Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9140a4e9 by Salvatore Bonaccorso at 2026-07-29T23:50:46+02:00
Add more trafficserver issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -312,25 +312,30 @@ CVE-2026-44943 (An Improper Limitation of a Pathname to a 
Restricted Directory (
 CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded 
credentials vuln ...)
        NOT-FOR-US: Care Everywhere Gateway
 CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic 
Server.  This  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-40272 (Improper Input Validation in the decode() function of the 
traceparser  ...)
        NOT-FOR-US: Blackberry
 CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS 
PROFINET ...)
        NOT-FOR-US: CODESYS
 CVE-2026-33930 (Apache Traffic Server copies the client Host header into a 
fixed-size  ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in 
Quick.CMS.  ...)
        NOT-FOR-US: Quick.CMS
 CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic 
Server.  Thi ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 i ...)
        NOT-FOR-US: IBM
 CVE-2026-24033 (Inconsistent Interpretation of HTTP Requests ('HTTP 
Request/Response S ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the 
request path a ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache 
Traffic Ser ...)
-       TODO: check
+       - trafficserver <unfixed>
+       NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall 
Manageme ...)
        NOT-FOR-US: Cisco
 CVE-2026-18257 (Improper validity period check for root issuer certificate in 
CycloneC ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9140a4e9a79f548a3fcd45b823c632cd5f8ad39b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9140a4e9a79f548a3fcd45b823c632cd5f8ad39b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to