Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
aafa7654 by Salvatore Bonaccorso at 2026-08-10T22:18:43+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -116,21 +116,21 @@ CVE-2026-72586 (A missing authentication vulnerability in
frangoteam/FUXA throug
CVE-2026-72585 (An authorization bypass vulnerability in Grafana through
13.2.0 allows ...)
TODO: check
CVE-2026-72584 (A time-of-check/time-of-use (TOCTOU) race condition in
fastschema thro ...)
- TODO: check
+ NOT-FOR-US: fastschema
CVE-2026-72583 (A stored cross-site scripting (XSS) vulnerability in
fastschema throug ...)
- TODO: check
+ NOT-FOR-US: fastschema
CVE-2026-72582 (A NULL pointer dereference vulnerability in fastschema through
v0.15.1 ...)
- TODO: check
+ NOT-FOR-US: fastschema
CVE-2026-72581 (A server-side request forgery (SSRF) vulnerability in
duhow/xiaoai-pat ...)
NOT-FOR-US: duhow/xiaoai-patch
CVE-2026-72580 (An OS command injection vulnerability in duhow/xiaoai-patch
through co ...)
NOT-FOR-US: duhow/xiaoai-patch
CVE-2026-72579 (An OS command injection vulnerability in NASA HyperCP (main
branch) al ...)
- TODO: check
+ NOT-FOR-US: NASA HyperCP
CVE-2026-72578 (A cross-site request forgery (CSRF) vulnerability in FreePBX
Framework ...)
- TODO: check
+ NOT-FOR-US: FreePBX Framework
CVE-2026-72577 (Multiple vulnerabilities in NASA fprime-gds through 3.4.3
allow an una ...)
- TODO: check
+ NOT-FOR-US: NASA fprime-gds
CVE-2026-72576 (A stored cross-site scripting (XSS) vulnerability in Bludit
4.0.0-beta ...)
NOT-FOR-US: Bludit
CVE-2026-72575 (An improper authorization vulnerability in daptin through
v0.12.34 all ...)
@@ -144,19 +144,19 @@ CVE-2026-72572 (A path traversal vulnerability in
o1lab/xmysql (all versions) al
CVE-2026-72571 (A path traversal vulnerability in mustafaakin/cast-localvideo
(all ver ...)
NOT-FOR-US: mustafaakin/cast-localvideo
CVE-2026-72570 (A stored cross-site scripting (XSS) vulnerability in
cube-root/directo ...)
- TODO: check
+ NOT-FOR-US: cube-root/directory-serve
CVE-2026-72569 (A path traversal vulnerability in cube-root/directory-serve
through 1. ...)
- TODO: check
+ NOT-FOR-US: cube-root/directory-serve
CVE-2026-72568 (An out-of-bounds read vulnerability in Redis through 8.8.1
allows an a ...)
TODO: check
CVE-2026-72567 (An improper path validation vulnerability in
AsyncFuncAI/deepwiki-open ...)
- TODO: check
+ NOT-FOR-US: AsyncFuncAI/deepwiki-open
CVE-2026-72566 (A server-side request forgery (SSRF) vulnerability in
automatisch thro ...)
TODO: check
CVE-2026-72565 (A SQL injection vulnerability in Tencent APIJSON through 8.1.8
allows ...)
- TODO: check
+ NOT-FOR-US: Tencent APIJSON
CVE-2026-72564 (An improper authorization vulnerability in fosrl/pangolin
through v1.2 ...)
- TODO: check
+ NOT-FOR-US: fosrl/pangolin
CVE-2026-71969 (OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a
buffer u ...)
- optee-os <unfixed>
NOTE: https://github.com/OP-TEE/optee_os/pull/7898
@@ -171,15 +171,15 @@ CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit
0aadfc2, contains a nu
NOTE: https://github.com/OP-TEE/optee_os/pull/7899
NOTE: Fixed by:
https://github.com/OP-TEE/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833
CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an
arbitrary file ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-71962 (Flowise versions 2.2.4 through 3.1.4 contain a missing
authorization v ...)
NOT-FOR-US: Flowise
CVE-2026-71959 (Bitwarden Server before 2026.7.2 does not verify that the
caller is a ...)
TODO: check
CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a
ManagedClusterMi ...)
- TODO: check
+ NOT-FOR-US: multicluster-global-hub
CVE-2026-71576 (A flaw was found in multicluster-global-hub. The manager
component imp ...)
- TODO: check
+ NOT-FOR-US: multicluster-global-hub
CVE-2026-71394 (GNU Emacs for Android improperly validates the table header
input in s ...)
- emacs <unfixed>
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aafa7654e1b951b0f400e86cc715cd2f96b30df0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aafa7654e1b951b0f400e86cc715cd2f96b30df0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits