Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a6c798fa by Salvatore Bonaccorso at 2026-07-17T21:18:46+02:00
Do not mention non-fix for CVE-2026-56362

- - - - -
d177759c by Salvatore Bonaccorso at 2026-07-17T21:19:55+02:00
Remove notes on some rejected CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6722,7 +6722,6 @@ CVE-2026-56775 (n8n before 1.123.55, 2.25.7, and 2.26.2 
contains an authorizatio
        NOT-FOR-US: n8n
 CVE-2026-56401
        REJECTED
-       NOT-FOR-US: Wazuh
 CVE-2026-56374 (ImageMagick before 7.1.2-19 contains a heap buffer overflow 
vulnerabil ...)
        - imagemagick 8:7.1.2.19+dfsg1-1
        [trixie] - imagemagick <postponed> (Minor issue, fix along in future 
update)
@@ -6736,7 +6735,6 @@ CVE-2026-56362 (ImageMagick before 7.1.2-15 contains a 
heap-buffer-overflow read
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gq5v-qf8q-fp77
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/364606e5cb955b622b13015814e255e1dadd701b
 (7.1.2-14)
        NOTE: See also https://github.com/ImageMagick/ImageMagick/issues/8567
-       NOTE: Not fixed in jumbo patch 
https://github.com/ImageMagick/ImageMagick/commit/e046417675d5c26e5f48816851a406c121c77469
 CVE-2026-56360 (n8n before versions 1.123.18 and 2.6.2 fails to verify 
HMAC-SHA256 sig ...)
        NOT-FOR-US: n8n
 CVE-2026-56359 (n8n before 2.8.0 contains a cross-site scripting vulnerability 
in the  ...)
@@ -10064,7 +10062,6 @@ CVE-2026-6686 (FatFs R0.16 and earlier contains an 
uninitialized cluster exposur
        NOT-FOR-US: FatFs
 CVE-2026-6685
        REJECTED
-       NOT-FOR-US: FatFs
 CVE-2026-6684 (FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' 
contain ...)
        NOT-FOR-US: FatFs
 CVE-2026-6683 (FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync 
logic  ...)
@@ -211921,7 +211918,6 @@ CVE-2024-7983 (In version 0.3.8 of open-webui, an 
endpoint for converting markdo
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7959
        REJECTED
-       NOT-FOR-US: open-webui/open-webui
 CVE-2024-7957 (An arbitrary file overwrite vulnerability exists in the 
ZulipConnector ...)
        NOT-FOR-US: danswer-ai/danswer
 CVE-2024-7819 (A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows 
attackers  ...)
@@ -211978,20 +211974,16 @@ CVE-2024-7043 (An improper access control 
vulnerability in open-webui/open-webui
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7040
        REJECTED
-       NOT-FOR-US: open-webui/open-webui
 CVE-2024-7039
        REJECTED
-       NOT-FOR-US: open-webui/open-webui
 CVE-2024-7036 (A vulnerability in open-webui/open-webui v0.3.8 allows an 
unauthentica ...)
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7035 (In version v0.3.8 of open-webui/open-webui, sensitive actions 
such as  ...)
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7034
        REJECTED
-       NOT-FOR-US: open-webui/open-webui
 CVE-2024-7033
        REJECTED
-       NOT-FOR-US: open-webui/open-webui
 CVE-2024-6986 (A Cross-site Scripting (XSS) vulnerability exists in the 
Settings page ...)
        NOT-FOR-US: parisneo/lollms-webui
 CVE-2024-6982 (A remote code execution vulnerability exists in the Calculate 
function ...)
@@ -262519,7 +262511,6 @@ CVE-2024-7041 (An Insecure Direct Object Reference 
(IDOR) vulnerability exists i
        NOT-FOR-US: open-webui
 CVE-2024-7038
        REJECTED
-       NOT-FOR-US: open-webui
 CVE-2024-7037 (In version v0.3.8 of open-webui/open-webui, the endpoint 
/api/pipeline ...)
        NOT-FOR-US: open-webui
 CVE-2024-5968 (The Photo Gallery by 10Web  WordPress plugin before 1.8.28 does 
not pr ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/54324d2597780343f75a8856717e91310fba3023...d177759c50d22ab79a6d08145678e3a3d7478a29

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/54324d2597780343f75a8856717e91310fba3023...d177759c50d22ab79a6d08145678e3a3d7478a29
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to