Skip to content

Commit ad37799

Browse files
Sync Collecting Fix Commits: Sun Aug 30 08:48:18 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent c80be1e commit ad37799

2 files changed

Lines changed: 32 additions & 0 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,36 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-6CV3-J4MC-JF2R": {
5+
"86a891354e54e56948849b7f16a55d166fb8d24c": "Publish Advisories\n\nGHSA-6cv3-j4mc-jf2r\nGHSA-6hcx-8gm4-gx5h\nGHSA-fq2p-334f-fcrf\nGHSA-h35r-6hg6-mcg3"
6+
},
7+
"GHSA-6HCX-8GM4-GX5H": {
8+
"86a891354e54e56948849b7f16a55d166fb8d24c": "Publish Advisories\n\nGHSA-6cv3-j4mc-jf2r\nGHSA-6hcx-8gm4-gx5h\nGHSA-fq2p-334f-fcrf\nGHSA-h35r-6hg6-mcg3"
9+
},
10+
"GHSA-FQ2P-334F-FCRF": {
11+
"86a891354e54e56948849b7f16a55d166fb8d24c": "Publish Advisories\n\nGHSA-6cv3-j4mc-jf2r\nGHSA-6hcx-8gm4-gx5h\nGHSA-fq2p-334f-fcrf\nGHSA-h35r-6hg6-mcg3"
12+
},
13+
"GHSA-H35R-6HG6-MCG3": {
14+
"86a891354e54e56948849b7f16a55d166fb8d24c": "Publish Advisories\n\nGHSA-6cv3-j4mc-jf2r\nGHSA-6hcx-8gm4-gx5h\nGHSA-fq2p-334f-fcrf\nGHSA-h35r-6hg6-mcg3"
15+
},
16+
"GHSA-699J-WCW4-P222": {
17+
"8b4d0f815ce277b9ea905743a58f75725d01876e": "Publish Advisories\n\nGHSA-699j-wcw4-p222\nGHSA-6r97-7v62-fg94\nGHSA-f3qf-7c7x-v322\nGHSA-fcmg-gfw5-mxq8\nGHSA-h63f-8gw3-5hc5\nGHSA-rjhq-q858-qc66"
18+
},
19+
"GHSA-6R97-7V62-FG94": {
20+
"8b4d0f815ce277b9ea905743a58f75725d01876e": "Publish Advisories\n\nGHSA-699j-wcw4-p222\nGHSA-6r97-7v62-fg94\nGHSA-f3qf-7c7x-v322\nGHSA-fcmg-gfw5-mxq8\nGHSA-h63f-8gw3-5hc5\nGHSA-rjhq-q858-qc66"
21+
},
22+
"GHSA-F3QF-7C7X-V322": {
23+
"8b4d0f815ce277b9ea905743a58f75725d01876e": "Publish Advisories\n\nGHSA-699j-wcw4-p222\nGHSA-6r97-7v62-fg94\nGHSA-f3qf-7c7x-v322\nGHSA-fcmg-gfw5-mxq8\nGHSA-h63f-8gw3-5hc5\nGHSA-rjhq-q858-qc66"
24+
},
25+
"GHSA-FCMG-GFW5-MXQ8": {
26+
"8b4d0f815ce277b9ea905743a58f75725d01876e": "Publish Advisories\n\nGHSA-699j-wcw4-p222\nGHSA-6r97-7v62-fg94\nGHSA-f3qf-7c7x-v322\nGHSA-fcmg-gfw5-mxq8\nGHSA-h63f-8gw3-5hc5\nGHSA-rjhq-q858-qc66"
27+
},
28+
"GHSA-H63F-8GW3-5HC5": {
29+
"8b4d0f815ce277b9ea905743a58f75725d01876e": "Publish Advisories\n\nGHSA-699j-wcw4-p222\nGHSA-6r97-7v62-fg94\nGHSA-f3qf-7c7x-v322\nGHSA-fcmg-gfw5-mxq8\nGHSA-h63f-8gw3-5hc5\nGHSA-rjhq-q858-qc66"
30+
},
31+
"GHSA-RJHQ-Q858-QC66": {
32+
"8b4d0f815ce277b9ea905743a58f75725d01876e": "Publish Advisories\n\nGHSA-699j-wcw4-p222\nGHSA-6r97-7v62-fg94\nGHSA-f3qf-7c7x-v322\nGHSA-fcmg-gfw5-mxq8\nGHSA-h63f-8gw3-5hc5\nGHSA-rjhq-q858-qc66"
33+
},
434
"GHSA-8FC6-VV8J-HX7J": {
535
"6b71cf85501995f7aefae7d2f41f6f43bc1b3c3d": "Publish Advisories\n\nGHSA-8fc6-vv8j-hx7j\nGHSA-gr3c-pxfm-8894"
636
},

data/fix-commits/lxd-0a821e82.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
"vcs_url": "https://github.com/lxc/lxd",
33
"vulnerabilities": {
44
"CVE-2026-81500": {
5+
"8723e980417255462f5123b2aff30973673b2076": "client/images: Prevent path traversal in downloaded image name\n\nThe local filename for an exported image came from server-controlled\ndata (Content-Disposition for unified images, the simplestreams index\npath) and was joined with the target directory. Basename it.\n\nThis addresses CVE-2026-81500\n\nSigned-off-by: St\u00e9phane Graber <stgraber@stgraber.org>",
56
"9e188e31e43c21fa8f2a4cac265aa246d4c947f2": "client/images: Prevent path traversal in downloaded image name\n\nThe local filename for an exported image came from server-controlled\ndata (Content-Disposition for unified images, the simplestreams index\npath) and was joined with the target directory. Basename it.\n\nThis addresses CVE-2026-81500\n\nSigned-off-by: St\u00e9phane Graber <stgraber@stgraber.org>"
67
},
78
"CVE-2026-81501": {
9+
"2521bf480af23765ea25754fd9a0a2ca146945c6": "incusd/images: Check access before reusing cross-project image\n\nimageDownload reused an image from another project without checking the\ncaller could view it, letting a client that knew a private fingerprint\nimport it. Only reuse it directly when public or viewable, otherwise\ndownload it (proving access) and dedupe against the on-disk copy.\n\nThis addresses CVE-2026-81501\n\nSigned-off-by: St\u00e9phane Graber <stgraber@stgraber.org>",
810
"83682ab16af5777b2a5650bb7c9878d57d0187f9": "incusd/images: Check access before reusing cross-project image\n\nimageDownload reused an image from another project without checking the\ncaller could view it, letting a client that knew a private fingerprint\nimport it. Only reuse it directly when public or viewable, otherwise\ndownload it (proving access) and dedupe against the on-disk copy.\n\nThis addresses CVE-2026-81501\n\nSigned-off-by: St\u00e9phane Graber <stgraber@stgraber.org>"
911
},
1012
"GHSA-6V6X-387M-RJ4W": {

0 commit comments

Comments
 (0)