Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
83f06975 by Moritz Muehlenhoff at 2026-08-25T21:38:31+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -603,15 +603,19 @@ CVE-2026-78685 (Medical Practice Management System
developed by Le-yan has a Rem
NOT-FOR-US: Medical Practice Management System
CVE-2026-78683 (NLTK before 3.10.0 (affected versions <=3.9.4) contains an
unsafe pick ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-rhp5-r9x4-f5g2
CVE-2026-78682 (NLTK before 3.10.3 contains a server-side request forgery
vulnerabilit ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-6ww7-3frv-cqxh
CVE-2026-78681 (NLTK versions before 3.10.3 use xml.etree.ElementTree to parse
XML in ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-97qj-x29f-37w7
CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute
paths when ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-6hwm-xvph-95vm
CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read
vulnerability ...)
- python-git <unfixed>
@@ -2343,6 +2347,7 @@ CVE-2026-XXXX [OpenZFS Linux open zpool manipulation and
escapes via unprivilege
NOTE: https://github.com/openzfs/zfs/pull/18959
CVE-2026-77682 [Use a user message to trigger form autofill]
- epiphany-browser <unfixed> (bug #1145177)
+ [trixie] - epiphany-browser <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2147
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/epiphany/-/commit/e85444e03490cff1584251028a11d5dfeb3accac
(50.6)
CVE-2026-66786
@@ -3646,6 +3651,7 @@ CVE-2026-64960 (ATutor Gameme module allows users to
upload files of any type an
NOT-FOR-US: ATutor
CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems.
Prior to 2. ...)
- nix <unfixed> (bug #1145021)
+ [trixie] - nix <no-dsa> (Minor issue)
NOTE:
https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f
NOTE: https://github.com/NixOS/nix/pull/15401
NOTE: Fixed by:
https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390
(2.35.0)
@@ -9048,6 +9054,7 @@ CVE-2026-66795 (A flaw was found in the
managedcluster-import-controller. The Ce
NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
CVE-2026-65976 (Deskflow is a keyboard and mouse sharing app. From 1.17.0
until contin ...)
- deskflow <unfixed> (bug #1145169)
+ [trixie] - deskflow <no-dsa> (Minor issue)
NOTE:
https://github.com/deskflow/deskflow/security/advisories/GHSA-jf7g-qghg-p54x
NOTE: Fixed by:
https://github.com/deskflow/deskflow/commit/8a535fd5dd48315eaaf6b93d5c7534d0592addef
NOTE: Fixed by:
https://github.com/deskflow/deskflow/commit/bcd3a658fc3b2ad735146fdc9efefa9462d195b7
@@ -9055,6 +9062,7 @@ CVE-2026-65974 (ERPNext is a free and open source
Enterprise Resource Planning t
NOT-FOR-US: ERPNext
CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to
continuous buil ...)
- deskflow <unfixed> (bug #1145169)
+ [trixie] - deskflow <no-dsa> (Minor issue)
NOTE:
https://github.com/deskflow/deskflow/security/advisories/GHSA-8rcq-7w87-h64j
NOTE: Fixed by:
https://github.com/deskflow/deskflow/commit/205a3c803e5298d56683660736ec1a41b671b56e
CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
@@ -9139,6 +9147,7 @@ CVE-2026-63667 (ApostropheCMS is an open-source Node.js
content management syste
NOT-FOR-US: ApostropheCMS
CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0
until contin ...)
- deskflow <unfixed> (bug #1145169)
+ [trixie] - deskflow <no-dsa> (Minor issue)
NOTE:
https://github.com/deskflow/deskflow/security/advisories/GHSA-gmvh-3c73-m5gg
NOTE: Fixed by:
https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f
CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx
Enterprise Ed ...)
@@ -23835,12 +23844,14 @@ CVE-2026-71497 (jsoup is a Java library for working
with real-world HTML. From 1
NOTE: Fixed by:
https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70
(jsoup-1.23.1)
CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering
CommonMar ...)
- php-league-commonmark 2.9.0-1
+ [trixie] - php-league-commonmark <no-dsa> (Minor issue)
NOTE:
https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv
NOTE: Fixed by:
https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8
(2.9.0)
NOTE: Fixed by:
https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb
(2.9.0)
NOTE: Fixed by:
https://github.com/thephpleague/commonmark/commit/c97b02e5e652b992033b93ba5d6182f706343fc6
(2.9.0)
CVE-2026-71478 (league/commonmark is a PHP library for parsing and rendering
CommonMar ...)
- php-league-commonmark 2.9.0-1
+ [trixie] - php-league-commonmark <no-dsa> (Minor issue)
NOTE:
https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc
NOTE: Fixed by:
https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c
(2.9.0)
CVE-2026-71476 (Nx is a monorepo solution for TypeScript and polyglot
codebases. From ...)
@@ -46314,6 +46325,7 @@ CVE-2026-59203 (Pillow is a Python imaging library.
From 12.0.0 through 12.2.0,
NOTE: Introduced by:
https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83
(12.0.0)
CVE-2026-59200 (Pillow is a Python imaging library. From 5.1.0 until 12.3.0,
PdfParser ...)
- pillow 12.3.0-1 (bug #1142274)
+ [trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue, DoS)
[bullseye] - pillow <postponed> (Minor issue, DoS)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f069754de829471d84d1123fb0420a0b735d64
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f069754de829471d84d1123fb0420a0b735d64
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits