Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3e8ce0c8 by Salvatore Bonaccorso at 2026-09-11T10:21:45+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -26,11 +26,11 @@ CVE-2026-89161 (In PCRE2 before 10.48, pcre2_jit_match 
mishandles a previously c
 CVE-2026-89151 (Forgejo before 16.0.4 allows use of restricted API tokens for 
unintend ...)
        - forgejo <itp> (bug #1058932)
 CVE-2026-89145 (Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to 
HTML-escape  ...)
-       TODO: check
+       NOT-FOR-US: Flextype CMS
 CVE-2026-89094 (Forgejo before 16.0.4 allows remote code execution via a 
crafted templ ...)
        - forgejo <itp> (bug #1058932)
 CVE-2026-89089 (A SQL injection vulnerability exists in the 
JasperReports-based report ...)
-       TODO: check
+       NOT-FOR-US: OpenNMS
 CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
        TODO: check
 CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to 
validate ...)
@@ -38,13 +38,13 @@ CVE-2026-89086 (In the jose package before 0.11.0 for 
OCaml, library calls to va
 CVE-2026-89060 (A flaw was found in multicluster-observability-addon. This 
vulnerabili ...)
        TODO: check
 CVE-2026-89054 (A missing authorization vulnerability in OpenNMS Horizon 
allows config ...)
-       TODO: check
+       NOT-FOR-US: OpenNMS
 CVE-2026-88260 (Authentication bypass using an alternate path or channel and 
Improper  ...)
-       TODO: check
+       NOT-FOR-US: Brainzcompany Zenius EMS
 CVE-2026-88062 (OmniRoute is an open-source AI gateway providing a single 
endpoint for ...)
-       TODO: check
+       NOT-FOR-US: OmniRoute
 CVE-2026-88061 (career-ops is an open-source AI-assisted job search and 
application ma ...)
-       TODO: check
+       NOT-FOR-US: career-ops
 CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is 
vulnerable ...)
        NOT-FOR-US: IBM
 CVE-2026-87908 (multiparty is a Node.js library for parsing 
multipart/form-data reques ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e8ce0c813d701afb602a608595bd64b198ec2e5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e8ce0c813d701afb602a608595bd64b198ec2e5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to