Daniel Leidert pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
75870980 by Daniel Leidert at 2026-08-08T23:40:36+02:00
lts: drop starlette from dla-needed and mark all CVEs is Bullseye as ignored
Bullseye requires an intrusive backport and no customer has expressed interest.
Dropping starlette/bullseye from dla-needed and marking all issues in Bullseye
as ignored.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -41212,12 +41212,14 @@ CVE-2026-54285 (opentelemetry-js is the OpenTelemetry
JavaScript Client. Prior t
CVE-2026-54283 (Starlette is a lightweight ASGI framework/toolkit. From 0.4.1
until 1. ...)
{DLA-4711-1}
- starlette 1.3.1-1 (bug #1140631)
+ [bullseye] - starlette <ignored> (Minor issue; requires intrusive
backport for CVE-2023-30798)
NOTE:
https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
NOTE: https://github.com/Kludex/starlette/pull/3329
NOTE: Fixed by:
https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735
(1.3.1)
CVE-2026-54282 (Starlette is a lightweight ASGI framework/toolkit. Prior to
1.3.0, the ...)
{DLA-4711-1}
- starlette 1.3.1-1 (bug #1140632)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE:
https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3
NOTE: https://github.com/Kludex/starlette/pull/3326
NOTE: Fixed by:
https://github.com/Kludex/starlette/commit/167b5850e809f38b27fbfed62d58bf6442855975
(1.3.0)
@@ -42838,6 +42840,7 @@ CVE-2026-48817 (Starlette is a lightweight ASGI
framework/toolkit. In versions 1
{DLA-4711-1}
- starlette 1.1.0-1
[trixie] - starlette <no-dsa> (Minor issue)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE:
https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c
NOTE: https://github.com/Kludex/starlette/pull/3286
NOTE:
https://github.com/Kludex/starlette/commit/e3f972225adb1d84b80dba132f520cc24cb84229
(1.1.0)
@@ -62848,6 +62851,7 @@ CVE-2025-26483 (Dell PowerFlex Manager, versions 4.6.2
and prior, contains an Op
CVE-2026-48710 (Starlette is a lightweight ASGI framework/toolkit. Prior to
version 1. ...)
{DSA-6302-1}
- starlette 1.1.0-1 (bug #1137375)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE: https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/
NOTE:
https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr
NOTE:
https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6
(1.0.1)
@@ -193765,7 +193769,7 @@ CVE-2025-5681 (Authorization Bypass Through
User-Controlled Key vulnerability in
CVE-2025-54121 (Starlette is a lightweight ASGI (Asynchronous Server Gateway
Interface ...)
- starlette 0.46.1-3 (bug #1109805)
[bookworm] - starlette 0.26.1-1+deb12u1
- [bullseye] - starlette <postponed> (minor issue; Dos can be fixed in
next update)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE:
https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73
NOTE: Fixed by:
https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1
(0.47.2)
NOTE:
https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403
@@ -283227,7 +283231,7 @@ CVE-2024-47876 (Sakai is a Collaboration and Learning
Environment. Starting in v
CVE-2024-47874 (Starlette is an Asynchronous Server Gateway Interface (ASGI)
framework ...)
- starlette 0.41.0-1 (bug #1085295)
[bookworm] - starlette 0.26.1-1+deb12u1
- [bullseye] - starlette <postponed> (Minor issue; can be fixed in next
update)
+ [bullseye] - starlette <ignored> (Minor issue; requires intrusive
backport for CVE-2023-30798)
NOTE:
https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw
NOTE:
https://github.com/encode/starlette/commit/fd038f3070c302bff17ef7d173dbb0b007617733
(0.40.0)
CVE-2024-47824 (matrix-react-sdk is react-based software development kit for
inserting ...)
@@ -394176,7 +394180,7 @@ CVE-2023-30758 (Cross-site scripting vulnerability in
Pleasanter 1.3.38.1 and ea
CVE-2023-29159 (Directory traversal vulnerability in Starlette versions 0.13.5
and lat ...)
- starlette 0.28.0-1
[bookworm] - starlette 0.26.1-1+deb12u1
- [bullseye] - starlette <no-dsa> (Minor issue)
+ [bullseye] - starlette <ignored> (Minor issue)
NOTE:
https://github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84px
NOTE:
https://github.com/encode/starlette/commit/1797de464124b090f10cf570441e8292936d63e3
(0.27.0)
CVE-2023-29154 (SQL injection vulnerability exists in the CONPROSYS HMI System
(CHS) v ...)
@@ -398278,7 +398282,7 @@ CVE-2023-30799 (MikroTik RouterOS stable before
6.49.7 and long-term through 6.4
NOT-FOR-US: MikroTik RouterOS
CVE-2023-30798 (There MultipartParser usage in Encode's Starlette python
framework bef ...)
- starlette 0.25.0-1
- [bullseye] - starlette <no-dsa> (Minor issue)
+ [bullseye] - starlette <ignored> (Too intrusive to backport)
NOTE:
https://github.com/encode/starlette/commit/8c74c2c8dba7030154f8af18e016136bea1938fa
(0.25.0)
NOTE:
https://github.com/encode/starlette/security/advisories/GHSA-74m5-2c7w-9w3x
CVE-2023-30797 (Netflix Lemur before version 1.3.2 used insufficiently random
values w ...)
=====================================
data/dla-needed.txt
=====================================
@@ -872,12 +872,6 @@ sssd
NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
NOTE: 20260804: SSSD should be tested carefully, with integration test
(rouca/FD)
--
-starlette/bullseye (dleidert)
- NOTE: 20260528: Added by Front-Desk (dleidert)
- NOTE: 20260528: follow DSA-6302-1 (dleidert/front-desk)
- NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
- NOTE: 20260801: Bullseye requires a very intrusive patch (CVE-2023-30798)
that is the base to fix other CVEs as well (dleidert)
---
strongswan/bullseye
NOTE: 20260423: Added by Front-Desk (pochu)
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/758709801c3f463889595dc1b3954f248a0a12cd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/758709801c3f463889595dc1b3954f248a0a12cd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits