Skip to content

Commit 07a1775

Browse files
Sync Collecting Fix Commits: Sun Sep 6 08:19:38 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 6d6fd48 commit 07a1775

3 files changed

Lines changed: 71 additions & 0 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 54 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,60 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-PQXV-X4WF-XVVC": {
5+
"79c0979acff67a783c8a48e3ce38c167eae98925": "Publish Advisories\n\nGHSA-pqxv-x4wf-xvvc\nGHSA-vpg3-44vc-j965\nGHSA-w592-pr34-frcq"
6+
},
7+
"GHSA-VPG3-44VC-J965": {
8+
"79c0979acff67a783c8a48e3ce38c167eae98925": "Publish Advisories\n\nGHSA-pqxv-x4wf-xvvc\nGHSA-vpg3-44vc-j965\nGHSA-w592-pr34-frcq"
9+
},
10+
"GHSA-W592-PR34-FRCQ": {
11+
"79c0979acff67a783c8a48e3ce38c167eae98925": "Publish Advisories\n\nGHSA-pqxv-x4wf-xvvc\nGHSA-vpg3-44vc-j965\nGHSA-w592-pr34-frcq"
12+
},
13+
"GHSA-CPF2-9R4X-H52P": {
14+
"a06c27fb40a1b06d516ebb4473c975503bf765aa": "Publish Advisories\n\nGHSA-cpf2-9r4x-h52p\nGHSA-g72p-v6gq-4x7m\nGHSA-q93p-5wpr-g629\nGHSA-rpvc-23w4-j8mm"
15+
},
16+
"GHSA-G72P-V6GQ-4X7M": {
17+
"a06c27fb40a1b06d516ebb4473c975503bf765aa": "Publish Advisories\n\nGHSA-cpf2-9r4x-h52p\nGHSA-g72p-v6gq-4x7m\nGHSA-q93p-5wpr-g629\nGHSA-rpvc-23w4-j8mm"
18+
},
19+
"GHSA-Q93P-5WPR-G629": {
20+
"a06c27fb40a1b06d516ebb4473c975503bf765aa": "Publish Advisories\n\nGHSA-cpf2-9r4x-h52p\nGHSA-g72p-v6gq-4x7m\nGHSA-q93p-5wpr-g629\nGHSA-rpvc-23w4-j8mm"
21+
},
22+
"GHSA-RPVC-23W4-J8MM": {
23+
"a06c27fb40a1b06d516ebb4473c975503bf765aa": "Publish Advisories\n\nGHSA-cpf2-9r4x-h52p\nGHSA-g72p-v6gq-4x7m\nGHSA-q93p-5wpr-g629\nGHSA-rpvc-23w4-j8mm"
24+
},
25+
"GHSA-2RC8-VF7F-V3HX": {
26+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
27+
},
28+
"GHSA-3557-5V9R-P922": {
29+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
30+
},
31+
"GHSA-45VP-4854-43R7": {
32+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
33+
},
34+
"GHSA-55W6-5HH5-WJ3R": {
35+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
36+
},
37+
"GHSA-5F24-G9G9-M3V8": {
38+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
39+
},
40+
"GHSA-5RHW-6RXG-24J3": {
41+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
42+
},
43+
"GHSA-7HGJ-8JR5-JHP5": {
44+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
45+
},
46+
"GHSA-J6GF-62P6-M62V": {
47+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
48+
},
49+
"GHSA-PV54-WQ7V-WF7V": {
50+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
51+
},
52+
"GHSA-XMHH-VJ2G-RX9G": {
53+
"878471f03af19d10a884fd0953c06d7006d87539": "Publish Advisories\n\nGHSA-2rc8-vf7f-v3hx\nGHSA-3557-5v9r-p922\nGHSA-45vp-4854-43r7\nGHSA-55w6-5hh5-wj3r\nGHSA-5f24-g9g9-m3v8\nGHSA-5rhw-6rxg-24j3\nGHSA-7hgj-8jr5-jhp5\nGHSA-j6gf-62p6-m62v\nGHSA-pv54-wq7v-wf7v\nGHSA-xmhh-vj2g-rx9g"
54+
},
55+
"GHSA-84QV-4WJ5-WWMM": {
56+
"1cdf1a0ab0727205440a42634f84ba4c24928347": "Publish GHSA-84qv-4wj5-wwmm"
57+
},
458
"GHSA-38RG-J8XG-2M77": {
559
"a8760aafdf4262344135c5b2523020bb2ee51e54": "Publish Advisories\n\nGHSA-38rg-j8xg-2m77\nGHSA-3hwr-w7cv-hwc6\nGHSA-6358-p8m7-jxv6\nGHSA-hxm6-fmm7-h7jm\nGHSA-qh73-x3c2-xph4"
660
},

data/fix-commits/gentoo.git-f7ec53e2.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://gitweb.gentoo.org/repo/gentoo.git",
33
"vulnerabilities": {
4+
"CVE-2025-14847": {
5+
"247d4663ce20aeec22082f209945c5bd3cb21db4": "dev-db/mongodb: Make requested changes to ebuilds\n\n.. and patches.\n\n* Remove 8.0.8 and 8.0.12 as they are vulnerable to mongobleed(CVE-2025-14847).\n* Remove 8.2.9, superceded by 8.3.x.\n* Version bump 8.0.23 to 8.0.26.\n\nBug: https://bugs.gentoo.org/968160\nBug: https://bugs.gentoo.org/967856\nBug: https://bugs.gentoo.org/976310\nSigned-off-by: Aaron Sears-Aldridge <geodelic@gmail.com>\nPart-of: https://github.com/gentoo/gentoo/pull/46392\nSigned-off-by: Sam James <sam@gentoo.org>"
6+
},
47
"CVE-2026-19042": {
58
"224d458d7b54078f75dfd9144279148e83f58ff9": "net-misc/teamviewer: add 15.81.5\n\nnew version that fixes multiple security issues:\n\nCVE-2026-19042, TV-2026-1009, CVSSv3 Score 8.8\nCVE-2026-16444, TV-2026-1008, CVSSv3 Score 7.5\n\nNote: x86 support has been dropped upstream.\nNo fixed 15.x version for x86 available.\n\nBug: https://bugs.gentoo.org/981678\nSigned-off-by: Martin Dummer <martin.dummer@gmx.net>\nPart-of: https://github.com/gentoo/gentoo/pull/46721\nSigned-off-by: Sam James <sam@gentoo.org>"
69
},

data/fix-commits/nixpkgs-97436190.json

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,20 @@
11
{
22
"vcs_url": "https://github.com/nixos/nixpkgs",
33
"vulnerabilities": {
4+
"CVE-2026-23868": {
5+
"e45057a03b74c9f7daa7a5443c6e10905b82fc85": "giflib: patch CVE-2026-23868 and CVE-2026-26740 (#547909)",
6+
"d610cc9cbb14584938357ffab13b64d6327ac141": "giflib: patch CVE-2026-23868 and CVE-2026-26740\n\nThe unstable branch upgraded to the next major version of `giflib`,\nwhich is a change that cannot be backported."
7+
},
8+
"CVE-2026-26740": {
9+
"e45057a03b74c9f7daa7a5443c6e10905b82fc85": "giflib: patch CVE-2026-23868 and CVE-2026-26740 (#547909)",
10+
"d610cc9cbb14584938357ffab13b64d6327ac141": "giflib: patch CVE-2026-23868 and CVE-2026-26740\n\nThe unstable branch upgraded to the next major version of `giflib`,\nwhich is a change that cannot be backported."
11+
},
12+
"GHSA-V5RW-PQ35-5XW4": {
13+
"bad7f20813ed581214c0e91912cb6415010e6e0e": "python3Packages.rarfile: 4.2 -> 4.5\n\nBackport reason: sabnzbd 5.1.2 requires rarfile >= 4.3 (it calls\nrarfile.rar5_s2k at import time, so the service fails to start with\nrarfile 4.2). 4.3 through 4.5 also carry security fixes:\n- 4.3: disallow extraction outside the extraction path via an existing\n symlink (markokr/rarfile#114)\n- 4.4: excessive allocation from an unchecked size field\n (GHSA-v5rw-pq35-5xw4)\n- 4.5: unbounded read with comments (GHSA-94vx-95fq-wwvp)\n\nChangelog: https://github.com/markokr/rarfile/blob/v4.5/doc/news.rst\n\n(cherry picked from commit 601183cab00345214a4d15ba1a4bb608558c0bdd)\nAssisted-by: Claude Code (Claude Fable 5.1)"
14+
},
15+
"GHSA-94VX-95FQ-WWVP": {
16+
"bad7f20813ed581214c0e91912cb6415010e6e0e": "python3Packages.rarfile: 4.2 -> 4.5\n\nBackport reason: sabnzbd 5.1.2 requires rarfile >= 4.3 (it calls\nrarfile.rar5_s2k at import time, so the service fails to start with\nrarfile 4.2). 4.3 through 4.5 also carry security fixes:\n- 4.3: disallow extraction outside the extraction path via an existing\n symlink (markokr/rarfile#114)\n- 4.4: excessive allocation from an unchecked size field\n (GHSA-v5rw-pq35-5xw4)\n- 4.5: unbounded read with comments (GHSA-94vx-95fq-wwvp)\n\nChangelog: https://github.com/markokr/rarfile/blob/v4.5/doc/news.rst\n\n(cherry picked from commit 601183cab00345214a4d15ba1a4bb608558c0bdd)\nAssisted-by: Claude Code (Claude Fable 5.1)"
17+
},
418
"CVE-2026-84202": {
519
"05eed2466efeb4e5e94b375818809c95e947c4ce": "python3Packages.modelscope: mark CVE-2026-84202 (#560326)",
620
"4a6afa6e1ed3c62eb78ae82d163ee42440c68d20": "python3Packages.modelscope: mark CVE-2026-84202\n\nFixes #559073."

0 commit comments

Comments
 (0)