[Git][security-tracker-team/security-tracker][master] Track fixes for three node.js modules in unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 13 10:56:23 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fdd5761e by Salvatore Bonaccorso at 2026-09-13T11:55:15+02:00
Track fixes for three node.js modules in unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2067,11 +2067,11 @@ CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support li
NOTE: https://github.com/python/cpython/pull/157266
NOTE: https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2 (main)
CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
- - node-morgan <unfixed> (bug #1147520)
+ - node-morgan 1.12.1+~1.9.10-1 (bug #1147520)
NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
NOTE: Fixed by: https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee (1.12.1)
CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
- - node-compression <unfixed> (bug #1147519)
+ - node-compression 1.8.2+~1.8.1-1 (bug #1147519)
NOTE: https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95
NOTE: Fixed by: https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff (v1.8.2)
CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
@@ -2328,7 +2328,7 @@ CVE-2026-88061 (career-ops is an open-source AI-assisted job search and applicat
CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable ...)
NOT-FOR-US: IBM
CVE-2026-87908 (multiparty is a Node.js library for parsing multipart/form-data reques ...)
- - node-multiparty <unfixed> (bug #1147414)
+ - node-multiparty 4.3.1+~4.2.1-1 (bug #1147414)
[trixie] - node-multiparty <no-dsa> (Minor issue)
NOTE: https://github.com/pillarjs/multiparty/security/advisories/GHSA-5h46-2939-q3wh
CVE-2026-86815 (The BackWPup WordPress plugin before 5.7.5 does not properly restrict ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fdd5761e0bc8457cb78383cd887441c0b0e33ef3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fdd5761e0bc8457cb78383cd887441c0b0e33ef3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260913/5e801ac1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list