Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2aed2f37 by Salvatore Bonaccorso at 2026-08-16T15:07:58+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4942,10 +4942,10 @@ CVE-2026-49826 (Concourse is a container-based 
automation system written in Go.
 CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to 
version 1.4 ...)
        NOT-FOR-US: erlang_quic
 CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 
6.0.0-Alpha9, Ca ...)
-       - capstone <unfixed>
+       - capstone <unfixed> (bug #1144518)
        NOTE: 
https://github.com/capstone-engine/capstone/security/advisories/GHSA-jrw4-wj52-2vw8
 CVE-2026-49263 (Capstone is a disassembly framework. Prior to version 
6.0.0-Alpha9, Ca ...)
-       - capstone <unfixed>
+       - capstone <unfixed> (bug #1144519)
        NOTE: 
https://github.com/capstone-engine/capstone/security/advisories/GHSA-5m9f-vqcm-g5pr
 CVE-2026-48528 (Metacat is data repository software that helps researchers 
preserve, s ...)
        NOT-FOR-US: Metacat
@@ -7794,7 +7794,7 @@ CVE-2026-55676 (Malcolm is a network traffic analysis 
tool suite. The file-uploa
 CVE-2026-48813 (Flawfinder is a a static analysis tool for finding 
vulnerabilities in  ...)
        NOT-FOR-US: Flawfinder
 CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO 
realtime c ...)
-       - python-engineio <unfixed>
+       - python-engineio <unfixed> (bug #1144515)
        NOTE: 
https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
        NOTE: Fixed by: 
https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e
 (v5.16.4)
 CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 
allow a lo ...)
@@ -9335,11 +9335,11 @@ CVE-2026-50058 (A vulnerability has been identified in 
Solid Edge SE2025 (All ve
 CVE-2026-49179 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO 
realtime c ...)
-       - python-engineio <unfixed>
+       - python-engineio <unfixed> (bug #1144516)
        NOTE: 
https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9
        TODO: checking upstream commit fixing issue, confusing infomation 
advisory claims both 4.13.2 and 4.13.5 to fix issue
 CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO 
realtime c ...)
-       - python-engineio <unfixed>
+       - python-engineio <unfixed> (bug #1144517)
        NOTE: 
https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5
 CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the 
open-source datab ...)
        NOT-FOR-US: Turso CLI



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aed2f375227a9b36c62458ec91b6b283feb7eb6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aed2f375227a9b36c62458ec91b6b283feb7eb6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to