Skip to content

Commit 4807456

Browse files
Sync Collecting Fix Commits: Mon Aug 10 21:03:51 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent e15370a commit 4807456

7 files changed

Lines changed: 606 additions & 97 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 24 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,30 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-JX74-CQJV-2C67": {
5+
"71fc59e86369b6ca56cae5875bd755903409681d": "Publish GHSA-jx74-cqjv-2c67",
6+
"4ac579cf75502357fa92d0b50d1eff45200d078a": "Merge pull request #8899 from github/BarakSrour-GHSA-jx74-cqjv-2c67",
7+
"bfa1efc0640d7eb84d39ed804a9ca7e328eb94c7": "Improve GHSA-jx74-cqjv-2c67",
8+
"2ed0e889bf2c1e22b5b737972085c1cdb4d3874b": "Publish Advisories\n\nGHSA-2956-977x-2w3r\nGHSA-c9hr-64h3-gxpc\nGHSA-hr7p-wg7r-hg9m\nGHSA-jx74-cqjv-2c67\nGHSA-pgwh-4jj4-qm8v\nGHSA-qq9q-xgm3-xv9g"
9+
},
10+
"GHSA-Q3J6-QGPJ-74H6": {
11+
"02482669d0842164732528abaf35b0d1d78c84be": "Publish Advisories\n\nGHSA-q3j6-qgpj-74h6\nGHSA-v39h-62p7-jpjc",
12+
"61cfa99f69514667a359677101bb00694af9ff72": "Merge pull request #9010 from github/jlang-ih-GHSA-q3j6-qgpj-74h6",
13+
"a2bc950a4c84e8ed8aed408afb4afcfbf829b574": "Improve GHSA-q3j6-qgpj-74h6",
14+
"b728f64d638206227adcda0854d50c634e948919": "Publish Advisories\n\nGHSA-q3j6-qgpj-74h6\nGHSA-qxhc-wx3p-2wmg"
15+
},
16+
"GHSA-V39H-62P7-JPJC": {
17+
"02482669d0842164732528abaf35b0d1d78c84be": "Publish Advisories\n\nGHSA-q3j6-qgpj-74h6\nGHSA-v39h-62p7-jpjc",
18+
"d8e54933e3561742d4dc3cd37a35f8cf082b2acd": "Merge pull request #9011 from github/jlang-ih-GHSA-v39h-62p7-jpjc",
19+
"36200027e9b9b4b1ce8313bd5c5bd3b7d5120a33": "Improve GHSA-v39h-62p7-jpjc",
20+
"d37c2e34851737c9ec34d4f08561be833f88b0df": "Publish Advisories\n\nGHSA-h9hm-m2xj-4rq9\nGHSA-v39h-62p7-jpjc"
21+
},
22+
"GHSA-JMVP-698C-4X3W": {
23+
"922e8173614870a19087818f6de9486603a72eaa": "Improve GHSA-jmvp-698c-4x3w",
24+
"02982d8d893aace32f779290fd6e7acff9d21165": "Publish Advisories\n\nGHSA-3wf2-2pq4-4rvc\nGHSA-jmvp-698c-4x3w\nGHSA-wm25-j4gw-6vr3\nGHSA-9v35-4xcr-w9ph\nGHSA-p3pf-mff8-3h47\nGHSA-9v35-4xcr-w9ph\nGHSA-p3pf-mff8-3h47",
25+
"6161773b6968cff7d26e502efcb0d772c0ac4ea0": "Publish GHSA-jmvp-698c-4x3w",
26+
"560e3c1f50833d45e6b3ba25c33ef963742e2f62": "Publish GHSA-jmvp-698c-4x3w"
27+
},
428
"GHSA-642R-3GJ9-2PJ5": {
529
"576b487c75f9d664104d7463e36abf30985a7475": "Improve GHSA-642r-3gj9-2pj5"
630
},
@@ -791,9 +815,6 @@
791815
"GHSA-HF6X-8P5F-CGMF": {
792816
"eebfe29382bab0555b71aeccfc726ee84366cc67": "Improve GHSA-hf6x-8p5f-cgmf"
793817
},
794-
"GHSA-RPF9-HRJR-88FV": {
795-
"6b5c5d130b77accffb77ce5856e9e73203fad25a": "Improve GHSA-rpf9-hrjr-88fv"
796-
},
797818
"GHSA-QHQW-RRW9-25RM": {
798819
"c4478bdf22a1479c24acc6633381c02caed82220": "Improve GHSA-qhqw-rrw9-25rm",
799820
"70041fd661d5e04a39d4ed65d38ab60a6ca23119": "Publish GHSA-qhqw-rrw9-25rm",
@@ -804,16 +825,6 @@
804825
"28000668d4f3fc84b67be781b3bc800450421516": "Improve GHSA-jjmj-jmhj-qwj2",
805826
"33a37fd652a997c38abd026516d447966a1f193b": "Publish Advisories\n\nGHSA-h8fp-f39c-q6mh\nGHSA-jjmj-jmhj-qwj2"
806827
},
807-
"GHSA-V39H-62P7-JPJC": {
808-
"36200027e9b9b4b1ce8313bd5c5bd3b7d5120a33": "Improve GHSA-v39h-62p7-jpjc",
809-
"158feaf3168512f846756e79d9ddd1866dda2df1": "Improve GHSA-v39h-62p7-jpjc",
810-
"d37c2e34851737c9ec34d4f08561be833f88b0df": "Publish Advisories\n\nGHSA-h9hm-m2xj-4rq9\nGHSA-v39h-62p7-jpjc"
811-
},
812-
"GHSA-Q3J6-QGPJ-74H6": {
813-
"a2bc950a4c84e8ed8aed408afb4afcfbf829b574": "Improve GHSA-q3j6-qgpj-74h6",
814-
"51d8aa7a0bfe346f40ca7bdb797b32409cad06bf": "Improve GHSA-q3j6-qgpj-74h6",
815-
"b728f64d638206227adcda0854d50c634e948919": "Publish Advisories\n\nGHSA-q3j6-qgpj-74h6\nGHSA-qxhc-wx3p-2wmg"
816-
},
817828
"GHSA-44PX-QJJC-XRHQ": {
818829
"eb95d6f1aa709acc66580d0e4173af863a47d98d": "Publish Advisories\n\nGHSA-44px-qjjc-xrhq\nGHSA-f4h3-qhg5-j6mq\nGHSA-jcmp-jxh2-4jc3\nGHSA-c43v-4cr8-6mvp\nGHSA-f4h3-qhg5-j6mq\nGHSA-jcmp-jxh2-4jc3",
819830
"02a57185dcba44f8a653e92247b70079f35552f7": "Publish GHSA-44px-qjjc-xrhq"
@@ -2530,10 +2541,6 @@
25302541
"GHSA-H3QP-GQRC-Q736": {
25312542
"46e0ea47f0a4eaef28a608063bebdf42cf9534ec": "Publish Advisories\n\nGHSA-h3qp-gqrc-q736\nGHSA-h3qp-gqrc-q736"
25322543
},
2533-
"GHSA-JX74-CQJV-2C67": {
2534-
"bfa1efc0640d7eb84d39ed804a9ca7e328eb94c7": "Improve GHSA-jx74-cqjv-2c67",
2535-
"2ed0e889bf2c1e22b5b737972085c1cdb4d3874b": "Publish Advisories\n\nGHSA-2956-977x-2w3r\nGHSA-c9hr-64h3-gxpc\nGHSA-hr7p-wg7r-hg9m\nGHSA-jx74-cqjv-2c67\nGHSA-pgwh-4jj4-qm8v\nGHSA-qq9q-xgm3-xv9g"
2536-
},
25372544
"GHSA-3CHG-M5W7-QFV5": {
25382545
"cafd0bc363a9841bbeefdbc3deaec0b2eb763ab2": "Publish Advisories\n\nGHSA-3chg-m5w7-qfv5\nGHSA-3chg-m5w7-qfv5"
25392546
},
@@ -152668,11 +152675,6 @@
152668152675
"10e3c01e808c34647acb583276da7345dec1c687": "Publish Advisories\n\nGHSA-3wf2-2pq4-4rvc\nGHSA-rwcj-7jjp-4w38\nGHSA-xw35-rrcp-g7xm",
152669152676
"1b47bcf8764aedddada9e3746d74554a284dfa33": "Publish Advisories\n\nGHSA-rpx8-fg6w-rm6x\nGHSA-3wf2-2pq4-4rvc\nGHSA-rwcj-7jjp-4w38\nGHSA-xw35-rrcp-g7xm"
152670152677
},
152671-
"GHSA-JMVP-698C-4X3W": {
152672-
"02982d8d893aace32f779290fd6e7acff9d21165": "Publish Advisories\n\nGHSA-3wf2-2pq4-4rvc\nGHSA-jmvp-698c-4x3w\nGHSA-wm25-j4gw-6vr3\nGHSA-9v35-4xcr-w9ph\nGHSA-p3pf-mff8-3h47\nGHSA-9v35-4xcr-w9ph\nGHSA-p3pf-mff8-3h47",
152673-
"6161773b6968cff7d26e502efcb0d772c0ac4ea0": "Publish GHSA-jmvp-698c-4x3w",
152674-
"560e3c1f50833d45e6b3ba25c33ef963742e2f62": "Publish GHSA-jmvp-698c-4x3w"
152675-
},
152676152678
"GHSA-WM25-J4GW-6VR3": {
152677152679
"02982d8d893aace32f779290fd6e7acff9d21165": "Publish Advisories\n\nGHSA-3wf2-2pq4-4rvc\nGHSA-jmvp-698c-4x3w\nGHSA-wm25-j4gw-6vr3\nGHSA-9v35-4xcr-w9ph\nGHSA-p3pf-mff8-3h47\nGHSA-9v35-4xcr-w9ph\nGHSA-p3pf-mff8-3h47",
152678152680
"2ea022ba84e83cbe3dd0a0407b30a8294185ddfb": "Publish GHSA-wm25-j4gw-6vr3"

data/fix-commits/angular-cli-4a405ed0.json

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,22 @@
11
{
22
"vcs_url": "https://github.com/angular/angular-cli",
33
"vulnerabilities": {
4+
"CVE-2026-13697": {
5+
"f7f60e69e77cda60378543a9ca9cc2c76c0bf34f": "fix(@angular/build): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822",
6+
"f348efe8b6d9c9d7014afb331eecda0a9478ba0a": "fix(@angular-devkit/build-angular): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822"
7+
},
8+
"CVE-2026-16729": {
9+
"f7f60e69e77cda60378543a9ca9cc2c76c0bf34f": "fix(@angular/build): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822",
10+
"f348efe8b6d9c9d7014afb331eecda0a9478ba0a": "fix(@angular-devkit/build-angular): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822"
11+
},
12+
"GHSA-4CWX-7WF7-3272": {
13+
"f7f60e69e77cda60378543a9ca9cc2c76c0bf34f": "fix(@angular/build): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822",
14+
"f348efe8b6d9c9d7014afb331eecda0a9478ba0a": "fix(@angular-devkit/build-angular): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822"
15+
},
16+
"GHSA-V3R7-H72X-CJCM": {
17+
"f7f60e69e77cda60378543a9ca9cc2c76c0bf34f": "fix(@angular/build): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822",
18+
"f348efe8b6d9c9d7014afb331eecda0a9478ba0a": "fix(@angular-devkit/build-angular): bump undici to 7.29.0\n\nBumps undici to version 7.29.0 to resolve a number of CVEs including CVE-2026-13697 (GHSA-4cwx-7wf7-3272) and CVE-2026-16729 (GHSA-v3r7-h72x-cjcm).\n\nCloses #33822"
19+
},
420
"CVE-2026-49356": {
521
"ba5d16cacab4139897d1f0cf4161562b1bd00553": "fix(@angular/cli): update dependency @modelcontextprotocol/sdk to v1.30.0\n\nCVE-2026-49356.\n\nFixes #33787",
622
"3962517b95c76016ff7bcb53662704dff18c0552": "fix(@angular/cli): update dependency @modelcontextprotocol/sdk to v1.30.0\n\nCVE-2026-49356.\n\nFixes #33787",

data/fix-commits/buildroot-0b809119.json

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,21 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-53586": {
5+
"3c2d207f8c65d025d12e40d786f5208933684f44": "package/libgit2: security bump version to 1.9.6\n\nv1.9.5 fixes CVE-2026-53586, CVE-2026-53587, CVE-2026-53585,\nCVE-2026-53584, CVE-2026-53583. v1.9.6 fixes other non-security issues.\n\nRelease notes:\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.5\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.6\n\nv1.9.5 also replaces a bundled vulnerable libpcre with libpcre2 and\nupdated the PCRE license in COPYING as a result. This is mostly useful\non Windows; On POSIX systems, libgit2 can use regcomp() and Buildroot\nalready asks for it. See:\nhttps://github.com/libgit2/libgit2/commit/3a9102dae9aef333791bf03ba1a00d2cc78ecfc2\n\nSigned-off-by: Nicolas Cavallari <nicolas.cavallari@green-communications.fr>\n[Julien: add link to license update upstream commit]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2026-53587": {
8+
"3c2d207f8c65d025d12e40d786f5208933684f44": "package/libgit2: security bump version to 1.9.6\n\nv1.9.5 fixes CVE-2026-53586, CVE-2026-53587, CVE-2026-53585,\nCVE-2026-53584, CVE-2026-53583. v1.9.6 fixes other non-security issues.\n\nRelease notes:\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.5\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.6\n\nv1.9.5 also replaces a bundled vulnerable libpcre with libpcre2 and\nupdated the PCRE license in COPYING as a result. This is mostly useful\non Windows; On POSIX systems, libgit2 can use regcomp() and Buildroot\nalready asks for it. See:\nhttps://github.com/libgit2/libgit2/commit/3a9102dae9aef333791bf03ba1a00d2cc78ecfc2\n\nSigned-off-by: Nicolas Cavallari <nicolas.cavallari@green-communications.fr>\n[Julien: add link to license update upstream commit]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2026-53585": {
11+
"3c2d207f8c65d025d12e40d786f5208933684f44": "package/libgit2: security bump version to 1.9.6\n\nv1.9.5 fixes CVE-2026-53586, CVE-2026-53587, CVE-2026-53585,\nCVE-2026-53584, CVE-2026-53583. v1.9.6 fixes other non-security issues.\n\nRelease notes:\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.5\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.6\n\nv1.9.5 also replaces a bundled vulnerable libpcre with libpcre2 and\nupdated the PCRE license in COPYING as a result. This is mostly useful\non Windows; On POSIX systems, libgit2 can use regcomp() and Buildroot\nalready asks for it. See:\nhttps://github.com/libgit2/libgit2/commit/3a9102dae9aef333791bf03ba1a00d2cc78ecfc2\n\nSigned-off-by: Nicolas Cavallari <nicolas.cavallari@green-communications.fr>\n[Julien: add link to license update upstream commit]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-53584": {
14+
"3c2d207f8c65d025d12e40d786f5208933684f44": "package/libgit2: security bump version to 1.9.6\n\nv1.9.5 fixes CVE-2026-53586, CVE-2026-53587, CVE-2026-53585,\nCVE-2026-53584, CVE-2026-53583. v1.9.6 fixes other non-security issues.\n\nRelease notes:\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.5\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.6\n\nv1.9.5 also replaces a bundled vulnerable libpcre with libpcre2 and\nupdated the PCRE license in COPYING as a result. This is mostly useful\non Windows; On POSIX systems, libgit2 can use regcomp() and Buildroot\nalready asks for it. See:\nhttps://github.com/libgit2/libgit2/commit/3a9102dae9aef333791bf03ba1a00d2cc78ecfc2\n\nSigned-off-by: Nicolas Cavallari <nicolas.cavallari@green-communications.fr>\n[Julien: add link to license update upstream commit]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
15+
},
16+
"CVE-2026-53583": {
17+
"3c2d207f8c65d025d12e40d786f5208933684f44": "package/libgit2: security bump version to 1.9.6\n\nv1.9.5 fixes CVE-2026-53586, CVE-2026-53587, CVE-2026-53585,\nCVE-2026-53584, CVE-2026-53583. v1.9.6 fixes other non-security issues.\n\nRelease notes:\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.5\nhttps://github.com/libgit2/libgit2/releases/tag/v1.9.6\n\nv1.9.5 also replaces a bundled vulnerable libpcre with libpcre2 and\nupdated the PCRE license in COPYING as a result. This is mostly useful\non Windows; On POSIX systems, libgit2 can use regcomp() and Buildroot\nalready asks for it. See:\nhttps://github.com/libgit2/libgit2/commit/3a9102dae9aef333791bf03ba1a00d2cc78ecfc2\n\nSigned-off-by: Nicolas Cavallari <nicolas.cavallari@green-communications.fr>\n[Julien: add link to license update upstream commit]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
18+
},
419
"CVE-2026-39879": {
520
"732a933e348440dee758c6fe90b384c8e3f7b052": "package/syslog-ng: security bump version to 4.12.0\n\nhttps://github.com/syslog-ng/syslog-ng/blob/syslog-ng-4.12.0/NEWS.md\n\nFixes CVE-2026-39879.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
621
},

data/fix-commits/expat-ecf459d6.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
{
22
"vcs_url": "https://android.googlesource.com/platform/external/expat",
33
"vulnerabilities": {
4+
"CVE-2026-72522": {
5+
"27c6536c2bfa857b6678b1038d14f43fd65a4aa6": "Merge pull request #1296 from libexpat/mozilla-2053153\n\n[CVE-2026-72522] Fix an OOB read and the resulting infinite loop in `*_toUtf16` functions",
6+
"8fbfb52fa88e040e8b0b7a9d39f260d6a9e8b6db": "Changes: Document surrogates issue CVE-2026-72522\n\nFor readers new to surrogates in Unicode:\nhttps://en.wikipedia.org/wiki/Universal_Character_Set_characters#Surrogates"
7+
},
48
"CVE-2026-56412": {
59
"11cd58eb92dd8ebd85e018eabb7357ee28fec1c7": "Merge pull request #1278 from hextheshadow/fix/cdata-handler-call-depth\n\n[CVE-2026-56412] lib: Guard `XML_TOK_DATA_CHARS` handler calls in `doCdataSection`"
610
},

data/fix-commits/nixpkgs-97436190.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://github.com/nixos/nixpkgs",
33
"vulnerabilities": {
4+
"CVE-2026-10805": {
5+
"33ece8ba82d5908b446d93063fa5649a6f29daf9": "networkmanager: 1.56.0 -> 1.58.0\n\nhttps://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/raw/1.58.0/NEWS\n\nFixes: CVE-2026-10805"
6+
},
47
"GHSA-HMQG-CXWW-WQHQ": {
58
"dee2f938fc84c486e12a5753e42d2b29d7dfe3bc": "wordpressPackages: update plugins and languages\n\nCloses: https://github.com/NixOS/nixpkgs/issues/532248\nCloses: https://github.com/NixOS/nixpkgs/issues/527024\nCloses: https://github.com/NixOS/nixpkgs/issues/532252\nCloses: https://github.com/NixOS/nixpkgs/issues/500147\nFixes: GHSA-hmqg-cxww-wqhq\nFixes: GHSA-3pwp-g2mj-5p3v\nSee also: https://github.com/WordPress/gutenberg/pull/81279\n\n(cherry picked from commit 60574be3faac9306d8664e503cff608854b83630)",
69
"60574be3faac9306d8664e503cff608854b83630": "wordpressPackages: update plugins and languages\n\nCloses: https://github.com/NixOS/nixpkgs/issues/532248\nCloses: https://github.com/NixOS/nixpkgs/issues/527024\nCloses: https://github.com/NixOS/nixpkgs/issues/532252\nCloses: https://github.com/NixOS/nixpkgs/issues/500147\nFixes: GHSA-hmqg-cxww-wqhq\nFixes: GHSA-3pwp-g2mj-5p3v\nSee also: https://github.com/WordPress/gutenberg/pull/81279"

0 commit comments

Comments
 (0)