Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6666622f by Salvatore Bonaccorso at 2026-08-21T07:26:50+02:00
Add more libevent issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -334,7 +334,9 @@ CVE-2026-64777 (A malicious builder peer may be able to
request an in-context fi
CVE-2026-63654 (Frappe is a full-stack web application framework. In version
16.31.0 a ...)
NOT-FOR-US: Frappe
CVE-2026-63495 (Libevent is an event notification library. From
2.2.0-alpha-dev until ...)
- TODO: check
+ - libevent <not-affected> (Vulnerable code not present)
+ NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-qx89-wf2v-vgmx
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/291c4d1cd75695e898030ebd5c4ddf26c094077b
(release-2.2.2-alpha)
CVE-2026-63490 (Handlebars.java provides logic-less and semantic Mustache
templates wi ...)
TODO: check
CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests
defined ...)
@@ -343,13 +345,25 @@ CVE-2026-63481 (Hurl is a command line tool that runs and
tests HTTP requests de
NOTE: https://github.com/Orange-OpenSource/hurl/pull/5119
NOTE: Fixed by:
https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e
CVE-2026-63388 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72
(release-2.1.13-stable)
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9
(release-2.2.2-alpha)
CVE-2026-63387 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/377b9022c3ac61aa4540b5dc4b70c60bf74c663d
(release-2.1.13-stable)
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/9877a7205ea024d0120effb040e1b8e034435407
(release-2.2.2-alpha)
CVE-2026-63385 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2
(release-2.1.13-stable)
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0
(release-2.2.2-alpha)
CVE-2026-63384 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
- TODO: check
+ - libevent 2.1.13-stable-1
+ NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416
(release-2.1.13-stable)
+ NOTE: Fixed by:
https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda
(release-2.2.2-alpha)
CVE-2026-63383 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6666622ff163f5953248c9b84c0123ee78037b11
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6666622ff163f5953248c9b84c0123ee78037b11
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits