Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d5f22633 by Salvatore Bonaccorso at 2026-07-17T09:07:48+02:00
Add Debian bug references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1980,7 +1980,7 @@ CVE-2026-49981 (Twig is a template language for PHP.
Prior to 3.27.0, the per-te
NOTE:
https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4
(v3.27.0)
NOTE: Duplicate of CVE-2026-46636
CVE-2026-49978 (DOMPurify is a DOM-only cross-site scripting sanitizer for
HTML, MathM ...)
- - node-dompurify <unfixed>
+ - node-dompurify <unfixed> (bug #1142280)
NOTE:
https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq
NOTE: Fixed by:
https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff
(3.4.7)
CVE-2026-49855 (Tornado is a Python web framework and asynchronous networking
library. ...)
@@ -2051,11 +2051,11 @@ CVE-2026-49476 (Soup Sieve is a CSS selector library
designed to be used with Be
NOTE:
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x
NOTE: Fixed by:
https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39
(2.8.4)
CVE-2026-49459 (DOMPurify is a DOM-only cross-site scripting sanitizer for
HTML, MathM ...)
- - node-dompurify <unfixed>
+ - node-dompurify <unfixed> (bug #1142280)
NOTE:
https://github.com/cure53/DOMPurify/security/advisories/GHSA-r47g-fvhr-h676
NOTE: Fixed by:
https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae
(3.4.6)
CVE-2026-49458 (DOMPurify is a DOM-only cross-site scripting sanitizer for
HTML, MathM ...)
- - node-dompurify <unfixed>
+ - node-dompurify <unfixed> (bug #1142280)
NOTE:
https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8
NOTE: Fixed by:
https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae
(3.4.6)
CVE-2026-49184 (Heap-based buffer overflow in Windows NTFS allows an
unauthorized atta ...)
@@ -4405,7 +4405,7 @@ CVE-2026-15374 (A flaw has been found in Eleveo Call
Recording Software 9.7.0. T
CVE-2026-15373 (A vulnerability was detected in Eleveo Call Recording Software
9.7.0. ...)
NOT-FOR-US: Eleveo Call Recording Software
CVE-2026-15146 (GNU Wget does not validate the IP address provided by an FTP
PASV resp ...)
- - wget <unfixed>
+ - wget <unfixed> (bug #1142284)
NOTE: Fixed by:
https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b
CVE-2026-15143 (A flaw was found in the file_type content detector of
guardrails-detec ...)
NOT-FOR-US: guardrails-detectors
@@ -4598,7 +4598,7 @@ CVE-2026-39245 (decompress before 4.2.2 contains an
improper path containment ch
CVE-2026-39243 (decompress before 4.2.2 allows arbitrary hardlink creation
during arch ...)
NOT-FOR-US: Node decompress module
CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function
of Arti ...)
- - jbig2dec <unfixed>
+ - jbig2dec <unfixed> (bug #1142282)
NOTE: Fixed by:
https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b
CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended
Endpoints ...)
NOT-FOR-US: Juniper
@@ -5369,7 +5369,7 @@ CVE-2026-47646 (Improper neutralization of input during
web page generation ('cr
CVE-2026-45045 (Fiber is an Express inspired web framework written in Go.
Prior to 3.3 ...)
NOT-FOR-US: Fiber
CVE-2026-44512 (Open Neural Network Exchange (ONNX) is an open standard for
machine le ...)
- - onnx <unfixed>
+ - onnx <unfixed> (bug #1142281)
NOTE:
https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77
NOTE: https://github.com/onnx/onnx/pull/7813
NOTE: Fixed by:
https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf
(v1.22.0)
@@ -6024,7 +6024,7 @@ CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before
1.651 for Perl have inv
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d
(1.651)
CVE-2026-15041 (A flaw was found in 389 Directory Server. The PBKDF2-SHA256
password v ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2498022
CVE-2026-15036 (A vulnerability was determined in Harness up to 2.28.2. This
vulnerabi ...)
NOT-FOR-US: Harness
@@ -6405,10 +6405,10 @@ CVE-2026-23698 (Vtiger CRM through 8.4.0 contains an
authenticated remote code e
CVE-2026-23697 (Vtiger CRM before 8.4.0 contains an authenticated file upload
vulnerab ...)
NOT-FOR-US: Vtiger CRM
CVE-2026-14969 (A flaw was found in 389-ds-base where the LDBM backend
attribute encry ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2497735
CVE-2026-14940 (A heap-buffer-overflow flaw was found in 389 Directory Server
(389-ds- ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2497697
CVE-2026-14935 (A logic vulnerability was found in GStreamer's webrtcbin
component. Th ...)
- gst-plugins-bad1.0 1.28.5-1
@@ -6479,7 +6479,7 @@ CVE-2026-12041 (The Chatra Live Chat + ChatBot + Cart
Saver plugin for WordPress
CVE-2026-11798 (The Social Share, Social Login and Social Comments Plugin
\u2013 Super ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11610 (A heap buffer overflow flaw was found in the SASL I/O layer of
389 Dir ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484414
CVE-2026-11348 (Improper verification of cryptographic signature vulnerability
in HAVE ...)
NOT-FOR-US: HAVELSAN
@@ -7596,19 +7596,19 @@ CVE-2026-14688 (A vulnerability was identified in
itsourcecode Online Hotel Mana
CVE-2026-14687 (A vulnerability was determined in 666ghj BettaFish up to
1.2.1. Impact ...)
NOT-FOR-US: BettaFish
CVE-2026-14686 (A vulnerability was found in HdrHistogram up to 2.2.2. This
issue affe ...)
- - hdrhistogram <unfixed>
+ - hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/222
CVE-2026-14685 (A vulnerability has been found in HdrHistogram up to 2.2.2.
This vulne ...)
- - hdrhistogram <unfixed>
+ - hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/221
CVE-2026-14684 (A flaw has been found in HdrHistogram up to 2.2.2. This
affects the fu ...)
- - hdrhistogram <unfixed>
+ - hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/220
CVE-2026-14683 (A vulnerability was detected in HdrHistogram up to 2.2.2.
Affected by ...)
- - hdrhistogram <unfixed>
+ - hdrhistogram <unfixed> (bug #1142286)
[trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/219
CVE-2026-14660 (A vulnerability was found in code-projects Online Job Portal
1.0. The ...)
@@ -7630,10 +7630,10 @@ CVE-2026-14653 (A vulnerability was determined in
SourceCodester Simple and Nice
CVE-2026-14652 (A vulnerability was found in SourceCodester Simple and Nice
Shopping C ...)
NOT-FOR-US: SourceCodester
CVE-2026-14651 (A vulnerability has been found in connorskees grass up to
0.13.4. The ...)
- - sass-grass <unfixed>
+ - sass-grass <unfixed> (bug #1142287)
NOTE: https://github.com/connorskees/grass/issues/117
CVE-2026-14650 (A flaw has been found in connorskees grass up to 0.13.4. The
affected ...)
- - sass-grass <unfixed>
+ - sass-grass <unfixed> (bug #1142287)
NOTE: https://github.com/connorskees/grass/issues/116
CVE-2026-14649 (A vulnerability was detected in code-projects Online Voting
System 1.0 ...)
NOT-FOR-US: code-projects
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5f226336f153be5ca15c7c0e9cf75bf1483eb87
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5f226336f153be5ca15c7c0e9cf75bf1483eb87
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits