Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 49685a66 by Salvatore Bonaccorso at 2026-08-18T21:38:40+02:00 Add CVE-2026-75926/hugo - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,5 +1,13 @@ CVE-2026-75926 (Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permis ...) - TODO: check + - hugo <unfixed> + [trixie] - hugo <not-affected> (Vulnerable code introduced later) + [bookworm] - hugo <not-affected> (Vulnerable code introduced later) + [bullseye] - hugo <not-affected> (Vulnerable code introduced later) + NOTE: https://github.com/gohugoio/hugo/issues/15178 + NOTE: https://github.com/gohugoio/hugo/issues/15171 + NOTE: Introduced with: https://github.com/gohugoio/hugo/commit/d65af84d1572326057a9a55e26beb0cee784698a (v0.161.1) + NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/8a55df7af2e6da31297245cc54fa2e3b521d93e8 (v0.165.0) + TODO: double check introducing commit, as CVE entry claims only starting 0.162.0 CVE-2026-75924 (A flaw was found in managed-serviceaccount. A compromised addon-manage ...) TODO: check CVE-2026-75915 (CodeWhale versions before 0.8.64 contain an environment variable expos ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49685a663e500a3a400df33ce2c40fdadcc451a1 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49685a663e500a3a400df33ce2c40fdadcc451a1 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
