[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 11 20:13:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d4c523d6 by security tracker role at 2026-09-11T19:13:01+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,303 @@
+CVE-2026-9160 (Improper neutralization of special elements used in a template engine  ...)
+	TODO: check
+CVE-2026-8304 (Missing Authorization vulnerability in TUBITAK BILGEM Software Technol ...)
+	TODO: check
+CVE-2026-8303 (Incorrect privilege assignment vulnerability in TUBITAK BILGEM Softwar ...)
+	TODO: check
+CVE-2026-8301 (Improper neutralization of special elements used in an OS command ('OS ...)
+	TODO: check
+CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access to the  ...)
+	TODO: check
+CVE-2026-89298 (A flaw was found in the Dynamic Client Registration service of Keycloa ...)
+	TODO: check
+CVE-2026-89265 (MoguBlog through 6.2 contains an authorization bypass vulnerability in ...)
+	TODO: check
+CVE-2026-89264 (MoguBlog through 6.2 fails to validate the comment author identity in  ...)
+	TODO: check
+CVE-2026-89263 (MoguBlog through 6.2 fails to authenticate requests to the /web/commen ...)
+	TODO: check
+CVE-2026-89262 (MoguBlog through 6.2 contains an authorization bypass vulnerability in ...)
+	TODO: check
+CVE-2026-89261 (MoguBlog through 6.2 exposes Elasticsearch index management endpoints  ...)
+	TODO: check
+CVE-2026-89260 (MoguBlog through 6.2 contains an XML external entity injection vulnera ...)
+	TODO: check
+CVE-2026-89259 (Hugo is a static site generator. From v0.161.0, Hugo executes Node too ...)
+	TODO: check
+CVE-2026-89258 (Hugo is a static site generator. In versions after v0.123.0 and before ...)
+	TODO: check
+CVE-2026-89257 (AVideo through 29.0 contains an insecure direct object reference (IDOR ...)
+	TODO: check
+CVE-2026-89256 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contain ...)
+	TODO: check
+CVE-2026-89255 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contain ...)
+	TODO: check
+CVE-2026-89254 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contain ...)
+	TODO: check
+CVE-2026-89253 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89252 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails t ...)
+	TODO: check
+CVE-2026-89251 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails t ...)
+	TODO: check
+CVE-2026-89250 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89249 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contain ...)
+	TODO: check
+CVE-2026-89248 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is miss ...)
+	TODO: check
+CVE-2026-89247 (WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and ear ...)
+	TODO: check
+CVE-2026-89246 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89245 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89244 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89243 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89242 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89241 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89240 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89239 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+	TODO: check
+CVE-2026-89212 (A flaw resulting in XML external entity (XXE) was found in Akana API P ...)
+	TODO: check
+CVE-2026-89179 (WeenyGenius, a computer lab management system by Howyar Technologies,  ...)
+	TODO: check
+CVE-2026-89178 (WeenyGenius, a computer lab management system by Howyar Technologies,  ...)
+	TODO: check
+CVE-2026-89177 (WeenyGenius, a computer lab management system by Howyar Technologies,  ...)
+	TODO: check
+CVE-2026-89176 (WeenyGenius, a computer lab management system developed by Howyar Tech ...)
+	TODO: check
+CVE-2026-89175 (Smart Video Intercom System developed by Kingdom Communication Associa ...)
+	TODO: check
+CVE-2026-89174 (Smart Video Intercom System developed by Kingdom Communication Associa ...)
+	TODO: check
+CVE-2026-89173 (Smart Video Intercom System developed by Kingdom Communication Associa ...)
+	TODO: check
+CVE-2026-89148 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contain ...)
+	TODO: check
+CVE-2026-89147 (Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in ...)
+	TODO: check
+CVE-2026-89146 (libp2p-rendezvous through 0.17.1 fails to validate registration TTL va ...)
+	TODO: check
+CVE-2026-89099 (A race condition in the document value layer of MongoDB Server can all ...)
+	TODO: check
+CVE-2026-89090 (An unrecovered panic in the event stream header decoder in Amazon AWS  ...)
+	TODO: check
+CVE-2026-89066 (Improper neutralization of special elements used in an OS command in t ...)
+	TODO: check
+CVE-2026-89065 (Relative path traversal in the generated file manifest cleanup compone ...)
+	TODO: check
+CVE-2026-89013 (Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerab ...)
+	TODO: check
+CVE-2026-89012 (Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypas ...)
+	TODO: check
+CVE-2026-89010 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V2 ...)
+	TODO: check
+CVE-2026-89009 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V2 ...)
+	TODO: check
+CVE-2026-87988 (An arbitrary file access vulnerability in Mistral Vibe allows an attac ...)
+	TODO: check
+CVE-2026-87987 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
+	TODO: check
+CVE-2026-87986 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
+	TODO: check
+CVE-2026-87985 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
+	TODO: check
+CVE-2026-87984 (An arbitrary file write vulnerability in Mistral Vibe, introduced in v ...)
+	TODO: check
+CVE-2026-87983 (An arbitrary file read vulnerability in Mistral Vibe, introduced in ve ...)
+	TODO: check
+CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support links, i ...)
+	TODO: check
+CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
+	TODO: check
+CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
+	TODO: check
+CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
+	TODO: check
+CVE-2026-87123 (hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 ca ...)
+	TODO: check
+CVE-2026-87122
+	REJECTED
+CVE-2026-87020 (An integer overflow in a specified pitch and buffer-size computation l ...)
+	TODO: check
+CVE-2026-86813 (The MetForm WordPress plugin before 4.1.9 does not properly neutralize ...)
+	TODO: check
+CVE-2026-86809 (The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does n ...)
+	TODO: check
+CVE-2026-86793 (SGLang allows unauthenticated pickle deserialization through /update_w ...)
+	TODO: check
+CVE-2026-85979 (Affected versions of Puppet Enterprise contain a command injection vul ...)
+	TODO: check
+CVE-2026-85116 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2 ...)
+	TODO: check
+CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootl ...)
+	TODO: check
+CVE-2026-84390 (A inclusion of sensitive information in source code vulnerability in F ...)
+	TODO: check
+CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
+	TODO: check
+CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
+	TODO: check
+CVE-2026-82578 (When XML batch processing is turned on and the XPath option is selecte ...)
+	TODO: check
+CVE-2026-82535 (Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scri ...)
+	TODO: check
+CVE-2026-82215 (The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 t ...)
+	TODO: check
+CVE-2026-82213 (The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not veri ...)
+	TODO: check
+CVE-2026-81910 (Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Inj ...)
+	TODO: check
+CVE-2026-81909 (Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in ...)
+	TODO: check
+CVE-2026-81908 (Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerabil ...)
+	TODO: check
+CVE-2026-81861 (CWE-522: Insufficiently Protected Credentials vulnerability that could ...)
+	TODO: check
+CVE-2026-80469 (An attacker may achieve arbitrary code execution on a target system by ...)
+	TODO: check
+CVE-2026-80462 (A vulnerability in the Chef Automate API gateway and identity validati ...)
+	TODO: check
+CVE-2026-7863 (Improper neutralization of special elements used in an OS command ('OS ...)
+	TODO: check
+CVE-2026-7298 (Improper neutralization of input during web page generation ('cross-si ...)
+	TODO: check
+CVE-2026-79396 (Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmw ...)
+	TODO: check
+CVE-2026-79395 (An improper authentication vulnerability in the WS-Security (wsse:User ...)
+	TODO: check
+CVE-2026-79394 (An insecure default configuration in the embedded Happytime RTSP serve ...)
+	TODO: check
+CVE-2026-79393 (A heap-based buffer overflow vulnerability in the WS-Addressing Action ...)
+	TODO: check
+CVE-2026-79362 (Certain Woltlab products are affected by RCE via Cache Poisoning. WCF  ...)
+	TODO: check
+CVE-2026-78807 (An issue in wpa_supplicant all versions before v.2.12 allows a local a ...)
+	TODO: check
+CVE-2026-78224 (The XSLT Transformer Step builds a bare TransformerFactory without the ...)
+	TODO: check
+CVE-2026-77159 (A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepare ...)
+	TODO: check
+CVE-2026-72710 (SPIP before 4.4.18 contains a remote code execution vulnerability in t ...)
+	TODO: check
+CVE-2026-72709 (SPIP before 4.4.18 contains a missing authorization vulnerability in t ...)
+	TODO: check
+CVE-2026-72708 (SPIP before 4.4.18 contains an unauthenticated blind SQL injection vul ...)
+	TODO: check
+CVE-2026-71646 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected  ...)
+	TODO: check
+CVE-2026-71644 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected  ...)
+	TODO: check
+CVE-2026-71641 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99 ...)
+	TODO: check
+CVE-2026-71416 (Headroom compresses data before the data reaches a large language mode ...)
+	TODO: check
+CVE-2026-70341 (Use after free in Microsoft Edge (Chromium-based) allows an authorized ...)
+	TODO: check
+CVE-2026-6642 (The Media Library Assistant plugin for WordPress is vulnerable to Stor ...)
+	TODO: check
+CVE-2026-6641 (The Media Library Assistant plugin for WordPress is vulnerable to Stor ...)
+	TODO: check
+CVE-2026-6640 (The Media Library Assistant plugin for WordPress is vulnerable to Stor ...)
+	TODO: check
+CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3  rendered remote  ...)
+	TODO: check
+CVE-2026-68497 (jackson-databind binds a JSON string to a javax.xml.datatype.Duration  ...)
+	TODO: check
+CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP S ...)
+	TODO: check
+CVE-2026-62140 (Unauthenticated Insecure Direct Object References (IDOR) in Quiz And S ...)
+	TODO: check
+CVE-2026-62139 (Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Googl ...)
+	TODO: check
+CVE-2026-62138 (Contributor Cross Site Scripting (XSS) in Visual Composer Website Buil ...)
+	TODO: check
+CVE-2026-62137 (Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.)
+	TODO: check
+CVE-2026-62136 (Unauthenticated Broken Access Control in Flexible Quantity \u2013 Meas ...)
+	TODO: check
+CVE-2026-62135 (Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.)
+	TODO: check
+CVE-2026-62134 (Contributor Insecure Direct Object References (IDOR) in Starter Templa ...)
+	TODO: check
+CVE-2026-62133 (Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versio ...)
+	TODO: check
+CVE-2026-62132 (Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.)
+	TODO: check
+CVE-2026-62114 (Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.)
+	TODO: check
+CVE-2026-62113 (Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4. ...)
+	TODO: check
+CVE-2026-62112 (Editor SQL Injection in Amelia <= 2.4.9 versions.)
+	TODO: check
+CVE-2026-62111 (Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 vers ...)
+	TODO: check
+CVE-2026-62110 (Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 v ...)
+	TODO: check
+CVE-2026-62109 (Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.)
+	TODO: check
+CVE-2026-62107 (Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versi ...)
+	TODO: check
+CVE-2026-62106 (Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3. ...)
+	TODO: check
+CVE-2026-62105 (Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versi ...)
+	TODO: check
+CVE-2026-62103 (Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 version ...)
+	TODO: check
+CVE-2026-62102 (Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.)
+	TODO: check
+CVE-2026-62089 (Missing Authorization vulnerability in Pixar Labs Master Addons for El ...)
+	TODO: check
+CVE-2026-62088 (Insertion of Sensitive Information Into Sent Data vulnerability in 10u ...)
+	TODO: check
+CVE-2026-57843 (NetBSD contains an information disclosure vulnerability in mm_open() w ...)
+	TODO: check
+CVE-2026-57842 (NetBSD contains a use-after-free and double-free vulnerability in msg_ ...)
+	TODO: check
+CVE-2026-54072 (Authorizer is an open-source, self-hostable authentication and authori ...)
+	TODO: check
+CVE-2026-54047 (Laci Synchroni is a decentralized mod and appearance sync server and p ...)
+	TODO: check
+CVE-2026-47839 (A vulnerability allows users authenticating through a federated OIDC p ...)
+	TODO: check
+CVE-2026-3869 (CWE-303 : Incorrect Implementation of Authentication Algorithm vulnera ...)
+	TODO: check
+CVE-2026-38058 (The endpoint on the iDirect iQ200 VSAT terminal returns the complete d ...)
+	TODO: check
+CVE-2026-38056 (A local privilege escalation vulnerability exists in the iDirect iQ200 ...)
+	TODO: check
+CVE-2026-27378 (Unauthenticated Broken Access Control in Deposits and Partial Payments ...)
+	TODO: check
+CVE-2026-19486 (A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gem ...)
+	TODO: check
+CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow vulnerability exis ...)
+	TODO: check
+CVE-2026-18122 (Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes res ...)
+	TODO: check
+CVE-2026-18061 (Improper restriction of XML external entity references in the RemoteQu ...)
+	TODO: check
+CVE-2026-17037 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
+	TODO: check
+CVE-2026-15710 (An information leakage vulnerability exists in the Endpoint DLP compon ...)
+	TODO: check
+CVE-2026-15439 (The GamiPress plugin for WordPress is vulnerable to authenticated (Sub ...)
+	TODO: check
+CVE-2026-11765 (Improper neutralization of argument delimiters in a command ('argument ...)
+	TODO: check
+CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which al ...)
+	TODO: check
+CVE-2025-15679 (Under certain circumstances such as reset to factory default operation ...)
+	TODO: check
+CVE-2024-12145 (The BuddyPress plugin for WordPress is vulnerable to Insecure Direct O ...)
+	TODO: check
 CVE-2026-9768
 	REJECTED
 CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server- ...)
@@ -35,7 +335,7 @@ CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
 	TODO: check
 CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to validate ...)
 	TODO: check
-CVE-2026-89060 (A flaw was found in multicluster-observability-addon. This vulnerabili ...)
+CVE-2026-89060 (A cross-namespace authorization flaw in multicluster-observability-add ...)
 	TODO: check
 CVE-2026-89054 (A missing authorization vulnerability in OpenNMS Horizon allows config ...)
 	NOT-FOR-US: OpenNMS
@@ -725,7 +1025,7 @@ CVE-2026-81793 (Unauthenticated Broken Access Control in Salon booking system <=
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81791 (Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-81789 (Unauthenticated Arbitrary File Deletion in Advanced Product Fields Ext ...)
+CVE-2026-81789 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81788 (Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 ve ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -5526,7 +5826,7 @@ CVE-2026-12230 (The LearnPress \u2013 WordPress LMS Plugin for Create and Sell O
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11891 (Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver,  ...)
 	NOT-FOR-US: Arm
-CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets ...)
+CVE-2026-11573 (Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serializ ...)
 	TODO: check
 CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
 	NOT-FOR-US: ARM
@@ -12324,17 +12624,20 @@ CVE-2024-58379 (nodemailer before 6.9.9 contains a regular expression denial of
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/dd8f5e8a4ddc99992e31df76bcff9c590035cd4a (v6.9.9)
 CVE-2023-31308 (A malicious virtual function can invoke the certain command handlers i ...)
 	NOT-FOR-US: AMD
-CVE-2026-89158 [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in pcre2_compile_32() causes out-of-bounds write on 32-bit systems]
+CVE-2026-89158 (PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 intege ...)
+	{DLA-4772-1}
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/ec9c286d5c10cf1c388b58a442ccefded42254fd (pcre2-10.48)
-CVE-2026-89160 [GHSA-9qww-pwc4-77qq: PCRE2: out-of-bounds reads in pcre2_match() when matching invalid UTF subjects with PCRE2_MATCH_INVALID_UTF]
+CVE-2026-89160 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCR ...)
+	{DLA-4772-1}
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/4889caf31a4c5a6b3c051f0031bf2dbd78f2c287 (pcre2-10.48)
-CVE-2026-89157 [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in pcre2_pattern_convert() with large patterns on 32-bit systems]
+CVE-2026-89157 (PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert o ...)
+	{DLA-4772-1}
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
@@ -12345,7 +12648,8 @@ CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/c932e70451eafef922ebef364ac25042f0031135 (pcre2-10.48)
-CVE-2026-89156 [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in pcre2_match() after JIT fallback with invalid UTF]
+CVE-2026-89156 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fa ...)
+	{DLA-4772-1}
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
@@ -12405,12 +12709,12 @@ CVE-2026-46352 [defrag: fragmented encapsulated traffic with fragments can lead
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-rc34-46x6-mxxm
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8561 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/519ded68fcd7c84d5d348735bba9b02036f91ef8 (suricata-8.0.5)
-CVE-2026-45770 [detect/lua: buffer overflow leads to sandbox escape]
+CVE-2026-45770 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-653j-cc95-vj4c
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8557 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/09c45d91a565642dffefeb87c7b54c4e3224db73 (suricata-8.0.5)
-CVE-2026-46387 [http2: excessive memory alloc with decompression bomb]
+CVE-2026-46387 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-45p7-j5wm-8wrx
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8555 (suricata-7.0.16)
@@ -12421,59 +12725,59 @@ CVE-2026-46387 [http2: excessive memory alloc with decompression bomb]
 	NOTE: https://github.com/OISF/suricata/commit/69107199d6fbff979bad2174cd3a904ab8951bd6 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/20104d09788b606b1de1923286d463a07ad47e6d (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/9c24b5bf1cd3e87f3e61ab89c972fce23ca227af (suricata-8.0.5)
-CVE-2026-45767 [datasets: save with load cmd can save to absolute filename]
+CVE-2026-45767 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-gfxq-gffp-w9rv
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8548 (suricata-7.0.16)
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8547 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/477120e3409a2270e5d698c89e7dbd0a74f1f218 (suricata-7.0.16)
 	NOTE: https://github.com/OISF/suricata/commit/654f5fa64ffbb9ce855f178b7f45cce8ce72ce68 (suricata-8.0.5)
-CVE-2026-45752 [detect: use-after-free in decompress transform pipeline]
+CVE-2026-45752 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-qmc9-vqq2-8mv3
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8541 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/11d1fe1ca866d82e8bb3dd4493016188d890aebd (suricata-8.0.5)
-CVE-2026-45751 [detect: heap-use-after-free in inspection-buffer transform chaining]
+CVE-2026-45751 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-59q6-j4w8-8pjx
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8542 (suricata-7.0.16)
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8540 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/89cde65f8d4314b007c723843b79dfa9e5e26e88 (suricata-7.0.16)
 	NOTE: https://github.com/OISF/suricata/commit/3d371fff99d7d0af0912543174c6ea2abb0ff6a3 (suricata-8.0.5)
-CVE-2026-45759 [http1: quadratic complexity with usage of HTTPParseContentDispositionHeader]
+CVE-2026-45759 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-cfq5-g2v5-6652
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8531 (suricata-7.0.16)
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8530 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/a41b135c5c054c806346f8d6e02d67b8f5594be0 (suricata-7.0.16)
 	NOTE: https://github.com/OISF/suricata/commit/8abe0f2a8de0d910d4d4461474f5bfb519877053 (suricata-8.0.5)
-CVE-2026-45761 [detect: case insensitivity in frames lead to buffer overflow]
+CVE-2026-45761 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-r74x-74x5-r9vm
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8528 (suricata-7.0.16)
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8527 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/df3336bf4f8e8034570b1608f87065391d79c022 (suricata-7.0.16)
 	NOTE: https://github.com/OISF/suricata/commit/31d3977720990bb0efd20be08a6c2362287ea460 (suricata-8.0.5)
-CVE-2026-45762 [defrag: incorrect ip fragment reuse causes remote crash]
+CVE-2026-45762 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-gv2j-f6jv-3878
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8512 (suricata-7.0.16)
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8511 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/b8ae15e2a049fac8714a6f37be3171a7376a4255 (suricata-7.0.16)
 	NOTE: https://github.com/OISF/suricata/commit/97d6fa9e1467f6e6957f32b034199c51980e2ffd (suricata-8.0.5)
-CVE-2026-45763 [lua: sandbox alloc_limit not enforced on new allocations]
+CVE-2026-45763 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-9h43-frr8-xx6m
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8508 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/3e064d47964982a93e5facb9b8700f32d869e139 (suricata-8.0.5)
-CVE-2026-45764 [http2: type confusion from protocol change]
+CVE-2026-45764 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-5rvq-72r5-rqhr
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8494 (suricata-7.0.16)
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8493 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/61c4df2821441226a2e0d3a5723f44ba95764cdd (suricata-7.0.16)
 	NOTE: https://github.com/OISF/suricata/commit/75a4641af6ee87a605e10557e6e2417330227a6a (suricata-8.0.5)
-CVE-2026-45765 [dnp3: unbounded reassembly]
+CVE-2026-45765 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-m8x4-c78g-r4vj
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8462 (suricata-7.0.16)
@@ -12484,7 +12788,7 @@ CVE-2026-45765 [dnp3: unbounded reassembly]
 	NOTE: https://github.com/OISF/suricata/commit/2a4947f0c0791b38b951b4140cb49bb814945045 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/d869f782f737515a0c406bbb86a91d5ff626f3e1 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/d62b7cd98054ab03156e7ce2cac15166b46ab391 (suricata-8.0.5)
-CVE-2026-45766 [nfs: OOM on stateful structures]
+CVE-2026-45766 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-jqr4-ch38-wvm6
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8420 (suricata-7.0.16)
@@ -12495,19 +12799,19 @@ CVE-2026-45766 [nfs: OOM on stateful structures]
 	NOTE: https://github.com/OISF/suricata/commit/f43d442251ab96adcc0bfece6919832b1dc8e9be (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/af37786ee48e0f53a3b29d6c9776f33cee9c67f9 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/c029c0958537224ef85f008a578265b52803021d (suricata-8.0.5)
-CVE-2026-45769 [ikev2: OOM due to unbounded client_transforms]
+CVE-2026-45769 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-hg2g-r464-5593
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8417 (suricata-7.0.16)
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8416 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/97251495e674836693c4636f1eb95fc10b191c15 (suricata-7.0.16)
 	NOTE: https://github.com/OISF/suricata/commit/3a6414eb6ae2b2368df51de50e1c1c980109c7a6 (suricata-8.0.5)
-CVE-2026-45768 [ldap: OOM on unbounded responses per tx]
+CVE-2026-45768 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.5-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-cr4x-w4c4-57p7
 	NOTE: https://redmine.openinfosecfoundation.org/issues/8406 (suricata-8.0.5)
 	NOTE: https://github.com/OISF/suricata/commit/82cf3d67b1f9fe963c372303ae36551146fee890 (suricata-8.0.5)
-CVE-2026-45747 [lua/tls: null dereference in GetCertInfo]
+CVE-2026-45747 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.1-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-vfc5-9844-rmhv
 	NOTE: https://redmine.openinfosecfoundation.org/issues/6286 (suricata-7.0.16)
@@ -13033,7 +13337,8 @@ CVE-2026-82457 (su-exec through 0.3 fails to validate numeric user and group ide
 	- su-exec <itp> (bug #1003059)
 CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network interface a ...)
 	NOT-FOR-US: Argo CD
-CVE-2026-82455 (RubyGems fails to re-validate path containment after filesystem symlin ...)
+CVE-2026-82455
+	REJECTED
 	- rubygems 4.0.15-2
 	[trixie] - rubygems <no-dsa> (Minor issue)
 	[bookworm] - rubygems <postponed> (Minor issue)
@@ -15957,7 +16262,7 @@ CVE-2026-65930 (LimeSurvey Community Edition 7.0.5 contains an authenticated sto
 	- limesurvey <itp> (bug #472802)
 CVE-2026-65647 (Improper symlink resolution before file access in Plesk allows remote  ...)
 	NOT-FOR-US: Plesk
-CVE-2026-65646 (Improper neutralization of special elements in Plesk allows remote aut ...)
+CVE-2026-65646 (Improper neutralization of special elements in in Plesk's DNS zone man ...)
 	NOT-FOR-US: Plesk
 CVE-2026-65642 (Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18. ...)
 	NOT-FOR-US: Plesk
@@ -27481,7 +27786,8 @@ CVE-2026-73395 (Unauthenticated Insecure Direct Object References (IDOR) in Book
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73393 (Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 vers ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-73392 (Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.)
+CVE-2026-73392
+	REJECTED
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73383 (Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.)
 	NOT-FOR-US: WordPress plugin or theme
@@ -74373,7 +74679,7 @@ CVE-2026-5348 (The Academy LMS \u2013 WordPress LMS Plugin for Complete eLearnin
 	NOT-FOR-US: WordPress plugin
 CVE-2026-58593 (NodeBB does not bind the claimed author of an inbound ActivityPub obje ...)
 	NOT-FOR-US: NodeBB
-CVE-2026-58592 (Ladybird contains a dangling-reference memory-safety flaw in its WebAs ...)
+CVE-2026-58592 (Ladybird before commit 2f9dc7e contains a dangling-reference memory-sa ...)
 	- ladybird <itp> (bug #1088305)
 CVE-2026-58457 (Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an  ...)
 	NOT-FOR-US: Shenzhen Aitemi
@@ -328154,7 +328460,8 @@ CVE-2024-8477 (The Newsletter, SMTP, Email marketing and Subscribe forms by Brev
 	NOT-FOR-US: WordPress plugin
 CVE-2024-8264 (Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes  ...)
 	NOT-FOR-US: Fortra
-CVE-2024-7049 (In version v0.3.8 of open-webui/open-webui, a vulnerability exists whe ...)
+CVE-2024-7049
+	REJECTED
 	NOT-FOR-US: open-webui
 CVE-2024-7048 (In version v0.3.8 of open-webui, an improper privilege management vuln ...)
 	NOT-FOR-US: open-webui



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4c523d6d82f7996ac655162521c0165039372b8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4c523d6d82f7996ac655162521c0165039372b8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/3faa97fe/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list