Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
cbecbe18 by Salvatore Bonaccorso at 2026-08-14T15:18:18+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-73655 (Trigger.dev is a platform for building and 
deploying fully manag
 CVE-2026-73654 (Trigger.dev is a platform for building and deploying fully 
managed AI  ...)
        NOT-FOR-US: Trigger.dev
 CVE-2026-73531 (django-helpdesk before 2.3.3 contains a stored cross-site 
scripting vu ...)
-       TODO: check
+       NOT-FOR-US: django-helpdesk
 CVE-2026-73530 (Flyto2 Core before 2.28.0 contains a server-side request 
forgery guard ...)
-       TODO: check
+       NOT-FOR-US: Flyto2 Core
 CVE-2026-73489 (Russh is a Rust SSH client & server library. Prior to 0.62.4, 
an authe ...)
        TODO: check
 CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory 
and file n ...)
@@ -71,7 +71,7 @@ CVE-2026-73480 (gdu fails to strip terminal escape sequences 
from directory and
 CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when 
printing marked ...)
        TODO: check
 CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
-       TODO: check
+       NOT-FOR-US: Trix
 CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From 
next-auth 5.0.0- ...)
        NOT-FOR-US: Next.js
 CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to 
@auth/core 0 ...)
@@ -81,39 +81,39 @@ CVE-2026-73417 (jupyterlab is an extensible environment for 
interactive and repr
 CVE-2026-73416 (jupyterlab is an extensible environment for interactive and 
reproducib ...)
        TODO: check
 CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 
3.39.18, packag ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-73305 (Budibase is an open-source low-code platform. Prior to 
3.39.24, POST / ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-73304 (Budibase is an open-source low-code platform. Prior to 
3.39.25, GET /a ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-73302 (Budibase is an open-source low-code platform. Prior to 
3.39.30, the OI ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-73039 (streama contains an insecure direct object reference 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: streama
 CVE-2026-72857 (Budibase before 3.40.0 fails to redact datasource credentials 
stored i ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72856 (Budibase versions before 3.40.0 contain an 
authorization/authenticatio ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72855 (Budibase before 3.40.0 contains server-side request forgery 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72853 (Budibase before 3.40.0 contains a SQL injection vulnerability 
in the O ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72851 (Budibase before 3.40.0 contains an unauthenticated SQL 
injection vulne ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72850 (Budibase before 3.40.0 fails to properly sanitize S3 object 
keys, allo ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72849 (Budibase before 3.40.0 contains a cross-site request forgery 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72842 (luci-app-lxc contains an ACL inconsistency vulnerability that 
allows l ...)
-       TODO: check
+       NOT-FOR-US: luci-app-lxc
 CVE-2026-72841 (luci-app-openvpn fails to properly validate the instance_name2 
paramet ...)
-       TODO: check
+       NOT-FOR-US: luci-app-openvpn
 CVE-2026-72840 (OpenWrt LuCI contains an overly permissive ACL definition in 
luci-mod- ...)
-       TODO: check
+       NOT-FOR-US: OpenWrt LuCI
 CVE-2026-72839 (filebrowser through 2.63.16 fails to properly restrict scope 
and permi ...)
-       TODO: check
+       NOT-FOR-US: filebrowser
 CVE-2026-72776 (AgenticSeek (commit fc242c7) contains an unauthenticated 
remote code e ...)
-       TODO: check
+       NOT-FOR-US: AgenticSeek
 CVE-2026-72687 (A flaw in Elasticsearch allows a low-privileged authenticated 
user to  ...)
        NOT-FOR-US: Elasticsearch
 CVE-2026-72686 (A flaw in Elasticsearch allows a low-privileged authenticated 
user to  ...)
@@ -135,7 +135,7 @@ CVE-2026-72678 (Elasticsearch does not validate a size 
value taken from a user-s
 CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the 
unauthorize ...)
        TODO: check
 CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') 
(CWE-94) in  ...)
-       TODO: check
+       NOT-FOR-US: Fleet Server
 CVE-2026-72675 (Missing Authorization (CWE-862) in Kibana can lead to 
cross-space info ...)
        TODO: check
 CVE-2026-72674 (Allocation of Resources Without Limits or Throttling (CWE-770) 
in Kiba ...)
@@ -169,7 +169,7 @@ CVE-2026-72659 (Allocation of Resources Without Limits or 
Throttling (CWE-770) i
 CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in Kibana can lead to 
privilege e ...)
        TODO: check
 CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in 
Fleet Se ...)
-       TODO: check
+       NOT-FOR-US: Fleet Server
 CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the 
ES|QL que ...)
        NOT-FOR-US: Elasticsearch
 CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined 
Object At ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbecbe18dd404cf7caf7f6d10df39c788fba20a4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbecbe18dd404cf7caf7f6d10df39c788fba20a4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to