Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1f86d422 by Salvatore Bonaccorso at 2026-06-24T22:27:45+02:00
Process some more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -183,7 +183,7 @@ CVE-2026-49851 (Mistune is a Python Markdown parser with
renderers and plugins.
- mistune <unfixed>
NOTE:
https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p
CVE-2026-49269 (Apple M1 GPUs retain register file data between compute shader
dispatc ...)
- TODO: check
+ NOT-FOR-US: Apple Silicon HW issue
CVE-2026-49247 (Jellyfin is an open source self hosted media server. From
10.9.0 until ...)
TODO: check
CVE-2026-49246 (Jellyfin is an open source self hosted media server. Prior to
10.11.10 ...)
@@ -193,31 +193,31 @@ CVE-2026-49220 (Jellyfin is an open source self hosted
media server. Prior to 10
CVE-2026-48793 (Jellyfin is an open source self hosted media server. Prior to
10.11.10 ...)
TODO: check
CVE-2026-48789 (AnythingLLM is an application that turns pieces of content
into contex ...)
- TODO: check
+ NOT-FOR-US: AnythingLLM
CVE-2026-48732 (Warp is an agentic development environment. From
0.2023.03.21.08.02.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-48731 (Warp is an agentic development environment. From
0.2024.02.20.08.01.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-48725 (Warp is an agentic development environment. From
0.2021.04.25.23.05.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-48721 (Warp is an agentic development environment. From
0.2025.10.08.08.12.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-48720 (Warp is an agentic development environment. From
0.2025.03.05.08.02.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-48719 (Warp is an agentic development environment. From
0.2025.08.06.08.12.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-48704 (Warp is an agentic development environment. From
0.2023.10.24.08.03.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-48703 (Warp is an agentic development environment. From
0.2025.04.09.08.11.st ...)
- TODO: check
+ NOT-FOR-US: Warp
CVE-2026-44022 (Docling simplifies document processing by parsing diverse
formats and ...)
- TODO: check
+ NOT-FOR-US: Docling
CVE-2026-44020 (Docling simplifies document processing by parsing diverse
formats and ...)
- TODO: check
+ NOT-FOR-US: Docling
CVE-2026-44017 (Docling simplifies document processing by parsing diverse
formats and ...)
- TODO: check
+ NOT-FOR-US: Docling
CVE-2026-44016 (Docling simplifies document processing by parsing diverse
formats and ...)
- TODO: check
+ NOT-FOR-US: Docling
CVE-2026-42450 (OpenColorIO is a color management framework for visual effects
and ani ...)
TODO: check
CVE-2026-35025 (ProFTPD through 1.3.9b and 1.3.10rc2 contains an access
control bypass ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f86d4221e5d75ae90183b2ee9454517ba5a0fd8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f86d4221e5d75ae90183b2ee9454517ba5a0fd8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits