Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
66290f4f by Moritz Muehlenhoff at 2026-08-31T19:53:16+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -20,6 +20,7 @@ CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read 
in pcre2_match() a
        NOTE: Fixed by: 
https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5
 pcre2-10.48-RC1)
 CVE-2026-19873
        - libhtml-formfu-perl <unfixed> (bug #1146310)
+       [trixie] - libhtml-formfu-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/43141785/
        NOTE: 
https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch
 CVE-2026-82727 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
@@ -96,6 +97,7 @@ CVE-2026-82624 (A flaw has been found in code-projects Simple 
Inventory System 1
        NOT-FOR-US: code-projects
 CVE-2026-82623 (A vulnerability was detected in open62541 up to 1.5.5. 
Affected by thi ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8199
 CVE-2026-82622 (A security vulnerability has been detected in code-projects 
Employee L ...)
        NOT-FOR-US: code-projects
@@ -13129,11 +13131,15 @@ CVE-2026-62441 (Vulnerability in the Oracle Hyperion 
Calculation Manager product
        NOT-FOR-US: Oracle
 CVE-2026-62377 (libheif is a HEIF and AVIF file format decoder and encoder. In 
1.23.0  ...)
        - libheif 1.23.1-1
+       [trixie] - libheif <no-dsa> (Minor issue)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-9ww4-9v47-m7pj
        NOTE: https://github.com/strukturag/libheif/issues/1844
        NOTE: Fixed by: 
https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3
 (v1.23.1)
 CVE-2026-62291 (libheif is a HEIF and AVIF file format decoder and encoder. In 
1.23.0  ...)
        - libheif 1.23.1-1
+       [trixie] - libheif <not-affected> (Vulnerable code not present, 
introduced in 1.20)
+       [bookworm] - libheif <not-affected> (Vulnerable code not present, 
introduced in 1.20)
+       [bullseye] - libheif <not-affected> (Vulnerable code not present, 
introduced in 1.20)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-xpw3-9rhw-482x
        NOTE: Fixed by: 
https://github.com/strukturag/libheif/commit/ac5521ad50399885de96bb6a0733a5d2442740f9
 (v1.23.1)
 CVE-2026-61342 (Vulnerability in the Oracle Hyperion Calculation Manager 
product of Or ...)
@@ -83745,6 +83751,7 @@ CVE-2026-5241 (A vulnerability in the LightGlue model 
loading path of huggingfac
        NOT-FOR-US: huggingface/transformers
 CVE-2026-5078 (Impact: The morgan logging middleware's :remote-user token 
extracts th ...)
        - node-morgan 1.12.0+~1.9.10-1
+       [trixie] - node-morgan <no-dsa> (Minor issue)
        NOTE: 
https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m
 CVE-2026-4035 (A vulnerability in mlflow/mlflow versions prior to 3.11.0 
allows for t ...)
        NOT-FOR-US: mlflow



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66290f4f26ec88eb685b62de176574f31708b20a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66290f4f26ec88eb685b62de176574f31708b20a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to