Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1d2d2695 by Moritz Muehlenhoff at 2026-02-27T12:52:49+01:00
trixie/bookworm triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -295,9 +295,13 @@ CVE-2026-2244 (A vulnerability in Google Cloud Vertex AI 
Workbench from7/21/2025
        NOT-FOR-US: Google Cloud Vertex AI Workbench
 CVE-2026-28296 (A flaw was found in the FTP GVfs backend. A remote attacker 
could expl ...)
        - gvfs <unfixed>
+       [trixie] - gvfs <no-dsa> (Minor issue)
+       [bookworm] - gvfs <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/833
 CVE-2026-28295 (A flaw was found in the FTP GVfs backend. A malicious FTP 
server can e ...)
        - gvfs <unfixed>
+       [trixie] - gvfs <no-dsa> (Minor issue)
+       [bookworm] - gvfs <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/832
 CVE-2026-28138 (Deserialization of Untrusted Data vulnerability in Stylemix 
uListing u ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -499,6 +503,8 @@ CVE-2026-27840 (ZITADEL is an open source identity 
management platform. Starting
        NOT-FOR-US: Zitadel
 CVE-2026-27837 (Dottie provides nested object access and manipulation in 
JavaScript. V ...)
        - node-dottie <unfixed> (bug #1129097)
+       [trixie] - node-dottie <no-dsa> (Minor issue)
+       [bookworm] - node-dottie <no-dsa> (Minor issue)
        NOTE: 
https://github.com/mickhansen/dottie.js/security/advisories/GHSA-r5mx-6wc6-7h9w
        NOTE: Fixed by: 
https://github.com/mickhansen/dottie.js/commit/7e8fa1345a4b46325f0eab8d7aeb1c4deaefdb14
 (v2.0.7)
        NOTE: CVE exists because of an incomplete fix for CVE-2023-26132.
@@ -1746,6 +1752,7 @@ CVE-2026-26981 (OpenEXR provides the specification and 
reference implementation
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/d2be382758adc3e9ab83a3de35138ec28d93ebd8
 (v3.3.7-rc)
 CVE-2026-26331 (yt-dlp is a command-line audio/video downloader. Starting in 
version 2 ...)
        - yt-dlp 2026.02.21-1
+       [trixie] - yt-dlp <no-dsa> (Minor issue)
        [bookworm] - yt-dlp <not-affected> (Vulnerable code introduced later)
        NOTE: 
https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-g3gw-q23r-pgqm
        NOTE: Introduced with: 
https://github.com/yt-dlp/yt-dlp/commit/db3ad8a67661d7b234a6954d9c6a4a9b1749f5eb
 (2023.06.21)
@@ -15889,6 +15896,7 @@ CVE-2025-15282 (User-controlled data URLs parsed by 
urllib.request.DataHandler a
        - python3.13 3.13.12-1 (bug #1126780)
        [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
+       [bookworm] - python3.11 <no-dsa> (Minor issue)
        - python3.9 <removed>
        - pypy3 <unfixed> (bug #1126781)
        [trixie] - pypy3 <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d2d2695de43523e4c6a3c0d16cc3360f4b50b16

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1d2d2695de43523e4c6a3c0d16cc3360f4b50b16
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to