Skip to content

Commit 918e965

Browse files
Sync Collecting Fix Commits: Mon Aug 3 01:26:28 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 32c9a4a commit 918e965

2 files changed

Lines changed: 60 additions & 16 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,17 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-QGCM-97X5-6Q8Q": {
5+
"9fef5da16101bb05700aa946748b4b746c339cb6": "Publish Advisories\n\nGHSA-qgcm-97x5-6q8q\nGHSA-v9mp-gj7h-85r3"
6+
},
7+
"GHSA-V9MP-GJ7H-85R3": {
8+
"9fef5da16101bb05700aa946748b4b746c339cb6": "Publish Advisories\n\nGHSA-qgcm-97x5-6q8q\nGHSA-v9mp-gj7h-85r3"
9+
},
10+
"GHSA-2FPX-XRC2-7QF3": {
11+
"c34866078ee9e9cccc13bc2b66d2998b42d7f4aa": "Improve GHSA-2fpx-xrc2-7qf3",
12+
"4e41c260e5602bc8d6cccfd8f0270b04788ef933": "Improve GHSA-2fpx-xrc2-7qf3",
13+
"8dc3f167441ae2f2fd591d239b08d45db0ca1ec1": "Publish Advisories\n\nGHSA-2fpx-xrc2-7qf3\nGHSA-3432-4g4q-g82w\nGHSA-4x8w-4g3r-gvr2\nGHSA-8q6m-q7p9-67pr\nGHSA-96cg-9pq4-jf4v\nGHSA-fpw6-p57h-mv5q\nGHSA-rgqr-jrx3-5xwx\nGHSA-whhc-4mg3-jgh7\nGHSA-xhx8-v4wm-937m"
14+
},
415
"GHSA-XRQW-3RRV-VX5W": {
516
"3086d196de1869e24affb64be13cc2137b1b0a4a": "Publish GHSA-xrqw-3rrv-vx5w"
617
},
@@ -34200,9 +34211,6 @@
3420034211
"GHSA-MF8F-5HFR-3CFM": {
3420134212
"639f0f1552323c66ee03752c877b13177a03ddd9": "Publish Advisories\n\nGHSA-34xc-8mm8-rq79\nGHSA-4p8f-q5hf-m6pr\nGHSA-4ph3-v6j7-j4pw\nGHSA-5xr7-9jmx-g4x4\nGHSA-7v8w-cr25-ggqq\nGHSA-h4xv-q4qh-g7q3\nGHSA-hmqj-h9pm-wq53\nGHSA-mf8f-5hfr-3cfm"
3420234213
},
34203-
"GHSA-2FPX-XRC2-7QF3": {
34204-
"8dc3f167441ae2f2fd591d239b08d45db0ca1ec1": "Publish Advisories\n\nGHSA-2fpx-xrc2-7qf3\nGHSA-3432-4g4q-g82w\nGHSA-4x8w-4g3r-gvr2\nGHSA-8q6m-q7p9-67pr\nGHSA-96cg-9pq4-jf4v\nGHSA-fpw6-p57h-mv5q\nGHSA-rgqr-jrx3-5xwx\nGHSA-whhc-4mg3-jgh7\nGHSA-xhx8-v4wm-937m"
34205-
},
3420634214
"GHSA-3432-4G4Q-G82W": {
3420734215
"8dc3f167441ae2f2fd591d239b08d45db0ca1ec1": "Publish Advisories\n\nGHSA-2fpx-xrc2-7qf3\nGHSA-3432-4g4q-g82w\nGHSA-4x8w-4g3r-gvr2\nGHSA-8q6m-q7p9-67pr\nGHSA-96cg-9pq4-jf4v\nGHSA-fpw6-p57h-mv5q\nGHSA-rgqr-jrx3-5xwx\nGHSA-whhc-4mg3-jgh7\nGHSA-xhx8-v4wm-937m"
3420834216
},

data/fix-commits/nixpkgs-97436190.json

Lines changed: 49 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,45 @@
11
{
22
"vcs_url": "https://github.com/nixos/nixpkgs",
33
"vulnerabilities": {
4+
"CVE-2026-5160": {
5+
"ffaf4a61127477ba92c7d83e9194710b1a93dfe4": "goshs: fix CVE-2026-5160\n\nUpdate goldmark to 1.7.17, the first patched version.\n\nhttps://pkg.go.dev/vuln/GO-2026-5320\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
6+
},
7+
"CVE-2026-32853": {
8+
"fc61be98dd8db5dcf0092364f9bdd70b501338c2": "[Backport release-26.05] libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#548487)",
9+
"4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)",
10+
"6e1c1648c76c042338d14316edee68cf38ff8c9e": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#545890)",
11+
"2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
12+
},
13+
"CVE-2026-32854": {
14+
"fc61be98dd8db5dcf0092364f9bdd70b501338c2": "[Backport release-26.05] libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#548487)",
15+
"4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)",
16+
"6e1c1648c76c042338d14316edee68cf38ff8c9e": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes (#545890)",
17+
"2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
18+
},
419
"CVE-2026-60074": {
20+
"efeafb47364537971d3d00dec9da5c1bff1b1a52": "[Backport release-26.05] perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548464)",
521
"e63e3c448f10ebac24ed508e7878d5b10e4aa9f1": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 7e09d3726c5850ddb11930780212eb14776e704e)",
622
"6d23509948f9e8cb740f2b018bb9d2ed262f732b": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548409)",
723
"7e09d3726c5850ddb11930780212eb14776e704e": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
824
},
925
"CVE-2026-60075": {
26+
"efeafb47364537971d3d00dec9da5c1bff1b1a52": "[Backport release-26.05] perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548464)",
1027
"e63e3c448f10ebac24ed508e7878d5b10e4aa9f1": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 7e09d3726c5850ddb11930780212eb14776e704e)",
1128
"6d23509948f9e8cb740f2b018bb9d2ed262f732b": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 (#548409)",
1229
"7e09d3726c5850ddb11930780212eb14776e704e": "perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075\n\nApply CPAN Security's complete fixes for rejecting non-ASCII numeric\ndate fields and bounding parser input before expensive regular\nexpressions run.\n\nMove the existing date fallback substitution to postPatch so the\nstandard patch phase applies the security patches first.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
1330
},
31+
"CVE-2026-1466": {
32+
"d6fb3e88631c45422b4c5627262241857906cc4a": "jirafeau: 4.4.0 -> 4.7.2\n\nhttps://gitlab.com/jirafeau/Jirafeau/-/blob/4.7.2/CHANGELOG.md\n\nUpdate to the continued official project namespace. This release contains the fix for CVE-2026-1466; extend the NixOS test with the vulnerable preview contract.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 44bfa48ab50ed97c09e4f674dcc755075c573a3f)",
33+
"44bfa48ab50ed97c09e4f674dcc755075c573a3f": "jirafeau: 4.4.0 -> 4.7.2\n\nhttps://gitlab.com/jirafeau/Jirafeau/-/blob/4.7.2/CHANGELOG.md\n\nUpdate to the continued official project namespace. This release contains the fix for CVE-2026-1466; extend the NixOS test with the vulnerable preview contract.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
34+
},
35+
"GHSA-87Q7-V983-QWCJ": {
36+
"4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)",
37+
"2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
38+
},
39+
"GHSA-XJP8-4QQV-5X4X": {
40+
"4cf468acf47540b7b9848031da17e3f613c50a35": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d)",
41+
"2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d": "libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes\n\nBackport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests.\n\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj\nhttps://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"
42+
},
1443
"CVE-2026-54387": {
1544
"24d8bf6dbc2092d18a27272bc63eefefcb41b496": "[Backport release-26.05] tinyproxy: fix CVE-2026-54387, CVE-2026-54388 and CVE-2026-55202 (#548448)",
1645
"dbd6ccb0175da77556187fadcf2d8354a4d50300": "tinyproxy: fix CVE-2026-54387, CVE-2026-54388 and CVE-2026-55202\n\nApply upstream fixes for ambiguous HTTP request framing and inconsistent stathost authentication and routing. No upstream release containing these fixes is available.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\n(cherry picked from commit 4d53f69eb7681739a0811914d7f47addd6fac7ff)",
@@ -33,6 +62,26 @@
3362
"939d0f3039a001dd0d21e3574c38a78f93ee1032": "kanidm_1_10: 1.10.4 -> 1.10.5\n\nhttps://github.com/kanidm/kanidm/releases/tag/v1.10.5\nhttps://github.com/kanidm/kanidm/security/advisories/GHSA-2pm5-6m23-h692\n\nFixes: GHSA-2pm5-6m23-h692\n(cherry picked from commit 1bb58b274f3d0067bb462b1fb42e8c844f0b4712)",
3463
"1bb58b274f3d0067bb462b1fb42e8c844f0b4712": "kanidm_1_10: 1.10.4 -> 1.10.5\n\nhttps://github.com/kanidm/kanidm/releases/tag/v1.10.5\nhttps://github.com/kanidm/kanidm/security/advisories/GHSA-2pm5-6m23-h692\n\nFixes: GHSA-2pm5-6m23-h692"
3564
},
65+
"CVE-2026-59882": {
66+
"fb6d49e15e3ce6d36f4f7a942ef5a6a53dca6b44": "freescout: 1.8.230 -> 1.8.232\n\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.231\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.232\n\nFixes: CVE-2026-59882, CVE-2026-45294, CVE-2026-45294"
67+
},
68+
"CVE-2026-45294": {
69+
"fb6d49e15e3ce6d36f4f7a942ef5a6a53dca6b44": "freescout: 1.8.230 -> 1.8.232\n\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.231\nhttps://github.com/freescout-help-desk/freescout/releases/tag/1.8.232\n\nFixes: CVE-2026-59882, CVE-2026-45294, CVE-2026-45294"
70+
},
71+
"CVE-2026-66066": {
72+
"b17bb7d10488acdd296d3871816e759d88d54104": "[release-26.05] redmine: Update rails to 7.2.3.2\n\nFixes CVE-2026-66066.\n\nSigned-off-by: Felix Singer <felixsinger@posteo.net>\nNot-cherry-picked-because: master branch has different major version",
73+
"6f074996277234fff040ef1c10173d16f4cff8a8": "redmine: Update rails to 8.1.3.1\n\nFixes CVE-2026-66066.\n\nSigned-off-by: Felix Singer <felixsinger@posteo.net>",
74+
"0cf1b4f2c3ebd28764715903b078119e2ab4bc1c": "[26.05] dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066 (#547197)",
75+
"c4c92c3a936ea635d841d8ba3d4c3a9910819da9": "dawarich: 1.10.1 -> 1.10.3; fix CVE-2026-66066 (#546764)",
76+
"000b011aed1091cb8ac05de5d929125f0ac09ae0": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066 (#547318)",
77+
"4e1ce3ad1f32ef7b37323f882de01e6d4f22fcbf": "[Backport release-26.05] mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547370)",
78+
"542613d084c6ec5dd159dc7dc8147760274309d9": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem\n\n(cherry picked from commit 54c08d3c5b637ab3b342af0012e3473cc97aae6e)",
79+
"8af8a1099c25904664679efc4a70e1b6ba7691cc": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547199)",
80+
"54c08d3c5b637ab3b342af0012e3473cc97aae6e": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem",
81+
"14e9d479e60563b19205a3700be27228f46c0655": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066",
82+
"d995cbf84eece5ddcb5a5350b88d083418d0b83e": "dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066\n\nNot-cherry-picked-because: dawarich on stable is outdated and needs a\ndifferent patch",
83+
"3f8c8fd95629d1d6b97088680e30776e3615628e": "dawarich: bump rails to 8.1.3.1 to fix CVE-2026-66066"
84+
},
3685
"CVE-2026-54527": {
3786
"9f6090dc2fba89c3f762370bb8d43ee63c6eca66": "[26.05] python3Packages.jupyterlab-git: fix CVE-2026-54527 and CVE-2026-54528 (#547982)",
3887
"2b739debfe4694326fbe790e55ae071530f8243c": "python3Packages.jupyterlab-git: fix CVE-2026-54527 and CVE-2026-54528\n\nBackport the upstream fixes to 0.52.0. The master fix updates to\n0.54.0, whose multi-package workspace is not present on release-26.05.\n\nhttps://redirect.github.com/NixOS/nixpkgs/pull/547220\nhttps://redirect.github.com/jupyterlab/jupyterlab-git/commit/c6d37b88f36aa59aee317930b95e427fb9d6b09b\nhttps://redirect.github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60ba6a73717fbd033\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)",
@@ -87,19 +136,6 @@
87136
"ab3328fca0bad0c6ab56df9df4ec0eafd2e062cc": "libssh2: patch CVE-2026-58050 and CVE-2026-58051 (#543937)",
88137
"572bf8abb5d7a93705ecdf2834f0bd7d675c7e95": "libssh2: patch CVE-2026-58050 and CVE-2026-58051\n\npatch source: https://github.com/libssh2/libssh2/issues/1925#issuecomment-4938515829\n\nFixes: CVE-2026-58050, CVE-2026-58051"
89138
},
90-
"CVE-2026-66066": {
91-
"6f074996277234fff040ef1c10173d16f4cff8a8": "redmine: Update rails to 8.1.3.1\n\nFixes CVE-2026-66066.\n\nSigned-off-by: Felix Singer <felixsinger@posteo.net>",
92-
"0cf1b4f2c3ebd28764715903b078119e2ab4bc1c": "[26.05] dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066 (#547197)",
93-
"c4c92c3a936ea635d841d8ba3d4c3a9910819da9": "dawarich: 1.10.1 -> 1.10.3; fix CVE-2026-66066 (#546764)",
94-
"000b011aed1091cb8ac05de5d929125f0ac09ae0": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066 (#547318)",
95-
"4e1ce3ad1f32ef7b37323f882de01e6d4f22fcbf": "[Backport release-26.05] mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547370)",
96-
"542613d084c6ec5dd159dc7dc8147760274309d9": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem\n\n(cherry picked from commit 54c08d3c5b637ab3b342af0012e3473cc97aae6e)",
97-
"8af8a1099c25904664679efc4a70e1b6ba7691cc": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem (#547199)",
98-
"54c08d3c5b637ab3b342af0012e3473cc97aae6e": "mastodon: patch CVE-2026-66066/GHSA-xr9x-r78c-5hrm in activesupport gem",
99-
"14e9d479e60563b19205a3700be27228f46c0655": "sure: 0.7.1 -> 0.7.2 && patch CVE-2026-66066",
100-
"d995cbf84eece5ddcb5a5350b88d083418d0b83e": "dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066\n\nNot-cherry-picked-because: dawarich on stable is outdated and needs a\ndifferent patch",
101-
"3f8c8fd95629d1d6b97088680e30776e3615628e": "dawarich: bump rails to 8.1.3.1 to fix CVE-2026-66066"
102-
},
103139
"CVE-2026-66063": {
104140
"6e046a96da8cdd8e784a50f553d7f8357f3e3a47": "goshs: fix CVE-2026-66063 and CVE-2026-66064 (#547661)",
105141
"e55b1ddf6b4b685949a6fc83fa08823ef28523c9": "goshs: fix CVE-2026-66063 and CVE-2026-66064\n\nBackport the upstream fixes for authorization bypasses caused by trailing slashes and multipart upload path traversal.\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)"

0 commit comments

Comments
 (0)