Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
174b9773 by security tracker role at 2026-09-01T07:12:48+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,303 @@
+CVE-2026-83772 (A vulnerability was detected in Cobham SATCOM VSAT7090 
Maritime Satell ...)
+       TODO: check
+CVE-2026-83744 (A security vulnerability has been detected in invoiceninja 
Invoice Nin ...)
+       TODO: check
+CVE-2026-83743 (A weakness has been identified in invoiceninja Invoice Ninja 
up to 5.1 ...)
+       TODO: check
+CVE-2026-83596 (A flaw was found in WebKitGTK. Processing malicious web 
content can ca ...)
+       TODO: check
+CVE-2026-83524 (A security vulnerability has been detected in RedPort 
Optimizer wXa-20 ...)
+       TODO: check
+CVE-2026-82971 (A vulnerability was determined in QVidium Opera11 
3.3.2a26-Ax4x-opera1 ...)
+       TODO: check
+CVE-2026-82957 (A vulnerability was found in hyperledger-firefly firefly up to 
1.4.0.  ...)
+       TODO: check
+CVE-2026-82954 (A vulnerability was detected in Dokploy up to 0.29.7. This 
issue affec ...)
+       TODO: check
+CVE-2026-82922 (A security vulnerability has been detected in ShopEx ECShop up 
to 2.5. ...)
+       TODO: check
+CVE-2026-82921 (A weakness has been identified in ShopEx ECShop up to 2.5.1. 
This affe ...)
+       TODO: check
+CVE-2026-82919 (A vulnerability was identified in cu silicon up to 0.1.5. 
Affected by  ...)
+       TODO: check
+CVE-2026-82914 (A security flaw has been discovered in kishan0725 
Hospital-Management- ...)
+       TODO: check
+CVE-2026-82909 (A vulnerability was determined in QuantumNous new-api up to 
1.0.0-rc.1 ...)
+       TODO: check
+CVE-2026-82908 (A vulnerability was found in MSI Dragon Center up to 
2.0.155.0. Affect ...)
+       TODO: check
+CVE-2026-82906 (A flaw has been found in sdcb chats up to 1.12.0. This impacts 
the fun ...)
+       TODO: check
+CVE-2026-82905 (A vulnerability was detected in sdcb chats up to 1.12.0. This 
affects  ...)
+       TODO: check
+CVE-2026-82882 (Devtron through 2.2.0 fails to enforce authorization checks on 
the GET ...)
+       TODO: check
+CVE-2026-82852 (Unauthenticated Server Side Request Forgery (SSRF) in MapSVG 
<= 8.15.0 ...)
+       TODO: check
+CVE-2026-82835 (A weakness has been identified in caoqianming django-vue-admin 
1.0. Th ...)
+       TODO: check
+CVE-2026-82834 (A security flaw has been discovered in Doccano Open Source 
Annotation  ...)
+       TODO: check
+CVE-2026-82833 (A vulnerability was identified in Doccano Open Source 
Annotation Tools ...)
+       TODO: check
+CVE-2026-82749 (Incorrect Authorization vulnerability in ash-project ash 
widens a rela ...)
+       TODO: check
+CVE-2026-82748 (Incorrect Authorization vulnerability in ash-project ash 
authorizes an ...)
+       TODO: check
+CVE-2026-82747 (Incorrect Authorization vulnerability in ash-project ash 
returns recor ...)
+       TODO: check
+CVE-2026-82746 (Missing Authorization vulnerability in ash-project ash allows 
an actor ...)
+       TODO: check
+CVE-2026-82745 (Improper Access Control vulnerability in ash-project ash lets 
a create ...)
+       TODO: check
+CVE-2026-82744 (Not Failing Securely (Failing Open) vulnerability in 
ash-project ash s ...)
+       TODO: check
+CVE-2026-82743 (Uncontrolled Resource Consumption vulnerability in ash-project 
ash let ...)
+       TODO: check
+CVE-2026-82742 (Uncontrolled Resource Consumption vulnerability in ash-project 
ash let ...)
+       TODO: check
+CVE-2026-82741 (Improper Validation of Specified Type of Input vulnerability 
in ash-pr ...)
+       TODO: check
+CVE-2026-82740 (Improper Input Validation vulnerability in ash-project ash 
fails to en ...)
+       TODO: check
+CVE-2026-82739 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
+       TODO: check
+CVE-2026-82738 (Improper Input Validation vulnerability in ash-project ash 
allows an a ...)
+       TODO: check
+CVE-2026-82737 (Integer Overflow or Wraparound vulnerability in ash-project 
ash lets a ...)
+       TODO: check
+CVE-2026-82736 (Incorrect Behavior Order: Validate Before Canonicalize 
vulnerability i ...)
+       TODO: check
+CVE-2026-82735 (Uncontrolled Resource Consumption vulnerability in ash-project 
ash all ...)
+       TODO: check
+CVE-2026-82734 (Improper Validation of Specified Quantity in Input 
vulnerability in as ...)
+       TODO: check
+CVE-2026-82733 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
+       TODO: check
+CVE-2026-82732 (Improper Input Validation vulnerability in ash-project 
ash_typescript  ...)
+       TODO: check
+CVE-2026-82731 (URL Redirection to Untrusted Site ('Open Redirect') 
vulnerability in a ...)
+       TODO: check
+CVE-2026-82730 (Incorrect Authorization vulnerability in ash-project 
ash_typescript al ...)
+       TODO: check
+CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.15 ...)
+       TODO: check
+CVE-2026-82397 (Tornado is a Python web framework and asynchronous networking 
library. ...)
+       TODO: check
+CVE-2026-82396 (Sulu is an open-source PHP content management system based on 
the Symf ...)
+       TODO: check
+CVE-2026-82395 (Sulu is an open-source PHP content management system based on 
the Symf ...)
+       TODO: check
+CVE-2026-82394 (Sulu is an open-source PHP content management system based on 
the Symf ...)
+       TODO: check
+CVE-2026-82393 (pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm 
accepts  ...)
+       TODO: check
+CVE-2026-82392 (pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 
until 11.1 ...)
+       TODO: check
+CVE-2026-82346 (A potential security vulnerability has been identified in the 
HP Image ...)
+       TODO: check
+CVE-2026-82229 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social 
Login a ...)
+       TODO: check
+CVE-2026-82228 (Unauthenticated Bypass Vulnerability in SiteGround Security <= 
1.6.6 v ...)
+       TODO: check
+CVE-2026-82226 (Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 
versions.)
+       TODO: check
+CVE-2026-82225 (Unauthenticated Broken Authentication in RegistrationMagic <= 
6.0.9.8  ...)
+       TODO: check
+CVE-2026-82224 (Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 
1.2.10 versio ...)
+       TODO: check
+CVE-2026-82221 (Unauthenticated Cross Site Scripting (XSS) in 
RegistrationMagic <= 6.0 ...)
+       TODO: check
+CVE-2026-81892 (EasyAdmin is a fast and modern admin generator for Symfony 
application ...)
+       TODO: check
+CVE-2026-81891 (elFinder is an open-source file manager for web, written in 
JavaScript ...)
+       TODO: check
+CVE-2026-81890 (elFinder is an open-source file manager for web, written in 
JavaScript ...)
+       TODO: check
+CVE-2026-81889 (elFinder is an open-source file manager for web, written in 
JavaScript ...)
+       TODO: check
+CVE-2026-81888 (@hono/oauth-providers is Authentication middleware for Hono. 
Prior to  ...)
+       TODO: check
+CVE-2026-81887 (Livewire is a full-stack framework for Laravel. From 
3.0.0-beta.1 unti ...)
+       TODO: check
+CVE-2026-81780 (Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 
versions.)
+       TODO: check
+CVE-2026-81779 (Improper Validation of Specified Quantity in Input 
vulnerability in Si ...)
+       TODO: check
+CVE-2026-81778 (Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 
1.0.6 versio ...)
+       TODO: check
+CVE-2026-81768 (Unauthenticated Cross Site Scripting (XSS) in Super Store 
Finder <= 7. ...)
+       TODO: check
+CVE-2026-81765 (Unauthenticated Cross Site Scripting (XSS) in Tailored Tools 
<= 3.0.2  ...)
+       TODO: check
+CVE-2026-81764 (Unauthenticated Cross Site Scripting (XSS) in Email Essentials 
<= 6.0. ...)
+       TODO: check
+CVE-2026-81763 (Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 
versions.)
+       TODO: check
+CVE-2026-81762 (Subscriber Broken Access Control in Booking and Rental Manager 
<= 2.7. ...)
+       TODO: check
+CVE-2026-81758 (Subscriber Broken Access Control in OwnerRez API <= 1.2.6 
versions.)
+       TODO: check
+CVE-2026-81756 (Unauthenticated SQL Injection in Smart Marketing SMS and 
Newsletters F ...)
+       TODO: check
+CVE-2026-81298 (Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 
4.0.5 v ...)
+       TODO: check
+CVE-2026-81297 (Subscriber Privilege Escalation in Fluent Forms Pro Add On 
Pack <= 6.2 ...)
+       TODO: check
+CVE-2026-81296 (Unauthenticated Broken Access Control in Fluent Forms Pro Add 
On Pack  ...)
+       TODO: check
+CVE-2026-81293 (Unauthenticated SQL Injection in WP Data Access <= 5.5.81 
versions.)
+       TODO: check
+CVE-2026-81291 (Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 
version ...)
+       TODO: check
+CVE-2026-81290 (Unauthenticated Cross Site Scripting (XSS) in Email 
Subscribers & News ...)
+       TODO: check
+CVE-2026-81287 (Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.)
+       TODO: check
+CVE-2026-81280 (Subscriber Sensitive Data Exposure in Print Barcode Labels for 
your Wo ...)
+       TODO: check
+CVE-2026-81278 (Missing Authorization vulnerability in WPExperts Post SMTP 
allows Expl ...)
+       TODO: check
+CVE-2026-81267 (A malicious webpage could stall a popup's cross-origin 
navigation afte ...)
+       TODO: check
+CVE-2026-79483 (FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable 
to a No ...)
+       TODO: check
+CVE-2026-79408 (An OS command injection vulnerability in MetaGPT 0.8.1 allows 
an attac ...)
+       TODO: check
+CVE-2026-79407 (A path traversal vulnerability in the SPO extension of MetaGPT 
0.8.1 a ...)
+       TODO: check
+CVE-2026-78319 (A service running on the affected products contains a 
potential Time-o ...)
+       TODO: check
+CVE-2026-77950 (Generation of Error Message Containing Sensitive Information 
vulnerabi ...)
+       TODO: check
+CVE-2026-77856 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
+       TODO: check
+CVE-2026-77823 (The LearnPress plugin for WordPress is vulnerable to SQL 
Injection via ...)
+       TODO: check
+CVE-2026-77353 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-77352 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-77351 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-77348 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-77189 (The Charitable \u2013 Donation & Fundraising Platform 
(Donation Forms, ...)
+       TODO: check
+CVE-2026-76006 (The Photo Gallery by Ays \u2013 Responsive Image Gallery 
plugin for Wo ...)
+       TODO: check
+CVE-2026-75980 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, 
Wikis, F ...)
+       TODO: check
+CVE-2026-75965 (The User Profile Builder \u2013 Beautiful User Registration 
Forms, Use ...)
+       TODO: check
+CVE-2026-75964 (The User Profile Builder \u2013 Beautiful User Registration 
Forms, Use ...)
+       TODO: check
+CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons, 
Widgets, Mega ...)
+       TODO: check
+CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent 
Management for  ...)
+       TODO: check
+CVE-2026-75594 (Kirby is an open-source content management system. Prior to 
4.9.5 and  ...)
+       TODO: check
+CVE-2026-75592 (Kirby is an open-source content management system. Prior to 
4.9.5 and  ...)
+       TODO: check
+CVE-2026-75460 (XueZhiSi Open Source Exam System <= 3.9.0 has a privilege 
escalation v ...)
+       TODO: check
+CVE-2026-75458 (The teacher-end interface POST /api/teacher/user/delete/{id} 
in XueZhi ...)
+       TODO: check
+CVE-2026-74837 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
+       TODO: check
+CVE-2026-71415 (Kirby is an open-source content management system. From 5.0.0 
until 5. ...)
+       TODO: check
+CVE-2026-67395 (A path traversal vulnerability exists in Sage Employee Self 
Service\u2 ...)
+       TODO: check
+CVE-2026-67394 (A critical local privilege escalation via OS command injection 
vulnera ...)
+       TODO: check
+CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote 
authenti ...)
+       TODO: check
+CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the 
separation of pr ...)
+       TODO: check
+CVE-2026-61641 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-61640 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-61639 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-61638 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-54600 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-54599 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-54598 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-54179 (backpack/crud provides Create, Read, Update & Delete (CRUD) 
functions  ...)
+       TODO: check
+CVE-2026-52730 (Xibo is an open source digital signage platform with a web 
content man ...)
+       TODO: check
+CVE-2026-51740 (Incorrect access control in the killProcess function of 
TOTOLINK T6 4. ...)
+       TODO: check
+CVE-2026-51739 (Incorrect access control in the CloudSrvVersionCheck function 
of TOTOL ...)
+       TODO: check
+CVE-2026-51738 (Incorrect access control in the LoadDefSettings function of 
TOTOLINK T ...)
+       TODO: check
+CVE-2026-51737 (Incorrect access control in the clearTracerouteLog function of 
TOTOLIN ...)
+       TODO: check
+CVE-2026-51736 (Incorrect access control in the clearSyslog function of 
TOTOLINK T6 4. ...)
+       TODO: check
+CVE-2026-51735 (Incorrect access control in the showSyslog function of 
TOTOLINK T6 4.1 ...)
+       TODO: check
+CVE-2026-51734 (Incorrect access control in the informSlaveUpdate function of 
TOTOLINK ...)
+       TODO: check
+CVE-2026-51733 (Incorrect access control in the FirmwareUpgrade function of 
TOTOLINK T ...)
+       TODO: check
+CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of 
TOTOLIN ...)
+       TODO: check
+CVE-2026-51731 (Incorrect access control in the delVlanCfg function of 
TOTOLINK T6 4.1 ...)
+       TODO: check
+CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
+       TODO: check
+CVE-2026-4560
+       REJECTED
+CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request 
desynchronization fo ...)
+       TODO: check
+CVE-2026-38577 (Insecure hardcoded credentials in the Admin account of Tenda 
HG21 V4.0 ...)
+       TODO: check
+CVE-2026-19952 (The Frontend Admin by DynamiApps plugin for WordPress is 
vulnerable to ...)
+       TODO: check
+CVE-2026-19948 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE 
with 70 ...)
+       TODO: check
+CVE-2026-19820 (A vulnerability in the Backblaze Client allows a local user to 
make th ...)
+       TODO: check
+CVE-2026-19806 (The Support Genix \u2013 Helpdesk, AI Chatbot, Knowledge Base 
& Custom ...)
+       TODO: check
+CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds 
Ads Listin ...)
+       TODO: check
+CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is 
vulnerable to St ...)
+       TODO: check
+CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path 
resolves an att ...)
+       TODO: check
+CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to 
generic SQL ...)
+       TODO: check
+CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an 
attacker to pro ...)
+       TODO: check
+CVE-2026-18488 (The Blocksy Companion plugin for WordPress is vulnerable to 
Stored Cro ...)
+       TODO: check
+CVE-2026-17589 (The Shopping Cart & eCommerce Store plugin for WordPress is 
vulnerable ...)
+       TODO: check
+CVE-2026-16787 (The Live Composer \u2013 Free WordPress Website Builder plugin 
for Wor ...)
+       TODO: check
+CVE-2026-14697 (net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a 
transmit ne ...)
+       TODO: check
+CVE-2026-13732 (A flaw was found in GDB's STABS debug format parser. The 
read_member_f ...)
+       TODO: check
+CVE-2026-13203 (The Live Composer \u2013 Free WordPress Website Builder plugin 
for Wor ...)
+       TODO: check
+CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is 
vulnerable to ...)
+       TODO: check
+CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In 
contact_ ...)
+       TODO: check
 CVE-2026-XXXX [GHSA-g89c-p67h-r497: Heap buffer overflow in 
`scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` 
items]
        - libheif 1.23.2-1
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
@@ -10595,6 +10895,7 @@ CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and 
AES-OCB decryption with an
 CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was 
identified in T ...)
        NOT-FOR-US: TPLink
 CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with 
custom en ...)
+       {DLA-4765-1}
        - expat 2.8.4-1 (bug #1144927)
        [trixie] - expat <no-dsa> (Minor issue)
        NOTE: https://github.com/libexpat/libexpat/pull/1322
@@ -29687,7 +29988,7 @@ CVE-2026-XXXX [Neutron sub-resource APIs do not verify 
parent ownership]
        NOTE: https://review.opendev.org/c/openstack/neutron/+/989624/
        NOTE: https://review.opendev.org/c/openstack/neutron/+/991586
 CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant 
infinite ...)
-       {DSA-6446-1}
+       {DSA-6446-1 DLA-4765-1}
        - expat 2.8.3-1 (bug #1144064)
        NOTE: https://github.com/libexpat/libexpat/pull/1296
        NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
@@ -72225,52 +72526,52 @@ CVE-2026-11745 (A vulnerability has been identified 
in centraldogma-server-mirro
 CVE-2026-10530 (The Pie Register  WordPress plugin before 3.8.4.10 does not 
use suffic ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-56412 (libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in 
doCdataS ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1278
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/d19e834794060d18c061d94452c35d725393ea58
 CVE-2026-56411 (xmlwf in libexpat before 2.8.2 has an integer overflow in 
endDoctypeDe ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1263
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5
 CVE-2026-56410 (xmlwf in libexpat before 2.8.2 has an integer overflow in 
resolveSyste ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1252
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea
 CVE-2026-56409 (xmlwf in libexpat before 2.8.2 has an integer overflow for the 
output  ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1259
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e
 CVE-2026-56408 (libexpat before 2.8.2 has an integer overflow in copyString.)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817
 CVE-2026-56407 (libexpat before 2.8.2 has an integer overflow in doProlog that 
is rela ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1262
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13
 CVE-2026-56406 (libexpat before 2.8.2 has an integer overflow in 
XML_ParseBuffer becau ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1255
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d
 CVE-2026-56405 (libexpat before 2.8.2 has an integer overflow in 
getAttributeId.)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1251
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0
 CVE-2026-56404 (libexpat before 2.8.2 has an integer overflow in addBinding.)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1249
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164
 CVE-2026-56403 (libexpat before 2.8.2 has an integer overflow in storeAtts.)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140557)
        NOTE: https://github.com/libexpat/libexpat/pull/1232
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648
@@ -72940,7 +73241,7 @@ CVE-2026-56132 (In libexpat before 2.8.2, there is a 
heap-based buffer overflow
        - expat 2.8.2-1 (bug #1140388)
        NOTE: https://github.com/libexpat/libexpat/pull/1272
 CVE-2026-56131 (libexpat before 2.8.2 lacks handler call depth tracking for 
calls to X ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1140387)
        NOTE: https://github.com/libexpat/libexpat/pull/1267
 CVE-2026-56099 (OpenBSD before commit 6a23123 (2026-06-18) contains an 
out-of-bounds r ...)
@@ -84128,7 +84429,7 @@ CVE-2026-50292 (In libinput before 1.30.4 and 1.31.x 
before 1.31.3, libinput-dev
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/libinput/libinput/-/commit/b2bde9504d42a5976d76e1f27c640dc561fbd99b
 (1.30.4)
        NOTE: https://www.openwall.com/lists/oss-security/2026/06/04/5
 CVE-2026-50219 (libexpat before 2.8.2 lacks handler call depth tracking for 
calls to X ...)
-       {DSA-6404-1}
+       {DSA-6404-1 DLA-4765-1}
        - expat 2.8.2-1 (bug #1138862)
        NOTE: https://github.com/libexpat/libexpat/pull/1246
 CVE-2026-8829 (HTML::Entities versions before 3.84 for Perl read freed heap 
memory in ...)
@@ -162176,7 +162477,7 @@ CVE-2026-22246 (Mastodon is a free, open-source 
social network server based on A
        - mastodon <itp> (bug #859741)
 CVE-2026-22245 (Mastodon is a free, open-source social network server based on 
Activit ...)
        - mastodon <itp> (bug #859741)
-CVE-2026-22244 (OpenMetadata is a unified metadata platform. Versions prior to 
1.11.4  ...)
+CVE-2026-22244 (OpenMetadata is a unified metadata platform. Versions 1.5.0 
through 1. ...)
        NOT-FOR-US: OpenMetadata
 CVE-2026-22242 (CoreShop is a Pimcore enhanced eCommerce solution. Prior to 
version 4. ...)
        NOT-FOR-US: CoreShop



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174b9773ede45a4b75ae17de8b406f6b5bf44561

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174b9773ede45a4b75ae17de8b406f6b5bf44561
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to