Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9396b663 by Salvatore Bonaccorso at 2026-07-18T16:27:19+02:00
Add new golang-oras-oras-go issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -127,11 +127,19 @@ CVE-2026-50271 (Datadog dd-trace-py is the Datadog Python
APM client. Prior to 4
CVE-2026-50197 (Skipper is an HTTP router and reverse proxy for service
composition. P ...)
NOT-FOR-US: Zalando Skipper
CVE-2026-50163 (oras-go is a Go library for managing OCI artifacts. Prior to
2.6.2, en ...)
- TODO: check
+ - golang-oras-oras-go <unfixed>
+ NOTE:
https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp
+ NOTE: https://github.com/oras-project/oras-go/pull/1232
+ NOTE: Fixed by:
https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451
(v2.6.2)
CVE-2026-50162 (oras-go is a Go library for managing OCI artifacts. Prior to
2.6.1, re ...)
- TODO: check
+ - golang-oras-oras-go <unfixed>
+ NOTE:
https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv
+ NOTE: Fixed by:
https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5
(v2.6.1)
CVE-2026-50151 (oras-go is a Go library for managing OCI artifacts. Prior to
2.6.1, re ...)
- TODO: check
+ - golang-oras-oras-go <unfixed>
+ NOTE:
https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7
+ NOTE: https://github.com/oras-project/oras-go/pull/1152
+ NOTE: Fixed by:
https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991
(v2.6.1)
CVE-2026-4942 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
send a s ...)
NOT-FOR-US: IBM
CVE-2026-4938 (IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security
Verify ...)
@@ -139,15 +147,22 @@ CVE-2026-4938 (IBM Verify Identity Access 11.0 through
11.0.2 and IBM Security V
CVE-2026-49977 (tarteaucitron.js is a compliant and accessible cookie banner.
Prior to ...)
NOT-FOR-US: tarteaucitron.js
CVE-2026-49852 (joserfc is a Python library that provides an implementation of
several ...)
- TODO: check
+ - joserfc 1.6.8-1
+ NOTE:
https://github.com/authlib/joserfc/security/advisories/GHSA-gg9x-qcx2-xmrh
+ NOTE: Fixed by:
https://github.com/authlib/joserfc/commit/86d00910b2b2d2d07503fee9b572906daefab7f1
(1.6.8)
CVE-2026-49834 (sigstore-go is a Go library for Sigstore signing and
verification. Pri ...)
- TODO: check
+ - sigstore-go 1.2.1-1
+ NOTE:
https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6
+ NOTE: https://github.com/sigstore/sigstore-go/pull/633
+ NOTE: Fixed by:
https://github.com/sigstore/sigstore-go/commit/dbb07e62623edd5b175fb9dd5a41dcb85a159207
(v1.2.0)
CVE-2026-49485 (HAPI FHIR is a complete implementation of the HL7 FHIR
standard for he ...)
NOT-FOR-US: HAPI FHIR
CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information
disclosure ...)
TODO: check
CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to
2.6.1, au ...)
- TODO: check
+ - golang-oras-oras-go <unfixed>
+ NOTE:
https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w
+ NOTE: Fixed by:
https://github.com/oras-project/oras-go/commit/7a9f4b0b9558821b0422152ebe21ae56930fe764
(v2.6.1)
CVE-2026-48819 (Hey API is an ecosystem for turning API specifications into
production ...)
NOT-FOR-US: Hey API
CVE-2026-48504 (OpenTelemetry Rust is the Rust OpenTelemetry implementation.
In 0.32.0 ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9396b66366cdb70069f4e97de863ee2df37f166e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9396b66366cdb70069f4e97de863ee2df37f166e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits