Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d6fd7965 by Salvatore Bonaccorso at 2026-08-20T09:23:06+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1019,15 +1019,15 @@ CVE-2026-62666 (Grav API Plugin is a RESTful API for 
Grav CMS that provides full
 CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery 
<= 30.0. ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav 
Twig conte ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.2, a s ...)
        TODO: check
 CVE-2026-61690 (Grav is a file-based Web platform. Prior to 2.0.1, Grav 
ZipArchiver::e ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-61518 (ISPConfig contains an authenticated SQL injection 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: ISPConfig
 CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a 
Missing  ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an 
Incorre ...)
@@ -1035,21 +1035,21 @@ CVE-2026-58564 (Dell Command Update (DCU), versions 
prior to 5.7.1, contain an I
 CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a 
Missing  ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map 
entries,  ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the 
number of sem ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-58086 (As an inadvertent side effect of an unrelated code change, 
PRIV_KTRACE ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-58085 (After dispatching a decrypt operation to OCF and receiving the 
result, ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-58084 (To retrieve the previous timer value, the kernel calls 
realtimer_getti ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-58083 (While the kernel was copying knotes during fork, a knote with 
a timer- ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-58082 (The ISO-2022 encoding module used a stack buffer sized to 
MB_LEN_MAX ( ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW, 
did not p ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a 
Time-of-check Ti ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an 
Imprope ...)
@@ -3213,7 +3213,7 @@ CVE-2026-60391 (Vulnerability in the Oracle Hyperion 
Financial Reporting product
 CVE-2026-59915 (Dell Alienware Command Center (AWCC), versions prior to 
6.14.20.0, con ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-57826 (An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In 
the X.509 ...)
-       TODO: check
+       NOT-FOR-US: openHiTLS
 CVE-2026-56874
        REJECTED
 CVE-2026-56873
@@ -4325,9 +4325,9 @@ CVE-2026-63328 (Trivy is a security scanner. Prior to 
0.72.0, plugin manifest me
 CVE-2026-62684 (File Browser is a file managing interface for uploading, 
deleting, pre ...)
        NOT-FOR-US: File Browser
 CVE-2026-62357 (Dragonfly is an in-memory data store built for modern 
application work ...)
-       TODO: check
+       NOT-FOR-US: Dragonfly
 CVE-2026-61696 (Forem is open source software for building communities. In 
versions be ...)
-       TODO: check
+       NOT-FOR-US: Forem
 CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based 
application ...)
        - rabbitmq-java-client <unfixed>
        NOTE: 
https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
@@ -4336,7 +4336,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows 
Java and JVM-based appli
        NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1995
        NOTE: Fixed by: 
https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472
 (v5.33.0)
 CVE-2026-61574 (authentik is an open-source identity provider. Prior to 
2026.2.6 and 2 ...)
-       TODO: check
+       NOT-FOR-US: authentik
 CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain 
an Expose ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in 
Kriptok Cr ...)
@@ -4344,14 +4344,14 @@ CVE-2026-5224 (Cleartext storage of sensitive 
information vulnerability in Kript
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 
1.11.1, JN ...)
        TODO: check
 CVE-2026-59940 (Seroval facilitates JS value stringification, including 
complex struct ...)
-       TODO: check
+       NOT-FOR-US: Seroval
 CVE-2026-59825 (Mastodon is a free, open-source social network server based on 
Activit ...)
        TODO: check
 CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom 
installation  ...)
        - zabbix <not-affected> (Windows-specific)
        NOTE: https://support.zabbix.com/browse/ZBX-28077
 CVE-2026-57580 (authentik is an open-source identity provider. Prior to 
2026.2.6 and 2 ...)
-       TODO: check
+       NOT-FOR-US: authentik
 CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 
8.0.10, 8 ...)
        TODO: check
 CVE-2026-55839 (Kestra is an open-source, event-driven orchestration platform. 
Prior t ...)
@@ -4883,11 +4883,11 @@ CVE-2026-63409 (Deskflow is a keyboard and mouse 
sharing app. From 1.17.0 until
 CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx 
Enterprise Ed ...)
        NOT-FOR-US: Onyx
 CVE-2026-57485 (Stirling-PDF is a locally hosted web application that 
facilitates vari ...)
-       TODO: check
+       NOT-FOR-US: Stirling-PDF
 CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)
-       TODO: check
+       NOT-FOR-US: Notepad++
 CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier, 
the POST  ...)
-       TODO: check
+       NOT-FOR-US: 9Router
 CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)
        TODO: check
 CVE-2026-54385



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to