Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ef68c294 by Salvatore Bonaccorso at 2026-08-11T22:03:32+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -54,25 +54,25 @@ CVE-2026-73212 (Coturn is a free open source implementation
of TURN and STUN Ser
CVE-2026-73211 (PeerTube is an ActivityPub-federated video streaming platform.
Prior t ...)
- peertube <itp> (bug #950821)
CVE-2026-73210 (A Server-Side Request Forgery (SSRF) vulnerability existed in
Lookyloo ...)
- TODO: check
+ NOT-FOR-US: Lookyloo PlaywrightCapture
CVE-2026-73162 (Affected versions of MISP cti-transmute expose several
state-changing ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73161 (Affected versions of cti-transmute improperly handle
conversion-table ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73160 (Affected versions of cti-transmute contain an SSRF
vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73159 (Affected versions of cti-transmute allow a tag's icon value to
be stor ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73158 (Affected versions of cti-transmute insufficiently validate
saved graph ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73157 (Affected versions of cti-transmute render data obtained from a
remote ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73156 (Affected versions of cti-transmute fail to HTML-escape
attacker-contro ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73155 (Affected versions of cti-transmute allow authenticated users
to add or ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73140 (Affected versions of cti-transmute fail to apply comment-level
access- ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform.
Prior t ...)
- peertube <itp> (bug #950821)
CVE-2026-73089 (Browserslist is a configuration tool for sharing target
browsers and N ...)
@@ -84,7 +84,7 @@ CVE-2026-73088 (Browserslist is a configuration tool for
sharing target browsers
NOTE:
https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g
NOTE: Fixed by:
https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51
(4.28.7)
CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From
10.5.2 unt ...)
- TODO: check
+ NOT-FOR-US: Dozzle
CVE-2026-73086 (nanoid is a secure, URL-friendly, unique string ID generator
for JavaS ...)
- node-postcss 8.5.14+~cs9.3.34-1
- node-mocha 9.1.4+ds1+~cs28.2.8-1
@@ -95,19 +95,19 @@ CVE-2026-73086 (nanoid is a secure, URL-friendly, unique
string ID generator for
NOTE: Fixed by:
https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3
(3.3.12)
NOTE: Fixed by:
https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac
(3.3.12)
CVE-2026-73085 (Audiobookshelf is a self-hosted audiobook and podcast server.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Audiobookshelf
CVE-2026-73084 (Activepieces is an open source AI workflow automation
platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73083 (Activepieces is an open source AI workflow automation
platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73082 (Activepieces is an open source AI workflow automation
platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73081 (Activepieces is an open source AI workflow automation
platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73080 (SeaweedFS is a distributed storage system. Prior to 4.24,
VolumeServer ...)
TODO: check
CVE-2026-73079 (Sub2API is an AI API gateway platform designed to distribute
and manag ...)
- TODO: check
+ NOT-FOR-US: Sub2API
CVE-2026-73078 (Vim is an open source, command line text editor. Prior to
9.2.0840, ru ...)
TODO: check
CVE-2026-73077 (Vim is an open source, command line text editor. Prior to
9.2.0839, th ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef68c29444e161ddd9f1cb27b70abca0a7e5484a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef68c29444e161ddd9f1cb27b70abca0a7e5484a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits