Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
84b2201d by Moritz Muehlenhoff at 2026-08-22T23:23:35+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -46,12 +46,15 @@ CVE-2026-75866 (Punk::OAuth2::Server versions through 0.03
for Perl issue access
NOT-FOR-US: Punk::OAuth2::Server Perl module
CVE-2026-71514 (NLTK 3.9.4 through 3.10.2 contains a path traversal
vulnerability in C ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/nltk/nltk/commit/10d34b3f4fe3fec74b76527a409eb0acbac2e8ab
(v3.10.3-rc1)
CVE-2026-71513 (NLTK before 3.10.3 contains a remote code execution
vulnerability in A ...)
- nltk <unfixed>
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea
(v3.10.3-rc1)
CVE-2026-70626 (NLTK versions before 3.9.4 contain a symlink escape
vulnerability in C ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9
CVE-2026-6258
REJECTED
@@ -77,31 +80,40 @@ CVE-2026-66916 (Joomla Extension - joomgalleryfriends.net -
Password-Protected C
NOT-FOR-US: Joomla
CVE-2026-66393 (NLTK versions before 3.9.4 contain an unbounded recursion
vulnerabilit ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw
CVE-2026-65915 (NLTK versions before 3.10.0 contain a logic bug in
FileSystemPathPoint ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9
CVE-2026-63312 (NLTK before 3.10.0 contains an arbitrary local file read
vulnerability ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8
CVE-2026-63311 (NLTK before 3.10.0 (affected versions <= 3.9.4) contains a
server-side ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-3gqm-fcw5-w839
CVE-2026-63310 (NLTK before 3.9.3 fails to verify file integrity after
downloading pac ...)
- nltk 3.9.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-5wp5-5229-5g6q
CVE-2026-62388 (NLTK versions before 3.10.0 default to ENFORCE=False in
pathsec.py, ca ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3
CVE-2026-62385 (NLTK versions before 3.10.0 contain a path traversal
vulnerability in ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4
CVE-2026-62384 (NLTK versions before 3.10.2 contain a symlink-based sandbox
bypass in ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv
NOTE: CVE exists because it is possible to bypass the fix for
CVE-2026-12074
CVE-2026-62383 (nltk versions before 3.10.2 contain a symlink-based arbitrary
file rea ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6
CVE-2026-62382 (PasswordPusher versions v1.45.11 through v2.9.5 contain an
improper au ...)
NOT-FOR-US: PasswordPusher
@@ -780,6 +792,7 @@ CVE-2026-77413 (JSONata is a JSON query and transformation
language. Prior to 1.
NOT-FOR-US: jsonata-js
CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From
0.124.0 u ...)
- golang-github-getkin-kin-openapi <unfixed>
+ [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-xhj3-7xw9-vr34
@@ -800,6 +813,7 @@ CVE-2026-77000 (The WP Social Media Login WordPress plugin
through 1.0.6 does no
NOT-FOR-US: WordPress plugin
CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From
0.10.0 un ...)
- golang-github-getkin-kin-openapi <unfixed>
+ [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-mmfr-pmjx-hw9w
@@ -1345,6 +1359,7 @@ CVE-2026-56875
REJECTED
CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and
earlier, Caps ...)
- capstone <unfixed>
+ [trixie] - capstone <no-dsa> (Minor issue)
NOTE:
https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4
NOTE: https://github.com/capstone-engine/capstone/pull/2968
NOTE: Fixed by:
https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e
(6.0.0-Alpha10)
@@ -1352,6 +1367,7 @@ CVE-2026-55894 (Capstone is a disassembly framework. In
6.0.0-Alpha9 and earlier
NOTE: Fixed by:
https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed
(v5 branch)
CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and
earlier, Caps ...)
- capstone <unfixed>
+ [trixie] - capstone <no-dsa> (Minor issue)
NOTE:
https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh
NOTE: https://github.com/capstone-engine/capstone/pull/2968
NOTE: Fixed by:
https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e
(6.0.0-Alpha10)
@@ -1424,6 +1440,7 @@ CVE-2026-49217 (Mailu is a mail server as a set of Docker
images. Prior to versi
NOT-FOR-US: Mailu
CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function
builds the ex ...)
- onnx <unfixed>
+ [trixie] - onnx <no-dsa> (Minor issue)
NOTE:
https://github.com/onnx/onnx/security/advisories/GHSA-q56x-g2fj-4rj6
CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder
(XmlBuilder module ...)
NOT-FOR-US: joshnuss xml_builder
@@ -2228,6 +2245,7 @@ CVE-2026-19586 (A pre-authentication OS command injection
vulnerability has been
NOT-FOR-US: TPLink
CVE-2026-18917 (A flaw was found in libvirt. An unprivileged local user could
exploit ...)
- libvirt <unfixed> (bug #1145069)
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: https://gitlab.com/libvirt/libvirt/-/work_items/903
NOTE: Introduced with:
https://gitlab.com/libvirt/libvirt/-/commit/34f2d0319d2098c77c8cc27d8350616029125a2b
(v1.2.6-rc1)
NOTE: Fixed by:
https://gitlab.com/libvirt/libvirt/-/commit/5a62cbf2907d4590283597b46da9c0f41e7b4d4f
@@ -2364,6 +2382,7 @@ CVE-2026-16922 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS
4.1 could allow a loca
NOT-FOR-US: IBM
CVE-2026-15743 (Catalyst::Plugin::Static::Simple versions through 0.38 for
Perl mark r ...)
- libcatalyst-plugin-static-simple-perl 0.38-1
+ [trixie] - libcatalyst-plugin-static-simple-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42860527/
NOTE:
https://github.com/perl-catalyst/Catalyst-Plugin-Static-Simple/pull/3
NOTE:
https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch
@@ -3496,15 +3515,19 @@ CVE-2026-66596 (Unauthenticated Cross Site Scripting
(XSS) in Newsletter <= 9.3.
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can
place a f ...)
- nnn <unfixed>
+ [trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can
createa direc ...)
- nnn <unfixed>
+ [trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-65610 (nnn stores homelen variable as uchar_t, which can only
represent value ...)
- nnn <unfixed>
+ [trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-65609 (nnn is vulnerable to Out-of-Bound write vulnerability.Due to
lack of v ...)
- nnn <unfixed>
+ [trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-64852 (Grav API Plugin is a RESTful API for Grav CMS that provides
full headl ...)
NOT-FOR-US: Grav plugin
@@ -6246,6 +6269,7 @@ CVE-2026-75107 (Grav Form Plugin before 9.1.19 fails to
escape field-definition
NOT-FOR-US: Grav plugin
CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet
length fi ...)
- bluez 5.87-2 (bug #1144961)
+ [trixie] - bluez <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
NOTE: Fixed by:
https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
NOTE: Followup:
https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
@@ -7006,6 +7030,7 @@ CVE-2026-50167 (Kurrier is a modern, self-hosted
workspace for email, calendar,
NOT-FOR-US: Kurrier
CVE-2026-50161 (libre is a generic library for real-time communications with
asynchron ...)
- libre <unfixed>
+ [trixie] - libre <no-dsa> (Minor issue)
NOTE:
https://github.com/baresip/re/security/advisories/GHSA-hvxv-v2gp-v93h
NOTE: https://github.com/baresip/re/pull/1584
NOTE: Fixed by:
https://github.com/baresip/re/commit/718b92615c7963670d26c1a2b246968b58d782e8
(v4.8.1)
@@ -13363,6 +13388,7 @@ CVE-2025-7639 (The vulnerability, if exploited, could
allow an authenticated mis
NOT-FOR-US: AVEVA
CVE-2025-71405 (chi versions before v5.2.2 contain an open redirect
vulnerability in t ...)
- golang-github-go-chi-chi 5.2.3-1
+ [trixie] - golang-github-go-chi-chi <no-dsa> (Minor issue)
[bookworm] - golang-github-go-chi-chi <ignored> (Minor issue; out of
LTS support)
[bullseye] - golang-github-go-chi-chi <ignored> (Minor issue; out of
LTS support)
NOTE:
https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93
@@ -16004,6 +16030,7 @@ CVE-2026-19566 (Net::CIDR::Set versions before 0.23 for
Perl allow memory exhaus
NOTE: Fixed by:
https://github.com/robrwo/perl-Net-CIDR-Set/commit/e16b27db676fd1ca671fbb31208a22c1b1ba9724
(0.23)
CVE-2026-9318 (tablib prior to 3.10.0 contains a stored cross-site scripting
vulnerab ...)
- python-tablib 3.10.0-1
+ [trixie] - python-tablib <no-dsa> (Minor issue)
NOTE: https://github.com/jazzband/tablib/pull/668
NOTE: Fixed by:
https://github.com/jazzband/tablib/commit/b0ff39fb9b2f457e5332249b4cc2ec11eabf46ee
(v3.10.0)
CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.7 ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -65,6 +65,8 @@ jupyterlab
--
kamailio
--
+libapache2-mod-auth-openidc (jmm)
+--
libdbi-perl (carnil)
--
libde265
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/84b2201d14f42b9fce769d24b11d4f4cf19ebbed
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/84b2201d14f42b9fce769d24b11d4f4cf19ebbed
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits