Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
75195ecf by Salvatore Bonaccorso at 2026-07-31T09:48:06+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,37 +5,37 @@ CVE-2026-6890
 CVE-2026-6889
        REJECTED
 CVE-2026-68563 (A flaw was found in ansible-collection-redhat-leapp. When a 
remediatio ...)
-       TODO: check
+       NOT-FOR-US: ansible-collection-redhat-leapp
 CVE-2026-68562 (A flaw was found in ansible-collection-redhat-leapp. An 
attacker with  ...)
-       TODO: check
+       NOT-FOR-US: ansible-collection-redhat-leapp
 CVE-2026-68503 (LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team 
operati ...)
-       TODO: check
+       NOT-FOR-US: LazyOwn RedTeam/APT Framework
 CVE-2026-68502 (LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team 
operati ...)
-       TODO: check
+       NOT-FOR-US: LazyOwn RedTeam/APT Framework
 CVE-2026-68501 (Sylius Mollie Plugin provides Mollie payment integration for 
Sylius ap ...)
-       TODO: check
+       NOT-FOR-US: Sylius Mollie Plugin
 CVE-2026-68500 (Sylius Mollie Plugin provides Mollie payment integration for 
Sylius ap ...)
-       TODO: check
+       NOT-FOR-US: Sylius Mollie Plugin
 CVE-2026-68499 (re2 provides Node.js bindings for Google's RE2 regular 
expression engi ...)
        TODO: check
 CVE-2026-67594 (Spikster through commit e1cdf8c contains a missing 
authentication vuln ...)
-       TODO: check
+       NOT-FOR-US: Spikster
 CVE-2026-67550 (re2 provides Node.js bindings for Google's RE2 regular 
expression engi ...)
        TODO: check
 CVE-2026-67530 (WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 
and earli ...)
-       TODO: check
+       NOT-FOR-US: WACRM
 CVE-2026-67529 (OpenProject is open-source, web-based project management 
software. Pri ...)
-       TODO: check
+       NOT-FOR-US: OpenProject
 CVE-2026-67528 (OpenProject is open-source, web-based project management 
software. Pri ...)
-       TODO: check
+       NOT-FOR-US: OpenProject
 CVE-2026-67527 (OpenProject is open-source, web-based project management 
software. Pri ...)
-       TODO: check
+       NOT-FOR-US: OpenProject
 CVE-2026-67208 (Juggle through 1.6.0 contains a remote code execution 
vulnerability th ...)
-       TODO: check
+       NOT-FOR-US: Juggle
 CVE-2026-67207 (Wolf CMS through 0.8.3.1 contains an authorization bypass 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Wolf CMS
 CVE-2026-67206 (Wolf CMS through 0.8.3.1 contains a remote code execution 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Wolf CMS
 CVE-2026-66803 (Improper access control in Azure Cosmos DB allows an 
unauthorized atta ...)
        NOT-FOR-US: Microsoft
 CVE-2026-66756 (Improper Protection of Alternate Path vulnerability in Apache 
Tika.  T ...)
@@ -43,35 +43,35 @@ CVE-2026-66756 (Improper Protection of Alternate Path 
vulnerability in Apache Ti
 CVE-2026-66755 (Relative Path Traversal in the ISA-Tab parser in Apache 
Software Found ...)
        TODO: check
 CVE-2026-66720 (The GOOSE subscriber component improperly validates the UTC 
timestamp  ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-66421 (OpenClaw Dashboard contains a stored cross-site scripting 
vulnerabilit ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-66420 (MeshCentral 1.1.21 contains a cross-site WebSocket hijacking 
protectio ...)
-       TODO: check
+       NOT-FOR-US: MeshCentral
 CVE-2026-66418 (OpenClaw Dashboard v3.0.0 contains a stored cross-site 
scripting vulne ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-66369 (The GOOSE parser contains an off-by-one boundary-handling flaw 
that ca ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-66364 (The GOOSE payload parser contains a boundary handling flaw 
that can be ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-66360 (The ISO Presentation layer contains a flaw in the handling of 
specific ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-66349 (The MMS server connection handler contains a flaw in its 
processing of ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-65835 (Capsule is a multi-tenancy and policy-based framework for 
Kubernetes.  ...)
-       TODO: check
+       NOT-FOR-US: Capsule
 CVE-2026-65834 (Capsule is a multi-tenancy and policy-based framework for 
Kubernetes.  ...)
-       TODO: check
+       NOT-FOR-US: Capsule
 CVE-2026-65423 (An integer overflow in the UA_Variant arrayDimensions product  
computa ...)
        TODO: check
 CVE-2026-65421 (The MMS BER decoder contains a flaw in decoding fixed-width 
BER fields ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-64816 (RapidRAW before 1.6.0 does not validate the lutPath field in 
preset fi ...)
-       TODO: check
+       NOT-FOR-US: RapidRAW
 CVE-2026-63559 (An integer overflow in the UA_Variant arrayDimensions product  
computa ...)
        TODO: check
 CVE-2026-63550 (The MMS BER decoder contains a boundary-handling flaw in the 
processin ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-63362 (An unsigned integer underflow in the PubSub signature 
verification pat ...)
        TODO: check
 CVE-2026-63223 (CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, 
the is_ ...)
@@ -85,17 +85,17 @@ CVE-2026-63220 (CodeIgniter is a PHP full-stack web 
framework. In versions prior
 CVE-2026-63035 (A heap use-after-free vulnerability in the 
TransferSubscriptions servi ...)
        TODO: check
 CVE-2026-63033 (A crafted IEC 60870-5-104 I-frame with a declared object count 
exceedi ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-62845 (Kamaji is the Hosted Control Plane Manager for Kubernetes. 
Prior to 26 ...)
-       TODO: check
+       NOT-FOR-US: Kamaji
 CVE-2026-62323 (Cloudreve is a self-hosted file management and sharing system. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Cloudreve
 CVE-2026-62246 (Kamaji is the Hosted Control Plane Manager for Kubernetes. 
Prior to 26 ...)
-       TODO: check
+       NOT-FOR-US: Kamaji
 CVE-2026-61893 (A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) 
and an   ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-61526 (AdonisJS HTTP Server is a package for handling HTTP requests 
in the Ad ...)
-       TODO: check
+       NOT-FOR-US: AdonisJS HTTP Server
 CVE-2026-5846 (The affectedWatchfire Controller Softwarecontains self-signed 
hard-cod ...)
        TODO: check
 CVE-2026-56758 (The ACSE layer contains a flaw in the processing of AARQ PDUs 
during M ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75195ecf02d95ecb5742701b8afc8b85a586977e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75195ecf02d95ecb5742701b8afc8b85a586977e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to