[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 3 08:27:30 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3e71f80c by Moritz Muehlenhoff at 2026-09-03T08:42:18+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -598,6 +598,7 @@ CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affe
NOT-FOR-US: Casdoor
CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
- node-js-yaml <unfixed>
+ [trixie] - node-js-yaml <no-dsa> (Minor issue)
NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
NOTE: https://github.com/nodeca/js-yaml/pull/797
NOTE: Fixed by: https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b (4.3.2)
@@ -1005,6 +1006,7 @@ CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an aut
NOT-FOR-US: Proxmox Virtual Environment
CVE-2026-82209
- curl 8.22.0-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-82209.html
NOTE: Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6 (curl-8_22_0)
@@ -1017,6 +1019,7 @@ CVE-2026-82208
NOTE: curl in Debian not built with wolfSSL support
CVE-2026-80255
- curl 8.22.0-1
+ [trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2026-80255.html
NOTE: Introduced with: https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603 (curl-8_13_0)
@@ -1028,11 +1031,13 @@ CVE-2026-80231
NOTE: Fixed by: https://github.com/curl/curl/commit/7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42 (rc-8_22_0-3)
CVE-2026-80230
- curl 8.22.0~rc3-1
+ [trixie] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-80230.html
NOTE: Introduced with: https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef (rc-8_22_0-3)
CVE-2026-80229
- curl 8.22.0~rc3-1
+ [trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2026-80229.html
NOTE: Introduced with: https://github.com/curl/curl/commit/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
@@ -1203,18 +1208,21 @@ CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83
NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe (v1.83.1)
CVE-2026-84270 (A flaw was found in the MTP backend in gvfs. When reading a file from ...)
- gvfs <unfixed> (bug #1146478)
+ [trixie] - gvfs <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/864
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/070e5e4223c97f7e793a342ba6e64df1095ccb0d (1.61.90)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/25add8b5103384c7edc8ad74722ed93eb3f6f077 (1.60.2)
CVE-2026-84269 (A flaw was found in the AFP backend in gvfs. When mounting a share, a ...)
- gvfs <unfixed> (bug #1146478)
+ [trixie] - gvfs <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/863
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/072a7e02d11f5b7dfa324b70dd0e16d60f9b9e60 (1.61.90)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/81525b2c917950554255784542674222bfee797d (1.60.2)
CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a share an ...)
- gvfs <unfixed> (bug #1146478)
+ [trixie] - gvfs <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/862
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/5ab77256f9c071c7c99a5298db1729cf143bff05 (1.61.90)
NOTE: Follow up: https://gitlab.gnome.org/GNOME/gvfs/-/commit/1ff24454d1c9b964a5f0efdd54c6d1421e770d64 (1.61.90)
@@ -1222,6 +1230,7 @@ CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a sh
NOTE: Follow up: https://gitlab.gnome.org/GNOME/gvfs/-/commit/1590471ad9c382de4fc544bdf49c8f424eea96f8 (1.60.2)
CVE-2026-84267 (A flaw was found in the SFTP backend in gvfs. When mounting a share, a ...)
- gvfs <unfixed> (bug #1146478)
+ [trixie] - gvfs <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/861
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/d9a59b8e385189b4783d9b66ca475f530fb26693 (1.61.90)
@@ -1230,6 +1239,7 @@ CVE-2026-84235 (A denial-of-service security issue exists in the affected produc
NOT-FOR-US: Rockwell Automation
CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...)
- rpm <unfixed>
+ [trixie] - rpm <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478409
TODO: check upstream details
CVE-2026-84232 (A flaw was found in pulpcore's content serving application. Files uplo ...)
@@ -2316,15 +2326,19 @@ CVE-2026-82664 (A security vulnerability has been detected in yaojingang GEOFlow
NOT-FOR-US: yaojingang GEOFlow
CVE-2026-82662 (Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ...)
- node-nodemailer 8.0.11+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-r7g4-qg5f-qqm2
CVE-2026-82661 (Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ...)
- node-nodemailer 8.0.11+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-268h-hp4c-crq3
CVE-2026-82660 (Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...)
- node-nodemailer 8.0.11+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
CVE-2026-82659 (nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...)
- node-nodemailer 9.0.3+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f
CVE-2026-82631 (A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ...)
- valkey <unfixed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e71f80c22453a39342751c4dd1d4d693a0bc9b6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e71f80c22453a39342751c4dd1d4d693a0bc9b6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/c93731ad/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list