Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
231b67ce by Moritz Muehlenhoff at 2026-08-16T23:32:03+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6960,37 +6960,37 @@ CVE-2026-19643 (An out-of-bounds read issue in the 
Base64 decoder in Amazon aws-
 CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon 
aws-sdk-c ...)
        NOT-FOR-US: Amazon
 CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do 
not valida ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup 
configuration to st ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in 
OpenNMS M ...)
-       TODO: check
+       NOT-FOR-US: OpenNMS
 CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions 
of OpenNM ...)
-       TODO: check
+       NOT-FOR-US: OpenNMS
 CVE-2026-19130 (A flaw was found in the provider-credential-controller 
component of mu ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
 CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon  WordPress 
plugin b ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may 
experien ...)
-       TODO: check
+       NOT-FOR-US: MongoDB BI Connector
 CVE-2026-19003 (A data source definition containing an over-length file path 
setting m ...)
-       TODO: check
+       NOT-FOR-US: MongoDB BI Connector
 CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter 
metadat ...)
-       TODO: check
+       NOT-FOR-US: MongoDB BI Connector
 CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the 
bounds of a ...)
-       TODO: check
+       NOT-FOR-US: MongoDB BI Connector
 CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not 
verify th ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point 
column va ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches 
VinceComm ...)
-       TODO: check
+       NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case) 
only an ...)
-       TODO: check
+       NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18744 (Any authenticated case participant can fetch any OTHER 
vendor's CaseSt ...)
-       TODO: check
+       NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow 
vulnerability in  ...)
        TODO: check
 CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This 
vulnerabilit ...)
@@ -6998,7 +6998,7 @@ CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio 
component. This vulner
 CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a 
remote att ...)
        TODO: check
 CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the 
operato ...)
-       TODO: check
+       NOT-FOR-US: Kuma
 CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
@@ -7052,7 +7052,7 @@ CVE-2026-14213 (The Booking for Appointments and Events 
Calendar  WordPress plug
 CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress 
plugin befor ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's 
virt-handler ...)
-       TODO: check
+       NOT-FOR-US: KubeVirt
 CVE-2026-13610 (The KiviCare  WordPress plugin before 4.5.2 does not restrict 
the role ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow 
an unau ...)
@@ -7452,15 +7452,15 @@ CVE-2026-18713 (IBM i 7.6, 7.5, 7.4, and 7.3 s 
vulnerable to privilege escalatio
 CVE-2026-18683 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege 
escalation via ...)
        NOT-FOR-US: IBM
 CVE-2026-18678 (When an operator adds an HTTPS control plane profile to 
kumactl withou ...)
-       TODO: check
+       NOT-FOR-US: Kuma
 CVE-2026-18677 (In Kong Mesh running in universal mode with a MeshIdentity 
whose SPIFF ...)
-       TODO: check
+       NOT-FOR-US: Kuma
 CVE-2026-18676 (The default kuma-cp configuration in Kong Mesh reveals the 
admin boots ...)
-       TODO: check
+       NOT-FOR-US: Kuma
 CVE-2026-18675 (The dataplane token validator in kuma-cp performs an unchecked 
Go type ...)
-       TODO: check
+       NOT-FOR-US: Kuma
 CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix 
domain s ...)
-       TODO: check
+       NOT-FOR-US: Kuma
 CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege 
escalation a ...)
        NOT-FOR-US: IBM
 CVE-2026-18663 (A flaw was found in 389-ds-base. The 
get_ldapmessage_controls_ext() fu ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/231b67ce4f27576e7bd0cdc3117cfb83b6b42bce

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/231b67ce4f27576e7bd0cdc3117cfb83b6b42bce
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to