[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 19 08:13:28 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8e453f46 by security tracker role at 2026-09-19T07:13:21+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,309 @@
+CVE-2026-93923 (SiYuan through 3.8.4 fails to escape heading style attributes when ren ...)
+ TODO: check
+CVE-2026-93922 (SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily N ...)
+ TODO: check
+CVE-2026-93921 (SiYuan versions through 3.8.4 fail to enforce publish access control i ...)
+ TODO: check
+CVE-2026-93894 (In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability w ...)
+ TODO: check
+CVE-2026-93873 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contac ...)
+ TODO: check
+CVE-2026-93872 (Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() ...)
+ TODO: check
+CVE-2026-93871 (Cotonti through 1.0.0 fails to validate redirect destinations in page ...)
+ TODO: check
+CVE-2026-93870 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the rating ...)
+ TODO: check
+CVE-2026-93869 (Cotonti through 1.0.0 contains an open redirect vulnerability in the c ...)
+ TODO: check
+CVE-2026-93868 (Cotonti through 1.0.0 derives password recovery validation tokens from ...)
+ TODO: check
+CVE-2026-93841 (vLLM through 0.29.0 contains a memory corruption vulnerability in the ...)
+ TODO: check
+CVE-2026-93840 (vLLM before 0.29.0 validates allowed_token_ids against tokenizer lengt ...)
+ TODO: check
+CVE-2026-93839 (LightLLM through 1.2.0 contains an authentication bypass vulnerability ...)
+ TODO: check
+CVE-2026-93838 (SGLang versions through 0.5.20 contain an unbounded memory allocation ...)
+ TODO: check
+CVE-2026-93741 (A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1 ...)
+ TODO: check
+CVE-2026-93740 (A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. ...)
+ TODO: check
+CVE-2026-93739 (A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. ...)
+ TODO: check
+CVE-2026-93738 (A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This ...)
+ TODO: check
+CVE-2026-93574 (A flaw was found in Netty's `netty-codec-http` component. A remote att ...)
+ TODO: check
+CVE-2026-93562 (A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of m ...)
+ TODO: check
+CVE-2026-93031 (The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, ...)
+ TODO: check
+CVE-2026-92967 (The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site ...)
+ TODO: check
+CVE-2026-92807 (The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable ...)
+ TODO: check
+CVE-2026-92708 (Svelte devalue is a JavaScript library that serializes values into str ...)
+ TODO: check
+CVE-2026-92435 (The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not v ...)
+ TODO: check
+CVE-2026-92430 (The Rede Ita\xfa for WooCommerce \u2014 Payment PIX, Credit Card and D ...)
+ TODO: check
+CVE-2026-92425 (The Hydra Booking \u2014 Appointment Scheduling & Booking Calendar Wor ...)
+ TODO: check
+CVE-2026-92421 (The Hydra Booking \u2014 Appointment Scheduling & Booking Calendar Wor ...)
+ TODO: check
+CVE-2026-92420 (The Hydra Booking \u2014 Appointment Scheduling & Booking Calendar Wor ...)
+ TODO: check
+CVE-2026-92404 (The MgoSync WordPress plugin before 2.1.7 does not have authorization ...)
+ TODO: check
+CVE-2026-92403 (The Secure Custom Fields WordPress plugin before 6.9.4 does not proper ...)
+ TODO: check
+CVE-2026-92229 (The The Forminator Forms \u2013 Contact Form, Payment Form & Custom Fo ...)
+ TODO: check
+CVE-2026-92099 (The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not requi ...)
+ TODO: check
+CVE-2026-91847 (The Online Scheduling and Appointment Booking System WordPress plugin ...)
+ TODO: check
+CVE-2026-91205 (A flaw was found in cockpit-files. A local unprivileged attacker can e ...)
+ TODO: check
+CVE-2026-91203 (A flaw was found in cockpit-files. This vulnerability allows a local a ...)
+ TODO: check
+CVE-2026-91202 (A flaw was found in cockpit-files. A low-privileged local user can exp ...)
+ TODO: check
+CVE-2026-89334 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages & ...)
+ TODO: check
+CVE-2026-89333 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
+ TODO: check
+CVE-2026-89274 (The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Sh ...)
+ TODO: check
+CVE-2026-89093 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages & ...)
+ TODO: check
+CVE-2026-89081 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
+ TODO: check
+CVE-2026-88944 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
+ TODO: check
+CVE-2026-88926 (The VikRentItems Flexible Rental Management System WordPress plugin be ...)
+ TODO: check
+CVE-2026-88824 (The Master Blocks WordPress plugin before 1.5.0 does not have authori ...)
+ TODO: check
+CVE-2026-88097 (Use after free in Microsoft Edge (Chromium-based) allows an unauthoriz ...)
+ TODO: check
+CVE-2026-87909 (The WP Photo Album Plus plugin for WordPress is vulnerable to Remote C ...)
+ TODO: check
+CVE-2026-86814 (The UsersWP WordPress plugin before 1.5.10 does not verify that a soc ...)
+ TODO: check
+CVE-2026-86591 (The Botiga Pro WordPress plugin before 1.6.5 does not perform any auth ...)
+ TODO: check
+CVE-2026-85680 (The Ultimate Member WordPress plugin before 2.13.1 does not escape a ...)
+ TODO: check
+CVE-2026-85574 (The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perf ...)
+ TODO: check
+CVE-2026-85272 (Open edX Platform enables the authoring and delivery of online learnin ...)
+ TODO: check
+CVE-2026-85271 (Open edX Platform enables the authoring and delivery of online learnin ...)
+ TODO: check
+CVE-2026-84750 (The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 doe ...)
+ TODO: check
+CVE-2026-84434 (The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File ...)
+ TODO: check
+CVE-2026-84241 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
+ TODO: check
+CVE-2026-84239 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84108 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
+ TODO: check
+CVE-2026-84106 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84105 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84089 (IBM Guardium Data Protection 12.2 could allow a local attacker to gain ...)
+ TODO: check
+CVE-2026-84086 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84085 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
+ TODO: check
+CVE-2026-84084 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
+ TODO: check
+CVE-2026-84083 (IBM Guardium Data Protection 12.2 is vulnerable to local privilege esc ...)
+ TODO: check
+CVE-2026-84082 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
+ TODO: check
+CVE-2026-84081 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
+ TODO: check
+CVE-2026-84078 (IBM Guardium Data Protection 12.2 is vulnerable to a missing authentic ...)
+ TODO: check
+CVE-2026-84077 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
+ TODO: check
+CVE-2026-84076 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84075 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
+ TODO: check
+CVE-2026-84074 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84073 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84071 (IBM Guardium Data Protection 12.2 is vulnerable to OS command injectio ...)
+ TODO: check
+CVE-2026-84070 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84064 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84036 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-84034 (IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credent ...)
+ TODO: check
+CVE-2026-84031 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-82967 (IBM Guardium Data Protection 12.2 is vulnerable to an authentication b ...)
+ TODO: check
+CVE-2026-82896 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-82893 (IBM Guardium Data Protection 12.2 could allow a local attacker to gain ...)
+ TODO: check
+CVE-2026-82892 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
+ TODO: check
+CVE-2026-82890 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-82887 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-82885 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-82832 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
+ TODO: check
+CVE-2026-82340 (IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated ins ...)
+ TODO: check
+CVE-2026-81937 (IBM Guardium Data Protection 12.2 is vulnerable to a command injection ...)
+ TODO: check
+CVE-2026-81933 (IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vul ...)
+ TODO: check
+CVE-2026-81669 (IBM Guardium Data Protection 12.2 is vulnerable to a command injection ...)
+ TODO: check
+CVE-2026-81657 (IBM Guardium Data Protection 12.2 could allow a remote unauthenticated ...)
+ TODO: check
+CVE-2026-81656 (IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vul ...)
+ TODO: check
+CVE-2026-81626 (IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vul ...)
+ TODO: check
+CVE-2026-81623 (IBM Guardium Data Protection 12.2 could allow an authenticated user to ...)
+ TODO: check
+CVE-2026-80442 (IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS ...)
+ TODO: check
+CVE-2026-80441 (IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated ...)
+ TODO: check
+CVE-2026-77875 (The application protects access through its calculator-style vault pas ...)
+ TODO: check
+CVE-2026-77820 (The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site ...)
+ TODO: check
+CVE-2026-77528 (Autobahn Python is a WebSocket and WAMP implementation for Python that ...)
+ TODO: check
+CVE-2026-76902 (CordysCRM is an open source AI-powered customer relationship managemen ...)
+ TODO: check
+CVE-2026-76901 (CordysCRM is an open source AI-powered customer relationship managemen ...)
+ TODO: check
+CVE-2026-76900 (CordysCRM is an open source AI-powered customer relationship managemen ...)
+ TODO: check
+CVE-2026-76899 (CordysCRM is an open source AI-powered customer relationship managemen ...)
+ TODO: check
+CVE-2026-76790 (The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not ...)
+ TODO: check
+CVE-2026-76554 (The WP Import Export Lite WordPress plugin before 3.9.35 does not veri ...)
+ TODO: check
+CVE-2026-75895 (In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was foun ...)
+ TODO: check
+CVE-2026-75885 (A flaw was found in the OpenShift console. Unauthenticated access to t ...)
+ TODO: check
+CVE-2026-75878 (IBM Sterling File Gateway could allow a remote attacker to bypass auth ...)
+ TODO: check
+CVE-2026-71855 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-71418 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-68928 (Acode is a powerful text and code editor for Android. From 1.11.6 unti ...)
+ TODO: check
+CVE-2026-63647 (CordysCRM is an open source AI-powered customer relationship managemen ...)
+ TODO: check
+CVE-2026-63646 (CordysCRM is an open source AI-powered customer relationship managemen ...)
+ TODO: check
+CVE-2026-63452 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-63451 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-63450 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-63449 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-63448 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-63447 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-63446 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
+ TODO: check
+CVE-2026-61822 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
+ TODO: check
+CVE-2026-61821 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
+ TODO: check
+CVE-2026-61820 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
+ TODO: check
+CVE-2026-61819 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
+ TODO: check
+CVE-2026-61818 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
+ TODO: check
+CVE-2026-61817 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
+ TODO: check
+CVE-2026-61781 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
+ TODO: check
+CVE-2026-61670 (microsandbox is an easy, fast, local-first microVM runtime and library ...)
+ TODO: check
+CVE-2026-52745 (CordysCRM is an open source AI-powered customer relationship managemen ...)
+ TODO: check
+CVE-2026-19860 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder WordPress plugin ...)
+ TODO: check
+CVE-2026-18869 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
+ TODO: check
+CVE-2026-17619 (IBM Platform RTM is vulnerable to SQL injection. A remote attacker cou ...)
+ TODO: check
+CVE-2026-17262 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a d ...)
+ TODO: check
+CVE-2026-16557 (The Nimble Page Builder WordPress plugin through 3.3.8 does not perfor ...)
+ TODO: check
+CVE-2026-15760 (The Divi Essential plugin for WordPress is vulnerable to sensitive inf ...)
+ TODO: check
+CVE-2026-15660 (The SEO Booster plugin for WordPress is vulnerable to Missing Authoriz ...)
+ TODO: check
+CVE-2026-13354 (The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerab ...)
+ TODO: check
+CVE-2026-12042 (The WP2Social Auto Publish plugin for WordPress is vulnerable to Store ...)
+ TODO: check
+CVE-2026-11727 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could al ...)
+ TODO: check
+CVE-2026-11726 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
+ TODO: check
+CVE-2026-11725 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
+ TODO: check
+CVE-2026-11722 (IBM WebSphere Application Server and WebSphere Application Server Libe ...)
+ TODO: check
+CVE-2026-11716 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
+ TODO: check
+CVE-2026-11711 (IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserial ...)
+ TODO: check
+CVE-2026-11710 (IBM WebSphere Application Server 8.5 is affected by an HTTP request sm ...)
+ TODO: check
+CVE-2026-11549 (IBM WebSphere Application Server and WebSphere Application Server Libe ...)
+ TODO: check
+CVE-2026-11548 (IBM WebSphere Application Server and WebSphere Application Server Libe ...)
+ TODO: check
+CVE-2026-11545 (IBM WebSphere Application Server 8.5 and 9.0 could allow a remote atta ...)
+ TODO: check
+CVE-2026-11540 (IBM WebSphere Application Server 9.0 and 8.5 could allow a remote atta ...)
+ TODO: check
+CVE-2026-11539 (IBM WebSphere Application Server 9.0 and 8.5 is affected by an authent ...)
+ TODO: check
+CVE-2025-15698 (The Business Name Generator WordPress plugin through 1.3 does not sani ...)
+ TODO: check
+CVE-2017-20284 (Caucho Resin contains a path traversal vulnerability in the documentat ...)
+ TODO: check
CVE-2026-93854 (In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce o ...)
- blazar <unfixed>
NOTE: https://launchpad.net/bugs/2162719
@@ -142,61 +448,61 @@ CVE-2026-93578 (A flaw was found in Netty's Online Certificate Status Protocol (
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536969
NOTE: https://github.com/netty/netty/security/advisories/GHSA-jhjp-5q4f-8wr2
-CVE-2026-93576 (Netty netty-codec-smtp \u2014 SMTP command-name field is not CRLF-vali ...)
+CVE-2026-93576 (A flaw was found in Netty netty-codec-smtp. The component does not pro ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536968
NOTE: https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p
-CVE-2026-93575 (### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder ...)
+CVE-2026-93575 (A flaw was found in Netty's MqttDecoder. An unauthenticated remote att ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536967
NOTE: https://github.com/netty/netty/security/advisories/GHSA-jqf3-r9ww-c5x8
-CVE-2026-93573 (Netty split Transfer-Encoding fields bypass final-chunked validation a ...)
+CVE-2026-93573 (A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allow ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536964
NOTE: https://github.com/netty/netty/security/advisories/GHSA-3jrc-fchc-59pw
-CVE-2026-93572 (## Summary `RedisArrayAggregator` recently added `maxElements` and `m ...)
+CVE-2026-93572 (A flaw was found in Netty's `RedisArrayAggregator` component. A remote ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536963
NOTE: https://github.com/netty/netty/security/advisories/GHSA-r4xx-7fpg-j8xg
-CVE-2026-93569 (HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, ...)
+CVE-2026-93569 (A flaw was found in Netty. A remote unauthenticated attacker can explo ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536962
NOTE: https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m
-CVE-2026-93568 (HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular ...)
+CVE-2026-93568 (A flaw was found in Netty. A remote attacker could exploit this vulner ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536961
NOTE: https://github.com/netty/netty/security/advisories/GHSA-w6j8-x45j-w75f
-CVE-2026-93567 (HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNEC ...)
+CVE-2026-93567 (A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNE ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536955
NOTE: https://github.com/netty/netty/security/advisories/GHSA-45h4-vhwh-fmhg
-CVE-2026-93566 (### Summary Netty skips strict chunk size line validation when the lin ...)
+CVE-2026-93566 (A flaw was found in Netty. A remote attacker could exploit this by sen ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536954
NOTE: https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698
-CVE-2026-93565 (### Summary `RtspMethods.valueOf()` silently strips trailing control b ...)
+CVE-2026-93565 (A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` fun ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536952
NOTE: https://github.com/netty/netty/security/advisories/GHSA-h75q-xqrh-59rf
-CVE-2026-93564 (HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (i ...)
+CVE-2026-93564 (A flaw was found in Netty. A reference-count leak in the HAProxy PROXY ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536953
NOTE: https://github.com/netty/netty/security/advisories/GHSA-j58c-g352-8h4p
-CVE-2026-93563 (Unbounded multi-line response accumulation in SmtpResponseDecoder lead ...)
+CVE-2026-93563 (A flaw was found in Netty's `SmtpResponseDecoder` component. A remote ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536976
NOTE: https://github.com/netty/netty/security/advisories/GHSA-pq4x-537v-r54q
-CVE-2026-93561 (Memcache binary codec signed/unsigned type mismatch causes frame desyn ...)
+CVE-2026-93561 (A flaw was found in io.netty/netty-codec-memcache. The Memcache binary ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536949
NOTE: https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg
-CVE-2026-93560 (STOMP codec content-length long-to-int truncation causes infinite deco ...)
+CVE-2026-93560 (A flaw was found in the Netty STOMP codec. A remote attacker could sen ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536939
NOTE: https://github.com/netty/netty/security/advisories/GHSA-hmf3-49g9-g7qq
CVE-2026-93559 (A vulnerability was identified in Forget-C Jellyfish AI Short Drama St ...)
NOT-FOR-US: Forget-C Jellyfish AI Short Drama Studio
-CVE-2026-93558 (Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandl ...)
+CVE-2026-93558 (A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, ...)
- netty <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536932
NOTE: https://github.com/netty/netty/security/advisories/GHSA-2g37-3h88-55hc
@@ -10284,7 +10590,7 @@ CVE-2026-13293 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LT
NOT-FOR-US: IBM
CVE-2026-13287 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
NOT-FOR-US: IBM
-CVE-2026-13285 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
+CVE-2026-13285 (IBM MQ is vulnerable to an XML external entity injection (XXE) attack ...)
NOT-FOR-US: IBM
CVE-2026-13277 (IBM Verify Identity Access could allow a remote attacker to conduct ph ...)
NOT-FOR-US: IBM
@@ -26481,50 +26787,50 @@ CVE-2026-89156 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a
[trixie] - pcre2 10.46-1~deb13u2
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5 pcre2-10.48-RC1)
-CVE-2026-57227 [mqtt: unbounded number of messages per tx]
+CVE-2026-57227 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.6-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-7h2h-hpj2-9w6p
NOTE: https://redmine.openinfosecfoundation.org/issues/8672 (suricata-7.0.17)
NOTE: https://redmine.openinfosecfoundation.org/issues/8653 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/5cde93dea38533c9b225128ba9d54955997dc273 (suricata-7.0.17)
NOTE: https://github.com/OISF/suricata/commit/c03666d261256df5a2d1f5800872da8a5addf6a5 (suricata-8.0.6)
-CVE-2026-57229 [smtp: evasion due to incomplete state reset]
+CVE-2026-57229 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.6-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-ph5p-pm8r-m355
NOTE: https://redmine.openinfosecfoundation.org/issues/8650 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/c0215c7e175b0000ef8450928dd1f3453c48379b (suricata-8.0.6)
-CVE-2026-57223 [windows: unquoted LocalSystem service ImagePath]
+CVE-2026-57223 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.6-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-jh8w-wf3f-58jp
NOTE: https://redmine.openinfosecfoundation.org/issues/8665 (suricata-7.0.17)
NOTE: https://redmine.openinfosecfoundation.org/issues/8627 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/0dad38fff024b4fec9bc8144d8b94dbca39aac2e (suricata-7.0.17)
NOTE: https://github.com/OISF/suricata/commit/2b924d47cc51d0b7760cda3519f2c04a2f65ea38 (suricata-8.0.6)
-CVE-2026-57225 [datasets: NULL dereference on unexpected ndjson files]
+CVE-2026-57225 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.6-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-vqqx-88xw-qqvc
NOTE: https://redmine.openinfosecfoundation.org/issues/8625 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/bd3293aca714f5d090b73e7d9be0e5cd7e3f5f53 (suricata-8.0.6)
-CVE-2026-57224 [dhcp: unbounded tx growth with unidirectional traffic]
+CVE-2026-57224 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.6-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-m2vc-g65c-ph7m
NOTE: https://redmine.openinfosecfoundation.org/issues/8622 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/f234d155bcf43df403ee0823b60de8d02e2b99b2 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/bac8a69ca48c14582d39a244a87edad44751ebe1 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/ef035c7603293a10c5ad087e3d20b05f75236144 (suricata-8.0.6)
-CVE-2026-57226 [detect/file_data: heap buffer overflow in SWF decompression depth handling]
+CVE-2026-57226 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.6-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-p33j-r48q-3jcf
NOTE: https://redmine.openinfosecfoundation.org/issues/8644 (suricata-7.0.17)
NOTE: https://redmine.openinfosecfoundation.org/issues/8643 (suricata-8.0.6)
NOTE: https://github.com/OISF/suricata/commit/82af0aeb7cec39e206a9ca96c4966425eddeaa74 (suricata-7.0.17)
NOTE: https://github.com/OISF/suricata/commit/b63224871b0f8b0b1f7b8c22d05ba8a5c5f69fbb (suricata-8.0.6)
-CVE-2026-57228 [mime: buffer over read in quoted printable decoding]
+CVE-2026-57228 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.1-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-qxm4-q7vx-7xj4
NOTE: https://redmine.openinfosecfoundation.org/issues/8608 (suricata-7.0.17)
NOTE: https://github.com/OISF/suricata/commit/19880f9d5bbe2b8f8e8867a577848dce2b532c86 (suricata-7.0.17)
-CVE-2026-57222 [ippair: IPv4/IPv6 hash collision can reuse wrong IPPair state]
+CVE-2026-57222 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
- suricata 1:8.0.6-1
NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-2r8x-23fw-hgcg
NOTE: https://redmine.openinfosecfoundation.org/issues/8569 (suricata-7.0.17)
@@ -53685,7 +53991,8 @@ CVE-2026-XXXX [GHSA-q4gr-vc25-57m5]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/9b990351898b18b48bf4e834bcbc618d270cf8b1 (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/85f241ef6b3784257f0278c4dfbd988355921862 (branch flatpak-1.16.x)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/b0f1704b34d2a551c0073a9fc5e918174a97af64 (branch flatpak-1.16.x)
-CVE-2026-93676 [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks]
+CVE-2026-93676 (xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing ...)
+ {DSA-6433-1}
- xdg-dbus-proxy 0.1.8-1 (bug #1144129)
[bookworm] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
[bullseye] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
@@ -69953,7 +70260,7 @@ CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious boot
[trixie] - ironic-python-agent <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
-CVE-2026-58264 [heap-based buffer overrun in command handler]
+CVE-2026-58264 (FluidSynth is a software synthesizer based on the SoundFont 2 specific ...)
- fluidsynth 2.5.6+dfsg-1
[trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
[bookworm] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
@@ -69962,7 +70269,7 @@ CVE-2026-58264 [heap-based buffer overrun in command handler]
NOTE: https://github.com/FluidSynth/fluidsynth/pull/1796
NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/8131539ad6c37a832bd67ee26791ef8e28259423 (v1.1.2)
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c87909d087 (v2.5.6)
-CVE-2026-61714 [heap-based buffer overflow in MIDI player]
+CVE-2026-61714 (FluidSynth is a software synthesizer based on the SoundFont 2 specific ...)
- fluidsynth 2.5.6+dfsg-1
[trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
[bookworm] - fluidsynth <postponed> (Needs a non-default synth.midi-channels > 16; MIDI file channels are masked to 4 bits so a crafted file cannot reach it)
@@ -69970,7 +70277,7 @@ CVE-2026-61714 [heap-based buffer overflow in MIDI player]
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6
NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/6c593180ce05f8bbbd07217456bc4376a4ab4505 (v2.2.4)
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/772702e00cc6acc7c607efb40283e2269211effc (v2.5.6)
-CVE-2026-61721 [heap-based buffer overrun for DLS samples]
+CVE-2026-61721 (FluidSynth is a software synthesizer based on the SoundFont 2 specific ...)
- fluidsynth 2.5.6+dfsg-1
[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
@@ -69978,7 +70285,7 @@ CVE-2026-61721 [heap-based buffer overrun for DLS samples]
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-59ph-rx8r-8p4j
NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/2354c2a9acdb26de7cdcd37c903ee108f46c0a7d (v2.5.6)
-CVE-2026-61723 ]DLS ptbl chunk integer overflow]
+CVE-2026-61723 (FluidSynth is a software synthesizer based on the SoundFont 2 specific ...)
- fluidsynth 2.5.6+dfsg-1
[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
@@ -69986,7 +70293,7 @@ CVE-2026-61723 ]DLS ptbl chunk integer overflow]
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-r4mc-v3p8-pv47
NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/a2ab32b9c3b9f8845b7254adea73c211f6c5a24c (v2.5.6)
-CVE-2026-61722 [DLS articulation chunk integer overflow]
+CVE-2026-61722 (FluidSynth is a software synthesizer based on the SoundFont 2 specific ...)
- fluidsynth 2.5.6+dfsg-1
[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
@@ -69994,7 +70301,7 @@ CVE-2026-61722 [DLS articulation chunk integer overflow]
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-hp72-35pr-6h6r
NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/4d7084fca7c876f5d738498b4917a39faf603425 (v2.5.6)
-CVE-2026-61720 [SF2 DMOD chunk integer underflow]
+CVE-2026-61720 (FluidSynth is a software synthesizer based on the SoundFont 2 specific ...)
- fluidsynth 2.5.6+dfsg-1
[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
@@ -137883,7 +138190,7 @@ CVE-2026-41248 (Clerk JavaScript is the official JavaScript repository for Clerk
NOT-FOR-US: Clerk
CVE-2026-41244 (Mojic is a CLI tool to transform readable C code into an unrecognizabl ...)
NOT-FOR-US: Mojic
-CVE-2026-93599 [RUSTSEC-2026-0104]
+CVE-2026-93599 (rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.10 ...)
- rust-rustls-webpki 0.103.13+ds-1
[trixie] - rust-rustls-webpki <no-dsa> (Minor issue)
NOTE: https://github.com/rustls/webpki/security/advisories/GHSA-82j2-j2ch-gfr8
@@ -146908,7 +147215,7 @@ CVE-2024-1490 (An authenticated remote attacker with high privileges can exploit
NOT-FOR-US: WAGO
CVE-2026-1403
- gitlab <removed>
-CVE-2026-93602 [RUSTSEC-2026-0049]
+CVE-2026-93602 (rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain fau ...)
- rust-rustls-webpki 0.103.10+ds-1 (bug #1133085)
[trixie] - rust-rustls-webpki <no-dsa> (Minor issue)
NOTE: https://github.com/rustls/webpki/security/advisories/GHSA-pwjx-qhcg-rvj4
@@ -180077,7 +180384,7 @@ CVE-2026-22225 (A command injection vulnerability may be exploited after the adm
NOT-FOR-US: TP-Link
CVE-2026-22224 (A command injection vulnerability may be exploited after the admin's a ...)
NOT-FOR-US: TP-Link
-CVE-2026-22223 (An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn ...)
+CVE-2026-22223 (An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and ...)
NOT-FOR-US: TP-Link
CVE-2026-22222 (An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web ...)
NOT-FOR-US: TP-Link
@@ -180174,7 +180481,7 @@ CVE-2026-1117 (A vulnerability in the `lollms_generation_events.py` component of
NOT-FOR-US: parisneo/lollms
CVE-2026-0921
REJECTED
-CVE-2026-0631 (An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn ...)
+CVE-2026-0631 (An OS Command Injection vulnerability in OpenVPN modules in TP-Link Ar ...)
NOT-FOR-US: TP-Link
CVE-2026-0630 (An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web ...)
NOT-FOR-US: TP-Link
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e453f4668b5f81cf0e7feb498ab5f87bb849fdd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e453f4668b5f81cf0e7feb498ab5f87bb849fdd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/93d911d2/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list