[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 20:12:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ba14af78 by security tracker role at 2026-09-03T19:12:42+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,153 +1,629 @@
+CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users having acc ...)
+	TODO: check
+CVE-2026-9853 (A vulnerability exists in SYS600 which allows any user authenticated t ...)
+	TODO: check
+CVE-2026-9852 (A CSV injection vulnerability exists in SYS600. Injected malicious for ...)
+	TODO: check
+CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path traversal vulnerability i ...)
+	TODO: check
+CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store, update, and ke ...)
+	TODO: check
+CVE-2026-85394 (python-jose through 3.5.0 fails to properly validate asymmetric keys i ...)
+	TODO: check
+CVE-2026-85393 (node-forge through 1.4.0 fails to validate element count in nested Dig ...)
+	TODO: check
+CVE-2026-85392 (Peppermint through 0.5.5 contains an authorization bypass vulnerabilit ...)
+	TODO: check
+CVE-2026-85391 (Peppermint through 0.5.5 contains a hardcoded JWT signing secret in do ...)
+	TODO: check
+CVE-2026-85390 (Checkmate through 3.11.0 omits the isAllowed role guard middleware on  ...)
+	TODO: check
+CVE-2026-85389 (Worklenz before 3.0.0 fails to verify task ownership by organization w ...)
+	TODO: check
+CVE-2026-85388 (Worklenz through 3.0.0 fails to properly validate the sort-field query ...)
+	TODO: check
+CVE-2026-85309 (Missing Authorization vulnerability in Supsystic Ultimate Maps by Sups ...)
+	TODO: check
+CVE-2026-85308 (Authorization Bypass Through User-Controlled Key vulnerability in Brai ...)
+	TODO: check
+CVE-2026-85307 (Insertion of Sensitive Information Into Sent Data vulnerability in Kev ...)
+	TODO: check
+CVE-2026-85306 (Missing Authorization vulnerability in Cascadia Web Services MountDev  ...)
+	TODO: check
+CVE-2026-85305 (Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Se ...)
+	TODO: check
+CVE-2026-85304 (Missing Authorization vulnerability in Unlimited Elements Unlimited El ...)
+	TODO: check
+CVE-2026-85303 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-85302 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-85242 (PlaywrightCapture contains a server-side request forgery (SSRF) vulner ...)
+	TODO: check
+CVE-2026-85239 (A vulnerability in MISP's event template handling allowed an authentic ...)
+	TODO: check
+CVE-2026-85238 (MISP contains a session fixation vulnerability in the CustomAuth authe ...)
+	TODO: check
+CVE-2026-85237 (A vulnerability in MISP's email-based one-time password (OTP) authenti ...)
+	TODO: check
+CVE-2026-85236 (A cross-site request forgery (CSRF) vulnerability existed in the cullE ...)
+	TODO: check
+CVE-2026-85230 (A persistent unsafe URL injection vulnerability exists in the MISP das ...)
+	TODO: check
+CVE-2026-85227 (MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in  ...)
+	TODO: check
+CVE-2026-85226 (MISP contains an authorization flaw in the OnDemand correlation engine ...)
+	TODO: check
+CVE-2026-85221 (MISP contains an improper TLS certificate validation vulnerability in  ...)
+	TODO: check
+CVE-2026-85216 (MISP contains an authentication bypass vulnerability in its LDAP and L ...)
+	TODO: check
+CVE-2026-85214 (vhr fails to validate user authorization in the PUT /hr/info endpoint, ...)
+	TODO: check
+CVE-2026-85213 (Kill Bill through 0.24.21 fails to enforce permission annotations on s ...)
+	TODO: check
+CVE-2026-85212 (CRMEB contains an authentication bypass vulnerability in the verifyAut ...)
+	TODO: check
+CVE-2026-85211 (Label Studio fails to apply organization filters when resolving storag ...)
+	TODO: check
+CVE-2026-85210 (Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is  ...)
+	TODO: check
+CVE-2026-85205 (A vulnerability was determined in itsourcecode Online Medicine Deliver ...)
+	TODO: check
+CVE-2026-85199 (Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a pat ...)
+	TODO: check
+CVE-2026-85187 (A security vulnerability has been detected in itsourcecode Online Medi ...)
+	TODO: check
+CVE-2026-85186 (A weakness has been identified in itsourcecode Online Medicine Deliver ...)
+	TODO: check
+CVE-2026-85183 (Taipy configures its socket.io server with wildcard CORS origin and cr ...)
+	TODO: check
+CVE-2026-85182 (vhr through commit 03abbd3 fails to verify that the account ID in PUT  ...)
+	TODO: check
+CVE-2026-85181 (CAT uses Java String.hashCode as the sole integrity check for session  ...)
+	TODO: check
+CVE-2026-85180 (Ollama fails to validate redirect destinations when pulling tensor-lay ...)
+	TODO: check
+CVE-2026-85179 (Label Studio through 1.23.0 fails to validate webhook URLs, allowing a ...)
+	TODO: check
+CVE-2026-85178 (Helicone's VaultManager.getDecryptedProviderKeyById() function in the  ...)
+	TODO: check
+CVE-2026-85177 (CRMEB through 6.0.0 fails to validate message ownership in the edit_me ...)
+	TODO: check
+CVE-2026-85176 (DbGate fails to validate jslid parameters in the jsldata controller, a ...)
+	TODO: check
+CVE-2026-85175 (SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete block ...)
+	TODO: check
+CVE-2026-85174 (SiYuan before v3.8.2 logs API tokens from query parameters in plaintex ...)
+	TODO: check
+CVE-2026-85173 (n8n versions before 2.36.2 contain a missing per-project authorization ...)
+	TODO: check
+CVE-2026-85172 (n8n versions before 2.34.1 contain a server-side request forgery vulne ...)
+	TODO: check
+CVE-2026-85171 (n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure ...)
+	TODO: check
+CVE-2026-85170 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content  ...)
+	TODO: check
+CVE-2026-85169 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression ...)
+	TODO: check
+CVE-2026-85168 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code ...)
+	TODO: check
+CVE-2026-85167 (n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection v ...)
+	TODO: check
+CVE-2026-85166 (n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credentia ...)
+	TODO: check
+CVE-2026-85165 (n8n versions before 2.36.2 contain an expression sandbox bypass vulner ...)
+	TODO: check
+CVE-2026-85164 (WWBN AVideo through commit c91b5975d contains a server-side request fo ...)
+	TODO: check
+CVE-2026-85163 (AVideo through commit c91b5975d contains a server-side request forgery ...)
+	TODO: check
+CVE-2026-85162 (AVideo through commit c91b5975d contains a cross-site request forgery  ...)
+	TODO: check
+CVE-2026-85161 (AVideo through commit c91b5975d contains a cross-site request forgery  ...)
+	TODO: check
+CVE-2026-85160 (AVideo through commit c91b5975d contains a cross-site request forgery  ...)
+	TODO: check
+CVE-2026-85159 (AVideo through commit c91b5975d contains a reflected cross-site script ...)
+	TODO: check
+CVE-2026-85158 (AVideo through commit c91b5975d contains a reflected cross-site script ...)
+	TODO: check
+CVE-2026-85157 (WWBN AVideo contains a broken access control vulnerability in the unau ...)
+	TODO: check
+CVE-2026-85156 (WWBN AVideo fails to properly validate access controls on the public c ...)
+	TODO: check
+CVE-2026-85155 (WWBN AVideo contains a SQL injection vulnerability in the sort column  ...)
+	TODO: check
+CVE-2026-85154 (WWBN AVideo contains an authentication failure vulnerability where the ...)
+	TODO: check
+CVE-2026-85150 (A NULL pointer dereference flaw was found in GStreamer's RTSP support  ...)
+	TODO: check
+CVE-2026-85138 (A vulnerability was detected in SeaCMS up to 13.6. Affected is the fun ...)
+	TODO: check
+CVE-2026-85137 (A security vulnerability has been detected in SeaCMS up to 13.6. This  ...)
+	TODO: check
+CVE-2026-85135 (A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. Thi ...)
+	TODO: check
+CVE-2026-85124 (@fastify/http-proxy versions before 11.6.2 do not validate proxied HTT ...)
+	TODO: check
+CVE-2026-85110 (A vulnerability was identified in Tenda HG10 300001138. Impacted is th ...)
+	TODO: check
+CVE-2026-85109 (A vulnerability was determined in Tenda HG10 300001138. This issue aff ...)
+	TODO: check
+CVE-2026-85107 (A vulnerability was found in NousResearch hermes-agent 0.18.0. This vu ...)
+	TODO: check
+CVE-2026-85106 (A vulnerability has been found in NousResearch hermes-agent 0.18.0. Th ...)
+	TODO: check
+CVE-2026-85105 (A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by ...)
+	TODO: check
+CVE-2026-85100 (A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Aff ...)
+	TODO: check
+CVE-2026-85093 (Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpo ...)
+	TODO: check
+CVE-2026-85092 (LiME through 1.12.0 fails to validate the disk acquisition output path ...)
+	TODO: check
+CVE-2026-85091 (zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ...)
+	TODO: check
+CVE-2026-85090 (FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability ...)
+	TODO: check
+CVE-2026-85089 (FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uniniti ...)
+	TODO: check
+CVE-2026-85084 (Out-of-bounds Write and Improper Validation of Array Index vulnerabili ...)
+	TODO: check
+CVE-2026-85040 (A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Aff ...)
+	TODO: check
+CVE-2026-85031 (A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted elemen ...)
+	TODO: check
+CVE-2026-85030 (A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32c ...)
+	TODO: check
+CVE-2026-85028 (Creation of a temporary file in a directory with insecure permissions  ...)
+	TODO: check
+CVE-2026-85022 (A vulnerability was identified in langgenius dify 1.13.0. Affected by  ...)
+	TODO: check
+CVE-2026-85021 (A vulnerability was determined in langgenius dify 1.13.0. Affected is  ...)
+	TODO: check
+CVE-2026-85012 (Improper neutralization of special elements used in an OS command (CWE ...)
+	TODO: check
+CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. In versi ...)
+	TODO: check
+CVE-2026-84971 (Improper handling of an unexpected value size in the decryption path o ...)
+	TODO: check
+CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing component of  ...)
+	TODO: check
+CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers of the  ...)
+	TODO: check
+CVE-2026-84968 (An out-of-bounds read in the BSON decoding component of the MongoDB PH ...)
+	TODO: check
+CVE-2026-84967 (A component of the MongoDB extension for Visual Studio Code does not n ...)
+	TODO: check
+CVE-2026-84966 (An incorrect numeric type conversion in the BSON document building com ...)
+	TODO: check
+CVE-2026-84965 (An integer wraparound in an allocation size calculation in the BSON li ...)
+	TODO: check
+CVE-2026-84964 (A double free in the OpenSSL-based TLS certificate revocation checking ...)
+	TODO: check
+CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of the M ...)
+	TODO: check
+CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
+	TODO: check
+CVE-2026-84888 (A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Th ...)
+	TODO: check
+CVE-2026-84887 (A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affe ...)
+	TODO: check
+CVE-2026-84886 (A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affe ...)
+	TODO: check
+CVE-2026-84885 (A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This ...)
+	TODO: check
+CVE-2026-84857 (A flaw has been found in sigoden aichat up to 0.30.4. This affects an  ...)
+	TODO: check
+CVE-2026-84856 (A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The i ...)
+	TODO: check
+CVE-2026-84852 (A security vulnerability has been detected in Reader Tools PDF Reader  ...)
+	TODO: check
+CVE-2026-84851 (An uncontrolled recursion issue exists in Amazon Ion-C versions before ...)
+	TODO: check
+CVE-2026-84849 (Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <=  ...)
+	TODO: check
+CVE-2026-84848 (Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9 ...)
+	TODO: check
+CVE-2026-84847 (Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 v ...)
+	TODO: check
+CVE-2026-84836 (Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Ship ...)
+	TODO: check
+CVE-2026-84834 (Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.)
+	TODO: check
+CVE-2026-84832 (SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-cont ...)
+	TODO: check
+CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged ...)
+	TODO: check
+CVE-2026-84830 (SEPPmail Secure Email Gateway before 15.0.7 contains a command injecti ...)
+	TODO: check
+CVE-2026-84815 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-84814 (Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.)
+	TODO: check
+CVE-2026-84813 (Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.)
+	TODO: check
+CVE-2026-84812 (Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2. ...)
+	TODO: check
+CVE-2026-84779 (Subscriber Broken Access Control in Agentimus \u2013 AI SEO, llms.txt  ...)
+	TODO: check
+CVE-2026-84778 (Unauthenticated Denial of Service Attack in Migrate Guru \u2013 Site M ...)
+	TODO: check
+CVE-2026-84777 (Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 ve ...)
+	TODO: check
+CVE-2026-84776 (Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 v ...)
+	TODO: check
+CVE-2026-84774 (Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.1 ...)
+	TODO: check
+CVE-2026-84773 (Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <=  ...)
+	TODO: check
+CVE-2026-84769 (Unauthenticated Insecure Direct Object References (IDOR) in Business D ...)
+	TODO: check
+CVE-2026-84768 (Unauthenticated SQL Injection in VikAppointments Services Booking Cale ...)
+	TODO: check
+CVE-2026-84767 (Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.)
+	TODO: check
+CVE-2026-84766 (Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 ver ...)
+	TODO: check
+CVE-2026-84765 (Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5. ...)
+	TODO: check
+CVE-2026-84763 (Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions ...)
+	TODO: check
+CVE-2026-84762 (Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.)
+	TODO: check
+CVE-2026-84761 (Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache  ...)
+	TODO: check
+CVE-2026-84758 (Unauthenticated Broken Access Control in Business Directory <= 6.4.26  ...)
+	TODO: check
+CVE-2026-84757 (Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.)
+	TODO: check
+CVE-2026-84756 (Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions ...)
+	TODO: check
+CVE-2026-84755 (Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.)
+	TODO: check
+CVE-2026-84754 (Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions ...)
+	TODO: check
+CVE-2026-84753 (Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.)
+	TODO: check
+CVE-2026-84752 (Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.)
+	TODO: check
+CVE-2026-84736 (In the current development version of Eclipse aeriOS, for which no off ...)
+	TODO: check
+CVE-2026-84452 (Windows ML CLI is a command line tool for building portable, performan ...)
+	TODO: check
+CVE-2026-84394 (fast-uri accepts a host that contains an unbalanced or misplaced autho ...)
+	TODO: check
+CVE-2026-84292 (fast-uri serializes the port component of a URI without validating it. ...)
+	TODO: check
+CVE-2026-84238 (Unauthenticated Broken Access Control in YITH Request a Quote for WooC ...)
+	TODO: check
+CVE-2026-84215 (Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.)
+	TODO: check
+CVE-2026-83961 (ColdFusion is affected by an Improper Authentication vulnerability tha ...)
+	TODO: check
+CVE-2026-83959 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-82918 (XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporat ...)
+	TODO: check
+CVE-2026-82526 (R2R through 3.6.6 contains a stacked SQL injection vulnerability that  ...)
+	TODO: check
+CVE-2026-82525 (Exterro FTK Imager before 8.3 contains an XML external entity (XXE) in ...)
+	TODO: check
+CVE-2026-82524 (UnoPim before 2.1.5 contains an authenticated file upload vulnerabilit ...)
+	TODO: check
+CVE-2026-82302 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized c ...)
+	TODO: check
+CVE-2026-82299 (Incorrect Authorization (CWE-863) in Kibana can lead to information di ...)
+	TODO: check
+CVE-2026-82298 (Incorrect Authorization (CWE-863) in Kibana can lead to denial of serv ...)
+	TODO: check
+CVE-2026-82180 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is ...)
+	TODO: check
+CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site  ...)
+	TODO: check
+CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken object-leve ...)
+	TODO: check
+CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 v ...)
+	TODO: check
+CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in  Ninja Forms File Upload ...)
+	TODO: check
+CVE-2026-81300 (Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact  ...)
+	TODO: check
+CVE-2026-81295 (Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5. ...)
+	TODO: check
+CVE-2026-81292 (Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1  ...)
+	TODO: check
+CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in Product Variations Swatches f ...)
+	TODO: check
+CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.)
+	TODO: check
+CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-autho ...)
+	TODO: check
+CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10 compatib ...)
+	TODO: check
+CVE-2026-80254 (Authorization bypass through user-controlled key issue exists in Shize ...)
+	TODO: check
+CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2 (dev-co ...)
+	TODO: check
+CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial Automation Gmb ...)
+	TODO: check
+CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized Modification o ...)
+	TODO: check
+CVE-2026-78595 (Missing Authorization in Kibana Leading to Information Disclosure / Mi ...)
+	TODO: check
+CVE-2026-78593 (An insufficiently validated configuration field in Kibana's Cribl inte ...)
+	TODO: check
+CVE-2026-78583 (Incorrect Authorization (CWE-863) in Kibana can lead to privilege esca ...)
+	TODO: check
+CVE-2026-78304
+	REJECTED
+CVE-2026-78080 (Joomla Extension - feenders.de - Unauthenticated SQL injection in JooD ...)
+	TODO: check
+CVE-2026-78069 (Joomla Extension - j2commerce.com - Missing authorization on Apps cont ...)
+	TODO: check
+CVE-2026-78065 (Joomla Extension - j2commerce.com - Guest checkout address disclosure  ...)
+	TODO: check
+CVE-2026-78064 (Joomla Extension - j2commerce.com - Anonymous cart-record tampering vi ...)
+	TODO: check
+CVE-2026-78000 (Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `p ...)
+	TODO: check
+CVE-2026-77999 (Joomla Extension - j2commerce.com - Unauthenticated PayPal callback fo ...)
+	TODO: check
+CVE-2026-76178 (A stored Cross-Site Scripting (XSS) vulnerability in the notification  ...)
+	TODO: check
+CVE-2026-76177 (Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?f ...)
+	TODO: check
+CVE-2026-76176 (SQL injection vulnerability in the endpoint /ocsreports/index.php?func ...)
+	TODO: check
+CVE-2026-76175 (SQL injection vulnerability in the del_check parameter of the /ocsrepo ...)
+	TODO: check
+CVE-2026-76174 (Unrestricted file upload vulnerability in the CSV file upload function ...)
+	TODO: check
+CVE-2026-75602 (OpenList a file list program that supports multiple storage. Prior to  ...)
+	TODO: check
+CVE-2026-75137 (UpSignOn for Windows before 7.19.0 contains a sensitive data exposure  ...)
+	TODO: check
+CVE-2026-75136 (UpSignOn for Windows before 7.19.0 contains an insecure credential sto ...)
+	TODO: check
+CVE-2026-75135 (UpSignOn for Windows before 7.19.0 contains a sensitive data exposure  ...)
+	TODO: check
+CVE-2026-75134 (SEOWriting plugin for WordPress through 1.12.5 contains a stored cross ...)
+	TODO: check
+CVE-2026-75036 (A security vulnerability was discovered in Fleet's Helm template prepr ...)
+	TODO: check
+CVE-2026-75035 (A flaw was found in Rancher Manager. When a non-administrative caller  ...)
+	TODO: check
+CVE-2026-75034 (A flaw was found in Rancher Manager. The SAML assertion replay protect ...)
+	TODO: check
+CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were propagated i ...)
+	TODO: check
+CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
+	TODO: check
+CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
+	TODO: check
+CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
+	TODO: check
+CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains  ...)
+	TODO: check
+CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller derived ...)
+	TODO: check
+CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path did not ...)
+	TODO: check
+CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The metadata w ...)
+	TODO: check
+CVE-2026-71222 (A heap out-of-bounds read vulnerability was found in gfs2-utils. The e ...)
+	TODO: check
+CVE-2026-71221 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
+	TODO: check
+CVE-2026-71220 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
+	TODO: check
+CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The hash table ...)
+	TODO: check
+CVE-2026-6071 (A remote code execution security issue exists in the affected products ...)
+	TODO: check
+CVE-2026-68860 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
+	TODO: check
+CVE-2026-66049
+	REJECTED
+CVE-2026-66048
+	REJECTED
+CVE-2026-63694 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains  ...)
+	TODO: check
+CVE-2026-63219 (GeoNetwork is a catalog application to manage spatially referenced res ...)
+	TODO: check
+CVE-2026-58400 (GeoNetwork is a catalog application to manage spatially referenced res ...)
+	TODO: check
+CVE-2026-57445 (Gardens v2 is a modular governance framework that enables communities  ...)
+	TODO: check
+CVE-2026-56128 (pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated user ...)
+	TODO: check
+CVE-2026-56127 (pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated user ...)
+	TODO: check
+CVE-2026-56126 (pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated user ...)
+	TODO: check
+CVE-2026-55658 (Gardens v2 is a modular governance framework that enables communities  ...)
+	TODO: check
+CVE-2026-53924 (Gardens v2 is a modular governance framework that enables communities  ...)
+	TODO: check
+CVE-2026-53720 (pymonocypher uses cython to wrap the Monocypher C library. Prior to ve ...)
+	TODO: check
+CVE-2026-50554 (Note Mark is an open-source note-taking application. Prior to version  ...)
+	TODO: check
+CVE-2026-49456 (Waku is the minimal React framework. Prior to version 1.0.0-beta.1, th ...)
+	TODO: check
+CVE-2026-49455 (Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Wa ...)
+	TODO: check
+CVE-2026-48486 (Signum Node is a HDD-mined cryptocurrency using an energy efficient an ...)
+	TODO: check
+CVE-2026-3852 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
+	TODO: check
+CVE-2026-3416 (The API Publisher component previously used a non-cryptographic pseudo ...)
+	TODO: check
+CVE-2026-35160 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains  ...)
+	TODO: check
+CVE-2026-2573 (The GutenKit \u2013 Page Builder Blocks, Patterns, and Templates for G ...)
+	TODO: check
+CVE-2026-17539 (RTU500 has a vulnerability, where high-load scenarios, such as sending ...)
+	TODO: check
+CVE-2026-15933 (OptimiDoc Server (On-Premise) stores credentials for external services ...)
+	TODO: check
+CVE-2026-15926
+	REJECTED
+CVE-2026-15431 (A potential security vulnerability has been identified in the HP Suppo ...)
+	TODO: check
+CVE-2025-12737 (The administrative operations within the Carbon Console do not adequat ...)
+	TODO: check
 CVE-2026-XXXX [Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free in libde265]
 	- libde265 1.1.2-1
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-xp3h-6f5r-8cxp
 CVE-2026-XXXX [heap-use-after-free in decoder_context::reset() via dangling previous_slice_header]
 	- libde265 1.1.2-1
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-mm7m-v26f-wf8x
-CVE-2026-56855
+CVE-2026-56855 (Previously, after a channel has been established, a malicious peer cou ...)
 	- golang-go.crypto 1:0.56.0-1
 	NOTE: https://github.com/golang/go/issues/81317
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce (v0.56.0)
-CVE-2026-78662
+CVE-2026-78662 (Previously, a channel registered in the mux's chanList is not usable u ...)
 	- golang-go.crypto 1:0.56.0-1
 	NOTE: https://github.com/golang/go/issues/81316
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/a6cdac60840750226b15617ac8858be44361b36b (v0.56.0)
-CVE-2026-80751 [pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()]
+CVE-2026-80751 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/090a95dbe13df9965279b588d97eda134831769c (7.2)
-CVE-2026-80750 [pmdomain: mediatek: fix remaining %pOF after of_node_put()]
+CVE-2026-80750 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/3e013bc8b941bd52c8e3a99798d0ae8792cb71ca (7.2)
-CVE-2026-80749 [drm/connector/hdmi: Fix out of bounds memory read]
+CVE-2026-80749 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/9ecf8ba763d0ffe0673538eb4bf7806f20455d19 (7.2)
-CVE-2026-80748 [mmc: loongson2: Fix sg iteration in data reorder functions]
+CVE-2026-80748 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/00179ed9fbe07799676e2cb63c4e7f0e7cd80a5c (7.2)
-CVE-2026-80746 [clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK]
+CVE-2026-80746 (In the Linux kernel, the following vulnerability has been resolved:  c ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/2ef00630c5c0b7b2c08aba7643f47594952d357e (7.2)
-CVE-2026-80745 [regulator: fp9931: Fix VPOS/VNEG voltage selector table]
+CVE-2026-80745 (In the Linux kernel, the following vulnerability has been resolved:  r ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/66694b5f90f3876fccb87bbd02b453cdc33b3ae4 (7.2)
-CVE-2026-80741 [drm/log: Fix out-of-bounds read on empty message length]
+CVE-2026-80741 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/60baa179ed1333535f6e2da4133511db55278ee4 (7.2)
-CVE-2026-80740 [drm/log: Fix infinite loop when scale is too large for display]
+CVE-2026-80740 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/f4f2bba28df9b9aaa00262a462139dbbcdc38d9f (7.2)
-CVE-2026-80757 [selinux: reject a class permission count below its inherited common]
+CVE-2026-80757 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/9a82dcd98b6e6e11cfd162410967951f12152528 (7.2-rc7)
-CVE-2026-80756 [selinux: do not cancel a policy conversion that never started]
+CVE-2026-80756 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e (7.2-rc7)
-CVE-2026-80755 [selinux: reject a permission value exceeding the class permission count]
+CVE-2026-80755 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.13-1
 	NOTE: https://git.kernel.org/linus/d14b5d0e97fccd27974fedc03b903408872907fd (7.2-rc7)
-CVE-2026-80754 [Input: synaptics-rmi4 - fix F55 transmitter electrode count typo]
+CVE-2026-80754 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/6058f0fea10f3caf63a435677358d1b8e9325114 (7.2-rc7)
-CVE-2026-80753 [ovpn: run deferred work on a module-owned workqueue]
+CVE-2026-80753 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
 	- linux 7.1.10-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/e9714db8041763f59dde152c812b96b3de05c6d9 (7.2)
-CVE-2026-80752 [Input: psxpad-spi - set driver data before use]
+CVE-2026-80752 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/732f38c36059e68ba3b4b89c56911d777fd3185c (7.2-rc7)
-CVE-2026-80747 [drm/amdkfd: Add bounds check for CRAT subtype length]
+CVE-2026-80747 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.10-1
 	NOTE: https://git.kernel.org/linus/6e7566ba4739dd573c331adde1c96690f7a567bd (7.2-rc6)
-CVE-2026-80744 [netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path]
+CVE-2026-80744 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/d02f592064347e0c1e0d84f24941ad338838cc48 (7.2)
-CVE-2026-80743 [ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers]
+CVE-2026-80743 (In the Linux kernel, the following vulnerability has been resolved:  A ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/f12afefb7b01f94d6d66d397f323a9914edbf70e (7.2)
-CVE-2026-80742 [af_packet: Don't send zero-byte data in tpacket_snd().]
+CVE-2026-80742 (In the Linux kernel, the following vulnerability has been resolved:  a ...)
 	- linux 7.1.10-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/6bcd76c134c55c697148acb5c0194e9666abdf84 (7.2)
-CVE-2026-80736 [thunderbolt: Fix bandwidth group reservation indexing]
+CVE-2026-80736 (In the Linux kernel, the following vulnerability has been resolved:  t ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/d2ee4d47aacbd2ba456092eeec670dba35fde291 (7.2-rc7)
-CVE-2026-80735 [ovpn: ensure socket is owned by ovpn before deref sk_user_data]
+CVE-2026-80735 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
 	- linux 7.1.9-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/59aed1eb60d70678a53acccb0cb337a26ce6680e (7.2-rc7)
-CVE-2026-80727 [x86/mce: Set up the polling timer before CMCI discovery]
+CVE-2026-80727 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/a213dfaa2596c1c0dc4dae91c14fbfa499c03223 (7.2-rc7)
-CVE-2026-80739 [net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock]
+CVE-2026-80739 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/6ddfba2ea98db21b001e0e5c472499156224650c (7.2-rc7)
-CVE-2026-80738 [bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie]
+CVE-2026-80738 (In the Linux kernel, the following vulnerability has been resolved:  b ...)
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/31a420a822ff92e2090bd5d65efe8e34e2d6d9b8 (7.2-rc7)
-CVE-2026-80737 [serial: amba-pl011: synchronize DMA teardown]
+CVE-2026-80737 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.107-1
 	NOTE: https://git.kernel.org/linus/440915499231e9db1c361aa45bb702e8fd3b4a32 (7.2-rc7)
-CVE-2026-80734 [btrfs: initialize inode mapping flags for cached inodes]
+CVE-2026-80734 (In the Linux kernel, the following vulnerability has been resolved:  b ...)
 	- linux 7.1.9-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/0ef349734a93227b45f65fc50a3311d1cc5f03e9 (7.2-rc7)
-CVE-2026-80733 [net: remove WARN_ON_ONCE() from sk_mc_loop()]
+CVE-2026-80733 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/b8a39a09ae4eaae04309e1e38ed6a1101d967496 (7.2-rc7)
-CVE-2026-80732 [ata: pata_sl82c105: fix bridge revision use-after-free]
+CVE-2026-80732 (In the Linux kernel, the following vulnerability has been resolved:  a ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/7700a31039cdc6715cb6cce7e7a664ee4e945f67 (7.2-rc7)
-CVE-2026-80731 [net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header]
+CVE-2026-80731 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/3b9a324e646d3657a8d9806dfbfe4f3e4066e882 (7.2-rc7)
-CVE-2026-80730 [ring-buffer: Fix crash passing ERR_PTR to kthread_stop()]
+CVE-2026-80730 (In the Linux kernel, the following vulnerability has been resolved:  r ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/91542863abade2fd4f2b361991f5386ad9d19c8c (7.2-rc7)
-CVE-2026-80729 [mm/huge_memory: initialise workingset state before folio split]
+CVE-2026-80729 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
 	- linux 7.1.9-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/aca1f2d5de17e138bc6c4859126b77e516b82541 (7.2-rc7)
-CVE-2026-80728 [Revert "drm/amdgpu: fix aperture mapping leak"]
+CVE-2026-80728 (In the Linux kernel, the following vulnerability has been resolved:  R ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/b96c529cd2551b78316a4afa3237b2ed96ba03c8 (7.2-rc7)
-CVE-2026-80726 [KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page]
+CVE-2026-80726 (In the Linux kernel, the following vulnerability has been resolved:  K ...)
 	- linux 7.1.9-1
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/5ec42d57655c690234c14aece6dd3f209778c1d8 (7.2-rc7)
@@ -200,7 +676,7 @@ CVE-2026-65140 [Fix a privilege escalation where an operator could alter Adminis
 CVE-2026-65165 [Fix various issues around job steps and node count discrepancies]
 	- slurm-wlm <unfixed> (bug #1146563)
 	NOTE: https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
-CVE-2026-76642
+CVE-2026-76642 (util-linux versions through 2.41.5 and 2.42.2 fail to check mount help ...)
 	- util-linux 2.42.3-1
 	[trixie] - util-linux <no-dsa> (Minor issue)
 	NOTE: https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f
@@ -1314,56 +1790,82 @@ CVE-2026-16658
 	- ansible <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
 CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on Android pri ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84352 (Use after free in WebGL in Google Chrome on on Android prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84354 (Incorrect authorization in FileSystem in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84359 (Information leak in Skia in Google Chrome prior to 152.0.7977.75 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84357 (Improper input validation in Omnibox in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84324 (Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84349 (Use after free in Browser in Google Chrome prior to 152.0.7977.75 allo ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84326 (Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84333 (Use after free in Dawn in Google Chrome on on Android prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84351 (Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84325 (Improper input validation in DataTransfer in Google Chrome prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84328 (Missing authorization in FileSystem in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84347 (Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84323 (Missing authorization in FileSystem in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84355 (Incorrect authorization in Navigation in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84358 (Improper privilege management in Downloads in Google Chrome prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84332 (Incorrect authorization in SiteSettings in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84330 (UI misrepresentation in FullScreen in Google Chrome on on Android prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84334 (Incorrect authorization in Chromoting in Google Chrome on on Windows p ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84348 (Information leak in MediaCapture in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84335 (Incorrect authorization in TabStrip in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84327 (Incorrect authorization in Autofill in Google Chrome on on Android pri ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84329 (Confused deputy in CredentialProvider in Google Chrome on on Windows p ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84356 (UI misrepresentation in FullScreen in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84350 (Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-84331 (Incorrect authorization in Actor in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
 CVE-2026-81928 (Net::DNS versions before 1.57 for Perl allow memory exhaustion via unb ...)
 	- libnet-dns-perl 1.57-1
@@ -1984,6 +2486,7 @@ CVE-2024-10085 (CWE-770: Allocation of Resources Without Limits or Throttlingvul
 CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites ...)
 	NOT-FOR-US: Kyverno
 CVE-2026-84145 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -1994,6 +2497,7 @@ CVE-2026-84144 (Internally found bugs present in Thunderbird 154 and Thunderbird
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
 CVE-2026-84143 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -2034,6 +2538,7 @@ CVE-2026-84132 (Information disclosure in the Networking: HTTP component. This v
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84132
 CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics component. ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -2059,6 +2564,7 @@ CVE-2026-84125 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84125
 CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -2069,6 +2575,7 @@ CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebG
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
 CVE-2026-84122 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -2076,6 +2583,7 @@ CVE-2026-84122 (Use-after-free in the Audio/Video component. This vulnerability
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84122
 CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security component. T ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -2083,6 +2591,7 @@ CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security compon
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84121
 CVE-2026-84120 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -2090,6 +2599,7 @@ CVE-2026-84120 (Use-after-free in the Audio/Video component. This vulnerability
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84120
 CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
+	{DSA-6481-1}
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -3426,7 +3936,7 @@ CVE-2026-82453 (rust-iot-platform through commit 5df942ab stores user passwords
 	NOT-FOR-US: rust-iot-platform
 CVE-2026-82452 (rust-iot-platform through commit 5df942ab contains an authentication b ...)
 	NOT-FOR-US: rust-iot-platform
-CVE-2026-82451 (Formwork through 2.3.14 contains a stored cross-site scripting vulnera ...)
+CVE-2026-82451 (Formwork before 2.3.11 contains a stored cross-site scripting vulnerab ...)
 	NOT-FOR-US: Formwork
 CVE-2026-82450 (BookStack before 26.05.4 contains a remote code execution vulnerabilit ...)
 	NOT-FOR-US: BookStack
@@ -7331,987 +7841,1314 @@ CVE-2026-79792 (A flaw has been found in zackees transcribe-anything up to 4.1.0
 CVE-2026-79654 (A flaw was found in Katello where the Content View History API does no ...)
 	NOT-FOR-US: Red Hat
 CVE-2026-79293 (Information leak in Animation in Google Chrome prior to 152.0.7977.65  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79292 (Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79291 (Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79290 (Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79289 (Improper control of a resource through its lifetime in Workers in Goog ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79288 (Improper input validation in Autofill in Google Chrome on on Android p ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79287 (Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79286 (Missing authorization in CustomTabs in Google Chrome on on Android pri ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79285 (Uninitialized resource in ANGLE in Google Chrome on on Windows prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79284 (UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79283 (UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79282 (Use after free in ANGLE in Google Chrome on on Android prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79276 (Improper privilege management in FileSystem in Google Chrome prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79275 (Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79274 (Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79273 (Incorrect reference resolution in WebView in Google Chrome on on Andro ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79272 (Improper input validation in FindInPage in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79271 (Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79270 (Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79269 (Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79267 (Race condition in Workers in Google Chrome prior to 152.0.7977.65 allo ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79266 (Use after free in DevTools in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79265 (Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79264 (Incorrect reference resolution in Preload in Google Chrome prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79263 (Race condition in Extensions in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79262 (Incorrect authorization in Network in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79261 (Incorrect authorization in Controls in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79260 (Improper input validation in Cookies in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79259 (Improper input validation in Safebrowsing in Google Chrome prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79258 (Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79257 (Use after free in Views in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79256 (Externally controlled reference in WebView in Google Chrome on on Andr ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79255 (Improper input validation in WebRTC in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79254 (Incorrect reference resolution in CustomTabs in Google Chrome on on An ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79253 (Improper input validation in Network in Google Chrome on on Windows pr ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79252 (Information leak in ServiceWorker in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79251 (Improper input validation in Network in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79250 (UI misrepresentation in Navigation in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79249 (Code injection in Bisection in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79248 (Incorrect authorization in Input in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79247 (Use after free in Chromoting in Google Chrome on on Windows prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79246 (Information leak in DataTransfer in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79245 (Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79244 (Use after free in Animation in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79243 (Improper input validation in ReadingList in Google Chrome on on Window ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79242 (Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79241 (Out of bounds read in GPU in Google Chrome on on Android prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79240 (Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79239 (Out of bounds read in Tint in Google Chrome on on Android prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79238 (Incorrect authorization in ServiceWorker in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79237 (Incorrect authorization in Navigation in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79236 (Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79235 (Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79234 (Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a rem ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79233 (UI misrepresentation in CustomTabs in Google Chrome on on Android prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79232 (Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79231 (Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79230 (Improper input validation in ANGLE in Google Chrome on on Mac prior to ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79229 (Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79228 (Incorrect authorization in SiteIsolation in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79227 (Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79226 (Improper privilege management in Regional Capabilities in Google Chrom ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79225 (Incorrect authorization in Browser in Google Chrome on on Android prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79224 (Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79223 (Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79222 (Incorrect authorization in CustomTabs in Google Chrome on on Android p ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79221 (Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79220 (Information leak in Network in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79219 (Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79218 (Incorrect authorization in Sandbox in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79217 (Incorrect authorization in Mobile in Google Chrome on on iOS prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79216 (Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79215 (Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allo ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79214 (Improper input validation in Preload in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79213 (Incorrect authorization in WebAppInstalls in Google Chrome on on Andro ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79212 (Missing authorization in Passwords in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79211 (Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79210 (Use after free in Audio in Google Chrome on on Android prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79209 (Type confusion in Animation in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79208 (Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79207 (Information leak in Passwords in Google Chrome on on iOS prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79206 (Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79205 (Incorrect authorization in Network in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79204 (UI misrepresentation in Input in Google Chrome on on Mac prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79203 (Improper input validation in DevTools in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79202 (Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79201 (Improper access control in Workers in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79200 (Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79199 (Incorrect authorization in Network in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79198 (Use after free in Platform in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79197 (Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79196 (Race condition in Editing in Google Chrome prior to 152.0.7977.65 allo ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79195 (Use after free in Script in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79194 (Use after free in Chromoting in Google Chrome on on Windows prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79193 (Information leak in Canvas in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79192 (Improper input validation in Variations in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79191 (Incorrect authorization in SiteIsolation in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79190 (Incorrect authorization in Extensions in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79189 (Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79188 (Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79187 (Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79186 (Incorrect authorization in Network in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79185 (Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79184 (Missing authorization in Preload in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79183 (Use after free in Accessibility in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79182 (Improper input validation in Media in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79181 (Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79180 (UI misrepresentation in CustomTabs in Google Chrome on on Android prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79179 (Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79178 (Incorrect authorization in Web Authentication (Passkeys & Security Key ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79177 (Incorrect authorization in Media in Google Chrome on on Windows prior  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79176 (UI misrepresentation in Extensions in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79175 (Type confusion in Accessibility in Google Chrome on on Windows prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79174 (Incorrect authorization in Extensions in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79173 (UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79155 (Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79154 (Missing authorization in DevTools in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79152 (Incorrect authorization in CustomTabs in Google Chrome on on Android p ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79151 (Improper input validation in Safebrowsing in Google Chrome prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79150 (Use after free in Views in Google Chrome on on Mac prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79149 (Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79148 (Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79147 (Information leak in Skia in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 	- libskia 146.20260602~git.3476902+dfsg-3
 CVE-2026-79146 (Information leak in CustomTabs in Google Chrome on on Android prior to ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79144 (Information leak in Skia in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79143 (Incorrect authorization in FileSystem in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79142 (Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79141 (Incorrect authorization in Browser in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79140 (Use after free in Views in Google Chrome on on Mac prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79139 (Improper input validation in Media in Google Chrome on on Windows prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79138 (Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79137 (Incorrect authorization in Extensions in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79136 (Incorrect authorization in ServiceWorker in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79134 (Incorrect authorization in GetUserMedia in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79133 (Incorrect authorization in Forms in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79132 (Improper input validation in Input in Google Chrome on on Android prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79131 (Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79130 (Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79129 (Use after free in Sessions in Google Chrome on on Android prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79128 (Use after free in Views in Google Chrome on on Mac prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79127 (Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79126 (Incorrect provision of specified functionality in Proxy in Google Chro ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79125 (Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79124 (Information leak in Intents in Google Chrome on on Android prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79123 (Improper input validation in NTP Footer in Google Chrome on on Windows ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79122 (Information leak in SignIn in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79121 (Improper input validation in Chromecast in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79120 (Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79119 (Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79118 (Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79117 (Race condition in WebAppInstalls in Google Chrome on on Android prior  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79116 (Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79112 (Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 	- libskia 146.20260602~git.3476902+dfsg-3
 CVE-2026-79111 (Improper input validation in Dawn in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79110 (Missing authorization in Preload in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79109 (Improper input validation in Printing in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79108 (UI misrepresentation in Web Authentication (Passkeys & Security Keys)  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79107 (Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79106 (Improper input validation in Input in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79105 (Improper input validation in Mobile in Google Chrome on on iOS prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79104 (Missing authorization in Sensor in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79103 (Incorrect reference resolution in Speech in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79099 (Missing authorization in Network in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79098 (UI misrepresentation in PermissionElement in Google Chrome prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79097 (Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79095 (Information leak in Payments in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79094 (Race condition in Workers in Google Chrome prior to 152.0.7977.65 allo ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79093 (Incorrect authorization in Paint in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79091 (Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79090 (Improper privilege management in Actor in Google Chrome prior to 152.0 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79089 (Race condition in Transactions Platform in Google Chrome on on Android ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79088 (Incorrect authorization in FileSystem in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79087 (Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79086 (Missing authorization in CustomTabs in Google Chrome on on Android pri ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79085 (Missing authorization in Network in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79084 (Inadequate encryption strength in Notifications in Google Chrome on on ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79083 (Improper enforcement of behavioral workflow in Media in Google Chrome  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79082 (Incorrect authorization in Transactions Platform in Google Chrome prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79078 (Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79077 (Incorrect authorization in WebProtect in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79076 (Improper input validation in Sync in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79075 (Information leak in Geolocation in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79074 (Information leak in Network in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79073 (Improper state validation in Parser in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79072 (Improper state validation in Performance in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79071 (Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79070 (Incorrect reference resolution in Cache in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79069 (Memory corruption in Tint in Google Chrome on on Mac prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79068 (Improper resource exposure in StreamsAPI in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79067 (Missing authorization in Network in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79066 (Improper input validation in Navigation in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79065 (Improper input validation in Network in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79064 (Use after free in Network in Google Chrome on on Mac prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79060 (Incorrect authorization in StorageAccessAPI in Google Chrome prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79059 (Information leak in BFCache in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79058 (Missing authorization in Passwords in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79057 (Race condition in Start in Google Chrome on on Android prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79056 (Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79055 (Information leak in Sharing in Google Chrome on on Android prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79054 (Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79053 (Missing authorization in Lighthouse in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79052 (Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79051 (Incorrect authorization in Loader in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79050 (Incorrect authorization in Network in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79049 (Incorrect reference resolution in Passwords in Google Chrome prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79048 (Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79047 (Use after free in Views in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79046 (Race condition in Permissions in Google Chrome on on Android prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79045 (Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79044 (Missing authorization in WebAppInstalls in Google Chrome on on Android ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79043 (Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79042 (Missing authorization in Payments in Google Chrome on on Android prior ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79041 (Missing authorization in Browser in Google Chrome on on Mac prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79040 (Uninitialized resource in GPU in Google Chrome on on Android prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79039 (Use after free in Mobile in Google Chrome on on iOS prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79038 (Incorrect authorization in WebProtect in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79034 (Information leak in CORS in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79033 (Insufficient control flow management in DevTools in Google Chrome prio ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79032 (Improper input validation in Network in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79031 (Improper resource exposure in Preload in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79030 (Observable discrepancy in Autofill in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79028 (Observable discrepancy in Network in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79027 (Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79026 (Use after free in Extensions in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79025 (Improper input validation in Workers in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79024 (Information leak in ServiceWorker in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79023 (Incorrect authorization in Editing in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79022 (UI misrepresentation in Transactions Platform in Google Chrome prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79021 (Missing authorization in InterestGroups in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79020 (Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79019 (Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79018 (Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79017 (Race condition in Extensions in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79016 (Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79015 (Improper input validation in ServiceWorker in Google Chrome prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79014 (Race condition in Autofill in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79013 (Improper input validation in Sync in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79012 (Use after free in Safebrowsing in Google Chrome on on Mac prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79011 (UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79010 (Operation on a resource after expiration or release in Network in Goog ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79009 (UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79008 (Improper input validation in GPU in Google Chrome on on Android prior  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79007 (Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79006 (Protection mechanism failure in HttpsUpgrades in Google Chrome prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79005 (Incorrect authorization in StorageAccessAPI in Google Chrome prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79004 (Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79003 (Incorrect authorization in Device in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79002 (Incorrect authorization in SiteIsolation in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79001 (Information leak in Bluetooth in Google Chrome on on Mac prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-79000 (Improper input validation in DeviceBoundSessionCredentials in Google C ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78999 (Improper privilege management in Navigation in Google Chrome prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78991 (Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78990 (Use after free in Compositing in Google Chrome prior to 152.0.7977.65  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78989 (Out of bounds read in ANGLE in Google Chrome on on Windows prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78987 (Information leak in Canvas in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78986 (Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78985 (Incorrect reference resolution in FileSystem in Google Chrome prior to ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78984 (Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78983 (Use after free in Views in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78981 (Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78980 (Improper input validation in ReaderMode in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78979 (Race condition in Core in Google Chrome on on Windows prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78978 (Out of bounds read in ANGLE in Google Chrome on on Windows prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78977 (Uninitialized resource in GPU in Google Chrome on on Android prior to  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78976 (Improper input validation in StorageAccessAPI in Google Chrome prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78975 (Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78974 (UI misrepresentation in Linux Toolkit Theming in Google Chrome prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78969 (Uninitialized resource in Video in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78968 (Missing authorization in Core in Google Chrome prior to 152.0.7977.65  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78967 (Missing authorization in BFCache in Google Chrome prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78966 (Externally controlled reference in QUIC in Google Chrome prior to 152. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78965 (Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78964 (Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78963 (Improper input validation in Media in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78962 (Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78961 (Incorrect authorization in Core in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78960 (Information leak in Extensions in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78959 (Improper handling of case sensitivity in FileSystem in Google Chrome p ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78958 (Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78957 (Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78956 (Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78955 (Observable discrepancy in PerformanceAPIs in Google Chrome prior to 15 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78954 (Incorrect authorization in Extensions in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78953 (Missing authorization in SiteIsolation in Google Chrome prior to 152.0 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78952 (Out of bounds write in Crashpad in Google Chrome on on Windows prior t ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78951 (Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78950 (Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78949 (Observable discrepancy in CustomTabs in Google Chrome on on Android pr ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78948 (Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78947 (Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78946 (Incorrect authorization in Select in Google Chrome prior to 152.0.7977 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78945 (Use after free in Views in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78944 (Use after free in DevTools in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78943 (Improper input validation in Editing in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78942 (Incorrect reference resolution in Loader in Google Chrome prior to 152 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78941 (Information leak in Core in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78940 (Improper initialization in Network in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78939 (Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78938 (Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78937 (Use after free in Search in Google Chrome on on Android prior to 152.0 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78936 (Observable discrepancy in CustomTabs in Google Chrome on on Android pr ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78935 (Use of uninitialized variable in Mobile in Google Chrome on on iOS pri ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78934 (Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 al ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78915 (Race condition in Enterprise in Google Chrome on on Windows prior to 1 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78914 (Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 	- libskia 146.20260602~git.3476902+dfsg-3
 CVE-2026-78913 (Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78912 (UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.6 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78911 (Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78910 (Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed  ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78909 (Use after free in Views in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78908 (Information leak in Canvas in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78907 (Incorrect authorization in WebProtect in Google Chrome prior to 152.0. ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78906 (Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78905 (Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78904 (Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowe ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78903 (Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78901 (Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78900 (Improper input validation in Media in Google Chrome prior to 152.0.797 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78899 (Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78898 (Incorrect authorization in Downloads in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78897 (Missing authorization in BrowserTag in Google Chrome prior to 152.0.79 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78896 (Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7 ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78895 (Information leak in Paint in Google Chrome prior to 152.0.7977.65 allo ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78894 (Race condition in Payments in Google Chrome prior to 152.0.7977.65 all ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78893 (Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allow ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78892 (Incorrect authorization in Chromoting in Google Chrome on on Windows p ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78891 (Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allo ...)
+	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-78655 (Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-fact ...)
@@ -9979,7 +10816,8 @@ CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.10 contains an authentication bypa
 	NOT-FOR-US: rConfig
 CVE-2026-77914 (rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerabili ...)
 	NOT-FOR-US: rConfig
-CVE-2026-76848 (TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings an ...)
+CVE-2026-76848
+	REJECTED
 	NOT-FOR-US: TypeORM
 CVE-2026-76847 (act starts an HTTP Artifacts V4 backend whenever a workflow uses actio ...)
 	NOT-FOR-US: nektos act
@@ -12029,7 +12867,8 @@ CVE-2026-41450 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 cont
 	NOT-FOR-US: UAC (Unix-like Artifacts Collector)
 CVE-2026-41449 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a  ...)
 	NOT-FOR-US: UAC (Unix-like Artifacts Collector)
-CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability in the  ...)
+CVE-2026-39909
+	REJECTED
 	- llama.cpp 8611+dfsg-1
 	NOTE: https://github.com/ggml-org/llama.cpp/pull/21175
 	NOTE: Fixed by: https://github.com/ggml-org/llama.cpp/commit/389c7d4955ba55c7418afaebf7c23d9ed64ef707 (b8585)
@@ -16844,6 +17683,7 @@ CVE-2026-75897 (Improper input validation in the capabilities route handler in O
 CVE-2026-75890
 	REJECTED
 CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
+	{DSA-6481-1}
 	- firefox 154.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -27103,7 +27943,7 @@ CVE-2026-16538 (The Wallet for WooCommerce WordPress plugin before 1.6.10 does n
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16294 (The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11 ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-16253 (The Total Upkeep  WordPress plugin before 1.17.3 does not adequately p ...)
+CVE-2026-16253 (The Total Upkeep WordPress plugin before 1.17.3 does not adequately pr ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16230 (The Formidable Digital Signatures plugin for WordPress is vulnerable t ...)
 	NOT-FOR-US: WordPress plugin
@@ -49817,7 +50657,7 @@ CVE-2026-16372 (Privilege escalation in the DOM: Content Processes component. Th
 	- firefox 153.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
 CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
-	{DSA-6418-1 DSA-6394-1 DLA-4727-1 DLA-4695-1}
+	{DSA-6481-1 DSA-6418-1 DSA-6394-1 DLA-4727-1 DLA-4695-1}
 	- firefox 153.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:140.13.0esr-1
@@ -49892,6 +50732,7 @@ CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vuln
 	- firefox 153.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
 CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This vulnerability ...)
+	{DSA-6481-1}
 	- firefox 153.0-1
 	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:153.2.0esr-1
@@ -62159,7 +63000,7 @@ CVE-2026-69184 [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial of service via unboun
 	NOTE: https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76
 	NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/f1288bbc70e9a1e0a77134c2382157e52d326aea (main)
 	NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/5c8341ba6ff3a8e4e4dfd616f8ed0418838b8b7b (v1.34.7)
-CVE-2026-33630
+CVE-2026-33630 (c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34 ...)
 	- c-ares 1.34.7-1
 	[trixie] - c-ares <no-dsa> (Minor issue)
 	[bookworm] - c-ares <not-affected> (Vulnerable event-loop code not present; read_answers()/requeue/host_query re-entrancy introduced in the 1.20+ rewrite, cf. CVE-2025-31498)
@@ -148159,7 +149000,7 @@ CVE-2025-15559 (An unauthenticated attacker can inject OS commands when calling
 	NOT-FOR-US: NesterSoft WorkTime
 CVE-2025-13590 (A malicious actor with administrative privileges can upload an arbitra ...)
 	NOT-FOR-US: WSO2
-CVE-2025-12107 (Due to the use of a vulnerable third-party Velocity template engine, a ...)
+CVE-2025-12107 (The Velocity template engine, utilized by the affected product, accept ...)
 	NOT-FOR-US: WSO2
 CVE-2019-25430 (Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting v ...)
 	NOT-FOR-US: Comodo Dome Firewall
@@ -474143,10 +474984,9 @@ CVE-2023-20579 (Improper Access Control in the AMD SPI protection feature may al
 	NOT-FOR-US: AMD
 CVE-2023-20578 (A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ...)
 	NOT-FOR-US: AMD
-CVE-2023-20577
+CVE-2023-20577 (A heap overflow in SMM module may allow an attacker with access to a s ...)
 	NOT-FOR-US: AMD
-CVE-2023-20576
-	RESERVED
+CVE-2023-20576 (Insufficient Verification of Data Authenticity in AGESA\u2122 may allo ...)
 	NOT-FOR-US: AMD
 CVE-2023-20575 (A potential power side-channel vulnerability in some AMD processors ma ...)
 	NOT-FOR-US: AMD
@@ -548991,10 +549831,10 @@ CVE-2021-43616 (The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds wit
 	NOTE: https://github.com/npm/cli/commit/457e0ae61bbc55846f5af44afa4066921923490f (v8.4.1)
 CVE-2021-43615 (An issue was discovered in HddPassword in Insyde InsydeH2O with kernel ...)
 	NOT-FOR-US: Insyde
-CVE-2021-43614
-	RESERVED
-CVE-2021-43613
-	RESERVED
+CVE-2021-43614 (Error in handling the PlatformLangCodes UEFI variable could cause a bu ...)
+	TODO: check
+CVE-2021-43613 (An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User an ...)
+	TODO: check
 CVE-2021-43612 (In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decod ...)
 	{DLA-3389-1}
 	- lldpd 1.0.13-1
@@ -564625,8 +565465,8 @@ CVE-2021-38491 (Mixed-content checks were unable to analyze opaque origins which
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-38/#CVE-2021-38491
 CVE-2021-38490 (Altova MobileTogether Server before 7.3 SP1 allows XML exponential ent ...)
 	NOT-FOR-US: Altova MobileTogether Server
-CVE-2021-38489
-	RESERVED
+CVE-2021-38489 (HDD password plaintext is stored in a UEFI variable.)
+	TODO: check
 CVE-2021-38488 (Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to  ...)
 	NOT-FOR-US: Delta Electronics DIALink
 CVE-2021-38487 (RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro vers ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ba14af780a8e1920b960b889996d14d269c779ab

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ba14af780a8e1920b960b889996d14d269c779ab
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/b39b848e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list