[Git][security-tracker-team/security-tracker][master] Add new python-httpx2 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 2 21:23:45 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
74269644 by Salvatore Bonaccorso at 2026-09-02T22:23:24+02:00
Add new python-httpx2 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -141,15 +141,31 @@ CVE-2026-84646 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user obje
CVE-2026-84645 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of type ...)
NOT-FOR-US: Jenkins (core or plugin)
CVE-2026-84382 (HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, t ...)
- TODO: check
+ - python-httpx2 2.12.0-1
+ NOTE: https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m
+ NOTE: https://github.com/pydantic/httpx2/pull/1126
+ NOTE: Fixed by: https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8 (v2.12.0)
CVE-2026-84381 (HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, h ...)
- TODO: check
+ - python-httpx2 <not-affected> (Vulnerable code never in a Debian released version)
+ NOTE: https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p
+ NOTE: https://github.com/pydantic/httpx2/pull/1104
+ NOTE: Fixed by: https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453 (v2.10.0)
CVE-2026-84380 (HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, R ...)
- TODO: check
+ - python-httpx2 2.12.0-1
+ NOTE: https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566
+ NOTE: https://github.com/pydantic/httpx2/pull/1137
+ NOTE: Fixed by: https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab (v2.11.0)
CVE-2026-84379 (HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, F ...)
- TODO: check
+ - python-httpx2 2.12.0-1
+ NOTE: https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6
+ NOTE: https://github.com/pydantic/httpx2/pull/1142
+ NOTE: Fixed by: https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d (v2.11.0)
CVE-2026-84378 (HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2 ...)
- TODO: check
+ - python-httpx2 2.12.0-1
+ NOTE: https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp
+ NOTE: https://github.com/pydantic/httpx2/pull/1071
+ NOTE: https://github.com/pydantic/httpx2/pull/1117
+ NOTE: Fixed by: https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414 (v2.10.0)
CVE-2026-84377 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or ...)
NOT-FOR-US: LiteLLM
CVE-2026-84376 (Astro is a web framework for content-driven websites. Prior to 7.2.4, ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/742696444bc84690a07b640dac9f79c372cb0bcc
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/742696444bc84690a07b640dac9f79c372cb0bcc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/195fb201/attachment.htm>
More information about the debian-security-tracker-commits
mailing list