[Git][security-tracker-team/security-tracker][master] Track fixed version for node-undici issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 5 12:31:35 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
04ba4985 by Salvatore Bonaccorso at 2026-09-05T13:28:41+02:00
Track fixed version for node-undici issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -319,22 +319,22 @@ CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-
CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
NOT-FOR-US: fastify/middie
CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and request- ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm
CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate size-limit ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v
CVE-2026-85014 (undici's experimental WebSocketStream client crashes the whole Node.js ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
CVE-2026-85008 (undici's cache interceptor documents that only safe HTTP methods are c ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv
CVE-2026-84961 (undici's BalancedPool constructor passes its entire options object thr ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3
CVE-2026-84947 (undici's dump interceptor reads and discards a response body up to a c ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968
CVE-2026-84937 (The Video Player for YouTube WordPress plugin before 2.1.0 does not p ...)
NOT-FOR-US: WordPress plugin
@@ -345,7 +345,7 @@ CVE-2026-84935 (The HT Menu WordPress plugin before 1.2.7 does not perform any
CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not perform a capa ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie response hea ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j
CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does not sani ...)
NOT-FOR-US: WordPress plugin
@@ -364,7 +364,7 @@ CVE-2026-84898 (The Eventin WordPress plugin before 4.1.21 does not properly va
CVE-2026-84896 (The King Addons for Elementor WordPress plugin before 51.1.77 does no ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84890 (undici's decompress interceptor decompresses response bodies according ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm
CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
NOT-FOR-US: WordPress plugin
@@ -693,7 +693,7 @@ CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1
CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user ...)
NOT-FOR-US: IBM
CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process during the ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5
CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker ...)
NOT-FOR-US: IBM
@@ -746,7 +746,7 @@ CVE-2026-18658 (IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.1
CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to ...)
NOT-FOR-US: IBM
CVE-2026-18540 (undici's retry interceptor can append the body of a ranged retry respo ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r
CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context ...)
NOT-FOR-US: IBM
@@ -765,7 +765,7 @@ CVE-2026-18198 (Improper neutralization of special elements used in an SQL comma
CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipula ...)
NOT-FOR-US: IBM
CVE-2026-18149 (undici's retry handler can leave an already-exposed response body pend ...)
- - node-undici <unfixed> (bug #1146745)
+ - node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x
CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
NOT-FOR-US: IBM
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/04ba4985f00978a33065a6b90b10b82fff4a89ac
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/04ba4985f00978a33065a6b90b10b82fff4a89ac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/17aeda2f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list