Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
231b67ce by Moritz Muehlenhoff at 2026-08-16T23:32:03+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6960,37 +6960,37 @@ CVE-2026-19643 (An out-of-bounds read issue in the
Base64 decoder in Amazon aws-
CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon
aws-sdk-c ...)
NOT-FOR-US: Amazon
CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do
not valida ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup
configuration to st ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in
OpenNMS M ...)
- TODO: check
+ NOT-FOR-US: OpenNMS
CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions
of OpenNM ...)
- TODO: check
+ NOT-FOR-US: OpenNMS
CVE-2026-19130 (A flaw was found in the provider-credential-controller
component of mu ...)
- TODO: check
+ NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon WordPress
plugin b ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may
experien ...)
- TODO: check
+ NOT-FOR-US: MongoDB BI Connector
CVE-2026-19003 (A data source definition containing an over-length file path
setting m ...)
- TODO: check
+ NOT-FOR-US: MongoDB BI Connector
CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter
metadat ...)
- TODO: check
+ NOT-FOR-US: MongoDB BI Connector
CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the
bounds of a ...)
- TODO: check
+ NOT-FOR-US: MongoDB BI Connector
CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not
verify th ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point
column va ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches
VinceComm ...)
- TODO: check
+ NOT-FOR-US: CERT/CC VINCE
CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case)
only an ...)
- TODO: check
+ NOT-FOR-US: CERT/CC VINCE
CVE-2026-18744 (Any authenticated case participant can fetch any OTHER
vendor's CaseSt ...)
- TODO: check
+ NOT-FOR-US: CERT/CC VINCE
CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow
vulnerability in ...)
TODO: check
CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This
vulnerabilit ...)
@@ -6998,7 +6998,7 @@ CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio
component. This vulner
CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a
remote att ...)
TODO: check
CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the
operato ...)
- TODO: check
+ NOT-FOR-US: Kuma
CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
@@ -7052,7 +7052,7 @@ CVE-2026-14213 (The Booking for Appointments and Events
Calendar WordPress plug
CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress
plugin befor ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's
virt-handler ...)
- TODO: check
+ NOT-FOR-US: KubeVirt
CVE-2026-13610 (The KiviCare WordPress plugin before 4.5.2 does not restrict
the role ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow
an unau ...)
@@ -7452,15 +7452,15 @@ CVE-2026-18713 (IBM i 7.6, 7.5, 7.4, and 7.3 s
vulnerable to privilege escalatio
CVE-2026-18683 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege
escalation via ...)
NOT-FOR-US: IBM
CVE-2026-18678 (When an operator adds an HTTPS control plane profile to
kumactl withou ...)
- TODO: check
+ NOT-FOR-US: Kuma
CVE-2026-18677 (In Kong Mesh running in universal mode with a MeshIdentity
whose SPIFF ...)
- TODO: check
+ NOT-FOR-US: Kuma
CVE-2026-18676 (The default kuma-cp configuration in Kong Mesh reveals the
admin boots ...)
- TODO: check
+ NOT-FOR-US: Kuma
CVE-2026-18675 (The dataplane token validator in kuma-cp performs an unchecked
Go type ...)
- TODO: check
+ NOT-FOR-US: Kuma
CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix
domain s ...)
- TODO: check
+ NOT-FOR-US: Kuma
CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege
escalation a ...)
NOT-FOR-US: IBM
CVE-2026-18663 (A flaw was found in 389-ds-base. The
get_ldapmessage_controls_ext() fu ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/231b67ce4f27576e7bd0cdc3117cfb83b6b42bce
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/231b67ce4f27576e7bd0cdc3117cfb83b6b42bce
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits