Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d5f22633 by Salvatore Bonaccorso at 2026-07-17T09:07:48+02:00
Add Debian bug references

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1980,7 +1980,7 @@ CVE-2026-49981 (Twig is a template language for PHP. 
Prior to 3.27.0, the per-te
        NOTE: 
https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4 
(v3.27.0)
        NOTE: Duplicate of CVE-2026-46636
 CVE-2026-49978 (DOMPurify is a DOM-only cross-site scripting sanitizer for 
HTML, MathM ...)
-       - node-dompurify <unfixed>
+       - node-dompurify <unfixed> (bug #1142280)
        NOTE: 
https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq
        NOTE: Fixed by: 
https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff
 (3.4.7)
 CVE-2026-49855 (Tornado is a Python web framework and asynchronous networking 
library. ...)
@@ -2051,11 +2051,11 @@ CVE-2026-49476 (Soup Sieve is a CSS selector library 
designed to be used with Be
        NOTE: 
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x
        NOTE: Fixed by: 
https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39
 (2.8.4)
 CVE-2026-49459 (DOMPurify is a DOM-only cross-site scripting sanitizer for 
HTML, MathM ...)
-       - node-dompurify <unfixed>
+       - node-dompurify <unfixed> (bug #1142280)
        NOTE: 
https://github.com/cure53/DOMPurify/security/advisories/GHSA-r47g-fvhr-h676
        NOTE: Fixed by: 
https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae
 (3.4.6)
 CVE-2026-49458 (DOMPurify is a DOM-only cross-site scripting sanitizer for 
HTML, MathM ...)
-       - node-dompurify <unfixed>
+       - node-dompurify <unfixed> (bug #1142280)
        NOTE: 
https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8
        NOTE: Fixed by: 
https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae
 (3.4.6)
 CVE-2026-49184 (Heap-based buffer overflow in Windows NTFS allows an 
unauthorized atta ...)
@@ -4405,7 +4405,7 @@ CVE-2026-15374 (A flaw has been found in Eleveo Call 
Recording Software 9.7.0. T
 CVE-2026-15373 (A vulnerability was detected in Eleveo Call Recording Software 
9.7.0.  ...)
        NOT-FOR-US: Eleveo Call Recording Software
 CVE-2026-15146 (GNU Wget does not validate the IP address provided by an FTP 
PASV resp ...)
-       - wget <unfixed>
+       - wget <unfixed> (bug #1142284)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b
 CVE-2026-15143 (A flaw was found in the file_type content detector of 
guardrails-detec ...)
        NOT-FOR-US: guardrails-detectors
@@ -4598,7 +4598,7 @@ CVE-2026-39245 (decompress before 4.2.2 contains an 
improper path containment ch
 CVE-2026-39243 (decompress before 4.2.2 allows arbitrary hardlink creation 
during arch ...)
        NOT-FOR-US: Node decompress module
 CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function 
of Arti ...)
-       - jbig2dec <unfixed>
+       - jbig2dec <unfixed> (bug #1142282)
        NOTE: Fixed by: 
https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b
 CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended 
Endpoints ...)
        NOT-FOR-US: Juniper
@@ -5369,7 +5369,7 @@ CVE-2026-47646 (Improper neutralization of input during 
web page generation ('cr
 CVE-2026-45045 (Fiber is an Express inspired web framework written in Go. 
Prior to 3.3 ...)
        NOT-FOR-US: Fiber
 CVE-2026-44512 (Open Neural Network Exchange (ONNX) is an open standard for 
machine le ...)
-       - onnx <unfixed>
+       - onnx <unfixed> (bug #1142281)
        NOTE: 
https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77
        NOTE: https://github.com/onnx/onnx/pull/7813
        NOTE: Fixed by: 
https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf 
(v1.22.0)
@@ -6024,7 +6024,7 @@ CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before 
1.651 for Perl have inv
        NOTE: 
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
        NOTE: Fixed by: 
https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d
 (1.651)
 CVE-2026-15041 (A flaw was found in 389 Directory Server. The PBKDF2-SHA256 
password v ...)
-       - 389-ds-base <unfixed>
+       - 389-ds-base <unfixed> (bug #1142285)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2498022
 CVE-2026-15036 (A vulnerability was determined in Harness up to 2.28.2. This 
vulnerabi ...)
        NOT-FOR-US: Harness
@@ -6405,10 +6405,10 @@ CVE-2026-23698 (Vtiger CRM through 8.4.0 contains an 
authenticated remote code e
 CVE-2026-23697 (Vtiger CRM before 8.4.0 contains an authenticated file upload 
vulnerab ...)
        NOT-FOR-US: Vtiger CRM
 CVE-2026-14969 (A flaw was found in 389-ds-base where the LDBM backend 
attribute encry ...)
-       - 389-ds-base <unfixed>
+       - 389-ds-base <unfixed> (bug #1142285)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2497735
 CVE-2026-14940 (A heap-buffer-overflow flaw was found in 389 Directory Server 
(389-ds- ...)
-       - 389-ds-base <unfixed>
+       - 389-ds-base <unfixed> (bug #1142285)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2497697
 CVE-2026-14935 (A logic vulnerability was found in GStreamer's webrtcbin 
component. Th ...)
        - gst-plugins-bad1.0 1.28.5-1
@@ -6479,7 +6479,7 @@ CVE-2026-12041 (The Chatra Live Chat + ChatBot + Cart 
Saver plugin for WordPress
 CVE-2026-11798 (The Social Share, Social Login and Social Comments Plugin 
\u2013 Super ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11610 (A heap buffer overflow flaw was found in the SASL I/O layer of 
389 Dir ...)
-       - 389-ds-base <unfixed>
+       - 389-ds-base <unfixed> (bug #1142285)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484414
 CVE-2026-11348 (Improper verification of cryptographic signature vulnerability 
in HAVE ...)
        NOT-FOR-US: HAVELSAN
@@ -7596,19 +7596,19 @@ CVE-2026-14688 (A vulnerability was identified in 
itsourcecode Online Hotel Mana
 CVE-2026-14687 (A vulnerability was determined in 666ghj BettaFish up to 
1.2.1. Impact ...)
        NOT-FOR-US: BettaFish
 CVE-2026-14686 (A vulnerability was found in HdrHistogram up to 2.2.2. This 
issue affe ...)
-       - hdrhistogram <unfixed>
+       - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/222
 CVE-2026-14685 (A vulnerability has been found in HdrHistogram up to 2.2.2. 
This vulne ...)
-       - hdrhistogram <unfixed>
+       - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/221
 CVE-2026-14684 (A flaw has been found in HdrHistogram up to 2.2.2. This 
affects the fu ...)
-       - hdrhistogram <unfixed>
+       - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/220
 CVE-2026-14683 (A vulnerability was detected in HdrHistogram up to 2.2.2. 
Affected by  ...)
-       - hdrhistogram <unfixed>
+       - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/219
 CVE-2026-14660 (A vulnerability was found in code-projects Online Job Portal 
1.0. The  ...)
@@ -7630,10 +7630,10 @@ CVE-2026-14653 (A vulnerability was determined in 
SourceCodester Simple and Nice
 CVE-2026-14652 (A vulnerability was found in SourceCodester Simple and Nice 
Shopping C ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-14651 (A vulnerability has been found in connorskees grass up to 
0.13.4. The  ...)
-       - sass-grass <unfixed>
+       - sass-grass <unfixed> (bug #1142287)
        NOTE: https://github.com/connorskees/grass/issues/117
 CVE-2026-14650 (A flaw has been found in connorskees grass up to 0.13.4. The 
affected  ...)
-       - sass-grass <unfixed>
+       - sass-grass <unfixed> (bug #1142287)
        NOTE: https://github.com/connorskees/grass/issues/116
 CVE-2026-14649 (A vulnerability was detected in code-projects Online Voting 
System 1.0 ...)
        NOT-FOR-US: code-projects



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5f226336f153be5ca15c7c0e9cf75bf1483eb87

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5f226336f153be5ca15c7c0e9cf75bf1483eb87
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to