[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 6 20:14:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
72d9c050 by security tracker role at 2026-09-06T19:14:05+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,94 @@
-CVE-2026-86219
+CVE-2026-86283 (MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collection ...)
+	TODO: check
+CVE-2026-86259 (OpenMAIC before 1.0.1 skips server-side request forgery validation in  ...)
+	TODO: check
+CVE-2026-86258 (nbviewer through 1.0.1 contains a path traversal vulnerability in Loca ...)
+	TODO: check
+CVE-2026-86257 (wger before 2.6 fails to sanitize first_name and last_name fields in t ...)
+	TODO: check
+CVE-2026-86256 (wger before 2.6 (affected versions <= 2.5.0) contains an open redirect ...)
+	TODO: check
+CVE-2026-86255 (wger before 2.5 fails to validate the maximum duration of routine date ...)
+	TODO: check
+CVE-2026-86254 (wger versions through master contain an incomplete authorization bypas ...)
+	TODO: check
+CVE-2026-86253 (h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vuln ...)
+	TODO: check
+CVE-2026-86252 (h3 versions before 1.15.9 fail to sanitize carriage return characters  ...)
+	TODO: check
+CVE-2026-86251 (h3 versions before 1.15.9 contain a path traversal vulnerability in th ...)
+	TODO: check
+CVE-2026-86250 (h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed ...)
+	TODO: check
+CVE-2026-86242 (Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin w ...)
+	TODO: check
+CVE-2026-86221 (A flaw has been found in SourceCodester Class and Exam Timetabling Sys ...)
+	TODO: check
+CVE-2026-86220 (A vulnerability was detected in SourceCodester Class and Exam Timetabl ...)
+	TODO: check
+CVE-2026-86217 (A vulnerability was detected in code-projects Hotel and Tourism Reserv ...)
+	TODO: check
+CVE-2026-86216 (A security vulnerability has been detected in code-projects Hotel and  ...)
+	TODO: check
+CVE-2026-86215 (A vulnerability was identified in Mstfakts College-Management-System.  ...)
+	TODO: check
+CVE-2026-86214 (A vulnerability was determined in Mstfakts College-Management-System.  ...)
+	TODO: check
+CVE-2026-86213 (A vulnerability was found in Mstfakts College-Management-System. This  ...)
+	TODO: check
+CVE-2026-86212 (A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerabil ...)
+	TODO: check
+CVE-2026-86211 (A flaw has been found in rabindralamsal inventory-management-system 1. ...)
+	TODO: check
+CVE-2026-86210 (A security vulnerability has been detected in SourceCodester Class and ...)
+	TODO: check
+CVE-2026-86209 (A weakness has been identified in SourceCodester Class and Exam Timeta ...)
+	TODO: check
+CVE-2026-86208 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
+	TODO: check
+CVE-2026-86205 (h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability  ...)
+	TODO: check
+CVE-2026-86183 (A vulnerability was identified in diem-project diem up to 5.1.3. This  ...)
+	TODO: check
+CVE-2026-86182 (A vulnerability was determined in diem-project diem up to 5.1.3. This  ...)
+	TODO: check
+CVE-2026-86181 (A vulnerability was found in code-projects Task Management System 1.0. ...)
+	TODO: check
+CVE-2026-86180 (A vulnerability has been found in code-projects Task Management System ...)
+	TODO: check
+CVE-2026-86179 (A flaw has been found in code-projects Daily Expense Manager 1.0. Affe ...)
+	TODO: check
+CVE-2026-86172 (A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts ...)
+	TODO: check
+CVE-2026-83534 (PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_d ...)
+	TODO: check
+CVE-2026-82751 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
+	TODO: check
+CVE-2026-82750 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
+	TODO: check
+CVE-2026-80439 (The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before  ...)
+	TODO: check
+CVE-2026-80437 (The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not p ...)
+	TODO: check
+CVE-2026-19862 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate o ...)
+	TODO: check
+CVE-2026-19859 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a ...)
+	TODO: check
+CVE-2026-19634 (PostgreSQL Anonymizer contains a SQL injection vulnerability in two im ...)
+	TODO: check
+CVE-2026-19633 (PostgreSQL Anonymizer contains a vulnerability that allows unprivilege ...)
+	TODO: check
+CVE-2022-51009 (PocketMine-MP before 4.7.2 fails to properly handle exceptions from th ...)
+	TODO: check
+CVE-2022-51008 (PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, a ...)
+	TODO: check
+CVE-2021-48007 (PocketMine-MP versions before 3.18.1 fail to validate NaN or INF value ...)
+	TODO: check
+CVE-2021-48006 (PocketMine-MP before 4.0.3 does not perform case-insensitive matching  ...)
+	TODO: check
+CVE-2020-37277 (PocketMine-MP versions before 3.15.4 contain a denial of service vulne ...)
+	TODO: check
+CVE-2026-86219 (Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept  ...)
 	- libauthen-sasl-perl <unfixed>
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43326063/
 	NOTE: Fixed by: https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d (v2.2100)
@@ -4032,61 +4122,61 @@ CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06 relies on a client's source
 	NOT-FOR-US: Oxford Nanopore MinKNOW
 CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentic ...)
 	NOT-FOR-US: Proxmox Virtual Environment
-CVE-2026-82209
+CVE-2026-82209 (When libpsl support is enabled, libcurl fails to enforce the Public Su ...)
 	- curl 8.22.0-1
 	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-82209.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6 (curl-8_22_0)
-CVE-2026-82208
+CVE-2026-82208 (With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ...)
 	- curl 8.22.0-1 (unimportant)
 	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
 	NOTE: https://curl.se/docs/CVE-2026-82208.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/0f2876b2c33f6784a27b6f7345bd8cd95b46352a (curl-8_9_1)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a (curl-8_22_0)
 	NOTE: curl in Debian not built with wolfSSL support
-CVE-2026-80255
+CVE-2026-80255 (A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ...)
 	- curl 8.22.0-1
 	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
 	NOTE: https://curl.se/docs/CVE-2026-80255.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603 (curl-8_13_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/4f6aa41a0145e930e766775dbe860883d350aa0a (curl-8_22_0)
-CVE-2026-80231
+CVE-2026-80231 (A flaw in libcurl makes it wrongly reuse an existing HTTPS connection  ...)
 	- curl <not-affected> (Only affects Curl on Windows and macOS)
 	NOTE: https://curl.se/docs/CVE-2026-80231.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/148534db57dda611cf8516e92e4d6e35fc1e5074 (curl-7_71_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42 (rc-8_22_0-3)
-CVE-2026-80230
+CVE-2026-80230 (When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ...)
 	- curl 8.22.0~rc3-1
 	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-80230.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef (rc-8_22_0-3)
-CVE-2026-80229
+CVE-2026-80229 (When performing transfers via libcurl\u2019s multi interface, pooled T ...)
 	- curl 8.22.0~rc3-1
 	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
 	NOTE: https://curl.se/docs/CVE-2026-80229.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb (rc-8_22_0-3)
-CVE-2026-19931
+CVE-2026-19931 (A flaw in libcurl makes it wrongly reuse an HTTP connection setup for  ...)
 	- curl 8.22.0~rc2-1
 	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-19931.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)
-CVE-2026-18924
+CVE-2026-18924 (A flaw in libcurl's handling of HTTP/2 Server Push streams, when the p ...)
 	- curl 8.22.0~rc2-1
 	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <postponed> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-18924.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43 (rc-8_22_0-1)
-CVE-2026-13608
+CVE-2026-13608 (A flaw in the libcurl SASL negotiation for LDAP authentication allows  ...)
 	- curl 8.22.0~rc2-1
 	[trixie] - curl <no-dsa> (Minor issue)
 	[bookworm] - curl <postponed> (Minor issue)
@@ -78732,28 +78822,28 @@ CVE-2026-8296 (In affected versions of Octopus Server with certain access levels
 CVE-2026-6798 (The 2Download Connector for 2DL Hosted Checkout plugin for WordPress i ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-56211 (A remote code execution vulnerability was found in libaom, the referen ...)
-	{DSA-6411-1}
+	{DSA-6411-1 DLA-4774-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t encoder control, introduced in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490802
 	NOTE: https://issues.chromium.org/issues/503993985
 CVE-2026-56210 (A heap-buffer-overflow read vulnerability was found in libaom, the ref ...)
-	{DSA-6411-1}
+	{DSA-6411-1 DLA-4774-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks the SVC encoder layer_context array, introduced in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490801
 	NOTE: https://issues.chromium.org/issues/503975732
 CVE-2026-56209 (An arbitrary address write vulnerability was found in libaom, the refe ...)
-	{DSA-6411-1}
+	{DSA-6411-1 DLA-4774-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t encoder control, introduced in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490800
 	NOTE: https://issues.chromium.org/issues/503993984
 CVE-2026-56208 (A heap buffer overflow vulnerability was found in libaom, the referenc ...)
-	{DSA-6411-1}
+	{DSA-6411-1 DLA-4774-1}
 	- aom 3.14.1-1 (bug #1140428)
 	[bullseye] - aom <not-affected> (1.0.0 lacks LAP two-pass mode (encoder), introduced upstream in 2.0.0)
 	NOTE: https://aomedia.googlesource.com/aom/+/243f8ae84bfbc495b3a3c12948abc4dff3af2f84
@@ -137572,12 +137662,12 @@ CVE-2026-33171 (Statamic is a Laravel and Git powered content management system
 CVE-2026-33166 (Allure 2 is the version 2.x branch of Allure Report, a multi-language  ...)
 	NOT-FOR-US: Allure
 CVE-2026-33165 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
-	{DLA-4550-1}
+	{DSA-6486-1 DLA-4550-1}
 	- libde265 1.0.18-1 (bug #1131468)
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-653q-9f73-8hvg
 	NOTE: Fixed by: https://github.com/strukturag/libde265/commit/c7891e412106130b83f8e8ea8b7f907e9449b658 (v1.0.17)
 CVE-2026-33164 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
-	{DLA-4550-1}
+	{DSA-6486-1 DLA-4550-1}
 	- libde265 1.0.18-1 (bug #1131469)
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r
 	NOTE: Fixed by: https://github.com/strukturag/libde265/commit/c7891e412106130b83f8e8ea8b7f907e9449b658 (v1.0.17)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72d9c050fec4d3f93290360c3c9f3d2dd7077e40

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72d9c050fec4d3f93290360c3c9f3d2dd7077e40
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/a35b1eb9/attachment.htm>


More information about the debian-security-tracker-commits mailing list