Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
72d9c050 by security tracker role at 2026-09-06T19:14:05+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,94 @@
-CVE-2026-86219
+CVE-2026-86283 (MISP's UiBeta theme collection view
(app/View/Themed/UiBeta/Collection ...)
+ TODO: check
+CVE-2026-86259 (OpenMAIC before 1.0.1 skips server-side request forgery
validation in ...)
+ TODO: check
+CVE-2026-86258 (nbviewer through 1.0.1 contains a path traversal vulnerability
in Loca ...)
+ TODO: check
+CVE-2026-86257 (wger before 2.6 fails to sanitize first_name and last_name
fields in t ...)
+ TODO: check
+CVE-2026-86256 (wger before 2.6 (affected versions <= 2.5.0) contains an open
redirect ...)
+ TODO: check
+CVE-2026-86255 (wger before 2.5 fails to validate the maximum duration of
routine date ...)
+ TODO: check
+CVE-2026-86254 (wger versions through master contain an incomplete
authorization bypas ...)
+ TODO: check
+CVE-2026-86253 (h3 (npm package) versions <= 2.0.1-rc.14 contain a path
traversal vuln ...)
+ TODO: check
+CVE-2026-86252 (h3 versions before 1.15.9 fail to sanitize carriage return
characters ...)
+ TODO: check
+CVE-2026-86251 (h3 versions before 1.15.9 contain a path traversal
vulnerability in th ...)
+ TODO: check
+CVE-2026-86250 (h3 versions before 2.0.1-rc.18 fail to validate the chunk
count parsed ...)
+ TODO: check
+CVE-2026-86242 (Bifrost HTTP transport before 2.0.0 accepts an enabled custom
plugin w ...)
+ TODO: check
+CVE-2026-86221 (A flaw has been found in SourceCodester Class and Exam
Timetabling Sys ...)
+ TODO: check
+CVE-2026-86220 (A vulnerability was detected in SourceCodester Class and Exam
Timetabl ...)
+ TODO: check
+CVE-2026-86217 (A vulnerability was detected in code-projects Hotel and
Tourism Reserv ...)
+ TODO: check
+CVE-2026-86216 (A security vulnerability has been detected in code-projects
Hotel and ...)
+ TODO: check
+CVE-2026-86215 (A vulnerability was identified in Mstfakts
College-Management-System. ...)
+ TODO: check
+CVE-2026-86214 (A vulnerability was determined in Mstfakts
College-Management-System. ...)
+ TODO: check
+CVE-2026-86213 (A vulnerability was found in Mstfakts
College-Management-System. This ...)
+ TODO: check
+CVE-2026-86212 (A vulnerability has been found in Open5GS 2.7.7/2.8.0. This
vulnerabil ...)
+ TODO: check
+CVE-2026-86211 (A flaw has been found in rabindralamsal
inventory-management-system 1. ...)
+ TODO: check
+CVE-2026-86210 (A security vulnerability has been detected in SourceCodester
Class and ...)
+ TODO: check
+CVE-2026-86209 (A weakness has been identified in SourceCodester Class and
Exam Timeta ...)
+ TODO: check
+CVE-2026-86208 (A security flaw has been discovered in SourceCodester Class
and Exam T ...)
+ TODO: check
+CVE-2026-86205 (h3 versions before 2.0.1-rc.18 contain an open redirect
vulnerability ...)
+ TODO: check
+CVE-2026-86183 (A vulnerability was identified in diem-project diem up to
5.1.3. This ...)
+ TODO: check
+CVE-2026-86182 (A vulnerability was determined in diem-project diem up to
5.1.3. This ...)
+ TODO: check
+CVE-2026-86181 (A vulnerability was found in code-projects Task Management
System 1.0. ...)
+ TODO: check
+CVE-2026-86180 (A vulnerability has been found in code-projects Task
Management System ...)
+ TODO: check
+CVE-2026-86179 (A flaw has been found in code-projects Daily Expense Manager
1.0. Affe ...)
+ TODO: check
+CVE-2026-86172 (A vulnerability was detected in DefaultFuction CRM 1.0.0. This
impacts ...)
+ TODO: check
+CVE-2026-83534 (PostgreSQL Anonymizer contains a vulnerability in the
anon.anonymize_d ...)
+ TODO: check
+CVE-2026-82751 (Improper Validation of Specified Quantity in Input in ZenHive
mpp allo ...)
+ TODO: check
+CVE-2026-82750 (Improper Validation of Specified Quantity in Input in ZenHive
mpp allo ...)
+ TODO: check
+CVE-2026-80439 (The Redirection for Contact Form 7 WordPress plugin from 2.2.7
before ...)
+ TODO: check
+CVE-2026-80437 (The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2
does not p ...)
+ TODO: check
+CVE-2026-19862 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not
validate o ...)
+ TODO: check
+CVE-2026-19859 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not
sanitize a ...)
+ TODO: check
+CVE-2026-19634 (PostgreSQL Anonymizer contains a SQL injection vulnerability
in two im ...)
+ TODO: check
+CVE-2026-19633 (PostgreSQL Anonymizer contains a vulnerability that allows
unprivilege ...)
+ TODO: check
+CVE-2022-51009 (PocketMine-MP before 4.7.2 fails to properly handle exceptions
from th ...)
+ TODO: check
+CVE-2022-51008 (PocketMine-MP before 4.12.3 fails to limit unauthenticated
sessions, a ...)
+ TODO: check
+CVE-2021-48007 (PocketMine-MP versions before 3.18.1 fail to validate NaN or
INF value ...)
+ TODO: check
+CVE-2021-48006 (PocketMine-MP before 4.0.3 does not perform case-insensitive
matching ...)
+ TODO: check
+CVE-2020-37277 (PocketMine-MP versions before 3.15.4 contain a denial of
service vulne ...)
+ TODO: check
+CVE-2026-86219 (Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl
accept ...)
- libauthen-sasl-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43326063/
NOTE: Fixed by:
https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d
(v2.2100)
@@ -4032,61 +4122,61 @@ CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06
relies on a client's source
NOT-FOR-US: Oxford Nanopore MinKNOW
CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an
authentic ...)
NOT-FOR-US: Proxmox Virtual Environment
-CVE-2026-82209
+CVE-2026-82209 (When libpsl support is enabled, libcurl fails to enforce the
Public Su ...)
- curl 8.22.0-1
[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-82209.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465
(curl-7_46_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6
(curl-8_22_0)
-CVE-2026-82208
+CVE-2026-82208 (With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_S ...)
- curl 8.22.0-1 (unimportant)
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2026-82208.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/0f2876b2c33f6784a27b6f7345bd8cd95b46352a
(curl-8_9_1)
NOTE: Fixed by:
https://github.com/curl/curl/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a
(curl-8_22_0)
NOTE: curl in Debian not built with wolfSSL support
-CVE-2026-80255
+CVE-2026-80255 (A `Set-Cookie:` header using tab (horizontal tab, ASCII code
9) instea ...)
- curl 8.22.0-1
[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2026-80255.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603
(curl-8_13_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/4f6aa41a0145e930e766775dbe860883d350aa0a
(curl-8_22_0)
-CVE-2026-80231
+CVE-2026-80231 (A flaw in libcurl makes it wrongly reuse an existing HTTPS
connection ...)
- curl <not-affected> (Only affects Curl on Windows and macOS)
NOTE: https://curl.se/docs/CVE-2026-80231.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/148534db57dda611cf8516e92e4d6e35fc1e5074
(curl-7_71_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42
(rc-8_22_0-3)
-CVE-2026-80230
+CVE-2026-80230 (When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options
that di ...)
- curl 8.22.0~rc3-1
[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-80230.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591
(curl-7_45_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef
(rc-8_22_0-3)
-CVE-2026-80229
+CVE-2026-80229 (When performing transfers via libcurl\u2019s multi interface,
pooled T ...)
- curl 8.22.0~rc3-1
[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2026-80229.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854
(rc-8_14_0-1)
NOTE: Fixed by:
https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb
(rc-8_22_0-3)
-CVE-2026-19931
+CVE-2026-19931 (A flaw in libcurl makes it wrongly reuse an HTTP connection
setup for ...)
- curl 8.22.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-19931.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59
(curl-7_64_1)
NOTE: Fixed by:
https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f
(rc-8_22_0-2)
-CVE-2026-18924
+CVE-2026-18924 (A flaw in libcurl's handling of HTTP/2 Server Push streams,
when the p ...)
- curl 8.22.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-18924.html
NOTE: Introduced with:
https://github.com/curl/curl/commit/ea7134ac874a66107e54ff93657ac565cf2ec4aa
(curl-7_44_0)
NOTE: Fixed by:
https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43
(rc-8_22_0-1)
-CVE-2026-13608
+CVE-2026-13608 (A flaw in the libcurl SASL negotiation for LDAP authentication
allows ...)
- curl 8.22.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <postponed> (Minor issue)
@@ -78732,28 +78822,28 @@ CVE-2026-8296 (In affected versions of Octopus Server
with certain access levels
CVE-2026-6798 (The 2Download Connector for 2DL Hosted Checkout plugin for
WordPress i ...)
NOT-FOR-US: WordPress plugin
CVE-2026-56211 (A remote code execution vulnerability was found in libaom, the
referen ...)
- {DSA-6411-1}
+ {DSA-6411-1 DLA-4774-1}
- aom 3.14.1-1 (bug #1140428)
[bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t
encoder control, introduced in 2.0.0)
NOTE:
https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490802
NOTE: https://issues.chromium.org/issues/503993985
CVE-2026-56210 (A heap-buffer-overflow read vulnerability was found in libaom,
the ref ...)
- {DSA-6411-1}
+ {DSA-6411-1 DLA-4774-1}
- aom 3.14.1-1 (bug #1140428)
[bullseye] - aom <not-affected> (1.0.0 lacks the SVC encoder
layer_context array, introduced in 2.0.0)
NOTE:
https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490801
NOTE: https://issues.chromium.org/issues/503975732
CVE-2026-56209 (An arbitrary address write vulnerability was found in libaom,
the refe ...)
- {DSA-6411-1}
+ {DSA-6411-1 DLA-4774-1}
- aom 3.14.1-1 (bug #1140428)
[bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t
encoder control, introduced in 2.0.0)
NOTE:
https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490800
NOTE: https://issues.chromium.org/issues/503993984
CVE-2026-56208 (A heap buffer overflow vulnerability was found in libaom, the
referenc ...)
- {DSA-6411-1}
+ {DSA-6411-1 DLA-4774-1}
- aom 3.14.1-1 (bug #1140428)
[bullseye] - aom <not-affected> (1.0.0 lacks LAP two-pass mode
(encoder), introduced upstream in 2.0.0)
NOTE:
https://aomedia.googlesource.com/aom/+/243f8ae84bfbc495b3a3c12948abc4dff3af2f84
@@ -137572,12 +137662,12 @@ CVE-2026-33171 (Statamic is a Laravel and Git
powered content management system
CVE-2026-33166 (Allure 2 is the version 2.x branch of Allure Report, a
multi-language ...)
NOT-FOR-US: Allure
CVE-2026-33165 (libde265 is an open source implementation of the h.265 video
codec. Pr ...)
- {DLA-4550-1}
+ {DSA-6486-1 DLA-4550-1}
- libde265 1.0.18-1 (bug #1131468)
NOTE:
https://github.com/strukturag/libde265/security/advisories/GHSA-653q-9f73-8hvg
NOTE: Fixed by:
https://github.com/strukturag/libde265/commit/c7891e412106130b83f8e8ea8b7f907e9449b658
(v1.0.17)
CVE-2026-33164 (libde265 is an open source implementation of the h.265 video
codec. Pr ...)
- {DLA-4550-1}
+ {DSA-6486-1 DLA-4550-1}
- libde265 1.0.18-1 (bug #1131469)
NOTE:
https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r
NOTE: Fixed by:
https://github.com/strukturag/libde265/commit/c7891e412106130b83f8e8ea8b7f907e9449b658
(v1.0.17)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72d9c050fec4d3f93290360c3c9f3d2dd7077e40
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72d9c050fec4d3f93290360c3c9f3d2dd7077e40
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits