Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d4c523d6 by security tracker role at 2026-09-11T19:13:01+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,303 @@
+CVE-2026-9160 (Improper neutralization of special elements used in a template
engine ...)
+ TODO: check
+CVE-2026-8304 (Missing Authorization vulnerability in TUBITAK BILGEM Software
Technol ...)
+ TODO: check
+CVE-2026-8303 (Incorrect privilege assignment vulnerability in TUBITAK BILGEM
Softwar ...)
+ TODO: check
+CVE-2026-8301 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access
to the ...)
+ TODO: check
+CVE-2026-89298 (A flaw was found in the Dynamic Client Registration service of
Keycloa ...)
+ TODO: check
+CVE-2026-89265 (MoguBlog through 6.2 contains an authorization bypass
vulnerability in ...)
+ TODO: check
+CVE-2026-89264 (MoguBlog through 6.2 fails to validate the comment author
identity in ...)
+ TODO: check
+CVE-2026-89263 (MoguBlog through 6.2 fails to authenticate requests to the
/web/commen ...)
+ TODO: check
+CVE-2026-89262 (MoguBlog through 6.2 contains an authorization bypass
vulnerability in ...)
+ TODO: check
+CVE-2026-89261 (MoguBlog through 6.2 exposes Elasticsearch index management
endpoints ...)
+ TODO: check
+CVE-2026-89260 (MoguBlog through 6.2 contains an XML external entity injection
vulnera ...)
+ TODO: check
+CVE-2026-89259 (Hugo is a static site generator. From v0.161.0, Hugo executes
Node too ...)
+ TODO: check
+CVE-2026-89258 (Hugo is a static site generator. In versions after v0.123.0
and before ...)
+ TODO: check
+CVE-2026-89257 (AVideo through 29.0 contains an insecure direct object
reference (IDOR ...)
+ TODO: check
+CVE-2026-89256 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
+ TODO: check
+CVE-2026-89255 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
+ TODO: check
+CVE-2026-89254 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
+ TODO: check
+CVE-2026-89253 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89252 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
fails t ...)
+ TODO: check
+CVE-2026-89251 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
fails t ...)
+ TODO: check
+CVE-2026-89250 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89249 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
+ TODO: check
+CVE-2026-89248 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
is miss ...)
+ TODO: check
+CVE-2026-89247 (WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1
and ear ...)
+ TODO: check
+CVE-2026-89246 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89245 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89244 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89243 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89242 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89241 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89240 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89239 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+ TODO: check
+CVE-2026-89212 (A flaw resulting in XML external entity (XXE) was found in
Akana API P ...)
+ TODO: check
+CVE-2026-89179 (WeenyGenius, a computer lab management system by Howyar
Technologies, ...)
+ TODO: check
+CVE-2026-89178 (WeenyGenius, a computer lab management system by Howyar
Technologies, ...)
+ TODO: check
+CVE-2026-89177 (WeenyGenius, a computer lab management system by Howyar
Technologies, ...)
+ TODO: check
+CVE-2026-89176 (WeenyGenius, a computer lab management system developed by
Howyar Tech ...)
+ TODO: check
+CVE-2026-89175 (Smart Video Intercom System developed by Kingdom Communication
Associa ...)
+ TODO: check
+CVE-2026-89174 (Smart Video Intercom System developed by Kingdom Communication
Associa ...)
+ TODO: check
+CVE-2026-89173 (Smart Video Intercom System developed by Kingdom Communication
Associa ...)
+ TODO: check
+CVE-2026-89148 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
+ TODO: check
+CVE-2026-89147 (Net-SNMP through 5.9.5.2 contains a denial of service
vulnerability in ...)
+ TODO: check
+CVE-2026-89146 (libp2p-rendezvous through 0.17.1 fails to validate
registration TTL va ...)
+ TODO: check
+CVE-2026-89099 (A race condition in the document value layer of MongoDB Server
can all ...)
+ TODO: check
+CVE-2026-89090 (An unrecovered panic in the event stream header decoder in
Amazon AWS ...)
+ TODO: check
+CVE-2026-89066 (Improper neutralization of special elements used in an OS
command in t ...)
+ TODO: check
+CVE-2026-89065 (Relative path traversal in the generated file manifest cleanup
compone ...)
+ TODO: check
+CVE-2026-89013 (Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass
vulnerab ...)
+ TODO: check
+CVE-2026-89012 (Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive
denylist bypas ...)
+ TODO: check
+CVE-2026-89010 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to
M35M1_V2 ...)
+ TODO: check
+CVE-2026-89009 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to
M35M1_V2 ...)
+ TODO: check
+CVE-2026-87988 (An arbitrary file access vulnerability in Mistral Vibe allows
an attac ...)
+ TODO: check
+CVE-2026-87987 (An arbitrary code execution vulnerability in Mistral Vibe
allows an at ...)
+ TODO: check
+CVE-2026-87986 (An arbitrary code execution vulnerability in Mistral Vibe
allows an at ...)
+ TODO: check
+CVE-2026-87985 (An arbitrary code execution vulnerability in Mistral Vibe
allows an at ...)
+ TODO: check
+CVE-2026-87984 (An arbitrary file write vulnerability in Mistral Vibe,
introduced in v ...)
+ TODO: check
+CVE-2026-87983 (An arbitrary file read vulnerability in Mistral Vibe,
introduced in ve ...)
+ TODO: check
+CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support
links, i ...)
+ TODO: check
+CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In
versions b ...)
+ TODO: check
+CVE-2026-87776 (compression is a Node.js and Express compression middleware.
In versio ...)
+ TODO: check
+CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal
vulnerabi ...)
+ TODO: check
+CVE-2026-87123 (hbs is an Express view engine wrapper for Handlebars. Version
4.3.0 ca ...)
+ TODO: check
+CVE-2026-87122
+ REJECTED
+CVE-2026-87020 (An integer overflow in a specified pitch and buffer-size
computation l ...)
+ TODO: check
+CVE-2026-86813 (The MetForm WordPress plugin before 4.1.9 does not properly
neutralize ...)
+ TODO: check
+CVE-2026-86809 (The Persian Elementor WordPress plugin from 2.7.10 before
2.8.2 does n ...)
+ TODO: check
+CVE-2026-86793 (SGLang allows unauthenticated pickle deserialization through
/update_w ...)
+ TODO: check
+CVE-2026-85979 (Affected versions of Puppet Enterprise contain a command
injection vul ...)
+ TODO: check
+CVE-2026-85116 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin
from 1.2 ...)
+ TODO: check
+CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential
for bootl ...)
+ TODO: check
+CVE-2026-84390 (A inclusion of sensitive information in source code
vulnerability in F ...)
+ TODO: check
+CVE-2026-82617 (The two built-in name-finder patterns exposed by
opennlp.tools.namefin ...)
+ TODO: check
+CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier
allow an au ...)
+ TODO: check
+CVE-2026-82578 (When XML batch processing is turned on and the XPath option is
selecte ...)
+ TODO: check
+CVE-2026-82535 (Chamilo LMS before 1.11.42 and 3.0.0 contains a stored
cross-site scri ...)
+ TODO: check
+CVE-2026-82215 (The Payment Gateway PayPay for WooCommerce WordPress plugin
from 0.5 t ...)
+ TODO: check
+CVE-2026-82213 (The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does
not veri ...)
+ TODO: check
+CVE-2026-81910 (Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side
Template Inj ...)
+ TODO: check
+CVE-2026-81909 (Concrete CMS 9 through 9.5.2 is vulnerable to Missing
Authorization in ...)
+ TODO: check
+CVE-2026-81908 (Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization
vulnerabil ...)
+ TODO: check
+CVE-2026-81861 (CWE-522: Insufficiently Protected Credentials vulnerability
that could ...)
+ TODO: check
+CVE-2026-80469 (An attacker may achieve arbitrary code execution on a target
system by ...)
+ TODO: check
+CVE-2026-80462 (A vulnerability in the Chef Automate API gateway and identity
validati ...)
+ TODO: check
+CVE-2026-7863 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-7298 (Improper neutralization of input during web page generation
('cross-si ...)
+ TODO: check
+CVE-2026-79396 (Use of hardcoded default credentials in Xiongmai IP Camera
XM530 firmw ...)
+ TODO: check
+CVE-2026-79395 (An improper authentication vulnerability in the WS-Security
(wsse:User ...)
+ TODO: check
+CVE-2026-79394 (An insecure default configuration in the embedded Happytime
RTSP serve ...)
+ TODO: check
+CVE-2026-79393 (A heap-based buffer overflow vulnerability in the
WS-Addressing Action ...)
+ TODO: check
+CVE-2026-79362 (Certain Woltlab products are affected by RCE via Cache
Poisoning. WCF ...)
+ TODO: check
+CVE-2026-78807 (An issue in wpa_supplicant all versions before v.2.12 allows a
local a ...)
+ TODO: check
+CVE-2026-78224 (The XSLT Transformer Step builds a bare TransformerFactory
without the ...)
+ TODO: check
+CVE-2026-77159 (A symlink-following flaw was found in libvirt's
qemuTPMEmulatorPrepare ...)
+ TODO: check
+CVE-2026-72710 (SPIP before 4.4.18 contains a remote code execution
vulnerability in t ...)
+ TODO: check
+CVE-2026-72709 (SPIP before 4.4.18 contains a missing authorization
vulnerability in t ...)
+ TODO: check
+CVE-2026-72708 (SPIP before 4.4.18 contains an unauthenticated blind SQL
injection vul ...)
+ TODO: check
+CVE-2026-71646 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested
affected ...)
+ TODO: check
+CVE-2026-71644 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested
affected ...)
+ TODO: check
+CVE-2026-71641 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to
commit 5c99 ...)
+ TODO: check
+CVE-2026-71416 (Headroom compresses data before the data reaches a large
language mode ...)
+ TODO: check
+CVE-2026-70341 (Use after free in Microsoft Edge (Chromium-based) allows an
authorized ...)
+ TODO: check
+CVE-2026-6642 (The Media Library Assistant plugin for WordPress is vulnerable
to Stor ...)
+ TODO: check
+CVE-2026-6641 (The Media Library Assistant plugin for WordPress is vulnerable
to Stor ...)
+ TODO: check
+CVE-2026-6640 (The Media Library Assistant plugin for WordPress is vulnerable
to Stor ...)
+ TODO: check
+CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3 rendered
remote ...)
+ TODO: check
+CVE-2026-68497 (jackson-databind binds a JSON string to a
javax.xml.datatype.Duration ...)
+ TODO: check
+CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache
OpenNLP S ...)
+ TODO: check
+CVE-2026-62140 (Unauthenticated Insecure Direct Object References (IDOR) in
Quiz And S ...)
+ TODO: check
+CVE-2026-62139 (Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit
by Googl ...)
+ TODO: check
+CVE-2026-62138 (Contributor Cross Site Scripting (XSS) in Visual Composer
Website Buil ...)
+ TODO: check
+CVE-2026-62137 (Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14
versions.)
+ TODO: check
+CVE-2026-62136 (Unauthenticated Broken Access Control in Flexible Quantity
\u2013 Meas ...)
+ TODO: check
+CVE-2026-62135 (Unauthenticated Broken Access Control in Booktics <= 1.0.24
versions.)
+ TODO: check
+CVE-2026-62134 (Contributor Insecure Direct Object References (IDOR) in
Starter Templa ...)
+ TODO: check
+CVE-2026-62133 (Subscriber Cross Site Request Forgery (CSRF) in RTMKit <=
2.1.5 versio ...)
+ TODO: check
+CVE-2026-62132 (Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0
versions.)
+ TODO: check
+CVE-2026-62114 (Unauthenticated Broken Access Control in Passster <= 4.3.13
versions.)
+ TODO: check
+CVE-2026-62113 (Contributor Insecure Direct Object References (IDOR) in Slim
SEO <= 4. ...)
+ TODO: check
+CVE-2026-62112 (Editor SQL Injection in Amelia <= 2.4.9 versions.)
+ TODO: check
+CVE-2026-62111 (Contributor Cross Site Scripting (XSS) in Simple Payment <=
2.5.4 vers ...)
+ TODO: check
+CVE-2026-62110 (Contributor Cross Site Scripting (XSS) in Bold Page Builder <=
5.9.9 v ...)
+ TODO: check
+CVE-2026-62109 (Editor SQL Injection in Sky Addons for Elementor <= 3.8.4
versions.)
+ TODO: check
+CVE-2026-62107 (Unauthenticated PHP Object Injection in Masteriyo - LMS <=
3.4.0 versi ...)
+ TODO: check
+CVE-2026-62106 (Subscriber Privilege Escalation in SMS Alert Order
Notifications <= 3. ...)
+ TODO: check
+CVE-2026-62105 (Unauthenticated PHP Object Injection in ThemeREX Addons <
2.45.0 versi ...)
+ TODO: check
+CVE-2026-62103 (Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0
version ...)
+ TODO: check
+CVE-2026-62102 (Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3
versions.)
+ TODO: check
+CVE-2026-62089 (Missing Authorization vulnerability in Pixar Labs Master
Addons for El ...)
+ TODO: check
+CVE-2026-62088 (Insertion of Sensitive Information Into Sent Data
vulnerability in 10u ...)
+ TODO: check
+CVE-2026-57843 (NetBSD contains an information disclosure vulnerability in
mm_open() w ...)
+ TODO: check
+CVE-2026-57842 (NetBSD contains a use-after-free and double-free vulnerability
in msg_ ...)
+ TODO: check
+CVE-2026-54072 (Authorizer is an open-source, self-hostable authentication and
authori ...)
+ TODO: check
+CVE-2026-54047 (Laci Synchroni is a decentralized mod and appearance sync
server and p ...)
+ TODO: check
+CVE-2026-47839 (A vulnerability allows users authenticating through a
federated OIDC p ...)
+ TODO: check
+CVE-2026-3869 (CWE-303 : Incorrect Implementation of Authentication Algorithm
vulnera ...)
+ TODO: check
+CVE-2026-38058 (The endpoint on the iDirect iQ200 VSAT terminal returns the
complete d ...)
+ TODO: check
+CVE-2026-38056 (A local privilege escalation vulnerability exists in the
iDirect iQ200 ...)
+ TODO: check
+CVE-2026-27378 (Unauthenticated Broken Access Control in Deposits and Partial
Payments ...)
+ TODO: check
+CVE-2026-19486 (A Server-Side Request Forgery (SSRF) vulnerability in Google
Cloud Gem ...)
+ TODO: check
+CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow
vulnerability exis ...)
+ TODO: check
+CVE-2026-18122 (Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint
exposes res ...)
+ TODO: check
+CVE-2026-18061 (Improper restriction of XML external entity references in the
RemoteQu ...)
+ TODO: check
+CVE-2026-17037 (The Kirki \u2013 Freeform Page Builder, Website Builder &
Customizer p ...)
+ TODO: check
+CVE-2026-15710 (An information leakage vulnerability exists in the Endpoint
DLP compon ...)
+ TODO: check
+CVE-2026-15439 (The GamiPress plugin for WordPress is vulnerable to
authenticated (Sub ...)
+ TODO: check
+CVE-2026-11765 (Improper neutralization of argument delimiters in a command
('argument ...)
+ TODO: check
+CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal,
which al ...)
+ TODO: check
+CVE-2025-15679 (Under certain circumstances such as reset to factory default
operation ...)
+ TODO: check
+CVE-2024-12145 (The BuddyPress plugin for WordPress is vulnerable to Insecure
Direct O ...)
+ TODO: check
CVE-2026-9768
REJECTED
CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to
server- ...)
@@ -35,7 +335,7 @@ CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml
mishandles indexes.)
TODO: check
CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to
validate ...)
TODO: check
-CVE-2026-89060 (A flaw was found in multicluster-observability-addon. This
vulnerabili ...)
+CVE-2026-89060 (A cross-namespace authorization flaw in
multicluster-observability-add ...)
TODO: check
CVE-2026-89054 (A missing authorization vulnerability in OpenNMS Horizon
allows config ...)
NOT-FOR-US: OpenNMS
@@ -725,7 +1025,7 @@ CVE-2026-81793 (Unauthenticated Broken Access Control in
Salon booking system <=
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81791 (Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7
versions.)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-81789 (Unauthenticated Arbitrary File Deletion in Advanced Product
Fields Ext ...)
+CVE-2026-81789 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81788 (Subscriber Broken Access Control in IMPress for IDX Broker <=
3.3.0 ve ...)
NOT-FOR-US: WordPress plugin or theme
@@ -5526,7 +5826,7 @@ CVE-2026-12230 (The LearnPress \u2013 WordPress LMS
Plugin for Create and Sell O
NOT-FOR-US: WordPress plugin
CVE-2026-11891 (Use After Free vulnerability in Arm Ltd Valhall GPU Userspace
Driver, ...)
NOT-FOR-US: Arm
-CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization
(QtXml) lets ...)
+CVE-2026-11573 (Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode
serializ ...)
TODO: check
CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
NOT-FOR-US: ARM
@@ -12324,17 +12624,20 @@ CVE-2024-58379 (nodemailer before 6.9.9 contains a
regular expression denial of
NOTE: Fixed by:
https://github.com/nodemailer/nodemailer/commit/dd8f5e8a4ddc99992e31df76bcff9c590035cd4a
(v6.9.9)
CVE-2023-31308 (A malicious virtual function can invoke the certain command
handlers i ...)
NOT-FOR-US: AMD
-CVE-2026-89158 [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in
pcre2_compile_32() causes out-of-bounds write on 32-bit systems]
+CVE-2026-89158 (PCRE2 before 10.48, on 32-bit platforms, has a
pcre2_compile_32 intege ...)
+ {DLA-4772-1}
- pcre2 10.48-1
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859
NOTE: Fixed by:
https://github.com/PCRE2Project/pcre2/commit/ec9c286d5c10cf1c388b58a442ccefded42254fd
(pcre2-10.48)
-CVE-2026-89160 [GHSA-9qww-pwc4-77qq: PCRE2: out-of-bounds reads in
pcre2_match() when matching invalid UTF subjects with PCRE2_MATCH_INVALID_UTF]
+CVE-2026-89160 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read during
the PCR ...)
+ {DLA-4772-1}
- pcre2 10.48-1
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq
NOTE: Fixed by:
https://github.com/PCRE2Project/pcre2/commit/4889caf31a4c5a6b3c051f0031bf2dbd78f2c287
(pcre2-10.48)
-CVE-2026-89157 [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in
pcre2_pattern_convert() with large patterns on 32-bit systems]
+CVE-2026-89157 (PCRE2 before 10.48, on 32-bit platforms, has a
pcre2_pattern_convert o ...)
+ {DLA-4772-1}
- pcre2 10.48-1
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
@@ -12345,7 +12648,8 @@ CVE-2026-86145 (PCRE2 before 10.48 allows a
pcre2_dfa_match out-of-bounds write
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
NOTE: Fixed by:
https://github.com/PCRE2Project/pcre2/commit/c932e70451eafef922ebef364ac25042f0031135
(pcre2-10.48)
-CVE-2026-89156 [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in
pcre2_match() after JIT fallback with invalid UTF]
+CVE-2026-89156 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read after
a JIT fa ...)
+ {DLA-4772-1}
- pcre2 10.48-1
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
@@ -12405,12 +12709,12 @@ CVE-2026-46352 [defrag: fragmented encapsulated
traffic with fragments can lead
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-rc34-46x6-mxxm
NOTE: https://redmine.openinfosecfoundation.org/issues/8561
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/519ded68fcd7c84d5d348735bba9b02036f91ef8
(suricata-8.0.5)
-CVE-2026-45770 [detect/lua: buffer overflow leads to sandbox escape]
+CVE-2026-45770 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-653j-cc95-vj4c
NOTE: https://redmine.openinfosecfoundation.org/issues/8557
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/09c45d91a565642dffefeb87c7b54c4e3224db73
(suricata-8.0.5)
-CVE-2026-46387 [http2: excessive memory alloc with decompression bomb]
+CVE-2026-46387 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-45p7-j5wm-8wrx
NOTE: https://redmine.openinfosecfoundation.org/issues/8555
(suricata-7.0.16)
@@ -12421,59 +12725,59 @@ CVE-2026-46387 [http2: excessive memory alloc with
decompression bomb]
NOTE:
https://github.com/OISF/suricata/commit/69107199d6fbff979bad2174cd3a904ab8951bd6
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/20104d09788b606b1de1923286d463a07ad47e6d
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/9c24b5bf1cd3e87f3e61ab89c972fce23ca227af
(suricata-8.0.5)
-CVE-2026-45767 [datasets: save with load cmd can save to absolute filename]
+CVE-2026-45767 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-gfxq-gffp-w9rv
NOTE: https://redmine.openinfosecfoundation.org/issues/8548
(suricata-7.0.16)
NOTE: https://redmine.openinfosecfoundation.org/issues/8547
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/477120e3409a2270e5d698c89e7dbd0a74f1f218
(suricata-7.0.16)
NOTE:
https://github.com/OISF/suricata/commit/654f5fa64ffbb9ce855f178b7f45cce8ce72ce68
(suricata-8.0.5)
-CVE-2026-45752 [detect: use-after-free in decompress transform pipeline]
+CVE-2026-45752 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-qmc9-vqq2-8mv3
NOTE: https://redmine.openinfosecfoundation.org/issues/8541
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/11d1fe1ca866d82e8bb3dd4493016188d890aebd
(suricata-8.0.5)
-CVE-2026-45751 [detect: heap-use-after-free in inspection-buffer transform
chaining]
+CVE-2026-45751 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-59q6-j4w8-8pjx
NOTE: https://redmine.openinfosecfoundation.org/issues/8542
(suricata-7.0.16)
NOTE: https://redmine.openinfosecfoundation.org/issues/8540
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/89cde65f8d4314b007c723843b79dfa9e5e26e88
(suricata-7.0.16)
NOTE:
https://github.com/OISF/suricata/commit/3d371fff99d7d0af0912543174c6ea2abb0ff6a3
(suricata-8.0.5)
-CVE-2026-45759 [http1: quadratic complexity with usage of
HTTPParseContentDispositionHeader]
+CVE-2026-45759 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-cfq5-g2v5-6652
NOTE: https://redmine.openinfosecfoundation.org/issues/8531
(suricata-7.0.16)
NOTE: https://redmine.openinfosecfoundation.org/issues/8530
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/a41b135c5c054c806346f8d6e02d67b8f5594be0
(suricata-7.0.16)
NOTE:
https://github.com/OISF/suricata/commit/8abe0f2a8de0d910d4d4461474f5bfb519877053
(suricata-8.0.5)
-CVE-2026-45761 [detect: case insensitivity in frames lead to buffer overflow]
+CVE-2026-45761 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-r74x-74x5-r9vm
NOTE: https://redmine.openinfosecfoundation.org/issues/8528
(suricata-7.0.16)
NOTE: https://redmine.openinfosecfoundation.org/issues/8527
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/df3336bf4f8e8034570b1608f87065391d79c022
(suricata-7.0.16)
NOTE:
https://github.com/OISF/suricata/commit/31d3977720990bb0efd20be08a6c2362287ea460
(suricata-8.0.5)
-CVE-2026-45762 [defrag: incorrect ip fragment reuse causes remote crash]
+CVE-2026-45762 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-gv2j-f6jv-3878
NOTE: https://redmine.openinfosecfoundation.org/issues/8512
(suricata-7.0.16)
NOTE: https://redmine.openinfosecfoundation.org/issues/8511
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/b8ae15e2a049fac8714a6f37be3171a7376a4255
(suricata-7.0.16)
NOTE:
https://github.com/OISF/suricata/commit/97d6fa9e1467f6e6957f32b034199c51980e2ffd
(suricata-8.0.5)
-CVE-2026-45763 [lua: sandbox alloc_limit not enforced on new allocations]
+CVE-2026-45763 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-9h43-frr8-xx6m
NOTE: https://redmine.openinfosecfoundation.org/issues/8508
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/3e064d47964982a93e5facb9b8700f32d869e139
(suricata-8.0.5)
-CVE-2026-45764 [http2: type confusion from protocol change]
+CVE-2026-45764 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-5rvq-72r5-rqhr
NOTE: https://redmine.openinfosecfoundation.org/issues/8494
(suricata-7.0.16)
NOTE: https://redmine.openinfosecfoundation.org/issues/8493
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/61c4df2821441226a2e0d3a5723f44ba95764cdd
(suricata-7.0.16)
NOTE:
https://github.com/OISF/suricata/commit/75a4641af6ee87a605e10557e6e2417330227a6a
(suricata-8.0.5)
-CVE-2026-45765 [dnp3: unbounded reassembly]
+CVE-2026-45765 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-m8x4-c78g-r4vj
NOTE: https://redmine.openinfosecfoundation.org/issues/8462
(suricata-7.0.16)
@@ -12484,7 +12788,7 @@ CVE-2026-45765 [dnp3: unbounded reassembly]
NOTE:
https://github.com/OISF/suricata/commit/2a4947f0c0791b38b951b4140cb49bb814945045
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/d869f782f737515a0c406bbb86a91d5ff626f3e1
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/d62b7cd98054ab03156e7ce2cac15166b46ab391
(suricata-8.0.5)
-CVE-2026-45766 [nfs: OOM on stateful structures]
+CVE-2026-45766 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-jqr4-ch38-wvm6
NOTE: https://redmine.openinfosecfoundation.org/issues/8420
(suricata-7.0.16)
@@ -12495,19 +12799,19 @@ CVE-2026-45766 [nfs: OOM on stateful structures]
NOTE:
https://github.com/OISF/suricata/commit/f43d442251ab96adcc0bfece6919832b1dc8e9be
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/af37786ee48e0f53a3b29d6c9776f33cee9c67f9
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/c029c0958537224ef85f008a578265b52803021d
(suricata-8.0.5)
-CVE-2026-45769 [ikev2: OOM due to unbounded client_transforms]
+CVE-2026-45769 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-hg2g-r464-5593
NOTE: https://redmine.openinfosecfoundation.org/issues/8417
(suricata-7.0.16)
NOTE: https://redmine.openinfosecfoundation.org/issues/8416
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/97251495e674836693c4636f1eb95fc10b191c15
(suricata-7.0.16)
NOTE:
https://github.com/OISF/suricata/commit/3a6414eb6ae2b2368df51de50e1c1c980109c7a6
(suricata-8.0.5)
-CVE-2026-45768 [ldap: OOM on unbounded responses per tx]
+CVE-2026-45768 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.5-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-cr4x-w4c4-57p7
NOTE: https://redmine.openinfosecfoundation.org/issues/8406
(suricata-8.0.5)
NOTE:
https://github.com/OISF/suricata/commit/82cf3d67b1f9fe963c372303ae36551146fee890
(suricata-8.0.5)
-CVE-2026-45747 [lua/tls: null dereference in GetCertInfo]
+CVE-2026-45747 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
- suricata 1:8.0.1-1
NOTE:
https://github.com/OISF/suricata/security/advisories/GHSA-vfc5-9844-rmhv
NOTE: https://redmine.openinfosecfoundation.org/issues/6286
(suricata-7.0.16)
@@ -13033,7 +13337,8 @@ CVE-2026-82457 (su-exec through 0.3 fails to validate
numeric user and group ide
- su-exec <itp> (bug #1003059)
CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network
interface a ...)
NOT-FOR-US: Argo CD
-CVE-2026-82455 (RubyGems fails to re-validate path containment after
filesystem symlin ...)
+CVE-2026-82455
+ REJECTED
- rubygems 4.0.15-2
[trixie] - rubygems <no-dsa> (Minor issue)
[bookworm] - rubygems <postponed> (Minor issue)
@@ -15957,7 +16262,7 @@ CVE-2026-65930 (LimeSurvey Community Edition 7.0.5
contains an authenticated sto
- limesurvey <itp> (bug #472802)
CVE-2026-65647 (Improper symlink resolution before file access in Plesk allows
remote ...)
NOT-FOR-US: Plesk
-CVE-2026-65646 (Improper neutralization of special elements in Plesk allows
remote aut ...)
+CVE-2026-65646 (Improper neutralization of special elements in in Plesk's DNS
zone man ...)
NOT-FOR-US: Plesk
CVE-2026-65642 (Insecure direct object reference in Plesk 18.0.79.7 and
earlier or 18. ...)
NOT-FOR-US: Plesk
@@ -27481,7 +27786,8 @@ CVE-2026-73395 (Unauthenticated Insecure Direct Object
References (IDOR) in Book
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73393 (Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <=
10.46 vers ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-73392 (Unauthenticated SQL Injection in Super Store Finder <= 7.8
versions.)
+CVE-2026-73392
+ REJECTED
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73383 (Shop manager Arbitrary File Download in CTX Feed <= 6.6.47
versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -74373,7 +74679,7 @@ CVE-2026-5348 (The Academy LMS \u2013 WordPress LMS
Plugin for Complete eLearnin
NOT-FOR-US: WordPress plugin
CVE-2026-58593 (NodeBB does not bind the claimed author of an inbound
ActivityPub obje ...)
NOT-FOR-US: NodeBB
-CVE-2026-58592 (Ladybird contains a dangling-reference memory-safety flaw in
its WebAs ...)
+CVE-2026-58592 (Ladybird before commit 2f9dc7e contains a dangling-reference
memory-sa ...)
- ladybird <itp> (bug #1088305)
CVE-2026-58457 (Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02)
contains an ...)
NOT-FOR-US: Shenzhen Aitemi
@@ -328154,7 +328460,8 @@ CVE-2024-8477 (The Newsletter, SMTP, Email marketing
and Subscribe forms by Brev
NOT-FOR-US: WordPress plugin
CVE-2024-8264 (Fortra's Robot Schedule Enterprise Agent prior to version 3.05
writes ...)
NOT-FOR-US: Fortra
-CVE-2024-7049 (In version v0.3.8 of open-webui/open-webui, a vulnerability
exists whe ...)
+CVE-2024-7049
+ REJECTED
NOT-FOR-US: open-webui
CVE-2024-7048 (In version v0.3.8 of open-webui, an improper privilege
management vuln ...)
NOT-FOR-US: open-webui
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4c523d6d82f7996ac655162521c0165039372b8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4c523d6d82f7996ac655162521c0165039372b8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits