Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3b28f1ec by security tracker role at 2026-07-20T19:13:46+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,40 +1,334 @@
-CVE-2026-64207 [net/sched: dualpi2: fix GSO backlog accounting]
+CVE-2026-8170 (The mv, cp, and rm file utilities exposed within the ExtremeXOS 
(EXOS) ...)
+       TODO: check
+CVE-2026-8169 (ExtremeXOS (EXOS) uses a challenge-response mechanism to 
authorize acc ...)
+       TODO: check
+CVE-2026-6793 (Improper neutralization of input during web page generation 
('cross-si ...)
+       TODO: check
+CVE-2026-64623 (Network-AI before 5.13.4 contains an improper cryptographic 
signature  ...)
+       TODO: check
+CVE-2026-64622 (Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 
fail to ap ...)
+       TODO: check
+CVE-2026-64621 (FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a 
double- ...)
+       TODO: check
+CVE-2026-64620 (FreeRDP before 3.28.0 (affected <=3.27.1) contains a 
heap-based buffer ...)
+       TODO: check
+CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG 
image rea ...)
+       TODO: check
+CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of 
Service via de ...)
+       TODO: check
+CVE-2026-64193 (Net::DNS versions through 1.55 for Perl allow remote execution 
injecti ...)
+       TODO: check
+CVE-2026-63763 (SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a 
confused dep ...)
+       TODO: check
+CVE-2026-63762 (SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a 
denial o ...)
+       TODO: check
+CVE-2026-63761 (SurrealDB before 3.1.0 silently substitutes the ES384 
algorithm when a ...)
+       TODO: check
+CVE-2026-63760 (SurrealDB before 3.1.0 fails to enforce the configured 
recursion depth ...)
+       TODO: check
+CVE-2026-63759 (SurrealDB before 3.1.0 fails to enforce recursion depth limits 
in the  ...)
+       TODO: check
+CVE-2026-63758 (SurrealDB versions before 3.1.0 contain an authorization 
bypass vulner ...)
+       TODO: check
+CVE-2026-63757 (SurrealDB versions before 3.1.0 contain a session hijacking 
vulnerabil ...)
+       TODO: check
+CVE-2026-63756 (SurrealDB versions before 3.1.0 contain a 
time-of-check/time-of-use ra ...)
+       TODO: check
+CVE-2026-63755 (SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses 
in SELECT ...)
+       TODO: check
+CVE-2026-63754 (SurrealDB versions before 3.1.0 contain a denial of service 
vulnerabil ...)
+       TODO: check
+CVE-2026-63753 (SurrealDB before 3.1.0 fails to refresh authentication state 
in LIVE S ...)
+       TODO: check
+CVE-2026-63752 (SurrealDB before 3.1.0 contains an authorization bypass 
vulnerability  ...)
+       TODO: check
+CVE-2026-63751 (SurrealDB versions before 3.1.0 contain a field-level 
permission bypas ...)
+       TODO: check
+CVE-2026-63750 (SurrealDB versions before 3.1.0 fail to apply the 
SURREAL_WEBSOCKET_MA ...)
+       TODO: check
+CVE-2026-63749 (SurrealDB versions before 3.1.0 contain an authentication 
bypass vulne ...)
+       TODO: check
+CVE-2026-63748 (SurrealDB versions before 3.1.0 contain an information 
disclosure vuln ...)
+       TODO: check
+CVE-2026-63747 (SurrealDB versions before 3.1.0 contain a denial of service 
vulnerabil ...)
+       TODO: check
+CVE-2026-63746 (SurrealDB versions before 3.1.0 fail to enforce table SELECT 
permissio ...)
+       TODO: check
+CVE-2026-63745 (SurrealDB versions before 3.1.0 contain an authorization 
bypass vulner ...)
+       TODO: check
+CVE-2026-63744 (SurrealDB before 3.1.5 contains a server-side request forgery 
vulnerab ...)
+       TODO: check
+CVE-2026-63743 (SurrealDB before 3.1.0 contains a capability bypass 
vulnerability in H ...)
+       TODO: check
+CVE-2026-63742 (SurrealDB versions before 3.1.0 contain a field-level SELECT 
permissio ...)
+       TODO: check
+CVE-2026-63741 (SurrealDB versions before 3.1.0 fail to validate DEFINE 
NAMESPACE or D ...)
+       TODO: check
+CVE-2026-63740 (SurrealDB versions before 3.1.4 fail to properly enforce 
SELECT permis ...)
+       TODO: check
+CVE-2026-63739 (SurrealDB before 3.1.5 contains an arbitrary file read 
vulnerability i ...)
+       TODO: check
+CVE-2026-63738 (SurrealDB versions 3.1.0 before 3.1.5 fail to enforce 
field-level SELE ...)
+       TODO: check
+CVE-2026-63737 (SurrealDB versions before 3.1.5 contain a denial of service 
vulnerabil ...)
+       TODO: check
+CVE-2026-63736 (SurrealDB before 3.2.0 contains a server-side request forgery 
vulnerab ...)
+       TODO: check
+CVE-2026-63735 (SurrealDB versions before 3.2.0 fail to validate namespace and 
databas ...)
+       TODO: check
+CVE-2026-63734 (SurrealDB versions before 3.2.0 contain a denial of service 
vulnerabil ...)
+       TODO: check
+CVE-2026-63733 (SurrealDB versions before 3.2.0 contain a permissions bypass 
vulnerabi ...)
+       TODO: check
+CVE-2026-63429 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.9, ` ...)
+       TODO: check
+CVE-2026-63428 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.9, ` ...)
+       TODO: check
+CVE-2026-63108 (Roo Code through 3.54.0 contains a command injection 
vulnerability in  ...)
+       TODO: check
+CVE-2026-63107 (LimeSurvey through 6.17.10 and 7.0.4 contains a server-side 
request fo ...)
+       TODO: check
+CVE-2026-63102 (rConfig Core before 8.2.8 contains a privilege escalation 
vulnerabilit ...)
+       TODO: check
+CVE-2026-63071 (Improper Isolation or Compartmentalization vulnerability in 
Apache Syn ...)
+       TODO: check
+CVE-2026-62418 (Low-privileged authenticated Server-Side Request Forgery 
(SSRF)  vulne ...)
+       TODO: check
+CVE-2026-62183 (Improper Privilege Management vulnerability in Apache Syncope. 
 When:  ...)
+       TODO: check
+CVE-2026-60034 (The Joomla extension JMedia is vulnerable to a stored XSS 
vulnerabilit ...)
+       TODO: check
+CVE-2026-60033 (The Joomla extension JMedia is vulnerable to an SSRF 
vulnerability. Re ...)
+       TODO: check
+CVE-2026-60032 (The Joomla extension JMedia is vulnerable to an authenticated 
arbitrar ...)
+       TODO: check
+CVE-2026-60031 (The Joomla extension Quix Page Builder Pro is vulnerable to an 
informa ...)
+       TODO: check
+CVE-2026-60030 (The Joomla extension Quix Page Builder Pro is vulnerable to an 
imprope ...)
+       TODO: check
+CVE-2026-60029 (The Joomla extension Quix Page Builder Pro is vulnerable to an 
authent ...)
+       TODO: check
+CVE-2026-60028 (The Joomla extension Quix Page Builder Pro is vulnerable to an 
authent ...)
+       TODO: check
+CVE-2026-60027 (The Joomla extension Quix Page Builder Pro is vulnerable to a 
unauthen ...)
+       TODO: check
+CVE-2026-60026 (The Joomla extension Quix Page Builder Pro is vulnerable to an 
authent ...)
+       TODO: check
+CVE-2026-59238 (Stored Cross-site Scripting (CWE-79) in the client-side report 
renderi ...)
+       TODO: check
+CVE-2026-58484 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
+       TODO: check
+CVE-2026-58482 (Network-AI, a TypeScript/Node.js multi-agent orchestrator, has 
a shipp ...)
+       TODO: check
+CVE-2026-58481 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
+       TODO: check
+CVE-2026-58414 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
+       TODO: check
+CVE-2026-58413 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
+       TODO: check
+CVE-2026-57311 (Windu CMS does not validate types of uploaded files. An 
authenticated  ...)
+       TODO: check
+CVE-2026-57310 (Windu CMS uses hashing algorithm based on MD5 and SHA1 with 
static sal ...)
+       TODO: check
+CVE-2026-57309 (A Blind SQL injection vulnerability has been identified in 
Windu CMS.  ...)
+       TODO: check
+CVE-2026-57308 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
+       TODO: check
+CVE-2026-54910 (FileBrowser Quantum is a free, self-hosted, web-based file 
manager. Pr ...)
+       TODO: check
+CVE-2026-54685 (FileBrowser Quantum is a free, self-hosted, web-based file 
manager. Pr ...)
+       TODO: check
+CVE-2026-54051 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
+       TODO: check
+CVE-2026-53421 (Improper Isolation or Compartmentalization vulnerability in 
Apache Syn ...)
+       TODO: check
+CVE-2026-53405 (Improper Isolation or Compartmentalization vulnerability in 
Apache Syn ...)
+       TODO: check
+CVE-2026-52349 (Directory Traversal vulnerability in Menyoo 2.0 Versions 
before commit ...)
+       TODO: check
+CVE-2026-51386
+       REJECTED
+CVE-2026-51027 (An issue in FileThingie v.2.5.7 allows a remote attacker to 
obtain sen ...)
+       TODO: check
+CVE-2026-51026 (Directory Traversal vulnerability in FileThingie v.2.5.7 
allows a remo ...)
+       TODO: check
+CVE-2026-50743 (A CSRF vulnerability exists in the `zone-include.php` script 
in Revive ...)
+       TODO: check
+CVE-2026-48824 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
+       TODO: check
+CVE-2026-48812 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-48389 (DNG SDK versions 1.7.1 2536 and earlier are affected by a 
Stack-based  ...)
+       TODO: check
+CVE-2026-47276 (In nanomq versions 0.24.11 and earlier, a NULL pointer 
dereference in  ...)
+       TODO: check
+CVE-2026-47275 (In nanomq versions 0.24.11 and earlier, a NULL pointer 
dereference in  ...)
+       TODO: check
+CVE-2026-46715 (Flask-Security-Too allows users to add security features to 
their Flas ...)
+       TODO: check
+CVE-2026-46701 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
+       TODO: check
+CVE-2026-46671 (Rust OneNote File Parser is a parser for Microsoft OneNote 
files imple ...)
+       TODO: check
+CVE-2026-46555 (WhatsApp MCP Server is a Model Context Protocol (MCP) server 
for Whats ...)
+       TODO: check
+CVE-2026-46516 (Frogman provides headless FreePBX control. Prior to version 
1.6.6, Fro ...)
+       TODO: check
+CVE-2026-46428 (lettre is a a mailer library for Rust. Starting in version 
0.10.1 and  ...)
+       TODO: check
+CVE-2026-46415 (The Caddy Defender plugin is a middleware for Caddy that 
allows users  ...)
+       TODO: check
+CVE-2026-46412 (@beproduct/nestjs-auth is a NestJS authentication module for 
BeProduct ...)
+       TODO: check
+CVE-2026-46410 (FileBrowser Quantum is a free, self-hosted, web-based file 
manager. Ve ...)
+       TODO: check
+CVE-2026-45797 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.7, t ...)
+       TODO: check
+CVE-2026-45713 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
+       TODO: check
+CVE-2026-45712 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
+       TODO: check
+CVE-2026-45711 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
+       TODO: check
+CVE-2026-45709 (Mailpit is an email testing tool and API for developers. The 
fix for G ...)
+       TODO: check
+CVE-2026-45295 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-45270 (CI4MS is a CodeIgniter 4-based content management system 
skeleton. Pri ...)
+       TODO: check
+CVE-2026-45139 (CI4MS is a CodeIgniter 4-based content management system 
skeleton. Pri ...)
+       TODO: check
+CVE-2026-44228 (RT is an open source, enterprise-grade issue and ticket 
tracking syste ...)
+       TODO: check
+CVE-2026-42210 (Webmin is a web-based system administration tool for Unix-like 
servers ...)
+       TODO: check
+CVE-2026-40187 (In egroupware version 26.0 and earlier, an authenticated 
administrator ...)
+       TODO: check
+CVE-2026-39879 (Due to a missing sanitization call in 
[`afsql_dd_run_query`](https://g ...)
+       TODO: check
+CVE-2026-39878 (Chamilo LMS versions 1.11.38 and earlier contain a stored 
cross-site s ...)
+       TODO: check
+CVE-2026-39385 (Frappe LMS is an open source learning management system. In 
version 2. ...)
+       TODO: check
+CVE-2026-35591 (libvips is a fast image processing library with low memory 
needs. The  ...)
+       TODO: check
+CVE-2026-35590 (libvips is a fast image processing library with low memory 
needs. The  ...)
+       TODO: check
+CVE-2026-35217 (NanoMQ contains a protocol-semantics flaw in its MQTT v5 
`SUBSCRIBE` h ...)
+       TODO: check
+CVE-2026-35198 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.7, a ...)
+       TODO: check
+CVE-2026-35048 (The Piwigo installer in versions 16.3.0 and earlier accepts 
POST param ...)
+       TODO: check
+CVE-2026-34239 (Chamilo version 1.11.40 and earlier are vulnerable to 
authenticated re ...)
+       TODO: check
+CVE-2026-33328 (libvips is a fast image processing library with low memory 
needs. On 3 ...)
+       TODO: check
+CVE-2026-33327 (libvips is a fast image processing library with low memory 
needs. The  ...)
+       TODO: check
+CVE-2026-32825 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32824 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32823 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32822 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32821 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32820 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32819 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32807 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-32806 (dataCycle is a data management system for centrally storing, 
managing, ...)
+       TODO: check
+CVE-2026-2445 (The affected product accepts user-supplied input within a URL 
paramete ...)
+       TODO: check
+CVE-2026-28220 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-27823 (A vulnerability has been identified in EGroupware that may 
lead to Rem ...)
+       TODO: check
+CVE-2026-26483 (Mettle SendPortal 3.0.1 and earlier contains a stored 
cross-site scrip ...)
+       TODO: check
+CVE-2026-26199 (HDF5 is a high-performance library and a file format 
specification tha ...)
+       TODO: check
+CVE-2026-26197 (HDF5 is a high-performance library and a file format 
specification tha ...)
+       TODO: check
+CVE-2026-25039 (Parsec is a cloud-based application for simple and 
cryptographically s ...)
+       TODO: check
+CVE-2026-21824 (HCL Commerce contains an privilege escalation vulnerability 
that could ...)
+       TODO: check
+CVE-2026-16312
+       REJECTED
+CVE-2026-16277 (A stack-based buffer overflow was found in rpcbind's rpcinfo 
utility.  ...)
+       TODO: check
+CVE-2026-16254 (A flaw was found in claircore's apk package scanner. Malformed 
package ...)
+       TODO: check
+CVE-2026-16252 (A security flaw has been discovered in Beijing Shenzhou Shihan 
Technol ...)
+       TODO: check
+CVE-2026-16248 (A vulnerability was found in Tenda AC10 
16.03.10.09_multi_TDE01. This  ...)
+       TODO: check
+CVE-2026-16247 (In _connect.BRAIN versions prior to 5.06, the application 
LogPathConfi ...)
+       TODO: check
+CVE-2026-16246 (In BRAIN2 versions prior to 3.09, the application 
LogPathConfig.exe is ...)
+       TODO: check
+CVE-2026-16244 (A security vulnerability has been detected in itsourcecode 
Hospital Ma ...)
+       TODO: check
+CVE-2026-16242 (A flaw was found in the Konnectivity proxy-server 
configuration for ho ...)
+       TODO: check
+CVE-2026-15813 (A vulnerability was found in the network packet 
de-fragmentation engin ...)
+       TODO: check
+CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability 
exists withi ...)
+       TODO: check
+CVE-2026-14448 (An high privileged remote attacker can exploit an 
authenticated OS com ...)
+       TODO: check
+CVE-2026-13724 (Client-Side Enforcement of Server-Side Security vulnerability 
in Gobit ...)
+       TODO: check
+CVE-2026-12701 (A path traversal vulnerability was found in pulpcore. The 
relative_pat ...)
+       TODO: check
+CVE-2026-12341 (This vulnerability impacts all versions of IdentityIQ and 
allows an un ...)
+       TODO: check
+CVE-2026-12080 (A flaw was found in the QEMU Guest Agent (qga). A local 
unprivileged u ...)
+       TODO: check
+CVE-2026-64207 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.1.4-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/05ed733b65ab977dd931e7f7ac0f62fdb81205c2 (7.2-rc1)
-CVE-2026-64206 [Bluetooth: L2CAP: cancel pending_rx_work before taking 
conn->lock]
+CVE-2026-64206 (In the Linux kernel, the following vulnerability has been 
resolved:  B ...)
        - linux 7.1.4-1
        NOTE: 
https://git.kernel.org/linus/2641a9e0a1dd4af2e21995470a21d55dd35e5203 (7.2-rc3)
-CVE-2026-64205 [i2c: i801: fix hardware state machine corruption in error path]
+CVE-2026-64205 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 7.1.4-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/10dd1a736d557e310a77117832874729a0175d57 (7.2-rc1)
-CVE-2026-64192 [bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is 
uninitialized]
+CVE-2026-64192 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
        - linux 7.1.4-1
        NOTE: 
https://git.kernel.org/linus/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4 (7.2-rc2)
-CVE-2026-64191 [i2c: stub: Reject I2C block transfers with invalid length]
+CVE-2026-64191 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 7.0.14-1
        [trixie] - linux 6.12.95-1
        [bookworm] - linux 6.1.177-1
        NOTE: 
https://git.kernel.org/linus/6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e (7.1-rc3)
-CVE-2026-64190 [net: team: fix NULL pointer dereference in team_xmit during 
mode change]
+CVE-2026-64190 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.1.3-1
        NOTE: 
https://git.kernel.org/linus/25fe708bbc59289d3d1ea4b126fbc1b460a072a5 (7.1-rc6)
-CVE-2026-64189 [netfilter: ipset: fix race between dump and ip_set_list resize]
+CVE-2026-64189 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.1.4-1
        NOTE: 
https://git.kernel.org/linus/7cd9103283b26b917360ec99d7d2f2d761bcf1ab (7.2-rc2)
-CVE-2026-64188 [net: qualcomm: rmnet: fix endpoint use-after-free in 
rmnet_dellink()]
+CVE-2026-64188 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.0.14-1
        [trixie] - linux 6.12.95-1
        [bookworm] - linux 6.1.177-1
        NOTE: 
https://git.kernel.org/linus/d00c953a8f69921f484b629801766da68f27f658 (7.1-rc5)
-CVE-2026-64187 [xfs: fail recovery on a committed log item with no regions]
+CVE-2026-64187 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
        - linux 7.1.4-1
        NOTE: 
https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
-CVE-2026-13577
+CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure 
session ids  ...)
        - libdancer2-perl <unfixed>
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41975698/
 CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy 
Terms Word ...)
@@ -6860,11 +7154,11 @@ CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 
2.1.3 for Perl allow denial
        - libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792358/
        NOTE: Fixed by: 
https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2
 (2.1.3)
-CVE-2026-63090 [Authenticated SFTP sessions can overflow the SFTP packet 
buffer]
+CVE-2026-63090 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based 
buffer overf ...)
        - proftpd-dfsg 1.3.9c~dfsg-1
        NOTE: https://github.com/proftpd/proftpd/issues/2190
        NOTE: Fixed by: 
https://github.com/proftpd/proftpd/commit/ce13286900a7e25f1e3403620496868d73292f6b
 (v1.3.9c)
-CVE-2026-63091 [SCP signed-size integer overflow; heap over-read]
+CVE-2026-63091 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer 
overflow ...)
        - proftpd-dfsg 1.3.9c~dfsg-1
        NOTE: https://github.com/proftpd/proftpd/pull/2201
        NOTE: Fixed by: 
https://github.com/proftpd/proftpd/commit/baf4b7929758c72cdb6cf16325fa25f435d23db6
 (v1.3.9c)
@@ -10545,45 +10839,45 @@ CVE-2026-42505 (Handshakes which used Encrypted 
Client Hello could be de-anonymi
        NOTE: https://github.com/golang/go/issues/79282
        NOTE: Fixed by: 
https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 
(go1.26.5)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/fc9f821bb660c1dcb9e57868b62f62bf3afb5842 
(go1.25.12)
-CVE-2026-41252
+CVE-2026-41252 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j
-CVE-2026-41521
+CVE-2026-41521 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-v8w6-pf78-9458
-CVE-2026-44178
+CVE-2026-44178 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hh7r-2rmq-q4g4
-CVE-2026-42218
+CVE-2026-42218 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3wr5-fwmh-qh34
-CVE-2026-44978
+CVE-2026-44978 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9cg5-f7m7-ppvj
-CVE-2026-54538
+CVE-2026-54538 (xrdp is an open source RDP server. In versions 0.10.6 and 
prior, a n i ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9j3q-9mvw-qv7j
-CVE-2026-55238
+CVE-2026-55238 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-mg8j-x9rw-9xv3
-CVE-2026-55626
+CVE-2026-55626 (xrdp is an open source RDP server. In versions 0.10.6 and 
prior, when  ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        [trixie] - xrdp <not-affected> (Vulnerable code introduced later)
        [bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r
-CVE-2026-55639
+CVE-2026-55639 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-6g36-mxcf-r3gc
-CVE-2026-55645
+CVE-2026-55645 (xrdp is an open source RDP server. Versions 0.10.6 and prior 
contain a ...)
        [experimental] - xrdp 0.10.6.1-1
        - xrdp 0.10.6.1-2
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3m4m-h22g-c7xx
@@ -16595,7 +16889,7 @@ CVE-2026-57958 (Mixpost through 2.6.0 contains a 
reflected cross-site scripting
        NOT-FOR-US: Mixpost
 CVE-2026-57957 (Papermark through 0.22.0 contains a cross-origin resource 
sharing (COR ...)
        NOT-FOR-US: Papermark
-CVE-2026-57956 (SigNoz through 0.130.1 contains a broken access control 
vulnerability  ...)
+CVE-2026-57956 (SigNoz before 0.133.0 contains a broken access control 
vulnerability t ...)
        NOT-FOR-US: SigNoz
 CVE-2026-57955 (SigNoz through 0.130.1 contains a SQL injection vulnerability 
that all ...)
        NOT-FOR-US: SigNoz
@@ -27358,7 +27652,7 @@ CVE-2026-23970 (Unauthenticated Cross Site Scripting 
(XSS) in Redirection for Co
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-12162 (Improper host validation in the social login autofill feature 
in  Devo ...)
        NOT-FOR-US: Devolutions
-CVE-2026-12161 (Improper input validation in the SSH Elevate Shell feature in  
Devolut ...)
+CVE-2026-12161 (Improper input validation in the SSH Elevate Shell feature 
allows an a ...)
        NOT-FOR-US: Devolutions
 CVE-2026-11931 (Incorrect default permissions in Kiro IDE on macOS and Linux 
before ve ...)
        NOT-FOR-US: Amazon
@@ -45508,7 +45802,7 @@ CVE-2026-44230
        NOTE: https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
        NOTE: Introduced with: 
https://github.com/bestpractical/rt/commit/1db06229c5839a158f2365c436d9aa325d6ea459
 (rt-5.0.4beta1)
        NOTE: Fixed by: 
https://github.com/bestpractical/rt/commit/510d8d6c6a260da22830039e362c990a6c029665
 (rt-5.0.10)
-CVE-2026-44227
+CVE-2026-44227 (RT is an open source, enterprise-grade issue and ticket 
tracking syste ...)
        - request-tracker5 <not-affected> (Only affects RT6)
        - request-tracker4 <not-affected> (Only affects RT6)
        NOTE: https://github.com/bestpractical/rt/releases/tag/rt-6.0.3
@@ -98899,14 +99193,14 @@ CVE-2026-2003 (Improper validation of type 
"oidvector" in PostgreSQL allows a da
        - postgresql-13 <removed>
        NOTE: 
https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/
        NOTE: Fixed by: 
https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=3b6588cd902faa967f61f539f057f9b7643cf6a5
 (REL_18_2)
-CVE-2026-26081 [BUG/MAJOR: quic: reject invalid token]
+CVE-2026-26081 (HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a 
length  ...)
        {DSA-6130-1}
        - haproxy 3.2.11-2
        [bookworm] - haproxy <not-affected> (Vulnerable code introduced later)
        [bullseye] - haproxy <not-affected> (Vulnerable code introduced later)
        NOTE: Fixed by: 
https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=a05eade0f07483e6b6d0b61b1749e9093647e802
 (v3.0.16)
        NOTE: Fixed by: 
https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=4765277f4f915baac2d57db63538ff0a59966deb
 (v3.2.12)
-CVE-2026-26080 [BUG/MAJOR: quic: fix parsing frame type]
+CVE-2026-26080 (HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can 
enter a ...)
        - haproxy 3.2.11-2
        [trixie] - haproxy <not-affected> (Vulnerable code introduced later)
        [bookworm] - haproxy <not-affected> (Vulnerable code introduced later)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b28f1ec9095c3821bed06e932afa003e22f6719

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b28f1ec9095c3821bed06e932afa003e22f6719
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to