[Git][security-tracker-team/security-tracker][master] Add new rclone issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 10 21:51:24 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6d5a6ce8 by Salvatore Bonaccorso at 2026-09-10T22:50:47+02:00
Add new rclone issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -260,17 +260,34 @@ CVE-2026-88022 (Improper neutralization of special elements in data query logic
CVE-2026-88021 (Consul and Consul Enterprise are vulnerable to an authorization bypass ...)
TODO: check
CVE-2026-88018 (rclone is a command-line program to sync files and directories to and ...)
- TODO: check
+ - rclone <unfixed>
+ NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-xwwr-4h3p-r22c
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/90595f34f27f569be6b27c57fe5ab65057d323bd (1.75.1)
CVE-2026-88017 (rclone is a command-line program to sync files and directories to and ...)
- TODO: check
+ - rclone <unfixed>
+ NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-c476-6w5q-jw77
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/c6af0b57c2b4af848bc968c2b407354476184b99 (v1.75.1)
CVE-2026-88016 (rclone is a command-line program to sync files and directories to and ...)
- TODO: check
+ - rclone <unfixed>
+ NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/17b0c03338a857bcb0a68d2d4c82ddbdec3f7893 (v1.75.1)
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/a7ab39d3d1958afa1446982c1dc4e4a73a887e3e (v1.75.1)
CVE-2026-88015 (rclone is a command-line program to sync files and directories to and ...)
- TODO: check
+ - rclone <unfixed>
+ NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9 (v1.75.1)
CVE-2026-88014 (rclone is a command-line program to sync files and directories to and ...)
- TODO: check
+ - rclone <unfixed>
+ NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-66hp-wgxq-6f5q
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/5dae3adbf571a6cd9ba501eb47397a7e871e1ae0 (v1.75.1)
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/6507e13d5a83789f500af96d7188c302c9d74d98 (v1.75.1)
+ TODO: check, said to affect only 1.72.0 onwards
CVE-2026-88013 (rclone is a command-line program to sync files and directories to and ...)
- TODO: check
+ - rclone <unfixed>
+ NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-486v-q2wf-fp2r
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/22859b7e696cea3c563c6ba04c6b7f91f74456b4 (v1.75.1)
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/79fbc0842f74e02cb84f0e3e7261d169983c8831 (v1.75.1)
+ NOTE: Fixed by: https://github.com/rclone/rclone/commit/925fb4fb21eb25e75cd1b64fdd17ded857784bfc (v1.75.1)
CVE-2026-88012 (Traefik is an open source HTTP reverse proxy and load balancer. From 2 ...)
- traefik <itp> (bug #983289)
CVE-2026-88011 (Traefik is an open source HTTP reverse proxy and load balancer. Prior ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d5a6ce85617299d05754d98428f96d79b6c0156
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d5a6ce85617299d05754d98428f96d79b6c0156
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/fa4f9d16/attachment.htm>
More information about the debian-security-tracker-commits
mailing list