Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7fa21ab2 by Moritz Muehlenhoff at 2026-08-23T20:21:48+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -953,6 +953,7 @@ CVE-2026-59989 (Phalcon is a high-performance, full-stack 
PHP framework. In 5.15
        NOT-FOR-US: Phalcon
 CVE-2026-55185 (Miniflux 2 is an open source feed reader. Prior to 2.3.1, 
IsRelativePa ...)
        - miniflux 2.3.2-1
+       [trixie] - miniflux <no-dsa> (Minor issue)
        NOTE: 
https://github.com/miniflux/v2/security/advisories/GHSA-m999-j542-5w3r
        NOTE: https://github.com/miniflux/v2/pull/4362
        NOTE: Fixed by: 
https://github.com/miniflux/v2/commit/c896bafdaa19c3f280b02b1059f84706495f1949 
(2.3.1)
@@ -2261,7 +2262,9 @@ CVE-2026-49996 (SecureDrop Client is a desktop app for 
journalists to securely c
        NOT-FOR-US: SecureDrop Client
 CVE-2026-49825 (lxml is a library for processing XML and HTML in the Python 
language.  ...)
        - lxml <unfixed>
+       [trixie] - lxml <no-dsa> (Minor issue)
        - lxml-html-clean <unfixed>
+       [trixie] - lxml-html-clean <no-dsa> (Minor issue)
        NOTE: 
https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f
        NOTE: Fixed by: 
https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0 
(lxml-6.1.1)
        NOTE: lxml-html-clean was split out of lxml in 5.2.0
@@ -7052,6 +7055,7 @@ CVE-2026-54570 (AngleSharp is a .NET library for parsing 
angle bracket based hyp
        NOT-FOR-US: AngleSharp
 CVE-2026-54552 (sh provides Python process launching. Prior to 2.2.4, the _uid 
option  ...)
        - python-sh <unfixed>
+       [trixie] - python-sh <no-dsa> (Minor issue)
        NOTE: 
https://github.com/amoffat/sh/security/advisories/GHSA-q38v-wp89-2w55
        NOTE: https://github.com/amoffat/sh/pull/776
        NOTE: Fixed by: 
https://github.com/amoffat/sh/commit/3d855daba91f87a089b490c0d1cf1df3faace2f1 
(2.2.4)
@@ -14203,6 +14207,7 @@ CVE-2026-73567 (sm-crypto provides JavaScript 
implementations of the Chinese cry
        NOT-FOR-US: sm-crypto
 CVE-2026-73566 (node-tar is a tar archive manipulation library for Node.js. 
Prior to 7 ...)
        - node-tar 7.5.22+~4.0.1-1
+       [trixie] - node-tar <no-dsa> (Minor issue)
        NOTE: 
https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m
        NOTE: Fixed 
by:https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a
 (v7.5.21)
 CVE-2026-73565 (@hono/node-server allows running the Hono application on 
Node.js. From ...)
@@ -44682,10 +44687,12 @@ CVE-2026-59835 (A exposure of resource to wrong 
sphere vulnerability in Fortinet
        NOT-FOR-US: Fortinet
 CVE-2026-59733 (Rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1142269)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d
 (v1.74.4)
 CVE-2026-59732 (Rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1142269)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c
 (v1.74.4)
 CVE-2026-59674 (A UNIX Symbolic Link (Symlink) Following vulnerability in 
openSUSE Tum ...)
@@ -45212,6 +45219,7 @@ CVE-2026-54684 (jadx is a Dex to Java decompiler. From 
1.5.2 to 1.5.5, a malicio
        NOT-FOR-US: jadx
 CVE-2026-54572 (Rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1142269)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265
 (v1.74.4)
 CVE-2026-54429 (A vulnerability has been identified in SIMATIC S7-PLCSIM 
Advanced (All ...)
@@ -751231,6 +751239,7 @@ CVE-2018-1000645 (LibreHealthIO lh-ehr version 
<REL-2.0.0 contains an Authentica
        NOT-FOR-US: LibreHealthIO
 CVE-2018-1000644 (Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML 
External Enti ...)
        - rdf4j <unfixed> (bug #1144952)
+       [trixie] - rdf4j <no-dsa> (Minor issue)
        NOTE: https://github.com/eclipse-rdf4j/rdf4j/issues/1056
        NOTE: Fixed by: 
https://github.com/eclipse-rdf4j/rdf4j/commit/50f2f51950227a4ec595a2922d81da487aba5135
 (2.4.1)
        NOTE: When fixing this issue make sure to make the fix complete and not 
open CVE-2026-15803


=====================================
data/dsa-needed.txt
=====================================
@@ -116,6 +116,8 @@ python-msgpack
 --
 rabbitmq-server
 --
+rails
+--
 redis
 --
 roundcube
@@ -146,6 +148,8 @@ sogo
 --
 starlette
 --
+suricata-update
+--
 tomcat10
 --
 tomcat11



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7fa21ab257ba5cdffbb0783f6e15bb07918e887d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7fa21ab257ba5cdffbb0783f6e15bb07918e887d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to