Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7e867bc9 by Salvatore Bonaccorso at 2026-09-15T07:23:13+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -314,7 +314,7 @@ CVE-2026-78318 (Improper neutralization of input during web 
page generation ('cr
 CVE-2026-78299 (In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack 
archive  ...)
        TODO: check
 CVE-2026-77884 (Gallery - Private Photo Vault 1.0.41 starts an unauthenticated 
HTTP se ...)
-       TODO: check
+       NOT-FOR-US: Gallery - Private Photo Vault
 CVE-2026-77883 (Exposure of sensitive information through data queries 
vulnerability i ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77181 (Incorrect Authorization vulnerability in Apache Syncope.    An 
adminis ...)
@@ -342,7 +342,7 @@ CVE-2026-73668 (Incorrect Authorization vulnerability in 
Apache Syncope.      An
 CVE-2026-73579 (Incorrect Authorization vulnerability in Apache Syncope.    
Any search ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73494 (blaze is a Scala library for building asynchronous pipelines, 
with a f ...)
-       TODO: check
+       NOT-FOR-US: blaze
 CVE-2026-73470 (Improper Privilege Management vulnerability in Apache Syncope. 
     De ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73370 (Incorrect Authorization vulnerability in Apache Syncope.    
Delegated  ...)
@@ -358,37 +358,37 @@ CVE-2026-73178 (Exposure of Sensitive Information to an 
Unauthorized Actor vulne
 CVE-2026-72524 (Incorrect Authorization vulnerability in Apache Doris allows 
an authen ...)
        TODO: check
 CVE-2026-70658 (Pay is a payments engine for Ruby on Rails 6.0 and higher. 
Prior to 11 ...)
-       TODO: check
+       NOT-FOR-US: pay-rails
 CVE-2026-68570 (Incorrect Authorization vulnerability in Apache Doris allows 
an authen ...)
        TODO: check
 CVE-2026-61701 (Laravel MagicLink creates links for authentication without a 
password  ...)
-       TODO: check
+       NOT-FOR-US: Laravel MagicLink
 CVE-2026-61534 (Yayson is a library for serializing and reading JSON API data 
in JavaS ...)
-       TODO: check
+       NOT-FOR-US: Yayson
 CVE-2026-5132 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
        TODO: check
 CVE-2026-59960 (Argos JavaScript provides official Argos SDKs for JavaScript. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: Argos JavaScript
 CVE-2026-59570 (On affected versions of Zscaler client connector, a 
pre-installed peer ...)
        NOT-FOR-US: Zscaler
 CVE-2026-59569 (An improper input validation vulnerability in Zscaler Client 
Connector ...)
        NOT-FOR-US: Zscaler
 CVE-2026-59178 (ESPHome Device Builder Dashboard is a dashboard for the 
ESPHome home m ...)
-       TODO: check
+       NOT-FOR-US: ESPHome Device Builder Dashboard
 CVE-2026-57583 (OpenZeppelin Contracts Wizard is a web application to 
interactively bu ...)
-       TODO: check
+       NOT-FOR-US: OpenZeppelin Contracts Wizard
 CVE-2026-57581 (DotVVM is an open source MVVM framework for web applications. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: DotVVM
 CVE-2026-57579 (Alchemy is an open source content management system engine 
written in  ...)
-       TODO: check
+       NOT-FOR-US: Alchemy CMS
 CVE-2026-57578 (DotVVM is an open source MVVM framework for web applications. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: DotVVM
 CVE-2026-57577 (DotVVM is an open source MVVM framework for web applications. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: DotVVM
 CVE-2026-57570 (backpack/crud provides Create, Read, Update & Delete (CRUD) 
functions  ...)
-       TODO: check
+       NOT-FOR-US: backpack/crud
 CVE-2026-57497 (webtransport-go is an implementation of the WebTransport 
protocol. Pri ...)
-       TODO: check
+       NOT-FOR-US: webtransport-go
 CVE-2026-57145 (PraisonAI is a multi-agent teams system. Prior to 4.6.62, 
src/praisona ...)
        NOT-FOR-US: PraisonAI
 CVE-2026-57132 (PraisonAI is a multi-agent teams system. Prior to 4.6.62, 
setting PRAI ...)
@@ -422,15 +422,15 @@ CVE-2026-57115 (PraisonAI is a multi-agent teams system. 
Prior to praisonaiagent
 CVE-2026-56839 (PraisonAI is a multi-agent teams system. Prior to 4.6.59, the 
CODE_TOO ...)
        NOT-FOR-US: PraisonAI
 CVE-2026-55866 (SpiceDB is an open source database system for creating and 
managing se ...)
-       TODO: check
+       NOT-FOR-US: SpiceDB
 CVE-2026-55847 (Allure 2 is the version 2.x branch of Allure Report, a 
multi-language  ...)
-       TODO: check
+       NOT-FOR-US: Allure
 CVE-2026-55846 (Allure 2 is the version 2.x branch of Allure Report, a 
multi-language  ...)
-       TODO: check
+       NOT-FOR-US: Allure
 CVE-2026-55837 (dbt-mcp is a Model Context Protocol server for interacting 
with dbt. P ...)
-       TODO: check
+       NOT-FOR-US: dbt-mcp
 CVE-2026-55832 (Tract is a tiny, no-nonsense, self-contained TensorFlow and 
ONNX infer ...)
-       TODO: check
+       NOT-FOR-US: Tract
 CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From 
4.0.0 unti ...)
        NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-55451 (gettext-converter provides gettext resource conversion 
utilities for J ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e867bc9940c5ec5b4fdff464ba02e4cadc7a968

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e867bc9940c5ec5b4fdff464ba02e4cadc7a968
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to