Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a454be6d by Salvatore Bonaccorso at 2026-08-05T10:19:42+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15,9 +15,9 @@ CVE-2026-71191 (In OpenStack Swift through 2.38.0, S3API
middleware does not enf
CVE-2026-71190 (In OpenStack Swift through 2.38.0, the proxy server Accept
header pars ...)
TODO: check
CVE-2026-70620 (Odysseus before commit 87babb5 contains a server-side request
forgery ...)
- TODO: check
+ NOT-FOR-US: Odysseus
CVE-2026-70619 (Odysseus before commit bf325f6 contains a missing
authorization vulner ...)
- TODO: check
+ NOT-FOR-US: Odysseus
CVE-2026-70594 (Ghost is a Node.js content management system. From 2.2.0 until
6.54.1, ...)
- ghost <itp> (bug #892150)
CVE-2026-70593 (Ghost is a Node.js content management system. From 0.10.0
until 6.54.1 ...)
@@ -33,43 +33,43 @@ CVE-2026-70589 (Ghost is a Node.js content management
system. From 4.22.0 until
CVE-2026-70588 (Ghost is a Node.js content management system. From 5.26.0
until 6.54.1 ...)
- ghost <itp> (bug #892150)
CVE-2026-70554 (MaxSite CMS contains a PHP object injection vulnerability that
allows ...)
- TODO: check
+ NOT-FOR-US: MaxSite CMS
CVE-2026-70553 (MaxSite CMS contains a remote code execution vulnerability
that allows ...)
- TODO: check
+ NOT-FOR-US: MaxSite CMS
CVE-2026-70552 (MaxSite CMS 109.5 and earlier contains an authentication
bypass vulner ...)
- TODO: check
+ NOT-FOR-US: MaxSite CMS
CVE-2026-70494 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70493 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70492 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70491 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70490 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70489 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70488 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70487 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70486 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70485 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70484 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70483 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70482 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70481 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70480 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70479 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-70478 (Flowise is a drag & drop user interface to build a customized
large la ...)
NOT-FOR-US: Flowise
CVE-2026-70477 (Flowise is a drag & drop user interface to build a customized
large la ...)
@@ -79,9 +79,9 @@ CVE-2026-70476 (Flowise is a drag & drop user interface to
build a customized la
CVE-2026-70475 (Flowise is a drag & drop user interface to build a customized
large la ...)
NOT-FOR-US: Flowise
CVE-2026-70375 (HashBrown CMS through 1.4.6 contains an OS Command Injection
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: HashBrown CMS
CVE-2026-70374 (HashBrown CMS through 1.4.6 contains an OS Command Injection
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: HashBrown CMS
CVE-2026-68080 (It was not possible to govern the rate at which the broker
would respo ...)
TODO: check
CVE-2026-68078 (It was not possible to govern the maximum number of transfer
frames pe ...)
@@ -97,7 +97,7 @@ CVE-2026-68073 (A pre-authentication attacker could leverage
type nesting to cau
CVE-2026-68060 (A pre-authentication attacker could leverage type size/count
handling ...)
TODO: check
CVE-2026-67979 (Incorrect access control in the Executive Services dynamic
application ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67862 (open62541 1.5.5 contains a buffer-overflow in the high-level
attribute ...)
TODO: check
CVE-2026-67861 (An issue in open62541 v.1.5.5 and before allows a remote
attacker to c ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a454be6dc17b0a11c07d0dd2ae2ea93b1e31b21c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a454be6dc17b0a11c07d0dd2ae2ea93b1e31b21c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits