Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
662a5a78 by Salvatore Bonaccorso at 2026-07-29T22:43:00+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-9720 (The Facturaci\xf3n Electr\xf3nica Costa Rica plugin for
WordPress is v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-9177 (A Server-Side Template Injection (SSTI) vulnerability was
identified ...)
- TODO: check
+ NOT-FOR-US: Axway
CVE-2026-8791 (The Booking System Trafft plugin for WordPress is vulnerable to
Stored ...)
NOT-FOR-US: WordPress plugin
CVE-2026-8497 (Improper certificate validation in the Devolutions Server
connection h ...)
@@ -15,17 +15,17 @@ CVE-2026-7436 (The WPC Badge Management for WooCommerce
plugin for WordPress is
CVE-2026-6089 (The WP CTA plugin for WordPress is vulnerable to Server-Side
Request F ...)
NOT-FOR-US: WordPress plugin
CVE-2026-67429 (Flyto2 Core is an execution kernel for automation and AI-agent
workflo ...)
- TODO: check
+ NOT-FOR-US: Flyto2 Core
CVE-2026-67428 (Flyto2 Core is an execution kernel for automation and AI-agent
workflo ...)
- TODO: check
+ NOT-FOR-US: Flyto2 Core
CVE-2026-67427 (Flyto2 Core is an execution kernel for automation and AI-agent
workflo ...)
- TODO: check
+ NOT-FOR-US: Flyto2 Core
CVE-2026-67426 (Flyto2 Core is an execution kernel for automation and AI-agent
workflo ...)
- TODO: check
+ NOT-FOR-US: Flyto2 Core
CVE-2026-67425 (Flyto2 Core is an execution kernel for automation and AI-agent
workflo ...)
- TODO: check
+ NOT-FOR-US: Flyto2 Core
CVE-2026-67424 (Flyto2 Core is an execution kernel for automation and AI-agent
workflo ...)
- TODO: check
+ NOT-FOR-US: Flyto2 Core
CVE-2026-67217 (cJSON through 1.7.19 applies RFC 6902 JSON Patch operations
non-atomic ...)
TODO: check
CVE-2026-67216 (cJSON through 1.7.19 contains an inefficient algorithmic
complexity fl ...)
@@ -41,19 +41,19 @@ CVE-2026-67201 (V through 0.5.2, fixed in commit 85859f0,
contains a server-side
CVE-2026-67194 (Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2
allow a ...)
TODO: check
CVE-2026-67193 (Xlight FTP Server before 3.9.5 contains an information
disclosure vuln ...)
- TODO: check
+ NOT-FOR-US: Xlight FTP Server
CVE-2026-67192 (Xlight FTP Server before 3.9.5 contains a pre-authentication
stack buf ...)
- TODO: check
+ NOT-FOR-US: Xlight FTP Server
CVE-2026-67191 (Xlight FTP Server before 3.9.5 contains a pre-authentication
heap buff ...)
- TODO: check
+ NOT-FOR-US: Xlight FTP Server
CVE-2026-67188
REJECTED
CVE-2026-66737
REJECTED
CVE-2026-66724 (MWDB Core versions >=2.0.0 and <2.19.0 contain a missing
authorization ...)
- TODO: check
+ NOT-FOR-US: MWDB Core
CVE-2026-66723 (MWDB Core versions >=2.2.0 and <2.19.0 contain a missing
authorization ...)
- TODO: check
+ NOT-FOR-US: MWDB Core
CVE-2026-66490 (Joomla Extension - balbooa.com - Stored cross-site scripting
via a com ...)
NOT-FOR-US: Joomla
CVE-2026-66489 (Joomla Extension - balbooa.com - Various unauthenticated file
system d ...)
@@ -61,7 +61,7 @@ CVE-2026-66489 (Joomla Extension - balbooa.com - Various
unauthenticated file sy
CVE-2026-66488 (Joomla Extension - balbooa.com - Payment bypass in Gridbox <
2.20.2)
NOT-FOR-US: Joomla
CVE-2026-66400 (Grav Login Plugin versions before 3.8.13 contain an
insufficient sessi ...)
- TODO: check
+ NOT-FOR-US: Grav Login Plugin
CVE-2026-66051
REJECTED
CVE-2026-65947 (Joomla Extension - balbooa.com - Various CSRF vectors in the
admin int ...)
@@ -107,9 +107,9 @@ CVE-2026-64556 (In the Linux kernel, the following
vulnerability has been resolv
CVE-2026-62995 (joserfc is a Python library that provides an implementation of
several ...)
TODO: check
CVE-2026-60113 (AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN)
Interface befo ...)
- TODO: check
+ NOT-FOR-US: AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN)
Interface
CVE-2026-60112 (AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a
missing aut ...)
- TODO: check
+ NOT-FOR-US: AMMOS Instrument Toolkit (AIT) GUI
CVE-2026-5060 (The MasterStudy LMS WordPress Plugin \u2013 for Online Courses
and Edu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-59920 (Netty is an asynchronous, event-driven network application
framework. ...)
@@ -127,7 +127,7 @@ CVE-2026-59898 (Netty is an asynchronous, event-driven
network application frame
CVE-2026-59247 (Insufficient Verification of Data Authenticity vulnerability
in Gleam ...)
TODO: check
CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted
`verify_signatur ...)
- TODO: check
+ NOT-FOR-US: Apache Airflow FAB provider
CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when
plugins reset ...)
TODO: check
CVE-2026-58188 (Several Apache Traffic Server experimental plugins have
memory-safety ...)
@@ -195,43 +195,43 @@ CVE-2026-56389 (GNU Bison allows for an execution of an
arbitrary program during
CVE-2026-55995 (A Double Free vulnerability in open-iscsi allows
anunauthenticatedMITM ...)
TODO: check
CVE-2026-54735 (Prebid Server is an open-source solution for running real-time
adverti ...)
- TODO: check
+ NOT-FOR-US: Prebid Server
CVE-2026-54727 (proot-distro is a utility for managing proot containers. Prior
to vers ...)
TODO: check
CVE-2026-54705 (MathLive provides web components for math display and input.
Prior to ...)
TODO: check
CVE-2026-54693 (ZITADEL is an open source identity management platform. From
2.43.0 th ...)
- TODO: check
+ NOT-FOR-US: Zitadel
CVE-2026-54680 (Logging operator automates the deployment and configuration of
Kuberne ...)
- TODO: check
+ NOT-FOR-US: Kubernetes Logging operator
CVE-2026-54666 (swagger-typescript-api generates API clients for Fetch or
Axios from a ...)
- TODO: check
+ NOT-FOR-US: swagger-typescript-api
CVE-2026-54664 (swagger-typescript-api generates API clients for Fetch or
Axios from a ...)
- TODO: check
+ NOT-FOR-US: swagger-typescript-api
CVE-2026-54663 (swagger-typescript-api generates API clients for Fetch or
Axios from O ...)
- TODO: check
+ NOT-FOR-US: swagger-typescript-api
CVE-2026-54662 (swagger-typescript-api generates API clients for Fetch or
Axios from O ...)
- TODO: check
+ NOT-FOR-US: swagger-typescript-api
CVE-2026-54661 (swagger-typescript-api generates API clients for Fetch or
Axios from a ...)
- TODO: check
+ NOT-FOR-US: swagger-typescript-api
CVE-2026-54660 (swagger-typescript-api generates API clients for Fetch or
Axios from O ...)
- TODO: check
+ NOT-FOR-US: swagger-typescript-api
CVE-2026-54574 (proot-distro is a utility for managing proot containers. Prior
to vers ...)
TODO: check
CVE-2026-54082 (veraPDF validation model is an implementation of the veraPDF
validatio ...)
- TODO: check
+ NOT-FOR-US: veraPDF
CVE-2026-54081 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to
1.30.2 and 1. ...)
- TODO: check
+ NOT-FOR-US: veraPDF
CVE-2026-54080 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to
1.30.2 and 1. ...)
- TODO: check
+ NOT-FOR-US: veraPDF
CVE-2026-54079 (veraPDF validation provides PDF/A and PDF/UA validation,
feature repor ...)
- TODO: check
+ NOT-FOR-US: veraPDF
CVE-2026-54078 (veraPDF validation model is an implementation of the veraPDF
validatio ...)
- TODO: check
+ NOT-FOR-US: veraPDF
CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for
rootless ...)
TODO: check
CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <=
26.3.9.8 ...)
- TODO: check
+ NOT-FOR-US: ClickHouse Server
CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize
non\u2011SGR termin ...)
TODO: check
CVE-2026-50641 (Streamsoft Business Intelligence (BI) stores users' passwords
in plain ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/662a5a787ade0ee33c5ef247962e5c336c73e0c3
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/662a5a787ade0ee33c5ef247962e5c336c73e0c3
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits