[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 11 21:25:06 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c51e463d by Moritz Muehlenhoff at 2026-09-11T22:23:00+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -355,6 +355,7 @@ CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vuln
NOT-FOR-US: IBM
CVE-2026-87908 (multiparty is a Node.js library for parsing multipart/form-data reques ...)
- node-multiparty <unfixed> (bug #1147414)
+ [trixie] - node-multiparty <no-dsa> (Minor issue)
NOTE: https://github.com/pillarjs/multiparty/security/advisories/GHSA-5h46-2939-q3wh
CVE-2026-86815 (The BackWPup WordPress plugin before 5.7.5 does not properly restrict ...)
NOT-FOR-US: WordPress plugin
@@ -522,6 +523,7 @@ CVE-2026-54054 (Transmute is a free, open-source, self-hosted file conversion an
NOT-FOR-US: Transmute
CVE-2026-49836 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
- psd-tools 1.17.4+dfsg.1-1
+ [trixie] - psd-tools <no-dsa> (Minor issue)
NOTE: https://github.com/psd-tools/psd-tools/security/advisories/GHSA-2rmg-vrx8-9j2f
NOTE: https://github.com/psd-tools/psd-tools/pull/657 (v1.17.1)
CVE-2026-3096 (The product's web portals allow external links to be opened in a new b ...)
@@ -588,6 +590,7 @@ CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin before
NOT-FOR-US: WordPress plugin
CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When p ...)
- gst-plugins-good1.0 1.28.7-1
+ [trixie] - gst-plugins-good1.0 <no-dsa> (Minor issue)
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0079.html
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5235
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12433
@@ -598,6 +601,7 @@ CVE-2026-89011 (isomorphic-git before 1.42.0 contains a prototype pollution vuln
NOT-FOR-US: isomorphic-git
CVE-2026-89092 (The nscd service in the GNU C Library 2.3.4 onwards may crash due to a ...)
- glibc <unfixed> (bug #1147395)
+ [trixie] - glibc <no-dsa> (Minor issue)
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34624
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016
CVE-2026-9338 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denia ...)
@@ -867,6 +871,7 @@ CVE-2026-88044 (rclone is a command-line program to sync files and directories t
NOTE: Fixed by: https://github.com/rclone/rclone/commit/739403963abf6f58003c2becd5f7c4ad0d644153 (v1.75.1)
CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP cookies, use ...)
- node-cookies <unfixed> (bug #1147405)
+ [trixie] - node-cookies <no-dsa> (Minor issue)
NOTE: https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
NOTE: Fixed by: https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c (v0.9.2)
CVE-2026-88036 (Improper neutralization of special elements in data query logic in the ...)
@@ -3988,6 +3993,7 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remo
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/f41e1865781f74d1cadfe2fbdfeefed946026f12 (v2.15.3)
CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts user-supplied ZIP a ...)
- gnome-tweaks <unfixed>
+ [trixie] - gnome-tweaks <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gnome-tweaks/-/issues/542
CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability in the s ...)
NOT-FOR-US: XenForo
@@ -6033,6 +6039,7 @@ CVE-2026-86478 (In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improp
NOT-FOR-US: JetBrains
CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)
- glib2.0 <unfixed> (bug #1147411)
+ [trixie] - glib2.0 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2473839
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/4044
CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly constrained ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c51e463d5b3349cca44d35cb2efbf9d2ce6d97d8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c51e463d5b3349cca44d35cb2efbf9d2ce6d97d8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/a5d7a781/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list