Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2011e0dd by Salvatore Bonaccorso at 2026-08-17T21:55:37+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -127,29 +127,29 @@ CVE-2026-74253 (Joomla Extension - regularlabs.com - 
Unauthenticated RCE through
 CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read 
vulnerabil ...)
        NOT-FOR-US: TIER IV Nebula
 CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
-       TODO: check
+       NOT-FOR-US: Kiota
 CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and 
modify its ...)
        TODO: check
 CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: COVESA Open1722
 CVE-2026-73522 (COVESA Open1722 through 0.9.2 contains a stack buffer overflow 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: COVESA Open1722
 CVE-2026-73424 (Astro is a web framework for content-driven websites. From 
10.0.3 unti ...)
-       TODO: check
+       NOT-FOR-US: Astro
 CVE-2026-71980 (Belledonne Communications bcg729 through 1.1.2 contains an 
out-of-boun ...)
-       TODO: check
+       NOT-FOR-US: Belledonne Communications bcg729
 CVE-2026-71979 (INDI (Instrument Neutral Distributed Interface) indiserver 
through 2.2 ...)
-       TODO: check
+       NOT-FOR-US: INDI (Instrument Neutral Distributed Interface) indiserver
 CVE-2026-71693
        REJECTED
 CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in 
some of the ...)
-       TODO: check
+       NOT-FOR-US: openshift-metal3/fakefish
 CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to 
scripts ...)
-       TODO: check
+       NOT-FOR-US: FakeFish
 CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
        TODO: check
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
-       TODO: check
+       NOT-FOR-US: New API
 CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, 
version p ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via 
WebSocket deco ...)
@@ -163,15 +163,15 @@ CVE-2026-68518 (Glances is an open-source system 
cross-platform monitoring tool.
 CVE-2026-68517 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        TODO: check
 CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription 
component. T ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Multicluster Global Hub
 CVE-2026-64868 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
-       TODO: check
+       NOT-FOR-US: New API
 CVE-2026-64866 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
-       TODO: check
+       NOT-FOR-US: New API
 CVE-2026-64865 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
-       TODO: check
+       NOT-FOR-US: New API
 CVE-2026-64859 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
-       TODO: check
+       NOT-FOR-US: New API
 CVE-2026-62982 (Glances is an open-source system cross-platform monitoring 
tool. From  ...)
        TODO: check
 CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with 
pluggable I/O. P ...)
@@ -217,13 +217,13 @@ CVE-2026-54284 (sqlparse is a non-validating SQL parser 
module for Python. Prior
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
        NOT-FOR-US: Discourse
 CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 
5.4.x bef ...)
-       TODO: check
+       NOT-FOR-US: StudIP
 CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs 
Billetterie CSE -  ...)
-       TODO: check
+       NOT-FOR-US: Pronis Loisirs Billetterie CSE
 CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1 allows a remote 
attacker to e ...)
-       TODO: check
+       NOT-FOR-US: DataHub
 CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to 
escalate ...)
-       TODO: check
+       NOT-FOR-US: GAPTEQ Designer
 CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 
2510.1.0.20  ...)
        TODO: check
 CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote 
attacker ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2011e0dd8a6ad4dd0888ba00802ce1a37869df4b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2011e0dd8a6ad4dd0888ba00802ce1a37869df4b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to