Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5fb623a9 by Salvatore Bonaccorso at 2026-08-15T09:36:34+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8,29 +8,29 @@ CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles 
quality of service (
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/12
        NOTE: https://bugs.launchpad.net/octavia/+bug/2161500
 CVE-2026-74247 (A flaw was found in Red Hat Quay. A user with 
FEATURE_BUILD_SUPPORT en ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Quay
 CVE-2026-74245 (A flaw was found in Red Hat Quay's exported logs feature. An 
unauthent ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Quay
 CVE-2026-74244 (A flaw was found in Red Hat Quay's Stripe billing webhook 
handler. Thi ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Quay
 CVE-2026-74243 (A flaw was found in Red Hat Quay. When the 
SECURITY_SCANNER_V4_PSK (pr ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Quay
 CVE-2026-74242 (A flaw was found in Red Hat Quay. An administrator of any 
repository,  ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Quay
 CVE-2026-74241 (A flaw was found in Red Hat Quay's external Lightweight 
Directory Acce ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Quay
 CVE-2026-74240 (A flaw was found in Red Hat Quay's JWT (JSON Web Token) 
validation for ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Quay
 CVE-2026-73683 (Laravel Socialite's Facebook provider contains an 
authentication bypas ...)
-       TODO: check
+       NOT-FOR-US: Laravel Socialite's Facebook provider
 CVE-2026-73682 (Semaphore versions prior to 2.18.20 contain an OS command 
injection (a ...)
-       TODO: check
+       NOT-FOR-US: Semaphore UI
 CVE-2026-73680 (Cockpit CMS 2.14.0 and prior contains a command injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Cockpit CMS
 CVE-2026-73679 (ImpressCMS contains an authenticated remote code execution 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: ImpressCMS
 CVE-2026-73678 (MindsDB Minds Platform version 26.1.0 and earlier contains an 
unauthen ...)
-       TODO: check
+       NOT-FOR-US: MindsDB
 CVE-2026-71571 (Joomla Extension - icagenda.com -  Authenticated SQL injection 
via une ...)
        NOT-FOR-US: Joomla
 CVE-2026-71570 (Joomla Extension - icagenda.com - ACL bypass allowing 
arbitrary user e ...)
@@ -50,9 +50,9 @@ CVE-2026-63649 (The Windows interactive service in OpenVPN 
2.4.0 through 2.6.21
 CVE-2026-50523 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-50029 (js-toml is a TOML parser for JavaScript, Prior to version 
1.1.2, the i ...)
-       TODO: check
+       NOT-FOR-US: js-toml
 CVE-2026-50027 (mcp-memory-service is a semantic memory layer for AI 
applications. Pri ...)
-       TODO: check
+       NOT-FOR-US: mcp-memory-service
 CVE-2026-39925
        REJECTED
 CVE-2026-34492 (External control of file name or path vulnerability in Johnson 
Control ...)
@@ -4130,11 +4130,11 @@ CVE-2026-57469 (Nozomi Networks Labs identified a 
CWE-352: Cross-Site Request Fo
 CVE-2026-53970 (ZeroBrew version 0.3.1 and prior contains a missing integrity 
verifica ...)
        NOT-FOR-US: ZeroBrew
 CVE-2026-49989 (CrateDB is a distributed SQL database. Prior to versions 6.2.8 
and 6.3 ...)
-       TODO: check
+       NOT-FOR-US: CrateDB
 CVE-2026-49986 (The Cortex MCP server (`neuro-cortex-memory`), a 
cross-platform persis ...)
-       TODO: check
+       NOT-FOR-US: Cortex MCP server
 CVE-2026-49826 (Concourse is a container-based automation system written in 
Go. Prior  ...)
-       TODO: check
+       NOT-FOR-US: Concourse
 CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to 
version 1.4 ...)
        TODO: check
 CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 
6.0.0-Alpha9, Ca ...)
@@ -4369,7 +4369,7 @@ CVE-2026-73480 (gdu fails to strip terminal escape 
sequences from directory and
        NOTE: https://github.com/dundee/gdu/pull/616
        NOTE: Fixed by: 
https://github.com/dundee/gdu/commit/5d76fab735f190fd645896de90ac9982b6382aeb
 CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when 
printing marked ...)
-       TODO: check
+       NOT-FOR-US: dua-cli
 CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
        NOT-FOR-US: Trix
 CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From 
next-auth 5.0.0- ...)
@@ -4511,9 +4511,9 @@ CVE-2026-72630 (Incorrect Authorization (CWE-863) in 
Kibana Fleet can lead to pr
 CVE-2026-72629 (Authorization Bypass Through User-Controlled Key (CWE-639) in 
Kibana c ...)
        - kibana <itp> (bug #700337)
 CVE-2026-59714 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
-       TODO: check
+       NOT-FOR-US: Open WebUI
 CVE-2026-49864 (wetty provides terminal access in browser over http/https. 
Prior to ve ...)
-       TODO: check
+       NOT-FOR-US: wetty
 CVE-2026-49096 (Uncaught Exception (CWE-248) in Kibana Cases can lead to 
denial of ser ...)
        TODO: check
 CVE-2026-49089 (Allocation of Resources Without Limits or Throttling (CWE-770) 
in Kiba ...)
@@ -6032,17 +6032,17 @@ CVE-2026-59916 (Dell Display and Peripheral Manager 
(DDPM Windows), versions pri
 CVE-2026-59914 (Dell Display and Peripheral Manager (DDPM Windows), versions 
prior to  ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-50544 (NortheBridge/luminalshine is a Sunshine-compatible game stream 
host fo ...)
-       TODO: check
+       NOT-FOR-US: NortheBridge/luminalshine
 CVE-2026-4879 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-49819 (UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 
are vuln ...)
-       TODO: check
+       NOT-FOR-US: UpSnap
 CVE-2026-49481 (UpSnap is a wake on lan web app. Versions prior to 5.4.0 have 
an OS co ...)
-       TODO: check
+       NOT-FOR-US: UpSnap
 CVE-2026-49473 (@cedar-policy/authorization-for-expressjs is an open-source 
Express.js ...)
-       TODO: check
+       NOT-FOR-US: cedar-policy/authorization-for-expressjs
 CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote 
unpublished con ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with 
sigstore  ...)
        TODO: check
 CVE-2026-47718 (FUXA is a web-based Process Visualization 
(SCADA/HMI/Dashboard) softwa ...)
@@ -6497,15 +6497,15 @@ CVE-2026-64639 (Incorrect database cloning process in 
Plesk from 18.0.52 before
 CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception 
nodes by  ...)
        TODO: check
 CVE-2026-57858 (Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored 
cross-si ...)
-       TODO: check
+       NOT-FOR-US: Cal.com Cal.diy
 CVE-2026-54183 (Apache Airflow's secrets masker hides values stored under 
sensitive ke ...)
        TODO: check
 CVE-2026-53996 (NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c 
contains a mis ...)
-       TODO: check
+       NOT-FOR-US: NetBSD
 CVE-2026-50561 (Yuxi is a large-model-based intelligent knowledge base and 
knowledge g ...)
-       TODO: check
+       NOT-FOR-US: Yuxi
 CVE-2026-49467 (Pingvin Share X is a secure and easy self-hosted file sharing 
platform ...)
-       TODO: check
+       NOT-FOR-US: Pingvin Share X
 CVE-2026-49349 (regclient is a Docker and OCI Registry Client in Go. Prior to 
version  ...)
        TODO: check
 CVE-2026-49262 (In the Aimeos Pagible content management system prior to 
version 0.10. ...)
@@ -6959,7 +6959,7 @@ CVE-2026-66145 (An unauthenticated remote code execution 
vulnerability was ident
 CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write 
from any ...)
        NOT-FOR-US: Mira
 CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS 
terminates ...)
-       TODO: check
+       NOT-FOR-US: temporalio ui-server
 CVE-2026-64954 (Velociraptor allows scheduling new collections via VQL queries 
in note ...)
        NOT-FOR-US: Velociraptor
 CVE-2026-64934 (The Mira cloud API accepts the firmware version reported by 
the compan ...)
@@ -9809,9 +9809,9 @@ CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an 
unauthenticated SQL inje
 CVE-2026-63105 (ReadyEcommerce before 4.5.2 contains a stored cross-site 
scripting (XS ...)
        NOT-FOR-US: ReadyEcommerceCrafty Controller
 CVE-2026-59233 (Missing Authorization in the permission management component 
in Roskus ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-59112 (Improper verification of cryptographic signature and Improper 
Check fo ...)
-       TODO: check
+       NOT-FOR-US: Estonian Information System Authority (RIA)
 CVE-2026-59091 (A flaw was found in GIMP's file format plugins, including 
those for PS ...)
        - gimp <unfixed>
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16510
@@ -9832,7 +9832,7 @@ CVE-2026-59087 (A flaw was found in the GIMP image 
manipulation program, specifi
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16491
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/bb36034bedb06305402ce836129efe8c8d4ad41d
 CVE-2026-57279 (Cybozu Garoon contains a cross-site scripting vulnerability. 
If this v ...)
-       TODO: check
+       NOT-FOR-US: Cybozu
 CVE-2026-56620 (HCL BigFix Mobileis vulnerable to information disclosure due 
to improp ...)
        NOT-FOR-US: HCL
 CVE-2026-56619 (HCL BigFix Mobile is vulnerable to Reflected Cross-Site 
Scripting (Ref ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fb623a96febd15fa2fd534e8f3cf165024da52f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fb623a96febd15fa2fd534e8f3cf165024da52f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to