Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1885a5c5 by security tracker role at 2026-08-14T19:14:27+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,249 @@
+CVE-2026-73850 (Emlog is an open source website building system. In 2.6.20 and
earlier ...)
+ TODO: check
+CVE-2026-73849 (Emlog is an open source website building system. In 2.6.26 and
earlier ...)
+ TODO: check
+CVE-2026-73847 (Emlog is an open source website building system. In 2.6.26 and
earlier ...)
+ TODO: check
+CVE-2026-73846 (CKAN MCP Server is a tool for querying CKAN open data portals.
Prior t ...)
+ TODO: check
+CVE-2026-73845 (CKAN MCP Server is a tool for querying CKAN open data portals.
Prior t ...)
+ TODO: check
+CVE-2026-73844 (CKAN MCP Server is a tool for querying CKAN open data portals.
Prior t ...)
+ TODO: check
+CVE-2026-73673 (Netis NC63 router firmware V3.0.0.3327 contains an
unauthenticated fir ...)
+ TODO: check
+CVE-2026-73633 (Uncontrolled resource consumption vulnerability in the JSON
plugin of ...)
+ TODO: check
+CVE-2026-73630 (SiYuan before v3.7.4 contains an information disclosure
vulnerability ...)
+ TODO: check
+CVE-2026-73107
+ REJECTED
+CVE-2026-73051 (actix-http versions before 3.12.1 contain an HTTP request
smuggling vu ...)
+ TODO: check
+CVE-2026-73049 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
+ TODO: check
+CVE-2026-73048 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
+ TODO: check
+CVE-2026-72970 (Heap-based buffer overflow in Microsoft Edge (Chromium-based)
allows a ...)
+ TODO: check
+CVE-2026-72859 (Budibase versions 3.39.4 before 3.40.0 contain an
authorization regres ...)
+ TODO: check
+CVE-2026-72838 (FileBrowser versions before 2.63.19 fail to enforce the
declared Uploa ...)
+ TODO: check
+CVE-2026-72837 (File Browser versions before 2.63.20 fail to honor the
createUserDir i ...)
+ TODO: check
+CVE-2026-72836 (FileBrowser before 2.63.19 does not account for
case-insensitive files ...)
+ TODO: check
+CVE-2026-72835 (filebrowser versions before v2.63.21 fail to canonicalize
paths before ...)
+ TODO: check
+CVE-2026-72834 (filebrowser before 2.63.19 contains a permission bypass in the
/api/re ...)
+ TODO: check
+CVE-2026-72833 (The Grav API plugin (getgrav/grav-plugin-api) versions >=
1.0.6 and <= ...)
+ TODO: check
+CVE-2026-72832 (Grav versions from 1.5.2 through 2.0.12 contain a stored
cross-site sc ...)
+ TODO: check
+CVE-2026-72831 (The Flex Objects plugin (through 1.4.6, tested with Grav
2.0.11) conta ...)
+ TODO: check
+CVE-2026-72830 (Grav API plugin versions before 1.0.13 fail to enforce API key
scope c ...)
+ TODO: check
+CVE-2026-72829 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13
contains a ...)
+ TODO: check
+CVE-2026-72828 (Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails
to enfor ...)
+ TODO: check
+CVE-2026-72827 (Grav CMS before 2.0.13 contains a server-side template
injection vulne ...)
+ TODO: check
+CVE-2026-72826 (The getgrav/grav-plugin-api plugin before 1.0.13 fails to
validate tha ...)
+ TODO: check
+CVE-2026-72825 (The getgrav/grav-plugin-api plugin before 1.0.13 contains an
API-key s ...)
+ TODO: check
+CVE-2026-72824 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13
contains a ...)
+ TODO: check
+CVE-2026-72823 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13
contains a ...)
+ TODO: check
+CVE-2026-72822 (The getgrav/grav-plugin-api Composer package before 1.0.13
(affected < ...)
+ TODO: check
+CVE-2026-72821 (Grav Form plugin versions before 9.1.15 contain a stored
cross-site sc ...)
+ TODO: check
+CVE-2026-72820 (Grav versions before 2.0.13 fail to properly validate backup
profile r ...)
+ TODO: check
+CVE-2026-72819 (Grav CMS before 2.0.13 contains a remote code execution
vulnerability ...)
+ TODO: check
+CVE-2026-72817 (go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing
vulnera ...)
+ TODO: check
+CVE-2026-72816 (go-chi/chi through 5.2.1 contains an IP spoofing vulnerability
in the ...)
+ TODO: check
+CVE-2026-72815 (go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP
spoofing v ...)
+ TODO: check
+CVE-2026-72814 (The actix-files crate (actix_files) before version 0.6.10
contains an ...)
+ TODO: check
+CVE-2026-72813 (actix-files before 0.6.10 contains a denial of service
vulnerability t ...)
+ TODO: check
+CVE-2026-72812 (SiYuan versions before v3.7.4 contain a missing authorization
vulnerab ...)
+ TODO: check
+CVE-2026-72811 (SiYuan versions <= v3.7.2 contain a SQL injection
vulnerability in the ...)
+ TODO: check
+CVE-2026-72810 (SiYuan versions before v3.7.4 contain a publish-boundary
bypass vulner ...)
+ TODO: check
+CVE-2026-69101 (Datavane TIS v5.0.0 contains an XML external entity (XXE)
injection vu ...)
+ TODO: check
+CVE-2026-66272 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
+ TODO: check
+CVE-2026-66271 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
+ TODO: check
+CVE-2026-66270 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
+ TODO: check
+CVE-2026-63702 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
+ TODO: check
+CVE-2026-63701 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
+ TODO: check
+CVE-2026-63700 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
+ TODO: check
+CVE-2026-63361 (LimeSurvey Community Edition 7.0.5 contains an authenticated
reflected ...)
+ TODO: check
+CVE-2026-57472 (Nozomi Networks Labs identified a CWE-22: Improper Limitation
of a Pat ...)
+ TODO: check
+CVE-2026-57471 (Nozomi Networks Labs identified a CWE-22: Improper Limitation
of a Pat ...)
+ TODO: check
+CVE-2026-57469 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request
Forgery ...)
+ TODO: check
+CVE-2026-53970 (ZeroBrew version 0.3.1 and prior contains a missing integrity
verifica ...)
+ TODO: check
+CVE-2026-49989 (CrateDB is a distributed SQL database. Prior to versions 6.2.8
and 6.3 ...)
+ TODO: check
+CVE-2026-49986 (The Cortex MCP server (`neuro-cortex-memory`), a
cross-platform persis ...)
+ TODO: check
+CVE-2026-49826 (Concourse is a container-based automation system written in
Go. Prior ...)
+ TODO: check
+CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to
version 1.4 ...)
+ TODO: check
+CVE-2026-49282 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
+ TODO: check
+CVE-2026-49263 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
+ TODO: check
+CVE-2026-48528 (Metacat is data repository software that helps researchers
preserve, s ...)
+ TODO: check
+CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an
excessive amo ...)
+ TODO: check
+CVE-2026-46439 (compliance-trestle is a tooling platform for managing
compliance as co ...)
+ TODO: check
+CVE-2026-46380 (compliance-trestle is a tooling platform for managing
compliance as co ...)
+ TODO: check
+CVE-2026-1621 (Authentication bypass by primary weakness vulnerability in
Universal S ...)
+ TODO: check
+CVE-2026-19884 (In Eclipse Theia versions up to and including 1.69.0, opening
a folder ...)
+ TODO: check
+CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on
Java (l ...)
+ TODO: check
+CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP
response ...)
+ TODO: check
+CVE-2026-19871 (Use of Hard-coded Credentials in the human resources component
in Rosk ...)
+ TODO: check
+CVE-2026-19870 (Authorization Bypass Through User-Controlled Key in the
payroll module ...)
+ TODO: check
+CVE-2026-19847 (A security flaw has been discovered in TOTOLINK A800R
4.1.2cu.5137_B20 ...)
+ TODO: check
+CVE-2026-19846 (A vulnerability was identified in TOTOLINK A800R
4.1.2cu.5137_B2020073 ...)
+ TODO: check
+CVE-2026-19845 (A vulnerability was determined in TOTOLINK A800R
4.1.2cu.5137_B2020073 ...)
+ TODO: check
+CVE-2026-19844 (A vulnerability was found in TOTOLINK A800R
4.1.2cu.5137_B20200730. Th ...)
+ TODO: check
+CVE-2026-19841 (A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted
is an u ...)
+ TODO: check
+CVE-2026-19839 (A vulnerability was detected in SourceCodester Simple Doctors
Appointm ...)
+ TODO: check
+CVE-2026-19838 (A security vulnerability has been detected in Webkul Bagisto
up to 2.4 ...)
+ TODO: check
+CVE-2026-19837 (A weakness has been identified in Webkul Bagisto up to 2.4.4.
This aff ...)
+ TODO: check
+CVE-2026-19836 (A security flaw has been discovered in Webkul Bagisto up to
2.4.4. Aff ...)
+ TODO: check
+CVE-2026-19835 (A vulnerability was identified in Webkul Bagisto up to 2.4.4.
Affected ...)
+ TODO: check
+CVE-2026-19834 (A vulnerability was determined in Webkul Bagisto up to 2.4.4.
Affected ...)
+ TODO: check
+CVE-2026-19830 (A vulnerability was found in TRENDnet TEW-816DRM
GURNC4.OT182B-C-TN-R1 ...)
+ TODO: check
+CVE-2026-19829 (A security flaw has been discovered in 648540858
wvp-GB28181-pro 2.7.4 ...)
+ TODO: check
+CVE-2026-19828 (A vulnerability was identified in 648540858 wvp-GB28181-pro
2.7.4-2026 ...)
+ TODO: check
+CVE-2026-19827 (A flaw has been found in alldatacenter alldata up to 0.6.8.
This impac ...)
+ TODO: check
+CVE-2026-19826 (A vulnerability was detected in alldatacenter alldata up to
0.6.8. Thi ...)
+ TODO: check
+CVE-2026-19825 (A security vulnerability has been detected in SourceCodester
Simple Cl ...)
+ TODO: check
+CVE-2026-19824 (A weakness has been identified in Tenda W20E
15.11.0.6(1068_1546_841)_ ...)
+ TODO: check
+CVE-2026-19823 (A security flaw has been discovered in Tenda W20E
15.11.0.6(1068_1546_ ...)
+ TODO: check
+CVE-2026-19822 (A vulnerability was identified in Tenda W20E
15.11.0.6(1068_1546_841)_ ...)
+ TODO: check
+CVE-2026-19821 (A vulnerability was determined in Tenda AC12
15.03.06.23_multi_TD01. T ...)
+ TODO: check
+CVE-2026-19815 (A flaw has been found in TOTOLINK A800R
4.1.2cu.5137_B20200730. Affect ...)
+ TODO: check
+CVE-2026-19814 (A vulnerability was detected in TOTOLINK A800R
4.1.2cu.5137_B20200730. ...)
+ TODO: check
+CVE-2026-19813 (A security vulnerability has been detected in TOTOLINK A800R
4.1.2cu.5 ...)
+ TODO: check
+CVE-2026-19812 (A weakness has been identified in TOTOLINK A800R
4.1.2cu.5137_B2020073 ...)
+ TODO: check
+CVE-2026-19794 (The WP-Stats plugin for WordPress is vulnerable to Stored
Cross-Site S ...)
+ TODO: check
+CVE-2026-19768 (Improper control of generation of code ('Code Injection') in
the setti ...)
+ TODO: check
+CVE-2026-19682 (A command injection vulnerability exists in Security Center
where a re ...)
+ TODO: check
+CVE-2026-19681 (An authenticated command injection vulnerability exists in
Security Ce ...)
+ TODO: check
+CVE-2026-19680 (A SQL injection vulnerability exists in Security Center that
could all ...)
+ TODO: check
+CVE-2026-19679 (An input validation vulnerability exists in Security Center's
file upl ...)
+ TODO: check
+CVE-2026-19639 (An improper access control vulnerability exists where an
authenticated ...)
+ TODO: check
+CVE-2026-19636 (An issue was identified in which CSRF tokens were generated
using a pr ...)
+ TODO: check
+CVE-2026-19635 (A local privilege escalation vulnerability exists in Security
Center. ...)
+ TODO: check
+CVE-2026-19631 (A SQL injection vulnerability exists in Security Center that
could all ...)
+ TODO: check
+CVE-2026-19629 (A privilege escalation vulnerability exists in Tenable
Security Center ...)
+ TODO: check
+CVE-2026-19628 (A command injection vulnerability exists in Tenable Security
Center. A ...)
+ TODO: check
+CVE-2026-19626 (A remote code execution vulnerability exists in Tenable
Security Cente ...)
+ TODO: check
+CVE-2026-19188 (A critical OS command injection vulnerability has been
identified in t ...)
+ TODO: check
+CVE-2026-18403 (LimeSurvey Community Edition 7.0.5 contains an authenticated
SQL injec ...)
+ TODO: check
+CVE-2026-16772 (In Akaunting versions <= 3.1.21, low\u2011privileged
authenticated use ...)
+ TODO: check
+CVE-2026-13198 (Nozomi Networks Labs identified a CWE-362: Concurrent
Execution using ...)
+ TODO: check
+CVE-2026-13197 (Nozomi Networks Labs identified a CWE-362: Concurrent
Execution using ...)
+ TODO: check
+CVE-2026-13196 (Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write
vulnera ...)
+ TODO: check
+CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an
infinite ...)
+ TODO: check
+CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in
kernel/u ...)
+ TODO: check
+CVE-2026-12365 (A use-after-free exists in the Zephyr second-generation work
queue (ke ...)
+ TODO: check
+CVE-2026-12364 (The user-space system-call verifier
z_vrfy_z_log_msg_static_create() i ...)
+ TODO: check
+CVE-2026-12363 (The LoRaWAN Fragmented Data Block Transport service
(subsys/lorawan/se ...)
+ TODO: check
+CVE-2025-7639 (The vulnerability, if exploited, could allow an authenticated
miscrean ...)
+ TODO: check
+CVE-2025-71405 (chi versions before v5.2.2 contain an open redirect
vulnerability in t ...)
+ TODO: check
+CVE-2023-7347
+ REJECTED
CVE-2026-XXXX [RUSTSEC-2025-0168]
- rust-zip 2.5.0-1
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0168.html
@@ -313,7 +559,7 @@ CVE-2026-19746 (A vulnerability has been found in Calix
GigaSpire 26.1.0. The af
TODO: check
CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is
an unknow ...)
TODO: check
-CVE-2026-19617 (A flaw was found in libdm. A remote attacker could craft a
malicious L ...)
+CVE-2026-19617 (A flaw was found in libdm. A local attacker could craft a
malicious Lo ...)
TODO: check
CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through
6.0.1.0 ...)
NOT-FOR-US: IBM
@@ -816,7 +1062,8 @@ CVE-2026-73340 (Contributor Cross Site Scripting (XSS) in
Featured Image from UR
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73266 (A flaw was found in the clusterclaims-controller component of
Multiclu ...)
NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
-CVE-2026-73188 (Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1
versions.)
+CVE-2026-73188
+ REJECTED
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73038 (NodeBB before 4.15.0 contains a stored cross-site scripting
vulnerabil ...)
NOT-FOR-US: NodeBB
@@ -1117,7 +1364,8 @@ CVE-2026-28186 (Subscriber Broken Access Control in
Travelfic Toolkit <= 1.5.1 v
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28185 (Unauthenticated Broken Authentication in Log in with Google <=
1.4.2 v ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-28184 (Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44
versions.)
+CVE-2026-28184
+ REJECTED
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28182 (Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP
Newsletter <= ...)
NOT-FOR-US: WordPress plugin or theme
@@ -1290,7 +1538,7 @@ CVE-2026-13048 (Data::MuForm::Localizer versions through
0.05 for Perl execute P
CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through
1.162360 f ...)
NOT-FOR-US: Form::Processor Perl module
CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a
server ad ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1298,7 +1546,7 @@ CVE-2026-6464 (Untrusted data inclusion in PostgreSQL
psql COPY may allow a serv
NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER
TYPE co ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1306,7 +1554,7 @@ CVE-2026-6469 (Incorrect ownership assignment in
PostgreSQL ALTER TABLE ALTER TY
NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an
object crea ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1314,7 +1562,7 @@ CVE-2026-6470 (Missing authorization in PostgreSQL DDL
commands allows an object
NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a
non-supe ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1322,7 +1570,7 @@ CVE-2026-6471 (Missing authorization in PostgreSQL
logical decoding allows a non
NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data
type functi ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1330,7 +1578,7 @@ CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector
and tsquery data type
NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers
allows a use ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1338,7 +1586,7 @@ CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto
disabled ciphers allows
NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query
author to e ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1346,7 +1594,7 @@ CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp
allows the query autho
NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role
membership, role ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1354,7 +1602,7 @@ CVE-2026-14666 (Incomplete tracking in PostgreSQL of
changes to role membership,
NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type
selectivit ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1362,7 +1610,7 @@ CVE-2026-14668 (Type confusion regarding input of
PostgreSQL ctid data type sele
NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows
the par ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1370,7 +1618,7 @@ CVE-2026-14669 (Heap buffer overflow in PostgreSQL
to_char(timestamptz) allows t
NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied
hash allows ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1378,7 +1626,7 @@ CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl
return of a tied hash
NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object
creator ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1394,7 +1642,7 @@ CVE-2026-14672 (Observable response discrepancy in
PostgreSQL SCRAM authenticati
NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee
of amchec ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1409,7 +1657,7 @@ CVE-2026-14676 (Heap buffer overflow in PostgreSQL
pg_stat_statements allows the
NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and
plperl all ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1417,7 +1665,7 @@ CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit
builds of pltcl and plpe
NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit
function reads ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1425,7 +1673,7 @@ CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm
index picksplit function
NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching
allows an o ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1433,7 +1681,7 @@ CVE-2026-14679 (Stack buffer overflow in PostgreSQL
argument name matching allow
NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments
allows a ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1449,7 +1697,7 @@ CVE-2026-14681 (Improper enforcement of message integrity
in PostgreSQL GSSAPI s
NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object
owner t ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1457,7 +1705,7 @@ CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT()
deparse allows an object o
NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user
to direct ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1472,7 +1720,7 @@ CVE-2026-16238 (Type confusion in PostgreSQL
pg_restore_attribute_stats() allows
NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows
a user t ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1480,7 +1728,7 @@ CVE-2026-16239 (Type confusion in PostgreSQL
"portal"/cursor lifecycle allows a
NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server
administ ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1488,7 +1736,7 @@ CVE-2026-16241 (Integer underflow in PostgreSQL ECPG
allows a database server ad
NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a
user to d ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1496,7 +1744,7 @@ CVE-2026-18024 (Buffer over-read in PostgreSQL ascii()
SQL function allows a use
NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a
malicious s ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1504,7 +1752,7 @@ CVE-2026-18408 (Untrusted data inclusion in pg_dump in
PostgreSQL allows a malic
NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function
transform ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1982,7 +2230,7 @@ CVE-2026-53783 (rsync before3.5.0 contains a
time-of-check to time-of-use (TOCTO
CVE-2026-53786 (rsyncbefore 3.5.0contains a filter rule bypass vulnerability
that allo ...)
- rsync <unfixed>
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53798 (rsync tbefore 3.5.0contains a privilege confusion
vulnerability in the ...)
+CVE-2026-53798 (rsync before 3.5.0contains a privilege confusion vulnerability
in the ...)
- rsync <unfixed>
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53788 (rsync before 3.5.0contains a newline injection vulnerability
in the na ...)
@@ -16731,7 +16979,7 @@ CVE-2026-61547
- librabbitmq 0.17.0-1
NOTE:
https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
NOTE: Fixed by:
https://github.com/alanxz/rabbitmq-c/commit/02d278663f3a93db9fe4fb4e7e34dc96b83c107b
(v0.17.0)
-CVE-2026-58224 [The CTDB protocol has bounds checking issues]
+CVE-2026-58224 (A flaw was found in Samba's CTDB, the clustered database
service used ...)
{DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58224-advisory.html
@@ -20647,7 +20895,7 @@ CVE-2026-65482 (Contributor Cross Site Scripting (XSS)
in LA-Studio Element Kit
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65481 (Contributor Local File Inclusion in Vino <= 1.9 versions.)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-65480 (Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1
versions.)
+CVE-2026-65480 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65479 (Subscriber Broken Access Control in Reviewer <= 3.14.2
versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -35129,6 +35377,7 @@ CVE-2026-59946 (Composer is a dependency Manager for
the PHP language. Prior to
NOTE: Fixed by:
https://github.com/composer/composer/commit/502c6c4f699802d9cf464728b3e8a95674f919a0
(2.10.2)
NOTE: Fixed by:
https://github.com/composer/composer/commit/c50b1efd13ebd73f6dca19b31424c5a02bf93cc1
(2.2.29)
CVE-2026-59939 (httplib2 is a comprehensive HTTP client library for Python.
Prior to 0 ...)
+ {DSA-6441-1}
- python-httplib2 0.32.0-1
NOTE:
https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
NOTE: Fixed by:
https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427
(v0.32.0)
@@ -42931,6 +43180,7 @@ CVE-2026-13676 (fast-uri versions 2.3.1 through 3.1.2
and 4.0.0 fail to canonica
NOTE:
https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6
NOTE: Embedded fast-uri used and provided as node-fast-uri, starting
with forky
CVE-2026-13595 (A flaw was found in the libblkid library of util-linux. During
nested ...)
+ {DSA-6442-1}
- util-linux 2.42.2-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494101
NOTE:
https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c
(master)
@@ -52600,6 +52850,7 @@ CVE-2026-53615 [Integer Overflow or Wraparound in
libblkid/src/partitions/dos.c]
- util-linux <unfixed> (bug #1140197)
NOTE:
https://github.com/util-linux/util-linux/security/advisories/GHSA-h4rw-gv36-wmp5
CVE-2026-53614 [Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2
Environment Variable - nosuid/noexec Bypass in SUID mount(8)]
+ {DSA-6442-1}
- util-linux 2.42.2-1 (bug #1140196)
[bookworm] - util-linux <not-affected> (Vulnerable code introduced
later)
[bullseye] - util-linux <not-affected> (Vulnerable code introduced
later)
@@ -52607,11 +52858,13 @@ CVE-2026-53614 [Local Privilege Escalation via
LIBMOUNT_FORCE_MOUNT2 Environment
NOTE: Fixed by:
https://github.com/util-linux/util-linux/commit/31e37c1c7dcf25b76ccf41391fe934a75644c661
(v2.42.2)
NOTE: Fixed by:
https://github.com/util-linux/util-linux/commit/cc81bbcec598cb91f0eb8456282f33eed820ed5f
(v2.41.5)
CVE-2026-53613 [Local Privilege Escalation via TOCTOU in mount(8) - Target
Path Redirection]
+ {DSA-6442-1}
- util-linux 2.42.2-1 (bug #1140195)
NOTE:
https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g
NOTE: Fixed by:
https://github.com/util-linux/util-linux/commit/0d3d55975aa3492c62fd345eac38f41cd166c0b0
(v2.42.2)
NOTE: Fixed by:
https://github.com/util-linux/util-linux/commit/0b010025a0e429bc80355c94db86a843395d49e2
(v2.41.5)
CVE-2026-53612 [Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c
chmod/chown]
+ {DSA-6442-1}
- util-linux 2.42.2-1 (bug #1140194)
[bookworm] - util-linux <not-affected> (Vulnerable code introduced
later)
[bullseye] - util-linux <not-affected> (Vulnerable code introduced
later)
@@ -55632,7 +55885,7 @@ CVE-2026-6893 (A flaw was found in dracut. A remote
attacker on the adjacent net
[trixie] - dracut <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2459963
NOTE: https://github.com/dracut-ng/dracut/pull/2469
-CVE-2026-53472
+CVE-2026-53472 (A flaw was found in migration-planner. Insufficient validation
of the ...)
NOT-FOR-US: kubev2v/migration-planner
CVE-2026-9758 (Improper comparison with the certificates trusted list in S2OPC
allows ...)
NOT-FOR-US: S2OPC library
@@ -63608,7 +63861,7 @@ CVE-2026-46243 (In the Linux kernel, the following
vulnerability has been resolv
[bookworm] - linux 6.1.174-1
[bullseye] - linux 5.10.257-1
NOTE:
https://git.kernel.org/linus/3da1fdf4efbc490041eb4f836bf596201203f8f2 (7.1-rc5)
-CVE-2026-47192
+CVE-2026-47192 (kas is a setup tool for bitbake based projects. Starting in
version 4. ...)
- kas 5.3-1
[trixie] - kas <no-dsa> (Minor issue)
[bookworm] - kas <not-affected> (Vulnerable code not present)
@@ -63616,7 +63869,7 @@ CVE-2026-47192
NOTE:
https://github.com/siemens/kas/security/advisories/GHSA-4vqc-wpwg-vh7j
NOTE: Introduced with:
https://github.com/siemens/kas/commit/a2480fe59b6421eb96cf3bd86527ae6e412a331e
(4.8)
NOTE: Fixed by:
https://github.com/siemens/kas/commit/5b2114becfc154b16ef496d24f8c2191a2297f57
(5.3)
-CVE-2026-47191
+CVE-2026-47191 (kas is a setup tool for bitbake based projects. Prior to
version 5.3, ...)
- kas 5.3-1
[trixie] - kas <no-dsa> (Minor issue)
[bookworm] - kas <no-dsa> (Minor issue)
@@ -67544,7 +67797,7 @@ CVE-2026-41579 (runc is a CLI tool for spawning and
running containers according
NOTE: https://www.openwall.com/lists/oss-security/2026/06/13/2
NOTE:
https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47
NOTE: Fixed by:
https://github.com/opencontainers/runc/commit/864db8042dbb191028676f80addf8c35f348aee2
-CVE-2026-47766
+CVE-2026-47766 (crun is an open source OCI Container Runtime fully written in
C. Prior ...)
- crun 1.28-1
[trixie] - crun <no-dsa> (Minor issue)
[bookworm] - crun <no-dsa> (Minor issue)
@@ -74933,7 +75186,7 @@ CVE-2026-6479 (Uncontrolled recursion in PostgreSQL SSL
and GSS negotiation allo
- postgresql-13 <removed>
NOTE:
https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
CVE-2026-6473 (Integer wraparound in multiple PostgreSQL server features
allows an un ...)
- {DSA-6438-1 DSA-6270-1 DSA-6269-1 DLA-4646-1}
+ {DSA-6438-1 DSA-6270-1 DSA-6269-1 DLA-4740-1 DLA-4646-1}
- postgresql-18 18.4-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -101633,6 +101886,7 @@ CVE-2024-40849 (A race condition was addressed with
additional validation. This
CVE-2023-7342 (HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a
privil ...)
NOT-FOR-US: HiSecOS web server
CVE-2026-27456 (util-linux is a random collection of Linux utilities. Prior to
version ...)
+ {DSA-6442-1}
- util-linux 2.42-1
[bookworm] - util-linux <no-dsa> (Minor issue)
[bullseye] - util-linux <postponed> (Minor issue)
@@ -148244,7 +148498,7 @@ CVE-2025-14633 (The F70 Lead Document Download plugin
for WordPress is vulnerabl
NOT-FOR-US: WordPress plugin
CVE-2025-14591 (In Delphix Continuous Compliance version 2025.3.0 and later,
following ...)
NOT-FOR-US: Perforce
-CVE-2025-14300 (The HTTPS service on Tapo C200 V3 exposes a connectAP
interface withou ...)
+CVE-2025-14300 (The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5
exposes a ...)
NOT-FOR-US: TP-Link
CVE-2025-14299 (The HTTPS server on Tapo C200 V3 does not properly validate
the Conten ...)
NOT-FOR-US: TP-Link
@@ -195154,7 +195408,7 @@ CVE-2025-8715 (Improper neutralization of newlines in
pg_dump in PostgreSQL allo
NOTE: https://www.postgresql.org/support/security/CVE-2025-8715/
NOTE:
https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=70693c645f6e490b9ed450e8611e94ab7af3aad2
(master)
CVE-2025-8714 (Untrusted data inclusion in pg_dump in PostgreSQL allows a
malicious s ...)
- {DLA-4273-1}
+ {DLA-4740-1 DLA-4273-1}
- postgresql-17 17.6-1
[trixie] - postgresql-17 17.6-0+deb13u1
- postgresql-15 <removed>
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1885a5c515eee894de4f43520da6319cf9aedda9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1885a5c515eee894de4f43520da6319cf9aedda9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits