Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c394781b by Salvatore Bonaccorso at 2026-09-15T22:45:59+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -116,13 +116,13 @@ CVE-2026-91926 (A flaw was found in gss-ntlmssp. A memory
leak occurs in the NTL
- gss-ntlmssp <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2533698
CVE-2026-91925 (Polyaxon through 2.16.4 renders operation specification fields
with an ...)
- TODO: check
+ NOT-FOR-US: Polyaxon
CVE-2026-91924 (pgweb through 0.17.0 leaves the POST /api/connect endpoint
unguarded w ...)
- TODO: check
+ NOT-FOR-US: pgweb
CVE-2026-91923 (KubeSphere through 4.1.3 contains a server-side request
forgery vulner ...)
- TODO: check
+ NOT-FOR-US: KubeSphere
CVE-2026-91922 (Steedos Platform through 3.0.15-beta.47 contains a reflected
cross-sit ...)
- TODO: check
+ NOT-FOR-US: Steedos Platform
CVE-2026-91859 (Affected versions of MISP can record incorrect access-log data
for req ...)
- misp <itp> (bug #1144317)
CVE-2026-91857 (Affected versions of MISP expose several state-changing
controller act ...)
@@ -136,13 +136,13 @@ CVE-2026-91853 (A vulnerability has been found in
TOTOLINK X5000R 9.1.0cu.2089_B
CVE-2026-91851 (Affected versions of MISP incorrectly filter dashboard
templates that ...)
- misp <itp> (bug #1144317)
CVE-2026-91849 (A security flaw has been discovered in WuzhiCMS up to 4.1.0.
This affe ...)
- TODO: check
+ NOT-FOR-US: WuzhiCMS
CVE-2026-91848 (A vulnerability was identified in WuzhiCMS up to 4.1.0.
Affected by th ...)
- TODO: check
+ NOT-FOR-US: WuzhiCMS
CVE-2026-91846 (Affected versions of MISP allow a collection element to be
created fro ...)
- misp <itp> (bug #1144317)
CVE-2026-91842 (A vulnerability has been found in OpenBankProject OBP-API up
to 1.10.1 ...)
- TODO: check
+ NOT-FOR-US: OpenBankProject OBP-API
CVE-2026-91836 (A flaw has been found in OpenClaw ClawScan up to 0.1.6. This
affects a ...)
NOT-FOR-US: OpenClaw
CVE-2026-91835 (A vulnerability was detected in OpenClaw ClawScan up to 0.1.6.
The imp ...)
@@ -178,7 +178,7 @@ CVE-2026-90439 (NGINX Plus and NGINX Open Source have a
vulnerability in the ngx
CVE-2026-89308 (An unauthenticated OS command injection vulnerability exists
in thepin ...)
TODO: check
CVE-2026-89307 (The "Firma Circolare" feature in the "Design Scuole Italia"
WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress theme
CVE-2026-89026 (The Issabel Framework, the web framework supporting Issabel
PBX softwa ...)
TODO: check
CVE-2026-89025 (Hirschmann HiOS Switch Platform devices contain a
denial-of-service vu ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c394781b5e8abbc20de21ea7465c6c5f5e0b22cd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c394781b5e8abbc20de21ea7465c6c5f5e0b22cd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits