Skip to content

security: ignore CVE-2026-6100 in Grype (Python decompressor UAF)#1461

Merged
apyrgio merged 1 commit intofreedomofpress:mainfrom
herbenderbler:add-cve-check
Apr 15, 2026
Merged

security: ignore CVE-2026-6100 in Grype (Python decompressor UAF)#1461
apyrgio merged 1 commit intofreedomofpress:mainfrom
herbenderbler:add-cve-check

Conversation

@herbenderbler
Copy link
Copy Markdown
Contributor

Document CVE-2026-6100 / GHSA-pg25-7cx5-cvcm with Debian tracker and advisory links; align Grype scans with rationale that Dangerzone does not reuse lzma/bz2/gzip decompressors after MemoryError.

This fix originated in #1460 (comment)

Document CVE-2026-6100 / GHSA-pg25-7cx5-cvcm with Debian tracker and
advisory links; align Grype scans with rationale that Dangerzone does
not reuse lzma/bz2/gzip decompressors after MemoryError.
@apyrgio apyrgio merged commit 76b2d1d into freedomofpress:main Apr 15, 2026
@herbenderbler herbenderbler deleted the add-cve-check branch April 15, 2026 12:46
@apyrgio
Copy link
Copy Markdown
Contributor

apyrgio commented Apr 15, 2026

Thanks again!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants