Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
aafa7654 by Salvatore Bonaccorso at 2026-08-10T22:18:43+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -116,21 +116,21 @@ CVE-2026-72586 (A missing authentication vulnerability in 
frangoteam/FUXA throug
 CVE-2026-72585 (An authorization bypass vulnerability in Grafana through 
13.2.0 allows ...)
        TODO: check
 CVE-2026-72584 (A time-of-check/time-of-use (TOCTOU) race condition in 
fastschema thro ...)
-       TODO: check
+       NOT-FOR-US: fastschema
 CVE-2026-72583 (A stored cross-site scripting (XSS) vulnerability in 
fastschema throug ...)
-       TODO: check
+       NOT-FOR-US: fastschema
 CVE-2026-72582 (A NULL pointer dereference vulnerability in fastschema through 
v0.15.1 ...)
-       TODO: check
+       NOT-FOR-US: fastschema
 CVE-2026-72581 (A server-side request forgery (SSRF) vulnerability in 
duhow/xiaoai-pat ...)
        NOT-FOR-US: duhow/xiaoai-patch
 CVE-2026-72580 (An OS command injection vulnerability in duhow/xiaoai-patch 
through co ...)
        NOT-FOR-US: duhow/xiaoai-patch
 CVE-2026-72579 (An OS command injection vulnerability in NASA HyperCP (main 
branch) al ...)
-       TODO: check
+       NOT-FOR-US: NASA HyperCP
 CVE-2026-72578 (A cross-site request forgery (CSRF) vulnerability in FreePBX 
Framework ...)
-       TODO: check
+       NOT-FOR-US: FreePBX Framework
 CVE-2026-72577 (Multiple vulnerabilities in NASA fprime-gds through 3.4.3 
allow an una ...)
-       TODO: check
+       NOT-FOR-US: NASA fprime-gds
 CVE-2026-72576 (A stored cross-site scripting (XSS) vulnerability in Bludit 
4.0.0-beta ...)
        NOT-FOR-US: Bludit
 CVE-2026-72575 (An improper authorization vulnerability in daptin through 
v0.12.34 all ...)
@@ -144,19 +144,19 @@ CVE-2026-72572 (A path traversal vulnerability in 
o1lab/xmysql (all versions) al
 CVE-2026-72571 (A path traversal vulnerability in mustafaakin/cast-localvideo 
(all ver ...)
        NOT-FOR-US: mustafaakin/cast-localvideo
 CVE-2026-72570 (A stored cross-site scripting (XSS) vulnerability in 
cube-root/directo ...)
-       TODO: check
+       NOT-FOR-US: cube-root/directory-serve
 CVE-2026-72569 (A path traversal vulnerability in cube-root/directory-serve 
through 1. ...)
-       TODO: check
+       NOT-FOR-US: cube-root/directory-serve
 CVE-2026-72568 (An out-of-bounds read vulnerability in Redis through 8.8.1 
allows an a ...)
        TODO: check
 CVE-2026-72567 (An improper path validation vulnerability in 
AsyncFuncAI/deepwiki-open ...)
-       TODO: check
+       NOT-FOR-US: AsyncFuncAI/deepwiki-open
 CVE-2026-72566 (A server-side request forgery (SSRF) vulnerability in 
automatisch thro ...)
        TODO: check
 CVE-2026-72565 (A SQL injection vulnerability in Tencent APIJSON through 8.1.8 
allows  ...)
-       TODO: check
+       NOT-FOR-US: Tencent APIJSON
 CVE-2026-72564 (An improper authorization vulnerability in fosrl/pangolin 
through v1.2 ...)
-       TODO: check
+       NOT-FOR-US: fosrl/pangolin
 CVE-2026-71969 (OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a 
buffer u ...)
        - optee-os <unfixed>
        NOTE: https://github.com/OP-TEE/optee_os/pull/7898
@@ -171,15 +171,15 @@ CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 
0aadfc2, contains a nu
        NOTE: https://github.com/OP-TEE/optee_os/pull/7899
        NOTE: Fixed by: 
https://github.com/OP-TEE/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833
 CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
arbitrary file  ...)
-       TODO: check
+       NOT-FOR-US: CyberPanel
 CVE-2026-71962 (Flowise versions 2.2.4 through 3.1.4 contain a missing 
authorization v ...)
        NOT-FOR-US: Flowise
 CVE-2026-71959 (Bitwarden Server before 2026.7.2 does not verify that the 
caller is a  ...)
        TODO: check
 CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a 
ManagedClusterMi ...)
-       TODO: check
+       NOT-FOR-US: multicluster-global-hub
 CVE-2026-71576 (A flaw was found in multicluster-global-hub. The manager 
component imp ...)
-       TODO: check
+       NOT-FOR-US: multicluster-global-hub
 CVE-2026-71394 (GNU Emacs for Android improperly validates the table header 
input in s ...)
        - emacs <unfixed>
        NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aafa7654e1b951b0f400e86cc715cd2f96b30df0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aafa7654e1b951b0f400e86cc715cd2f96b30df0
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to