[Git][security-tracker-team/security-tracker][master] Track fixed version for two sabnzbdplus issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 13 18:42:31 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
58776c08 by Salvatore Bonaccorso at 2026-09-13T19:42:00+02:00
Track fixed version for two sabnzbdplus issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -21765,10 +21765,10 @@ CVE-2026-63676
[bookworm] - libyaml-perl <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1 (v1.320.0)
CVE-2026-XXXX [GHSA-q326-jpxx-jmjc: __wrapped__ dispatch bypass allows unauthenticated API access]
- - sabnzbdplus <unfixed> (bug #1147154)
+ - sabnzbdplus 5.1.3+dfsg-1 (bug #1147154)
NOTE: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-q326-jpxx-jmjc
CVE-2026-XXXX [GHSA-mjwj-v5mr-cmcg: PAR2 symlink bypass allows pickle remote code execution.]
- - sabnzbdplus <unfixed> (bug #1147154)
+ - sabnzbdplus 5.1.3+dfsg-1 (bug #1147154)
NOTE: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-mjwj-v5mr-cmcg
CVE-2026-XXXX [GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution]
- sabnzbdplus 5.1.2+dfsg-1 (bug #1145563)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58776c08cf3922d24e189bb46be0ef649423e075
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58776c08cf3922d24e189bb46be0ef649423e075
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260913/6158d39a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list