[Git][security-tracker-team/security-tracker][master] Add two cjose issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 12 10:31:20 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b6cd64f6 by Salvatore Bonaccorso at 2026-09-12T11:31:00+02:00
Add two cjose issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4800,9 +4800,13 @@ CVE-2026-6485 (UEFI BIOS embedded Shell could be used to bypass Secure Boot via
CVE-2026-55250 (Maravel, a PHP framework oriented towards dependency injection, prior ...)
NOT-FOR-US: Maravel
CVE-2026-53939 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
- TODO: check
+ - cjose 0.6.2.7-1
+ NOTE: https://github.com/OpenIDC/cjose/security/advisories/GHSA-f6wf-pqg3-6wqq
+ NOTE: Fixed by: https://github.com/OpenIDC/cjose/commit/2a6e5bd969fa20059fb00913fb9f57d77ea6a4d9 (v0.6.2.6)
CVE-2026-53938 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
- TODO: check
+ - cjose 0.6.2.7-1
+ NOTE: https://github.com/OpenIDC/cjose/security/advisories/GHSA-75r7-f5cv-g3wj
+ NOTE: Fixed by: https://github.com/OpenIDC/cjose/commit/8c51d245273583a658f24ef7b08ba22f848a34a5 (v0.6.2.5)
CVE-2026-53937 (MCP Kotlin SDK is the Kotlin Multiplatform software development kit fo ...)
NOT-FOR-US: MCP Kotlin SDK
CVE-2026-53933 (Maravel, a PHP framework oriented towards dependency injection, prior ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6cd64f65a3b5f1c0779c5790d45c8441c7e4885
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6cd64f65a3b5f1c0779c5790d45c8441c7e4885
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/ea41b7c2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list