[Git][security-tracker-team/security-tracker][master] Add new social-auth-core issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 26 09:17:12 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
63e3940b by Salvatore Bonaccorso at 2026-09-26T10:16:36+02:00
Add new social-auth-core issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2840,15 +2840,30 @@ CVE-2026-57590 (A missing authorization vulnerability exists in the Task Group A
CVE-2026-57440 (The EmbedVideo Extension is a MediaWiki extension which adds a parser ...)
NOT-FOR-US: SCBE-AETHERMOORE
CVE-2026-57179 (Python Social Auth is a social authentication/registration mechanism. ...)
- TODO: check
+ - social-auth-core 5.0.2-1
+ NOTE: https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg
+ NOTE: https://github.com/python-social-auth/social-core/pull/1816
+ NOTE: Fixed by: https://github.com/python-social-auth/social-core/commit/0418782454ac7bbc6a9230ea21f7f5066fe89686 (5.0.0)
CVE-2026-57178 (Python Social Auth is a social authentication/registration mechanism. ...)
- TODO: check
+ - social-auth-core 5.0.2-1
+ NOTE: https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h
+ NOTE: https://github.com/python-social-auth/social-core/pull/1811
+ NOTE: Fixed by: https://github.com/python-social-auth/social-core/commit/1bfacdd0379e5eb46e169a99ab648b835e9bb6a2 (5.0.0)
CVE-2026-57177 (Python Social Auth is a social authentication/registration mechanism. ...)
- TODO: check
+ - social-auth-core 5.0.2-1
+ NOTE: https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg
+ NOTE: https://github.com/python-social-auth/social-core/pull/1808
+ NOTE: Fixed by: https://github.com/python-social-auth/social-core/commit/4d332820e6b0583fde522956105a0e2beced5335 (5.0.0)
CVE-2026-57176 (Python Social Auth is a social authentication/registration mechanism. ...)
- TODO: check
+ - social-auth-core 5.0.2-1
+ NOTE: https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc
+ NOTE: https://github.com/python-social-auth/social-core/pull/1795
+ NOTE: Fixed by: https://github.com/python-social-auth/social-core/commit/dee7ad1785877afd355dd6860598823d2631b76e (5.0.0)
CVE-2026-57175 (Python Social Auth is a social authentication/registration mechanism. ...)
- TODO: check
+ - social-auth-core 5.0.2-1
+ NOTE: https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j
+ NOTE: https://github.com/python-social-auth/social-core/pull/1794
+ NOTE: Fixed by: https://github.com/python-social-auth/social-core/commit/5c72f71125bc60e4411f09e2a9f998de5da7fcb6 (5.0.0)
CVE-2026-56792 (Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain a ...)
NOT-FOR-US: Dell / EMC
CVE-2026-56744 (`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage comp ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/63e3940b4eca916482f401068a66dea87b1c1b28
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/63e3940b4eca916482f401068a66dea87b1c1b28
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/82345698/attachment.htm>
More information about the debian-security-tracker-commits
mailing list