Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
78da4a8d by security tracker role at 2026-08-28T07:14:39+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,7 +13,7 @@ CVE-2026-81934 (Redis contains a use-after-free vulnerability 
in the 'tlsProcess
 CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product 
photo u ...)
        TODO: check
 CVE-2026-81851 (A heap-based buffer overflow vulnerability in Fireware OS's 
iked proce ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-81848 (A vulnerability was determined in cyberchitta 
scrapling-fetch-mcp up t ...)
        TODO: check
 CVE-2026-81847 (A vulnerability was found in MAA-AI MaaMCP up to 
1.1.1.dev6+g2e4a41287 ...)
@@ -21,7 +21,7 @@ CVE-2026-81847 (A vulnerability was found in MAA-AI MaaMCP up 
to 1.1.1.dev6+g2e4
 CVE-2026-81845 (A vulnerability has been found in arben-adm 
mcp-sequential-thinking up ...)
        TODO: check
 CVE-2026-81838 (A relative path traversal issue in the zip extraction 
functionality in ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-81837 (A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. 
This issue  ...)
        TODO: check
 CVE-2026-81836 (A vulnerability was detected in RooCodeInc Roo-Code up to 
3.51.1. This ...)
@@ -35,11 +35,11 @@ CVE-2026-81833 (A security flaw has been discovered in 
RooCodeInc Roo-Code up to
 CVE-2026-81731 (Frappe 15.11.0 through 16.32.0 stores and renders the 
workspace card d ...)
        TODO: check
 CVE-2026-81730 (Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments 
under th ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-81729 (Dolibarr before 23.0.4 authorizes REST API document deletion 
against t ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-81728 (Dolibarr before 24.0.0 contains a SQL injection in its CSV and 
XLSX im ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-81530 (A weakness in the client-side encryption configuration surface 
of the  ...)
        TODO: check
 CVE-2026-81529 (Improper neutralization of delimiters in connection-URL 
construction a ...)
@@ -61,55 +61,55 @@ CVE-2026-81522 (A weakness in the MongoDB C++ Driver's 
handling of caller-suppli
 CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may 
accept a ...)
        TODO: check
 CVE-2026-78618 (A business logic flaw in WatchGuard Dimension allows an 
authenticated  ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78617 (WatchGuard Dimension's web login endpoint does not enforce 
effective r ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78616 (A Stored Cross-Site Scripting (XSS) vulnerability in 
WatchGuard Dimens ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78615 (A Reflected Cross-Site Scripting (XSS) vulnerability in 
WatchGuard Dim ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78614 (WatchGuard Dimension contains an authenticated SQL injection 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78613 (WatchGuard Dimension contains an authenticated SQL injection 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78612 (WatchGuard Dimension contains an authenticated SQL injection 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78610 (WatchGuard Dimension's Web UI exposes an administrator 
passphrase chan ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78500 (A blind server-side request forgery (SSRF) vulnerability 
WatchGuard Di ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78499 (A server-side request forgery (SSRF) vulnerability WatchGuard 
Dimensio ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78498 (A server-side request forgery (SSRF) vulnerability WatchGuard 
Dimensio ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78495 (A server-side request forgery (SSRF) vulnerability WatchGuard 
Dimensio ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78239 (Xiiaozet LK100W exposes a critical management function that 
can be  in ...)
        TODO: check
 CVE-2026-78195 (A Cross-Site Scripting (XSS) vulnerability in the WatchGuard 
Dimension ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78174 (WatchGuard Dimension records unredacted session identifiers 
for logged ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78103 (WatchGuard Dimension provides a client-side lock/unlock UI 
control for ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78047 (A stored cross-site scripting (XSS) vulnerability in 
WatchGuard Dimens ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78037 (Xiiaozet LK100W is vulnerable to OS command injection through 
its  web ...)
        TODO: check
 CVE-2026-78011 (An integer underflow vulnerability in the WatchGuard Fireware 
OS iked  ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78010 (A stack-based buffer overflow vulnerability in the WatchGuard 
Fireware ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78009 (An out-of-bounds read vulnerability in the WatchGuard Fireware 
OS iked ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-78008 (A buffer overflow vulnerability in the WatchGuard Fireware OS 
Manageme ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-77977 (Ebyte gateway product's vendor configuration utility does not 
require  ...)
        TODO: check
 CVE-2026-77438 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
        TODO: check
 CVE-2026-77365 (The Optimole \u2013 Optimize Images | Convert WebP & AVIF | 
CDN & Lazy ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77358 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In 
versions 0.33. ...)
        TODO: check
 CVE-2026-77341 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In 
version 0.49.0 ...)
@@ -129,7 +129,7 @@ CVE-2026-76179 (An improper protection of authentication 
tokens vulnerability ex
 CVE-2026-76060 (An authenticated OS command injection vulnerability exists in 
ZoneMind ...)
        TODO: check
 CVE-2026-76053 (The TranslatePress \u2013 Translate Multilingual sites with AI 
Transla ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75889 (Grafana Alloy\u2019s prometheus.operator.servicemonitors 
component all ...)
        TODO: check
 CVE-2026-75814 (The Ebyte device does not adequately verify the origin or 
authenticity ...)
@@ -149,7 +149,7 @@ CVE-2026-75339 (The storage endpoint /storage/upload of 
cjbi admin3 v3.0.0 are m
 CVE-2026-75337 (The static resource interface /api/static/{deployKey}/ of Yu 
AI Code M ...)
        TODO: check
 CVE-2026-74820 (ServiceNow has remediated a SQL injection vulnerability that 
was ident ...)
-       TODO: check
+       NOT-FOR-US: ServiceNow
 CVE-2026-73839 (Administrative credentials may be exposed in plaintext within 
the Ebyt ...)
        TODO: check
 CVE-2026-73809 (A cleartext transmission of sensitive information 
vulnerability exists ...)
@@ -161,7 +161,7 @@ CVE-2026-71396 (Bendix EC80 Brake ECUuses hard-coded 
credentials, which could al
 CVE-2026-71187 (The Ebyte device relies on client side authentication logic 
that can b ...)
        TODO: check
 CVE-2026-6876 (ServiceNow has remediated a sandbox escape security issue that 
was ide ...)
-       TODO: check
+       NOT-FOR-US: ServiceNow
 CVE-2026-69658 (MQTT credentials and control traffic are transmitted in 
cleartext,  ex ...)
        TODO: check
 CVE-2026-68967 (Bendix EC80 Brake ECUis vulnerable to an out-of-bounds write, 
which co ...)
@@ -181,31 +181,31 @@ CVE-2026-61800 (Wazuh is an open-source security platform 
providing unified XDR
 CVE-2026-61783 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
        TODO: check
 CVE-2026-5706 (In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended 
advertisem ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-59324 (When an IntegrationFlow uses .fluxTransform() with an 
asynchronous/reo ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59322 (The EmbeddedHeadersJsonMessageMapper defaults to an overly 
permissive  ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59321 (A single ScriptEngine instance is reused for every message on 
a script ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59320 (When a container-level ErrorHandler is configured (the 
mitigation for  ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59319 (RedisChatMemoryRepository.findByMetadata() builds RediSearch 
tag and t ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59317 (DeadLetterPublishingRecovererFactory reads the 
retry_topic-original-ti ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59316 (Spring Authorization Server's default consent page renders 
user-contro ...)
        TODO: check
 CVE-2026-59315 (The Spring Cloud Config Monitor is susceptible to Denial of 
Service at ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59314 (Applications that build a Content-Disposition header value 
from untrus ...)
        TODO: check
 CVE-2026-59313 (Spring MVC applications using the functional web framework are 
vulnera ...)
        TODO: check
 CVE-2026-59311 (A local unprivileged user on the same host can redirect all 
Zip/UnZip  ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59307 (An operator who calls JdbcMessageStore.addAllowedPatterns(...) 
to rest ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59306 (Potential for deserialization of untrusted types in Spring 
Cloud Strea ...)
        TODO: check
 CVE-2026-59305 (Partition interceptor may be improperly added while sending 
message. S ...)
@@ -217,33 +217,33 @@ CVE-2026-59303 (Dynamic destination cache size is not 
properly bound in Spring C
 CVE-2026-59302 (Potential for logging sensitive data in Spring Cloud Stream. 
Spring Cl ...)
        TODO: check
 CVE-2026-59301 (Potential for logging sensitive data in Spring Cloud Function 
Azure. S ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59300 (Potential for logging sensitive data in Spring Cloud Function 
AWS. Spr ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59299 (Composition lookup can potentially poison base function in 
Spring Clou ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59298 (Potential for improper filtering of HTTP headers in Spring 
Cloud Funct ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59297 (Implementation of isSecure() call of 
ServerlessHttpServletRequest does ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59294 (ResourceCacheService.getCacheName() builds the on-disk 
filename by app ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59293 (Unless the application explicitly raises smbMinVersion, the 
jCIFS clie ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59292 (PropertiesPersistingMetadataStore, the default file-based 
ConcurrentMe ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59291 (Potential arbitrary file read and SSRF vulnerability in Spring 
Cloud F ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59289 (Spring for GraphQL's Spring Data pagination support resolves 
arguments ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59288 (The GraphiQL page bundled with Spring for GraphQL sends 
requests to th ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59287 (Spring for GraphQL is vulnerable to Denial of Service attacks 
when usi ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59286 (The GraphiQL page bundled with Spring for GraphQL loads 
JavaScript lib ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59285 (Spring for GraphQL applications are vulnerable to Unsafe 
Deserializati ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59284 (There is no allow list for property keys when Spring Cloud 
Commons wri ...)
        TODO: check
 CVE-2026-59283 (Applications that evaluate Spring Expression Language (SpEL) 
expressio ...)
@@ -267,7 +267,7 @@ CVE-2026-54718 (Silverstripe Advanced Workflow is a highly 
configurable step-bas
 CVE-2026-54713 (CakePHP Queue is a queue-interop compatible queueing library. 
From 0.1 ...)
        TODO: check
 CVE-2026-54687 (n8n-nodes-sqlite3 is a node for operating a local SQLite 
database from ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-54085 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
        TODO: check
 CVE-2026-54084 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
@@ -285,9 +285,9 @@ CVE-2026-48996 (Trilium is an open-source hierarchical 
note-taking application.
 CVE-2026-47727 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
        TODO: check
 CVE-2026-44629 (Improper access control to the Synergis Softwire installation 
folder.  ...)
-       TODO: check
+       NOT-FOR-US: Genetec
 CVE-2026-3129 (The LiteSpeed Cache plugin for WordPress is vulnerable to 
Stored Cross ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-38822 (In openNDS before 11.0.0, the client_params.sh script, invoked 
by the  ...)
        TODO: check
 CVE-2026-38821 (A heap-based buffer overflow vulnerability exists in openNDS 
before 11 ...)
@@ -353,53 +353,53 @@ CVE-2026-35869 (A Command Injection vulnerability exists 
in the bs_SetLimitCli_i
 CVE-2026-35868 (A Command Injection vulnerability exists in the 
bs_SetLimitCli_info fu ...)
        TODO: check
 CVE-2026-34620 (DNG SDK versions 1.7.1 2502 and earlier are affected by an 
out-of-boun ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-34616 (DNG SDK versions 1.7.1 2502 and earlier are affected by an 
out-of-boun ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-30612 (An issue in Time4 Popcorn for Windows <= 6.2.1.18 and 
Time4Popcorn for ...)
        TODO: check
 CVE-2026-25250 (EAZ EazyFix 12.9 allows a Security Feature Bypass related to a 
"Missin ...)
        TODO: check
 CVE-2026-19318 (A stack-based buffer overflow vulnerability in the WatchGuard 
Fireware ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-19317 (An out-of-bounds read vulnerability in the WatchGuard Fireware 
OS iked ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-19316 (A double-free vulnerability in the WatchGuard Fireware OS iked 
process ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-19315 (A type confusion vulnerability in the iked process of 
WatchGuard Firew ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-19314 (An integer underflow vulnerability in the WatchGuard Fireware 
OS iked  ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-19313 (An heap overflow vulnerability in the WatchGuard Fireware OS 
iked proc ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-19092 (The Tutor LMS WordPress plugin before 4.0.6 does not prevent 
request d ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18983 (The One User Avatar | User Profile Picture plugin for 
WordPress is vul ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18978 (The LiteSpeed Cache plugin for WordPress is vulnerable to 
Stored Cross ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18965 (PayRange APIis missing proper authorization on management 
endpoints, w ...)
        TODO: check
 CVE-2026-18886 (ServiceNow has remediated an improper access control 
vulnerability tha ...)
-       TODO: check
+       NOT-FOR-US: ServiceNow
 CVE-2026-18885 (ServiceNow has remediated a code injection vulnerability that 
was iden ...)
-       TODO: check
+       NOT-FOR-US: ServiceNow
 CVE-2026-18717 (ASE2000 2.35 through 2.37 is vulnerable to an improper 
certificate val ...)
        TODO: check
 CVE-2026-18324 (The Forminator Forms \u2013 Contact Form, Payment Form & 
Custom Form B ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17610 (In SiSDK v2026.6.0 and earlier, high network traffic loads can 
cause a ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-16759 (The Tutor LMS \u2013 eLearning and online course solution 
plugin for W ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16654 (The Avada (Fusion) Builder plugin for WordPress is vulnerable 
to Store ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15798 (The Smart Slider 3 plugin for WordPress is vulnerable to 
Stored Cross- ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13108 (WatchGuard Dimension is susceptible to a denial-of-service 
condition w ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-13086 (A stack-based buffer overflow in the epm (Endpoint Protection 
Manager) ...)
-       TODO: check
+       NOT-FOR-US: WatchGuard
 CVE-2026-10036 (SpeechBrain before 1.1.1 contains an arbitrary code execution 
vulnerab ...)
        TODO: check
 CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially 
crafted JPEG  ...)
@@ -117257,7 +117257,7 @@ CVE-2026-4429 (The OSM \u2013 OpenStreetMap plugin 
for WordPress is vulnerable t
 CVE-2026-4402
        REJECTED
 CVE-2026-4398 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-4336 (The Ultimate FAQ Accordion plugin for WordPress is vulnerable 
to Store ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-4332 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78da4a8d8b07e1c7a5817bf20116d97db44cd191

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78da4a8d8b07e1c7a5817bf20116d97db44cd191
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to