[Git][security-tracker-team/security-tracker][master] new znuny issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 22 09:54:24 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
18917052 by Moritz Muehlenhoff at 2026-09-22T10:54:03+02:00
new znuny issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,11 @@
+CVE-2026-XXXX [ZSA-2026-15]
+	- znuny 6.5.25-1
+	[trixie] - znuny <no-dsa> (Non-free not supported)
+	NOTE: https://www.znuny.org/en/advisories/zsa-2026-15
+CVE-2026-XXXX [ZSA-2026-14]
+	- znuny 6.5.25-1
+	[trixie] - znuny <no-dsa> (Non-free not supported)
+	NOTE: https://www.znuny.org/en/advisories/zsa-2026-14
 CVE-2026-94627 (vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV ...)
 	- vllm <itp> (bug #1095237)
 CVE-2026-94626 (vLLM through 0.29.0 fails to validate the tp_size parameter in kv_tran ...)
@@ -102361,8 +102369,8 @@ CVE-2026-48937 (A flaw in Node.js HTTP/2 server API can cause servers to keep ac
 	NOTE: https://github.com/nodejs/node/commit/a1a5bb968303229d4a3a7c9e389dc3ece6237b4c (v22.23.0)
 CVE-2026-48617 (A flaw in Node.js Permission Model enforcement allows Bypass via `proc ...)
 	- nodejs 24.17.0+dfsg+~cs24.13.2-1
-	[bookworm] - nodejs <not-affected> ((Permission Model is a Node 20+ feature)
-	[bullseye] - nodejs <not-affected> ((Permission Model is a Node 20+ feature)
+	[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
+	[bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
 	NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#permission-model-bypass-via-processreportwritereport-path-misvalidation-cve-2026-48617---low
 	NOTE: https://github.com/nodejs/node/commit/2f62693801a12bc8a485b3b7da3239ac522f607d (v22.23.0)
 CVE-2026-47833 (setupBpmLogs follows symlink for bpm.log open and chown \u2014 contain ...)
@@ -114819,8 +114827,9 @@ CVE-2026-48190 (An incorrect handling of permissions in OTRS External Interface
 CVE-2026-48189 (An improper Input Validation vulnerability in OTRS Customer Backend mo ...)
 	NOT-FOR-US: OTRS
 CVE-2026-48188 (An improper Input Validation vulnerability in OTRS or ((OTRS)) Communi ...)
-	NOT-FOR-US: OTRS
-	NOTE: Could possibly affect Znuny, we'll let their security team figure it out
+	- znuny 6.5.25-1
+	[trixie] - znuny <no-dsa> (Non-free not supported)
+	NOTE: https://www.znuny.org/en/advisories/zsa-2026-13
 CVE-2026-48187 (An uncontrolled allocation of resources without limits or throttling i ...)
 	NOT-FOR-US: OTRS
 	NOTE: Could possibly affect Znuny, we'll let their security team figure it out



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18917052cac8f00d7e19a06185ba91da285be62f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18917052cac8f00d7e19a06185ba91da285be62f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/89c059bf/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list