Skip to content

Commit 8d42d2a

Browse files
Sync Collecting Fix Commits: Tue Aug 11 21:26:22 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 24ba3d0 commit 8d42d2a

7 files changed

Lines changed: 104 additions & 33 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 35 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,41 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-9MRH-PW7C-9MQM": {
5+
"e5d2459446d2155eb51cae59233db5752ae5ecae": "Publish GHSA-9mrh-pw7c-9mqm"
6+
},
7+
"GHSA-VG44-H755-9HW7": {
8+
"4c4902ec390613a15c8f9fe87d8a54a2be27edc5": "Publish GHSA-vg44-h755-9hw7"
9+
},
10+
"GHSA-FX4Q-GJRX-2JW6": {
11+
"376f28636f48b824466277a9e3cd3b427abb703c": "Publish GHSA-fx4q-gjrx-2jw6"
12+
},
13+
"GHSA-GG8C-3338-XW2F": {
14+
"49606c41a98fb879ef6002d1c337617bd697b649": "Publish GHSA-gg8c-3338-xw2f"
15+
},
16+
"GHSA-4C3C-R6P8-C863": {
17+
"3b5b8d0df74ca562f071187a069981188418ed93": "Publish GHSA-4c3c-r6p8-c863",
18+
"42aaed8d7e8da8cb9c127a415e13af1002b5d771": "Publish Advisories\n\nGHSA-4c3c-r6p8-c863\nGHSA-5w7q-77mv-v69f\nGHSA-98x5-vq43-vc5p\nGHSA-cgwc-pv48-fhj5"
19+
},
20+
"GHSA-9MR8-PWPW-3J2W": {
21+
"3d5a7ece6db62a69713b1766a33187f9333ba7c3": "Publish GHSA-9mr8-pwpw-3j2w"
22+
},
23+
"GHSA-JQHP-238X-QHGF": {
24+
"a030d1e2051dc3bc94a2d278171b95835ab81855": "Publish GHSA-jqhp-238x-qhgf"
25+
},
26+
"GHSA-M93F-WJ8C-RP8P": {
27+
"da8da86bb2b97d8815d8545ba0adc1eaf76d1b22": "Publish GHSA-m93f-wj8c-rp8p"
28+
},
29+
"GHSA-R6MH-95JW-G7QG": {
30+
"862f487fdb513ba1c7a2fb1ea41cf4f75100c277": "Publish GHSA-r6mh-95jw-g7qg"
31+
},
32+
"GHSA-Q7CG-43MG-QP69": {
33+
"4eb4fd4b45ade583f100a98592f20d3bf935f7b7": "Publish GHSA-q7cg-43mg-qp69",
34+
"3fa7f26a3e7d23d5fd4feb255720d53d27f68286": "Publish Advisories\n\nGHSA-q7cg-43mg-qp69\nGHSA-cfqj-9g2g-w7q6\nGHSA-phwq-j96m-2c2q\nGHSA-mfhv-gwf8-4m88\nGHSA-hm53-hrhh-gwfq\nGHSA-8x94-hmjh-97hq"
35+
},
36+
"GHSA-87FV-VQQR-M4JR": {
37+
"db308485b9bda6981175647782e8fb83bc08aa93": "Publish GHSA-87fv-vqqr-m4jr"
38+
},
439
"GHSA-6V23-65FJ-8G7C": {
540
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
641
},
@@ -13113,9 +13148,6 @@
1311313148
"GHSA-RHQ6-9RGH-V45C": {
1311413149
"7d47c66ea198f924e335698c7cc019dcba2873de": "Publish Advisories\n\nGHSA-fhp4-pr5j-46m5\nGHSA-j7f5-gfqm-pcx3\nGHSA-rhq6-9rgh-v45c"
1311513150
},
13116-
"GHSA-4C3C-R6P8-C863": {
13117-
"42aaed8d7e8da8cb9c127a415e13af1002b5d771": "Publish Advisories\n\nGHSA-4c3c-r6p8-c863\nGHSA-5w7q-77mv-v69f\nGHSA-98x5-vq43-vc5p\nGHSA-cgwc-pv48-fhj5"
13118-
},
1311913151
"GHSA-5W7Q-77MV-V69F": {
1312013152
"42aaed8d7e8da8cb9c127a415e13af1002b5d771": "Publish Advisories\n\nGHSA-4c3c-r6p8-c863\nGHSA-5w7q-77mv-v69f\nGHSA-98x5-vq43-vc5p\nGHSA-cgwc-pv48-fhj5"
1312113153
},
@@ -264704,9 +264736,6 @@
264704264736
"GHSA-PF2J-9QMP-JQR2": {
264705264737
"bb4cb4fc1e14e520aa4497081110d0361aefeec9": "Publish Advisories\n\nGHSA-ff7x-qrg7-qggm\nGHSA-pf2j-9qmp-jqr2"
264706264738
},
264707-
"GHSA-Q7CG-43MG-QP69": {
264708-
"3fa7f26a3e7d23d5fd4feb255720d53d27f68286": "Publish Advisories\n\nGHSA-q7cg-43mg-qp69\nGHSA-cfqj-9g2g-w7q6\nGHSA-phwq-j96m-2c2q\nGHSA-mfhv-gwf8-4m88\nGHSA-hm53-hrhh-gwfq\nGHSA-8x94-hmjh-97hq"
264709-
},
264710264739
"GHSA-CFQJ-9G2G-W7Q6": {
264711264740
"3fa7f26a3e7d23d5fd4feb255720d53d27f68286": "Publish Advisories\n\nGHSA-q7cg-43mg-qp69\nGHSA-cfqj-9g2g-w7q6\nGHSA-phwq-j96m-2c2q\nGHSA-mfhv-gwf8-4m88\nGHSA-hm53-hrhh-gwfq\nGHSA-8x94-hmjh-97hq"
264712264741
},

data/fix-commits/buildroot-0b809119.json

Lines changed: 29 additions & 22 deletions
Large diffs are not rendered by default.

data/fix-commits/caddy-9ed25a7b.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/caddyserver/caddy",
33
"vulnerabilities": {
4+
"GHSA-F59H-Q822-G45G": {
5+
"947087cadd596c6e391e0df09e7e975afd2b4cbc": "Merge commit from fork\n\nCaddy's underscore header filter (GHSA-f59h-q822-g45g) only checked\nfor `_`. PHP folds `.` to `_` when registering $_SERVER keys the same\nway CGI/FastCGI folds `-` to `_`, so a dotted alias (e.g. Remote.User)\nsurvived the filter and collided with the legitimate hyphenated\nheader once it reached a PHP/FastCGI backend, bypassing forward_auth\ncopy_headers the same way the underscore alias did.\n\nExtends the filter to drop `.` symmetrically, adds an\n`expected_dot_headers` allowlist mirroring `expected_underscore_headers`,\nand handles header names containing both separators (only an exact\nallowlist entry is honored there, since a prefix glob's free-form\nsuffix can't be vetted for an embedded second separator).\n\nRoot cause identified by @iliaal in the FrankenPHP advisory\nGHSA-49wc-4hcv-v58q."
6+
},
7+
"GHSA-49WC-4HCV-V58Q": {
8+
"947087cadd596c6e391e0df09e7e975afd2b4cbc": "Merge commit from fork\n\nCaddy's underscore header filter (GHSA-f59h-q822-g45g) only checked\nfor `_`. PHP folds `.` to `_` when registering $_SERVER keys the same\nway CGI/FastCGI folds `-` to `_`, so a dotted alias (e.g. Remote.User)\nsurvived the filter and collided with the legitimate hyphenated\nheader once it reached a PHP/FastCGI backend, bypassing forward_auth\ncopy_headers the same way the underscore alias did.\n\nExtends the filter to drop `.` symmetrically, adds an\n`expected_dot_headers` allowlist mirroring `expected_underscore_headers`,\nand handles header names containing both separators (only an exact\nallowlist entry is honored there, since a prefix glob's free-form\nsuffix can't be vetted for an embedded second separator).\n\nRoot cause identified by @iliaal in the FrankenPHP advisory\nGHSA-49wc-4hcv-v58q."
9+
},
410
"GHSA-VCC4-2C75-VC9V": {
511
"e2eee6a7fce366321294c9c2a79f3146891dcbdf": "templates: Patch for GHSA-vcc4-2c75-vc9v (#7785)\n\n* Patch GHSA-vcc4-2c75-vc9v in stripHTML\n\ntemplates: fix funcStripHTML bypass via depth counter\r\n\r\nThe previous false-start approach allowed XSS bypass via inputs like <<>img src=x onerror=alert(1)> and failed on stacked angle brackets.\r\n\r\nReplace the tagStart/inTag state machine with a depth counter that mirrors PHP strip_tags behaviour: each '<' increments depth, each '>' decrements it, and text is only emitted at depth zero. Quoted attribute values (both single and double) are tracked so '>' inside href values does not prematurely close a tag.\n\nSigned-off-by: JM Sanchez <77505889+jmrcsnchz@users.noreply.github.com>\n\n* Update tplcontext_test.go\n\nTemplates: expand TestStripHTML with attack path coverage\n\nSigned-off-by: JM Sanchez <77505889+jmrcsnchz@users.noreply.github.com>\n\n---------\n\nSigned-off-by: JM Sanchez <77505889+jmrcsnchz@users.noreply.github.com>"
612
},

0 commit comments

Comments
 (0)