Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
75203532 by Salvatore Bonaccorso at 2026-08-14T23:18:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -470,7 +470,7 @@ CVE-2026-72651 (Allocation of Resources Without Limits or 
Throttling (CWE-770) i
 CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in 
Kibana c ...)
        - kibana <itp> (bug #700337)
 CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment 
Variable  ...)
-       TODO: check
+       NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to 
denial o ...)
        NOT-FOR-US: Elasticsearch
 CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in 
Elasticsearch ...)
@@ -480,7 +480,7 @@ CVE-2026-72643 (Kibana Agent Builder determines whether a 
caller owns a private
 CVE-2026-72642 (The native inference process that Elasticsearch uses to 
evaluate uploa ...)
        NOT-FOR-US: Elasticsearch
 CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of 
secret  ...)
-       TODO: check
+       NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-72639 (Elasticsearch does not enforce an upper bound on a 
user-supplied count ...)
        NOT-FOR-US: Elasticsearch
 CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to 
denial o ...)
@@ -1087,7 +1087,7 @@ CVE-2026-6387 (A potential authentication bypass 
vulnerability was reported in L
 CVE-2026-67991 (crmne/ruby_llm at commit 
fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
        NOT-FOR-US: ruby_llm
 CVE-2026-67990 (basecamp/upright at commit 
efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
-       TODO: check
+       NOT-FOR-US: basecamp/upright
 CVE-2026-67986 (amazing-print/amazing_print at commit 
dc890dfafdf07088ea901df53c19c271 ...)
        - ruby-amazing-print <unfixed>
        NOTE: https://gist.github.com/Zykis1024/21b13ddabf1a7d9707fd573518cefa71
@@ -1972,13 +1972,13 @@ CVE-2026-71469 (A flaw was found in search-v2-api. An 
unauthenticated attacker c
 CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project 
ash all ...)
-       TODO: check
+       NOT-FOR-US: ash-project ash
 CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to 
manipulate ...)
        TODO: check
 CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed 
Transfer-Encoding w ...)
        NOT-FOR-US: Apple
 CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability 
that all ...)
-       TODO: check
+       NOT-FOR-US: rConfig
 CVE-2026-63300 (An improper validation vulnerability in the 
instancePostMigration func ...)
        TODO: check
 CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an 
authenticated u ...)
@@ -2427,27 +2427,27 @@ CVE-2026-67283 (Joomla Extension - tabaoca.org - 
Improper ACL implementation all
 CVE-2026-67282 (Joomla Extension - fabrikar.com - Unauthenticated remote code 
executio ...)
        NOT-FOR-US: Joomla
 CVE-2026-67260 (Apache Airflow 3.3.0 moved human-in-the-loop tasks from the 
triggerer  ...)
-       TODO: check
+       - airflow <itp> (bug #819700)
 CVE-2026-66384 (An authenticated user may write data outside the intended 
Docker cache ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66382 (An authenticated user may write files outside the intended 
Artifactory ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66381 (A repository reader with cache-deploy permission may access 
content ou ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66380 (An authenticated user without repository read permission may 
access pr ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66379 (An authenticated user may view private Puppet module metadata 
without  ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66378 (An authenticated user without repository read permission may 
access pr ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66377 (An unauthenticated user may access restricted repository 
information u ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66376 (Credentials for a deleted user may remain valid for a short 
period und ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66375 (A low-privilege authenticated user may permanently remove 
protected in ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-66016 (Under specific self-hosted Helm configurations, generated TLS 
private  ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-65941 (In WhatsUp Gold versions released before 2026.0.2,an 
unauthenticated r ...)
        NOT-FOR-US: Progress Software
 CVE-2026-65940 (In WhatsUp Gold versions released before 2026.0.2, a 
privileged attack ...)
@@ -2459,7 +2459,7 @@ CVE-2026-65938 (In WhatsUp Gold versions released before 
2026.0.2,an improperaut
 CVE-2026-65937 (In WhatsUp Gold versions released before 2026.0.2, an 
authenticated at ...)
        NOT-FOR-US: Progress Software
 CVE-2026-65926 (An anonymous caller when anonymous access is enabled, or a 
low-privile ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-64955 (When Microsoft Excel imports a CSV file, it executes cells 
beginning w ...)
        NOT-FOR-US: Rapid7
 CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts.  
Velociraptor mi ...)
@@ -2467,7 +2467,7 @@ CVE-2026-64952 (The hunt_delete() VQL function allows 
deleting hunts.  Velocirap
 CVE-2026-64951 (A rogue Velociraptor client can upload a malformed sparse file 
such th ...)
        NOT-FOR-US: Rapid7
 CVE-2026-64639 (Incorrect database cloning process in Plesk from 18.0.52 
before 18.0.7 ...)
-       TODO: check
+       NOT-FOR-US: Plesk
 CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception 
nodes by  ...)
        TODO: check
 CVE-2026-57858 (Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored 
cross-si ...)
@@ -3784,9 +3784,9 @@ CVE-2026-68793 (Out-of-bounds read in Microsoft Office 
Excel allows an unauthori
 CVE-2026-68792 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-67180 (Google Turbinia allows arbitrary command execution via worker 
tasks. A ...)
-       TODO: check
+       NOT-FOR-US: Google Turbinia
 CVE-2026-67179 (Genkit does not properly validate host request headers. Any 
host on th ...)
-       TODO: check
+       NOT-FOR-US: Genkit
 CVE-2026-66810 (Heap-based buffer overflow in Microsoft Office Word allows an 
unauthor ...)
        NOT-FOR-US: Microsoft
 CVE-2026-66809 (Out-of-bounds read in Microsoft Office allows an unauthorized 
attacker ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to