[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Sep 19 17:04:36 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
57cd99c1 by Moritz Muehlenhoff at 2026-09-19T18:04:08+02:00
trixie triage
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -276,30 +276,37 @@ CVE-2026-63446 (Suricata is a network Intrusion Detection System, Intrusion Prev
NOTE: Fixed by: https://github.com/OISF/suricata/commit/60a83c62a1dfdfb589b2bad27fb7fc339fc964b7 (suricata-8.0.6)
CVE-2026-61822 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-9m6c-hw23-c6h2
NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
CVE-2026-61821 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-pxp2-x8cf-rfhc
NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
CVE-2026-61820 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-xqxh-6hh3-974m
NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
CVE-2026-61819 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-gv5h-j2cm-rhc3
NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
CVE-2026-61818 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-fm3m-9fh7-mqfc
NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
CVE-2026-61817 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-gmw2-52wc-258g
NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
CVE-2026-61781 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-742w-3j7c-qwvp
NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
CVE-2026-61670 (microsandbox is an easy, fast, local-first microVM runtime and library ...)
@@ -376,22 +383,27 @@ CVE-2026-93758 (An insecure direct object reference in the nested attributes han
NOT-FOR-US: Mongoid
CVE-2026-93753 (deepmerge through 4.3.1 contains a prototype poisoning vulnerability i ...)
- node-deepmerge <unfixed> (bug #1148407)
+ [trixie] - node-deepmerge <no-dsa> (Minor issue)
NOTE: https://github.com/TehShrike/deepmerge/issues/273
CVE-2026-93752 (CSSOM through 0.5.0 contains a denial of service vulnerability in CSSS ...)
NOT-FOR-US: CSSOM
CVE-2026-93751 (uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability ...)
- node-uri-js <unfixed> (bug #1148403)
+ [trixie] - node-uri-js <no-dsa> (Minor issue)
NOTE: https://github.com/garycourt/uri-js/issues/106
CVE-2026-93750 (http-cache-semantics through 4.2.0 contains a cache validation vulnera ...)
- node-got <unfixed> (bug #1148406)
+ [trixie] - node-got <no-dsa> (Minor issue)
NOTE: https://github.com/kornelski/http-cache-semantics/issues/57
NOTE: node-got embeds and provides node-http-cache-semantics
CVE-2026-93749 (source-map-js through 1.2.1 fails to validate the per-section offset l ...)
- node-postcss <unfixed> (bug #1148404)
+ [trixie] - node-postcss <no-dsa> (Minor issue)
NOTE: https://github.com/7rulnik/source-map-js/issues/76
NOTE: node-postcss embeds and provides node-source-map-js
CVE-2026-93748 (http-cache-semantics through 4.2.0 fails to properly validate security ...)
- node-got <unfixed> (bug #1148405)
+ [trixie] - node-got <no-dsa> (Minor issue)
NOTE: https://github.com/kornelski/http-cache-semantics/issues/56
NOTE: node-got embeds and provides node-http-cache-semantics
CVE-2026-93737 (Azkaban through 4.0.0 omits project permission checks in the ScheduleS ...)
@@ -400,6 +412,7 @@ CVE-2026-93736 (Mealie before 3.21.0 fails to validate user ownership in the rat
NOT-FOR-US: Mealie
CVE-2026-93690 (uri-js through 4.4.1 contains a denial of service vulnerability in the ...)
- node-uri-js <unfixed> (bug #1148402)
+ [trixie] - node-uri-js <no-dsa> (Minor issue)
NOTE: https://github.com/garycourt/uri-js/issues/105
CVE-2026-93689 (WinFsp through 2.2.26215 contains a null pointer dereference vulnerabi ...)
NOT-FOR-US: WinFsp
@@ -407,6 +420,7 @@ CVE-2026-93688 (SGLang through 0.5.19 in prefill/decode disaggregation mode with
NOT-FOR-US: SGLang
CVE-2026-93687 (braces through 3.0.3 contains a stack overflow vulnerability in the re ...)
- node-braces <unfixed> (bug #1148400)
+ [trixie] - node-braces <no-dsa> (Minor issue)
NOTE: https://github.com/micromatch/braces/issues/70
CVE-2026-93685 (A flaw was found in the multicluster-observability-addon. A remote att ...)
NOT-FOR-US: multicluster-observability-addon (Red Hat Advanced Cluster Management for Kubernetes 2)
@@ -462,20 +476,24 @@ CVE-2026-93591 (SiYuan versions before 3.8.3 contain an SQL injection vulnerabil
NOT-FOR-US: SiYuan
CVE-2026-93590 (ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/59046410c17e9421f0ad7b4bec478a892cf30c12 (7.1.2-31)
CVE-2026-93589 (ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/8f620237fe341e814430fe3621b867b0b615f446 (7.1.2-31)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/1e91833e30a88c104276dcfbc01bb68ac4528514 (6.9.13-56)
CVE-2026-93588 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL point ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-92rw-c5mw-27v4
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/c4b3c9039a1509e3e7869331773865b521a62f93 (7.1.2-31)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3b124bb81d3c53ec7d2b46f5ea04c00c4b07b9b3 (6.9.13-56)
CVE-2026-93587 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy byp ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/d779ac52f92c3045ced59362b483bee25a3fc784 (7.1.2-31)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b5da5eac006bae77c587a7c238e346c90ea52acd (7.1.2-31)
@@ -483,6 +501,7 @@ CVE-2026-93587 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a poli
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0d768346a13b63e4d791be4b798482abd1e050d5 (6.9.13-56)
CVE-2026-93586 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after- ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/282f455de5c80a7a0d1a713087db9c8fce344141 (7.1.2-31)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/4fe31106f41fa114945ceaf93226fb151ada0d19 (7.1.2-31)
@@ -631,6 +650,7 @@ CVE-2026-90884 (The WP Recipe Maker plugin for WordPress is vulnerable to Stored
CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes attacke ...)
- resteasy <unfixed>
- resteasy3.0 <unfixed>
+ [trixie] - resteasy3.0 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519756
NOTE: https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
NOTE: https://redhat.atlassian.net/browse/RESTEASY-3793
@@ -638,6 +658,7 @@ CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes a
CVE-2026-89058 (A flaw was found in RESTEasy's CorsFilter, which, when configured to a ...)
- resteasy <unfixed>
- resteasy3.0 <unfixed>
+ [trixie] - resteasy3.0 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519775
NOTE: https://github.com/resteasy/resteasy/security/advisories/GHSA-972r-f3fv-whm3
NOTE: https://redhat.atlassian.net/browse/RESTEASY-3796
@@ -717,6 +738,7 @@ CVE-2026-81942 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmw
NOT-FOR-US: PLANET
CVE-2026-81627 (A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c ...)
- qemu <unfixed>
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4206
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d61c8a6fb7388486353aa267ba0d75b098f16662 (master)
CVE-2026-81505 (Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's G ...)
@@ -1532,6 +1554,7 @@ CVE-2024-27123 (A cross-site scripting (XSS) vulnerability has been reported to
NOT-FOR-US: QNAP
CVE-2026-XXXX [OSSA-2026-039]
- octavia 18.0.0-4 (bug #1148175)
+ [trixie] - octavia <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/octavia/+bug/2162101
NOTE: https://bugs.launchpad.net/octavia/+bug/2162103
NOTE: https://security.openstack.org/ossa/OSSA-2026-039.html
@@ -1763,10 +1786,12 @@ CVE-2026-86038 (libp2p is a JavaScript implementation of the libp2p networking s
NOT-FOR-US: Node libp2p
CVE-2026-86000 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
- soupsieve <unfixed>
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-gjv8-xp57-g29c
NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef (2.9)
CVE-2026-85999 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
- soupsieve <unfixed>
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-j934-xhv5-fg8f
NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda (2.9)
CVE-2026-85721 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
@@ -4617,6 +4642,7 @@ CVE-2026-62997 (Kedro-Datasets provides data connectors for Kedro. From version
NOT-FOR-US: Kedro-Datasets
CVE-2026-62949 (AsyncSSH is a Python package which provides an asynchronous client and ...)
- python-asyncssh <unfixed>
+ [trixie] - python-asyncssh <no-dsa> (Minor issue)
NOTE: https://github.com/ronf/asyncssh/security/advisories/GHSA-rw4j-r22c-9gc3
NOTE: https://github.com/ronf/asyncssh/commit/9c354270c009285525e126721e8ed5fbed1f8a67 (v2.24.0)
NOTE: https://github.com/ronf/asyncssh/commit/756cbae5350789ce9735f15f704bae9b5a3608b8
@@ -5509,10 +5535,12 @@ CVE-2026-85756 (SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.
NOT-FOR-US: SSH.NET
CVE-2026-85732 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, th ...)
- golang-oras-oras-go 2.6.2-1
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-h7vf-4x9w-h99v
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/31da1963f8c327dd089cd29faeae95cf0fc50842 (v2.6.2)
CVE-2026-85731 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, co ...)
- golang-oras-oras-go 2.6.2-1
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-m37j-52j7-pjw7
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/adab2f25ea95ef4e6e41f50db9266a6701399422 (v2.6.2)
CVE-2026-85641 (The Formidable Forms WordPress plugin before 6.35 does not restrict w ...)
@@ -6500,51 +6528,61 @@ CVE-2026-77702 (The Eventin WordPress plugin before 4.1.24 does not prevent the
NOT-FOR-US: WordPress plugin
CVE-2026-77412 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readFi ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3
NOTE: https://github.com/rabbitmq/amqp091-go/pull/344
NOTE: https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf (v1.13.0)
CVE-2026-77411 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLo ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-c5pq-fr2g-9jpf
NOTE: https://github.com/rabbitmq/amqp091-go/pull/347
NOTE: https://github.com/rabbitmq/amqp091-go/commit/143c1ace5fa7344cee135e5c7d22970f0de68282 (v1.13.0)
CVE-2026-77410 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channe ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh
NOTE: https://github.com/rabbitmq/amqp091-go/pull/346
NOTE: https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382 (v1.13.0)
CVE-2026-77409 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channe ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-wxx3-cj7g-w73j
NOTE: https://github.com/rabbitmq/amqp091-go/pull/349
NOTE: https://github.com/rabbitmq/amqp091-go/commit/5b0ccbb8d7bc3dfa18129d9b0f9256d656809494 (v1.13.0)
CVE-2026-77408 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the wr ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-j497-x9hr-x34x
NOTE: https://github.com/rabbitmq/amqp091-go/pull/354
NOTE: https://github.com/rabbitmq/amqp091-go/commit/6959423aa2784a1971e399175dfb2065dea0f3b0 (v1.13.0)
CVE-2026-77407 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainA ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-27gv-rfvv-22mv
NOTE: https://github.com/rabbitmq/amqp091-go/pull/350
NOTE: https://github.com/rabbitmq/amqp091-go/commit/fa013b8447eb60988db3c9281ff6b981e4d2fb4f (v1.13.0)
CVE-2026-77406 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channe ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-rm6m-hrcw-jw33
NOTE: https://github.com/rabbitmq/amqp091-go/pull/351
NOTE: https://github.com/rabbitmq/amqp091-go/commit/3b879e1d1d25b544e26b3bc3d7db3213203c0f3b (v1.13.0)
CVE-2026-77405 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsCon ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-33mj-cw25-m34h
NOTE: https://github.com/rabbitmq/amqp091-go/pull/355
NOTE: https://github.com/rabbitmq/amqp091-go/commit/c9fd433ecac2e557919e51acc9d809390c402c6e (v1.13.0)
CVE-2026-77404 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.St ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-465g-fh3v-9jw4
NOTE: https://github.com/rabbitmq/amqp091-go/pull/352
NOTE: https://github.com/rabbitmq/amqp091-go/commit/743d488e46955fe7ffc55506fe2c401d01216783 (v1.13.0)
CVE-2026-77403 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connec ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-xwwf-m8fg-p9q2
NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
NOTE: https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06 (v1.13.0)
@@ -7088,7 +7126,9 @@ CVE-2026-19535 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request Fo
NOT-FOR-US: Advantech
CVE-2026-19248 (QDomDocument XML parsing is vulnerable to a remotely-triggerable denia ...)
- qt6-base <unfixed> (bug #1148271)
+ [trixie] - qt6-base <no-dsa> (Minor issue)
- qtbase-opensource-src <unfixed> (bug #1148272)
+ [trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
NOTE: https://qt-project.atlassian.net/browse/QTBUG-147191
NOTE: https://github.com/qt/qtbase/commit/1303f05b33bb777626644729dd3b1330f60ecb7f (6.10)
CVE-2026-18595 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stor ...)
=====================================
data/DSA/list
=====================================
@@ -5,7 +5,7 @@
{CVE-2026-87429 CVE-2026-87430 CVE-2026-87431 CVE-2026-87432 CVE-2026-87433 CVE-2026-87434 CVE-2026-87435 CVE-2026-87436 CVE-2026-87437 CVE-2026-87438 CVE-2026-87439 CVE-2026-87440 CVE-2026-87441 CVE-2026-87442 CVE-2026-87443 CVE-2026-87444 CVE-2026-87445 CVE-2026-87446 CVE-2026-87447 CVE-2026-87448 CVE-2026-87449 CVE-2026-87450 CVE-2026-87451 CVE-2026-87452 CVE-2026-87453 CVE-2026-87454 CVE-2026-87455 CVE-2026-87456 CVE-2026-87457 CVE-2026-87458 CVE-2026-87459 CVE-2026-87460 CVE-2026-87461 CVE-2026-87462 CVE-2026-87463 CVE-2026-87464 CVE-2026-87465 CVE-2026-87466 CVE-2026-87467 CVE-2026-87468 CVE-2026-87469 CVE-2026-87470 CVE-2026-87471 CVE-2026-87472 CVE-2026-87473 CVE-2026-87474 CVE-2026-87475 CVE-2026-87476 CVE-2026-87477 CVE-2026-87478 CVE-2026-87479 CVE-2026-87480 CVE-2026-87481 CVE-2026-87482 CVE-2026-87483 CVE-2026-87484 CVE-2026-87485 CVE-2026-87486 CVE-2026-87487 CVE-2026-87488 CVE-2026-87489 CVE-2026-87490 CVE-2026-87491 CVE-2026-87492 CVE-2026-87493 CVE-2026-87494 CVE-2026-87495 CVE-2026-87496 CVE-2026-87497 CVE-2026-87498 CVE-2026-87499 CVE-2026-87500 CVE-2026-87501 CVE-2026-87502 CVE-2026-87503 CVE-2026-87504 CVE-2026-87505 CVE-2026-87506 CVE-2026-87507 CVE-2026-87508 CVE-2026-87509 CVE-2026-87510 CVE-2026-87511 CVE-2026-87512 CVE-2026-87513 CVE-2026-87514 CVE-2026-87515 CVE-2026-87516 CVE-2026-87517 CVE-2026-87518 CVE-2026-87519 CVE-2026-87520 CVE-2026-87521 CVE-2026-87522 CVE-2026-87523 CVE-2026-87524 CVE-2026-87525 CVE-2026-87526 CVE-2026-87527 CVE-2026-87528 CVE-2026-87529 CVE-2026-87530 CVE-2026-87531 CVE-2026-87532 CVE-2026-87533 CVE-2026-87534 CVE-2026-87535 CVE-2026-87536 CVE-2026-87537 CVE-2026-87538 CVE-2026-87539 CVE-2026-87540 CVE-2026-87541 CVE-2026-87542 CVE-2026-87543 CVE-2026-87544 CVE-2026-87545 CVE-2026-87546 CVE-2026-87547 CVE-2026-87548 CVE-2026-87549 CVE-2026-87550 CVE-2026-87551 CVE-2026-87552 CVE-2026-87553 CVE-2026-87554 CVE-2026-87555 CVE-2026-87556 CVE-2026-87557 CVE-2026-87558 CVE-2026-87559 CVE-2026-87560 CVE-2026-87561 CVE-2026-87562 CVE-2026-87563 CVE-2026-87564 CVE-2026-87565 CVE-2026-87566 CVE-2026-87567 CVE-2026-87568 CVE-2026-87569 CVE-2026-87570 CVE-2026-87571 CVE-2026-87572 CVE-2026-87573 CVE-2026-87574 CVE-2026-87575 CVE-2026-87576 CVE-2026-87577 CVE-2026-87578 CVE-2026-87579 CVE-2026-87580 CVE-2026-87581 CVE-2026-87582 CVE-2026-87583 CVE-2026-87584 CVE-2026-87585 CVE-2026-87586 CVE-2026-87587 CVE-2026-87588 CVE-2026-87589 CVE-2026-87590 CVE-2026-87591 CVE-2026-87592 CVE-2026-87593 CVE-2026-87594 CVE-2026-87595 CVE-2026-87596 CVE-2026-87597 CVE-2026-87598 CVE-2026-87599 CVE-2026-87600 CVE-2026-87601 CVE-2026-87602 CVE-2026-87603 CVE-2026-87604 CVE-2026-87605 CVE-2026-87606 CVE-2026-87607 CVE-2026-87608 CVE-2026-87609 CVE-2026-87610 CVE-2026-87611 CVE-2026-87612 CVE-2026-87613 CVE-2026-87614 CVE-2026-87615 CVE-2026-87616 CVE-2026-87617 CVE-2026-87618 CVE-2026-87619 CVE-2026-87620 CVE-2026-87621 CVE-2026-87622 CVE-2026-87623 CVE-2026-87624 CVE-2026-87625 CVE-2026-87626 CVE-2026-87627 CVE-2026-87628 CVE-2026-87629 CVE-2026-87630 CVE-2026-87631 CVE-2026-87632 CVE-2026-87633 CVE-2026-87634 CVE-2026-87635 CVE-2026-87636 CVE-2026-87637 CVE-2026-87638 CVE-2026-87639 CVE-2026-87640 CVE-2026-87641 CVE-2026-87642 CVE-2026-87643 CVE-2026-87644 CVE-2026-87645 CVE-2026-87646 CVE-2026-87647 CVE-2026-87648 CVE-2026-87649 CVE-2026-87650 CVE-2026-87651 CVE-2026-87652 CVE-2026-87653 CVE-2026-87654 CVE-2026-87655 CVE-2026-87656 CVE-2026-87657 CVE-2026-87658 CVE-2026-91708 CVE-2026-91709 CVE-2026-91710 CVE-2026-91711 CVE-2026-91712 CVE-2026-91713 CVE-2026-91714 CVE-2026-91715 CVE-2026-91716 CVE-2026-91717 CVE-2026-91718 CVE-2026-91719 CVE-2026-91720 CVE-2026-91721 CVE-2026-91722 CVE-2026-91723 CVE-2026-91724 CVE-2026-91725 CVE-2026-91726 CVE-2026-91727 CVE-2026-91728 CVE-2026-91729 CVE-2026-91730 CVE-2026-91731 CVE-2026-91732 CVE-2026-91733 CVE-2026-91734 CVE-2026-91735 CVE-2026-91736 CVE-2026-91737 CVE-2026-91738 CVE-2026-91739 CVE-2026-91740 CVE-2026-91741 CVE-2026-91742 CVE-2026-91743 CVE-2026-91744 CVE-2026-91745 CVE-2026-91746 CVE-2026-91747 CVE-2026-91748 CVE-2026-91749}
[trixie] - chromium 153.0.8010.47-2~deb13u1
[17 Sep 2026] DSA-6505-1 bind9 - security update
- {CVE-2026-19033 CVE-2026-19662 CVE-2026-19666 CVE-2026-19667 CVE-2026-19668 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736}
+ {CVE-2026-19033 CVE-2026-19662 CVE-2026-19666 CVE-2026-19667 CVE-2026-19668 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 CVE-2026-78301 CVE-2026-19941}
[trixie] - bind9 1:9.20.29-1~deb13u1
[17 Sep 2026] DSA-6504-1 libapache2-mod-auth-openidc - security update
{CVE-2026-54789}
=====================================
data/dsa-needed.txt
=====================================
@@ -44,6 +44,8 @@ firebird3.0
--
firebird4.0
--
+freerdp3
+--
gegl (jmm)
move to 0.4.72
--
@@ -86,6 +88,13 @@ netty
--
network-manager-iodine
--
+network-manager-sstp
+ no upstream fix yet, if totally dead removal is an option
+--
+network-manager-vpnc
+ no upstream fix yet, if totally dead removal is an option
+--
+
nodejs (jmm)
Bastien Roucaries posted debdiff for review
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57cd99c14ed1b9ff9d0210aeda2074eef279e164
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57cd99c14ed1b9ff9d0210aeda2074eef279e164
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/8f7d605e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list