[Git][security-tracker-team/security-tracker][master] Add two new msgpack-java issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 12 20:43:25 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
780981d9 by Salvatore Bonaccorso at 2026-09-12T21:42:58+02:00
Add two new msgpack-java issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -56,9 +56,11 @@ CVE-2026-90533 (Flowise before 3.1.4 contains a broken access control vulnerabil
CVE-2026-90474 (MCPHub before 1.0.32 contains an authentication bypass vulnerability i ...)
NOT-FOR-US: MCPHub
CVE-2026-90473 (msgpack-java through 0.9.12 contains an integer overflow vulnerability ...)
- TODO: check
+ - msgpack-java <unfixed>
+ NOTE: https://github.com/msgpack/msgpack-java/issues/1014
CVE-2026-90472 (msgpack-java through 0.9.12 contains a stack overflow vulnerability in ...)
- TODO: check
+ - msgpack-java <unfixed>
+ NOTE: https://github.com/msgpack/msgpack-java/issues/1015
CVE-2026-89172 (Improper protection of physical side channels vulnerability in Microch ...)
NOT-FOR-US: Microchip
CVE-2026-85200 (The GEO my WP plugin for WordPress is vulnerable to Local File Inclusi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/780981d90e9390699bbe8867d278d17198bedf32
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/780981d90e9390699bbe8867d278d17198bedf32
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/b475418f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list