Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a6c798fa by Salvatore Bonaccorso at 2026-07-17T21:18:46+02:00
Do not mention non-fix for CVE-2026-56362
- - - - -
d177759c by Salvatore Bonaccorso at 2026-07-17T21:19:55+02:00
Remove notes on some rejected CVEs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6722,7 +6722,6 @@ CVE-2026-56775 (n8n before 1.123.55, 2.25.7, and 2.26.2
contains an authorizatio
NOT-FOR-US: n8n
CVE-2026-56401
REJECTED
- NOT-FOR-US: Wazuh
CVE-2026-56374 (ImageMagick before 7.1.2-19 contains a heap buffer overflow
vulnerabil ...)
- imagemagick 8:7.1.2.19+dfsg1-1
[trixie] - imagemagick <postponed> (Minor issue, fix along in future
update)
@@ -6736,7 +6735,6 @@ CVE-2026-56362 (ImageMagick before 7.1.2-15 contains a
heap-buffer-overflow read
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gq5v-qf8q-fp77
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/364606e5cb955b622b13015814e255e1dadd701b
(7.1.2-14)
NOTE: See also https://github.com/ImageMagick/ImageMagick/issues/8567
- NOTE: Not fixed in jumbo patch
https://github.com/ImageMagick/ImageMagick/commit/e046417675d5c26e5f48816851a406c121c77469
CVE-2026-56360 (n8n before versions 1.123.18 and 2.6.2 fails to verify
HMAC-SHA256 sig ...)
NOT-FOR-US: n8n
CVE-2026-56359 (n8n before 2.8.0 contains a cross-site scripting vulnerability
in the ...)
@@ -10064,7 +10062,6 @@ CVE-2026-6686 (FatFs R0.16 and earlier contains an
uninitialized cluster exposur
NOT-FOR-US: FatFs
CVE-2026-6685
REJECTED
- NOT-FOR-US: FatFs
CVE-2026-6684 (FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1'
contain ...)
NOT-FOR-US: FatFs
CVE-2026-6683 (FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync
logic ...)
@@ -211921,7 +211918,6 @@ CVE-2024-7983 (In version 0.3.8 of open-webui, an
endpoint for converting markdo
NOT-FOR-US: open-webui/open-webui
CVE-2024-7959
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7957 (An arbitrary file overwrite vulnerability exists in the
ZulipConnector ...)
NOT-FOR-US: danswer-ai/danswer
CVE-2024-7819 (A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows
attackers ...)
@@ -211978,20 +211974,16 @@ CVE-2024-7043 (An improper access control
vulnerability in open-webui/open-webui
NOT-FOR-US: open-webui/open-webui
CVE-2024-7040
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7039
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7036 (A vulnerability in open-webui/open-webui v0.3.8 allows an
unauthentica ...)
NOT-FOR-US: open-webui/open-webui
CVE-2024-7035 (In version v0.3.8 of open-webui/open-webui, sensitive actions
such as ...)
NOT-FOR-US: open-webui/open-webui
CVE-2024-7034
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7033
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-6986 (A Cross-site Scripting (XSS) vulnerability exists in the
Settings page ...)
NOT-FOR-US: parisneo/lollms-webui
CVE-2024-6982 (A remote code execution vulnerability exists in the Calculate
function ...)
@@ -262519,7 +262511,6 @@ CVE-2024-7041 (An Insecure Direct Object Reference
(IDOR) vulnerability exists i
NOT-FOR-US: open-webui
CVE-2024-7038
REJECTED
- NOT-FOR-US: open-webui
CVE-2024-7037 (In version v0.3.8 of open-webui/open-webui, the endpoint
/api/pipeline ...)
NOT-FOR-US: open-webui
CVE-2024-5968 (The Photo Gallery by 10Web WordPress plugin before 1.8.28 does
not pr ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/54324d2597780343f75a8856717e91310fba3023...d177759c50d22ab79a6d08145678e3a3d7478a29
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/54324d2597780343f75a8856717e91310fba3023...d177759c50d22ab79a6d08145678e3a3d7478a29
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits