[Git][security-tracker-team/security-tracker][master] new openimageio issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 20 18:46:19 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e10175ba by Moritz Muehlenhoff at 2026-09-20T19:45:52+02:00
new openimageio issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1073,7 +1073,11 @@ CVE-2026-6205 (An external control of file name or path vulnerability in Upload
CVE-2026-68914 (Mojolicious is a real-time web framework for Perl. Prior to 9.47, the ...)
TODO: check
CVE-2026-67549 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <not-affected> (Vulnerable code introduced later)
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-3wxw-rqhw-j2w4
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5296
+ NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/6e9b86ee4cce8fd7bed6cfb101a266d8f8a296d4 (v3.2.0.3-beta1)
+ NOTE: Introduced by: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/730687ae79bb6c3290afff535aa0e98b0531d165 (v3.1.4.0-beta)
CVE-2026-67103 (HCL BigFix Service Management is affected by Cross-Site Scripting (XSS ...)
NOT-FOR-US: HCL
CVE-2026-67102 (HCL BigFix Service Management is affected by a high-severity Broken Ac ...)
@@ -1083,25 +1087,47 @@ CVE-2026-67101 (HCL BigFix Service Management is affected by a Server-Side Reque
CVE-2026-67100 (HCL BigFix Service Management is affected by SQL Injection flaw and a ...)
NOT-FOR-US: HCL
CVE-2026-65970 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <not-affected> (Vulnerable code introduced later)
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-v278-gpwr-r836
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5294
+ NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/31201c22df477b105b105c0dcfbf5d3d46db431b (v3.2.0.3-beta1)
+ NOTE: Introduced by: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/730687ae79bb6c3290afff535aa0e98b0531d165 (v3.1.4.0-beta)
CVE-2026-65969 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-9mwc-fjgj-8wmq
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5292
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/134977da625a84fc5a09a34321806f1fe0093c24 (v3.2.0.3-beta1)
CVE-2026-64847 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
TODO: check
CVE-2026-63638 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-9hxv-jvgr-3x8g
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5283
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/6f2b2e85b3b3933ccc5a46303d5535f99bfa39fb (v3.2.0.3-beta1)
CVE-2026-63635 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-3c8w-9xvm-r6gf
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5282
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/50481b0f90932a4675f65f3cc26407139cb9e20e (v3.2.0.3-beta1)
CVE-2026-63458 (Perses is an open-source dashboard and visualization project for obser ...)
NOT-FOR-US: Perses
CVE-2026-63445 (Perses is an open-source dashboard and visualization project for obser ...)
NOT-FOR-US: Perses
CVE-2026-63422 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xh5r-whph-qmc5
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5295
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/7303134f13b0f9dc738b8ecabecd8c9f90cbd4c9 (v3.2.0.3-beta1)
CVE-2026-63420 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-x877-h4xx-5m5j
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5307
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/4995b25b8216552630e0aee0d8870e0d3aaae7ee (v3.2.0.3-beta1)
CVE-2026-63419 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-w6wc-gcf4-5pj2
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5268
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/9cda48b150294c7f024e680a6c9b0402e50f4816 (v3.2.0.3-beta1)
CVE-2026-63406 (AnyCable is a realtime server for reliable two-way communication that ...)
TODO: check
CVE-2026-63405 (AnyCable is a realtime server for reliable two-way communication that ...)
@@ -1133,13 +1159,22 @@ CVE-2026-61633 (NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client fu
CVE-2026-60115
REJECTED
CVE-2026-59956 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-hjfv-gvxc-qgvh
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5251
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/f01bd16764b2a06f372899e3e302280a7f9c8c02 (v3.2.0.3-beta1)
CVE-2026-59181 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xh8r-vmqq-56pp
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5250
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/908f22f5528e88e5e96184c194caa26b54b2b85f (v3.2.0.3-beta1)
CVE-2026-59163 (Mnemosyne is a memory layer for artificial intelligence agents. Prior ...)
TODO: check
CVE-2026-59156 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- TODO: check
+ - openimageio <unfixed>
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xvwr-x6ch-v2fq
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5248
+ NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/b0de7d40d06eb4abc7ef14c1321a1a2a976d8c1c (v3.2.0.3-beta1)
CVE-2026-58197 (ToolHive is a utility designed to simplify the deployment and manageme ...)
NOT-FOR-US: ToolHive
CVE-2026-56597 (HCL BigFix Service Management is affected by a Sensitive Information L ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e10175baf236f469dbca862ffc9330209c5ee1f1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e10175baf236f469dbca862ffc9330209c5ee1f1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/9efddb30/attachment.htm>
More information about the debian-security-tracker-commits
mailing list