Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ebe8c36c by Salvatore Bonaccorso at 2026-08-01T22:00:14+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -10,44 +10,44 @@ CVE-2026-67353 (guzzlehttp/guzzle versions before 7.15.1 
contain a denial of ser
        - guzzle 7.15.1-1
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79
 CVE-2026-67352 (luci-app-https-dns-proxy contains a stored cross-site 
scripting vulner ...)
-       TODO: check
+       NOT-FOR-US: luci-app-https-dns-proxy
 CVE-2026-67344 (ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA 
database per ...)
-       TODO: check
+       NOT-FOR-US: ArcadeDB
 CVE-2026-67343 (ArcadeDB versions before 26.7.2 fail to properly redact the 
cluster to ...)
-       TODO: check
+       NOT-FOR-US: ArcadeDB
 CVE-2026-67342 (ArcadeDB versions before 26.7.2 contain an authorization 
bypass vulner ...)
-       TODO: check
+       NOT-FOR-US: ArcadeDB
 CVE-2026-67341 (ArcadeDB versions before 26.7.2 fail to enforce scripting 
authorizatio ...)
-       TODO: check
+       NOT-FOR-US: ArcadeDB
 CVE-2026-67340 (ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger 
scripts to loo ...)
-       TODO: check
+       NOT-FOR-US: ArcadeDB
 CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly 
isolate Prox ...)
        - guzzle 7.14.2-1
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting 
vulnera ...)
        TODO: check
 CVE-2026-67337 (better-auth versions before 1.4.9 contain a two-factor 
authentication  ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67336 (better-auth versions before 1.6.11 contain insecure 
cryptographic defa ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67335 (better-auth versions before 1.6.2 fail to validate the OAuth 
state par ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67334 (better-auth versions before 1.6.11 fail to delete cached 
sessions when ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67333 (better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 
through ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67332 (@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind 
access-t ...)
-       TODO: check
+       NOT-FOR-US: Better Auth (oauth-provider)
 CVE-2026-67331 (better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail 
to bind  ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67330 (@better-auth/scim (a better-auth plugin) versions >= 
1.4.0-beta.27 thr ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67329 (@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 
1.7.0-beta ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67328 (@better-auth/sso versions before 1.6.21 contain multiple 
authenticatio ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67327 (better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release 
versions > ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2026-67326 (GitPython before 3.1.50 fails to validate newline characters 
in the se ...)
        TODO: check
 CVE-2026-67325 (GitPython before 3.1.51 contains an incomplete command 
injection block ...)
@@ -79,15 +79,15 @@ CVE-2026-67313 (axios versions 0.28.0 and later contain 
uncontrolled recursion i
 CVE-2026-67312 (axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 
1.18.0  ...)
        TODO: check
 CVE-2026-67311 (Budibase before 3.38.1 contains a server-side request forgery 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-67310 (OpenRemote (org.openremote:openremote) versions <= 1.26.2 
contain an i ...)
-       TODO: check
+       NOT-FOR-US: OpenRemote
 CVE-2026-67309 (Traefik versions >= v3.7.0 and <= v3.7.7 contain a path 
traversal vuln ...)
        TODO: check
 CVE-2026-67308 (Wazuh workflows before 44bf114 contain a shell injection 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-67307 (Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or 
override ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-67306 (FreeRDP versions 3.28.0 and earlier contain an out-of-bounds 
read vuln ...)
        TODO: check
 CVE-2026-67305 (FreeRDP Windows client before 3.29.0 contains a heap buffer 
overflow v ...)
@@ -131,13 +131,13 @@ CVE-2026-66402 (FreeRDP before 3.29.0 (affected versions 
<= 3.28.0) contains mul
 CVE-2026-66401 (FreeRDP before 3.29.0 contains an out-of-bounds heap read 
vulnerabilit ...)
        TODO: check
 CVE-2026-55735 (Improper Verification of Cryptographic Signature in ueberauth 
guardian ...)
-       TODO: check
+       NOT-FOR-US: ueberauth guardian
 CVE-2026-55734 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: ueberauth guardian
 CVE-2026-55733 (Allocation of Resources Without Limits or Throttling in 
ueberauth guar ...)
-       TODO: check
+       NOT-FOR-US: ueberauth guardian
 CVE-2026-54894 (Allocation of Resources Without Limits or Throttling in 
ueberauth guar ...)
-       TODO: check
+       NOT-FOR-US: ueberauth guardian
 CVE-2026-2916 (The Jeg Kit for Elementor plugin for WordPress is vulnerable to 
Sensit ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-2411 (Zephyr's Bluetooth host declares a GATT characteristic as two 
consecut ...)
@@ -209,11 +209,11 @@ CVE-2026-10773 (The DHCPv4 client helper 
net_dhcpv4_msg_type_name() in subsys/ne
 CVE-2026-10772
        REJECTED
 CVE-2025-71404 (better-auth versions after v0.0.2 and before 1.1.16 contain a 
reflecte ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2025-71403 (better-auth versions before 1.1.20 contain a bypass 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2025-71402 (better-auth versions greater than 1.3.34 and before 1.4.0 
contain a vu ...)
-       TODO: check
+       NOT-FOR-US: Better Auth
 CVE-2025-14469 (The Theme Editor plugin for WordPress is vulnerable to 
Cross-Site Requ ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-14073 (The WooCommerce PayPal Payments plugin for WordPress is 
vulnerable to  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe8c36c080b3e9723987879ac5277bb157c069d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe8c36c080b3e9723987879ac5277bb157c069d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to