Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
96327711 by Sylvain Beucler at 2026-07-15T11:22:04+02:00
lts: shaarli postponed

also: low popcon, no sponsors

- - - - -
17bf9d3f by Sylvain Beucler at 2026-07-15T11:22:05+02:00
lts: add caddy/bookworm, nats-server/bookworm, node-dompurify/bookworm, 
rtpengine/bookworm

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -19414,6 +19414,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0184]
        NOTE: https://github.com/rust-lang/git2-rs/pull/1254
 CVE-2026-50190
        - shaarli <unfixed> (bug #1140348)
+       [bookworm] - shaarli <postponed> (Minor issue, XSS)
        NOTE: 
https://github.com/shaarli/Shaarli/security/advisories/GHSA-xm98-h5jj-64xv
 CVE-2026-9860 (The Offload, AI & Optimize with Cloudflare Images plugin for 
WordPress ...)
        NOT-FOR-US: WordPress plugin
@@ -19499,12 +19500,15 @@ CVE-2026-48979 (PHP Standard Library (PSL) is set of 
APIs covering async, collec
        NOT-FOR-US: PHP Standard Library (PSL)
 CVE-2026-48823 (Shaarli is a personal bookmarking service. Versions 0.16.1 and 
prior c ...)
        - shaarli <unfixed> (bug #1140347)
+       [bookworm] - shaarli <postponed> (Minor issue, XSS)
        NOTE: 
https://github.com/shaarli/Shaarli/security/advisories/GHSA-68qr-fvv8-6mc6
 CVE-2026-48822 (Shaarli is a personal bookmarking service. Versions 0.16.1 and 
prior c ...)
        - shaarli <unfixed> (bug #1140346)
+       [bookworm] - shaarli <postponed> (Minor issue, XSS)
        NOTE: 
https://github.com/shaarli/Shaarli/security/advisories/GHSA-2hgr-63wv-x462
 CVE-2026-48821 (Shaarli is a personal bookmarking service. Versions 0.16.1 and 
prior c ...)
        - shaarli <unfixed> (bug #1140345)
+       [bookworm] - shaarli <postponed> (Minor issue, XSS)
        NOTE: 
https://github.com/shaarli/Shaarli/security/advisories/GHSA-mw63-f9qj-c5h3
 CVE-2026-48820 (CakePHP is a rapid development framework for PHP. In versions 
4.5.11 a ...)
        NOT-FOR-US: CakePHP


=====================================
data/dla-needed.txt
=====================================
@@ -102,6 +102,10 @@ cacti
   NOTE: 20260630: Added by Front-Desk (dleidert)
   NOTE: 20260630: A new bunch of issues and in DSA list (dleidert/front-desk)
 --
+caddy/bookworm
+  NOTE: 20260715: Added by Front-Desk (Beuc)
+  NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
+--
 calibre/bullseye
   NOTE: 20260222: Added by Front-Desk (rouca)
   NOTE: 20260429: partial update (abhijith)
@@ -470,6 +474,10 @@ nagvis/bullseye
   NOTE: 20250629: Next DLA for 2 new issues has been released (dleidert)
   NOTE: 20250629: PU is ready and will be tested before sending the PU request 
(dleidert)
 --
+nats-server/bookworm
+  NOTE: 20260715: Added by Front-Desk (Beuc)
+  NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
+--
 netatalk/bullseye
   NOTE: 20260518: Added by Front-Desk (Beuc)
   NOTE: 20260518: DSA-6280-1 released fixing 20 patches for trixie.
@@ -491,6 +499,10 @@ nginx (charles)
   NOTE: 20260618: There was also a customer request to fix it. (charles)
   NOTE: 20260630: Bullseye fix release with 2 CVE fixes + http2 bomb fix. 
Bookworm coming soon. (charles)
 --
+node-dompurify/bookworm
+  NOTE: 20260715: Added by Front-Desk (Beuc)
+  NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
+--
 node-lodash/bookworm (utkarsh)
   NOTE: 20260703: Added by Front-Desk (dleidert)
   NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this 
(dleidert/front-desk)
@@ -642,6 +654,10 @@ rsync (Thorsten Alteholz)
   NOTE: 20260615: Requested by Sylvain to track regressions, same as in 
dsa-needed. (charles)
   NOTE: 20260705: making progress with updated patches
 --
+rtpengine/bookworm
+  NOTE: 20260715: Added by Front-Desk (Beuc)
+  NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
+--
 ruby-oj
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 
(GHSA); affects 2.17-3.14.



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1d807ee6c9842b37484711b214e69e59bc28fbc9...17bf9d3f747c9620f1104b59409dcd847a353a06

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1d807ee6c9842b37484711b214e69e59bc28fbc9...17bf9d3f747c9620f1104b59409dcd847a353a06
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to