Skip to content

Commit 81b61c5

Browse files
Sync Collecting Fix Commits: Wed Sep 2 16:56:28 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent aefc2dd commit 81b61c5

8 files changed

Lines changed: 536 additions & 68 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 373 additions & 63 deletions
Large diffs are not rendered by default.

data/fix-commits/gitlab-accd617b.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
"vcs_url": "https://gitlab.com/gitlab-org/gitlab",
33
"vulnerabilities": {
44
"GHSA-2X63-GW47-W4MM": {
5+
"11985383a7e66db208dab02742fb9debb8bfaa50": "Merge branch 'duo/fix/626827-bump-websocket-driver-to-0.8.2' into 'master' \n\nBump websocket-driver to 0.8.2 in remaining lockfiles (GHSA-2x63-gw47-w4mm)\n\nSee merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/252879\n\nMerged-by: Panos Kanellidis <pkanellidis@gitlab.com>\nApproved-by: Anas Shahid <ashahid@gitlab.com>\nApproved-by: Panos Kanellidis <pkanellidis@gitlab.com>\nCo-authored-by: Duo Developer <service_account_group_9970_1976e9ecde3c53c783b64edb9ae993eb@noreply.gitlab.com>",
56
"dbec9ef841fec3bf7e893642aeecf33b2f8a77ce": "Bump websocket-driver to 0.8.2 in remaining lockfiles\n\nFix GHSA-2x63-gw47-w4mm by updating websocket-driver from outdated\nversions in two lockfiles that were missed in the initial fix:\n- gems/gitlab-database-load_balancing: 0.8.0 -> 0.8.2\n- vendor/gems/microsoft_graph_mailer: 0.7.5 -> 0.8.2\n\nResolves https://gitlab.com/gitlab-org/gitlab/-/work_items/626827\n\nChangelog: security"
67
},
78
"CVE-2022-1944": {

data/fix-commits/langchain-c5a32632.json

Lines changed: 9 additions & 0 deletions
Large diffs are not rendered by default.

data/fix-commits/langchainjs-af8f3570.json

Lines changed: 12 additions & 0 deletions
Large diffs are not rendered by default.

data/fix-commits/langgraph-642743ad.json

Lines changed: 3 additions & 0 deletions
Large diffs are not rendered by default.

data/fix-commits/lxd-ac1584d1.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
{
22
"vcs_url": "https://github.com/canonical/lxd",
33
"vulnerabilities": {
4+
"GHSA-G4CM-F533-78HQ": {
5+
"fad2d82df7ea52e39d70d45b161cc30960981dfc": "client/images: sanitize server-provided image file names (From Incus) (#18940)\n\n## Checklist\n\n- [x] I have read the [contributing\nguidelines](https://github.com/canonical/lxd/blob/main/CONTRIBUTING.md)\nand attest that all commits in this PR are [signed\noff](https://github.com/canonical/lxd/blob/main/CONTRIBUTING.md#including-a-signed-off-by-line-in-your-commits),\n[cryptographically\nsigned](https://github.com/canonical/lxd/blob/main/CONTRIBUTING.md#commit-signature-verification),\nand follow this project's [commit\nstructure](https://github.com/canonical/lxd/blob/main/CONTRIBUTING.md#commit-structure).\n- [x] I have checked and added or updated relevant documentation.\n\nThis sanitizes the server-supplied MetaName in the response to an lxd\nimage request to include only a possible file name and no path\ncomponents. There are also new unit tests to verify the behavior.\n\nThis addresses GHSA-g4cm-f533-78hq.",
6+
"45fd28e8787d6baf890a051c848b09fd99ee54d9": "client/images: Prevent path traversal in downloaded image name\n\nThe local filename for an exported image came from server-controlled\ndata (Content-Disposition for unified images, the simplestreams index\npath) and was joined with the target directory. Basename it.\n\nThis addresses GHSA-g4cm-f533-78hq.\n\nSigned-off-by: St\u00e9phane Graber <stgraber@stgraber.org>\n(cherry picked from commit 9e188e31e43c21fa8f2a4cac265aa246d4c947f2)\nSigned-off-by: Joseph Robert Torsella <joey.torsella@canonical.com>\nLicense: Apache-2.0"
7+
},
48
"CVE-2026-30405": {
59
"40a14d0d94cbbff4e67f43283756a0c9ea2ae82a": "lxd/bgp/server: switch from `github.com/osrg/gobgp/v3` to `github.com/osrg/gobgp/v4`\n\nhttps://github.com/advisories/GHSA-4p9m-8gc4-rw2h (GO-2026-4736/CVE-2026-30405)\nis only fixed in v4.\n\nTweak the error inspection in `removePrefixByUUID` to be more specific while\nstill matching the upstream error.\n\nhttps://github.com/osrg/gobgp/blob/a31017415c8e85fdc2d30c43fcbd6f3cab7ae760/pkg/server/server.go#L2544-L2546\n```\n\t\t\tif len(deletePathList) == 0 {\n\t\t\t\treturn fmt.Errorf(\"can't find a specified path(s) with the given UUID(s)\")\n\t\t\t}\n```\n\nAlso, rename `family` variable to avoid name clashes.\n\nSigned-off-by: Simon Deziel <simon.deziel@canonical.com>"
610
},

data/fix-commits/nixpkgs-97436190.json

Lines changed: 104 additions & 0 deletions
Large diffs are not rendered by default.

data/fix-commits/util-linux.git-4c15e64f.json

Lines changed: 30 additions & 5 deletions
Large diffs are not rendered by default.

0 commit comments

Comments
 (0)