Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ecc1c581 by Salvatore Bonaccorso at 2026-09-16T22:03:58+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
CVE-2026-92729 (SigNoz versions 0.88.0 through 0.141.0 fail to apply
authorization wra ...)
- TODO: check
+ NOT-FOR-US: SigNoz
CVE-2026-92720 (Kubero through 3.1.1 fails to apply authentication guards to
the notif ...)
- TODO: check
+ NOT-FOR-US: Kubero
CVE-2026-92719 (Quickwit through 0.9.0 fails to validate the host and scheme
of the qu ...)
- TODO: check
+ NOT-FOR-US: Quickwit
CVE-2026-92718 (Nuclei versions before 3.11.1 cache template signature
verification ba ...)
- TODO: check
+ NOT-FOR-US: Nuclei
CVE-2026-92717 (Covenant through 0.6 registers the CovenantHub SignalR hub
without an ...)
- TODO: check
+ NOT-FOR-US: Covenant
CVE-2026-92716 (Shuffle through 2.2.1 contains a cross-tenant privilege
escalation vul ...)
TODO: check
CVE-2026-92627 (A heap-use-after-free vulnerability exists in H5T__conv_f_f()
in src/H ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ecc1c5814be27d8b7d9579e8999a972ac44cbf30
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ecc1c5814be27d8b7d9579e8999a972ac44cbf30
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits