Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e9646a48 by Moritz Muehlenhoff at 2026-08-08T18:00:28+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -382,6 +382,7 @@ CVE-2026-19206 (A security flaw has been discovered in MZ 
Automation libiec61850
        NOT-FOR-US: mz-automation libiec61850
 CVE-2026-19082 (Imager versions from 0.45_02 before 1.034 for Perl may expose 
adjacent ...)
        - libimager-perl 1.034+dfsg-1
+       [trixie] - libimager-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42492379/
        NOTE: 
https://github.com/tonycoz/imager/security/advisories/GHSA-hx46-55wp-hv6m
        NOTE: Fixed by: 
https://github.com/tonycoz/imager/commit/24bde0427a113264d53f45a9c29ae756d84c82fe
 (v1.034)
@@ -482,6 +483,7 @@ CVE-2026-71498 (node-re2 provides RE2 regular expression 
bindings for Node.js. P
        NOTE: Fixed by: 
https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4
 (1.26.1)
 CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 
1.14.3  ...)
        - jsoup <unfixed> (bug #1143906)
+       [trixie] - jsoup <no-dsa> (Minor issue)
        NOTE: 
https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8
        NOTE: https://github.com/jhy/jsoup/issues/2538
        NOTE: Fixed by: 
https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70 
(jsoup-1.23.1)
@@ -3174,6 +3176,7 @@ CVE-2026-18773 (A vulnerability was detected in 
NousResearch hermes-agent up to
        NOT-FOR-US: NousResearch
 CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source 
rlottie ...)
        - rlottie <unfixed>
+       [trixie] - rlottie <no-dsa> (Minor issue)
        NOTE: https://github.com/Samsung/rlottie/pull/596
 CVE-2026-18770 (A vulnerability has been found in vibesurf-ai VibeSurf up to 
cd6e519d5 ...)
        NOT-FOR-US: vibesurf-ai VibeSurf
@@ -3811,6 +3814,7 @@ CVE-2026-15430 (Improper access control in the 
IRP_MJ_WRITE command interface in
        NOT-FOR-US: Wellbia XIGNCODE3
 CVE-2026-12259 (In nltk version 3.9.4, the 
`nltk.downloader.Downloader._download_packa ...)
        - nltk <unfixed>
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: https://huntr.com/bounties/659ccf6d-12d4-4d4a-84c0-078633c35a5d
 CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0 
retrieve ...)
        NOT-FOR-US: Latvijas Valsts radio un televizijas centrs (LVRTC)
@@ -11585,6 +11589,7 @@ CVE-2026-14955 (The Checkout Field Editor for 
WooCommerce (Pro) plugin for WordP
        NOT-FOR-US: WordPress plugin
 CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains 
an eval  ...)
        - nltk 3.9.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/
        NOTE: https://github.com/nltk/nltk/pull/3465
        NOTE: Fixed by: 
https://github.com/nltk/nltk/commit/e373c8c3d10e236672ef65c38ca7d24612941553 
(3.9.3)
@@ -16511,13 +16516,17 @@ CVE-2026-15145 (The Essential Addons for Elementor 
\u2013 Popular Elementor Temp
        NOT-FOR-US: WordPress plugin
 CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When 
parsing mult ...)
        - libsoup3 <unfixed> (bug #1142838)
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/512
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/524
        NOTE: 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/7334c38f1f6aa5e64207cb415cf2509838c52b37
 (3.7.1)
 CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials 
without scopin ...)
        - libsoup3 <unfixed> (bug #1142837)
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
 CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET 
/api/v1/stack-deployment/st ...)
        NOT-FOR-US: zenml
@@ -20410,26 +20419,31 @@ CVE-2026-54497 (view_component is a framework for 
building reusable, testable, a
        NOT-FOR-US: view_component framework
 CVE-2026-54490 (websocket-driver is a WebSocket protocol handler with 
pluggable I/O. P ...)
        - node-websocket-driver <unfixed> (bug #1142415)
+       [trixie] - node-websocket-driver <no-dsa> (Minor issue)
        NOTE: 
https://github.com/faye/websocket-driver-node/security/advisories/GHSA-mp7j-qc5w-4988
        NOTE: Fixed by: 
https://github.com/faye/websocket-driver-node/commit/c55679a5b18251dd0a55d18a0cc6a4fd8822b92f
 (0.7.5)
 CVE-2026-54466 (websocket-driver is a WebSocket protocol handler with 
pluggable I/O. P ...)
        - node-websocket-driver <unfixed> (bug #1142415)
+       [trixie] - node-websocket-driver <no-dsa> (Minor issue)
        NOTE: 
https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6
        NOTE: Fixed by: 
https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680
 (0.7.5)
 CVE-2026-54465 (websocket-driver is a WebSocket protocol handler with 
pluggable I/O. P ...)
        - ruby-websocket-driver 0.8.1-1
+       [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
        [bookworm] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
        [bullseye] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
        NOTE: 
https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-8j3g-f24p-4mpw
        NOTE: Fixed by: 
https://github.com/faye/websocket-driver-ruby/commit/17b569f232896e71d458404ccf4854f80e987710
 (0.8.1)
 CVE-2026-54464 (### Impact  If this library is used in tandem with the 
`permessage-def ...)
        - ruby-websocket-driver 0.8.1-1
+       [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
        [bookworm] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
        [bullseye] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
        NOTE: 
https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-33ph-fccm-39pj
        NOTE: Fixed by: 
https://github.com/faye/websocket-driver-ruby/commit/fa8641724f10bf3273585f1dcf9041f540bbd036
 (0.8.1)
 CVE-2026-54463 (websocket-driver is a WebSocket protocol handler with 
pluggable I/O. P ...)
        - ruby-websocket-driver 0.8.1-1
+       [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
        [bookworm] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
        [bullseye] - ruby-websocket-driver <postponed> (Minor Issue; DoS)
        NOTE: 
https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p
@@ -25160,6 +25174,7 @@ CVE-2026-15552 (Enterprise Cloud Database developed by 
Ragic has a Stored Cross-
        NOT-FOR-US: Ragic
 CVE-2026-15551 (Integer overflow or wraparound vulnerability in Samsung Open 
Source rl ...)
        - rlottie <unfixed>
+       [trixie] - rlottie <no-dsa> (Minor issue)
        NOTE: https://github.com/Samsung/rlottie/pull/595
        NOTE: Fixed by: 
https://github.com/Samsung/rlottie/commit/f487eff2f8086b84ae1c7faa0418abec909e874b
 CVE-2026-15539 (A security vulnerability has been detected in SourceCodester 
Online Bo ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9646a48b4c348ca7498966c82bce70b7751222a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9646a48b4c348ca7498966c82bce70b7751222a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to