Skip to content

Commit 6c0f27e

Browse files
Sync Collecting Fix Commits: Sat May 23 12:53:22 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 2e4a665 commit 6c0f27e

2 files changed

Lines changed: 9 additions & 0 deletions

File tree

data/fix-commits/nixpkgs-97436190.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://github.com/nixos/nixpkgs",
33
"vulnerabilities": {
4+
"CVE-2026-9256": {
5+
"308c3c352cdbda17ab08b750886d3b5895018a05": "nginx: 1.30.1 -> 1.30.2\n\nChangelog: https://nginx.org/en/CHANGES-1.30\nAdvisory: https://my.f5.com/manage/s/article/K000161377\n\nFixes: CVE-2026-9256"
6+
},
47
"CVE-2026-46529": {
58
"837e9d61303079f52c21e3da2ffebbc5cdf8c91e": "evince: 48.1 -> 48.4\n\nSecurity update for CVE-2026-46529\nSee https://gitlab.gnome.org/GNOME/evince/-/work_items/2153\n\n(cherry picked from commit 436577778a7e429aa7af4f6809fa65867616bf34)",
69
"436577778a7e429aa7af4f6809fa65867616bf34": "evince: 48.1 -> 48.4\n\nSecurity update for CVE-2026-46529\nSee https://gitlab.gnome.org/GNOME/evince/-/work_items/2153"

data/fix-commits/prometheus-f95ed07a.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/prometheus/prometheus",
33
"vulnerabilities": {
4+
"CVE-2026-44990": {
5+
"fcf6d37fed143781a6260f12b6dae1b729b1b1e7": "web/ui: bump sanitize-html in mantine-ui to v2.17.4 [SECURITY]\n\nThe previous commit on this branch only refreshed the legacy react-app\nlockfile, leaving the mantine-ui workspace lockfile pinned at\nsanitize-html 2.17.3 \u2014 which is in the affected range of CVE-2026-44990\n/ GHSA-rpr9-rxv7-x643 (CVSS 9.3 critical, default-config XSS via the\n<xmp> raw-text passthrough). Bump the declared range in\nweb/ui/mantine-ui/package.json from ^2.17.3 to ^2.17.4 and refresh the\nworkspace-root lockfile so the modern UI is patched too.\n\nThe lockfile delta is small because the mantine-ui workspace was already\non htmlparser2 v10 and dayjs via other deps; the only new transitive\naddition is launder 1.7.1 (now a direct dependency of sanitize-html).\n\n```release-notes\n[SECURITY] Update sanitize-html to v2.17.4 to fix CVE-2026-44990 (XSS via the <xmp> raw-text passthrough) in the bundled mantine-ui and react-app UIs.\n```\n\nSigned-off-by: Arve Knudsen <arve.knudsen@gmail.com>"
6+
},
7+
"GHSA-RPR9-RXV7-X643": {
8+
"fcf6d37fed143781a6260f12b6dae1b729b1b1e7": "web/ui: bump sanitize-html in mantine-ui to v2.17.4 [SECURITY]\n\nThe previous commit on this branch only refreshed the legacy react-app\nlockfile, leaving the mantine-ui workspace lockfile pinned at\nsanitize-html 2.17.3 \u2014 which is in the affected range of CVE-2026-44990\n/ GHSA-rpr9-rxv7-x643 (CVSS 9.3 critical, default-config XSS via the\n<xmp> raw-text passthrough). Bump the declared range in\nweb/ui/mantine-ui/package.json from ^2.17.3 to ^2.17.4 and refresh the\nworkspace-root lockfile so the modern UI is patched too.\n\nThe lockfile delta is small because the mantine-ui workspace was already\non htmlparser2 v10 and dayjs via other deps; the only new transitive\naddition is launder 1.7.1 (now a direct dependency of sanitize-html).\n\n```release-notes\n[SECURITY] Update sanitize-html to v2.17.4 to fix CVE-2026-44990 (XSS via the <xmp> raw-text passthrough) in the bundled mantine-ui and react-app UIs.\n```\n\nSigned-off-by: Arve Knudsen <arve.knudsen@gmail.com>"
9+
},
410
"GHSA-39J6-789Q-QXVH": {
511
"9122d1f50bd3056bffd035b202612fe116c13efd": "Merge pull request #18650 from roidelapluie/roidelapluie/ghsa-39j6-789q-qxvh-3.5\n\ndiscovery/stackit: use config.Secret for ServiceAccountKey and PrivateKey",
612
"fd2d158f49819797216c263790fd46370be1b06a": "discovery/stackit: use config.Secret for ServiceAccountKey and PrivateKey\n\nFixes GHSA-39j6-789q-qxvh\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",

0 commit comments

Comments
 (0)