140401,13 @@ CVE-2026-28695 (Craft is a content management system (CMS). There is an authenti
 CVE-2026-28435 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
 	[experimental] - cpp-httplib 0.41.0+ds-1
 	- cpp-httplib 0.41.0+ds-3 (bug #1130234)
+	[trixie] - cpp-httplib <no-dsa> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xvfx-w463-6fpp
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/c99d7472b5cf4869d3897b9afc9792063a3d15a8 (v0.35.0)
 CVE-2026-28434 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
 	[experimental] - cpp-httplib 0.41.0+ds-1
 	- cpp-httplib 0.41.0+ds-3 (bug #1130232)
+	[trixie] - cpp-httplib <no-dsa> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8mpw-r4gc-xm7q
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/defd907c7469c5c8281247b73bbd07be24c31164 (v0.35.0)
 CVE-2026-28427 (OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/635491ca1e9e9b9b3209516c15f0f9482d500cad

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/635491ca1e9e9b9b3209516c15f0f9482d500cad
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/e714d557/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list