Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0904b210 by Salvatore Bonaccorso at 2026-09-10T22:07:40+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -48,45 +48,45 @@ CVE-2026-88921 (MISP contains an HTML injection 
vulnerability in the MISPElement
 CVE-2026-88915 (Affected versions of MISP do not consistently enforce the 
acting user' ...)
        - misp <itp> (bug #1144317)
 CVE-2026-88899 (knowns versions before 0.31.0 fail to properly validate the 
x-opencode ...)
-       TODO: check
+       NOT-FOR-US: knowns-dev/knowns
 CVE-2026-88898 (AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize 
callers ...)
-       TODO: check
+       NOT-FOR-US: AppFlowy-Cloud
 CVE-2026-88897 (Flextype CMS through 1.0.0-alpha.3 accepts API authentication 
credenti ...)
-       TODO: check
+       NOT-FOR-US: Flextype CMS
 CVE-2026-88896 (EspoCRM before 10.0.4 is vulnerable to server-side request 
forgery. Ho ...)
-       TODO: check
+       NOT-FOR-US: EspoCRM
 CVE-2026-88895 (CyberPanel before 3.0.5 fails to enforce two-factor 
authentication on  ...)
-       TODO: check
+       NOT-FOR-US: CyberPanel
 CVE-2026-88894 (Snipe-IT's predefined kit checkout path does not enforce Full 
Multiple ...)
        TODO: check
 CVE-2026-88893 (OpenPanel share lookup procedures fail to validate access 
controls and ...)
-       TODO: check
+       NOT-FOR-US: OpenPanel
 CVE-2026-88892 (OpenPanel is an analytics platform. In all versions (no 
patched releas ...)
-       TODO: check
+       NOT-FOR-US: OpenPanel
 CVE-2026-88891 (OpenPanel fails to enforce read-only project access level on 
26 of 29  ...)
-       TODO: check
+       NOT-FOR-US: OpenPanel
 CVE-2026-88890 (OpenPanel through commit cd24bb8 contains an SQL injection 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: OpenPanel
 CVE-2026-88889 (Renovate before 44.14.7 contains a command injection 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88888 (Renovate before 44.14.7 contains a command injection 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88887 (Renovate is a dependency update automation tool. When listing 
tags/dig ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88886 (Renovate is a dependency update automation tool. In versions 
before 44 ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88885 (Renovate before 44.14.7 contains a command injection 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88884 (Renovate is a dependency update automation tool. In versions 
before 44 ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88883 (Renovate is an automated dependency update tool. In versions 
before 44 ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88882 (Renovate is a dependency update automation tool. In versions 
before 44 ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88881 (Renovate, a dependency update tool, follows pagination links 
supplied  ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88880 (Renovate before 44.11.3 fails to validate Link header 
destinations whe ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-88879 (Traefik is an HTTP reverse proxy and load balancer. In Traefik 
v1.x, v ...)
        - traefik <itp> (bug #983289)
 CVE-2026-88878 (Traefik is an HTTP reverse proxy and load balancer. In 
versions >= v2. ...)
@@ -94,29 +94,29 @@ CVE-2026-88878 (Traefik is an HTTP reverse proxy and load 
balancer. In versions
 CVE-2026-88877 (Traefik is a HTTP reverse proxy and load balancer. In versions 
>= v3.7 ...)
        - traefik <itp> (bug #983289)
 CVE-2026-88876 (AVideo through revision 
c3edcc274c389816d434acadac07ee78eaf330c1 conta ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88875 (AVideo through revision 
c3edcc274c389816d434acadac07ee78eaf330c1 (mast ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88874 (AVideo through revision 
c3edcc274c389816d434acadac07ee78eaf330c1 (mast ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88873 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88872 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88871 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 (m ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88870 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88869 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88868 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88867 (WWBN AVideo, in versions up to and including commit 
c3edcc274c389816d4 ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88866 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88865 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
fails t ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-88864 (Capgo (capgo.app) fails to restrict direct write access to the 
public. ...)
        TODO: check
 CVE-2026-88863 (capgo.app (npm package `capgo`) through version 12.207.1 does 
not comp ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0904b210e65367e911c8e68651ba8c66f31da29f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0904b210e65367e911c8e68651ba8c66f31da29f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to