[Git][security-tracker-team/security-tracker][master] new python-anyio issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 20 19:23:52 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
65e61f02 by Moritz Muehlenhoff at 2026-09-20T20:23:28+02:00
new python-anyio issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1098,7 +1098,10 @@ CVE-2026-65969 (OpenImageIO is a toolset for reading, writing, and manipulating
NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5292
NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/134977da625a84fc5a09a34321806f1fe0093c24 (v3.2.0.3-beta1)
CVE-2026-64847 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
- TODO: check
+ - python-anyio <unfixed>
+ NOTE: https://github.com/agronholm/anyio/security/advisories/GHSA-5p39-cfhj-2xmp
+ NOTE: https://github.com/agronholm/anyio/pull/1207
+ NOTE: https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040 (4.14.2)
CVE-2026-63638 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- openimageio <unfixed>
NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-9hxv-jvgr-3x8g
@@ -1133,7 +1136,10 @@ CVE-2026-63406 (AnyCable is a realtime server for reliable two-way communication
CVE-2026-63405 (AnyCable is a realtime server for reliable two-way communication that ...)
NOT-FOR-US: AnyCable
CVE-2026-63349 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
- TODO: check
+ - python-anyio <unfixed>
+ NOTE: https://github.com/agronholm/anyio/security/advisories/GHSA-3w57-8xmc-8v26
+ NOTE: https://github.com/agronholm/anyio/pull/1209
+ NOTE: https://github.com/agronholm/anyio/commit/eb562e6462ee46b1904e50b02ce00a858cdeb200 (4.14.2)
CVE-2026-63199 (Perses is an open-source dashboard and visualization project for obser ...)
NOT-FOR-US: Perses
CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of Btrfs sub ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/65e61f0247ce2b907acd21219313a0fec3eaa158
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/65e61f0247ce2b907acd21219313a0fec3eaa158
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/9163aa9c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list