Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
83f06975 by Moritz Muehlenhoff at 2026-08-25T21:38:31+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -603,15 +603,19 @@ CVE-2026-78685 (Medical Practice Management System 
developed by Le-yan has a Rem
        NOT-FOR-US: Medical Practice Management System
 CVE-2026-78683 (NLTK before 3.10.0 (affected versions <=3.9.4) contains an 
unsafe pick ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-rhp5-r9x4-f5g2
 CVE-2026-78682 (NLTK before 3.10.3 contains a server-side request forgery 
vulnerabilit ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-6ww7-3frv-cqxh
 CVE-2026-78681 (NLTK versions before 3.10.3 use xml.etree.ElementTree to parse 
XML in  ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-97qj-x29f-37w7
 CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute 
paths when  ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-6hwm-xvph-95vm
 CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read 
vulnerability  ...)
        - python-git <unfixed>
@@ -2343,6 +2347,7 @@ CVE-2026-XXXX [OpenZFS Linux open zpool manipulation and 
escapes via unprivilege
        NOTE: https://github.com/openzfs/zfs/pull/18959
 CVE-2026-77682 [Use a user message to trigger form autofill]
        - epiphany-browser <unfixed> (bug #1145177)
+       [trixie] - epiphany-browser <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2147
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/epiphany/-/commit/e85444e03490cff1584251028a11d5dfeb3accac
 (50.6)
 CVE-2026-66786
@@ -3646,6 +3651,7 @@ CVE-2026-64960 (ATutor Gameme module allows users to 
upload files of any type an
        NOT-FOR-US: ATutor
 CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems. 
Prior to 2. ...)
        - nix <unfixed> (bug #1145021)
+       [trixie] - nix <no-dsa> (Minor issue)
        NOTE: 
https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f
        NOTE: https://github.com/NixOS/nix/pull/15401
        NOTE: Fixed by: 
https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390 
(2.35.0)
@@ -9048,6 +9054,7 @@ CVE-2026-66795 (A flaw was found in the 
managedcluster-import-controller. The Ce
        NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
 CVE-2026-65976 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 
until contin ...)
        - deskflow <unfixed> (bug #1145169)
+       [trixie] - deskflow <no-dsa> (Minor issue)
        NOTE: 
https://github.com/deskflow/deskflow/security/advisories/GHSA-jf7g-qghg-p54x
        NOTE: Fixed by: 
https://github.com/deskflow/deskflow/commit/8a535fd5dd48315eaaf6b93d5c7534d0592addef
        NOTE: Fixed by: 
https://github.com/deskflow/deskflow/commit/bcd3a658fc3b2ad735146fdc9efefa9462d195b7
@@ -9055,6 +9062,7 @@ CVE-2026-65974 (ERPNext is a free and open source 
Enterprise Resource Planning t
        NOT-FOR-US: ERPNext
 CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to 
continuous buil ...)
        - deskflow <unfixed> (bug #1145169)
+       [trixie] - deskflow <no-dsa> (Minor issue)
        NOTE: 
https://github.com/deskflow/deskflow/security/advisories/GHSA-8rcq-7w87-h64j
        NOTE: Fixed by: 
https://github.com/deskflow/deskflow/commit/205a3c803e5298d56683660736ec1a41b671b56e
 CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
@@ -9139,6 +9147,7 @@ CVE-2026-63667 (ApostropheCMS is an open-source Node.js 
content management syste
        NOT-FOR-US: ApostropheCMS
 CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 
until contin ...)
        - deskflow <unfixed> (bug #1145169)
+       [trixie] - deskflow <no-dsa> (Minor issue)
        NOTE: 
https://github.com/deskflow/deskflow/security/advisories/GHSA-gmvh-3c73-m5gg
        NOTE: Fixed by: 
https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f
 CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx 
Enterprise Ed ...)
@@ -23835,12 +23844,14 @@ CVE-2026-71497 (jsoup is a Java library for working 
with real-world HTML. From 1
        NOTE: Fixed by: 
https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70 
(jsoup-1.23.1)
 CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering 
CommonMar ...)
        - php-league-commonmark 2.9.0-1
+       [trixie] - php-league-commonmark <no-dsa> (Minor issue)
        NOTE: 
https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv
        NOTE: Fixed by: 
https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8
 (2.9.0)
        NOTE: Fixed by: 
https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb
 (2.9.0)
        NOTE: Fixed by: 
https://github.com/thephpleague/commonmark/commit/c97b02e5e652b992033b93ba5d6182f706343fc6
 (2.9.0)
 CVE-2026-71478 (league/commonmark is a PHP library for parsing and rendering 
CommonMar ...)
        - php-league-commonmark 2.9.0-1
+       [trixie] - php-league-commonmark <no-dsa> (Minor issue)
        NOTE: 
https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc
        NOTE: Fixed by: 
https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c
 (2.9.0)
 CVE-2026-71476 (Nx is a monorepo solution for TypeScript and polyglot 
codebases. From  ...)
@@ -46314,6 +46325,7 @@ CVE-2026-59203 (Pillow is a Python imaging library. 
From 12.0.0 through 12.2.0,
        NOTE: Introduced by: 
https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83
 (12.0.0)
 CVE-2026-59200 (Pillow is a Python imaging library. From 5.1.0 until 12.3.0, 
PdfParser ...)
        - pillow 12.3.0-1 (bug #1142274)
+       [trixie] - pillow <no-dsa> (Minor issue)
        [bookworm] - pillow <postponed> (Minor issue, DoS)
        [bullseye] - pillow <postponed> (Minor issue, DoS)
        NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f069754de829471d84d1123fb0420a0b735d64

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f069754de829471d84d1123fb0420a0b735d64
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to