Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0d741bac by Sylvain Beucler at 2026-07-14T16:05:10+02:00
CVE-2025-27533/activemq: bookworm postponed

- - - - -
89c14c43 by Sylvain Beucler at 2026-07-14T16:15:45+02:00
CVE-2026-55213/h2o: bookworm postponed

- - - - -
752fcde6 by Sylvain Beucler at 2026-07-14T16:21:13+02:00
CVE-2026-40295/ruby-devise: bookwoom,bullseye postponed

- - - - -
fd04e95f by Sylvain Beucler at 2026-07-14T16:27:57+02:00
CVE-2026-44836,CVE-2026-44837/ruby-view-component: bookworm postponed

- - - - -
5db26e66 by Sylvain Beucler at 2026-07-14T16:36:04+02:00
lts: pypdf/pypdf2 postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1141,6 +1141,8 @@ CVE-2026-55229 (Gotenberg is a Docker-powered stateless 
API for PDF files. Prior
        NOT-FOR-US: Gotenberg
 CVE-2026-55213 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and 
HTTP/3. Pr ...)
        - h2o <removed>
+       [bookworm] - h2o <postponed> (Minor issue, DoS)
+       [bullseye] - h2o <postponed> (Minor issue, DoS)
        NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-432c-8xmj-frmq
 CVE-2026-55187 (Mailpit is an email testing tool and API for developers. Prior 
to 1.30 ...)
        NOT-FOR-US: Mailpit
@@ -2444,14 +2446,20 @@ CVE-2026-59939 (httplib2 is a comprehensive HTTP client 
library for Python. Prio
 CVE-2026-59936 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.14 ...)
        - pypdf <unfixed> (bug #1141771)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5xf7-4p34-54qr
        NOTE: https://github.com/py-pdf/pypdf/pull/3891
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/ec3b14596186c40caca7cf8ab9b2155203e01b5b 
(6.14.1)
 CVE-2026-59935 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.14 ...)
        - pypdf <unfixed> (bug #1141771)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g867-7843-wf8q
        NOTE: https://github.com/py-pdf/pypdf/pull/3892
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/5a33a46416aa1ae6c025ff90a3cca57631fdafd2 
(6.14.2)
@@ -2880,14 +2888,20 @@ CVE-2026-5356 (The LatePoint \u2013 Calendar Booking 
Plugin for Appointments and
 CVE-2026-59938 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.14 ...)
        - pypdf <unfixed> (bug #1141771)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgp
        NOTE: https://github.com/py-pdf/pypdf/pull/3888
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7a 
(6.14.0)
 CVE-2026-59937 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.14 ...)
        - pypdf <unfixed> (bug #1141771)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-55h5-xmcq-c37v
        NOTE: https://github.com/py-pdf/pypdf/pull/3887
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/b5fc5aa714f4b696fb9b1deaa35a9e4a4eb50dae 
(6.14.0)
@@ -7074,7 +7088,10 @@ CVE-2026-57585 (MessagePack is the serializer 
implementation for Python msgpack.
 CVE-2026-57204 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
        - pypdf <unfixed> (bug #1141339)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-jm82-fx9c-mx94
        NOTE: https://github.com/py-pdf/pypdf/pull/3871
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/bbd083d1196d276d9c542418f77ac49e06de3ff1 
(6.13.3)
@@ -15759,19 +15776,28 @@ CVE-2026-54911 (UltraJSON is a fast JSON encoder and 
decoder written in pure C w
 CVE-2026-54651 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
        - pypdf <unfixed> (bug #1140629)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9xf-7f8q-9mcj
        NOTE: https://github.com/py-pdf/pypdf/pull/3839
 CVE-2026-54531 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
        - pypdf <unfixed> (bug #1140629)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-m2v9-299j-rv96
        NOTE: https://github.com/py-pdf/pypdf/pull/3830
 CVE-2026-54530 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
        - pypdf <unfixed> (bug #1140629)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-52x6-gq3r-vpf4
        NOTE: https://github.com/py-pdf/pypdf/pull/3830
 CVE-2026-54281 (Nest is a framework for building scalable Node.js server-side 
applicat ...)
@@ -15791,13 +15817,19 @@ CVE-2026-49468 (LiteLLM is a proxy server (AI 
Gateway) to call LLM APIs in OpenA
 CVE-2026-49461 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.12 ...)
        - pypdf <unfixed> (bug #1140629)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-j543-4vmf-qm7v
        NOTE: https://github.com/py-pdf/pypdf/pull/3805
 CVE-2026-49460 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.12 ...)
        - pypdf <unfixed> (bug #1140629)
        [trixie] - pypdf <no-dsa> (Minor issue)
+       [bookworm] - pypdf <postponed> (Minor issue)
        - pypdf2 <removed>
+       [bookworm] - pypdf2 <postponed> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5hgr-hg42-57jg
        NOTE: https://github.com/py-pdf/pypdf/pull/3806
 CVE-2026-48746 (vLLM is an inference and serving engine for large language 
models (LLM ...)
@@ -31961,6 +31993,7 @@ CVE-2026-48735 (pypdf is a free and open-source 
pure-python PDF library. Prior t
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-wjqc-6w8f-h24c
        NOTE: https://github.com/py-pdf/pypdf/pull/3796
 CVE-2026-48526 (PyJWT is a JSON Web Token implementation in Python. Prior to 
2.13.0, w ...)
@@ -32004,6 +32037,7 @@ CVE-2026-48156 (pypdf is a free and open-source 
pure-python PDF library. Prior t
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-248m-82v9-q6g6
        NOTE: https://github.com/py-pdf/pypdf/pull/3791
 CVE-2026-48155 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.12 ...)
@@ -32012,6 +32046,7 @@ CVE-2026-48155 (pypdf is a free and open-source 
pure-python PDF library. Prior t
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-cj93-chg6-vgv8
        NOTE: https://github.com/py-pdf/pypdf/pull/3790
 CVE-2026-47762 (TinyMCE is an open source rich text editor. Prior to 5.11.1, 
7.9.3, an ...)
@@ -35710,9 +35745,11 @@ CVE-2026-44843 (LangChain is a framework for building 
agents and LLM-powered app
        NOT-FOR-US: LangChain
 CVE-2026-44837 (view_component is a framework for building reusable, testable, 
and enc ...)
        - ruby-view-component 4.12.0-1 (bug #1138259)
+       [bookworm] - ruby-view-component <postponed> (Contrib not supported)
        NOTE: 
https://github.com/ViewComponent/view_component/security/advisories/GHSA-hg3h-g7xc-f7vp
 CVE-2026-44836 (view_component is a framework for building reusable, testable, 
and enc ...)
        - ruby-view-component 4.12.0-1 (bug #1138259)
+       [bookworm] - ruby-view-component <postponed> (Contrib not supported)
        NOTE: 
https://github.com/ViewComponent/view_component/security/advisories/GHSA-7f3r-gwc9-2995
 CVE-2026-44833 (Snipe-IT is an IT asset/license management system. Prior to 
8.4.1, an  ...)
        - snipe-it <itp> (bug #1005172)
@@ -37127,6 +37164,8 @@ CVE-2026-40411 (Improper input validation in Azure 
Virtual Network Gateway allow
        NOT-FOR-US: Microsoft
 CVE-2026-40295 (Devise is an authentication solution for Rails based on 
Warden. In ver ...)
        - ruby-devise <removed>
+       [bookworm] - ruby-devise <postponed> (Minor issue, open redirect)
+       [bullseye] - ruby-devise <postponed> (Minor issue, open redirect)
        NOTE: 
https://github.com/heartcombo/devise/security/advisories/GHSA-jp94-3292-c3xv
        NOTE: Fixed by: 
https://github.com/heartcombo/devise/commit/025fe2124f9928766fc46520e999633b598d0360
 (v5.0.4)
 CVE-2026-3294 (An authentication logic vulnerability in multiple TP-Link range 
extend ...)
@@ -55726,6 +55765,7 @@ CVE-2026-41314 (pypdf is a free and open-source 
pure-python PDF library. An atta
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-x284-j5p8-9c5p
        NOTE: https://github.com/py-pdf/pypdf/pull/3734
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11 
(6.10.2)
@@ -55735,6 +55775,7 @@ CVE-2026-41313 (pypdf is a free and open-source 
pure-python PDF library. An atta
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-4pxv-j86v-mhcw
        NOTE: https://github.com/py-pdf/pypdf/pull/3735
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/c50a0104cf083356f7c7f5d61410466a57f5c88a 
(6.10.2)
@@ -55744,6 +55785,7 @@ CVE-2026-41312 (pypdf is a free and open-source 
pure-python PDF library. An atta
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-7gw9-cf7v-778f
        NOTE: https://github.com/py-pdf/pypdf/pull/3734
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11 
(6.10.2)
@@ -55809,6 +55851,7 @@ CVE-2026-41168 (pypdf is a free and open-source 
pure-python PDF library. An atta
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-jj6c-8h6c-hppx
        NOTE: https://github.com/py-pdf/pypdf/pull/3733
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/62338e9d36419cf193ccec7331784f45df1d70b3 
(6.10.1)
@@ -59289,6 +59332,7 @@ CVE-2026-40260 (pypdf is a free and open-source 
pure-python PDF library. In vers
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-3crg-w4f6-42mx
        NOTE: https://github.com/py-pdf/pypdf/pull/3724
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/b15a374e5ca648d4878e57c3b2c0551e7f8cc7f8 
(6.10.0)
@@ -74385,6 +74429,7 @@ CVE-2026-33699 (pypdf is a free and open-source 
pure-python PDF library. Version
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-87mj-5ggw-8qc3
        NOTE: https://github.com/py-pdf/pypdf/pull/3693
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/02b1345f77fdbc006faccc301507df4fb1855413 
(6.9.2)
@@ -75366,6 +75411,7 @@ CVE-2026-33123 (pypdf is a free and open-source 
pure-python PDF library. Version
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-qpxp-75px-xjcp
        NOTE: https://github.com/py-pdf/pypdf/pull/3686
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/0b5d05de59a055c132b435ee2375bc32ff04d48e 
(6.9.1)
@@ -79921,6 +79967,7 @@ CVE-2026-31826 (pypdf is a free and open-source 
pure-python PDF library. Prior t
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-hqmh-ppp3-xvm7
        NOTE: https://github.com/py-pdf/pypdf/pull/3675
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/3c550b3196adeba1506a26e57c09c09fac75e9aa 
(6.8.0)
@@ -82230,6 +82277,7 @@ CVE-2026-28804 (pypdf is a free and open-source 
pure-python PDF library. Prior t
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-9m86-7pmv-2852
        NOTE: https://github.com/py-pdf/pypdf/pull/3666
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/648c627d2657447dfb1773412af05a0a5103b98f 
(6.7.5)
@@ -85547,6 +85595,7 @@ CVE-2026-27888 (pypdf is a free and open-source 
pure-python PDF library. Prior t
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-x7hp-r3qg-r3cj
        NOTE: https://github.com/py-pdf/pypdf/pull/3658
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/7a4c8246ed48d9d328fb596942271da47b6d109c 
(6.7.3)
@@ -86160,6 +86209,7 @@ CVE-2026-27628 (pypdf is a free and open-source 
pure-python PDF library. Prior t
        [bookworm] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <no-dsa> (Minor issue)
+       [bullseye] - pypdf2 <postponed> (Minor issue)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-2rw7-x74f-jg35
        NOTE: https://github.com/py-pdf/pypdf/issues/3654
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/f0a462d36971cf077d74492a348d0d06fd60ea4d 
(6.7.2)
@@ -191541,6 +191591,7 @@ CVE-2024-12120 (The Royal Elementor Addons and 
Templates plugin for WordPress is
 CVE-2025-27533 (Memory Allocation with Excessive Size Value vulnerability in 
Apache Ac ...)
        {DLA-4222-1}
        - activemq 5.17.6+dfsg-2 (bug #1104933)
+       [bookworm] - activemq <postponed> (Minor issue, DoS)
        NOTE: https://issues.apache.org/jira/browse/AMQ-6596
        NOTE: Fixed by https://github.com/apache/activemq/pull/1399
 CVE-2025-4372 (Use after free in WebAudio in Google Chrome prior to 
136.0.7103.92 all ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/28648881cbdb61a6c34b2affb7dce7453ef25c90...5db26e66a35a1372a8ff515f322d1cd52b8bcfa8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/28648881cbdb61a6c34b2affb7dce7453ef25c90...5db26e66a35a1372a8ff515f322d1cd52b8bcfa8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to