Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e2b65a79 by Moritz Muehlenhoff at 2026-08-19T08:35:39+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1034,7 +1034,7 @@ CVE-2026-1199 (Zabbix API and Frontend login lockout
mechanism has a flaw where
CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the patched versions fails to
enforce fie ...)
TODO: check
CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak
authorizatio ...)
- TODO: check
+ NOT-FOR-US: Red Hat build of Keycloak
CVE-2026-19501 (CSV export functionality in Brainstorm Force SureForms
version, <= 2.1 ...)
TODO: check
CVE-2026-19500 (The Entries component in Brainstorm Force SureForms version,
less than ...)
@@ -1042,7 +1042,7 @@ CVE-2026-19500 (The Entries component in Brainstorm Force
SureForms version, les
CVE-2026-19447 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-18963 (A flaw was found in the reset-credentials flow of the
keycloak-service ...)
- TODO: check
+ NOT-FOR-US: Red Hat build of Keycloak
CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of
protection a ...)
TODO: check
CVE-2026-18751 (External control of file name or path vulnerability in Citrix
WorkSpac ...)
@@ -1086,7 +1086,7 @@ CVE-2026-15806 (The HTTPPasswordMgr class in the
urllib.request module, along wi
CVE-2026-15585 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
TODO: check
CVE-2026-12564 (A flaw was found in the AAP Controller's HashiCorp Vault
credential pl ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2025-9211 (Unescaped stored values in application security page in Otalio
Ship Pr ...)
TODO: check
CVE-2025-9210 (Missing signature validation in JSON Web Tokens in Otalio Ship
Propert ...)
@@ -10081,7 +10081,7 @@ CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve
Stimulatoraccepts severa
CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly
restrict ac ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18710 (A MongoDB driver component could write sensitive configuration
informa ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18634 (An insecure handling of serialized objects vulnerability was
found in ...)
NOT-FOR-US: SonicWall
CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not
sanitise a ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2b65a79d570a3f752f3a0d6e8ed47ae8f20a1c0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2b65a79d570a3f752f3a0d6e8ed47ae8f20a1c0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits