Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b2053690 by Utkarsh Gupta at 2026-07-22T14:12:45+05:30
lts: node-ajv not-affected in bullseye/bookworm (uses uri-js, not fast-uri)
- - - - -
b237d293 by Utkarsh Gupta at 2026-07-22T14:12:46+05:30
lts: simplesamlphp postponed in bookworm/bullseye (CVE-2026-49284)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3881,6 +3881,8 @@ CVE-2026-16222 (A vulnerability was found in 1Panel-dev
CordysCRM up to 1.4.1. T
CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including
the 3.x ...)
- node-ajv <unfixed>
[trixie] - node-ajv <no-dsa> (Minor issue)
+ [bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable
fast-uri; fast-uri adopted only in ajv 8.x)
+ [bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable
fast-uri; fast-uri adopted only in ajv 8.x)
NOTE:
https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx
CVE-2026-16220 (A vulnerability has been found in code-projects Online
Examination Sys ...)
NOT-FOR-US: code-projects
@@ -6657,6 +6659,8 @@ CVE-2026-49485 (HAPI FHIR is a complete implementation of
the HL7 FHIR standard
NOT-FOR-US: HAPI FHIR
CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information
disclosure ...)
- simplesamlphp <unfixed>
+ [bookworm] - simplesamlphp <postponed> (Reachability-gated: multi-IdP
mixed-trust deployments only; SP warns-and-continues on issuer mismatch and
accepts unsigned Response InResponseTo; fix along with the next DLA)
+ [bullseye] - simplesamlphp <postponed> (Reachability-gated: multi-IdP
mixed-trust deployments only; SP warns-and-continues on issuer mismatch and
accepts unsigned Response InResponseTo; fix along with the next DLA)
NOTE:
https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to
2.6.1, au ...)
- golang-oras-oras-go <unfixed> (bug #1142456)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5313ff174f882cf9cfd668f48172bd7937437ecb...b237d29357ff9b621ee7698b665f8d00e11fad0f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits