Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
0904b210 by Salvatore Bonaccorso at 2026-09-10T22:07:40+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -48,45 +48,45 @@ CVE-2026-88921 (MISP contains an HTML injection
vulnerability in the MISPElement
CVE-2026-88915 (Affected versions of MISP do not consistently enforce the
acting user' ...)
- misp <itp> (bug #1144317)
CVE-2026-88899 (knowns versions before 0.31.0 fail to properly validate the
x-opencode ...)
- TODO: check
+ NOT-FOR-US: knowns-dev/knowns
CVE-2026-88898 (AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize
callers ...)
- TODO: check
+ NOT-FOR-US: AppFlowy-Cloud
CVE-2026-88897 (Flextype CMS through 1.0.0-alpha.3 accepts API authentication
credenti ...)
- TODO: check
+ NOT-FOR-US: Flextype CMS
CVE-2026-88896 (EspoCRM before 10.0.4 is vulnerable to server-side request
forgery. Ho ...)
- TODO: check
+ NOT-FOR-US: EspoCRM
CVE-2026-88895 (CyberPanel before 3.0.5 fails to enforce two-factor
authentication on ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-88894 (Snipe-IT's predefined kit checkout path does not enforce Full
Multiple ...)
TODO: check
CVE-2026-88893 (OpenPanel share lookup procedures fail to validate access
controls and ...)
- TODO: check
+ NOT-FOR-US: OpenPanel
CVE-2026-88892 (OpenPanel is an analytics platform. In all versions (no
patched releas ...)
- TODO: check
+ NOT-FOR-US: OpenPanel
CVE-2026-88891 (OpenPanel fails to enforce read-only project access level on
26 of 29 ...)
- TODO: check
+ NOT-FOR-US: OpenPanel
CVE-2026-88890 (OpenPanel through commit cd24bb8 contains an SQL injection
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: OpenPanel
CVE-2026-88889 (Renovate before 44.14.7 contains a command injection
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88888 (Renovate before 44.14.7 contains a command injection
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88887 (Renovate is a dependency update automation tool. When listing
tags/dig ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88886 (Renovate is a dependency update automation tool. In versions
before 44 ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88885 (Renovate before 44.14.7 contains a command injection
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88884 (Renovate is a dependency update automation tool. In versions
before 44 ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88883 (Renovate is an automated dependency update tool. In versions
before 44 ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88882 (Renovate is a dependency update automation tool. In versions
before 44 ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88881 (Renovate, a dependency update tool, follows pagination links
supplied ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88880 (Renovate before 44.11.3 fails to validate Link header
destinations whe ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-88879 (Traefik is an HTTP reverse proxy and load balancer. In Traefik
v1.x, v ...)
- traefik <itp> (bug #983289)
CVE-2026-88878 (Traefik is an HTTP reverse proxy and load balancer. In
versions >= v2. ...)
@@ -94,29 +94,29 @@ CVE-2026-88878 (Traefik is an HTTP reverse proxy and load
balancer. In versions
CVE-2026-88877 (Traefik is a HTTP reverse proxy and load balancer. In versions
>= v3.7 ...)
- traefik <itp> (bug #983289)
CVE-2026-88876 (AVideo through revision
c3edcc274c389816d434acadac07ee78eaf330c1 conta ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88875 (AVideo through revision
c3edcc274c389816d434acadac07ee78eaf330c1 (mast ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88874 (AVideo through revision
c3edcc274c389816d434acadac07ee78eaf330c1 (mast ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88873 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88872 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88871 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 (m ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88870 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88869 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88868 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
contain ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88867 (WWBN AVideo, in versions up to and including commit
c3edcc274c389816d4 ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88866 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88865 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
fails t ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-88864 (Capgo (capgo.app) fails to restrict direct write access to the
public. ...)
TODO: check
CVE-2026-88863 (capgo.app (npm package `capgo`) through version 12.207.1 does
not comp ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0904b210e65367e911c8e68651ba8c66f31da29f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0904b210e65367e911c8e68651ba8c66f31da29f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits