Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2aed2f37 by Salvatore Bonaccorso at 2026-08-16T15:07:58+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4942,10 +4942,10 @@ CVE-2026-49826 (Concourse is a container-based
automation system written in Go.
CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to
version 1.4 ...)
NOT-FOR-US: erlang_quic
CVE-2026-49282 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
- - capstone <unfixed>
+ - capstone <unfixed> (bug #1144518)
NOTE:
https://github.com/capstone-engine/capstone/security/advisories/GHSA-jrw4-wj52-2vw8
CVE-2026-49263 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
- - capstone <unfixed>
+ - capstone <unfixed> (bug #1144519)
NOTE:
https://github.com/capstone-engine/capstone/security/advisories/GHSA-5m9f-vqcm-g5pr
CVE-2026-48528 (Metacat is data repository software that helps researchers
preserve, s ...)
NOT-FOR-US: Metacat
@@ -7794,7 +7794,7 @@ CVE-2026-55676 (Malcolm is a network traffic analysis
tool suite. The file-uploa
CVE-2026-48813 (Flawfinder is a a static analysis tool for finding
vulnerabilities in ...)
NOT-FOR-US: Flawfinder
CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO
realtime c ...)
- - python-engineio <unfixed>
+ - python-engineio <unfixed> (bug #1144515)
NOTE:
https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
NOTE: Fixed by:
https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e
(v5.16.4)
CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0
allow a lo ...)
@@ -9335,11 +9335,11 @@ CVE-2026-50058 (A vulnerability has been identified in
Solid Edge SE2025 (All ve
CVE-2026-49179 (Improper neutralization of special elements used in a command
('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO
realtime c ...)
- - python-engineio <unfixed>
+ - python-engineio <unfixed> (bug #1144516)
NOTE:
https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9
TODO: checking upstream commit fixing issue, confusing infomation
advisory claims both 4.13.2 and 4.13.5 to fix issue
CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO
realtime c ...)
- - python-engineio <unfixed>
+ - python-engineio <unfixed> (bug #1144517)
NOTE:
https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5
CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the
open-source datab ...)
NOT-FOR-US: Turso CLI
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aed2f375227a9b36c62458ec91b6b283feb7eb6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aed2f375227a9b36c62458ec91b6b283feb7eb6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits