[Git][security-tracker-team/security-tracker][master] new pgbouncer issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 13:16:09 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1fedf7cf by Moritz Muehlenhoff at 2026-09-24T14:15:44+02:00
new pgbouncer issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -748,9 +748,9 @@ CVE-2026-6721 (IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote
CVE-2026-6718 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access contr ...)
NOT-FOR-US: IBM
CVE-2026-6669 (Missing upper bound on the key derivation iteration count accepted dur ...)
- TODO: check
+ - pgbouncer <unfixed>
CVE-2026-6668 (Integer overflow in the packet buffer growth logic in PgBouncer throug ...)
- TODO: check
+ - pgbouncer <unfixed>
CVE-2026-6327 (IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to in ...)
NOT-FOR-US: IBM
CVE-2026-68492 (An untrusted search path vulnerability in Plesk from 18.0.34 before 18 ...)
@@ -908,7 +908,7 @@ CVE-2026-3626 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to
CVE-2026-31377 (An Improper Authentication vulnerability in the Apache Doris Frontend ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-19888 (Missing validation of a mandatory attribute in the SCRAM client-final- ...)
- TODO: check
+ - pgbouncer <unfixed>
CVE-2026-19599 (ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were v ...)
NOT-FOR-US: Zoho
CVE-2026-19267 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fedf7cf71e9c97f37b35d2c39c3b1545ac26b48
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fedf7cf71e9c97f37b35d2c39c3b1545ac26b48
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/3aa5756c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list