Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
eb9863a5 by Salvatore Bonaccorso at 2026-07-29T23:47:19+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -256,9 +256,9 @@ CVE-2026-55995 (A Double Free vulnerability in open-iscsi 
allows anunauthenticat
 CVE-2026-54735 (Prebid Server is an open-source solution for running real-time 
adverti ...)
        NOT-FOR-US: Prebid Server
 CVE-2026-54727 (proot-distro is a utility for managing proot containers. Prior 
to vers ...)
-       TODO: check
+       NOT-FOR-US: proot-distro
 CVE-2026-54705 (MathLive provides web components for math display and input. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: MathLive
 CVE-2026-54693 (ZITADEL is an open source identity management platform. From 
2.43.0 th ...)
        NOT-FOR-US: Zitadel
 CVE-2026-54680 (Logging operator automates the deployment and configuration of 
Kuberne ...)
@@ -276,7 +276,7 @@ CVE-2026-54661 (swagger-typescript-api generates API 
clients for Fetch or Axios
 CVE-2026-54660 (swagger-typescript-api generates API clients for Fetch or 
Axios from O ...)
        NOT-FOR-US: swagger-typescript-api
 CVE-2026-54574 (proot-distro is a utility for managing proot containers. Prior 
to vers ...)
-       TODO: check
+       NOT-FOR-US: proot-distro
 CVE-2026-54082 (veraPDF validation model is an implementation of the veraPDF 
validatio ...)
        NOT-FOR-US: veraPDF
 CVE-2026-54081 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to 
1.30.2 and 1. ...)
@@ -292,13 +292,13 @@ CVE-2026-52791 (fuse-overlayfs is an implementation of 
overlayfs in FUSE for roo
 CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <= 
26.3.9.8  ...)
        NOT-FOR-US: ClickHouse Server
 CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize 
non\u2011SGR termin ...)
-       TODO: check
+       NOT-FOR-US: diff-so-fancy
 CVE-2026-50641 (Streamsoft Business Intelligence (BI) stores users' passwords 
in plain ...)
-       TODO: check
+       NOT-FOR-US: Streamsoft
 CVE-2026-50622 (Description: Missing Authorizationin Apache Atlas. A missing 
authoriza ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-50558 (Penelope Shell Handler is a post-exploitation shell handler 
for author ...)
-       TODO: check
+       NOT-FOR-US: Penelope Shell Handler
 CVE-2026-4604 (The Klubraum Membership Request plugin for WordPress is 
vulnerable to  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-44944 (An Incorrect Authorization vulnerability in open-iscsi 
allowsunprivili ...)
@@ -306,7 +306,7 @@ CVE-2026-44944 (An Incorrect Authorization vulnerability in 
open-iscsi allowsunp
 CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory 
('Path  ...)
        TODO: check
 CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded 
credentials vuln ...)
-       TODO: check
+       NOT-FOR-US: Care Everywhere Gateway
 CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic 
Server.  This  ...)
        TODO: check
 CVE-2026-40272 (Improper Input Validation in the decode() function of the 
traceparser  ...)
@@ -316,7 +316,7 @@ CVE-2026-35226 (An out\u2011of\u2011bounds write 
vulnerability in the CODESYS PR
 CVE-2026-33930 (Apache Traffic Server copies the client Host header into a 
fixed-size  ...)
        TODO: check
 CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in 
Quick.CMS.  ...)
-       TODO: check
+       NOT-FOR-US: Quick.CMS
 CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic 
Server.  Thi ...)
        TODO: check
 CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 i ...)
@@ -328,13 +328,13 @@ CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and 
port from the request
 CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache 
Traffic Ser ...)
        TODO: check
 CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall 
Manageme ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-18257 (Improper validity period check for root issuer certificate in 
CycloneC ...)
-       TODO: check
+       NOT-FOR-US: S2OPC library
 CVE-2026-18255 (A flaw was found in Quay. A user configured in 
GLOBAL_READONLY_SUPER_U ...)
-       TODO: check
+       NOT-FOR-US: Quay
 CVE-2026-18236 (A vulnerability in the Agent Development Kit (ADK) allows for 
continua ...)
-       TODO: check
+       NOT-FOR-US: adk-python
 CVE-2026-18220 (An out-of-bounds write vulnerability was found in the BFD 
library's DL ...)
        TODO: check
 CVE-2026-18207 (A flaw was found in the client policy enforcement mechanism of 
Keycloa ...)
@@ -342,17 +342,17 @@ CVE-2026-18207 (A flaw was found in the client policy 
enforcement mechanism of K
 CVE-2026-18201 (Keycloak provides a way to manage identity providers and 
organizations ...)
        TODO: check
 CVE-2026-18197 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress link library
 CVE-2026-18192 (VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: Vacron
 CVE-2026-18191 (VIN-DS783E-E6 developed by Vacron has a Hidden Functionality 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: Vacron
 CVE-2026-18174 (@fastify/forwarded resolves client addresses from the 
X-Forwarded-For  ...)
-       TODO: check
+       NOT-FOR-US: fastify/forwarded
 CVE-2026-17550 (A maliciously crafted DWG or DXF file, when parsed through 
Autodesk Au ...)
        NOT-FOR-US: Autodesk
 CVE-2026-16751 (Authorization Bypass in the emergency recovery approval 
component in E ...)
-       TODO: check
+       NOT-FOR-US: Ente Technologies Ente Museum Server
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie 
attributes. ...)
        TODO: check
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, 
Quiz, & Co ...)
@@ -360,19 +360,19 @@ CVE-2026-16655 (The Fluent Forms \u2013 Customizable 
Contact Forms, Survey, Quiz
 CVE-2026-16597 (The GTM4WP \u2013 A Google Tag Manager (GTM) plugin for 
WordPress plug ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16543 (Kong Operator's embedded Kong Kubernetes Ingress Controller 
(KIC) allo ...)
-       TODO: check
+       NOT-FOR-US: Kong Kubernetes Ingress Controller (KIC)
 CVE-2026-16465 (A maliciously crafted DWG or DXF file, when parsed through 
Autodesk Au ...)
        NOT-FOR-US: Autodesk
 CVE-2026-16463 (A maliciously crafted DXF file, when parsed through Autodesk 
AutoCAD,  ...)
        NOT-FOR-US: Autodesk
 CVE-2026-16328 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not 
restrict how  ...)
-       TODO: check
+       NOT-FOR-US: consul-mcp-server
 CVE-2026-16326 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not 
properly isol ...)
-       TODO: check
+       NOT-FOR-US: consul-mcp-server
 CVE-2026-15228 (Kong Kubernetes Ingress Controller (KIC) allows a user with 
namespace- ...)
-       TODO: check
+       NOT-FOR-US: Kong Kubernetes Ingress Controller (KIC)
 CVE-2026-15144 (@fastify/rate-limit before 11.2.0 keys rate-limit buckets by 
the verba ...)
-       TODO: check
+       NOT-FOR-US: fastify/rate-limit
 CVE-2026-14900 (The Cost Calculator Builder PRO plugin for WordPress is 
vulnerable to  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14529 (IBM WebSphere Application Server 9.0, and 8.5 and IBM 
WebSphere Applic ...)
@@ -384,7 +384,7 @@ CVE-2026-14354 (CWE-522 Insufficiently Protected 
Credentials vulnerability exist
 CVE-2026-14270 (The Extra Checkout Options (addon for Extra Product Options & 
Add-Ons  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of 
Develar's ap ...)
-       TODO: check
+       NOT-FOR-US: Develar app-builder
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control 
private  ...)
        TODO: check
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to 
Stored Cros ...)
@@ -396,7 +396,7 @@ CVE-2026-12935 (The TL-WR940N v6 router contains a 
vulnerability in its RTSP con
 CVE-2026-12927 (CWE-787 Out-of-bounds write vulnerability exists that could 
cause loss ...)
        NOT-FOR-US: Schneider Electric
 CVE-2026-12895 (SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 
and Frapp ...)
-       TODO: check
+       NOT-FOR-US: Frappe ERPNext
 CVE-2026-12703 (TeamViewer Full Client and Hostfor macOS before version 
15.80containa  ...)
        NOT-FOR-US: TeamViewer
 CVE-2026-11973 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable 
to gene ...)
@@ -406,7 +406,7 @@ CVE-2026-10684 (In subsys/debug/coredump/coredump_shell.c, 
print_coredump_hdr()
 CVE-2026-0667 (CWE-754: Improper Check for Unusual or Exceptional Conditions 
vulnerab ...)
        NOT-FOR-US: Schneider Electric
 CVE-2025-60931 (An Insecure Direct Object Reference (IDOR) in the Employee 
Compensatio ...)
-       TODO: check
+       NOT-FOR-US: Infor Global HR
 CVE-2025-10656 (The Spreadsheet Price Changer for WooCommerce and WP 
E-commerce \u2013 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-64560 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
@@ -562,7 +562,7 @@ CVE-2026-17162 (The WowStore \u2013 Store Builder & Product 
Blocks for WooCommer
 CVE-2026-17161 (The WowStore \u2013 Store Builder & Product Blocks for 
WooCommerce plu ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16581 (In igloohome Smart Lock Mobile App versions 3.2.3 and prior, 
an Inclus ...)
-       TODO: check
+       NOT-FOR-US: igloohome Smart Lock Mobile App
 CVE-2026-16347 (MikroTik RouterOS contains a weakness in its API 
authentication handli ...)
        NOT-FOR-US: MikroTik
 CVE-2026-16192 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 i ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb9863a59c5cc102264368b0b40f7c7bb0ed3f5e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb9863a59c5cc102264368b0b40f7c7bb0ed3f5e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to