Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b43390a7 by security tracker role at 2026-08-29T19:13:12+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,67 @@
+CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory
traversal.)
+ TODO: check
+CVE-2026-82477 (In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an
SSRF iss ...)
+ TODO: check
+CVE-2026-82476 (Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT
address ...)
+ TODO: check
+CVE-2026-82475 (iFlytek astron-agent through 1.1.1 contains an authorization
bypass vu ...)
+ TODO: check
+CVE-2026-82474 (Sudo through 1.9.17p2 fails to apply intercept policy checks
to the ex ...)
+ TODO: check
+CVE-2026-82473 (KubeEdge CloudCore through 1.23.1 accepts node task status
reports on ...)
+ TODO: check
+CVE-2026-82472 (Documenso before 2.13.0 accepts PDF file uploads on the
/api/files/upl ...)
+ TODO: check
+CVE-2026-82470 (Rodauth before 2.47.0 contains a time-based one-time password
reuse vu ...)
+ TODO: check
+CVE-2026-82469 (Rodauth before 2.47.0 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-82468 (Rodauth before 2.47.0 contains a cross-site request forgery
protection ...)
+ TODO: check
+CVE-2026-82467 (Rodauth before 2.47.0 fails to validate protocol-relative
return-to pa ...)
+ TODO: check
+CVE-2026-82466 (Rodauth before 2.46.0 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-82465 (pac4j-saml before 6.5.6 does not require signature validation
of SAML ...)
+ TODO: check
+CVE-2026-82464 (pac4j-core before 6.5.6 contains an open redirect
vulnerability in Def ...)
+ TODO: check
+CVE-2026-82463 (pac4j-core before 6.5.6 contains an authentication bypass
vulnerabilit ...)
+ TODO: check
+CVE-2026-82462 (pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only
an access ...)
+ TODO: check
+CVE-2026-82461 (pac4j-oidc before 6.5.6 fails to verify access token
signatures, issue ...)
+ TODO: check
+CVE-2026-82460 (Cloud Commander before 19.20.2 contains a directory traversal
vulnerab ...)
+ TODO: check
+CVE-2026-82457 (su-exec through 0.3 fails to validate numeric user and group
identifie ...)
+ TODO: check
+CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network
interface a ...)
+ TODO: check
+CVE-2026-82455 (RubyGems fails to re-validate path containment after
filesystem symlin ...)
+ TODO: check
+CVE-2026-82454 (The Omnivore API (packages/api) before the fix in commit
abf53d6 conta ...)
+ TODO: check
+CVE-2026-82453 (rust-iot-platform through commit 5df942ab stores user
passwords in cle ...)
+ TODO: check
+CVE-2026-82452 (rust-iot-platform through commit 5df942ab contains an
authentication b ...)
+ TODO: check
+CVE-2026-82451 (Formwork through 2.3.14 contains a stored cross-site scripting
vulnera ...)
+ TODO: check
+CVE-2026-82450 (BookStack before 26.05.4 contains a remote code execution
vulnerabilit ...)
+ TODO: check
+CVE-2026-82449 (Cockpit CMS before 2.14.1 contains an account enumeration
vulnerabilit ...)
+ TODO: check
+CVE-2026-82448 (Shinobi before commit 5a76c74f contains a hardcoded connection
key in ...)
+ TODO: check
+CVE-2026-82447 (Skyvern before 1.0.45 contains a sandbox escape vulnerability
in TextP ...)
+ TODO: check
+CVE-2026-82364 (A security vulnerability has been detected in macrozheng mall
up to 1. ...)
+ TODO: check
+CVE-2026-75807 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress
is vulne ...)
+ TODO: check
+CVE-2026-14494 (The Sigma Forms Pro plugin for WordPress is vulnerable to
Remote Code ...)
+ TODO: check
CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When
processing a spe ...)
- gimp <unfixed>
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
@@ -184,7 +248,7 @@ CVE-2026-62904 (Incorrect authorization in Microsoft Edge
(Chromium-based) allow
NOT-FOR-US: Microsoft
CVE-2026-58616 (Concurrent execution using shared resource with improper
synchronizati ...)
NOT-FOR-US: Microsoft
-CVE-2026-56100 (SpringBlade versions 2.7.3 through 3.5.0 contain a privilege
escalatio ...)
+CVE-2026-56100 (SpringBlade versions from 2.7.3 up to but not including 5.0.0
contain ...)
NOT-FOR-US: SpringBlade
CVE-2026-55891 (PrivateBin is an online pastebin where the server has zero
knowledge o ...)
NOT-FOR-US: PrivateBin
@@ -5225,7 +5289,7 @@ CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user
endpoint with the profi
NOT-FOR-US: Ech0
CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization
on nine c ...)
NOT-FOR-US: Ech0
-CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery
vulnerabilit ...)
+CVE-2026-79671 (Ech0 before 4.4.3 contains a server-side request forgery
vulnerability ...)
NOT-FOR-US: Ech0
CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting
vulnerability ...)
NOT-FOR-US: Ech0
@@ -6286,13 +6350,13 @@ CVE-2026-78212 (4MOSAn developed by 4MOSAn Security
Technology Co., Ltd. has an
NOT-FOR-US: 4MOSAn
CVE-2026-78211 (4MOSAn GCB Doctor developed by 4MOSAn Security Technology has
a OS Com ...)
NOT-FOR-US: 4MOSAn
-CVE-2026-78209 (exceljs-hardened versions before 5.0.0 fail to neutralize
leading equa ...)
+CVE-2026-78209 (exceljs through 4.4.0 fails to neutralize leading equals,
plus, minus, ...)
NOT-FOR-US: exceljs-hardened
-CVE-2026-78208 (exceljs-hardened before 5.0.0 contains a path traversal
vulnerability ...)
+CVE-2026-78208 (exceljs through 4.4.0 contains a path traversal vulnerability
in the W ...)
NOT-FOR-US: exceljs-hardened
-CVE-2026-78207 (exceljs-hardened before 5.0.0 contains a prototype pollution
vulnerabi ...)
+CVE-2026-78207 (exceljs through 4.4.0 contains a prototype pollution
vulnerability in ...)
NOT-FOR-US: exceljs-hardened
-CVE-2026-78206 (exceljs-hardened before 5.0.0 decompresses all entries from
supplied x ...)
+CVE-2026-78206 (exceljs through 4.4.0 decompresses all entries from supplied
xlsx arch ...)
NOT-FOR-US: exceljs-hardened
CVE-2026-78205 (BentoML's outbound connection safeguard (make_safe_connect in
_interna ...)
NOT-FOR-US: BentoML
@@ -6384,7 +6448,7 @@ CVE-2026-77994 (Joomla Extension - joomlack.fr - Second
order SQL injection in P
NOT-FOR-US: Joomla
CVE-2026-77993 (Joomla Extension - joomlack.fr - Reflected XSS in Page Builder
CK < 3. ...)
NOT-FOR-US: Joomla
-CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.13 contains an authentication
bypass vul ...)
+CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.10 contains an authentication
bypass vul ...)
NOT-FOR-US: rConfig
CVE-2026-77914 (rConfig Core 8.0.0 before 8.2.13 contains a path traversal
vulnerabili ...)
NOT-FOR-US: rConfig
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b43390a70a9e6fe34b6b4f494a66a2d3a7427496
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b43390a70a9e6fe34b6b4f494a66a2d3a7427496
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits