Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f41d70da by Salvatore Bonaccorso at 2026-07-13T07:04:00+02:00
Process some NFUs
- - - - -
50569cd1 by Salvatore Bonaccorso at 2026-07-13T07:04:03+02:00
Add CVE-2026-449512/onnx
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -632,9 +632,9 @@ CVE-2026-57474 (Deloitte AI Assist for Customer disclosed
some configuration inf
CVE-2026-57167 (PeerTube is an ActivityPub-federated video streaming platform.
Prior t ...)
- peertube <itp> (bug #950821)
CVE-2026-56814 (Plug.Parsers.MULTIPART, the multipart request-body parser used
to hand ...)
- TODO: check
+ NOT-FOR-US: elixir-plug plug
CVE-2026-56813 (Improper Neutralization of Parameter/Argument Delimiters
vulnerability ...)
- TODO: check
+ NOT-FOR-US: elixir-plug plug
CVE-2026-56765 (Vikunja before 2.2.1 contains an authorization flaw where the
LinkShar ...)
NOT-FOR-US: Vikunja
CVE-2026-56690 (Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s)
an Improp ...)
@@ -806,7 +806,7 @@ CVE-2026-3251 (Improper neutralization of input during web
page generation ('cro
CVE-2026-39903 (Simple Machines Forum 2.1 prior to 2.1.8 and 3.0 prior to 3.0
Alpha 5 ...)
NOT-FOR-US: Simple Machines Forum
CVE-2026-39244 (adm-zip before 0.5.18 is vulnerable to denial of service via a
crafted ...)
- TODO: check
+ NOT-FOR-US: Node adm-zip module
CVE-2026-38059 (The iDirect iQ200 exposes the /api/identity and /api/ REST API
endpoin ...)
NOT-FOR-US: iDirect iQ200
CVE-2026-38057 (The iDirect iQ200 does not validate CSRF tokens on
state-changing API ...)
@@ -1026,11 +1026,11 @@ CVE-2026-44787 (Discourse is an open-source discussion
platform. Prior to 2026.6
CVE-2026-44342 (New API is a large language mode (LLM) gateway and artificial
intellig ...)
NOT-FOR-US: New API
CVE-2026-39246 (decompress before 4.2.2 allows arbitrary symlink creation
during archi ...)
- TODO: check
+ NOT-FOR-US: Node decompress module
CVE-2026-39245 (decompress before 4.2.2 contains an improper path containment
check th ...)
- TODO: check
+ NOT-FOR-US: Node decompress module
CVE-2026-39243 (decompress before 4.2.2 allows arbitrary hardlink creation
during arch ...)
- TODO: check
+ NOT-FOR-US: Node decompress module
CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function
of Arti ...)
TODO: check
CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended
Endpoints ...)
@@ -1793,7 +1793,10 @@ CVE-2026-47646 (Improper neutralization of input during
web page generation ('cr
CVE-2026-45045 (Fiber is an Express inspired web framework written in Go.
Prior to 3.3 ...)
NOT-FOR-US: Fiber
CVE-2026-44512 (Open Neural Network Exchange (ONNX) is an open standard for
machine le ...)
- TODO: check
+ - onnx <unfixed>
+ NOTE:
https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77
+ NOTE: https://github.com/onnx/onnx/pull/7813
+ NOTE: Fixed by:
https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf
(v1.22.0)
CVE-2026-44332 (Fiber is an Express inspired web framework written in Go.
Prior to 3.3 ...)
NOT-FOR-US: Fiber
CVE-2026-44161 (Fluentd collects events from various data sources and writes
them to f ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c01edb230a4a051605ffccbb81a600d5df306769...50569cd1e96aa347f198226c02c432fee41813f9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c01edb230a4a051605ffccbb81a600d5df306769...50569cd1e96aa347f198226c02c432fee41813f9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits