Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e9807efd by Salvatore Bonaccorso at 2026-08-05T21:24:35+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -69,55 +69,55 @@ CVE-2026-7326 (A cross-site request forgery vulnerability
in the Admin UI of Pro
CVE-2026-7105 (The Xpro Addons plugin for WordPress is vulnerable to
unauthorized cre ...)
NOT-FOR-US: WordPress plugin
CVE-2026-71294 (Cotonti CMS's Comments plugin deserializes user-supplied data
without ...)
- TODO: check
+ NOT-FOR-US: Cotonti CMS
CVE-2026-71293 (Statamic CMS's user-augmentation resolver,
AugmentedUser::get() in src ...)
- TODO: check
+ NOT-FOR-US: Statamic CMS
CVE-2026-71292 (Subrion CMS's admin grid sorting helper, _gridGetSorting() in
includes ...)
- TODO: check
+ NOT-FOR-US: Subrion CMS
CVE-2026-71291 (Bolt CMS renders content field values through Twig's full
application- ...)
- TODO: check
+ NOT-FOR-US: Bolt CMS
CVE-2026-71289 (The NASA-AMMOS Asynchronous Network Management System (ANMS)
reference ...)
- TODO: check
+ NOT-FOR-US: NASA-AMMOS
CVE-2026-71288 (Koha's guided report builder (reports/guided_reports.pl) reads
the `or ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-71287 (Cacti's sanitize_sql_column() (lib/functions.php) sanitizes
user-suppl ...)
TODO: check
CVE-2026-71286 (The render-template component of ember-dynamic-render-template
(addon/ ...)
- TODO: check
+ NOT-FOR-US: ember-dynamic-render-template
CVE-2026-71285 (Uptime Kuma's Matomo analytics integration
(server/analytics/matomo-an ...)
- TODO: check
+ NOT-FOR-US: Uptime Kuma
CVE-2026-71284 (Fledge's backup-restore upload handler, upload_backup()
(python/fledge ...)
- TODO: check
+ NOT-FOR-US: Fledge
CVE-2026-71283 (Fledge's backup-restore upload handler, upload_backup()
(python/fledge ...)
- TODO: check
+ NOT-FOR-US: Fledge
CVE-2026-71282 (ChirpStack's SQLite-backend device tag filtering
(chirpstack/src/stora ...)
- TODO: check
+ NOT-FOR-US: ChirpStack
CVE-2026-71281 (Hugging Face peft's LoRA-GA and CorDA initialization modules
(src/peft ...)
- TODO: check
+ NOT-FOR-US: Hugging Face peft
CVE-2026-71280 (go-shiori's DownloadBookmark() (internal/core/download.go)
fetches a c ...)
- TODO: check
+ NOT-FOR-US: go-shiori
CVE-2026-71279 (Zigbee2MQTT's ExternalJSExtension.getFilePath()
(lib/extension/externa ...)
- TODO: check
+ NOT-FOR-US: Zigbee2MQTT
CVE-2026-71278 (rust-iot-platform allows creating a "calc rule" via POST
/calc-rule/cr ...)
- TODO: check
+ NOT-FOR-US: rust-iot-platform
CVE-2026-71277 (rust-iot-platform's AuthToken request-guard implementation
(api/src/ma ...)
- TODO: check
+ NOT-FOR-US: rust-iot-platform
CVE-2026-71276 (Magistrala (formerly Mainflux)'s message-readers API reads a
`format` ...)
- TODO: check
+ NOT-FOR-US: Magistrala
CVE-2026-71275 (OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c)
reflects ...)
- TODO: check
+ NOT-FOR-US: OpenBK7231T
CVE-2026-71274 (OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c)
stores cha ...)
- TODO: check
+ NOT-FOR-US: OpenBK7231T
CVE-2026-71273 (OpenBK7231T's /cfg_wifi_set endpoint
(src/httpserver/http_fns.c) accep ...)
- TODO: check
+ NOT-FOR-US: OpenBK7231T
CVE-2026-71272 (Memos' webhook dispatch function safeDialContext()
(internal/webhook/w ...)
- TODO: check
+ NOT-FOR-US: Memos
CVE-2026-71271 (Memos' webhook URL validation, isReservedIP()
(internal/webhook/valida ...)
- TODO: check
+ NOT-FOR-US: Memos
CVE-2026-71270 (Stirling-PDF's POST /api/v1/convert/url/pdf endpoint
(ConvertWebsiteTo ...)
- TODO: check
+ NOT-FOR-US: Stirling-PDF
CVE-2026-71269 (Node-RED's local-filesystem library storage module
(getLibraryEntry() ...)
- TODO: check
+ NOT-FOR-US: Node-RED
CVE-2026-71268 (OpenPLC Runtime v3's compile_program() function
(webserver/openplc.py) ...)
TODO: check
CVE-2026-71267 (microtar's mtar_write_file_header() and
mtar_write_dir_header() functi ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9807efd477d7e3968dca194825176e401045234
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9807efd477d7e3968dca194825176e401045234
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits