[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 05:17:52 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1db59d14 by Salvatore Bonaccorso at 2026-09-04T06:17:18+02:00
Add Debian bug references for some CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1321,7 +1321,7 @@ CVE-2026-84425 (A vulnerability was found in zhayujie CowAgent up to 2.1.3. This
 CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affects an ...)
 	NOT-FOR-US: Casdoor
 CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
-	- node-js-yaml <unfixed>
+	- node-js-yaml <unfixed> (bug #1146637)
 	[trixie] - node-js-yaml <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
 	NOTE: https://github.com/nodeca/js-yaml/pull/797
@@ -1363,7 +1363,7 @@ CVE-2026-84361 (Composer is a dependency Manager for the PHP language. From 1.0
 	NOTE: Fixed by: https://github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220 (2.10.3)
 	NOTE: Fixed by: https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af (2.2.30)
 CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
-	- pypdf <unfixed>
+	- pypdf <unfixed> (bug #1146638)
 	[trixie] - pypdf <no-dsa> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
@@ -1951,14 +1951,14 @@ CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b (0.6.0)
 CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
-	- golang-google-grpc <unfixed>
+	- golang-google-grpc <unfixed> (bug #1146639)
 	NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc
 	NOTE: https://github.com/grpc/grpc-go/pull/9331
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176 (master)
 	NOTE: https://github.com/grpc/grpc-go/pull/9333 (v1.83.x backport)
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77 (v1.83.1)
 CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...)
-	- golang-google-grpc <unfixed>
+	- golang-google-grpc <unfixed> (bug #1146639)
 	NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3
 	NOTE: https://github.com/grpc/grpc-go/pull/9332
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8 (master)
@@ -2163,7 +2163,7 @@ CVE-2026-83605 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83595 (AVideo contains a cross-site request forgery vulnerability in plugin/A ...)
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-83557 (DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator appli ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1146640)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j
 	NOTE: https://github.com/FasterXML/jackson-databind/issues/6156
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/6155



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1db59d1478d69d171cf37575f1b417c67b1d930e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1db59d1478d69d171cf37575f1b417c67b1d930e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/819b2205/attachment.htm>


More information about the debian-security-tracker-commits mailing list