[Git][security-tracker-team/security-tracker][master] Add two cjose issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 10:31:20 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b6cd64f6 by Salvatore Bonaccorso at 2026-09-12T11:31:00+02:00
Add two cjose issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4800,9 +4800,13 @@ CVE-2026-6485 (UEFI BIOS embedded Shell could be used to bypass Secure Boot via
 CVE-2026-55250 (Maravel, a PHP framework oriented towards dependency injection, prior  ...)
 	NOT-FOR-US: Maravel
 CVE-2026-53939 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
-	TODO: check
+	- cjose 0.6.2.7-1
+	NOTE: https://github.com/OpenIDC/cjose/security/advisories/GHSA-f6wf-pqg3-6wqq
+	NOTE: Fixed by: https://github.com/OpenIDC/cjose/commit/2a6e5bd969fa20059fb00913fb9f57d77ea6a4d9 (v0.6.2.6)
 CVE-2026-53938 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
-	TODO: check
+	- cjose 0.6.2.7-1
+	NOTE: https://github.com/OpenIDC/cjose/security/advisories/GHSA-75r7-f5cv-g3wj
+	NOTE: Fixed by: https://github.com/OpenIDC/cjose/commit/8c51d245273583a658f24ef7b08ba22f848a34a5 (v0.6.2.5)
 CVE-2026-53937 (MCP Kotlin SDK is the Kotlin Multiplatform software development kit fo ...)
 	NOT-FOR-US: MCP Kotlin SDK
 CVE-2026-53933 (Maravel, a PHP framework oriented towards dependency injection, prior  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6cd64f65a3b5f1c0779c5790d45c8441c7e4885

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6cd64f65a3b5f1c0779c5790d45c8441c7e4885
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/ea41b7c2/attachment.htm>


More information about the debian-security-tracker-commits mailing list