Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
31308903 by Salvatore Bonaccorso at 2026-09-13T21:47:39+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -24,23 +24,23 @@ CVE-2026-90775 (PostGIS address_standardizer through 3.7.0 
fails to validate the
        NOTE: https://github.com/postgis/address_standardizer/pull/6
        NOTE: Fixed by: 
https://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a
 CVE-2026-90774 (rustypaste before 0.18.1 validates the destination path before 
applyin ...)
-       TODO: check
+       NOT-FOR-US: rustypaste
 CVE-2026-90773 (procs through 0.14.12 fails to sanitize escape sequences in 
process co ...)
        TODO: check
 CVE-2026-90772 (Amundsen frontend through 4.3.0 renders table, dashboard, and 
feature  ...)
-       TODO: check
+       NOT-FOR-US: Amundsen
 CVE-2026-90771 (joi before versions 17.13.8 and 18.2.9 contains a prototype 
pollution  ...)
-       TODO: check
+       NOT-FOR-US: Node joi
 CVE-2026-90770 (Spug through 3.4.0 contains a remote code execution 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: spug
 CVE-2026-90769 (Open Notebook before 1.11.0 fails to validate the URL 
parameter in POS ...)
-       TODO: check
+       NOT-FOR-US: Open Notebook
 CVE-2026-90768 (CAPEv2 through commit 471ee4b fails to validate task ownership 
in REST ...)
-       TODO: check
+       NOT-FOR-US: CAPEv2
 CVE-2026-90767 (Froxlor before 2.3.12 fails to properly validate multi-line 
SSH public ...)
        TODO: check
 CVE-2026-90579 (A vulnerability has been found in cheshire-cat-ai Cheshire Cat 
AI up t ...)
-       TODO: check
+       NOT-FOR-US: cheshire-cat-ai Cheshire Cat AI
 CVE-2026-90578 (A flaw has been found in GPAC up to f1219cde. Affected by this 
issue i ...)
        TODO: check
 CVE-2026-90577 (A vulnerability was detected in GPAC up to f1219cde. Affected 
by this  ...)
@@ -54,49 +54,49 @@ CVE-2026-90574 (A security flaw has been discovered in 
itsourcecode Sales and In
 CVE-2026-90573 (A vulnerability was identified in GPAC up to f1219cde. The 
impacted el ...)
        TODO: check
 CVE-2026-90572 (A vulnerability was determined in davenardella snap7 up to 
1.4.3. The  ...)
-       TODO: check
+       NOT-FOR-US: davenardella snap7
 CVE-2026-90571 (A vulnerability was found in Exrick xmall up to 
19e7917d5ed3bd2a2421a3 ...)
-       TODO: check
+       NOT-FOR-US: Exrick xmall
 CVE-2026-90570 (A vulnerability has been found in linlinjava litemall 
1.4.0/1.5.0/1.6. ...)
-       TODO: check
+       NOT-FOR-US: linlinjava litemall
 CVE-2026-90569 (A flaw has been found in linlinjava litemall 
1.5.0/1.6.0/1.7.0/1.8.0.  ...)
-       TODO: check
+       NOT-FOR-US: linlinjava litemall
 CVE-2026-90568 (A vulnerability was detected in moxi624 Mogu Blog v2 up to 
5.2. This a ...)
-       TODO: check
+       NOT-FOR-US: moxi624 Mogu Blog
 CVE-2026-90567 (A security vulnerability has been detected in quequnlong 
shiyi-blog up ...)
-       TODO: check
+       NOT-FOR-US: quequnlong shiyi-blog
 CVE-2026-90566 (A weakness has been identified in Rizwan17 
inventory-management-system ...)
-       TODO: check
+       NOT-FOR-US: Rizwan17 inventory-management-system
 CVE-2026-90565 (A security flaw has been discovered in Rizwan17 
inventory-management-s ...)
-       TODO: check
+       NOT-FOR-US: Rizwan17 inventory-management-system
 CVE-2026-90564 (A vulnerability was identified in quequnlong shiyi-blog 
1.0.0-1.2.1. T ...)
-       TODO: check
+       NOT-FOR-US: quequnlong shiyi-blog
 CVE-2026-90563 (A vulnerability was determined in maliangnansheng 
bbs-springboot 3.0.0 ...)
-       TODO: check
+       NOT-FOR-US: maliangnansheng bbs-springboot
 CVE-2026-90562 (LangBot before 4.10.11 generates password recovery keys with 
only 24 b ...)
-       TODO: check
+       NOT-FOR-US: LangBot
 CVE-2026-90561 (Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 
contain a sto ...)
-       TODO: check
+       NOT-FOR-US: Strapi
 CVE-2026-90529 (A vulnerability has been found in DataEase up to 
2.10.25/2.10.26. Affe ...)
        NOT-FOR-US: DataEase
 CVE-2026-90528 (A flaw has been found in TDuckApp tduck-platform up to 5.3. 
Affected b ...)
-       TODO: check
+       NOT-FOR-US: TDuckApp tduck-platform
 CVE-2026-90527 (A vulnerability was detected in quequnlong shiyi-blog up to 
1.2.1. Aff ...)
-       TODO: check
+       NOT-FOR-US: quequnlong shiyi-blog
 CVE-2026-90526 (A security vulnerability has been detected in SourceCodester 
School Re ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-90525 (A weakness has been identified in itsourcecode Sales and 
Inventory Sys ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-90524 (A security flaw has been discovered in jaychouchannel 
Tourism-Manageme ...)
-       TODO: check
+       NOT-FOR-US: jaychouchannel Tourism-Management-System
 CVE-2026-90523 (A vulnerability was identified in jaychouchannel 
Tourism-Management-Sy ...)
-       TODO: check
+       NOT-FOR-US: jaychouchannel Tourism-Management-System
 CVE-2026-90522 (A vulnerability was determined in jaychouchannel 
Tourism-Management-Sy ...)
-       TODO: check
+       NOT-FOR-US: jaychouchannel Tourism-Management-System
 CVE-2026-90521 (A vulnerability was found in jaychouchannel 
Tourism-Management-System  ...)
-       TODO: check
+       NOT-FOR-US: jaychouchannel Tourism-Management-System
 CVE-2026-90520 (A vulnerability has been found in jaychouchannel 
Tourism-Management-Sy ...)
-       TODO: check
+       NOT-FOR-US: jaychouchannel Tourism-Management-System
 CVE-2026-90519 (A weakness has been identified in PHPGurukul Bank Locker 
Management Sy ...)
        NOT-FOR-US: PHPGurukul
 CVE-2026-90518 (A security flaw has been discovered in PHPGurukul Bank Locker 
Manageme ...)
@@ -110,9 +110,9 @@ CVE-2026-90515 (A vulnerability was determined in 
SourceCodester School Registra
 CVE-2026-90514 (A vulnerability has been found in SourceCodester School 
Registration a ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-90513 (A flaw has been found in simalexan api-lambda-send-email-ses 
up to bda ...)
-       TODO: check
+       NOT-FOR-US: simalexan api-lambda-send-email-ses
 CVE-2026-90511 (A vulnerability was detected in GongShengyue OnlineBooks up to 
dfc5eac ...)
-       TODO: check
+       NOT-FOR-US: GongShengyue OnlineBooks
 CVE-2026-90510 (A security vulnerability has been detected in dromara 
orion-visor up t ...)
        TODO: check
 CVE-2026-90509 (A weakness has been identified in dromara orion-visor up to 
2.5.7. Aff ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/313089034e538554b2e559b10931f2ca36480bf4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/313089034e538554b2e559b10931f2ca36480bf4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to