Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
03cd64c4 by Utkarsh Gupta at 2026-07-12T08:25:06+05:30
lts: golang-1.19 not-affected in bookworm (CVE-2026-42505, CVE-2026-39822)
- - - - -
efd20b4a by Utkarsh Gupta at 2026-07-12T08:25:07+05:30
lts: golang-github-cli-go-gh postponed in bookworm (CVE-2026-48501)
- - - - -
07e8df86 by Utkarsh Gupta at 2026-07-12T08:25:08+05:30
lts: golang-github-go-git-go-billy postponed in bookworm (CVE-2026-44973,
CVE-2026-44740)
- - - - -
39dea7f8 by Utkarsh Gupta at 2026-07-12T08:25:09+05:30
lts: golang-github-go-git-go-git postponed in bookworm (CVE-2026-45571,
CVE-2026-45570, CVE-2026-45022, CVE-2026-41506)
- - - - -
cc0effdd by Utkarsh Gupta at 2026-07-12T08:25:10+05:30
lts: golang-github-labstack-echo postponed in bookworm (CVE-2026-55677)
- - - - -
fb31396d by Utkarsh Gupta at 2026-07-12T08:25:11+05:30
lts: golang-github-pion-dtls.v2 postponed in bookworm (CVE-2026-54908)
- - - - -
e44a7125 by Utkarsh Gupta at 2026-07-12T08:25:12+05:30
lts: golang-golang-x-image postponed in bookworm (CVE-2026-42500)
- - - - -
1e381bdc by Utkarsh Gupta at 2026-07-12T08:25:13+05:30
lts: golang-golang-x-net postponed in bookworm (6 CVEs)
- - - - -
a311f4f7 by Utkarsh Gupta at 2026-07-12T08:25:14+05:30
lts: golang-go.crypto postponed in bookworm (13 CVEs)
- - - - -
9dc1d322 by Utkarsh Gupta at 2026-07-12T08:25:30+05:30
lts: jython not-affected in bookworm (CVE-2026-4360)
- - - - -
f3a799d9 by Utkarsh Gupta at 2026-07-12T08:25:31+05:30
lts: rust-tar postponed in bookworm (CVE-2026-33056, CVE-2026-33055)
- - - - -
65907e9b by Utkarsh Gupta at 2026-07-12T08:25:33+05:30
lts: rustc postponed in bookworm (CVE-2026-33056, CVE-2026-33055)
- - - - -
e30029b6 by Utkarsh Gupta at 2026-07-12T08:32:08+05:30
lts: rust RUSTSEC issues postponed in bookworm (14 entries)
- - - - -
6284fc7f by Utkarsh Gupta at 2026-07-12T08:32:25+05:30
lts: lxd end-of-life in bookworm (28 CVEs)
- - - - -
d5f0aa12 by Utkarsh Gupta at 2026-07-12T08:32:27+05:30
lts: wolfssl end-of-life in bookworm (24 CVEs)
- - - - -
c17cb4f3 by Utkarsh Gupta at 2026-07-12T08:32:30+05:30
lts: php-horde-imp end-of-life in bookworm (CVE-2026-58451)
- - - - -
ae5ec562 by Utkarsh Gupta at 2026-07-12T08:32:32+05:30
lts: php-horde-vfs end-of-life in bookworm (CVE-2026-60102)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1868,6 +1868,7 @@ CVE-2026-60124 (An authorization bypass in MISP\u2019s
EventsController::importM
NOT-FOR-US: MISP
CVE-2026-60102 (Horde Virtual File System (VFS) API before 3.0.1 contains an
OS comman ...)
- php-horde-vfs <unfixed>
+ [bookworm] - php-horde-vfs <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/horde/Vfs/pull/10
NOTE:
https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361
(v3.0.1)
CVE-2026-60092 (AVideo (Meet plugin) through commit
e8d6119f3cb1b849149906efeb0a41fc02 ...)
@@ -2712,6 +2713,7 @@ CVE-2026-39822 (On Unix systems, opening a file in an
os.Root improperly follows
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
+ [bookworm] - golang-1.19 <not-affected> (os.Root API introduced in Go
1.24; absent in 1.19)
- golang-1.15 <not-affected> (Vulnerable code introduced later)
NOTE: golang-1.15: os.Root API introduced in Go 1.24
(go.dev/doc/go1.24); absent in 1.15
NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
@@ -2725,6 +2727,7 @@ CVE-2026-42505 (Handshakes which used Encrypted Client
Hello could be de-anonymi
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
+ [bookworm] - golang-1.19 <not-affected> (crypto/tls client ECH
introduced in Go 1.23; absent in 1.19)
- golang-1.15 <not-affected> (Vulnerable code introduced later)
NOTE: golang-1.15: crypto/tls client Encrypted Client Hello introduced
in Go 1.23 (issue #63369); absent in 1.15
NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
@@ -3430,15 +3433,18 @@ CVE-2024-6228 (The Notifications for Forms & WordPress
Actions WordPress plugin
CVE-2026-XXXX [RUSTSEC-2026-0190]
- rust-anyhow <unfixed> (bug #1141593)
[trixie] - rust-anyhow <no-dsa> (Minor issue)
+ [bookworm] - rust-anyhow <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0190.html
NOTE: https://github.com/dtolnay/anyhow/issues/451
CVE-2026-XXXX [RUSTSEC-2026-0193]
- rust-ammonia <unfixed> (bug #1141594)
[trixie] - rust-ammonia <no-dsa> (Minor issue)
+ [bookworm] - rust-ammonia <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0193.html
CVE-2026-XXXX [RUSTSEC-2026-0194]
- rust-quick-xml <unfixed> (bug #1141595)
[trixie] - rust-quick-xml <no-dsa> (Minor issue)
+ [bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0194.html
NOTE: https://github.com/tafia/quick-xml/issues/969
NOTE: https://github.com/tafia/quick-xml/pull/971
@@ -3456,6 +3462,7 @@ CVE-2026-13705 (Imager versions before 1.032 for Perl
have a heap out-of-bounds
CVE-2026-XXXX [RUSTSEC-2026-0195]
- rust-quick-xml <unfixed> (bug #1141588)
[trixie] - rust-quick-xml <no-dsa> (Minor issue)
+ [bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0195.html
NOTE: https://github.com/tafia/quick-xml/issues/970
NOTE:
https://github.com/tafia/quick-xml/commit/7ca25266e94987210daa864889ab15c9332c8a2a
(v0.41.0)
@@ -3470,11 +3477,13 @@ CVE-2026-XXXX [RUSTSEC-2026-0199]
CVE-2026-XXXX [RUSTSEC-2026-0202]
- rust-cxx <unfixed> (bug #1141591)
[trixie] - rust-cxx <no-dsa> (Minor issue)
+ [bookworm] - rust-cxx <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0202.html
NOTE: https://github.com/dtolnay/cxx/issues/1729
CVE-2026-XXXX [RUSTSEC-2026-0166]
- rust-stackvector <unfixed> (bug #1141592)
[trixie] - rust-stackvector <no-dsa> (Minor issue)
+ [bookworm] - rust-stackvector <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0166.html
NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/3
NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/5
@@ -3842,6 +3851,7 @@ CVE-2025-13475 (In multi-tenanted deployments, the
application consent managemen
CVE-2026-XXXX [RUSTSEC-2026-0185]
- rust-quinn-proto <unfixed> (bug #1141481)
[trixie] - rust-quinn-proto <no-dsa> (Minor issue)
+ [bookworm] - rust-quinn-proto <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0185.html
NOTE: https://github.com/quinn-rs/quinn/pull/2694
CVE-2026-XXXX [RUSTSEC-2026-0187]
@@ -3854,6 +3864,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0187]
CVE-2026-XXXX [RUSTSEC-2026-0186]
- rust-memmap2 <unfixed> (bug #1141479)
[trixie] - rust-memmap2 <no-dsa> (Minor issue)
+ [bookworm] - rust-memmap2 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0186.html
NOTE:
https://github.com/RazrFalcon/memmap2-rs/commit/cee7cf03a9ee095982a3c37b7aac8e3f68f1a00c
(v0.9.11)
CVE-2026-53360 (In the Linux kernel, the following vulnerability has been
resolved: K ...)
@@ -4986,6 +4997,7 @@ CVE-2026-55153 (mchange-commons-java is a Java library of
shared utility classes
CVE-2026-54908 (Pion DTLS is a Go implementation of Datagram Transport Layer
Security. ...)
- golang-github-pion-dtls.v2 <unfixed> (bug #1141306)
[trixie] - golang-github-pion-dtls.v2 <no-dsa> (Minor issue)
+ [bookworm] - golang-github-pion-dtls.v2 <postponed> (Minor issue;
remote DoS via crafted ServerKeyExchange)
- golang-github-pion-dtls-v3 <unfixed> (bug #1141307)
NOTE:
https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j
NOTE: https://github.com/pion/dtls/pull/839
@@ -5376,6 +5388,7 @@ CVE-2026-58452 (JAIOTlink C492A-W6 Wi-Fi IP cameras
running firmware 4.8.30.5770
CVE-2026-58451 (Horde IMP before 7.0.1 contains a path traversal vulnerability
in lib/ ...)
- horde3 <removed>
- php-horde-imp <unfixed> (bug #1141341)
+ [bookworm] - php-horde-imp <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/horde/imp/pull/85
NOTE: Fixed by:
https://github.com/horde/imp/commit/fba972fab72ee6871e5d56e6390bee38593085de
(v7.0.1)
CVE-2026-58399 (@acastellon/auth is an authentication control system for
microservices ...)
@@ -8062,6 +8075,7 @@ CVE-2026-4360 (In the Tarfile.extract() function, the
filter parameter is not pa
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- jython <unfixed>
[trixie] - jython <no-dsa> (Minor issue)
+ [bookworm] - jython <not-affected> (extraction filters/PEP 706 absent
in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
[bullseye] - jython <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed> (bug #1141531)
[trixie] - pypy3 <no-dsa> (Minor issue)
@@ -9623,6 +9637,7 @@ CVE-2026-9699 (Mattermost Plugins versions <=11.6
10.18.11 11.3.6 11.6.5.0 fail
CVE-2026-9640 (A privilege escalation vulnerability exists in LXD from 6.0
before 6.9 ...)
{DSA-6373-1}
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-ppq7-4492-5552
NOTE: https://github.com/canonical/lxd/pull/18301
NOTE: https://github.com/canonical/lxd/pull/18303
@@ -9630,6 +9645,7 @@ CVE-2026-9640 (A privilege escalation vulnerability
exists in LXD from 6.0 befor
CVE-2026-9639 (Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD
up to v ...)
{DSA-6373-1}
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8
NOTE: https://github.com/canonical/lxd/pull/18320
NOTE: https://github.com/canonical/lxd/pull/18390
@@ -9913,6 +9929,7 @@ CVE-2026-55686 (Podman is a tool for managing OCI
containers and pods. From 3.0.
CVE-2026-55677 (Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's
router a ...)
- golang-github-labstack-echo <unfixed> (bug #1141444)
[trixie] - golang-github-labstack-echo <no-dsa> (Minor issue)
+ [bookworm] - golang-github-labstack-echo <postponed> (Minor issue;
encoded-slash %2F static route bypass)
- golang-github-labstack-echo.v3 <removed>
[bullseye] - golang-github-labstack-echo.v3 <postponed> (Minor issue;
limited/case-by-case golang support, no upstream v3 fix)
- golang-github-labstack-echo.v2 <removed>
@@ -10033,6 +10050,7 @@ CVE-2026-2053 (The WSO2 API Manager's message flow
component, when processing WS
CVE-2026-28385 (In Canonical LXD versions 4.12 through 6.9, a Server-Side
Request Forg ...)
- lxd <removed>
[trixie] - lxd <postponed> (Fix along in future DSA)
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-3gq2-x4qg-p4g6
NOTE: https://github.com/canonical/lxd/pull/18462
CVE-2026-24547 (Unauthenticated Broken Access Control in SiteGround Email
Marketing <= ...)
@@ -10121,6 +10139,7 @@ CVE-2026-8797 (An access control deficiency
vulnerability exists in ExpressUpdat
CVE-2026-8720 (wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message
when t ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10447 (v5.9.2-stable)
CVE-2026-8661 (Server-Side Cross-Site Scripting and Server-Side Request
Forgery vulne ...)
NOT-FOR-US: Rapid7
@@ -10129,58 +10148,72 @@ CVE-2026-8380 (The Frontend File Manager Plugin
WordPress plugin through 23.6 do
CVE-2026-7532 (iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is
not defi ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10354 (v5.9.2-stable)
CVE-2026-7531 (Use-after-free in PQC hybrid key-share handling. This is an
incomplete ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10327 (v5.9.2-stable)
CVE-2026-7511 (PKCS7_verify signer confusion allows forged signatures, where
the sign ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6731 (X.509 name constraint bypass via the Subject Common Name when
treated ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10223 (v5.9.2-stable)
CVE-2026-6681 (The PKCS#7 decode path ignores the caller-supplied output
buffer size ...)
- wolfssl 5.9.2-1
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK
serialization p ...)
- wolfssl 5.9.2-1
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
CVE-2026-6678 (Integer underflow in wc_PKCS7_DecryptOri when handling crafted
Other R ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6450 (A CRL critical extension bypass exists in ParseCRL_Extensions
where cr ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10239 (v5.9.2-stable)
CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding
the cont ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10222 (v5.9.2-stable)
CVE-2026-6331 (HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a
zero-le ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half
of the ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6329 (PKCS#12 MAC verification uses an attacker-controlled comparison
length ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6325 (Out-of-bounds write in SetSuitesHashSigAlgo when processing an
oversiz ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10204 (v5.9.2-stable)
CVE-2026-6092 (When HAVE_ENCRYPT_THEN_MAC is configured, the implementation
could fal ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10167 (v5.9.2-stable)
CVE-2026-57522 (Bitwarden Server before 2026.5.0 contains a JSON injection
vulnerabili ...)
- bitwarden <itp> (bug #956836)
@@ -10193,18 +10226,22 @@ CVE-2026-56445 (The qrscp application's C-STORE
handler uses a specific instance
CVE-2026-55964 (Chain intermediate CA:TRUE without keyCertSign accepted as a
signing C ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55962 (TLS 1.3 post-handshake authentication (PHA) issue where a
server could ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55960 (Un-negotiated Raw Public Key (RFC 7250) accepted in place of
an X.509 ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55958 (Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript
buffer. In ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10705 (v5.9.2-stable)
CVE-2026-54479 (The WebSocket backend uses charging station identifiers to
uniquely as ...)
NOT-FOR-US: Evoke
@@ -10368,18 +10405,21 @@ CVE-2026-48750
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9
NOTE: https://github.com/canonical/lxd/pull/18590
CVE-2026-48751
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv
NOTE: https://github.com/canonical/lxd/pull/18604
CVE-2026-48752
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479
NOTE:
https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef
(v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18590
@@ -10387,6 +10427,7 @@ CVE-2026-48755
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4
NOTE:
https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88
(v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18597
@@ -10394,6 +10435,7 @@ CVE-2026-48769
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x
NOTE:
https://github.com/lxc/incus/commit/46d6ef232186df5535c49ca9f3597cab381f9b86
(v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18594
@@ -10401,6 +10443,7 @@ CVE-2026-55621
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f
NOTE:
https://github.com/lxc/incus/commit/2e01078366e2653712719dec82318e51c6d21b28
(v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18603
@@ -10408,6 +10451,7 @@ CVE-2026-55622
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg
NOTE:
https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb
(v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18603
@@ -10415,6 +10459,7 @@ CVE-2026-48749
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv
NOTE: https://github.com/canonical/lxd/pull/18590
CVE-2026-XXXX [ZSA-2026-12]
@@ -10454,14 +10499,17 @@ CVE-2026-6432 (Improper bounds validation in
EmberZNet SDK versions 9.0.2 and ea
CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When
decrypti ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when
parsing craf ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
CVE-2026-6091 (Partial-chain certificate verification may accept chains that
terminat ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10170 (v5.9.2-stable)
CVE-2026-57700 (Unrestricted Upload of File with Dangerous Type vulnerability
in Daan. ...)
NOT-FOR-US: WordPress plugin or theme
@@ -10628,10 +10676,12 @@ CVE-2026-56005 (Subscriber Cross Site Scripting (XSS)
in WP Activity Log <= 5.6.
CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative
single m ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate
(certs-only) ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55895 (Vim is an open source, command line text editor. Prior to
9.2.0663, a ...)
- vim 2:9.2.0782-1 (bug #1140775)
@@ -16219,11 +16269,13 @@ CVE-2026-9692 (Mojolicious::Sessions::Storable
versions through 0.05 for Perl ge
CVE-2026-XXXX [RUSTSEC-2026-0183]
- rust-git2 <unfixed>
[trixie] - rust-git2 <no-dsa> (Minor issue)
+ [bookworm] - rust-git2 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0183.html
NOTE: https://github.com/rust-lang/git2-rs/pull/1250
CVE-2026-XXXX [RUSTSEC-2026-0184]
- rust-git2 <unfixed>
[trixie] - rust-git2 <no-dsa> (Minor issue)
+ [bookworm] - rust-git2 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0184.html
NOTE: https://github.com/rust-lang/git2-rs/pull/1254
CVE-2026-50190
@@ -19496,6 +19548,7 @@ CVE-2026-11527 (Config::IniFiles versions before
3.001000 for Perl allow OS comm
CVE-2026-XXXX [RUSTSEC-2026-0178]
- rust-tokio-postgres <unfixed> (bug #1140013)
[trixie] - rust-tokio-postgres <no-dsa> (Minor issue)
+ [bookworm] - rust-tokio-postgres <postponed> (Limited support, minor
issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0178.html
NOTE:
https://github.com/rust-postgres/rust-postgres/commit/7a00ffa9ad4d951ec0a4564b52f1780fa9d353c1
(tokio-postgres-v0.7.18)
CVE-2026-XXXX [RUSTSEC-2026-0176]
@@ -19829,16 +19882,19 @@ CVE-2026-XXXX [RUSTSEC-2026-0172]
CVE-2026-XXXX [RUSTSEC-2026-0180]
- rust-postgres-protocol 0.6.12-1 (bug #1139876)
[trixie] - rust-postgres-protocol <no-dsa> (Minor issue)
+ [bookworm] - rust-postgres-protocol <postponed> (Limited support, minor
issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0180.html
NOTE:
https://github.com/rust-postgres/rust-postgres/commit/a7cf84b5c46431cbca9d8ff50508c23f446efa7d
(postgres-protocol-v0.6.12)
CVE-2026-XXXX [RUSTSEC-2026-0179]
- rust-postgres-protocol 0.6.12-1 (bug #1139876)
[trixie] - rust-postgres-protocol <no-dsa> (Minor issue)
+ [bookworm] - rust-postgres-protocol <postponed> (Limited support, minor
issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0179.html
NOTE:
https://github.com/rust-postgres/rust-postgres/commit/d40097a36a85068ea50a3afbf0ce154ba439e7f0
(postgres-protocol-v0.6.12)
CVE-2026-XXXX [RUSTSEC-2026-0177]
- rust-pyo3 <unfixed> (bug #1139875)
[trixie] - rust-pyo3 <no-dsa> (Minor issue)
+ [bookworm] - rust-pyo3 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0177.html
NOTE: https://github.com/PyO3/pyo3/pull/6096
CVE-2026-9641 (Crypt::PBKDF2 versions before 0.261630 for Perl have a weak
default al ...)
@@ -28393,6 +28449,7 @@ CVE-2026-45131 (CloudPirates Open Source Helm Charts is
a collection of Helm cha
CVE-2026-44740 (Billy is an interface filesystem abstraction for Go. Prior to
versions ...)
- golang-github-go-git-go-billy <unfixed>
[trixie] - golang-github-go-git-go-billy <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-billy <postponed> (Limited
support, minor issue; DoS on malformed input)
- golang-github-go-git-go-billy-v6 <unfixed>
NOTE:
https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6
CVE-2026-44211 (Cline is an autonomous coding agent as an SDK, IDE extension,
or CLI a ...)
@@ -29250,6 +29307,7 @@ CVE-2026-44285 (FastGPT is an AI Agent building
platform. Prior to 4.15.0-beta1,
CVE-2026-42500 (Decoding a paletted BMP file with an out-of-range palette
index result ...)
- golang-golang-x-image 0.42.0-1 (bug #1138257)
[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-image <postponed> (Limited support, minor
issue; BMP OOB read)
[bullseye] - golang-golang-x-image <no-dsa> (Minor issue)
NOTE: https://github.com/golang/go/issues/79576
NOTE: https://go-review.googlesource.com/c/image/+/781500
@@ -29377,6 +29435,7 @@ CVE-2026-48501 (GitHub CLI (gh) is GitHub\u2019s
official command line tool. Pri
[trixie] - golang-github-cli-go-gh-v2 <no-dsa> (Minor issue)
- golang-github-cli-go-gh <unfixed>
[trixie] - golang-github-cli-go-gh <no-dsa> (Minor issue)
+ [bookworm] - golang-github-cli-go-gh <postponed> (Limited support,
minor issue; token leak to sibling *.github.com hosts)
NOTE: https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9
CVE-2026-47745 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0,
the admi ...)
NOT-FOR-US: Shopper
@@ -30402,6 +30461,7 @@ CVE-2026-45023 (AutoGPT is a workflow automation
platform for creating, deployin
CVE-2026-44973 (Billy is an interface filesystem abstraction for Go. Prior to
5.9.0, m ...)
- golang-github-go-git-go-billy <unfixed>
[trixie] - golang-github-go-git-go-billy <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-billy <postponed> (Limited
support, minor issue; path traversal)
- golang-github-go-git-go-billy-v6 <unfixed>
NOTE:
https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2
CVE-2026-44885 (Portainer Community Edition is a lightweight service delivery
platform ...)
@@ -32157,11 +32217,13 @@ CVE-2026-45571 (go-git is an extensible git
implementation library written in pu
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support,
minor issue; path traversal)
NOTE:
https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96
CVE-2026-45570 (go-git is an extensible git implementation library written in
pure Go. ...)
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support,
minor issue; SSH argument quoting)
NOTE:
https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp
CVE-2026-45548 (Budibase is an open-source low-code platform. Prior to 3.34.8,
the pro ...)
NOT-FOR-US: Budibase
@@ -32189,6 +32251,7 @@ CVE-2026-45022 (go-git is an extensible git
implementation library written in pu
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support,
minor issue; signature-verification bypass)
NOTE:
https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp
CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC
client. In ...)
- libvncserver 0.9.15+dfsg-5 (bug #1138174)
@@ -35974,12 +36037,14 @@ CVE-2026-42626 (HP ENVY 5000 series printers
VERBASPP1N003.2237A.00 do not prope
CVE-2026-42506 (Parsing arbitrary HTML which is then rendered using Render can
result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor
issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor
issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79571
CVE-2026-42502 (Parsing arbitrary HTML which is then rendered using Render can
result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor
issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor
issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79572
@@ -36008,6 +36073,7 @@ CVE-2026-39964 (TypeBot is a chatbot builder tool. In
versions prior to 3.16.0,
CVE-2026-39821 (The ToASCII and ToUnicode functions incorrectly accept
Punycode-encode ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor
issue; IDNA Punycode validation)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor
issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/78760
@@ -36035,18 +36101,21 @@ CVE-2026-28444 (Typebot is a chatbot builder tool. In
versions 3.15.2 and prior,
CVE-2026-27136 (Parsing arbitrary HTML which is then rendered using Render can
result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor
issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor
issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79575
CVE-2026-25681 (Parsing arbitrary HTML which is then rendered using Render can
result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor
issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor
issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79574
CVE-2026-25680 (Parsing arbitrary HTML can consume excessive CPU time,
possibly leadin ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor
issue; html parse CPU DoS)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor
issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79573
@@ -36202,18 +36271,21 @@ CVE-2026-47101 (LiteLLM prior to 1.83.14 allows an
authenticated internal_user t
CVE-2026-46598 (For certain crafted inputs, a 'ed25519.PrivateKey' was created
by cast ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79596
CVE-2026-46597 (An incorrectly placed cast from bytes to int allowed for
server-side p ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79561
CVE-2026-46595 (Previously, CVE-2024-45337 fixed an authorization bypass for
misused s ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79570
@@ -36222,6 +36294,7 @@ CVE-2026-44409 (There is an an information disclosure
vulnerability in ZTE MU525
CVE-2026-42508 (Previously, a revoked 'SignatureKey' belonging to a CA was not
correct ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79568
@@ -36230,54 +36303,63 @@ CVE-2026-3481 (The WP Blockade plugin for WordPress
is vulnerable to Reflected C
CVE-2026-39835 (SSH servers which use CertChecker as a public key callback
without set ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79563
CVE-2026-39834 (When writing data larger than 4GB in a single Write call on an
SSH cha ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79567
CVE-2026-39833 (The in-memory keyring returned by NewKeyring() silently
accepted keys ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79436
CVE-2026-39832 (When adding a key to a remote agent constraint extensions such
as rest ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79435
CVE-2026-39831 (The Verify() method for FIDO/U2F security key types
(sk-ecdsa-sha2-nis ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79566
CVE-2026-39830 (A malicious SSH peer could send unsolicited global request
responses t ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79564
CVE-2026-39829 (The RSA and DSA public key parsers did not enforce size limits
on key ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79565
CVE-2026-39828 (When an SSH server authentication callback returned
PartialSuccessErro ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79562
CVE-2026-39827 (An authenticated SSH client that repeatedly opened channels
which were ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow
bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/35127
@@ -43824,6 +43906,7 @@ CVE-2026-41506 (go-git is an extensible git
implementation library written in pu
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1 (bug #1136095)
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support,
minor issue; credential leak on cross-host redirect)
NOTE:
https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963
NOTE: Fixed by:
https://github.com/go-git/go-git/commit/bcd20a9c525826081262a06a9ed9c3167abfcd53
(v5.18.0)
CVE-2026-41497 (PraisonAI is a multi-agent teams system. Prior to version
4.6.9, the f ...)
@@ -49618,18 +49701,21 @@ CVE-2026-41685 (Incus is a system container and
virtual machine manager. Prior t
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-98vh-x9cx-9cfp
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-41684 (Incus is a system container and virtual machine manager. Prior
to vers ...)
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-x5r6-jr56-89pv
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-41648 (Incus is a system container and virtual machine manager. Prior
to vers ...)
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-67wx-r9xr-x75x
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-41647 (Incus is a system container and virtual machine manager. Prior
to vers ...)
@@ -49641,6 +49727,7 @@ CVE-2026-40251 (Incus is a system container and virtual
machine manager. In vers
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-4m88-wxj4-9qj6
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-40243 (Incus is a system container and virtual machine manager. In
versions b ...)
@@ -49652,6 +49739,7 @@ CVE-2026-40197 (Incus is a system container and virtual
machine manager. In vers
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-r7w7-mmxr-47r9
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-35527 (Incus is an open source container and virtual machine manager.
In vers ...)
@@ -61860,6 +61948,7 @@ CVE-2026-34179 (In Canonical LXD versions 4.12 through
6.7, the doCertificateUpd
{DSA-6213-1 DSA-6212-1}
- incus 6.0.6-3
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-c3h3-89qf-jqm5
NOTE: https://github.com/canonical/lxd/pull/17936
NOTE:
https://github.com/canonical/lxd/commit/8c0c8dcc0f7b6ef59524bfeae198b6081248a88d
@@ -61878,6 +61967,7 @@ CVE-2026-34177 (Canonical LXD versions 4.12 through 6.7
contain an incomplete de
{DSA-6213-1}
- incus 6.0.2-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f
NOTE: https://github.com/canonical/lxd/pull/17909
NOTE:
https://github.com/canonical/lxd/commit/2f85d3ec0a6f9c9de8c003b81591ec173d489914
@@ -69340,6 +69430,7 @@ CVE-2026-33542 (Incus is a system container and virtual
machine manager. Prior t
{DSA-6188-1 DSA-6184-1}
- incus 6.0.6-2
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/pull/3092
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-p8mm-23gg-jc9r
CVE-2026-33711 (Incus is a system container and virtual machine manager. Incus
provide ...)
@@ -69358,6 +69449,7 @@ CVE-2026-33897 (Incus is a system container and virtual
machine manager. Prior t
{DSA-6188-1 DSA-6184-1}
- incus 6.0.6-2
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/pull/3092
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-83xr-5xxr-mh92
CVE-2026-33898 (Incus is a system container and virtual machine manager. Prior
to vers ...)
@@ -74344,9 +74436,11 @@ CVE-2026-33057 (Mesop is a Python-based UI framework
that allows users to build
CVE-2026-33056 (tar-rs is a tar archive reading/writing library for Rust. In
versions ...)
- rustc 1.92.0+dfsg1-2
[trixie] - rustc <no-dsa> (Minor issue)
+ [bookworm] - rustc <postponed> (Minor issue, parsing inconsistencies
among tar libraries, requires recompiling rdeps)
[bullseye] - rustc <postponed> (Minor issue, parsing inconsistencies
among tar libraries, requires recompiling rdeps)
- rust-tar 0.4.45-1 (bug #1131481)
[trixie] - rust-tar <no-dsa> (Minor issue)
+ [bookworm] - rust-tar <postponed> (Minor issue, parsing inconsistencies
among tar libraries, requires recompiling rdeps)
[bullseye] - rust-tar <postponed> (Minor issue, parsing inconsistencies
among tar libraries, requires recompiling rdeps)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0067.html
NOTE:
https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph
@@ -74354,9 +74448,11 @@ CVE-2026-33056 (tar-rs is a tar archive
reading/writing library for Rust. In ver
CVE-2026-33055 (tar-rs is a tar archive reading/writing library for Rust.
Versions 0.4 ...)
- rustc 1.92.0+dfsg1-2 (bug #1135225)
[trixie] - rustc <no-dsa> (Minor issue)
+ [bookworm] - rustc <postponed> (Minor issue, path traversal, requires
recompiling rdeps)
[bullseye] - rustc <postponed> (Minor issue, path traversal, requires
recompiling rdeps)
- rust-tar 0.4.45-1 (bug #1131480)
[trixie] - rust-tar <no-dsa> (Minor issue)
+ [bookworm] - rust-tar <postponed> (Minor issue, path traversal,
requires recompiling rdeps)
[bullseye] - rust-tar <postponed> (Minor issue, path traversal,
requires recompiling rdeps)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0068.html
NOTE:
https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-gchp-q4r4-x4ff
@@ -77695,6 +77791,7 @@ CVE-2026-28384 (An improper sanitization of the
compression_algorithm parameter
{DSA-6188-1 DSA-6184-1}
- incus 6.0.6-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-4rmf-rcp8-2r9g
NOTE: https://github.com/canonical/lxd/pull/17820
NOTE: https://github.com/lxc/incus/pull/2972
@@ -99376,12 +99473,14 @@ CVE-2026-23954 (Incus is a system container and
virtual machine manager. Version
{DSA-6153-1 DSA-6109-1}
- incus 6.0.5-8
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7
NOTE:
https://github.com/canonical/lxd/commit/9a80e47b358e56fb2c9f7abad61b1d0ac654b6fa
(lxd-5.0.6)
CVE-2026-23953 (Incus is a system container and virtual machine manager. In
versions 6 ...)
{DSA-6153-1 DSA-6109-1}
- incus 6.0.5-8
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-x6jc-phwx-hp32
NOTE:
https://github.com/canonical/lxd/commit/6343c2cb0c2c5d4057821f05094671bff032ede8
(lxd-5.0.6)
CVE-2024-31884
@@ -128690,6 +128789,7 @@ CVE-2025-64507 (Incus is a system container and
virtual machine manager. An issu
- incus 6.0.5-4
- lxd <removed>
[trixie] - lxd 5.0.2+git20231211.1364ae4-9+deb13u2
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf
NOTE: https://github.com/lxc/incus/issues/2641
NOTE: Fixed by: https://github.com/lxc/incus/pull/2642
@@ -141458,6 +141558,7 @@ CVE-2025-54293 (Path Traversal in the log file
retrieval function in Canonical L
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-472f-vmf2-pr3h
CVE-2025-54292 (Path traversal in Canonical LXD LXD-UI versions before 6.5 and
5.21.4 ...)
NOT-FOR-US: Canonical LXD LXD-UI (not bundled in src:lxd or src:incus)
@@ -141487,16 +141588,19 @@ CVE-2025-54288 (Information Spoofing in devLXD
Server in Canonical LXD versions
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-7232-97c6-j525
CVE-2025-54287 (Template Injection in instance snapshot creation component in
Canonica ...)
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6
CVE-2025-54286 (Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD
versions ...)
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-p8hw-rfjg-689h
CVE-2025-54086 (CVE-2025-54086 is an excess permissions vulnerability in the
Warehouse ...)
NOT-FOR-US: Absolute Software
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e4fd8128c65e1a07bd26a91d0df6d8871cefbef8...ae5ec5623d3865db6e731e5c7c511a9b413ddb2b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e4fd8128c65e1a07bd26a91d0df6d8871cefbef8...ae5ec5623d3865db6e731e5c7c511a9b413ddb2b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits