git: eac754bd0e19 - main - security/vuxml: Refine the immich CVE-2026-82272 entry
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 16 Sep 2026 14:24:44 UTC
The branch main has been updated by joneum:
URL: https://cgit.FreeBSD.org/ports/commit/?id=eac754bd0e198157c62760cd44c433a2ca4e18ee
commit eac754bd0e198157c62760cd44c433a2ca4e18ee
Author: Jochen Neumeister <joneum@FreeBSD.org>
AuthorDate: 2026-09-16 14:23:18 +0000
Commit: Jochen Neumeister <joneum@FreeBSD.org>
CommitDate: 2026-09-16 14:24:32 +0000
security/vuxml: Refine the immich CVE-2026-82272 entry
Sponsored by: Netzkommune GmbH
---
security/vuxml/vuln/2026.xml | 18 ++++++++++++------
1 file changed, 12 insertions(+), 6 deletions(-)
diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index ad8554fc0804..a59ca9df66b4 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -442,21 +442,27 @@
<affects>
<package>
<name>immich</name>
- <range><le>3.2.1</le></range>
+ <range><le>3.2.2</le></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
- <p>NVD reports:</p>
+ <p>VulnCheck reports:</p>
<blockquote cite="https://nvd.nist.gov/vuln/detail/CVE-2026-82272">
<p>Immich through 3.1.0 fails to properly enforce locked asset
visibility when assets are locked through the single-asset
endpoint, allowing them to remain accessible through shared
albums and links.</p>
</blockquote>
- <p>The single-asset code path still lacks the album removal that the
- bulk path performs, so 3.2.1 is affected as well. Upstream has not
- released a fix yet.</p>
+ <p>In 3.2.2 the single-asset endpoint still lacks the album removal
+ that the bulk endpoint performs, and the album and shared link
+ access checks still carry no visibility filter. Both code paths
+ of the web interface use the bulk endpoint, so the state can only
+ be reached by calling the API directly, and such assets stay
+ visible only to those the owner already shares the album or the
+ link with. The identifier was assigned by VulnCheck, not by the
+ immich project, which has published no advisory and has not
+ confirmed the report. NVD has not analysed the entry.</p>
</body>
</description>
<references>
@@ -467,7 +473,7 @@
<dates>
<discovery>2026-08-28</discovery>
<entry>2026-09-11</entry>
- <modified>2026-09-15</modified>
+ <modified>2026-09-16</modified>
</dates>
</vuln>