Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3ad24b8c by Salvatore Bonaccorso at 2026-08-11T22:30:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -146,9 +146,9 @@ CVE-2026-73070 (Vim is an open source, command line text
editor. Prior to 9.2.08
NOTE: https://github.com/vim/vim/security/advisories/GHSA-49m8-wwxj-mr69
NOTE: Fixed by:
https://github.com/vim/vim/commit/5598618b2daf8e36b3bf0251caaefcf0bf8e85e4
(v9.2.0842)
CVE-2026-73069 (Twenty is an open-source CRM (customer relationship
management) platfo ...)
- TODO: check
+ NOT-FOR-US: Twenty CRM
CVE-2026-73068 (ToolJet is the open-source foundation am AI-native platform
for buildi ...)
- TODO: check
+ NOT-FOR-US: ToolJet
CVE-2026-73067 (Tesseract is an open source OCR engine. Prior to 5.5.3, a
crafted .tra ...)
- tesseract <unfixed>
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h
@@ -165,7 +165,7 @@ CVE-2026-72971 (Improper link resolution before file access
('link following') i
CVE-2026-72925 (SWC is a TypeScript / JavaScript compiler written in Rust.
Prior to @s ...)
TODO: check
CVE-2026-72922 (AutoGPT is a workflow automation platform for creating,
deploying, and ...)
- TODO: check
+ NOT-FOR-US: AutoGPT
CVE-2026-72921 (SeaweedFS is a distributed storage system. Prior to 4.24, the
weed/ser ...)
- seaweedfs <itp> (bug #956957)
CVE-2026-72920 (SeaweedFS is a distributed storage system. Prior to 4.24, the
filer re ...)
@@ -219,9 +219,9 @@ CVE-2026-72750 (n8n before 1.123.67, 2.31.5, and 2.32.1
contains a SQL injection
CVE-2026-72749 (n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype
pollution ...)
NOT-FOR-US: n8n
CVE-2026-72748 (AVideo contains an unauthenticated arbitrary file write
vulnerability ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-72747 (AVideo fails to sanitize the phone field during user
registration, all ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-72746 (FreeRDP before 3.30.0 contains a server-side authentication
bypass in ...)
- freerdp3 3.30.0+dfsg-1
- freerdp2 <not-affected> (Vulnerable code ot present)
@@ -232,11 +232,11 @@ CVE-2026-72745 (FreeRDP before 3.30.0 contains an
out-of-bounds vulnerability in
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
CVE-2026-72744 (Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and <
3.21.10, conta ...)
- TODO: check
+ NOT-FOR-US: Nuxt
CVE-2026-72742 (DSPy 3.3.0b1 contains a file exfiltration vulnerability in the
Image a ...)
- TODO: check
+ NOT-FOR-US: DSPy
CVE-2026-72713 (XAgent contains a path traversal vulnerability in the
workspace file e ...)
- TODO: check
+ NOT-FOR-US: XAgent
CVE-2026-72712 (Nmap versions up to and including 7.99 contains a denial of
service vu ...)
TODO: check
CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a
root us ...)
@@ -1913,7 +1913,7 @@ CVE-2026-72874 (Dokploy is a free, self-hostable Platform
as a Service (PaaS). P
CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
NOT-FOR-US: Dokploy
CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a
stored cros ...)
- TODO: check
+ NOT-FOR-US: SQLBot
CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an
authenticated c ...)
TODO: check
CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an
authenticated r ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ad24b8c2a7ca9add7ec474d9e567cf5a6b1480a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ad24b8c2a7ca9add7ec474d9e567cf5a6b1480a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits