Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
75203532 by Salvatore Bonaccorso at 2026-08-14T23:18:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -470,7 +470,7 @@ CVE-2026-72651 (Allocation of Resources Without Limits or
Throttling (CWE-770) i
CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in
Kibana c ...)
- kibana <itp> (bug #700337)
CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment
Variable ...)
- TODO: check
+ NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to
denial o ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in
Elasticsearch ...)
@@ -480,7 +480,7 @@ CVE-2026-72643 (Kibana Agent Builder determines whether a
caller owns a private
CVE-2026-72642 (The native inference process that Elasticsearch uses to
evaluate uploa ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of
secret ...)
- TODO: check
+ NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
CVE-2026-72639 (Elasticsearch does not enforce an upper bound on a
user-supplied count ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to
denial o ...)
@@ -1087,7 +1087,7 @@ CVE-2026-6387 (A potential authentication bypass
vulnerability was reported in L
CVE-2026-67991 (crmne/ruby_llm at commit
fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
NOT-FOR-US: ruby_llm
CVE-2026-67990 (basecamp/upright at commit
efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
- TODO: check
+ NOT-FOR-US: basecamp/upright
CVE-2026-67986 (amazing-print/amazing_print at commit
dc890dfafdf07088ea901df53c19c271 ...)
- ruby-amazing-print <unfixed>
NOTE: https://gist.github.com/Zykis1024/21b13ddabf1a7d9707fd573518cefa71
@@ -1972,13 +1972,13 @@ CVE-2026-71469 (A flaw was found in search-v2-api. An
unauthenticated attacker c
CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project
ash all ...)
- TODO: check
+ NOT-FOR-US: ash-project ash
CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to
manipulate ...)
TODO: check
CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed
Transfer-Encoding w ...)
NOT-FOR-US: Apple
CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability
that all ...)
- TODO: check
+ NOT-FOR-US: rConfig
CVE-2026-63300 (An improper validation vulnerability in the
instancePostMigration func ...)
TODO: check
CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an
authenticated u ...)
@@ -2427,27 +2427,27 @@ CVE-2026-67283 (Joomla Extension - tabaoca.org -
Improper ACL implementation all
CVE-2026-67282 (Joomla Extension - fabrikar.com - Unauthenticated remote code
executio ...)
NOT-FOR-US: Joomla
CVE-2026-67260 (Apache Airflow 3.3.0 moved human-in-the-loop tasks from the
triggerer ...)
- TODO: check
+ - airflow <itp> (bug #819700)
CVE-2026-66384 (An authenticated user may write data outside the intended
Docker cache ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66382 (An authenticated user may write files outside the intended
Artifactory ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66381 (A repository reader with cache-deploy permission may access
content ou ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66380 (An authenticated user without repository read permission may
access pr ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66379 (An authenticated user may view private Puppet module metadata
without ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66378 (An authenticated user without repository read permission may
access pr ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66377 (An unauthenticated user may access restricted repository
information u ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66376 (Credentials for a deleted user may remain valid for a short
period und ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66375 (A low-privilege authenticated user may permanently remove
protected in ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66016 (Under specific self-hosted Helm configurations, generated TLS
private ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-65941 (In WhatsUp Gold versions released before 2026.0.2,an
unauthenticated r ...)
NOT-FOR-US: Progress Software
CVE-2026-65940 (In WhatsUp Gold versions released before 2026.0.2, a
privileged attack ...)
@@ -2459,7 +2459,7 @@ CVE-2026-65938 (In WhatsUp Gold versions released before
2026.0.2,an improperaut
CVE-2026-65937 (In WhatsUp Gold versions released before 2026.0.2, an
authenticated at ...)
NOT-FOR-US: Progress Software
CVE-2026-65926 (An anonymous caller when anonymous access is enabled, or a
low-privile ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-64955 (When Microsoft Excel imports a CSV file, it executes cells
beginning w ...)
NOT-FOR-US: Rapid7
CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts.
Velociraptor mi ...)
@@ -2467,7 +2467,7 @@ CVE-2026-64952 (The hunt_delete() VQL function allows
deleting hunts. Velocirap
CVE-2026-64951 (A rogue Velociraptor client can upload a malformed sparse file
such th ...)
NOT-FOR-US: Rapid7
CVE-2026-64639 (Incorrect database cloning process in Plesk from 18.0.52
before 18.0.7 ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception
nodes by ...)
TODO: check
CVE-2026-57858 (Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored
cross-si ...)
@@ -3784,9 +3784,9 @@ CVE-2026-68793 (Out-of-bounds read in Microsoft Office
Excel allows an unauthori
CVE-2026-68792 (Improper neutralization of special elements used in a command
('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-67180 (Google Turbinia allows arbitrary command execution via worker
tasks. A ...)
- TODO: check
+ NOT-FOR-US: Google Turbinia
CVE-2026-67179 (Genkit does not properly validate host request headers. Any
host on th ...)
- TODO: check
+ NOT-FOR-US: Genkit
CVE-2026-66810 (Heap-based buffer overflow in Microsoft Office Word allows an
unauthor ...)
NOT-FOR-US: Microsoft
CVE-2026-66809 (Out-of-bounds read in Microsoft Office allows an unauthorized
attacker ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits