Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
110e77f0 by Moritz Muehlenhoff at 2026-08-12T20:20:51+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,19 @@
+CVE-2026-59242
+ - airflow <itp> (bug #819700)
+CVE-2026-59244
+ - airflow <itp> (bug #819700)
+CVE-2026-68968
+ - airflow <itp> (bug #819700)
+CVE-2026-65017
+ - airflow <itp> (bug #819700)
+CVE-2026-68076
+ - airflow <itp> (bug #819700)
+CVE-2026-68971
+ - airflow <itp> (bug #819700)
+CVE-2026-68970
+ - airflow <itp> (bug #819700)
+CVE-2026-68969
+ - airflow <itp> (bug #819700)
CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access
controls]
- ironic 1:35.0.1-10
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
@@ -132,7 +148,7 @@ CVE-2026-73233 (FreeCAD is a free and open-source
multiplatform 3D parametric mo
CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf
allows a ...)
TODO: check
CVE-2026-73231 (Faker generates massive amounts of fake data in the browser
and Node.j ...)
- TODO: check
+ NOT-FOR-US: Faker
CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security
tools. ...)
NOT-FOR-US: Ente
CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for
building ...)
@@ -231,7 +247,7 @@ CVE-2026-48763 (TypeBot is a chatbot builder tool. Versions
prior to 3.17.0 expo
CVE-2026-48762 (TypeBot is a chatbot builder tool. Prior to version 3.16.0,
the OpenAI ...)
NOT-FOR-US: TypeBot
CVE-2026-45618 (LiquidJS is a Shopify/GitHub Pages compatible template engine.
Prior t ...)
- TODO: check
+ NOT-FOR-US: LiquidJS
CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19 contain an
incorrectly-resolved na ...)
TODO: check
CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer
overflow v ...)
@@ -243,7 +259,7 @@ CVE-2026-19588 (Integer Overflow to Buffer Overflow
vulnerability in Samsung Ope
CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung
Open Source ...)
TODO: check
CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass
(insecure direc ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command
is gated ...)
TODO: check
CVE-2026-19217 (The Royal Addons for Elementor WordPress plugin before
1.7.1065 does ...)
@@ -263,7 +279,7 @@ CVE-2026-18961 (The Social Login, Passkeys, Magic Link &
Email OTP \u2013 Passwo
CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not
have auth ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts
several undi ...)
- TODO: check
+ NOT-FOR-US: Pulsetto Vagus Nerve Stimulator
CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly
restrict ac ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18710 (A MongoDB driver component could write sensitive configuration
informa ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/110e77f056e689171115b6974dbb90206d14ce37
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/110e77f056e689171115b6974dbb90206d14ce37
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits