Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8e6e6726 by Salvatore Bonaccorso at 2026-09-03T21:55:42+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18,7 +18,7 @@ CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path 
traversal vulnerabi
        NOTE: https://github.com/rubyzip/rubyzip/issues/664
        NOTE: Fixed by: 
https://github.com/rubyzip/rubyzip/commit/17edfbf4423b83211b075acc23a7d8640da63449
 (v3.4.0)
 CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store, 
update, and ke ...)
-       TODO: check
+       NOT-FOR-US: UnoPim
 CVE-2026-85394 (python-jose through 3.5.0 fails to properly validate 
asymmetric keys i ...)
        - python-jose <not-affected> (Incomplete fix for CVE-2024-33663 not 
applied)
        NOTE: https://github.com/mpdavis/python-jose/issues/414
@@ -26,15 +26,15 @@ CVE-2026-85394 (python-jose through 3.5.0 fails to properly 
validate asymmetric
 CVE-2026-85393 (node-forge through 1.4.0 fails to validate element count in 
nested Dig ...)
        TODO: check
 CVE-2026-85392 (Peppermint through 0.5.5 contains an authorization bypass 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Peppermint Lab Peppermint
 CVE-2026-85391 (Peppermint through 0.5.5 contains a hardcoded JWT signing 
secret in do ...)
-       TODO: check
+       NOT-FOR-US: Peppermint Lab Peppermint
 CVE-2026-85390 (Checkmate through 3.11.0 omits the isAllowed role guard 
middleware on  ...)
-       TODO: check
+       NOT-FOR-US: Checkmate
 CVE-2026-85389 (Worklenz before 3.0.0 fails to verify task ownership by 
organization w ...)
-       TODO: check
+       NOT-FOR-US: Worklenz
 CVE-2026-85388 (Worklenz through 3.0.0 fails to properly validate the 
sort-field query ...)
-       TODO: check
+       NOT-FOR-US: Worklenz
 CVE-2026-85309 (Missing Authorization vulnerability in Supsystic Ultimate Maps 
by Sups ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85308 (Authorization Bypass Through User-Controlled Key vulnerability 
in Brai ...)
@@ -52,7 +52,7 @@ CVE-2026-85303 (Improper Neutralization of Input During Web 
Page Generation ('Cr
 CVE-2026-85302 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85242 (PlaywrightCapture contains a server-side request forgery 
(SSRF) vulner ...)
-       TODO: check
+       NOT-FOR-US: PlaywrightCapture
 CVE-2026-85239 (A vulnerability in MISP's event template handling allowed an 
authentic ...)
        TODO: check
 CVE-2026-85238 (MISP contains a session fixation vulnerability in the 
CustomAuth authe ...)
@@ -72,39 +72,39 @@ CVE-2026-85221 (MISP contains an improper TLS certificate 
validation vulnerabili
 CVE-2026-85216 (MISP contains an authentication bypass vulnerability in its 
LDAP and L ...)
        TODO: check
 CVE-2026-85214 (vhr fails to validate user authorization in the PUT /hr/info 
endpoint, ...)
-       TODO: check
+       NOT-FOR-US: vhr
 CVE-2026-85213 (Kill Bill through 0.24.21 fails to enforce permission 
annotations on s ...)
-       TODO: check
+       NOT-FOR-US: Kill Bill
 CVE-2026-85212 (CRMEB contains an authentication bypass vulnerability in the 
verifyAut ...)
-       TODO: check
+       NOT-FOR-US: CRMEB
 CVE-2026-85211 (Label Studio fails to apply organization filters when 
resolving storag ...)
-       TODO: check
+       NOT-FOR-US: Label Studio
 CVE-2026-85210 (Oppia's AdminRoleHandler GET endpoint in 
core/controllers/admin.py is  ...)
-       TODO: check
+       NOT-FOR-US: Oppia
 CVE-2026-85205 (A vulnerability was determined in itsourcecode Online Medicine 
Deliver ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-85199 (Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 
contain a pat ...)
-       TODO: check
+       NOT-FOR-US: Eclipse aeriOS Self-orchestrator
 CVE-2026-85187 (A security vulnerability has been detected in itsourcecode 
Online Medi ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-85186 (A weakness has been identified in itsourcecode Online Medicine 
Deliver ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-85183 (Taipy configures its socket.io server with wildcard CORS 
origin and cr ...)
-       TODO: check
+       NOT-FOR-US: Taipy
 CVE-2026-85182 (vhr through commit 03abbd3 fails to verify that the account ID 
in PUT  ...)
-       TODO: check
+       NOT-FOR-US: vhr
 CVE-2026-85181 (CAT uses Java String.hashCode as the sole integrity check for 
session  ...)
-       TODO: check
+       NOT-FOR-US: CAT
 CVE-2026-85180 (Ollama fails to validate redirect destinations when pulling 
tensor-lay ...)
        TODO: check
 CVE-2026-85179 (Label Studio through 1.23.0 fails to validate webhook URLs, 
allowing a ...)
-       TODO: check
+       NOT-FOR-US: Label Studio
 CVE-2026-85178 (Helicone's VaultManager.getDecryptedProviderKeyById() function 
in the  ...)
-       TODO: check
+       NOT-FOR-US: Helicone
 CVE-2026-85177 (CRMEB through 6.0.0 fails to validate message ownership in the 
edit_me ...)
-       TODO: check
+       NOT-FOR-US: CRMEB
 CVE-2026-85176 (DbGate fails to validate jslid parameters in the jsldata 
controller, a ...)
-       TODO: check
+       NOT-FOR-US: DbGate
 CVE-2026-85175 (SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an 
incomplete block ...)
        NOT-FOR-US: SiYuan
 CVE-2026-85174 (SiYuan before v3.8.2 logs API tokens from query parameters in 
plaintex ...)
@@ -128,27 +128,27 @@ CVE-2026-85166 (n8n before 2.35.4 and 2.36.x before 
2.36.2 does not validate cre
 CVE-2026-85165 (n8n versions before 2.36.2 contain an expression sandbox 
bypass vulner ...)
        NOT-FOR-US: n8n
 CVE-2026-85164 (WWBN AVideo through commit c91b5975d contains a server-side 
request fo ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85163 (AVideo through commit c91b5975d contains a server-side request 
forgery ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85162 (AVideo through commit c91b5975d contains a cross-site request 
forgery  ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85161 (AVideo through commit c91b5975d contains a cross-site request 
forgery  ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85160 (AVideo through commit c91b5975d contains a cross-site request 
forgery  ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85159 (AVideo through commit c91b5975d contains a reflected 
cross-site script ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85158 (AVideo through commit c91b5975d contains a reflected 
cross-site script ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85157 (WWBN AVideo contains a broken access control vulnerability in 
the unau ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85156 (WWBN AVideo fails to properly validate access controls on the 
public c ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85155 (WWBN AVideo contains a SQL injection vulnerability in the sort 
column  ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85154 (WWBN AVideo contains an authentication failure vulnerability 
where the ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85150 (A NULL pointer dereference flaw was found in GStreamer's RTSP 
support  ...)
        TODO: check
 CVE-2026-85138 (A vulnerability was detected in SeaCMS up to 13.6. Affected is 
the fun ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e6e672608a6bf97c4e6f5e5b2c7aedd92700d6e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e6e672608a6bf97c4e6f5e5b2c7aedd92700d6e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to