Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
57cd99c1 by Moritz Muehlenhoff at 2026-09-19T18:04:08+02:00
trixie triage
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -276,30 +276,37 @@ CVE-2026-63446 (Suricata is a network Intrusion Detection
System, Intrusion Prev
NOTE: Fixed by:
https://github.com/OISF/suricata/commit/60a83c62a1dfdfb589b2bad27fb7fc339fc964b7
(suricata-8.0.6)
CVE-2026-61822 (pg_partman is a PostgreSQL extension that manages partitioned
tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE:
https://github.com/pgpartman/pg_partman/security/advisories/GHSA-9m6c-hw23-c6h2
NOTE: Fixed by:
https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361
(v5.5.0)
CVE-2026-61821 (pg_partman is a PostgreSQL extension that manages partitioned
tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE:
https://github.com/pgpartman/pg_partman/security/advisories/GHSA-pxp2-x8cf-rfhc
NOTE: Fixed by:
https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361
(v5.5.0)
CVE-2026-61820 (pg_partman is a PostgreSQL extension that manages partitioned
tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE:
https://github.com/pgpartman/pg_partman/security/advisories/GHSA-xqxh-6hh3-974m
NOTE: Fixed by:
https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361
(v5.5.0)
CVE-2026-61819 (pg_partman is a PostgreSQL extension that manages partitioned
tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE:
https://github.com/pgpartman/pg_partman/security/advisories/GHSA-gv5h-j2cm-rhc3
NOTE: Fixed by:
https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361
(v5.5.0)
CVE-2026-61818 (pg_partman is a PostgreSQL extension that manages partitioned
tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE:
https://github.com/pgpartman/pg_partman/security/advisories/GHSA-fm3m-9fh7-mqfc
NOTE: Fixed by:
https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361
(v5.5.0)
CVE-2026-61817 (pg_partman is a PostgreSQL extension that manages partitioned
tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE:
https://github.com/pgpartman/pg_partman/security/advisories/GHSA-gmw2-52wc-258g
NOTE: Fixed by:
https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361
(v5.5.0)
CVE-2026-61781 (pg_partman is a PostgreSQL extension that manages partitioned
tables b ...)
- pg-partman 5.5.0-1
+ [trixie] - pg-partman <no-dsa> (Minor issue)
NOTE:
https://github.com/pgpartman/pg_partman/security/advisories/GHSA-742w-3j7c-qwvp
NOTE: Fixed by:
https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361
(v5.5.0)
CVE-2026-61670 (microsandbox is an easy, fast, local-first microVM runtime and
library ...)
@@ -376,22 +383,27 @@ CVE-2026-93758 (An insecure direct object reference in
the nested attributes han
NOT-FOR-US: Mongoid
CVE-2026-93753 (deepmerge through 4.3.1 contains a prototype poisoning
vulnerability i ...)
- node-deepmerge <unfixed> (bug #1148407)
+ [trixie] - node-deepmerge <no-dsa> (Minor issue)
NOTE: https://github.com/TehShrike/deepmerge/issues/273
CVE-2026-93752 (CSSOM through 0.5.0 contains a denial of service vulnerability
in CSSS ...)
NOT-FOR-US: CSSOM
CVE-2026-93751 (uri-js through 4.4.1 contains an improper UTF-8 decoding
vulnerability ...)
- node-uri-js <unfixed> (bug #1148403)
+ [trixie] - node-uri-js <no-dsa> (Minor issue)
NOTE: https://github.com/garycourt/uri-js/issues/106
CVE-2026-93750 (http-cache-semantics through 4.2.0 contains a cache validation
vulnera ...)
- node-got <unfixed> (bug #1148406)
+ [trixie] - node-got <no-dsa> (Minor issue)
NOTE: https://github.com/kornelski/http-cache-semantics/issues/57
NOTE: node-got embeds and provides node-http-cache-semantics
CVE-2026-93749 (source-map-js through 1.2.1 fails to validate the per-section
offset l ...)
- node-postcss <unfixed> (bug #1148404)
+ [trixie] - node-postcss <no-dsa> (Minor issue)
NOTE: https://github.com/7rulnik/source-map-js/issues/76
NOTE: node-postcss embeds and provides node-source-map-js
CVE-2026-93748 (http-cache-semantics through 4.2.0 fails to properly validate
security ...)
- node-got <unfixed> (bug #1148405)
+ [trixie] - node-got <no-dsa> (Minor issue)
NOTE: https://github.com/kornelski/http-cache-semantics/issues/56
NOTE: node-got embeds and provides node-http-cache-semantics
CVE-2026-93737 (Azkaban through 4.0.0 omits project permission checks in the
ScheduleS ...)
@@ -400,6 +412,7 @@ CVE-2026-93736 (Mealie before 3.21.0 fails to validate user
ownership in the rat
NOT-FOR-US: Mealie
CVE-2026-93690 (uri-js through 4.4.1 contains a denial of service
vulnerability in the ...)
- node-uri-js <unfixed> (bug #1148402)
+ [trixie] - node-uri-js <no-dsa> (Minor issue)
NOTE: https://github.com/garycourt/uri-js/issues/105
CVE-2026-93689 (WinFsp through 2.2.26215 contains a null pointer dereference
vulnerabi ...)
NOT-FOR-US: WinFsp
@@ -407,6 +420,7 @@ CVE-2026-93688 (SGLang through 0.5.19 in prefill/decode
disaggregation mode with
NOT-FOR-US: SGLang
CVE-2026-93687 (braces through 3.0.3 contains a stack overflow vulnerability
in the re ...)
- node-braces <unfixed> (bug #1148400)
+ [trixie] - node-braces <no-dsa> (Minor issue)
NOTE: https://github.com/micromatch/braces/issues/70
CVE-2026-93685 (A flaw was found in the multicluster-observability-addon. A
remote att ...)
NOT-FOR-US: multicluster-observability-addon (Red Hat Advanced Cluster
Management for Kubernetes 2)
@@ -462,20 +476,24 @@ CVE-2026-93591 (SiYuan versions before 3.8.3 contain an
SQL injection vulnerabil
NOT-FOR-US: SiYuan
CVE-2026-93590 (ImageMagick before 7.1.2-31 contains a policy bypass
vulnerability in ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/59046410c17e9421f0ad7b4bec478a892cf30c12
(7.1.2-31)
CVE-2026-93589 (ImageMagick before 7.1.2-31 and 6.9.13-56 contains a
division-by-zero ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/8f620237fe341e814430fe3621b867b0b615f446
(7.1.2-31)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/1e91833e30a88c104276dcfbc01bb68ac4528514
(6.9.13-56)
CVE-2026-93588 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a
NULL point ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-92rw-c5mw-27v4
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/c4b3c9039a1509e3e7869331773865b521a62f93
(7.1.2-31)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/3b124bb81d3c53ec7d2b46f5ea04c00c4b07b9b3
(6.9.13-56)
CVE-2026-93587 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a
policy byp ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/d779ac52f92c3045ced59362b483bee25a3fc784
(7.1.2-31)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/b5da5eac006bae77c587a7c238e346c90ea52acd
(7.1.2-31)
@@ -483,6 +501,7 @@ CVE-2026-93587 (ImageMagick before 7.1.2-31 and before
6.9.13-56 contains a poli
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/0d768346a13b63e4d791be4b798482abd1e050d5
(6.9.13-56)
CVE-2026-93586 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a
use-after- ...)
- imagemagick 8:7.1.2.31+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/282f455de5c80a7a0d1a713087db9c8fce344141
(7.1.2-31)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/4fe31106f41fa114945ceaf93226fb151ada0d19
(7.1.2-31)
@@ -631,6 +650,7 @@ CVE-2026-90884 (The WP Recipe Maker plugin for WordPress is
vulnerable to Stored
CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes
attacke ...)
- resteasy <unfixed>
- resteasy3.0 <unfixed>
+ [trixie] - resteasy3.0 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519756
NOTE:
https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
NOTE: https://redhat.atlassian.net/browse/RESTEASY-3793
@@ -638,6 +658,7 @@ CVE-2026-89059 (A flaw was found in RESTEasy's
IIOImageProvider, which decodes a
CVE-2026-89058 (A flaw was found in RESTEasy's CorsFilter, which, when
configured to a ...)
- resteasy <unfixed>
- resteasy3.0 <unfixed>
+ [trixie] - resteasy3.0 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519775
NOTE:
https://github.com/resteasy/resteasy/security/advisories/GHSA-972r-f3fv-whm3
NOTE: https://redhat.atlassian.net/browse/RESTEASY-3796
@@ -717,6 +738,7 @@ CVE-2026-81942 (PLANET IGS-5225-8P2T4S industrial managed
switch V1 and V2 firmw
NOT-FOR-US: PLANET
CVE-2026-81627 (A flaw was found in QEMU. The VAPIC setup hypercall in
hw/i386/vapic.c ...)
- qemu <unfixed>
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4206
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/d61c8a6fb7388486353aa267ba0d75b098f16662
(master)
CVE-2026-81505 (Convoy is a cloud native webhooks gateway. Prior to 26.6.8,
Convoy's G ...)
@@ -1532,6 +1554,7 @@ CVE-2024-27123 (A cross-site scripting (XSS)
vulnerability has been reported to
NOT-FOR-US: QNAP
CVE-2026-XXXX [OSSA-2026-039]
- octavia 18.0.0-4 (bug #1148175)
+ [trixie] - octavia <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/octavia/+bug/2162101
NOTE: https://bugs.launchpad.net/octavia/+bug/2162103
NOTE: https://security.openstack.org/ossa/OSSA-2026-039.html
@@ -1763,10 +1786,12 @@ CVE-2026-86038 (libp2p is a JavaScript implementation
of the libp2p networking s
NOT-FOR-US: Node libp2p
CVE-2026-86000 (Soup Sieve is a CSS selector library designed to be used with
Beautifu ...)
- soupsieve <unfixed>
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE:
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-gjv8-xp57-g29c
NOTE: Fixed by:
https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef
(2.9)
CVE-2026-85999 (Soup Sieve is a CSS selector library designed to be used with
Beautifu ...)
- soupsieve <unfixed>
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE:
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-j934-xhv5-fg8f
NOTE: Fixed by:
https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda
(2.9)
CVE-2026-85721 (The AsyncHttpClient (AHC) library allows Java applications to
easily e ...)
@@ -4617,6 +4642,7 @@ CVE-2026-62997 (Kedro-Datasets provides data connectors
for Kedro. From version
NOT-FOR-US: Kedro-Datasets
CVE-2026-62949 (AsyncSSH is a Python package which provides an asynchronous
client and ...)
- python-asyncssh <unfixed>
+ [trixie] - python-asyncssh <no-dsa> (Minor issue)
NOTE:
https://github.com/ronf/asyncssh/security/advisories/GHSA-rw4j-r22c-9gc3
NOTE:
https://github.com/ronf/asyncssh/commit/9c354270c009285525e126721e8ed5fbed1f8a67
(v2.24.0)
NOTE:
https://github.com/ronf/asyncssh/commit/756cbae5350789ce9735f15f704bae9b5a3608b8
@@ -5509,10 +5535,12 @@ CVE-2026-85756 (SSH.NET is a Secure Shell (SSH) library
for .NET. Prior to 2026.
NOT-FOR-US: SSH.NET
CVE-2026-85732 (oras-go is a Go library for managing OCI artifacts. Prior to
2.6.2, th ...)
- golang-oras-oras-go 2.6.2-1
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
NOTE:
https://github.com/oras-project/oras-go/security/advisories/GHSA-h7vf-4x9w-h99v
NOTE: Fixed by:
https://github.com/oras-project/oras-go/commit/31da1963f8c327dd089cd29faeae95cf0fc50842
(v2.6.2)
CVE-2026-85731 (oras-go is a Go library for managing OCI artifacts. Prior to
2.6.2, co ...)
- golang-oras-oras-go 2.6.2-1
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
NOTE:
https://github.com/oras-project/oras-go/security/advisories/GHSA-m37j-52j7-pjw7
NOTE: Fixed by:
https://github.com/oras-project/oras-go/commit/adab2f25ea95ef4e6e41f50db9266a6701399422
(v2.6.2)
CVE-2026-85641 (The Formidable Forms WordPress plugin before 6.35 does not
restrict w ...)
@@ -6500,51 +6528,61 @@ CVE-2026-77702 (The Eventin WordPress plugin before
4.1.24 does not prevent the
NOT-FOR-US: WordPress plugin
CVE-2026-77412 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, readFi ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3
NOTE: https://github.com/rabbitmq/amqp091-go/pull/344
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf
(v1.13.0)
CVE-2026-77411 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, readLo ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-c5pq-fr2g-9jpf
NOTE: https://github.com/rabbitmq/amqp091-go/pull/347
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/143c1ace5fa7344cee135e5c7d22970f0de68282
(v1.13.0)
CVE-2026-77410 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, Channe ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh
NOTE: https://github.com/rabbitmq/amqp091-go/pull/346
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382
(v1.13.0)
CVE-2026-77409 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, Channe ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-wxx3-cj7g-w73j
NOTE: https://github.com/rabbitmq/amqp091-go/pull/349
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/5b0ccbb8d7bc3dfa18129d9b0f9256d656809494
(v1.13.0)
CVE-2026-77408 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, the wr ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-j497-x9hr-x34x
NOTE: https://github.com/rabbitmq/amqp091-go/pull/354
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/6959423aa2784a1971e399175dfb2065dea0f3b0
(v1.13.0)
CVE-2026-77407 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, PlainA ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-27gv-rfvv-22mv
NOTE: https://github.com/rabbitmq/amqp091-go/pull/350
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/fa013b8447eb60988db3c9281ff6b981e4d2fb4f
(v1.13.0)
CVE-2026-77406 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, Channe ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-rm6m-hrcw-jw33
NOTE: https://github.com/rabbitmq/amqp091-go/pull/351
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/3b879e1d1d25b544e26b3bc3d7db3213203c0f3b
(v1.13.0)
CVE-2026-77405 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, tlsCon ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-33mj-cw25-m34h
NOTE: https://github.com/rabbitmq/amqp091-go/pull/355
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/c9fd433ecac2e557919e51acc9d809390c402c6e
(v1.13.0)
CVE-2026-77404 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, URI.St ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-465g-fh3v-9jw4
NOTE: https://github.com/rabbitmq/amqp091-go/pull/352
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/743d488e46955fe7ffc55506fe2c401d01216783
(v1.13.0)
CVE-2026-77403 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to
1.13.0, Connec ...)
- golang-github-rabbitmq-amqp091-go 1.14.0-1
+ [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
NOTE:
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-xwwf-m8fg-p9q2
NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06
(v1.13.0)
@@ -7088,7 +7126,9 @@ CVE-2026-19535 (Nozomi Networks Labs identified a
CWE-352: Cross-Site Request Fo
NOT-FOR-US: Advantech
CVE-2026-19248 (QDomDocument XML parsing is vulnerable to a
remotely-triggerable denia ...)
- qt6-base <unfixed> (bug #1148271)
+ [trixie] - qt6-base <no-dsa> (Minor issue)
- qtbase-opensource-src <unfixed> (bug #1148272)
+ [trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
NOTE: https://qt-project.atlassian.net/browse/QTBUG-147191
NOTE:
https://github.com/qt/qtbase/commit/1303f05b33bb777626644729dd3b1330f60ecb7f
(6.10)
CVE-2026-18595 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable
to Stor ...)
=====================================
data/DSA/list
=====================================
@@ -5,7 +5,7 @@
{CVE-2026-87429 CVE-2026-87430 CVE-2026-87431 CVE-2026-87432
CVE-2026-87433 CVE-2026-87434 CVE-2026-87435 CVE-2026-87436 CVE-2026-87437
CVE-2026-87438 CVE-2026-87439 CVE-2026-87440 CVE-2026-87441 CVE-2026-87442
CVE-2026-87443 CVE-2026-87444 CVE-2026-87445 CVE-2026-87446 CVE-2026-87447
CVE-2026-87448 CVE-2026-87449 CVE-2026-87450 CVE-2026-87451 CVE-2026-87452
CVE-2026-87453 CVE-2026-87454 CVE-2026-87455 CVE-2026-87456 CVE-2026-87457
CVE-2026-87458 CVE-2026-87459 CVE-2026-87460 CVE-2026-87461 CVE-2026-87462
CVE-2026-87463 CVE-2026-87464 CVE-2026-87465 CVE-2026-87466 CVE-2026-87467
CVE-2026-87468 CVE-2026-87469 CVE-2026-87470 CVE-2026-87471 CVE-2026-87472
CVE-2026-87473 CVE-2026-87474 CVE-2026-87475 CVE-2026-87476 CVE-2026-87477
CVE-2026-87478 CVE-2026-87479 CVE-2026-87480 CVE-2026-87481 CVE-2026-87482
CVE-2026-87483 CVE-2026-87484 CVE-2026-87485 CVE-2026-87486 CVE-2026-87487
CVE-2026-87488 CVE-2026-87489 CVE-2026-87490 CVE-2026-87491 CVE-2026-87492
CVE-2026-87493 CVE-2026-87494 CVE-2026-87495 CVE-2026-87496 CVE-2026-87497
CVE-2026-87498 CVE-2026-87499 CVE-2026-87500 CVE-2026-87501 CVE-2026-87502
CVE-2026-87503 CVE-2026-87504 CVE-2026-87505 CVE-2026-87506 CVE-2026-87507
CVE-2026-87508 CVE-2026-87509 CVE-2026-87510 CVE-2026-87511 CVE-2026-87512
CVE-2026-87513 CVE-2026-87514 CVE-2026-87515 CVE-2026-87516 CVE-2026-87517
CVE-2026-87518 CVE-2026-87519 CVE-2026-87520 CVE-2026-87521 CVE-2026-87522
CVE-2026-87523 CVE-2026-87524 CVE-2026-87525 CVE-2026-87526 CVE-2026-87527
CVE-2026-87528 CVE-2026-87529 CVE-2026-87530 CVE-2026-87531 CVE-2026-87532
CVE-2026-87533 CVE-2026-87534 CVE-2026-87535 CVE-2026-87536 CVE-2026-87537
CVE-2026-87538 CVE-2026-87539 CVE-2026-87540 CVE-2026-87541 CVE-2026-87542
CVE-2026-87543 CVE-2026-87544 CVE-2026-87545 CVE-2026-87546 CVE-2026-87547
CVE-2026-87548 CVE-2026-87549 CVE-2026-87550 CVE-2026-87551 CVE-2026-87552
CVE-2026-87553 CVE-2026-87554 CVE-2026-87555 CVE-2026-87556 CVE-2026-87557
CVE-2026-87558 CVE-2026-87559 CVE-2026-87560 CVE-2026-87561 CVE-2026-87562
CVE-2026-87563 CVE-2026-87564 CVE-2026-87565 CVE-2026-87566 CVE-2026-87567
CVE-2026-87568 CVE-2026-87569 CVE-2026-87570 CVE-2026-87571 CVE-2026-87572
CVE-2026-87573 CVE-2026-87574 CVE-2026-87575 CVE-2026-87576 CVE-2026-87577
CVE-2026-87578 CVE-2026-87579 CVE-2026-87580 CVE-2026-87581 CVE-2026-87582
CVE-2026-87583 CVE-2026-87584 CVE-2026-87585 CVE-2026-87586 CVE-2026-87587
CVE-2026-87588 CVE-2026-87589 CVE-2026-87590 CVE-2026-87591 CVE-2026-87592
CVE-2026-87593 CVE-2026-87594 CVE-2026-87595 CVE-2026-87596 CVE-2026-87597
CVE-2026-87598 CVE-2026-87599 CVE-2026-87600 CVE-2026-87601 CVE-2026-87602
CVE-2026-87603 CVE-2026-87604 CVE-2026-87605 CVE-2026-87606 CVE-2026-87607
CVE-2026-87608 CVE-2026-87609 CVE-2026-87610 CVE-2026-87611 CVE-2026-87612
CVE-2026-87613 CVE-2026-87614 CVE-2026-87615 CVE-2026-87616 CVE-2026-87617
CVE-2026-87618 CVE-2026-87619 CVE-2026-87620 CVE-2026-87621 CVE-2026-87622
CVE-2026-87623 CVE-2026-87624 CVE-2026-87625 CVE-2026-87626 CVE-2026-87627
CVE-2026-87628 CVE-2026-87629 CVE-2026-87630 CVE-2026-87631 CVE-2026-87632
CVE-2026-87633 CVE-2026-87634 CVE-2026-87635 CVE-2026-87636 CVE-2026-87637
CVE-2026-87638 CVE-2026-87639 CVE-2026-87640 CVE-2026-87641 CVE-2026-87642
CVE-2026-87643 CVE-2026-87644 CVE-2026-87645 CVE-2026-87646 CVE-2026-87647
CVE-2026-87648 CVE-2026-87649 CVE-2026-87650 CVE-2026-87651 CVE-2026-87652
CVE-2026-87653 CVE-2026-87654 CVE-2026-87655 CVE-2026-87656 CVE-2026-87657
CVE-2026-87658 CVE-2026-91708 CVE-2026-91709 CVE-2026-91710 CVE-2026-91711
CVE-2026-91712 CVE-2026-91713 CVE-2026-91714 CVE-2026-91715 CVE-2026-91716
CVE-2026-91717 CVE-2026-91718 CVE-2026-91719 CVE-2026-91720 CVE-2026-91721
CVE-2026-91722 CVE-2026-91723 CVE-2026-91724 CVE-2026-91725 CVE-2026-91726
CVE-2026-91727 CVE-2026-91728 CVE-2026-91729 CVE-2026-91730 CVE-2026-91731
CVE-2026-91732 CVE-2026-91733 CVE-2026-91734 CVE-2026-91735 CVE-2026-91736
CVE-2026-91737 CVE-2026-91738 CVE-2026-91739 CVE-2026-91740 CVE-2026-91741
CVE-2026-91742 CVE-2026-91743 CVE-2026-91744 CVE-2026-91745 CVE-2026-91746
CVE-2026-91747 CVE-2026-91748 CVE-2026-91749}
[trixie] - chromium 153.0.8010.47-2~deb13u1
[17 Sep 2026] DSA-6505-1 bind9 - security update
- {CVE-2026-19033 CVE-2026-19662 CVE-2026-19666 CVE-2026-19667
CVE-2026-19668 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692
CVE-2026-80274 CVE-2026-81563 CVE-2026-81736}
+ {CVE-2026-19033 CVE-2026-19662 CVE-2026-19666 CVE-2026-19667
CVE-2026-19668 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692
CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 CVE-2026-78301 CVE-2026-19941}
[trixie] - bind9 1:9.20.29-1~deb13u1
[17 Sep 2026] DSA-6504-1 libapache2-mod-auth-openidc - security update
{CVE-2026-54789}
=====================================
data/dsa-needed.txt
=====================================
@@ -44,6 +44,8 @@ firebird3.0
--
firebird4.0
--
+freerdp3
+--
gegl (jmm)
move to 0.4.72
--
@@ -86,6 +88,13 @@ netty
--
network-manager-iodine
--
+network-manager-sstp
+ no upstream fix yet, if totally dead removal is an option
+--
+network-manager-vpnc
+ no upstream fix yet, if totally dead removal is an option
+--
+
nodejs (jmm)
Bastien Roucaries posted debdiff for review
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57cd99c14ed1b9ff9d0210aeda2074eef279e164
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57cd99c14ed1b9ff9d0210aeda2074eef279e164
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits