[Git][security-tracker-team/security-tracker][master] Add new exiv2 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 09:24:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
34de8174 by Salvatore Bonaccorso at 2026-09-05T10:20:25+02:00
Add new exiv2 issues

Note there were as well a ouple of not yet CVEified low severity
iessues. I skipped them now on purpose to not clutter the list iwth temp
entries for pratically non-issues/low-severity issue. When/if they get
assingned then the intention would be to backfill those as well.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,12 @@
+CVE-2026-49275 [GHSA-hxph-pv7w-8649: Out of bounds read in CrwMap::decodeBasic]
+	- exiv2 0.28.9+dfsg-1
+	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649
+CVE-2026-68547 [GHSA-jcgh-p9v3-pw6j: Heap out-of-bounds read in RemoteIo when reading block-aligned remote CRW files]
+	- exiv2 0.28.9+dfsg-1
+	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j
+CVE-2026-68546 [GHSA-3695-mjv8-3r52: Heap out-of-bounds write in RemoteIo when reading from a malicious remote server (WebReady/Curl builds)]
+	- exiv2 0.28.9+dfsg-1
+	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52
 CVE-2026-9317 (Nango before 0.71.6 contains a missing authentication vulnerability in ...)
 	NOT-FOR-US: Nango
 CVE-2026-9186 (IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated atta ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34de8174381ae2159493f08186cf99e3e5c26d8f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34de8174381ae2159493f08186cf99e3e5c26d8f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/a5973c35/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list