Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a95e5e29 by Salvatore Bonaccorso at 2026-08-22T10:25:58+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -33,9 +33,9 @@ CVE-2026-76905 (kin-openapi is a Go project for handling 
OpenAPI files. From 0.1
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-mmfr-pmjx-hw9w
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/1d0a337c9b1570fab283be8a04c8af6e43b9a22c
 (v0.141.0)
 CVE-2026-76904 (GeoTools is an open source Java library that provides tools 
for geospa ...)
-       TODO: check
+       NOT-FOR-US: GeoTools
 CVE-2026-76876 (Craftplan before 0.5.1 contains a broken access control 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Craftplan
 CVE-2026-76793 (The Firebase Authentication WordPress plugin before 1.7.1 does 
not req ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-76789 (The Slider Hero with Video Background, Animation WordPress 
plugin befo ...)
@@ -79,7 +79,7 @@ CVE-2026-69225 (There is an information disclosure 
vulnerability in Esri Portal
 CVE-2026-69224 (There is an information disclosure vulnerability in Esri 
Portal for Ar ...)
        NOT-FOR-US: Esri
 CVE-2026-68508 (Hydra is a framework for elegantly configuring complex 
applications. P ...)
-       TODO: check
+       NOT-FOR-US: Hydra
 CVE-2026-67619
        REJECTED
 CVE-2026-67362 (Joomla Extension - j2commerce.com - Open redirect in cart 
controller i ...)
@@ -93,35 +93,35 @@ CVE-2026-67359 (Joomla Extension - j2commerce.com - Order 
content disclosure J2S
 CVE-2026-67358 (Joomla Extension - j2commerce.com - Download quota 
manipulation in J2S ...)
        NOT-FOR-US: Joomla
 CVE-2026-64679 (Atlantis is a self-hosted golang application that listens for 
Terrafor ...)
-       TODO: check
+       NOT-FOR-US: Atlantis
 CVE-2026-63421 (Keystone is a content management system for Node.js. Prior to 
6.5.3, t ...)
-       TODO: check
+       NOT-FOR-US: Keystone CMS
 CVE-2026-63135 (YOURLS is a self-hosted, customizable URL shortener written in 
PHP. Fr ...)
-       TODO: check
+       NOT-FOR-US: YOURLS
 CVE-2026-62960 (Git for Windows is the Windows port of Git. Prior to 
2.55.0.windows.4, ...)
        TODO: check
 CVE-2026-62316 (Microsoft UFO open-source framework for intelligent automation 
across  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft UFO
 CVE-2026-62283 (Nezha Monitoring is a self-hostable, lightweight, servers and 
websites ...)
-       TODO: check
+       NOT-FOR-US: Nezha Monitoring
 CVE-2026-61824 (Defuddle cleans up HTML pages. Prior to 0.19.1, site 
extractors interp ...)
-       TODO: check
+       NOT-FOR-US: Defuddle
 CVE-2026-61539 (Xinference is an inference API for running open-source, 
speech, and mu ...)
-       TODO: check
+       NOT-FOR-US: Xinference
 CVE-2026-59989 (Phalcon is a high-performance, full-stack PHP framework. In 
5.15.0 and ...)
-       TODO: check
+       NOT-FOR-US: Phalcon
 CVE-2026-55185 (Miniflux 2 is an open source feed reader. Prior to 2.3.1, 
IsRelativePa ...)
        TODO: check
 CVE-2026-55168 (Runtipi is a personal homeserver orchestrator. In 4.10.0 and 
earlier,  ...)
-       TODO: check
+       NOT-FOR-US: Runtipi
 CVE-2026-54457 (TensorZero is an open-source LLMOps platform that unifies an 
LLM gatew ...)
-       TODO: check
+       NOT-FOR-US: TensorZero
 CVE-2026-53656 (FiftyOne is an open-source platform for refining high-quality 
datasets ...)
-       TODO: check
+       NOT-FOR-US: FiftyOne
 CVE-2026-53572 (KEDA is a Kubernetes-based Event Driven Autoscaling component. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: KEDA
 CVE-2026-53541 (OliveTin gives access to predefined shell commands from a web 
interfac ...)
-       TODO: check
+       NOT-FOR-US: OliveTin
 CVE-2026-53531 (RaTeX is a KaTeX-compatible math rendering engine written in 
Rust. Pri ...)
        TODO: check
 CVE-2026-53530 (RaTeX is a KaTeX-compatible math rendering engine written in 
Rust. Pri ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a95e5e29caa9e7a3a03617212022aa68494adbf5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a95e5e29caa9e7a3a03617212022aa68494adbf5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to