[Git][security-tracker-team/security-tracker][master] Add CVE-2026-84308/phpseclib
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 2 21:54:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b0c6c2f9 by Salvatore Bonaccorso at 2026-09-02T22:52:23+02:00
Add CVE-2026-84308/phpseclib
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -610,7 +610,12 @@ CVE-2026-84361 (Composer is a dependency Manager for the PHP language. From 1.0
CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
TODO: check
CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 3.0.57 and ...)
- TODO: check
+ - php-phpseclib4 4.0.1-1
+ - php-phpseclib3 3.0.57-1
+ - php-phpseclib <not-affected> (Vulnerable code not present)
+ - phpseclib <not-affected> (Vulnerable code not present)
+ NOTE: https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6
+ NOTE: Fixed by: https://github.com/phpseclib/phpseclib/commit/fb56bc5bb9009b54a6c26b31aeec8ed944f17373 (4.0.1, 3.0.57)
CVE-2026-84307 (Filament is a collection of full-stack components for accelerated Lara ...)
NOT-FOR-US: Filament
CVE-2026-84306 (Filament is a collection of full-stack components for accelerated Lara ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0c6c2f993a94ae42bca43a617d6852627d6b328
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0c6c2f993a94ae42bca43a617d6852627d6b328
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/8b6c877b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list