Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a5d208de by Salvatore Bonaccorso at 2026-09-19T09:42:49+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5,25 +5,25 @@ CVE-2026-93922 (SiYuan through 3.8.4 renders notebook names
as raw HTML in the D
CVE-2026-93921 (SiYuan versions through 3.8.4 fail to enforce publish access
control i ...)
NOT-FOR-US: SiYuan
CVE-2026-93873 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in
the contac ...)
- TODO: check
+ NOT-FOR-US: Cotonti
CVE-2026-93872 (Cotonti 1.0.0 passes the base64-decoded cb parameter to
unserialize() ...)
- TODO: check
+ NOT-FOR-US: Cotonti
CVE-2026-93871 (Cotonti through 1.0.0 fails to validate redirect destinations
in page ...)
- TODO: check
+ NOT-FOR-US: Cotonti
CVE-2026-93870 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in
the rating ...)
- TODO: check
+ NOT-FOR-US: Cotonti
CVE-2026-93869 (Cotonti through 1.0.0 contains an open redirect vulnerability
in the c ...)
- TODO: check
+ NOT-FOR-US: Cotonti
CVE-2026-93868 (Cotonti through 1.0.0 derives password recovery validation
tokens from ...)
- TODO: check
+ NOT-FOR-US: Cotonti
CVE-2026-93841 (vLLM through 0.29.0 contains a memory corruption vulnerability
in the ...)
TODO: check
CVE-2026-93840 (vLLM before 0.29.0 validates allowed_token_ids against
tokenizer lengt ...)
TODO: check
CVE-2026-93839 (LightLLM through 1.2.0 contains an authentication bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: LightLLM
CVE-2026-93838 (SGLang versions through 0.5.20 contain an unbounded memory
allocation ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-93741 (A security flaw has been discovered in Totolink A3002MU
Hh-B20211125.1 ...)
NOT-FOR-US: TOTOLINK
CVE-2026-93740 (A vulnerability was identified in Totolink A3002MU
Hh-B20211125.1046. ...)
@@ -43,7 +43,7 @@ CVE-2026-92967 (The Pochipp plugin for WordPress is
vulnerable to Reflected Cros
CVE-2026-92807 (The Save as PDF Plugin by PDFCrowd plugin for WordPress is
vulnerable ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92708 (Svelte devalue is a JavaScript library that serializes values
into str ...)
- TODO: check
+ NOT-FOR-US: Svelte devalue
CVE-2026-92435 (The Mailchimp for WooCommerce WordPress plugin before 6.1.1
does not v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92430 (The Rede Ita\xfa for WooCommerce \u2014 Payment PIX, Credit
Card and D ...)
@@ -99,9 +99,9 @@ CVE-2026-85680 (The Ultimate Member WordPress plugin before
2.13.1 does not esc
CVE-2026-85574 (The Unbounce Landing Pages WordPress plugin before 1.1.5 does
not perf ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85272 (Open edX Platform enables the authoring and delivery of online
learnin ...)
- TODO: check
+ NOT-FOR-US: Open edX Platform
CVE-2026-85271 (Open edX Platform enables the authoring and delivery of online
learnin ...)
- TODO: check
+ NOT-FOR-US: Open edX Platform
CVE-2026-84750 (The Ultra Addons for Contact Form 7 WordPress plugin before
3.5.51 doe ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84434 (The Gravity Forms plugin for WordPress is vulnerable to
Arbitrary File ...)
@@ -646,9 +646,9 @@ CVE-2026-84444 (libheif is a HEIF and AVIF file format
decoder and encoder. Prio
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-j264-xvrp-5v7q
NOTE: Fixed by:
https://github.com/strukturag/libheif/commit/e65071f59a1ac08aa1eb0d07a831deaf6bb4d03b
(v1.23.2)
CVE-2026-84400 (CareCam CM2507 IP cameras contain an insufficiently protected
network ...)
- TODO: check
+ NOT-FOR-US: CareCam CM2507 IP cameras
CVE-2026-84398 (CM2507 IP cameras accept an empty password for a privileged
account ex ...)
- TODO: check
+ NOT-FOR-US: CM2507 IP cameras
CVE-2026-84384 (libheif is a HEIF and AVIF file format decoder and encoder.
From 1.19. ...)
- libheif 1.23.2-1
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-24wx-9w62-c96w
@@ -656,45 +656,45 @@ CVE-2026-84384 (libheif is a HEIF and AVIF file format
decoder and encoder. From
CVE-2026-83561 (The Complianz GDPR/CCPA Cookie Consent Banner plugin for
WordPress is ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81946 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2
firmware ve ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-81945 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2
firmware ve ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-81944 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2
firmware ve ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-81943 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2
firmware ve ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-81942 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2
firmware ve ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-81627 (A flaw was found in QEMU. The VAPIC setup hypercall in
hw/i386/vapic.c ...)
TODO: check
CVE-2026-81505 (Convoy is a cloud native webhooks gateway. Prior to 26.6.8,
Convoy's G ...)
- TODO: check
+ NOT-FOR-US: Convoy
CVE-2026-81321 (CM2507 IP cameras store configured wireless network
credentials in cle ...)
- TODO: check
+ NOT-FOR-US: CM2507 IP cameras
CVE-2026-81305 (CM2507 IP cameras automatically execute a predetermined script
from re ...)
- TODO: check
+ NOT-FOR-US: CM2507 IP cameras
CVE-2026-81182 (SysReptor is a fully customizable pentest reporting platform.
Prior to ...)
- TODO: check
+ NOT-FOR-US: SysReptor
CVE-2026-81181 (SysReptor is a fully customizable pentest reporting platform.
Prior to ...)
- TODO: check
+ NOT-FOR-US: SysReptor
CVE-2026-81180 (SysReptor is a fully customizable pentest reporting platform.
Prior to ...)
- TODO: check
+ NOT-FOR-US: SysReptor
CVE-2026-81179 (SysReptor is a fully customizable pentest reporting platform.
Prior to ...)
- TODO: check
+ NOT-FOR-US: SysReptor
CVE-2026-81178 (SysReptor is a fully customizable pentest reporting platform.
Prior to ...)
- TODO: check
+ NOT-FOR-US: SysReptor
CVE-2026-7006 (Sublime Text for Windows through Build 4192 (Sublime Text 4)
and Build ...)
TODO: check
CVE-2026-79294 (Cross Site Scripting vulnerability in Moonshot AI Kimi version
as of 2 ...)
- TODO: check
+ NOT-FOR-US: Moonshot AI Kimi
CVE-2026-77960 (Bransys ELDis shipped with hardcoded MQTT credentials, which
will gran ...)
- TODO: check
+ NOT-FOR-US: Bransys
CVE-2026-77929 (ClipBucket v5 before 5.5.3-#182 contains a file upload
vulnerability t ...)
- TODO: check
+ NOT-FOR-US: ClipBucket
CVE-2026-77928 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection
vulnera ...)
- TODO: check
+ NOT-FOR-US: ClipBucket
CVE-2026-77927 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection
vulnera ...)
- TODO: check
+ NOT-FOR-US: ClipBucket
CVE-2026-77616 (Semantic MediaWiki is a free, open-source extension to
MediaWiki that ...)
NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77610 (Semantic MediaWiki is a free, open-source extension to
MediaWiki that ...)
@@ -1762,27 +1762,27 @@ CVE-2026-85078 (Sanic is an opensource python web
server/framework. In version 2
CVE-2026-85077 (Sanic is an opensource python web server/framework. Prior to
version 2 ...)
NOT-FOR-US: Sanic
CVE-2026-82761 (Time-of-check Time-of-use (TOCTOU) Race Condition
vulnerability in tea ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-82760 (Inefficient Algorithmic Complexity vulnerability in
team-alembic AshAu ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-82759 (Use of a One-Way Hash with a Predictable Salt vulnerability in
team-al ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-82723 (Insertion of Sensitive Information into Log File vulnerability
in team ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-82685 (Authorization Bypass Through User-Controlled Key vulnerability
in team ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-81868 (Steeltoe is an open source project that provides a collection
of libra ...)
- TODO: check
+ NOT-FOR-US: Steeltoe
CVE-2026-81829 (A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is
used by ...)
NOT-FOR-US: quarkus-smallrye-jwt
CVE-2026-81637 (Insufficient Session Expiration vulnerability in team-alembic
AshAuthe ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-81632 (Use of HTTP Request With Sensitive Query String vulnerability
in team- ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-81516 (Steeltoe is an open source project that provides a collection
of libra ...)
- TODO: check
+ NOT-FOR-US: Steeltoe
CVE-2026-81515 (Steeltoe is an open source project that provides a collection
of libra ...)
- TODO: check
+ NOT-FOR-US: Steeltoe
CVE-2026-81481 (Dell OpenManage Server Administrator, versions prior to
11.1.0.3, cont ...)
NOT-FOR-US: Dell / EMC
CVE-2026-81480 (Dell OpenManage Server Administrator, versions prior to
11.1.0.3, cont ...)
@@ -1824,19 +1824,19 @@ CVE-2026-80356 (Dell OpenManage Server Administrator,
versions prior to 11.1.0.3
CVE-2026-80355 (Dell OpenManage Server Administrator, versions prior to
11.1.0.3, cont ...)
NOT-FOR-US: Dell / EMC
CVE-2026-80218 (Improper Authentication vulnerability in team-alembic
AshAuthenticatio ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-79752 (CakePHP is a rapid development framework for PHP. Prior to
4.5.12, 4.6 ...)
TODO: check
CVE-2026-78528 (Unauthenticated Broken Access Control in BerqWP <= 4.1.15
versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-78428 (For users authenticated through SAML or OpenID Connect (OIDC),
this vu ...)
- TODO: check
+ NOT-FOR-US: NeuVector
CVE-2026-78427 (The NeuVector admission webhook silently excludes containers
from poli ...)
- TODO: check
+ NOT-FOR-US: NeuVector
CVE-2026-78426 (The NeuVector JWT verifier accepts noncanonical Base64URL
encodings of ...)
- TODO: check
+ NOT-FOR-US: NeuVector
CVE-2026-78425 (Authorised users of outside applications behind the same
corporate ide ...)
- TODO: check
+ NOT-FOR-US: NeuVector
CVE-2026-78296 (Insufficient Verification of Data Authenticity vulnerability
in WP Man ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-78295 (Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO
<= 7.1. ...)
@@ -1844,9 +1844,9 @@ CVE-2026-78295 (Unauthenticated Cross Site Request
Forgery (CSRF) in Xagio SEO <
CVE-2026-78294 (Contributor Cross Site Scripting (XSS) in Geo Mashup <=
1.13.21 versi ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-78223 (Improper Verification of Cryptographic Signature vulnerability
in team ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-77614 (Opencast is a free, open-source platform to support the
management of ...)
- TODO: check
+ NOT-FOR-US: Opencast
CVE-2026-76834 (b2evolution CMS versions 6.7.8 through 7.2.5 contain an
incomplete fix ...)
TODO: check
CVE-2026-76781 (A flaw was found in libxml2. A local user or an attacker
providing a s ...)
@@ -4490,7 +4490,7 @@ CVE-2026-81869 (OpenTelemetry-Go is the Go implementation
of OpenTelemetry. From
CVE-2026-81866 (Apache NiFi 2.9.0 through 2.11.0 provide Connector
configuration updat ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026
release ...)
- TODO: check
+ NOT-FOR-US: Canva application
CVE-2026-76646 (A remote attacker could cause excessive resource consumption
by supply ...)
TODO: check
CVE-2026-76460 (A vulnerability in an API of Cisco Identity Services Engine
(ISE) coul ...)
@@ -5504,7 +5504,7 @@ CVE-2026-84501 (An unauthenticated attacker can inject
arbitrary fake log lines
CVE-2026-84439 (When audit logging is enabled (zookeeper.audit.enable=true),
an unauth ...)
TODO: check
CVE-2026-84408 (QND contains an improper access control vulnerability in a
named pipe, ...)
- TODO: check
+ NOT-FOR-US: QND
CVE-2026-84397 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
NOT-FOR-US: Adobe
CVE-2026-84088 (The Xpro Addons \u2014 140+ Widgets for Elementor WordPress
plugin bef ...)
@@ -6380,11 +6380,11 @@ CVE-2026-82993 (Vulnerability in the PeopleSoft
Enterprise PeopleTools product o
CVE-2026-82992 (Vulnerability in the Siebel CRM Deployment product of Oracle
Siebel CR ...)
NOT-FOR-US: Oracle
CVE-2026-82964 (Improper preservation of permissions in the Avast sandbox
minifilter d ...)
- TODO: check
+ NOT-FOR-US: Avast
CVE-2026-82567 (The myPRO Manager notification gateway exposes an
unauthenticated HTTP ...)
- TODO: check
+ NOT-FOR-US: myPRO Manager
CVE-2026-82410 (Pocketbase is an open source web backend written in go. Prior
to 0.22. ...)
- TODO: check
+ NOT-FOR-US: Pocketbase
CVE-2026-82399 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the
DNS-over-H ...)
- coredns <itp> (bug #880676)
CVE-2026-82311 (Apache Airflow FAB provider: resetting a user's password does
not dele ...)
@@ -6404,13 +6404,13 @@ CVE-2026-81926 (Concrete CMS 9.4.0 through 9.5.2 did
not escape colliding page p
CVE-2026-81925 (Concrete CMS before 9.5.3 improperly neutralized a
user-supplied custo ...)
NOT-FOR-US: Concrete CMS
CVE-2026-81876 (HAPI FHIR is a complete implementation of the HL7 FHIR
standard for he ...)
- TODO: check
+ NOT-FOR-US: HAPI FHIR
CVE-2026-81875 (HAPI FHIR is a complete implementation of the HL7 FHIR
standard for he ...)
- TODO: check
+ NOT-FOR-US: HAPI FHIR
CVE-2026-81855 (A hardcoded cryptographic client authentication key
vulnerability exis ...)
- TODO: check
+ NOT-FOR-US: Wartsila
CVE-2026-81326 (QND uses a hard-coded cryptographic key, which may allow a
local attac ...)
- TODO: check
+ NOT-FOR-US: QND
CVE-2026-81176 (Svelte devalue is a JavaScript library that serializes values
into str ...)
NOT-FOR-US: Sveltejs devalue
CVE-2026-7514 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
@@ -6424,7 +6424,7 @@ CVE-2026-79708 (GitLab has remediated an issue in GitLab
EE affecting all versio
CVE-2026-79651 (A flaw was found in the theme localization endpoints of the
keycloak-s ...)
- keycloak <itp> (bug #1088287)
CVE-2026-79298 (An issue in Howyar Technologies Inc SysReturn Versions prior
to 11.3.0 ...)
- TODO: check
+ NOT-FOR-US: Howyar Technologies Inc SysReturn
CVE-2026-78474 (The Ni WooCommerce Sales Report WordPress plugin before 4.2.0
does no ...)
NOT-FOR-US: WordPress plugin
CVE-2026-78472 (The Ni WooCommerce Sales Report WordPress plugin before 4.2.0
does no ...)
@@ -6432,7 +6432,7 @@ CVE-2026-78472 (The Ni WooCommerce Sales Report
WordPress plugin before 4.2.0 d
CVE-2026-78252 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-78225 (A hardcoded cryptographic server key vulnerability exists in
the deplo ...)
- TODO: check
+ NOT-FOR-US: Wartsila
CVE-2026-78088 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell
with PayP ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77702 (The Eventin WordPress plugin before 4.1.24 does not prevent
the token ...)
@@ -6488,7 +6488,7 @@ CVE-2026-77403 (RabbitMQ amqp091-go is a Go AMQP 0.9.1
client. Prior to 1.13.0,
NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
NOTE:
https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06
(v1.13.0)
CVE-2026-77401 (Zope AccessControl provides a general security framework for
use in Zo ...)
- TODO: check
+ NOT-FOR-US: Zope
CVE-2026-77360 (oRPC is an tool that helps build APIs that are end-to-end
type-safe an ...)
TODO: check
CVE-2026-77190 (On affected platforms running Arista EOS, an unauthenticated
attacker ...)
@@ -10849,7 +10849,7 @@ CVE-2026-90463 (A flaw was found in the sssd NSS
responder. This input validatio
CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-89321 (Publishing limits the compressed size of a VSIX
(ovsx.publishing.max-c ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL
Injection v ...)
NOT-FOR-US: Thinking Software Technology
CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2
contain ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d208de8694491b4fd5b5c9e67c82663b3ea81c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d208de8694491b4fd5b5c9e67c82663b3ea81c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits