Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8e6e6726 by Salvatore Bonaccorso at 2026-09-03T21:55:42+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18,7 +18,7 @@ CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path
traversal vulnerabi
NOTE: https://github.com/rubyzip/rubyzip/issues/664
NOTE: Fixed by:
https://github.com/rubyzip/rubyzip/commit/17edfbf4423b83211b075acc23a7d8640da63449
(v3.4.0)
CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store,
update, and ke ...)
- TODO: check
+ NOT-FOR-US: UnoPim
CVE-2026-85394 (python-jose through 3.5.0 fails to properly validate
asymmetric keys i ...)
- python-jose <not-affected> (Incomplete fix for CVE-2024-33663 not
applied)
NOTE: https://github.com/mpdavis/python-jose/issues/414
@@ -26,15 +26,15 @@ CVE-2026-85394 (python-jose through 3.5.0 fails to properly
validate asymmetric
CVE-2026-85393 (node-forge through 1.4.0 fails to validate element count in
nested Dig ...)
TODO: check
CVE-2026-85392 (Peppermint through 0.5.5 contains an authorization bypass
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Peppermint Lab Peppermint
CVE-2026-85391 (Peppermint through 0.5.5 contains a hardcoded JWT signing
secret in do ...)
- TODO: check
+ NOT-FOR-US: Peppermint Lab Peppermint
CVE-2026-85390 (Checkmate through 3.11.0 omits the isAllowed role guard
middleware on ...)
- TODO: check
+ NOT-FOR-US: Checkmate
CVE-2026-85389 (Worklenz before 3.0.0 fails to verify task ownership by
organization w ...)
- TODO: check
+ NOT-FOR-US: Worklenz
CVE-2026-85388 (Worklenz through 3.0.0 fails to properly validate the
sort-field query ...)
- TODO: check
+ NOT-FOR-US: Worklenz
CVE-2026-85309 (Missing Authorization vulnerability in Supsystic Ultimate Maps
by Sups ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-85308 (Authorization Bypass Through User-Controlled Key vulnerability
in Brai ...)
@@ -52,7 +52,7 @@ CVE-2026-85303 (Improper Neutralization of Input During Web
Page Generation ('Cr
CVE-2026-85302 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-85242 (PlaywrightCapture contains a server-side request forgery
(SSRF) vulner ...)
- TODO: check
+ NOT-FOR-US: PlaywrightCapture
CVE-2026-85239 (A vulnerability in MISP's event template handling allowed an
authentic ...)
TODO: check
CVE-2026-85238 (MISP contains a session fixation vulnerability in the
CustomAuth authe ...)
@@ -72,39 +72,39 @@ CVE-2026-85221 (MISP contains an improper TLS certificate
validation vulnerabili
CVE-2026-85216 (MISP contains an authentication bypass vulnerability in its
LDAP and L ...)
TODO: check
CVE-2026-85214 (vhr fails to validate user authorization in the PUT /hr/info
endpoint, ...)
- TODO: check
+ NOT-FOR-US: vhr
CVE-2026-85213 (Kill Bill through 0.24.21 fails to enforce permission
annotations on s ...)
- TODO: check
+ NOT-FOR-US: Kill Bill
CVE-2026-85212 (CRMEB contains an authentication bypass vulnerability in the
verifyAut ...)
- TODO: check
+ NOT-FOR-US: CRMEB
CVE-2026-85211 (Label Studio fails to apply organization filters when
resolving storag ...)
- TODO: check
+ NOT-FOR-US: Label Studio
CVE-2026-85210 (Oppia's AdminRoleHandler GET endpoint in
core/controllers/admin.py is ...)
- TODO: check
+ NOT-FOR-US: Oppia
CVE-2026-85205 (A vulnerability was determined in itsourcecode Online Medicine
Deliver ...)
NOT-FOR-US: itsourcecode System
CVE-2026-85199 (Eclipse aeriOS Self-orchestrator versions prior to 1.2.1
contain a pat ...)
- TODO: check
+ NOT-FOR-US: Eclipse aeriOS Self-orchestrator
CVE-2026-85187 (A security vulnerability has been detected in itsourcecode
Online Medi ...)
NOT-FOR-US: itsourcecode System
CVE-2026-85186 (A weakness has been identified in itsourcecode Online Medicine
Deliver ...)
NOT-FOR-US: itsourcecode System
CVE-2026-85183 (Taipy configures its socket.io server with wildcard CORS
origin and cr ...)
- TODO: check
+ NOT-FOR-US: Taipy
CVE-2026-85182 (vhr through commit 03abbd3 fails to verify that the account ID
in PUT ...)
- TODO: check
+ NOT-FOR-US: vhr
CVE-2026-85181 (CAT uses Java String.hashCode as the sole integrity check for
session ...)
- TODO: check
+ NOT-FOR-US: CAT
CVE-2026-85180 (Ollama fails to validate redirect destinations when pulling
tensor-lay ...)
TODO: check
CVE-2026-85179 (Label Studio through 1.23.0 fails to validate webhook URLs,
allowing a ...)
- TODO: check
+ NOT-FOR-US: Label Studio
CVE-2026-85178 (Helicone's VaultManager.getDecryptedProviderKeyById() function
in the ...)
- TODO: check
+ NOT-FOR-US: Helicone
CVE-2026-85177 (CRMEB through 6.0.0 fails to validate message ownership in the
edit_me ...)
- TODO: check
+ NOT-FOR-US: CRMEB
CVE-2026-85176 (DbGate fails to validate jslid parameters in the jsldata
controller, a ...)
- TODO: check
+ NOT-FOR-US: DbGate
CVE-2026-85175 (SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an
incomplete block ...)
NOT-FOR-US: SiYuan
CVE-2026-85174 (SiYuan before v3.8.2 logs API tokens from query parameters in
plaintex ...)
@@ -128,27 +128,27 @@ CVE-2026-85166 (n8n before 2.35.4 and 2.36.x before
2.36.2 does not validate cre
CVE-2026-85165 (n8n versions before 2.36.2 contain an expression sandbox
bypass vulner ...)
NOT-FOR-US: n8n
CVE-2026-85164 (WWBN AVideo through commit c91b5975d contains a server-side
request fo ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85163 (AVideo through commit c91b5975d contains a server-side request
forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85162 (AVideo through commit c91b5975d contains a cross-site request
forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85161 (AVideo through commit c91b5975d contains a cross-site request
forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85160 (AVideo through commit c91b5975d contains a cross-site request
forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85159 (AVideo through commit c91b5975d contains a reflected
cross-site script ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85158 (AVideo through commit c91b5975d contains a reflected
cross-site script ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85157 (WWBN AVideo contains a broken access control vulnerability in
the unau ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85156 (WWBN AVideo fails to properly validate access controls on the
public c ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85155 (WWBN AVideo contains a SQL injection vulnerability in the sort
column ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85154 (WWBN AVideo contains an authentication failure vulnerability
where the ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85150 (A NULL pointer dereference flaw was found in GStreamer's RTSP
support ...)
TODO: check
CVE-2026-85138 (A vulnerability was detected in SeaCMS up to 13.6. Affected is
the fun ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e6e672608a6bf97c4e6f5e5b2c7aedd92700d6e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e6e672608a6bf97c4e6f5e5b2c7aedd92700d6e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits