[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2026-90711/node-proxy-addr: bookworm postponed

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Thu Sep 17 15:16:11 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
00c466ad by Sylvain Beucler at 2026-09-17T16:16:00+02:00
CVE-2026-90711/node-proxy-addr: bookworm postponed

- - - - -
b92d82b9 by Sylvain Beucler at 2026-09-17T16:16:02+02:00
CVE-2026-84308/php-phpseclib3: bookworm postponed

- - - - -
72352a74 by Sylvain Beucler at 2026-09-17T16:16:03+02:00
lts: add network-manager-iodine

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -5461,6 +5461,7 @@ CVE-2026-90812 (A security vulnerability has been detected in cosmicstack-labs m
 CVE-2026-90711 (proxy-addr is a Node.js module that determines a request's client addr ...)
 	- node-proxy-addr 2.0.8+~cs2.3.7-1
 	[trixie] - node-proxy-addr <no-dsa> (Minor issue)
+	[bookworm] - node-proxy-addr <postponed> (Minor issue)
 	NOTE: https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h
 CVE-2026-89141 (The AI Engine \u2013 The Chatbot, AI Framework & MCP for WordPress plu ...)
 	NOT-FOR-US: WordPress plugin
@@ -19900,6 +19901,7 @@ CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 3.0.5
 	- php-phpseclib4 4.0.1-1
 	- php-phpseclib3 3.0.57-1
 	[trixie] - php-phpseclib3 <no-dsa> (Minor issue)
+	[bookworm] - php-phpseclib3 <postponed> (Minor issue, local side-channel attack)
 	- php-phpseclib <not-affected> (Vulnerable code not present)
 	- phpseclib <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6


=====================================
data/dla-needed.txt
=====================================
@@ -425,7 +425,11 @@ netty (rouca)
 --
 network-manager-fortisslvpn
   NOTE: 20260917: Added by Front-Desk (Beuc)
-  NOTE: 20260917: LPE; package only present in LTS (Beuc/front-desk)
+  NOTE: 20260917: LPE; package only present in LTS. Dead upstream, reporter suggests
+  NOTE: 20260917: migrating to NetworkManager-openconnect, we could EOL (Beuc/front-desk)
+--
+network-manager-iodine
+  NOTE: 20260917: Added by Front-Desk (Beuc)
 --
 network-manager-l2tp
   NOTE: 20260915: Added by Front-Desk (Beuc)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/330659caaea8656e9358afd6b57f143a1d14e22b...72352a74856275ef82e8a2a66d98b25c21895898

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/330659caaea8656e9358afd6b57f143a1d14e22b...72352a74856275ef82e8a2a66d98b25c21895898
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/1a02b851/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list