[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some CVEs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 05:17:52 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1db59d14 by Salvatore Bonaccorso at 2026-09-04T06:17:18+02:00
Add Debian bug references for some CVEs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1321,7 +1321,7 @@ CVE-2026-84425 (A vulnerability was found in zhayujie CowAgent up to 2.1.3. This
CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affects an ...)
NOT-FOR-US: Casdoor
CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
- - node-js-yaml <unfixed>
+ - node-js-yaml <unfixed> (bug #1146637)
[trixie] - node-js-yaml <no-dsa> (Minor issue)
NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
NOTE: https://github.com/nodeca/js-yaml/pull/797
@@ -1363,7 +1363,7 @@ CVE-2026-84361 (Composer is a dependency Manager for the PHP language. From 1.0
NOTE: Fixed by: https://github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220 (2.10.3)
NOTE: Fixed by: https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af (2.2.30)
CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
- - pypdf <unfixed>
+ - pypdf <unfixed> (bug #1146638)
[trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
@@ -1951,14 +1951,14 @@ CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b (0.6.0)
CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
- - golang-google-grpc <unfixed>
+ - golang-google-grpc <unfixed> (bug #1146639)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc
NOTE: https://github.com/grpc/grpc-go/pull/9331
NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176 (master)
NOTE: https://github.com/grpc/grpc-go/pull/9333 (v1.83.x backport)
NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77 (v1.83.1)
CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...)
- - golang-google-grpc <unfixed>
+ - golang-google-grpc <unfixed> (bug #1146639)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3
NOTE: https://github.com/grpc/grpc-go/pull/9332
NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8 (master)
@@ -2163,7 +2163,7 @@ CVE-2026-83605 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
CVE-2026-83595 (AVideo contains a cross-site request forgery vulnerability in plugin/A ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-83557 (DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator appli ...)
- - jackson-databind <unfixed>
+ - jackson-databind <unfixed> (bug #1146640)
NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j
NOTE: https://github.com/FasterXML/jackson-databind/issues/6156
NOTE: https://github.com/FasterXML/jackson-databind/pull/6155
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1db59d1478d69d171cf37575f1b417c67b1d930e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1db59d1478d69d171cf37575f1b417c67b1d930e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/819b2205/attachment.htm>
More information about the debian-security-tracker-commits
mailing list