[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-81525
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 08:15:43 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d0f60af1 by Salvatore Bonaccorso at 2026-09-04T09:15:30+02:00
Update status for CVE-2026-81525
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5922,10 +5922,7 @@ CVE-2026-81527 (A NoSQL/expression injection weakness exists in the LINQ-to-aggr
CVE-2026-81526 (The MongoDB Rust Driver does not neutralize special characters in a ca ...)
NOT-FOR-US: MongoDB Rust Driver
CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently sanitize spec ...)
- - php-mongodb <unfixed>
- [trixie] - php-mongodb <no-dsa> (Minor issue)
- NOTE: https://jira.mongodb.org/browse/PHPLIB-1927
- NOTE: Fixed by: https://github.com/mongodb/mongo-php-library/commit/6f305a3b21740080255a3093b12458274c7cc8ca (2.4.1)
+ NOT-FOR-US: mongo-php-library (not same as php-mongodb)
CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in caller-s ...)
- mongo-c-driver 2.5.1-1
[trixie] - mongo-c-driver <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d0f60af1a70f124b4fdd5640f501283d754b8415
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d0f60af1a70f124b4fdd5640f501283d754b8415
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/9d9c33ce/attachment.htm>
More information about the debian-security-tracker-commits
mailing list