Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8ced0a4d by Salvatore Bonaccorso at 2026-08-05T21:58:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -201,31 +201,31 @@ CVE-2026-71225 (A flaw was found in libkcapi. When
performing one-shot symmetric
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
TODO: check details, AI assisted report
CVE-2026-71215 (art-template's sub-template resolution logic
(src/compile/adapter/reso ...)
- TODO: check
+ NOT-FOR-US: art-template
CVE-2026-71214 (The Aerie/PlanDev sequencing-server's authorization middleware
(sequen ...)
- TODO: check
+ NOT-FOR-US: NASA-AMMOS
CVE-2026-71213 (Typemill's login endpoint (POST /tm/login,
ControllerWebAuth::login()) ...)
- TODO: check
+ NOT-FOR-US: Typemill
CVE-2026-71212 (xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp
command-line in ...)
- TODO: check
+ NOT-FOR-US: xidown
CVE-2026-71211 (MLflow's AI Gateway accepts an auth_config.api_base value when
creatin ...)
NOT-FOR-US: mlflow
CVE-2026-71210 (Mealie's AsyncSafeTransport SSRF guard
(mealie/pkgs/safehttp/transport ...)
- TODO: check
+ NOT-FOR-US: Mealie
CVE-2026-71209 (audiobookshelf's authentication-exemption check
(server/routers/Auth.j ...)
- TODO: check
+ NOT-FOR-US: Audiobookshelf
CVE-2026-71208 (KubeSphere's cluster-controller reconciliation
(pkg/utils/clusterclien ...)
- TODO: check
+ NOT-FOR-US: KubeSphere
CVE-2026-71207 (The Stock-Inventory-Management-System application's login.php
assigns ...)
- TODO: check
+ NOT-FOR-US: Stock-Inventory-Management-System
CVE-2026-71206 (Shiori's CheckToken function (internal/domains/auth.go)
validates only ...)
- TODO: check
+ NOT-FOR-US: Shiori
CVE-2026-71205 (changedetection.io's /login route checks the submitted
password agains ...)
- TODO: check
+ NOT-FOR-US: changedetection.io
CVE-2026-71204 (changedetection.io's /settings save handler builds an update
dict from ...)
- TODO: check
+ NOT-FOR-US: changedetection.io
CVE-2026-71203 (changedetection.io's REST API resources are protected by an
@auth.chec ...)
- TODO: check
+ NOT-FOR-US: changedetection.io
CVE-2026-71202 (The raster Rust crate's crop() function (src/editor.rs) clamps
the cro ...)
TODO: check
CVE-2026-70612 (Electron is a framework for writing cross-platform desktop
application ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ced0a4d2c008d0c278347d2b709ce34c19b71f4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ced0a4d2c008d0c278347d2b709ce34c19b71f4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits