Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a95e5e29 by Salvatore Bonaccorso at 2026-08-22T10:25:58+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -33,9 +33,9 @@ CVE-2026-76905 (kin-openapi is a Go project for handling
OpenAPI files. From 0.1
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-mmfr-pmjx-hw9w
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/1d0a337c9b1570fab283be8a04c8af6e43b9a22c
(v0.141.0)
CVE-2026-76904 (GeoTools is an open source Java library that provides tools
for geospa ...)
- TODO: check
+ NOT-FOR-US: GeoTools
CVE-2026-76876 (Craftplan before 0.5.1 contains a broken access control
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Craftplan
CVE-2026-76793 (The Firebase Authentication WordPress plugin before 1.7.1 does
not req ...)
NOT-FOR-US: WordPress plugin
CVE-2026-76789 (The Slider Hero with Video Background, Animation WordPress
plugin befo ...)
@@ -79,7 +79,7 @@ CVE-2026-69225 (There is an information disclosure
vulnerability in Esri Portal
CVE-2026-69224 (There is an information disclosure vulnerability in Esri
Portal for Ar ...)
NOT-FOR-US: Esri
CVE-2026-68508 (Hydra is a framework for elegantly configuring complex
applications. P ...)
- TODO: check
+ NOT-FOR-US: Hydra
CVE-2026-67619
REJECTED
CVE-2026-67362 (Joomla Extension - j2commerce.com - Open redirect in cart
controller i ...)
@@ -93,35 +93,35 @@ CVE-2026-67359 (Joomla Extension - j2commerce.com - Order
content disclosure J2S
CVE-2026-67358 (Joomla Extension - j2commerce.com - Download quota
manipulation in J2S ...)
NOT-FOR-US: Joomla
CVE-2026-64679 (Atlantis is a self-hosted golang application that listens for
Terrafor ...)
- TODO: check
+ NOT-FOR-US: Atlantis
CVE-2026-63421 (Keystone is a content management system for Node.js. Prior to
6.5.3, t ...)
- TODO: check
+ NOT-FOR-US: Keystone CMS
CVE-2026-63135 (YOURLS is a self-hosted, customizable URL shortener written in
PHP. Fr ...)
- TODO: check
+ NOT-FOR-US: YOURLS
CVE-2026-62960 (Git for Windows is the Windows port of Git. Prior to
2.55.0.windows.4, ...)
TODO: check
CVE-2026-62316 (Microsoft UFO open-source framework for intelligent automation
across ...)
- TODO: check
+ NOT-FOR-US: Microsoft UFO
CVE-2026-62283 (Nezha Monitoring is a self-hostable, lightweight, servers and
websites ...)
- TODO: check
+ NOT-FOR-US: Nezha Monitoring
CVE-2026-61824 (Defuddle cleans up HTML pages. Prior to 0.19.1, site
extractors interp ...)
- TODO: check
+ NOT-FOR-US: Defuddle
CVE-2026-61539 (Xinference is an inference API for running open-source,
speech, and mu ...)
- TODO: check
+ NOT-FOR-US: Xinference
CVE-2026-59989 (Phalcon is a high-performance, full-stack PHP framework. In
5.15.0 and ...)
- TODO: check
+ NOT-FOR-US: Phalcon
CVE-2026-55185 (Miniflux 2 is an open source feed reader. Prior to 2.3.1,
IsRelativePa ...)
TODO: check
CVE-2026-55168 (Runtipi is a personal homeserver orchestrator. In 4.10.0 and
earlier, ...)
- TODO: check
+ NOT-FOR-US: Runtipi
CVE-2026-54457 (TensorZero is an open-source LLMOps platform that unifies an
LLM gatew ...)
- TODO: check
+ NOT-FOR-US: TensorZero
CVE-2026-53656 (FiftyOne is an open-source platform for refining high-quality
datasets ...)
- TODO: check
+ NOT-FOR-US: FiftyOne
CVE-2026-53572 (KEDA is a Kubernetes-based Event Driven Autoscaling component.
Prior t ...)
- TODO: check
+ NOT-FOR-US: KEDA
CVE-2026-53541 (OliveTin gives access to predefined shell commands from a web
interfac ...)
- TODO: check
+ NOT-FOR-US: OliveTin
CVE-2026-53531 (RaTeX is a KaTeX-compatible math rendering engine written in
Rust. Pri ...)
TODO: check
CVE-2026-53530 (RaTeX is a KaTeX-compatible math rendering engine written in
Rust. Pri ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a95e5e29caa9e7a3a03617212022aa68494adbf5
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a95e5e29caa9e7a3a03617212022aa68494adbf5
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits