Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
62fd926d by Salvatore Bonaccorso at 2026-07-30T09:43:13+02:00
Update status for node-ws issues
CVE-2026-62389 got rejected because it is a duplicate of CVE-2026-48779.
Merge useful tracking information from CVE-2026-62389 to CVE-2026-48779.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15209,9 +15209,6 @@ CVE-2026-62683 (File Browser is a file managing
interface for uploading, deletin
NOT-FOR-US: File Browser
CVE-2026-62389
REJECTED
- - node-ws 8.21.1+~cs14.19.1-1 (bug #1142271)
- NOTE: https://github.com/websockets/ws/issues/2331
- NOTE: Fixed by:
https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d
(8.21.1)
CVE-2026-62378 (RustFS Console is a web management console for the RustFS
distributed ...)
NOT-FOR-US: RustFS
CVE-2026-62294 (Flameshot is powerful yet simple to use screenshot software.
Prior to ...)
@@ -36734,11 +36731,13 @@ CVE-2026-48782 (Pydantic AI is a Python agent
framework for building application
CVE-2026-48781 (Postiz is an AI social media scheduling tool. In versions
prior to 2.2 ...)
NOT-FOR-US: Postiz
CVE-2026-48779 (ws is an open source WebSocket client and server for Node.js.
All vers ...)
- - node-ws 8.21.0+~cs14.19.1-1 (bug #1140429)
+ - node-ws 8.21.0+~cs14.19.1-1 (bug #1140429; bug #1142271)
[trixie] - node-ws <no-dsa> (Minor issue)
[bookworm] - node-ws <postponed> (Minor issue; memory-exhaustion DoS
from a malicious peer, fixed in 8.21.0/7.5.11)
[bullseye] - node-ws <postponed> (Minor issue; memory-exhaustion DoS
from a malicious peer, fixed in 8.21.0/7.5.11)
NOTE:
https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p
+ NOTE: https://github.com/websockets/ws/issues/2331
+ NOTE: Fixed by:
https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d
(8.21.1)
CVE-2026-48777 (FileBrowser Quantum is a free, self-hosted, web-based file
manager. Ve ...)
NOT-FOR-US: FileBrowser Quantum
CVE-2026-48776 (LangGraph Python SDK is used to connect to running LangGraph
API serve ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits