Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6fe799f9 by Salvatore Bonaccorso at 2026-09-05T10:06:21+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9317 (Nango before 0.71.6 contains a missing authentication 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Nango
 CVE-2026-9186 (IBM Langflow OSS 1.0.0 through 1.11.2 allows remote 
authenticated atta ...)
        NOT-FOR-US: IBM
 CVE-2026-9138 (IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an 
authenti ...)
@@ -39,13 +39,13 @@ CVE-2026-86137 (In libxml2 before 2.15.4, 
xmlFAParsePosCharGroup has an out-of-b
        NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2
 (v2.15.4)
 CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate 
redirect ta ...)
-       TODO: check
+       NOT-FOR-US: Camaleon CMS
 CVE-2026-86098 (ntop nDPI versions before 6.0 contain a heap buffer overflow 
vulnerabi ...)
        TODO: check
 CVE-2026-86097 (PX4 Autopilot through 1.17.0 contains a null pointer 
dereference vulne ...)
-       TODO: check
+       NOT-FOR-US: PX4 Autopilot
 CVE-2026-86096 (PX4 Autopilot through 1.17.0 contains a use-after-free 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: PX4 Autopilot
 CVE-2026-86095 (Unidata netcdf-c through 4.10.1 contains an out-of-bounds 
write vulner ...)
        TODO: check
 CVE-2026-86091 (ntopng before 6.7.260717 fails to check user privileges in the 
pools b ...)
@@ -61,161 +61,161 @@ CVE-2026-85781 (Unverified ownership of a storage access 
point in the volume del
 CVE-2026-85769 (A flaw was found in libtpms, a library that provides software 
TPM 2.0  ...)
        TODO: check
 CVE-2026-85730 (smol-toml is a small, fast, and correct TOML parser and 
serializer. Pr ...)
-       TODO: check
+       NOT-FOR-US: smol-toml
 CVE-2026-85704 (A security flaw has been discovered in ramon-victor 
freegpt-webui up t ...)
-       TODO: check
+       NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85703 (A flaw has been found in ramon-victor freegpt-webui up to 
098db3dfeb41 ...)
-       TODO: check
+       NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85702 (A security vulnerability has been detected in ramon-victor 
freegpt-web ...)
-       TODO: check
+       NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85701 (A vulnerability has been found in ramon-victor freegpt-webui 
up to 098 ...)
-       TODO: check
+       NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85700 (Onyx 4.6.6 fails to properly restrict access to custom tool 
credential ...)
-       TODO: check
+       NOT-FOR-US: Onyx
 CVE-2026-85699 (jina-ai reader contains a server-side request forgery 
vulnerability wh ...)
-       TODO: check
+       NOT-FOR-US: jina-ai reader
 CVE-2026-85698 (Turso through 0.8.0-pre.8 contains an out-of-bounds read 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Turso
 CVE-2026-85697 (Documenso 2.17.0 contains an access control vulnerability in 
the PDF-s ...)
-       TODO: check
+       NOT-FOR-US: Documenso
 CVE-2026-85696 (SadTalker contains an OS command injection vulnerability in 
the video  ...)
-       TODO: check
+       NOT-FOR-US: SadTalker
 CVE-2026-85695 (FastChat contains an authentication bypass vulnerability in 
the /regis ...)
-       TODO: check
+       NOT-FOR-US: FastChat
 CVE-2026-85694 (LaVague 0.2.35 contains a remote code execution vulnerability 
in Pytho ...)
-       TODO: check
+       NOT-FOR-US: LaVague
 CVE-2026-85693 (Chatbot UI contains an authorization bypass vulnerability in 
the retri ...)
-       TODO: check
+       NOT-FOR-US: Chatbot UI
 CVE-2026-85692 (Nightingale (n9e), as of commit 8362cbe (main branch, 
confirmed 2026-0 ...)
-       TODO: check
+       NOT-FOR-US: Nightingale (n9e)
 CVE-2026-85691 (MegaParse 0.0.55 contains an unauthenticated server-side 
request forge ...)
-       TODO: check
+       NOT-FOR-US: MegaParse
 CVE-2026-85690 (Plandex 2.2.1 contains a path traversal vulnerability in the 
ApplyFile ...)
-       TODO: check
+       NOT-FOR-US: Plandex
 CVE-2026-85689 (llmware 0.4.6 contains an SQL injection vulnerability in the 
collectio ...)
-       TODO: check
+       NOT-FOR-US: llmware
 CVE-2026-85688 (TEN Framework 0.11.71 contains unauthenticated arbitrary file 
read and ...)
-       TODO: check
+       NOT-FOR-US: TEN Framework
 CVE-2026-85687 (surya 0.22.1 screenshot server contains an unauthenticated 
arbitrary f ...)
-       TODO: check
+       NOT-FOR-US: surya
 CVE-2026-85686 (ms-swift 4.5.2 contains a server-side request forgery 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: ms-swift
 CVE-2026-85685 (AgentScope through 2.0.7.post1 contains a path traversal 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: AgentScope
 CVE-2026-85684 (marker through 2.0.0 contains a path traversal vulnerability 
in the Fa ...)
-       TODO: check
+       NOT-FOR-US: marker
 CVE-2026-85676 (Dub contains an open redirect vulnerability in the redir_url 
query par ...)
-       TODO: check
+       NOT-FOR-US: Dub
 CVE-2026-85675 (OWL's DocumentProcessingToolkit contains a server-side request 
forgery ...)
-       TODO: check
+       NOT-FOR-US: OWL
 CVE-2026-85674 (aider (aider-chat) automatically loads a .aider.conf.yml 
configuration ...)
-       TODO: check
+       NOT-FOR-US: aider (aider-chat)
 CVE-2026-85673 (LLaMA-Factory contains a server-side request forgery 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: LLaMA-Factory
 CVE-2026-85672 (zerox 1.1.20 contains an OS command injection vulnerability in 
the fil ...)
-       TODO: check
+       NOT-FOR-US: zerox
 CVE-2026-85671 (QAnything 2.0.0 contains an authentication bypass 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: QAnything
 CVE-2026-85670 (tokenizers (Hugging Face) is affected by an out-of-bounds 
buffer acces ...)
-       TODO: check
+       NOT-FOR-US: tokenizers (Hugging Face)
 CVE-2026-85669 (potpie through 2.0.0 fails to verify user ownership on the 
POST /conve ...)
-       TODO: check
+       NOT-FOR-US: potpie
 CVE-2026-85668 (Xinference (affected commit 4a94832, v3.x) contains an 
unauthenticated ...)
-       TODO: check
+       NOT-FOR-US: Xinference
 CVE-2026-85667 (xiaobei through 5.5.2 fails to implement authentication or 
signature v ...)
-       TODO: check
+       NOT-FOR-US: xiaobei
 CVE-2026-85666 (OGX (formerly Llama Stack, affected at commit fbe8e0f) 
contains an una ...)
-       TODO: check
+       NOT-FOR-US: OGX
 CVE-2026-85665 (Bruno versions through 3.4.2 fail to validate file paths in 
request bo ...)
-       TODO: check
+       NOT-FOR-US: Bruno
 CVE-2026-85664 (Chroma 1.5.9 fails to validate maximum bounds on HNSW index 
parameters ...)
-       TODO: check
+       NOT-FOR-US: Chroma
 CVE-2026-85663 (Aim 3.29.1 remote tracking server fails to authenticate 
requests and d ...)
-       TODO: check
+       NOT-FOR-US: Aim
 CVE-2026-85662 (Marqo 2.26.0 contains a server-side request forgery 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: Marqo
 CVE-2026-85661 (excel-mcp-server 0.1.8 fails to enforce path confinement in 
stdio mode ...)
-       TODO: check
+       NOT-FOR-US: excel-mcp-server
 CVE-2026-85660 (cli-mcp-server 0.2.5 contains a command allowlist bypass 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: cli-mcp-server
 CVE-2026-85656 (An OS command injection issue in the 
log4j-cve-2021-44228-hotpatch pac ...)
        NOT-FOR-US: Amazon
 CVE-2026-85654 (Improper neutralization of special elements used in a template 
engine  ...)
        NOT-FOR-US: Amazon
 CVE-2026-85651 (Trigger.dev versions before 4.5.2 fail to validate environment 
members ...)
-       TODO: check
+       NOT-FOR-US: Trigger.dev
 CVE-2026-85650 (Trigger.dev before 4.5.2 contains a server-side request 
forgery vulner ...)
-       TODO: check
+       NOT-FOR-US: Trigger.dev
 CVE-2026-85649 ((Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier 
contains a fa ...)
-       TODO: check
+       NOT-FOR-US: (Holloway) Chew software-actualizer
 CVE-2026-85643 (A flaw has been found in code-projects Online Shopping System 
1.0. Imp ...)
        NOT-FOR-US: code-projects
 CVE-2026-85639 (A security vulnerability has been detected in jofpin trape 
2.0. This v ...)
-       TODO: check
+       NOT-FOR-US: jofpin trape
 CVE-2026-85638 (A weakness has been identified in jofpin trape 2.0. This 
affects an un ...)
-       TODO: check
+       NOT-FOR-US: jofpin trape
 CVE-2026-85637 (A security flaw has been discovered in jofpin trape 1.0.0/2.0. 
Affecte ...)
-       TODO: check
+       NOT-FOR-US: jofpin trape
 CVE-2026-85636 (A vulnerability was identified in jofpin trape 1.0.0. Affected 
by this ...)
-       TODO: check
+       NOT-FOR-US: jofpin trape
 CVE-2026-85626 (git-mcp-server 2.15.1 contains an argument injection 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: git-mcp-server
 CVE-2026-85625 (sift (sift.js) 17.1.3 enumerates query keys with for...in, 
which walks ...)
-       TODO: check
+       NOT-FOR-US: sift (sift.js)
 CVE-2026-85624 (Blinko 1.8.7 contains a cross-user private note disclosure 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Blinko
 CVE-2026-85623 (goose 1.37.0 executes arbitrary commands from recipe stdio 
extensions  ...)
-       TODO: check
+       NOT-FOR-US: goose
 CVE-2026-85622 (AppFlowy-Cloud through 0.9.64 fails to validate workspace 
membership w ...)
-       TODO: check
+       NOT-FOR-US: AppFlowy-Cloud
 CVE-2026-85621 (LobeChat (LobeHub) 2.2.1 does not properly verify inbound 
chat-platfor ...)
-       TODO: check
+       NOT-FOR-US: LobeChat (LobeHub)
 CVE-2026-85620 (Postgres MCP Pro 0.3.0 contains a restricted-mode bypass 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Postgres MCP Pro
 CVE-2026-85619 (AppFlowy-Cloud 0.9.64 fails to verify that requested collab 
objects be ...)
-       TODO: check
+       NOT-FOR-US: AppFlowy-Cloud
 CVE-2026-85618 (ConvertX 0.17.0 contains an arbitrary file read vulnerability 
in the x ...)
-       TODO: check
+       NOT-FOR-US: ConvertX
 CVE-2026-85617 (snipe-it versions before 8.6.3 contain an authorization bypass 
vulnera ...)
        TODO: check
 CVE-2026-85616 (Snipe-IT versions before 8.6.2 contain an authorization bypass 
vulnera ...)
        TODO: check
 CVE-2026-85615 (Openpanel before 2.3.0 contains an insecure direct object 
reference vu ...)
-       TODO: check
+       NOT-FOR-US: Openpanel
 CVE-2026-85614 (OpenPanel before 2.3.0 contains an unauthenticated server-side 
request ...)
-       TODO: check
+       NOT-FOR-US: Openpanel
 CVE-2026-85613 (OpenPanel before 2.3.0 contains a cross-site scripting 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Openpanel
 CVE-2026-85612 (OpenPanel before 2.3.0 contains an unauthenticated server-side 
request ...)
-       TODO: check
+       NOT-FOR-US: Openpanel
 CVE-2026-85611 (OpenPanel before 2.3.0 contains a cross-tenant broken object 
level aut ...)
-       TODO: check
+       NOT-FOR-US: Openpanel
 CVE-2026-85610 (OpenPanel before 2.3.0 fails to properly validate chart 
formula expres ...)
-       TODO: check
+       NOT-FOR-US: Openpanel
 CVE-2026-85609 (Openpanel before 2.3.0 contains an unauthenticated full-read 
server-si ...)
-       TODO: check
+       NOT-FOR-US: Openpanel
 CVE-2026-85608 (Douyin_TikTok_Download_API through 4.1.2 contains a 
server-side reques ...)
-       TODO: check
+       NOT-FOR-US: Douyin_TikTok_Download_API
 CVE-2026-85607 (Blinko 1.8.7 contains an authorization bypass (IDOR) 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Blinko
 CVE-2026-85606 (firecrawl-mcp-server 3.20.2 contains an arbitrary local file 
read vuln ...)
-       TODO: check
+       NOT-FOR-US: firecrawl-mcp-server
 CVE-2026-85605 (Slink before 1.12.3 fails to properly authorize access to 
image commen ...)
-       TODO: check
+       NOT-FOR-US: Slink
 CVE-2026-85604 (Grav before 2.0.19 (affected versions <= 2.0.17) contains a 
remote cod ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-85603 (Grav versions before 1.10.55 contain a path traversal 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-85602 (The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 
through ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS plugin
 CVE-2026-85601 (Grav Admin before 2.0.20 fails to sanitize output from 
marked.parse()  ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-85600 (Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 
contain a s ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-85599 (Grav Shortcode Core before 6.2.5 contains stored cross-site 
scripting  ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-85598 (Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS 
detecti ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-85597 (Traefik before v2.11.55 contains a TLS option conflict 
resolution vuln ...)
        TODO: check
 CVE-2026-85596 (Traefik versions >= v3.7.0 and <= v3.7.10 contain an 
authentication by ...)
@@ -225,21 +225,21 @@ CVE-2026-85595 (Traefik versions before v2.11.55 contain 
an authentication bypas
 CVE-2026-85594 (Traefik versions from v3.7.1 fail to enforce 
crossProviderNamespaces r ...)
        TODO: check
 CVE-2026-85593 (phpMyFAQ versions before 4.1.8 contain a stored cross-site 
scripting v ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85592 (phpMyFAQ before 4.1.8 contains an authorization bypass 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85591 (phpMyFAQ versions before 4.1.8 contain an authentication 
bypass vulner ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85590 (phpMyFAQ before 4.1.8 contains an authentication bypass 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85589 (phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85588 (phpMyFAQ versions before 4.1.8 include live TOTP shared 
secrets in pla ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85587 (phpMyFAQ before 4.1.8 enforces incorrect permission checks on 
admin co ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85586 (phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when 
the store ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-85585 (SiYuan before v3.8.2 contains an unbounded resource 
consumption vulner ...)
        NOT-FOR-US: SiYuan
 CVE-2026-85584 (SiYuan versions before v3.8.2 contain a denial of service 
vulnerabilit ...)
@@ -257,15 +257,15 @@ CVE-2026-85579 (SiYuan is affected by an information 
disclosure vulnerability (c
 CVE-2026-85578 (SiYuan through 3.8.1 contains an authorization bypass 
vulnerability in ...)
        NOT-FOR-US: SiYuan
 CVE-2026-85577 (AVideo through commit c91b5975d contains a reflected 
cross-site script ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-85547 (A cross-site request forgery (CSRF) vulnerability exists in 
MISP due t ...)
        TODO: check
 CVE-2026-85546 (MISP contains a cross-site request forgery (CSRF) 
vulnerability in the ...)
        TODO: check
 CVE-2026-85541 (DreamMaker developed by Interinfo has a Reflected Cross-site 
Scripting ...)
-       TODO: check
+       NOT-FOR-US: Interinfo
 CVE-2026-85540 (DreamMaker developed by Interinfo has a SQL Injection 
vulnerability. A ...)
-       TODO: check
+       NOT-FOR-US: Interinfo
 CVE-2026-85538 (An incorrect authorization vulnerability in MISP allowed 
authenticated ...)
        TODO: check
 CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2 
request bod ...)
@@ -273,9 +273,9 @@ CVE-2026-85534 (A flaw was found in libsoup. When a client 
sends an HTTP/2 reque
 CVE-2026-85533 (An authorization flaw in MISP allowed an authenticated user to 
submit  ...)
        TODO: check
 CVE-2026-85528 (Improper input validation of the auto-configuration account 
identifier ...)
-       TODO: check
+       NOT-FOR-US: Snowflake JDBC Driver
 CVE-2026-85525 (Improper OCSP response validation in the Snowflake Python, Go, 
JDBC, a ...)
-       TODO: check
+       NOT-FOR-US: Snowflake Drivers
 CVE-2026-85522 (A vulnerability was detected in valkey-io valkey up to 
9.5.4/9.1.0. Af ...)
        TODO: check
 CVE-2026-85517 (A flaw has been found in code-projects Vehicle Management 
System 1.0.  ...)
@@ -283,9 +283,9 @@ CVE-2026-85517 (A flaw has been found in code-projects 
Vehicle Management System
 CVE-2026-85516 (A vulnerability was detected in code-projects Vehicle 
Management Syste ...)
        NOT-FOR-US: code-projects
 CVE-2026-85514 (A security vulnerability has been detected in StackStorm st2 
up to 3.9 ...)
-       TODO: check
+       NOT-FOR-US: StackStorm
 CVE-2026-85513 (A weakness has been identified in StackStorm st2 up to 3.9.0. 
This iss ...)
-       TODO: check
+       NOT-FOR-US: StackStorm
 CVE-2026-85512 (A security flaw has been discovered in SourceCodester Class 
and Exam T ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-85311 (Missing Authorization vulnerability in Kings Plugins 
MarketKing allows ...)
@@ -295,7 +295,7 @@ CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper 
neutralization of input
 CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a 
Man-in-the ...)
        TODO: check
 CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide 
whether to r ...)
-       TODO: check
+       NOT-FOR-US: fastify/middie
 CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and 
request- ...)
        TODO: check
 CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate 
size-limit  ...)
@@ -339,11 +339,11 @@ CVE-2026-84890 (undici's decompress interceptor 
decompresses response bodies acc
 CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not 
restrict ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-84504 (fastify versions before 5.12.2 treat the object resolved by a 
successf ...)
-       TODO: check
+       NOT-FOR-US: fastify
 CVE-2026-84469 (fastify versions before 5.12.2 decide whether to compile a 
request sch ...)
-       TODO: check
+       NOT-FOR-US: fastify
 CVE-2026-84428 (fastify versions before 5.12.2 implement the case-insensitive 
nature o ...)
-       TODO: check
+       NOT-FOR-US: fastify
 CVE-2026-84225 (The Kirki  WordPress plugin before 6.3.0 does not check that a 
user is ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-84221 (The Kirki  WordPress plugin before 6.3.0 does not escape a 
user-suppli ...)
@@ -369,7 +369,7 @@ CVE-2026-83543 (The Greenshift  WordPress plugin before 
13.2.0 does not validate
 CVE-2026-82923 (The AI Website Builder WordPress plugin (GitHub build) 1.0.0 
does not  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the 
OrderConfirmController at GET ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-82846 (The Masteriyo LMS  WordPress plugin before 3.4.0 does not 
sanitise and ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in 
elixir-mint mint a ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fe799f91d16a3ff9c4df9ecd10bcbd4b81dcf87

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fe799f91d16a3ff9c4df9ecd10bcbd4b81dcf87
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to