Bugs with TODO items

Show "check" TODOs

BugDescriptionNote
CVE-2016-1584In all versions of Unity8 a running but not active application on a la ...check proper tracking update
CVE-2022-23538github.com/sylabs/scs-library-client is the Go client for the Singular ...check details, might as well affect golang-github-apptainer-container-library-client
CVE-2022-50942Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ...check status upstream
CVE-2023-26044react/http is an event-driven, streaming HTTP client and server implem ...check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected
CVE-2023-49316In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...check if affecting ldap-account-manager or unused path
CVE-2023-50251php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50252php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50262Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ...check sources embedding php-dompdf if affected
CVE-2024-22420JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-22421JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2025-4382A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ...double check if vulnerability only considered present after grub_is_cli_disabled is introduced
CVE-2025-6499A vulnerability classified as problematic was found in vstakhov libucl ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-8671A mismatch caused by client-triggered server-sent stream resets betwee ...check, some projects will assign own CVEs and should then be covered under that specific CVE instead
CVE-2025-8941A flaw was found in linux-pam. The pam_namespace module may improperly ...check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes
CVE-2025-11010A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-11147Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ...clarifying with reporter and Eduard Bloch on the issue.
CVE-2025-60796phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...check, possibly not reported upstream
CVE-2025-60797phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60798phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60799phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...check, possibly not reported upstream
CVE-2025-61982An arbitrary code execution vulnerability exists in the Code Stream di ...check upstream status
CVE-2025-67108eProsima Fast-DDS v3.3 was discovered to contain improper validation f ...check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream
CVE-2025-69534Python-Markdown version 3.8 contain a vulnerability where malformed HT ...Asking whether it really needs a backport: https://bugs.debian.org/1131896
CVE-2025-69720The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ...check upstream status
CVE-2026-0708A flaw was found in libucl. A remote attacker could exploit this by pr ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2026-1703When pip is installing and extracting a maliciously crafted wheel arch ...check as well pipenv
CVE-2026-4833A weakness has been identified in Orc discount up to 3.0.1.2. This iss ...check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present
CVE-2026-7701A security vulnerability has been detected in Telegram Desktop up to 6 ...check upstream reports
CVE-2026-7790Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ...check if embedded copy in rabbitmq-server is problematic
CVE-2026-8484A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" ...double-check source packages, as there is not much details from cert.pl post
CVE-2026-8851SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ...check correctness
CVE-2026-13500A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected ...check upstream reporting and status
CVE-2026-13501A security vulnerability has been detected in antlr ANTLR4 up to 4.13. ...check upstream reporting and status
CVE-2026-13502A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the f ...check upstream reporting and status
CVE-2026-13503A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by ...check upstream reporting and status
CVE-2026-15779A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ...check if Red Hat specific
CVE-2026-16493A flaw was found in ansible-core. The _extract_collection_from_git() f ...check upstream details
CVE-2026-23479Redis is an in-memory data structure store. In redis-server from 7.2.0 ...check redict and valkey
CVE-2026-23631Redis is an in-memory data structure store. In all versions of redis-s ...check redict and valkey
CVE-2026-25243Redis is an in-memory data structure store. In versions of redis-serve ...check redict and valkey
CVE-2026-26197HDF5 is a high-performance library and a file format specification tha ...check, isolate upstream change, might only be relevant for 2.0.0 onwards
CVE-2026-26199HDF5 is a high-performance library and a file format specification tha ...isolate fixing commit
CVE-2026-27586Caddy is an extensible server platform that uses TLS by default. Prior ...check, introducing version
CVE-2026-27970Angular is a development platform for building mobile and desktop web ...check status for older versions
CVE-2026-28687ImageMagick is free and open-source software used for editing and mani ...For imagemagick6 superseded by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete
CVE-2026-28687ImageMagick is free and open-source software used for editing and mani ...Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41)
CVE-2026-28688ImageMagick is free and open-source software used for editing and mani ...For imagemagick6 by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete
CVE-2026-28688ImageMagick is free and open-source software used for editing and mani ...Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41)
CVE-2026-29022dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ...qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact
CVE-2026-32635Angular is a development platform for building mobile and desktop web ...check status for older versions
CVE-2026-36499A missing upper-bound check in the udpif_set_threads() function of Ope ...check, unclear status/validity
CVE-2026-39178A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted
CVE-2026-39179A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted
CVE-2026-39860Nix is a package manager for Linux and other Unix systems. A bug in th ...check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729
CVE-2026-40033FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ...unclear fixing commit references, incorrect reference in CVE entry?
CVE-2026-41889pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ...check the other golang-github-jackc-pgx* sources
CVE-2026-42308Pillow is a Python imaging library. Prior to version 12.2.0, if a font ...research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes
CVE-2026-42503gopls by default communicates via pipe. However, -port and -listen fla ...check impact on golang-golang-x-tools
CVE-2026-55223c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ...check if that is an issue with the packaged version
CVE-2026-55654A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds ...check details, AI generated report
CVE-2026-55655A flaw was found in OpenSSH. A local unprivileged attacker on a Linux ...check details, AI generated report
CVE-2026-58050libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...check with upstream, only affecting libssh2 on Winddows?
CVE-2026-58051libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...check with upstream, only affecting libssh2 on Winddows?
CVE-2026-59843A flaw was found in libssh. A remote authenticated peer can advertise ...check fixing commit in libssh-0.12.1

Search for package or bug name: Reporting problems