[Git][security-tracker-team/security-tracker][master] lts: follow no-dsa triage for low-priority packages

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Wed Sep 16 16:32:45 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
abb39fa5 by Sylvain Beucler at 2026-09-16T17:30:59+02:00
lts: follow no-dsa triage for low-priority packages

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1456,6 +1456,7 @@ CVE-2026-90854 (A security flaw has been discovered in SourceCodester/katojkalem
 CVE-2026-90852 (A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This  ...)
 	- zstd-jni-java <unfixed>
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/issues/404
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936 (1.5.7-14)
 CVE-2026-90851 (A flaw has been found in PHPGurukul Hostel Management System 3.0. This ...)
@@ -2579,6 +2580,7 @@ CVE-2026-82232 (Improper neutralization of special elements used in an SQL comma
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path trave ...)
 	- pymupdf <unfixed>
 	[trixie] - pymupdf <no-dsa> (Minor issue)
+	[bookworm] - pymupdf <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/pymupdf/PyMuPDF/commit/b2c8f3a859fed35c379a44df566f770dc3e18605
 CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a DOM-base ...)
 	NOT-FOR-US: TripleLift
@@ -2886,6 +2888,7 @@ CVE-2026-XXXX [GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode pr
 CVE-2026-86320
 	- flatpak-builder 1.4.11-1 (bug #1147700)
 	[trixie] - flatpak-builder <no-dsa> (Minor issue)
+	[bookworm] - flatpak-builder <postponed> (Minor issue)
 	NOTE: https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
 CVE-2026-90691 (A security vulnerability has been detected in 0x4m4 HexStrike AI up to ...)
 	NOT-FOR-US: 0x4m4 HexStrike AI
@@ -3234,6 +3237,7 @@ CVE-2026-90777 (ESPnet before 202609 deserializes pretrained model checkpoints u
 CVE-2026-90776 (Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time comp ...)
 	- node-nodemailer 10.0.10+~8.0.1-1 (bug #1147617)
 	[trixie] - node-nodemailer <no-dsa> (Minor issue)
+	[bookworm] - node-nodemailer <postponed> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-prgh-xp8r-p3m5
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/c07f17518d25aca8ab2ad66968dcbca538c24b89 (v10.0.5)
 CVE-2026-90775 (PostGIS address_standardizer through 3.7.0 fails to validate the Weigh ...)
@@ -3431,6 +3435,7 @@ CVE-2026-77773 (The Contact Form to Chat Apps | Click to Chat to Order  WordPres
 CVE-2026-90560 (zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read ...)
 	- zstd-jni-java <unfixed>
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/issues/405
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f (v1.5.7-14)
 CVE-2026-90559 (snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerabi ...)
@@ -3438,6 +3443,7 @@ CVE-2026-90559 (snappy-java through 1.1.10.8 contains an out-of-bounds write vul
 CVE-2026-90558 (sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in ...)
 	- sngrep 1.8.4-2 (bug #1147622)
 	[trixie] - sngrep <no-dsa> (Minor issue)
+	[bookworm] - sngrep <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b
 CVE-2026-90555 (vLLM versions before 0.28.0 fail to validate audio sample rate headers ...)
 	- vllm <itp> (bug #1095237)
@@ -3520,6 +3526,7 @@ CVE-2026-10148 (The Booking for Appointments and Events Calendar plugin for Word
 CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email addresses sup ...)
 	- aiosmtplib 5.1.3-1 (bug #1147474)
 	[trixie] - aiosmtplib <no-dsa> (Minor issue)
+	[bookworm] - aiosmtplib <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)
 CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password to an ...)
 	- ironic <unfixed>
@@ -3570,6 +3577,7 @@ CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce t
 CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in start_decod ...)
 	- libstb <unfixed> (bug #1147728)
 	[trixie] - libstb <no-dsa> (Minor issue)
+	[bookworm] - libstb <postponed> (Minor issue)
 	NOTE: https://github.com/nothings/stb/issues/1928
 	NOTE: https://github.com/nothings/stb/issues/1933
 	NOTE: https://github.com/nothings/stb/issues/1947
@@ -5438,11 +5446,13 @@ CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support li
 CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
 	- node-morgan 1.12.1+~1.9.10-1 (bug #1147520)
 	[trixie] - node-morgan <no-dsa> (Minor issue)
+	[bookworm] - node-morgan <postponed> (Minor issue)
 	NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
 	NOTE: Fixed by: https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee (1.12.1)
 CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
 	- node-compression 1.8.2+~1.8.1-1 (bug #1147519)
 	[trixie] - node-compression <no-dsa> (Minor issue)
+	[bookworm] - node-compression <postponed> (Minor issue)
 	NOTE: https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95
 	NOTE: Fixed by: https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff (v1.8.2)
 CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
@@ -5471,6 +5481,7 @@ CVE-2026-84390 (A inclusion of sensitive information in source code vulnerabilit
 CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
 	- apache-opennlp 2.5.12-1 (bug #1147511)
 	[trixie] - apache-opennlp <no-dsa> (Minor issue)
+	[bookworm] - apache-opennlp <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
 	NOT-FOR-US: NextGen Connect (Mirth Connect)
@@ -5686,6 +5697,7 @@ CVE-2026-89089 (A SQL injection vulnerability exists in the JasperReports-based
 CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
 	- ocaml-cstruct 6.3.0-1 (bug #1147522)
 	[trixie] - ocaml-cstruct <no-dsa> (Minor issue)
+	[bookworm] - ocaml-cstruct <postponed> (Minor issue)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-20
 	NOTE: https://github.com/mirage/ocaml-cstruct/pull/324 (v6.3.0)
 CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to validate ...)
@@ -5705,6 +5717,7 @@ CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vuln
 CVE-2026-87908 (multiparty is a Node.js library for parsing multipart/form-data reques ...)
 	- node-multiparty 4.3.1+~4.2.1-1 (bug #1147414)
 	[trixie] - node-multiparty <no-dsa> (Minor issue)
+	[bookworm] - node-multiparty <postponed> (Minor issue)
 	NOTE: https://github.com/pillarjs/multiparty/security/advisories/GHSA-5h46-2939-q3wh
 CVE-2026-86815 (The BackWPup  WordPress plugin before 5.7.5 does not properly restrict ...)
 	NOT-FOR-US: WordPress plugin
@@ -5813,16 +5826,19 @@ CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authe
 CVE-2026-79592 (An out-of-bounds read vulnerability exists in the xls_dumpSummary() fu ...)
 	- r-cran-readxl <unfixed> (bug #1147420)
 	[trixie] - r-cran-readxl <no-dsa> (Minor issue)
+	[bookworm] - r-cran-readxl <postponed> (Minor issue)
 	NOTE: https://github.com/libxls/libxls/issues/162
 	NOTE: Fixed by: https://github.com/libxls/libxls/commit/0b31cdbfee31e929aee65906db35691dfe798bd9
 CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists in the  ...)
 	- r-cran-readxl <unfixed> (bug #1147420)
 	[trixie] - r-cran-readxl <no-dsa> (Minor issue)
+	[bookworm] - r-cran-readxl <postponed> (Minor issue)
 	NOTE: https://github.com/libxls/libxls/issues/161
 	NOTE: Fixed by: https://github.com/libxls/libxls/commit/881f6ec3dabb017af878949a6ed7167613bd7a69
 CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism parser co ...)
 	- mruby <unfixed>
 	[trixie] - mruby <no-dsa> (Minor issue)
+	[bookworm] - mruby <postponed> (Minor issue)
 	NOTE: https://github.com/mruby/mruby/issues/7032
 	NOTE: Fixed by: https://github.com/mruby/mruby/commit/c6866eed4ad5640b552ba79d16063e7ec70a0ac9 (4.1.0-rc)
 CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticat ...)
@@ -5876,6 +5892,7 @@ CVE-2026-54054 (Transmute is a free, open-source, self-hosted file conversion an
 CVE-2026-49836 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
 	- psd-tools 1.17.4+dfsg.1-1
 	[trixie] - psd-tools <no-dsa> (Minor issue)
+	[bookworm] - psd-tools <postponed> (Minor issue)
 	NOTE: https://github.com/psd-tools/psd-tools/security/advisories/GHSA-2rmg-vrx8-9j2f
 	NOTE: https://github.com/psd-tools/psd-tools/pull/657 (v1.17.1)
 CVE-2026-3096 (The product's web portals allow external links to be opened in a new b ...)
@@ -5973,11 +5990,13 @@ CVE-2026-89049 (A server-side request forgery issue due to improper validation o
 CVE-2026-89046 (zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds re ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-rm53-6wf5-f34m
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646 (v1.5.7-14)
 CVE-2026-89045 (zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative l ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-9jx2-gfp9-phfm
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646 (v1.5.7-14)
 CVE-2026-89044 (Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final th ...)
@@ -6229,6 +6248,7 @@ CVE-2026-88044 (rclone is a command-line program to sync files and directories t
 CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP cookies, use ...)
 	- node-cookies 0.9.2+~0.9.2-1 (bug #1147405)
 	[trixie] - node-cookies <no-dsa> (Minor issue)
+	[bookworm] - node-cookies <postponed> (Minor issue)
 	NOTE: https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
 	NOTE: Fixed by: https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c (v0.9.2)
 CVE-2026-88036 (Improper neutralization of special elements in data query logic in the ...)
@@ -6263,6 +6283,7 @@ CVE-2026-88031 (Improper neutralization of special elements in data query logic
 CVE-2026-88030 (Improper neutralization of special elements in data query logic in the ...)
 	- ruby-mongo 2.26.0-1 (bug #1147409)
 	[trixie] - ruby-mongo <no-dsa> (Minor issue)
+	[bookworm] - ruby-mongo <postponed> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/RUBY-3941
 	NOTE: Fixed by: https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d (v2.26.0)
 CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
@@ -6597,6 +6618,7 @@ CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop Conta
 CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template loading mec ...)
 	- libfreemarker-java <unfixed> (bug #1147516)
 	[trixie] - libfreemarker-java <no-dsa> (Minor issue)
+	[bookworm] - libfreemarker-java <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y
 CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted u ...)
 	NOT-FOR-US: BurgerEditor
@@ -6617,6 +6639,7 @@ CVE-2026-79522 (An out-of-bounds read in the gf_dm_get_chunk_data function (src/
 CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h)  ...)
 	- libstb <unfixed> (bug #1147725)
 	[trixie] - libstb <postponed> (Minor issue, revisit when fixed upstream)
+	[bookworm] - libstb <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/nothings/stb/issues/1963
 CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of nothings ...)
 	- libstb <unfixed> (unimportant)
@@ -6789,6 +6812,7 @@ CVE-2026-87927 (MaxSite CMS through 109.6 contains a local file inclusion vulner
 CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail to validate closed state in set ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-2jw3-mg7f-vw4q
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e (v1.5.7-14)
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)
@@ -6819,17 +6843,20 @@ CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose a
 CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936 (v1.5.7-14)
 CVE-2026-87824 (zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-257p-3h6w-pg7h
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/bba6cfca2c0897f1fa004f4193247479f10da853 (v1.5.7-14)
 CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f (v1.5.7-14)
 CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid means duri ...)
@@ -6872,6 +6899,7 @@ CVE-2026-87806 (Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 co
 CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
+	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb (v1.5.7-14)
 CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnera ...)
@@ -7379,16 +7407,19 @@ CVE-2026-87747 (The Enterprise Cloud Database developed by Ragic has an Arbitrar
 CVE-2026-87737 (An issue was discovered in the mirage-crypto-ec package before 2.4.0 f ...)
 	- ocaml-mirage-crypto 2.4.0-1
 	[trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
+	[bookworm] - ocaml-mirage-crypto <postponed> (Minor issue)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-17
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/1a61aeee7f593ec067612df1739ec905eab0450f (v2.4.0)
 CVE-2026-87736 (An issue was discovered in the mirage-crypto-ec package before 2.3.0 f ...)
 	- ocaml-mirage-crypto 2.3.0-1
 	[trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
+	[bookworm] - ocaml-mirage-crypto <postponed> (Minor issue)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-15
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/1f0bf67044e67cf6e46911fcd77a0ff706b6c3e7 (v2.3.0)
 CVE-2026-87735 (An issue was discovered in the mirage-crypto-pk package before 2.3.0 f ...)
 	- ocaml-mirage-crypto 2.3.0-1
 	[trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
+	[bookworm] - ocaml-mirage-crypto <postponed> (Minor issue)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-14
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/a0f59a0c90eb067505b55a03d3bb104eacd6dd33 (v2.3.0)
 CVE-2026-87734 (An issue was discovered in the utcp package before 0.0.6 for OCaml. Ou ...)
@@ -7396,11 +7427,13 @@ CVE-2026-87734 (An issue was discovered in the utcp package before 0.0.6 for OCa
 CVE-2026-87733 (An issue was discovered in the mirage-crypto-ec function before 2.2.0  ...)
 	- ocaml-mirage-crypto 2.2.0-1
 	[trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
+	[bookworm] - ocaml-mirage-crypto <postponed> (Minor issue)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-13
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/ca84f5ee8ede80bd1dd2aa4cd7cc90197752184e (v2.2.0)
 CVE-2026-87732 (An issue was discovered in the mirage-crypto package before 2.2.0 for  ...)
 	- ocaml-mirage-crypto 2.2.0-1
 	[trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
+	[bookworm] - ocaml-mirage-crypto <postponed> (Minor issue)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-12
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/25e7570aec91e092b347561c23f84b6ec39e7163 (v2.2.0)
 CVE-2026-87724 (Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_ ...)
@@ -8613,25 +8646,30 @@ CVE-2026-87049
 CVE-2026-86564 (A flaw was found in DPDK lib/vhost. Missing length validation before r ...)
 	- dpdk <unfixed> (bug #1147518)
 	[trixie] - dpdk <no-dsa> (Minor issue)
+	[bookworm] - dpdk <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529682
 CVE-2026-85630 (HTML::FormHandler versions before 0.410002 for Perl render field attri ...)
 	- libhtml-formhandler-perl 0.410002-1 (bug #1147198)
 	[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
+	[bookworm] - libhtml-formhandler-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387553/
 	NOTE: Fixed by: https://github.com/gshank/html-formhandler/commit/a887271e91d755e6486a9f433ae932deb1d2c4a6 (0.410002)
 CVE-2026-85485 (HTML::FormHandler versions before 0.410002 for Perl render some error  ...)
 	- libhtml-formhandler-perl 0.410002-1 (bug #1147198)
 	[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
+	[bookworm] - libhtml-formhandler-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387537/
 	NOTE: Fixed by: https://github.com/gshank/html-formhandler/commit/2ea9e138dbfe231e317c13936abe6583217c807f (0.410002)
 CVE-2026-85484 (HTML::FormHandler versions before 0.410002 for Perl render option grou ...)
 	- libhtml-formhandler-perl 0.410002-1 (bug #1147198)
 	[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
+	[bookworm] - libhtml-formhandler-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387507/
 	NOTE: Fixed by: https://github.com/gshank/html-formhandler/commit/49b562e0fed5146fc1a372c5fa8a879876b8841d (0.410002)
 CVE-2026-19872 (HTML::FormHandler versions before 0.410000 for Perl allow cross-site s ...)
 	- libhtml-formhandler-perl 0.410002-1 (bug #1147198)
 	[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
+	[bookworm] - libhtml-formhandler-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387502/
 	NOTE: Fixed by: https://github.com/gshank/html-formhandler/commit/2574fdb4561f5c32d44cfbfbb3188345d49eb5a2 (0.410000)
 CVE-2026-9331 (The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is  ...)
@@ -9396,6 +9434,7 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remo
 CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts user-supplied ZIP a ...)
 	- gnome-tweaks <unfixed> (bug #1147509)
 	[trixie] - gnome-tweaks <no-dsa> (Minor issue)
+	[bookworm] - gnome-tweaks <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gnome-tweaks/-/issues/542
 CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability in the s ...)
 	NOT-FOR-US: XenForo
@@ -12418,6 +12457,7 @@ CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redir
 CVE-2026-86098 (ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerabi ...)
 	- ndpi <unfixed> (bug #1146882)
 	[trixie] - ndpi <no-dsa> (Minor issue)
+	[bookworm] - ndpi <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/ntop/nDPI/commit/94e82c1de12323d992895830231865736a8abf2c (6.0)
 CVE-2026-86097 (PX4 Autopilot through 1.17.0 contains a null pointer dereference vulne ...)
 	NOT-FOR-US: PX4 Autopilot
@@ -12428,6 +12468,7 @@ CVE-2026-86095 (Unidata netcdf-c through 4.10.1 contains an out-of-bounds write
 	[trixie] - netcdf <no-dsa> (Minor issue)
 	- netcdf-parallel <unfixed>
 	[trixie] - netcdf-parallel <no-dsa> (Minor issue)
+	[bookworm] - netcdf-parallel <postponed> (Minor issue)
 CVE-2026-86091 (ntopng before 6.7.260717 fails to check user privileges in the pools b ...)
 	- ntopng <removed>
 CVE-2026-86090 (ntopng before 6.7.260717 fails to perform authorization checks in the  ...)
@@ -13978,6 +14019,7 @@ CVE-2026-80761 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-90556 (Freeciv versions before 3.2.6 contain a heap buffer overflow in workli ...)
 	- freeciv 3.2.6+ds-1
 	[trixie] - freeciv <no-dsa> (Minor issue)
+	[bookworm] - freeciv <end-of-life> (Games are not supported in LTS)
 	NOTE: https://redmine.freeciv.org/issues/2161
 CVE-2026-90557 (Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vul ...)
 	- freeciv 3.2.6+ds-1 (unimportant)
@@ -14670,6 +14712,7 @@ CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. In
 CVE-2026-84971 (Improper handling of an unexpected value size in the decryption path o ...)
 	- libmongocrypt 1.20.4-1
 	[trixie] - libmongocrypt <no-dsa> (Minor issue)
+	[bookworm] - libmongocrypt <postponed> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-971
 CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing component of  ...)
 	- mongo-cxx-driver 4.5.2-1
@@ -14709,6 +14752,7 @@ CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of
 CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
 	- libmongocrypt 1.20.2-1
 	[trixie] - libmongocrypt <no-dsa> (Minor issue)
+	[bookworm] - libmongocrypt <postponed> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-960
 CVE-2026-84888 (A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Th ...)
 	NOT-FOR-US: RightNow-AI OpenFang
@@ -14930,30 +14974,36 @@ CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path d
 CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The metadata w ...)
 	- gfs2-utils <unfixed> (bug #1146712)
 	[trixie] - gfs2-utils <no-dsa> (Minor issue)
+	[bookworm] - gfs2-utils <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
 	TODO: check upstream details
 CVE-2026-71223
 	- gfs2-utils <unfixed> (bug #1146712)
 	[trixie] - gfs2-utils <no-dsa> (Minor issue)
+	[bookworm] - gfs2-utils <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511400
 CVE-2026-71222 (A heap out-of-bounds read vulnerability was found in gfs2-utils. The e ...)
 	- gfs2-utils <unfixed> (bug #1146712)
 	[trixie] - gfs2-utils <no-dsa> (Minor issue)
+	[bookworm] - gfs2-utils <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511399
 	TODO: check upstream details
 CVE-2026-71221 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
 	- gfs2-utils <unfixed> (bug #1146712)
 	[trixie] - gfs2-utils <no-dsa> (Minor issue)
+	[bookworm] - gfs2-utils <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511396
 	TODO: check upstream details
 CVE-2026-71220 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
 	- gfs2-utils <unfixed> (bug #1146712)
 	[trixie] - gfs2-utils <no-dsa> (Minor issue)
+	[bookworm] - gfs2-utils <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511398
 	TODO: check upstream details
 CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The hash table ...)
 	- gfs2-utils <unfixed> (bug #1146712)
 	[trixie] - gfs2-utils <no-dsa> (Minor issue)
+	[bookworm] - gfs2-utils <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507750
 	TODO: check upstream details
 CVE-2026-6071 (A remote code execution security issue exists in the affected products ...)
@@ -15511,6 +15561,7 @@ CVE-2026-79754 (Nuclio is a "Serverless" framework for Real-Time Events and Data
 CVE-2026-78689 (Description   NGINX JavaScript (njs) has a vulnerability in the XML mo ...)
 	- libnginx-mod-js 1.0.1-1
 	[trixie] - libnginx-mod-js <no-dsa> (Minor issue)
+	[bookworm] - libnginx-mod-js <postponed> (Minor issue)
 	NOTE: https://my.f5.com/manage/s/article/K000162602
 	NOTE: Fixed by: https://github.com/nginx/njs/commit/1308b320821aa209a7985cc8f52c09a515130ba6 (1.0.1)
 	NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
@@ -15557,6 +15608,7 @@ CVE-2026-78408 (The nsenter --join-cgroup option opens the target cgroup.procs f
 CVE-2026-78222 (A vulnerability exists in NGINX JavaScript where a malformed HTTP resp ...)
 	- libnginx-mod-js 1.0.1-1
 	[trixie] - libnginx-mod-js <no-dsa> (Minor issue)
+	[bookworm] - libnginx-mod-js <postponed> (Minor issue)
 	NOTE: https://my.f5.com/manage/s/article/K000162603
 	NOTE: https://github.com/nginx/njs/commit/a62feb4831e75c75c446298ca4a23862dcfcbab4 (1.0.1)
 	NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
@@ -16633,18 +16685,21 @@ CVE-2026-83619 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83618 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-vr34-hp96-76pp
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362 (0.9.12)
 CVE-2026-83617 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-jxjr-3g7g-3944
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362 (0.9.12)
 CVE-2026-83616 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
@@ -16653,6 +16708,7 @@ CVE-2026-83616 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83615 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
@@ -16661,6 +16717,7 @@ CVE-2026-83615 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83614 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
@@ -16669,6 +16726,7 @@ CVE-2026-83614 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83613 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
@@ -16677,12 +16735,14 @@ CVE-2026-83613 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83612 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-6mj3-qw4j-hgrw
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/7ced40c06c28d151e996a97045018c3559ae4707 (0.9.12)
 CVE-2026-83611 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
@@ -16691,6 +16751,7 @@ CVE-2026-83611 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83610 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
@@ -16699,12 +16760,14 @@ CVE-2026-83610 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83609 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-3px3-54cx-rmw9
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362 (0.9.12)
 CVE-2026-83608 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.12-1 (bug #1146473)
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv
 	NOTE: https://github.com/xmldom/xmldom/pull/1071
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
@@ -16713,6 +16776,7 @@ CVE-2026-83608 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83607 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.11-1
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj
 	NOTE: https://github.com/xmldom/xmldom/pull/1043
 	NOTE: https://github.com/xmldom/xmldom/pull/1050
@@ -16721,12 +16785,14 @@ CVE-2026-83607 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2
 CVE-2026-83606 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.11-1
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-g53g-w8rj-fmg7
 	NOTE: https://github.com/xmldom/xmldom/pull/1039
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/73df6b8bdbd86f904b9e8c3ab9c49aa54ef2802e (0.9.11)
 CVE-2026-83605 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.11-1
 	[trixie] - node-xmldom <no-dsa> (Minor issue)
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm
 	NOTE: https://github.com/xmldom/xmldom/pull/1043
 	NOTE: https://github.com/xmldom/xmldom/pull/1050
@@ -17497,8 +17563,10 @@ CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote au
 CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
 	- smarty4 <unfixed>
 	[trixie] - smarty4 <no-dsa> (Minor issue)
+	[bookworm] - smarty4 <postponed> (Minor issue)
 	- smarty3 <unfixed>
 	[trixie] - smarty3 <no-dsa> (Minor issue)
+	[bookworm] - smarty3 <postponed> (Minor issue)
 	NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-cq55-c7wv-pxmq
 	NOTE: https://github.com/smarty-php/smarty/pull/1194
 	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/31e06fc087a8b5a9b236c1e5dacc1c2850a2c115 (v5.8.2)
@@ -24633,6 +24701,7 @@ CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed through
 CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
 CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:rea ...)
 	NOT-FOR-US: Ech0
@@ -24669,6 +24738,7 @@ CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on the
 CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution vulnerabil ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw
 CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos package. This  ...)
 	- sos <unfixed> (bug #1145981)
@@ -25275,18 +25345,22 @@ CVE-2026-78685 (Medical Practice Management System developed by Le-yan has a Rem
 CVE-2026-78683 (NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pick ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-rhp5-r9x4-f5g2
 CVE-2026-78682 (NLTK before 3.10.3 contains a server-side request forgery vulnerabilit ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6ww7-3frv-cqxh
 CVE-2026-78681 (NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in  ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-97qj-x29f-37w7
 CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute paths when  ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6hwm-xvph-95vm
 CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read vulnerability  ...)
 	- python-git 3.1.61-1 (bug #1145672)
@@ -26156,11 +26230,13 @@ CVE-2026-12554 (Potential security vulnerabilities have been identified in HP Ea
 CVE-2026-10618 (Hugo's default fenced-code-block renderer writes attribute values take ...)
 	- hugo <unfixed> (bug #1146720)
 	[trixie] - hugo <no-dsa> (Minor issue)
+	[bookworm] - hugo <postponed> (Minor issue)
 	NOTE: https://github.com/gohugoio/hugo/issues/15247
 	NOTE: https://github.com/gohugoio/hugo/commit/e4dc48cf7f8e06fc1e7e4c290dccc7c35d881c55
 CVE-2026-10582 (Hugo's security.http.urls allowlist is the only control on outbound fe ...)
 	- hugo <unfixed> (bug #1146720)
 	[trixie] - hugo <no-dsa> (Minor issue)
+	[bookworm] - hugo <postponed> (Minor issue)
 	NOTE: https://github.com/gohugoio/hugo/issues/15247
 	NOTE: https://github.com/gohugoio/hugo/commit/d6e6f9e500eebdeae8e28de830fff2e3bfc7d534
 CVE-2025-68833 (HCL Hive Keycloak IAM Instance is affected by insufficient granularity ...)
@@ -26322,14 +26398,17 @@ CVE-2026-75866 (Punk::OAuth2::Server versions through 0.03 for Perl issue access
 CVE-2026-71514 (NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in C ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/nltk/nltk/commit/10d34b3f4fe3fec74b76527a409eb0acbac2e8ab (v3.10.3-rc1)
 CVE-2026-71513 (NLTK before 3.10.3 contains a remote code execution vulnerability in A ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea (v3.10.3-rc1)
 CVE-2026-70626 (NLTK versions before 3.9.4 contain a symlink escape vulnerability in C ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9
 CVE-2026-6258
 	REJECTED
@@ -26361,37 +26440,45 @@ CVE-2026-66916 (Joomla Extension - joomgalleryfriends.net - Password-Protected C
 CVE-2026-66393 (NLTK versions before 3.9.4 contain an unbounded recursion vulnerabilit ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw
 CVE-2026-65915 (NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPoint ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9
 CVE-2026-63312 (NLTK before 3.10.0 contains an arbitrary local file read vulnerability ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8
 CVE-2026-63311 (NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gqm-fcw5-w839
 CVE-2026-63310
 	REJECTED
 CVE-2026-62388 (NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, ca ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3
 CVE-2026-62385 (NLTK versions before 3.10.0 contain a path traversal vulnerability in  ...)
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4
 CVE-2026-62384 (NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in  ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv
 	NOTE: CVE exists because it is possible to bypass the fix for CVE-2026-12074
 CVE-2026-62383 (nltk versions before 3.10.2 contain a symlink-based arbitrary file rea ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6
 CVE-2026-62382 (PasswordPusher versions v1.45.11 through v2.9.5 contain an improper au ...)
 	NOT-FOR-US: PasswordPusher
@@ -27598,6 +27685,7 @@ CVE-2026-72843 (The customer update route in EverShop is declared with "access":
 CVE-2026-72818 (The URLS regular expression in nltk/tokenize/casual.py, compiled into  ...)
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/issues/3704
 	NOTE: Fixed by: https://github.com/nltk/nltk/commit/7808692d451b962711005d954859bb83aabcf8fa (v3.10.3-rc1)
 CVE-2026-71862 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
@@ -33481,6 +33569,7 @@ CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for mach
 CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
 	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
+	[bookworm] - rabbitmq-java-client <postponed> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-pxv4-2wfj
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2000
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e96232ae7efa75ea4fa8 (main)
@@ -33489,6 +33578,7 @@ CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based appli
 CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
 	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
+	[bookworm] - rabbitmq-java-client <postponed> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1999
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01 (main)
@@ -33497,6 +33587,7 @@ CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based appli
 CVE-2026-63335 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
 	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
+	[bookworm] - rabbitmq-java-client <postponed> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-qx7j-jv8m-fppr
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1959
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/31735344d9f9dfc53740b67f06e560e8846b9322 (main)
@@ -33513,6 +33604,7 @@ CVE-2026-61696 (Forem is open source software for building communities. In versi
 CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
 	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
+	[bookworm] - rabbitmq-java-client <postponed> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1994
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591 (main)
@@ -40171,10 +40263,12 @@ CVE-2026-XXXX [RUSTSEC-2026-0221]
 CVE-2026-12876
 	- nltk <unfixed> (bug #1144456)
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf
 CVE-2026-12841
 	- nltk 3.10.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 CVE-2026-XXXX [RUSTSEC-2026-0257]
 	- rust-webbrowser <unfixed> (bug #1144396)
 	[trixie] - rust-webbrowser <no-dsa> (Minor issue)
@@ -42743,14 +42837,17 @@ CVE-2026-77648 (In OpenStack Glance through 32.0.0, the /v2/tasks API accepts ty
 CVE-2026-12061
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-fg7f-2386-8897
 CVE-2026-12072
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6hm5-jgcp-p838
 CVE-2026-12074
 	- nltk 3.10.0-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-xh95-f55m-82fw
 CVE-2026-68868 (The Google Cloud Secret Manager secrets backend in Apache Airflow's Go ...)
 	NOT-FOR-US: Apache Airflow provider
@@ -45255,18 +45352,22 @@ CVE-2026-XXXX [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses pa
 CVE-2026-73141 [GHSA-xmcv-mjpv-x46q: Audio decoders: stack VLA exhaustion]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-xmcv-mjpv-x46q
 CVE-2026-73142 [GHSA-5xr9-fmm8-7p8x: remotetrx NetUplink: connection object leak DoS]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5xr9-fmm8-7p8x
 CVE-2026-73143 [GHSA-38fq-mrrg-8rmr: RtlTcp: malformed greeting causes daemon exit]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-38fq-mrrg-8rmr
 CVE-2026-73144 [GHSA-qccg-7pw6-787v: FRN module: unbounded memory growth]
 	- svxlink 26.05.1-1
 	[trixie] - svxlink <no-dsa> (Minor issue)
+	[bookworm] - svxlink <postponed> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-qccg-7pw6-787v
 CVE-2026-73145 [GHSA-58ph-q79f-7x9x: HTTP server: unbounded request accumulation]
 	- svxlink 26.05.1-1
@@ -48361,6 +48462,7 @@ CVE-2026-12570 (A vulnerability in keras-team/keras versions <= 3.15.0 allows fo
 CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk ...)
 	- nltk <unfixed> (bug #1144456)
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513003
 CVE-2026-70395 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
 	NOT-FOR-US: ash-project ash
@@ -49632,6 +49734,7 @@ CVE-2026-12501 (The WP Travel Engine WordPress plugin before 6.8.2 does not veri
 CVE-2026-12261 (A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 al ...)
 	- nltk <unfixed> (bug #1144456)
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://huntr.com/bounties/8b8c381e-08a8-4e4f-bb46-a320c96a364f
 CVE-2026-11976 (The official MonsterInsights Pro update distribution bucket (`monster- ...)
 	NOT-FOR-US: WordPress plugin
@@ -52626,6 +52729,7 @@ CVE-2026-15430 (Improper access control in the IRP_MJ_WRITE command interface in
 CVE-2026-12259 (In nltk version 3.9.4, the `nltk.downloader.Downloader._download_packa ...)
 	- nltk <unfixed> (bug #1144456)
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://huntr.com/bounties/659ccf6d-12d4-4d4a-84c0-078633c35a5d
 CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0 retrieve ...)
 	NOT-FOR-US: Latvijas Valsts radio un televizijas centrs (LVRTC)
@@ -60753,6 +60857,7 @@ CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for WordP
 CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval  ...)
 	- nltk 3.9.3-1
 	[trixie] - nltk <no-dsa> (Minor issue)
+	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/
 	NOTE: https://github.com/nltk/nltk/pull/3465
 	NOTE: Fixed by: https://github.com/nltk/nltk/commit/e373c8c3d10e236672ef65c38ca7d24612941553 (3.9.3)
@@ -180217,6 +180322,7 @@ CVE-2026-22776 (cpp-httplib is a C++11 single-file header-only cross platform HT
 	[experimental] - cpp-httplib 0.41.0+ds-1
 	- cpp-httplib 0.41.0+ds-3 (bug #1126754)
 	[trixie] - cpp-httplib <no-dsa> (Minor issue)
+	[bookworm] - cpp-httplib <postponed> (Minor issue)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h934-98h4-j43q
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/2e2e47bab1ae6a853476eecbc4bf279dd1fef792 (0.30.1)
 CVE-2026-22771 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/abb39fa5297afa9a06ab8364bd648712d2a93080

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/abb39fa5297afa9a06ab8364bd648712d2a93080
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/e60faeaa/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list