Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c780ef26 by Salvatore Bonaccorso at 2026-09-11T05:44:18+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,7 +9,7 @@ CVE-2026-9163 (Improper neutralization of special elements used
in an SQL comman
CVE-2026-9161 (Observable response discrepancy vulnerability in DernekPlus
Website Te ...)
NOT-FOR-US: DernekPlus
CVE-2026-8323 (URL redirection to untrusted site ('open redirect')
vulnerability in A ...)
- TODO: check
+ NOT-FOR-US: Armiya Information Technologies
CVE-2026-89049 (A server-side request forgery issue due to improper validation
of equi ...)
NOT-FOR-US: Amazon
CVE-2026-89046 (zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an
out-of-bounds re ...)
@@ -244,9 +244,9 @@ CVE-2026-88030 (Improper neutralization of special elements
in data query logic
CVE-2026-88029 (Improper neutralization of special elements in data query
logic in the ...)
TODO: check
CVE-2026-88028 (Improper neutralization of special elements in data query
logic in the ...)
- TODO: check
+ NOT-FOR-US: MongoDB integration for Laravel
CVE-2026-88027 (Improper neutralization of special elements in data query
logic in the ...)
- TODO: check
+ NOT-FOR-US: MongoDB integration for Laravel
CVE-2026-88026 (Improper neutralization of regular-expression metacharacters
in the LI ...)
NOT-FOR-US: MongoDB C# Driver
CVE-2026-88025 (Improper neutralization of special elements in data query
logic in the ...)
@@ -254,9 +254,9 @@ CVE-2026-88025 (Improper neutralization of special elements
in data query logic
CVE-2026-88024 (Improper neutralization of special elements in data query
logic in the ...)
NOT-FOR-US: MongoDB Rust Driver
CVE-2026-88023 (Improper neutralization of special elements in data query
logic in the ...)
- TODO: check
+ NOT-FOR-US: MongoDB PHP Library
CVE-2026-88022 (Improper neutralization of special elements in data query
logic in the ...)
- TODO: check
+ NOT-FOR-US: MongoDB integration for Laravel
CVE-2026-88021 (Consul and Consul Enterprise are vulnerable to an
authorization bypass ...)
TODO: check
CVE-2026-88018 (rclone is a command-line program to sync files and directories
to and ...)
@@ -299,23 +299,23 @@ CVE-2026-88008 (Traefik is an open source HTTP reverse
proxy and load balancer.
CVE-2026-88007 (Traefik is an open source HTTP reverse proxy and load
balancer. From 2 ...)
- traefik <itp> (bug #983289)
CVE-2026-88006 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-88005 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
- TODO: check
+ NOT-FOR-US: Open WebUI
CVE-2026-88004 (Traefik is an open source HTTP reverse proxy and load
balancer. From 3 ...)
- traefik <itp> (bug #983289)
CVE-2026-87993 (The consul-template library is vulnerable to an information
disclosure ...)
- TODO: check
+ NOT-FOR-US: consul-template
CVE-2026-87962 (t-digest versions 3.1 through 3.3 contain a denial of service
vulnerab ...)
- TODO: check
+ NOT-FOR-US: t-digest
CVE-2026-87961 (ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a
heap-based out-o ...)
- TODO: check
+ NOT-FOR-US: ESP32-audioI2S
CVE-2026-87913 (A missing S3 bucket ownership verification in the AWS Security
Agent M ...)
NOT-FOR-US: Amazon
CVE-2026-87912 (A missing S3 bucket ownership verification in the AWS Security
Agent p ...)
NOT-FOR-US: Amazon
CVE-2026-87803 (An authorization bypass vulnerability exists in the Countly
Server DBV ...)
- TODO: check
+ NOT-FOR-US: Countly
CVE-2026-87107 (Consul and Consul Enterprise are vulnerable to an
authorization bypass ...)
TODO: check
CVE-2026-87106 (Consul and Consul Enterprise are vulnerable to a denial of
service in ...)
@@ -425,15 +425,15 @@ CVE-2026-78083 (Joomla Extension - joomshaper.com -
Missing CSRF Token Verificat
CVE-2026-78082 (Joomla Extension - joomshaper.com - Unauthenticated SQL
Injection in P ...)
NOT-FOR-US: Joomla
CVE-2026-75584 (ION-DTN before 4.2.1-a.1 contains a denial of service
vulnerability th ...)
- TODO: check
+ NOT-FOR-US: NASA ION-DTN
CVE-2026-73699 (FileRun before 2026.3.0 contains a PHP object injection
vulnerability ...)
- TODO: check
+ NOT-FOR-US: FileRun
CVE-2026-73698 (FileRun before 2026.3.0 contains a SQL injection vulnerability
that al ...)
- TODO: check
+ NOT-FOR-US: FileRun
CVE-2026-73694 (FileRun before 2026.3.0 contains an OS command injection
vulnerability ...)
- TODO: check
+ NOT-FOR-US: FileRun
CVE-2026-73693 (FileRun before 2026.3.0 contains an OS command injection
vulnerability ...)
- TODO: check
+ NOT-FOR-US: FileRun
CVE-2026-6285 (Weak Password Recovery Mechanism for Forgotten Password
vulnerability ...)
TODO: check
CVE-2026-68527 (Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an
authori ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c780ef26a138d67fb39e47966289de9044e01b7e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c780ef26a138d67fb39e47966289de9044e01b7e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits