Your message dated Mon, 03 Aug 2026 09:06:15 +0000
with message-id <[email protected]>
and subject line Bug#1143457: fixed in node-ajv 8.20.0~ds+~cs7.1.3-1
has caused the Debian Bug report #1143457,
regarding node-ajv: CVE-2026-18446
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143457: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143457
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-ajv
Version: 8.20.0~ds+~cs7.1.2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-ajv.

CVE-2026-18446[0]:
| fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double
| forward slash to recognize a URI authority, so a reference that uses
| a backslash based introducer in place of it (backslash backslash,
| forward slash backslash, or backslash forward slash) is parsed with
| no authority and folds into the path. Node's native WHATWG URL
| parser instead treats a backslash as interchangeable with a forward
| slash for special schemes, so the two parsers extract different
| hosts from the same input. Applications that use fast-uri to enforce
| host based policy such as allowlists, SSRF filtering, or redirect
| validation before passing the same URL into Node's URL or fetch
| consumers can be steered to an unintended host. Upgrade to fast-uri
| 4.1.2, 3.1.5, or 2.4.4.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18446
    https://www.cve.org/CVERecord?id=CVE-2026-18446
[1] https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-ajv
Source-Version: 8.20.0~ds+~cs7.1.3-1
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-ajv, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-ajv package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 03 Aug 2026 10:41:40 +0200
Source: node-ajv
Architecture: source
Version: 8.20.0~ds+~cs7.1.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1143457
Changes:
 node-ajv (8.20.0~ds+~cs7.1.3-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version 8.20.0~ds+~cs7.1.3
     (Closes: #1143457, CVE-2026-18446)
Checksums-Sha1: 
 23e7b2c3adb2d179a9b7fe33d8386d4db77f23a0 2995 node-ajv_8.20.0~ds+~cs7.1.3-1.dsc
 e9eb88d2d29bd89c0979db3889d2ac01bef8cb29 15784 
node-ajv_8.20.0~ds+~cs7.1.3.orig-ajv-formats.tar.xz
 6c88cda55aea72c8ddf970be293e9d1169d5f481 33004 
node-ajv_8.20.0~ds+~cs7.1.3.orig-fast-uri.tar.xz
 252fb7dcb0ee564c8ccca05ce47f18a5869e455e 157948 
node-ajv_8.20.0~ds+~cs7.1.3.orig.tar.xz
 51e7ddf825206f8b5e35cbf0dbb51e7b8af69860 82636 
node-ajv_8.20.0~ds+~cs7.1.3-1.debian.tar.xz
Checksums-Sha256: 
 4130acee5e888e35dbc3f3c0093b54274e566fa4a1bbd73304d17b9c3b8a02ea 2995 
node-ajv_8.20.0~ds+~cs7.1.3-1.dsc
 cb2d4c8318b09e8dc95400cef30007678adde921f2f96e40555186cf0b284795 15784 
node-ajv_8.20.0~ds+~cs7.1.3.orig-ajv-formats.tar.xz
 278824fea3fc15b303607677dbbda6b6e10cd8edfea8e61b8921cf5b56cce158 33004 
node-ajv_8.20.0~ds+~cs7.1.3.orig-fast-uri.tar.xz
 dc39049f1740e184d79b4ba4d59b804f7c2dee3885e6eda9fbcfdfeb73799d8f 157948 
node-ajv_8.20.0~ds+~cs7.1.3.orig.tar.xz
 0c0f725f68ec729c94a539b2c0d078ee1bcbf5886395b1e599041619c6332f40 82636 
node-ajv_8.20.0~ds+~cs7.1.3-1.debian.tar.xz
Files: 
 3aec8eabf97329526944ddfb39cc1deb 2995 javascript optional 
node-ajv_8.20.0~ds+~cs7.1.3-1.dsc
 d731ebdc55c16ebfc43bac566641a2bb 15784 javascript optional 
node-ajv_8.20.0~ds+~cs7.1.3.orig-ajv-formats.tar.xz
 2ec27b6921e70806d5197ed14d894b5a 33004 javascript optional 
node-ajv_8.20.0~ds+~cs7.1.3.orig-fast-uri.tar.xz
 a4bf97e93b7b8a0e274d0267430f0c7b 157948 javascript optional 
node-ajv_8.20.0~ds+~cs7.1.3.orig.tar.xz
 d554b300b7167537df747932b9178404 82636 javascript optional 
node-ajv_8.20.0~ds+~cs7.1.3-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmpwVOgACgkQ9tdMp8mZ
7umjERAAiKq2xAc+cliictjhhVhqoB+eVuBwtbW0WBHHntGKxnv2J6sj1eqZ5WN1
y/l4fhdpRB1wje8KM/pXWiDdLhnq9sCJTekPKBkln1f8ZuzmeY8+g7CS7LiX/+I7
yomiYvTx5OU7kHER3vwDiy0gjUe1ZbFhzy3CkHYVHpeFEdOGSeTa5njwcXawJs4p
tMDZzejuVJPnQpg+pDFUrwqrSa7Q+QQYtD0FvicU3I7J7px9PDOvwGabPmpyrxN0
fLH0oHR65A7r7M4xRahG7NBzTT/dcFRbh14Nosl6dq12cHD2h2fZMyaunELg4lhh
GnqmnZ/t6Z+S8JxNKVZpIRczkpPhpeXtqTS/FcMb02XKzJdbc5nz4TEt2mjDAVV5
CHDDErtWZnSApFj6g7gq3QZRCKzf7LkCQx0GlrEXfxL1b/Koag3hhgj7DgcX/J7y
DsMphbZr2wWZvgaw4a5VAYbWUlpdQg080WQtU+e2fECyg8YvzejjS/hKHotdoi7A
bSi322QK679wTzipvA9X7FXHs8rLv3MKvQRafJtu1+6oTCDhgOwk52u+FmW6miYC
QR+YKG1bBaM3RD8TcZF7JQAa3aqP/Oucy6aOk/B2+2oj4/ZFGJ9pqBuQP95pf3dn
pjnLyOFi9r2OvVipNEu3UT3HmQ+mIs2mZoJAADFCEPYBE/VzdVg=
=v6zz
-----END PGP SIGNATURE-----

Attachment: pgpHenh3q1zPx.pgp
Description: PGP signature


--- End Message ---
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to