Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9946565b by Salvatore Bonaccorso at 2026-07-12T08:40:24+02:00
Simplify overlong note, the advisory contains enough information
- - - - -
2e894241 by Salvatore Bonaccorso at 2026-07-12T08:54:11+02:00
Process some NFUs
- - - - -
b44f15ef by Salvatore Bonaccorso at 2026-07-12T08:54:37+02:00
Add CVE-2026-55213/h2o
- - - - -
951fca40 by Salvatore Bonaccorso at 2026-07-12T08:54:54+02:00
Add CVE-2026-54329/snipe-it
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -98,7 +98,7 @@ CVE-2026-6801 (The Context Blog theme for WordPress is
vulnerable to Sensitive I
CVE-2026-5743 (The SimpLy Gallery Block & Lightbox plugin for WordPress is
vulnerable ...)
NOT-FOR-US: WordPress plugin
CVE-2026-59155 (Nezha Monitoring is a self-hostable, lightweight, servers and
websites ...)
- TODO: check
+ NOT-FOR-US: Nezha Monitoring
CVE-2026-58591 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
NOT-FOR-US: Drupal core and addons
CVE-2026-58590 (Missing Authorization vulnerability in Drupal FlowDrop allows
Forceful ...)
@@ -110,21 +110,21 @@ CVE-2026-58588 (Improper Neutralization of Input During
Web Page Generation ("Cr
CVE-2026-58587 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
NOT-FOR-US: Drupal core and addons
CVE-2026-58503 (Frappe is a full-stack web application framework. Prior to
16.16.0 and ...)
- TODO: check
+ NOT-FOR-US: Frappe
CVE-2026-58499 (EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS
is vulne ...)
- TODO: check
+ NOT-FOR-US: EverOS
CVE-2026-57850 (RustDesk before 1.4.9 does not enforce a session's authorized
connecti ...)
- TODO: check
+ NOT-FOR-US: RustDesk
CVE-2026-57807 (Authentication Bypass Using an Alternate Path or Channel
vulnerability ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57584 (Phalcon is a high-performance, full-stack PHP framework. Prior
to 5.15 ...)
- TODO: check
+ NOT-FOR-US: RustDesk
CVE-2026-57575 (Misskey is an open source, federated social media platform.
Prior to 2 ...)
- TODO: check
+ NOT-FOR-US: Misskey
CVE-2026-57574 (Misskey is an open source, federated social media platform.
Prior to 2 ...)
- TODO: check
+ NOT-FOR-US: Misskey
CVE-2026-57230 (OpenReplay is a self-hosted session replay suite. Prior to
1.27.0, the ...)
- TODO: check
+ NOT-FOR-US: OpenReplay
CVE-2026-57221 (RabbitMQ is a messaging and streaming broker. Prior to
3.13.15, 4.0.20 ...)
TODO: check
CVE-2026-57220 (RabbitMQ is a messaging and streaming broker. Prior to 4.2.6,
the Rabb ...)
@@ -148,19 +148,19 @@ CVE-2026-57212 (RabbitMQ is a messaging and streaming
broker. Prior to 3.13.14,
CVE-2026-57211 (RabbitMQ is a messaging and streaming broker. Prior to 4.1.11
and 4.2. ...)
TODO: check
CVE-2026-55884 (Tilt defines dev environments as code for microservice apps on
Kuberne ...)
- TODO: check
+ NOT-FOR-US: Tilt
CVE-2026-55883 (Tilt defines dev environments as code for microservice apps on
Kuberne ...)
- TODO: check
+ NOT-FOR-US: Tilt
CVE-2026-55882 (Tilt defines dev environments as code for microservice apps on
Kuberne ...)
- TODO: check
+ NOT-FOR-US: Tilt
CVE-2026-55881 (OpenReplay is a self-hosted session replay suite. From 1.22.0
before 1 ...)
- TODO: check
+ NOT-FOR-US: OpenReplay
CVE-2026-55880 (OpenReplay is a self-hosted session replay suite. In 1.27.0
and earlie ...)
- TODO: check
+ NOT-FOR-US: OpenReplay
CVE-2026-55879 (OpenReplay is a self-hosted session replay suite. From 1.24.0
before 1 ...)
- TODO: check
+ NOT-FOR-US: OpenReplay
CVE-2026-55852 (Frappe is a full-stack web application framework. Prior to
16.23.0 and ...)
- TODO: check
+ NOT-FOR-US: Frappe
CVE-2026-55810 (Improperly Controlled Modification of Dynamically-Determined
Object At ...)
NOT-FOR-US: Drupal core and addons
CVE-2026-55809 (Improperly Controlled Modification of Dynamically-Determined
Object At ...)
@@ -176,13 +176,13 @@ CVE-2026-55804 (Improperly Controlled Modification of
Dynamically-Determined Obj
CVE-2026-55803 (Improperly Controlled Modification of Dynamically-Determined
Object At ...)
NOT-FOR-US: Drupal core and addons
CVE-2026-55789 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-55665 (Grist is spreadsheet software using Python as its formula
language. Pr ...)
- TODO: check
+ NOT-FOR-US: Grist
CVE-2026-55664 (Grist is spreadsheet software using Python as its formula
language. Pr ...)
- TODO: check
+ NOT-FOR-US: Grist
CVE-2026-55659 (Grist is spreadsheet software using Python as its formula
language. Pr ...)
- TODO: check
+ NOT-FOR-US: Grist
CVE-2026-55515 (Snipe-IT is an IT asset/license management system. Prior to
8.6.2, the ...)
- snipe-it <itp> (bug #1005172)
CVE-2026-55481 (Snipe-IT is an IT asset/license management system. Prior to
8.6.2, def ...)
@@ -202,25 +202,26 @@ CVE-2026-55461 (Snipe-IT is an IT asset/license
management system. Prior to 8.6.
CVE-2026-55452 (Snipe-IT is an IT asset/license management system. Prior to
8.5.0, Act ...)
- snipe-it <itp> (bug #1005172)
CVE-2026-55405 (LangChain4j is a Java library for building LLM-powered
applications on ...)
- TODO: check
+ NOT-FOR-US: LangChain4j
CVE-2026-55377 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-55370 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-55233 (OpenResty is a high performance web platform. From 1.29.2.1 to
before ...)
TODO: check
CVE-2026-55229 (Gotenberg is a Docker-powered stateless API for PDF files.
Prior to 8. ...)
- TODO: check
+ NOT-FOR-US: Gotenberg
CVE-2026-55213 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and
HTTP/3. Pr ...)
- TODO: check
+ - h2o <removed>
+ NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-432c-8xmj-frmq
CVE-2026-55187 (Mailpit is an email testing tool and API for developers. Prior
to 1.30 ...)
TODO: check
CVE-2026-55175 (Spinnaker is an open source, multi-cloud continuous delivery
platform. ...)
- TODO: check
+ NOT-FOR-US: Spinnaker
CVE-2026-54736 (Phalcon is a high-performance, full-stack PHP framework. Prior
to 5.14 ...)
- TODO: check
+ NOT-FOR-US: Phalcon
CVE-2026-54714 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-52761 (ModSecurity is an open source, cross platform web application
firewall ...)
TODO: check
CVE-2026-52747 (ModSecurity is an open source, cross platform web application
firewall ...)
@@ -485,9 +486,9 @@ CVE-2026-59180 (Apprise is an open source library which
allows you to send a not
NOTE: https://github.com/caronc/apprise/pull/1610
NOTE: Fixed by:
https://github.com/caronc/apprise/commit/68c0aef218055e4586cf4605fd6b56358f5f462d
(v1.11.0)
CVE-2026-59162 (Excelize is a Go language library for reading and writing
Microsoft Ex ...)
- TODO: check
+ NOT-FOR-US: Excelize
CVE-2026-59161 (Excelize is a Go language library for reading and writing
Microsoft Ex ...)
- TODO: check
+ NOT-FOR-US: Excelize
CVE-2026-59154 (Wekan is open source kanban built with Meteor. Prior to 9.64,
Wekan ha ...)
- wekan <itp> (bug #819238)
CVE-2026-59151 (Prowler is a cloud security platform. Prior to 5.30.3,
Prowler's SAML ...)
@@ -499,7 +500,7 @@ CVE-2026-58493 (grav-plugin-database is the database plugin
for Grav CMS. Prior
CVE-2026-58492 (grav-plugin-database is the database plugin for Grav CMS.
Prior to 1.2 ...)
NOT-FOR-US: grav-plugin-database
CVE-2026-58225 (SQL Injection vulnerability in elixir-ecto postgrex allows an
attacker ...)
- TODO: check
+ NOT-FOR-US: elixir-ecto postgrex
CVE-2026-57994 (phpMyFAQ before 4.1.5 applies inconsistent active=yes and
publication- ...)
NOT-FOR-US: phpMyFAQ
CVE-2026-57961 (phpMyFAQ before 4.1.5 contains a potential authenticated path
traversa ...)
@@ -581,7 +582,7 @@ CVE-2026-55781 (NanaZip is the 7-Zip derivative intended
for the modern Windows
CVE-2026-55780 (NanaZip is the 7-Zip derivative intended for the modern
Windows experi ...)
NOT-FOR-US: NanaZip
CVE-2026-55687 (ESF-IDF is the Espressif Internet of Things (IOT) Development
Framewor ...)
- TODO: check
+ NOT-FOR-US: ESF-IDF
CVE-2026-55672 (ZITADEL is an open source identity management platform. Prior
to 3.4.1 ...)
NOT-FOR-US: Zitadel
CVE-2026-55671 (ZITADEL is an open source identity management platform. From
4.0.0-rc. ...)
@@ -621,11 +622,11 @@ CVE-2026-54469 (Dell Unisphere for PowerMax, version(s)
10.3.0.5 and prior, cont
CVE-2026-54468 (Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior,
contain(s) ...)
NOT-FOR-US: Dell / EMC
CVE-2026-54329 (Snipe-IT is an IT asset/license management system. Prior to
8.6.2, the ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-54149 (MaxKB is an open-source AI assistant for enterprise. Prior to
2.10.0-l ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-54063 (Excelize is a Go language library for reading and writing
Microsoft Ex ...)
- TODO: check
+ NOT-FOR-US: Excelize
CVE-2026-54001 (osquery is a SQL powered operating system instrumentation,
monitoring, ...)
TODO: check
CVE-2026-54000 (osquery is a SQL powered operating system instrumentation,
monitoring, ...)
@@ -633,9 +634,9 @@ CVE-2026-54000 (osquery is a SQL powered operating system
instrumentation, monit
CVE-2026-53780
REJECTED
CVE-2026-53657 (Lima launches Linux virtual machines, typically on macOS, for
running ...)
- TODO: check
+ NOT-FOR-US: Lima
CVE-2026-53653 (Grav is a file-based Web platform. Prior to 1.7.53 and
2.0.0-rc.8, Gra ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-53450 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
TODO: check
CVE-2026-53449 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
@@ -643,7 +644,7 @@ CVE-2026-53449 (Coturn is a free open source implementation
of TURN and STUN Ser
CVE-2026-53448 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
TODO: check
CVE-2026-51119 (An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to
escalat ...)
- TODO: check
+ NOT-FOR-US: Invixium IXM WEB
CVE-2026-46388 (osquery is a SQL powered operating system instrumentation,
monitoring, ...)
TODO: check
CVE-2026-41880 (R-SOFT DMS is vulnerable toOS Command Injection in the Optical
Charact ...)
@@ -2186,7 +2187,7 @@ CVE-2026-49145 (App::Ack versions through 3.10.0 for Perl
read arbitrary files v
[bullseye] - ack <postponed> (Minor issue; local-only, needs untrusted
project .ackrc; --files-from still unfixed upstream)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41643327/
NOTE: Fixed by:
https://github.com/beyondgrep/ack3/commit/45ff5fe77dbd96f7332f31943102291f878f30b8
(v3.10.0)
- NOTE: 45ff5fe (v3.10.0) is only a partial fix: it adds --follow to the
project .ackrc blocklist but --files-from remains accepted, so arbitrary file
read via --files-from is still unfixed upstream.
+ NOTE: v3.10.0 only released with a partial fix for the --follow-option.
CVE-2026-44840 (Dgraph is an open source distributed GraphQL database. Prior
to versio ...)
TODO: check
CVE-2026-41122 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7,
LTS2026 r ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b8641cc96f8f8797f11d05a985e95fd6b248af3f...951fca40b0b0efb61a9237c79143ec2c712f4ee1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b8641cc96f8f8797f11d05a985e95fd6b248af3f...951fca40b0b0efb61a9237c79143ec2c712f4ee1
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits