Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
174b9773 by security tracker role at 2026-09-01T07:12:48+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,303 @@
+CVE-2026-83772 (A vulnerability was detected in Cobham SATCOM VSAT7090
Maritime Satell ...)
+ TODO: check
+CVE-2026-83744 (A security vulnerability has been detected in invoiceninja
Invoice Nin ...)
+ TODO: check
+CVE-2026-83743 (A weakness has been identified in invoiceninja Invoice Ninja
up to 5.1 ...)
+ TODO: check
+CVE-2026-83596 (A flaw was found in WebKitGTK. Processing malicious web
content can ca ...)
+ TODO: check
+CVE-2026-83524 (A security vulnerability has been detected in RedPort
Optimizer wXa-20 ...)
+ TODO: check
+CVE-2026-82971 (A vulnerability was determined in QVidium Opera11
3.3.2a26-Ax4x-opera1 ...)
+ TODO: check
+CVE-2026-82957 (A vulnerability was found in hyperledger-firefly firefly up to
1.4.0. ...)
+ TODO: check
+CVE-2026-82954 (A vulnerability was detected in Dokploy up to 0.29.7. This
issue affec ...)
+ TODO: check
+CVE-2026-82922 (A security vulnerability has been detected in ShopEx ECShop up
to 2.5. ...)
+ TODO: check
+CVE-2026-82921 (A weakness has been identified in ShopEx ECShop up to 2.5.1.
This affe ...)
+ TODO: check
+CVE-2026-82919 (A vulnerability was identified in cu silicon up to 0.1.5.
Affected by ...)
+ TODO: check
+CVE-2026-82914 (A security flaw has been discovered in kishan0725
Hospital-Management- ...)
+ TODO: check
+CVE-2026-82909 (A vulnerability was determined in QuantumNous new-api up to
1.0.0-rc.1 ...)
+ TODO: check
+CVE-2026-82908 (A vulnerability was found in MSI Dragon Center up to
2.0.155.0. Affect ...)
+ TODO: check
+CVE-2026-82906 (A flaw has been found in sdcb chats up to 1.12.0. This impacts
the fun ...)
+ TODO: check
+CVE-2026-82905 (A vulnerability was detected in sdcb chats up to 1.12.0. This
affects ...)
+ TODO: check
+CVE-2026-82882 (Devtron through 2.2.0 fails to enforce authorization checks on
the GET ...)
+ TODO: check
+CVE-2026-82852 (Unauthenticated Server Side Request Forgery (SSRF) in MapSVG
<= 8.15.0 ...)
+ TODO: check
+CVE-2026-82835 (A weakness has been identified in caoqianming django-vue-admin
1.0. Th ...)
+ TODO: check
+CVE-2026-82834 (A security flaw has been discovered in Doccano Open Source
Annotation ...)
+ TODO: check
+CVE-2026-82833 (A vulnerability was identified in Doccano Open Source
Annotation Tools ...)
+ TODO: check
+CVE-2026-82749 (Incorrect Authorization vulnerability in ash-project ash
widens a rela ...)
+ TODO: check
+CVE-2026-82748 (Incorrect Authorization vulnerability in ash-project ash
authorizes an ...)
+ TODO: check
+CVE-2026-82747 (Incorrect Authorization vulnerability in ash-project ash
returns recor ...)
+ TODO: check
+CVE-2026-82746 (Missing Authorization vulnerability in ash-project ash allows
an actor ...)
+ TODO: check
+CVE-2026-82745 (Improper Access Control vulnerability in ash-project ash lets
a create ...)
+ TODO: check
+CVE-2026-82744 (Not Failing Securely (Failing Open) vulnerability in
ash-project ash s ...)
+ TODO: check
+CVE-2026-82743 (Uncontrolled Resource Consumption vulnerability in ash-project
ash let ...)
+ TODO: check
+CVE-2026-82742 (Uncontrolled Resource Consumption vulnerability in ash-project
ash let ...)
+ TODO: check
+CVE-2026-82741 (Improper Validation of Specified Type of Input vulnerability
in ash-pr ...)
+ TODO: check
+CVE-2026-82740 (Improper Input Validation vulnerability in ash-project ash
fails to en ...)
+ TODO: check
+CVE-2026-82739 (Generation of Error Message Containing Sensitive Information
vulnerabi ...)
+ TODO: check
+CVE-2026-82738 (Improper Input Validation vulnerability in ash-project ash
allows an a ...)
+ TODO: check
+CVE-2026-82737 (Integer Overflow or Wraparound vulnerability in ash-project
ash lets a ...)
+ TODO: check
+CVE-2026-82736 (Incorrect Behavior Order: Validate Before Canonicalize
vulnerability i ...)
+ TODO: check
+CVE-2026-82735 (Uncontrolled Resource Consumption vulnerability in ash-project
ash all ...)
+ TODO: check
+CVE-2026-82734 (Improper Validation of Specified Quantity in Input
vulnerability in as ...)
+ TODO: check
+CVE-2026-82733 (Generation of Error Message Containing Sensitive Information
vulnerabi ...)
+ TODO: check
+CVE-2026-82732 (Improper Input Validation vulnerability in ash-project
ash_typescript ...)
+ TODO: check
+CVE-2026-82731 (URL Redirection to Untrusted Site ('Open Redirect')
vulnerability in a ...)
+ TODO: check
+CVE-2026-82730 (Incorrect Authorization vulnerability in ash-project
ash_typescript al ...)
+ TODO: check
+CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.15 ...)
+ TODO: check
+CVE-2026-82397 (Tornado is a Python web framework and asynchronous networking
library. ...)
+ TODO: check
+CVE-2026-82396 (Sulu is an open-source PHP content management system based on
the Symf ...)
+ TODO: check
+CVE-2026-82395 (Sulu is an open-source PHP content management system based on
the Symf ...)
+ TODO: check
+CVE-2026-82394 (Sulu is an open-source PHP content management system based on
the Symf ...)
+ TODO: check
+CVE-2026-82393 (pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm
accepts ...)
+ TODO: check
+CVE-2026-82392 (pnpm is a package manager. Prior to 10.34.5 and from 11.0.0
until 11.1 ...)
+ TODO: check
+CVE-2026-82346 (A potential security vulnerability has been identified in the
HP Image ...)
+ TODO: check
+CVE-2026-82229 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social
Login a ...)
+ TODO: check
+CVE-2026-82228 (Unauthenticated Bypass Vulnerability in SiteGround Security <=
1.6.6 v ...)
+ TODO: check
+CVE-2026-82226 (Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2
versions.)
+ TODO: check
+CVE-2026-82225 (Unauthenticated Broken Authentication in RegistrationMagic <=
6.0.9.8 ...)
+ TODO: check
+CVE-2026-82224 (Unauthenticated Cross Site Scripting (XSS) in SliceWP <=
1.2.10 versio ...)
+ TODO: check
+CVE-2026-82221 (Unauthenticated Cross Site Scripting (XSS) in
RegistrationMagic <= 6.0 ...)
+ TODO: check
+CVE-2026-81892 (EasyAdmin is a fast and modern admin generator for Symfony
application ...)
+ TODO: check
+CVE-2026-81891 (elFinder is an open-source file manager for web, written in
JavaScript ...)
+ TODO: check
+CVE-2026-81890 (elFinder is an open-source file manager for web, written in
JavaScript ...)
+ TODO: check
+CVE-2026-81889 (elFinder is an open-source file manager for web, written in
JavaScript ...)
+ TODO: check
+CVE-2026-81888 (@hono/oauth-providers is Authentication middleware for Hono.
Prior to ...)
+ TODO: check
+CVE-2026-81887 (Livewire is a full-stack framework for Laravel. From
3.0.0-beta.1 unti ...)
+ TODO: check
+CVE-2026-81780 (Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2
versions.)
+ TODO: check
+CVE-2026-81779 (Improper Validation of Specified Quantity in Input
vulnerability in Si ...)
+ TODO: check
+CVE-2026-81778 (Subscriber Cross Site Scripting (XSS) in Kalles Addons <=
1.0.6 versio ...)
+ TODO: check
+CVE-2026-81768 (Unauthenticated Cross Site Scripting (XSS) in Super Store
Finder <= 7. ...)
+ TODO: check
+CVE-2026-81765 (Unauthenticated Cross Site Scripting (XSS) in Tailored Tools
<= 3.0.2 ...)
+ TODO: check
+CVE-2026-81764 (Unauthenticated Cross Site Scripting (XSS) in Email Essentials
<= 6.0. ...)
+ TODO: check
+CVE-2026-81763 (Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2
versions.)
+ TODO: check
+CVE-2026-81762 (Subscriber Broken Access Control in Booking and Rental Manager
<= 2.7. ...)
+ TODO: check
+CVE-2026-81758 (Subscriber Broken Access Control in OwnerRez API <= 1.2.6
versions.)
+ TODO: check
+CVE-2026-81756 (Unauthenticated SQL Injection in Smart Marketing SMS and
Newsletters F ...)
+ TODO: check
+CVE-2026-81298 (Unauthenticated Cross Site Scripting (XSS) in LeadConnector <=
4.0.5 v ...)
+ TODO: check
+CVE-2026-81297 (Subscriber Privilege Escalation in Fluent Forms Pro Add On
Pack <= 6.2 ...)
+ TODO: check
+CVE-2026-81296 (Unauthenticated Broken Access Control in Fluent Forms Pro Add
On Pack ...)
+ TODO: check
+CVE-2026-81293 (Unauthenticated SQL Injection in WP Data Access <= 5.5.81
versions.)
+ TODO: check
+CVE-2026-81291 (Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7
version ...)
+ TODO: check
+CVE-2026-81290 (Unauthenticated Cross Site Scripting (XSS) in Email
Subscribers & News ...)
+ TODO: check
+CVE-2026-81287 (Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.)
+ TODO: check
+CVE-2026-81280 (Subscriber Sensitive Data Exposure in Print Barcode Labels for
your Wo ...)
+ TODO: check
+CVE-2026-81278 (Missing Authorization vulnerability in WPExperts Post SMTP
allows Expl ...)
+ TODO: check
+CVE-2026-81267 (A malicious webpage could stall a popup's cross-origin
navigation afte ...)
+ TODO: check
+CVE-2026-79483 (FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable
to a No ...)
+ TODO: check
+CVE-2026-79408 (An OS command injection vulnerability in MetaGPT 0.8.1 allows
an attac ...)
+ TODO: check
+CVE-2026-79407 (A path traversal vulnerability in the SPO extension of MetaGPT
0.8.1 a ...)
+ TODO: check
+CVE-2026-78319 (A service running on the affected products contains a
potential Time-o ...)
+ TODO: check
+CVE-2026-77950 (Generation of Error Message Containing Sensitive Information
vulnerabi ...)
+ TODO: check
+CVE-2026-77856 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
+ TODO: check
+CVE-2026-77823 (The LearnPress plugin for WordPress is vulnerable to SQL
Injection via ...)
+ TODO: check
+CVE-2026-77353 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-77352 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-77351 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-77348 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-77189 (The Charitable \u2013 Donation & Fundraising Platform
(Donation Forms, ...)
+ TODO: check
+CVE-2026-76006 (The Photo Gallery by Ays \u2013 Responsive Image Gallery
plugin for Wo ...)
+ TODO: check
+CVE-2026-75980 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs,
Wikis, F ...)
+ TODO: check
+CVE-2026-75965 (The User Profile Builder \u2013 Beautiful User Registration
Forms, Use ...)
+ TODO: check
+CVE-2026-75964 (The User Profile Builder \u2013 Beautiful User Registration
Forms, Use ...)
+ TODO: check
+CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons,
Widgets, Mega ...)
+ TODO: check
+CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent
Management for ...)
+ TODO: check
+CVE-2026-75594 (Kirby is an open-source content management system. Prior to
4.9.5 and ...)
+ TODO: check
+CVE-2026-75592 (Kirby is an open-source content management system. Prior to
4.9.5 and ...)
+ TODO: check
+CVE-2026-75460 (XueZhiSi Open Source Exam System <= 3.9.0 has a privilege
escalation v ...)
+ TODO: check
+CVE-2026-75458 (The teacher-end interface POST /api/teacher/user/delete/{id}
in XueZhi ...)
+ TODO: check
+CVE-2026-74837 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
+ TODO: check
+CVE-2026-71415 (Kirby is an open-source content management system. From 5.0.0
until 5. ...)
+ TODO: check
+CVE-2026-67395 (A path traversal vulnerability exists in Sage Employee Self
Service\u2 ...)
+ TODO: check
+CVE-2026-67394 (A critical local privilege escalation via OS command injection
vulnera ...)
+ TODO: check
+CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote
authenti ...)
+ TODO: check
+CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the
separation of pr ...)
+ TODO: check
+CVE-2026-61641 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-61640 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-61639 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-61638 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-54600 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-54599 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-54598 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-54179 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-52730 (Xibo is an open source digital signage platform with a web
content man ...)
+ TODO: check
+CVE-2026-51740 (Incorrect access control in the killProcess function of
TOTOLINK T6 4. ...)
+ TODO: check
+CVE-2026-51739 (Incorrect access control in the CloudSrvVersionCheck function
of TOTOL ...)
+ TODO: check
+CVE-2026-51738 (Incorrect access control in the LoadDefSettings function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51737 (Incorrect access control in the clearTracerouteLog function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51736 (Incorrect access control in the clearSyslog function of
TOTOLINK T6 4. ...)
+ TODO: check
+CVE-2026-51735 (Incorrect access control in the showSyslog function of
TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51734 (Incorrect access control in the informSlaveUpdate function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51733 (Incorrect access control in the FirmwareUpgrade function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51731 (Incorrect access control in the delVlanCfg function of
TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
+ TODO: check
+CVE-2026-4560
+ REJECTED
+CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request
desynchronization fo ...)
+ TODO: check
+CVE-2026-38577 (Insecure hardcoded credentials in the Admin account of Tenda
HG21 V4.0 ...)
+ TODO: check
+CVE-2026-19952 (The Frontend Admin by DynamiApps plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-19948 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE
with 70 ...)
+ TODO: check
+CVE-2026-19820 (A vulnerability in the Backblaze Client allows a local user to
make th ...)
+ TODO: check
+CVE-2026-19806 (The Support Genix \u2013 Helpdesk, AI Chatbot, Knowledge Base
& Custom ...)
+ TODO: check
+CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds
Ads Listin ...)
+ TODO: check
+CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is
vulnerable to St ...)
+ TODO: check
+CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path
resolves an att ...)
+ TODO: check
+CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to
generic SQL ...)
+ TODO: check
+CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an
attacker to pro ...)
+ TODO: check
+CVE-2026-18488 (The Blocksy Companion plugin for WordPress is vulnerable to
Stored Cro ...)
+ TODO: check
+CVE-2026-17589 (The Shopping Cart & eCommerce Store plugin for WordPress is
vulnerable ...)
+ TODO: check
+CVE-2026-16787 (The Live Composer \u2013 Free WordPress Website Builder plugin
for Wor ...)
+ TODO: check
+CVE-2026-14697 (net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a
transmit ne ...)
+ TODO: check
+CVE-2026-13732 (A flaw was found in GDB's STABS debug format parser. The
read_member_f ...)
+ TODO: check
+CVE-2026-13203 (The Live Composer \u2013 Free WordPress Website Builder plugin
for Wor ...)
+ TODO: check
+CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In
contact_ ...)
+ TODO: check
CVE-2026-XXXX [GHSA-g89c-p67h-r497: Heap buffer overflow in
`scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl`
items]
- libheif 1.23.2-1
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
@@ -10595,6 +10895,7 @@ CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and
AES-OCB decryption with an
CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was
identified in T ...)
NOT-FOR-US: TPLink
CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with
custom en ...)
+ {DLA-4765-1}
- expat 2.8.4-1 (bug #1144927)
[trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1322
@@ -29687,7 +29988,7 @@ CVE-2026-XXXX [Neutron sub-resource APIs do not verify
parent ownership]
NOTE: https://review.opendev.org/c/openstack/neutron/+/989624/
NOTE: https://review.opendev.org/c/openstack/neutron/+/991586
CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant
infinite ...)
- {DSA-6446-1}
+ {DSA-6446-1 DLA-4765-1}
- expat 2.8.3-1 (bug #1144064)
NOTE: https://github.com/libexpat/libexpat/pull/1296
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
@@ -72225,52 +72526,52 @@ CVE-2026-11745 (A vulnerability has been identified
in centraldogma-server-mirro
CVE-2026-10530 (The Pie Register WordPress plugin before 3.8.4.10 does not
use suffic ...)
NOT-FOR-US: WordPress plugin
CVE-2026-56412 (libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in
doCdataS ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1278
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/d19e834794060d18c061d94452c35d725393ea58
CVE-2026-56411 (xmlwf in libexpat before 2.8.2 has an integer overflow in
endDoctypeDe ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1263
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5
CVE-2026-56410 (xmlwf in libexpat before 2.8.2 has an integer overflow in
resolveSyste ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1252
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea
CVE-2026-56409 (xmlwf in libexpat before 2.8.2 has an integer overflow for the
output ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1259
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e
CVE-2026-56408 (libexpat before 2.8.2 has an integer overflow in copyString.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817
CVE-2026-56407 (libexpat before 2.8.2 has an integer overflow in doProlog that
is rela ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1262
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13
CVE-2026-56406 (libexpat before 2.8.2 has an integer overflow in
XML_ParseBuffer becau ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1255
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d
CVE-2026-56405 (libexpat before 2.8.2 has an integer overflow in
getAttributeId.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1251
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0
CVE-2026-56404 (libexpat before 2.8.2 has an integer overflow in addBinding.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1249
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164
CVE-2026-56403 (libexpat before 2.8.2 has an integer overflow in storeAtts.)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140557)
NOTE: https://github.com/libexpat/libexpat/pull/1232
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648
@@ -72940,7 +73241,7 @@ CVE-2026-56132 (In libexpat before 2.8.2, there is a
heap-based buffer overflow
- expat 2.8.2-1 (bug #1140388)
NOTE: https://github.com/libexpat/libexpat/pull/1272
CVE-2026-56131 (libexpat before 2.8.2 lacks handler call depth tracking for
calls to X ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1140387)
NOTE: https://github.com/libexpat/libexpat/pull/1267
CVE-2026-56099 (OpenBSD before commit 6a23123 (2026-06-18) contains an
out-of-bounds r ...)
@@ -84128,7 +84429,7 @@ CVE-2026-50292 (In libinput before 1.30.4 and 1.31.x
before 1.31.3, libinput-dev
NOTE: Fixed by:
https://gitlab.freedesktop.org/libinput/libinput/-/commit/b2bde9504d42a5976d76e1f27c640dc561fbd99b
(1.30.4)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/04/5
CVE-2026-50219 (libexpat before 2.8.2 lacks handler call depth tracking for
calls to X ...)
- {DSA-6404-1}
+ {DSA-6404-1 DLA-4765-1}
- expat 2.8.2-1 (bug #1138862)
NOTE: https://github.com/libexpat/libexpat/pull/1246
CVE-2026-8829 (HTML::Entities versions before 3.84 for Perl read freed heap
memory in ...)
@@ -162176,7 +162477,7 @@ CVE-2026-22246 (Mastodon is a free, open-source
social network server based on A
- mastodon <itp> (bug #859741)
CVE-2026-22245 (Mastodon is a free, open-source social network server based on
Activit ...)
- mastodon <itp> (bug #859741)
-CVE-2026-22244 (OpenMetadata is a unified metadata platform. Versions prior to
1.11.4 ...)
+CVE-2026-22244 (OpenMetadata is a unified metadata platform. Versions 1.5.0
through 1. ...)
NOT-FOR-US: OpenMetadata
CVE-2026-22242 (CoreShop is a Pimcore enhanced eCommerce solution. Prior to
version 4. ...)
NOT-FOR-US: CoreShop
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174b9773ede45a4b75ae17de8b406f6b5bf44561
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174b9773ede45a4b75ae17de8b406f6b5bf44561
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits