Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c48fbdc4 by Salvatore Bonaccorso at 2026-08-07T09:45:58+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,11 +5,11 @@ CVE-2026-7406 (A maliciously crafted BMP file, when parsed 
through certain Autod
 CVE-2026-7405 (A maliciously crafted TIF file, when parsed through certain 
Autodesk p ...)
        NOT-FOR-US: Autodesk
 CVE-2026-71555 (PILOS (Platform for Interactive Live-Online Seminars) is a 
frontend fo ...)
-       TODO: check
+       NOT-FOR-US: PILOS (Platform for Interactive Live-Online Seminars)
 CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. 
Version ...)
        TODO: check
 CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting 
vulnerability cau ...)
-       TODO: check
+       NOT-FOR-US: CTI-Transmute
 CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. 
Prior t ...)
        TODO: check
 CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 
1.14.3  ...)
@@ -21,11 +21,11 @@ CVE-2026-71478 (league/commonmark is a PHP library for 
parsing and rendering Com
 CVE-2026-71476 (Nx is a monorepo solution for TypeScript and polyglot 
codebases. From  ...)
        TODO: check
 CVE-2026-71447 (AIL Project contains a stored cross-site scripting 
vulnerability in th ...)
-       TODO: check
+       NOT-FOR-US: AIL framework
 CVE-2026-71446 (AIL Framework contains a stored cross-site scripting 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: AIL framework
 CVE-2026-71445 (AIL Framework contained a reflected cross-site scripting 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: AIL framework
 CVE-2026-71439 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
        TODO: check
 CVE-2026-71438 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
@@ -35,11 +35,11 @@ CVE-2026-71437 (Mermaid is a JavaScript tool that uses 
Markdown-inspired text to
 CVE-2026-71436 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
        TODO: check
 CVE-2026-71435 (Statamic is a Laravel and Git powered content management 
system (CMS). ...)
-       TODO: check
+       NOT-FOR-US: Statamic CMS
 CVE-2026-71434 (Statamic is a Laravel and Git powered content management 
system (CMS). ...)
-       TODO: check
+       NOT-FOR-US: Statamic CMS
 CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the 
Postgres a ...)
-       TODO: check
+       NOT-FOR-US: LangGraph Checkpoint
 CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. 
Prior t ...)
        TODO: check
 CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load 
balancer. From 3 ...)
@@ -59,11 +59,11 @@ CVE-2026-70638 (llama.cpp builds b1886 through b7445 
contain an integer overflow
 CVE-2026-70636 (Flowise through 3.1.4 contains an authentication bypass 
vulnerability  ...)
        NOT-FOR-US: Flowise
 CVE-2026-70635 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains 
an out-o ...)
-       TODO: check
+       NOT-FOR-US: Timescale TimescaleDB
 CVE-2026-70634 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains 
an out-o ...)
-       TODO: check
+       NOT-FOR-US: Timescale TimescaleDB
 CVE-2026-70633 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains 
an out-o ...)
-       TODO: check
+       NOT-FOR-US: Timescale TimescaleDB
 CVE-2026-70632 (FFmpeg versions from 4.4 up to, but not including, 9.0 contain 
an out- ...)
        TODO: check
 CVE-2026-70631 (FFmpeg versions from 0.5 up to, but not including, 9.0 contain 
an unin ...)
@@ -75,11 +75,11 @@ CVE-2026-70629 (FFmpeg versions from 3.0 up to, but not 
including, 9.0 contain a
 CVE-2026-70628 (FFmpeg versions from 0.5 up to, but not including, 9.0 contain 
a signe ...)
        TODO: check
 CVE-2026-70559 (Dinky's SysConfigController.getAll() handler for GET 
/api/sysConfig/ge ...)
-       TODO: check
+       NOT-FOR-US: dinky
 CVE-2026-70558 (Dinky's POST /download/uploadFromRsByLocal handler passes the 
caller-s ...)
-       TODO: check
+       NOT-FOR-US: dinky
 CVE-2026-70557 (diboot-core's POST /common/load-related-data endpoint resolves 
caller- ...)
-       TODO: check
+       NOT-FOR-US: diboot-core
 CVE-2026-70332 (Server-side request forgery (ssrf) in Microsoft Office 
SharePoint allo ...)
        NOT-FOR-US: Microsoft
 CVE-2026-69125
@@ -105,17 +105,17 @@ CVE-2026-68941
 CVE-2026-68823 (Exposed dangerous method or function in Azure Confidential 
Ledger allo ...)
        NOT-FOR-US: Microsoft
 CVE-2026-67689 (SQL Injection vulnerability in FineAdmin V1.0 allows a remote 
attacker ...)
-       TODO: check
+       NOT-FOR-US: FineAdmin
 CVE-2026-67688 (ICS-Park Smart Park Management System v2.0 contains an 
unrestricted fi ...)
-       TODO: check
+       NOT-FOR-US: ICS-Park Smart Park Management System
 CVE-2026-67687 (Insecure Permissions vulnerability in ics-park v.2.0 allows a 
remote a ...)
-       TODO: check
+       NOT-FOR-US: ICS-Park Smart Park Management System
 CVE-2026-67622 (Flowise through 3.1.4 contains an insecure direct object 
reference vul ...)
        NOT-FOR-US: Flowise
 CVE-2026-67621 (Flowise through 3.1.4 contains a missing authorization 
vulnerability t ...)
        NOT-FOR-US: Flowise
 CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and detects violations of 
a define ...)
-       TODO: check
+       NOT-FOR-US: PHP_CodeSniffer
 CVE-2026-67422 (pymdown-extensions is a collection of extensions for the 
Python Markdo ...)
        TODO: check
 CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows 
an auth ...)
@@ -127,13 +127,13 @@ CVE-2026-65400 (An authentication issue was addressed 
with improved state manage
 CVE-2026-64677 (Anki is a program for creating and reviewing flashcards. Prior 
to 25.0 ...)
        TODO: check
 CVE-2026-64665 (Statamic is a Laravel and Git powered content management 
system (CMS). ...)
-       TODO: check
+       NOT-FOR-US: Statamic CMS
 CVE-2026-64664 (Statamic is a Laravel and Git powered content management 
system (CMS). ...)
-       TODO: check
+       NOT-FOR-US: Statamic CMS
 CVE-2026-64663 (Statamic is a Laravel and Git powered content management 
system (CMS). ...)
-       TODO: check
+       NOT-FOR-US: Statamic CMS
 CVE-2026-64662 (Statamic is a Laravel and Git powered content management 
system (CMS). ...)
-       TODO: check
+       NOT-FOR-US: Statamic CMS
 CVE-2026-64655 (GitHub CLI (gh) is GitHub\u2019s official command line tool. 
Prior to  ...)
        TODO: check
 CVE-2026-64654 (GitHub CLI (gh) is GitHub's official command line tool. Prior 
to versi ...)
@@ -143,9 +143,9 @@ CVE-2026-64653 (GitHub CLI (gh) is GitHub\u2019s official 
command line tool. Pri
 CVE-2026-64652 (GitHub CLI (gh) is GitHub's official command line tool. Prior 
to versi ...)
        TODO: check
 CVE-2026-63725 (sysPass's FileBackupService::doBackupFiles() in 
lib/SP/Services/Backup ...)
-       TODO: check
+       NOT-FOR-US: sysPass
 CVE-2026-63637 (Dgraph is an open source distributed GraphQL database. Prior 
to 25.3.8 ...)
-       TODO: check
+       NOT-FOR-US: Dgraph
 CVE-2026-63508 (Missing authentication for critical function in Microsoft 
Planetary Co ...)
        NOT-FOR-US: Microsoft
 CVE-2026-62918 (Improper verification of cryptographic signature in Microsoft 
Teams al ...)
@@ -155,7 +155,7 @@ CVE-2026-62896 (Improper authentication in Microsoft Teams 
allows an authorized
 CVE-2026-62873 (Improper verification of cryptographic signature in Microsoft 
365 Admi ...)
        NOT-FOR-US: Microsoft
 CVE-2026-62857 (Fedify is a TypeScript library for building federated server 
apps powe ...)
-       TODO: check
+       NOT-FOR-US: Fedify
 CVE-2026-62836 (Improper restriction of communication channel to intended 
endpoints in ...)
        NOT-FOR-US: Microsoft
 CVE-2026-62830 (Missing authorization in Azure SRE Agent allows an authorized 
attacker ...)
@@ -163,11 +163,11 @@ CVE-2026-62830 (Missing authorization in Azure SRE Agent 
allows an authorized at
 CVE-2026-61632 (PyMdown Extensions is a set of extensions for the 
Python-Markdown mark ...)
        TODO: check
 CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in 
os/net/app-layer/mqtt ...)
-       TODO: check
+       NOT-FOR-US: Contiki-NG
 CVE-2026-5856 (Contiki-NG's DNS/mDNS resolver skip_name() in 
os/services/resolv/resol ...)
-       TODO: check
+       NOT-FOR-US: Contiki-NG
 CVE-2026-5855 (Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in 
os/services/lwm2m/lw ...)
-       TODO: check
+       NOT-FOR-US: Contiki-NG
 CVE-2026-5336 (The DataPress (Dataverse Integration) WordPress plugin before 
2.91 doe ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-59118 (Improper authorization in Microsoft Power Apps allows an 
unauthorized  ...)
@@ -179,11 +179,11 @@ CVE-2026-56162 (Improper authentication in Azure SQL 
Database allows an unauthor
 CVE-2026-56161 (Improper access control in Azure Logic Apps allows an 
authorized attac ...)
        NOT-FOR-US: Microsoft
 CVE-2026-54717 (Silverstripe CMS is an open source content management system. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: Silverstripe CMS
 CVE-2026-53984 (Ground Station prior to0.6.0 contains an unauthenticated 
database-dest ...)
-       TODO: check
+       NOT-FOR-US: Ground Station
 CVE-2026-53983 (Ground Station prior to0.6.0contains an unauthenticated blind 
server-s ...)
-       TODO: check
+       NOT-FOR-US: Ground Station
 CVE-2026-50515 (Deserialization of untrusted data in Azure Service Bus allows 
an autho ...)
        NOT-FOR-US: Microsoft
 CVE-2026-50481 (Modification of assumed-immutable data (maid) in Azure Active 
Director ...)
@@ -193,7 +193,7 @@ CVE-2026-50159 (Mermaid is a JavaScript tool that uses 
Markdown-inspired text to
 CVE-2026-49746 (Software installed and run as a non-privileged user may 
conduct improp ...)
        NOT-FOR-US: Imagination Technologies
 CVE-2026-49391 (Frappe is a full-stack web application framework. Prior to 
16.19.0 and ...)
-       TODO: check
+       NOT-FOR-US: Frappe
 CVE-2026-49163 (Improper limitation of a pathname to a restricted directory 
('path tra ...)
        NOT-FOR-US: Microsoft
 CVE-2026-49005 (The root password hash of the device can be obtained through 
unencrypt ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c48fbdc42c97d20f1951187f9f025853050f3c74

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c48fbdc42c97d20f1951187f9f025853050f3c74
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to