[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 20:14:31 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a3cd012e by security tracker role at 2026-09-05T19:14:24+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,115 @@
+CVE-2026-86197 (Grav before 2.0.20 contains a cross-site scripting vulnerability in th ...)
+	TODO: check
+CVE-2026-86196 (Grav API plugin versions before 1.0.20 build password reset links from ...)
+	TODO: check
+CVE-2026-86195 (grav-plugin-api versions before 1.0.20 contain a privilege escalation  ...)
+	TODO: check
+CVE-2026-86194 (Grav Form Plugin before 9.1.22 fails to verify page authorization when ...)
+	TODO: check
+CVE-2026-86193 (grav-plugin-api before 1.0.20 fails to validate group-inherited super  ...)
+	TODO: check
+CVE-2026-86192 (SiYuan versions before v3.8.2 fail to properly filter private attribut ...)
+	TODO: check
+CVE-2026-86191 (SiYuan versions before v3.8.2 contain an information disclosure vulner ...)
+	TODO: check
+CVE-2026-86190 (WWBN AVideo contains a broken access control vulnerability in videoVie ...)
+	TODO: check
+CVE-2026-86189 (WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.j ...)
+	TODO: check
+CVE-2026-86188 (AVideo with YPTSocket plugin enabled contains a cross-site scripting v ...)
+	TODO: check
+CVE-2026-86187 (WWBN AVideo generates passwords for external-login accounts using rand ...)
+	TODO: check
+CVE-2026-86186 (AVideo API fails to enforce rate limits when clients send a bot User-A ...)
+	TODO: check
+CVE-2026-86185 (Bilibili Desktop through 1.18.0 disables TLS certificate verification  ...)
+	TODO: check
+CVE-2026-86184 (Lara Dashboard before 1.3.0 contains an authentication bypass vulnerab ...)
+	TODO: check
+CVE-2026-86178 (Pixelfed through 0.12.9 fails to validate follower status in StoryComp ...)
+	TODO: check
+CVE-2026-86177 (Pterodactyl Panel before 1.14.1 fails to validate action-specific perm ...)
+	TODO: check
+CVE-2026-86176 (NetBox through 4.7.0 fails to properly scope user-private records in R ...)
+	TODO: check
+CVE-2026-86175 (NetBox through 4.7.0 fails to redact sensitive data source backend cre ...)
+	TODO: check
+CVE-2026-86174 (Plane through 1.4.2 fails to validate that issues belong to the deploy ...)
+	TODO: check
+CVE-2026-86173 (MindsDB through 26.1.0 contains a server-side request forgery vulnerab ...)
+	TODO: check
+CVE-2026-86169 (Axolotl through 0.18.0 contains a remote code execution vulnerability  ...)
+	TODO: check
+CVE-2026-86124 (AutoAgent contains an unauthenticated remote code execution vulnerabil ...)
+	TODO: check
+CVE-2026-86123 (SQL Chat contains four unauthenticated API endpoints that accept clien ...)
+	TODO: check
+CVE-2026-86122 (Rowboat through 0.9.1 fails to validate custom MCP server and webhook  ...)
+	TODO: check
+CVE-2026-86121 (Cua computer-server versions before 0.3.42 skip authentication when th ...)
+	TODO: check
+CVE-2026-86120 (APITable through 1.13.0-beta.1 contains an incorrect authorization vul ...)
+	TODO: check
+CVE-2026-86119 (Webstudio through 0.296.0 contains an unauthenticated server-side requ ...)
+	TODO: check
+CVE-2026-86118 (gonic versions before 0.22.0 fail to validate administrator privileges ...)
+	TODO: check
+CVE-2026-86117 (Coolify through 4.3.17 contains an authentication bypass vulnerability ...)
+	TODO: check
+CVE-2026-86116 (Metabase versions before 0.63.1 fail to enforce data analyst permissio ...)
+	TODO: check
+CVE-2026-86115 (Sim before 0.8.14 classifies tool requests as internal based on URL pr ...)
+	TODO: check
+CVE-2026-86114 (Arcane versions before 2.0.0 fail to properly restrict template operat ...)
+	TODO: check
+CVE-2026-86113 (BookWyrm through 0.9.1 contains an authorization bypass vulnerability  ...)
+	TODO: check
+CVE-2026-86112 (BookWyrm through 0.9.1 fails to validate user visibility permissions i ...)
+	TODO: check
+CVE-2026-86111 (BookWyrm through 0.9.1 fails to validate user visibility permissions i ...)
+	TODO: check
+CVE-2026-85414 (The Gallery : FooGallery plugin for WordPress is vulnerable to Stored  ...)
+	TODO: check
+CVE-2026-83625 (The Contact Form by Supsystic plugin for WordPress is vulnerable to St ...)
+	TODO: check
+CVE-2026-82752 (Improper Validation of Specified Quantity in Input vulnerability in as ...)
+	TODO: check
+CVE-2026-81543 (The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnera ...)
+	TODO: check
+CVE-2026-76573 (The Pods \u2013 Custom Content Types and Fields plugin for WordPress i ...)
+	TODO: check
+CVE-2026-75586 (The Unlimited Elements For Elementor plugin for WordPress is vulnerabl ...)
+	TODO: check
+CVE-2026-75018 (The Custom Contact Forms plugin for WordPress is vulnerable to authori ...)
+	TODO: check
+CVE-2026-6554 (libpcap BPF interpreter treats the offset in the 'ja L' BPF instructio ...)
+	TODO: check
+CVE-2026-6244 (libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions ...)
+	TODO: check
+CVE-2026-31912 (libpcap BPF interpreter detects neither reaching the end of the filter ...)
+	TODO: check
+CVE-2026-31911 (libpcap BPF interpreter calls abort() if it encounters a BPF instructi ...)
+	TODO: check
+CVE-2026-18313 (rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_ ...)
+	TODO: check
+CVE-2026-18238 (The rpcap client code that processes a RPCAP_MSG_PACKET message receiv ...)
+	TODO: check
+CVE-2026-15550 (The Ninja Forms - Save Progress plugin for WordPress is vulnerable to  ...)
+	TODO: check
+CVE-2026-12843 (The LearnDash LMS plugin for WordPress is vulnerable to authorization  ...)
+	TODO: check
+CVE-2026-10196 (The Mail Mint \u2013 Email Marketing, Newsletter, Email Automation & W ...)
+	TODO: check
+CVE-2026-0799 (In BPF instructions that load/store a value from/to a scratch memory r ...)
+	TODO: check
+CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress is vuln ...)
+	TODO: check
+CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability in the o ...)
+	TODO: check
+CVE-2025-15614 (ugrep before 7.6.0 contains a heap buffer over-read vulnerability in t ...)
+	TODO: check
+CVE-2024-11080 (The Post Grid and Gutenberg Blocks \u2013 ComboBlocks plugin for WordP ...)
+	TODO: check
 CVE-2026-49275 [GHSA-hxph-pv7w-8649: Out of bounds read in CrwMap::decodeBasic]
 	- exiv2 0.28.9+dfsg-1
 	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649
@@ -140,7 +252,7 @@ CVE-2026-85667 (xiaobei through 5.5.2 fails to implement authentication or signa
 	NOT-FOR-US: xiaobei
 CVE-2026-85666 (OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an una ...)
 	NOT-FOR-US: OGX
-CVE-2026-85665 (Bruno versions through 3.4.2 fail to validate file paths in request bo ...)
+CVE-2026-85665 (Bruno versions through 4.1.0 fail to validate file paths in request bo ...)
 	NOT-FOR-US: Bruno
 CVE-2026-85664 (Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters ...)
 	NOT-FOR-US: Chroma
@@ -216,7 +328,7 @@ CVE-2026-85606 (firecrawl-mcp-server 3.20.2 contains an arbitrary local file rea
 	NOT-FOR-US: firecrawl-mcp-server
 CVE-2026-85605 (Slink before 1.12.3 fails to properly authorize access to image commen ...)
 	NOT-FOR-US: Slink
-CVE-2026-85604 (Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote cod ...)
+CVE-2026-85604 (Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote cod ...)
 	NOT-FOR-US: Grav CMS
 CVE-2026-85603 (Grav versions before 1.10.55 contain a path traversal vulnerability in ...)
 	NOT-FOR-US: Grav CMS
@@ -230,11 +342,11 @@ CVE-2026-85599 (Grav Shortcode Core before 6.2.5 contains stored cross-site scri
 	NOT-FOR-US: Grav plugin
 CVE-2026-85598 (Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detecti ...)
 	NOT-FOR-US: Grav CMS
-CVE-2026-85597 (Traefik before v2.11.55 contains a TLS option conflict resolution vuln ...)
+CVE-2026-85597 (Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS optio ...)
 	- traefik <itp> (bug #983289)
 CVE-2026-85596 (Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication by ...)
 	- traefik <itp> (bug #983289)
-CVE-2026-85595 (Traefik versions before v2.11.55 contain an authentication bypass vuln ...)
+CVE-2026-85595 (Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 c ...)
 	- traefik <itp> (bug #983289)
 CVE-2026-85594 (Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces r ...)
 	- traefik <itp> (bug #983289)
@@ -5511,7 +5623,8 @@ CVE-2026-XXXX [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in pcre2_pattern_
 	[bookworm] - pcre2 10.42-1+deb12u1
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3 (pcre2-10.48-RC1)
-CVE-2026-86145 [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit]
+CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...)
+	{DLA-4772-1}
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
@@ -47882,6 +47995,7 @@ CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-
 	NOTE: https://github.com/libssh2/libssh2/pull/2198
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
 CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bo ...)
+	{DLA-4773-1}
 	- libssh2 1.11.1-5 (bug #1142856)
 	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/libssh2/libssh2/pull/2202
@@ -47894,6 +48008,7 @@ CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-
 	NOTE: https://github.com/libssh2/libssh2/pull/2401
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
 CVE-2026-66032 (libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-fre ...)
+	{DLA-4773-1}
 	- libssh2 1.11.1-5 (bug #1142856)
 	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/libssh2/libssh2/pull/2180
@@ -71623,12 +71738,14 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
 	NOTE: https://github.com/bikini/exploitarium/tree/main/7zip-rar5-motw-chain-poc
 	NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
 CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but  ...)
+	{DLA-4773-1}
 	- libssh2 1.11.1-6 (bug #1144415)
 	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
 	NOTE: https://github.com/libssh2/libssh2/pull/2127
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
 CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
+	{DLA-4773-1}
 	- libssh2 1.11.1-6 (bug #1144415)
 	[trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
@@ -78886,7 +79003,7 @@ CVE-2026-10034 (The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to
 CVE-2025-7737 (DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Pl ...)
 	NOT-FOR-US: Hitachi
 CVE-2025-15661 (libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bo ...)
-	{DSA-6365-1}
+	{DSA-6365-1 DLA-4773-1}
 	- libssh2 1.11.1-4 (bug #1140401)
 	NOTE: https://github.com/libssh2/libssh2/pull/1705
 	NOTE: https://github.com/libssh2/libssh2/pull/1717
@@ -112772,7 +112889,7 @@ CVE-2026-7600 (A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This imp
 CVE-2026-7599 (A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects  ...)
 	NOT-FOR-US: Dayoooun hwpx-mcp
 CVE-2026-7598 (A security vulnerability has been detected in libssh2 up to 1.11.1. Th ...)
-	{DSA-6365-1}
+	{DSA-6365-1 DLA-4773-1}
 	- libssh2 1.11.1-3 (bug #1135647)
 	[bullseye] - libssh2 <postponed> (Minor issue, unlikely user/pass length)
 	NOTE: https://github.com/libssh2/libssh2/pull/1858



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3cd012e71a97c34fb525a317a275c0616b3810f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3cd012e71a97c34fb525a317a275c0616b3810f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/562285da/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list