Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bdb3893c by security tracker role at 2026-08-17T19:14:39+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy()
in dri ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was
possible via u ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75059 (In JetBrains PyCharm before 2026.2.1 code execution via Quick
Document ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75058 (In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in
the Ecl ...)
TODO: check
CVE-2026-75057 (In JetBrains IntelliJ IDEA before 2026.1.5 git credentials
were writte ...)
@@ -19,21 +19,21 @@ CVE-2026-75053 (In JetBrains IntelliJ IDEA before 2026.2.1
sSRF was possible via
CVE-2026-75052 (In JetBrains IntelliJ IDEA before 2026.2.1 command execution
via craft ...)
TODO: check
CVE-2026-75051 (In JetBrains YouTrack before 2026.2.17917 unauthorised project
transfe ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75050 (In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS
attack wa ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75049 (In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an
authentica ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75048 (In JetBrains YouTrack before 2026.2.18068 stored XSS via the
fenced co ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75047 (In JetBrains YouTrack before 2026.2.18177 doS attack was
possible via ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75046 (In JetBrains YouTrack before 2026.2.18112 an authenticated
user could ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75045 (In JetBrains YouTrack before 2025.3.156085, 2026.1.13913,
2026.2.181 ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75044 (In JetBrains YouTrack before 2025.3.156085, 2026.1.13914,
2026.2.180 ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75011 (A flaw has been found in kylecui NetForensicMCP 2.1.0.
Impacted is the ...)
TODO: check
CVE-2026-74901 (openssl_encrypt versions before 1.4.0 contain an
authentication bypass ...)
@@ -99,31 +99,31 @@ CVE-2026-74870 (openssl_encrypt (pip) versions <= 1.4.7
contain an information e
CVE-2026-74869 (stoatchat before 0.15.0 contains a missing authorization
vulnerability ...)
TODO: check
CVE-2026-74868 (SiYuan versions before 3.7.4 contain an unthrottled
brute-force vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74867 (SiYuan versions before 3.7.4 contain a cross-site request
forgery vuln ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74858 (A vulnerability has been found in jae-jae fetcher-mcp up to
0.3.9. Imp ...)
TODO: check
CVE-2026-74845 (Official Document Management System developed by 2100
Technology has a ...)
TODO: check
CVE-2026-74843 (A vulnerability was determined in Wavlink WN531P3 and WN535M1
V250922. ...)
- TODO: check
+ NOT-FOR-US: Wavlink
CVE-2026-74842 (A vulnerability was found in Kira-Pgr PromptShopMCP up to
5bc0cd17358e ...)
TODO: check
CVE-2026-74802 (SiYuan versions before 3.7.4 contain a cross-site WebSocket
hijacking ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74801 (SiYuan before 3.7.4 fails to properly escape workspace
directory paths ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74800 (SiYuan before v3.7.4 fails to set Content-Disposition and
X-Content-Ty ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74799 (SiYuan before 3.7.4 registers Go net/http/pprof debug
endpoints includ ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74798 (SiYuan kernel before v3.7.4 contains a path traversal
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74254 (Joomla Extension - joomlack.fr - SQL injection in Page Builder
CK < 3. ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE
through unver ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read
vulnerabil ...)
TODO: check
CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to
1.29.1 ...)
@@ -151,9 +151,9 @@ CVE-2026-71491 (sqlparse is a non-validating SQL parser
module for Python. Prior
CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial
intellig ...)
TODO: check
CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10,
version p ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via
WebSocket deco ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-68520 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
TODO: check
CVE-2026-68519 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
@@ -181,11 +181,11 @@ CVE-2026-60107
CVE-2026-60106
REJECTED
CVE-2026-59911 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Insertion o ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Improper Ne ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path
Travers ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59903 (Netty is an asynchronous, event-driven network application
framework. ...)
TODO: check
CVE-2026-59902 (Netty is an asynchronous, event-driven network application
framework. ...)
@@ -195,27 +195,27 @@ CVE-2026-59894 (sqlparse is a non-validating SQL parser
module for Python. Prior
CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
TODO: check
CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to
2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-58561 (Null pointer dereference issue in the image codec
module.Impact: Succe ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-58560 (Null pointer dereference issue in the image codec
module.Impact: Succe ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-56686 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Improper Ne ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56685 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Improper Ne ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56090 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an
Uncontrolle ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56089 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path
Travers ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o
2026.1.6, 202 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to
2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
TODO: check
CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to
2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and
5.4.x bef ...)
TODO: check
CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs
Billetterie CSE - ...)
@@ -237,55 +237,55 @@ CVE-2026-50769 (The CRM+ application before and including
version 2025.6 from Br
CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH
ImageMaster ...)
TODO: check
CVE-2026-49308 (Permission control vulnerability in the clipboard
module.Impact: Succe ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49307 (Permission control vulnerability in the multi-mode input
module.Impact ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49306 (UAF vulnerability in the time and time zone module.Impact:
Successful ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49305 (Permission control vulnerability in the Wi-Fi enhancement
module.Impac ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49304 (Permission control vulnerability in the device key management
module.I ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49303 (Permission control vulnerability in the notification
module.Impact: Su ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49302 (Permission control vulnerability in the notification service
module.Im ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact:
Success ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to
version 0.19. ...)
TODO: check
CVE-2026-46345 (compliance-trestle is a tooling platform for managing
compliance as co ...)
TODO: check
CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint
Privilege ...)
- TODO: check
+ NOT-FOR-US: BeyondTrust
CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode
component of ...)
- TODO: check
+ NOT-FOR-US: BeyondTrust
CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based
Cross-Site Scri ...)
TODO: check
CVE-2026-33437 (Stirling-PDF is a locally hosted web application that
facilitates vari ...)
TODO: check
CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital
Management Syste ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-19999 (A security vulnerability has been detected in Open Asset
Import Librar ...)
TODO: check
CVE-2026-19998 (A weakness has been identified in code-projects Online
Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent
directory ...)
TODO: check
CVE-2026-18674 (On a Kong Mesh global control plane, resources received over
the zone- ...)
TODO: check
CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software
Technologies ...)
TODO: check
CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software
Technologies ...)
TODO: check
CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <=
5.12.5 and ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and
below versi ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and
below, a pa ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The
Mattermost G ...)
TODO: check
CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6,
10.11.x <= 10. ...)
@@ -305,15 +305,15 @@ CVE-2026-15218 (A flaw was found in the maas-api and
maas-controller ServiceAcco
CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim
Software ...)
TODO: check
CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows
Input D ...)
- TODO: check
+ NOT-FOR-US: OpenText
CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression
code conta ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12629 (The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails
to ackn ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin
(WJA) t ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited
%NOTIFYEV: ev ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21,
11.8.x <= 1 ...)
TODO: check
CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve
generative ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits