Your message dated Thu, 30 Jul 2026 13:05:53 +0000
with message-id <[email protected]>
and subject line Bug#1143071: fixed in node-ajv 8.20.0~ds+~cs7.1.2-1
has caused the Debian Bug report #1143071,
regarding node-ajv: CVE-2026-13676
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143071: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143071
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-ajv
Version: 8.20.0~ds+~cs6.1.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for node-ajv.
CVE-2026-13676[0]:
| fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize
| Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion
| path calls a helper that does not exist on the global URL
| constructor, silently leaving the host in its original Unicode form
| while normalize() and equal() still return values that differ from a
| WHATWG-compatible URL parser. Applications that use fast-uri to
| enforce host-based policy (denylists, loopback filtering, redirect
| validation, outbound proxy routing) before passing the same URL to
| Node's URL or fetch can be bypassed when the two implementations
| resolve the same input to different hosts. Patches: upgrade to fast-
| uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds:
| enforce host policy using the same URL parser used for the actual
| request, or reject non-ASCII hosts before policy checks.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-13676
https://www.cve.org/CVERecord?id=CVE-2026-13676
[1] https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-ajv
Source-Version: 8.20.0~ds+~cs7.1.2-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-ajv, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-ajv package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 30 Jul 2026 14:50:10 +0200
Source: node-ajv
Architecture: source
Version: 8.20.0~ds+~cs7.1.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1143064 1143071
Changes:
node-ajv (8.20.0~ds+~cs7.1.2-1) unstable; urgency=medium
.
* Team upload
* New upstream version
(Closes: #1143064, #1143071, CVE-2026-16221, CVE-2026-13676)
Checksums-Sha1:
676c5e8171c9aad024f61aa8cc7e009ff93d2f8c 2995 node-ajv_8.20.0~ds+~cs7.1.2-1.dsc
e9eb88d2d29bd89c0979db3889d2ac01bef8cb29 15784
node-ajv_8.20.0~ds+~cs7.1.2.orig-ajv-formats.tar.xz
bb3f3e3efe349b9047ddb0f1d14ef010b67ec15a 28820
node-ajv_8.20.0~ds+~cs7.1.2.orig-fast-uri.tar.xz
252fb7dcb0ee564c8ccca05ce47f18a5869e455e 157948
node-ajv_8.20.0~ds+~cs7.1.2.orig.tar.xz
691ff06439db89affd1799b2e95779e097ba5393 82644
node-ajv_8.20.0~ds+~cs7.1.2-1.debian.tar.xz
Checksums-Sha256:
a6162316ff36f6ee7d893079ca55e596b4c7a5d997b719ba15ffdea202f9515a 2995
node-ajv_8.20.0~ds+~cs7.1.2-1.dsc
cb2d4c8318b09e8dc95400cef30007678adde921f2f96e40555186cf0b284795 15784
node-ajv_8.20.0~ds+~cs7.1.2.orig-ajv-formats.tar.xz
933b221c2c241cdebf7d8820704ba759f53e4a3183ba24ddc3ab919b6f961b15 28820
node-ajv_8.20.0~ds+~cs7.1.2.orig-fast-uri.tar.xz
dc39049f1740e184d79b4ba4d59b804f7c2dee3885e6eda9fbcfdfeb73799d8f 157948
node-ajv_8.20.0~ds+~cs7.1.2.orig.tar.xz
909d3ddfe8e57085f5c20a53db709af35aba0ae97f77122af9c77c6d8290b188 82644
node-ajv_8.20.0~ds+~cs7.1.2-1.debian.tar.xz
Files:
c7b89665d7ccdce4ba1d064558448720 2995 javascript optional
node-ajv_8.20.0~ds+~cs7.1.2-1.dsc
d731ebdc55c16ebfc43bac566641a2bb 15784 javascript optional
node-ajv_8.20.0~ds+~cs7.1.2.orig-ajv-formats.tar.xz
00d7c5f444be961cd3e8d12da393763a 28820 javascript optional
node-ajv_8.20.0~ds+~cs7.1.2.orig-fast-uri.tar.xz
a4bf97e93b7b8a0e274d0267430f0c7b 157948 javascript optional
node-ajv_8.20.0~ds+~cs7.1.2.orig.tar.xz
faa35211da5aae77a870ce3daf5f93e5 82644 javascript optional
node-ajv_8.20.0~ds+~cs7.1.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmprSREACgkQ9tdMp8mZ
7ungww//bpcwXx9HIhLpzql/E8WBpL60jl4b8BHOl3EGjh8YmrYqf+lYiDAfnxsM
zQSRIOPa+pBJoZ4ggwzyTfLQ7LBo5mdJA0KzfoP2WbvzJaGuZeqIeVlHUAl7BWXw
CLJT1qm0i/rfXUJVJEznyWXESe2pghDD5WtMnsRvJXvQw0D/LncSQ7tuES1FQqug
dIENbTAlUifHgQd4x106lPIA60F4i8hcmFR+8GosEwJdJ3gxjQePn5IE+ZFJFiWV
zAdjYLqdtW2f9zi04F++uxGjAtWAF3wvs58I6WRxuImU6uH/xwV+LIUK9Htf7OFG
njDEBwwJQLr/PSeV2a3j53UVy+UBbSgPWq6CRuMPdLpulOLAc0mozvdpYn0R2IRg
n4oir5yBJ1mW6Gqwx0mPQRxqOAZ4cptCJBhPcUzsOColR/tne8FmfYAhldZvgxpQ
O5YUmylQU/rIiTAOv1uwG2LWXJp5qk38AkNoGGKfUPQqQ61cyRFoJo9hnlBwSDrQ
o2x+LRo9Um05kEC9W4gqvKqC/2c4dXwER9g5oaOnHqSZmDpZYRqq/53i7HmVpiqc
0Kao3HlWDZBxWjFuACVmzew/SQUaDcjfyjYvjBo3DX7Wo5ychLds0RvIuG26raSG
PX3mvgoANOjWh+xjA5UF0xWm1YZ+20QFyo7xvvpolfQBg1+32xk=
=89kc
-----END PGP SIGNATURE-----
pgpsuS_xd702F.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel