[Git][security-tracker-team/security-tracker][master] Add two new flatpak-builder issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Sep 14 14:17:13 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
34799a53 by Salvatore Bonaccorso at 2026-09-14T15:16:44+02:00
Add two new flatpak-builder issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,9 @@
+CVE-2026-XXXX [GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode protections across multiple source subtypes]
+ - flatpak-builder <unfixed> (bug #1147701)
+ NOTE: https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-484h-v688-jq5j
+CVE-2026-86320
+ - flatpak-builder <unfixed> (bug #1147700)
+ NOTE: https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
CVE-2026-90691 (A security vulnerability has been detected in 0x4m4 HexStrike AI up to ...)
NOT-FOR-US: 0x4m4 HexStrike AI
CVE-2026-90690 (A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff57 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34799a53310dee6878baba0e56d9a6d317cce6b6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34799a53310dee6878baba0e56d9a6d317cce6b6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/4b8d6e24/attachment.htm>
More information about the debian-security-tracker-commits
mailing list