[Git][security-tracker-team/security-tracker][master] lts: mark some issues as limited support

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Sat Sep 5 07:53:09 BST 2026



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
35f99455 by Emilio Pozuelo Monfort at 2026-09-05T08:50:51+02:00
lts: mark some issues as limited support

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1637,10 +1637,12 @@ CVE-2026-XXXX [heap-use-after-free in decoder_context::reset() via dangling prev
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-mm7m-v26f-wf8x
 CVE-2026-56855 (Previously, after a channel has been established, a malicious peer cou ...)
 	- golang-go.crypto 1:0.56.0-1
+	[bookworm] - golang-go.crypto <postponed> (Limited support)
 	NOTE: https://github.com/golang/go/issues/81317
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce (v0.56.0)
 CVE-2026-78662 (Previously, a channel registered in the mux's chanList is not usable u ...)
 	- golang-go.crypto 1:0.56.0-1
+	[bookworm] - golang-go.crypto <postponed> (Limited support)
 	NOTE: https://github.com/golang/go/issues/81316
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/a6cdac60840750226b15617ac8858be44361b36b (v0.56.0)
 CVE-2026-80751 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
@@ -3071,6 +3073,7 @@ CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b (0.6.0)
 CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
 	- golang-google-grpc <unfixed> (bug #1146639)
+	[bookworm] - golang-google-grpc <postponed> (Limited support)
 	NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc
 	NOTE: https://github.com/grpc/grpc-go/pull/9331
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176 (master)
@@ -3078,6 +3081,7 @@ CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77 (v1.83.1)
 CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...)
 	- golang-google-grpc <unfixed> (bug #1146639)
+	[bookworm] - golang-google-grpc <postponed> (Limited support)
 	NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3
 	NOTE: https://github.com/grpc/grpc-go/pull/9332
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8 (master)
@@ -5910,6 +5914,7 @@ CVE-2026-58106 (CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r
 	NOT-FOR-US: Ericsson
 CVE-2026-56854 (The source-address critical option in the Permissions returned by an a ...)
 	- golang-go.crypto 1:0.55.0-1
+	[bookworm] - golang-go.crypto <postponed> (Limited support)
 	NOTE: https://github.com/golang/go/issues/80213
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/e557b08ec2b4f5dd00f38356919fc7b051dd88f8 (v0.55.0)
 CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
@@ -5992,6 +5997,7 @@ CVE-2026-37237 (vLLM up to and including 0.17.0 allows remote attackers to cause
 CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The ap ...)
 	- golang-github-grpc-ecosystem-grpc-gateway 2.30.0-1
 	[trixie] - golang-github-grpc-ecosystem-grpc-gateway <no-dsa> (Minor issue)
+	[bookworm] - golang-github-grpc-ecosystem-grpc-gateway <postponed> (Limited support)
 	NOTE: https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc (v2.29.0)
 CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST command to co ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
@@ -6836,6 +6842,7 @@ CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of caller-suppli
 CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may accept a ...)
 	- golang-mongodb-mongo-driver <unfixed> (bug #1146711)
 	[trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
+	[bookworm] - golang-mongodb-mongo-driver <postponed> (Limited support)
 	NOTE: https://jira.mongodb.org/browse/GODRIVER-4075
 	NOTE: Bulk Write API improved in: https://github.com/mongodb/mongo-go-driver/commit/50cf0c20d228975074c0010bfb688917e25934a4 (v2.1.0)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-go-driver/commit/2ccb9c0ebe924b8445bdbbc6914f07e9072d1e4a (v2.8.2)
@@ -7965,6 +7972,7 @@ CVE-2026-79938 (Dell PowerProtect Cyber Recovery, versions prior to 20.3, contai
 CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a comprom ...)
 	- golang-github-rabbitmq-amqp091-go 1.14.0-1 (bug #1145982)
 	[trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
+	[bookworm] - golang-github-rabbitmq-amqp091-go <postponed> (Limited support)
 	NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp
 	NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
 	NOTE: Fixed by (merge): https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0 (v1.13.0)
@@ -10487,6 +10495,7 @@ CVE-2026-77693 (The Order Tip for WooCommerce WordPress plugin before 1.6.0 does
 CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range header p ...)
 	- libsoup3 <unfixed> (bug #1145785)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/538
@@ -11842,6 +11851,7 @@ CVE-2026-52490 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 all
 CVE-2026-45404 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From versi ...)
 	- golang-opentelemetry-otel <unfixed>
 	[trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
+	[bookworm] - golang-opentelemetry-otel <postponed> (Limited support)
 	NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p
 CVE-2026-34968 (Adminer before 5.4.3 contains an arbitrary file deletion vulnerability ...)
 	- adminer 5.4.3+dfsg-1
@@ -13482,6 +13492,7 @@ CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a ca
 CVE-2026-77682 [Use a user message to trigger form autofill]
 	- epiphany-browser 51~rc-1 (bug #1145177)
 	[trixie] - epiphany-browser <no-dsa> (Minor issue)
+	[bookworm] - epiphany-browser <postponed> (Limited support)
 	NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2147
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/epiphany/-/commit/e85444e03490cff1584251028a11d5dfeb3accac (50.6)
 CVE-2026-66786 (A flaw was found in submariner. In cert-auth mode, the connection conf ...)
@@ -14530,6 +14541,7 @@ CVE-2026-77019 (A vulnerability was determined in CodeAstro Apartment Visitor Ma
 CVE-2026-77014 (A flaw was found in libsoup's SoupServer HTTP Range header processing. ...)
 	- libsoup3 <unfixed> (bug #1144976)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
@@ -20062,6 +20074,7 @@ CVE-2026-23938 (An authenticated administrator is able to crash Zabbix server or
 CVE-2026-23937 (The Zabbix API host.get action can be exploited by authenticated users ...)
 	- zabbix 1:7.0.29+dfsg-1 (bug #1144945)
 	[trixie] - zabbix <no-dsa> (Minor issue)
+	[bookworm] - zabbix <postponed> (Limited support)
 	NOTE: https://support.zabbix.com/browse/ZBX-28074
 CVE-2026-23935 (A Zabbix administrator is able to read out of bounds memory by utilizi ...)
 	- zabbix 1:7.0.29+dfsg-1 (bug #1144946)
@@ -26924,6 +26937,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80744
 	NOTE: Fixed by: https://github.com/golang/go/commit/b0365c1777662ae45534c0e728a12a8b19874759 (go1.27rc3)
@@ -26936,6 +26950,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80745
 	NOTE: Fixed by: https://github.com/golang/go/commit/a3876703796b5d3db7a7c6f2193e8663399f2339 (go1.27rc3)
@@ -26948,6 +26963,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80481
 	NOTE: Fixed by: https://github.com/golang/go/commit/d5eeaa7de337f01173036096619cba09e31bde1a (go1.27rc3)
@@ -26960,6 +26976,7 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80205
 	NOTE: Fixed by: https://github.com/golang/go/commit/cb4d292bb634ab89a62995f2384df9389d876333 (go1.27rc3)
@@ -26972,6 +26989,7 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80494
 	NOTE: Fixed by: https://github.com/golang/go/commit/bd62f0c26450224a26857a6d38a738d31f8fbaf6 (go1.27rc3)
@@ -26984,6 +27002,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80528
 	NOTE: Fixed by: https://github.com/golang/go/commit/95ae6418f3d8c588ecd6fb366707e04b6009028d (go1.27rc3)
@@ -26996,6 +27015,7 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80435
 	NOTE: Fixed by: https://github.com/golang/go/commit/bcdba48a6adcaceabb3696e46b50be21dc739b5e (go1.27rc3)
@@ -27008,6 +27028,7 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhausti
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <postponed> (Limited support)
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80405
 	NOTE: Fixed by: https://github.com/golang/go/commit/41cb2f352e2b4cfb93809ede794d7e5ee9ec2c68 (go1.27rc3)
@@ -34878,6 +34899,7 @@ CVE-2026-66060 (Home Assistant is open source home automation software focused o
 CVE-2026-65819 (gopacket provides packet processing capabilities for Go. Through versi ...)
 	- golang-github-gopacket-gopacket <unfixed> (bug #1144416)
 	[trixie] - golang-github-gopacket-gopacket <no-dsa> (Minor issue)
+	[bookworm] - golang-github-gopacket-gopacket <postponed> (Limited support)
 	- gopacket <unfixed>
 	[trixie] - gopacket <no-dsa> (Minor issue)
 	[bookworm] - gopacket <postponed> (Minor issue)
@@ -35086,6 +35108,7 @@ CVE-2026-71557 (go-git is an extensible git implementation library written in pu
 	- golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
 	- golang-github-go-git-go-git <unfixed> (bug #1143903)
 	[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+	[bookworm] - golang-github-go-git-go-git <postponed> (Limited support)
 	NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j
 	NOTE: https://github.com/go-git/go-git/pull/2247
 	NOTE: Fixed by (merge): https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36 (v6.0.0-alpha.5)
@@ -35095,6 +35118,7 @@ CVE-2026-71556 (go-git is an extensible git implementation library written in pu
 	- golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
 	- golang-github-go-git-go-git <unfixed> (bug #1143903)
 	[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+	[bookworm] - golang-github-go-git-go-git <postponed> (Limited support)
 	NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm
 	NOTE: Fixed by: https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac (v6.0.0-alpha.5)
 	NOTE: Fixed by: https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab (v5.19.2)
@@ -35784,6 +35808,7 @@ CVE-2026-19054 (A vulnerability was detected in Lspace-io lspace-server up to 79
 CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser reads web ad ...)
 	- epiphany-browser 51~rc-1 (bug #1143966)
 	[trixie] - epiphany-browser <no-dsa> (Minor issue)
+	[bookworm] - epiphany-browser <postponed> (Limited support)
 	NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
 	NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/commit/13dd600719d7aac532ed6c84ea0d12dd372d4ac4
 CVE-2026-18367 (A privilege escalation vulnerability allows local users to execute arb ...)
@@ -39682,6 +39707,7 @@ CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMap
 	- golang-github-pion-stun-v3 <unfixed> (bug #1144414)
 	- golang-github-pion-stun <unfixed>
 	[trixie] - golang-github-pion-stun <no-dsa> (Minor issue)
+	[bookworm] - golang-github-pion-stun <postponed> (Limited support)
 	NOTE: https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc
 	NOTE: https://github.com/pion/stun/pull/278
 	NOTE: Fixed by: https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 (v3.1.3)
@@ -43535,11 +43561,13 @@ CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulne
 CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
 	- rust-tiny-http <unfixed> (bug #1142989)
 	[trixie] - rust-tiny-http <no-dsa> (Minor issue)
+	[bookworm] - rust-tiny-http <postponed> (Limited support)
 	NOTE: https://github.com/theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-/tree/master
 	NOTE: https://github.com/tiny-http/tiny-http/issues/288
 CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
 	- rust-tiny-http <unfixed> (bug #1142989)
 	[trixie] - rust-tiny-http <no-dsa> (Minor issue)
+	[bookworm] - rust-tiny-http <postponed> (Limited support)
 	NOTE: https://github.com/theopaid/CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master
 	NOTE: https://github.com/tiny-http/tiny-http/issues/287
 CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vuln ...)
@@ -46876,6 +46904,7 @@ CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated a
 CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is established thr ...)
 	- libsoup3 <unfixed> (bug #1142846)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506951
@@ -46883,6 +46912,7 @@ CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is establish
 CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding parser uses ...)
 	- libsoup3 <unfixed> (bug #1142845)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506950
@@ -46890,6 +46920,7 @@ CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding parse
 CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in the soup ...)
 	- libsoup3 <unfixed> (bug #1142844)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506949
@@ -59697,6 +59728,7 @@ CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and Exam
 CVE-2026-15714 (An out-of-bounds read vulnerability was found in libsoup's multipart p ...)
 	- libsoup3 <unfixed> (bug #1142843)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499942
@@ -59704,6 +59736,7 @@ CVE-2026-15714 (An out-of-bounds read vulnerability was found in libsoup's multi
 CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implementation. ...)
 	- libsoup3 <unfixed> (bug #1142842)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499941
@@ -59711,12 +59744,14 @@ CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implement
 CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
 	- libsoup3 <unfixed> (bug #1142841)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
 CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing impleme ...)
 	- libsoup3 <unfixed> (bug #1142840)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499924
@@ -59724,6 +59759,7 @@ CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing i
 CVE-2026-15709 (A flaw was found in libsoup's WebSocket implementation when using the  ...)
 	- libsoup3 <unfixed> (bug #1142839)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
+	[bookworm] - libsoup3 <postponed> (Limited support)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499922



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/35f994558902c5e8f556285cdfe67bb5a1589b98

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/35f994558902c5e8f556285cdfe67bb5a1589b98
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/0fdf19ee/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list