Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
306043a6 by Moritz Muehlenhoff at 2026-10-01T10:40:42+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1003,8 +1003,10 @@ CVE-2026-19553 (ssl.SSLContext.wrap_bio() didn't require 
the server_hostname arg
        - python3.15 <unfixed>
        - python3.14 <unfixed>
        - python3.13 <unfixed>
+       [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
        - pypy3 <unfixed>
+       [trixie] - pypy3 <no-dsa> (Minor issue)
        NOTE: https://github.com/python/cpython/issues/156793
        NOTE: https://github.com/python/cpython/pull/158503
        NOTE: 
https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082
 (3.15 branch)
@@ -1076,7 +1078,9 @@ CVE-2026-103432 (apcupsd through 3.14.14 has an sscanf 
stack-based buffer overfl
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493140
 CVE-2026-103399 (A flaw was found in SoupServer (libsoup). When an HTTP/1.x 
client send ...)
        - libsoup3 3.8.0-1
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543949
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/539
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/560
@@ -1124,10 +1128,12 @@ CVE-2026-103227 (A weakness has been identified in GPAC 
up to 26.07.0. Affected
        - gpac <removed>
 CVE-2026-103226 (A vulnerability was identified in Artifex Ghostscript up to 
10.09.0. A ...)
        - ghostscript 10.08.0~dfsg-1
+       [trixie] - ghostscript <no-dsa> (Minor issue)
        NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=709672
        NOTE: Fixed by: 
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=cbdc86cc7a95c792baae3a15c7acf59b95fbcd5c
 (ghostpdl-10.08.0)
 CVE-2026-103222 (A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. 
This imp ...)
        - c-blosc2 <unfixed>
+       [trixie] - c-blosc2 <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/Blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc
 (v3.3.3)
 CVE-2026-103118 (A vulnerability was detected in GraphicsMagick up to 1.3.47. 
Affected  ...)
        - graphicsmagick <unfixed>
@@ -1300,8 +1306,10 @@ CVE-2026-19445 (A remote, unauthenticated TLS client can 
make a server crash or
        - python3.15 <unfixed>
        - python3.14 <unfixed>
        - python3.13 <unfixed>
+       [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
        - pypy3 <unfixed>
+       [trixie] - pypy3 <no-dsa> (Minor issue)
        NOTE: https://github.com/python/cpython/issues/156293
        NOTE: https://github.com/python/cpython/pull/158504
        NOTE: 
https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7
 (3.15 branch)
@@ -1475,6 +1483,7 @@ CVE-2026-75823 (The User Frontend  WordPress plugin 
before 4.3.12 does not preve
        NOT-FOR-US: WordPress plugin
 CVE-2026-74225 (U-Boot before 2026.10-rc5 contains out-of-bounds memory access 
in dhcp ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: Introduced with: 
https://github.com/u-boot/u-boot/commit/a0245818f7f8e375abc00f36ff88326331e4e2f9
 (v2023.07-rc2)
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/20209a62bc8565fc1e040882bc03c71ff0d73076
 (v2026.10-rc5)
 CVE-2026-74222 (U-Boot before 2026.10-rc5 contains a use-after-free 
vulnerability in t ...)
@@ -1483,10 +1492,12 @@ CVE-2026-74222 (U-Boot before 2026.10-rc5 contains a 
use-after-free vulnerabilit
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/2d94618a58aeb7630f18eee33419ce48d0fd3616
 (v2026.10-rc5)
 CVE-2026-74221 (U-Boot before 2026.10-rc5 contains a buffer overflow in 
nfs_readlink_r ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: Introduced with: 
https://github.com/u-boot/u-boot/commit/cf3a4f1e86ecdd24f87b615051b49d8e1968c230
 (v2019.10-rc4)
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd
 (v2026.10-rc5)
 CVE-2026-74220 (U-Boot before 2026.10-rc5 contains a buffer overflow in 
nfs_read_reply ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: Introduced with: 
https://github.com/u-boot/u-boot/commit/aa207cf3a6d68f39d64cd29057a4fb63943e9078
 (v2019.10-rc4)
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/0bbf09859658b8cc9ac13be41af23b516b8ef69a
 (v2026.10-rc5)
 CVE-2026-72510 (The "supplier_no" parameter used in the business allocation 
search fea ...)
@@ -1499,13 +1510,16 @@ CVE-2026-71974 (U-Boot before 2026.10-rc3 contains an 
out-of-bounds write vulner
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/35432ef6fe2c79ab72709966e64815a45eb55c76
 (v2026.10-rc3)
 CVE-2026-71973 (U-Boot before 2026.10-rc4 contains an integer overflow 
vulnerability i ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: Introduced with: 
https://github.com/u-boot/u-boot/commit/c51006130370b48b7eb5a93ada745385aa27f6bf
 (v2020.10-rc2)
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/561ae28cb56a082cfa90c1c421c4955bc215470b
 (v2026.10-rc4)
 CVE-2026-71972 (U-Boot through 2026.10-rc5 contains an out-of-bounds write 
vulnerabili ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/5201e83342d64c2f438ea35158575f28225e752e
 CVE-2026-71971 (U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled 
contains an ou ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/u-boot/u-boot/commit/04ca915d5bf39dda5d1bce62d04d2b59d293c5b9
 (v2026.10-rc3)
 CVE-2026-71379 (The file export endpoint allows any unauthenticated attacker 
to export ...)
        NOT-FOR-US: Toptech Systems
@@ -1675,9 +1689,11 @@ CVE-2026-102842 (A vulnerability was identified in 
gedelumbung HospitalManagemen
        NOT-FOR-US: gedelumbung HospitalManagement
 CVE-2026-102805 (A flaw has been found in Nothings stb up to 1.16. This 
affects the fun ...)
        - libstb <unfixed>
+       [trixie] - libstb <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://github.com/nothings/stb/issues/1964
 CVE-2026-102804 (A vulnerability was detected in Nothings stb up to 
2c980bb59875b0d3214 ...)
        - libstb <unfixed>
+       [trixie] - libstb <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://github.com/nothings/stb/issues/1961
 CVE-2026-102794 (A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. 
This iss ...)
        NOT-FOR-US: Ziroom ZHOME A0101
@@ -1699,14 +1715,17 @@ CVE-2026-102620 (A vulnerability was determined in 
Freedesktop Poppler 26.06.0/2
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/245d3c6823377755f2c1d5fdddd010279c6ed94d
 CVE-2026-101283 (iperf3 3.20\u20133.21 (esnet/iperf) has a pre-auth heap 
buffer overflo ...)
        - iperf3 <unfixed>
+       [trixie] - iperf3 <no-dsa> (Minor issue)
        NOTE: https://github.com/esnet/iperf/releases/tag/3.22
        NOTE: 
https://github.com/esnet/iperf/commit/e29f6504dcfac7d2961fed4fd66364115e36fe5a 
(3.22)
 CVE-2026-101276 (iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated 
heap use- ...)
        - iperf3 <unfixed>
+       [trixie] - iperf3 <no-dsa> (Minor issue)
        NOTE: https://github.com/esnet/iperf/releases/tag/3.22
        NOTE: 
https://github.com/esnet/iperf/commit/9bea2d9a49d54870e2405c209fa60bf134a8a1a1 
(3.22)
 CVE-2026-102253 (iperf3 versions prior to 3.22 contains a denial of service 
vulnerabili ...)
        - iperf3 <unfixed>
+       [trixie] - iperf3 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/esnet/iperf/commit/a25378f8cbbaa7b3db5674ca3dcc19658ae65da3 
(3.22)
        NOTE: https://github.com/esnet/iperf/releases/tag/3.22
 CVE-2026-102252 (A path traversal vulnerability (CWE-22) in the embedded VMDK 
filesyste ...)
@@ -1951,6 +1970,7 @@ CVE-2026-77177 (Open GenAI Stack (aka ogx-ai) 2026-06-11, 
as used in the Meta AI
        NOT-FOR-US: Open GenAI Stack (aka ogx-ai)
 CVE-2026-76875 (PyPy before versions 3.11.16 and 3.12.14 contains a 
use-after-free vul ...)
        - pypy3 8.0.0+dfsg-1
+       [trixie] - pypy3 <no-dsa> (Minor issue)
 CVE-2026-76720 (A vulnerability in HPE OneView can be remotely exploited to 
cause a UR ...)
        NOT-FOR-US: HPE
 CVE-2026-76719 (A security vulnerability in HPE OneView may be exploited 
remotely to p ...)
@@ -1987,6 +2007,7 @@ CVE-2026-65102 (NVIDIA DeepStream  contains a 
vulnerability where an attacker co
        NOT-FOR-US: NVIDIA
 CVE-2026-63209 (compress provides various compression algorithms. Prior to 
version 1.1 ...)
        - golang-github-klauspost-compress 1.19.0+ds1-1
+       [trixie] - golang-github-klauspost-compress <no-dsa> (Minor issue)
        NOTE: 
https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw
        NOTE: Fixed by: 
https://github.com/klauspost/compress/commit/539243b8823ee8f03e49969823d57c348c917536
 (v1.19.0)
 CVE-2026-4523 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
@@ -2203,25 +2224,33 @@ CVE-2026-102559 (A flaw was found in libsoup. When 
constructing a masked WebSock
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/d7f074f8c8c90216f2476522836287c6f80fc53e
 (3.7.3)
 CVE-2026-102558 (A flaw was found in libsoup. When max-incoming-payload-size 
is unlimit ...)
        - libsoup3 3.8.0-1
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543274
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/381a474ff437d0f7573d2bb3e8d3027260ab584f
 (3.7.3)
 CVE-2026-102557 (A flaw was found in libsoup. When reassembling fragmented 
WebSocket me ...)
        - libsoup3 3.8.0-1
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543231
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/d7f074f8c8c90216f2476522836287c6f80fc53e
 (3.7.3)
 CVE-2026-102556 (A flaw was found in libsoup. When handling an incoming 
WebSocket Pong  ...)
        - libsoup3 3.8.0-1
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543229
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/d2cbaf25f81a9ce041714cf842c366c67b0b873e
 (3.7.3)
 CVE-2026-102555 (A flaw was found in libsoup. The soup_uri_decode_data_uri() 
function i ...)
        - libsoup3 3.8.0-1
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543224
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/e4f032268fa18f691a6c34d6adcb5b666f3e3f77
 (3.7.3)
@@ -3041,13 +3070,15 @@ CVE-2026-102333 (httpdbg before 2.2.1 fails to validate 
URL schemes in recorded
 CVE-2026-102332 (Dozzle versions before 11.1.2 fail to sanitize container 
display names ...)
        NOT-FOR-US: Dozzle
 CVE-2026-102297 (ZoneMinder before 1.38.4 fails to apply per-monitor access 
restriction ...)
-       - zoneminder <unfixed>
+       - zoneminder <unfixed> (unimportant)
        NOTE: 
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mg2g-jmfc-3w8g
        NOTE: Fixed by: 
https://github.com/ZoneMinder/zoneminder/commit/aafe580b231bbeead12a110a957d85a26f7a23be
 (1.38.4)
+       NOTE: Only supported for trusted users/behind auth
 CVE-2026-102296 (ZoneMinder before 1.38.4 contains static buffer overflow 
vulnerabiliti ...)
-       - zoneminder <unfixed>
+       - zoneminder <unfixed> (unimportant)
        NOTE: 
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-93j4-rcp9-9jx6
        NOTE: Fixed by: 
https://github.com/ZoneMinder/zoneminder/commit/2596e5fb64c0348e615577b0ab08dc38b6dc6ed8
 (1.38.4)
+       NOTE: Only supported for trusted users/behind auth
 CVE-2026-102293 (A vulnerability was identified in realjerrytang tacomall 
1.0.0. Impact ...)
        NOT-FOR-US: realjerrytang tacomall
 CVE-2026-102292 (A flaw has been found in coolbeans1212 MateisHomePage-Website 
up to ea ...)
@@ -3246,9 +3277,10 @@ CVE-2026-100371 (InvoicePlane is a self-hosted open 
source application for manag
 CVE-2026-100370 (DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. 
Prior to vers ...)
        NOT-FOR-US: DOMSanitizer
 CVE-2024-58386 (ZoneMinder versions 1.37.0 before 1.38.0 contain a path 
traversal vuln ...)
-       - zoneminder <unfixed>
+       - zoneminder <unfixed> (unimportant)
        NOTE: 
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-8fw2-wh82-vv4h
        NOTE: Fixed by: 
https://github.com/ZoneMinder/zoneminder/commit/3b379e99c0c1e539334ad4186c15ad0dc6c238b9
 (1.37.65)
+       NOTE: Only supported for trusted users/behind auth
 CVE-2024-42002 (A code injection vulnerability has been discovered in the 
Robot Operat ...)
        NOT-FOR-US: Operating System 2 (ROS 2) 'ros2topic' CLI tool
 CVE-2026-96415 (Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 
and 4.4.0  ...)
@@ -3338,6 +3370,7 @@ CVE-2026-97686 (Wind River VxWorks 7 prior to 26.09, 
specific system call argume
        NOT-FOR-US: WindRiver
 CVE-2026-97399 (The strncasecmp function in the GNU C Library 2.24 and later 
optimized ...)
        - glibc <unfixed>
+       [trixie] - glibc <no-dsa> (Minor issue)
        NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34683
        NOTE: 
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0024
 CVE-2026-97335 (Incorrect authorization in the custom storage volume creation 
endpoint ...)
@@ -3603,57 +3636,68 @@ CVE-2026-101910 (ip-address is a library for parsing 
and manipulating IPv4 and I
        NOTE: Fixed by: 
https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8
 (v10.5.1)
 CVE-2026-101909 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b 
(v0.34.0)
 CVE-2026-101908 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101907 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-r4gj-5m52-g5wh
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101906 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101905 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101904 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101903 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-c29m-xwm3-cm6r
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101902 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101901 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101900 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
 CVE-2026-101898 (Axios is a promise-based HTTP client for the browser and 
Node.js. From ...)
        - node-axios 1.20.0-1
+       [trixie] - node-axios <no-dsa> (Minor issue)
        NOTE: 
https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v
        NOTE: https://github.com/axios/axios/pull/11141
        NOTE: Fixed by: 
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a 
(v1.20.0)
@@ -78429,6 +78473,7 @@ CVE-2026-58042 (A flaw in Node.js can cause 
dns.resolveAny() Aborts the Node.js
        NOTE: Fixed by: 
https://github.com/nodejs/node/commit/22efc051a3c3b3bbddbb3cb06ce1ca5775923c01 
(v22.23.2)
 CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale 
StatementSyncIterator cre ...)
        - nodejs 24.19.0+dfsg+~cs24.13.3-1
+       [trixie] - nodejs <not-affected> (Vulnerable code not present, 
introduced in 22.x)
        [bookworm] - nodejs <not-affected> (vulnerable code introduced in v22 
with experimental sqlite module)
        [bullseye] - nodejs <not-affected> (vulnerable code introduced in v22 
with experimental sqlite module)
        NOTE: 
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodesqlite-sqltagstore-iterator-replay-can-re-execute-writes-cve-2026-58041---medium



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/306043a61e58070a007c7156bd1399565fa4f1c6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/306043a61e58070a007c7156bd1399565fa4f1c6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to