Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4c575af7 by Salvatore Bonaccorso at 2026-09-14T22:05:40+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -39,23 +39,23 @@ CVE-2026-90947 (A flaw was found in GIMP. When processing a 
specially crafted li
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c
 (master)
 CVE-2026-90946 (DeepWiki-Open through commit d92819a contains an arbitrary 
file read v ...)
-       TODO: check
+       NOT-FOR-US: DeepWiki-Open
 CVE-2026-90945 (Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for 
JWT tok ...)
-       TODO: check
+       NOT-FOR-US: Crawlab
 CVE-2026-90944 (Krayin CRM through 2.2.6 exposes the POST 
/admin/mail/inbound-parse en ...)
-       TODO: check
+       NOT-FOR-US: Krayin CRM
 CVE-2026-90943 (parallax filament-comments through 3.0.0 contains a stored 
cross-site  ...)
-       TODO: check
+       NOT-FOR-US: parallax filament-comments
 CVE-2026-90942 (Casdoor through 4.4.0 fails to properly mask the instance-wide 
built-i ...)
-       TODO: check
+       NOT-FOR-US: Casdoor
 CVE-2026-90941 (novel-plus through 5.3.3 contains an authorization bypass 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: novel-plus
 CVE-2026-90940 (novel-plus through 5.3.3 contains an insecure default 
cache-management ...)
-       TODO: check
+       NOT-FOR-US: novel-plus
 CVE-2026-90939 (novel-plus through 5.3.3 contains an information disclosure 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: novel-plus
 CVE-2026-90938 (LangBot's plugin runtime (pip package langbot_plugin) through 
0.4.17 s ...)
-       TODO: check
+       NOT-FOR-US: LangBot
 CVE-2026-90937 (froxlor versions before 2.2.5 fail to validate newline 
characters in s ...)
        TODO: check
 CVE-2026-90936 (Froxlor before 2.3.7 fails to properly scope sender alias 
lookups to t ...)
@@ -63,49 +63,49 @@ CVE-2026-90936 (Froxlor before 2.3.7 fails to properly 
scope sender alias lookup
 CVE-2026-90935 (Froxlor before 2.3.7 fails to validate the mysql_server 
parameter agai ...)
        TODO: check
 CVE-2026-90934 (EspoCRM before 10.0.4 contains a field-level security bypass 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: EspoCRM
 CVE-2026-90933 (laradashboard through 1.2.2 contains a missing authorization 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: laradashboard
 CVE-2026-90932 (LaraDashboard versions 0.9.2 through 1.2.2 contain a path 
traversal vu ...)
-       TODO: check
+       NOT-FOR-US: LaraDashboard
 CVE-2026-90931 (LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize 
SVG file c ...)
-       TODO: check
+       NOT-FOR-US: LaraDashboard
 CVE-2026-90930 (File Browser through 2.63.23 applies path rules to the 
requested lexic ...)
-       TODO: check
+       NOT-FOR-US: File Browser
 CVE-2026-90929 (File Browser versions >= 2.5.0 and <= 2.63.23 contain an 
incorrect aut ...)
-       TODO: check
+       NOT-FOR-US: File Browser
 CVE-2026-90928 (File Browser through 2.63.23 contains a memory exhaustion 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: File Browser
 CVE-2026-90927 (filebrowser through 2.63.23 fails to limit WebSocket message 
size in t ...)
-       TODO: check
+       NOT-FOR-US: File Browser
 CVE-2026-90919 (LightLLM through 1.2.0 contains a remote code execution 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: LightLLM
 CVE-2026-90898 (Bifrost registers MCP clients through its management API. A 
stdio clie ...)
-       TODO: check
+       NOT-FOR-US: Bifrost
 CVE-2026-90895 (Affected versions of MISP\u2019s interactive CLI shell 
implement acces ...)
        TODO: check
 CVE-2026-90894 (Parallels Desktop runsprl_disp_serviceas root. Local clients 
reach it  ...)
-       TODO: check
+       NOT-FOR-US: Parallels Desktop
 CVE-2026-90893 (MISP contains a Cross-Site Request Forgery (CSRF) 
vulnerability in the ...)
        TODO: check
 CVE-2026-90891 (ASRock Polychrome SYNC/RGB software utility developed by 
ASRock Inc. h ...)
-       TODO: check
+       NOT-FOR-US: ASRock Polychrome SYNC/RGB software
 CVE-2026-90890 (ASRock Polychrome SYNC/RGB software utility developed by 
ASRock Inc. h ...)
-       TODO: check
+       NOT-FOR-US: ASRock
 CVE-2026-90811 (A weakness has been identified in cosmicstack-labs 
mercury-agent up to ...)
-       TODO: check
+       NOT-FOR-US: cosmicstack-labs mercury-agent
 CVE-2026-90810 (A security flaw has been discovered in cosmicstack-labs 
mercury-agent  ...)
-       TODO: check
+       NOT-FOR-US: cosmicstack-labs mercury-agent
 CVE-2026-90809 (A vulnerability was identified in HKUDS nanobot up to 0.2.1. 
The affec ...)
-       TODO: check
+       NOT-FOR-US: HKUDS nanobot
 CVE-2026-90808 (A vulnerability was determined in HKUDS nanobot up to 0.2.1. 
Impacted  ...)
-       TODO: check
+       NOT-FOR-US: HKUDS nanobot
 CVE-2026-90807 (A vulnerability was found in nanocoai NanoClaw up to 2.1.17. 
This issu ...)
-       TODO: check
+       NOT-FOR-US: nanocoai NanoClaw
 CVE-2026-90806 (A vulnerability has been found in DjangoCRM django-crm up to 
1.2. This ...)
-       TODO: check
+       NOT-FOR-US: DjangoCRM django-crm
 CVE-2026-90805 (A flaw has been found in subhajitkhan 
online-clinic-management-system  ...)
-       TODO: check
+       NOT-FOR-US: subhajitkhan online-clinic-management-system
 CVE-2026-90804 (A vulnerability was detected in GNU Binutils 2.47. Affected by 
this is ...)
        TODO: check
 CVE-2026-90803 (A security vulnerability has been detected in GNU Binutils 
2.47. Affec ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c575af7073934a18e9320433fedfb823b8a06b0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c575af7073934a18e9320433fedfb823b8a06b0
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to