[Git][security-tracker-team/security-tracker][master] Add bug reference for node-webfont issue to query help from maintainers

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 19:23:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b01bcfe9 by Salvatore Bonaccorso at 2026-09-14T20:23:25+02:00
Add bug reference for node-webfont issue to query help from maintainers

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -38002,7 +38002,7 @@ CVE-2026-73571 (An authorization bypass vulnerability exists in Zimbra Collabora
 CVE-2026-73570 (A remote code execution vulnerability exists in Zimbra Collaboration ( ...)
 	NOT-FOR-US: Zimbra
 CVE-2026-73569 (fast-xml-parser allows users to process XML from JS object without C/C ...)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8r6m-32jq-jx6q
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e546e03987662de5495d050b5fba26bea65383f (v5.10.1)
 	NOTE: node-webfont provides node-fast-xml-parser
@@ -119112,7 +119112,7 @@ CVE-2026-41654 (Weblate is a web based localization tool. Prior to version 5.17.
 CVE-2026-41653 (BentoPDF is a client-side PDF toolkit that is self hostable. Prior to  ...)
 	NOT-FOR-US: BentoPDF
 CVE-2026-41650 (fast-xml-parser allows users to process XML from JS object without C/C ...)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-gh4j-gqv2-49f6
 	NOTE: node-webfont provides node-fast-xml-parser
 CVE-2026-41644 (monetr is a budgeting application for recurring expenses. Prior to ver ...)
@@ -145481,7 +145481,7 @@ CVE-2026-33399 (Wallos is an open-source, self-hostable personal subscription tr
 CVE-2026-33353 (Soft Serve is a self-hostable Git server for the command line. From ve ...)
 	NOT-FOR-US: Soft Serve
 CVE-2026-33349 (fast-xml-parser allows users to process XML from JS object without C/C ...)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-jp2q-39xq-3w4g
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/commit/239b64aa1fc5c5455ddebbbb54a187eb68c9fdb7
 	NOTE: node-webfont provides node-fast-xml-parser
@@ -147976,7 +147976,7 @@ CVE-2026-33038 (WWBN AVideo is an open source video platform. Versions 25.0 and
 CVE-2026-33037 (WWBN AVideo is an open source video platform. In versions 25.0 and bel ...)
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-33036 (fast-xml-parser allows users to process XML from JS object without C/C ...)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8gc5-j5rx-235r
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/commit/bd26122c838e6a55e7d7ac49b4ccc01a49999a01
 	NOTE: node-webfont provides node-fast-xml-parser
@@ -157804,7 +157804,7 @@ CVE-2026-27945 (ZITADEL is an open source identity management platform. Zitadel
 CVE-2026-27943 (OpenEMR is a free and open source electronic health records and medica ...)
 	NOT-FOR-US: OpenEMR
 CVE-2026-27942 (fast-xml-parser allows users to validate XML, parse XML to JS object,  ...)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-fj3w-jwp8-x2g3
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/pull/791
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/commit/c13a961910f14986295dd28484eee830fa1a0e8a
@@ -160129,7 +160129,7 @@ CVE-2026-26046 (A vulnerability was found in a Moodle TeX filter administrative
 CVE-2026-26045 (A flaw was identified in Moodle\u2019s backup restore functionality wh ...)
 	- moodle <removed>
 CVE-2026-25896 (fast-xml-parser allows users to validate XML, parse XML to JS object,  ...)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-m7jm-9gc2-mpf2
 	NOTE: Fixed by: https://github.com/NaturalIntelligence/fast-xml-parser/commit/943ef0eb1b2d3284e72dd74f44a042ee9f07026e (v5.3.5)
 	NOTE: Fixed by: https://github.com/NaturalIntelligence/fast-xml-parser/commit/ddcd0acf26ddd682cb0dc15a2bd6aa3b96bb1e69 (v5.3.5)
@@ -161107,7 +161107,7 @@ CVE-2026-26280 (systeminformation is a System and OS information library for nod
 	- jupyterlab 4.0.11+ds5+~cs11.25.27-1
 	NOTE: node-systeminformation split from jupyterlab
 CVE-2026-26278 (fast-xml-parser allows users to validate XML, parse XML to JS object,  ...)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-jmr7-xgp7-cmfj
 	NOTE: Fixed by: https://github.com/NaturalIntelligence/fast-xml-parser/commit/910dae5be2de2955e968558fadf6e8f74f117a77 (v5.3.6)
 	NOTE: node-webfont provides node-fast-xml-parser
@@ -457207,7 +457207,7 @@ CVE-2023-26922 (SQL injection vulnerability found in Varisicte matrix-gui v.2 al
 CVE-2023-26921 (OS Command Injection vulnerability in quectel AG550QCN allows attacker ...)
 	NOT-FOR-US: quectel
 CVE-2023-26920 (fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.)
-	- node-webfont <undetermined>
+	- node-webfont <unfixed> (bug #1147730)
 	NOTE: https://gist.github.com/Sudistark/a5a45bd0804d522a1392cb5023aa7ef7
 	NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/commit/2b032a4f799c63d83991e4f992f1c68e4dd05804 (4.2.1)
 	NOTE: node-webfont provides node-fast-xml-parser



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b01bcfe9170c15bfaf515bcccde9f69e012d3c13

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b01bcfe9170c15bfaf515bcccde9f69e012d3c13
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/8d3a9d61/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list