Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
4c575af7 by Salvatore Bonaccorso at 2026-09-14T22:05:40+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -39,23 +39,23 @@ CVE-2026-90947 (A flaw was found in GIMP. When processing a
specially crafted li
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c
(master)
CVE-2026-90946 (DeepWiki-Open through commit d92819a contains an arbitrary
file read v ...)
- TODO: check
+ NOT-FOR-US: DeepWiki-Open
CVE-2026-90945 (Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for
JWT tok ...)
- TODO: check
+ NOT-FOR-US: Crawlab
CVE-2026-90944 (Krayin CRM through 2.2.6 exposes the POST
/admin/mail/inbound-parse en ...)
- TODO: check
+ NOT-FOR-US: Krayin CRM
CVE-2026-90943 (parallax filament-comments through 3.0.0 contains a stored
cross-site ...)
- TODO: check
+ NOT-FOR-US: parallax filament-comments
CVE-2026-90942 (Casdoor through 4.4.0 fails to properly mask the instance-wide
built-i ...)
- TODO: check
+ NOT-FOR-US: Casdoor
CVE-2026-90941 (novel-plus through 5.3.3 contains an authorization bypass
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: novel-plus
CVE-2026-90940 (novel-plus through 5.3.3 contains an insecure default
cache-management ...)
- TODO: check
+ NOT-FOR-US: novel-plus
CVE-2026-90939 (novel-plus through 5.3.3 contains an information disclosure
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: novel-plus
CVE-2026-90938 (LangBot's plugin runtime (pip package langbot_plugin) through
0.4.17 s ...)
- TODO: check
+ NOT-FOR-US: LangBot
CVE-2026-90937 (froxlor versions before 2.2.5 fail to validate newline
characters in s ...)
TODO: check
CVE-2026-90936 (Froxlor before 2.3.7 fails to properly scope sender alias
lookups to t ...)
@@ -63,49 +63,49 @@ CVE-2026-90936 (Froxlor before 2.3.7 fails to properly
scope sender alias lookup
CVE-2026-90935 (Froxlor before 2.3.7 fails to validate the mysql_server
parameter agai ...)
TODO: check
CVE-2026-90934 (EspoCRM before 10.0.4 contains a field-level security bypass
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: EspoCRM
CVE-2026-90933 (laradashboard through 1.2.2 contains a missing authorization
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: laradashboard
CVE-2026-90932 (LaraDashboard versions 0.9.2 through 1.2.2 contain a path
traversal vu ...)
- TODO: check
+ NOT-FOR-US: LaraDashboard
CVE-2026-90931 (LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize
SVG file c ...)
- TODO: check
+ NOT-FOR-US: LaraDashboard
CVE-2026-90930 (File Browser through 2.63.23 applies path rules to the
requested lexic ...)
- TODO: check
+ NOT-FOR-US: File Browser
CVE-2026-90929 (File Browser versions >= 2.5.0 and <= 2.63.23 contain an
incorrect aut ...)
- TODO: check
+ NOT-FOR-US: File Browser
CVE-2026-90928 (File Browser through 2.63.23 contains a memory exhaustion
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: File Browser
CVE-2026-90927 (filebrowser through 2.63.23 fails to limit WebSocket message
size in t ...)
- TODO: check
+ NOT-FOR-US: File Browser
CVE-2026-90919 (LightLLM through 1.2.0 contains a remote code execution
vulnerability ...)
- TODO: check
+ NOT-FOR-US: LightLLM
CVE-2026-90898 (Bifrost registers MCP clients through its management API. A
stdio clie ...)
- TODO: check
+ NOT-FOR-US: Bifrost
CVE-2026-90895 (Affected versions of MISP\u2019s interactive CLI shell
implement acces ...)
TODO: check
CVE-2026-90894 (Parallels Desktop runsprl_disp_serviceas root. Local clients
reach it ...)
- TODO: check
+ NOT-FOR-US: Parallels Desktop
CVE-2026-90893 (MISP contains a Cross-Site Request Forgery (CSRF)
vulnerability in the ...)
TODO: check
CVE-2026-90891 (ASRock Polychrome SYNC/RGB software utility developed by
ASRock Inc. h ...)
- TODO: check
+ NOT-FOR-US: ASRock Polychrome SYNC/RGB software
CVE-2026-90890 (ASRock Polychrome SYNC/RGB software utility developed by
ASRock Inc. h ...)
- TODO: check
+ NOT-FOR-US: ASRock
CVE-2026-90811 (A weakness has been identified in cosmicstack-labs
mercury-agent up to ...)
- TODO: check
+ NOT-FOR-US: cosmicstack-labs mercury-agent
CVE-2026-90810 (A security flaw has been discovered in cosmicstack-labs
mercury-agent ...)
- TODO: check
+ NOT-FOR-US: cosmicstack-labs mercury-agent
CVE-2026-90809 (A vulnerability was identified in HKUDS nanobot up to 0.2.1.
The affec ...)
- TODO: check
+ NOT-FOR-US: HKUDS nanobot
CVE-2026-90808 (A vulnerability was determined in HKUDS nanobot up to 0.2.1.
Impacted ...)
- TODO: check
+ NOT-FOR-US: HKUDS nanobot
CVE-2026-90807 (A vulnerability was found in nanocoai NanoClaw up to 2.1.17.
This issu ...)
- TODO: check
+ NOT-FOR-US: nanocoai NanoClaw
CVE-2026-90806 (A vulnerability has been found in DjangoCRM django-crm up to
1.2. This ...)
- TODO: check
+ NOT-FOR-US: DjangoCRM django-crm
CVE-2026-90805 (A flaw has been found in subhajitkhan
online-clinic-management-system ...)
- TODO: check
+ NOT-FOR-US: subhajitkhan online-clinic-management-system
CVE-2026-90804 (A vulnerability was detected in GNU Binutils 2.47. Affected by
this is ...)
TODO: check
CVE-2026-90803 (A security vulnerability has been detected in GNU Binutils
2.47. Affec ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c575af7073934a18e9320433fedfb823b8a06b0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c575af7073934a18e9320433fedfb823b8a06b0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits