[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2026-90711/node-proxy-addr: bookworm postponed
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Thu Sep 17 15:16:11 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
00c466ad by Sylvain Beucler at 2026-09-17T16:16:00+02:00
CVE-2026-90711/node-proxy-addr: bookworm postponed
- - - - -
b92d82b9 by Sylvain Beucler at 2026-09-17T16:16:02+02:00
CVE-2026-84308/php-phpseclib3: bookworm postponed
- - - - -
72352a74 by Sylvain Beucler at 2026-09-17T16:16:03+02:00
lts: add network-manager-iodine
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -5461,6 +5461,7 @@ CVE-2026-90812 (A security vulnerability has been detected in cosmicstack-labs m
CVE-2026-90711 (proxy-addr is a Node.js module that determines a request's client addr ...)
- node-proxy-addr 2.0.8+~cs2.3.7-1
[trixie] - node-proxy-addr <no-dsa> (Minor issue)
+ [bookworm] - node-proxy-addr <postponed> (Minor issue)
NOTE: https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h
CVE-2026-89141 (The AI Engine \u2013 The Chatbot, AI Framework & MCP for WordPress plu ...)
NOT-FOR-US: WordPress plugin
@@ -19900,6 +19901,7 @@ CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 3.0.5
- php-phpseclib4 4.0.1-1
- php-phpseclib3 3.0.57-1
[trixie] - php-phpseclib3 <no-dsa> (Minor issue)
+ [bookworm] - php-phpseclib3 <postponed> (Minor issue, local side-channel attack)
- php-phpseclib <not-affected> (Vulnerable code not present)
- phpseclib <not-affected> (Vulnerable code not present)
NOTE: https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6
=====================================
data/dla-needed.txt
=====================================
@@ -425,7 +425,11 @@ netty (rouca)
--
network-manager-fortisslvpn
NOTE: 20260917: Added by Front-Desk (Beuc)
- NOTE: 20260917: LPE; package only present in LTS (Beuc/front-desk)
+ NOTE: 20260917: LPE; package only present in LTS. Dead upstream, reporter suggests
+ NOTE: 20260917: migrating to NetworkManager-openconnect, we could EOL (Beuc/front-desk)
+--
+network-manager-iodine
+ NOTE: 20260917: Added by Front-Desk (Beuc)
--
network-manager-l2tp
NOTE: 20260915: Added by Front-Desk (Beuc)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/330659caaea8656e9358afd6b57f143a1d14e22b...72352a74856275ef82e8a2a66d98b25c21895898
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/330659caaea8656e9358afd6b57f143a1d14e22b...72352a74856275ef82e8a2a66d98b25c21895898
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/1a02b851/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list