Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1fb40135 by Salvatore Bonaccorso at 2026-08-05T21:40:19+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -119,75 +119,75 @@ CVE-2026-71270 (Stirling-PDF's POST
/api/v1/convert/url/pdf endpoint (ConvertWeb
CVE-2026-71269 (Node-RED's local-filesystem library storage module
(getLibraryEntry() ...)
NOT-FOR-US: Node-RED
CVE-2026-71268 (OpenPLC Runtime v3's compile_program() function
(webserver/openplc.py) ...)
- TODO: check
+ NOT-FOR-US: OpenPLC
CVE-2026-71267 (microtar's mtar_write_file_header() and
mtar_write_dir_header() functi ...)
- TODO: check
+ NOT-FOR-US: microtar
CVE-2026-71266 (tinyobjloader-c's tinyobj_parse_and_index_mtl_file()
(tinyobj_loader_c ...)
TODO: check
CVE-2026-71265 (Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC
messages (h ...)
TODO: check
CVE-2026-71264 (WLED's GET /json/cfg endpoint (registered in
wled00/wled_server.cpp) c ...)
- TODO: check
+ NOT-FOR-US: WLED
CVE-2026-71263 (The LINUXTCP port of FreeModbus contains an off-by-one bounds
check in ...)
TODO: check
CVE-2026-71262 (IoTSharp BlobStorageController.cs lacks the [Authorize]
attribute appl ...)
- TODO: check
+ NOT-FOR-US: IoTSharp
CVE-2026-71261 (dr_libs dr_wav.h (all versions through current master)
contains an int ...)
TODO: check
CVE-2026-71260 (ESPHome through 2026.7.0-dev discloses plaintext passwords via
its web ...)
- TODO: check
+ NOT-FOR-US: ESPHome
CVE-2026-71259 (ESPHome through 2026.7.0-dev contains an operator-precedence
bug in th ...)
- TODO: check
+ NOT-FOR-US: ESPHome
CVE-2026-71256 (nanoMODBUS through v1.23.0 contains an out-of-bounds stack
read leadin ...)
- TODO: check
+ NOT-FOR-US: nanoMODBUS
CVE-2026-71255 (nanoMODBUS through v1.23.0 contains an out-of-bounds write in
the Modb ...)
- TODO: check
+ NOT-FOR-US: nanoMODBUS
CVE-2026-71254 (nanoMODBUS through v1.23.0 contains an out-of-bounds write in
the Modb ...)
- TODO: check
+ NOT-FOR-US: nanoMODBUS
CVE-2026-71252 (toner-management's admin state-changing handlers (add.php,
edit.php, d ...)
- TODO: check
+ NOT-FOR-US: toner-management
CVE-2026-71251 (Akaunting's shared download route
(app/Http/Controllers/Common/Uploads ...)
- TODO: check
+ NOT-FOR-US: Akaunting
CVE-2026-71250 (Firefly III's webhook URL validator (IsValidWebhookUrl.php)
filters mo ...)
- TODO: check
+ NOT-FOR-US: Firefly
CVE-2026-71249 (299Ko's public contact form
(plugin/contact/controllers/ContactControl ...)
- TODO: check
+ NOT-FOR-US: 299Ko public contact form
CVE-2026-71248 (Inventory-Management-System-PHP's login.php constructs its
authenticat ...)
- TODO: check
+ NOT-FOR-US: Inventory-Management-System-PHP
CVE-2026-71247 (Documenso's sign-field-with-token.ts, used by the live
document-signin ...)
- TODO: check
+ NOT-FOR-US: Documenso
CVE-2026-71246 (Pixelfed's SearchController (behind the auth middleware)
accepts a URL ...)
- TODO: check
+ NOT-FOR-US: Pixelfed
CVE-2026-71245 (Mautic's getLeadIdsByFieldValueAction
(LeadBundle/Controller/AjaxContr ...)
- TODO: check
+ NOT-FOR-US: Mautic
CVE-2026-71244 (Paperless-ngx's MailAccountViewSet.test() action, when called
with an ...)
- TODO: check
+ NOT-FOR-US: Paperless-ngx
CVE-2026-71243 (The backmeup npm package assembles shell command strings by
directly c ...)
- TODO: check
+ NOT-FOR-US: backmeup npm package
CVE-2026-71242 (Crater's NotePolicy checks only a blanket Bouncer ability
(manage-all- ...)
- TODO: check
+ NOT-FOR-US: Crater
CVE-2026-71241 (Book-Management-System's Flask API endpoints /student,
/record, /books ...)
- TODO: check
+ NOT-FOR-US: Book-Management-System
CVE-2026-71240 (DjangoCRM's toggle_default_sorting view is the only route in
common/ur ...)
- TODO: check
+ NOT-FOR-US: DjangoCRM
CVE-2026-71239 (DjangoCRM's massmail module renders user-controlled EmlMessage
fields ...)
- TODO: check
+ NOT-FOR-US: DjangoCRM
CVE-2026-71238 (DjangoCRM ships with its Django SECRET_KEY hardcoded directly
in the c ...)
- TODO: check
+ NOT-FOR-US: DjangoCRM
CVE-2026-71237 (Miantang/IoT-PHP's index.php implements a POST /userlogin
route that r ...)
- TODO: check
+ NOT-FOR-US: Miantang/IoT-PHP
CVE-2026-71236 (Grocy's API request-body parser
(controllers/Api/BaseApiController.php ...)
TODO: check
CVE-2026-71235 (Magistrala's Rules Engine allows authenticated users to create
rules w ...)
- TODO: check
+ NOT-FOR-US: Magistrala
CVE-2026-71234 (Documize Community's attachment download route
(domain/attachment/endp ...)
- TODO: check
+ NOT-FOR-US: Documize
CVE-2026-71233 (InvoiceNinja v5-stable renders an invoice or quote's "terms"
field in ...)
- TODO: check
+ NOT-FOR-US: InvoiceNinja
CVE-2026-71232 (MacCMS10's admin template editor
(application/admin/controller/Templat ...)
- TODO: check
+ NOT-FOR-US: MacCMS10
CVE-2026-71231 (IOTSmartHome's gui/login.php checkCookie() function builds an
authenti ...)
- TODO: check
+ NOT-FOR-US: IOTSmartHome
CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence
an applic ...)
TODO: check
CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error:
libkcapi's one ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb40135ad821a5724781db3c325b7f41df78fb7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb40135ad821a5724781db3c325b7f41df78fb7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits