Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d74812c by Chris Lamb at 2026-08-22T11:04:33-07:00
Triage CVE-2025-30153, CVE-2026-73501, CVE-2026-73502, CVE-2026-76905 & 
CVE-2026-77354 in golang-github-getkin-kin-openapi for bookworm and bullseye 
LTS.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -619,6 +619,8 @@ CVE-2026-77413 (JSONata is a JSON query and transformation 
language. Prior to 1.
        NOT-FOR-US: jsonata-js
 CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 
0.124.0 u ...)
        - golang-github-getkin-kin-openapi <unfixed>
+       [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
+       [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-xhj3-7xw9-vr34
        NOTE: https://github.com/getkin/kin-openapi/pull/923
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/1223a0f215d2cf9beb2d9eb9ea2649d001c21388
 (v0.142.0)
@@ -637,6 +639,8 @@ CVE-2026-77000 (The WP Social Media Login WordPress plugin 
through 1.0.6 does no
        NOT-FOR-US: WordPress plugin
 CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From 
0.10.0 un ...)
        - golang-github-getkin-kin-openapi <unfixed>
+       [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
+       [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-mmfr-pmjx-hw9w
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/1d0a337c9b1570fab283be8a04c8af6e43b9a22c
 (v0.141.0)
 CVE-2026-76904 (GeoTools is an open source Java library that provides tools 
for geospa ...)
@@ -6463,6 +6467,8 @@ CVE-2026-73692
 CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From 
0.2.0 unt ...)
        - golang-github-getkin-kin-openapi <unfixed> (bug #1144951)
        [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
+       [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
+       [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-jpcw-4wr7-c3vq
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/68ac2affa325514d7d6e731204d6a1edf6bdff64
 (v0.144.0)
 CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
@@ -14786,6 +14792,8 @@ CVE-2026-73519 (WolfStack before 25.9.2 contains a 
hard-coded cluster-authentica
 CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior 
to 0.144 ...)
        - golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
        [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
+       [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
+       [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da
 (v0.144.0)
 CVE-2026-73500 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
@@ -256511,6 +256519,8 @@ CVE-2025-30154 (reviewdog/action-setup is a GitHub 
action that installs reviewdo
        NOT-FOR-US: reviewdog/action-setup GitHub action
 CVE-2025-30153 (kin-openapi is a Go project for handling OpenAPI files. Prior 
to 0.131 ...)
        - golang-github-getkin-kin-openapi 0.135.0-1
+       [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
+       [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-wq9g-9vfc-cfq9
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/67f0b233ffc01332f7d993f79490fbea5f4455f1
 (v0.131.0)
 CVE-2025-30152 (The Syliud PayPal Plugin is the Sylius Core Team\u2019s plugin 
for the ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d74812c9deef653fca19cffde33a074e646b4d9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d74812c9deef653fca19cffde33a074e646b4d9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to