Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3266caca by security tracker role at 2026-09-11T07:12:44+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,302 @@
-CVE-2026-88914
+CVE-2026-9768
+ REJECTED
+CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to
server- ...)
+ TODO: check
+CVE-2026-9327 (IBM WebSphere Application Server 9.0, and 8.5 could allow an
authentic ...)
+ TODO: check
+CVE-2026-9225 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an
authenti ...)
+ TODO: check
+CVE-2026-9176 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to
a secur ...)
+ TODO: check
+CVE-2026-8778 (The MIPL Grouped Checkout Fields for WooCommerce \u2013
Customize & Or ...)
+ TODO: check
+CVE-2026-89169 (live-boot ff8867c allows attackers to bypass the
dm-verity-enforce-roo ...)
+ TODO: check
+CVE-2026-89162 (In PCRE2 before 10.48, pcre2_serialize_encode might disclose
two bytes ...)
+ TODO: check
+CVE-2026-89161 (In PCRE2 before 10.48, pcre2_jit_match mishandles a previously
copied ...)
+ TODO: check
+CVE-2026-89160 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read during
the PCR ...)
+ TODO: check
+CVE-2026-89158 (PCRE2 before 10.48, on 32-bit platforms, has a
pcre2_compile_32 intege ...)
+ TODO: check
+CVE-2026-89157 (PCRE2 before 10.48, on 32-bit platforms, has a
pcre2_pattern_convert o ...)
+ TODO: check
+CVE-2026-89156 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read after
a JIT fa ...)
+ TODO: check
+CVE-2026-89151 (Forgejo before 16.0.4 allows use of restricted API tokens for
unintend ...)
+ TODO: check
+CVE-2026-89145 (Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to
HTML-escape ...)
+ TODO: check
+CVE-2026-89094 (Forgejo before 16.0.4 allows remote code execution via a
crafted templ ...)
+ TODO: check
+CVE-2026-89089 (A SQL injection vulnerability exists in the
JasperReports-based report ...)
+ TODO: check
+CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
+ TODO: check
+CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to
validate ...)
+ TODO: check
+CVE-2026-89060 (A flaw was found in multicluster-observability-addon. This
vulnerabili ...)
+ TODO: check
+CVE-2026-89054 (A missing authorization vulnerability in OpenNMS Horizon
allows config ...)
+ TODO: check
+CVE-2026-88260 (Authentication bypass using an alternate path or channel and
Improper ...)
+ TODO: check
+CVE-2026-88062 (OmniRoute is an open-source AI gateway providing a single
endpoint for ...)
+ TODO: check
+CVE-2026-88061 (career-ops is an open-source AI-assisted job search and
application ma ...)
+ TODO: check
+CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is
vulnerable ...)
+ TODO: check
+CVE-2026-87908 (multiparty is a Node.js library for parsing
multipart/form-data reques ...)
+ TODO: check
+CVE-2026-86815 (The BackWPup WordPress plugin before 5.7.5 does not properly
restrict ...)
+ TODO: check
+CVE-2026-86812 (The WPCafe WordPress plugin before 3.0.18 does not correctly
restrict ...)
+ TODO: check
+CVE-2026-86782 (The Visualizer WordPress plugin before 4.0.6 does not
properly author ...)
+ TODO: check
+CVE-2026-86781 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects
WordPre ...)
+ TODO: check
+CVE-2026-86780 (The Featured Image with URL WordPress plugin before 1.0.6 does
not san ...)
+ TODO: check
+CVE-2026-86779 (The Visualizer WordPress plugin before 4.0.6 does not
properly author ...)
+ TODO: check
+CVE-2026-86093 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could
allow a ...)
+ TODO: check
+CVE-2026-86087 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could
allow a ...)
+ TODO: check
+CVE-2026-85678 (The AI Builder WordPress plugin before 2.7.8 does not
sanitise custom ...)
+ TODO: check
+CVE-2026-85677 (The Gutenverse News WordPress plugin before 3.3.3 does not
restrict t ...)
+ TODO: check
+CVE-2026-85025 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an
unauthen ...)
+ TODO: check
+CVE-2026-84960 (The WP-Members Membership Plugin plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-84941 (An information disclosure vulnerability in the SAML Single
Sign-On (SS ...)
+ TODO: check
+CVE-2026-84889 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-84432 (Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF
token in t ...)
+ TODO: check
+CVE-2026-83546 (The CoolClock WordPress plugin before 4.3.8 does not properly
escape a ...)
+ TODO: check
+CVE-2026-83545 (The CoolClock WordPress plugin before 4.3.8 does not properly
escape a ...)
+ TODO: check
+CVE-2026-82305 (The YITH WooCommerce Wishlist WordPress plugin before 4.18.1
does not ...)
+ TODO: check
+CVE-2026-82107 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-82100 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-82099 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-82098 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-82097 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-82095 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-82092 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-81941 (IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated
non-admi ...)
+ TODO: check
+CVE-2026-81940 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-81906 (Concrete CMS OAuth callback login path prior to version 9.5.3
did not ...)
+ TODO: check
+CVE-2026-81905 (Concrete CMS below 9.5.3 stores user validation hashes for
multiple pu ...)
+ TODO: check
+CVE-2026-81825 (The Simple Ajax Chat \u2013 Add a Fast, Secure Chat Box plugin
for Wor ...)
+ TODO: check
+CVE-2026-81754 (The Vigilant \u2013 100% Free Security Suite: Firewall, 2FA,
Login, He ...)
+ TODO: check
+CVE-2026-81554 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-81551 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-81550 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-81540 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-81268 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-81265 (IBM Langflow OSS 1.0.0 through 1.11.5.)
+ TODO: check
+CVE-2026-81213 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
attacker to ...)
+ TODO: check
+CVE-2026-81211 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-81210 (IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three
caller- ...)
+ TODO: check
+CVE-2026-81207 (IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any
authenticated t ...)
+ TODO: check
+CVE-2026-81204 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
attacker to ...)
+ TODO: check
+CVE-2026-80436 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-80434 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-80424 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-80380 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote attac ...)
+ TODO: check
+CVE-2026-80378 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
+ TODO: check
+CVE-2026-7438 (The Bold Timeline Lite plugin for WordPress is vulnerable to
Stored Cr ...)
+ TODO: check
+CVE-2026-79742 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-79725 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-79724 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
attacker to ...)
+ TODO: check
+CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-79592 (An out-of-bounds read vulnerability exists in the
xls_dumpSummary() fu ...)
+ TODO: check
+CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists
in the ...)
+ TODO: check
+CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism
parser co ...)
+ TODO: check
+CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-78573 (IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a
remote ...)
+ TODO: check
+CVE-2026-78571 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
+ TODO: check
+CVE-2026-78569 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow an
authenticated att ...)
+ TODO: check
+CVE-2026-78172 (The Themify \u2013 WooCommerce Product Filter plugin for
WordPress is ...)
+ TODO: check
+CVE-2026-77807 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and
Marketing Auto ...)
+ TODO: check
+CVE-2026-77150 (The Unlimited Elements For Elementor plugin for WordPress is
vulnerabl ...)
+ TODO: check
+CVE-2026-76653 (A missing authentication vulnerability in the VPN
configuration manage ...)
+ TODO: check
+CVE-2026-76652 (An authenticated directory traversal vulnerability in file
upload func ...)
+ TODO: check
+CVE-2026-76059 (IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could
submit cus ...)
+ TODO: check
+CVE-2026-75940 (A vulnerability was reported in Lenovo Health Android
Application, dis ...)
+ TODO: check
+CVE-2026-75777 (IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow
a local ...)
+ TODO: check
+CVE-2026-75624 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
+ TODO: check
+CVE-2026-74925 (The MultiVendorX WordPress plugin before 5.0.16 does not
restrict who ...)
+ TODO: check
+CVE-2026-73785 (A potential security vulnerability in HPE IceWall Federation
Agent and ...)
+ TODO: check
+CVE-2026-73784 (A potential security vulnerability in HPE IceWall products
could be ex ...)
+ TODO: check
+CVE-2026-71647 (An issue in EGO-Planner-v2 All versions up to commit
5c99a95880401e259 ...)
+ TODO: check
+CVE-2026-71645 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested
affected ...)
+ TODO: check
+CVE-2026-71643 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to
commit 5c99 ...)
+ TODO: check
+CVE-2026-71642 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to
commit 5c99 ...)
+ TODO: check
+CVE-2026-71640 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to
commit 5c99 ...)
+ TODO: check
+CVE-2026-63427 (An authentication bypass vulnerability was discovered in
Lenovo Softwa ...)
+ TODO: check
+CVE-2026-57844
+ REJECTED
+CVE-2026-54054 (Transmute is a free, open-source, self-hosted file conversion
and comp ...)
+ TODO: check
+CVE-2026-49836 (psd-tools is a Python package for working with Adobe Photoshop
PSD fil ...)
+ TODO: check
+CVE-2026-45770 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45769 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45768 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45767 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45766 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45765 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45764 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45762 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45761 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45759 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45752 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-45751 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
+ TODO: check
+CVE-2026-3096 (The product's web portals allow external links to be opened in
a new b ...)
+ TODO: check
+CVE-2026-36392 (FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site
Scriptin ...)
+ TODO: check
+CVE-2026-2310 (IBM webMethods Integration Server 11.1 IBM webMethods
Integration is v ...)
+ TODO: check
+CVE-2026-19991 (The UsersWP plugin for WordPress is vulnerable to Arbitrary
File Delet ...)
+ TODO: check
+CVE-2026-19985 (The Relevanssi \u2013 A Better Search plugin for WordPress is
vulnerab ...)
+ TODO: check
+CVE-2026-19646 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2,
ART 9.0, ...)
+ TODO: check
+CVE-2026-19596 (An XML External Entity (XXE) vulnerability exists in the XML
collector ...)
+ TODO: check
+CVE-2026-19136 (A potential command injection vulnerability was reported in
the Tianxi ...)
+ TODO: check
+CVE-2026-18994 (A potential improper authorization vulnerability was reported
in the L ...)
+ TODO: check
+CVE-2026-18964 (The Floating Chat Widget: Contact Chat Icons, Telegram Chat,
Line Mess ...)
+ TODO: check
+CVE-2026-18579 (The WP Photo Album Plus plugin for WordPress is vulnerable to
Stored C ...)
+ TODO: check
+CVE-2026-18562 (The HUSKY \u2013 Products Filter Professional for WooCommerce
plugin f ...)
+ TODO: check
+CVE-2026-18561 (The Unlimited Elements For Elementor plugin for WordPress is
vulnerabl ...)
+ TODO: check
+CVE-2026-18121 (Concrete CMS 9.5.2 and below is vulnerable to an authorization
bypass ...)
+ TODO: check
+CVE-2026-17176 (An OS command injection vulnerability in the TDDP module of
Deco BE110 ...)
+ TODO: check
+CVE-2026-16174 (Netskope was notified about a potential gap in Netskope
Endpoint DLP ( ...)
+ TODO: check
+CVE-2026-16172 (Netskope was notified of an out-of-bounds heap read affecting
the Endp ...)
+ TODO: check
+CVE-2026-15462 (The Sticky Chat Widget plugin for WordPress is vulnerable to
SQL Injec ...)
+ TODO: check
+CVE-2026-14566 (The advanced-customized-prompts WordPress plugin through 1.0.1
does no ...)
+ TODO: check
+CVE-2026-14565 (The advanced-customized-prompts WordPress plugin through 1.0.1
does no ...)
+ TODO: check
+CVE-2026-14563 (The advanced-customized-prompts WordPress plugin through 1.0.1
does no ...)
+ TODO: check
+CVE-2026-14562 (The teddy-bear-customize-addon WordPress plugin through 1.0.5
does not ...)
+ TODO: check
+CVE-2026-14560 (The teddy-bear-customize-addon WordPress plugin through 1.0.5
does not ...)
+ TODO: check
+CVE-2026-14559 (The teddy-bear-customize-addon WordPress plugin through 1.0.5
does not ...)
+ TODO: check
+CVE-2026-13326 (An out-of-bounds read in Qt NFC's language code length parsing
allows ...)
+ TODO: check
+CVE-2026-12215 (The OTP Login & Register Woocommerce plugin for WordPress is
vulnerabl ...)
+ TODO: check
+CVE-2026-11813 (A potential improper permissions vulnerability was reported in
the Len ...)
+ TODO: check
+CVE-2026-11496 (The Woo PDF Invoice Builder plugin (also distributed as "PDF
Builder f ...)
+ TODO: check
+CVE-2026-11446 (The Booktics \u2013 Booking Calendar for Appointments and
Service Busi ...)
+ TODO: check
+CVE-2025-57231 (Path Traversal in avatar attachments in Docmost v0.21.0 allows
an unau ...)
+ TODO: check
+CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin
before 3.0.10 ...)
+ TODO: check
+CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4
plugin. When p ...)
- gst-plugins-good1.0 1.28.7-1
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0079.html
NOTE:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5235
@@ -6,9 +304,9 @@ CVE-2026-88914
NOTE:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12437
NOTE: Fixed by:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a2a14d1b23d4a74d388f43745f000ea4999bf1d3
(1.28.7)
NOTE: Fixed by:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/c297f67b20d6284e58ebb2bcd61a1a3ffa0eedab
(1.28.7)
-CVE-2026-89011
+CVE-2026-89011 (isomorphic-git before 1.42.0 contains a prototype pollution
vulnerabil ...)
NOT-FOR-US: isomorphic-git
-CVE-2026-89092 [Stack overflow in nscd due to unbounded alloca use]
+CVE-2026-89092 (The nscd service in the GNU C Library 2.3.4 onwards may crash
due to a ...)
- glibc <unfixed>
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34624
NOTE:
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016
@@ -5768,58 +6066,58 @@ CVE-2026-78254 (The ftp and scp tasks of Apache Ant can
download files from a re
NOTE:
https://github.com/apache/ant/commit/07ee9c418e3bd3e7d0287fc9aaba3011e88f0dc2
(ANT_1.10.18_RC1)
NOTE:
https://github.com/apache/ant/commit/9252566cab812c59a5695679ba11f497e85aabb0
(ANT_1.10.18_RC1)
NOTE:
https://github.com/apache/ant/commit/3807d672ea18d9f8dafd5eb9b2fe1de05f664539
(ANT_1.10.18_RC1)
-CVE-2026-78123
+CVE-2026-78123 (strongSwan 5.0.2 through 6.0.7 has an Expired Pointer
Dereference in P ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78123
-CVE-2026-78124
+CVE-2026-78124 (strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate
enumeration i ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78124
-CVE-2026-78126
+CVE-2026-78126 (strongSwan 4.1.10 through 6.0.7 allows a NULL pointer
dereference in t ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78126).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78126
-CVE-2026-78127
+CVE-2026-78127 (libcharon in strongSwan 4.1.2 through 6.0.7 has a missing
release of m ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78127).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78127
-CVE-2026-78129
+CVE-2026-78129 (strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5
decrypti ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78129).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78129/
-CVE-2026-78130
+CVE-2026-78130 (strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference
in the x ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78130).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78130
-CVE-2026-78131
+CVE-2026-78131 (strongSwan 4.2.0 through 6.0.7 has a missing release of memory
after i ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78131).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78131
-CVE-2026-78132
+CVE-2026-78132 (strongSwan 5.1.3 through 6.0.7 has an infinite loop in the
x509 plugin ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78132).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78132
-CVE-2026-78133
+CVE-2026-78133 (libcharon in strongSwan 6.0.0 through 6.0.7 has a
use-after-free in IK ...)
{DSA-6487-1}
- strongswan 6.1.0-1
[bookworm] - strongswan <not-affected> (Vulnerable code introduced
later)
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78133).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78133/
-CVE-2026-78134
+CVE-2026-78134 (strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in
the eap ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html
NOTE: Patches: https://download.strongswan.org/security/CVE-2026-78134/
-CVE-2026-78135
+CVE-2026-78135 (libcharon in strongSwan 5.9.7 through 6.0.7 mishandles
behavioral work ...)
{DSA-6487-1}
- strongswan 6.1.0-1
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html
@@ -22304,31 +22602,37 @@ CVE-2026-63481 (Hurl is a command line tool that runs
and tests HTTP requests de
NOTE: https://github.com/Orange-OpenSource/hurl/pull/5119
NOTE: Fixed by:
https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e
CVE-2026-63388 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72
(release-2.1.13-stable)
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9
(release-2.2.2-alpha)
CVE-2026-63387 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/377b9022c3ac61aa4540b5dc4b70c60bf74c663d
(release-2.1.13-stable)
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/9877a7205ea024d0120effb040e1b8e034435407
(release-2.2.2-alpha)
CVE-2026-63385 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2
(release-2.1.13-stable)
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0
(release-2.2.2-alpha)
CVE-2026-63384 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416
(release-2.1.13-stable)
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda
(release-2.2.2-alpha)
CVE-2026-63383 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb
(release-2.1.13-stable)
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321
(release-2.2.2-alpha)
CVE-2026-63382 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6
(release-2.1.13-stable)
@@ -22336,6 +22640,7 @@ CVE-2026-63382 (Libevent is an event notification
library. Prior to 2.1.13 and 2
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e
(release-2.2.2-alpha)
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660
(release-2.2.2-alpha)
CVE-2026-63381 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c
(release-2.1.13-stable)
@@ -22345,6 +22650,7 @@ CVE-2026-63380 (Libevent is an event notification
library. Prior to 2.2.2-alpha,
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/825c18bd99f556b59d61200523237f264d5cc734
(release-2.2.2-alpha)
CVE-2026-63379 (Libevent is an event notification library. Prior to 2.1.13 and
2.2.2-a ...)
+ {DSA-6493-1}
- libevent 2.1.13-stable-1
NOTE:
https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6
NOTE: Fixed by:
https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636
(release-2.1.13-stable)
@@ -73479,7 +73785,7 @@ CVE-2026-12996 (A use-after-free in OpenVPN 2.6.0
through 2.6.20 and 2.7_alpha1
[bullseye] - openvpn 2.5.1-3+deb11u4
NOTE: Fixed by:
https://github.com/OpenVPN/openvpn/commit/5ee1f9b90fe03ecf7cef5431147ecaabbe96db9e
(v2.7.5)
NOTE: The issue is caused by the patch for CVE-2026-40215. Bullseye's
version contains the fix for both.
-CVE-2026-49838
+CVE-2026-49838 (GoBGP is an open source Border Gateway Protocol (BGP)
implementation i ...)
- gobgp 4.7.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
[bookworm] - gobgp <postponed> (Minor issue, DoS via empty AS_PATH in
confed eBGP validation)
@@ -96152,7 +96458,7 @@ CVE-2026-50593 (Graphite before 1.3.15 has an integer
underflow and resultant ou
[bookworm] - graphite2 1.3.14-1+deb12u1
[bullseye] - graphite2 <postponed> (Minor issue)
NOTE: Fixed by:
https://github.com/silnrsi/graphite/commit/ad78c6b7319909e1540c1b134e115ced03417866
(1.3.15)
-CVE-2026-49837
+CVE-2026-49837 (GoBGP is an open source Border Gateway Protocol (BGP)
implementation i ...)
- gobgp 4.6.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
[bookworm] - gobgp <postponed> (Minor issue, OPEN capability length
under-enforcement)
@@ -136261,6 +136567,7 @@ CVE-2026-34876 (An issue was discovered in Mbed TLS
3.x before 3.6.6. An out-of-
[bullseye] - mbedtls <not-affected> (Vulnerable code not present)
NOTE:
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ccm-finish-boundary-check/
CVE-2026-34835 (Rack is a modular Ruby web server interface. From versions
3.0.0.beta1 ...)
+ {DSA-6492-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
[bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136269,7 +136576,7 @@ CVE-2026-34835 (Rack is a modular Ruby web server
interface. From versions 3.0.0
NOTE: Fixed by:
https://github.com/rack/rack/commit/224662608dad63b31ba138d7e76e4ca8e42e9fc6
(v3.2.6)
NOTE: Fixed by:
https://github.com/rack/rack/commit/c49558af795b4c1978d16db071c8344db05a2b0d
(v3.1.21)
CVE-2026-34831 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-q2ww-5357-x388
@@ -136277,7 +136584,7 @@ CVE-2026-34831 (Rack is a modular Ruby web server
interface. Prior to versions 2
NOTE: Fixed by:
https://github.com/rack/rack/commit/c3645d377f0335a779812bf3f36e238d87d9b4e6
(v3.1.21)
NOTE: Fixed by:
https://github.com/rack/rack/commit/a75847314e8ad847a5b66e7215381c4ed51f6aa7
(v2.2.23)
CVE-2026-34830 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-qv7j-4883-hwh7
@@ -136285,7 +136592,7 @@ CVE-2026-34830 (Rack is a modular Ruby web server
interface. Prior to versions 2
NOTE: Fixed by:
https://github.com/rack/rack/commit/59a0966a484f2903833fa3e4c81919d3c645738d
(v3.1.21)
NOTE: Fixed by:
https://github.com/rack/rack/commit/7f288de93768b5cc44a5f4ed1ac02470d8fe52f4
(v2.2.23)
CVE-2026-34829 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-8vqr-qjwx-82mw
@@ -136295,6 +136602,7 @@ CVE-2026-34829 (Rack is a modular Ruby web server
interface. Prior to versions 2
CVE-2026-34828 (listmonk is a standalone, self-hosted, newsletter and mailing
list man ...)
NOT-FOR-US: listmonk
CVE-2026-34827 (Rack is a modular Ruby web server interface. From versions
3.0.0.beta1 ...)
+ {DSA-6492-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
[bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136303,7 +136611,7 @@ CVE-2026-34827 (Rack is a modular Ruby web server
interface. From versions 3.0.0
NOTE: Fixed by:
https://github.com/rack/rack/commit/bfb69142dbe2a1e3298ad52d12935938d1b58205
(v3.2.6)
NOTE: Fixed by:
https://github.com/rack/rack/commit/17ce7836be1523a7b453f3c06fe070ad7c954708
(v3.1.21)
CVE-2026-34826 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-x8cg-fq8g-mxfx
@@ -136379,7 +136687,7 @@ CVE-2026-34791 (Endian Firewall version 3.3.25 and
prior allow authenticated use
CVE-2026-34790 (Endian Firewall version 3.3.25 and prior allow authenticated
users to ...)
NOT-FOR-US: Endian Firewall
CVE-2026-34786 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-q4qf-9j86-f5mh
@@ -136387,7 +136695,7 @@ CVE-2026-34786 (Rack is a modular Ruby web server
interface. Prior to versions 2
NOTE: Fixed by:
https://github.com/rack/rack/commit/84937c38065d0a7630828fdd526201c5241a9619
(v3.1.21)
NOTE: Fixed by:
https://github.com/rack/rack/commit/4207d22e58a41d57a2c6e1ed2602170504b000c7
(v2.2.23)
CVE-2026-34785 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-h2jq-g4cq-5ppq
@@ -136395,7 +136703,7 @@ CVE-2026-34785 (Rack is a modular Ruby web server
interface. Prior to versions 2
NOTE: Fixed by:
https://github.com/rack/rack/commit/a17cb99b3440a4db09fb920407adf5ead127704c
(v3.1.21)
NOTE: Fixed by:
https://github.com/rack/rack/commit/203730e4abb2fac3a0514d6dc3ac56de82bdff9a
(v2.2.23)
CVE-2026-34763 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-7mqq-6cf9-v2qp
@@ -136478,7 +136786,7 @@ CVE-2026-34426 (OpenClaw versions prior to commit
b57b680contain an approval byp
CVE-2026-34425 (OpenClaw versions prior to commit 8aceaf5 contain a preflight
validati ...)
NOT-FOR-US: OpenClaw
CVE-2026-34230 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-v569-hp3g-36wr
@@ -136534,6 +136842,7 @@ CVE-2026-33271 (Local privilege escalation due to
insecure folder permissions. T
CVE-2026-32871 (FastMCP is a Pythonic way to build MCP servers and clients.
Prior to v ...)
NOT-FOR-US: FastMCP
CVE-2026-32762 (Rack is a modular Ruby web server interface. From versions
3.0.0.beta1 ...)
+ {DSA-6492-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
[bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136641,6 +136950,7 @@ CVE-2026-28728 (Local privilege escalation due to DLL
hijacking vulnerability. T
CVE-2026-27774 (Local privilege escalation due to DLL hijacking vulnerability.
The fol ...)
NOT-FOR-US: Acronis
CVE-2026-26962 (Rack is a modular Ruby web server interface. From version
3.2.0 to bef ...)
+ {DSA-6492-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
[bookworm] - ruby-rack <not-affected> (Vulnerable code introduced later)
@@ -136649,7 +136959,7 @@ CVE-2026-26962 (Rack is a modular Ruby web server
interface. From version 3.2.0
NOTE: Fixed by:
https://github.com/rack/rack/commit/d50c4d3dab62fa80b2a276271d0d4fb338cfa7df
(v3.2.6)
NOTE: Fixed by:
https://github.com/rack/rack/commit/ae320b46617e9131c34ad77ea15f1c3b036c43e6
(v3.1.22)
CVE-2026-26961 (Rack is a modular Ruby web server interface. Prior to versions
2.2.23, ...)
- {DLA-4706-1}
+ {DSA-6492-1 DLA-4706-1}
[experimental] - ruby-rack 3.2.6-1
- ruby-rack 3.2.6-2
NOTE:
https://github.com/rack/rack/security/advisories/GHSA-vgpv-f759-9wx3
@@ -306288,14 +306598,12 @@ CVE-2024-48943
NOTE: https://nicmx.github.io/FORT-validator/CVE.html
NOTE:
https://github.com/NICMx/FORT-validator/commit/4ee88d1c3fa7df763dd52312134cd93c1ce50870
(1.6.4)
CVE-2024-56170 (A validation integrity issue was discovered in Fort through
1.6.4 befo ...)
- {DSA-6490-1}
- fort-validator <unfixed> (bug #1090916)
[trixie] - fort-validator <postponed> (Minor issue, revisit when fixed
upstream)
[bookworm] - fort-validator <postponed> (Minor issue, revisit when
fixed upstream)
[bullseye] - fort-validator <postponed> (Minor issue, wait until it's
fixed upstream)
NOTE: https://github.com/NICMx/FORT-validator/issues/82
CVE-2024-56169 (A validation integrity issue was discovered in Fort through
1.6.4 befo ...)
- {DSA-6490-1}
- fort-validator <unfixed> (bug #1090916)
[trixie] - fort-validator <postponed> (Minor issue, revisit when fixed
upstream)
[bookworm] - fort-validator <postponed> (Minor issue, revisit when
fixed upstream)
@@ -533640,8 +533948,8 @@ CVE-2022-26964 (Weak password derivation for export
in Devolutions Remote Deskto
NOT-FOR-US: Devolutions Remote Desktop Manager
CVE-2022-26963
RESERVED
-CVE-2022-26962
- RESERVED
+CVE-2022-26962 (Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under
NP_BCCAS- ...)
+ TODO: check
CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS
under NP_ ...)
NOT-FOR-US: Italtel NetMatch-S
CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is
affected by ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3266cacadf9f78f5842555c6e04bf13a0b6e4cf4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3266cacadf9f78f5842555c6e04bf13a0b6e4cf4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits