Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0c85ff9c by Salvatore Bonaccorso at 2026-08-14T09:46:55+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -437,9 +437,9 @@ CVE-2026-73252 [Built-in TLS short-record handling]
 CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
        - mongoose 7.23+ds-1
 CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to 
two sumdb  ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -448,9 +448,9 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable 
of forging up to two
        NOTE: Fixed by: 
https://github.com/golang/go/commit/115eb476aaca4531374c42e19e6f199265c2e25e 
(go1.26.6)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/b0b8c97d1386bb3eb978e727ed0b1df8e14df569 
(go1.25.13)
 CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module 
content no ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -459,9 +459,9 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving 
arbitrary module cont
        NOTE: Fixed by: 
https://github.com/golang/go/commit/9f6980fd5c03840b0f6764e8ec7c705b90989eee 
(go1.26.6)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb 
(go1.25.13)
 CVE-2026-56859 (Previously, DecodeElement would reset the depth counter 
causing it to  ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -470,9 +470,9 @@ CVE-2026-56859 (Previously, DecodeElement would reset the 
depth counter causing
        NOTE: Fixed by: 
https://github.com/golang/go/commit/9918f26ab31a6bf9209ecc06465cab0e287e90f1 
(go1.26.6)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 
(go1.25.13)
 CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it 
reads a  ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -481,9 +481,9 @@ CVE-2026-56853 (When a server is configured to support 
unencrypted HTTP/2, it re
        NOTE: Fixed by: 
https://github.com/golang/go/commit/5bbd22ff78daf010c5bd19c466a0c45ac78503d4 
(go1.26.6)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 
(go1.25.13)
 CVE-2026-56860 (Previously, resolving relative paths containing parent 
directory ('..' ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -492,9 +492,9 @@ CVE-2026-56860 (Previously, resolving relative paths 
containing parent directory
        NOTE: Fixed by: 
https://github.com/golang/go/commit/128893dbf9a6b4d6e7c99942096e2c0018d6fe57 
(go1.26.6)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/962b300d32b68fd5f3c11674f711fc0e86251664 
(go1.25.13)
 CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered 
as state- ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -503,9 +503,9 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are 
always considered as
        NOTE: Fixed by: 
https://github.com/golang/go/commit/b6432317a176b1b5595aa597dc1864a4cc4a81b2 
(go1.26.6)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/677cfe54ecac147c4992e38204641bf61662524f 
(go1.25.13)
 CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' 
early, al ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -514,9 +514,9 @@ CVE-2026-56858 (Previously, pathological inputs could close 
an unescaped '/' ear
        NOTE: Fixed by: 
https://github.com/golang/go/commit/33ecb966ca47e55034272a9146e23e9909507f6d 
(go1.26.6)
        NOTE: Fixed by: 
https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 
(go1.25.13)
 CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack 
exhaustion whe ...)
-       - golang-1.27 <unfixed>
-       - golang-1.26 <unfixed>
-       - golang-1.25 <unfixed>
+       - golang-1.27 <unfixed> (bug #1144340)
+       - golang-1.26 <unfixed> (bug #1144341)
+       - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
        - golang-1.19 <removed>
        - golang-1.15 <removed>
@@ -578,32 +578,32 @@ CVE-2026-73629 (Serendipity before 2.6.0 contains a 
server-side request forgery
 CVE-2026-73628 (Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected 
cross-s ...)
        - serendipity <removed>
 CVE-2026-73627 (JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 
and >=4 ...)
-       - jupyterlab <unfixed>
+       - jupyterlab <unfixed> (bug #1144343)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm
 CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an 
allowlist/b ...)
-       - jupyterlab <unfixed>
+       - jupyterlab <unfixed> (bug #1144343)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j
 CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code 
execution vulne ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144344)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3
 CVE-2026-73624 (GitPython versions before 3.1.54 contain an arbitrary file 
overwrite v ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144344)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-x663-mwxc
 CVE-2026-73623 (GitPython before 3.1.54 contains an incomplete denylist in 
unsafe_git_ ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144344)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-6p8h-3wgx-97gf
 CVE-2026-73622 (GitPython before 3.1.55 fails to disable environment variable 
expansio ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144344)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-94p4-4cq8-9g67
        NOTE: Distinct but releated to CVE-2026-67322
 CVE-2026-73621 (GitPython before 3.1.56 contains an argument injection 
vulnerability i ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144344)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-p538-c434-8v24
 CVE-2026-73620 (GitPython before 3.1.57 fails to guard git option forwarding 
in IndexF ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144344)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3f7w-8rr8-f37f
 CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the 
unsafe_ ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144344)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-539m-9xh6-q6rr
 CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection 
vulnerability ...)
        NOT-FOR-US: Budibase
@@ -1467,16 +1467,16 @@ CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 
11.0.0.1 and IBM DataPower
 CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded 
cluster-authentication s ...)
        NOT-FOR-US: WolfStack
 CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior 
to 0.144 ...)
-       - golang-github-getkin-kin-openapi <unfixed>
+       - golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da
 (v0.144.0)
 CVE-2026-73500 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
-       - etcd <unfixed>
+       - etcd <unfixed> (bug #1144346)
        NOTE: 
https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
        NOTE: https://github.com/etcd-io/etcd/pull/22130
        NOTE: Fixed by: 
https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057 
(v3.5.33)
 CVE-2026-73499 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
-       - etcd <unfixed>
+       - etcd <unfixed> (bug #1144346)
        NOTE: 
https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
        NOTE: Fixed by: 
https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7 
(v3.5.33)
 CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for 
Atlassian p ...)
@@ -1526,11 +1526,11 @@ CVE-2026-73433 (A flaw was found in GStreamer 
gst-plugins-good (avidemux). When
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/c429d2a33496b54b8e6c00dbf1fdc4e3f52d8481
 (1.26.8)
        NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0072.html
 CVE-2026-73430 (Russh is a Rust SSH client & server library. Prior to 0.62.4, 
an unaut ...)
-       - rust-russh <unfixed>
+       - rust-russh <unfixed> (bug #1144347)
        NOTE: 
https://github.com/Eugeny/russh/security/advisories/GHSA-5xvq-cp9x-6p6r
        NOTE: Fixed by: 
https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d 
(v0.62.4)
 CVE-2026-73429 (Russh is a Rust SSH client & server library. Prior to 0.62.4, 
a malici ...)
-       - rust-russh <unfixed>
+       - rust-russh <unfixed> (bug #1144347)
        NOTE: 
https://github.com/Eugeny/russh/security/advisories/GHSA-g9hv-x236-4qp3
        NOTE: Fixed by: 
https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d 
(v0.62.4)
 CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
@@ -1546,7 +1546,7 @@ CVE-2026-73419 (NextAuth.js provides authentication for 
Next.js. Prior to@auth/c
 CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to 
@auth/core 0 ...)
        NOT-FOR-US: Next.js
 CVE-2026-73415 (jupyterlab is an extensible environment for interactive and 
reproducib ...)
-       - jupyterlab <unfixed>
+       - jupyterlab <unfixed> (bug #1144343)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
        NOTE: https://github.com/jupyterlab/jupyterlab/pull/19186
        NOTE: Fixed by: 
https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c
 (v4.5.10)
@@ -2008,7 +2008,7 @@ CVE-2026-73297 (Microsoft UFO open-source framework for 
intelligent automation a
 CVE-2026-73296 (Microsoft UFO open-source framework for intelligent automation 
across  ...)
        NOT-FOR-US: Microsoft UFO
 CVE-2026-73295 (Material for MkDocs is a powerful documentation framework 
built on top ...)
-       - mkdocs-material <unfixed>
+       - mkdocs-material <unfixed> (bug #1144348)
        NOTE: 
https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
        NOTE: Fixed by: 
https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25
 (9.7.7)
 CVE-2026-73294 (Semaphore UI is a web interface for managing DevOps tools. 
Prior to 2. ...)
@@ -2509,19 +2509,19 @@ CVE-2026-73241 (FreeRDP is a free implementation of the 
Remote Desktop Protocol.
        NOTE: Fixed by: 
https://github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695
 (3.30.0)
        NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/pull/13065
 CVE-2026-73235 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
-       - freecad <unfixed>
+       - freecad <unfixed> (bug #1144349)
        [trixie] - freecad <no-dsa> (Minor issue)
        NOTE: 
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-cp6c-87x9-xf49
        NOTE: https://github.com/FreeCAD/FreeCAD/pull/31280
        NOTE: Fixed by: 
https://github.com/FreeCAD/FreeCAD/commit/7d1b8f5806db578db99feb348e55a6b0eaff7c73
 (1.1.2)
 CVE-2026-73234 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
-       - freecad <unfixed>
+       - freecad <unfixed> (bug #1144349)
        [trixie] - freecad <no-dsa> (Minor issue)
        NOTE: 
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-5vqh-3v38-jw2r
        NOTE: https://github.com/FreeCAD/FreeCAD/pull/31281
        NOTE: Fixed by: 
https://github.com/FreeCAD/FreeCAD/commit/f19b18b7d93729a29a90e96e0ae192b5d054b86d
 (1.1.2)
 CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
-       - freecad <unfixed>
+       - freecad <unfixed> (bug #1144349)
        [trixie] - freecad <no-dsa> (Minor issue)
        NOTE: 
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-2rq3-gx3h-489q
        NOTE: https://github.com/FreeCAD/FreeCAD/pull/31312
@@ -2537,7 +2537,7 @@ CVE-2026-73231 (Faker generates massive amounts of fake 
data in the browser and
 CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security 
tools.  ...)
        NOT-FOR-US: Ente
 CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for 
building  ...)
-       - djangorestframework <unfixed>
+       - djangorestframework <unfixed> (bug #1144350)
        NOTE: 
https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
        NOTE: https://github.com/encode/django-rest-framework/pull/10012
        NOTE: Fixed by: 
https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e
 (3.17.2)
@@ -2912,7 +2912,7 @@ CVE-2026-19560 (Use after free in Blink in Google Chrome 
prior to 151.0.7922.137
 CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR 
R7000 model ...)
        NOT-FOR-US: Netgear
 CVE-2026-73228 (Django REST framework is a toolkit for building Web APIs. 
Prior to 3.1 ...)
-       - djangorestframework <unfixed>
+       - djangorestframework <unfixed> (bug #1144350)
        NOTE: 
https://github.com/encode/django-rest-framework/security/advisories/GHSA-2m8g-3cmr-wg3w
        NOTE: https://github.com/encode/django-rest-framework/pull/10013
        NOTE: Fixed by: 
https://github.com/encode/django-rest-framework/commit/2912dc98042f78e27636551fc22eeaf10f725fdd
 (3.17.2)
@@ -12157,7 +12157,7 @@ CVE-2026-67339 (guzzlehttp/guzzle versions before 
7.14.2 fail to properly isolat
        [trixie] - guzzle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting 
vulnera ...)
-       - jupyterlab <unfixed>
+       - jupyterlab <unfixed> (bug #1144343)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
        NOTE: 
https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6
 (v4.6.0rc0)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12
 (v4.6.0rc1)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c85ff9cbf1ff2a7c0d8cbc782b02fd0444c6a97

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c85ff9cbf1ff2a7c0d8cbc782b02fd0444c6a97
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to