Debian Package Tracker
Register | Log in
Subscribe

vnu

Nu Html Checker (v.Nu)

Choose email to subscribe with

general
  • source: vnu (main)
  • version: 26.8.15.1+dfsg-1
  • maintainer: Fab Stz (DMD) (DM)
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • testing: 26.5.2.1+dfsg-2
  • unstable: 26.8.15.1+dfsg-1
versioned links
  • 26.5.2.1+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 26.8.15.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libvnu-java
  • libvnu-java-common
  • vnu
  • vnu-client
  • vnu-common
  • vnu-jetty12
  • vnu-server
  • vnu-tomcat11
action needed
Debci reports failed tests high
  • unstable: pass (log)
    The tests ran in 0:03:19
    Last run: 2026-05-25T04:04:34.000Z
    Previous status: unknown

  • testing: fail (log)
    The tests ran in 0:02:51
    Last run: 2026-08-15T21:04:36.000Z
    Previous status: unknown

Created: 2026-08-14 Last update: 2026-08-23 21:30
A new upstream version is available: 26.8.21 high
A new upstream version 26.8.21 is available, you should consider packaging it.
Created: 2026-08-19 Last update: 2026-08-23 20:31
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2025-15104: Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).
Created: 2026-05-02 Last update: 2026-08-19 00:31
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2025-15104: Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).
Created: 2026-06-13 Last update: 2026-08-19 00:31
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • libvnu-java-common could be marked Multi-Arch: foreign
Created: 2026-05-02 Last update: 2026-08-23 18:02
2 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 67ed84681df65401f5a8503580a41908fa00663a
Author: Fab Stz <fabstz-it@yahoo.fr>
Date:   Wed Aug 19 15:58:17 2026 +0200

    Depends: vnu-server requires procps
    
    Closes: #1144847

commit a6eae7a8c7b47fc5c35e3c494e1e944d0a3db123
Author: Fab Stz <fabstz-it@yahoo.fr>
Date:   Tue Aug 18 22:13:10 2026 +0200

    d/control: Improve description of libvnu-java & libvnu-java-common packages
    
    This will silent the lintian information:
    
    duplicate-short-description libvnu-java libvnu-java-common


https://salsa.debian.org/api/v4/projects/java-team%2Fvnu API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-08-18 Last update: 2026-08-19 15:02
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-19 Last update: 2026-08-19 09:18
debian/patches: 2 patches to forward upstream low

Among the 15 debian patches available in version 26.8.15.1+dfsg-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-05-02 Last update: 2026-08-19 08:31
testing migrations
  • excuses:
    • Migration status for vnu (26.5.2.1+dfsg-2 to 26.8.15.1+dfsg-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for vnu/26.8.15.1+dfsg-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/v/vnu.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 5 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-08-18] Accepted vnu 26.8.15.1+dfsg-1 (source) into unstable (Fab Stz)
  • [2026-08-11] vnu 26.5.2.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-06] Accepted vnu 26.5.2.1+dfsg-2 (source) into unstable (Fab Stz)
  • [2026-08-04] Accepted vnu 26.5.2.1+dfsg-1 (source) into unstable (Fab Stz)
  • [2026-06-13] vnu 23.4.11+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2026-06-02] Accepted vnu 23.4.11+dfsg-5 (source) into unstable (Fab Stz)
  • [2026-05-27] Accepted vnu 23.4.11+dfsg-4 (source) into unstable (Fab Stz)
  • [2026-05-14] Accepted vnu 23.4.11+dfsg-3 (source) into unstable (Fab Stz)
  • [2026-05-07] Accepted vnu 23.4.11+dfsg-2 (source) into unstable (Fab Stz)
  • [2026-05-01] Accepted vnu 23.4.11+dfsg-1 (source all) into unstable (Debian FTP Masters) (signed by: Emmanuel Bourg)
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 1
  • patch: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 26.8.15.1+dfsg-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing