Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a5d208de by Salvatore Bonaccorso at 2026-09-19T09:42:49+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,25 +5,25 @@ CVE-2026-93922 (SiYuan through 3.8.4 renders notebook names 
as raw HTML in the D
 CVE-2026-93921 (SiYuan versions through 3.8.4 fail to enforce publish access 
control i ...)
        NOT-FOR-US: SiYuan
 CVE-2026-93873 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in 
the contac ...)
-       TODO: check
+       NOT-FOR-US: Cotonti
 CVE-2026-93872 (Cotonti 1.0.0 passes the base64-decoded cb parameter to 
unserialize()  ...)
-       TODO: check
+       NOT-FOR-US: Cotonti
 CVE-2026-93871 (Cotonti through 1.0.0 fails to validate redirect destinations 
in page  ...)
-       TODO: check
+       NOT-FOR-US: Cotonti
 CVE-2026-93870 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in 
the rating ...)
-       TODO: check
+       NOT-FOR-US: Cotonti
 CVE-2026-93869 (Cotonti through 1.0.0 contains an open redirect vulnerability 
in the c ...)
-       TODO: check
+       NOT-FOR-US: Cotonti
 CVE-2026-93868 (Cotonti through 1.0.0 derives password recovery validation 
tokens from ...)
-       TODO: check
+       NOT-FOR-US: Cotonti
 CVE-2026-93841 (vLLM through 0.29.0 contains a memory corruption vulnerability 
in the  ...)
        TODO: check
 CVE-2026-93840 (vLLM before 0.29.0 validates allowed_token_ids against 
tokenizer lengt ...)
        TODO: check
 CVE-2026-93839 (LightLLM through 1.2.0 contains an authentication bypass 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: LightLLM
 CVE-2026-93838 (SGLang versions through 0.5.20 contain an unbounded memory 
allocation  ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-93741 (A security flaw has been discovered in Totolink A3002MU 
Hh-B20211125.1 ...)
        NOT-FOR-US: TOTOLINK
 CVE-2026-93740 (A vulnerability was identified in Totolink A3002MU 
Hh-B20211125.1046.  ...)
@@ -43,7 +43,7 @@ CVE-2026-92967 (The Pochipp plugin for WordPress is 
vulnerable to Reflected Cros
 CVE-2026-92807 (The Save as PDF Plugin by PDFCrowd plugin for WordPress is 
vulnerable  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-92708 (Svelte devalue is a JavaScript library that serializes values 
into str ...)
-       TODO: check
+       NOT-FOR-US: Svelte devalue
 CVE-2026-92435 (The Mailchimp for WooCommerce WordPress plugin before 6.1.1 
does not v ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-92430 (The Rede Ita\xfa for WooCommerce \u2014 Payment PIX, Credit 
Card and D ...)
@@ -99,9 +99,9 @@ CVE-2026-85680 (The Ultimate Member  WordPress plugin before 
2.13.1 does not esc
 CVE-2026-85574 (The Unbounce Landing Pages WordPress plugin before 1.1.5 does 
not perf ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-85272 (Open edX Platform enables the authoring and delivery of online 
learnin ...)
-       TODO: check
+       NOT-FOR-US: Open edX Platform
 CVE-2026-85271 (Open edX Platform enables the authoring and delivery of online 
learnin ...)
-       TODO: check
+       NOT-FOR-US: Open edX Platform
 CVE-2026-84750 (The Ultra Addons for Contact Form 7 WordPress plugin before 
3.5.51 doe ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-84434 (The Gravity Forms plugin for WordPress is vulnerable to 
Arbitrary File ...)
@@ -646,9 +646,9 @@ CVE-2026-84444 (libheif is a HEIF and AVIF file format 
decoder and encoder. Prio
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-j264-xvrp-5v7q
        NOTE: Fixed by: 
https://github.com/strukturag/libheif/commit/e65071f59a1ac08aa1eb0d07a831deaf6bb4d03b
 (v1.23.2)
 CVE-2026-84400 (CareCam CM2507 IP cameras contain an insufficiently protected 
network  ...)
-       TODO: check
+       NOT-FOR-US: CareCam CM2507 IP cameras
 CVE-2026-84398 (CM2507 IP cameras accept an empty password for a privileged 
account ex ...)
-       TODO: check
+       NOT-FOR-US: CM2507 IP cameras
 CVE-2026-84384 (libheif is a HEIF and AVIF file format decoder and encoder. 
From 1.19. ...)
        - libheif 1.23.2-1
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-24wx-9w62-c96w
@@ -656,45 +656,45 @@ CVE-2026-84384 (libheif is a HEIF and AVIF file format 
decoder and encoder. From
 CVE-2026-83561 (The Complianz GDPR/CCPA Cookie Consent Banner plugin for 
WordPress is  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-81946 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 
firmware ve ...)
-       TODO: check
+       NOT-FOR-US: PLANET
 CVE-2026-81945 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 
firmware ve ...)
-       TODO: check
+       NOT-FOR-US: PLANET
 CVE-2026-81944 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 
firmware ve ...)
-       TODO: check
+       NOT-FOR-US: PLANET
 CVE-2026-81943 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 
firmware ve ...)
-       TODO: check
+       NOT-FOR-US: PLANET
 CVE-2026-81942 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 
firmware ve ...)
-       TODO: check
+       NOT-FOR-US: PLANET
 CVE-2026-81627 (A flaw was found in QEMU. The VAPIC setup hypercall in 
hw/i386/vapic.c ...)
        TODO: check
 CVE-2026-81505 (Convoy is a cloud native webhooks gateway. Prior to 26.6.8, 
Convoy's G ...)
-       TODO: check
+       NOT-FOR-US: Convoy
 CVE-2026-81321 (CM2507 IP cameras store configured wireless network 
credentials in cle ...)
-       TODO: check
+       NOT-FOR-US: CM2507 IP cameras
 CVE-2026-81305 (CM2507 IP cameras automatically execute a predetermined script 
from re ...)
-       TODO: check
+       NOT-FOR-US: CM2507 IP cameras
 CVE-2026-81182 (SysReptor is a fully customizable pentest reporting platform. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: SysReptor
 CVE-2026-81181 (SysReptor is a fully customizable pentest reporting platform. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: SysReptor
 CVE-2026-81180 (SysReptor is a fully customizable pentest reporting platform. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: SysReptor
 CVE-2026-81179 (SysReptor is a fully customizable pentest reporting platform. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: SysReptor
 CVE-2026-81178 (SysReptor is a fully customizable pentest reporting platform. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: SysReptor
 CVE-2026-7006 (Sublime Text for Windows through Build 4192 (Sublime Text 4) 
and Build ...)
        TODO: check
 CVE-2026-79294 (Cross Site Scripting vulnerability in Moonshot AI Kimi version 
as of 2 ...)
-       TODO: check
+       NOT-FOR-US: Moonshot AI Kimi
 CVE-2026-77960 (Bransys ELDis shipped with hardcoded MQTT credentials, which 
will gran ...)
-       TODO: check
+       NOT-FOR-US: Bransys
 CVE-2026-77929 (ClipBucket v5 before 5.5.3-#182 contains a file upload 
vulnerability t ...)
-       TODO: check
+       NOT-FOR-US: ClipBucket
 CVE-2026-77928 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: ClipBucket
 CVE-2026-77927 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: ClipBucket
 CVE-2026-77616 (Semantic MediaWiki is a free, open-source extension to 
MediaWiki that  ...)
        NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77610 (Semantic MediaWiki is a free, open-source extension to 
MediaWiki that  ...)
@@ -1762,27 +1762,27 @@ CVE-2026-85078 (Sanic is an opensource python web 
server/framework. In version 2
 CVE-2026-85077 (Sanic is an opensource python web server/framework. Prior to 
version 2 ...)
        NOT-FOR-US: Sanic
 CVE-2026-82761 (Time-of-check Time-of-use (TOCTOU) Race Condition 
vulnerability in tea ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-82760 (Inefficient Algorithmic Complexity vulnerability in 
team-alembic AshAu ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-82759 (Use of a One-Way Hash with a Predictable Salt vulnerability in 
team-al ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-82723 (Insertion of Sensitive Information into Log File vulnerability 
in team ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-82685 (Authorization Bypass Through User-Controlled Key vulnerability 
in team ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-81868 (Steeltoe is an open source project that provides a collection 
of libra ...)
-       TODO: check
+       NOT-FOR-US: Steeltoe
 CVE-2026-81829 (A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is 
used by ...)
        NOT-FOR-US: quarkus-smallrye-jwt
 CVE-2026-81637 (Insufficient Session Expiration vulnerability in team-alembic 
AshAuthe ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-81632 (Use of HTTP Request With Sensitive Query String vulnerability 
in team- ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-81516 (Steeltoe is an open source project that provides a collection 
of libra ...)
-       TODO: check
+       NOT-FOR-US: Steeltoe
 CVE-2026-81515 (Steeltoe is an open source project that provides a collection 
of libra ...)
-       TODO: check
+       NOT-FOR-US: Steeltoe
 CVE-2026-81481 (Dell OpenManage Server Administrator, versions prior to 
11.1.0.3, cont ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-81480 (Dell OpenManage Server Administrator, versions prior to 
11.1.0.3, cont ...)
@@ -1824,19 +1824,19 @@ CVE-2026-80356 (Dell OpenManage Server Administrator, 
versions prior to 11.1.0.3
 CVE-2026-80355 (Dell OpenManage Server Administrator, versions prior to 
11.1.0.3, cont ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-80218 (Improper Authentication vulnerability in team-alembic 
AshAuthenticatio ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-79752 (CakePHP is a rapid development framework for PHP. Prior to 
4.5.12, 4.6 ...)
        TODO: check
 CVE-2026-78528 (Unauthenticated Broken Access Control in BerqWP <= 4.1.15 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78428 (For users authenticated through SAML or OpenID Connect (OIDC), 
this vu ...)
-       TODO: check
+       NOT-FOR-US: NeuVector
 CVE-2026-78427 (The NeuVector admission webhook silently excludes containers 
from poli ...)
-       TODO: check
+       NOT-FOR-US: NeuVector
 CVE-2026-78426 (The NeuVector JWT verifier accepts noncanonical Base64URL 
encodings of ...)
-       TODO: check
+       NOT-FOR-US: NeuVector
 CVE-2026-78425 (Authorised users of outside applications behind the same 
corporate ide ...)
-       TODO: check
+       NOT-FOR-US: NeuVector
 CVE-2026-78296 (Insufficient Verification of Data Authenticity vulnerability 
in WP Man ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78295 (Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO 
<= 7.1. ...)
@@ -1844,9 +1844,9 @@ CVE-2026-78295 (Unauthenticated Cross Site Request 
Forgery (CSRF) in Xagio SEO <
 CVE-2026-78294 (Contributor Cross Site Scripting (XSS) in  Geo Mashup <= 
1.13.21 versi ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78223 (Improper Verification of Cryptographic Signature vulnerability 
in team ...)
-       TODO: check
+       NOT-FOR-US: team-alembic
 CVE-2026-77614 (Opencast is a free, open-source platform to support the 
management of  ...)
-       TODO: check
+       NOT-FOR-US: Opencast
 CVE-2026-76834 (b2evolution CMS versions 6.7.8 through 7.2.5 contain an 
incomplete fix ...)
        TODO: check
 CVE-2026-76781 (A flaw was found in libxml2. A local user or an attacker 
providing a s ...)
@@ -4490,7 +4490,7 @@ CVE-2026-81869 (OpenTelemetry-Go is the Go implementation 
of OpenTelemetry. From
 CVE-2026-81866 (Apache NiFi 2.9.0 through 2.11.0 provide Connector 
configuration updat ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026 
release ...)
-       TODO: check
+       NOT-FOR-US: Canva application
 CVE-2026-76646 (A remote attacker could cause excessive resource consumption 
by supply ...)
        TODO: check
 CVE-2026-76460 (A vulnerability in an API of Cisco Identity Services Engine 
(ISE) coul ...)
@@ -5504,7 +5504,7 @@ CVE-2026-84501 (An unauthenticated attacker can inject 
arbitrary fake log lines
 CVE-2026-84439 (When audit logging is enabled (zookeeper.audit.enable=true), 
an unauth ...)
        TODO: check
 CVE-2026-84408 (QND contains an improper access control vulnerability in a 
named pipe, ...)
-       TODO: check
+       NOT-FOR-US: QND
 CVE-2026-84397 (Adobe Experience Manager is affected by a stored Cross-Site 
Scripting  ...)
        NOT-FOR-US: Adobe
 CVE-2026-84088 (The Xpro Addons \u2014 140+ Widgets for Elementor WordPress 
plugin bef ...)
@@ -6380,11 +6380,11 @@ CVE-2026-82993 (Vulnerability in the PeopleSoft 
Enterprise PeopleTools product o
 CVE-2026-82992 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
        NOT-FOR-US: Oracle
 CVE-2026-82964 (Improper preservation of permissions in the Avast sandbox 
minifilter d ...)
-       TODO: check
+       NOT-FOR-US: Avast
 CVE-2026-82567 (The myPRO Manager notification gateway exposes an 
unauthenticated HTTP ...)
-       TODO: check
+       NOT-FOR-US: myPRO Manager
 CVE-2026-82410 (Pocketbase is an open source web backend written in go. Prior 
to 0.22. ...)
-       TODO: check
+       NOT-FOR-US: Pocketbase
 CVE-2026-82399 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the 
DNS-over-H ...)
        - coredns <itp> (bug #880676)
 CVE-2026-82311 (Apache Airflow FAB provider: resetting a user's password does 
not dele ...)
@@ -6404,13 +6404,13 @@ CVE-2026-81926 (Concrete CMS 9.4.0 through 9.5.2 did 
not escape colliding page p
 CVE-2026-81925 (Concrete CMS before 9.5.3 improperly neutralized a 
user-supplied custo ...)
        NOT-FOR-US: Concrete CMS
 CVE-2026-81876 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
-       TODO: check
+       NOT-FOR-US: HAPI FHIR
 CVE-2026-81875 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
-       TODO: check
+       NOT-FOR-US: HAPI FHIR
 CVE-2026-81855 (A hardcoded cryptographic client authentication key 
vulnerability exis ...)
-       TODO: check
+       NOT-FOR-US: Wartsila
 CVE-2026-81326 (QND uses a hard-coded cryptographic key, which may allow a 
local attac ...)
-       TODO: check
+       NOT-FOR-US: QND
 CVE-2026-81176 (Svelte devalue is a JavaScript library that serializes values 
into str ...)
        NOT-FOR-US: Sveltejs devalue
 CVE-2026-7514 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
@@ -6424,7 +6424,7 @@ CVE-2026-79708 (GitLab has remediated an issue in GitLab 
EE affecting all versio
 CVE-2026-79651 (A flaw was found in the theme localization endpoints of the 
keycloak-s ...)
        - keycloak <itp> (bug #1088287)
 CVE-2026-79298 (An issue in Howyar Technologies Inc SysReturn Versions prior 
to 11.3.0 ...)
-       TODO: check
+       NOT-FOR-US: Howyar Technologies Inc SysReturn
 CVE-2026-78474 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 
does no ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-78472 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 
does no ...)
@@ -6432,7 +6432,7 @@ CVE-2026-78472 (The Ni WooCommerce Sales Report  
WordPress plugin before 4.2.0 d
 CVE-2026-78252 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-78225 (A hardcoded cryptographic server key vulnerability exists in 
the deplo ...)
-       TODO: check
+       NOT-FOR-US: Wartsila
 CVE-2026-78088 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell 
with PayP ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77702 (The Eventin  WordPress plugin before 4.1.24 does not prevent 
the token ...)
@@ -6488,7 +6488,7 @@ CVE-2026-77403 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 
client. Prior to 1.13.0,
        NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
        NOTE: 
https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06
 (v1.13.0)
 CVE-2026-77401 (Zope AccessControl provides a general security framework for 
use in Zo ...)
-       TODO: check
+       NOT-FOR-US: Zope
 CVE-2026-77360 (oRPC is an tool that helps build APIs that are end-to-end 
type-safe an ...)
        TODO: check
 CVE-2026-77190 (On affected platforms running Arista EOS, an unauthenticated 
attacker  ...)
@@ -10849,7 +10849,7 @@ CVE-2026-90463 (A flaw was found in the sssd NSS 
responder. This input validatio
 CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
        - mattermost-server <itp> (bug #823556)
 CVE-2026-89321 (Publishing limits the compressed size of a VSIX 
(ovsx.publishing.max-c ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL 
Injection v ...)
        NOT-FOR-US: Thinking Software Technology
 CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 
contain ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d208de8694491b4fd5b5c9e67c82663b3ea81c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d208de8694491b4fd5b5c9e67c82663b3ea81c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to