Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d6fd7965 by Salvatore Bonaccorso at 2026-08-20T09:23:06+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1019,15 +1019,15 @@ CVE-2026-62666 (Grav API Plugin is a RESTful API for
Grav CMS that provides full
CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery
<= 30.0. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav
Twig conte ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to
8.6.2, a s ...)
TODO: check
CVE-2026-61690 (Grav is a file-based Web platform. Prior to 2.0.1, Grav
ZipArchiver::e ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav CMS that provides
full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-61518 (ISPConfig contains an authenticated SQL injection
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: ISPConfig
CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a
Missing ...)
NOT-FOR-US: Dell / EMC
CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an
Incorre ...)
@@ -1035,21 +1035,21 @@ CVE-2026-58564 (Dell Command Update (DCU), versions
prior to 5.7.1, contain an I
CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a
Missing ...)
NOT-FOR-US: Dell / EMC
CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map
entries, ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the
number of sem ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58086 (As an inadvertent side effect of an unrelated code change,
PRIV_KTRACE ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58085 (After dispatching a decrypt operation to OCF and receiving the
result, ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58084 (To retrieve the previous timer value, the kernel calls
realtimer_getti ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58083 (While the kernel was copying knotes during fork, a knote with
a timer- ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58082 (The ISO-2022 encoding module used a stack buffer sized to
MB_LEN_MAX ( ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW,
did not p ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a
Time-of-check Ti ...)
NOT-FOR-US: Dell / EMC
CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an
Imprope ...)
@@ -3213,7 +3213,7 @@ CVE-2026-60391 (Vulnerability in the Oracle Hyperion
Financial Reporting product
CVE-2026-59915 (Dell Alienware Command Center (AWCC), versions prior to
6.14.20.0, con ...)
NOT-FOR-US: Dell / EMC
CVE-2026-57826 (An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In
the X.509 ...)
- TODO: check
+ NOT-FOR-US: openHiTLS
CVE-2026-56874
REJECTED
CVE-2026-56873
@@ -4325,9 +4325,9 @@ CVE-2026-63328 (Trivy is a security scanner. Prior to
0.72.0, plugin manifest me
CVE-2026-62684 (File Browser is a file managing interface for uploading,
deleting, pre ...)
NOT-FOR-US: File Browser
CVE-2026-62357 (Dragonfly is an in-memory data store built for modern
application work ...)
- TODO: check
+ NOT-FOR-US: Dragonfly
CVE-2026-61696 (Forem is open source software for building communities. In
versions be ...)
- TODO: check
+ NOT-FOR-US: Forem
CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based
application ...)
- rabbitmq-java-client <unfixed>
NOTE:
https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
@@ -4336,7 +4336,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows
Java and JVM-based appli
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1995
NOTE: Fixed by:
https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472
(v5.33.0)
CVE-2026-61574 (authentik is an open-source identity provider. Prior to
2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain
an Expose ...)
NOT-FOR-US: Dell / EMC
CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in
Kriptok Cr ...)
@@ -4344,14 +4344,14 @@ CVE-2026-5224 (Cleartext storage of sensitive
information vulnerability in Kript
CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to
1.11.1, JN ...)
TODO: check
CVE-2026-59940 (Seroval facilitates JS value stringification, including
complex struct ...)
- TODO: check
+ NOT-FOR-US: Seroval
CVE-2026-59825 (Mastodon is a free, open-source social network server based on
Activit ...)
TODO: check
CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom
installation ...)
- zabbix <not-affected> (Windows-specific)
NOTE: https://support.zabbix.com/browse/ZBX-28077
CVE-2026-57580 (authentik is an open-source identity provider. Prior to
2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14,
8.0.10, 8 ...)
TODO: check
CVE-2026-55839 (Kestra is an open-source, event-driven orchestration platform.
Prior t ...)
@@ -4883,11 +4883,11 @@ CVE-2026-63409 (Deskflow is a keyboard and mouse
sharing app. From 1.17.0 until
CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx
Enterprise Ed ...)
NOT-FOR-US: Onyx
CVE-2026-57485 (Stirling-PDF is a locally hosted web application that
facilitates vari ...)
- TODO: check
+ NOT-FOR-US: Stirling-PDF
CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.7 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier,
the POST ...)
- TODO: check
+ NOT-FOR-US: 9Router
CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.7 ...)
TODO: check
CVE-2026-54385
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits