[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 3 08:27:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3e71f80c by Moritz Muehlenhoff at 2026-09-03T08:42:18+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -598,6 +598,7 @@ CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affe
 	NOT-FOR-US: Casdoor
 CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
 	- node-js-yaml <unfixed>
+	[trixie] - node-js-yaml <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
 	NOTE: https://github.com/nodeca/js-yaml/pull/797
 	NOTE: Fixed by: https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b (4.3.2)
@@ -1005,6 +1006,7 @@ CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an aut
 	NOT-FOR-US: Proxmox Virtual Environment
 CVE-2026-82209
 	- curl 8.22.0-1
+	[trixie] - curl <no-dsa> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-82209.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6 (curl-8_22_0)
@@ -1017,6 +1019,7 @@ CVE-2026-82208
 	NOTE: curl in Debian not built with wolfSSL support
 CVE-2026-80255
 	- curl 8.22.0-1
+	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
 	NOTE: https://curl.se/docs/CVE-2026-80255.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603 (curl-8_13_0)
@@ -1028,11 +1031,13 @@ CVE-2026-80231
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42 (rc-8_22_0-3)
 CVE-2026-80230
 	- curl 8.22.0~rc3-1
+	[trixie] - curl <no-dsa> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-80230.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef (rc-8_22_0-3)
 CVE-2026-80229
 	- curl 8.22.0~rc3-1
+	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
 	NOTE: https://curl.se/docs/CVE-2026-80229.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
@@ -1203,18 +1208,21 @@ CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe (v1.83.1)
 CVE-2026-84270 (A flaw was found in the MTP backend in gvfs. When reading a file from  ...)
 	- gvfs <unfixed> (bug #1146478)
+	[trixie] - gvfs <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/864
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/070e5e4223c97f7e793a342ba6e64df1095ccb0d (1.61.90)
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/25add8b5103384c7edc8ad74722ed93eb3f6f077 (1.60.2)
 CVE-2026-84269 (A flaw was found in the AFP backend in gvfs. When mounting a share, a  ...)
 	- gvfs <unfixed> (bug #1146478)
+	[trixie] - gvfs <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/863
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/072a7e02d11f5b7dfa324b70dd0e16d60f9b9e60 (1.61.90)
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/81525b2c917950554255784542674222bfee797d (1.60.2)
 CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a share an ...)
 	- gvfs <unfixed> (bug #1146478)
+	[trixie] - gvfs <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/862
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/5ab77256f9c071c7c99a5298db1729cf143bff05 (1.61.90)
 	NOTE: Follow up: https://gitlab.gnome.org/GNOME/gvfs/-/commit/1ff24454d1c9b964a5f0efdd54c6d1421e770d64 (1.61.90)
@@ -1222,6 +1230,7 @@ CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a sh
 	NOTE: Follow up: https://gitlab.gnome.org/GNOME/gvfs/-/commit/1590471ad9c382de4fc544bdf49c8f424eea96f8 (1.60.2)
 CVE-2026-84267 (A flaw was found in the SFTP backend in gvfs. When mounting a share, a ...)
 	- gvfs <unfixed> (bug #1146478)
+	[trixie] - gvfs <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/861
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/d9a59b8e385189b4783d9b66ca475f530fb26693 (1.61.90)
@@ -1230,6 +1239,7 @@ CVE-2026-84235 (A denial-of-service security issue exists in the affected produc
 	NOT-FOR-US: Rockwell Automation
 CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...)
 	- rpm <unfixed>
+	[trixie] - rpm <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478409
 	TODO: check upstream details
 CVE-2026-84232 (A flaw was found in pulpcore's content serving application. Files uplo ...)
@@ -2316,15 +2326,19 @@ CVE-2026-82664 (A security vulnerability has been detected in yaojingang GEOFlow
 	NOT-FOR-US: yaojingang GEOFlow
 CVE-2026-82662 (Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-r7g4-qg5f-qqm2
 CVE-2026-82661 (Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-268h-hp4c-crq3
 CVE-2026-82660 (Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
 CVE-2026-82659 (nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...)
 	- node-nodemailer 9.0.3+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f
 CVE-2026-82631 (A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ...)
 	- valkey <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e71f80c22453a39342751c4dd1d4d693a0bc9b6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e71f80c22453a39342751c4dd1d4d693a0bc9b6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/c93731ad/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list