Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
dc65c13e by Salvatore Bonaccorso at 2026-07-30T10:30:20+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,27 +7,27 @@ CVE-2026-6336 (GitLab has remediated an issue in GitLab CE/EE
affecting all vers
CVE-2026-6267 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-6102 (MSI Center NTIOLib_X64 Origin Validation Error Local Privilege
Escalat ...)
- TODO: check
+ NOT-FOR-US: MSI Center
CVE-2026-67595 (VaahCMS versions 2.0.0 through 2.3.4 contain a malicious
obfuscated Ja ...)
- TODO: check
+ NOT-FOR-US: VaahCMS
CVE-2026-67439 (OliveTin gives safe and simple access to predefined shell
commands fro ...)
- TODO: check
+ NOT-FOR-US: OliveTin
CVE-2026-67438 (OliveTin gives access to predefined shell commands from a web
interfac ...)
- TODO: check
+ NOT-FOR-US: OliveTin
CVE-2026-67437 (OliveTin gives access to predefined shell commands from a web
interfac ...)
- TODO: check
+ NOT-FOR-US: OliveTin
CVE-2026-67436 (Linuxfabrik monitoring-plugins provides Python monitoring
plugins for ...)
- TODO: check
+ NOT-FOR-US: Linuxfabrik monitoring-plugins (different from
src:monitoring-plugins)
CVE-2026-67435 (linuxfabrik-lib provides Python modules for database access,
caching, ...)
- TODO: check
+ NOT-FOR-US: linuxfabrik-lib
CVE-2026-67433 (Linuxfabrik monitoring-plugins provides Python monitoring
plugins for ...)
- TODO: check
+ NOT-FOR-US: Linuxfabrik monitoring-plugins (different from
src:monitoring-plugins)
CVE-2026-67432 (MCP Ruby SDK is the official Ruby SDK for Model Context
Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-67431 (MCP Ruby SDK is the official Ruby SDK for Model Context
Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-67430 (MCP Ruby SDK is the official Ruby SDK for Model Context
Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-67248 (A stack-based buffer overflow vulnerability was found in the
File Expl ...)
NOT-FOR-US: Asustor
CVE-2026-67247 (A path traversal vulnerability was found in the IHM Log
handling of AD ...)
@@ -39,17 +39,17 @@ CVE-2026-67245 (A path traversal vulnerability was found in
the VPN Clients on t
CVE-2026-67244 (A format string vulnerability was found in the Notification
OAuth sett ...)
NOT-FOR-US: Asustor
CVE-2026-65975 (Pydantic AI is a Python agent framework for building
applications and ...)
- TODO: check
+ NOT-FOR-US: Pydantic AI
CVE-2026-64685 (ImageMagick is free and open-source software used for editing
and mani ...)
- imagemagick 8:7.1.2.27+dfsg1-1
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/093f476e985d61557ea75ad0ef30d491dff816f3
(7.1.2-27)
CVE-2026-64635 (Improper handling of the returnUrl parameter in the Forgot
Password fu ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-63119 (MCP Ruby SDK is the official Ruby SDK for Model Context
Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-63118 (MCP Ruby SDK is the official Ruby SDK for Model Context
Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-62946 (ImageMagick is free and open-source software used for editing
and mani ...)
- imagemagick 8:7.1.2.27+dfsg1-1
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h22j-f9xw-xjjm
@@ -66,19 +66,19 @@ CVE-2026-62343 (ImageMagick is free and open-source
software used for editing an
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/9acf93f66b0f8495fa222e1a27c3db534cd78864
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/b3a93f501011a8882ec4962dd6db9f0a71e6f050
(6.9.13-51)
CVE-2026-5492 (DriveLock Directory Traversal Information Disclosure
Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5491 (DriveLock Directory Traversal Information Disclosure
Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5490 (DriveLock SQL Injection Privilege Escalation Vulnerability.
This vulne ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5489 (DriveLock Directory Traversal Information Disclosure
Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5487 (DriveLock Directory Traversal Information Disclosure
Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5057 (ATEN Unizon RpcProvider Missing Authentication
Denial-of-Service Vulne ...)
- TODO: check
+ NOT-FOR-US: ATEN
CVE-2026-59952 (Valibot helps validate data using a schema. Versions prior to
1.4.2 ca ...)
- TODO: check
+ NOT-FOR-US: Valibot
CVE-2026-59328 (Spring Tools for Eclipse renders Spring Boot starter wizard
dependency ...)
TODO: check
CVE-2026-59327 (Spring Tools for Eclipse stores the Spring Boot DevTools
remote secret ...)
@@ -86,9 +86,9 @@ CVE-2026-59327 (Spring Tools for Eclipse stores the Spring
Boot DevTools remote
CVE-2026-59326 (The Spring Boot language server logs the raw value of the
https_proxy/ ...)
TODO: check
CVE-2026-58066 (Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2,
8.4.5, 8.3 ...)
- TODO: check
+ NOT-FOR-US: Rocket.Chat
CVE-2026-58046 (Improper neutralization in the Plesk XML-RPC API allows a
remote authe ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-58043 (A flaw in Node.js Permission Model enforcement can over-grant
filesyst ...)
TODO: check
CVE-2026-58040 (An incomplete fix has been identified in Node.js: HTTPS Agent
TLS sess ...)
@@ -98,9 +98,9 @@ CVE-2026-56850 (A flaw in Node.js HTTPS Agent connection
reuse can cause PFX obj
CVE-2026-56847 (A flaw in Node.js Permission Model enforcement allows
`trace_events.cr ...)
TODO: check
CVE-2026-54249 (Pydantic AI is a Python agent framework for building
Generative AI app ...)
- TODO: check
+ NOT-FOR-US: Pydantic AI
CVE-2026-50782 (Jinher OA C6 contains an XML External Entity (XXE) injection
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Jinher OA
CVE-2026-4672 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-48449 (Adobe Campaign Classic (ACC) is affected by an Incorrect
Authorization ...)
@@ -114,7 +114,7 @@ CVE-2026-47873 (The Boot Dashboard Docker integration in
Spring Tools publishes
CVE-2026-47858 (Starting Spring Boot applications in the Spring Tools with the
live in ...)
TODO: check
CVE-2026-46678 (Pydantic AI is a Python agent framework for building
Generative AI app ...)
- TODO: check
+ NOT-FOR-US: Pydantic AI
CVE-2026-3093 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-1982 (The Persian Elementor
(\u0627\u0644\u0645\u0646\u062a\u0648\u0631 \u06 ...)
@@ -122,7 +122,7 @@ CVE-2026-1982 (The Persian Elementor
(\u0627\u0644\u0645\u0646\u062a\u0648\u0631
CVE-2026-1360 (The BuddyPress plugin for WordPress is vulnerable to
Deserialization o ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18266 (Dify AI Workflow oauth_redirect_url Open Redirect
Vulnerability. This ...)
- TODO: check
+ NOT-FOR-US: Dify
CVE-2026-18188 (A format string vulnerability was found in the Rsync Backup on
the ADM ...)
NOT-FOR-US: Asustor
CVE-2026-18187 (A format string vulnerability was found in the Internal Backup
on the ...)
@@ -1270,7 +1270,7 @@ CVE-2026-16092 (The Improved Save Button plugin for
WordPress is vulnerable to s
CVE-2026-15975 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-15929 (Improper neutralization of special elements used in an SQL
command ('S ...)
- TODO: check
+ NOT-FOR-US: LG
CVE-2026-15831 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-15382 (The Ultimate Addons for WPBakery Page Builder WordPress plugin
before ...)
@@ -1340,15 +1340,15 @@ CVE-2026-13344 (The Essential Addons for Elementor
WordPress plugin before 6.6.
CVE-2026-13330 (The Animation Addons for Elementor WordPress plugin before
2.7.0 does ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13309 (Autel MaxiCharger AC Elite Home NFC Stack-based Buffer
Overflow Arbitr ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13308 (Autel MaxiCharger AC Elite Home WebSockets Integer Underflow
Remote Co ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13307 (Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow
Arbitra ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13306 (Autel MaxiCharger AC Elite Home USB Authentication Bypass
Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13305 (Autel MaxiCharger AC Elite Home Software Update Improper
Verification ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13268 (G DATA Total Security Backup Service Link Following Local
Privilege Es ...)
TODO: check
CVE-2026-13178 (The Eventin WordPress plugin before 4.1.16 does not properly
authoriz ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc65c13edfecc9cd04c5b294f5623a8024da8652
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc65c13edfecc9cd04c5b294f5623a8024da8652
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits