git: 5446292c8d46 - main - security/vuxml: Document two vulnerabilities in immich
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 11 Sep 2026 13:03:05 UTC
The branch main has been updated by joneum:
URL: https://cgit.FreeBSD.org/ports/commit/?id=5446292c8d46dd5dbed1745114d80ce52f3f46c7
commit 5446292c8d46dd5dbed1745114d80ce52f3f46c7
Author: Jochen Neumeister <joneum@FreeBSD.org>
AuthorDate: 2026-09-11 08:55:41 +0000
Commit: Jochen Neumeister <joneum@FreeBSD.org>
CommitDate: 2026-09-11 13:02:49 +0000
security/vuxml: Document two vulnerabilities in immich
Sponsored by: Netzkommune GmbH
---
security/vuxml/vuln/2026.xml | 64 ++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 64 insertions(+)
diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index bb8982eb5958..2a3098f40859 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,67 @@
+ <vuln vid="fcc6917b-adbc-11f1-a655-3497f65b111b">
+ <topic>immich -- locked assets remain accessible through shared albums and links</topic>
+ <affects>
+ <package>
+ <name>immich</name>
+ <range><le>3.2.0</le></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>NVD reports:</p>
+ <blockquote cite="https://nvd.nist.gov/vuln/detail/CVE-2026-82272">
+ <p>Immich through 3.1.0 fails to properly enforce locked asset
+ visibility when assets are locked through the single-asset
+ endpoint, allowing them to remain accessible through shared
+ albums and links.</p>
+ </blockquote>
+ <p>The single-asset code path still lacks the album removal that the
+ bulk path performs, so 3.2.0 is affected as well. Upstream has not
+ released a fix yet.</p>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2026-82272</cvename>
+ <url>https://nvd.nist.gov/vuln/detail/CVE-2026-82272</url>
+ <url>https://github.com/immich-app/immich/issues/29526</url>
+ </references>
+ <dates>
+ <discovery>2026-08-28</discovery>
+ <entry>2026-09-11</entry>
+ </dates>
+ </vuln>
+
+ <vuln vid="fcc6baaa-adbc-11f1-a655-3497f65b111b">
+ <topic>immich -- open redirect and reflected XSS in maintenance endpoint</topic>
+ <affects>
+ <package>
+ <name>immich</name>
+ <range><lt>3.2.0</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>The immich project reports:</p>
+ <blockquote cite="https://github.com/immich-app/immich/security/advisories/GHSA-h5w4-vjv4-9r5q">
+ <p>The /maintenance endpoint fails to validate the continue URL
+ parameter. When maintenance mode is disabled, which is the
+ default, the application accepts unvalidated redirect targets,
+ enabling both open redirects and reflected cross-site scripting.
+ An unauthenticated user can craft a malicious link leading to
+ account takeover, including administrative accounts, through
+ same-origin API requests with credentials.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>https://github.com/immich-app/immich/security/advisories/GHSA-h5w4-vjv4-9r5q</url>
+ </references>
+ <dates>
+ <discovery>2026-08-23</discovery>
+ <entry>2026-09-11</entry>
+ </dates>
+ </vuln>
+
<vuln vid="5d69ee28-adb9-11f1-9d0e-4c526214c986">
<topic>redpanda-connect -- memory exhaustion via oversized AMQP frames</topic>
<affects>