[Git][security-tracker-team/security-tracker][master] lts: mark some issues as postponed

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Fri Sep 4 12:46:18 BST 2026



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4e3817ce by Emilio Pozuelo Monfort at 2026-09-04T13:45:27+02:00
lts: mark some issues as postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1085,10 +1085,12 @@ CVE-2026-84839 (A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.
 CVE-2026-84838 (A flaw was found in rpmuncompress. This command injection vulnerabilit ...)
 	- rpm <unfixed> (bug #1146602)
 	[trixie] - rpm <no-dsa> (Minor issue)
+	[bookworm] - rpm <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462222
 CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command injection v ...)
 	- rpm <unfixed> (bug #1146602)
 	[trixie] - rpm <no-dsa> (Minor issue)
+	[bookworm] - rpm <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478408
 CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst allows Expl ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -1661,6 +1663,7 @@ CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affe
 CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
 	- node-js-yaml <unfixed> (bug #1146637)
 	[trixie] - node-js-yaml <no-dsa> (Minor issue)
+	[bookworm] - node-js-yaml <postponed> (Minor issue)
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
 	NOTE: https://github.com/nodeca/js-yaml/pull/797
 	NOTE: Fixed by: https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b (4.3.2)
@@ -1686,6 +1689,7 @@ CVE-2026-84367 (joi is a schema description language and data validator for Java
 CVE-2026-84366 (Scrapy is a high-level web crawling and scraping framework for Python. ...)
 	- python-scrapy 2.17.0-1
 	[trixie] - python-scrapy <no-dsa> (Minor issue)
+	[bookworm] - python-scrapy <postponed> (Minor issue)
 	NOTE: https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx
 	NOTE: Fixed by: https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b (2.17.0)
 CVE-2026-84365 (Hono is a Web application framework that provides support for any Java ...)
@@ -1703,6 +1707,7 @@ CVE-2026-84361 (Composer is a dependency Manager for the PHP language. From 1.0
 CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed> (bug #1146638)
 	[trixie] - pypdf <no-dsa> (Minor issue)
+	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
 	NOTE: https://github.com/py-pdf/pypdf/pull/3964
@@ -2071,6 +2076,7 @@ CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an aut
 CVE-2026-82209
 	- curl 8.22.0-1
 	[trixie] - curl <no-dsa> (Minor issue)
+	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-82209.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6 (curl-8_22_0)
@@ -2096,6 +2102,7 @@ CVE-2026-80231
 CVE-2026-80230
 	- curl 8.22.0~rc3-1
 	[trixie] - curl <no-dsa> (Minor issue)
+	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-80230.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef (rc-8_22_0-3)
@@ -2109,18 +2116,21 @@ CVE-2026-80229
 CVE-2026-19931
 	- curl 8.22.0~rc2-1
 	[trixie] - curl <no-dsa> (Minor issue)
+	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-19931.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)
 CVE-2026-18924
 	- curl 8.22.0~rc2-1
 	[trixie] - curl <no-dsa> (Minor issue)
+	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-18924.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43 (rc-8_22_0-1)
 CVE-2026-13608
 	- curl 8.22.0~rc2-1
 	[trixie] - curl <no-dsa> (Minor issue)
+	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-13608.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519 (rc-8_22_0-1)
@@ -2131,12 +2141,14 @@ CVE-2026-84373 (Vitest is a testing framework powered by Vite. From 2.1.0 until
 CVE-2026-84311 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed> (bug #1146476)
 	[trixie] - pypdf <no-dsa> (Minor issue)
+	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527050
 	TODO: check upstream references
 CVE-2026-84310 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed> (bug #1146476)
 	[trixie] - pypdf <no-dsa> (Minor issue)
+	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527049
 	TODO: check upstream references
@@ -2265,6 +2277,7 @@ CVE-2026-84331 (Incorrect authorization in Actor in Google Chrome prior to 152.0
 CVE-2026-81928 (Net::DNS versions before 1.57 for Perl allow memory exhaustion via unb ...)
 	- libnet-dns-perl 1.57-1
 	[trixie] - libnet-dns-perl <no-dsa> (Minor issue)
+	[bookworm] - libnet-dns-perl <postponed> (Minor issue)
 	NOTE: https://rt.cpan.org/Ticket/Display.html?id=181125
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43194862/
 	NOTE: https://metacpan.org/release/NLNETLABS/Net-DNS-1.57/diff/NLNETLABS/Net-DNS-1.56
@@ -2305,6 +2318,7 @@ CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83
 CVE-2026-84270 (A flaw was found in the MTP backend in gvfs. When reading a file from  ...)
 	- gvfs <unfixed> (bug #1146478)
 	[trixie] - gvfs <no-dsa> (Minor issue)
+	[bookworm] - gvfs <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/864
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/070e5e4223c97f7e793a342ba6e64df1095ccb0d (1.61.90)
@@ -2312,6 +2326,7 @@ CVE-2026-84270 (A flaw was found in the MTP backend in gvfs. When reading a file
 CVE-2026-84269 (A flaw was found in the AFP backend in gvfs. When mounting a share, a  ...)
 	- gvfs <unfixed> (bug #1146478)
 	[trixie] - gvfs <no-dsa> (Minor issue)
+	[bookworm] - gvfs <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/863
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/072a7e02d11f5b7dfa324b70dd0e16d60f9b9e60 (1.61.90)
@@ -2319,6 +2334,7 @@ CVE-2026-84269 (A flaw was found in the AFP backend in gvfs. When mounting a sha
 CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a share an ...)
 	- gvfs <unfixed> (bug #1146478)
 	[trixie] - gvfs <no-dsa> (Minor issue)
+	[bookworm] - gvfs <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/862
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/5ab77256f9c071c7c99a5298db1729cf143bff05 (1.61.90)
 	NOTE: Follow up: https://gitlab.gnome.org/GNOME/gvfs/-/commit/1ff24454d1c9b964a5f0efdd54c6d1421e770d64 (1.61.90)
@@ -2327,6 +2343,7 @@ CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a sh
 CVE-2026-84267 (A flaw was found in the SFTP backend in gvfs. When mounting a share, a ...)
 	- gvfs <unfixed> (bug #1146478)
 	[trixie] - gvfs <no-dsa> (Minor issue)
+	[bookworm] - gvfs <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/861
 	NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/340
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/d9a59b8e385189b4783d9b66ca475f530fb26693 (1.61.90)
@@ -2336,6 +2353,7 @@ CVE-2026-84235 (A denial-of-service security issue exists in the affected produc
 CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...)
 	- rpm <unfixed> (bug #1146602)
 	[trixie] - rpm <no-dsa> (Minor issue)
+	[bookworm] - rpm <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478409
 	TODO: check upstream details
 CVE-2026-84232 (A flaw was found in pulpcore's content serving application. Files uplo ...)
@@ -3100,6 +3118,7 @@ CVE-2026-82730 (Incorrect Authorization vulnerability in ash-project ash_typescr
 CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
 	- pypdf <unfixed> (bug #1146476)
 	[trixie] - pypdf <no-dsa> (Minor issue)
+	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m
 	NOTE: https://github.com/py-pdf/pypdf/pull/3947
@@ -3406,6 +3425,7 @@ CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP command injection
 CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command injection vul ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
 	[trixie] - node-nodemailer <no-dsa> (Minor issue)
+	[bookworm] - node-nodemailer <postponed> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-vvjj-xcjg-gr5g
 CVE-2026-82838 (The default docker image shipped for Venueless did not properly ensure ...)
 	NOT-FOR-US: rami.io products
@@ -3452,6 +3472,7 @@ CVE-2026-82801 (A vulnerability was detected in NASA earthdata-search 1.0.0. Aff
 CVE-2026-82797 (Uncontrolled Recursion vulnerability in Samsung Open Source rlottie al ...)
 	- rlottie <unfixed>
 	[trixie] - rlottie <no-dsa> (Minor issue)
+	[bookworm] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/603
 CVE-2026-82703 (A security flaw has been discovered in Edimax BR-6214K 1.40. This vuln ...)
 	NOT-FOR-US: Edimax
@@ -3518,18 +3539,22 @@ CVE-2026-82664 (A security vulnerability has been detected in yaojingang GEOFlow
 CVE-2026-82662 (Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
 	[trixie] - node-nodemailer <no-dsa> (Minor issue)
+	[bookworm] - node-nodemailer <postponed> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-r7g4-qg5f-qqm2
 CVE-2026-82661 (Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
 	[trixie] - node-nodemailer <no-dsa> (Minor issue)
+	[bookworm] - node-nodemailer <postponed> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-268h-hp4c-crq3
 CVE-2026-82660 (Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
 	[trixie] - node-nodemailer <no-dsa> (Minor issue)
+	[bookworm] - node-nodemailer <postponed> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
 CVE-2026-82659 (nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...)
 	- node-nodemailer 9.0.3+~8.0.1-1
 	[trixie] - node-nodemailer <no-dsa> (Minor issue)
+	[bookworm] - node-nodemailer <postponed> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f
 CVE-2026-82631 (A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ...)
 	- valkey <unfixed> (bug #1146641)
@@ -3777,6 +3802,7 @@ CVE-2026-17615 (A flaw was found in RESTEasy's SourceProvider. This vulnerabilit
 	- resteasy <unfixed>
 	- resteasy3.0 <unfixed>
 	[trixie] - resteasy3.0 <ignored> (Minor issue, no reverse deps in Trixie)
+	[bookworm] - resteasy3.0 <postponed> (Minor issue, no reverse deps in Trixie)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507635
 CVE-2026-14696 (When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_br ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
@@ -3826,6 +3852,7 @@ CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in pcre2_match() a
 CVE-2026-19873 (HTML::FormFu versions through 2.08 for Perl allow resource exhaustion  ...)
 	- libhtml-formfu-perl 2.07000-3 (bug #1146310)
 	[trixie] - libhtml-formfu-perl <no-dsa> (Minor issue)
+	[bookworm] - libhtml-formfu-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43141785/
 	NOTE: https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch
 CVE-2026-82727 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
@@ -3967,6 +3994,7 @@ CVE-2026-82592 (A vulnerability was detected in D-Link DIR-825M 1.1.8. This affe
 CVE-2026-82591 (A security vulnerability has been detected in Open Asset Import Librar ...)
 	- assimp <unfixed> (bug #1146642)
 	[trixie] - assimp <no-dsa> (Minor issue)
+	[bookworm] - assimp <postponed> (Minor issue)
 	NOTE: https://github.com/assimp/assimp/pull/6718
 	NOTE: Fixed by: https://github.com/assimp/assimp/commit/bf9dabb617c46e5133dac65cca6bff177917afcb
 CVE-2026-82590 (A weakness has been identified in Open5GS up to 2.7.7. The affected el ...)
@@ -4234,6 +4262,7 @@ CVE-2026-58581
 CVE-2026-82562 (### Summary    When `qs.parse` is called with `comma: true` and `throw ...)
 	- node-qs 6.16.0+ds+~6.15.1-1
 	[trixie] - node-qs <no-dsa> (Minor issue)
+	[bookworm] - node-qs <postponed> (Minor issue)
 	NOTE: https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx
 	NOTE: Fixed by: https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464 (v6.16.0)
 CVE-2026-82482 (A security vulnerability has been detected in coppermine-gallery Coppe ...)
@@ -4255,6 +4284,7 @@ CVE-2026-82421 (A vulnerability was identified in itsourcecode Sales and Invento
 CVE-2026-82417 (### Summary    `qs.stringify` throws a `TypeError` when it serializes  ...)
 	- node-qs 6.16.0+ds+~6.15.1-1
 	[trixie] - node-qs <no-dsa> (Minor issue)
+	[bookworm] - node-qs <postponed> (Minor issue)
 	NOTE: https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g
 	NOTE: Fixed by: https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6 (v6.16.0)
 CVE-2026-81766 (The Really Simple Security  WordPress plugin before 9.8.0 does not che ...)
@@ -4288,6 +4318,7 @@ CVE-2026-14307 (The geotargetingwp WordPress plugin before 3.5.6.2 does not sani
 CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory traversal.)
 	- ocaml-cohttp <unfixed> (bug #1146137)
 	[trixie] - ocaml-cohttp <no-dsa> (Minor issue)
+	[bookworm] - ocaml-cohttp <postponed> (Minor issue)
 	NOTE: https://github.com/mirage/ocaml-cohttp/pull/1145 (6.3.0)
 CVE-2026-82477 (In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF iss ...)
 	NOT-FOR-US: MITRE SAF Heimdall
@@ -4342,6 +4373,7 @@ CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network inter
 CVE-2026-82455 (RubyGems fails to re-validate path containment after filesystem symlin ...)
 	- rubygems <unfixed>
 	[trixie] - rubygems <no-dsa> (Minor issue)
+	[bookworm] - rubygems <postponed> (Minor issue)
 	NOTE: https://github.com/ruby/rubygems/pull/9493
 	NOTE: Fixed by (merge): https://github.com/ruby/rubygems/commit/103ca4230deacb31b9fcd813de109e83b5fc71ac
 CVE-2026-82454 (The Omnivore API (packages/api) before the fix in commit abf53d6 conta ...)
@@ -4601,6 +4633,7 @@ CVE-2026-55634 (Pimcore is an Open Source Data & Experience Management Platform.
 CVE-2026-55584 (phpSysInfo is a customizable PHP script that displays system informati ...)
 	- phpsysinfo <unfixed>
 	[trixie] - phpsysinfo <no-dsa> (Minor issue)
+	[bookworm] - phpsysinfo <postponed> (Minor issue)
 	NOTE: https://github.com/phpsysinfo/phpsysinfo/security/advisories/GHSA-786w-p5pm-cvgh
 	NOTE: https://github.com/phpsysinfo/phpsysinfo/commit/019fa2d7e568ea11461adb4bd33da5dc87c4b9ab (v3.4.6)
 CVE-2026-55569 (aqua is a declarative command-line version manager written in Go. Prio ...)
@@ -4870,6 +4903,7 @@ CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
 	- libsolv <unfixed>
 	[trixie] - libsolv <no-dsa> (Minor issue)
+	[bookworm] - libsolv <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
 	TODO: check upstream status, no references from Red Hat
 CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
@@ -5177,6 +5211,7 @@ CVE-2026-18393 (A flaw was found in FFmpeg. The tdsc_load_cursor() function writ
 CVE-2026-15603 (morgan is an HTTP request logger middleware for Node.js. In versions p ...)
 	- node-morgan 1.12.0+~1.9.10-1
 	[trixie] - node-morgan <no-dsa> (Minor issue)
+	[bookworm] - node-morgan <postponed> (Minor issue)
 	NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-jxfw-x594-9x9m
 CVE-2026-14942
 	REJECTED
@@ -5972,10 +6007,12 @@ CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently sanitiz
 CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in caller-s ...)
 	- mongo-c-driver 2.5.1-1
 	[trixie] - mongo-c-driver <no-dsa> (Minor issue)
+	[bookworm] - mongo-c-driver <postponed> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6424
 CVE-2026-81523 (A missing input-validation issue in MongoDB libmongocrypt's automatic- ...)
 	- libmongocrypt 1.20.3-1
 	[trixie] - libmongocrypt <no-dsa> (Minor issue)
+	[bookworm] - libmongocrypt <postponed> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-977
 CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of caller-supplied nam ...)
 	- mongo-cxx-driver 4.5.1-1
@@ -6037,11 +6074,13 @@ CVE-2026-77365 (The Optimole \u2013 Optimize Images | Convert WebP & AVIF | CDN
 CVE-2026-77358 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33. ...)
 	- cpp-httplib <unfixed> (bug #1145977)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-w7p7-f35j-mw7q
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/2f986fd5e56e7c5f686d965174516360930f371d (v0.50.1)
 CVE-2026-77341 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0 ...)
 	- cpp-httplib <unfixed> (bug #1145976)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-2r2h-jc8w-w66c
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/568d434e72fc51729d0ad33abffb181e5f7a453d (v0.50.0)
 CVE-2026-76945 (The affected Ebyte device relies on client-managed authentication toke ...)
@@ -6406,6 +6445,7 @@ CVE-2026-10036 (SpeechBrain before 1.1.1 contains an arbitrary code execution vu
 CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG  ...)
 	- gdk-pixbuf <unfixed> (bug #1145988)
 	[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
+	[bookworm] - gdk-pixbuf <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
 	NOTE: Introduced with: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4af78023ce7d3b5e3cec422a59bb4f48fa4f5886 (2.43.4)
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01
@@ -6413,11 +6453,13 @@ CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially crafted
 CVE-2026-80489
 	- glibc <unfixed> (bug #1145987)
 	[trixie] - glibc <no-dsa> (Minor issue)
+	[bookworm] - glibc <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524870
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34568
 CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a specially c ...)
 	- python-jwcrypto <unfixed> (bug #1145983)
 	[trixie] - python-jwcrypto <no-dsa> (Minor issue)
+	[bookworm] - python-jwcrypto <postponed> (Minor issue)
 	NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
 CVE-2026-81501
 	- incus 7.0.1-3
@@ -6430,6 +6472,7 @@ CVE-2026-81500
 CVE-2026-18374 (Passing an effectively empty string to the `,ccs=` syntax extension of ...)
 	- glibc <unfixed>
 	[trixie] - glibc <no-dsa> (Minor issue)
+	[bookworm] - glibc <postponed> (Minor issue)
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015
 CVE-2026-81827 (Affected versions of Flowintel incorrectly attempted to validate login ...)
 	NOT-FOR-US: Flowintel
@@ -6454,26 +6497,32 @@ CVE-2026-81735 (startServer.ts in the mcp-http-server package of UI-TARS-desktop
 CVE-2026-81727 (NLTK versions before 3.10.3 contain a filesystem containment bypass vu ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-f794-5jv7-7672
 CVE-2026-81726 (NLTK through 3.10.3 contains a path traversal vulnerability in model-a ...)
 	- nltk <unfixed>
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xp
 CVE-2026-81725 (NLTK before 3.10.3 contains a regular expression denial of service vul ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-8mpw-7fpc-4gqj
 CVE-2026-81724 (NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-cw6x-m8jw-qmrh
 CVE-2026-81723 (NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnera ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-vp2x-qp44-57v7
 CVE-2026-81722 (nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94g
 CVE-2026-81721 (openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in  ...)
 	NOT-FOR-US: OpenSSL Encrypt
@@ -6696,6 +6745,7 @@ CVE-2026-78257 (Contributor PHP Object Injection in Booking and Rental Manager <
 CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker can tr ...)
 	- rsyslog 8.2608.0-4 (bug #1145980)
 	[trixie] - rsyslog <no-dsa> (Minor issue)
+	[bookworm] - rsyslog <postponed> (Minor issue)
 	NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3
 	NOTE: https://github.com/rsyslog/rsyslog/pull/7525
 	NOTE: https://github.com/rsyslog/rsyslog/commit/667e3f61aec5ee02c5c2ee6f0f8accf6fe4301a9
@@ -7117,6 +7167,7 @@ CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via th
 CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia diagram e ...)
 	- dia <unfixed>
 	[trixie] - dia <no-dsa> (Minor issue)
+	[bookworm] - dia <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/580
 CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
 	- seaweedfs <itp> (bug #956957)
@@ -7435,12 +7486,14 @@ CVE-2023-27503
 CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the community.general  ...)
 	- ansible <unfixed>
 	[trixie] - ansible <no-dsa> (Minor issue)
+	[bookworm] - ansible <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
 CVE-2026-78360
 	NOT-FOR-US: fedora-infra/anitya
 CVE-2026-77117
 	- glibc <unfixed> (bug #1145880)
 	[trixie] - glibc <no-dsa> (Minor issue)
+	[bookworm] - glibc <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523274
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34556
 CVE-2026-9668 (With legitimate user credentials in hand, attackers can construct mali ...)
@@ -7838,10 +7891,12 @@ CVE-2026-80233 (CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN
 CVE-2026-80206 (NLTK before 3.10.3 contains a regular expression denial of service (Re ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-w3v8-gmh9-3wv7
 CVE-2026-80205 (NLTK versions before 3.10.0 contain a regular expression denial of ser ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-rrv8-h7p8-rx55
 CVE-2026-80204 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not a ...)
 	NOT-FOR-US: Grav plugin
@@ -7869,6 +7924,7 @@ CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all ver
 CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia diagram  ...)
 	- dia <unfixed>
 	[trixie] - dia <no-dsa> (Minor issue)
+	[bookworm] - dia <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/581
 CVE-2026-77557 (A malicious actor with access to the network could exploit an Improper ...)
 	NOT-FOR-US: Ubiquiti UniFi
@@ -8222,11 +8278,13 @@ CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how m
 CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, the Linux ...)
 	- bluez <unfixed> (bug #1145869)
 	[trixie] - bluez <no-dsa> (Minor issue)
+	[bookworm] - bluez <postponed> (Minor issue)
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
 CVE-2026-80185 (BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can  ...)
 	- bluez <unfixed> (bug #1145870)
 	[trixie] - bluez <no-dsa> (Minor issue)
+	[bookworm] - bluez <postponed> (Minor issue)
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
 CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or escape the ...)
@@ -9638,6 +9696,7 @@ CVE-2026-72924 (GitHub CLI (gh) is GitHub's official command line tool. Versions
 CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect authentication  ...)
 	- ruby-doorkeeper-openid-connect 1.10.5-1
 	[trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
+	[bookworm] - ruby-doorkeeper-openid-connect <postponed> (Minor issue)
 	NOTE: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-8r7r-wh7x-27ff
 	NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/abb47dc5e6012ea05eda0b7979cc6bd41904011b (v1.10.4)
 CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...)
@@ -9856,6 +9915,7 @@ CVE-2026-45018 (Chainlit is a Python framework for building production-ready con
 CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, ...)
 	- ruby-doorkeeper-openid-connect 1.10.1-1
 	[trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
+	[bookworm] - ruby-doorkeeper-openid-connect <postponed> (Minor issue)
 	NOTE: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-m6vc-f87m-cc2h
 	NOTE: Fixed by: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/561af83dcf71b95b3772dfbc0a1796c7f50b2175 (v1.10.0)
 CVE-2026-43670 (A Content Security Policy bypass was addressed with improved enforceme ...)
@@ -9869,6 +9929,7 @@ CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecos
 CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)
 	- sqlite3 3.53.2-1
 	[trixie] - sqlite3 <no-dsa> (Minor issue)
+	[bookworm] - sqlite3 <postponed> (Minor issue)
 	NOTE: https://github.com/20000419/CVE-2026-39113
 	NOTE: https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508 (version-3.53.0)
 CVE-2026-38474 (GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d1 ...)
@@ -9976,6 +10037,7 @@ CVE-2026-80182 (In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1
 CVE-2026-19499
 	- glibc <unfixed> (bug #1145891)
 	[trixie] - glibc <no-dsa> (Minor issue)
+	[bookworm] - glibc <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523258
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34510
 CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not  ...)
@@ -10028,28 +10090,34 @@ CVE-2026-79773 (Winter CMS before 1.2.13 contains a local file inclusion vulnera
 CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value from xm ...)
 	- ruby-nokogiri 1.19.1+dfsg-1
 	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+	[bookworm] - ruby-nokogiri <postponed> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532
 CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Styl ...)
 	- ruby-nokogiri 1.19.3+dfsg-1
 	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+	[bookworm] - ruby-nokogiri <postponed> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v2fc-qm4h-8hqv
 CVE-2026-79770 (Nokogiri versions before 1.19.3 contain regular expression denial of s ...)
 	- ruby-nokogiri 1.19.3+dfsg-1
 	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+	[bookworm] - ruby-nokogiri <postponed> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-c4rq-3m3g-8wgx
 CVE-2026-79769 (Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bou ...)
 	- ruby-nokogiri 1.19.4+dfsg-1
 	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+	[bookworm] - ruby-nokogiri <postponed> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-g9g8-vgvw-g3vf
 CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found in galaxy ...)
 	NOT-FOR-US: Ansible Galaxy server plugin for Pulp
 CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal vulnerability in  ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-p4rw-rvv2-7xwr
 CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed through the pe ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3
 CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ...)
 	- nltk 3.10.3-1
@@ -10596,6 +10664,7 @@ CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby implementation only, when the pack
 CVE-2026-63676
 	- libyaml-perl 1.321-1
 	[trixie] - libyaml-perl <no-dsa> (Minor issue)
+	[bookworm] - libyaml-perl <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1 (v1.320.0)
 CVE-2026-XXXX [GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution]
 	- sabnzbdplus 5.1.2+dfsg-1 (bug #1145563)
@@ -10679,6 +10748,7 @@ CVE-2026-63075 (Issue summary: When OpenSSL processes QUIC traffic from a peer t
 CVE-2026-19953 (URI versions before 5.36 for Perl encode non-NFC host names to non-sta ...)
 	- liburi-perl 5.36-1
 	[trixie] - liburi-perl <no-dsa> (Minor issue)
+	[bookworm] - liburi-perl <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/libwww-perl/URI/commit/8c213ff92fdae45d0fabb7bc16f6a6f27e911395 (v5.36)
 CVE-2026-7455 (A maliciously crafted FLT file, when parsed through Autodesk 3ds Max,  ...)
 	NOT-FOR-US: Autodesk
@@ -10793,6 +10863,7 @@ CVE-2026-76816 (Netty is an asynchronous, event-driven network application frame
 CVE-2026-76098 (Mistune is a Python Markdown parser with renderers and plugins. Versio ...)
 	- mistune <unfixed> (bug #1145881)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <postponed> (Minor issue)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-6m44-fpc8-c3rq
 	NOTE: https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2 (v3.3.3)
 CVE-2026-76063 (The FundEngine \u2013 Donation and Crowdfunding Platform plugin for Wo ...)
@@ -11058,6 +11129,7 @@ CVE-2026-78369 (RansomLook contains a missing authentication vulnerability in th
 CVE-2026-78367 (A vulnerability was found in RPM's rpmbuild tarball processing. When p ...)
 	- rpm <unfixed> (bug #1145876)
 	[trixie] - rpm <no-dsa> (Minor issue)
+	[bookworm] - rpm <postponed> (Minor issue)
 	NOTE: https://github.com/rpm-software-management/rpm/issues/4314
 CVE-2026-78365 (Authorization Bypass Through User-Controlled Key in the supplier API i ...)
 	NOT-FOR-US: Roskus Prospero Flow CRM
@@ -11624,6 +11696,7 @@ CVE-2026-75922 (Reverse::Proxy versions before 0.04 for Perl allow HTTP request
 CVE-2026-19542 [Out-of-bounds stack array access in tdelete]
 	- glibc 2.43-4
 	[trixie] - glibc <no-dsa> (Minor issue)
+	[bookworm] - glibc <postponed> (Minor issue)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34506
 	NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
 CVE-2026-78136 (chirpmyradio CHIRP before 39178db allows eval injection via crafted CS ...)
@@ -11741,6 +11814,7 @@ CVE-2026-68769
 CVE-2026-68768 (hashcat contains a heap-based buffer overflow (out-of-bounds write) in ...)
 	- hashcat <unfixed> (bug #1145171)
 	[trixie] - hashcat <no-dsa> (Minor issue)
+	[bookworm] - hashcat <postponed> (Minor issue)
 	NOTE: https://github.com/hashcat/hashcat/issues/4740
 	NOTE: https://github.com/hashcat/hashcat/pull/4754
 	NOTE: Fixed by: https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89
@@ -11753,6 +11827,7 @@ CVE-2026-68767 (hashcat's fgetl() function in src/filehandling.c writes a null t
 CVE-2026-68766 (hashcat fails to restrict command-line options when parsing restore fi ...)
 	- hashcat <unfixed> (bug #1145171)
 	[trixie] - hashcat <no-dsa> (Minor issue)
+	[bookworm] - hashcat <postponed> (Minor issue)
 	NOTE: https://github.com/hashcat/hashcat/issues/4738
 	NOTE: Fixed by: https://github.com/hashcat/hashcat/commit/fcae69f2438ff8eae0dc8e206b78067a1e465ed4
 CVE-2026-66917 (Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery  ...)
@@ -12816,6 +12891,7 @@ CVE-2026-11418
 CVE-2026-77781 (Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exceptio ...)
 	- libtie-hash-regex-perl 1.14-3
 	[trixie] - libtie-hash-regex-perl <no-dsa> (Minor issue)
+	[bookworm] - libtie-hash-regex-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42893692/
 	NOTE: Fixed by: https://github.com/davorg-cpan/tie-hash-regex/commit/4239732cb76233543e2ded8ff5e0f238af152e0c (RELEASE_2.0.0)
 CVE-2026-9324
@@ -13165,6 +13241,7 @@ CVE-2026-56875
 CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
 	- capstone <unfixed> (bug #1145195)
 	[trixie] - capstone <no-dsa> (Minor issue)
+	[bookworm] - capstone <postponed> (Minor issue)
 	NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4
 	NOTE: https://github.com/capstone-engine/capstone/pull/2968
 	NOTE: Fixed by: https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e (6.0.0-Alpha10)
@@ -13173,6 +13250,7 @@ CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier
 CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
 	- capstone <unfixed> (bug #1145195)
 	[trixie] - capstone <no-dsa> (Minor issue)
+	[bookworm] - capstone <postponed> (Minor issue)
 	NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh
 	NOTE: https://github.com/capstone-engine/capstone/pull/2968
 	NOTE: Fixed by: https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e (6.0.0-Alpha10)
@@ -13247,6 +13325,7 @@ CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to versi
 CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function builds the ex ...)
 	- onnx <unfixed> (bug #1145196)
 	[trixie] - onnx <no-dsa> (Minor issue)
+	[bookworm] - onnx <postponed> (Minor issue)
 	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-q56x-g2fj-4rj6
 CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
 	NOT-FOR-US: joshnuss xml_builder
@@ -13673,6 +13752,7 @@ CVE-2026-75514 (BunkerWeb is an open-source, next-generation Web Application Fir
 CVE-2026-75140 (jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolle ...)
 	- jsoup <unfixed> (bug #1144972)
 	[trixie] - jsoup <no-dsa> (Minor issue)
+	[bookworm] - jsoup <postponed> (Minor issue)
 	NOTE: https://github.com/jhy/jsoup/pull/2556
 	NOTE: Fixed by: https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a
 CVE-2026-74021 (Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.)
@@ -13757,6 +13837,7 @@ CVE-2026-73196 (A flaw was found in FreeIPA. A low-privilege authenticated user
 CVE-2026-72854 (msgpack_unpacker_expand_buffer in src/unpack.c, reached through the pu ...)
 	- msgpack-c <unfixed>
 	[trixie] - msgpack-c <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - msgpack-c <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/msgpack/msgpack-c/issues/1181
 CVE-2026-72852 (hank-ai/darknet sizes a convolutional layer's weight and output heap b ...)
 	NOT-FOR-US: hank-ai/darknet
@@ -13887,6 +13968,7 @@ CVE-2026-64960 (ATutor Gameme module allows users to upload files of any type an
 CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems. Prior to 2. ...)
 	- nix <unfixed> (bug #1145021)
 	[trixie] - nix <no-dsa> (Minor issue)
+	[bookworm] - nix <postponed> (Minor issue)
 	NOTE: https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f
 	NOTE: https://github.com/NixOS/nix/pull/15401
 	NOTE: Fixed by: https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390 (2.35.0)
@@ -13994,6 +14076,7 @@ CVE-2026-55095 (OpenProject is open-source, web-based project management softwar
 CVE-2026-54770 (WebOb provides objects for HTTP requests and responses. Prior to 1.8.1 ...)
 	- python-webob <unfixed>
 	[trixie] - python-webob <no-dsa> (Minor issue)
+	[bookworm] - python-webob <postponed> (Minor issue)
 	NOTE: https://github.com/Pylons/webob/security/advisories/GHSA-6hx8-3wjj-gr8g
 	NOTE: Fixed by: https://github.com/Pylons/webob/commit/ff89560643fb252751b4db8806a283b5377f1f07 (1.8.11)
 CVE-2026-54625 (django CMS is a content management system powered by Django. Prior to  ...)
@@ -14064,6 +14147,7 @@ CVE-2026-19586 (A pre-authentication OS command injection vulnerability has been
 CVE-2026-18917 (A flaw was found in libvirt. An unprivileged local user could exploit  ...)
 	- libvirt 12.7.0-1 (bug #1145069)
 	[trixie] - libvirt <no-dsa> (Minor issue)
+	[bookworm] - libvirt <postponed> (Minor issue)
 	NOTE: https://gitlab.com/libvirt/libvirt/-/work_items/903
 	NOTE: Introduced with: https://gitlab.com/libvirt/libvirt/-/commit/34f2d0319d2098c77c8cc27d8350616029125a2b (v1.2.6-rc1)
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/5a62cbf2907d4590283597b46da9c0f41e7b4d4f (v12.7.0-rc1)
@@ -14241,6 +14325,7 @@ CVE-2026-16922 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a loca
 CVE-2026-15743 (Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark r ...)
 	- libcatalyst-plugin-static-simple-perl 0.38-1
 	[trixie] - libcatalyst-plugin-static-simple-perl <no-dsa> (Minor issue)
+	[bookworm] - libcatalyst-plugin-static-simple-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42860527/
 	NOTE: https://github.com/perl-catalyst/Catalyst-Plugin-Static-Simple/pull/3
 	NOTE: https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch
@@ -14456,8 +14541,10 @@ CVE-2026-76879 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4
 CVE-2026-76878 (In OpenStack Aodh before 22.0.1, the alarm list API bypasses project s ...)
 	- aodh 22.0.0-3 (bug #1144879)
 	[trixie] - aodh <no-dsa> (Minor issue)
+	[bookworm] - aodh <postponed> (Minor issue)
 	- watcher 16.0.0-5 (bug #1144880)
 	[trixie] - watcher <no-dsa> (Minor issue)
+	[bookworm] - watcher <postponed> (Minor issue)
 	NOTE: https://launchpad.net/bugs/2161276
 	NOTE: https://launchpad.net/bugs/2161771
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-036.html
@@ -15409,18 +15496,22 @@ CVE-2026-66596 (Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.
 CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can place a f ...)
 	- nnn <unfixed> (bug #1145170)
 	[trixie] - nnn <no-dsa> (Minor issue)
+	[bookworm] - nnn <postponed> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can createa direc ...)
 	- nnn <unfixed> (bug #1145170)
 	[trixie] - nnn <no-dsa> (Minor issue)
+	[bookworm] - nnn <postponed> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-65610 (nnn stores homelen variable as uchar_t, which can only represent value ...)
 	- nnn <unfixed> (bug #1145170)
 	[trixie] - nnn <no-dsa> (Minor issue)
+	[bookworm] - nnn <postponed> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-65609 (nnn is vulnerable to Out-of-Bound write vulnerability.Due to lack of v ...)
 	- nnn <unfixed> (bug #1145170)
 	[trixie] - nnn <no-dsa> (Minor issue)
+	[bookworm] - nnn <postponed> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-64852 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
 	NOT-FOR-US: Grav plugin
@@ -15686,6 +15777,7 @@ CVE-2026-19672 (The tarfile module's tar and data  extraction filters created di
 	- python3.9 <removed>
 	- pypy3 <unfixed>
 	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[bookworm] - pypy3 <postponed> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/
 	NOTE: https://github.com/python/cpython/issues/155999
 	NOTE: https://github.com/python/cpython/pull/156000
@@ -15796,11 +15888,13 @@ CVE-2019-25766 (Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repos
 CVE-2026-73639
 	- libimager-perl 1.035+dfsg-1
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
+	[bookworm] - libimager-perl <postponed> (Minor issue)
 	NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-jhx5-34j8-9g88
 	NOTE: https://github.com/tonycoz/imager/pull/567
 CVE-2026-73638
 	- libimager-perl 1.035+dfsg-1
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
+	[bookworm] - libimager-perl <postponed> (Minor issue)
 	NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-j47j-8w8p-3mmc
 	NOTE: https://github.com/tonycoz/imager/issues/568
 CVE-2026-XXXX [GHSA-xrfq-jhgh-wqch: Authentication bypass in the web interface]
@@ -15811,12 +15905,14 @@ CVE-2026-XXXX [GHSA-xrfq-jhgh-wqch: Authentication bypass in the web interface]
 CVE-2026-72889 (Net::OAuth versions before 0.33 for Perl allow the sender to choose th ...)
 	- libnet-oauth-perl 0.33-1 (bug #1144854)
 	[trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
+	[bookworm] - libnet-oauth-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818761/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5
 	NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/c467adf45c8d77ac4b92ad78b3eebf949252ba7f
 CVE-2026-75589 (Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256  ...)
 	- libnet-oauth-perl 0.33-1 (bug #1144855)
 	[trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
+	[bookworm] - libnet-oauth-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818763/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-g8xr-69p3-gw56
 	NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/a1a16b58add85668ef4fcda642a486ceed098eba
@@ -17960,6 +18056,7 @@ CVE-2026-15571 (A flaw was found in the legacy client-initiated account-linking
 CVE-2026-75900 (An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_C ...)
 	- swtpm 0.10.2-1 (bug #1144810)
 	[trixie] - swtpm <no-dsa> (Minor issue)
+	[bookworm] - swtpm <postponed> (Minor issue)
 	NOTE: https://github.com/stefanberger/swtpm/pull/1155
 	NOTE: Fixed by: https://github.com/stefanberger/swtpm/commit/dc5f5ee3d8261a4d9814ad5da69164a118822401 (master)
 	NOTE: Fixed by: https://github.com/stefanberger/swtpm/commit/afc9e512a0459b12776e8fa509cfa039908c6be6 (v0.10.2)
@@ -18084,6 +18181,7 @@ CVE-2026-75911 (CodeWhale versions before 0.8.64 fail to properly validate the a
 CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplo ...)
 	- libmodplug 1:0.8.9.0-4 (bug #1144933)
 	[trixie] - libmodplug <no-dsa> (Minor issue)
+	[bookworm] - libmodplug <postponed> (Minor issue)
 	NOTE: https://github.com/Konstanty/libmodplug/issues/103
 CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
 	NOT-FOR-US: RAGFlow
@@ -18187,6 +18285,7 @@ CVE-2026-75107 (Grav Form Plugin before 9.1.19 fails to escape field-definition
 CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet length fi ...)
 	- bluez 5.87-2 (bug #1144961)
 	[trixie] - bluez <no-dsa> (Minor issue)
+	[bookworm] - bluez <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
 	NOTE: Followup: https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
@@ -18706,6 +18805,7 @@ CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking Si
 CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
 	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
+	[bookworm] - rabbitmq-java-client <postponed> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-93j5-89vc-pph4
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/09af76fce136f3136931654a0a1d43095c80e2f0 (main)
@@ -18714,6 +18814,7 @@ CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based appli
 CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
 	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
+	[bookworm] - rabbitmq-java-client <postponed> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2 (main)
@@ -18832,6 +18933,7 @@ CVE-2026-63639 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0
 CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
 	- onnx <unfixed> (bug #1145196)
 	[trixie] - onnx <no-dsa> (Minor issue)
+	[bookworm] - onnx <postponed> (Minor issue)
 	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-p893-rvq9-2xf9
 	NOTE: https://github.com/onnx/onnx/pull/7880
 	NOTE: Fixed by: https://github.com/onnx/onnx/commit/e9c74f596eaa0250f89e52a54160a25bbcb25b66 (v1.22.0)
@@ -18880,6 +18982,7 @@ CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kript
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
 	- lz4-java 1.11.2+ds1-1 (bug #1145019)
 	[trixie] - lz4-java <no-dsa> (Minor issue)
+	[bookworm] - lz4-java <postponed> (Minor issue)
 	NOTE: https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
 	NOTE: Fixed by: https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da (v1.11.1)
 CVE-2026-59940 (Seroval facilitates JS value stringification, including complex struct ...)
@@ -18918,6 +19021,7 @@ CVE-2026-54570 (AngleSharp is a .NET library for parsing angle bracket based hyp
 CVE-2026-54552 (sh provides Python process launching. Prior to 2.2.4, the _uid option  ...)
 	- python-sh <unfixed> (bug #1145886)
 	[trixie] - python-sh <no-dsa> (Minor issue)
+	[bookworm] - python-sh <postponed> (Minor issue)
 	NOTE: https://github.com/amoffat/sh/security/advisories/GHSA-q38v-wp89-2w55
 	NOTE: https://github.com/amoffat/sh/pull/776
 	NOTE: Fixed by: https://github.com/amoffat/sh/commit/3d855daba91f87a089b490c0d1cf1df3faace2f1 (2.2.4)
@@ -18954,6 +19058,7 @@ CVE-2026-50167 (Kurrier is a modern, self-hosted workspace for email, calendar,
 CVE-2026-50161 (libre is a generic library for real-time communications with asynchron ...)
 	- libre <unfixed>
 	[trixie] - libre <no-dsa> (Minor issue)
+	[bookworm] - libre <postponed> (Minor issue)
 	NOTE: https://github.com/baresip/re/security/advisories/GHSA-hvxv-v2gp-v93h
 	NOTE: https://github.com/baresip/re/pull/1584
 	NOTE: Fixed by: https://github.com/baresip/re/commit/718b92615c7963670d26c1a2b246968b58d782e8 (v4.8.1)
@@ -19182,6 +19287,7 @@ CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
 	- pypy3 <unfixed>
 	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[bookworm] - pypy3 <postponed> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/
 	NOTE: https://github.com/python/cpython/issues/155292
 	NOTE: https://github.com/python/cpython/pull/155293
@@ -19200,6 +19306,7 @@ CVE-2026-15806 (The HTTPPasswordMgr class in the urllib.request module, along wi
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
 	- pypy3 <unfixed>
 	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[bookworm] - pypy3 <postponed> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/
 	NOTE: https://github.com/python/cpython/issues/155694
 	NOTE: https://github.com/python/cpython/pull/155696
@@ -19327,6 +19434,7 @@ CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap buffer
 CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to ...)
 	- mini-httpd 1.30-18 (bug #1144953)
 	[trixie] - mini-httpd <no-dsa> (Minor issue)
+	[bookworm] - mini-httpd <postponed> (Minor issue)
 CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remo ...)
 	NOT-FOR-US: OSSRS SRS (Simple Realtime Server)
 CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an ...)
@@ -19686,6 +19794,7 @@ CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1
 CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
 	- node-postcss 8.5.19+~cs10.2.23-1
 	[trixie] - node-postcss <no-dsa> (Minor issue)
+	[bookworm] - node-postcss <postponed> (Minor issue)
 	NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849
 	NOTE: Fixed by: https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c (8.5.18)
 CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation vulnerabi ...)
@@ -19707,6 +19816,7 @@ CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to s
 CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
 	[trixie] - sqlparse <no-dsa> (Minor issue)
+	[bookworm] - sqlparse <postponed> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87 (0.6.0)
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
@@ -19718,6 +19828,7 @@ CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocke
 CVE-2026-68520 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
 	- glances 4.5.6+dfsg-1
 	[trixie] - glances <no-dsa> (Minor issue)
+	[bookworm] - glances <postponed> (Minor issue)
 	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-4h34-v6r8-mmjc
 	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/8d0f8276c2abd2e9d400bd6c84bdfba0dfcab065 (v4.5.6)
 CVE-2026-68519 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
@@ -19730,11 +19841,13 @@ CVE-2026-68519 (Glances is an open-source system cross-platform monitoring tool.
 CVE-2026-68518 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
 	- glances 4.5.6+dfsg-1
 	[trixie] - glances <no-dsa> (Minor issue)
+	[bookworm] - glances <postponed> (Minor issue)
 	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-qcpp-8x79-hhp3
 	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/9c280eae5419da680827024b60f6265956e31994 (v4.5.6)
 CVE-2026-68517 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
 	- glances 4.5.6+dfsg-1
 	[trixie] - glances <no-dsa> (Minor issue)
+	[bookworm] - glances <postponed> (Minor issue)
 	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg
 	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/890858944ab9d03730ec6b1ba42d4015e6d85db5 (v4.5.6)
 CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription component. T ...)
@@ -19757,6 +19870,7 @@ CVE-2026-62982 (Glances is an open-source system cross-platform monitoring tool.
 CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
 	- ruby-websocket-driver 0.8.2-1
 	[trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
+	[bookworm] - ruby-websocket-driver <postponed> (Minor issue)
 	NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-2x63-gw47-w4mm
 	NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/7d6fd87759a2fdc83590d3b49ffa661dc53fa128 (0.8.2)
 CVE-2026-60107
@@ -19783,11 +19897,13 @@ CVE-2026-59902 (Netty is an asynchronous, event-driven network application frame
 CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
 	[trixie] - sqlparse <no-dsa> (Minor issue)
+	[bookworm] - sqlparse <postponed> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/53ff44b53e27cff78259acc1af015506fea60f63 (0.6.0)
 CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
 	[trixie] - sqlparse <no-dsa> (Minor issue)
+	[bookworm] - sqlparse <postponed> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e (0.6.0)
 CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -19811,6 +19927,7 @@ CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1
 CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
 	[trixie] - sqlparse <no-dsa> (Minor issue)
+	[bookworm] - sqlparse <postponed> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f (0.6.0)
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -19868,6 +19985,7 @@ CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management
 CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
 	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <no-dsa> (Minor issue)
+	[bookworm] - assimp <postponed> (Minor issue)
 	NOTE: https://github.com/assimp/assimp/issues/6633
 	NOTE: https://github.com/assimp/assimp/pull/6759
 	NOTE: https://github.com/assimp/assimp/commit/50d767984e78d51b53e2020fdf0967fd624bc377
@@ -19876,6 +19994,7 @@ CVE-2026-19998 (A weakness has been identified in code-projects Online Shopping
 CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent directory ...)
 	- node-extract-zip <unfixed> (bug #1144934)
 	[trixie] - node-extract-zip <no-dsa> (Minor issue)
+	[bookworm] - node-extract-zip <postponed> (Minor issue)
 	NOTE: https://github.com/max-mapper/extract-zip/pull/160
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
 	NOT-FOR-US: Kong Mesh
@@ -20008,14 +20127,17 @@ CVE-2026-19971 (A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the
 CVE-2026-19970 (A vulnerability was detected in Open Asset Import Library Assimp 17c12 ...)
 	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/assimp/assimp/issues/6632
 CVE-2026-19969 (A security vulnerability has been detected in Open Asset Import Librar ...)
 	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/assimp/assimp/issues/6631
 CVE-2026-19968 (A weakness has been identified in Open Asset Import Library Assimp 17c ...)
 	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <no-dsa> (Minor issue)
+	[bookworm] - assimp <postponed> (Minor issue)
 	NOTE: https://github.com/assimp/assimp/issues/6630
 	NOTE: https://github.com/assimp/assimp/pull/6717
 	NOTE: https://github.com/assimp/assimp/commit/c39d8c15dbbe03174af61d8eedbbf90120f4eb9f
@@ -20024,6 +20146,7 @@ CVE-2026-19968 (A weakness has been identified in Open Asset Import Library Assi
 CVE-2026-19967 (A security flaw has been discovered in Open Asset Import Library Assim ...)
 	- assimp <unfixed> (bug #1145890)
 	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/assimp/assimp/issues/6624
 CVE-2026-19966 (A vulnerability was identified in CodeCanyon TimeCamp Integration for  ...)
 	NOT-FOR-US: CodeCanyon TimeCamp Integration for CRM
@@ -20132,12 +20255,14 @@ CVE-2024-13784 (The Contact Form, Survey, Quiz & Popup Form Builder \u2013 ARFor
 CVE-2026-72888 (Net::OAuth versions before 0.32 for Perl allow memory exhaustion via u ...)
 	- libnet-oauth-perl 0.32-1 (bug #1144539)
 	[trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
+	[bookworm] - libnet-oauth-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733455/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-m2cv-cq5x-47ph
 	NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/ee713fc96263c70b3b9a5280612618b474576f8f
 CVE-2026-72887 (Net::OAuth::Client versions before 0.32 for Perl allow the service pro ...)
 	- libnet-oauth-perl 0.32-1 (bug #1144539)
 	[trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
+	[bookworm] - libnet-oauth-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733454/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-jh72-4qq2-8j6g
 	NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/fd505dac1988723ed96721657663f2e4ac731644
@@ -21058,6 +21183,7 @@ CVE-2026-74250 (In OpenStack Ironic before 38.0.1, the autodetect deploy interfa
 CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) p ...)
 	- octavia 18.0.0-3 (bug #1144459)
 	[trixie] - octavia <no-dsa> (Minor issue)
+	[bookworm] - octavia <postponed> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/12
 	NOTE: https://bugs.launchpad.net/octavia/+bug/2161500
 CVE-2026-74247 (A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT en ...)
@@ -25295,10 +25421,12 @@ CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to versi
 CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
 	- capstone <unfixed> (bug #1144518)
 	[trixie] - capstone <no-dsa> (Minor issue)
+	[bookworm] - capstone <postponed> (Minor issue)
 	NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-jrw4-wj52-2vw8
 CVE-2026-49263 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
 	- capstone <unfixed> (bug #1144519)
 	[trixie] - capstone <no-dsa> (Minor issue)
+	[bookworm] - capstone <postponed> (Minor issue)
 	NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-5m9f-vqcm-g5pr
 CVE-2026-48528 (Metacat is data repository software that helps researchers preserve, s ...)
 	NOT-FOR-US: Metacat
@@ -25419,6 +25547,7 @@ CVE-2026-13196 (Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write v
 CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an infinite  ...)
 	- dnsmasq <unfixed> (bug #1144649)
 	[trixie] - dnsmasq <no-dsa> (Minor issue)
+	[bookworm] - dnsmasq <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2486360
 CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in kernel/u ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
@@ -26197,6 +26326,7 @@ CVE-2026-73567 (sm-crypto provides JavaScript implementations of the Chinese cry
 CVE-2026-73566 (node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...)
 	- node-tar 7.5.22+~4.0.1-1
 	[trixie] - node-tar <no-dsa> (Minor issue)
+	[bookworm] - node-tar <postponed> (Minor issue)
 	NOTE: https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m
 	NOTE: Fixed by:https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a (v7.5.21)
 CVE-2026-73565 (@hono/node-server allows running the Hono application on Node.js. From ...)
@@ -26226,6 +26356,7 @@ CVE-2026-73532 (Fluent Forms Pro 6.2.7 contains an embedded malicious code vulne
 CVE-2026-73515 (PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability ...)
 	- postgis <unfixed> (bug #1144647)
 	[trixie] - postgis <no-dsa> (Minor issue)
+	[bookworm] - postgis <postponed> (Minor issue)
 	NOTE: https://gitea.osgeo.org/postgis/postgis/pulls/669
 	NOTE: https://gitea.osgeo.org/postgis/postgis/commit/767fa40644253281f6d4e8b06811489b0a0f9b0d (stable-3.6)
 	NOTE: https://gitea.osgeo.org/postgis/postgis/commit/d2b5298d8b82ec1a4a667594422e9670b6dbd7e1 (stable-3.5)
@@ -26780,6 +26911,7 @@ CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the commentLis
 CVE-2022-4993 (HTML::FormHandler versions through 0.40068 for Perl allow attacker sel ...)
 	- libhtml-formhandler-perl 0.40068-3
 	[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue; will be fixed via point release)
+	[bookworm] - libhtml-formhandler-perl <postponed> (Minor issue; will be fixed via point release)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42659947/
 	NOTE: https://security.metacpan.org/patches/H/HTML-FormHandler/0.40068/CVE-2022-4993-r2.patch
 CVE-2026-13048 (Data::MuForm::Localizer versions through 0.05 for Perl execute Perl fr ...)
@@ -27039,12 +27171,14 @@ CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to
 CVE-2026-73500 (etcd is a distributed key-value store for the data of a distributed sy ...)
 	- etcd <unfixed> (bug #1144346)
 	[trixie] - etcd <no-dsa> (Minor issue)
+	[bookworm] - etcd <postponed> (Minor issue)
 	NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
 	NOTE: https://github.com/etcd-io/etcd/pull/22130
 	NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057 (v3.5.33)
 CVE-2026-73499 (etcd is a distributed key-value store for the data of a distributed sy ...)
 	- etcd <unfixed> (bug #1144346)
 	[trixie] - etcd <no-dsa> (Minor issue)
+	[bookworm] - etcd <postponed> (Minor issue)
 	NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
 	NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7 (v3.5.33)
 CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
@@ -27056,18 +27190,21 @@ CVE-2026-73493 (Http4s (http4s-blaze-server) is a minimal, idiomatic Scala inter
 CVE-2026-73492 (Loofah is a general library for manipulating and transforming HTML/XML ...)
 	- ruby-loofah 2.25.2-1
 	[trixie] - ruby-loofah <no-dsa> (Minor issue)
+	[bookworm] - ruby-loofah <postponed> (Minor issue)
 	NOTE: https://github.com/flavorjones/loofah/security/advisories/GHSA-5qhf-9phg-95m2
 	NOTE: https://github.com/flavorjones/loofah/pull/308
 	NOTE: Fixed by: https://github.com/flavorjones/loofah/commit/f1be9d893b5a8dd79240441a912d8897e74c38c0 (v2.25.2)
 CVE-2026-73491 (Loofah is a general library for manipulating and transforming HTML/XML ...)
 	- ruby-loofah 2.25.2-1
 	[trixie] - ruby-loofah <no-dsa> (Minor issue)
+	[bookworm] - ruby-loofah <postponed> (Minor issue)
 	NOTE: https://github.com/flavorjones/loofah/security/advisories/GHSA-8whx-365g-h9vv
 	NOTE: https://github.com/flavorjones/loofah/pull/308
 	NOTE: Fixed by: https://github.com/flavorjones/loofah/commit/5e91af861e3cdab47b91dd0b81f3afdfd13a5e19 (v2.25.2)
 CVE-2026-73490 (Loofah is a general library for manipulating and transforming HTML/XML ...)
 	- ruby-loofah 2.25.2-1
 	[trixie] - ruby-loofah <no-dsa> (Minor issue)
+	[bookworm] - ruby-loofah <postponed> (Minor issue)
 	NOTE: https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf
 	NOTE: https://github.com/flavorjones/loofah/pull/308
 	NOTE: Fixed by: https://github.com/flavorjones/loofah/commit/20867b9be689521887364b74822c41ef830523c9 (v2.25.2)
@@ -27307,6 +27444,7 @@ CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks authoriz
 CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due to a flaw ...)
 	- rsyslog 8.2608.0-1 (bug #1144616)
 	[trixie] - rsyslog <no-dsa> (Minor issue)
+	[bookworm] - rsyslog <postponed> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/5
 	NOTE: https://github.com/rsyslog/rsyslog/pull/7410
 	NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
@@ -27623,6 +27761,7 @@ CVE-2026-73296 (Microsoft UFO open-source framework for intelligent automation a
 CVE-2026-73295 (Material for MkDocs is a powerful documentation framework built on top ...)
 	- mkdocs-material <unfixed> (bug #1144348)
 	[trixie] - mkdocs-material <no-dsa> (Minor issue)
+	[bookworm] - mkdocs-material <postponed> (Minor issue)
 	NOTE: https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
 	NOTE: Fixed by: https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25 (9.7.7)
 CVE-2026-73294 (Semaphore UI is a web interface for managing DevOps tools. Prior to 2. ...)
@@ -28017,6 +28156,7 @@ CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access con
 CVE-2026-77648 (In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=imp ...)
 	- glance 2:32.0.0-3 (bug #1144212)
 	[trixie] - glance <no-dsa> (Minor issue)
+	[bookworm] - glance <postponed> (Minor issue)
 	NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0105
 	NOTE: https://bugs.launchpad.net/glance/+bug/2152110
 CVE-2026-12061
@@ -28094,12 +28234,14 @@ CVE-2026-52059 [RSA-PSS CertificateVerify checks only 0xbc trailer]
 CVE-2026-19566 (Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion a ...)
 	- libnet-cidr-set-perl 0.23-1
 	[trixie] - libnet-cidr-set-perl <no-dsa> (Minor issue)
+	[bookworm] - libnet-cidr-set-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42620063/
 	NOTE: https://github.com/robrwo/perl-Net-CIDR-Set/security/advisories/GHSA-grjr-r4x5-mx4p
 	NOTE: Fixed by: https://github.com/robrwo/perl-Net-CIDR-Set/commit/e16b27db676fd1ca671fbb31208a22c1b1ba9724 (0.23)
 CVE-2026-9318 (tablib prior to 3.10.0 contains a stored cross-site scripting vulnerab ...)
 	- python-tablib 3.10.0-1
 	[trixie] - python-tablib <no-dsa> (Minor issue)
+	[bookworm] - python-tablib <postponed> (Minor issue)
 	NOTE: https://github.com/jazzband/tablib/pull/668
 	NOTE: Fixed by: https://github.com/jazzband/tablib/commit/b0ff39fb9b2f457e5332249b4cc2ec11eabf46ee (v3.10.0)
 CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
@@ -28107,11 +28249,13 @@ CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior to
 CVE-2026-73249 (calibre is an e-book manager. Prior to 9.12.0, the calibre Content Ser ...)
 	- calibre 9.12.0+ds+~0.10.6-1
 	[trixie] - calibre <no-dsa> (Minor issue)
+	[bookworm] - calibre <postponed> (Minor issue)
 	NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-5x64-w63v-x2g6
 	NOTE: Fixed by: https://github.com/kovidgoyal/calibre/commit/71295e8b62801e1ccecaa4fac47e6942f11cfe1e (v9.12.0)
 CVE-2026-73248 (calibre is an e-book manager. Prior to 9.12.0, calibre processes attac ...)
 	- calibre 9.12.0+ds+~0.10.6-1
 	[trixie] - calibre <no-dsa> (Minor issue)
+	[bookworm] - calibre <postponed> (Minor issue)
 	NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx
 	NOTE: Fixed by: https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8 (v9.12.0)
 CVE-2026-73247 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
@@ -28170,6 +28314,7 @@ CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security t
 CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building  ...)
 	- djangorestframework <unfixed> (bug #1144350)
 	[trixie] - djangorestframework <no-dsa> (Minor issue)
+	[bookworm] - djangorestframework <postponed> (Minor issue)
 	NOTE: https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
 	NOTE: https://github.com/encode/django-rest-framework/pull/10012
 	NOTE: Fixed by: https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e (3.17.2)
@@ -28265,6 +28410,7 @@ CVE-2026-48813 (Flawfinder is a a static analysis tool for finding vulnerabiliti
 CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO realtime c ...)
 	- python-engineio <unfixed> (bug #1144515)
 	[trixie] - python-engineio <no-dsa> (Minor issue)
+	[bookworm] - python-engineio <postponed> (Minor issue)
 	NOTE: https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
 	NOTE: Fixed by: https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e (v5.16.4)
 CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
@@ -28287,11 +28433,13 @@ CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API (`snowfl
 CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Open Sour ...)
 	- rlottie <unfixed> (bug #1144473)
 	[trixie] - rlottie <no-dsa> (Minor issue)
+	[bookworm] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/600
 	NOTE: https://github.com/Samsung/rlottie/commit/27f2f23ece8a98f3e0a870e2c125faaac37e8904
 CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung Open Source ...)
 	- rlottie <unfixed> (bug #1144472)
 	[trixie] - rlottie <no-dsa> (Minor issue)
+	[bookworm] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/599
 	NOTE: https://github.com/Samsung/rlottie/commit/34465a9e93c38af9a5287ad28400bb932c1a2a92
 CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure direc ...)
@@ -28419,18 +28567,21 @@ CVE-2026-19496
 CVE-2026-73283 (In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_ke ...)
 	- openssh 1:10.5p1-1 (bug #1144192)
 	[trixie] - openssh <no-dsa> (Minor issue)
+	[bookworm] - openssh <postponed> (Minor issue)
 	- openssh-gssapi 1:10.5p1-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
 CVE-2026-73282 (In ssh in OpenSSH before 10.5, a use-after-free for realloc data can o ...)
 	- openssh 1:10.5p1-1 (bug #1144192)
 	[trixie] - openssh <no-dsa> (Minor issue)
+	[bookworm] - openssh <postponed> (Minor issue)
 	- openssh-gssapi 1:10.5p1-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
 CVE-2026-73281 (In ssh-agent in OpenSSH before 10.5, some operations can occur remotel ...)
 	- openssh 1:10.5p1-1 (bug #1144192)
 	[trixie] - openssh <no-dsa> (Minor issue)
+	[bookworm] - openssh <postponed> (Minor issue)
 	- openssh-gssapi 1:10.5p1-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
@@ -28577,6 +28728,7 @@ CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR R7000
 CVE-2026-73228 (Django REST framework is a toolkit for building Web APIs. Prior to 3.1 ...)
 	- djangorestframework <unfixed> (bug #1144350)
 	[trixie] - djangorestframework <no-dsa> (Minor issue)
+	[bookworm] - djangorestframework <postponed> (Minor issue)
 	NOTE: https://github.com/encode/django-rest-framework/security/advisories/GHSA-2m8g-3cmr-wg3w
 	NOTE: https://github.com/encode/django-rest-framework/pull/10013
 	NOTE: Fixed by: https://github.com/encode/django-rest-framework/commit/2912dc98042f78e27636551fc22eeaf10f725fdd (3.17.2)
@@ -28653,11 +28805,13 @@ CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform. P
 CVE-2026-73089 (Browserslist is a configuration tool for sharing target browsers and N ...)
 	- node-browserslist 4.28.7+~cs8.16.65-1
 	[trixie] - node-browserslist <no-dsa> (Minor issue)
+	[bookworm] - node-browserslist <postponed> (Minor issue)
 	NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx
 	NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f2931a3ff2a3a31abf84ef01a7400b270aad6405 (4.28.7)
 CVE-2026-73088 (Browserslist is a configuration tool for sharing target browsers and N ...)
 	- node-browserslist 4.28.7+~cs8.16.65-1
 	[trixie] - node-browserslist <no-dsa> (Minor issue)
+	[bookworm] - node-browserslist <postponed> (Minor issue)
 	NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g
 	NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51 (4.28.7)
 CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From 10.5.2 unt ...)
@@ -28665,6 +28819,7 @@ CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From 10.5
 CVE-2026-73086 (nanoid is a secure, URL-friendly, unique string ID generator for JavaS ...)
 	- node-postcss 8.5.14+~cs9.3.34-1
 	[trixie] - node-postcss <no-dsa> (Minor issue)
+	[bookworm] - node-postcss <postponed> (Minor issue)
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
 	NOTE: node-postcss bundles nanoid
 	NOTE: node-mocha/9.1.4+ds1+~cs28.2.8-1 removes the node-nanoid copy
@@ -28730,6 +28885,7 @@ CVE-2026-73068 (ToolJet is the open-source foundation am AI-native platform for
 CVE-2026-73067 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
 	- tesseract <unfixed> (bug #1144388)
 	[trixie] - tesseract <no-dsa> (Minor issue)
+	[bookworm] - tesseract <postponed> (Minor issue)
 	NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h
 	NOTE: https://github.com/tesseract-ocr/tesseract/pull/4581
 	NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/55287a94b8044c05ce3fd10f5aca6ebbd238e518 (5.5.3)
@@ -28737,6 +28893,7 @@ CVE-2026-73067 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafte
 CVE-2026-73066 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
 	- tesseract <unfixed> (bug #1144388)
 	[trixie] - tesseract <no-dsa> (Minor issue)
+	[bookworm] - tesseract <postponed> (Minor issue)
 	NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7j76-5rq5-5jg8
 	NOTE: https://github.com/tesseract-ocr/tesseract/pull/4588
 	NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/2f4d2f4bf45c363785d7bf1da29b6628f8939a72 (5.5.3)
@@ -28820,11 +28977,13 @@ CVE-2026-72712 (Nmap versions up to and including 7.99 contains a denial of serv
 CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a root us ...)
 	- mrtg 2.17.10-15 (bug #1144393)
 	[trixie] - mrtg <no-dsa> (Minor issue)
+	[bookworm] - mrtg <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460973
 	NOTE: Fixed by: https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269
 CVE-2026-72693 (`openvt -u` is intended to identify the owner of the current VT and th ...)
 	- kbd <unfixed> (bug #1144392)
 	[trixie] - kbd <no-dsa> (Minor issue)
+	[bookworm] - kbd <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462115
 	NOTE: Fixed by: https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698 (v2.10.0)
 CVE-2026-72610 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
@@ -29832,11 +29991,13 @@ CVE-2026-49179 (Improper neutralization of special elements used in a command ('
 CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
 	- python-engineio <unfixed> (bug #1144516)
 	[trixie] - python-engineio <no-dsa> (Minor issue)
+	[bookworm] - python-engineio <postponed> (Minor issue)
 	NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9
 	TODO: checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue
 CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
 	- python-engineio <unfixed> (bug #1144517)
 	[trixie] - python-engineio <no-dsa> (Minor issue)
+	[bookworm] - python-engineio <postponed> (Minor issue)
 	NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5
 CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the open-source datab ...)
 	NOT-FOR-US: Turso CLI
@@ -30330,46 +30491,55 @@ CVE-2016-20097 (Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerabil
 CVE-2026-20707 (Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html
 CVE-2026-20901 (Improper input validation for some Intel(R) Xeon(R) processors within  ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html
 CVE-2026-20713 (Always-incorrect control flow implementation in some firmware for some ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html
 CVE-2026-20760 (Improper handling of overlap between protected memory ranges in some m ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html
 CVE-2026-20716 (Improper access control for some Intel(R) Processors within Ring 3: Us ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html
 CVE-2025-35973 (Improper handling of values for some Intel(R) Processors within Ring 0 ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.cve.org/CVERecord?id=CVE-2025-35973
 CVE-2026-20917 (Exposure of sensitive information caused by incorrect data forwarding  ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html
 CVE-2025-31938 (Insufficient granularity of access control in some subsystem for some  ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html
 CVE-2025-31936 (Improper handling of overlap between protected memory ranges for some  ...)
 	- intel-microcode <unfixed> (bug #1144158)
 	[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
+	[bookworm] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html
 CVE-2026-71194 (In OpenStack Designate before 22.0.2, the mDNS handler performs pool-b ...)
@@ -30520,42 +30690,52 @@ CVE-2026-73144 [GHSA-qccg-7pw6-787v: FRN module: unbounded memory growth]
 CVE-2026-73145 [GHSA-58ph-q79f-7x9x: HTTP server: unbounded request accumulation]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-58ph-q79f-7x9x
 CVE-2026-73146 [GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-r2gm-p682-3mpm
 CVE-2026-73147 [GHSA-pc2g-2p95-4cr5: TCL command injection in reflector client]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-pc2g-2p95-4cr5
 CVE-2026-73148 [GHSA-6wgq-wg3w-jgvx: svxreflector: use-after-free write via dangling JSON reference]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-6wgq-wg3w-jgvx
 CVE-2026-73149 [GHSA-mh75-5pr3-qv2p: NetRx: out-of-bounds read via unvalidated MsgAudio length]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-mh75-5pr3-qv2p
 CVE-2026-73150 [GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-4f8x-49pf-3x5v
 CVE-2026-73151 [GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-x5r8-rq62-q9cj
 CVE-2026-73152 [GHSA-4g8q-rgxf-fmgf: EchoLink proxy: integer truncation in message length]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-4g8q-rgxf-fmgf
 CVE-2026-73153 [GHSA-624p-cp8x-6hp6: EchoLink RTCP/SDES: out-of-bounds read]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-624p-cp8x-6hp6
 CVE-2026-73154 [GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5g48-xjmf-7p4q
 CVE-2026-XXXX [GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems]
 	- ostree 2026.3-1 (bug #1144106)
@@ -30577,6 +30757,7 @@ CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 contains
 CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a path trave ...)
 	- unearth 0.18.3-1 (bug #1144401)
 	[trixie] - unearth <no-dsa> (Minor issue)
+	[bookworm] - unearth <postponed> (Minor issue)
 	NOTE: https://github.com/frostming/unearth/issues/180
 	NOTE: https://github.com/frostming/unearth/pull/181
 	NOTE: Fixed by: https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3c8ba (0.18.3)
@@ -30702,6 +30883,7 @@ CVE-2026-66760 (SAP Approuter does not correctly validate client certificates in
 CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a process  ...)
 	- libvirt 12.6.0-1
 	[trixie] - libvirt <no-dsa> (Minor issue)
+	[bookworm] - libvirt <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513065
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b (v12.6.0-rc2)
 CVE-2026-5304 (An ACAP configuration file lacks input validation, which could potenti ...)
@@ -30761,11 +30943,13 @@ CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated as
 CVE-2026-19518 (Improper Validation of Specified Quantity in Input vulnerability in Sa ...)
 	- rlottie <unfixed> (bug #1144646)
 	[trixie] - rlottie <no-dsa> (Minor issue)
+	[bookworm] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/596
 	NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578
 CVE-2026-19517 (Improper Validation of Specified Quantity in Input and Allocation of R ...)
 	- rlottie <unfixed> (bug #1144646)
 	[trixie] - rlottie <no-dsa> (Minor issue)
+	[bookworm] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/596
 	NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578
 CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the destinatio ...)
@@ -31094,6 +31278,7 @@ CVE-2026-6373 (Exposure of sensitive system information to an unauthorized contr
 CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to v ...)
 	- glibc 2.43-4 (bug #1144252)
 	[trixie] - glibc <no-dsa> (Minor issue)
+	[bookworm] - glibc <postponed> (Minor issue)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34090
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
@@ -31170,6 +31355,7 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory
 CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or convert op ...)
 	- libvirt 12.6.0-1
 	[trixie] - libvirt <no-dsa> (Minor issue)
+	[bookworm] - libvirt <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513066
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/69335a484768d550854da1133d5490074695e825 (v12.6.0-rc2)
 CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection  ...)
@@ -31401,6 +31587,7 @@ CVE-2026-18503 (Attacker-controlled CSV samples can trigger super-linear  regula
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
 	- pypy3 <unfixed>
 	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[bookworm] - pypy3 <postponed> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/
 	NOTE: https://github.com/python/cpython/issues/98820
 	NOTE: https://github.com/python/cpython/pull/153694
@@ -31422,6 +31609,7 @@ CVE-2026-18370 (entr is vulnerable to Heap-based buffer overflow in run_utility(
 CVE-2026-16742 (systemd-homed contains a local privilege escalation bug via arbitrary  ...)
 	- systemd 261.2-1
 	[trixie] - systemd <no-dsa> (Minor issue)
+	[bookworm] - systemd <postponed> (Minor issue)
 	NOTE: https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/d392d17143423e7af0cdb5bd0f64b43da8952662 (v261.2)
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/a7bce5b2052bdb098ad0729768c72e1df9a86adc (v261.2)
@@ -31439,6 +31627,7 @@ CVE-2026-15060 (When systemd-machined >= v259 (or v258 with a custom `polkit` po
 CVE-2026-15059 (Local unprivileged users can terminate arbitrary local processes via a ...)
 	- systemd 261~rc3-1
 	[trixie] - systemd <no-dsa> (Minor issue)
+	[bookworm] - systemd <postponed> (Minor issue)
 	NOTE: https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/cde88c4ea364e816619f385a870d074ebc12fe0f (v261-rc3)
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/a8feb2f23565d39df5c90a753c851c1934a53117 (v258.9)
@@ -31503,6 +31692,7 @@ CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, impro
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
 	- glibc 2.43-3
 	[trixie] - glibc <no-dsa> (Minor issue)
+	[bookworm] - glibc <postponed> (Minor issue)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34091
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0013
 CVE-2026-68424 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
@@ -33433,6 +33623,7 @@ CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant in
 CVE-2026-19389 (Multiple integer overflow and underflow vulnerabilities were found in  ...)
 	- gst-plugins-ugly1.0 1.28.6-1
 	[trixie] - gst-plugins-ugly1.0 <no-dsa> (Minor issue)
+	[bookworm] - gst-plugins-ugly1.0 <postponed> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12233
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12243
 	NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a598edfef83878f714ea53925ae802f49c3b31a6 (1.28.6)
@@ -33847,6 +34038,7 @@ CVE-2026-65819 (gopacket provides packet processing capabilities for Go. Through
 	[trixie] - golang-github-gopacket-gopacket <no-dsa> (Minor issue)
 	- gopacket <unfixed>
 	[trixie] - gopacket <no-dsa> (Minor issue)
+	[bookworm] - gopacket <postponed> (Minor issue)
 	NOTE: https://github.com/gopacket/gopacket/security/advisories/GHSA-8mcr-459q-5mx2
 	NOTE: Fixed by: https://github.com/gopacket/gopacket/commit/210f25fb9b3ca1af2eb649936f78ad6991b6c9c5 (v1.7.1)
 CVE-2026-64676 (Kata Containers is an open source implementation of lightweight Virtua ...)
@@ -33886,6 +34078,7 @@ CVE-2026-48122 (Ruby LSP is an implementation of the language server protocol fo
 CVE-2026-48120 (Kakoune is a code editor. Prior to version 2026.05.21, the bundled, en ...)
 	- kakoune 2026.05.21-1 (bug #1143968)
 	[trixie] - kakoune <no-dsa> (Minor issue)
+	[bookworm] - kakoune <postponed> (Minor issue)
 	NOTE: https://github.com/mawww/kakoune/security/advisories/GHSA-h99r-h8cp-vwcq
 	NOTE: Fixed by: https://github.com/mawww/kakoune/commit/25c7b13b244fd1ddacc63ecfe1784b5ebc2ba825 (v2026.05.21)
 CVE-2026-48047 (XWiki Platform WebJars API is a package for XWiki, a generic wiki plat ...)
@@ -34011,6 +34204,7 @@ CVE-2026-9169 (DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.
 CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
 	- pypdf <unfixed> (bug #1143902)
 	[trixie] - pypdf <no-dsa> (Minor issue)
+	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
 	NOTE: https://github.com/py-pdf/pypdf/pull/3944
@@ -34018,6 +34212,7 @@ CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior t
 CVE-2026-71852 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
 	- pypdf <unfixed> (bug #1143902)
 	[trixie] - pypdf <no-dsa> (Minor issue)
+	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42
 	NOTE: https://github.com/py-pdf/pypdf/pull/3946
@@ -34036,6 +34231,7 @@ CVE-2026-71848 (Hono is a Web application framework that provides support for an
 CVE-2026-71847 (Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, ...)
 	- ruby-json 2.21.2+dfsg-1 (bug #1143948)
 	[trixie] - ruby-json <no-dsa> (Minor issue)
+	[bookworm] - ruby-json <postponed> (Minor issue)
 	NOTE: https://github.com/ruby/json/security/advisories/GHSA-9hj4-r449-hfvc
 	NOTE: Fixed by: https://github.com/ruby/json/commit/2c332bfe2bfb0e754da07e2a0310ef106bf46482 (v2.21.2)
 CVE-2026-71560 (Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.   ...)
@@ -34101,8 +34297,10 @@ CVE-2026-62996 (Smarty is a template engine for PHP, facilitating the separation
 CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
 	- smarty4 <unfixed> (bug #1145020)
 	[trixie] - smarty4 <no-dsa> (Minor issue)
+	[bookworm] - smarty4 <postponed> (Minor issue)
 	- smarty3 <unfixed>
 	[trixie] - smarty3 <no-dsa> (Minor issue)
+	[bookworm] - smarty3 <postponed> (Minor issue)
 	NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-f6wf-28g6-769x
 	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/99c048ce7a590c519b79fbd38ad0143a08183a1f (v5.8.2)
 	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/a1ccdb0518021a559b4066c37b76a42c86bbce90 (v4.5.7)
@@ -34229,12 +34427,14 @@ CVE-2026-19206 (A security flaw has been discovered in MZ Automation libiec61850
 CVE-2026-19082 (Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent ...)
 	- libimager-perl 1.034+dfsg-1
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
+	[bookworm] - libimager-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42492379/
 	NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-hx46-55wp-hv6m
 	NOTE: Fixed by: https://github.com/tonycoz/imager/commit/24bde0427a113264d53f45a9c29ae756d84c82fe (v1.034)
 CVE-2026-19079 (A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was  ...)
 	- policycoreutils <unfixed> (bug #1143965)
 	[trixie] - policycoreutils <no-dsa> (Minor issue)
+	[bookworm] - policycoreutils <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679
 CVE-2026-18497 (A heap-buffer-overflow vulnerability exists in the nothings stb TrueTy ...)
 	- libstb <unfixed> (unimportant)
@@ -34328,6 +34528,7 @@ CVE-2026-71555 (PILOS (Platform for Interactive Live-Online Seminars) is a front
 CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...)
 	- python-h2 <unfixed> (bug #1143905)
 	[trixie] - python-h2 <no-dsa> (Minor issue)
+	[bookworm] - python-h2 <postponed> (Minor issue)
 	NOTE: https://github.com/python-hyper/h2/security/advisories/GHSA-6hr6-w5qg-qmwg
 	NOTE: Fixed by: https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6 (4.4.1)
 CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting vulnerability cau ...)
@@ -34341,6 +34542,7 @@ CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. P
 CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1.14.3  ...)
 	- jsoup <unfixed> (bug #1143906)
 	[trixie] - jsoup <no-dsa> (Minor issue)
+	[bookworm] - jsoup <postponed> (Minor issue)
 	[bullseye] - jsoup <not-affected> (Vulnerable code introduced in 1.14.3)
 	NOTE: https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8
 	NOTE: https://github.com/jhy/jsoup/issues/2538
@@ -34349,6 +34551,7 @@ CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1
 CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
 	- php-league-commonmark 2.9.0-1
 	[trixie] - php-league-commonmark <no-dsa> (Minor issue)
+	[bookworm] - php-league-commonmark <postponed> (Minor issue)
 	NOTE: https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv
 	NOTE: Fixed by: https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8 (2.9.0)
 	NOTE: Fixed by: https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb (2.9.0)
@@ -34356,6 +34559,7 @@ CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering Com
 CVE-2026-71478 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
 	- php-league-commonmark 2.9.0-1
 	[trixie] - php-league-commonmark <no-dsa> (Minor issue)
+	[bookworm] - php-league-commonmark <postponed> (Minor issue)
 	NOTE: https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc
 	NOTE: Fixed by: https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c (2.9.0)
 CVE-2026-71476 (Nx is a monorepo solution for TypeScript and polyglot codebases. From  ...)
@@ -34501,6 +34705,7 @@ CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and detects violations of a
 CVE-2026-67422 (pymdown-extensions is a collection of extensions for the Python Markdo ...)
 	- pymdown-extensions 11.0.1-1
 	[trixie] - pymdown-extensions <no-dsa> (Minor issue)
+	[bookworm] - pymdown-extensions <postponed> (Minor issue)
 	NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-gm37-52c6-37mw
 	NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/c68498598d7b13011bb4571350b6e3612a4ce44b (11.0.1)
 CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows an auth ...)
@@ -34561,6 +34766,7 @@ CVE-2026-62830 (Missing authorization in Azure SRE Agent allows an authorized at
 CVE-2026-61632 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
 	- pymdown-extensions 11.0.1-1
 	[trixie] - pymdown-extensions <no-dsa> (Minor issue)
+	[bookworm] - pymdown-extensions <postponed> (Minor issue)
 	NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-9xwg-3r6f-jcx2
 CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt ...)
 	NOT-FOR-US: Contiki-NG
@@ -34863,6 +35069,7 @@ CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows authe
 CVE-2026-18938 (A flaw was found in p11-kit. A local attacker, or one with equivalent  ...)
 	- p11-kit 0.26.5-1 (bug #1144476)
 	[trixie] - p11-kit <no-dsa> (Minor issue)
+	[bookworm] - p11-kit <postponed> (Minor issue)
 	NOTE: https://github.com/p11-glue/p11-kit/pull/777
 	NOTE: Fixed by: https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc (0.26.5)
 CVE-2026-64638 (WordPress is vulnerable to a pre-auth reflected XSS vulnerability on t ...)
@@ -35037,10 +35244,12 @@ CVE-2026-19177 (Insufficient validation of untrusted input in UI in Google Chrom
 CVE-2026-61478
 	- libvirt 12.6.0-1
 	[trixie] - libvirt <no-dsa> (Minor issue)
+	[bookworm] - libvirt <postponed> (Minor issue)
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/68da70aae766c6271b8d3b466374d3cc7d1a8afb (v12.6.0-rc1)
 CVE-2026-61477 (An injection vulnerability was found in libvirt's virtual network driv ...)
 	- libvirt 12.6.0-1
 	[trixie] - libvirt <no-dsa> (Minor issue)
+	[bookworm] - libvirt <postponed> (Minor issue)
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/d44836a1dc6771ac22f69755fc69bf730f0eec87 (v12.6.0-rc1)
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/289ffa796d737a79a4c05d07232ebd75def9a12a (v12.6.0-rc1)
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/cb8974b923e3c40cde96f0c7bceaa638f7f9c72b (v12.6.0-rc1)
@@ -35791,6 +36000,7 @@ CVE-2026-18909 (A stack-based buffer overflow vulnerability exists in ELAN Micro
 CVE-2026-18839 (An integer underflow was found in the popt library when formatting hel ...)
 	- popt <unfixed>
 	[trixie] - popt <no-dsa> (Minor issue)
+	[bookworm] - popt <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511010
 CVE-2026-18510 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
 	NOT-FOR-US: WordPress plugin
@@ -36095,14 +36305,17 @@ CVE-2026-71231 (IOTSmartHome's gui/login.php checkCookie function builds an auth
 CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence an applic ...)
 	- libkcapi <unfixed> (bug #1143974)
 	[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462867
 CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one ...)
 	- libkcapi <unfixed> (bug #1143974)
 	[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462114
 CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot symmetric ciphe ...)
 	- libkcapi <unfixed> (bug #1143974)
 	[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
 CVE-2026-71215 (art-template's sub-template resolution logic (src/compile/adapter/reso ...)
 	NOT-FOR-US: art-template
@@ -36810,6 +37023,7 @@ CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is vulnerable
 CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with network access ...)
 	- isc-dhcp <removed>
 	[trixie] - isc-dhcp <ignored> (ISC DHCP not covered by security support in Trixie)
+	[bookworm] - isc-dhcp <postponed> (ISC DHCP not covered by security support in Trixie)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2508081
 CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPr ...)
 	NOT-FOR-US: WordPress plugin
@@ -37037,14 +37251,17 @@ CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js
 CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up to and  ...)
 	- pdm 2.27.0-1
 	[trixie] - pdm <no-dsa> (Minor issue)
+	[bookworm] - pdm <postponed> (Minor issue)
 	NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf
 CVE-2026-47764 (pdm is a Python package and dependency manager supporting the latest P ...)
 	- pdm 2.27.0-1
 	[trixie] - pdm <no-dsa> (Minor issue)
+	[bookworm] - pdm <postponed> (Minor issue)
 	NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-78v8-vpjp-cjqh
 CVE-2026-47763 (pdm is a Python package and dependency manager supporting the latest P ...)
 	- pdm 2.27.0-1
 	[trixie] - pdm <no-dsa> (Minor issue)
+	[bookworm] - pdm <postponed> (Minor issue)
 	NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm
 CVE-2026-47623 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
 	NOT-FOR-US: NVIDIA
@@ -37132,6 +37349,7 @@ CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up to
 CVE-2026-18772 (Improperly controlled sequential memory allocation vulnerability in Sa ...)
 	- rlottie <unfixed> (bug #1143931)
 	[trixie] - rlottie <no-dsa> (Minor issue)
+	[bookworm] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/596
 CVE-2026-18770 (A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d5 ...)
 	NOT-FOR-US: vibesurf-ai VibeSurf
@@ -37252,6 +37470,7 @@ CVE-2026-69246 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0
 	[experimental] - guzzle 8.0.1-1
 	- guzzle 7.15.2-1 (bug #1143595)
 	[trixie] - guzzle <no-dsa> (Minor issue)
+	[bookworm] - guzzle <postponed> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
@@ -37259,6 +37478,7 @@ CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0
 	[experimental] - guzzle 8.0.1-1
 	- guzzle 7.15.2-1 (bug #1143595)
 	[trixie] - guzzle <no-dsa> (Minor issue)
+	[bookworm] - guzzle <postponed> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
@@ -37463,6 +37683,7 @@ CVE-2026-41447 (FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vu
 CVE-2026-18739 (A flaw was found in popt, a command-line option parsing library. An of ...)
 	- popt <unfixed>
 	[trixie] - popt <no-dsa> (Minor issue)
+	[bookworm] - popt <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2510737
 CVE-2026-18738 (Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vu ...)
 	NOT-FOR-US: Shlink
@@ -37581,6 +37802,7 @@ CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive authenticatio
 CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
 	- node-postcss 8.5.23+~cs10.2.23-1
 	[trixie] - node-postcss <no-dsa> (Minor issue)
+	[bookworm] - node-postcss <postponed> (Minor issue)
 	NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
 	NOTE: Fixed by: https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 (8.5.23)
 CVE-2026-69152 (The brace-expansion library generates arbitrary strings containing a c ...)
@@ -37780,10 +38002,12 @@ CVE-2026-18574 (An authentication bypass vulnerability in Check Point Security M
 CVE-2026-18508 (A flaw was found in GNU tar. When extracting an archive with the --one ...)
 	- tar <unfixed> (bug #1143836)
 	[trixie] - tar <no-dsa> (Minor issue)
+	[bookworm] - tar <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509843
 CVE-2026-18477 (A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's increm ...)
 	- tar <unfixed> (bug #1143836)
 	[trixie] - tar <no-dsa> (Minor issue)
+	[bookworm] - tar <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509735
 CVE-2026-18248 (@fastify/aws-lambda version 6.4.0 decorates each Fastify request with  ...)
 	NOT-FOR-US: fastify/aws-lambda
@@ -38230,14 +38454,17 @@ CVE-2026-6453 (The CubeWP Framework plugin for WordPress is vulnerable to SQL In
 CVE-2026-67355 (guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...)
 	- guzzle 7.15.1-1
 	[trixie] - guzzle <no-dsa> (Minor issue)
+	[bookworm] - guzzle <postponed> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577
 CVE-2026-67354 (guzzlehttp/guzzle versions before 7.15.1 contain an information disclo ...)
 	- guzzle 7.15.1-1
 	[trixie] - guzzle <no-dsa> (Minor issue)
+	[bookworm] - guzzle <postponed> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8
 CVE-2026-67353 (guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...)
 	- guzzle 7.15.1-1
 	[trixie] - guzzle <no-dsa> (Minor issue)
+	[bookworm] - guzzle <postponed> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79
 CVE-2026-67352 (luci-app-https-dns-proxy contains a stored cross-site scripting vulner ...)
 	NOT-FOR-US: luci-app-https-dns-proxy
@@ -38254,6 +38481,7 @@ CVE-2026-67340 (ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts
 CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...)
 	- guzzle 7.14.2-1
 	[trixie] - guzzle <no-dsa> (Minor issue)
+	[bookworm] - guzzle <postponed> (Minor issue)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
 	- jupyterlab 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4 (bug #1144343)
@@ -38302,6 +38530,7 @@ CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable ex
 CVE-2026-67321 (axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...)
 	- node-axios 1.18.0-1
 	[trixie] - node-axios <no-dsa> (Minor issue)
+	[bookworm] - node-axios <postponed> (Minor issue)
 	NOTE: https://github.com/axios/axios/security/advisories/GHSA-hcpx-6fm6-wx23
 CVE-2026-67320 (axios in a Node.js deployment using the HTTP adapter can route request ...)
 	- node-axios 1.18.0-1
@@ -38312,6 +38541,7 @@ CVE-2026-67320 (axios in a Node.js deployment using the HTTP adapter can route r
 CVE-2026-67319 (axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited prop ...)
 	- node-axios 1.18.0-1
 	[trixie] - node-axios <no-dsa> (Minor issue)
+	[bookworm] - node-axios <postponed> (Minor issue)
 	NOTE: https://github.com/axios/axios/security/advisories/GHSA-7q8q-rj6j-mhjq
 CVE-2026-67318 (axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the con ...)
 	- node-axios 1.18.0-1
@@ -38322,10 +38552,12 @@ CVE-2026-67318 (axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce t
 CVE-2026-67317 (axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for W ...)
 	- node-axios 1.18.0-1
 	[trixie] - node-axios <no-dsa> (Minor issue)
+	[bookworm] - node-axios <postponed> (Minor issue)
 	NOTE: https://github.com/axios/axios/security/advisories/GHSA-jqh4-m9w3-8hp9
 CVE-2026-67316 (axios is vulnerable to read-side prototype-pollution gadgets that can  ...)
 	- node-axios 1.18.0-1
 	[trixie] - node-axios <no-dsa> (Minor issue)
+	[bookworm] - node-axios <postponed> (Minor issue)
 	NOTE: https://github.com/axios/axios/security/advisories/GHSA-mmx7-hfxf-jppx
 CVE-2026-67315 (axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to r ...)
 	- node-axios 1.18.0-1
@@ -38342,10 +38574,12 @@ CVE-2026-67314 (axios versions >=1.15.2 and <1.18.0 contain prototype-pollution
 CVE-2026-67313 (axios versions 0.28.0 and later contain uncontrolled recursion in form ...)
 	- node-axios 1.18.0-1
 	[trixie] - node-axios <no-dsa> (Minor issue)
+	[bookworm] - node-axios <postponed> (Minor issue)
 	NOTE: https://github.com/axios/axios/security/advisories/GHSA-42h9-826w-cgv3
 CVE-2026-67312 (axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0  ...)
 	- node-axios 1.18.0-1
 	[trixie] - node-axios <no-dsa> (Minor issue)
+	[bookworm] - node-axios <postponed> (Minor issue)
 	NOTE: https://github.com/axios/axios/security/advisories/GHSA-pmv8-rq9r-6j72
 CVE-2026-67311 (Budibase before 3.38.1 contains a server-side request forgery vulnerab ...)
 	NOT-FOR-US: Budibase
@@ -41467,6 +41701,7 @@ CVE-2026-17650 (Use after free in Compositing in Google Chrome prior to 151.0.79
 CVE-2026-16728 (undici's retry interceptor can deliver a response whose body length do ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
 CVE-2026-16727 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
 	NOT-FOR-US: ASUS
@@ -41531,6 +41766,7 @@ CVE-2026-15235 (The MotoPress Hotel Booking WordPress plugin before 6.0.4 does n
 CVE-2026-15157 (undici does not validate the type property of a duck-typed blob-like r ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
 CVE-2026-15153 (The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise a ...)
 	NOT-FOR-US: WordPress plugin
@@ -41543,6 +41779,7 @@ CVE-2026-14923 (The Sync Post With Other Site WordPress plugin before 1.9.3 does
 CVE-2026-14643 (undici's cache interceptor mishandles optional whitespace placed aroun ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54
 CVE-2026-14602 (The Remote API WordPress plugin through 0.2 does not authenticate a re ...)
 	NOT-FOR-US: WordPress plugin
@@ -41688,6 +41925,7 @@ CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion lea
 CVE-2026-67214 (nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in ...)
 	- node-postcss 8.5.15+~cs9.3.39-1
 	[trixie] - node-postcss <no-dsa> (Minor issue)
+	[bookworm] - node-postcss <postponed> (Minor issue)
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
 	[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
 	NOTE: node-postcss bundles nanoid
@@ -41696,6 +41934,7 @@ CVE-2026-67214 (nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite l
 CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...)
 	- node-postcss 8.5.8+~cs9.3.30-1
 	[trixie] - node-postcss <no-dsa> (Minor issue)
+	[bookworm] - node-postcss <postponed> (Minor issue)
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
 	[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
 	NOTE: node-postcss bundles nanoid
@@ -41957,6 +42196,7 @@ CVE-2026-54078 (veraPDF validation model is an implementation of the veraPDF val
 CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for rootless  ...)
 	- fuse-overlayfs <unfixed> (bug #1143058)
 	[trixie] - fuse-overlayfs <no-dsa> (Minor issue)
+	[bookworm] - fuse-overlayfs <postponed> (Minor issue)
 	NOTE: https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
 	NOTE: Fixed by: https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f (v1.17)
 CVE-2026-51992
@@ -42037,6 +42277,7 @@ CVE-2026-16751 (Authorization Bypass in the emergency recovery approval componen
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143063)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
 	NOT-FOR-US: WordPress plugin
@@ -42071,6 +42312,7 @@ CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Devela
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
 	- node-undici 8.9.0+dfsg+~cs3.2.0-1 (bug #1143070)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
 	NOT-FOR-US: WordPress plugin
@@ -42687,6 +42929,7 @@ CVE-2026-21047 (Out-of-bounds write in ImsService prior to SMR Jul-2026 Release
 CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences (rseq) du ...)
 	- criu 4.2-5
 	[trixie] - criu <no-dsa> (Minor issue)
+	[bookworm] - criu <postponed> (Minor issue)
 	NOTE: https://github.com/checkpoint-restore/criu/pull/3097
 	NOTE: https://github.com/checkpoint-restore/criu/security/advisories/GHSA-fvqj-jvxf-x3wp
 CVE-2026-18085 (An Improper Input Validation in the BlackBerry UEMManagementConsoleofB ...)
@@ -43658,6 +43901,7 @@ CVE-2026-58662 (Improper Validation of Specified Quantity in Input, Out-of-bound
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d
 CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
 	[experimental] - thrift 0.24.0-1
@@ -43677,6 +43921,7 @@ CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib binding
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt
 CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary crafted ...)
 	NOT-FOR-US: proCertum SmartSign
@@ -43690,16 +43935,19 @@ CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bi
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed> (bug #1145700)
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx
 CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings.  This is ...)
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/8pbnw4dyxxc9opp6qq725jhrzg25v8q7
 CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...)
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo
 CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources Without Li ...)
 	[experimental] - thrift 0.24.0-1
@@ -43773,16 +44021,19 @@ CVE-2026-48586 (Improper Handling of Highly Compressed Data (Data Amplification)
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq
 CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/2popgc4ks1l87jjho1w5fpk5k4x06b7h
 CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj
 CVE-2026-48052 (Papra is a minimalistic document management and archiving platform. Pr ...)
 	NOT-FOR-US: Papra
@@ -43801,6 +44052,7 @@ CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib zip
 CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
 	- node-postcss 8.5.12+~cs9.3.32-1
 	[trixie] - node-postcss <no-dsa> (Minor issue)
+	[bookworm] - node-postcss <postponed> (Minor issue)
 	NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-6g55-p6wh-862q
 	NOTE: https://github.com/postcss/postcss/commit/aaec7b78b3ce2792585b4b300ef1bd5dd5b3e8ad (8.5.12)
 	NOTE: https://github.com/postcss/postcss/commit/c64b7488d2731dfa16213739b42c34faf5a9eba3 (8.5.12)
@@ -43810,11 +44062,13 @@ CVE-2026-45112 (Allocation of Resources Without Limits or Throttling vulnerabili
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/hl9kmf1z2o3lxvspoj3g9ykl8lj9mdxc
 CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
 	[experimental] - thrift 0.24.0-1
 	- thrift <unfixed>
 	[trixie] - thrift <no-dsa> (Minor issue)
+	[bookworm] - thrift <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
 CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erlang OT ...)
 	{DSA-6464-1}
@@ -43970,6 +44224,7 @@ CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp d006858/e15ef
 CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a ref ...)
 	- xmlrpc-c <unfixed> (bug #1143065)
 	[trixie] - xmlrpc-c <no-dsa> (Minor issue)
+	[bookworm] - xmlrpc-c <postponed> (Minor issue)
 	NOTE: https://www.themissinglink.com.au/security-advisories/cve-2026-15928
 	NOTE: https://sourceforge.net/p/xmlrpc-c/code/3342/
 CVE-2026-14827 (The Calendar WordPress plugin before 1.3.18 does not properly escape a ...)
@@ -46303,6 +46558,7 @@ CVE-2026-16743 (A flaw was found in accountsservice. The systemd-homed code path
 CVE-2026-16730 (A flaw was found in dbus-broker. When the process file-descriptor limi ...)
 	- dbus-broker <unfixed> (bug #1142850)
 	[trixie] - dbus-broker <no-dsa> (Minor issue)
+	[bookworm] - dbus-broker <postponed> (Minor issue)
 	NOTE: https://github.com/bus1/dbus-broker/issues/435
 	NOTE: https://github.com/bus1/dbus-broker/commit/c4a3c886366f7bd566ec9a55b3855ade8290fa17
 	NOTE: https://github.com/bus1/dbus-broker/commit/aaa9fd6bbc2d5d7bfeca039f9c457b7f88a50dde
@@ -46363,6 +46619,7 @@ CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to Stor
 CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXT ...)
 	- zaqar 22.0.0-3 (bug #1142858)
 	[trixie] - zaqar <no-dsa> (Minor issue)
+	[bookworm] - zaqar <postponed> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/7
 	NOTE: https://launchpad.net/bugs/2161254
 CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped user  ...)
@@ -46640,6 +46897,7 @@ CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary file
 CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains  ...)
 	- pytorch-vision <unfixed> (bug #1142689)
 	[trixie] - pytorch-vision <no-dsa> (Minor issue)
+	[bookworm] - pytorch-vision <postponed> (Minor issue)
 	NOTE: https://github.com/pytorch/vision/issues/9551
 	NOTE: https://github.com/pytorch/vision/pull/9520
 	NOTE: Fixed by: https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed
@@ -47255,6 +47513,7 @@ CVE-2026-14282 (The GoDAM \u2013 Organize WordPress Media Library & File Manager
 CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of service via m ...)
 	- node-brace-expansion <unfixed> (bug #1142832)
 	[trixie] - node-brace-expansion <no-dsa> (Minor issue)
+	[bookworm] - node-brace-expansion <postponed> (Minor issue)
 	NOTE: https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5 (v5.0.8)
 	NOTE: When fixing this issue make sure to make it complete and not open CVE-2026-69152.
 CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress is vuln ...)
@@ -50758,6 +51017,7 @@ CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is vulnerable
 CVE-2026-16493 (A flaw was found in ansible-core. The _extract_collection_from_git() f ...)
 	- ansible-core <unfixed>
 	[trixie] - ansible-core <no-dsa> (Minor issue)
+	[bookworm] - ansible-core <postponed> (Minor issue)
 	- ansible 5.4.0-1
 	[bullseye] - ansible <postponed> (Needs only work when CVE-2026-11332 is fixed as well)
 	NOTE: ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid
@@ -51939,6 +52199,7 @@ CVE-2026-64187 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure session ids  ...)
 	- libdancer2-perl <unfixed> (bug #1142718)
 	[trixie] - libdancer2-perl <no-dsa> (Minor issue)
+	[bookworm] - libdancer2-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41975698/
 CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy Terms Word ...)
 	NOT-FOR-US: WordPress plugin
@@ -54747,11 +55008,13 @@ CVE-2026-54497 (view_component is a framework for building reusable, testable, a
 CVE-2026-54490 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
 	- node-websocket-driver 0.7.5+~cs0.6.14-1 (bug #1142415)
 	[trixie] - node-websocket-driver <no-dsa> (Minor issue)
+	[bookworm] - node-websocket-driver <postponed> (Minor issue)
 	NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-mp7j-qc5w-4988
 	NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/c55679a5b18251dd0a55d18a0cc6a4fd8822b92f (0.7.5)
 CVE-2026-54466 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
 	- node-websocket-driver 0.7.5+~cs0.6.14-1 (bug #1142415)
 	[trixie] - node-websocket-driver <no-dsa> (Minor issue)
+	[bookworm] - node-websocket-driver <postponed> (Minor issue)
 	NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6
 	NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680 (0.7.5)
 CVE-2026-54465 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
@@ -54791,6 +55054,7 @@ CVE-2026-54171 (Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0,
 CVE-2026-54163 (secure_headers manages application of security headers with many safe  ...)
 	- ruby-secure-headers 7.3.0-1
 	[trixie] - ruby-secure-headers <no-dsa> (Minor issue)
+	[bookworm] - ruby-secure-headers <postponed> (Minor issue)
 	NOTE: https://github.com/github/secure_headers/security/advisories/GHSA-rqq5-2gf9-4w4q
 	NOTE: Fixed by: https://github.com/github/secure_headers/commit/286a79dea80c6a9be4ca93e0f284c923cf77e539 (7.3.0)
 CVE-2026-54159 (PrestaShop ps_facetedsearch is a module that adds layered navigation f ...)
@@ -55569,6 +55833,7 @@ CVE-2026-47084 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.1
 CVE-2026-47083 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+	[bookworm] - cyrus-imapd <postponed> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47082 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
 	{DLA-4766-1}
@@ -55617,6 +55882,7 @@ CVE-2026-46341 (The Apify MCP server enables AI agents to extract data from webs
 CVE-2026-46338 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
 	- pymdown-extensions 11.0.1-1
 	[trixie] - pymdown-extensions <no-dsa> (Minor issue)
+	[bookworm] - pymdown-extensions <postponed> (Minor issue)
 	NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h
 	NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c (10.21.3)
 CVE-2026-46336 (Manyfold is an open source, self-hosted web application for managing a ...)
@@ -56835,11 +57101,13 @@ CVE-2026-59835 (A exposure of resource to wrong sphere vulnerability in Fortinet
 CVE-2026-59733 (Rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1142269)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d (v1.74.4)
 CVE-2026-59732 (Rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1142269)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c (v1.74.4)
 CVE-2026-59674 (A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tum ...)
@@ -57369,6 +57637,7 @@ CVE-2026-54684 (jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicio
 CVE-2026-54572 (Rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1142269)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265 (v1.74.4)
 CVE-2026-54429 (A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All ...)
@@ -58057,11 +58326,13 @@ CVE-2026-49783 (Improperly implemented security check for standard in Windows Se
 CVE-2026-49477 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
 	- soupsieve 2.8.4-1
 	[trixie] - soupsieve <no-dsa> (Minor issue)
+	[bookworm] - soupsieve <postponed> (Minor issue)
 	NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37
 	NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3 (2.8.4)
 CVE-2026-49476 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
 	- soupsieve 2.8.4-1
 	[trixie] - soupsieve <no-dsa> (Minor issue)
+	[bookworm] - soupsieve <postponed> (Minor issue)
 	NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x
 	NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39 (2.8.4)
 CVE-2026-49459 (DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...)
@@ -58789,6 +59060,7 @@ CVE-2026-42491
 CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a stable re ...)
 	- libmojolicious-perl 9.48+dfsg-1
 	[trixie] - libmojolicious-perl <no-dsa> (Minor issue)
+	[bookworm] - libmojolicious-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41816171/
 	NOTE: Fixed by: https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27 (v9.48)
 CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the table file  ...)
@@ -59029,11 +59301,13 @@ CVE-2025-15665 (The Ultimate Before After Image Slider & Gallery  WordPress plug
 CVE-2026-58102 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-o ...)
 	- libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
 	[trixie] - libcrypt-openssl-x509-perl <no-dsa> (Minor issue)
+	[bookworm] - libcrypt-openssl-x509-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792355/
 	NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/757289bfce095455c104d4adfe9312e7b339620f (2.1.3)
 CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of se ...)
 	- libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
 	[trixie] - libcrypt-openssl-x509-perl <no-dsa> (Minor issue)
+	[bookworm] - libcrypt-openssl-x509-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792358/
 	NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2 (2.1.3)
 CVE-2026-63090 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overf ...)
@@ -59551,6 +59825,7 @@ CVE-2026-15552 (Enterprise Cloud Database developed by Ragic has a Stored Cross-
 CVE-2026-15551 (Integer overflow or wraparound vulnerability in Samsung Open Source rl ...)
 	- rlottie <unfixed> (bug #1143933)
 	[trixie] - rlottie <no-dsa> (Minor issue)
+	[bookworm] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/595
 	NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/f487eff2f8086b84ae1c7faa0418abec909e874b
 CVE-2026-15539 (A security vulnerability has been detected in SourceCodester Online Bo ...)
@@ -60326,6 +60601,7 @@ CVE-2026-59190 (grav-plugin-admin is an HTML user interface that provides a way
 CVE-2026-59180 (Apprise is an open source library which allows you to send a notificat ...)
 	- apprise 1.11.0-1
 	[trixie] - apprise <no-dsa> (Minor issue)
+	[bookworm] - apprise <postponed> (Minor issue)
 	NOTE: https://github.com/caronc/apprise/security/advisories/GHSA-856c-92hv-3vxx
 	NOTE: https://github.com/caronc/apprise/pull/1610
 	NOTE: Fixed by: https://github.com/caronc/apprise/commit/68c0aef218055e4586cf4605fd6b56358f5f462d (v1.11.0)
@@ -61447,6 +61723,7 @@ CVE-2026-58525 (Improper access control in Microsoft Edge (Chromium-based) allow
 CVE-2026-58501 (Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid ...)
 	- python-zeep 4.3.3-1 (bug #1141819)
 	[trixie] - python-zeep <no-dsa> (Minor issue)
+	[bookworm] - python-zeep <postponed> (Minor issue)
 	NOTE: https://github.com/mvantellingen/python-zeep/security/advisories/GHSA-4cc2-g9w2-fhf6
 	NOTE: https://github.com/mvantellingen/python-zeep/commit/83eb07bc6c84d841329d4f88856fecdba86f753e (4.3.3)
 CVE-2026-58494 (Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0 ...)
@@ -61487,6 +61764,7 @@ CVE-2026-55470 (HAPI FHIR is a complete implementation of the HL7 FHIR standard
 CVE-2026-55404 (yt-dlp and youtube-dl are command-line audio/video downloaders. Prior  ...)
 	- yt-dlp 2026.07.04-1
 	[trixie] - yt-dlp <no-dsa> (Minor issue)
+	[bookworm] - yt-dlp <postponed> (Minor issue)
 	NOTE: https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32
 	NOTE: Fixed by: https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 (2026.07.04)
 CVE-2026-55206 (py7zr is a Python-based library and utility to support 7zip archive co ...)
@@ -66510,8 +66788,10 @@ CVE-2026-14193 (DVP80ES300T with Improper Validation of Array Index Vulnerabilit
 CVE-2026-14191 (An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev)  ...)
 	- rar 2:7.23-1
 	[trixie] - rar <no-dsa> (non-free not supported)
+	[bookworm] - rar <postponed> (non-free not supported)
 	- unrar-nonfree 1:7.2.7-1
 	[trixie] - unrar-nonfree <no-dsa> (non-free not supported)
+	[bookworm] - unrar-nonfree <postponed> (non-free not supported)
 CVE-2026-13773 (IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 g ...)
 	NOT-FOR-US: IBM
 CVE-2026-13772 (IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query La ...)
@@ -75305,6 +75585,7 @@ CVE-2026-55654 (A flaw was found in OpenSSH. This vulnerability, a heap out-of-b
 	- openssh-gssapi <unfixed> (bug #1143924)
 	- openssh 1:10.4p1-5
 	[trixie] - openssh <no-dsa> (Minor issue)
+	[bookworm] - openssh <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462493
 	NOTE: openssh/1:10.4p1-5 dropped the GSS-API authentication and key exchange support
 CVE-2026-55653 (A flaw was found in OpenSSH. A malicious SSH server can exploit a doub ...)
@@ -87987,6 +88268,7 @@ CVE-2026-5241 (A vulnerability in the LightGlue model loading path of huggingfac
 CVE-2026-5078 (Impact: The morgan logging middleware's :remote-user token extracts th ...)
 	- node-morgan 1.12.0+~1.9.10-1
 	[trixie] - node-morgan <no-dsa> (Minor issue)
+	[bookworm] - node-morgan <postponed> (Minor issue)
 	NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m
 CVE-2026-4035 (A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for t ...)
 	NOT-FOR-US: mlflow
@@ -90336,6 +90618,7 @@ CVE-2026-46599 (The TIFF decoder does not place a limit on the size of PackBits-
 CVE-2026-46527 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
 	- cpp-httplib <unfixed> (bug #1138578)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-hg3g-vrg8-578g
 CVE-2026-46385 (iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro arr ...)
 	NOT-FOR-US: iskorotkov/avro
@@ -90354,10 +90637,12 @@ CVE-2026-45613 (Rizin is a UNIX-like reverse engineering framework and command-l
 CVE-2026-45372 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
 	- cpp-httplib <unfixed> (bug #1138578)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjxg-64p4-vj4m
 CVE-2026-45352 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
 	- cpp-httplib <unfixed> (bug #1138578)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h6wq-j5mv-f3q8
 CVE-2026-45324 (Rizin is a UNIX-like reverse engineering framework and command-line to ...)
 	NOT-FOR-US: Rizin
@@ -128884,6 +129169,7 @@ CVE-2026-34442 (FreeScout is a free help desk and shared inbox built with PHP's
 CVE-2026-34441 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
 	- cpp-httplib 0.41.0+ds-3 (bug #1133187)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-jv63-rm9j-6jwc
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/6fd97aeca0faa1c6e1bd7ae8150c821dcff31c3b (v0.40.0)
 CVE-2026-34406 (APTRS (Automated Penetration Testing Reporting System) is a Python and ...)
@@ -130440,6 +130726,7 @@ CVE-2026-33745 (cpp-httplib is a C++11 single-file header-only cross platform HT
 	[experimental] - cpp-httplib 0.41.0+ds-1
 	- cpp-httplib 0.41.0+ds-3 (bug #1132162)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-6hrp-7fq9-3qv2
 CVE-2026-33744 (BentoML is a Python library for building online serving systems optimi ...)
 	NOT-FOR-US: BentoML
@@ -139879,6 +140166,7 @@ CVE-2026-31870 (cpp-httplib is a C++11 single-file header-only cross platform HT
 	[experimental] - cpp-httplib 0.41.0+ds-1
 	- cpp-httplib 0.41.0+ds-3 (bug #1130505)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-39q5-hh6x-jpxx
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/e41ec36274a235d8b0bbf21d57e32068a30f6519 (v0.37.1)
 CVE-2026-31868 (Parse Server is an open source backend that can be deployed to any inf ...)
@@ -143733,12 +144021,14 @@ CVE-2026-28435 (cpp-httplib is a C++11 single-file header-only cross platform HT
 	[experimental] - cpp-httplib 0.41.0+ds-1
 	- cpp-httplib 0.41.0+ds-3 (bug #1130234)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xvfx-w463-6fpp
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/c99d7472b5cf4869d3897b9afc9792063a3d15a8 (v0.35.0)
 CVE-2026-28434 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
 	[experimental] - cpp-httplib 0.41.0+ds-1
 	- cpp-httplib 0.41.0+ds-3 (bug #1130232)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8mpw-r4gc-xm7q
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/defd907c7469c5c8281247b73bbd07be24c31164 (v0.35.0)
 CVE-2026-28427 (OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1 ...)
@@ -271419,6 +271709,7 @@ CVE-2025-26695 (When requesting an OpenPGP key from a WKD server, an incorrect p
 CVE-2025-25977 (An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code ...)
 	- znuny 6.5.24-1
 	[trixie] - znuny <no-dsa> (Non-free not supported)
+	[bookworm] - znuny <postponed> (Non-free not supported)
 	NOTE: https://www.znuny.org/en/releases/znuny-lts-6-5-24
 CVE-2025-25940 (VisiCut 2.1 allows code execution via Insecure XML Deserialization in  ...)
 	NOT-FOR-US: VisiCut
@@ -763485,6 +763776,7 @@ CVE-2018-1000645 (LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authentica
 CVE-2018-1000644 (Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Enti ...)
 	- rdf4j <unfixed> (bug #1144952)
 	[trixie] - rdf4j <no-dsa> (Minor issue)
+	[bookworm] - rdf4j <postponed> (Minor issue)
 	NOTE: https://github.com/eclipse-rdf4j/rdf4j/issues/1056
 	NOTE: Fixed by: https://github.com/eclipse-rdf4j/rdf4j/commit/50f2f51950227a4ec595a2922d81da487aba5135 (2.4.1)
 	NOTE: When fixing this issue make sure to make the fix complete and not open CVE-2026-15803
@@ -806620,6 +806912,7 @@ CVE-2018-0500 (Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and includin
 CVE-2026-77643 (A cross-site scripting vulnerability in  queryparser/termgenerator_int ...)
 	- xapian-core 1.4.32-1 (bug #1144490)
 	[trixie] - xapian-core <no-dsa> (Minor issue)
+	[bookworm] - xapian-core <postponed> (Minor issue)
 	NOTE: https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html
 	NOTE: https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update
 CVE-2018-0499 (A cross-site scripting vulnerability in queryparser/termgenerator_inte ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e3817ce4525aa79acf8845b988061a9825ba582

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e3817ce4525aa79acf8845b988061a9825ba582
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/1ea8a9f8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list