Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ea0b5fb7 by Salvatore Bonaccorso at 2026-08-25T22:36:03+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -69,37 +69,37 @@ CVE-2026-79674 (NLTK versions before 3.10.3 contain a path
sandbox bypass vulner
- nltk 3.10.3-1
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the
profile:rea ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization
on nine c ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79669 (Ech0 before 4.4.3 lacks authorization checks on system log
endpoints a ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79668 (Ech0 before 4.7.3 contains an authentication bypass
vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79667 (Ech0 version 4.3.4 and earlier fails to reliably enforce
scoped access ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79666 (Ech0 before 4.4.3 fails to enforce administrator authorization
on dash ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79665 (Ech0 before 4.5.1 contains an authorization bypass
vulnerability where ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79664 (Ech0 before 4.7.3 fails to properly revoke access tokens
created with ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79663 (Ech0 before 4.7.3 contains a stored cross-site scripting
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79662 (Ech0 through 4.5.6 contains an OAuth redirect URI validation
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79661 (Ech0 through 4.5.6 registers the PUT /api/echo/like/:id
endpoint on th ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79660 (Ech0 versions before 4.7.3 expose guest commenter email
addresses thro ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79659 (Ech0 before 4.7.3 contains a server-side request forgery
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on
the Accep ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution
vulnerabil ...)
- nltk 3.10.3-1
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw
@@ -369,39 +369,39 @@ CVE-2026-55553 (urllib is an HTTP client for Node.js that
supports authenticatio
CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP.
Prior to 0.2 ...)
TODO: check
CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, pr ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55540 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.51, is ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55539 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.51, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55538 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.51, pr ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55537 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, Jo ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55536 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, Br ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55535 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55534 (PraisonAI is a multi-agent teams system. From praisonai 4.6.34
until 4 ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55533 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, cr ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55532 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, MC ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55531 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55530 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55529 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55528 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55527 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55526 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55525 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55419 (Reachy Mini is an SDK for controlling Reachy Mini robots.
Prior to 1.8 ...)
TODO: check
CVE-2026-53561 (An improper authentication vulnerability in HiveServer2 SAML
bearer-to ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea0b5fb7f7d0a5190d6e86938cecb1dcde0087e0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea0b5fb7f7d0a5190d6e86938cecb1dcde0087e0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits