Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
7e867bc9 by Salvatore Bonaccorso at 2026-09-15T07:23:13+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -314,7 +314,7 @@ CVE-2026-78318 (Improper neutralization of input during web
page generation ('cr
CVE-2026-78299 (In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack
archive ...)
TODO: check
CVE-2026-77884 (Gallery - Private Photo Vault 1.0.41 starts an unauthenticated
HTTP se ...)
- TODO: check
+ NOT-FOR-US: Gallery - Private Photo Vault
CVE-2026-77883 (Exposure of sensitive information through data queries
vulnerability i ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-77181 (Incorrect Authorization vulnerability in Apache Syncope. An
adminis ...)
@@ -342,7 +342,7 @@ CVE-2026-73668 (Incorrect Authorization vulnerability in
Apache Syncope. An
CVE-2026-73579 (Incorrect Authorization vulnerability in Apache Syncope.
Any search ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-73494 (blaze is a Scala library for building asynchronous pipelines,
with a f ...)
- TODO: check
+ NOT-FOR-US: blaze
CVE-2026-73470 (Improper Privilege Management vulnerability in Apache Syncope.
De ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-73370 (Incorrect Authorization vulnerability in Apache Syncope.
Delegated ...)
@@ -358,37 +358,37 @@ CVE-2026-73178 (Exposure of Sensitive Information to an
Unauthorized Actor vulne
CVE-2026-72524 (Incorrect Authorization vulnerability in Apache Doris allows
an authen ...)
TODO: check
CVE-2026-70658 (Pay is a payments engine for Ruby on Rails 6.0 and higher.
Prior to 11 ...)
- TODO: check
+ NOT-FOR-US: pay-rails
CVE-2026-68570 (Incorrect Authorization vulnerability in Apache Doris allows
an authen ...)
TODO: check
CVE-2026-61701 (Laravel MagicLink creates links for authentication without a
password ...)
- TODO: check
+ NOT-FOR-US: Laravel MagicLink
CVE-2026-61534 (Yayson is a library for serializing and reading JSON API data
in JavaS ...)
- TODO: check
+ NOT-FOR-US: Yayson
CVE-2026-5132 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
TODO: check
CVE-2026-59960 (Argos JavaScript provides official Argos SDKs for JavaScript.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Argos JavaScript
CVE-2026-59570 (On affected versions of Zscaler client connector, a
pre-installed peer ...)
NOT-FOR-US: Zscaler
CVE-2026-59569 (An improper input validation vulnerability in Zscaler Client
Connector ...)
NOT-FOR-US: Zscaler
CVE-2026-59178 (ESPHome Device Builder Dashboard is a dashboard for the
ESPHome home m ...)
- TODO: check
+ NOT-FOR-US: ESPHome Device Builder Dashboard
CVE-2026-57583 (OpenZeppelin Contracts Wizard is a web application to
interactively bu ...)
- TODO: check
+ NOT-FOR-US: OpenZeppelin Contracts Wizard
CVE-2026-57581 (DotVVM is an open source MVVM framework for web applications.
Prior to ...)
- TODO: check
+ NOT-FOR-US: DotVVM
CVE-2026-57579 (Alchemy is an open source content management system engine
written in ...)
- TODO: check
+ NOT-FOR-US: Alchemy CMS
CVE-2026-57578 (DotVVM is an open source MVVM framework for web applications.
Prior to ...)
- TODO: check
+ NOT-FOR-US: DotVVM
CVE-2026-57577 (DotVVM is an open source MVVM framework for web applications.
Prior to ...)
- TODO: check
+ NOT-FOR-US: DotVVM
CVE-2026-57570 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
- TODO: check
+ NOT-FOR-US: backpack/crud
CVE-2026-57497 (webtransport-go is an implementation of the WebTransport
protocol. Pri ...)
- TODO: check
+ NOT-FOR-US: webtransport-go
CVE-2026-57145 (PraisonAI is a multi-agent teams system. Prior to 4.6.62,
src/praisona ...)
NOT-FOR-US: PraisonAI
CVE-2026-57132 (PraisonAI is a multi-agent teams system. Prior to 4.6.62,
setting PRAI ...)
@@ -422,15 +422,15 @@ CVE-2026-57115 (PraisonAI is a multi-agent teams system.
Prior to praisonaiagent
CVE-2026-56839 (PraisonAI is a multi-agent teams system. Prior to 4.6.59, the
CODE_TOO ...)
NOT-FOR-US: PraisonAI
CVE-2026-55866 (SpiceDB is an open source database system for creating and
managing se ...)
- TODO: check
+ NOT-FOR-US: SpiceDB
CVE-2026-55847 (Allure 2 is the version 2.x branch of Allure Report, a
multi-language ...)
- TODO: check
+ NOT-FOR-US: Allure
CVE-2026-55846 (Allure 2 is the version 2.x branch of Allure Report, a
multi-language ...)
- TODO: check
+ NOT-FOR-US: Allure
CVE-2026-55837 (dbt-mcp is a Model Context Protocol server for interacting
with dbt. P ...)
- TODO: check
+ NOT-FOR-US: dbt-mcp
CVE-2026-55832 (Tract is a tiny, no-nonsense, self-contained TensorFlow and
ONNX infer ...)
- TODO: check
+ NOT-FOR-US: Tract
CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From
4.0.0 unti ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55451 (gettext-converter provides gettext resource conversion
utilities for J ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e867bc9940c5ec5b4fdff464ba02e4cadc7a968
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e867bc9940c5ec5b4fdff464ba02e4cadc7a968
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits