CVE coverage

Debian 12 CVE tracker

Noxen pulls Debian 12 (Bookworm) CVE data from OSV.dev's Debian ecosystem feed, which mirrors the Debian Security Tracker. Records are deduped against NVD and shipped in a signed snapshot, rebuilt daily.

Live

Headline numbers

  • Total CVE records (all distros)Loading…
  • Last buildLoading…
  • OSV records (Debian + others)Loading…
  • NVD records (cross-platform)Loading…

How matching works

What Noxen does for a Debian 12 host

  1. Reads /etc/os-release over SSH to confirm the host is on Debian 12.
  2. Reads the dpkg package list - every binary package, plus its corresponding source package via dpkg-query --showformat='${Source}'.
  3. Filters the local feed cache to OSV records tagged with ecosystem Debian:12.
  4. For each record, compares your installed version against the OSV-published fix version using the Debian/Ubuntu version-comparison rules (epoch, upstream, debian-revision).
  5. Emits a finding only when the installed version is older than the fix. Where Ubuntu Pro / ESM-only fixes apply, they are flagged separately.

Live listings

Top recent critical CVEs (Debian 12 / Debian ecosystem)

Most-recently-published critical CVEs in the Debian 12 / Debian ecosystem. Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.

CVESev.CVSSSummaryPackageFix inPublished
DEBIAN-CVE-2026-106446critical9.8Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLitenode-handlebars-
DEBIAN-CVE-2026-106419critical9.6Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)chromium-
DEBIAN-CVE-2026-106417critical9.6Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)chromium-
DEBIAN-CVE-2026-106414critical9.6Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium securchromium-
DEBIAN-CVE-2026-106401critical9.6Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)chromium-
DEBIAN-CVE-2026-106382critical9.6Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)chromium-
DEBIAN-CVE-2026-106375critical9.6Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)chromium-
DEBIAN-CVE-2026-106372critical9.6Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)chromium-

Top recent high-severity CVEs (Debian 12 / Debian ecosystem)

CVESev.CVSSSummaryPackageFix inPublished
DEBIAN-CVE-2026-77214high8.2expat-
DEBIAN-CVE-2026-46570high8.1ntfs-3g-
DEBIAN-CVE-2026-46572high7.4ntfs-3g-
DEBIAN-CVE-2026-42618high7.1ntfs-3g-
DEBIAN-CVE-2026-42617high7.1ntfs-3g-
DEBIAN-CVE-2026-106062high7.8A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated bufgimp-
DEBIAN-CVE-2026-101258high7.8A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corrupghostscript-
DEBIAN-CVE-2026-83550high7.1A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows foprometheus-postgres-exporter-

New to severity terminology? CVE, CVSS, CWE, CPE explained.

Notable

Recent CVEs Debian 12 operators should know.

FAQ

Frequently asked about Debian 12 CVEs

How many CVEs affect Debian 12?

Debian 12 (Bookworm) is filtered out of the broader Debian ecosystem feed by ecosystem tag (Debian:12). Live counts appear at the top of this page; the underlying feed is rebuilt daily.

How do I check Debian 12 CVEs on a running host?

For a quick check: apt list --upgradable 2>/dev/null | grep -ci security. For a per-CVE breakdown with fix versions, Noxen reads dpkg over SSH and matches installed source-package versions against the OSV Debian:12 ecosystem feed.

Scan a Debian 12 fleet with Noxen

Add your Debian 12 hosts via your existing ~/.ssh/config; Noxen reads dpkg state and matches against the live signed feed. No agent, no SaaS round-trip. $12/month, or $120/year.

← back to the CVE dashboard   Debian 13 →   Debian 11 →