Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ace661af by Salvatore Bonaccorso at 2026-07-29T07:57:13+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -95,7 +95,7 @@ CVE-2026-66746 (Rouille 0.4.0 through 3.6.2 contains an HTTP
response splitting
CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in
hotfix 202607 ...)
NOT-FOR-US: Artica Proxy
CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the
Tribes-based cluste ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache
Tomcat's Web ...)
- tomcat11 <unfixed> (unimportant)
- tomcat10 <unfixed> (unimportant)
@@ -288,7 +288,7 @@ CVE-2026-47726 (nebula-mesh is a self-hosted control plane
for Slack Nebula mesh
CVE-2026-47725 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
NOT-FOR-US: Nebula Mesh
CVE-2026-47483 (NVIDIA DCGM Exporter for all platforms contains a
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: NVIDIA DCGM Exporter
CVE-2026-47427 (GitHub MCP Server is GitHub's official MCP Server. Prior to
1.1.0, the ...)
NOT-FOR-US: GitHub MCP Server
CVE-2026-45293 (WordPress Coding Standards is a set of PHP_CodeSniffer rules
(sniffs) ...)
@@ -52763,7 +52763,7 @@ CVE-2026-24193 (NVIDIA Display Driver for Windows and
Linux contains a vulnerabi
CVE-2026-24192 (NVIDIA Display Driver for Linux contains a vulnerability where
an atta ...)
TODO: check
CVE-2026-24191 (NVIDIA Display Driver for Windows contains a vulnerability
where an at ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-24190 (NVIDIA Display Driver for Windows and Linux contains a
vulnerability i ...)
TODO: check
CVE-2026-24187 (NVIDIA Display Driver for Linux contains a vulnerability where
an atta ...)
@@ -58127,7 +58127,7 @@ CVE-2026-44440 (ERPNext is a free and open source
Enterprise Resource Planning t
CVE-2026-44439 (PlaywrightCapture is a simple replacement for splash using
playwright. ...)
NOT-FOR-US: PlaywrightCapture
CVE-2026-44437 (The Angular SSR is a server-rise rendering tool for Angular
applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-44432 (urllib3 is an HTTP client library for Python. From 2.6.0 to
before 2.7 ...)
- python-urllib3 2.7.0-1 (bug #1136654)
[trixie] - python-urllib3 <not-affected> (Vulnerable code introduced
later)
@@ -87543,7 +87543,7 @@ CVE-2026-33413 (etcd is a distributed key-value store
for the data of a distribu
CVE-2026-33402 (Sakai is a Collaboration and Learning Environment (CLE). In
versions 2 ...)
NOT-FOR-US: Sakai
CVE-2026-33397 (The Angular SSR is a server-rise rendering tool for Angular
applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-33396 (OneUptime is an open-source monitoring and observability
platform. Pri ...)
NOT-FOR-US: OneUptime
CVE-2026-33343 (etcd is a distributed key-value store for the data of a
distributed sy ...)
@@ -102530,9 +102530,9 @@ CVE-2026-27795 (LangChain is a framework for building
LLM-powered applications.
CVE-2026-27794 (LangGraph Checkpoint defines the base interface for LangGraph
checkpoi ...)
NOT-FOR-US: LangGraph Checkpoint
CVE-2026-27739 (The Angular SSR is a server-rise rendering tool for Angular
applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-27738 (The Angular SSR is a server-rise rendering tool for Angular
applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-27736 (BigBlueButton is an open-source virtual classroom. In versions
on the ...)
NOT-FOR-US: BigBlueButton
CVE-2026-27730 (esm.sh is a no-build content delivery network (CDN) for web
developmen ...)
@@ -102546,7 +102546,7 @@ CVE-2026-27706 (Plane is an an open-source project
management tool. Prior to ver
CVE-2026-27705 (Plane is an an open-source project management tool. Prior to
version 1 ...)
NOT-FOR-US: Plane
CVE-2026-27704 (The Dart and Flutter SDKs provide software development kits
for the Da ...)
- TODO: check
+ NOT-FOR-US: Dart and Flutter SDKs
CVE-2026-27702 (Budibase is a low code platform for creating internal tools,
workflows ...)
NOT-FOR-US: Budibase
CVE-2026-27701 (LiveCode is an open-source, client-side code playground. Prior
to comm ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ace661afaf74c6b53d9b5a6c2e02ecaa9bd8771b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ace661afaf74c6b53d9b5a6c2e02ecaa9bd8771b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits