[Git][security-tracker-team/security-tracker][master] Mark trafficserver as removed from unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 21 15:51:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7cad11fe by Salvatore Bonaccorso at 2026-09-21T16:50:28+02:00
Mark trafficserver as removed from unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -66266,13 +66266,13 @@ CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege Escalation in Gridbox
 CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object injection  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin connections wit ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when dechunking  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table before co ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-64557 (In the Linux kernel, the following vulnerability has been resolved:  B ...)
 	{DSA-6405-1 DLA-4724-1 DLA-4723-1 DLA-4720-1}
@@ -66317,94 +66317,94 @@ CVE-2026-59247 (Insufficient Verification of Data Authenticity vulnerability in
 CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted `verify_signatur ...)
 	NOT-FOR-US: Apache Airflow FAB provider
 CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when plugins reset  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58188 (Several Apache Traffic Server experimental plugins have memory-safety  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58187 (The Apache Traffic Server multiplexer plugin overruns its chunk-decode ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58186 (The Apache Traffic Server webp_transform plugin can decode unsafely an ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58185 (The Apache Traffic Server intercept plugin has a use-after-free.  This ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58184 (The Apache Traffic Server header_rewrite plugin can crash or corrupt m ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58183 (The Apache Traffic Server prefetch plugin can crash when processing at ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58182 (The Apache Traffic Server ts_lua plugin mishandles initialization, tra ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58181 (The Apache Traffic Server uri_signing and url_sig plugins can exhaust  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58180 (The Apache Traffic Server txn_box plugin overflows the stack from atta ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58179 (The Apache Traffic Server regex_remap plugin overflows the stack and i ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58178 (The Apache Traffic Server ESI plugin can recurse without bound and fet ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58177 (The Apache Traffic Server Cripts framework has out-of-bounds writes, p ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58175 (Apache Traffic Server leaks memory when handling HostDB SRV records.   ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58164 (Apache Traffic Server has use-after-free and time-of-check/time-of-use ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58163 (Apache Traffic Server mishandles on-disk cache fields and object lifet ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58162 (The Apache Traffic Server certifier plugin generates certificates base ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58161 (Apache Traffic Server can crash from null dereferences and dangling re ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58160 (Apache Traffic Server reads out of bounds while parsing DNS answers.   ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58159 (Apache Traffic Server can bypass IP access controls on UDS listeners a ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58158 (Apache Traffic Server mishandles PROXY protocol input, truncating port ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58157 (Apache Traffic Server can reuse server sessions and tunnels improperly ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58156 (Apache Traffic Server mis-parses ports in URLs and userinfo, allowing  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58155 (Apache Traffic Server truncates over-long header names, allowing heade ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58154 (Apache Traffic Server can write out of bounds or overflow integers whi ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58153 (Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 client ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58152 (Apache Traffic Server mishandles integers while decoding HPACK/XPACK h ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58151 (Apache Traffic Server can be crashed or driven to resource exhaustion  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58150 (Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requ ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked messages are ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output paths. Gramma ...)
 	- bison <unfixed> (bug #1143158)
@@ -66489,29 +66489,29 @@ CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory (
 CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vuln ...)
 	NOT-FOR-US: Care Everywhere Gateway
 CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-40272 (Improper Input Validation in the decode() function of the traceparser  ...)
 	NOT-FOR-US: Blackberry
 CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS PROFINET ...)
 	NOT-FOR-US: CODESYS
 CVE-2026-33930 (Apache Traffic Server copies the client Host header into a fixed-size  ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick.CMS.  ...)
 	NOT-FOR-US: Quick.CMS
 CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
 	NOT-FOR-US: IBM
 CVE-2026-24033 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the request path a ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache Traffic Ser ...)
-	- trafficserver <unfixed> (bug #1143062)
+	- trafficserver <removed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall Manageme ...)
 	NOT-FOR-US: Cisco
@@ -79939,7 +79939,7 @@ CVE-2026-15905 (Use after free in Aura in Google Chrome prior to 150.0.7871.128
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache Traffic Serv ...)
-	- trafficserver <unfixed> (bug #1142387)
+	- trafficserver <removed> (bug #1142387)
 	[bookworm] - trafficserver <postponed> (Minor issue, DoS)
 	[bullseye] - trafficserver <postponed> (Minor issue, DoS)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/5
@@ -152679,12 +152679,12 @@ CVE-2026-0634 (Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on
 	NOT-FOR-US: TECNO Mobile
 CVE-2025-65114 (Apache Traffic Server allows request smuggling if chunked messages are ...)
 	{DSA-6199-1}
-	- trafficserver <unfixed> (bug #1132717)
+	- trafficserver <removed> (bug #1132717)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/04/02/6
 	NOTE: https://github.com/apache/trafficserver/commit/e5accd7929c5cb96a01cc9afda1f6336dab59b64 (9.2.13)
 CVE-2025-58136 (A bug in POST request handling causes a crash under a certain conditio ...)
 	{DSA-6199-1}
-	- trafficserver <unfixed> (bug #1132717)
+	- trafficserver <removed> (bug #1132717)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/04/02/6
 	NOTE: https://github.com/apache/trafficserver/commit/cb9e4a162fe16101f3c0a9baafe6bf5baa17b68c (9.2.13)
 CVE-2025-43264 (The issue was addressed with improved memory handling. This issue is f ...)
@@ -264002,13 +264002,13 @@ CVE-2025-38005 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/fca280992af8c2fbd511bc43f65abb4a17363f2f (6.15-rc7)
 CVE-2025-31698 (ACL configured in ip_allow.config or remap.config does not use IP addr ...)
 	{DSA-5948-1}
-	- trafficserver <unfixed> (bug #1108044)
+	- trafficserver <removed> (bug #1108044)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/06/17/7
 	NOTE: https://github.com/apache/trafficserver/commit/ce942e0acacd5cc9f38bd07565a1dfc5ffed0e33 (9.2.11-rc0)
 	NOTE: https://github.com/apache/trafficserver/commit/91a654dfa4de0c48aa222b87bfb909f9f21b03e0 (master)
 CVE-2025-49763 (ESI plugin does not have the limit for maximum inclusion depth, and th ...)
 	{DSA-5948-1}
-	- trafficserver <unfixed> (bug #1108044)
+	- trafficserver <removed> (bug #1108044)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/06/17/7
 	NOTE: https://github.com/apache/trafficserver/commit/2db8b8dc96e57fc292850f77b9783630cc9590b9 (9.2.11-rc0)
 	NOTE: https://github.com/apache/trafficserver/commit/7f178de7de19498c1c320ea9b62c2f32355f3893 (master)
@@ -287705,7 +287705,7 @@ CVE-2024-13673 (The Big Boom Directory plugin for WordPress is vulnerable to Sto
 	NOT-FOR-US: WordPress plugin
 CVE-2024-53868 (Apache Traffic Server allows request smuggling if chunked messages are ...)
 	{DSA-5948-1}
-	- trafficserver <unfixed> (bug #1101996)
+	- trafficserver <removed> (bug #1101996)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/04/02/4
 	NOTE: https://github.com/apache/trafficserver/commit/f266206adb95951436a21850cef2ad8e9e4a28cf
 	NOTE: https://github.com/apache/trafficserver/commit/3d2f29c88f9b073cb0fd3b9c7f85430e2170acbb (9.2.10-rc0)
@@ -297051,7 +297051,7 @@ CVE-2024-36347 (Improper signature verification in AMD CPU ROM microcode patch l
 	NOTE: https://www.openwall.com/lists/oss-security/2025/11/01/1
 CVE-2024-56202 (Expected Behavior Violation vulnerability in Apache Traffic Server.  T ...)
 	{DSA-5896-1}
-	- trafficserver <unfixed> (bug #1099691)
+	- trafficserver <removed> (bug #1099691)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/03/05/1
 	NOTE: https://github.com/apache/trafficserver/commit/1cca4a29520f9258be6c3fad5092939dbe9d3562 (9.2.9-rc0)
 CVE-2024-56196 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
@@ -297059,12 +297059,12 @@ CVE-2024-56196 (Improper Access Control vulnerability in Apache Traffic Server.
 	NOTE: https://www.openwall.com/lists/oss-security/2025/03/05/1
 CVE-2024-56195 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
 	{DSA-5896-1}
-	- trafficserver <unfixed> (bug #1099691)
+	- trafficserver <removed> (bug #1099691)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/03/05/1
 	NOTE: https://github.com/apache/trafficserver/commit/483f84ea4ae2511834abd90014770b27a5082a4c (9.2.9-rc0)
 CVE-2024-38311 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
 	{DSA-5896-1}
-	- trafficserver <unfixed> (bug #1099691)
+	- trafficserver <removed> (bug #1099691)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/03/05/1
 	NOTE: https://github.com/apache/trafficserver/commit/a16c4b6bb0b126047c68dafbdf6311ac1586fc0b (9.2.9-rc0)
 CVE-2025-27625 (In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects start ...)
@@ -332422,7 +332422,7 @@ CVE-2024-10146 (The Simple File List WordPress plugin before 6.1.13 does not san
 	NOT-FOR-US: WordPress plugin
 CVE-2024-50306 (Unchecked return value can allow Apache Traffic Server to retain privi ...)
 	{DSA-5896-1 DLA-4055-1}
-	- trafficserver <unfixed> (bug #1087531)
+	- trafficserver <removed> (bug #1087531)
 	NOTE: https://www.openwall.com/lists/oss-security/2024/11/13/1
 	NOTE: https://github.com/apache/trafficserver/pull/11855
 	NOTE: Fixed by: https://github.com/apache/trafficserver/commit/27f504883547502b1f5e4e389edd7f26e3ab246f (9.2.6-rc0)
@@ -332432,13 +332432,13 @@ CVE-2024-50306 (Unchecked return value can allow Apache Traffic Server to retain
 	NOTE: Followup: https://github.com/apache/trafficserver/commit/d4dda9b5583d19e2eee268fec59aa487d61fc079 (master)
 CVE-2024-38479 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
 	{DSA-5896-1 DLA-4055-1}
-	- trafficserver <unfixed> (bug #1087531)
+	- trafficserver <removed> (bug #1087531)
 	NOTE: https://www.openwall.com/lists/oss-security/2024/11/13/1
 	NOTE: https://github.com/apache/trafficserver/pull/11856
 	NOTE: https://github.com/apache/trafficserver/commit/b8861231702ac5df7d5de401e82440c1cf20b633 (9.2.6-rc0)
 CVE-2024-50305 (Valid Host header field can cause Apache Traffic Server to crash on so ...)
 	{DSA-5896-1}
-	- trafficserver <unfixed> (bug #1087531)
+	- trafficserver <removed> (bug #1087531)
 	NOTE: https://www.openwall.com/lists/oss-security/2024/11/13/1
 	NOTE: https://github.com/apache/trafficserver/issues/8461
 	NOTE: https://github.com/apache/trafficserver/commit/5e39658f7c0bc91613468c9513ba22ede1739d7e (9.2.6-rc0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cad11fef6030295f0b6a4a3d03dcbeedf5f8124

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cad11fef6030295f0b6a4a3d03dcbeedf5f8124
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/ba2e0901/attachment.htm>


More information about the debian-security-tracker-commits mailing list