[Git][security-tracker-team/security-tracker][master] Annotate some upstream commits

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 14:14:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bdb3c6cb by Salvatore Bonaccorso at 2026-09-05T15:14:16+02:00
Annotate some upstream commits

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -40264,11 +40264,11 @@ CVE-2026-67324 (GitPython 3.1.50 fails to recognize joined short-option forms su
 CVE-2026-67323 (GitPython before 3.1.51 fails to guard against dangerous Git options p ...)
 	- python-git 3.1.61-1 (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v
-	NOTE: https://github.com/gitpython-developers/GitPython/commit/701ce32fe5ba8cb622c0e0342a376a6beb47d738
+	NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/701ce32fe5ba8cb622c0e0342a376a6beb47d738 (3.1.51)
 CVE-2026-67322 (GitPython before 3.1.52 is vulnerable to environment-variable exfiltra ...)
 	- python-git 3.1.61-1 (bug #1143454)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
-	NOTE: https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2
+	NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2 (3.1.52)
 CVE-2026-67321 (axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...)
 	- node-axios 1.18.0-1
 	[trixie] - node-axios <no-dsa> (Minor issue)
@@ -115179,12 +115179,13 @@ CVE-2026-42215 (GitPython is a python library used to interact with Git reposito
 	- python-git 3.1.50-1 (bug #1135349)
 	[trixie] - python-git <no-dsa> (Minor issue)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4
-	NOTE: https://github.com/gitpython-developers/GitPython/commit/0f68db0710f9125762fca5dbc2328593537ae923
+	NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/0f68db0710f9125762fca5dbc2328593537ae923 (3.1.47)
 CVE-2026-42284 (GitPython is a python library used to interact with Git repositories.  ...)
 	- python-git 3.1.50-1 (bug #1135350)
 	[trixie] - python-git <no-dsa> (Minor issue)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485
-	NOTE: https://github.com/gitpython-developers/GitPython/commit/da545232d0401fb9fb7660f9ff67991996674dda
+	NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/pull/2130
+	NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0 (3.1.47)
 CVE-2026-7363 (Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to  ...)
 	{DSA-6239-1}
 	- chromium 147.0.7727.137-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3c6cbdfda7c4467e10b53a37a49f86f374080

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3c6cbdfda7c4467e10b53a37a49f86f374080
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/706e44ca/attachment.htm>


More information about the debian-security-tracker-commits mailing list