Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e17c4c27 by security tracker role at 2026-08-31T07:13:52+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,277 @@
+CVE-2026-82727 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
+       TODO: check
+CVE-2026-82726 (Permissive Regular Expression vulnerability in ash-project 
ash_phoenix ...)
+       TODO: check
+CVE-2026-82725 (Authorization Bypass Through User-Controlled Key vulnerability 
in ash- ...)
+       TODO: check
+CVE-2026-82724 (Incorrect Authorization vulnerability in ash-project 
ash_phoenix invok ...)
+       TODO: check
+CVE-2026-82722 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
+       TODO: check
+CVE-2026-82681 (Improper Encoding or Escaping of Output vulnerability in 
ash-project a ...)
+       TODO: check
+CVE-2026-82673 (Improper Limitation of a Pathname to a Restricted Directory 
(Path Trav ...)
+       TODO: check
+CVE-2026-82658 (Admidio versions before 5.0.12 contain a broken access control 
vulnera ...)
+       TODO: check
+CVE-2026-82657 (Admidio before 5.0.12 fails to enforce login-only module 
restrictions  ...)
+       TODO: check
+CVE-2026-82656 (Admidio before 5.0.12 fails to sanitize album names in the 
photo ZIP d ...)
+       TODO: check
+CVE-2026-82655 (Admidio before 5.0.12 contains a blind SQL injection 
vulnerability in  ...)
+       TODO: check
+CVE-2026-82654 (SiYuan before v3.8.1 fails to properly escape block name, 
alias, and m ...)
+       TODO: check
+CVE-2026-82653 (SiYuan before v3.8.1 contains a stored cross-site scripting 
vulnerabil ...)
+       TODO: check
+CVE-2026-82652 (SiYuan before v3.8.1 fails to filter invisible-tier content 
from SQL e ...)
+       TODO: check
+CVE-2026-82651 (SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath 
guard (intr ...)
+       TODO: check
+CVE-2026-82650 (SiYuan 3.8.0 contains a path traversal / sensitive file 
exposure vulne ...)
+       TODO: check
+CVE-2026-82649 (SiYuan Windows installer before version 3.8.1 (affected 
versions >= 2. ...)
+       TODO: check
+CVE-2026-82648 (WWBN AVideo contains a server-side request forgery filter 
bypass vulne ...)
+       TODO: check
+CVE-2026-82647 (WWBN AVideo contains a cross-site request forgery 
vulnerability in sen ...)
+       TODO: check
+CVE-2026-82646 (WWBN AVideo contains an unauthenticated reflected cross-site 
scripting ...)
+       TODO: check
+CVE-2026-82645 (AVideo (current commit e01e41ecc and earlier) exposes stream 
credentia ...)
+       TODO: check
+CVE-2026-82644 (WWBN AVideo (current e01e41ecc and earlier) contains a 
brute-force rat ...)
+       TODO: check
+CVE-2026-82643 (WWBN AVideo contains an unauthenticated credential submission 
vulnerab ...)
+       TODO: check
+CVE-2026-82642 (Readest is an open-source e-book reader built on Tauri. In 
versions pr ...)
+       TODO: check
+CVE-2026-82641 (keploy versions 3.1.0 through 3.6.25 bind the agent 
control-plane HTTP ...)
+       TODO: check
+CVE-2026-82640 (browser-use web-ui versions 2.0.0 through 3.0.0 write 
configured LLM A ...)
+       TODO: check
+CVE-2026-82639 (NextChat versions from 2.15.8 through 2.16.1 contain an 
improper URL v ...)
+       TODO: check
+CVE-2026-82638 (jina-ai reader disables its private-address guard outside 
Google Cloud ...)
+       TODO: check
+CVE-2026-82637 (browser-use web-ui versions 2.0.0 through 3.0.0 fail to 
validate brows ...)
+       TODO: check
+CVE-2026-82636 (Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command 
injecti ...)
+       TODO: check
+CVE-2026-82635 (Pake before 3.13.1 joins the JavaScript-supplied filename for 
the down ...)
+       TODO: check
+CVE-2026-82634 (Frappe Framework development builds contain an authorization 
flaw in t ...)
+       TODO: check
+CVE-2026-82633 (Dolibarr versions 10.0.0 before 24.0.0 fail to perform 
per-object auth ...)
+       TODO: check
+CVE-2026-82628 (A vulnerability was found in Colorful iGameCenter 2.0.0.81. 
This vulne ...)
+       TODO: check
+CVE-2026-82625 (A vulnerability has been found in code-projects Simple 
Inventory Syste ...)
+       TODO: check
+CVE-2026-82624 (A flaw has been found in code-projects Simple Inventory System 
1.0. Af ...)
+       TODO: check
+CVE-2026-82623 (A vulnerability was detected in open62541 up to 1.5.5. 
Affected by thi ...)
+       TODO: check
+CVE-2026-82622 (A security vulnerability has been detected in code-projects 
Employee L ...)
+       TODO: check
+CVE-2026-82621 (A weakness has been identified in Soarkey StudentManagement 
and \u5b66 ...)
+       TODO: check
+CVE-2026-82620 (A security flaw has been discovered in Soarkey 
StudentManagement and \ ...)
+       TODO: check
+CVE-2026-82619 (A vulnerability was identified in Systerel S2OPC up to 1.7.3. 
The impa ...)
+       TODO: check
+CVE-2026-82618 (A vulnerability was determined in Systerel S2OPC up to 1.7.3. 
The affe ...)
+       TODO: check
+CVE-2026-82616 (A vulnerability was found in TOTOLINK NR1800X 
9.1.0u.6681_B20230703. I ...)
+       TODO: check
+CVE-2026-82615 (A vulnerability has been found in itsourcecode Online Medicine 
Deliver ...)
+       TODO: check
+CVE-2026-82614 (A flaw has been found in itsourcecode Online Medicine Delivery 
System  ...)
+       TODO: check
+CVE-2026-82613 (A vulnerability was detected in itsourcecode Online Medicine 
Delivery  ...)
+       TODO: check
+CVE-2026-82612 (A security vulnerability has been detected in itsourcecode 
Online Medi ...)
+       TODO: check
+CVE-2026-82611 (A weakness has been identified in itsourcecode Online Medicine 
Deliver ...)
+       TODO: check
+CVE-2026-82610 (A security flaw has been discovered in itsourcecode Online 
Medicine De ...)
+       TODO: check
+CVE-2026-82609 (A vulnerability was identified in itsourcecode Sales and 
Inventory Sys ...)
+       TODO: check
+CVE-2026-82608 (A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. 
This aff ...)
+       TODO: check
+CVE-2026-82607 (A vulnerability was found in Cozmoslabs Profile Builder Plugin 
up to 3 ...)
+       TODO: check
+CVE-2026-82605 (A vulnerability has been found in BareBones BBEdit up to 
15.5.5. The a ...)
+       TODO: check
+CVE-2026-82604 (A flaw has been found in BareBones BBEdit up to 15.5.5. 
Impacted is an ...)
+       TODO: check
+CVE-2026-82603 (A vulnerability was detected in SeaCMS up to 13.6. This issue 
affects  ...)
+       TODO: check
+CVE-2026-82602 (A security vulnerability has been detected in SeaCMS up to 
13.6. This  ...)
+       TODO: check
+CVE-2026-82601 (A weakness has been identified in SeaCMS up to 13.6. This 
affects an u ...)
+       TODO: check
+CVE-2026-82600 (A security flaw has been discovered in SeaCMS up to 13.6. 
Affected by  ...)
+       TODO: check
+CVE-2026-82599 (A vulnerability was identified in SeaCMS up to 13.6. Affected 
by this  ...)
+       TODO: check
+CVE-2026-82598 (A vulnerability was determined in SeaCMS up to 13.6. Affected 
is the f ...)
+       TODO: check
+CVE-2026-82597 (A vulnerability was identified in TOTOLINK NR1800X 
9.1.0u.6681_B202307 ...)
+       TODO: check
+CVE-2026-82596 (A vulnerability was determined in LatencyUtils up to 2.0.3. 
Affected b ...)
+       TODO: check
+CVE-2026-82595 (A vulnerability was found in D-Link DIR-825M 1.1.8. Affected 
by this v ...)
+       TODO: check
+CVE-2026-82594 (A vulnerability has been found in LogNet 
grpc-spring-boot-starter up t ...)
+       TODO: check
+CVE-2026-82593 (A flaw has been found in D-Link DIR-825M 1.1.8. This impacts 
the funct ...)
+       TODO: check
+CVE-2026-82592 (A vulnerability was detected in D-Link DIR-825M 1.1.8. This 
affects th ...)
+       TODO: check
+CVE-2026-82591 (A security vulnerability has been detected in Open Asset 
Import Librar ...)
+       TODO: check
+CVE-2026-82590 (A weakness has been identified in Open5GS up to 2.7.7. The 
affected el ...)
+       TODO: check
+CVE-2026-82589 (A security flaw has been discovered in Open5GS up to 2.7.7. 
Impacted i ...)
+       TODO: check
+CVE-2026-82588 (A vulnerability was identified in Open5GS up to 2.7.7. This 
issue affe ...)
+       TODO: check
+CVE-2026-82587 (A vulnerability was determined in Open5GS up to 2.7.7. This 
vulnerabil ...)
+       TODO: check
+CVE-2026-82580 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
+       TODO: check
+CVE-2026-82579 (Loop with Unreachable Exit Condition (Infinite Loop) 
vulnerability in  ...)
+       TODO: check
+CVE-2026-82564 (Authorization Bypass Through User-Controlled Key vulnerability 
in ash- ...)
+       TODO: check
+CVE-2026-82556 (A vulnerability was found in Forgejo up to 15.0.4. This issue 
affects  ...)
+       TODO: check
+CVE-2026-82555 (A vulnerability has been found in TOTOLINK N600R 
4.3.0cu.7866_B2022050 ...)
+       TODO: check
+CVE-2026-82554 (A flaw has been found in SourceCodester Queue Management 
System 1.0. T ...)
+       TODO: check
+CVE-2026-82553 (A vulnerability was detected in sambitraj Student Management 
System up ...)
+       TODO: check
+CVE-2026-82552 (A security vulnerability has been detected in Linux Foundation 
Magma 1 ...)
+       TODO: check
+CVE-2026-82551 (A weakness has been identified in Linux Foundation Magma 
1.9.0. Affect ...)
+       TODO: check
+CVE-2026-82550 (A security flaw has been discovered in Linux Foundation Magma 
1.9.0. T ...)
+       TODO: check
+CVE-2026-82549 (A vulnerability was identified in Linux Foundation Magma 
1.9.0. This a ...)
+       TODO: check
+CVE-2026-82548 (A vulnerability was determined in Linux Foundation Magma 
1.9.0. The im ...)
+       TODO: check
+CVE-2026-82547 (A vulnerability was found in Linux Foundation Magma 1.9.0. The 
affecte ...)
+       TODO: check
+CVE-2026-82545 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
+       TODO: check
+CVE-2026-82544 (A flaw has been found in wger-project wger up to 2.6.0-alpha2. 
This is ...)
+       TODO: check
+CVE-2026-82543 (A vulnerability was detected in vastsa FileCodeBox up to 2.3. 
This vul ...)
+       TODO: check
+CVE-2026-82542 (A weakness has been identified in Tenda HG10 300001138. 
Affected by th ...)
+       TODO: check
+CVE-2026-82541 (A security flaw has been discovered in itsourcecode Sales and 
Inventor ...)
+       TODO: check
+CVE-2026-82540 (A vulnerability was identified in itsourcecode Sales and 
Inventory Sys ...)
+       TODO: check
+CVE-2026-82539 (A vulnerability was determined in TOTOLINK A720R 
4.1.5cu.630_B20250509 ...)
+       TODO: check
+CVE-2026-82488 (A vulnerability was identified in Beetel 450TC3 01.00.00_01. 
This vuln ...)
+       TODO: check
+CVE-2026-82487 (A vulnerability was determined in Beetel 450TC3 01.00.00_01. 
This affe ...)
+       TODO: check
+CVE-2026-82486 (A vulnerability was found in SiteServer SSCMS 7.4.0. Affected 
by this  ...)
+       TODO: check
+CVE-2026-82485 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
+       TODO: check
+CVE-2026-82484 (A flaw has been found in itsourcecode Sales and Inventory 
System 1.0.  ...)
+       TODO: check
+CVE-2026-82483 (A vulnerability was detected in coppermine-gallery Coppermine 
Photo Ga ...)
+       TODO: check
+CVE-2026-82367 (Exposure of Data Element to Wrong Session vulnerability in 
ash-project ...)
+       TODO: check
+CVE-2026-81853 (Authorization Bypass Through User-Controlled Key vulnerability 
in ash- ...)
+       TODO: check
+CVE-2026-81852 (Use of Insufficiently Random Values vulnerability in 
ash-project ash_a ...)
+       TODO: check
+CVE-2026-81643 (Incorrect Authorization vulnerability in ash-project 
ash_graphql deliv ...)
+       TODO: check
+CVE-2026-81636 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
+       TODO: check
+CVE-2026-81633 (Improper Input Validation vulnerability in ash-project 
ash_graphql all ...)
+       TODO: check
+CVE-2026-81322 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
+       TODO: check
+CVE-2026-81319 (Deserialization of Untrusted Data vulnerability in ash-project 
ash_clo ...)
+       TODO: check
+CVE-2026-81318 (Incorrect Authorization vulnerability in ash-project ash_sql 
allows a  ...)
+       TODO: check
+CVE-2026-81316 (Incorrect Authorization vulnerability in ash-project ash_sql 
allows a  ...)
+       TODO: check
+CVE-2026-81315 (Origin Validation Error vulnerability in ash-project ash_ai 
allows a m ...)
+       TODO: check
+CVE-2026-80227 (Incorrect Comparison vulnerability in ash-project ash_sql 
allows a use ...)
+       TODO: check
+CVE-2026-80223 (Incorrect Authorization vulnerability in ash-project 
ash_graphql allow ...)
+       TODO: check
+CVE-2026-78699 (Unchecked Return Value vulnerability in ash-project 
ash_postgres allow ...)
+       TODO: check
+CVE-2026-78693 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
+       TODO: check
+CVE-2026-78691 (Improper Neutralization of Special Elements in Data Query 
Logic vulner ...)
+       TODO: check
+CVE-2026-78228 (Uncontrolled Recursion vulnerability in ash-project ash_oban 
allows a  ...)
+       TODO: check
+CVE-2026-78038 (Improperly Controlled Modification of Dynamically-Determined 
Object At ...)
+       TODO: check
+CVE-2026-77956 (Improper Control of Generation of Code (Code Injection) 
vulnerability  ...)
+       TODO: check
+CVE-2026-77850 (Stored Cross-site Scripting vulnerability in ash-project 
ash_admin exe ...)
+       TODO: check
+CVE-2026-77454 (Incorrect Authorization vulnerability in ash-project ash_sql 
allows a  ...)
+       TODO: check
+CVE-2026-77013 (The 
\u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
+       TODO: check
+CVE-2026-75760 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
+       TODO: check
+CVE-2026-75757 (Reliance on Cookies without Validation and Integrity Checking 
vulnerab ...)
+       TODO: check
+CVE-2026-68951 (GROWI contains an incorrect authorization vulnerability. If 
this vulne ...)
+       TODO: check
+CVE-2026-64844
+       REJECTED
+CVE-2026-64843
+       REJECTED
+CVE-2026-64842
+       REJECTED
+CVE-2026-64841
+       REJECTED
+CVE-2026-64840
+       REJECTED
+CVE-2026-64839
+       REJECTED
+CVE-2026-58574 (Dell PowerStore contains a Missing Authentication for Critical 
Functio ...)
+       TODO: check
+CVE-2026-56718 (AJCloud AJY IPC firmware prior to version 01.10715.11.37 
contains a pa ...)
+       TODO: check
+CVE-2026-56716
+       REJECTED
+CVE-2026-56715
+       REJECTED
+CVE-2026-56713
+       REJECTED
+CVE-2026-53620 (GROWI contains a vulnerability with an authorization bypass 
through us ...)
+       TODO: check
+CVE-2026-40465 (NSP is vulnerable to an open redirect due to insufficient 
server-side  ...)
+       TODO: check
+CVE-2026-40464 (NSP is vulnerable to a stored XSS due to insufficient 
validation or en ...)
+       TODO: check
+CVE-2026-40463 (WaveSuite is affected by an insufficient role-based access 
control vul ...)
+       TODO: check
 CVE-2026-18054
        - qemu 1:11.1.0+ds-1
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba
 (v11.1.0-rc3)
@@ -26871,45 +27145,45 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in 
Apache Airflow's Yandex pr
 CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager 
backends i ...)
        NOT-FOR-US: Apache Airflow provider
 CVE-2026-74998 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
responses f ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b
 (1.6.18)
 CVE-2026-75006 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
insufficien ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
 (1.6.18)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9
 (1.6.18)
 CVE-2026-75003 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an 
unclosed ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
 (1.6.18)
 CVE-2026-75007 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
LDAP se ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540
 (1.6.18)
 CVE-2026-75004 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
improper ru ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e
 (1.6.18)
 CVE-2026-74997 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
cmd_lea ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
 (1.6.18)
        NOTE: Follow-up: 
https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a
 (release-1.6)
 CVE-2026-75002 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
mail search ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
 (1.6.18)
 CVE-2026-75010 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
modoboa ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
 (1.6.18)
 CVE-2026-74999 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
"Add to ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8
 (1.6.18)
 CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
improper HT ...)
-       {DLA-4760-1}
+       {DSA-6479-1 DLA-4760-1}
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f
 (1.6.18)
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a 
usernam ...)
@@ -46954,7 +47228,7 @@ CVE-2026-64612 (A flaw was found in libcupsfilters and 
cups-filters. The PNG ima
        NOTE: 
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
        NOTE: 
https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419acbd0cbcc8340f41a383f35aae12
 (2.2.0)
 CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of 
Service via de ...)
-       {DSA-6459-1}
+       {DSA-6459-1 DLA-4761-1}
        - libnet-dns-perl 1.56-1 (bug #1142503)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/
        NOTE: https://rt.cpan.org/Ticket/Display.html?id=179946
@@ -65067,17 +65341,17 @@ CVE-2026-77640 (tor before 0.4.9.9 was prone to an 
infinite loop when decompress
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41274
 CVE-2026-77584 (Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that 
arrives on ...)
-       {DSA-6372-1}
+       {DSA-6372-1 DLA-4656-1}
        - tor 0.4.9.11-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41258 
(private ATM)
 CVE-2026-77587 (Tor before 0.4.9.11 is prone to a use-after-free (and 
potential double ...)
-       {DSA-6372-1}
+       {DSA-6372-1 DLA-4656-1}
        - tor 0.4.9.11-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41306
 CVE-2026-77638 (Tor before 0.4.9.11 is prone to a race condition where in just 
the rig ...)
-       {DSA-6372-1}
+       {DSA-6372-1 DLA-4656-1}
        - tor 0.4.9.11-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41297
@@ -70980,14 +71254,14 @@ CVE-2026-54286 (Hono is a Web application framework 
that provides support for an
 CVE-2026-54285 (opentelemetry-js is the OpenTelemetry JavaScript Client. Prior 
to 2.8. ...)
        NOT-FOR-US: opentelemetry-js
 CVE-2026-54283 (Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 
until 1. ...)
-       {DLA-4711-1}
+       {DSA-6478-1 DLA-4711-1}
        - starlette 1.3.1-1 (bug #1140631)
        [bullseye] - starlette <ignored> (Minor issue; requires intrusive 
backport for CVE-2023-30798)
        NOTE: 
https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
        NOTE: https://github.com/Kludex/starlette/pull/3329
        NOTE: Fixed by: 
https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735
 (1.3.1)
 CVE-2026-54282 (Starlette is a lightweight ASGI framework/toolkit. Prior to 
1.3.0, the ...)
-       {DLA-4711-1}
+       {DSA-6478-1 DLA-4711-1}
        - starlette 1.3.1-1 (bug #1140632)
        [bullseye] - starlette <ignored> (Minor issue)
        NOTE: 
https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3
@@ -72605,7 +72879,7 @@ CVE-2026-48821 (Shaarli is a personal bookmarking 
service. Versions 0.16.1 and p
 CVE-2026-48820 (CakePHP is a rapid development framework for PHP. In versions 
4.5.11 a ...)
        - cakephp <removed>
 CVE-2026-48817 (Starlette is a lightweight ASGI framework/toolkit. In versions 
1.0.1 a ...)
-       {DLA-4711-1}
+       {DSA-6478-1 DLA-4711-1}
        - starlette 1.1.0-1
        [bullseye] - starlette <ignored> (Minor issue)
        NOTE: 
https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e17c4c27f767d8dd0229a89931d7e3f5ecbba4a6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e17c4c27f767d8dd0229a89931d7e3f5ecbba4a6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to