Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a4551e43 by Salvatore Bonaccorso at 2026-07-29T22:50:20+02:00
Add new trafficserver issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -95,11 +95,14 @@ CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege 
Escalation in Gridbox
 CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object 
injection  ...)
        NOT-FOR-US: Joomla
 CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin 
connections wit ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when 
dechunking  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table 
before co ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-64557 (In the Linux kernel, the following vulnerability has been 
resolved:  B ...)
        - linux 7.1.5-1
        NOTE: 
https://git.kernel.org/linus/6fef032af0092ed5ccb767239a9ac1bc38c08a40 (7.2-rc3)
@@ -133,65 +136,95 @@ CVE-2026-59247 (Insufficient Verification of Data 
Authenticity vulnerability in
 CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted 
`verify_signatur ...)
        NOT-FOR-US: Apache Airflow FAB provider
 CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when 
plugins reset  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58188 (Several Apache Traffic Server experimental plugins have 
memory-safety  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58187 (The Apache Traffic Server multiplexer plugin overruns its 
chunk-decode ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58186 (The Apache Traffic Server webp_transform plugin can decode 
unsafely an ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58185 (The Apache Traffic Server intercept plugin has a 
use-after-free.  This ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58184 (The Apache Traffic Server header_rewrite plugin can crash or 
corrupt m ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58183 (The Apache Traffic Server prefetch plugin can crash when 
processing at ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58182 (The Apache Traffic Server ts_lua plugin mishandles 
initialization, tra ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58181 (The Apache Traffic Server uri_signing and url_sig plugins can 
exhaust  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58180 (The Apache Traffic Server txn_box plugin overflows the stack 
from atta ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58179 (The Apache Traffic Server regex_remap plugin overflows the 
stack and i ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58178 (The Apache Traffic Server ESI plugin can recurse without bound 
and fet ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58177 (The Apache Traffic Server Cripts framework has out-of-bounds 
writes, p ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58175 (Apache Traffic Server leaks memory when handling HostDB SRV 
records.   ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58164 (Apache Traffic Server has use-after-free and 
time-of-check/time-of-use ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58163 (Apache Traffic Server mishandles on-disk cache fields and 
object lifet ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58162 (The Apache Traffic Server certifier plugin generates 
certificates base ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58161 (Apache Traffic Server can crash from null dereferences and 
dangling re ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58160 (Apache Traffic Server reads out of bounds while parsing DNS 
answers.   ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58159 (Apache Traffic Server can bypass IP access controls on UDS 
listeners a ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58158 (Apache Traffic Server mishandles PROXY protocol input, 
truncating port ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58157 (Apache Traffic Server can reuse server sessions and tunnels 
improperly ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58156 (Apache Traffic Server mis-parses ports in URLs and userinfo, 
allowing  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58155 (Apache Traffic Server truncates over-long header names, 
allowing heade ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58154 (Apache Traffic Server can write out of bounds or overflow 
integers whi ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58153 (Apache Traffic Server forwards HTTP/2 origin trailers to 
HTTP/1 client ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58152 (Apache Traffic Server mishandles integers while decoding 
HPACK/XPACK h ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58151 (Apache Traffic Server can be crashed or driven to resource 
exhaustion  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58150 (Apache Traffic Server does not reject Transfer-Encoding in 
HTTP/2 requ ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked 
messages are ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output 
paths. Gramma ...)
        TODO: check
 CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program 
during HTML  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to