Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6c9e6d2d by security tracker role at 2026-09-14T19:13:57+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,10 +1,545 @@
+CVE-2026-9812 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-91081 (Docs through 5.6.1 contains a server-side request forgery
vulnerabilit ...)
+ TODO: check
+CVE-2026-91080 (webhook through 2.8.3 reads the entire request body into
memory before ...)
+ TODO: check
+CVE-2026-91079 (Huly Platform through 0.7.426 contains a server-side request
forgery v ...)
+ TODO: check
+CVE-2026-91021 (Trilium Notes, version v0.103.0 and earlier, contains a stored
cross-s ...)
+ TODO: check
+CVE-2026-90996 (A flaw was found in sssd. A local unprivileged user could send
a speci ...)
+ TODO: check
+CVE-2026-90995 (A flaw was found in SSSD (System Security Services Daemon). A
local at ...)
+ TODO: check
+CVE-2026-90994 (A flaw was found in sssd, specifically within the PAM
(Pluggable Authe ...)
+ TODO: check
+CVE-2026-90961 (The LdapAuth and LinOTPAuth authentication plugins in MISP
contain an ...)
+ TODO: check
+CVE-2026-90957 (Affected versions of MISP serve uploaded SVG images inline
without a r ...)
+ TODO: check
+CVE-2026-90955 (Affected versions of MISP\u2019s interactive CLI shell do not
reliably ...)
+ TODO: check
+CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader.
When proc ...)
+ TODO: check
+CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an
ICO fil ...)
+ TODO: check
+CVE-2026-90947 (A flaw was found in GIMP. When processing a specially crafted
lighting ...)
+ TODO: check
+CVE-2026-90946 (DeepWiki-Open through commit d92819a contains an arbitrary
file read v ...)
+ TODO: check
+CVE-2026-90945 (Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for
JWT tok ...)
+ TODO: check
+CVE-2026-90944 (Krayin CRM through 2.2.6 exposes the POST
/admin/mail/inbound-parse en ...)
+ TODO: check
+CVE-2026-90943 (parallax filament-comments through 3.0.0 contains a stored
cross-site ...)
+ TODO: check
+CVE-2026-90942 (Casdoor through 4.4.0 fails to properly mask the instance-wide
built-i ...)
+ TODO: check
+CVE-2026-90941 (novel-plus through 5.3.3 contains an authorization bypass
vulnerabilit ...)
+ TODO: check
+CVE-2026-90940 (novel-plus through 5.3.3 contains an insecure default
cache-management ...)
+ TODO: check
+CVE-2026-90939 (novel-plus through 5.3.3 contains an information disclosure
vulnerabil ...)
+ TODO: check
+CVE-2026-90938 (LangBot's plugin runtime (pip package langbot_plugin) through
0.4.17 s ...)
+ TODO: check
+CVE-2026-90937 (froxlor versions before 2.2.5 fail to validate newline
characters in s ...)
+ TODO: check
+CVE-2026-90936 (Froxlor before 2.3.7 fails to properly scope sender alias
lookups to t ...)
+ TODO: check
+CVE-2026-90935 (Froxlor before 2.3.7 fails to validate the mysql_server
parameter agai ...)
+ TODO: check
+CVE-2026-90934 (EspoCRM before 10.0.4 contains a field-level security bypass
vulnerabi ...)
+ TODO: check
+CVE-2026-90933 (laradashboard through 1.2.2 contains a missing authorization
vulnerabi ...)
+ TODO: check
+CVE-2026-90932 (LaraDashboard versions 0.9.2 through 1.2.2 contain a path
traversal vu ...)
+ TODO: check
+CVE-2026-90931 (LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize
SVG file c ...)
+ TODO: check
+CVE-2026-90930 (File Browser through 2.63.23 applies path rules to the
requested lexic ...)
+ TODO: check
+CVE-2026-90929 (File Browser versions >= 2.5.0 and <= 2.63.23 contain an
incorrect aut ...)
+ TODO: check
+CVE-2026-90928 (File Browser through 2.63.23 contains a memory exhaustion
vulnerabilit ...)
+ TODO: check
+CVE-2026-90927 (filebrowser through 2.63.23 fails to limit WebSocket message
size in t ...)
+ TODO: check
+CVE-2026-90919 (LightLLM through 1.2.0 contains a remote code execution
vulnerability ...)
+ TODO: check
+CVE-2026-90898 (Bifrost registers MCP clients through its management API. A
stdio clie ...)
+ TODO: check
+CVE-2026-90895 (Affected versions of MISP\u2019s interactive CLI shell
implement acces ...)
+ TODO: check
+CVE-2026-90894 (Parallels Desktop runsprl_disp_serviceas root. Local clients
reach it ...)
+ TODO: check
+CVE-2026-90893 (MISP contains a Cross-Site Request Forgery (CSRF)
vulnerability in the ...)
+ TODO: check
+CVE-2026-90891 (ASRock Polychrome SYNC/RGB software utility developed by
ASRock Inc. h ...)
+ TODO: check
+CVE-2026-90890 (ASRock Polychrome SYNC/RGB software utility developed by
ASRock Inc. h ...)
+ TODO: check
+CVE-2026-90811 (A weakness has been identified in cosmicstack-labs
mercury-agent up to ...)
+ TODO: check
+CVE-2026-90810 (A security flaw has been discovered in cosmicstack-labs
mercury-agent ...)
+ TODO: check
+CVE-2026-90809 (A vulnerability was identified in HKUDS nanobot up to 0.2.1.
The affec ...)
+ TODO: check
+CVE-2026-90808 (A vulnerability was determined in HKUDS nanobot up to 0.2.1.
Impacted ...)
+ TODO: check
+CVE-2026-90807 (A vulnerability was found in nanocoai NanoClaw up to 2.1.17.
This issu ...)
+ TODO: check
+CVE-2026-90806 (A vulnerability has been found in DjangoCRM django-crm up to
1.2. This ...)
+ TODO: check
+CVE-2026-90805 (A flaw has been found in subhajitkhan
online-clinic-management-system ...)
+ TODO: check
+CVE-2026-90804 (A vulnerability was detected in GNU Binutils 2.47. Affected by
this is ...)
+ TODO: check
+CVE-2026-90803 (A security vulnerability has been detected in GNU Binutils
2.47. Affec ...)
+ TODO: check
+CVE-2026-90802 (A weakness has been identified in GNU Binutils 2.47. Affected
is the f ...)
+ TODO: check
+CVE-2026-90801 (A security flaw has been discovered in GNU Binutils 2.47. This
impacts ...)
+ TODO: check
+CVE-2026-90796 (A vulnerability was identified in itsourcecode Leave
Management System ...)
+ TODO: check
+CVE-2026-90795 (A vulnerability was determined in itsourcecode Loan Management
System ...)
+ TODO: check
+CVE-2026-90794 (A vulnerability was found in GPAC up to f1219cde. The affected
element ...)
+ TODO: check
+CVE-2026-90793 (A vulnerability has been found in GPAC up to f1219cde.
Impacted is the ...)
+ TODO: check
+CVE-2026-90792 (A flaw has been found in GPAC up to f1219cde. This issue
affects the f ...)
+ TODO: check
+CVE-2026-90791 (A vulnerability was detected in GPAC up to f1219cde. This
vulnerabilit ...)
+ TODO: check
+CVE-2026-90790 (A security vulnerability has been detected in a2aproject
a2a-python up ...)
+ TODO: check
+CVE-2026-90789 (A weakness has been identified in itsourcecode Leave
Management System ...)
+ TODO: check
+CVE-2026-90788 (A security flaw has been discovered in magicblack MacCMS10
2026.1000.4 ...)
+ TODO: check
+CVE-2026-90787 (A vulnerability was identified in Soarkey StudentManagement up
to e08f ...)
+ TODO: check
+CVE-2026-90786 (A vulnerability was determined in Dvidelabs flatcc up to
0.6.3. This i ...)
+ TODO: check
+CVE-2026-90785 (A vulnerability was found in Dvidelabs flatcc up to 0.6.3.
This affect ...)
+ TODO: check
+CVE-2026-90784 (A vulnerability has been found in Dvidelabs flatcc up to
0.6.3. The im ...)
+ TODO: check
+CVE-2026-90716 (A vulnerability was detected in marcobambini Gravity up to
0.9.7. This ...)
+ TODO: check
+CVE-2026-90715 (A security vulnerability has been detected in marcobambini
Gravity up ...)
+ TODO: check
+CVE-2026-90714 (A weakness has been identified in marcobambini Gravity up to
0.9.7. Th ...)
+ TODO: check
+CVE-2026-90713 (A security flaw has been discovered in vllm-project vLLM up to
0.29.0. ...)
+ TODO: check
+CVE-2026-90712 (A vulnerability was identified in Gitlawb openclaude up to
0.30.0. Imp ...)
+ TODO: check
+CVE-2026-90710 (A vulnerability was determined in taisan tarzan-cms 1.0.0.
This issue ...)
+ TODO: check
+CVE-2026-90709 (A security vulnerability has been detected in Yot CMS up to
3.3.1. Aff ...)
+ TODO: check
+CVE-2026-90708 (A weakness has been identified in Yot CMS up to 3.3.1.
Affected by thi ...)
+ TODO: check
+CVE-2026-90707 (A security flaw has been discovered in Open5GS up to 2.7.x.
Affected i ...)
+ TODO: check
+CVE-2026-90706 (A vulnerability was identified in D-Link DWR-M921 1.1.52. This
impacts ...)
+ TODO: check
+CVE-2026-90705 (A vulnerability was determined in D-Link DWR-M921 1.1.52. This
affects ...)
+ TODO: check
+CVE-2026-90704 (A vulnerability was found in D-Link DWR-M921 1.1.52. The
impacted elem ...)
+ TODO: check
+CVE-2026-90703 (A vulnerability has been found in D-Link DWR-M921 1.1.52. The
affected ...)
+ TODO: check
+CVE-2026-90702 (A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is
the funct ...)
+ TODO: check
+CVE-2026-90701 (A vulnerability was detected in subhajitkhan
online-clinic-management- ...)
+ TODO: check
+CVE-2026-90700 (A security vulnerability has been detected in itsourcecode
Sales and I ...)
+ TODO: check
+CVE-2026-90699 (A weakness has been identified in D-Link DWR-M920 1.1.7. This
issue af ...)
+ TODO: check
+CVE-2026-90698 (A security flaw has been discovered in memcached
1.6.41/1.6.42/1.6.43. ...)
+ TODO: check
+CVE-2026-90697 (A vulnerability was identified in SourceCodester Inventory
Management ...)
+ TODO: check
+CVE-2026-90696 (A vulnerability was determined in SourceCodester Inventory
Management ...)
+ TODO: check
+CVE-2026-90695 (A vulnerability was found in SourceCodester Inventory
Management Syste ...)
+ TODO: check
+CVE-2026-90694 (A vulnerability has been found in SourceCodester Inventory
Management ...)
+ TODO: check
+CVE-2026-90693 (A flaw has been found in D-Link DIR-878 120B05. This impacts
the funct ...)
+ TODO: check
+CVE-2026-90692 (A vulnerability was detected in D-Link DIR-878 120B05. This
affects th ...)
+ TODO: check
+CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input
validation vuln ...)
+ TODO: check
+CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-89321 (Publishing limits the compressed size of a VSIX
(ovsx.publishing.max-c ...)
+ TODO: check
+CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL
Injection v ...)
+ TODO: check
+CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2
contain ...)
+ TODO: check
+CVE-2026-89021 (MikroTik RouterOS before 7.24.2 contains a path traversal
vulnerabilit ...)
+ TODO: check
+CVE-2026-89020 (MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2
(stable) contai ...)
+ TODO: check
+CVE-2026-88932 (multer is a Node.js middleware for handling
multipart/form-data upload ...)
+ TODO: check
+CVE-2026-88819 (In Siglet current and past versions the refresh token handler
do not e ...)
+ TODO: check
+CVE-2026-87802 (Improper verification of cryptographic signature vulnerability
in Apac ...)
+ TODO: check
+CVE-2026-87785 (Authentication bypass by spoofing vulnerability in Apache
Syncope. ...)
+ TODO: check
+CVE-2026-87779 (Insertion of sensitive information into log file vulnerability
in Apac ...)
+ TODO: check
+CVE-2026-87087
+ REJECTED
+CVE-2026-86836 (In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent
creates wor ...)
+ TODO: check
+CVE-2026-86830 (Incorrect privilege assignment in Temporary Elevated Access
Management ...)
+ TODO: check
+CVE-2026-86460 (Cypher injection vulnerability in the Neo4j persistence layer
when pro ...)
+ TODO: check
+CVE-2026-86349 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-86348 (Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0
fail to rec ...)
+ TODO: check
+CVE-2026-85921 (Double free in Windows Secure Kernel Mode allows an authorized
attacke ...)
+ TODO: check
+CVE-2026-85892 (Concurrent execution using shared resource with improper
synchronizati ...)
+ TODO: check
+CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to
1.82.2 and ...)
+ TODO: check
+CVE-2026-84179 (Description getTopologyPageInfo merged the Nimbus daemon
configurat ...)
+ TODO: check
+CVE-2026-82920 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-82441 (Description A submitted topology carries two lists of
blobstore keys, ...)
+ TODO: check
+CVE-2026-82439 (Description The DRPC server kept a map from function name to
request ...)
+ TODO: check
+CVE-2026-82438 (Description Three separate mechanisms allowed a web page on
an unrela ...)
+ TODO: check
+CVE-2026-82437 (Description The Logviewer offers `logs.users` and
`logs.groups` so op ...)
+ TODO: check
+CVE-2026-82435 (Description The worker's Netty message decoder is installed
ahead of ...)
+ TODO: check
+CVE-2026-82434 (Description When ZooKeeper authentication is configured,
Storm delibe ...)
+ TODO: check
+CVE-2026-82433 (Description `getNimbusConf` returned the complete daemon
configuratio ...)
+ TODO: check
+CVE-2026-82432 (Description Nimbus validated `topology.blobstore.map` against
the cal ...)
+ TODO: check
+CVE-2026-82431 (Description `SimpleACLAuthorizer` evaluated the user-level
command se ...)
+ TODO: check
+CVE-2026-82430 (Description When launching a Docker or OCI worker, the
setuid-root `w ...)
+ TODO: check
+CVE-2026-82429 (Description The setuid-root `worker-launcher` binary adjusts
ownershi ...)
+ TODO: check
+CVE-2026-82428 (Description Dependency artifacts uploaded with `storm jar
--artifacts ...)
+ TODO: check
+CVE-2026-82427 (Description A topology's `topology.blobstore.map` lets the
submitter ...)
+ TODO: check
+CVE-2026-82426 (Description Nimbus accepted the `uploadedJarLocation`
argument of `su ...)
+ TODO: check
+CVE-2026-82232 (Improper neutralization of special elements used in an SQL
command ('S ...)
+ TODO: check
+CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a
path trave ...)
+ TODO: check
+CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a
DOM-base ...)
+ TODO: check
+CVE-2026-81566 (Joomla Extension - joomshaper.com - Missing Access Control in
Menu Ite ...)
+ TODO: check
+CVE-2026-81565 (Joomla Extension - joomshaper.com - Missing Directory
Confinement in M ...)
+ TODO: check
+CVE-2026-81564 (Joomla Extension - joomshaper.com - Missing Directory
Confinement in M ...)
+ TODO: check
+CVE-2026-81301 (Ekia File Manager 1.2.7 exposes
com.ekia.filecontrolmanager.OpenFilePr ...)
+ TODO: check
+CVE-2026-7848 (Alior Bank PrestaShop module "raty"for commercial partners is
vulnerab ...)
+ TODO: check
+CVE-2026-7208 (Yealink SIP-T33G firmware versions 124.86.x.x prior to
124.87.0.0 cont ...)
+ TODO: check
+CVE-2026-79701 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA
Bypass in ...)
+ TODO: check
+CVE-2026-79700 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA
Bypass via ...)
+ TODO: check
+CVE-2026-78375 (Joomla Extension - joomshaper.com - Authenticated Privileged
SQL Injec ...)
+ TODO: check
+CVE-2026-78336 (Insertion of sensitive information into sent data
vulnerability in Apa ...)
+ TODO: check
+CVE-2026-78330 (Incorrect privilege assignment vulnerability in Apache
Syncope. When ...)
+ TODO: check
+CVE-2026-78318 (Improper neutralization of input during web page generation
('cross-si ...)
+ TODO: check
+CVE-2026-78299 (In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack
archive ...)
+ TODO: check
+CVE-2026-77884 (Gallery - Private Photo Vault 1.0.41 starts an unauthenticated
HTTP se ...)
+ TODO: check
+CVE-2026-77883 (Exposure of sensitive information through data queries
vulnerability i ...)
+ TODO: check
+CVE-2026-77181 (Incorrect Authorization vulnerability in Apache Syncope. An
adminis ...)
+ TODO: check
+CVE-2026-77147 (Improper Control of Generation of Code ('Code Injection')
vulnerabilit ...)
+ TODO: check
+CVE-2026-77051 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
+ TODO: check
+CVE-2026-76461 (A vulnerability in the email parsing of Cisco AsyncOS Software
for Cis ...)
+ TODO: check
+CVE-2026-76443 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-76442 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-76441 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-76440 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-75030 (Missing Authorization vulnerability in Apache Syncope. An
administr ...)
+ TODO: check
+CVE-2026-75015 (Insufficiently Protected Credentials vulnerability in Apache
Syncope. ...)
+ TODO: check
+CVE-2026-73668 (Incorrect Authorization vulnerability in Apache Syncope.
An admin ...)
+ TODO: check
+CVE-2026-73579 (Incorrect Authorization vulnerability in Apache Syncope.
Any search ...)
+ TODO: check
+CVE-2026-73494 (blaze is a Scala library for building asynchronous pipelines,
with a f ...)
+ TODO: check
+CVE-2026-73470 (Improper Privilege Management vulnerability in Apache Syncope.
De ...)
+ TODO: check
+CVE-2026-73370 (Incorrect Authorization vulnerability in Apache Syncope.
Delegated ...)
+ TODO: check
+CVE-2026-73236 (Incorrect Authorization vulnerability in Apache Syncope.
Delegated ...)
+ TODO: check
+CVE-2026-73195 (Improper Encoding or Escaping of Output vulnerability in
Apache Syncop ...)
+ TODO: check
+CVE-2026-73191 (URL Redirection to Untrusted Site ('Open Redirect')
vulnerability in A ...)
+ TODO: check
+CVE-2026-73178 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
+ TODO: check
+CVE-2026-72524 (Incorrect Authorization vulnerability in Apache Doris allows
an authen ...)
+ TODO: check
+CVE-2026-70658 (Pay is a payments engine for Ruby on Rails 6.0 and higher.
Prior to 11 ...)
+ TODO: check
+CVE-2026-68570 (Incorrect Authorization vulnerability in Apache Doris allows
an authen ...)
+ TODO: check
+CVE-2026-61701 (Laravel MagicLink creates links for authentication without a
password ...)
+ TODO: check
+CVE-2026-61534 (Yayson is a library for serializing and reading JSON API data
in JavaS ...)
+ TODO: check
+CVE-2026-5132 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-59960 (Argos JavaScript provides official Argos SDKs for JavaScript.
Prior to ...)
+ TODO: check
+CVE-2026-59570 (On affected versions of Zscaler client connector, a
pre-installed peer ...)
+ TODO: check
+CVE-2026-59569 (An improper input validation vulnerability in Zscaler Client
Connector ...)
+ TODO: check
+CVE-2026-59178 (ESPHome Device Builder Dashboard is a dashboard for the
ESPHome home m ...)
+ TODO: check
+CVE-2026-57583 (OpenZeppelin Contracts Wizard is a web application to
interactively bu ...)
+ TODO: check
+CVE-2026-57581 (DotVVM is an open source MVVM framework for web applications.
Prior to ...)
+ TODO: check
+CVE-2026-57579 (Alchemy is an open source content management system engine
written in ...)
+ TODO: check
+CVE-2026-57578 (DotVVM is an open source MVVM framework for web applications.
Prior to ...)
+ TODO: check
+CVE-2026-57577 (DotVVM is an open source MVVM framework for web applications.
Prior to ...)
+ TODO: check
+CVE-2026-57570 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-57497 (webtransport-go is an implementation of the WebTransport
protocol. Pri ...)
+ TODO: check
+CVE-2026-57145 (PraisonAI is a multi-agent teams system. Prior to 4.6.62,
src/praisona ...)
+ TODO: check
+CVE-2026-57132 (PraisonAI is a multi-agent teams system. Prior to 4.6.62,
setting PRAI ...)
+ TODO: check
+CVE-2026-57131 (PraisonAI is a multi-agent teams system. Prior to 4.6.58,
praisonai.jo ...)
+ TODO: check
+CVE-2026-57130 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-57129 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-57128 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-57127 (PraisonAI is a multi-agent teams system. Prior to 4.6.58,
recipe serve ...)
+ TODO: check
+CVE-2026-57126 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-57125 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.59 and ...)
+ TODO: check
+CVE-2026-57124 (PraisonAI is a multi-agent teams system. Prior to 4.6.59, the
default ...)
+ TODO: check
+CVE-2026-57123 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-57122 (PraisonAI is a multi-agent teams system. Prior to 4.6.59, the
WhatsApp ...)
+ TODO: check
+CVE-2026-57120 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-57119 (PraisonAI is a multi-agent teams system. Prior to 4.6.59, the
unauthen ...)
+ TODO: check
+CVE-2026-57115 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-56839 (PraisonAI is a multi-agent teams system. Prior to 4.6.59, the
CODE_TOO ...)
+ TODO: check
+CVE-2026-55866 (SpiceDB is an open source database system for creating and
managing se ...)
+ TODO: check
+CVE-2026-55847 (Allure 2 is the version 2.x branch of Allure Report, a
multi-language ...)
+ TODO: check
+CVE-2026-55846 (Allure 2 is the version 2.x branch of Allure Report, a
multi-language ...)
+ TODO: check
+CVE-2026-55837 (dbt-mcp is a Model Context Protocol server for interacting
with dbt. P ...)
+ TODO: check
+CVE-2026-55832 (Tract is a tiny, no-nonsense, self-contained TensorFlow and
ONNX infer ...)
+ TODO: check
+CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From
4.0.0 unti ...)
+ TODO: check
+CVE-2026-55451 (gettext-converter provides gettext resource conversion
utilities for J ...)
+ TODO: check
+CVE-2026-55416 (Pimcore is an Open Source Data & Experience Management
Platform. Prior ...)
+ TODO: check
+CVE-2026-55253 (LangChain MongoDB provides integrations between MongoDB,
Atlas, LangCh ...)
+ TODO: check
+CVE-2026-55236 (langgraph-api implements the LangGraph API for rapid
development and t ...)
+ TODO: check
+CVE-2026-55235 (langgraph-api implements the LangGraph API for rapid
development and t ...)
+ TODO: check
+CVE-2026-55102 (hashi-vault-js is a Node.js module for interacting with the
HashiCorp ...)
+ TODO: check
+CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation
to a ne ...)
+ TODO: check
+CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior
to 70.0 ...)
+ TODO: check
+CVE-2026-55072 (Pimcore is an Open Source Data & Experience Management
Platform. Prior ...)
+ TODO: check
+CVE-2026-54723 (devpi is a Python package index staging server and packaging,
testing, ...)
+ TODO: check
+CVE-2026-54567 (Flask-Reuploaded provides file uploads for Flask. From 1.5.0
until 1.6 ...)
+ TODO: check
+CVE-2026-54542 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake
protocol ba ...)
+ TODO: check
+CVE-2026-54541 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake
protocol ba ...)
+ TODO: check
+CVE-2026-54529 (SQLAdmin is a flexible Admin interface for SQLAlchemy models.
Prior to ...)
+ TODO: check
+CVE-2026-54452 (safeurl is a server-side request forgery protection library.
Prior to ...)
+ TODO: check
+CVE-2026-54182 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-54181 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-54180 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-54178 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-54177 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-54176 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-54175 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
+ TODO: check
+CVE-2026-54156 (node-opcua is an OPC UA implementation for TypeScript and
Node.js. Pri ...)
+ TODO: check
+CVE-2026-54155 (node-opcua is an OPC UA implementation for TypeScript and
Node.js. Pri ...)
+ TODO: check
+CVE-2026-54150 (next-video is a library for adding video to Next.js
applications. Prio ...)
+ TODO: check
+CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony
application ...)
+ TODO: check
+CVE-2026-53752 (docx4j is an open source Java library for creating, editing,
and savin ...)
+ TODO: check
+CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that
provides centr ...)
+ TODO: check
+CVE-2026-53659 (http4k is a functional toolkit for Kotlin HTTP applications.
Prior to ...)
+ TODO: check
+CVE-2026-53496 (ExifReader is a JavaScript Exif information parser. Prior to
4.40.1, E ...)
+ TODO: check
+CVE-2026-53495 (containerd is an open-source container runtime. Prior to
1.7.35, 2.0.1 ...)
+ TODO: check
+CVE-2026-50276 (dd-trace-rb is Datadog's client library for Ruby. Prior to
2.32.0, W3C ...)
+ TODO: check
+CVE-2026-50270 (dd-trace-java is a Datadog APM client for Java. Prior to
1.62.0, W3C b ...)
+ TODO: check
+CVE-2026-50157 (Auth0 Symfony is a Symfony SDK for Auth0 Authentication and
Management ...)
+ TODO: check
+CVE-2026-4103 (Insufficient HTML sanitization in the Publisher Portal and
Developer P ...)
+ TODO: check
+CVE-2026-49400 (October System provides the system module for October Content
Manageme ...)
+ TODO: check
+CVE-2026-49250 (Conform, a type-safe form validation library, allows the
parsing of ne ...)
+ TODO: check
+CVE-2026-47256 (OpenTelemetry, also known as OTel, is a vendor-neutral open
source Obs ...)
+ TODO: check
+CVE-2026-46696 (October System provides the system module for October Content
Manageme ...)
+ TODO: check
+CVE-2026-44162 (fluent-plugin-s3 is an Amazon S3 input and output plugin for
Fluentd. ...)
+ TODO: check
+CVE-2026-34151 (XWiki Platform is a generic wiki platform. Prior to 17.10.5
and 18.2.0 ...)
+ TODO: check
+CVE-2026-25687 (A race condition in the ZPA tunnel handler of affected
versions of Zsc ...)
+ TODO: check
+CVE-2026-21391 (An improper validation vulnerability exists within PingAM
where a well ...)
+ TODO: check
+CVE-2026-20773 (A role-based access control issue was identified in the
administrative ...)
+ TODO: check
+CVE-2026-20353 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-19543 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2,
ART 9.0, ...)
+ TODO: check
+CVE-2026-18515 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-18151 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
+ TODO: check
+CVE-2026-15923 (The Zephyr SDIO subsystem function
sdio_io_rw_extended_helper() in sub ...)
+ TODO: check
+CVE-2026-15893 (net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c
derives a ...)
+ TODO: check
+CVE-2026-15814 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-15600 (Alior Bank PrestaShop module "raty" for commercial partners is
vulnera ...)
+ TODO: check
+CVE-2026-14344 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-14259 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-13417 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-12985 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-12882 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-12518 (A local privilege escalation vulnerability in the Logitech
Logi Option ...)
+ TODO: check
+CVE-2026-12258 (Inadequate access control in Hiperdino\u2019s REST v1.0 API.
The publi ...)
+ TODO: check
+CVE-2026-11993 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-10556 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2026-10542 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
+ TODO: check
+CVE-2025-24890 (gitoxide is an implementation of git written in Rust. Prior to
0.13.3, ...)
+ TODO: check
+CVE-2024-58383 (Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3)
generate ...)
+ TODO: check
CVE-2026-19624
+ {DSA-6498-1}
- network-manager-l2tp 1.52.6-1
NOTE: Fixed by:
https://github.com/nm-l2tp/NetworkManager-l2tp/commit/3704d8c9d5e5f9ed1626a8ce7627a04247cea673
(1.52.6, 1.20.26)
CVE-2026-75131
+ {DSA-6498-1}
- network-manager-l2tp 1.52.6-1
NOTE: Fixed by:
https://github.com/nm-l2tp/NetworkManager-l2tp/commit/64879ce0ad866f7c9a45babe4d95731a916ea00f
(1.52.6, 1.20.26)
CVE-2026-75883
+ {DSA-6498-1}
- network-manager-l2tp 1.52.6-1
NOTE: Fixed by:
https://github.com/nm-l2tp/NetworkManager-l2tp/commit/64879ce0ad866f7c9a45babe4d95731a916ea00f
(1.52.6, 1.20.26)
CVE-2026-XXXX [GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode
protections across multiple source subtypes]
@@ -216,6 +751,7 @@ CVE-2026-74933 (The GenieWords WordPress plugin from 1.5.27
to 1.5.34 does not h
CVE-2026-68955 (The installer for Rakuten Kobo Desktop Application (Windows
version) i ...)
NOT-FOR-US: installer for Rakuten Kobo Desktop Application (Windows
version)
CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is
insuffici ...)
+ {DSA-6361-1}
- ffmpeg 7:8.1.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
NOTE: Fixed by:
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/8439e0203744a30d280668fcd086f74ed5001da1
(n9.0)
@@ -223,6 +759,7 @@ CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read
because there is ins
NOTE: Fixed by:
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/ebff1abbad8b036bfc0f52a4785433b06e865e3b
(n8.0.2)
NOTE: Fixed by:
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c7a0013d5fedb4a875446a3cd7e6fa9beba4e81a
(n7.1.4)
CVE-2026-52296 (FFmpeg before 9.0 has an out-of-bounds read because of missing
require ...)
+ {DSA-6361-1}
- ffmpeg 7:8.1.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
NOTE: Fixed by:
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/23227a444de4a8f7696f46660cdd044b460f7e47
(n9.0)
@@ -4274,7 +4811,7 @@ CVE-2026-74761 (Improper input validation in TopicRegion
in Apache ActiveMQ, Apa
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-73334 (Potential problem for users of
theorg.apache.parquet.crypto.keytools p ...)
NOT-FOR-US: Apache software not packaged in Debian
-CVE-2026-73324 (VLC media player copies an RTSP response line into a fixed
buffer with ...)
+CVE-2026-73324 (Certain VLC media player builds in versions 3.0.0 through
3.0.23 conta ...)
- vlc <unfixed>
CVE-2026-70425 (Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0,
Versions 9.8. ...)
NOT-FOR-US: Dell / EMC
@@ -4294,7 +4831,7 @@ CVE-2026-61907 (An issue was discovered in Cyrus IMAP
before 3.12.4. JMAP snooze
NOTE:
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html
CVE-2026-57866 (Server side request forgery in Apache Impala versions 4.4.x
and 4.5.x. ...)
NOT-FOR-US: Apache software not packaged in Debian
-CVE-2026-56711 (VLC media player computes the size of a picture buffer with
32-bit ari ...)
+CVE-2026-56711 (VLC media player versions 3.0.0 through 3.0.23 contain a
memory-safety ...)
- vlc <unfixed>
CVE-2026-56207 (Signature of Bearer token is not verified in last step of
SAML2 authen ...)
NOT-FOR-US: Apache software not packaged in Debian
@@ -11472,7 +12009,7 @@ CVE-2026-78043 (The Windows Interactive Service in
OpenVPN 2.7_alpha1 through 2.
- openvpn <not-affected> (Only affects OpenVPN on Windows)
CVE-2026-81738 (OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6
driver a ...)
- openvpn <not-affected> (Only affects OpenVPN on Windows)
-CVE-2026-71198
+CVE-2026-71198 (In OpenStack Glance before 32.0.1, the location API does not
validate ...)
- glance 2:32.0.0-4 (bug #1146594)
[trixie] - glance <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
@@ -21648,7 +22185,7 @@ CVE-2026-80182 (In OpenStack Keystone before 29.0.3,
tokens obtained via OAuth1
- keystone 2:29.0.2-1 (bug #1145669)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
NOTE: https://bugs.launchpad.net/keystone/+bug/2153453
-CVE-2026-19499
+CVE-2026-19499 (Calling strfmon and strfmon_l in the GNU C Library version
2.38 to 2.4 ...)
- glibc 2.43-5 (bug #1145891)
[trixie] - glibc <no-dsa> (Minor issue)
[bookworm] - glibc <postponed> (Minor issue)
@@ -23328,7 +23865,7 @@ CVE-2026-10053 (GitLab has remediated an issue in
GitLab CE/EE affecting all ver
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-75922 (Reverse::Proxy versions before 0.04 for Perl allow HTTP
request smuggl ...)
NOT-FOR-US: Reverse::Proxy Perl module
-CVE-2026-19542 [Out-of-bounds stack array access in tdelete]
+CVE-2026-19542 (Calling tdelete on a sufficiently deep tree in the GNU C
Library versi ...)
- glibc 2.43-4
[trixie] - glibc <no-dsa> (Minor issue)
[bookworm] - glibc <postponed> (Minor issue)
@@ -46534,7 +47071,7 @@ CVE-2026-48074 (OpenReception's appointment booking
software provides an end-to-
NOT-FOR-US: OpenReception
CVE-2026-48071 (OpenReception's appointment booking software provides an
end-to-end en ...)
NOT-FOR-US: OpenReception
-CVE-2026-48054 (OpenZeppelin Contracts Wizardis a web application to
interactively bui ...)
+CVE-2026-48054 (OpenZeppelin Contracts Wizard is a web application to
interactively bu ...)
NOT-FOR-US: OpenZeppelin
CVE-2026-47765 (Frappe is a full-stack web application framework. Prior to
15.110.0 an ...)
NOT-FOR-US: Frappe
@@ -56039,7 +56576,7 @@ CVE-2026-50540 (Kata Containers is an open source
project focusing on a standard
NOT-FOR-US: Kata Containers
CVE-2026-50149 (Contour is a Kubernetes ingress controller using Envoy proxy.
In versi ...)
NOT-FOR-US: Contour
-CVE-2026-47701
+CVE-2026-47701 (The OpenTelemetry Operator is a Kubernetes Operator for the
OpenTeleme ...)
NOT-FOR-US: OpenTelemetry Operator
CVE-2026-16566
- ansible <unfixed> (bug #1146700)
@@ -72809,7 +73346,7 @@ CVE-2026-39245 (decompress before 4.2.2 contains an
improper path containment ch
CVE-2026-39243 (decompress before 4.2.2 allows arbitrary hardlink creation
during arch ...)
NOT-FOR-US: Node decompress module
CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function
of Arti ...)
- {DSA-6488-1}
+ {DSA-6488-1 DLA-4779-1}
- jbig2dec <unfixed> (bug #1142282)
NOTE: Fixed by:
https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b
CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended
Endpoints ...)
@@ -89908,7 +90445,7 @@ CVE-2025-69138 (Subscriber Privilege Escalation in
Genemy <= 1.6.6 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2025-69135 (Subscriber SQL Injection in Events Schedule - WordPress Events
Calenda ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2025-69130 (Subscriber PHP Object Injection in Entrepreneur - Booking for
Small Bu ...)
+CVE-2025-69130 (Deserialization of Untrusted Data vulnerability in Pixel
Makers Creati ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2025-69129 (Unauthenticated Arbitrary File Upload in WordPress &
WooCommerce Scrap ...)
NOT-FOR-US: WordPress plugin or theme
@@ -90623,7 +91160,7 @@ CVE-2026-27429 (Unauthenticated PHP Object Injection in
Nifty <= 1.4.1 versions.
NOT-FOR-US: WordPress plugin or theme
CVE-2026-27395 (Unauthenticated Privilege Escalation in Support Board < 3.8.9
versions ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-25470 (Improper Control of Generation of Code ('Code Injection')
vulnerabilit ...)
+CVE-2026-25470 (Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) -
Custom Pos ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-22313 (The device has a webserver that exposes a REST API
authenticated with ...)
NOT-FOR-US: iSAP Smart Collector
@@ -233312,7 +233849,7 @@ CVE-2025-53343 (Missing Authorization vulnerability
in GoodLayers Modernize mode
NOT-FOR-US: WordPress plugin or theme
CVE-2025-53342 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2025-53341 (Missing Authorization vulnerability in Themovation App, SaaS &
Softwar ...)
+CVE-2025-53341 (Missing Authorization vulnerability in Pixel Makers Creative
INC. App, ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2025-53330 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
@@ -967829,7 +968366,7 @@ CVE-2013-1447 (OpenJPEG 1.3 and earlier allows remote
attackers to cause a denia
{DSA-2808-1}
- openjpeg 1.3+dfsg-4.7 (bug #731237)
CVE-2013-1446
- RESERVED
+ REJECTED
CVE-2013-1445 (The Crypto.Random.atfork function in PyCrypto before 2.6.1 does
not pr ...)
{DSA-2781-1}
- python-crypto 2.6.1-1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c9e6d2d0ce8da54ee1ceb812819bede51e49cfb
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c9e6d2d0ce8da54ee1ceb812819bede51e49cfb
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits