Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
4cee12c3 by Salvatore Bonaccorso at 2026-07-29T22:48:06+02:00
Add new cjson issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -27,11 +27,14 @@ CVE-2026-67425 (Flyto2 Core is an execution kernel for
automation and AI-agent w
CVE-2026-67424 (Flyto2 Core is an execution kernel for automation and AI-agent
workflo ...)
NOT-FOR-US: Flyto2 Core
CVE-2026-67217 (cJSON through 1.7.19 applies RFC 6902 JSON Patch operations
non-atomic ...)
- TODO: check
+ - cjson <unfixed>
+ NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
CVE-2026-67216 (cJSON through 1.7.19 contains an inefficient algorithmic
complexity fl ...)
- TODO: check
+ - cjson <unfixed>
+ NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion
leading t ...)
- TODO: check
+ - cjson <unfixed>
+ NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in
the custom ...)
TODO: check
CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the
customA ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4cee12c3cbd3d3860f1e48d524a15c5b4e9dd4e5
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4cee12c3cbd3d3860f1e48d524a15c5b4e9dd4e5
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits