[Git][security-tracker-team/security-tracker][master] Add two new resteasy issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 19 06:47:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0a45e05c by Salvatore Bonaccorso at 2026-09-19T07:47:28+02:00
Add two new resteasy issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -275,9 +275,19 @@ CVE-2026-90981 (The Newsletter \u2013 Send awesome emails from WordPress plugin
 CVE-2026-90884 (The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes attacke ...)
-	TODO: check
+	- resteasy <unfixed>
+	- resteasy3.0 <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519756
+	NOTE: https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
+	NOTE: https://redhat.atlassian.net/browse/RESTEASY-3793
+	NOTE: Fixed by: https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb (v7.0.5.Final)
 CVE-2026-89058 (A flaw was found in RESTEasy's CorsFilter, which, when configured to a ...)
-	TODO: check
+	- resteasy <unfixed>
+	- resteasy3.0 <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519775
+	NOTE: https://github.com/resteasy/resteasy/security/advisories/GHSA-972r-f3fv-whm3
+	NOTE: https://redhat.atlassian.net/browse/RESTEASY-3796
+	NOTE: Fixed by: https://github.com/resteasy/resteasy/commit/b31525814f77a0619f612440ff27111174dbfef8 (v7.0.5.Final)
 CVE-2026-88623 (NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read ...)
 	NOT-FOR-US: NUUO Network Video Recorder
 CVE-2026-88622 (NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a45e05cd60f557389cf02fbd1254ee70be53371

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a45e05cd60f557389cf02fbd1254ee70be53371
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/9ba13d7d/attachment.htm>


More information about the debian-security-tracker-commits mailing list