Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6650770c by Salvatore Bonaccorso at 2026-07-31T22:07:24+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11,31 +11,31 @@ CVE-2026-68574
 CVE-2026-67822 (Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow 
vulnera ...)
        NOT-FOR-US: Tenda
 CVE-2026-67607 (LightFTP 2.3.1 contains a race condition vulnerability that 
allows rem ...)
-       TODO: check
+       NOT-FOR-US: LightFTP
 CVE-2026-67350 (Serendipity before 2.6.1 contains an open redirect 
vulnerability in ex ...)
        TODO: check
 CVE-2026-65636 (Improper Neutralization of CRLF Sequences vulnerability in 
ufirstgroup ...)
-       TODO: check
+       NOT-FOR-US: ymlr
 CVE-2026-65313 (A provisioning script used when installing HIPASE-250 
(formerly 250 SC ...)
-       TODO: check
+       NOT-FOR-US: ANDRITZ
 CVE-2026-65311 (The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 
SCALA) i ...)
-       TODO: check
+       NOT-FOR-US: ANDRITZ
 CVE-2026-65310 (ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default 
configuration  ...)
-       TODO: check
+       NOT-FOR-US: ANDRITZ
 CVE-2026-65309 (ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions 
stores an ...)
-       TODO: check
+       NOT-FOR-US: ANDRITZ
 CVE-2026-64607 (HttpClient based on the classic i/o model fails to correctly 
release t ...)
        TODO: check
 CVE-2026-59232 (Cross-site Scripting in the lead index view in Roskus Prospero 
Flow CR ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-59231 (Server-Side Request Forgery in the PDF export component in 
maalfer Pen ...)
-       TODO: check
+       NOT-FOR-US: maalfer Pentestify
 CVE-2026-58048 (Improper preservation of SQL mode when renaming databases in  
cPanel a ...)
-       TODO: check
+       NOT-FOR-US: cPanel
 CVE-2026-58047 (HTTP Smuggling in cPanel allows potential leak of credentials.)
-       TODO: check
+       NOT-FOR-US: cPanel
 CVE-2026-57232 (Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and 
from 5.7. ...)
-       TODO: check
+       NOT-FOR-US: Contao CMS
 CVE-2026-56571 (HCL iControl was affected by Improper Error Handling 
vulnerabilities.  ...)
        NOT-FOR-US: HCL
 CVE-2026-56570 (HCL iControl was affected by Auto complete Enabled 
vulnerabilities. It ...)
@@ -47,15 +47,15 @@ CVE-2026-56568 (HCL iControl was affected by Information 
Exposure Through Verbos
 CVE-2026-56567 (HCL iControl v4.3.0 was affected by Security Misconfiguration 
vulnerab ...)
        NOT-FOR-US: HCL
 CVE-2026-55824 (Contao is an Open Source CMS. In versions 4.13.40 through 
5.3.46 and 5 ...)
-       TODO: check
+       NOT-FOR-US: Contao CMS
 CVE-2026-55100 (hashi-vault-js is a Node.js module for interacting with the 
HashiCorp  ...)
-       TODO: check
+       NOT-FOR-US: hashi-vault-js
 CVE-2026-54737 (@phun-ky/defaults-deep is a library like lodash defaultsDeep 
with arra ...)
-       TODO: check
+       NOT-FOR-US: phun-ky/defaults-deep
 CVE-2026-54729 (DSSRF is a Node.js library that provides a wide range of 
utilities and ...)
-       TODO: check
+       NOT-FOR-US: DSSRF
 CVE-2026-54725 (vault-secrets-webhook is a Kubernetes mutating webhook that 
makes dire ...)
-       TODO: check
+       NOT-FOR-US: vault-secrets-webhook
 CVE-2026-53505 (Thumbor is an open-source photo thumbnail service by 
globo.com. Prior  ...)
        TODO: check
 CVE-2026-53504 (Thumbor is an open-source photo thumbnail service by 
globo.com. Prior  ...)
@@ -69,11 +69,11 @@ CVE-2026-53501 (Thumbor is an open-source photo thumbnail 
service by globo.com.
 CVE-2026-53500 (Thumbor is an open-source photo thumbnail service by 
globo.com. Prior  ...)
        TODO: check
 CVE-2026-52857 (Wings is the server control plane for Pterodactyl, a free, 
open-source ...)
-       TODO: check
+       NOT-FOR-US: Wings
 CVE-2026-52856 (Wings is the server control plane for Pterodactyl, a free, 
open-source ...)
-       TODO: check
+       NOT-FOR-US: Wings
 CVE-2026-52855 (Wings is the server control plane for Pterodactyl, a free, 
open-source ...)
-       TODO: check
+       NOT-FOR-US: Wings
 CVE-2026-51301
        REJECTED
 CVE-2026-51299
@@ -163,9 +163,9 @@ CVE-2026-51230
 CVE-2026-51229
        REJECTED
 CVE-2026-46594 (A reflected cross-site scripting (XSS) vulnerability has been 
identifi ...)
-       TODO: check
+       NOT-FOR-US: PHPJabbers
 CVE-2026-46593 (A SQL injection vulnerability has been identified in the PHP 
Jabbers - ...)
-       TODO: check
+       NOT-FOR-US: PHPJabbers
 CVE-2026-34497 (Improper neutralization of Script-Related HTML tags in a web 
page (bas ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-34495 (Improper neutralization of input during web page generation 
('cross-si ...)
@@ -177,7 +177,7 @@ CVE-2026-28145 (Insufficient Verification of Data 
Authenticity vulnerability in
 CVE-2026-28144 (Insertion of Sensitive Information Into Sent Data 
vulnerability in Fli ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-25552 (Ghost CLI before 1.30.1 contains an IP spoofing vulnerability 
that all ...)
-       TODO: check
+       NOT-FOR-US: Ghost CLI
 CVE-2026-21662 (Unrestricted upload of file with dangerous type vulnerability 
in Johns ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-18481 (Stored cross-site scripting in the participant URL handling in 
AWS Ops ...)
@@ -211,7 +211,7 @@ CVE-2026-18206 (A flaw was found in the keycloak-services 
component of Keycloak,
 CVE-2026-18203 (A flaw was found in the group policy evaluation logic of 
Keycloak, an  ...)
        TODO: check
 CVE-2026-18141 (A flaw was found in aap-gateway, a component of Ansible 
Automation Pla ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-17592
        REJECTED
 CVE-2026-17567 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, 
Quiz, & Co ...)
@@ -219,7 +219,7 @@ CVE-2026-17567 (The Fluent Forms \u2013 Customizable 
Contact Forms, Survey, Quiz
 CVE-2026-17566 (pgAdmin 4's Import/Export Data tool builds a psql \copy (...) 
command  ...)
        TODO: check
 CVE-2026-17561 (Improper Control of Generation of Code ('Code Injection') 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Logsign SIEM
 CVE-2026-17351 (The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the 
LLM-supplied ...)
        TODO: check
 CVE-2026-17350 (The per-tool permission system (custom roles / role-based tool 
permiss ...)
@@ -235,9 +235,9 @@ CVE-2026-17346 (The fix for CVE-2026-12044 in pgAdmin 4 
9.16 hardened qtLiteral
 CVE-2026-16843 (Some Hikvision Wireless Access Points are vulnerable to 
authenticated  ...)
        NOT-FOR-US: Hikvision
 CVE-2026-16504 (Deployment of the VPS.org one-click Zulip template deploys a 
hardcoded ...)
-       TODO: check
+       NOT-FOR-US: VPS.org one-click Zulip template
 CVE-2026-16503 (Deployment of the VPS.org one-click Supabase template deploys 
a Postgr ...)
-       TODO: check
+       NOT-FOR-US: VPS.org one-click Supabase template
 CVE-2026-16105 (A flaw was found in the RoleContainerResource component of 
Keycloak. T ...)
        TODO: check
 CVE-2026-15722 (A stack buffer overflow flaw was found in 389 Directory Server 
(389-ds ...)
@@ -251,13 +251,13 @@ CVE-2026-10686 (Zephyr's IPv6 forwarding path re-sent 
routed unicast packets wit
 CVE-2026-10685 (The Zephyr Bluetooth GATT client CCC-write response handler 
gatt_write ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10079 (A flaw was found in Red Hat Advanced Cluster Security for 
Kubernetes ( ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Advanced Cluster Security for Kubernetes (RHACS)
 CVE-2025-67651 (A Cross-Site Request Forgery (CSRF) vulnerability has been 
identified  ...)
-       TODO: check
+       NOT-FOR-US: PHPJabbers
 CVE-2025-67650 (An authenticated SQL injection vulnerability has been 
identified in mu ...)
-       TODO: check
+       NOT-FOR-US: PHPJabbers
 CVE-2025-67649 (A SQL injection vulnerability has been identified in PHP 
Jabbers -Car  ...)
-       TODO: check
+       NOT-FOR-US: PHPJabbers
 CVE-2025-62347 (HCL iControl was affected by Improper Input Validation 
vulnerability.  ...)
        NOT-FOR-US: HCL
 CVE-2026-XXXX [GHSA-6v6x-387m-rj4w: Project restriction bypass on network 
address sets]



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6650770c8b8a2b02c4645bd5722df4d7b85b24e9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6650770c8b8a2b02c4645bd5722df4d7b85b24e9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to