Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ed86498b by Moritz Muehlenhoff at 2026-08-17T13:15:49+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -5009,6 +5009,7 @@ CVE-2026-73107
REJECTED
CVE-2026-73051 (actix-http versions before 3.12.1 contain an HTTP request
smuggling vu ...)
- rust-actix-http 3.13.1-1
+ [trixie] - rust-actix-http <no-dsa> (Minor issue)
NOTE:
https://github.com/actix/actix-web/security/advisories/GHSA-xhj4-vrgc-hr34
CVE-2026-73049 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
NOT-FOR-US: SiYuan
@@ -5116,9 +5117,11 @@ CVE-2026-49457 (erlang_quic is a pure Erlang QUIC
implementation. Prior to versi
NOT-FOR-US: erlang_quic
CVE-2026-49282 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
- capstone <unfixed> (bug #1144518)
+ [trixie] - capstone <no-dsa> (Minor issue)
NOTE:
https://github.com/capstone-engine/capstone/security/advisories/GHSA-jrw4-wj52-2vw8
CVE-2026-49263 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
- capstone <unfixed> (bug #1144519)
+ [trixie] - capstone <no-dsa> (Minor issue)
NOTE:
https://github.com/capstone-engine/capstone/security/advisories/GHSA-5m9f-vqcm-g5pr
CVE-2026-48528 (Metacat is data repository software that helps researchers
preserve, s ...)
NOT-FOR-US: Metacat
@@ -5282,6 +5285,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0221]
NOTE: https://github.com/smol-rs/event-listener/pull/163
CVE-2026-12876
- nltk <unfixed> (bug #1144456)
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf
CVE-2026-12841
- nltk 3.10.3-1
@@ -5303,6 +5307,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0256]
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0256.html
CVE-2026-XXXX [RUSTSEC-2026-0255]
- rust-sized-chunks <unfixed> (bug #1144399)
+ [trixie] - rust-sized-chunks <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0255.html
CVE-2026-8715 (Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an
arbitrary ...)
NOT-FOR-US: Vault Secrets Operator
@@ -7904,6 +7909,7 @@ CVE-2026-73230 (Ente provides end-to-end encrypted cloud
services and security t
NOT-FOR-US: Ente
CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for
building ...)
- djangorestframework <unfixed> (bug #1144350)
+ [trixie] - djangorestframework <no-dsa> (Minor issue)
NOTE:
https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
NOTE: https://github.com/encode/django-rest-framework/pull/10012
NOTE: Fixed by:
https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e
(3.17.2)
@@ -8285,6 +8291,7 @@ CVE-2026-9214 (Insufficient input validation
vulnerability in the NETGEAR R7000
NOT-FOR-US: Netgear
CVE-2026-73228 (Django REST framework is a toolkit for building Web APIs.
Prior to 3.1 ...)
- djangorestframework <unfixed> (bug #1144350)
+ [trixie] - djangorestframework <no-dsa> (Minor issue)
NOTE:
https://github.com/encode/django-rest-framework/security/advisories/GHSA-2m8g-3cmr-wg3w
NOTE: https://github.com/encode/django-rest-framework/pull/10013
NOTE: Fixed by:
https://github.com/encode/django-rest-framework/commit/2912dc98042f78e27636551fc22eeaf10f725fdd
(3.17.2)
@@ -11073,6 +11080,7 @@ CVE-2026-18370 (entr is vulnerable to Heap-based buffer
overflow in run_utility(
NOTE: Doesn't cross any security boundary
CVE-2026-16742 (systemd-homed contains a local privilege escalation bug via
arbitrary ...)
- systemd 261.2-1
+ [trixie] - systemd <no-dsa> (Minor issue)
NOTE:
https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv
NOTE: Fixed by:
https://github.com/systemd/systemd/commit/d392d17143423e7af0cdb5bd0f64b43da8952662
(v261.2)
NOTE: Fixed by:
https://github.com/systemd/systemd/commit/a7bce5b2052bdb098ad0729768c72e1df9a86adc
(v261.2)
@@ -17627,6 +17635,7 @@ CVE-2026-67322 (GitPython before 3.1.52 is vulnerable
to environment-variable ex
NOTE:
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573
CVE-2026-67321 (axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0
contain a ...)
- node-axios 1.18.0-1
+ [trixie] - node-axios <no-dsa> (Minor issue)
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-hcpx-6fm6-wx23
CVE-2026-67320 (axios in a Node.js deployment using the HTTP adapter can route
request ...)
- node-axios 1.18.0-1
@@ -17636,6 +17645,7 @@ CVE-2026-67320 (axios in a Node.js deployment using the
HTTP adapter can route r
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-gcfj-64vw-6mp9
CVE-2026-67319 (axios before 0.33.0 (and 1.x before 1.18.0) can consume
inherited prop ...)
- node-axios 1.18.0-1
+ [trixie] - node-axios <no-dsa> (Minor issue)
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-7q8q-rj6j-mhjq
CVE-2026-67318 (axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce
the con ...)
- node-axios 1.18.0-1
@@ -17645,9 +17655,11 @@ CVE-2026-67318 (axios versions >=1.13.0 (Node.js HTTP
adapter) fail to enforce t
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-mwf2-3pr3-8698
CVE-2026-67317 (axios versions 1.7.0 before 1.18.0 fail to enforce
maxBodyLength for W ...)
- node-axios 1.18.0-1
+ [trixie] - node-axios <no-dsa> (Minor issue)
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-jqh4-m9w3-8hp9
CVE-2026-67316 (axios is vulnerable to read-side prototype-pollution gadgets
that can ...)
- node-axios 1.18.0-1
+ [trixie] - node-axios <no-dsa> (Minor issue)
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-mmx7-hfxf-jppx
CVE-2026-67315 (axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0
fail to r ...)
- node-axios 1.18.0-1
@@ -17663,9 +17675,11 @@ CVE-2026-67314 (axios versions >=1.15.2 and <1.18.0
contain prototype-pollution
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-xj6q-8x83-jv6g
CVE-2026-67313 (axios versions 0.28.0 and later contain uncontrolled recursion
in form ...)
- node-axios 1.18.0-1
+ [trixie] - node-axios <no-dsa> (Minor issue)
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-42h9-826w-cgv3
CVE-2026-67312 (axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before
1.18.0 ...)
- node-axios 1.18.0-1
+ [trixie] - node-axios <no-dsa> (Minor issue)
NOTE:
https://github.com/axios/axios/security/advisories/GHSA-pmv8-rq9r-6j72
CVE-2026-67311 (Budibase before 3.38.1 contains a server-side request forgery
vulnerab ...)
NOT-FOR-US: Budibase
=====================================
data/dsa-needed.txt
=====================================
@@ -32,6 +32,8 @@ containerd
--
cups
--
+designate
+--
dulwich
--
erlang
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed86498b499935b777b21e92bc74636968b2b5bd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed86498b499935b777b21e92bc74636968b2b5bd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits