[Git][security-tracker-team/security-tracker][master] CVE-2026-78679: Add commit link
Emmanuel Arias (@eamanu)
eamanu at debian.org
Fri Sep 18 21:46:46 BST 2026
Emmanuel Arias pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7d8bcaac by Emmanuel Arias at 2026-09-18T17:46:31-03:00
CVE-2026-78679: Add commit link
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -33541,6 +33541,7 @@ CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute paths
CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read vulnerability ...)
- python-git 3.1.61-1 (bug #1145672)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6 (3.1.59)
CVE-2026-78678 (GitPython versions before 3.1.59 contain an incomplete denylist in the ...)
- python-git 3.1.61-1 (bug #1145672)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d8bcaacb39e533a9247cb2159d794c8cb3c52f1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d8bcaacb39e533a9247cb2159d794c8cb3c52f1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/78363e98/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list