[Git][security-tracker-team/security-tracker][master] Annotate some upstream commits
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 5 14:14:41 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bdb3c6cb by Salvatore Bonaccorso at 2026-09-05T15:14:16+02:00
Annotate some upstream commits
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -40264,11 +40264,11 @@ CVE-2026-67324 (GitPython 3.1.50 fails to recognize joined short-option forms su
CVE-2026-67323 (GitPython before 3.1.51 fails to guard against dangerous Git options p ...)
- python-git 3.1.61-1 (bug #1143454)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v
- NOTE: https://github.com/gitpython-developers/GitPython/commit/701ce32fe5ba8cb622c0e0342a376a6beb47d738
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/701ce32fe5ba8cb622c0e0342a376a6beb47d738 (3.1.51)
CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable exfiltra ...)
- python-git 3.1.61-1 (bug #1143454)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
- NOTE: https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2 (3.1.52)
CVE-2026-67321 (axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...)
- node-axios 1.18.0-1
[trixie] - node-axios <no-dsa> (Minor issue)
@@ -115179,12 +115179,13 @@ CVE-2026-42215 (GitPython is a python library used to interact with Git reposito
- python-git 3.1.50-1 (bug #1135349)
[trixie] - python-git <no-dsa> (Minor issue)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4
- NOTE: https://github.com/gitpython-developers/GitPython/commit/0f68db0710f9125762fca5dbc2328593537ae923
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/0f68db0710f9125762fca5dbc2328593537ae923 (3.1.47)
CVE-2026-42284 (GitPython is a python library used to interact with Git repositories. ...)
- python-git 3.1.50-1 (bug #1135350)
[trixie] - python-git <no-dsa> (Minor issue)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485
- NOTE: https://github.com/gitpython-developers/GitPython/commit/da545232d0401fb9fb7660f9ff67991996674dda
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/pull/2130
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0 (3.1.47)
CVE-2026-7363 (Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to ...)
{DSA-6239-1}
- chromium 147.0.7727.137-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3c6cbdfda7c4467e10b53a37a49f86f374080
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3c6cbdfda7c4467e10b53a37a49f86f374080
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/706e44ca/attachment.htm>
More information about the debian-security-tracker-commits
mailing list