Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
0d741bac by Sylvain Beucler at 2026-07-14T16:05:10+02:00
CVE-2025-27533/activemq: bookworm postponed
- - - - -
89c14c43 by Sylvain Beucler at 2026-07-14T16:15:45+02:00
CVE-2026-55213/h2o: bookworm postponed
- - - - -
752fcde6 by Sylvain Beucler at 2026-07-14T16:21:13+02:00
CVE-2026-40295/ruby-devise: bookwoom,bullseye postponed
- - - - -
fd04e95f by Sylvain Beucler at 2026-07-14T16:27:57+02:00
CVE-2026-44836,CVE-2026-44837/ruby-view-component: bookworm postponed
- - - - -
5db26e66 by Sylvain Beucler at 2026-07-14T16:36:04+02:00
lts: pypdf/pypdf2 postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1141,6 +1141,8 @@ CVE-2026-55229 (Gotenberg is a Docker-powered stateless
API for PDF files. Prior
NOT-FOR-US: Gotenberg
CVE-2026-55213 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and
HTTP/3. Pr ...)
- h2o <removed>
+ [bookworm] - h2o <postponed> (Minor issue, DoS)
+ [bullseye] - h2o <postponed> (Minor issue, DoS)
NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-432c-8xmj-frmq
CVE-2026-55187 (Mailpit is an email testing tool and API for developers. Prior
to 1.30 ...)
NOT-FOR-US: Mailpit
@@ -2444,14 +2446,20 @@ CVE-2026-59939 (httplib2 is a comprehensive HTTP client
library for Python. Prio
CVE-2026-59936 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.14 ...)
- pypdf <unfixed> (bug #1141771)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5xf7-4p34-54qr
NOTE: https://github.com/py-pdf/pypdf/pull/3891
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/ec3b14596186c40caca7cf8ab9b2155203e01b5b
(6.14.1)
CVE-2026-59935 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.14 ...)
- pypdf <unfixed> (bug #1141771)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g867-7843-wf8q
NOTE: https://github.com/py-pdf/pypdf/pull/3892
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/5a33a46416aa1ae6c025ff90a3cca57631fdafd2
(6.14.2)
@@ -2880,14 +2888,20 @@ CVE-2026-5356 (The LatePoint \u2013 Calendar Booking
Plugin for Appointments and
CVE-2026-59938 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.14 ...)
- pypdf <unfixed> (bug #1141771)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgp
NOTE: https://github.com/py-pdf/pypdf/pull/3888
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7a
(6.14.0)
CVE-2026-59937 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.14 ...)
- pypdf <unfixed> (bug #1141771)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-55h5-xmcq-c37v
NOTE: https://github.com/py-pdf/pypdf/pull/3887
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/b5fc5aa714f4b696fb9b1deaa35a9e4a4eb50dae
(6.14.0)
@@ -7074,7 +7088,10 @@ CVE-2026-57585 (MessagePack is the serializer
implementation for Python msgpack.
CVE-2026-57204 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
- pypdf <unfixed> (bug #1141339)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-jm82-fx9c-mx94
NOTE: https://github.com/py-pdf/pypdf/pull/3871
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/bbd083d1196d276d9c542418f77ac49e06de3ff1
(6.13.3)
@@ -15759,19 +15776,28 @@ CVE-2026-54911 (UltraJSON is a fast JSON encoder and
decoder written in pure C w
CVE-2026-54651 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
- pypdf <unfixed> (bug #1140629)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9xf-7f8q-9mcj
NOTE: https://github.com/py-pdf/pypdf/pull/3839
CVE-2026-54531 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
- pypdf <unfixed> (bug #1140629)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-m2v9-299j-rv96
NOTE: https://github.com/py-pdf/pypdf/pull/3830
CVE-2026-54530 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
- pypdf <unfixed> (bug #1140629)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-52x6-gq3r-vpf4
NOTE: https://github.com/py-pdf/pypdf/pull/3830
CVE-2026-54281 (Nest is a framework for building scalable Node.js server-side
applicat ...)
@@ -15791,13 +15817,19 @@ CVE-2026-49468 (LiteLLM is a proxy server (AI
Gateway) to call LLM APIs in OpenA
CVE-2026-49461 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.12 ...)
- pypdf <unfixed> (bug #1140629)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-j543-4vmf-qm7v
NOTE: https://github.com/py-pdf/pypdf/pull/3805
CVE-2026-49460 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.12 ...)
- pypdf <unfixed> (bug #1140629)
[trixie] - pypdf <no-dsa> (Minor issue)
+ [bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5hgr-hg42-57jg
NOTE: https://github.com/py-pdf/pypdf/pull/3806
CVE-2026-48746 (vLLM is an inference and serving engine for large language
models (LLM ...)
@@ -31961,6 +31993,7 @@ CVE-2026-48735 (pypdf is a free and open-source
pure-python PDF library. Prior t
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-wjqc-6w8f-h24c
NOTE: https://github.com/py-pdf/pypdf/pull/3796
CVE-2026-48526 (PyJWT is a JSON Web Token implementation in Python. Prior to
2.13.0, w ...)
@@ -32004,6 +32037,7 @@ CVE-2026-48156 (pypdf is a free and open-source
pure-python PDF library. Prior t
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-248m-82v9-q6g6
NOTE: https://github.com/py-pdf/pypdf/pull/3791
CVE-2026-48155 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.12 ...)
@@ -32012,6 +32046,7 @@ CVE-2026-48155 (pypdf is a free and open-source
pure-python PDF library. Prior t
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-cj93-chg6-vgv8
NOTE: https://github.com/py-pdf/pypdf/pull/3790
CVE-2026-47762 (TinyMCE is an open source rich text editor. Prior to 5.11.1,
7.9.3, an ...)
@@ -35710,9 +35745,11 @@ CVE-2026-44843 (LangChain is a framework for building
agents and LLM-powered app
NOT-FOR-US: LangChain
CVE-2026-44837 (view_component is a framework for building reusable, testable,
and enc ...)
- ruby-view-component 4.12.0-1 (bug #1138259)
+ [bookworm] - ruby-view-component <postponed> (Contrib not supported)
NOTE:
https://github.com/ViewComponent/view_component/security/advisories/GHSA-hg3h-g7xc-f7vp
CVE-2026-44836 (view_component is a framework for building reusable, testable,
and enc ...)
- ruby-view-component 4.12.0-1 (bug #1138259)
+ [bookworm] - ruby-view-component <postponed> (Contrib not supported)
NOTE:
https://github.com/ViewComponent/view_component/security/advisories/GHSA-7f3r-gwc9-2995
CVE-2026-44833 (Snipe-IT is an IT asset/license management system. Prior to
8.4.1, an ...)
- snipe-it <itp> (bug #1005172)
@@ -37127,6 +37164,8 @@ CVE-2026-40411 (Improper input validation in Azure
Virtual Network Gateway allow
NOT-FOR-US: Microsoft
CVE-2026-40295 (Devise is an authentication solution for Rails based on
Warden. In ver ...)
- ruby-devise <removed>
+ [bookworm] - ruby-devise <postponed> (Minor issue, open redirect)
+ [bullseye] - ruby-devise <postponed> (Minor issue, open redirect)
NOTE:
https://github.com/heartcombo/devise/security/advisories/GHSA-jp94-3292-c3xv
NOTE: Fixed by:
https://github.com/heartcombo/devise/commit/025fe2124f9928766fc46520e999633b598d0360
(v5.0.4)
CVE-2026-3294 (An authentication logic vulnerability in multiple TP-Link range
extend ...)
@@ -55726,6 +55765,7 @@ CVE-2026-41314 (pypdf is a free and open-source
pure-python PDF library. An atta
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-x284-j5p8-9c5p
NOTE: https://github.com/py-pdf/pypdf/pull/3734
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11
(6.10.2)
@@ -55735,6 +55775,7 @@ CVE-2026-41313 (pypdf is a free and open-source
pure-python PDF library. An atta
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-4pxv-j86v-mhcw
NOTE: https://github.com/py-pdf/pypdf/pull/3735
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/c50a0104cf083356f7c7f5d61410466a57f5c88a
(6.10.2)
@@ -55744,6 +55785,7 @@ CVE-2026-41312 (pypdf is a free and open-source
pure-python PDF library. An atta
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-7gw9-cf7v-778f
NOTE: https://github.com/py-pdf/pypdf/pull/3734
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11
(6.10.2)
@@ -55809,6 +55851,7 @@ CVE-2026-41168 (pypdf is a free and open-source
pure-python PDF library. An atta
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-jj6c-8h6c-hppx
NOTE: https://github.com/py-pdf/pypdf/pull/3733
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/62338e9d36419cf193ccec7331784f45df1d70b3
(6.10.1)
@@ -59289,6 +59332,7 @@ CVE-2026-40260 (pypdf is a free and open-source
pure-python PDF library. In vers
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-3crg-w4f6-42mx
NOTE: https://github.com/py-pdf/pypdf/pull/3724
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/b15a374e5ca648d4878e57c3b2c0551e7f8cc7f8
(6.10.0)
@@ -74385,6 +74429,7 @@ CVE-2026-33699 (pypdf is a free and open-source
pure-python PDF library. Version
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-87mj-5ggw-8qc3
NOTE: https://github.com/py-pdf/pypdf/pull/3693
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/02b1345f77fdbc006faccc301507df4fb1855413
(6.9.2)
@@ -75366,6 +75411,7 @@ CVE-2026-33123 (pypdf is a free and open-source
pure-python PDF library. Version
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-qpxp-75px-xjcp
NOTE: https://github.com/py-pdf/pypdf/pull/3686
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/0b5d05de59a055c132b435ee2375bc32ff04d48e
(6.9.1)
@@ -79921,6 +79967,7 @@ CVE-2026-31826 (pypdf is a free and open-source
pure-python PDF library. Prior t
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-hqmh-ppp3-xvm7
NOTE: https://github.com/py-pdf/pypdf/pull/3675
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/3c550b3196adeba1506a26e57c09c09fac75e9aa
(6.8.0)
@@ -82230,6 +82277,7 @@ CVE-2026-28804 (pypdf is a free and open-source
pure-python PDF library. Prior t
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-9m86-7pmv-2852
NOTE: https://github.com/py-pdf/pypdf/pull/3666
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/648c627d2657447dfb1773412af05a0a5103b98f
(6.7.5)
@@ -85547,6 +85595,7 @@ CVE-2026-27888 (pypdf is a free and open-source
pure-python PDF library. Prior t
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-x7hp-r3qg-r3cj
NOTE: https://github.com/py-pdf/pypdf/pull/3658
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/7a4c8246ed48d9d328fb596942271da47b6d109c
(6.7.3)
@@ -86160,6 +86209,7 @@ CVE-2026-27628 (pypdf is a free and open-source
pure-python PDF library. Prior t
[bookworm] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <no-dsa> (Minor issue)
+ [bullseye] - pypdf2 <postponed> (Minor issue)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-2rw7-x74f-jg35
NOTE: https://github.com/py-pdf/pypdf/issues/3654
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/f0a462d36971cf077d74492a348d0d06fd60ea4d
(6.7.2)
@@ -191541,6 +191591,7 @@ CVE-2024-12120 (The Royal Elementor Addons and
Templates plugin for WordPress is
CVE-2025-27533 (Memory Allocation with Excessive Size Value vulnerability in
Apache Ac ...)
{DLA-4222-1}
- activemq 5.17.6+dfsg-2 (bug #1104933)
+ [bookworm] - activemq <postponed> (Minor issue, DoS)
NOTE: https://issues.apache.org/jira/browse/AMQ-6596
NOTE: Fixed by https://github.com/apache/activemq/pull/1399
CVE-2025-4372 (Use after free in WebAudio in Google Chrome prior to
136.0.7103.92 all ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/28648881cbdb61a6c34b2affb7dce7453ef25c90...5db26e66a35a1372a8ff515f322d1cd52b8bcfa8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/28648881cbdb61a6c34b2affb7dce7453ef25c90...5db26e66a35a1372a8ff515f322d1cd52b8bcfa8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits