[Git][security-tracker-team/security-tracker][master] Add new python-git issue

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 26 21:03:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5c8aaf37 by Salvatore Bonaccorso at 2026-09-26T22:02:54+02:00
Add new python-git issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -116,7 +116,9 @@ CVE-2026-100690 (Hugo versions from v0.161.0 through v0.165.0 run Node.js tools
 	- hugo 0.166.0-1
 	NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-x3mx-cm49-8m9c
 CVE-2026-100689 (GitPython before 3.1.62 does not validate the `path` field read from a ...)
-	TODO: check
+	- python-git 3.1.62-1
+	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-59cr-6r3x-644w
+	NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/1ed0ebc2f2e74d979cdc367a4864a7731fdcc093 (3.1.62)
 CVE-2026-100688 (Budibase server before 3.45.0 contains a cross-tenant information disc ...)
 	NOT-FOR-US: Budibase
 CVE-2026-100687 (Budibase Server before 3.45.0 fails to redact plaintext datasource cre ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c8aaf3793447d2bb50c7e4b12a8475b40963b04

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c8aaf3793447d2bb50c7e4b12a8475b40963b04
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/4706424c/attachment.htm>


More information about the debian-security-tracker-commits mailing list