[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 1 17:00:43 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
635491ca by Moritz Muehlenhoff at 2026-09-01T18:00:27+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -169,6 +169,7 @@ CVE-2026-82730 (Incorrect Authorization vulnerability in ash-project ash_typescr
NOT-FOR-US: ash-project
CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
- pypdf <unfixed>
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m
NOTE: https://github.com/py-pdf/pypdf/pull/3947
@@ -3264,18 +3265,22 @@ CVE-2026-3129 (The LiteSpeed Cache plugin for WordPress is vulnerable to Stored
NOT-FOR-US: WordPress plugin
CVE-2026-38822 (In openNDS before 11.0.0, the client_params.sh script, invoked by the ...)
- opennds <unfixed>
+ [trixie] - opennds <no-dsa> (Minor issue)
[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/294983e859bb678eef7db06fc9f6afab0b489d8e (v11.0.0)
CVE-2026-38821 (A heap-based buffer overflow vulnerability exists in openNDS before 11 ...)
- opennds <unfixed>
+ [trixie] - opennds <no-dsa> (Minor issue)
[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9 (v11.0.0)
CVE-2026-38820 (openNDS before 11.0.0 is susceptible to unauthenticated OS command exe ...)
- opennds <unfixed>
+ [trixie] - opennds <no-dsa> (Minor issue)
[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252 (v11.0.0)
CVE-2026-38819 (Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticate ...)
- opennds <unfixed>
+ [trixie] - opennds <no-dsa> (Minor issue)
[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c (v11.0.0)
NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c (v11.0.0)
@@ -3445,6 +3450,7 @@ CVE-2026-80489
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34568
CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a specially c ...)
- python-jwcrypto <unfixed> (bug #1145983)
+ [trixie] - python-jwcrypto <no-dsa> (Minor issue)
NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
CVE-2026-81501
- incus 7.0.1-3
@@ -4460,6 +4466,7 @@ CVE-2023-27503
REJECTED
CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the community.general ...)
- ansible <unfixed>
+ [trixie] - ansible <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
CVE-2026-78360
NOT-FOR-US: fedora-infra/anitya
@@ -6335,6 +6342,7 @@ CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions
NOTE: https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh
CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication ...)
- ruby-doorkeeper-openid-connect 1.10.5-1
+ [trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
NOTE: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-8r7r-wh7x-27ff
NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/abb47dc5e6012ea05eda0b7979cc6bd41904011b (v1.10.4)
CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
@@ -6552,6 +6560,7 @@ CVE-2026-45018 (Chainlit is a Python framework for building production-ready con
NOT-FOR-US: Chainlit
CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, ...)
- ruby-doorkeeper-openid-connect 1.10.1-1
+ [trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
NOTE: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-m6vc-f87m-cc2h
NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/561af83dcf71b95b3772dfbc0a1796c7f50b2175 (v1.10.0)
CVE-2026-43670 (A Content Security Policy bypass was addressed with improved enforceme ...)
@@ -10686,6 +10695,7 @@ CVE-2026-55095 (OpenProject is open-source, web-based project management softwar
NOT-FOR-US: OpenProject
CVE-2026-54770 (WebOb provides objects for HTTP requests and responses. Prior to 1.8.1 ...)
- python-webob <unfixed>
+ [trixie] - python-webob <no-dsa> (Minor issue)
NOTE: https://github.com/Pylons/webob/security/advisories/GHSA-6hx8-3wjj-gr8g
NOTE: Fixed by: https://github.com/Pylons/webob/commit/ff89560643fb252751b4db8806a283b5377f1f07 (1.8.11)
CVE-2026-54625 (django CMS is a content management system powered by Django. Prior to ...)
@@ -16442,6 +16452,7 @@ CVE-2026-62982 (Glances is an open-source system cross-platform monitoring tool.
NOTE: CVE exists because of an incomplete fix for CVE-2026-32608.
CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
- ruby-websocket-driver 0.8.2-1
+ [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-2x63-gw47-w4mm
NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/7d6fd87759a2fdc83590d3b49ffa661dc53fa128 (0.8.2)
CVE-2026-60107
@@ -24882,10 +24893,11 @@ CVE-2026-71467 (A flaw was found in search-v2-api. The authentication middleware
NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache HttpCompone ...)
- httpcomponents-core5 <unfixed>
- - httpcomponents-client <undetermined>
+ [trixie] - httpcomponents-core5 <not-affected> (Vulnerable code not present, introduced in 5.4)
+ [bookworm] - httpcomponents-core5 <not-affected> (Vulnerable code not present, introduced in 5.4)
+ - httpcomponents-client <not-affected> (Introduced in 5.4)
NOTE: https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq
NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/6
- TODO: check, claimed to affect only version 5.2 onwards
CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of Red Hat Ad ...)
NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-70339 (Access of resource using incompatible type ('type confusion') in Micro ...)
@@ -51926,6 +51938,7 @@ CVE-2024-23564 (HCL Aftermarket EPC is affected by Business Logic Vulnerability
CVE-2026-14266 (7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Executio ...)
{DLA-4719-1 DLA-4718-1}
- 7zip 26.02+dfsg-1 (bug #1142293)
+ [trixie] - 7zip <no-dsa> (Minor issue, will be fixed via spu)
- p7zip 16.02+transitional.1
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only an empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -140388,11 +140401,13 @@ CVE-2026-28695 (Craft is a content management system (CMS). There is an authenti
CVE-2026-28435 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
[experimental] - cpp-httplib 0.41.0+ds-1
- cpp-httplib 0.41.0+ds-3 (bug #1130234)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xvfx-w463-6fpp
NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/c99d7472b5cf4869d3897b9afc9792063a3d15a8 (v0.35.0)
CVE-2026-28434 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
[experimental] - cpp-httplib 0.41.0+ds-1
- cpp-httplib 0.41.0+ds-3 (bug #1130232)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8mpw-r4gc-xm7q
NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/defd907c7469c5c8281247b73bbd07be24c31164 (v0.35.0)
CVE-2026-28427 (OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/635491ca1e9e9b9b3209516c15f0f9482d500cad
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/635491ca1e9e9b9b3209516c15f0f9482d500cad
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/e714d557/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list