Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
31308903 by Salvatore Bonaccorso at 2026-09-13T21:47:39+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -24,23 +24,23 @@ CVE-2026-90775 (PostGIS address_standardizer through 3.7.0
fails to validate the
NOTE: https://github.com/postgis/address_standardizer/pull/6
NOTE: Fixed by:
https://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a
CVE-2026-90774 (rustypaste before 0.18.1 validates the destination path before
applyin ...)
- TODO: check
+ NOT-FOR-US: rustypaste
CVE-2026-90773 (procs through 0.14.12 fails to sanitize escape sequences in
process co ...)
TODO: check
CVE-2026-90772 (Amundsen frontend through 4.3.0 renders table, dashboard, and
feature ...)
- TODO: check
+ NOT-FOR-US: Amundsen
CVE-2026-90771 (joi before versions 17.13.8 and 18.2.9 contains a prototype
pollution ...)
- TODO: check
+ NOT-FOR-US: Node joi
CVE-2026-90770 (Spug through 3.4.0 contains a remote code execution
vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: spug
CVE-2026-90769 (Open Notebook before 1.11.0 fails to validate the URL
parameter in POS ...)
- TODO: check
+ NOT-FOR-US: Open Notebook
CVE-2026-90768 (CAPEv2 through commit 471ee4b fails to validate task ownership
in REST ...)
- TODO: check
+ NOT-FOR-US: CAPEv2
CVE-2026-90767 (Froxlor before 2.3.12 fails to properly validate multi-line
SSH public ...)
TODO: check
CVE-2026-90579 (A vulnerability has been found in cheshire-cat-ai Cheshire Cat
AI up t ...)
- TODO: check
+ NOT-FOR-US: cheshire-cat-ai Cheshire Cat AI
CVE-2026-90578 (A flaw has been found in GPAC up to f1219cde. Affected by this
issue i ...)
TODO: check
CVE-2026-90577 (A vulnerability was detected in GPAC up to f1219cde. Affected
by this ...)
@@ -54,49 +54,49 @@ CVE-2026-90574 (A security flaw has been discovered in
itsourcecode Sales and In
CVE-2026-90573 (A vulnerability was identified in GPAC up to f1219cde. The
impacted el ...)
TODO: check
CVE-2026-90572 (A vulnerability was determined in davenardella snap7 up to
1.4.3. The ...)
- TODO: check
+ NOT-FOR-US: davenardella snap7
CVE-2026-90571 (A vulnerability was found in Exrick xmall up to
19e7917d5ed3bd2a2421a3 ...)
- TODO: check
+ NOT-FOR-US: Exrick xmall
CVE-2026-90570 (A vulnerability has been found in linlinjava litemall
1.4.0/1.5.0/1.6. ...)
- TODO: check
+ NOT-FOR-US: linlinjava litemall
CVE-2026-90569 (A flaw has been found in linlinjava litemall
1.5.0/1.6.0/1.7.0/1.8.0. ...)
- TODO: check
+ NOT-FOR-US: linlinjava litemall
CVE-2026-90568 (A vulnerability was detected in moxi624 Mogu Blog v2 up to
5.2. This a ...)
- TODO: check
+ NOT-FOR-US: moxi624 Mogu Blog
CVE-2026-90567 (A security vulnerability has been detected in quequnlong
shiyi-blog up ...)
- TODO: check
+ NOT-FOR-US: quequnlong shiyi-blog
CVE-2026-90566 (A weakness has been identified in Rizwan17
inventory-management-system ...)
- TODO: check
+ NOT-FOR-US: Rizwan17 inventory-management-system
CVE-2026-90565 (A security flaw has been discovered in Rizwan17
inventory-management-s ...)
- TODO: check
+ NOT-FOR-US: Rizwan17 inventory-management-system
CVE-2026-90564 (A vulnerability was identified in quequnlong shiyi-blog
1.0.0-1.2.1. T ...)
- TODO: check
+ NOT-FOR-US: quequnlong shiyi-blog
CVE-2026-90563 (A vulnerability was determined in maliangnansheng
bbs-springboot 3.0.0 ...)
- TODO: check
+ NOT-FOR-US: maliangnansheng bbs-springboot
CVE-2026-90562 (LangBot before 4.10.11 generates password recovery keys with
only 24 b ...)
- TODO: check
+ NOT-FOR-US: LangBot
CVE-2026-90561 (Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1
contain a sto ...)
- TODO: check
+ NOT-FOR-US: Strapi
CVE-2026-90529 (A vulnerability has been found in DataEase up to
2.10.25/2.10.26. Affe ...)
NOT-FOR-US: DataEase
CVE-2026-90528 (A flaw has been found in TDuckApp tduck-platform up to 5.3.
Affected b ...)
- TODO: check
+ NOT-FOR-US: TDuckApp tduck-platform
CVE-2026-90527 (A vulnerability was detected in quequnlong shiyi-blog up to
1.2.1. Aff ...)
- TODO: check
+ NOT-FOR-US: quequnlong shiyi-blog
CVE-2026-90526 (A security vulnerability has been detected in SourceCodester
School Re ...)
NOT-FOR-US: SourceCodester
CVE-2026-90525 (A weakness has been identified in itsourcecode Sales and
Inventory Sys ...)
NOT-FOR-US: itsourcecode System
CVE-2026-90524 (A security flaw has been discovered in jaychouchannel
Tourism-Manageme ...)
- TODO: check
+ NOT-FOR-US: jaychouchannel Tourism-Management-System
CVE-2026-90523 (A vulnerability was identified in jaychouchannel
Tourism-Management-Sy ...)
- TODO: check
+ NOT-FOR-US: jaychouchannel Tourism-Management-System
CVE-2026-90522 (A vulnerability was determined in jaychouchannel
Tourism-Management-Sy ...)
- TODO: check
+ NOT-FOR-US: jaychouchannel Tourism-Management-System
CVE-2026-90521 (A vulnerability was found in jaychouchannel
Tourism-Management-System ...)
- TODO: check
+ NOT-FOR-US: jaychouchannel Tourism-Management-System
CVE-2026-90520 (A vulnerability has been found in jaychouchannel
Tourism-Management-Sy ...)
- TODO: check
+ NOT-FOR-US: jaychouchannel Tourism-Management-System
CVE-2026-90519 (A weakness has been identified in PHPGurukul Bank Locker
Management Sy ...)
NOT-FOR-US: PHPGurukul
CVE-2026-90518 (A security flaw has been discovered in PHPGurukul Bank Locker
Manageme ...)
@@ -110,9 +110,9 @@ CVE-2026-90515 (A vulnerability was determined in
SourceCodester School Registra
CVE-2026-90514 (A vulnerability has been found in SourceCodester School
Registration a ...)
NOT-FOR-US: SourceCodester
CVE-2026-90513 (A flaw has been found in simalexan api-lambda-send-email-ses
up to bda ...)
- TODO: check
+ NOT-FOR-US: simalexan api-lambda-send-email-ses
CVE-2026-90511 (A vulnerability was detected in GongShengyue OnlineBooks up to
dfc5eac ...)
- TODO: check
+ NOT-FOR-US: GongShengyue OnlineBooks
CVE-2026-90510 (A security vulnerability has been detected in dromara
orion-visor up t ...)
TODO: check
CVE-2026-90509 (A weakness has been identified in dromara orion-visor up to
2.5.7. Aff ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/313089034e538554b2e559b10931f2ca36480bf4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/313089034e538554b2e559b10931f2ca36480bf4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits