{"schema_version":1,"title":"Debian vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 58 vulnerabilities in Debian: 0 in the last 7 days and 1 in the last 90 days, 19 of them critical and 12 exploited in the wild. The most recent, CVE-2026-89169, was published on 11 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/debian","json_url":"https://junglewise.ai/threats/vendors/debian.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/debian","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":20,"all_time":58,"critical":19,"exploited":12,"last_7_days":0,"last_30_days":1,"last_90_days":1,"last_365_days":14},"latest":[{"cve":"CVE-2026-89169","cvss":6.2,"epss":0.0015,"slug":"cve-2026-89169-debian-live-boot-dm-verity-bypass-when-verity-file-missing","title":"Debian live-boot dm-verity bypass when .verity file missing","severity":"info","exploited":false,"published_at":"2026-09-11T05:16:38.84+00:00","url":"https://junglewise.ai/threats/cve-2026-89169-debian-live-boot-dm-verity-bypass-when-verity-file-missing"},{"cve":"CVE-2026-11853","cvss":0,"slug":"cve-2026-11853-debian-debusine-path-traversal-in-manifest-parser","title":"Debian Debusine path traversal in manifest parser","severity":"info","exploited":false,"published_at":"2026-06-10T10:16:31.467+00:00","url":"https://junglewise.ai/threats/cve-2026-11853-debian-debusine-path-traversal-in-manifest-parser"},{"cve":"CVE-2026-11852","cvss":5.3,"slug":"cve-2026-11852-debian-debusine-broken-access-control-in-artifact-relations","title":"Debian Debusine broken access control in artifact relations","severity":"info","exploited":false,"published_at":"2026-06-10T10:16:31.35+00:00","url":"https://junglewise.ai/threats/cve-2026-11852-debian-debusine-broken-access-control-in-artifact-relations"},{"cve":"CVE-2026-34757","cvss":5.1,"slug":"cve-2026-34757-libpng-use-after-free-in-chunk-setter-functions","title":"libpng use-after-free in chunk setter functions","severity":"medium","exploited":false,"published_at":"2026-04-09T15:16:11.003+00:00","url":"https://junglewise.ai/threats/cve-2026-34757-libpng-use-after-free-in-chunk-setter-functions"},{"cve":"CVE-2026-4948","cvss":5.5,"epss":0.0002,"slug":"cve-2026-4948-firewalld-incorrect-authorization-in-d-bus-setters","title":"firewalld incorrect authorization in D-Bus setters","severity":"medium","exploited":false,"published_at":"2026-03-27T06:16:39.543+00:00","url":"https://junglewise.ai/threats/cve-2026-4948-firewalld-incorrect-authorization-in-d-bus-setters"},{"cve":"CVE-2026-4775","cvss":7.8,"epss":0.0005,"slug":"cve-2026-4775-libtiff-signed-integer-overflow-in-putcontig8bitycbcr44tile","title":"libtiff signed integer overflow in putcontig8bitYCbCr44tile","severity":"high","exploited":false,"published_at":"2026-03-24T15:16:39.693+00:00","url":"https://junglewise.ai/threats/cve-2026-4775-libtiff-signed-integer-overflow-in-putcontig8bitycbcr44tile"},{"cve":"CVE-2006-10003","cvss":9.8,"epss":0.0051,"slug":"cve-2006-10003-cpan-xml-parser-heap-buffer-overflow-in-st-serial-stack","title":"CPAN XML::Parser heap buffer overflow in st_serial_stack","severity":"critical","exploited":false,"published_at":"2026-03-19T12:16:17.047+00:00","url":"https://junglewise.ai/threats/cve-2006-10003-cpan-xml-parser-heap-buffer-overflow-in-st-serial-stack"},{"cve":"CVE-2026-2921","cvss":7.8,"epss":0.0084,"slug":"cve-2026-2921-gstreamer-riff-palette-integer-overflow-in-avi-handling","title":"GStreamer RIFF palette integer overflow in AVI handling","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:32.73+00:00","url":"https://junglewise.ai/threats/cve-2026-2921-gstreamer-riff-palette-integer-overflow-in-avi-handling"},{"cve":"CVE-2026-3497","cvss":7.5,"epss":0.0005,"slug":"cve-2026-3497-openssh-gssapi-uninitialized-variable-use-in-linux-distributions","title":"OpenSSH GSSAPI uninitialized variable use in Linux distributions","severity":"high","exploited":false,"published_at":"2026-03-12T19:16:19.91+00:00","url":"https://junglewise.ai/threats/cve-2026-3497-openssh-gssapi-uninitialized-variable-use-in-linux-distributions"},{"cve":"CVE-2026-2219","cvss":7.5,"epss":0.0002,"slug":"cve-2026-2219-debian-dpkg-infinite-loop-in-zstd-decompression","title":"Debian dpkg infinite loop in zstd decompression","severity":"high","exploited":false,"published_at":"2026-03-07T09:16:07.823+00:00","url":"https://junglewise.ai/threats/cve-2026-2219-debian-dpkg-infinite-loop-in-zstd-decompression"},{"cve":"CVE-2026-25506","cvss":7.7,"epss":0.0027,"slug":"cve-2026-25506-munge-buffer-overflow-in-munged-message-unpacking","title":"MUNGE buffer overflow in munged message unpacking","severity":"high","exploited":false,"published_at":"2026-02-10T19:16:03.72+00:00","url":"https://junglewise.ai/threats/cve-2026-25506-munge-buffer-overflow-in-munged-message-unpacking"},{"cve":"CVE-2026-23490","cvss":7.5,"epss":0.0077,"slug":"cve-2026-23490-pyasn1-memory-exhaustion-dos-in-oid-decoder","title":"pyasn1 memory exhaustion DoS in OID decoder","severity":"high","exploited":false,"published_at":"2026-01-16T19:16:19.117+00:00","url":"https://junglewise.ai/threats/cve-2026-23490-pyasn1-memory-exhaustion-dos-in-oid-decoder"},{"cve":"CVE-2025-53066","cvss":7.5,"slug":"cve-2025-53066-oracle-java-se-and-graalvm-information-exposure-in-jaxp","title":"Oracle Java SE and GraalVM Information Exposure in JAXP","severity":"high","exploited":false,"published_at":"2025-10-21T20:20:47.177+00:00","url":"https://junglewise.ai/threats/cve-2025-53066-oracle-java-se-and-graalvm-information-exposure-in-jaxp"},{"cve":"CVE-2025-53057","cvss":5.9,"slug":"cve-2025-53057-oracle-java-se-and-graalvm-improper-access-control-in-security","title":"Oracle Java SE and GraalVM improper access control in Security component","severity":"medium","exploited":false,"published_at":"2025-10-21T20:20:45.24+00:00","url":"https://junglewise.ai/threats/cve-2025-53057-oracle-java-se-and-graalvm-improper-access-control-in-security"},{"cve":"CVE-2025-9086","cvss":7.5,"epss":0.001,"slug":"cve-2025-9086-curl-out-of-bounds-read-in-cookie-path-comparison","title":"curl out-of-bounds read in cookie path comparison","severity":"high","exploited":false,"published_at":"2025-09-12T06:15:44.1+00:00","url":"https://junglewise.ai/threats/cve-2025-9086-curl-out-of-bounds-read-in-cookie-path-comparison"},{"cve":"CVE-2025-6020","cvss":7.8,"slug":"cve-2025-6020-linux-pam-privilege-escalation-in-pam-namespace-module","title":"Linux-PAM privilege escalation in pam_namespace module","severity":"high","exploited":false,"published_at":"2025-06-17T13:15:21.66+00:00","url":"https://junglewise.ai/threats/cve-2025-6020-linux-pam-privilege-escalation-in-pam-namespace-module"},{"cve":"CVE-2023-0386","cvss":7.8,"epss":0.5424,"slug":"cve-2023-0386-linux-kernel-privilege-escalation-in-overlayfs","title":"Linux Kernel privilege escalation in OverlayFS","severity":"critical","exploited":true,"published_at":"2025-06-17T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0386-linux-kernel-privilege-escalation-in-overlayfs"},{"cve":"CVE-2025-4598","cvss":4.7,"epss":0.0011,"slug":"cve-2025-4598-systemd-systemd-coredump-race-condition-in-suid-crash-handling","title":"systemd systemd-coredump race condition in SUID crash handling","severity":"medium","exploited":false,"published_at":"2025-05-30T14:15:23.557+00:00","url":"https://junglewise.ai/threats/cve-2025-4598-systemd-systemd-coredump-race-condition-in-suid-crash-handling"},{"cve":"CVE-2025-3576","cvss":5.9,"slug":"cve-2025-3576-mit-kerberos-message-spoofing-via-rc4-hmac-md5-md5-collisions","title":"MIT Kerberos message spoofing via RC4-HMAC-MD5 MD5 collisions","severity":"medium","exploited":false,"published_at":"2025-04-15T06:15:44.047+00:00","url":"https://junglewise.ai/threats/cve-2025-3576-mit-kerberos-message-spoofing-via-rc4-hmac-md5-md5-collisions"},{"cve":"CVE-2024-53197","cvss":7.8,"slug":"cve-2024-53197-linux-kernel-out-of-bounds-access-vulnerability","title":"Linux Kernel Out-of-Bounds Access Vulnerability","severity":"critical","exploited":true,"published_at":"2025-04-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-53197-linux-kernel-out-of-bounds-access-vulnerability"},{"cve":"CVE-2024-53150","cvss":7.1,"slug":"cve-2024-53150-linux-kernel-out-of-bounds-read-vulnerability","title":"Linux Kernel Out-of-Bounds Read Vulnerability","severity":"critical","exploited":true,"published_at":"2025-04-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-53150-linux-kernel-out-of-bounds-read-vulnerability"},{"cve":"CVE-2025-26465","cvss":6.8,"slug":"cve-2025-26465-openbsd-openssh-mitm-via-verifyhostkeydns-error-mishandling","title":"OpenBSD OpenSSH MitM via VerifyHostKeyDNS error mishandling","severity":"medium","exploited":false,"published_at":"2025-02-18T19:15:29.23+00:00","url":"https://junglewise.ai/threats/cve-2025-26465-openbsd-openssh-mitm-via-verifyhostkeydns-error-mishandling"},{"cve":"CVE-2024-12133","cvss":5.3,"slug":"cve-2024-12133-gnu-libtasn1-denial-of-service-via-inefficient-der-decoding","title":"GNU libtasn1 denial of service via inefficient DER decoding","severity":"medium","exploited":false,"published_at":"2025-02-10T16:15:37.26+00:00","url":"https://junglewise.ai/threats/cve-2024-12133-gnu-libtasn1-denial-of-service-via-inefficient-der-decoding"},{"cve":"CVE-2024-53104","cvss":7.8,"slug":"cve-2024-53104-linux-kernel-out-of-bounds-write-vulnerability","title":"Linux Kernel Out-of-Bounds Write Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-53104-linux-kernel-out-of-bounds-write-vulnerability"},{"cve":"CVE-2024-37383","cvss":6.1,"slug":"cve-2024-37383-roundcube-webmail-cross-site-scripting-xss-vulnerability","title":"RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability","severity":"critical","exploited":true,"published_at":"2024-10-24T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-37383-roundcube-webmail-cross-site-scripting-xss-vulnerability"}],"vendor":{"hub":true,"name":"Debian","slug":"debian","homepage":"https://www.debian.org/","description":"A community-driven project that develops and maintains the Debian GNU/Linux operating system.","url":"https://junglewise.ai/threats/vendors/debian"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2018-6789","cvss":9.8,"slug":"cve-2018-6789-exim-buffer-overflow-vulnerability","title":"Exim Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2018-6789-exim-buffer-overflow-vulnerability"},{"cve":"CVE-2023-0266","cvss":7.9,"slug":"cve-2023-0266-linux-kernel-use-after-free-vulnerability","title":"Linux Kernel Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2023-03-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0266-linux-kernel-use-after-free-vulnerability"},{"cve":"CVE-2023-0386","cvss":7.8,"epss":0.5424,"slug":"cve-2023-0386-linux-kernel-privilege-escalation-in-overlayfs","title":"Linux Kernel privilege escalation in OverlayFS","severity":"critical","exploited":true,"published_at":"2025-06-17T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0386-linux-kernel-privilege-escalation-in-overlayfs"},{"cve":"CVE-2024-53197","cvss":7.8,"slug":"cve-2024-53197-linux-kernel-out-of-bounds-access-vulnerability","title":"Linux Kernel Out-of-Bounds Access Vulnerability","severity":"critical","exploited":true,"published_at":"2025-04-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-53197-linux-kernel-out-of-bounds-access-vulnerability"},{"cve":"CVE-2024-53104","cvss":7.8,"slug":"cve-2024-53104-linux-kernel-out-of-bounds-write-vulnerability","title":"Linux Kernel Out-of-Bounds Write Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-53104-linux-kernel-out-of-bounds-write-vulnerability"},{"cve":"CVE-2024-36971","cvss":7.8,"slug":"cve-2024-36971-android-kernel-remote-code-execution-vulnerability","title":"Android Kernel Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-36971-android-kernel-remote-code-execution-vulnerability"},{"cve":"CVE-2023-4911","cvss":7.8,"slug":"cve-2023-4911-gnu-c-library-buffer-overflow-vulnerability","title":"GNU C Library Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-10-03T18:15:10.463+00:00","url":"https://junglewise.ai/threats/cve-2023-4911-gnu-c-library-buffer-overflow-vulnerability"},{"cve":"CVE-2021-3560","cvss":7.8,"slug":"cve-2021-3560-red-hat-polkit-incorrect-authorization-vulnerability","title":"Red Hat Polkit Incorrect Authorization Vulnerability","severity":"critical","exploited":true,"published_at":"2023-05-12T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3560-red-hat-polkit-incorrect-authorization-vulnerability"},{"cve":"CVE-2019-2215","cvss":7.8,"slug":"cve-2019-2215-android-kernel-use-after-free-vulnerability","title":"Android Kernel Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-2215-android-kernel-use-after-free-vulnerability"},{"cve":"CVE-2024-53150","cvss":7.1,"slug":"cve-2024-53150-linux-kernel-out-of-bounds-read-vulnerability","title":"Linux Kernel Out-of-Bounds Read Vulnerability","severity":"critical","exploited":true,"published_at":"2025-04-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-53150-linux-kernel-out-of-bounds-read-vulnerability"}],"generated_at":"2026-09-26T10:07:00.179841+00:00","technologies":[{"name":"Debian GNU/Linux","slug":"debian","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/debian"}]}