Feature Requests
New / Open / Unreviewed

[Feature] while updating the security updates for a server+packages should be nice to associate the concerned CVE

Hello,

I think that all is in the title, I don't know how you determine if it's a security update or not, but I suppose that you retrieve it from packages informations.

Debian for example :
apt change log apache2-bin

apache2 (2.4.58-1ubuntu8.11) noble-security; urgency=medium

  * SECURITY REGRESSION: mod_md setting MDStapleOthers is ignored breaking
    OCSP for some domains (LP: 2142766)
    - debian/patches/CVE-2025-55753-3.patch: update mod_md to version
      2.6.7 which fixes a regression in MDStapleOthers.

 -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 05 Mar 2026 12:31:54 -0500

Surely if you can do this and store CVE infos in database, it should also be available on API hosts (stats endpoint).

By this way we could made some automation for remediation.

Thanks by advance

0 Comments

Posting anonymously

No comments yet. Be the first to share your thoughts!