Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1e850af3 by Salvatore Bonaccorso at 2026-08-06T22:03:07+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,19 +3,19 @@ CVE-2026-61477
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2512068
TODO: wait and update entry once RH has updated records, reference
upstream issue
CVE-2026-8166 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: e-Logo Purchasing Portal
CVE-2026-70646 (aiosend is a synchronous and asynchronous Crypto Pay API
client. Pror ...)
- TODO: check
+ NOT-FOR-US: aiosend
CVE-2026-70637 (LightFTP through 2.4 contains multiple data race
vulnerabilities in ft ...)
- TODO: check
+ NOT-FOR-US: LightFTP
CVE-2026-70556 (Hubzilla 11.2.1 contains a cross-site request forgery
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Hubzilla
CVE-2026-68750 (Inefficient Algorithmic Complexity vulnerability in the
traversal engi ...)
- TODO: check
+ NOT-FOR-US: rrrene html_sanitize_ex
CVE-2026-68749 (Inefficient Regular Expression Complexity vulnerability in the
CSS scr ...)
- TODO: check
+ NOT-FOR-US: rrrene html_sanitize_ex
CVE-2026-68747 (Improper Neutralization of Special Elements in Output Used by
a Downst ...)
- TODO: check
+ NOT-FOR-US: rrrene html_sanitize_ex
CVE-2026-68481 (In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked
access tok ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68079 (In Apache CXF's DefaultEncryptingCodeDataProvider,a captured
authoriza ...)
@@ -25,13 +25,13 @@ CVE-2026-67261 (Dell Virtual Storage Integrator for VMware
vSphere Client, versi
CVE-2026-66909 (Apache CXF's JMS transport deserializes the body of any
inbound JMS Ob ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66843 (Inclusion of Functionality from Untrusted Control Sphere
vulnerability ...)
- TODO: check
+ NOT-FOR-US: rrrene html_sanitize_ex
CVE-2026-66829 (URL Redirection to Untrusted Site ('Open Redirect')
vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: rrrene html_sanitize_ex
CVE-2026-66733 (Sonic 3 A.I.R. before commit 2492d18 contains an unbounded
memory allo ...)
- TODO: check
+ NOT-FOR-US: Sonic 3 A.I.R.
CVE-2026-66732 (Sonic 3 A.I.R. before commit 2492d18 contains a missing source
address ...)
- TODO: check
+ NOT-FOR-US: Sonic 3 A.I.R.
CVE-2026-66712 (Unauthenticated Broken Access Control in Simple Membership <=
4.7.8 ve ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66711 (Subscriber Cross Site Scripting (XSS) in WooCommerce
Multilingual & Mu ...)
@@ -105,7 +105,7 @@ CVE-2026-66439 (Unauthenticated Cross Site Scripting (XSS)
in Advanced AJAX Prod
CVE-2026-66425 (Unauthenticated Broken Authentication in Gutena Forms \u2013
Contact F ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66370 (URL Redirection to Untrusted Site ('Open Redirect')
vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: rrrene html_sanitize_ex
CVE-2026-65583 (Apache CXF\u2019s OIDC relying-party token validation could
accept sel ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-65581 (Unauthenticated PHP Object Injection in AI ANN <= 1.29.0
versions.)
@@ -211,7 +211,7 @@ CVE-2026-61466 (In Apache CXF's OAuth2 Dynamic Client
Registration endpoint, the
CVE-2026-5430 (The JWT authentication mechanism accepts tokens signed with
algorithms ...)
NOT-FOR-US: WSO2
CVE-2026-5423 (@neo4j/graphqllibrary versions prior to 7.5.6 fail to verify
the authe ...)
- TODO: check
+ NOT-FOR-US: neo4j/graphql
CVE-2026-5391 (The LatePoint plugin for WordPress is vulnerable to Stored
Cross-Site ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5158 (The Post Grid Gutenberg Blocks for News, Magazines, Blog
Websites \u20 ...)
@@ -225,23 +225,23 @@ CVE-2026-57818 (A race condition in
JCacheCodeDataProvider allows an attacker to
CVE-2026-57817 (The OpenID Connect Core 1.0 specification mandates that the RP
MUST va ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-55980 (A denial-of-service vulnerability inCatchPulsecould allow an
attacker ...)
- TODO: check
+ NOT-FOR-US: CatchPulse
CVE-2026-55979 (An improper access control check inCatchPulse'snamed pipe
communicatio ...)
- TODO: check
+ NOT-FOR-US: CatchPulse
CVE-2026-55978 (An improper access control vulnerability inCatchPulsecould
allow a non ...)
- TODO: check
+ NOT-FOR-US: CatchPulse
CVE-2026-54489 (Dell Virtual Storage Integrator for VMware vSphere Client,
versions pr ...)
NOT-FOR-US: Dell / EMC
CVE-2026-54225 (Apache CXF allows to control the maximum attachment size via
the"attac ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-53985 (Ground Station prior to 0.6.0contains an unauthenticated
denial-of-ser ...)
- TODO: check
+ NOT-FOR-US: Ground Station
CVE-2026-53977 (OpenChamber 1.11.7 contains an authentication bypass
vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: OpenChamber
CVE-2026-53976 (OpenChamber 1.11.7 contains a path traversal vulnerability in
the file ...)
- TODO: check
+ NOT-FOR-US: OpenChamber
CVE-2026-53975 (OpenChamber 1.11.7 contains an unauthenticated remote code
execution v ...)
- TODO: check
+ NOT-FOR-US: OpenChamber
CVE-2026-43622 (llama.cpp builds b1886 through b7445 contain a double free
vulnerabili ...)
TODO: check
CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not
saniti ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e850af3f50f4355c93593fca0b041ef3b1744d6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e850af3f50f4355c93593fca0b041ef3b1744d6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits