[Git][security-tracker-team/security-tracker][master] Add Debian bug references for node-undici issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 12:26:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cacba784 by Salvatore Bonaccorso at 2026-09-05T13:24:20+02:00
Add Debian bug references for node-undici issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -319,22 +319,22 @@ CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-
 CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
 	NOT-FOR-US: fastify/middie
 CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and request- ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm
 CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate size-limit  ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v
 CVE-2026-85014 (undici's experimental WebSocketStream client crashes the whole Node.js ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
 CVE-2026-85008 (undici's cache interceptor documents that only safe HTTP methods are c ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv
 CVE-2026-84961 (undici's BalancedPool constructor passes its entire options object thr ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3
 CVE-2026-84947 (undici's dump interceptor reads and discards a response body up to a c ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968
 CVE-2026-84937 (The Video Player for YouTube  WordPress plugin before 2.1.0 does not p ...)
 	NOT-FOR-US: WordPress plugin
@@ -345,7 +345,7 @@ CVE-2026-84935 (The HT Menu  WordPress plugin before 1.2.7 does not perform any
 CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not perform a capa ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie response hea ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j
 CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does not sani ...)
 	NOT-FOR-US: WordPress plugin
@@ -364,7 +364,7 @@ CVE-2026-84898 (The Eventin  WordPress plugin before 4.1.21 does not properly va
 CVE-2026-84896 (The King Addons for Elementor  WordPress plugin before 51.1.77 does no ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84890 (undici's decompress interceptor decompresses response bodies according ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm
 CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
 	NOT-FOR-US: WordPress plugin
@@ -693,7 +693,7 @@ CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1
 CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user  ...)
 	NOT-FOR-US: IBM
 CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process during the ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5
 CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker ...)
 	NOT-FOR-US: IBM
@@ -746,7 +746,7 @@ CVE-2026-18658 (IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.1
 CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to ...)
 	NOT-FOR-US: IBM
 CVE-2026-18540 (undici's retry interceptor can append the body of a ranged retry respo ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r
 CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context  ...)
 	NOT-FOR-US: IBM
@@ -765,7 +765,7 @@ CVE-2026-18198 (Improper neutralization of special elements used in an SQL comma
 CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipula ...)
 	NOT-FOR-US: IBM
 CVE-2026-18149 (undici's retry handler can leave an already-exposed response body pend ...)
-	- node-undici <unfixed>
+	- node-undici <unfixed> (bug #1146745)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x
 CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
 	NOT-FOR-US: IBM



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cacba78475cecbfa5697a0b2c9bfcb0ca2225899

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cacba78475cecbfa5697a0b2c9bfcb0ca2225899
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/336c4de2/attachment.htm>


More information about the debian-security-tracker-commits mailing list