[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-76221: Add commit link
Emmanuel Arias (@eamanu)
eamanu at debian.org
Fri Sep 18 21:30:21 BST 2026
Emmanuel Arias pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c3c10aa6 by Emmanuel Arias at 2026-09-18T17:27:12-03:00
CVE-2026-76221: Add commit link
- - - - -
08790708 by Emmanuel Arias at 2026-09-18T17:29:45-03:00
CVE-2026-76222: Add commit link
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -38050,9 +38050,11 @@ CVE-2026-76223 (ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enfo
CVE-2026-76222 (GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)
- python-git 3.1.61-1 (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/e4b8e7d026ca6abb4cf604f8e77093432ce23c06 (3.1.58)
CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection vulnerability ...)
- python-git 3.1.61-1 (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgr
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/a495ccd3b547ccd60b2187215823b72a9c0188bf (3.1.58)
CVE-2026-76220 (GitPython before 3.1.58 contains a command execution vulnerability in ...)
- python-git 3.1.61-1 (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/51fb578b0c46c8d771503cb1f3060a5b372998e3...087907084f783e0a0d40fb3bfb3aaf1a9f5a048d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/51fb578b0c46c8d771503cb1f3060a5b372998e3...087907084f783e0a0d40fb3bfb3aaf1a9f5a048d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/eca76e51/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list