Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
635491ca by Moritz Muehlenhoff at 2026-09-01T18:00:27+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -169,6 +169,7 @@ CVE-2026-82730 (Incorrect Authorization vulnerability in 
ash-project ash_typescr
        NOT-FOR-US: ash-project
 CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.15 ...)
        - pypdf <unfixed>
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m
        NOTE: https://github.com/py-pdf/pypdf/pull/3947
@@ -3264,18 +3265,22 @@ CVE-2026-3129 (The LiteSpeed Cache plugin for WordPress 
is vulnerable to Stored
        NOT-FOR-US: WordPress plugin
 CVE-2026-38822 (In openNDS before 11.0.0, the client_params.sh script, invoked 
by the  ...)
        - opennds <unfixed>
+       [trixie] - opennds <no-dsa> (Minor issue)
        [bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
        NOTE: Fixed by: 
https://github.com/openNDS/openNDS/commit/294983e859bb678eef7db06fc9f6afab0b489d8e
 (v11.0.0)
 CVE-2026-38821 (A heap-based buffer overflow vulnerability exists in openNDS 
before 11 ...)
        - opennds <unfixed>
+       [trixie] - opennds <no-dsa> (Minor issue)
        [bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
        NOTE: Fixed by: 
https://github.com/openNDS/openNDS/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9
 (v11.0.0)
 CVE-2026-38820 (openNDS before 11.0.0 is susceptible to unauthenticated OS 
command exe ...)
        - opennds <unfixed>
+       [trixie] - opennds <no-dsa> (Minor issue)
        [bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
        NOTE: Fixed by: 
https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252
 (v11.0.0)
 CVE-2026-38819 (Multiple memory leaks in openNDS before 11.0.0 allow an 
unauthenticate ...)
        - opennds <unfixed>
+       [trixie] - opennds <no-dsa> (Minor issue)
        [bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
        NOTE: Fixed by: 
https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c
 (v11.0.0)
        NOTE: Fixed by: 
https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c
 (v11.0.0)
@@ -3445,6 +3450,7 @@ CVE-2026-80489
        NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34568
 CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a 
specially c ...)
        - python-jwcrypto <unfixed> (bug #1145983)
+       [trixie] - python-jwcrypto <no-dsa> (Minor issue)
        NOTE: 
https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
 CVE-2026-81501
        - incus 7.0.1-3
@@ -4460,6 +4466,7 @@ CVE-2023-27503
        REJECTED
 CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the 
community.general  ...)
        - ansible <unfixed>
+       [trixie] - ansible <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
 CVE-2026-78360
        NOT-FOR-US: fedora-infra/anitya
@@ -6335,6 +6342,7 @@ CVE-2026-72924 (GitHub CLI (gh) is GitHub's official 
command line tool. Versions
        NOTE: https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh
 CVE-2026-70665 (Doorkeeper OpenID Connect implements an OpenID Connect 
authentication  ...)
        - ruby-doorkeeper-openid-connect 1.10.5-1
+       [trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
        NOTE: 
https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-8r7r-wh7x-27ff
        NOTE: Fixed by: 
https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/abb47dc5e6012ea05eda0b7979cc6bd41904011b
 (v1.10.4)
 CVE-2026-68763 (Uncontrolled Resource Consumption vulnerability in Apache 
Tomcatvia an ...)
@@ -6552,6 +6560,7 @@ CVE-2026-45018 (Chainlit is a Python framework for 
building production-ready con
        NOT-FOR-US: Chainlit
 CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In 
version 1.9.0, ...)
        - ruby-doorkeeper-openid-connect 1.10.1-1
+       [trixie] - ruby-doorkeeper-openid-connect <no-dsa> (Minor issue)
        NOTE: 
https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-m6vc-f87m-cc2h
        NOTE: Fixed by: 
https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/561af83dcf71b95b3772dfbc0a1796c7f50b2175
 (v1.10.0)
 CVE-2026-43670 (A Content Security Policy bypass was addressed with improved 
enforceme ...)
@@ -10686,6 +10695,7 @@ CVE-2026-55095 (OpenProject is open-source, web-based 
project management softwar
        NOT-FOR-US: OpenProject
 CVE-2026-54770 (WebOb provides objects for HTTP requests and responses. Prior 
to 1.8.1 ...)
        - python-webob <unfixed>
+       [trixie] - python-webob <no-dsa> (Minor issue)
        NOTE: 
https://github.com/Pylons/webob/security/advisories/GHSA-6hx8-3wjj-gr8g
        NOTE: Fixed by: 
https://github.com/Pylons/webob/commit/ff89560643fb252751b4db8806a283b5377f1f07 
(1.8.11)
 CVE-2026-54625 (django CMS is a content management system powered by Django. 
Prior to  ...)
@@ -16442,6 +16452,7 @@ CVE-2026-62982 (Glances is an open-source system 
cross-platform monitoring tool.
        NOTE: CVE exists because of an incomplete fix for CVE-2026-32608.
 CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with 
pluggable I/O. P ...)
        - ruby-websocket-driver 0.8.2-1
+       [trixie] - ruby-websocket-driver <no-dsa> (Minor issue)
        NOTE: 
https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-2x63-gw47-w4mm
        NOTE: Fixed by: 
https://github.com/faye/websocket-driver-ruby/commit/7d6fd87759a2fdc83590d3b49ffa661dc53fa128
 (0.8.2)
 CVE-2026-60107
@@ -24882,10 +24893,11 @@ CVE-2026-71467 (A flaw was found in search-v2-api. 
The authentication middleware
        NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache 
HttpCompone ...)
        - httpcomponents-core5 <unfixed>
-       - httpcomponents-client <undetermined>
+       [trixie] - httpcomponents-core5 <not-affected> (Vulnerable code not 
present, introduced in 5.4)
+       [bookworm] - httpcomponents-core5 <not-affected> (Vulnerable code not 
present, introduced in 5.4)
+       - httpcomponents-client <not-affected> (Introduced in 5.4)
        NOTE: https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/6
-       TODO: check, claimed to affect only version 5.2 onwards
 CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of 
Red Hat Ad ...)
        NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-70339 (Access of resource using incompatible type ('type confusion') 
in Micro ...)
@@ -51926,6 +51938,7 @@ CVE-2024-23564 (HCL Aftermarket EPC is affected by 
Business Logic Vulnerability
 CVE-2026-14266 (7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code 
Executio ...)
        {DLA-4719-1 DLA-4718-1}
        - 7zip 26.02+dfsg-1 (bug #1142293)
+       [trixie] - 7zip <no-dsa> (Minor issue, will be fixed via spu)
        - p7zip 16.02+transitional.1
        NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only an empty 
source package
        NOTE: depending on 7zip. Mark this version as fixed version.
@@ -140388,11 +140401,13 @@ CVE-2026-28695 (Craft is a content management 
system (CMS). There is an authenti
 CVE-2026-28435 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        [experimental] - cpp-httplib 0.41.0+ds-1
        - cpp-httplib 0.41.0+ds-3 (bug #1130234)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xvfx-w463-6fpp
        NOTE: Fixed by: 
https://github.com/yhirose/cpp-httplib/commit/c99d7472b5cf4869d3897b9afc9792063a3d15a8
 (v0.35.0)
 CVE-2026-28434 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        [experimental] - cpp-httplib 0.41.0+ds-1
        - cpp-httplib 0.41.0+ds-3 (bug #1130232)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8mpw-r4gc-xm7q
        NOTE: Fixed by: 
https://github.com/yhirose/cpp-httplib/commit/defd907c7469c5c8281247b73bbd07be24c31164
 (v0.35.0)
 CVE-2026-28427 (OpenDeck is Linux software for your Elgato Stream Deck. Prior 
to 2.8.1 ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/635491ca1e9e9b9b3209516c15f0f9482d500cad

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/635491ca1e9e9b9b3209516c15f0f9482d500cad
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to