[Git][security-tracker-team/security-tracker][master] Add new mattermost-server issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 21:45:38 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5bd4977e by Salvatore Bonaccorso at 2026-09-14T22:45:18+02:00
Add new mattermost-server issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -201,7 +201,7 @@ CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input validatio
 	- sssd <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479268
 CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2026-89321 (Publishing limits the compressed size of a VSIX (ovsx.publishing.max-c ...)
 	TODO: check
 CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL Injection v ...)
@@ -231,9 +231,9 @@ CVE-2026-86830 (Incorrect privilege assignment in Temporary Elevated Access Mana
 CVE-2026-86460 (Cypher injection vulnerability in the Neo4j persistence layer when pro ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86349 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2026-86348 (Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to rec ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2026-85921 (Double free in Windows Secure Kernel Mode allows an authorized attacke ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-85892 (Concurrent execution using shared resource with improper synchronizati ...)
@@ -243,7 +243,7 @@ CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.82
 CVE-2026-84179 (Description    getTopologyPageInfo merged the Nimbus daemon configurat ...)
 	TODO: check
 CVE-2026-82920 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2026-82441 (Description  A submitted topology carries two lists of blobstore keys, ...)
 	TODO: check
 CVE-2026-82439 (Description  The DRPC server kept a map from function name to request  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bd4977ed44551ef428d02cdbacfba7c2384c815

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bd4977ed44551ef428d02cdbacfba7c2384c815
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/9bc59de3/attachment.htm>


More information about the debian-security-tracker-commits mailing list