Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f24eb1a1 by Salvatore Bonaccorso at 2026-08-24T22:49:27+02:00
Add new fast-uri issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -240,7 +240,12 @@ CVE-2026-76830
 CVE-2026-76829
        REJECTED
 CVE-2026-76172 (fast-uri is a URI parser for Node.js. During parsing it runs a 
legacy  ...)
-       TODO: check
+       - node-ajv <unfixed>
+       [trixie] - node-ajv <no-dsa> (Minor issue)
+       [bookworm] - node-ajv <not-affected> (fast-uri not present)
+       [bullseye] - node-ajv <not-affected> (fast-uri not present)
+       NOTE: 
https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp
+       NOTE: Embedded fast-uri used and provided as node-fast-uri, starting 
with forky
 CVE-2026-76073 (Label Studio does not scope the annotation detail endpoint to 
the requ ...)
        NOT-FOR-US: Label Studio
 CVE-2026-76072 (The Continue CLI applies an incomplete denylist as its only 
barrier to ...)
@@ -254,11 +259,26 @@ CVE-2026-76055 (Improper Neutralization of Special 
Elements used in an OS Comman
 CVE-2026-76054 (Invocation of Process Using Visible Sensitive Information in 
Black Duc ...)
        NOT-FOR-US: Black Duck
 CVE-2026-75975 (fast-uri is a URI parser for Node.js. Its custom parser for 
bracketed  ...)
-       TODO: check
+       - node-ajv <unfixed>
+       [trixie] - node-ajv <no-dsa> (Minor issue)
+       [bookworm] - node-ajv <not-affected> (fast-uri not present)
+       [bullseye] - node-ajv <not-affected> (fast-uri not present)
+       NOTE: 
https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc
+       NOTE: Embedded fast-uri used and provided as node-fast-uri, starting 
with forky
 CVE-2026-75931 (fast-uri is a URI parser for Node.js. It canonicalizes a host 
to its A ...)
-       TODO: check
+       - node-ajv <unfixed>
+       [trixie] - node-ajv <no-dsa> (Minor issue)
+       [bookworm] - node-ajv <not-affected> (fast-uri not present)
+       [bullseye] - node-ajv <not-affected> (fast-uri not present)
+       NOTE: 
https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8
+       NOTE: Embedded fast-uri used and provided as node-fast-uri, starting 
with forky
 CVE-2026-75899 (fast-uri is a URI parser for Node.js. It decodes percent 
escapes in a  ...)
-       TODO: check
+       - node-ajv <unfixed>
+       [trixie] - node-ajv <no-dsa> (Minor issue)
+       [bookworm] - node-ajv <not-affected> (fast-uri not present)
+       [bullseye] - node-ajv <not-affected> (fast-uri not present)
+       NOTE: 
https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf
+       NOTE: Embedded fast-uri used and provided as node-fast-uri, starting 
with forky
 CVE-2026-75371 (An integer handling flaw in the cobs_decode function of 
SpaceDot Acube ...)
        NOT-FOR-US: SpaceDot AcubeSAT OBC software
 CVE-2026-75370 (An out-of-bounds read/write vulnerability in the 
MessageParser::parseE ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f24eb1a10781386a0f0f50a7b94dd9196d97bdda

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f24eb1a10781386a0f0f50a7b94dd9196d97bdda
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to