Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
237c5de5 by Utkarsh Gupta at 2026-07-22T03:22:23+05:30
lts: aardvark-dns not-affected in bookworm

(CVE-2026-35406, TCP serving absent in 1.4.0)

- - - - -
2601f637 by Utkarsh Gupta at 2026-07-22T03:22:24+05:30
lts: busybox postponed in bookworm

(ash/awk memory-safety, CVE-2026-38752 to CVE-2026-38755)

- - - - -
7ddb1f8b by Utkarsh Gupta at 2026-07-22T03:22:25+05:30
lts: c3p0 postponed in bookworm (CVE-2026-27830)

- - - - -
800dc08b by Utkarsh Gupta at 2026-07-22T03:22:26+05:30
dla-needed: extend calibre to bookworm (CVE-2026-53511)

- - - - -
83b14a14 by Utkarsh Gupta at 2026-07-22T03:22:27+05:30
lts: capnproto postponed in bookworm

(CVE-2026-32239, CVE-2026-32240)

- - - - -
e645a6f8 by Utkarsh Gupta at 2026-07-22T03:22:28+05:30
lts: coturn postponed in bookworm

(CVE-2026-27624/40613/43915/43994)

- - - - -
1f8bf381 by Utkarsh Gupta at 2026-07-22T03:22:30+05:30
lts: geary postponed in bookworm/bullseye (CVE-2026-13324)

- - - - -
810bd2b0 by Utkarsh Gupta at 2026-07-22T03:22:31+05:30
lts: triage glances in bookworm

(CVE-2026-46606/46607/46608/46611/53925)

- - - - -
4b7ae7d2 by Utkarsh Gupta at 2026-07-22T03:22:33+05:30
lts: guzzle postponed in bookworm (CVE-2026-55568/55767/59883)

- - - - -
0b745686 by Utkarsh Gupta at 2026-07-22T03:22:34+05:30
lts: hdrhistogram postponed in bookworm/bullseye

(CVE-2026-14683 to CVE-2026-14686)

- - - - -
56e22bc1 by Utkarsh Gupta at 2026-07-22T03:22:36+05:30
lts: httpcomponents-core5 postponed in bookworm

(CVE-2026-54399, CVE-2026-54428)

- - - - -
bee598be by Utkarsh Gupta at 2026-07-22T03:22:37+05:30
lts: triage hugo in bookworm/bullseye

(CVE-2026-50133 to CVE-2026-58404)

- - - - -
dde4df23 by Utkarsh Gupta at 2026-07-22T03:22:39+05:30
lts: inspircd postponed in bookworm/bullseye

- - - - -
e3b93549 by Utkarsh Gupta at 2026-07-22T03:22:40+05:30
lts: jansi1 not-affected in bookworm (CVE-2026-8484, no native code)

- - - - -
996b1ede by Utkarsh Gupta at 2026-07-22T03:22:42+05:30
lts: jupyter-server postponed in bookworm/bullseye

- - - - -
4ed36ba8 by Utkarsh Gupta at 2026-07-22T03:22:43+05:30
dla-needed: extend busybox to bookworm; drop postponed tags

busybox is sponsored across all suites and already queued for bullseye
(dla-needed) and buster+stretch (ela-needed). CVE-2026-38752..38755 are
in shared ash/awk code, so fix bookworm alongside the others rather than
postponing the newest LTS release. Per-CVE bookworm postponed tags are
redundant once bookworm is queued, so drop them.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -10883,6 +10883,7 @@ CVE-2026-59887 (linkify-it is a links recognition 
library with full Unicode supp
 CVE-2026-59883 (Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, 
CookieJar di ...)
        - guzzle 7.12.3-1
        [trixie] - guzzle <no-dsa> (Minor issue)
+       [bookworm] - guzzle <postponed> (Minor issue; SetCookie::matchesDomain 
IP-domain suffix match)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-g446-98w2-8p5w
        NOTE: https://github.com/guzzle/guzzle/pull/3694
        NOTE: Fixed by: 
https://github.com/guzzle/guzzle/commit/b9944c161b12d9ee9c9334cfc5b9659ecd7451f8
 (7.12.3)
@@ -11859,6 +11860,8 @@ CVE-2026-48588 (An issue was discovered in Django 6.0 
before 6.0.7 and 5.2 befor
 CVE-2026-XXXX [InspIRCd Security Advisory 2026-01]
        - inspircd <unfixed> (bug #1141625)
        [trixie] - inspircd <no-dsa> (Minor issue)
+       [bookworm] - inspircd <postponed> (Minor issue; only exploitable with 
non-default ldapauth/ldapoper module loaded and LDAP configured)
+       [bullseye] - inspircd <postponed> (Minor issue; only exploitable with 
non-default ldapauth/ldapoper module loaded and LDAP configured)
        NOTE: https://docs.inspircd.org/security/2026-01/
        NOTE: 
https://github.com/inspircd/inspircd/commit/b7e5357b144c2e20c72431e22f0f2b13e5be82ce
 (v4.11.0)
        NOTE: 
https://github.com/inspircd/inspircd/commit/6319ae4fb8c10dabc9464ad49faec532096fbcb5
 (v4.11.0)
@@ -11887,18 +11890,24 @@ CVE-2026-59710 (showdown contains a stored cross-site 
scripting vulnerability in
 CVE-2026-58404 (Hugo is a static site generator. From v0.162.0 through 
v0.163.0, the d ...)
        - hugo <unfixed> (bug #1141772)
        [trixie] - hugo <no-dsa> (Minor issue)
+       [bookworm] - hugo <not-affected> (Alt-IPv4-encoding bypass of 
security.http.urls added in v0.162.0)
+       [bullseye] - hugo <not-affected> (Alt-IPv4-encoding bypass of 
security.http.urls added in v0.162.0)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-r46f-3rpw-hxrv
        NOTE: https://github.com/gohugoio/hugo/pull/15020
        NOTE: Fixed by: 
https://github.com/gohugoio/hugo/commit/a00b5c72ac57afe26df6688ece3ca544a56df372
 (v0.163.1)
 CVE-2026-58403 (Hugo is a static site generator. From v0.123.0 through 
v0.163.0, Hugo' ...)
        - hugo <unfixed> (bug #1141772)
        [trixie] - hugo <no-dsa> (Minor issue)
+       [bookworm] - hugo <not-affected> (RootMappingFs.statRoot symlink 
regression introduced in v0.123.0)
+       [bullseye] - hugo <not-affected> (RootMappingFs.statRoot symlink 
regression introduced in v0.123.0)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-c3wq-j5vh-68rc
        NOTE: https://github.com/gohugoio/hugo/pull/15020
        NOTE: Fixed by: 
https://github.com/gohugoio/hugo/commit/cf9c8f93ca2a2838ce378f9e36d052ac2f79e229
 (v0.163.1)
 CVE-2026-58402 (Hugo is a static site generator. From 0.60.0 until 0.163.3, 
Hugo's def ...)
        - hugo <unfixed> (bug #1141772)
        [trixie] - hugo <no-dsa> (Minor issue)
+       [bookworm] - hugo <postponed> (Minor issue; code-fence info-string XSS, 
only exploitable without control of content; mirrors trixie)
+       [bullseye] - hugo <postponed> (Minor issue; code-fence info-string XSS, 
only exploitable without control of content; mirrors trixie)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-q76j-gcg9-vxc6
        NOTE: https://github.com/gohugoio/hugo/pull/15051
        NOTE: Fixed by: 
https://github.com/gohugoio/hugo/commit/ce1a7e0bce3713af40496ded3c2c0ceeed49231d
 (v0.163.3)
@@ -11965,16 +11974,22 @@ CVE-2026-53640 (FOSSBilling is a free, open-source 
billing and client management
 CVE-2026-50135 (Hugo is a static site generator. From 0.123.0 to 0.161.1, a 
regression ...)
        - hugo 0.162.1-1
        [trixie] - hugo <no-dsa> (Minor issue)
+       [bookworm] - hugo <not-affected> (resources.Get symlink-following 
regression in RootMappingFs.statRoot introduced in v0.123.0)
+       [bullseye] - hugo <not-affected> (resources.Get symlink-following 
regression in RootMappingFs.statRoot introduced in v0.123.0)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpw
        NOTE: Fixed by: 
https://github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7a
 (v0.162.0)
 CVE-2026-50134 (Hugo is a static site generator. From 0.91.0 until 0.162.0, 
resources. ...)
        - hugo 0.162.1-1
        [trixie] - hugo <no-dsa> (Minor issue)
+       [bookworm] - hugo <postponed> (Minor issue; redirect targets not 
re-validated against security.http.urls; mirrors trixie)
+       [bullseye] - hugo <not-affected> (security.http.urls policy introduced 
in v0.91.0; config/security package absent in 0.80.0)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8g
        NOTE: Fixed by: 
https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50
 (v0.162.0)
 CVE-2026-50133 (Hugo is a static site generator. Prior to 0.162.0, Hugo 
accepts conten ...)
        - hugo 0.162.1-1
        [trixie] - hugo <no-dsa> (Minor issue)
+       [bookworm] - hugo <postponed> (Minor issue; unsanitized text/html 
content files, fixed by security.allowContent default-deny in v0.162.0; mirrors 
trixie)
+       [bullseye] - hugo <postponed> (Minor issue; unsanitized text/html 
content files, fixed by security.allowContent default-deny in v0.162.0; mirrors 
trixie)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-c54g-xjwj-8g82
        NOTE: Fixed by: 
https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1
 (v0.162.0)
 CVE-2026-4375 (The DoLeads Integrator WordPress plugin through 0.65, wp2epub 
WordPres ...)
@@ -12759,18 +12774,26 @@ CVE-2026-14687 (A vulnerability was determined in 
666ghj BettaFish up to 1.2.1.
 CVE-2026-14686 (A vulnerability was found in HdrHistogram up to 2.2.2. This 
issue affe ...)
        - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
+       [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
+       [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/222
 CVE-2026-14685 (A vulnerability has been found in HdrHistogram up to 2.2.2. 
This vulne ...)
        - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
+       [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
+       [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/221
 CVE-2026-14684 (A flaw has been found in HdrHistogram up to 2.2.2. This 
affects the fu ...)
        - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
+       [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
+       [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/220
 CVE-2026-14683 (A vulnerability was detected in HdrHistogram up to 2.2.2. 
Affected by  ...)
        - hdrhistogram <unfixed> (bug #1142286)
        [trixie] - hdrhistogram <postponed> (Minor issue, revisit when fixed 
upstream)
+       [bookworm] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
+       [bullseye] - hdrhistogram <postponed> (Minor issue, untrusted-input 
DoS/integrity; unfixed upstream, revisit when fixed)
        NOTE: https://github.com/HdrHistogram/HdrHistogram/issues/219
 CVE-2026-14660 (A vulnerability was found in code-projects Online Job Portal 
1.0. The  ...)
        NOT-FOR-US: code-projects
@@ -14507,6 +14530,7 @@ CVE-2026-55510 (ImageMagick is free and open-source 
software used for editing an
 CVE-2026-54428 (Allocation of resources without limits or throttling in the 
HTTP/2 HPA ...)
        - httpcomponents-core5 <unfixed> (bug #1141387)
        [trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
+       [bookworm] - httpcomponents-core5 <postponed> (Minor issue; HTTP/2 
HPACK decoder present in 5.x, unlike 4.x)
        - httpcomponents-core <unfixed>
        [trixie] - httpcomponents-core <no-dsa> (Minor issue)
        [bookworm] - httpcomponents-core <not-affected> (HTTP/2 HPACK not 
implemented in httpcomponents-core 4.x (v5-only feature))
@@ -14516,6 +14540,7 @@ CVE-2026-54428 (Allocation of resources without limits 
or throttling in the HTTP
 CVE-2026-54399 (Uncontrolled Resource Consumption vulnerability in the 
HTTP/1.1 messag ...)
        - httpcomponents-core5 <unfixed> (bug #1141387)
        [trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
+       [bookworm] - httpcomponents-core5 <postponed> (Minor issue)
        - httpcomponents-core <unfixed>
        [trixie] - httpcomponents-core <no-dsa> (Minor issue)
        [bookworm] - httpcomponents-core <postponed> (Minor issue)
@@ -19360,6 +19385,8 @@ CVE-2026-11625 (Bytes::Random::Secure versions through 
0.29 for Perl share inter
 CVE-2026-13324
        - geary <unfixed>
        [trixie] - geary <no-dsa> (Minor issue)
+       [bookworm] - geary <postponed> (Minor issue; mailto ?attach= silently 
attaches local files, follow trixie)
+       [bullseye] - geary <postponed> (Minor issue; mailto ?attach= silently 
attaches local files, follow trixie)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2492860
 CVE-2026-9222 (Setracker2 Android Companion App com.tgelec.setracker versions 
3.1.5 a ...)
        NOT-FOR-US: Setracker2 Android Companion App com.tgelec.setracker
@@ -20083,6 +20110,7 @@ CVE-2026-54024 (LibreChat is an enhanced ChatGPT clone 
that supports multiple AI
 CVE-2026-53925 (Glances is an open-source system cross-platform monitoring 
tool. From  ...)
        - glances 4.5.5+dfsg-1
        [trixie] - glances <no-dsa> (Minor issue)
+       [bookworm] - glances <postponed> (Minor issue; secure_popen operator 
interpretation present in secure.py, reachable via actions.py; requires config 
write access)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-3vwc-qwhc-3mj7
 CVE-2026-50573 (pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm 
install` ...)
        - pnpm <itp> (bug #985669)
@@ -20157,18 +20185,22 @@ CVE-2026-46732 (Dell Display and Peripheral Manager 
(DDPM Mac), versions prior t
 CVE-2026-46611 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        - glances 4.5.5+dfsg-1
        [trixie] - glances <no-dsa> (Minor issue)
+       [bookworm] - glances <postponed> (Minor issue; XML-RPC 
GlancesXMLRPCHandler lacks Host-header validation, DNS-rebinding 
defense-in-depth)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-w856-8p3r-p338
 CVE-2026-46608 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        - glances 4.5.5+dfsg-1
        [trixie] - glances <no-dsa> (Minor issue)
+       [bookworm] - glances <not-affected> (XML-RPC cors_origins allowlist 
mechanism introduced in 4.5.3; absent in 3.3.1.1)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-87qc-fj39-wccr
 CVE-2026-46607 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        - glances 4.5.5+dfsg-1
        [trixie] - glances <no-dsa> (Minor issue)
+       [bookworm] - glances <postponed> (Minor issue; outdated.py _load_cache 
pickle.load of cached glances-version.db present; requires local cache write)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-9837-48hr-q32j
 CVE-2026-46606 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        - glances 4.5.5+dfsg-1
        [trixie] - glances <no-dsa> (Minor issue)
+       [bookworm] - glances <not-affected> (KVM/virsh vms monitoring plugin is 
a 4.x feature; no vms/virsh plugin in 3.3.1.1)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-v5r2-qh84-fjx5
 CVE-2026-45233 (HTMLy CMS through 3.1.1 contains a path traversal 
vulnerability that a ...)
        NOT-FOR-US: HTMLy CMS
@@ -24041,6 +24073,8 @@ CVE-2026-44889 (WebOb provides objects for HTTP 
requests and responses. Prior to
 CVE-2026-44727 (Jupyter Server is the backend for Jupyter web applications. 
Prior to 2 ...)
        - jupyter-server 2.20.0-1
        [trixie] - jupyter-server <no-dsa> (Minor issue)
+       [bookworm] - jupyter-server <postponed> (Minor issue; stored XSS in 
nbconvert handlers, present, revisit with next update)
+       [bullseye] - jupyter-server <postponed> (Minor issue; stored XSS in 
nbconvert handlers, present, revisit with next update)
        NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp
        NOTE: Fixed by: 
https://github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bd
 (v2.20.0)
 CVE-2026-44311 (Fabric.js is a Javascript HTML5 canvas library. Prior to 
7.4.0, a pote ...)
@@ -25167,10 +25201,12 @@ CVE-2016-20085 (Realtek High Definition Audio Driver 
6.0.1.6730 contains an unqu
 CVE-2026-55568 (Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in 
certain c ...)
        - guzzle 7.12.1-1
        [trixie] - guzzle <no-dsa> (Minor issue)
+       [bookworm] - guzzle <postponed> (Minor issue; curl handler HTTPS-proxy 
downgrade, needs libcurl older than 7.50.2)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-wpwq-4j6v-78m3
 CVE-2026-55767 (Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, 
CookieJar in ...)
        - guzzle 7.12.1-1
        [trixie] - guzzle <no-dsa> (Minor issue)
+       [bookworm] - guzzle <postponed> (Minor issue; SetCookie dot-only Domain 
matches any host)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-cwxw-98qj-8qjx
 CVE-2026-52910 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
        {DSA-6355-1 DLA-4671-1 DLA-4665-1 DLA-4664-1}
@@ -25317,11 +25353,13 @@ CVE-2026-44663 (OpenEXR is the reference 
implementation and specification for th
 CVE-2026-43994 (Coturn is a free open source implementation of TURN and STUN 
Server. V ...)
        - coturn 4.12.0-1 (bug #1140563)
        [trixie] - coturn <no-dsa> (Minor issue)
+       [bookworm] - coturn <postponed> (Minor issue; decode_oauth_token_gcm() 
OAuth nonce stack overflow present in 4.6.1, only reachable with non-default 
--oauth)
        NOTE: 
https://github.com/coturn/coturn/security/advisories/GHSA-74pg-rfh2-5qw5
        NOTE: Fixed by: 
https://github.com/coturn/coturn/commit/46368b3e1ecda2175f8db8b05ece8bbdbf844cea
 (4.10.0)
 CVE-2026-43915 (Coturn is a free open source implementation of TURN and STUN 
Server. V ...)
        - coturn 4.12.0-1
        [trixie] - coturn <no-dsa> (Minor issue)
+       [bookworm] - coturn <postponed> (Minor issue; web-admin stored XSS, 
is_secure_string()/raw username rendering present in 4.6.1)
        NOTE: 
https://github.com/coturn/coturn/security/advisories/GHSA-xxf5-9vj2-g84j
 CVE-2026-40624 (Improper input validation in AVer PTC500S, PTC115, PTC500+, 
and PTC115 ...)
        NOT-FOR-US: AVer
@@ -27438,6 +27476,7 @@ CVE-2026-8484 (A heap buffer overflow vulnerability 
exists in the Jansi JNI "ioc
        [bullseye] - jansi <not-affected> (jansi 1.x ships no native code; the 
vulnerable JNI ioctl is in jansi-native)
        - jansi1 <unfixed>
        [trixie] - jansi1 <no-dsa> (Minor issue)
+       [bookworm] - jansi1 <not-affected> (jansi1 1.18 ships no native code; 
the vulnerable JNI ioctl is in jansi-native)
        - jansi-native <unfixed>
        [trixie] - jansi-native <no-dsa> (Minor issue)
        [bookworm] - jansi-native <postponed> (Minor issue)
@@ -36291,6 +36330,8 @@ CVE-2026-7888 (Concrete CMS below 9.5.2 is vulnerable 
to PHP Object Injection vi
 CVE-2026-6657 (A vulnerability in jupyter-server versions 1.12.0 through 
2.17.0 allow ...)
        - jupyter-server <unfixed>
        [trixie] - jupyter-server <no-dsa> (Minor issue)
+       [bookworm] - jupyter-server <postponed> (Minor issue; unanchored 
allow_origin_pat re.match present, revisit with next update)
+       [bullseye] - jupyter-server <postponed> (Minor issue; unanchored 
allow_origin_pat re.match present, revisit with next update)
        NOTE: https://huntr.com/bounties/18f642db-3569-43b3-b58d-ff97be4b09d7
 CVE-2026-5241 (A vulnerability in the LightGlue model loading path of 
huggingface/tra ...)
        NOT-FOR-US: huggingface/transformers
@@ -37068,6 +37109,8 @@ CVE-2026-7195 (CWE-20: Improper Input Validation in web 
services in Progress Sit
 CVE-2026-5422 (A path traversal vulnerability exists in jupyter-server version 
2.17.0 ...)
        - jupyter-server <unfixed>
        [trixie] - jupyter-server <no-dsa> (Minor issue)
+       [bookworm] - jupyter-server <postponed> (Minor issue; _get_os_path 
startswith(root) sibling-prefix traversal present, revisit with next update)
+       [bullseye] - jupyter-server <postponed> (Minor issue; _get_os_path 
startswith(root) sibling-prefix traversal present, revisit with next update)
        NOTE: https://huntr.com/bounties/24a36953-6490-466f-8cb2-a90d1ca56e0f
 CVE-2026-5191 (The Tiled Gallery Carousel Without JetPack plugin for WordPress 
is vul ...)
        NOT-FOR-US: WordPress plugin
@@ -57495,6 +57538,8 @@ CVE-2026-41950 (Dify before version 1.14.0 contains an 
authorization bypass vuln
 CVE-2026-40934 (Jupyter Server is the backend for Jupyter web applications. In 
version ...)
        - jupyter-server 2.20.0-1 (bug #1136022)
        [trixie] - jupyter-server <no-dsa> (Minor issue)
+       [bookworm] - jupyter-server <postponed> (Minor issue; 
cookie_secret_file persistence present, revisit with next update)
+       [bullseye] - jupyter-server <postponed> (Minor issue; 
cookie_secret_file persistence present, revisit with next update)
        NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f
 CVE-2026-40331 (Masa CMS is an open source content management system. In 
versions 7.2. ...)
        NOT-FOR-US: Masa CMS
@@ -57507,6 +57552,8 @@ CVE-2026-40280 (Gotenberg is an API-based document 
conversion tool. In versions
 CVE-2026-40110 (Jupyter Server is the backend for Jupyter web applications. In 
version ...)
        - jupyter-server 2.20.0-1 (bug #1136022)
        [trixie] - jupyter-server <no-dsa> (Minor issue)
+       [bookworm] - jupyter-server <postponed> (Minor issue; unanchored 
allow_origin_pat re.match present, revisit with next update)
+       [bullseye] - jupyter-server <postponed> (Minor issue; unanchored 
allow_origin_pat re.match present, revisit with next update)
        NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p
        NOTE: https://github.com/jupyter-server/jupyter_server/pull/603
        NOTE: 
https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea
 (v2.18.0)
@@ -57530,6 +57577,8 @@ CVE-2026-35453 (PhpSpreadsheet is a library for reading 
and writing spreadsheet
 CVE-2026-35397 (Jupyter Server is the backend for Jupyter web applications. In 
version ...)
        - jupyter-server 2.20.0-1 (bug #1136022)
        [trixie] - jupyter-server <no-dsa> (Minor issue)
+       [bookworm] - jupyter-server <postponed> (Minor issue; contents root_dir 
sibling-prefix traversal present, revisit with next update)
+       [bullseye] - jupyter-server <postponed> (Minor issue; contents root_dir 
sibling-prefix traversal present, revisit with next update)
        NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3
 CVE-2026-34596 (Sandboxie-Plus is an open source sandbox-based isolation 
software for  ...)
        NOT-FOR-US: Sandboxie-Plus
@@ -57798,6 +57847,8 @@ CVE-2025-66369 (An issue was discovered in MM in 
Samsung Mobile Processor, Weara
 CVE-2025-61669 (Jupyter Server is the backend for Jupyter web applications. In 
jupyter ...)
        - jupyter-server 2.20.0-1 (bug #1136022)
        [trixie] - jupyter-server <no-dsa> (Minor issue)
+       [bookworm] - jupyter-server <postponed> (Minor issue; _redirect_safe 
next-param open redirect present, revisit with next update)
+       [bullseye] - jupyter-server <postponed> (Minor issue; _redirect_safe 
next-param open redirect present, revisit with next update)
        NOTE: 
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-qh7q-6qm3-653w
 CVE-2025-52206 (ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) 
via the sy ...)
        NOT-FOR-US: ISPConfig
@@ -66015,6 +66066,7 @@ CVE-2026-40614 (PJSIP is a free and open source 
multimedia communication library
 CVE-2026-40613 (Coturn is a free open source implementation of TURN and STUN 
Server. P ...)
        - coturn 4.12.0-1 (bug #1134577)
        [trixie] - coturn <no-dsa> (Minor issue)
+       [bookworm] - coturn <postponed> (Minor issue; unaligned STUN attr 
pointer casts present in 4.6.1, ARM64-only DoS)
        NOTE: 
https://github.com/coturn/coturn/security/advisories/GHSA-j662-9wcj-mf36
        NOTE: Fixed by: 
https://github.com/coturn/coturn/commit/eaa9e7920e98cd10d24ade07f474ddb4e05dc1ea
 (4.10.0)
 CVE-2026-40611 (Let's Encrypt client and ACME library written in Go (Lego). 
Prior to 4 ...)
@@ -72765,6 +72817,7 @@ CVE-2026-35533 (mise manages dev tools like node, 
python, cmake, and terraform.
 CVE-2026-35406 (Aardvark-dns is an authoritative dns server for A/AAAA 
container recor ...)
        - aardvark-dns 1.16.0-3
        [trixie] - aardvark-dns <no-dsa> (Minor issue)
+       [bookworm] - aardvark-dns <not-affected> (TCP DNS serving not 
implemented in 1.4.0; register_port() is UDP-only, the vulnerable TCP loop in 
src/dns/coredns.rs was added upstream later; advisory affects 1.16.0 and later)
        NOTE: 
https://github.com/containers/aardvark-dns/security/advisories/GHSA-hfpq-x728-986j
        NOTE: Fixed by: 
https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1
 (main)
        NOTE: Fixed by: 
https://github.com/containers/aardvark-dns/commit/b66c50e88ead4416ae3cd86044e5905cb33f2d4b
 (v1.17.1)
@@ -87171,6 +87224,7 @@ CVE-2026-32240 (Cap'n Proto is a data interchange 
format and capability-based RP
        [experimental] - capnproto 1.4.0-1
        - capnproto 1.4.0-2 (bug #1130877)
        [trixie] - capnproto <no-dsa> (Minor issue)
+       [bookworm] - capnproto <postponed> (minor issue)
        [bullseye] - capnproto <postponed> (minor issue)
        NOTE: 
https://github.com/capnproto/capnproto/security/advisories/GHSA-vpcq-mx5v-32wm
        NOTE: Fixed by: 
https://github.com/capnproto/capnproto/commit/2744b3c012b4aa3c31cefb61ec656829fa5c0e36
 (v1.4.0)
@@ -87178,6 +87232,7 @@ CVE-2026-32239 (Cap'n Proto is a data interchange 
format and capability-based RP
        [experimental] - capnproto 1.4.0-1
        - capnproto 1.4.0-2 (bug #1130877)
        [trixie] - capnproto <no-dsa> (Minor issue)
+       [bookworm] - capnproto <postponed> (minor issue)
        [bullseye] - capnproto <postponed> (minor issue)
        NOTE: 
https://github.com/capnproto/capnproto/security/advisories/GHSA-qjx3-pp3m-9jpm
        NOTE: Fixed by: 
https://github.com/capnproto/capnproto/commit/2744b3c012b4aa3c31cefb61ec656829fa5c0e36
 (v1.4.0)
@@ -93799,6 +93854,7 @@ CVE-2026-27831 (rldns is an open source DNS server. 
Version 1.3 has a heap-based
 CVE-2026-27830 (c3p0, a JDBC Connection pooling library, is vulnerable to 
attack via m ...)
        - c3p0 <unfixed> (bug #1129318)
        [trixie] - c3p0 <no-dsa> (Minor issue)
+       [bookworm] - c3p0 <postponed> (Minor issue; userOverridesAsString 
deserialization reachable only via attacker-controlled bean property or JNDI 
Reference; fix needs 0.12.0 rewrite)
        NOTE: 
https://github.com/swaldman/c3p0/security/advisories/GHSA-5476-xc4j-rqcv
        NOTE: Fixed by: 
https://github.com/swaldman/c3p0/commit/e14cbd8166e423e2e9a9d6f08b2add3433492d6e
 (v0.12.0)
 CVE-2026-27829 (Astro is a web framework. In versions 9.0.0 through 9.5.3, a 
bug in As ...)
@@ -94486,6 +94542,7 @@ CVE-2025-0976 (Information Exposure Vulnerability 
inHitachi Ops Center API Confi
 CVE-2026-27624 (Coturn is a free open source implementation of TURN and STUN 
Server. C ...)
        - coturn 4.12.0-1 (bug #1129267)
        [trixie] - coturn <no-dsa> (Minor issue)
+       [bookworm] - coturn <postponed> (Minor issue; denied-peer-ip ACL bypass 
via v4-mapped IPv6, address-check functions lack IN6_IS_ADDR_V4MAPPED in 4.6.1)
        NOTE: 
https://github.com/coturn/coturn/security/advisories/GHSA-j8mm-mpf8-gvjg
        NOTE: 
https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b
 (4.9.0)
 CVE-2026-3121 (A flaw was found in Keycloak. An administrator with 
`manage-clients` p ...)


=====================================
data/dla-needed.txt
=====================================
@@ -80,9 +80,11 @@ bouncycastle
   NOTE: 20260417: Priority: Fix CVE-2026-5588 then try to fix other pilled CVE 
(rouca/FD)
   NOTE: 20260717: Also add for bookworm (Beuc/front-desk)
 --
-busybox/bullseye
+busybox
   NOTE: 20260511: Added by Front-Desk (dleidert)
   NOTE: 20260511: A bunch of issues has piled up and last update was in early 
2025 (dleidert/front-desk)
+  NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
+  NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
 --
 c3p0/bullseye
   NOTE: 20260414: Added by Front-Desk (rouca)
@@ -109,10 +111,13 @@ caddy/bookworm
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
-calibre/bullseye
+calibre
   NOTE: 20260222: Added by Front-Desk (rouca)
   NOTE: 20260429: partial update (abhijith)
   NOTE: 20260430: Revisit when rest of the CVEs are fixed upstream (abhijith)
+  NOTE: 20260722: Also add for bookworm; CVE-2026-53511 arbitrary code exec
+  NOTE: 20260722: via composite python: template in a malicious ebook,
+  NOTE: 20260722: auto-evaluated on Add books (utkarsh)
 --
 chromium/bookworm (Emilio)
   NOTE: 20260721: Added by Front-Desk (utkarsh)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d8472697b7da15b42345174acb606fffff8c7f23...4ed36ba85c92dcf239b24ea7978088f20ba6b8f5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d8472697b7da15b42345174acb606fffff8c7f23...4ed36ba85c92dcf239b24ea7978088f20ba6b8f5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to