Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a5f7263f by Salvatore Bonaccorso at 2026-08-13T14:34:28+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -67,13 +67,13 @@ CVE-2026-73429 (Russh is a Rust SSH client & server 
library. Prior to 0.62.4, a
        NOTE: 
https://github.com/Eugeny/russh/security/advisories/GHSA-g9hv-x236-4qp3
        NOTE: Fixed by: 
https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d 
(v0.62.4)
 CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
-       TODO: check
+       NOT-FOR-US: Trix
 CVE-2026-73425 (Astro is a web framework for content-driven websites. Prior to 
8.1.2,  ...)
-       TODO: check
+       NOT-FOR-US: Astro
 CVE-2026-73423 (Astro is a web framework for content-driven websites. From 
7.0.0 until ...)
-       TODO: check
+       NOT-FOR-US: Astro
 CVE-2026-73422 (Astro is a web framework for content-driven websites. From 
2.9.0 until ...)
-       TODO: check
+       NOT-FOR-US: Astro
 CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior 
to@auth/core 0. ...)
        NOT-FOR-US: Next.js
 CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to 
@auth/core 0 ...)
@@ -165,15 +165,15 @@ CVE-2026-72787 (Craft CMS versions before 5.10.8 contain 
a stored cross-site scr
 CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication 
bypass vuln ...)
        NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription 
component of ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Advanced Cluster Management (RHACM)
 CVE-2026-72506 (VoiceTra provided by National Institute of Information and 
Communicati ...)
-       TODO: check
+       NOT-FOR-US: VoiceTra
 CVE-2026-71846 (A flaw was found in insights-client. The component's 
ServiceAccount is ...)
        TODO: check
 CVE-2026-71473 (A flaw was found in the `search-v2-operator` component. A user 
with sp ...)
        TODO: check
 CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with 
administrati ...)
-       TODO: check
+       NOT-FOR-US: acm-search-v2-rhel9
 CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker 
can exp ...)
        TODO: check
 CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
@@ -584,7 +584,7 @@ CVE-2026-71408 (A allocation of resources without limits or 
throttling vulnerabi
 CVE-2026-71407 (A Stack-based Buffer Overflow vulnerability [CWE-121] 
vulnerability in ...)
        NOT-FOR-US: Fortinet
 CVE-2026-70560 (Ultimate POS (Stock Management & Point of Sale) contains a 
stored cros ...)
-       TODO: check
+       NOT-FOR-US: Ultimate POS (Stock Management & Point of Sale)
 CVE-2026-70547 (An authenticated user without repository read permission may 
access pa ...)
        TODO: check
 CVE-2026-70468 (A authentication bypass using an alternate path or channel 
vulnerabili ...)
@@ -1889,11 +1889,11 @@ CVE-2026-69278 (Incorrect authorization in Visual 
Studio Code allows an unauthor
 CVE-2026-69223 (Apache Allura's webhooks are vulnerable toServer-Side Request 
Forgery  ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-69119 (Taubyte Tau v1.1.10 contains a missing authorization 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Taubyte Tau
 CVE-2026-69117 (NetBox 4.5.8 contains an ORM injection vulnerability that 
allows authe ...)
        TODO: check
 CVE-2026-69115 (OpenIM Server v3.8.3 contains a missing authorization 
vulnerability th ...)
-       TODO: check
+       NOT-FOR-US: OpenIM Server
 CVE-2026-69113 (Cap v0.3.1 contains a broken access control vulnerability in 
the POST  ...)
        TODO: check
 CVE-2026-69109 (A vulnerability has been identified in Siemens License Server 
(SLS) (A ...)
@@ -3462,7 +3462,7 @@ CVE-2026-69118 (Cachet through 2.4.1 contains a 
server-side template injection v
 CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown 
rendering an ...)
        NOT-FOR-US: FlyEnv
 CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel 
message ...)
-       TODO: check
+       NOT-FOR-US: Spacebar Server
 CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path 
traversal vulne ...)
        NOT-FOR-US: Hugging Face Accelerate
 CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP 
NetWeaver App ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f7263fdb892fbe6e70b8e4f7a2b3e89110f5e8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f7263fdb892fbe6e70b8e4f7a2b3e89110f5e8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to