[Git][security-tracker-team/security-tracker][master] Add CVE-2026-19773/libwebsockets
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 07:22:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
27124e07 by Salvatore Bonaccorso at 2026-09-22T08:22:13+02:00
Add CVE-2026-19773/libwebsockets
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9940,7 +9940,9 @@ CVE-2026-19774 (BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vul
NOTE: https://github.com/bluez/bluez/pull/2251
NOTE: Fixed by: https://github.com/bluez/bluez/commit/912f5efb0dd9bb08e408d33371a57182c5678aef (5.87)
CVE-2026-19773 (libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Rem ...)
- TODO: check
+ - libwebsockets <unfixed>
+ NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-590/
+ NOTE: Fixed by: https://github.com/warmcat/libwebsockets/commit/824151862f37bc72f46d9a3e01d5b9408d313a0b (v5.0.0)
CVE-2026-19641 (On affected platforms running Arista EOS with password authentication ...)
NOT-FOR-US: Arista Networks
CVE-2026-19515 (The WSO2 Integrator MI VS Code extension fails to properly sanitize or ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27124e074bd6d26d44dafc07c030b690a99d135f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27124e074bd6d26d44dafc07c030b690a99d135f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/b1d993eb/attachment.htm>
More information about the debian-security-tracker-commits
mailing list