Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e093cc3a by Salvatore Bonaccorso at 2026-08-03T21:35:57+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its 
authen ...)
-       TODO: check
+       NOT-FOR-US: PaperCut
 CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive 
authentication att ...)
-       TODO: check
+       NOT-FOR-US: PaperCut
 CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and 
modify its ...)
        TODO: check
 CVE-2026-69152 (The brace-expansion library generates arbitrary strings 
containing a c ...)
@@ -13,41 +13,41 @@ CVE-2026-69149 (Angular is a development platform for 
building mobile and deskto
 CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names 
in git  ...)
        TODO: check
 CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 
snapshots co ...)
-       TODO: check
+       NOT-FOR-US: OpenWrt luci-app-dockerman
 CVE-2026-69095 (OpenWrt luci-app-bmx7 before commit 
5890760a454dad2cb00389dba2cdc5e779 ...)
-       TODO: check
+       NOT-FOR-US: OpenWrt
 CVE-2026-69094 (Admidio before 5.0.11 contains an insecure direct object 
reference vul ...)
-       TODO: check
+       NOT-FOR-US: Admidio
 CVE-2026-69093 (Admidio before 5.0.11 does not validate the adm_csrf_token in 
modules/ ...)
-       TODO: check
+       NOT-FOR-US: Admidio
 CVE-2026-69092 (Admidio versions before 5.0.11 contain a reflected cross-site 
scriptin ...)
-       TODO: check
+       NOT-FOR-US: Admidio
 CVE-2026-69091 (Admidio before 5.0.11 contains an authentication bypass 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Admidio
 CVE-2026-69090 (Admidio before 5.0.11 fails to validate target organization 
membership ...)
-       TODO: check
+       NOT-FOR-US: Admidio
 CVE-2026-69089 (Grav CMS 2.0.10 contains a path traversal vulnerability in 
ImageMedium ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-69088 (Grav CMS versions 2.0.7 through 2.0.10 fail to validate 
fully-qualifie ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-69087 (The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 
contains ...)
-       TODO: check
+       NOT-FOR-US: Grav form plugin (getgrav/grav-plugin-form)
 CVE-2026-69086 (SiYuan versions before v3.7.3 fail to validate the avID 
parameter on a ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-69085 (SiYuan before v3.7.3 contains a SQL injection vulnerability in 
the /ap ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-69084 (SiYuan versions <= v3.7.2 expose the 
/api/search/searchEmbedBlock endp ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-69083 (SiYuan versions before v3.7.3 contain SQL injection 
vulnerabilities in ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-69082 (CTI-Transmute contained a cross-site request forgery 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: CTI-Transmute
 CVE-2026-69079 (CTI-Transmute contains an uncontrolled resource-consumption 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: CTI-Transmute
 CVE-2026-69078 (CTI-Transmute is affected by a server-side request forgery 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: CTI-Transmute
 CVE-2026-69075 (FlowIntel is affected by a stored cross-site scripting 
vulnerability t ...)
-       TODO: check
+       NOT-FOR-US: FlowIntel
 CVE-2026-68945 (Angular is a development platform for building mobile and 
desktop web  ...)
        TODO: check
 CVE-2026-68930 (Russh is a Rust SSH client & server library. Prior to 0.62.5, 
russh di ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e093cc3aeb4b324d001ff25651b6dec6924898f5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e093cc3aeb4b324d001ff25651b6dec6924898f5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to