Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1d343642 by Moritz Muehlenhoff at 2026-08-28T13:14:00+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -767,9 +767,11 @@ CVE-2026-81526 (The MongoDB Rust Driver does not 
neutralize special characters i
        NOT-FOR-US: MongoDB Rust Driver
 CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently 
sanitize spec ...)
        - php-mongodb <unfixed>
+       [trixie] - php-mongodb <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/PHPLIB-1927
 CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in 
caller-s ...)
        - mongo-c-driver 2.5.1-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6424
 CVE-2026-81523 (A missing input-validation issue in MongoDB libmongocrypt's 
automatic- ...)
        TODO: check
@@ -1171,21 +1173,27 @@ CVE-2026-81735 (startServer.ts in the mcp-http-server 
package of UI-TARS-desktop
        NOT-FOR-US: mcp-http-server
 CVE-2026-81727 (NLTK versions before 3.10.3 contain a filesystem containment 
bypass vu ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-f794-5jv7-7672
 CVE-2026-81726 (NLTK through 3.10.3 contains a path traversal vulnerability in 
model-a ...)
        - nltk <unfixed>
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xp
 CVE-2026-81725 (NLTK before 3.10.3 contains a regular expression denial of 
service vul ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-8mpw-7fpc-4gqj
 CVE-2026-81724 (NLTK before 3.10.3 contains an uncontrolled recursion 
vulnerability in ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-cw6x-m8jw-qmrh
 CVE-2026-81723 (NLTK versions before 3.10.3 contain a quadratic CPU exhaustion 
vulnera ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-vp2x-qp44-57v7
 CVE-2026-81722 (nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) 
contains an ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94g
 CVE-2026-81721 (openssl_encrypt before 1.4.9 fails to validate KDF cost 
parameters in  ...)
        NOT-FOR-US: OpenSSL Encrypt



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d343642c649a3ca6fb08eb45edce20d0c9e1308

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d343642c649a3ca6fb08eb45edce20d0c9e1308
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to