[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 16 18:26:24 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4e4f9316 by Moritz Muehlenhoff at 2026-09-16T19:25:16+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -354,11 +354,12 @@ CVE-2026-91825 (Affected versions of MISP fail to authorize a submitted sharing
CVE-2026-91819 (Affected versions of MISP rely on CakePHP request-method override proc ...)
- misp <itp> (bug #1144317)
CVE-2026-91786 (A flaw was found in GNOME Shell. When processing icons from a remote s ...)
- - gnome-shell <unfixed>
+ - gnome-shell <unfixed> (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/9365
NOTE: https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/4418
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gnome-shell/-/commit/8a3f208d0123b4831b1a4ba1040acc4f9091d465 (51.0)
NOTE: https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/4417 (backports for 50.5)
+ NOTE: Crash in GUI component, marginal security impact
CVE-2026-91782 (A vulnerability was detected in GNU Binutils 2.47. Affected by this vu ...)
- binutils <unfixed> (unimportant)
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34448
@@ -426,11 +427,13 @@ CVE-2026-87730
REJECTED
CVE-2026-86818 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by ...)
- node-ajv <unfixed>
+ [trixie] - node-ajv <no-dsa> (Minor issue)
[bookworm] - node-ajv <not-affected> (fast-uri not present)
NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-jvvf-x445-j334
CVE-2026-86472 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by ...)
- node-ajv <unfixed>
+ [trixie] - node-ajv <no-dsa> (Minor issue)
[bookworm] - node-ajv <not-affected> (fast-uri not present)
NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj
@@ -490,9 +493,11 @@ CVE-2026-80217 (Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4
NOT-FOR-US: LITE-ON
CVE-2026-79705 (A flaw was found in the buildah/copier Go package. When used outside o ...)
- golang-github-containers-buildah <unfixed>
+ [trixie] - golang-github-containers-buildah <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523419
CVE-2026-79699 (A flaw was found in the containers/storage library. A crafted tar arch ...)
- golang-github-containers-storage <unfixed>
+ [trixie] - golang-github-containers-storage <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523408
CVE-2026-79551 (Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to ...)
NOT-FOR-US: Tenda
@@ -780,6 +785,7 @@ CVE-2026-55770 (OpenBao is an open source identity-based secrets management syst
- openbao <itp> (bug #1069794)
CVE-2026-55701 (The OpenTelemetry Collector Contrib repository contains components for ...)
- golang-opentelemetry-contrib <unfixed>
+ [trixie] - golang-opentelemetry-contrib <no-dsa> (Minor issue)
NOTE: https://github.com/open-telemetry/opentelemetry-collector-contrib/security/advisories/GHSA-w5cv-pw74-4rxc
NOTE: https://github.com/open-telemetry/opentelemetry-collector-contrib/pull/47854
NOTE: https://github.com/open-telemetry/opentelemetry-collector-contrib/commit/54143ccd14f5ebd74ca741739d2099c7fbebbd98 (v0.151.0)
@@ -2193,6 +2199,7 @@ CVE-2026-17628 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authe
NOT-FOR-US: IBM
CVE-2026-17495 (moment is a JavaScript date library for parsing, validating, manipulat ...)
- node-moment <unfixed>
+ [trixie] - node-moment <no-dsa> (Minor issue)
NOTE: https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw
CVE-2026-17467 (IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a rem ...)
NOT-FOR-US: IBM
@@ -2840,6 +2847,7 @@ CVE-2026-49250 (Conform, a type-safe form validation library, allows the parsing
TODO: check
CVE-2026-47256 (OpenTelemetry, also known as OTel, is a vendor-neutral open source Obs ...)
- golang-opentelemetry-contrib <unfixed>
+ [trixie] - golang-opentelemetry-contrib <no-dsa> (Minor issue)
NOTE: https://github.com/open-telemetry/opentelemetry-collector-contrib/security/advisories/GHSA-4jvg-4jfx-fmhc
NOTE: https://github.com/open-telemetry/opentelemetry-collector-contrib/commit/3113638f216143f523b57f447728464337ae4903 (v0.154.0)
CVE-2026-46696 (October System provides the system module for October Content Manageme ...)
@@ -11830,6 +11838,7 @@ CVE-2026-18355 (A heap buffer overflow flaw was found in the SASL I/O layer of 3
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509186
CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion ...)
- libprotocol-http2-perl 1.14-1 (bug #1147222)
+ [trixie] - libprotocol-http2-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43351225/
NOTE: Fixed by: https://github.com/vlet/p5-Protocol-HTTP2/commit/27a488a34d74fd16f123e5e6186d4f677faa246f (1.14)
CVE-2026-14444 (The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Es ...)
@@ -11999,6 +12008,7 @@ CVE-2026-86232 (A weakness has been identified in itsourcecode Sales and Invento
NOT-FOR-US: itsourcecode System
CVE-2026-86231 (A security flaw has been discovered in mwiede jsch up to 2.28.5. Affec ...)
- jsch <unfixed>
+ [trixie] - jsch <no-dsa> (Minor issue)
NOTE: https://github.com/mwiede/jsch/issues/1091
NOTE: https://github.com/mwiede/jsch/pull/1098
NOTE: Fixed by: https://github.com/mwiede/jsch/commit/194a2f76a5c0f1c3f778565be3fd66bcafc42d23 (jsch-2.28.6)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e4f93162bc6cb0f037cd1835bef1fb47b2eacd9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e4f93162bc6cb0f037cd1835bef1fb47b2eacd9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/0321e8d0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list