Debian Package Tracker
Register | Log in
Subscribe

kanboard

kanban project management software

Choose email to subscribe with

general
  • source: kanboard (main)
  • version: 1.2.48+ds-1
  • maintainer: Joseph Nahmias (DMD)
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • testing: 1.2.48+ds-1
  • unstable: 1.2.48+ds-1
versioned links
  • 1.2.48+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • kanboard
action needed
A new upstream version is available: 1.2.49 high
A new upstream version 1.2.49 is available, you should consider packaging it.
Created: 2026-01-08 Last update: 2026-01-09 05:00
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2026-21879: Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs such as //evil.com, attackers can bypass the filter_var($url, FILTER_VALIDATE_URL) validation check. This vulnerability could be exploited to conduct phishing attacks, steal user credentials, or distribute malware. The issue is fixed in version 1.2.49.
  • CVE-2026-21880: Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
  • CVE-2026-21881: Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse proxy. An attacker can impersonate any user, including administrators, by simply sending a spoofed HTTP header. This issue is fixed in version 1.2.49.
Created: 2026-01-08 Last update: 2026-01-08 22:00
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2026-21879: Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs such as //evil.com, attackers can bypass the filter_var($url, FILTER_VALIDATE_URL) validation check. This vulnerability could be exploited to conduct phishing attacks, steal user credentials, or distribute malware. The issue is fixed in version 1.2.49.
  • CVE-2026-21880: Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
  • CVE-2026-21881: Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse proxy. An attacker can impersonate any user, including administrators, by simply sending a spoofed HTTP header. This issue is fixed in version 1.2.49.
Created: 2026-01-08 Last update: 2026-01-08 22:00
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2025-11-11 Last update: 2026-01-09 05:31
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 1.2.49+ds-1, distribution unstable) and new commits in its VCS. You should consider whether it's time to make an upload.
Created: 2026-01-09 Last update: 2026-01-09 04:31
debian/patches: 3 patches to forward upstream low

Among the 9 debian patches available in version 1.2.48+ds-1 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2025-08-29 Last update: 2025-12-19 12:01
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.3 instead of 4.7.2).
Created: 2025-12-23 Last update: 2025-12-23 20:00
news
[rss feed]
  • [2026-01-09] Accepted kanboard 1.2.49+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2025-12-22] kanboard 1.2.48+ds-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-19] Accepted kanboard 1.2.48+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2025-09-30] kanboard 1.2.47+ds-2 MIGRATED to testing (Debian testing watch)
  • [2025-09-28] Accepted kanboard 1.2.47+ds-2 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2025-09-18] kanboard 1.2.47+ds-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-31] Accepted kanboard 1.2.47+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2025-08-28] Accepted kanboard 1.2.44+ds-1 (source all) into unstable (Debian FTP Masters) (signed by: Joe Nahmias)
  • [2025-03-12] Removed 1.2.31+ds2-1 from unstable (Debian FTP Masters)
  • [2023-10-26] kanboard REMOVED from testing (Debian testing watch)
  • [2023-07-22] Accepted kanboard 1.2.26+ds-2+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Joe Nahmias)
  • [2023-07-16] Accepted kanboard 1.2.26+ds-2+deb12u2 (source) into stable-security (Debian FTP Masters) (signed by: Joe Nahmias)
  • [2023-07-14] kanboard 1.2.31+ds2-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-09] Accepted kanboard 1.2.31+ds2-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-07-09] kanboard 1.2.31+ds-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-04] Accepted kanboard 1.2.31+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-07-03] Accepted kanboard 1.2.30+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-06-28] Accepted kanboard 1.2.26+ds-2+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Joe Nahmias)
  • [2023-06-13] kanboard 1.2.26+ds-4 MIGRATED to testing (Debian testing watch)
  • [2023-06-08] Accepted kanboard 1.2.26+ds-4 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-06-02] Accepted kanboard 1.2.26+ds-3 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-05-24] kanboard 1.2.26+ds-2 MIGRATED to testing (Debian testing watch)
  • [2023-05-17] Accepted kanboard 1.2.26+ds-2 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-01-20] kanboard 1.2.26+ds-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-15] Accepted kanboard 1.2.26+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-01-12] Accepted kanboard 1.2.25+ds-3 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2023-01-12] Accepted kanboard 1.2.25+ds-2 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2022-11-17] Accepted kanboard 1.2.25+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • [2022-10-15] Accepted kanboard 1.2.23+ds-1.1 (source) into unstable (Michael Biebl)
  • [2022-09-13] Accepted kanboard 1.2.23+ds-1 (source) into unstable (Joseph Nahmias) (signed by: Joe Nahmias)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing