Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a4551e43 by Salvatore Bonaccorso at 2026-07-29T22:50:20+02:00
Add new trafficserver issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -95,11 +95,14 @@ CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege
Escalation in Gridbox
CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object
injection ...)
NOT-FOR-US: Joomla
CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin
connections wit ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when
dechunking ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table
before co ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-64557 (In the Linux kernel, the following vulnerability has been
resolved: B ...)
- linux 7.1.5-1
NOTE:
https://git.kernel.org/linus/6fef032af0092ed5ccb767239a9ac1bc38c08a40 (7.2-rc3)
@@ -133,65 +136,95 @@ CVE-2026-59247 (Insufficient Verification of Data
Authenticity vulnerability in
CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted
`verify_signatur ...)
NOT-FOR-US: Apache Airflow FAB provider
CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when
plugins reset ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58188 (Several Apache Traffic Server experimental plugins have
memory-safety ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58187 (The Apache Traffic Server multiplexer plugin overruns its
chunk-decode ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58186 (The Apache Traffic Server webp_transform plugin can decode
unsafely an ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58185 (The Apache Traffic Server intercept plugin has a
use-after-free. This ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58184 (The Apache Traffic Server header_rewrite plugin can crash or
corrupt m ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58183 (The Apache Traffic Server prefetch plugin can crash when
processing at ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58182 (The Apache Traffic Server ts_lua plugin mishandles
initialization, tra ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58181 (The Apache Traffic Server uri_signing and url_sig plugins can
exhaust ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58180 (The Apache Traffic Server txn_box plugin overflows the stack
from atta ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58179 (The Apache Traffic Server regex_remap plugin overflows the
stack and i ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58178 (The Apache Traffic Server ESI plugin can recurse without bound
and fet ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58177 (The Apache Traffic Server Cripts framework has out-of-bounds
writes, p ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58175 (Apache Traffic Server leaks memory when handling HostDB SRV
records. ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58164 (Apache Traffic Server has use-after-free and
time-of-check/time-of-use ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58163 (Apache Traffic Server mishandles on-disk cache fields and
object lifet ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58162 (The Apache Traffic Server certifier plugin generates
certificates base ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58161 (Apache Traffic Server can crash from null dereferences and
dangling re ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58160 (Apache Traffic Server reads out of bounds while parsing DNS
answers. ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58159 (Apache Traffic Server can bypass IP access controls on UDS
listeners a ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58158 (Apache Traffic Server mishandles PROXY protocol input,
truncating port ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58157 (Apache Traffic Server can reuse server sessions and tunnels
improperly ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58156 (Apache Traffic Server mis-parses ports in URLs and userinfo,
allowing ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58155 (Apache Traffic Server truncates over-long header names,
allowing heade ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58154 (Apache Traffic Server can write out of bounds or overflow
integers whi ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58153 (Apache Traffic Server forwards HTTP/2 origin trailers to
HTTP/1 client ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58152 (Apache Traffic Server mishandles integers while decoding
HPACK/XPACK h ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58151 (Apache Traffic Server can be crashed or driven to resource
exhaustion ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58150 (Apache Traffic Server does not reject Transfer-Encoding in
HTTP/2 requ ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked
messages are ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output
paths. Gramma ...)
TODO: check
CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program
during HTML ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits