Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9a1e3aa1 by Salvatore Bonaccorso at 2026-09-01T21:56:44+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13,7 +13,7 @@ CVE-2026-9622 (A denial-of-service security issue exists
within RSLinx\xae Class
CVE-2026-9621 (A denial-of-service security issue exists within RSLinx\xae
Classic. T ...)
NOT-FOR-US: Rockwell Automation
CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Wyoming
CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
- sqlparse <unfixed>
NOTE:
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
@@ -62,71 +62,71 @@ CVE-2026-84235 (A denial-of-service security issue exists
in the affected produc
CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a
specially cra ...)
TODO: check
CVE-2026-84232 (A flaw was found in pulpcore's content serving application.
Files uplo ...)
- TODO: check
+ NOT-FOR-US: pulpcore
CVE-2026-84218 (A flaw was found in Jolokia's JSR-160 proxy functionality
where insuff ...)
- TODO: check
+ NOT-FOR-US: Jolokia
CVE-2026-84207 (Heym before 0.0.98 fails to apply SSRF egress guards to
WebSocket Send ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-84206 (Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on
the ass ...)
TODO: check
CVE-2026-84205 (GROWI contains an access control vulnerability in the GET
/_api/v3/rev ...)
- TODO: check
+ NOT-FOR-US: GROWI
CVE-2026-84204 (GROWI contains an access control vulnerability in the GET
/_api/v3/att ...)
- TODO: check
+ NOT-FOR-US: GROWI
CVE-2026-84203 (Memos versions 0.26.0 through 0.30.0 fail to revoke refresh
tokens whe ...)
- TODO: check
+ NOT-FOR-US: Memos
CVE-2026-84202 (ModelScope uses PyYAML's unsafe yaml.Loader to parse model
configurati ...)
- TODO: check
+ NOT-FOR-US: ModelScope
CVE-2026-84201 (appium-mcp-server through 0.1.61 fails to validate or
normalize file p ...)
- TODO: check
+ NOT-FOR-US: appium-mcp-server
CVE-2026-84200 (Kyverno versions v1.9.0 through v1.12.7 contain a policy
exception han ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84199 (Kyverno before 1.16.2 contains a server-side request forgery
(SSRF) vu ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84196 (Kyverno before 1.18.0 contains a server-side request forgery
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84195 (Kyverno before 1.16.4 automatically attaches the admission
controller' ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84194 (LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0)
contain an ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84193 (LibreNMS through 26.2.0 contains a stored cross-site scripting
vulnera ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84192 (LibreNMS before 26.3.1 contains a stored cross-site scripting
vulnerab ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84191 (LibreNMS before 26.5.0 contains stored cross-site scripting
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84190 (LibreNMS versions before 26.5.0 contain a remote code
execution vulner ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84189 (LibreNMS through 26.4.0 renders JSON fields (name, ip, model,
author, ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84188 (LibreNMS versions <= 26.4.0 contain a stored cross-site
scripting vuln ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84187 (AVideo contains a missing authentication vulnerability in
plugin/Live/ ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-84165 (A vulnerability relating to incorrect access control in
OpenNebula by ...)
TODO: check
CVE-2026-84153 (A vulnerability was determined in Xinhu Rainrock RockOA up to
2.3.2. T ...)
- TODO: check
+ NOT-FOR-US: Xinhu Rainrock RockOA
CVE-2026-84149 (This vulnerability exists in the ERP system due to exposure of
reposit ...)
- TODO: check
+ NOT-FOR-US: Multi-tenant ERP System
CVE-2026-84148 (This vulnerability exists in the ERP system due to improper
authentica ...)
- TODO: check
+ NOT-FOR-US: Multi-tenant ERP System
CVE-2026-84147 (This vulnerability exists in the ERP system due to improper
authentica ...)
- TODO: check
+ NOT-FOR-US: Multi-tenant ERP System
CVE-2026-84115 (A vulnerability was found in Cleo Harmony up to 5.8.1.10. The
affected ...)
- TODO: check
+ NOT-FOR-US: Cleo Harmony
CVE-2026-84114 (A vulnerability has been found in Cleo Harmony up to 5.8.1.10.
Impacte ...)
- TODO: check
+ NOT-FOR-US: Cleo Harmony
CVE-2026-84111 (A flaw has been found in Chanjet CRM up to 20260707. This
issue affect ...)
- TODO: check
+ NOT-FOR-US: Chanjet CRM
CVE-2026-84110 (A vulnerability was detected in Releasit Releasit COD Form &
Upsells v ...)
- TODO: check
+ NOT-FOR-US: Releasit Releasit COD Form & Upsells
CVE-2026-84109 (A weakness has been identified in Xinhu Rainrock RockOA up to
2.7.6. A ...)
- TODO: check
+ NOT-FOR-US: Xinhu Rainrock RockOA
CVE-2026-84061 (A security flaw has been discovered in zhongyu09 OpenChatBI up
to 0.3. ...)
- TODO: check
+ NOT-FOR-US: zhongyu09 OpenChatBI
CVE-2026-84059 (A flaw has been found in ICP DAS UA-2200 and UA-5200 up to
20260704. T ...)
- TODO: check
+ NOT-FOR-US: ICP DAS UA-2200 and UA-5200
CVE-2026-83619 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level
2 Core) ...)
TODO: check
CVE-2026-83618 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level
2 Core) ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a1e3aa1d6b2308b2e14b56d304a8eb2570dfdcd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a1e3aa1d6b2308b2e14b56d304a8eb2570dfdcd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits