Skip to content

Commit 6d9660a

Browse files
Sync Collecting Fix Commits: Tue Jul 21 21:52:55 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent bdcfc23 commit 6d9660a

10 files changed

Lines changed: 601 additions & 232 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 502 additions & 220 deletions
Large diffs are not rendered by default.

data/fix-commits/buildroot-0b809119.json

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,39 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-15370": {
5+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2026-59842": {
8+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2026-59843": {
11+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-59844": {
14+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
15+
},
16+
"CVE-2026-59845": {
17+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
18+
},
19+
"CVE-2026-59846": {
20+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
21+
},
22+
"CVE-2026-59847": {
23+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
24+
},
25+
"CVE-2026-59848": {
26+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
27+
},
28+
"CVE-2026-59849": {
29+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
30+
},
31+
"CVE-2026-59850": {
32+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
33+
},
34+
"CVE-2026-59851": {
35+
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
36+
},
437
"CVE-2026-42616": {
538
"26811cb110217797fb44862aa401d68e73f9b1ae": "package/ntfs-3g: security bump version to 2026.7.7\n\nhttps://github.com/tuxera/ntfs-3g/wiki/NTFS-3G-Release-History\nhttps://seclists.org/oss-sec/2026/q3/152\n\n Multiple vulnerabilities have been discovered in ntfs-3g.\n A new version 2026.7.7 is now available at https://github.com/tuxera/ntfs-3g\n\n (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616)\n Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)\n Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618)\n Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569)\n Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571)\n Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570)\n Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572)\n Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135)\n Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136)\n\nSwitched to sha256 tarball hash provided by upstream.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
639
},

data/fix-commits/echo-bf86764e.json

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,7 @@
11
{
22
"vcs_url": "https://github.com/labstack/echo",
33
"vulnerabilities": {
4-
"GHSA-3PMX-CF9F-34XR": {
5-
"91f630e034cbe0f5f21b3b450ce222fa0f7ab8c1": "fix(static): disable static path unescaping by default to prevent ACL bypass\n\nFixes GHSA-3pmx-cf9f-34xr, a bypass of the GHSA-vfp3-v2gw-7wfq fix.\n\nThe router matches the raw, still-encoded request path, so encoded\nseparators and dot segments in a static wildcard are not seen as\ntraversal during routing. Unescaping them in the static file resolver\nafterwards let an attacker reach a file across a route-level middleware\nguard the encoded path never matched:\n\n - /public/%2E%2E/admin/secret.txt resolved to admin/secret.txt\n (high severity, default router)\n - /public%2F..%2Fadmin%2Fsecret.txt under UseEscapedPathForMatching=true,\n where the router decodes the path itself before the handler sees it\n\nRather than keep extending an encoding denylist, address the root cause:\nmake static path unescaping opt-in.\n\n - echo: Config.EnablePathUnescapingStaticFiles (default false) controls\n unescaping for Echo.Static/StaticFS and Group.Static/StaticFS.\n - middleware: StaticConfig.EnablePathUnescaping replaces the now\n deprecated DisablePathUnescaping (default is the safe, no-unescape mode).\n\nWith unescaping off, %2F/%5C/%2E%2E stay literal and never become\nseparators or traversal. As defense in depth, and to also close the\nUseEscapedPathForMatching variant (where the router, not the handler,\ndoes the decoding), reject any \"..\" path segment in the resolved\nwildcard via pathutil.HasDotDotSegment, mirroring the fs.ValidPath\n\"no .. element\" invariant. The existing encoded-separator guard remains\nas a backstop on the opt-in unescaping path.\n\nBREAKING CHANGE: static files whose names contain URL-encoded characters\n(e.g. \"hello world.txt\" via /hello%20world.txt) are no longer served by\ndefault; set EnablePathUnescapingStaticFiles / EnablePathUnescaping to\nopt back in.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"
6-
},
74
"GHSA-VFP3-V2GW-7WFQ": {
8-
"91f630e034cbe0f5f21b3b450ce222fa0f7ab8c1": "fix(static): disable static path unescaping by default to prevent ACL bypass\n\nFixes GHSA-3pmx-cf9f-34xr, a bypass of the GHSA-vfp3-v2gw-7wfq fix.\n\nThe router matches the raw, still-encoded request path, so encoded\nseparators and dot segments in a static wildcard are not seen as\ntraversal during routing. Unescaping them in the static file resolver\nafterwards let an attacker reach a file across a route-level middleware\nguard the encoded path never matched:\n\n - /public/%2E%2E/admin/secret.txt resolved to admin/secret.txt\n (high severity, default router)\n - /public%2F..%2Fadmin%2Fsecret.txt under UseEscapedPathForMatching=true,\n where the router decodes the path itself before the handler sees it\n\nRather than keep extending an encoding denylist, address the root cause:\nmake static path unescaping opt-in.\n\n - echo: Config.EnablePathUnescapingStaticFiles (default false) controls\n unescaping for Echo.Static/StaticFS and Group.Static/StaticFS.\n - middleware: StaticConfig.EnablePathUnescaping replaces the now\n deprecated DisablePathUnescaping (default is the safe, no-unescape mode).\n\nWith unescaping off, %2F/%5C/%2E%2E stay literal and never become\nseparators or traversal. As defense in depth, and to also close the\nUseEscapedPathForMatching variant (where the router, not the handler,\ndoes the decoding), reject any \"..\" path segment in the resolved\nwildcard via pathutil.HasDotDotSegment, mirroring the fs.ValidPath\n\"no .. element\" invariant. The existing encoded-separator guard remains\nas a backstop on the opt-in unescaping path.\n\nBREAKING CHANGE: static files whose names contain URL-encoded characters\n(e.g. \"hello world.txt\" via /hello%20world.txt) are no longer served by\ndefault; set EnablePathUnescapingStaticFiles / EnablePathUnescaping to\nopt back in.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
95
"c3fa2a27ff92b2b8db360de614f999ef1da24725": "fix(static): reject encoded path separators that bypass route-level middleware (#3011)\n\nv4 backport of GHSA-vfp3-v2gw-7wfq. See PR #3011.",
106
"8d1ae9d3360a71672418856d58753af25f2c3986": "fix(static): reject encoded path separators that bypass route-level middleware (#3009)\n\nFixes GHSA-vfp3-v2gw-7wfq. See PR #3009."
117
},

0 commit comments

Comments
 (0)