[Git][security-tracker-team/security-tracker][master] Process two forgejo issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 11 09:21:35 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e294ccfa by Salvatore Bonaccorso at 2026-09-11T10:21:03+02:00
Process two forgejo issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -24,11 +24,11 @@ CVE-2026-89161 (In PCRE2 before 10.48, pcre2_jit_match mishandles a previously c
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE: https://github.com/PCRE2Project/pcre2/pull/937
CVE-2026-89151 (Forgejo before 16.0.4 allows use of restricted API tokens for unintend ...)
- TODO: check
+ - forgejo <itp> (bug #1058932)
CVE-2026-89145 (Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape ...)
TODO: check
CVE-2026-89094 (Forgejo before 16.0.4 allows remote code execution via a crafted templ ...)
- TODO: check
+ - forgejo <itp> (bug #1058932)
CVE-2026-89089 (A SQL injection vulnerability exists in the JasperReports-based report ...)
TODO: check
CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e294ccfa69acbbae627f4dfd5d87337664c5fbf3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e294ccfa69acbbae627f4dfd5d87337664c5fbf3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/5fd8e555/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list