Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f6a5e856 by Salvatore Bonaccorso at 2026-05-06T09:29:21+02:00
Add new jupyter-server issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18,7 +18,8 @@ CVE-2026-44331 (In ProFTPD through 1.3.9a before 7666224, a 
SQL injection vulner
 CVE-2026-41950 (Dify before version 1.14.0 contains an authorization bypass 
vulnerabil ...)
        NOT-FOR-US: Dify
 CVE-2026-40934 (Jupyter Server is the backend for Jupyter web applications. In 
version ...)
-       TODO: check
+       - jupyter-server <unfixed>
+       NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f
 CVE-2026-40331 (Masa CMS is an open source content management system. In 
versions 7.2. ...)
        NOT-FOR-US: Masa CMS
 CVE-2026-40330 (Masa CMS is an open source content management system. In 
versions 7.2. ...)
@@ -28,7 +29,11 @@ CVE-2026-40329 (Masa CMS is an open source content 
management system. In version
 CVE-2026-40280 (Gotenberg is an API-based document conversion tool. In 
versions 8.30.1 ...)
        NOT-FOR-US: Gotenberg
 CVE-2026-40110 (Jupyter Server is the backend for Jupyter web applications. In 
version ...)
-       TODO: check
+       - jupyter-server <unfixed>
+       NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p
+       NOTE: https://github.com/jupyter-server/jupyter_server/pull/603
+       NOTE: 
https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea
 (v2.18.0)
+       NOTE: 
https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8
 (v2.18.0)
 CVE-2026-40075 (OpenMRS Core is an open source electronic medical record 
system platfo ...)
        NOT-FOR-US: OpenMRS
 CVE-2026-40068 (In versions 2.1.63 through 2.1.83 of Claude Code, the folder 
trust det ...)
@@ -46,7 +51,8 @@ CVE-2026-35579 (CoreDNS is a DNS server written in Go. In 
versions prior to 1.14
 CVE-2026-35453 (PhpSpreadsheet is a library for reading and writing 
spreadsheet files. ...)
        NOT-FOR-US: PhpSpreadsheet
 CVE-2026-35397 (Jupyter Server is the backend for Jupyter web applications. In 
version ...)
-       TODO: check
+       - jupyter-server <unfixed>
+       NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3
 CVE-2026-34596 (Sandboxie-Plus is an open source sandbox-based isolation 
software for  ...)
        NOT-FOR-US: Sandboxie-Plus
 CVE-2026-34527 (Sandboxie-Plus is an open source sandbox-based isolation 
software for  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6a5e85653786f68967c1846e7897355f0c7f944

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6a5e85653786f68967c1846e7897355f0c7f944
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to