[Git][security-tracker-team/security-tracker][master] new sail issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 19:47:45 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8fdf30b2 by Moritz Muehlenhoff at 2026-09-20T20:47:05+02:00
new sail issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1711,7 +1711,9 @@ CVE-2026-54734 (Prebid Server Java is the Java version of Prebid Server. Prior t
 CVE-2026-54716 (Valhalla is an open source routing engine and accompanying libraries f ...)
 	NOT-FOR-US: Valhalla
 CVE-2026-54692 (SAIL is a cross-platform library for loading and saving images with su ...)
-	TODO: check
+	- sail 1.2.0-1
+	NOTE: https://github.com/HappySeaFox/sail/security/advisories/GHSA-gp27-qv2x-55v5
+	NOTE: https://github.com/HappySeaFox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1 (v1.0.0)
 CVE-2026-54671 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, We ...)
 	NOT-FOR-US: WeGIA
 CVE-2026-54670 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, th ...)
@@ -1742,9 +1744,13 @@ CVE-2026-54634 (Hamlib is a ham radio control library for radios, rotators, and
 CVE-2026-54633 (PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1 ...)
 	TODO: check
 CVE-2026-54627 (SAIL is a cross-platform library for loading and saving images with su ...)
-	TODO: check
+	- sail 1.2.0-1
+	NOTE: https://github.com/HappySeaFox/sail/security/advisories/GHSA-ccqf-rv86-h3wm
+	NOTE: https://github.com/HappySeaFox/sail/commit/f44a8b779a1fc527fc6bc5caa71a66a8ed940d50 (v1.0.0)
 CVE-2026-54626 (SAIL is a cross-platform library for loading and saving images with su ...)
-	TODO: check
+	- sail 1.2.0-1
+	NOTE: https://github.com/HappySeaFox/sail/security/advisories/GHSA-744p-cqg2-m33h
+	NOTE: https://github.com/HappySeaFox/sail/commit/fa24bceb93958ad665dbc3cf6b49a1079ab12559 (v1.0.0)
 CVE-2026-54618 (Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Pr ...)
 	NOT-FOR-US: Obsidian Web MCP
 CVE-2026-54613 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fdf30b2b8afaff0f57ce499cc33b9e5d934cb06

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fdf30b2b8afaff0f57ce499cc33b9e5d934cb06
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/3a2cd96d/attachment.htm>


More information about the debian-security-tracker-commits mailing list