Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4d74812c by Chris Lamb at 2026-08-22T11:04:33-07:00
Triage CVE-2025-30153, CVE-2026-73501, CVE-2026-73502, CVE-2026-76905 &
CVE-2026-77354 in golang-github-getkin-kin-openapi for bookworm and bullseye
LTS.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -619,6 +619,8 @@ CVE-2026-77413 (JSONata is a JSON query and transformation
language. Prior to 1.
NOT-FOR-US: jsonata-js
CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From
0.124.0 u ...)
- golang-github-getkin-kin-openapi <unfixed>
+ [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
+ [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-xhj3-7xw9-vr34
NOTE: https://github.com/getkin/kin-openapi/pull/923
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/1223a0f215d2cf9beb2d9eb9ea2649d001c21388
(v0.142.0)
@@ -637,6 +639,8 @@ CVE-2026-77000 (The WP Social Media Login WordPress plugin
through 1.0.6 does no
NOT-FOR-US: WordPress plugin
CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From
0.10.0 un ...)
- golang-github-getkin-kin-openapi <unfixed>
+ [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
+ [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-mmfr-pmjx-hw9w
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/1d0a337c9b1570fab283be8a04c8af6e43b9a22c
(v0.141.0)
CVE-2026-76904 (GeoTools is an open source Java library that provides tools
for geospa ...)
@@ -6463,6 +6467,8 @@ CVE-2026-73692
CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From
0.2.0 unt ...)
- golang-github-getkin-kin-openapi <unfixed> (bug #1144951)
[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
+ [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
+ [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-jpcw-4wr7-c3vq
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/68ac2affa325514d7d6e731204d6a1edf6bdff64
(v0.144.0)
CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for
everyday w ...)
@@ -14786,6 +14792,8 @@ CVE-2026-73519 (WolfStack before 25.9.2 contains a
hard-coded cluster-authentica
CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior
to 0.144 ...)
- golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
+ [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
+ [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da
(v0.144.0)
CVE-2026-73500 (etcd is a distributed key-value store for the data of a
distributed sy ...)
@@ -256511,6 +256519,8 @@ CVE-2025-30154 (reviewdog/action-setup is a GitHub
action that installs reviewdo
NOT-FOR-US: reviewdog/action-setup GitHub action
CVE-2025-30153 (kin-openapi is a Go project for handling OpenAPI files. Prior
to 0.131 ...)
- golang-github-getkin-kin-openapi 0.135.0-1
+ [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
+ [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-wq9g-9vfc-cfq9
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/67f0b233ffc01332f7d993f79490fbea5f4455f1
(v0.131.0)
CVE-2025-30152 (The Syliud PayPal Plugin is the Sylius Core Team\u2019s plugin
for the ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d74812c9deef653fca19cffde33a074e646b4d9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d74812c9deef653fca19cffde33a074e646b4d9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits