Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1bb5bfd6 by Salvatore Bonaccorso at 2026-08-06T10:37:07+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -147,55 +147,55 @@ CVE-2026-71309 (rclone is a command-line program to sync 
files and directories t
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/cc5a189f00efe68ed0ddb32d3237b42549a9f264
 (v1.75.0)
 CVE-2026-70618 (Spacebar Server before commit 51da17c contains a missing 
authorization ...)
-       TODO: check
+       NOT-FOR-US: Spacebar Server
 CVE-2026-70617 (Spacebar Server before commit dcfd910 contains a missing 
authorization ...)
-       TODO: check
+       NOT-FOR-US: Spacebar Server
 CVE-2026-70616 (boringproxy through 0.10.0 contains a resource exhaustion 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: boringproxy
 CVE-2026-70615 (boringproxy through 0.10.0 contains a newline injection 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: boringproxy
 CVE-2026-69111 (Milvus through 2.6.22 and 3.0.0 contains an unauthenticated 
denial of  ...)
-       TODO: check
+       NOT-FOR-US: Milvus
 CVE-2026-68746 (Not Failing Securely ('Failing Open') vulnerability in 
livebook-dev li ...)
-       TODO: check
+       NOT-FOR-US: livebook-dev livebook
 CVE-2026-67873 (A heap-based buffer overflow exists in lib60870-C 2.4.0 in the 
server- ...)
-       TODO: check
+       NOT-FOR-US: mz-automation lib60870
 CVE-2026-67872 (An issue in Systerel S2OPC 1.7.3 allows a remote attacker to 
cause a d ...)
-       TODO: check
+       NOT-FOR-US: Systerel S2OPC
 CVE-2026-67871 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a 
remote  ...)
-       TODO: check
+       NOT-FOR-US: Systerel S2OPC
 CVE-2026-67870 (In open62541 v1.5.5, the server-side AddReferences 
implementation cont ...)
        TODO: check
 CVE-2026-67869 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a 
remote atta ...)
        TODO: check
 CVE-2026-67867 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a 
remote  ...)
-       TODO: check
+       NOT-FOR-US: Systerel S2OPC
 CVE-2026-67866 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a 
remote  ...)
-       TODO: check
+       NOT-FOR-US: Systerel S2OPC
 CVE-2026-67865 (S2OPC 1.7.3 contains an out-of-bounds read in 
RepublishResponse handli ...)
-       TODO: check
+       NOT-FOR-US: Systerel S2OPC
 CVE-2026-67864 (An issue in open62541 v.1.5.5 and before allows a remote 
attacker to c ...)
        TODO: check
 CVE-2026-67863 (In open62541 1.5.5, a server-side use-after-free exists in the 
local M ...)
        TODO: check
 CVE-2026-67531 (FrontMCP is a TypeScript-first framework for the Model Context 
Protoco ...)
-       TODO: check
+       NOT-FOR-US: FrontMCP
 CVE-2026-66885 (Cross-Site Request Forgery (CSRF) vulnerability in 
livebook-dev livebo ...)
-       TODO: check
+       NOT-FOR-US: livebook-dev livebook
 CVE-2026-66881 (Relative Path Traversal vulnerability in livebook-dev livebook 
allows  ...)
-       TODO: check
+       NOT-FOR-US: livebook-dev livebook
 CVE-2026-66298 (Origin Validation Error vulnerability in livebook-dev livebook 
allows  ...)
-       TODO: check
+       NOT-FOR-US: livebook-dev livebook
 CVE-2026-66297 (Improper Neutralization of Special Elements used in an OS 
Command (OS  ...)
-       TODO: check
+       NOT-FOR-US: livebook-dev livebook
 CVE-2026-55524 (PraisonAI is a multi-agent teams system. In versions prior to 
1.6.58,  ...)
-       TODO: check
+       NOT-FOR-US: PraisonAI
 CVE-2026-55523 (PraisonAI is a multi-agent teams system. In versions 1.5.128 
through 1 ...)
-       TODO: check
+       NOT-FOR-US: PraisonAI
 CVE-2026-55522 (PraisonAI is a multi-agent teams system. In versions 3.9.26 
through 4. ...)
-       TODO: check
+       NOT-FOR-US: PraisonAI
 CVE-2026-52466 (Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable 
to toIno ...)
-       TODO: check
+       NOT-FOR-US: Open Library Foundation VuFind
 CVE-2026-34966 (Gitea prior to 1.27.0 contains a server-side request forgery 
vulnerabi ...)
        TODO: check
 CVE-2026-21766 (The default login portlet in HCL Digital Experience and 
Digital Experi ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1bb5bfd6a3b483d024a2ca70cbcb2ec83a5a91b9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1bb5bfd6a3b483d024a2ca70cbcb2ec83a5a91b9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to