[Git][security-tracker-team/security-tracker][master] Add CVE-2026-75758/elixir-lang

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 07:47:40 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e35168c4 by Salvatore Bonaccorso at 2026-09-03T08:28:49+02:00
Add CVE-2026-75758/elixir-lang

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3805,7 +3805,16 @@ CVE-2026-77701 (The WCFM Marketplace  WordPress plugin before 3.8.2 does not cor
 CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentic ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard library al ...)
-	TODO: check
+	- elixir-lang <unfixed>
+	[bookworm] - elixir-lang <not-affected> (Vulnerable code introduced later)
+	NOTE: https://github.com/elixir-lang/elixir/security/advisories/GHSA-jf5q-v438-665c
+	NOTE: https://cna.erlef.org/cves/CVE-2026-75758.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-75758
+	NOTE: Introduced with: https://github.com/elixir-lang/elixir/commit/9718f2b90ce086ff8614d5782f4ec528495c98dd (v1.15.0-rc.0)
+	NOTE: Fixed by: https://github.com/elixir-lang/elixir/commit/1eff1acffd49bdcc0d7f57ca74c1603328eed68a (main)
+	NOTE: Fixed by: https://github.com/elixir-lang/elixir/commit/0bba5887577b1e328da825bd018815fdc519685a (v1.20.4)
+	NOTE: Fixed by: https://github.com/elixir-lang/elixir/commit/a983c8c043b1fbf1d95df78a29149222dac2988c (v1.19.6)
+	NOTE: Fixed by: https://github.com/elixir-lang/elixir/commit/5230d73968f1b4969d2a2646786fa6c71475f5cc (v1.18.5)
 CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
 	NOT-FOR-US: SOY
 CVE-2026-73209 (An attacker that has valid credentials can send crafted compressed dat ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e35168c4277a75e93ce6aee6e7efbdf7b377e6f4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e35168c4277a75e93ce6aee6e7efbdf7b377e6f4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/efd8c677/attachment.htm>


More information about the debian-security-tracker-commits mailing list