Skip to content

fix(cve): CVE-2026-10805 - libnm-sd-shared: reject urls containing unexpected characters - #27

Open
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix-cve/CVE-2026-10805
Open

fix(cve): CVE-2026-10805 - libnm-sd-shared: reject urls containing unexpected characters#27
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix-cve/CVE-2026-10805

Conversation

@deepin-ci-robot

Copy link
Copy Markdown
Contributor

CVE: CVE-2026-10805 (medium) - URL 验证缺陷:_http_url_is_valid() 仅拒绝非 ASCII 字节,但接受了控制字符、双引号和反斜杠,可能导致注入攻击
Upstream: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/commit/5326760073c06157652b7e0d0865ada2eb0e393b

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b

…expected characters

CVE: CVE-2026-10805 (medium) - URL 验证缺陷:_http_url_is_valid() 仅拒绝非 ASCII 字节,但接受了控制字符、双引号和反斜杠,可能导致注入攻击
Upstream: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/commit/5326760073c06157652b7e0d0865ada2eb0e393b

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@deepin-ci-robot deepin-ci-robot added cve CVE security fix generated-by-ai Generated by AI agent labels Jul 24, 2026
@deepin-ci-robot
deepin-ci-robot requested a review from BLumia July 24, 2026 05:07
@github-actions

Copy link
Copy Markdown

TAG Bot

TAG: 1.44.2-7deepin11
EXISTED: no
DISTRIBUTION: unstable

@deepin-ci-robot
deepin-ci-robot requested a review from myml July 24, 2026 05:07
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign goldendeng for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

/integrate

@github-actions

Copy link
Copy Markdown

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#4410
PrNumber: 4410
PrBranch: auto-integration-30256412821

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cve CVE security fix generated-by-ai Generated by AI agent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant