Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 91b447f3 by Salvatore Bonaccorso at 2026-01-20T05:49:12+01:00 Track fixed version for CVE-2025-54121/starlette The fix landed already earlier in unstable with [1]. [1]: https://tracker.debian.org/news/1651946/accepted-starlette-0461-3-source-into-unstable/ Link: https://salsa.debian.org/security-tracker-team/security-tracker/-/merge_requests/257 Thanks: Matheus Polkorny - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -65587,7 +65587,7 @@ CVE-2025-6235 (In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vu CVE-2025-5681 (Authorization Bypass Through User-Controlled Key vulnerability in Turt ...) NOT-FOR-US: Turtek Software Eyotek CVE-2025-54121 (Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface ...) - - starlette 0.50.0-1 (bug #1109805) + - starlette 0.46.1-3 (bug #1109805) [bookworm] - starlette <no-dsa> (Minor issue) [bullseye] - starlette <postponed> (minor issue; Dos can be fixed in next update) NOTE: https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/91b447f37fe731aed157f93cdaad9f985833e65e -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/91b447f37fe731aed157f93cdaad9f985833e65e You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
