Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4ba19497 by security tracker role at 2026-08-14T07:15:02+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -51,9 +51,9 @@ CVE-2026-73479 (dua-cli fails to filter terminal escape 
sequences when printing
 CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
        TODO: check
 CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From 
next-auth 5.0.0- ...)
-       TODO: check
+       NOT-FOR-US: Next.js
 CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to 
@auth/core 0 ...)
-       TODO: check
+       NOT-FOR-US: Next.js
 CVE-2026-73417 (jupyterlab is an extensible environment for interactive and 
reproducib ...)
        TODO: check
 CVE-2026-73416 (jupyterlab is an extensible environment for interactive and 
reproducib ...)
@@ -93,23 +93,23 @@ CVE-2026-72839 (filebrowser through 2.63.16 fails to 
properly restrict scope and
 CVE-2026-72776 (AgenticSeek (commit fc242c7) contains an unauthenticated 
remote code e ...)
        TODO: check
 CVE-2026-72687 (A flaw in Elasticsearch allows a low-privileged authenticated 
user to  ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72686 (A flaw in Elasticsearch allows a low-privileged authenticated 
user to  ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72685 (A flaw in Elasticsearch allows a low-privileged authenticated 
user who ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72684 (A flaw in Elasticsearch allows an authenticated user holding 
only read ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72683 (A flaw in Elasticsearch allows an authenticated user with the 
privileg ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72681 (Kibana Agent Builder does not correctly verify that the 
requesting use ...)
        TODO: check
 CVE-2026-72680 (Kibana Agent Builder A2A JSON-RPC API endpoint derives the 
identifier  ...)
        TODO: check
 CVE-2026-72679 (Elasticsearch does not apply its configurable input length 
restriction ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72678 (Elasticsearch does not validate a size value taken from a 
user-supplie ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the 
unauthorize ...)
        TODO: check
 CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') 
(CWE-94) in  ...)
@@ -149,7 +149,7 @@ CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in 
Kibana can lead to privi
 CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in 
Fleet Se ...)
        TODO: check
 CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the 
ES|QL que ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined 
Object At ...)
        TODO: check
 CVE-2026-72653 (Allocation of Resources Without Limits or Throttling (CWE-770) 
in Kiba ...)
@@ -161,21 +161,21 @@ CVE-2026-72650 (Authorization Bypass Through 
User-Controlled Key (CWE-639) in Ki
 CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment 
Variable  ...)
        TODO: check
 CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to 
denial o ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in 
Elasticsearch ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72643 (Kibana Agent Builder determines whether a caller owns a 
private agent  ...)
        TODO: check
 CVE-2026-72642 (The native inference process that Elasticsearch uses to 
evaluate uploa ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of 
secret  ...)
        TODO: check
 CVE-2026-72639 (Elasticsearch does not enforce an upper bound on a 
user-supplied count ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to 
denial o ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72636 (Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard 
matchin ...)
-       TODO: check
+       NOT-FOR-US: Elasticsearch
 CVE-2026-72632 (Observable Discrepancy (CWE-203) in Kibana Fleet can lead to 
informati ...)
        TODO: check
 CVE-2026-72631 (Improper Privilege Management (CWE-269) in Kibana Fleet can 
lead to pr ...)
@@ -199,19 +199,19 @@ CVE-2026-45725 (compliance-trestle is a tooling platform 
for managing compliance
 CVE-2026-3883
        REJECTED
 CVE-2026-19811 (A security flaw has been discovered in TOTOLINK A800R 
4.1.2cu.5137_B20 ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-19792 (A security flaw has been discovered in Tenda G0 up to 
20260625. Impact ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19791 (A weakness has been identified in Tenda G0 up to 20260625. The 
affecte ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19790 (A vulnerability was identified in Tenda G0 up to 20260625. 
This issue  ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19789 (A vulnerability was determined in Tenda AC1206 
15.03.06.23_multi_TD01. ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19788 (A vulnerability was found in Tenda AC1206 
15.03.06.23_multi_TD01. This ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19787 (A vulnerability was determined in SourceCodester Air Cargo 
Management  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-19786 (A vulnerability was found in francoisjacquet RosarioSIS up to 
12.8. Th ...)
        TODO: check
 CVE-2026-19785 (A vulnerability has been found in francoisjacquet RosarioSIS 
up to 12. ...)
@@ -223,7 +223,7 @@ CVE-2026-19771 (A vulnerability was identified in Baicells 
EG3661M BaiCE_BQ6_2.0
 CVE-2026-19770 (A vulnerability was identified in feedmob fm-mcp-servers 
0.0.3. Affect ...)
        TODO: check
 CVE-2026-19767 (A weakness has been identified in itsourcecode Hospital 
Management Sys ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-19765 (A security flaw has been discovered in eyaushev 
swagger-testcase-mcp 5 ...)
        TODO: check
 CVE-2026-19764 (A vulnerability was identified in Raisecom Communication 
Command and D ...)
@@ -247,13 +247,13 @@ CVE-2026-19752 (A vulnerability was found in EnzoVezzaro 
mcp-dominican-layer up
 CVE-2026-19751 (A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 
39dd373 ...)
        TODO: check
 CVE-2026-19750 (A flaw has been found in Tenda CH, CP and TX3 
V21.x/V22.x/V25.x/V26.x/ ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19749 (A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, 
CP3 Pro, C ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19748 (A security vulnerability has been detected in Tenda CH7, CH7G, 
CH10, C ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19747 (A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, 
CP3 Pro, ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The 
affected ...)
        TODO: check
 CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is 
an unknow ...)
@@ -261,171 +261,171 @@ CVE-2026-19745 (A flaw has been found in Calix 
GigaSpire 26.1.0. Impacted is an
 CVE-2026-19617 (A flaw was found in libdm. A remote attacker could craft a 
malicious L ...)
        TODO: check
 CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 
6.0.1.0 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19297 (IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote 
attacker to  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18846 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow 
from im ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18741 (Worksuite SaaS versions prior to 6.0.14 contains a stored 
cross-site s ...)
        TODO: check
 CVE-2026-18715 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18671 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated 
attacker to  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18532
        REJECTED
 CVE-2026-18511 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18509 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18249 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18193 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
bypass s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18164 (An undocumented hard-coded credential, shared by all device 
units, is  ...)
        TODO: check
 CVE-2026-18109 (The W3 Total Cache plugin for WordPress is vulnerable to 
Stored Cross- ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18101 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
gain elev ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18086 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
execute a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18077 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18068 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
obtain s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18039 (The Essential Addons for Elementor  WordPress plugin before 
6.7.2 does ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18020 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17649 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
obtain s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17502 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17482 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a 
remote att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17481 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a 
remote att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17476 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17473 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a 
remote att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17468 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a 
remote att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17438 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
obtain se ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17272 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17229 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17226 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17223 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17216 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17212 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17206 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
execute  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17199 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17101 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
execute  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
obtain s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17088 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17077 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17076 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17075 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
obtain s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17074 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17069 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17045 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17043 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17029 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
execute a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17004 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16987 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
gain elev ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16982 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16975 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16967 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16961 (IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A 
remote attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16929 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16908 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16898 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16896 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16887 (IBM i 7.6 could allow a remote attacker to cause a denial of 
service d ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16878 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16871 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16868 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16867 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
access s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16861 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16859 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
obtain s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16853 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
obtain s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16815 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16810 (The Bit Form \u2013 Contact Form, Payment Forms, Multi Step 
Forms, Cal ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16739 (The Epeken All Kurir for Woocommerce WordPress plugin through 
2.1.2 do ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16722 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16713 (IBM Documentation Offline 1.0.0 through 1.4.1 IBM 
Documentation could  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16692 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16674 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-15205 (The Paymob for WooCommerce WordPress plugin before 4.1.9 does 
not prop ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14875 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is 
vulnerable t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-14525 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 I ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-14290 (The Embed Google Photos album WordPress plugin through 2.2.1 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13460 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 
6.0.1.0 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-13365 (IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to 
cross-site  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12949 (The Wishlist Member plugin for WordPress is vulnerable to 
Account Take ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12743 (The affiliate-toolkit \u2013 Multi-Network Affiliate & Amazon 
Product  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10571 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 i ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2025-10308 (The Astro Booking Engine plugin for WordPress is vulnerable to 
Cross-S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-73261 [Built-in TCP/IP malformed TCP option handling]
        - mongoose 7.23+ds-1
 CVE-2026-73260 [Built-in TLS X.509 DER parsing bounds check]



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4ba194970a2d36ded2dc5381f56ade12cb8ef76b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4ba194970a2d36ded2dc5381f56ade12cb8ef76b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to