Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d6c506bb by security tracker role at 2026-08-12T19:13:55+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,18 +1,404 @@
-CVE-2026-59242
+CVE-2026-8667 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-7427 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-73432 (Vulnerability-Lookup contains a server-side request forgery 
(SSRF) vul ...)
+       TODO: check
+CVE-2026-73431 (Vulnerability-Lookup contains an  authentication weakness in 
its accou ...)
+       TODO: check
+CVE-2026-73405 (An authorization bypass vulnerability in Vulnerability-Lookup 
allowed  ...)
+       TODO: check
+CVE-2026-73374 (A stored cross-site scripting (XSS) vulnerability existed in 
Vulnerabi ...)
+       TODO: check
+CVE-2026-73327 (Joomla 6.1.1 contains a path traversal vulnerability in the 
com_joomla ...)
+       TODO: check
+CVE-2026-73325 (Fujitsu Research's OneCompression library 1.2.0 contains an 
unsafe des ...)
+       TODO: check
+CVE-2026-73301 (Budibase is an open-source low-code platform. Prior to 
3.39.25, the GE ...)
+       TODO: check
+CVE-2026-73300 (Budibase is an open-source low-code platform. Prior to 3.40.0, 
the MyS ...)
+       TODO: check
+CVE-2026-73299 (Prompty is a markdown file format (.prompty) for LLM prompts. 
Prior to ...)
+       TODO: check
+CVE-2026-73298 (The Microsoft Container Migration Solution Accelerator is a 
multi-serv ...)
+       TODO: check
+CVE-2026-73297 (Microsoft UFO open-source framework for intelligent automation 
across  ...)
+       TODO: check
+CVE-2026-73296 (Microsoft UFO open-source framework for intelligent automation 
across  ...)
+       TODO: check
+CVE-2026-73295 (Material for MkDocs is a powerful documentation framework 
built on top ...)
+       TODO: check
+CVE-2026-73294 (Semaphore UI is a web interface for managing DevOps tools. 
Prior to 2. ...)
+       TODO: check
+CVE-2026-73293 (Semaphore UI is a web interface for managing DevOps tools.  
Prior to 2 ...)
+       TODO: check
+CVE-2026-73292 (Semaphore UI is a web interface for managing DevOps tools. 
Prior to 2. ...)
+       TODO: check
+CVE-2026-73291 (Seerr is an open-source media request and discovery manager 
for Jellyf ...)
+       TODO: check
+CVE-2026-73290 (RustFS is a distributed object storage system built in Rust. 
Prior to  ...)
+       TODO: check
+CVE-2026-73289 (RustFS is a distributed object storage system built in Rust. 
Prior to  ...)
+       TODO: check
+CVE-2026-73288 (RustFS is a distributed object storage system built in Rust. 
Prior to  ...)
+       TODO: check
+CVE-2026-73287 (RustFS is a distributed object storage system built in Rust. 
Prior to  ...)
+       TODO: check
+CVE-2026-73286 (RustFS is a distributed object storage system built in Rust. 
Prior to  ...)
+       TODO: check
+CVE-2026-73285 (RustFS is a distributed object storage system built in Rust. 
From 1.0. ...)
+       TODO: check
+CVE-2026-73284 (RustFS is a distributed object storage system built in Rust. 
RustFS Ad ...)
+       TODO: check
+CVE-2026-73265 (RustFS is a distributed object storage system built in Rust. 
RustFS au ...)
+       TODO: check
+CVE-2026-73264 (Prowler is a cloud security platform. Prior to 5.33.1, an 
authenticate ...)
+       TODO: check
+CVE-2026-73263 (Prowler is a cloud security platform. Prior to 5.36.0, the 
Kubernetes  ...)
+       TODO: check
+CVE-2026-73262 (Prowler is a cloud security platform. Prior to 5.37.0, 
Prowler's HTML  ...)
+       TODO: check
+CVE-2026-73240 (Specifically crafted inputs may lead to git argument injection 
in Apac ...)
+       TODO: check
+CVE-2026-73239 (Insecure Direct Object Reference (IDOR) due to missing 
permission chec ...)
+       TODO: check
+CVE-2026-73238 (XSS vulnerability in code display in Apache Allura.  This 
issue affect ...)
+       TODO: check
+CVE-2026-73237 (XSS vulnerability in Markdown handling in Apache Allura.  This 
issue a ...)
+       TODO: check
+CVE-2026-71408 (A allocation of resources without limits or throttling 
vulnerability i ...)
+       TODO: check
+CVE-2026-71407 (A Stack-based Buffer Overflow vulnerability [CWE-121] 
vulnerability in ...)
+       TODO: check
+CVE-2026-70560 (Ultimate POS (Stock Management & Point of Sale) contains a 
stored cros ...)
+       TODO: check
+CVE-2026-70547 (An authenticated user without repository read permission may 
access pa ...)
+       TODO: check
+CVE-2026-70468 (A authentication bypass using an alternate path or channel 
vulnerabili ...)
+       TODO: check
+CVE-2026-70467 (A server-side request forgery (ssrf) vulnerability in Fortinet 
FortiSI ...)
+       TODO: check
+CVE-2026-70466 (A incomplete list of disallowed inputs vulnerability in 
Fortinet Forti ...)
+       TODO: check
+CVE-2026-70465 (A buffer copy without checking size of input ('classic buffer 
overflow ...)
+       TODO: check
+CVE-2026-69107 (An unauthenticated user may access restricted artifacts in 
JFrog Artif ...)
+       TODO: check
+CVE-2026-69106 (A low-privileged user may poison cached artifact metadata 
under specif ...)
+       TODO: check
+CVE-2026-69105 (An unauthenticated attacker may cause untrusted package 
content to be  ...)
+       TODO: check
+CVE-2026-68760 (An unauthenticated user may bypass authentication under 
specific cache ...)
+       TODO: check
+CVE-2026-68759 (A holder of a valid integration credential may impersonate 
other users ...)
+       TODO: check
+CVE-2026-68758 (A low-privileged authenticated user may access restricted 
support info ...)
+       TODO: check
+CVE-2026-68757 (A user with access to a valid SAML response may impersonate 
another us ...)
+       TODO: check
+CVE-2026-68756 (A party with write access to stored session data may affect 
JFrog Arti ...)
+       TODO: check
+CVE-2026-68755 (A bundle writer may create misleading release promotion 
information un ...)
+       TODO: check
+CVE-2026-68754 (A repository publisher without delete permission may modify 
protected  ...)
+       TODO: check
+CVE-2026-68753 (An unauthenticated user may access restricted Artifactory 
content when ...)
+       TODO: check
+CVE-2026-68752 (A Project Resource Manager may gain broader administrative 
privileges  ...)
+       TODO: check
+CVE-2026-67587 (Apache Airflow's Task SDK rebuilt a `Callback` object from 
serialized  ...)
+       TODO: check
+CVE-2026-67287 (Joomla Extension - joomshaper.com - Unauthenticated comment 
creation i ...)
+       TODO: check
+CVE-2026-67286 (Joomla Extension - joomshaper.com - Unauthenticated arbitrary 
director ...)
+       TODO: check
+CVE-2026-67285 (Joomla Extension - joomshaper.com - Unauthenticated arbitrary 
local PH ...)
+       TODO: check
+CVE-2026-67284 (Joomla Extension - tabaoca.org - Improper ACL implementation 
allows fi ...)
+       TODO: check
+CVE-2026-67283 (Joomla Extension - tabaoca.org - Improper ACL implementation 
allows fi ...)
+       TODO: check
+CVE-2026-67282 (Joomla Extension - fabrikar.com - Unauthenticated remote code 
executio ...)
+       TODO: check
+CVE-2026-67260 (Apache Airflow 3.3.0 moved human-in-the-loop tasks from the 
triggerer  ...)
+       TODO: check
+CVE-2026-66384 (An authenticated user may write data outside the intended 
Docker cache ...)
+       TODO: check
+CVE-2026-66382 (An authenticated user may write files outside the intended 
Artifactory ...)
+       TODO: check
+CVE-2026-66381 (A repository reader with cache-deploy permission may access 
content ou ...)
+       TODO: check
+CVE-2026-66380 (An authenticated user without repository read permission may 
access pr ...)
+       TODO: check
+CVE-2026-66379 (An authenticated user may view private Puppet module metadata 
without  ...)
+       TODO: check
+CVE-2026-66378 (An authenticated user without repository read permission may 
access pr ...)
+       TODO: check
+CVE-2026-66377 (An unauthenticated user may access restricted repository 
information u ...)
+       TODO: check
+CVE-2026-66376 (Credentials for a deleted user may remain valid for a short 
period und ...)
+       TODO: check
+CVE-2026-66375 (A low-privilege authenticated user may permanently remove 
protected in ...)
+       TODO: check
+CVE-2026-66016 (Under specific self-hosted Helm configurations, generated TLS 
private  ...)
+       TODO: check
+CVE-2026-65941 (In WhatsUp Gold versions released before 2026.0.2,an 
unauthenticated r ...)
+       TODO: check
+CVE-2026-65940 (In WhatsUp Gold versions released before 2026.0.2, a 
privileged attack ...)
+       TODO: check
+CVE-2026-65939 (In WhatsUp Gold versions released before 2026.0.2,a privileged 
attacke ...)
+       TODO: check
+CVE-2026-65938 (In WhatsUp Gold versions released before 2026.0.2,an 
improperauthoriza ...)
+       TODO: check
+CVE-2026-65937 (In WhatsUp Gold versions released before 2026.0.2, an 
authenticated at ...)
+       TODO: check
+CVE-2026-65926 (An anonymous caller when anonymous access is enabled, or a 
low-privile ...)
+       TODO: check
+CVE-2026-64955 (When Microsoft Excel imports a CSV file, it executes cells 
beginning w ...)
+       TODO: check
+CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts.  
Velociraptor mi ...)
+       TODO: check
+CVE-2026-64951 (A rogue Velociraptor client can upload a malformed sparse file 
such th ...)
+       TODO: check
+CVE-2026-64639 (Incorrect database cloning process in Plesk from 18.0.52 
before 18.0.7 ...)
+       TODO: check
+CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception 
nodes by  ...)
+       TODO: check
+CVE-2026-57858 (Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored 
cross-si ...)
+       TODO: check
+CVE-2026-54183 (Apache Airflow's secrets masker hides values stored under 
sensitive ke ...)
+       TODO: check
+CVE-2026-53996 (NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c 
contains a mis ...)
+       TODO: check
+CVE-2026-50561 (Yuxi is a large-model-based intelligent knowledge base and 
knowledge g ...)
+       TODO: check
+CVE-2026-49467 (Pingvin Share X is a secure and easy self-hosted file sharing 
platform ...)
+       TODO: check
+CVE-2026-49349 (regclient is a Docker and OCI Registry Client in Go. Prior to 
version  ...)
+       TODO: check
+CVE-2026-49262 (In the Aimeos Pagible content management system prior to 
version 0.10. ...)
+       TODO: check
+CVE-2026-48554 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are 
vulnerable ...)
+       TODO: check
+CVE-2026-48553 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are 
vulnerable ...)
+       TODO: check
+CVE-2026-48552 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are 
vulnerable ...)
+       TODO: check
+CVE-2026-48551 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 
contain a cros ...)
+       TODO: check
+CVE-2026-48550 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are 
vulnerable ...)
+       TODO: check
+CVE-2026-47234 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
+       TODO: check
+CVE-2026-47233 (Admidio is an open-source user management solution. Version 
5.0.9 adde ...)
+       TODO: check
+CVE-2026-47232 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
+       TODO: check
+CVE-2026-47231 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
+       TODO: check
+CVE-2026-47230 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
+       TODO: check
+CVE-2026-47229 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
+       TODO: check
+CVE-2026-47228 (Admidio is an open-source user management solution. 
`modules/registrat ...)
+       TODO: check
+CVE-2026-47227 (Admidio is an open-source user management solution. 
`modules/categorie ...)
+       TODO: check
+CVE-2026-47226 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
+       TODO: check
+CVE-2026-44741 (Pimcore's Admin Classic Bundle provides a Backend UI for 
Pimcore. Vers ...)
+       TODO: check
+CVE-2026-42018 (JFrog Artifactory could return an internal anonymous-user 
token to an  ...)
+       TODO: check
+CVE-2026-26035 (An Improper Authentication vulnerability [CWE-287] 
vulnerability in Fo ...)
+       TODO: check
+CVE-2026-19548 (Multiple Use-After-Free vulnerabilities were found in the 
add_archive_ ...)
+       TODO: check
+CVE-2026-19426 (POS System developed by FitSoft has a Missing Authentication 
vulnerabi ...)
+       TODO: check
+CVE-2026-19311 (Missing authorization in the Execute Monitor API in Amazon 
OpenSearch  ...)
+       TODO: check
+CVE-2026-18952 (Missing input validation in the threat intelligence feed 
parser in the ...)
+       TODO: check
+CVE-2026-18847 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
unauthenticated atta ...)
+       TODO: check
+CVE-2026-18713 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege 
escalation via  ...)
+       TODO: check
+CVE-2026-18683 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege 
escalation via ...)
+       TODO: check
+CVE-2026-18678 (When an operator adds an HTTPS control plane profile to 
kumactl withou ...)
+       TODO: check
+CVE-2026-18677 (In Kong Mesh running in universal mode with a MeshIdentity 
whose SPIFF ...)
+       TODO: check
+CVE-2026-18676 (The default kuma-cp configuration in Kong Mesh reveals the 
admin boots ...)
+       TODO: check
+CVE-2026-18675 (The dataplane token validator in kuma-cp performs an unchecked 
Go type ...)
+       TODO: check
+CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix 
domain s ...)
+       TODO: check
+CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege 
escalation a ...)
+       TODO: check
+CVE-2026-18663 (A flaw was found in 389-ds-base. The 
get_ldapmessage_controls_ext() fu ...)
+       TODO: check
+CVE-2026-18652 (Velociraptor allows reading Stacked result sets from the GUI. 
Velocira ...)
+       TODO: check
+CVE-2026-18499 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 i ...)
+       TODO: check
+CVE-2026-18250 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18246 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18244 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-18235 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18171 (Docker Sandboxes (sbx) applies the read-only intent of a 
runtime host  ...)
+       TODO: check
+CVE-2026-18144 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18106 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18098 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-18044 (The Estatik Real Estate Plugin WordPress plugin before 4.3.4 
does not  ...)
+       TODO: check
+CVE-2026-17420 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17419 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17418 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
+       TODO: check
+CVE-2026-17276 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17271 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
+       TODO: check
+CVE-2026-17268 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17266 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17248 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17222 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17218 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
execute  ...)
+       TODO: check
+CVE-2026-17110 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17109 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17095 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17094 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-17008 (The Quick Paypal Payments WordPress plugin through 5.7.50 does 
not ver ...)
+       TODO: check
+CVE-2026-16999 (Improper restriction of XML external entity reference 
vulnerability in ...)
+       TODO: check
+CVE-2026-16990 (The Payment Button for PayPal WordPress plugin through 
1.2.3.44 does n ...)
+       TODO: check
+CVE-2026-16956 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
+       TODO: check
+CVE-2026-16931 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
+       TODO: check
+CVE-2026-16907 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-16906 (IBM i 7.6, and 7.5 could allow a remote authenticated attacker 
to exec ...)
+       TODO: check
+CVE-2026-16904 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-16863 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-16860 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
+       TODO: check
+CVE-2026-16856 (IBM i 7.6, and 7.5 could allow a local attacker to gain 
elevated privi ...)
+       TODO: check
+CVE-2026-16747 (The Kirki WordPress plugin before 6.2.1 does not properly 
authorise it ...)
+       TODO: check
+CVE-2026-16694 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored 
cross-site script ...)
+       TODO: check
+CVE-2026-16627 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-16621 (The Payment Gateway for PayPal on WooCommerce WordPress plugin 
before  ...)
+       TODO: check
+CVE-2026-15803 (In Eclipse RDF4J, several XML parser entry points do not fully 
restric ...)
+       TODO: check
+CVE-2026-15423 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-15213 (The Welcart e-Commerce WordPress plugin before 2.11.33 does 
not verify ...)
+       TODO: check
+CVE-2026-15045 (The Wallet System for WooCommerce WordPress plugin before 
2.7.10 does  ...)
+       TODO: check
+CVE-2026-14479 (A maliciously crafted input, when processed by the Autodesk 
Installer  ...)
+       TODO: check
+CVE-2026-14478 (A maliciously created executable, when executed on the 
victim's machin ...)
+       TODO: check
+CVE-2026-11325 (Description    Cloudflare was recently notified by external 
researcher ...)
+       TODO: check
+CVE-2025-59327 (In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, 
bootxsa.efi ...)
+       TODO: check
+CVE-2025-59326 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to enforc ...)
+       TODO: check
+CVE-2025-59325 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to encryp ...)
+       TODO: check
+CVE-2025-59324 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to proper ...)
+       TODO: check
+CVE-2025-59323 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to valida ...)
+       TODO: check
+CVE-2025-59322 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to proper ...)
+       TODO: check
+CVE-2025-59321 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 
contains a defa ...)
+       TODO: check
+CVE-2025-59320 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores 
TPM2.0 s ...)
+       TODO: check
+CVE-2025-59319 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to certif ...)
+       TODO: check
+CVE-2025-41771 (An authenticated attacker with low privileges can access an 
endpoint i ...)
+       TODO: check
+CVE-2025-41770 (An unauthenticated denial-of-service vulnerability in the 
device's PLC ...)
+       TODO: check
+CVE-2025-41769 (The device's PROFINET service is affected by a buffer overflow 
vulnera ...)
+       TODO: check
+CVE-2025-35988
+       REJECTED
+CVE-2025-35977
+       REJECTED
+CVE-2025-32737
+       REJECTED
+CVE-2025-32087
+       REJECTED
+CVE-2025-32084
+       REJECTED
+CVE-2025-31943
+       REJECTED
+CVE-2025-30178
+       REJECTED
+CVE-2025-27570
+       REJECTED
+CVE-2025-27245
+       REJECTED
+CVE-2025-25275
+       REJECTED
+CVE-2025-24837
+       REJECTED
+CVE-2025-24488
+       REJECTED
+CVE-2025-20020
+       REJECTED
+CVE-2026-59242 (Apache Airflow's XCom `GET 
/api/v2/{...}/xcomEntries/{key}?deserialize ...)
        - airflow <itp> (bug #819700)
-CVE-2026-59244
+CVE-2026-59244 (Apache Airflow's secrets masker did not mask `var.json` 
Variable value ...)
        - airflow <itp> (bug #819700)
-CVE-2026-68968
+CVE-2026-68968 (Apache Airflow's Backfill API authorized a request against a 
Dag id su ...)
        - airflow <itp> (bug #819700)
-CVE-2026-65017
+CVE-2026-65017 (Apache Airflow's Config API did not mask team-scoped sensitive 
configu ...)
        - airflow <itp> (bug #819700)
-CVE-2026-68076
+CVE-2026-68076 (Apache Airflow's environment-variable secrets backend resolved 
a team- ...)
        - airflow <itp> (bug #819700)
-CVE-2026-68971
+CVE-2026-68971 (Apache Airflow's asset materialization endpoint (`POST 
/api/v2/assets/ ...)
        - airflow <itp> (bug #819700)
-CVE-2026-68970
+CVE-2026-68970 (Apache Airflow's Task SDK did not mask the contents of a 
Variable whos ...)
        - airflow <itp> (bug #819700)
-CVE-2026-68969
+CVE-2026-68969 (Apache Airflow wrote Variable values and Connection `extra` 
contents t ...)
        - airflow <itp> (bug #819700)
 CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access 
controls]
        - ironic 1:35.0.1-10
@@ -28,7 +414,7 @@ CVE-2026-12072
 CVE-2026-12074
        - nltk <unfixed>
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-xh95-f55m-82fw
-CVE-2026-68868
+CVE-2026-68868 (The Google Cloud Secret Manager secrets backend in Apache 
Airflow's Go ...)
        NOT-FOR-US: Apache Airflow provider
 CVE-2026-52073 [ppp_handle_ipcp attacker-controlled IPCP length -- OOB read]
        - mongoose 7.22+ds-1
@@ -88,7 +474,7 @@ CVE-2026-52060 [TLS certificate notAfter validated against 
hardcoded 2025-01-01
        - mongoose 7.22+ds-1
 CVE-2026-52059 [RSA-PSS CertificateVerify checks only 0xbc trailer]
        - mongoose 7.22+ds-1
-CVE-2026-19566
+CVE-2026-19566 (Net::CIDR::Set versions before 0.23 for Perl allow memory 
exhaustion a ...)
        - libnet-cidr-set-perl 0.23-1
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42620063/
        NOTE: 
https://github.com/robrwo/perl-Net-CIDR-Set/security/advisories/GHSA-grjr-r4x5-mx4p
@@ -729,12 +1115,14 @@ CVE-2026-72748 (AVideo contains an unauthenticated 
arbitrary file write vulnerab
        NOT-FOR-US: WWBN AVideo
 CVE-2026-72747 (AVideo fails to sanitize the phone field during user 
registration, all ...)
        NOT-FOR-US: WWBN AVideo
-CVE-2026-72746 (FreeRDP before 3.30.0 contains a server-side authentication 
bypass in  ...)
+CVE-2026-72746
+       REJECTED
        - freerdp3 3.30.0+dfsg-1
        - freerdp2 <not-affected> (Vulnerable code ot present)
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x
        NOTE: Fixed by: 
https://github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695
 (3.30.0)
-CVE-2026-72745 (FreeRDP before 3.30.0 contains an out-of-bounds vulnerability 
in kerbe ...)
+CVE-2026-72745
+       REJECTED
        - freerdp3 3.30.0+dfsg-1
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
@@ -1149,7 +1537,7 @@ CVE-2026-65678 (Use after free in Windows Win32K allows 
an authorized attacker t
        NOT-FOR-US: Microsoft
 CVE-2026-65675 (No cwe for this issue in Visual Studio Code CoPilot Chat 
Extension all ...)
        NOT-FOR-US: Microsoft
-CVE-2026-65673 (Entra Connect Elevation of Privilege Vulnerability)
+CVE-2026-65673 (Improper neutralization of special elements used in an sql 
command ('s ...)
        NOT-FOR-US: Microsoft
 CVE-2026-65672 (Heap-based buffer overflow in Windows Remote Access API allows 
an auth ...)
        NOT-FOR-US: Microsoft
@@ -2747,6 +3135,7 @@ CVE-2025-13294 (An unauthenticated SQL injection 
vulnerability exists in the web
 CVE-2025-13293 (A hard-coded or default root account credential in TBEA 
TLogger V2.1.0 ...)
        NOT-FOR-US: TBEA TLogger
 CVE-2026-19349
+       {DSA-6434-1 DLA-4734-1}
        - lemonldap-ng 2.23.3+ds-1
        NOTE: 
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d
 (v2.23.3)
        NOTE: 
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/eef2aa31ad26c685769c9602588bb85572da0c00
 (v2.23.3)
@@ -5055,7 +5444,7 @@ CVE-2026-15238 (The MotoPress Hotel Booking WordPress 
plugin before 6.2.3 does n
        NOT-FOR-US: WordPress plugin
 CVE-2026-15237 (The MotoPress Hotel Booking WordPress plugin before 6.2.3 does 
not per ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-15229 (The Pinpoint Booking System  WordPress plugin through 
2.9.9.6.9 does n ...)
+CVE-2026-15229 (The Pinpoint Booking System  WordPress plugin through 
2.9.9.7.1 does n ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15047 (The s2Member  WordPress plugin before 260805 does not escape 
several s ...)
        NOT-FOR-US: WordPress plugin
@@ -10514,6 +10903,7 @@ CVE-2026-62313 [Project isolation restriction bypass by 
omitting security.idmap.
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
        NOTE: https://github.com/lxc/incus/pull/3750
 CVE-2026-55707 (In OpenStack Neutron before 28.0.2, the subnetpool onboarding 
API does ...)
+       {DLA-4735-1}
        - neutron 2:28.0.1-2 (bug #1143170)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-032.html
        NOTE: https://bugs.launchpad.net/neutron/+bug/2152113
@@ -47214,6 +47604,7 @@ CVE-2026-56236 (Capgo CLI before 12.128.2 contains 
arbitrary file overwrite vuln
 CVE-2026-56229 (Capgo before 12.128.2 contains an authorization bypass 
vulnerability i ...)
        NOT-FOR-US: Cap-go
 CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. 
Impacted is ...)
+       {DSA-6434-1 DLA-4734-1}
        - lemonldap-ng 2.23.1+ds-1
        NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
        NOTE: 
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6c506bb3988a4220109c5a93bcac89565ae8b4a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6c506bb3988a4220109c5a93bcac89565ae8b4a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to