Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a8e97ef7 by Salvatore Bonaccorso at 2026-06-20T10:14:06+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -58,9 +58,9 @@ CVE-2026-49295 (libde265 is an open source implementation of
the h.265 video cod
NOTE:
https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
NOTE: Fixed by:
https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652
(v1.1.0)
CVE-2026-48794 (Authelia is an open-source authentication and authorization
server pro ...)
- TODO: check
+ NOT-FOR-US: Authelia
CVE-2026-48787 (gin-vue-admin is an AI-assisted basic development platform. In
version ...)
- TODO: check
+ NOT-FOR-US: Gin-Vue-Admin
CVE-2026-48774 (ProxySQL is a proxy for MySQL and its forks, as well as
PostgreSQL. In ...)
TODO: check
CVE-2026-48773 (ProxySQL is a proxy for MySQL and its forks, as well as
PostgreSQL. Ve ...)
@@ -72,13 +72,13 @@ CVE-2026-48584 (Execution with unnecessary privileges in
Azure Synapse allows an
CVE-2026-48582 (Missing authorization in Microsoft Exchange Online allows an
authorize ...)
NOT-FOR-US: Microsoft
CVE-2026-48129 (Kestra is an open-source, event-driven orchestration platform.
Prior t ...)
- TODO: check
+ NOT-FOR-US: Kestra
CVE-2026-48089 (DevGuard provides vulnerability management for the full
software suppl ...)
- TODO: check
+ NOT-FOR-US: DevGuard
CVE-2026-47645 (Url redirection to untrusted site ('open redirect') in
Microsoft 365 C ...)
NOT-FOR-US: Microsoft
CVE-2026-47203 (Authelia is an open-source authentication and authorization
server pro ...)
- TODO: check
+ NOT-FOR-US: Authelia
CVE-2026-45480 (Improper authentication in Azure Active Directory allows an
unauthoriz ...)
NOT-FOR-US: Microsoft
CVE-2026-42895 (Improper neutralization of special elements used in a command
('comman ...)
@@ -1159,7 +1159,7 @@ CVE-2026-48818 (Starlette is a lightweight ASGI
framework/toolkit. In versions 1
NOTE: https://github.com/Kludex/starlette/pull/3287
NOTE: Fixed by:
https://github.com/Kludex/starlette/commit/fd53168a7767b6b55ba5af787fd88f49e33cabc5
(1.1.0)
CVE-2026-48591 (Improper Neutralization of Script in Attributes in a Web Page
vulnerab ...)
- TODO: check
+ NOT-FOR-US: pragdave earmark
CVE-2026-48142 (NGINX Plus and NGINX Open Source have a vulnerability in the
ngx_http_ ...)
- nginx 1.30.1-5 (bug #1140361)
NOTE: https://my.f5.com/manage/s/article/K000161585
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8e97ef78d1ba715748a6e2206366d2516863a72
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8e97ef78d1ba715748a6e2206366d2516863a72
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits