[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 20:14:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
65dc8426 by security tracker role at 2026-09-18T19:13:57+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,17 +1,613 @@
+CVE-2026-93854 (In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce o ...)
+ TODO: check
+CVE-2026-93852 (In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET ...)
+ TODO: check
+CVE-2026-93765 (Mongoid contains an unsafe reflection weakness in the document persist ...)
+ TODO: check
+CVE-2026-93764 (Mongoid may omit encryption rules for fields declared on embedded mode ...)
+ TODO: check
+CVE-2026-93763 (A protection mechanism failure in the object-document mapper's encrypt ...)
+ TODO: check
+CVE-2026-93762 (Mongoid contains an unsafe reflection weakness in the query path used ...)
+ TODO: check
+CVE-2026-93761 (An inefficient regular expression complexity issue in the in-memory qu ...)
+ TODO: check
+CVE-2026-93760 (Mongoid does not restrict which query operators may come from caller-s ...)
+ TODO: check
+CVE-2026-93759 (Mongoid does not neutralize a string-typed query criterion supplied to ...)
+ TODO: check
+CVE-2026-93758 (An insecure direct object reference in the nested attributes handling ...)
+ TODO: check
+CVE-2026-93753 (deepmerge through 4.3.1 contains a prototype poisoning vulnerability i ...)
+ TODO: check
+CVE-2026-93752 (CSSOM through 0.5.0 contains a denial of service vulnerability in CSSS ...)
+ TODO: check
+CVE-2026-93751 (uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability ...)
+ TODO: check
+CVE-2026-93750 (http-cache-semantics through 4.2.0 contains a cache validation vulnera ...)
+ TODO: check
+CVE-2026-93749 (source-map-js through 1.2.1 fails to validate the per-section offset l ...)
+ TODO: check
+CVE-2026-93748 (http-cache-semantics through 4.2.0 fails to properly validate security ...)
+ TODO: check
+CVE-2026-93737 (Azkaban through 4.0.0 omits project permission checks in the ScheduleS ...)
+ TODO: check
+CVE-2026-93736 (Mealie before 3.21.0 fails to validate user ownership in the ratings a ...)
+ TODO: check
+CVE-2026-93690 (uri-js through 4.4.1 contains a denial of service vulnerability in the ...)
+ TODO: check
+CVE-2026-93689 (WinFsp through 2.2.26215 contains a null pointer dereference vulnerabi ...)
+ TODO: check
+CVE-2026-93688 (SGLang through 0.5.19 in prefill/decode disaggregation mode with Moonc ...)
+ TODO: check
+CVE-2026-93687 (braces through 3.0.3 contains a stack overflow vulnerability in the re ...)
+ TODO: check
+CVE-2026-93685 (A flaw was found in the multicluster-observability-addon. A remote att ...)
+ TODO: check
+CVE-2026-93676 (xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing ...)
+ TODO: check
+CVE-2026-93660 (SQLBot through 1.10.1 fails to verify dashboard ownership in update_re ...)
+ TODO: check
+CVE-2026-93659 (Concrete CMS Community Store before 2.7.8 renders customer-supplied or ...)
+ TODO: check
+CVE-2026-93658 (uutils coreutils versions before 0.10.0 apply setuid or setgid mode to ...)
+ TODO: check
+CVE-2026-93657 (hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC ...)
+ TODO: check
+CVE-2026-93653 (A denial of service flaw was found in Poppler's Splash backend. A craf ...)
+ TODO: check
+CVE-2026-93652 (Integer overflow in \xb5D3TN v0.15.0 TCPCLv3 handshake causes heap ove ...)
+ TODO: check
+CVE-2026-93650 (A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.4 ...)
+ TODO: check
+CVE-2026-93606 (vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` ...)
+ TODO: check
+CVE-2026-93605 (vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerabili ...)
+ TODO: check
+CVE-2026-93604 (vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untr ...)
+ TODO: check
+CVE-2026-93603 (vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nulli ...)
+ TODO: check
+CVE-2026-93602 (rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain fau ...)
+ TODO: check
+CVE-2026-93601 (rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101. ...)
+ TODO: check
+CVE-2026-93600 (rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0. ...)
+ TODO: check
+CVE-2026-93599 (rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.10 ...)
+ TODO: check
+CVE-2026-93598 (ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 ...)
+ TODO: check
+CVE-2026-93597 (ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addre ...)
+ TODO: check
+CVE-2026-93596 (ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails ...)
+ TODO: check
+CVE-2026-93595 (ArcadeDB before 26.9.1 contains an access control bypass vulnerability ...)
+ TODO: check
+CVE-2026-93594 (ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 ...)
+ TODO: check
+CVE-2026-93593 (ArcadeDB before 26.9.1 fails to enforce security-group types ACL entri ...)
+ TODO: check
+CVE-2026-93592 (vLLM versions before 0.28.0 fail to validate the lower bound of token ...)
+ TODO: check
+CVE-2026-93591 (SiYuan versions before 3.8.3 contain an SQL injection vulnerability in ...)
+ TODO: check
+CVE-2026-93590 (ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in ...)
+ TODO: check
+CVE-2026-93589 (ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero ...)
+ TODO: check
+CVE-2026-93588 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL point ...)
+ TODO: check
+CVE-2026-93587 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy byp ...)
+ TODO: check
+CVE-2026-93586 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after- ...)
+ TODO: check
+CVE-2026-93579 (A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a ...)
+ TODO: check
+CVE-2026-93578 (A flaw was found in Netty's Online Certificate Status Protocol (OCSP) ...)
+ TODO: check
+CVE-2026-93576 (Netty netty-codec-smtp \u2014 SMTP command-name field is not CRLF-vali ...)
+ TODO: check
+CVE-2026-93575 (### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder ...)
+ TODO: check
+CVE-2026-93573 (Netty split Transfer-Encoding fields bypass final-chunked validation a ...)
+ TODO: check
+CVE-2026-93572 (## Summary `RedisArrayAggregator` recently added `maxElements` and `m ...)
+ TODO: check
+CVE-2026-93569 (HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, ...)
+ TODO: check
+CVE-2026-93568 (HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular ...)
+ TODO: check
+CVE-2026-93567 (HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNEC ...)
+ TODO: check
+CVE-2026-93566 (### Summary Netty skips strict chunk size line validation when the lin ...)
+ TODO: check
+CVE-2026-93565 (### Summary `RtspMethods.valueOf()` silently strips trailing control b ...)
+ TODO: check
+CVE-2026-93564 (HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (i ...)
+ TODO: check
+CVE-2026-93563 (Unbounded multi-line response accumulation in SmtpResponseDecoder lead ...)
+ TODO: check
+CVE-2026-93561 (Memcache binary codec signed/unsigned type mismatch causes frame desyn ...)
+ TODO: check
+CVE-2026-93560 (STOMP codec content-length long-to-int truncation causes infinite deco ...)
+ TODO: check
+CVE-2026-93559 (A vulnerability was identified in Forget-C Jellyfish AI Short Drama St ...)
+ TODO: check
+CVE-2026-93558 (Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandl ...)
+ TODO: check
+CVE-2026-93534 (A vulnerability was identified in spatie Scotty up to 1.4.2. Affected ...)
+ TODO: check
+CVE-2026-93533 (A vulnerability was determined in spatie Scotty up to 1.4.4. This impa ...)
+ TODO: check
+CVE-2026-93532 (A security vulnerability has been detected in gedelumbung HospitalMana ...)
+ TODO: check
+CVE-2026-93531 (A weakness has been identified in gedelumbung HospitalManagement up to ...)
+ TODO: check
+CVE-2026-93506 (A vulnerability was determined in SveltyCMS 0.0.6. This issue affects ...)
+ TODO: check
+CVE-2026-93505 (A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affec ...)
+ TODO: check
+CVE-2026-93504 (A vulnerability has been found in SveltyCMS 0.0.6. This affects an unk ...)
+ TODO: check
+CVE-2026-93494 (A flaw was found in Netty's StompSubframeDecoder component. A remote a ...)
+ TODO: check
+CVE-2026-93493 (A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remo ...)
+ TODO: check
+CVE-2026-93492 (A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can ...)
+ TODO: check
+CVE-2026-93491 (A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated ...)
+ TODO: check
+CVE-2026-93488 (A flaw was found in Netty. SpdySessionHandler accepts an unlimited num ...)
+ TODO: check
+CVE-2026-93432 (A flaw was found in the Quarkus Qute template engine. When the {#eval} ...)
+ TODO: check
+CVE-2026-93338 (Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an in ...)
+ TODO: check
+CVE-2026-92976 (A stored Cross-Site Scripting (XSS) vulnerability in the profile manag ...)
+ TODO: check
+CVE-2026-92768 (A flaw was found in cockpit-machines. This vulnerability allows a loca ...)
+ TODO: check
+CVE-2026-92747 (A flaw was found in `cockpit-machines`. This vulnerability allows a lo ...)
+ TODO: check
+CVE-2026-92745 (A flaw was found in cockpit-machines. This vulnerability allows a loca ...)
+ TODO: check
+CVE-2026-92702 (Cocos AI is a confidential computing system for running AI workloads i ...)
+ TODO: check
+CVE-2026-92701 (trusted execution environments. In versions up to and including 0.8.2, ...)
+ TODO: check
+CVE-2026-92622 (The Strong Testimonials plugin for WordPress is vulnerable to Stored C ...)
+ TODO: check
+CVE-2026-92554 (The ShopLentor \u2013 All-in-One WooCommerce Growth & Store Enhancemen ...)
+ TODO: check
+CVE-2026-92249 (The Qi Addons For Elementor plugin for WordPress is vulnerable to Refl ...)
+ TODO: check
+CVE-2026-91149 (A flaw was found in Cockpit. An unauthenticated remote attacker can ex ...)
+ TODO: check
+CVE-2026-91147 (A flaw was found in `cockpit-ws`. This vulnerability allows a remote, ...)
+ TODO: check
+CVE-2026-91142 (A flaw was found in Cockpit. An integer overflow vulnerability in the ...)
+ TODO: check
+CVE-2026-91127 (File Viewer is a browser-native viewer for Office, PDF, CAD, archive, ...)
+ TODO: check
+CVE-2026-90981 (The Newsletter \u2013 Send awesome emails from WordPress plugin for Wo ...)
+ TODO: check
+CVE-2026-90884 (The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross ...)
+ TODO: check
+CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes attacke ...)
+ TODO: check
+CVE-2026-89058 (A flaw was found in RESTEasy's CorsFilter, which, when configured to a ...)
+ TODO: check
+CVE-2026-88623 (NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read ...)
+ TODO: check
+CVE-2026-88622 (NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection i ...)
+ TODO: check
+CVE-2026-88259 (CareCam CM2507 IP cameras do not require authentication for access to ...)
+ TODO: check
+CVE-2026-87915 (The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers w ...)
+ TODO: check
+CVE-2026-86689 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
+ TODO: check
+CVE-2026-86520 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
+ TODO: check
+CVE-2026-85705 (The Location Manager plugin for WordPress is vulnerable to generic SQL ...)
+ TODO: check
+CVE-2026-85652 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery plugin ...)
+ TODO: check
+CVE-2026-85511 (A flaw was found in EAP's Elytron. An EAP application whose security d ...)
+ TODO: check
+CVE-2026-85497 (CareCam CM2507 IP cameras store the device's root-account password usi ...)
+ TODO: check
+CVE-2026-85478 (A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 ex ...)
+ TODO: check
+CVE-2026-85410 (The Master Addons for Elementor \u2013 Elementor Addons, Widgets, Mega ...)
+ TODO: check
+CVE-2026-85058 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
+ TODO: check
+CVE-2026-84992 (md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeS ...)
+ TODO: check
+CVE-2026-84975 (PJSIP is a free and open source multimedia communication library writt ...)
+ TODO: check
+CVE-2026-84449 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
+ TODO: check
+CVE-2026-84448 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
+ TODO: check
+CVE-2026-84447 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 ...)
+ TODO: check
+CVE-2026-84446 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
+ TODO: check
+CVE-2026-84444 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
+ TODO: check
+CVE-2026-84400 (CareCam CM2507 IP cameras contain an insufficiently protected network ...)
+ TODO: check
+CVE-2026-84398 (CM2507 IP cameras accept an empty password for a privileged account ex ...)
+ TODO: check
+CVE-2026-84384 (libheif is a HEIF and AVIF file format decoder and encoder. From 1.19. ...)
+ TODO: check
+CVE-2026-83561 (The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is ...)
+ TODO: check
+CVE-2026-81946 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
+ TODO: check
+CVE-2026-81945 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
+ TODO: check
+CVE-2026-81944 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
+ TODO: check
+CVE-2026-81943 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
+ TODO: check
+CVE-2026-81942 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
+ TODO: check
+CVE-2026-81627 (A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c ...)
+ TODO: check
+CVE-2026-81505 (Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's G ...)
+ TODO: check
+CVE-2026-81321 (CM2507 IP cameras store configured wireless network credentials in cle ...)
+ TODO: check
+CVE-2026-81305 (CM2507 IP cameras automatically execute a predetermined script from re ...)
+ TODO: check
+CVE-2026-81182 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
+ TODO: check
+CVE-2026-81181 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
+ TODO: check
+CVE-2026-81180 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
+ TODO: check
+CVE-2026-81179 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
+ TODO: check
+CVE-2026-81178 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
+ TODO: check
+CVE-2026-7006 (Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build ...)
+ TODO: check
+CVE-2026-79294 (Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2 ...)
+ TODO: check
+CVE-2026-77960 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
+ TODO: check
+CVE-2026-77929 (ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability t ...)
+ TODO: check
+CVE-2026-77928 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnera ...)
+ TODO: check
+CVE-2026-77927 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnera ...)
+ TODO: check
+CVE-2026-77616 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
+ TODO: check
+CVE-2026-77610 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
+ TODO: check
+CVE-2026-77609 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
+ TODO: check
+CVE-2026-77608 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
+ TODO: check
+CVE-2026-77607 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
+ TODO: check
+CVE-2026-77606 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
+ TODO: check
+CVE-2026-77568 (Mojolicious is a real-time web framework for Perl. Prior to 9.48, the ...)
+ TODO: check
+CVE-2026-77396 (PJSIP is a free and open source multimedia communication library writt ...)
+ TODO: check
+CVE-2026-77386 (Kyoo is a self-hosted media server focused on movies, series, and anim ...)
+ TODO: check
+CVE-2026-77385 (Kyoo is a self-hosted media server focused on movies, series, and anim ...)
+ TODO: check
+CVE-2026-77339 (Process Compose is a scheduler and orchestrator for non-containerized ...)
+ TODO: check
+CVE-2026-77301 (adm-zip is a JavaScript library for creating and extracting ZIP archiv ...)
+ TODO: check
+CVE-2026-77240 (WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 a ...)
+ TODO: check
+CVE-2026-77239 (WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 a ...)
+ TODO: check
+CVE-2026-75961 (The NEX-Forms \u2013 Ultimate Forms Plugin for WordPress plugin for Wo ...)
+ TODO: check
+CVE-2026-75894 (In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found i ...)
+ TODO: check
+CVE-2026-75893 (In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow iss ...)
+ TODO: check
+CVE-2026-75892 (In osmo-ggsn 1.14.0 an out of bounds write issue was found in thegtp_d ...)
+ TODO: check
+CVE-2026-75883 (The code in pppd that formats a response to a PEAP Request packet in p ...)
+ TODO: check
+CVE-2026-75157 (Apache Airflow's asset queued-events DELETE endpoints checked the call ...)
+ TODO: check
+CVE-2026-75031 (In the interchange/interchange project, a critical remote code executi ...)
+ TODO: check
+CVE-2026-73863 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT ...)
+ TODO: check
+CVE-2026-71537 (Paymenter is a free and open-source webshop solution for management of ...)
+ TODO: check
+CVE-2026-6205 (An external control of file name or path vulnerability in Upload API i ...)
+ TODO: check
+CVE-2026-68914 (Mojolicious is a real-time web framework for Perl. Prior to 9.47, the ...)
+ TODO: check
+CVE-2026-67549 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-67103 (HCL BigFix Service Management is affected by Cross-Site Scripting (XSS ...)
+ TODO: check
+CVE-2026-67102 (HCL BigFix Service Management is affected by a high-severity Broken Ac ...)
+ TODO: check
+CVE-2026-67101 (HCL BigFix Service Management is affected by a Server-Side Request For ...)
+ TODO: check
+CVE-2026-67100 (HCL BigFix Service Management is affected by SQL Injection flaw and a ...)
+ TODO: check
+CVE-2026-65970 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-65969 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-64847 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
+ TODO: check
+CVE-2026-63638 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-63635 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-63458 (Perses is an open-source dashboard and visualization project for obser ...)
+ TODO: check
+CVE-2026-63445 (Perses is an open-source dashboard and visualization project for obser ...)
+ TODO: check
+CVE-2026-63422 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-63420 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-63419 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-63406 (AnyCable is a realtime server for reliable two-way communication that ...)
+ TODO: check
+CVE-2026-63405 (AnyCable is a realtime server for reliable two-way communication that ...)
+ TODO: check
+CVE-2026-63349 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
+ TODO: check
+CVE-2026-63199 (Perses is an open-source dashboard and visualization project for obser ...)
+ TODO: check
+CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of Btrfs sub ...)
+ TODO: check
+CVE-2026-62282 (OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, Open ...)
+ TODO: check
+CVE-2026-62279 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
+ TODO: check
+CVE-2026-62278 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
+ TODO: check
+CVE-2026-61833 (zot is a container image and artifact registry based on the Open Conta ...)
+ TODO: check
+CVE-2026-61795 (Capsule is a multi-tenancy and policy-based framework for Kubernetes. ...)
+ TODO: check
+CVE-2026-61794 (Capsule is a multi-tenancy and policy-based framework for Kubernetes. ...)
+ TODO: check
+CVE-2026-61682 (kcp is a Kubernetes-like control plane for form-factors and use-cases ...)
+ TODO: check
+CVE-2026-61672 (Capsule is a multi-tenancy and policy-based framework for Kubernetes. ...)
+ TODO: check
+CVE-2026-61633 (NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function ...)
+ TODO: check
+CVE-2026-60115
+ REJECTED
+CVE-2026-59956 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-59181 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-59163 (Mnemosyne is a memory layer for artificial intelligence agents. Prior ...)
+ TODO: check
+CVE-2026-59156 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-58197 (ToolHive is a utility designed to simplify the deployment and manageme ...)
+ TODO: check
+CVE-2026-56597 (HCL BigFix Service Management is affected by a Sensitive Information L ...)
+ TODO: check
+CVE-2026-56595 (HCL BigFix Service Management is affected by a CORS Misconfiguration v ...)
+ TODO: check
+CVE-2026-56592 (HCL BigFix Service Management is affected by an Improper Authenticatio ...)
+ TODO: check
+CVE-2026-56590 (HCL BigFix Service Management is affected by an Unrestricted File Uplo ...)
+ TODO: check
+CVE-2026-54148 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to ...)
+ TODO: check
+CVE-2026-54147 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to ...)
+ TODO: check
+CVE-2026-4036 (An improper neutralization of special elements used in an SQL command ...)
+ TODO: check
+CVE-2026-44639 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property ...)
+ TODO: check
+CVE-2026-40539 (An improper certificate validation vulnerability in Email API in Synol ...)
+ TODO: check
+CVE-2026-40538 (An improper restriction of excessive authentication attempts vulnerabi ...)
+ TODO: check
+CVE-2026-40537 (A server-side request forgery (SSRF) vulnerability in PersonMail API i ...)
+ TODO: check
+CVE-2026-40536 (An improper limitation of a pathname to a restricted directory ('path ...)
+ TODO: check
+CVE-2026-40535 (An improper limitation of a pathname to a restricted directory ('path ...)
+ TODO: check
+CVE-2026-40534 (An improper neutralization of input during web page generation ('cross ...)
+ TODO: check
+CVE-2026-40533 (An exposure of sensitive information through data queries vulnerabilit ...)
+ TODO: check
+CVE-2026-40532 (A direct request ('forced browsing') vulnerability in Wallpaper Path i ...)
+ TODO: check
+CVE-2026-40531 (An integer overflow or wraparound vulnerability in File Operation in S ...)
+ TODO: check
+CVE-2026-40530 (An improper neutralization of CRLF sequences ('CRLF injection') vulner ...)
+ TODO: check
+CVE-2026-33625 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
+ TODO: check
+CVE-2026-32641 (Parseable is a log analytics platform built for high-volume data inges ...)
+ TODO: check
+CVE-2026-28199 (An authenticated user with access to the NetBackup Flex OS management ...)
+ TODO: check
+CVE-2026-28198 (An authenticated, low-privileged user with access to the NetBackup Fle ...)
+ TODO: check
+CVE-2026-28197 (An authenticated, low-privileged user with access to the NetBackup Fle ...)
+ TODO: check
+CVE-2026-25684 (A file type attribution issue in Zscaler Internet Access File Type Con ...)
+ TODO: check
+CVE-2026-21848 (HCL BigFix Service Management is affected by a Security Misconfigurati ...)
+ TODO: check
+CVE-2026-21822 (HCLSoftware AppScan 360\xb0 was affected by a Path Traversal vulnerabi ...)
+ TODO: check
+CVE-2026-21806 (HCL BigFix Service Management is affected by an Administrative Session ...)
+ TODO: check
+CVE-2026-1037 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
+ TODO: check
+CVE-2026-1031 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
+ TODO: check
+CVE-2026-1030 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
+ TODO: check
+CVE-2026-1029 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
+ TODO: check
+CVE-2026-1025 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
+ TODO: check
+CVE-2026-18442 (The WCFM Marketplace \u2013 Multivendor Marketplace for WooCommerce pl ...)
+ TODO: check
+CVE-2026-18405 (The Jeg Kit for Elementor \u2013 Powerful Addons for Elementor, Widget ...)
+ TODO: check
+CVE-2026-17607 (The WP Inventory Manager plugin for WordPress is vulnerable to SQL Inj ...)
+ TODO: check
+CVE-2026-17586 (The VK All in One Expansion Unit plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2026-16777 (The Store Exporter \u2013 Export WooCommerce Products, Orders, Subscri ...)
+ TODO: check
+CVE-2026-16515 (net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one ...)
+ TODO: check
+CVE-2026-16514 (gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c wa ...)
+ TODO: check
+CVE-2026-16512 (gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced t ...)
+ TODO: check
+CVE-2026-15797 (The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers w ...)
+ TODO: check
+CVE-2026-15579 (An out-of-bounds write vulnerability exists in some of the Ethernet sw ...)
+ TODO: check
+CVE-2026-15275 (The WP Multi Store Locator Pro plugin for WordPress is vulnerable to g ...)
+ TODO: check
+CVE-2026-15004 (The FileBird \u2013 WordPress Media Library Folders & File Manager plu ...)
+ TODO: check
+CVE-2026-14472 (The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored ...)
+ TODO: check
+CVE-2026-14323 (The Printcart Web to Print Product Designer for WooCommerce plugin for ...)
+ TODO: check
+CVE-2026-13684 (An improper encoding or escaping of output vulnerability in SCGI in Sy ...)
+ TODO: check
+CVE-2026-13683 (An improper neutralization of special elements used in an SQL command ...)
+ TODO: check
+CVE-2026-13673 (An incorrect permission assignment for critical resource vulnerability ...)
+ TODO: check
+CVE-2026-13666 (An improper neutralization of CRLF sequences ('CRLF Injection') vulner ...)
+ TODO: check
+CVE-2026-13639 (An insufficient entropy vulnerability in login logic in Synology DiskS ...)
+ TODO: check
+CVE-2026-13635 (An improper encoding or escaping of output vulnerability in Auth API i ...)
+ TODO: check
+CVE-2026-13623 (An improper neutralization of input during web page generation ('Cross ...)
+ TODO: check
+CVE-2026-13471 (The LatePoint \u2013 Calendar Booking Plugin for Appointments and Even ...)
+ TODO: check
+CVE-2026-12954 (The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary Us ...)
+ TODO: check
+CVE-2026-12739 (The WP Easy Pay \u2013 Payment and Donation form Builder for Square pl ...)
+ TODO: check
+CVE-2026-12384 (Authorization bypass through User-Controlled key vulnerability in TECH ...)
+ TODO: check
+CVE-2026-11757 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-11538 (IBM WebSphere Application Server 9.0 and 8.5 is affected by a log inje ...)
+ TODO: check
+CVE-2026-11537 (IBM WebSphere Application Server 9.0, and 8.5 could allow a remote att ...)
+ TODO: check
+CVE-2026-11381 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
+ TODO: check
+CVE-2026-11378 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
+ TODO: check
+CVE-2026-11375 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
+ TODO: check
+CVE-2026-10858 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
+ TODO: check
+CVE-2026-10853 (IBM MQ could allow an authenticated attacker with cluster access to ca ...)
+ TODO: check
+CVE-2026-10841 (IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable ...)
+ TODO: check
+CVE-2026-10832 (A flaw was found in the DERDecoder class within wildfly-elytron-asn1. ...)
+ TODO: check
+CVE-2026-10751 (IBM MQ Java and JMS client libraries could allow an authenticated atta ...)
+ TODO: check
+CVE-2026-10747 (IBM MQ Appliance could allow a remote attacker to cause a denial of se ...)
+ TODO: check
+CVE-2026-10744 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
+ TODO: check
+CVE-2026-10575 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
+ TODO: check
+CVE-2026-10030 (IBM MQ Console allows authenticated non-administrative users to create ...)
+ TODO: check
+CVE-2026-10027 (IBM MQ could allow a remote attacker to cause a denial of service or e ...)
+ TODO: check
+CVE-2025-66455 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
+ TODO: check
+CVE-2025-61682 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
+ TODO: check
+CVE-2025-53837 (XWiki Rendering is a generic rendering system that converts textual in ...)
+ TODO: check
+CVE-2025-36421 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
+ TODO: check
+CVE-2025-36178 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
+ TODO: check
+CVE-2025-36147 (IBM Financial Transaction Manager for SWIFT Services for Multiplatform ...)
+ TODO: check
+CVE-2025-36076 (IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12. ...)
+ TODO: check
+CVE-2025-36045 (IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user t ...)
+ TODO: check
+CVE-2025-33147 (IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12. ...)
+ TODO: check
+CVE-2025-33141 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an aut ...)
+ TODO: check
+CVE-2025-1350 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
+ TODO: check
+CVE-2025-15399 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
+ TODO: check
+CVE-2025-14754 (IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to exec ...)
+ TODO: check
+CVE-2025-14753 (IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse ...)
+ TODO: check
+CVE-2025-13882 (IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 thr ...)
+ TODO: check
+CVE-2025-13533 (The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Sto ...)
+ TODO: check
+CVE-2024-56344 (IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12. ...)
+ TODO: check
+CVE-2023-5778 (Improper handling of length parameter inconsistency vulnerability in A ...)
+ TODO: check
+CVE-2023-54399 (Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the ...)
+ TODO: check
+CVE-2021-48008 (Chanjet CRM contains an unauthenticated SQL injection vulnerability th ...)
+ TODO: check
+CVE-2019-25776 (Weaver E-cology contains an unauthenticated SQL injection vulnerabilit ...)
+ TODO: check
CVE-2026-92828
NOT-FOR-US: OpenShift
CVE-2026-92218
NOT-FOR-US: release-service-utils
-CVE-2026-87743
+CVE-2026-87743 (A flaw was found in Quarkus HTTP security. An unauthenticated attacker ...)
NOT-FOR-US: quarkus-vertx-http
CVE-2026-77874
NOT-FOR-US: Hibernate ORM
-CVE-2026-93019 [TGA: don't interpret large color map sizes as negative]
+CVE-2026-93019 (Imager versions before 1.036 for Perl exit the process reading a TGA w ...)
- libimager-perl 1.036+dfsg-1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43654761/
NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2
NOTE: Fixed by: https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571 (v1.036)
-CVE-2026-93018 [paletted images: OOB access]
+CVE-2026-93018 (Imager versions before 1.036 for Perl disclose uninitialised heap memo ...)
- libimager-perl 1.036+dfsg-1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43654795/
NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-j7v7-cm4g-vrgf
@@ -2844,7 +3440,8 @@ CVE-2026-90170 (In the Linux kernel, the following vulnerability has been resolv
CVE-2026-90169 (In the Linux kernel, the following vulnerability has been resolved: k ...)
- linux 7.2.6-1
NOTE: https://git.kernel.org/linus/06c7b1d731bc105a8644f1b70165ba8b9416cbab (7.3-rc1)
-CVE-2026-90168 (In the Linux kernel, the following vulnerability has been resolved: k ...)
+CVE-2026-90168
+ REJECTED
- linux 7.2.6-1
NOTE: https://git.kernel.org/linus/f495154703cbcc0050cfd53469bd56965791616b (7.3-rc1)
CVE-2026-90167 (In the Linux kernel, the following vulnerability has been resolved: k ...)
@@ -13684,7 +14281,7 @@ CVE-2026-87090 (Consul and Consul Enterprise are vulnerable to an authorization
- consul <removed>
CVE-2026-85545 (There is an Vulnerability in some HikCentral Access Control versions. ...)
NOT-FOR-US: Hikvision
-CVE-2026-85544 (There is an Improper Encryption Configuration Vulnerability in some Hi ...)
+CVE-2026-85544 (Some Hikvision intercom products utilize an immutable factory value wh ...)
NOT-FOR-US: Hikvision
CVE-2026-85543 (Some Wi-Fi series camera products have insufficient permission validat ...)
NOT-FOR-US: Hikvision
@@ -22796,7 +23393,7 @@ CVE-2026-80726 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.9-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/5ec42d57655c690234c14aece6dd3f209778c1d8 (7.2-rc7)
-CVE-2026-84450 [`clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for GHSA-jc8f-p23p-5hjg)]
+CVE-2026-84450 (libheif is a HEIF and AVIF file format decoder and encoder. From 1.19. ...)
- libheif 1.23.3-1
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-gh5q-69gg-c964
CVE-2026-XXXX [Heap buffer overflow in unci mixed-interleave decoding with unequal chroma bit depths]
@@ -22807,7 +23404,7 @@ CVE-2026-XXXX [decoder deadlock (DoS) via alpha-aux reference cycle]
[trixie] - libheif <not-affected> (Introduced in 1.22)
[bookworm] - libheif <not-affected> (Introduced in 1.22)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-8fmq-r4pf-7m57
-CVE-2026-84451 [Incomplete fix for GHSA-73p7-m7gg-w2jv leaves libheif 1.23.1 vulnerable to an out-of-bounds read]
+CVE-2026-84451 (libheif is a HEIF and AVIF file format decoder and encoder. From 1.19. ...)
- libheif 1.23.3-1
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-hh47-fhqr-cj2r
CVE-2026-XXXX [heap OOB read / info disclosure (Op_YCbCr420_to_RRGGBBaa]
@@ -25226,7 +25823,7 @@ CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is vulnera
NOT-FOR-US: WordPress plugin
CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_ ...)
NOT-FOR-US: TechStore
-CVE-2026-84383 [GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items]
+CVE-2026-84383 (libheif is a HEIF and AVIF file format decoder and encoder. From 1.22. ...)
- libheif 1.23.2-1
[trixie] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
[bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
@@ -36168,37 +36765,37 @@ CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests de
NOTE: https://github.com/Orange-OpenSource/hurl/pull/5119
NOTE: Fixed by: https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e
CVE-2026-63388 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338
NOTE: Fixed by: https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72 (release-2.1.13-stable)
NOTE: Fixed by: https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9 (release-2.2.2-alpha)
CVE-2026-63387 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47
NOTE: Fixed by: https://github.com/libevent/libevent/commit/377b9022c3ac61aa4540b5dc4b70c60bf74c663d (release-2.1.13-stable)
NOTE: Fixed by: https://github.com/libevent/libevent/commit/9877a7205ea024d0120effb040e1b8e034435407 (release-2.2.2-alpha)
CVE-2026-63385 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2
NOTE: Fixed by: https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2 (release-2.1.13-stable)
NOTE: Fixed by: https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0 (release-2.2.2-alpha)
CVE-2026-63384 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8
NOTE: Fixed by: https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416 (release-2.1.13-stable)
NOTE: Fixed by: https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda (release-2.2.2-alpha)
CVE-2026-63383 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6
NOTE: Fixed by: https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb (release-2.1.13-stable)
NOTE: Fixed by: https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321 (release-2.2.2-alpha)
CVE-2026-63382 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j
NOTE: Fixed by: https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6 (release-2.1.13-stable)
@@ -36206,7 +36803,7 @@ CVE-2026-63382 (Libevent is an event notification library. Prior to 2.1.13 and 2
NOTE: Fixed by: https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e (release-2.2.2-alpha)
NOTE: Fixed by: https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660 (release-2.2.2-alpha)
CVE-2026-63381 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8
NOTE: Fixed by: https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c (release-2.1.13-stable)
@@ -36216,7 +36813,7 @@ CVE-2026-63380 (Libevent is an event notification library. Prior to 2.2.2-alpha,
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34
NOTE: Fixed by: https://github.com/libevent/libevent/commit/825c18bd99f556b59d61200523237f264d5cc734 (release-2.2.2-alpha)
CVE-2026-63379 (Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...)
- {DSA-6493-1}
+ {DSA-6493-1 DLA-4786-1}
- libevent 2.1.13-stable-1
NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6
NOTE: Fixed by: https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636 (release-2.1.13-stable)
@@ -69447,7 +70044,7 @@ CVE-2026-65492 (Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65491 (Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-65490 (Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5. ...)
+CVE-2026-65490 (Exposure of Sensitive System Information to an Unauthorized Control Sp ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65489 (Unauthenticated Broken Access Control in LA-Studio Element Kit for Ele ...)
NOT-FOR-US: WordPress plugin or theme
@@ -74147,7 +74744,7 @@ CVE-2026-56452 (Path traversal in the sshd-scp component of Apache MINA SSHD.Apa
- libmina-sshd-java <unfixed> (bug #1142679)
[trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/15
-CVE-2026-61548 [rsyslog mmpstrucdata stack overflow]
+CVE-2026-61548 (Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8 ...)
- rsyslog 8.2606.0-4
[trixie] - rsyslog 8.2504.0-1+deb13u2
[bookworm] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs module loaded + oversized RFC5424 structured-data)
@@ -81068,6 +81665,7 @@ CVE-2026-45646 (Allocation of resources without limits or throttling in ASP.NET
CVE-2026-45496 (Improper limitation of a pathname to a restricted directory ('path tra ...)
NOT-FOR-US: Microsoft
CVE-2026-45363 (ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token ...)
+ {DLA-4787-1}
- ruby-jwt 3.2.0-1
NOTE: https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x
NOTE: Fixed by: https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f (v3.2.0)
@@ -86080,7 +86678,7 @@ CVE-2026-59089 (A flaw was found in GIMP. The PlayStation TIM loader, responsibl
[bullseye] - gimp <not-affected> (PlayStation TIM loader plug-ins/common/file-tim.c added in GIMP 3.x; 2.10 has no such loader)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16493
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/53cdb27fa2b1676d11e9677c9975b5ad7b61b2ee
-CVE-2026-69186 [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via unvalidated DNS header record counts]
+CVE-2026-69186 (c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_ ...)
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
[bookworm] - c-ares <not-affected> (New DNS-record parser prealloc (ares_dns_record_rr_prealloc/ares_array_set_size) not present; introduced in the 1.20+ rewrite)
@@ -86089,7 +86687,7 @@ CVE-2026-69186 [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via
NOTE: https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab (main)
NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/e47c203f91cd8b749c8736bc18d75a31ffdec8f4 (v1.34.7)
-CVE-2026-69184 [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains]
+CVE-2026-69184 (c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_ ...)
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
[bookworm] - c-ares <not-affected> (Vulnerable 1.34 DNS-name decompression parser (src/lib/record/ares_dns_name.c, ares_buf) not present)
@@ -88265,14 +88863,14 @@ CVE-2026-10089 (The Insert Pages plugin for WordPress is vulnerable to Stored Cr
NOT-FOR-US: WordPress plugin
CVE-2026-10077 (The yootheme WordPress theme before 5.0.35 does not prevent its bundle ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-61552 [GHSA-jgqj-x5j9-vgcm: Icinga 2 DSL Injection via Unescaped Import Template Name]
+CVE-2026-61552 (Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2 ...)
{DSA-6426-1}
- icinga2 2.16.2-1
NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-jgqj-x5j9-vgcm
NOTE: https://icinga.com/blog/icinga2-security-release-v2-16-2/
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441 (v2.16.2)
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30 (v2.14.9)
-CVE-2026-61551 [GHSA-wh38-wg57-5w7g: Stack overflow via deeply nested JSON objects]
+CVE-2026-61551 (Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, ...)
{DSA-6426-1}
- icinga2 2.16.2-1
NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-wh38-wg57-5w7g
@@ -88293,7 +88891,7 @@ CVE-2026-61551 [GHSA-wh38-wg57-5w7g: Stack overflow via deeply nested JSON objec
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/69093a8ae0f09bbef8f589cbc67f131f167e5aa3 (v2.14.9)
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/221d3fa9a66c248bc478220e4a73e1be661dd449 (v2.14.9)
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/e23a3eb42d791f27c1073b56769800fe12156425 (v2.14.9)
-CVE-2026-61550 [GHSA-vj39-ww8j-vvx5: Improper access control for JSON-RPC update certificate messages]
+CVE-2026-61550 (Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2 ...)
{DSA-6426-1}
- icinga2 2.16.2-1
NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-vj39-ww8j-vvx5
@@ -93034,7 +93632,7 @@ CVE-2026-57324 (Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versio
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57323 (Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-57322 (Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions ...)
+CVE-2026-57322 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57321 (Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -97940,7 +98538,7 @@ CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar' filter could be b
NOTE: https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df (v3.15.0b4)
NOTE: https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c (v3.14.7)
NOTE: https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde (v3.13.15)
-CVE-2026-55556
+CVE-2026-55556 (Rsyslog is a rocket-fast system for log processing. From 8.2110.0 unti ...)
- rsyslog 8.2604.0-1 (unimportant)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/23/4
NOTE: imhttp rsyslog plugin not packaged in Debian
@@ -100663,7 +101261,7 @@ CVE-2026-47178 (libheif is a HEIF and AVIF file format decoder and encoder. In v
NOTE: https://project-zero.issues.chromium.org/issues/507396184
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-5x55-x5pf-9c6g
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/62d60530610110fc7bc6d08ff30f2cf23917a1eb (v1.22.0)
-CVE-2026-46655
+CVE-2026-46655 (virtio-win provides Windows paravirtualized drivers for QEMU and KVM. ...)
NOT-FOR-US: virtio drivers for Windows
CVE-2026-0163 (In multiple functions of vpu_ioctl.c, there is a possible use after fr ...)
NOT-FOR-US: Intel vpu driver
@@ -791770,6 +792368,7 @@ CVE-2018-13412 (An issue was discovered in the Self Service Portal in Zoho Manag
CVE-2018-13411 (An issue was discovered in Zoho ManageEngine Desktop Central before 10 ...)
NOT-FOR-US: Zoho ManageEngine Desktop Central
CVE-2018-13410 (Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, a ...)
+ {DLA-4785-1}
- zip 3.0-15 (unimportant; bug #903196)
[bookworm] - zip 3.0-13+deb12u1
NOTE: http://seclists.org/fulldisclosure/2018/Jul/24
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/65dc8426444f43c54d39ca00f3a4ba5e690c59e8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/65dc8426444f43c54d39ca00f3a4ba5e690c59e8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/908af8a3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list