Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
fd9f9be1 by Salvatore Bonaccorso at 2026-07-11T21:28:26+02:00
Rmove some notes
- - - - -
a86c5265 by Salvatore Bonaccorso at 2026-07-11T21:48:28+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,27 +9,27 @@ CVE-2026-61857 (ImageMagick before 7.1.2-26 contains a heap
use-after-free vulne
CVE-2026-61465 (ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check
for the a ...)
TODO: check
CVE-2026-61454 (The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before
2.0.4 embed ...)
- TODO: check
+ NOT-FOR-US: Grav CMS plugin
CVE-2026-61448 (Parse Server is affected by a stored cross-site scripting
(XSS) vulner ...)
NOT-FOR-US: Parse Server
CVE-2026-61447 (PraisonAI before 1.6.78 contains a remote code execution
vulnerability ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-61445 (PraisonAI before 4.6.78 contains arbitrary file write and
command exec ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-61442 (PraisonAI Platform (praisonai-platform) before 0.1.9 fails to
enforce ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-61439 (PraisonAI versions before 4.6.78 contain a prompt injection
defense mi ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-61429 (PraisonAI versions before 1.6.78 contain a server-side request
forgery ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-61428 (PraisonAI AgentMail versions before 4.6.78 lack signature
verification ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-61426 (PraisonAI before 1.7.3 contains an insecure default
configuration that ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-60090 (PraisonAI before 4.6.78 fails to validate the
caller-controlled dimens ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-60088 (PraisonAI before 4.6.78 fails to validate file path references
in cust ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-57828 (The Joomla extension Phoca Downloads is vulnerable to an
authenticated ...)
NOT-FOR-US: Joomla
CVE-2026-57827 (The Joomla extension RSFiles is vulnerable to an
unauthenticated arbit ...)
@@ -8025,9 +8025,6 @@ CVE-2026-4360 (In the Tarfile.extract() function, the
filter parameter is not pa
NOTE:
https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301
(3.15 branch)
NOTE:
https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0
(3.14 branch)
NOTE:
https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e
(3.13 branch)
- NOTE: [bullseye] python3.9 (3.9.2-1+deb11u7) predates the tarfile
extraction filters
- NOTE: (PEP 706, backported upstream in 3.9.17); extract()/extractall()
have no filter
- NOTE: parameter and Debian did not backport it, so the hardlink
filter-bypass is not present.
CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ. An
authentic ...)
- activemq <unfixed> (bug #1141385)
NOTE: https://lists.apache.org/thread/w82vtc3q02j5ot94tnyy1197y3wb98hl
@@ -14374,7 +14371,6 @@ CVE-2026-44517
[trixie] - golang-github-containers-buildah <no-dsa> (Minor issue)
[bookworm] - golang-github-containers-buildah <not-affected>
(Vulnerable build-context URL refactor introduced in 1.38.1; 1.28.2 predates it)
[bullseye] - golang-github-containers-buildah <not-affected>
(Vulnerable build-context URL refactor introduced in 1.38.1; 1.19.6 predates it)
- NOTE: GHSA-49p4-px3h-rq49 affects >= 1.38.1, < 1.43.2 (TempDirForURL
download-subdir path traversal); absent in bookworm 1.28.2 and bullseye 1.19.6.
Fixed by 54459cf8.
NOTE:
https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
NOTE: Fixed by:
https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
(v1.43.2)
CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar' filter could be
bypasse ...)
@@ -26260,7 +26256,6 @@ CVE-2026-49837
[trixie] - gobgp <no-dsa> (Minor issue)
[bookworm] - gobgp <postponed> (Minor issue, OPEN capability length
under-enforcement)
[bullseye] - gobgp <postponed> (Limited support)
- NOTE: GHSA scopes affected to v4 <= 4.5.0, but the CapLen-ignoring read
is present in 3.10.0 (bookworm) and 2.25.0 (bullseye):
CapFourOctetASNumber.DecodeFromBytes reads data[0:4] past the 2-byte header.
Minor (OPEN-time capability misparse).
NOTE:
https://github.com/osrg/gobgp/security/advisories/GHSA-gjrg-jjr3-56cm
CVE-2026-8916 (Out-of-bounds write vulnerability in Samsung Open Source
rlottie allow ...)
{DLA-4675-1}
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ada31145018ff4930b2bd9752f9330eac3c71bf2...a86c5265c99efbb34ee1a6ea84c114c2761d32b9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ada31145018ff4930b2bd9752f9330eac3c71bf2...a86c5265c99efbb34ee1a6ea84c114c2761d32b9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits