Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
7fa21ab2 by Moritz Muehlenhoff at 2026-08-23T20:21:48+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -953,6 +953,7 @@ CVE-2026-59989 (Phalcon is a high-performance, full-stack
PHP framework. In 5.15
NOT-FOR-US: Phalcon
CVE-2026-55185 (Miniflux 2 is an open source feed reader. Prior to 2.3.1,
IsRelativePa ...)
- miniflux 2.3.2-1
+ [trixie] - miniflux <no-dsa> (Minor issue)
NOTE:
https://github.com/miniflux/v2/security/advisories/GHSA-m999-j542-5w3r
NOTE: https://github.com/miniflux/v2/pull/4362
NOTE: Fixed by:
https://github.com/miniflux/v2/commit/c896bafdaa19c3f280b02b1059f84706495f1949
(2.3.1)
@@ -2261,7 +2262,9 @@ CVE-2026-49996 (SecureDrop Client is a desktop app for
journalists to securely c
NOT-FOR-US: SecureDrop Client
CVE-2026-49825 (lxml is a library for processing XML and HTML in the Python
language. ...)
- lxml <unfixed>
+ [trixie] - lxml <no-dsa> (Minor issue)
- lxml-html-clean <unfixed>
+ [trixie] - lxml-html-clean <no-dsa> (Minor issue)
NOTE:
https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f
NOTE: Fixed by:
https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0
(lxml-6.1.1)
NOTE: lxml-html-clean was split out of lxml in 5.2.0
@@ -7052,6 +7055,7 @@ CVE-2026-54570 (AngleSharp is a .NET library for parsing
angle bracket based hyp
NOT-FOR-US: AngleSharp
CVE-2026-54552 (sh provides Python process launching. Prior to 2.2.4, the _uid
option ...)
- python-sh <unfixed>
+ [trixie] - python-sh <no-dsa> (Minor issue)
NOTE:
https://github.com/amoffat/sh/security/advisories/GHSA-q38v-wp89-2w55
NOTE: https://github.com/amoffat/sh/pull/776
NOTE: Fixed by:
https://github.com/amoffat/sh/commit/3d855daba91f87a089b490c0d1cf1df3faace2f1
(2.2.4)
@@ -14203,6 +14207,7 @@ CVE-2026-73567 (sm-crypto provides JavaScript
implementations of the Chinese cry
NOT-FOR-US: sm-crypto
CVE-2026-73566 (node-tar is a tar archive manipulation library for Node.js.
Prior to 7 ...)
- node-tar 7.5.22+~4.0.1-1
+ [trixie] - node-tar <no-dsa> (Minor issue)
NOTE:
https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m
NOTE: Fixed
by:https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a
(v7.5.21)
CVE-2026-73565 (@hono/node-server allows running the Hono application on
Node.js. From ...)
@@ -44682,10 +44687,12 @@ CVE-2026-59835 (A exposure of resource to wrong
sphere vulnerability in Fortinet
NOT-FOR-US: Fortinet
CVE-2026-59733 (Rclone is a command-line program to sync files and directories
to and ...)
- rclone <unfixed> (bug #1142269)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d
(v1.74.4)
CVE-2026-59732 (Rclone is a command-line program to sync files and directories
to and ...)
- rclone <unfixed> (bug #1142269)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c
(v1.74.4)
CVE-2026-59674 (A UNIX Symbolic Link (Symlink) Following vulnerability in
openSUSE Tum ...)
@@ -45212,6 +45219,7 @@ CVE-2026-54684 (jadx is a Dex to Java decompiler. From
1.5.2 to 1.5.5, a malicio
NOT-FOR-US: jadx
CVE-2026-54572 (Rclone is a command-line program to sync files and directories
to and ...)
- rclone <unfixed> (bug #1142269)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265
(v1.74.4)
CVE-2026-54429 (A vulnerability has been identified in SIMATIC S7-PLCSIM
Advanced (All ...)
@@ -751231,6 +751239,7 @@ CVE-2018-1000645 (LibreHealthIO lh-ehr version
<REL-2.0.0 contains an Authentica
NOT-FOR-US: LibreHealthIO
CVE-2018-1000644 (Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML
External Enti ...)
- rdf4j <unfixed> (bug #1144952)
+ [trixie] - rdf4j <no-dsa> (Minor issue)
NOTE: https://github.com/eclipse-rdf4j/rdf4j/issues/1056
NOTE: Fixed by:
https://github.com/eclipse-rdf4j/rdf4j/commit/50f2f51950227a4ec595a2922d81da487aba5135
(2.4.1)
NOTE: When fixing this issue make sure to make the fix complete and not
open CVE-2026-15803
=====================================
data/dsa-needed.txt
=====================================
@@ -116,6 +116,8 @@ python-msgpack
--
rabbitmq-server
--
+rails
+--
redis
--
roundcube
@@ -146,6 +148,8 @@ sogo
--
starlette
--
+suricata-update
+--
tomcat10
--
tomcat11
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7fa21ab257ba5cdffbb0783f6e15bb07918e887d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7fa21ab257ba5cdffbb0783f6e15bb07918e887d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits